We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Windows 5.6.3.277 status, Support Tool and Mac documentation checked July 30, 2026

Malwarebytes Not Working? Fix Launch, Update and Scan Failures

Start with the exact symptom. A window that won't open, an update that can't reach the server and a scan that sits on one archive need different evidence and different fixes.

Current 5.6.3 issue trackedRepair before CleanProtection handoff included

Quick answer: First identify whether Malwarebytes won't open, can't update, won't start a scan, appears stuck during a scan or has a protection layer turned off. On Windows 5.6.3.277, there's also a current July 2026 issue in which some users can't reopen Malwarebytes after quitting and see “Unexpected error while signaling first instance”; Malwarebytes forum staff say development is working on a resolution. Preserve the exact error, version and logs, keep another trusted protection layer active, check the supported operating system and connection path, then use the official Support Tool Repair option before Clean or a full reinstall. Don't delete MBAMService, protected registry keys or drivers by hand.

Start with the failure you can actually observe

“Malwarebytes is not working” can mean five different things: the window never appears, the app opens but can't update, a scan won't begin, an active scan appears stuck, or one real-time protection module won't stay enabled. Choose the row that matches what you can see before changing the installation.

SymptomFirst evidenceFirst safe checkDon't start with
No window or exact launch errorError text, version, whether tray/service remainsOne reboot, current-issue check, logsRegistry or service deletion
Update spinner or connection errorApp version, clock, VPN/proxy/firewall stateCurrent update path and connection testRepeated reinstall
Scan button does nothingScan type, protection state, prior reportSmall supported scan and available storageEvery Custom Scan option
Scan sits on one stageCurrent object, file count, disk activity, elapsed timeWait, record object, isolate archive or driveCalling it frozen from the timer alone
Protection module is offWhich module, license, restart and conflict stateUpdate, restart once, preserve another protection layerDisabling all antivirus products

The distinction saves time. A server connection problem will survive a reinstall if the same proxy or hosts-file rule remains. A large archive can make a healthy scanner look motionless, while a damaged service can prevent even a small scan from starting.

If the product works and your question is which scan to choose, use our Malwarebytes scan-types guide. This page is for failures, not for turning every normal scan delay into an incident.

There's a current Windows 5.6.3.277 reopen issue

As of July 30, 2026, Malwarebytes lists Windows version 5.6.3.277 as the current release, dated July 23. Its public release notes mention notification changes and a quarantine-progress fix, but they don't yet announce a correction for the launch failure described below.

Users in the official “Unexpected error while signaling first instance” forum thread report that the app starts with Windows but may not reopen after they quit it. A forum expert wrote on July 29 that Malwarebytes was aware, and a root administrator said the development team was working on a solution.

The reports include Windows 10 and Windows 11 systems running 5.6.3, but the thread doesn't establish how common the defect is. Don't turn a handful of reports into a prevalence number, and don't assume every launch failure has this cause.

A same-day r/Malwarebytes report associated the timing with a July Windows update and linked the official forum. That's useful directional evidence, not proof that Windows Update caused the bug; the stronger shared pattern is Malwarebytes 5.6.3 after the application is quit.

Keep a protection layer active while you troubleshoot

If Malwarebytes is your registered Windows security provider and its real-time modules are unavailable, confirm that Microsoft Defender or another trusted antivirus has resumed active protection before downloading tools, opening email or browsing unfamiliar sites. Windows usually manages provider handoff, but “usually” isn't a verification.

Open Windows Security and check the current virus and threat protection provider rather than relying on an old tray icon. Don't switch off Defender, Malwarebytes and a second antivirus at the same time just to make an error disappear. A clean launch test isn't worth an unprotected troubleshooting session.

Malwarebytes Free is primarily an on-demand scanner, while paid Device Security tiers include real-time protection. Our Free versus Premium guide explains that product boundary, and our current Malwarebytes review covers the broader protection role.

Write down the error, version and timeline before changing anything

Capture the exact wording of the error, not a paraphrase such as “it crashed.” Record Windows or macOS version, Malwarebytes application version, component package when visible, the last successful update or scan, and whether the problem began after an app update, operating-system update, network change or another security installation.

Note what still works. A tray icon with no window, a responsive window with a dead update control and a scan that reaches one specific archive are different states. Save a screenshot that includes the time and relevant status, while redacting email addresses, license information and private paths.

The current community Malwarebytes troubleshooting sticky asks for operating system, version, exact error and prior steps because those details separate repeatable defects from guesswork. Keep the same discipline even if you solve the problem without posting.

If Malwarebytes won't open, separate a dead shortcut from a dead application

Try the current Start menu entry or Applications folder once instead of repeatedly clicking the same pinned shortcut. If one entry works and another does not, remove the stale shortcut and pin the working application. If neither opens, check whether a tray icon appears and whether Windows reports the exact first-instance error.

On Windows, wait for the desktop to finish loading before the test, especially immediately after an update. On Mac, use the menu-bar icon or Applications folder. Don't download a “fixed” executable from a search result, forum attachment or mirror; use only the verified vendor installer described in our Malwarebytes installation guide.

Malwarebytes' current app-won't-open article directs Windows and Mac users to collect diagnostic logs and contact Support. That short official page is a useful boundary: persistent launch failures need evidence, not an escalating collection of random service commands.

If it opens only after reboot, preserve that pattern

A reboot that restores access is a temporary state change, not a durable repair. Record whether Malwarebytes launches automatically, whether it opens a second time while still running, and whether the failure appears only after choosing Quit Malwarebytes. That sequence closely matches the current 5.6.3 forum reports.

Until Malwarebytes publishes a fixed build, avoid quitting the application unnecessarily if your system exhibits the exact current pattern. A forum administrator mentioned delayed startup as a temporary workaround, but the wording is ambiguous and shouldn't be treated as a universal instruction to delay real-time protection permanently.

Don't reinstall after every reboot. Several people in the current thread reported that reinstalling didn't remove the reopen failure. Repetition can erase logs and create activation or configuration noise without changing the underlying release.

The window, tray process and protection service aren't the same layer

A missing interface doesn't automatically prove that every protection component stopped. Conversely, a visible tray icon doesn't prove that all real-time modules are healthy. Check the status inside the application when it opens and confirm the active Windows security provider rather than inferring protection from one process name.

When Support asks for service information, record state and timestamps rather than trying to force protected components to stop. Access denied can be expected when self-protection is active. A protected security service should resist casual deletion by an administrator or by malware using the same privilege.

The current Windows General settings documentation says background launch is on by default and self-protection is normally enabled. Those defaults explain why ordinary startup and protected-service behavior may differ from a conventional desktop utility.

Don't delete MBAMService, drivers or registry keys by hand

The first post in the current forum thread describes deleting the MBAMService registry entry after the Support Tool Clean option didn't detect the product. That's a user's attempted workaround, not Malwarebytes guidance, and the launch problem remained after reinstall. We don't recommend reproducing it.

Manual removal can leave drivers, service registrations, scheduled components and activation state inconsistent. It can also destroy the exact evidence Support needs to distinguish a current product bug from installation damage. Use the signed Support Tool because its Repair and Clean actions understand the product's own component layout.

If you already removed components manually, stop improvising and tell Support exactly what changed. Our complete Malwarebytes uninstall guide covers the documented removal hierarchy without presenting registry deletion as routine maintenance.

Malwarebytes troubleshooting flow from symptom and evidence through baseline checks, update, logs and Repair, with Clean reinstall only after Repair fails
Diagnostic order: identify the failure, preserve evidence and protection, check the baseline, then use Repair before the separate Clean-reinstall escalation. GPT Image 2 educational diagram, not product UI.

An application update and a threat-intelligence update solve different gaps

The application version changes the interface, services and program code. Threat-intelligence and component updates refresh detection logic and supporting modules. A device can have a current application build but stale protection data, or fresh intelligence while still running an older supported application.

Record both statuses when possible. If a scan runs but can't recognize new threats because intelligence updates fail, reinstalling the same app build may hide the real server-access problem. If the application itself is affected by a release defect, new intelligence alone won't replace its executable code.

The official Windows application-update guide recommends automatic updates and documents the manual check. Use the version displayed after restart, not the installer filename in Downloads, as proof that the update completed.

Use the current Windows update path before downloading another installer

On current Windows builds, open Settings, choose General, find Application updates and select Check for updates. If the control keeps loading, note the time and exact behavior. If it returns an error, preserve the message instead of dismissing it and immediately launching a cleanup tool.

Malwarebytes' current update-failure article recommends one restart and the same Settings path, then Support if the update still fails. The page covers both Windows and macOS and explicitly frames the problem as a possible connection failure to Malwarebytes servers.

After an update appears to finish, reopen Settings and verify the displayed version. Compare it with the official Windows v5 lifecycle table, which currently lists 5.6.3.277 and component package 161.0.5685. Don't assume the newest downloaded installer has already replaced the running build.

Trace the update connection without dismantling security

Confirm that the device clock, date and time zone are correct because certificate validation depends on them. Test a normal trusted website and the Malwarebytes help site. A captive portal, filtered guest network or broken DNS path can make an update client fail even when one cached browser page still opens.

Check whether a VPN, deliberately configured proxy, DNS filter, hosts-file entry, third-party firewall or another security product can block Malwarebytes servers. The vendor lists those categories in its current update article. Change one layer at a time and restore it after the test so you know which condition mattered.

General settings say the home-user proxy option should normally remain off unless a proxy is intentionally configured. Don't paste an unknown proxy address from a forum. If a business or school manages the connection, ask its administrator to review logs and destination policy instead of bypassing controls.

Regional download restrictions are different from a broken update client. Don't use unofficial mirrors to evade a vendor territory notice. A modified installer creates a much larger security problem than the one you were trying to solve.

Unsupported Windows can look like a product failure

The current desktop system requirements list Windows 10 and Windows 11, an active internet connection, 4 GB of RAM and 1 GB of free installation space for Windows. Mac support currently spans macOS Big Sur 11 through Tahoe 26.

Malwarebytes ended current application support for Windows 7, 8 and 8.1 in 2026. Its legacy Windows notice says frozen compatible versions receive signature updates, but they don't become current Windows 5 builds. Don't force a modern installer onto an unsupported system.

A fully supported Windows edition can still be missing required servicing updates. Malwarebytes' Windows update guidance notes that missing security updates may block installation or updating. Finish the operating-system restart cycle before blaming the scanner.

If a scan won't start, reduce the test to the smallest useful scope

Confirm that the interface responds, protection information loads and the update status is current. Then start the ordinary scan recommended by the current app rather than selecting every disk, archive, rootkit and potentially unwanted-item option at once. A small reproducible failure is easier to diagnose than an overloaded custom job.

Review whether a previous scan is still finalizing or waiting for an action in Detection History. Check that the target drive is mounted and readable. If the button does nothing, record whether the event appears in reports or whether any error flashes and disappears.

The current Windows scan-settings documentation explains available detection controls, while our detailed scan guide separates Quick, Threat, Custom, Deep and rootkit use cases. Don't change PUP/PUM policy merely to make a scan begin.

A long scan isn't frozen merely because the counter pauses

Watch whether the current object changes, file count advances, disk activity continues and the interface responds. Large compressed archives, mail stores, virtual-machine disks, source trees with many tiny files and slow external drives can hold a stage for much longer than a normal user folder.

Rootkit scanning can also add substantial work and may inspect low-level objects differently. If you enabled it without a rootkit-specific reason, compare one normal scan rather than assuming the engine is broken. Keep the two reports so the changed scope remains visible.

A July 2026 Android community report described a scan running for hours and sticking around the Google photo picker; Malwarebytes Support asked for logs rather than declaring a universal fix. That platform-specific case shouldn't be transplanted onto Windows, but it reinforces the value of capturing the exact stage.

Record the current object before you stop a repeating scan

Take a screenshot of the current path or stage, elapsed time and item count before canceling. If the same object appears on the next controlled scan, you have a useful lead. If the location changes, the issue may be overall throughput rather than one corrupt archive.

Don't post a full private path publicly without redaction. Usernames, client names, medical folders and project codenames can appear in scanner views. Give Malwarebytes Support the unredacted diagnostic package through its private ticket route when needed.

If the object is an archive you created and trust, test a copied sample only when you have sufficient disk space and know it contains no active malicious material. If the archive came from an incident, keep it isolated and use the quarantine and false-positive guide instead of unpacking it casually.

Check free space, drive health and archive behavior

Repair and reinstall need working storage beyond the final application footprint. Confirm that the system drive and the scanned target have free space and that Windows or macOS doesn't report file-system errors. A failing external disk can stall reads while the scanner waits correctly for the operating system.

Temporarily disconnect an unnecessary questionable external drive only after safely ejecting it, then test a small local scan. Don't use that test to declare the external drive clean. It only tells you whether the scan engine can complete without that storage path.

Encrypted containers, cloud placeholders and virtual disks can produce permission or hydration delays. Make the file locally available when you own it and understand the impact, or exclude the test target only long enough to isolate the fault. A broad permanent exclusion isn't a performance fix.

If Real-Time Protection won't turn on, identify the exact module

Record whether Malware Protection, Web Protection, Ransomware Protection or another named layer is off. Check subscription and activation state, application and intelligence versions, and whether a restart is pending. A single module failing is more specific than “all shields are broken.”

Try the switch once and note whether it remains on, returns off immediately or produces an error. Repeated toggling can flood logs without changing state. Confirm that another trusted antivirus is active if Malware Protection remains unavailable.

General settings normally recommend leaving self-protection on and Delay Real-Time Protection off. Don't permanently weaken those defaults to hide a startup error. If a temporary vendor-documented workaround changes startup timing, date the change and reverse it after the fixed release is installed.

Another antivirus can create a conflict without being “bad”

Two security products can inspect the same file, network stream or low-level operation and interfere with each other's updates, drivers or protection startup. The current Malwarebytes coexistence guidance acknowledges possible protection, connectivity and stability conflicts and discusses mutual allowances when necessary.

Don't copy an entire exclusion list from one product into the other. First identify which component is blocked, confirm signatures and paths, and create the narrowest temporary exception supported by the vendors. Remove it after updates and retest.

Our Malwarebytes versus Microsoft Defender comparison explains the roles users commonly assign each product. For broader Windows choices, see the Windows 11 antivirus guide; replacing software is a separate decision from diagnosing one installation.

Use one controlled reboot, not a ritual restart loop

Save work, note protection state and restart once after an application update, operating-system update or repair prompt. After sign-in, wait for startup to settle, verify the active security provider and reproduce the same action. Record whether the result changed.

If reboot restores the app only until you choose Quit, you have captured a strong sequence for the current 5.6.3 issue. If it changes nothing, repeating the same restart five more times adds little evidence. Move to logs and the documented repair path.

A restart differs from shutting down on systems with Windows Fast Startup behavior, but don't change unrelated firmware or storage settings for a Malwarebytes UI failure. Use the ordinary Restart command unless official support directs otherwise.

Collect Windows logs before Repair changes the installation

Download the signed Malwarebytes Support Tool from the official help route and use its log-gathering function before Repair or Clean. The current log collection guide says the tool creates Mbst-grab-results.zip for a support case.

Treat that archive as private diagnostic material. It can include system, application and account context that doesn't belong in a public forum or cloud link. Attach it only through an authorized Malwarebytes ticket unless a support agent gives a different secure route.

Collecting before repair preserves the broken state. A successful repair can be good for the device but bad for root-cause evidence if every relevant log is overwritten or the old component layout disappears. Keep the collection time in your notes.

Use Support Tool Repair before a full Clean reinstall

The official Support Tool Repair guide says Repair removes and reinstalls Malwarebytes while saving configuration and activation-key information. That makes it the appropriate documented escalation for installation damage after baseline checks and logs.

Close other applications and save work before beginning because Windows will restart. Let the tool finish rather than killing it when the interface pauses during removal or installation. After sign-in, wait for Malwarebytes to initialize and verify version, update and protection state.

Repair isn't guaranteed to fix a current release bug. If the exact 5.6.3 first-instance sequence remains, preserve the new result and follow the vendor's current-issue status. A clean reinstall of the same affected build may reproduce the same defect.

Repair requires .NET Framework 4.8 and a restart

Malwarebytes currently lists .NET Framework 4.8 as a requirement for the Windows Support Tool Repair process. If the tool reports that it's missing or damaged, use the official Microsoft and Windows servicing path rather than downloading a repackaged framework installer from a third-party site.

Make sure the device has stable power, working storage and enough space for removal and reinstallation. On a laptop, connect power. On a managed device, confirm that policy allows the tool to make changes and restart Windows.

Record the Support Tool version and final result. A message that Repair completed, couldn't find a product or failed at one stage is useful evidence. Don't convert “product not found” into permission to delete service keys manually.

Repair and Clean are different escalation levels

Repair aims to rebuild the installation while preserving configuration and activation information. Clean is a full-removal route used when normal uninstall or repair can't leave a usable state. Because it changes more, it should come later and only after diagnostics are collected.

Before Clean, confirm access to the Malwarebytes account or activation information you're entitled to use, save necessary Allow list documentation and verify another protection provider. Don't assume every local preference or quarantine item will survive a full cleanup.

If the problem is a confirmed current-version defect, ask whether Clean will install the same build. More aggressive removal doesn't make identical program code behave differently. A Support ticket may be more productive than repeating the cycle.

A safe reinstall includes provenance, protection handoff and validation

Use the normal uninstaller first, then the official Support Tool Clean path only when needed. Follow the current Windows installation troubleshooting and download the installer from Malwarebytes, not an ad, mirror or forum attachment. Keep Defender or another trusted provider active during the gap and avoid risky browsing until real-time status is verified.

After reinstall, sign in or activate through the legitimate account flow and apply updates before restoring custom exceptions. Review each Allow list entry rather than importing historical exclusions blindly. A stale broad rule can make a fresh installation less safe than the damaged one.

Our installation and uninstall guides provide the platform-specific sequence. The Malwarebytes plans and renewal guide explains entitlement questions if activation, device count or account state is the actual blocker rather than program integrity.

On Mac, check permissions and collect the Mac-specific failure

Open Malwarebytes from Applications or the menu-bar icon and record whether macOS blocks launch, the app bounces and closes, or the interface opens without protection. Don't apply Windows service, registry or .NET instructions to macOS.

Confirm that the installed macOS version remains supported and that Malwarebytes has the current permissions required for its features. Our Malwarebytes for Mac review explains Full Disk Access and platform limits without pretending the Mac application is a port of every Windows component.

If the app won't open, the same official app-won't-open page directs Mac users toward diagnostic information and Support. Preserve the error and recent macOS or application changes before removing the bundle.

Mac update and connection errors have their own code families

On current macOS, use the Malwarebytes menu beside the Apple menu and choose Check for Updates. If the app can't reach the server, test the network, date and time, VPN and other security filtering one layer at a time, just as on Windows, while keeping the platform-specific interface path.

The current Mac error reference separates connection, activation and authentication failures. Preserve the exact code because an account sign-in problem doesn't require the same fix as a network connection failure.

If Privacy VPN is involved, diagnose it as a network layer rather than assuming the antivirus scanner is corrupt. Our Malwarebytes Privacy VPN review covers protocol, platform and connection boundaries separately.

Old Mac application data can block a reinstall

Dragging an application icon or installing over a damaged copy may leave supporting data that reproduces the failure. Malwarebytes' current Mac reinstall article says old application data can prevent reinstallation and points to the official Mac uninstall tool and restart.

Use that documented tool instead of deleting random Library folders from a forum list. A path that was correct for an older version may now belong to another component or contain diagnostics. Back up and preserve business-required information before removal.

After reinstall, recheck Full Disk Access and other required permissions rather than assuming macOS carried them forward. Run a small current scan and save its report. The Mac antivirus guide can help if the larger question becomes whether Malwarebytes still fits the device.

Validate five states before calling the repair successful

Confirm the running application version and component package, then complete an update check. Verify that the expected protection modules remain enabled after several minutes and after one restart. Check the active Windows security provider when Malwarebytes is supposed to provide real-time protection.

Run the smallest appropriate scan and open its report in Detection History. A green dashboard without a saved report proves less than a completed scan with current timestamps and definitions. If quarantine is involved, don't restore uncertain items merely to test the interface.

Finally, reproduce the original action once. If the failure occurred after Quit, close and reopen only when the current issue status or Support guidance makes that test sensible. If the app immediately fails again, document the result rather than repeating Clean.

A useful Support ticket is a compact incident record

Include operating system and build, Malwarebytes version and component package, exact error, first observed time, the last known working state, relevant updates or network changes, and the shortest reproduction sequence. State what still works and whether another protection provider is active.

Attach Mbst-grab-results.zip privately and mention whether Repair or Clean was attempted, including its result. If the issue matches the current first-instance bug, link the official thread and say whether quitting is required to reproduce it. Don't claim a Windows update caused it unless Malwarebytes confirms that cause.

Use the official Malwarebytes contact route. The current July 22 article directs users to the support-site chatbot and notes that Malwarebytes has no inbound support phone number. A concise ticket gives the support and development teams a better chance of comparing your logs with other cases than an angry screenshot without version or sequence.

Match the escalation to the failure pattern

Observed patternMost useful next stepProtection safeguardMain trap
5.6.3 opens at boot but not after QuitPreserve sequence and logs; follow current forum/release statusAvoid unnecessary Quit; verify modules/providerDeleting MBAMService or blaming Windows Update as proven cause
Check for updates spins foreverClock, network, VPN/proxy, hosts, firewall and SupportKeep real-time provider activeReinstalling without changing the blocked connection
Small scan won't startUpdate, status check, logs, then RepairUse another current provider if malware protection is unavailableLaunching the heaviest Custom Scan
Scan repeats one archive or driveRecord object and activity; isolate storage pathKeep suspicious material containedUnpacking an unknown archive casually
One real-time module turns off againRecord module, entitlement, conflict and logsConfirm overlapping provider coverageDisabling every security layer
Repair completes but exact bug remainsValidate version and file a reproducible ticketMaintain handoff until fixed buildRepeating Clean with the same build
Mac reinstall says old data remainsOfficial Mac uninstall tool, restart, reinstall and permissionsUse macOS and another trusted layer appropriatelyFollowing Windows registry instructions

The matrix is deliberately conservative. It preserves evidence and coverage before increasing the amount of change. A repair that follows a clear baseline can teach you something; a chain of unrelated tweaks makes the final success impossible to attribute.

If the device may already be infected, troubleshooting the security product is only one workstream. Use the malware removal guide for containment and recovery, and use AdwCleaner when adware or browser modifications are the defined target.

Keep performance, website blocks and mobile failures in their own lanes

High CPU or disk use while Malwarebytes otherwise works is a performance investigation, not automatically an installation failure. Capture the responsible process, scan state and workload. Don't use Clean as the first response to every gaming slowdown or busy scheduled scan.

A blocked website is a Web Protection or Browser Guard event and may not involve a local file or broken scanner. The Browser Guard review explains extension-level exceptions, while the quarantine guide covers local detections and narrow Allow list decisions.

Android and iOS use different scan and protection models. Our Malwarebytes mobile review explains why a Windows service fix can't apply to a phone. Separating those intents also prevents a support ticket from mixing three unrelated products.

Final order: evidence, baseline, update, logs, Repair, then Clean

Identify the exact failure and preserve the error, version, timing and protection state. Check current known issues, supported operating system, storage and connection path. Run one controlled restart and the smallest relevant test rather than changing five variables.

Collect the private diagnostic archive before Repair. Use Support Tool Repair for damaged Windows installations and validate version, intelligence, protection, scan and report afterward. Escalate to Clean or a full reinstall only when the documented repair path and Support context justify the larger change.

For the July 2026 first-instance error, keep the claim dated and narrow: reports associate it with Windows 5.6.3.277 after Quit, and Malwarebytes forum staff say a solution is being developed. Until a fixed release is published, don't promise that registry edits, repeated reinstalls or a particular Windows update explanation will solve it.

Malwarebytes launch, update and scan FAQ

Why will Malwarebytes not open after I quit it?

A current Windows 5.6.3.277 issue reported in late July 2026 can produce “Unexpected error while signaling first instance” after the app is quit. Malwarebytes forum staff say development is working on a resolution. Reboot can restore access temporarily, but preserve logs and check the official thread and release notes for a fixed build rather than repeatedly reinstalling.

Does the July 2026 Windows update cause the Malwarebytes launch error?

That cause hasn't been established. One Reddit report associated the timing with Windows Update, while the more direct official-forum reports describe the failure after Malwarebytes 5.6.3.277 is quit. Treat the Malwarebytes version and exit sequence as evidence, not proof that a particular Windows update caused it.

How do I fix Malwarebytes when Check for updates keeps loading?

Restart once, confirm the device clock and supported operating system, then check whether a VPN, proxy, hosts-file entry, DNS filter, firewall or another security product blocks Malwarebytes servers. On current Windows builds use Settings, General, Application updates, Check for updates. Save any exact error and contact Support if it persists.

What should I do if a Malwarebytes scan won't start?

Confirm that the app and protection services are responsive, update the application and threat intelligence, check free disk space and inspect the scan configuration. Try the smallest appropriate scan rather than immediately selecting every custom option. If the scan still won't start, collect logs before running Support Tool Repair.

How can I tell whether a Malwarebytes scan is frozen?

Watch the current object, elapsed time, file count, disk activity and whether the interface still responds. Large archives, virtual-machine images, slow external drives and rootkit scanning can hold one stage for a long time. Record the object before stopping so the next test can isolate the cause.

Should I use Malwarebytes Support Tool Repair or Clean?

Use Repair first for a damaged Windows installation. Malwarebytes says Repair removes and reinstalls the application while saving configuration and activation information. Clean is a later full-removal path and can erase useful state, so collect logs and confirm another protection layer before using it.

Does Malwarebytes Support Tool Repair restart Windows?

Yes. The current official Repair workflow requires .NET Framework 4.8 and restarts Windows while it removes and reinstalls Malwarebytes. Save work, close applications and collect diagnostics before beginning.

Can I delete MBAMService or Malwarebytes registry keys to fix the app?

No. Access-denied behavior can be part of self-protection, and manual deletion can damage the installation or remove evidence without fixing the underlying bug. Use the signed Malwarebytes Support Tool and its documented Repair or Clean paths instead.

Why will Malwarebytes Real-Time Protection not turn on?

Check subscription state, current app and intelligence versions, the individual protection module status, pending restart, other antivirus conflicts and Windows security health. Don't leave every security layer disabled during testing. If a module immediately turns off again, preserve logs and repair the installation.

What should I send Malwarebytes Support?

Include Windows or macOS version, Malwarebytes version and component package, exact error text, when the failure began, what still works, recent changes and the private diagnostic archive. The Windows Support Tool normally creates Mbst-grab-results.zip. Don't post that archive publicly because it can contain device and account context.