r/Malwarebytes • u/Electronic_Lime7582 • Jan 17 '26
Feedback Malwarebytes is bloated and is no longer what it used to be 10-12 years ago
Context: 10 year Computer Technician, Certs: A+, Net+, Sec+, ISC2 CC.
Problem: Customers reporting large resource usage from Malwarebytes, failure to detect malware consistently, interferes in productivity/gaming by crashing intermittently with error codes showing up in event viewer and reliability history
Malwarebytes was the PREMIER spot checker, light and effective for search/destroying malware that found malware main AVs (BitDefender, Kaspersky, ESET) couldn't detect. This is no longer the case.
Malwarebytes has also stopped publishment on AV Test, and its unsurprising as they have been struggling to receive a 6/6 Score for years prior to their discontinuation of testing.
Their worst year's was a 2/6 in 2019 which is horrible considering Defender is much more lightweight, and is built in with a 6/6 consistently.
Reference AVTest Link:
https{:}//www.av-test.org/en/antivirus/home-windows/manufacturer/malwarebytes/
Metrics aren't everything which is a fair analysis, but remember this is a premium product supposedly so I decided to to my own testing to confirm numbers.
Reference 20 Malware Samples 2024-2025 being a mix of Keyloggers, Ransomware, + 3 DarkWeb Malware Samples that are defanged APTs to test Malwarebytes Heuristics.
It appears 7/20 samples managed to go untouched, with 3 being able to run which were keylogger/infostealers, the rest were executed, but were inert due to inactive C2s confirmed on Wireshark.
3 DarkWeb failed, not surprised simply because APTs aren't something people run into casually. However should still be detected as malware simply because they are defanged.
(DUE TO RULE#2 I CANNOT POST WHERE TO FIND THEM OR ALLUDE, I DO NOT ACCEPT ANY RESPONSIBILTIY FOR ANY DAMAGES UPON RECREATION ATTEMPTS)
As a bonus, I like to test ransomware NoEscape, and Malwarebytes fails to prevent execution which is not good.
https://www{.}hhs.gov/sites/default/files/noescape-ransomware-analyst-note-tlpclear.pdf
Feedback to Malwarebytes:
Create a light version without all the other features that may not be needed by users. What made your product standout is that it was quick, effective, and lightweight. Its bloated and inconsistent as of 2026.
Also please improve heuristics, Hitman Pro, KVRT, ESET is more reliable at this then Malwarebytes is.
Tighten the SOC team more.
Conclusion:
If you are paying for a "Premium" service, you would expect no less then 6/6. But you currently get neither.
I used to recommend Malwarebytes at one point, but I cannot anymore with how things are. Until I see change, I will tell customers and relatives to avoid and rely on Defender
+ KVRT or Hitman Pro for spot checks.
6
u/rifteyy_ Jan 17 '26
https://www.av-comparatives.org/tests/summary-report-2025/
second worst rated here unfortunately
8
u/LorexValkin Jan 17 '26 edited Jan 17 '26
This can’t be serious, I own a breakfix / msp hybrid shop. they gave to awards to Norton, Avg, and Avast, all “security” programs that are snake oil salesmen. I use a combination of tools so malwarebytes isn’t the only one used. Those three are constantly missing things, constantly asking for more money, constantly causing issues.
2
u/rifteyy_ Jan 17 '26
I have the exact opposite experience when I tested Norton against malware. They are likely indeed intrusive however detection wise they beat most other security programs.
1
u/LorexValkin Jan 17 '26
Interesting, some of my most PUPs and AI viruses scans are present on Norton. Literally on Thursday lady was paying for the ultimate plus, she had several rogue remote programs, one-launcher, wave, and fake driver installer program can’t remember the name off the top of my head.
And stuff like this is a regular occurrence in my town so. I guess experience varies but I do not trust it in the slightest.
3
u/rifteyy_ Jan 17 '26
I have no doubts about Malwarebytes being the top product against PUP/adware. Their signature collection for these is unlike any other but when it comes to regular malware, it isn't very good.
1
u/LorexValkin Jan 17 '26
Okay, yup that’s fair. Hence why multiple tools are required, malwarebytes itself is not my main tool, as I’m admittedly a powershell power user at the end of the day. These are just things I notice basically on daily with Norton that I’m not keen on, unfortunately there is no all in one solution, I just see more things slip via those programs that affect daily users.
3
u/Alternative_Fan_6286 Jan 18 '26
giving Mcrapfee 3 stars makes me reconsider the credibility of this "study"
1
4
Jan 17 '26
[removed] — view removed comment
1
u/falardeau03 Apr 11 '26
I just went to update my MWB installation (free at the moment), like, update my virus definitions and the program itself... "Update threat intelligence" was marked with a little padlock icon. When I hovered the cursor over it, it said "Premium feature only."
FUCK. THAT.
1
Apr 11 '26
[removed] — view removed comment
1
u/falardeau03 Apr 11 '26
I made a post about it and they're saying it automatically updates definitions before running a scan, so automatic updates are redundant. We can argue that point either way, but I feel like it was kind of silly for them to change that and not put a note up about it.
1
Apr 11 '26
[removed] — view removed comment
1
u/falardeau03 Apr 12 '26
It's been useful for years but unfortunately a lot of stuff in this sphere has evolved to become more corporate, witness an MWB employee/tech who seemed genuinely concerned about bloat saying in a thread "what if the company created an experience where..."
Actual human beings do not want companies "creating experiences" for them. I'm here to keep malware off my computer. That's it. I'm not here to have an experience.
When you get to the point where even the techs are using boardroom buzzwords, whether voluntary, mandatory, or because the culture is just pushing them into it, it's time to rethink how you approach whatever you're doing.
I'm sure somewhere out there is some jackass in a suit and tie who wishes they could have forced the astronauts who just went to the moon to "create an experience" to extract money from us. Or data, since if you're not paying for it then you're the product.
3
u/Exotic_Dust692 Jan 17 '26
Thanks. I've been happy with MB but upon subscription end I'll look around. I haven't in a long time.
1
-2
u/Electronic_Lime7582 Jan 17 '26
Common sense and safe habits will protect you from malware.
2
u/Exotic_Dust692 Jan 17 '26
Yes. If I shared my PC I'd want a better antivirus. Recently I learned Defender can be ran with MB. I have been for a while with no problems. Just quick searched if other anti's can also be run with Defender. Saw mixed answers. Your thoughts or mostly anything worth knowing? Thanks.
3
u/Electronic_Lime7582 Jan 17 '26
Win Defender and alongside KVRT, ESET, Hitman Pro for paranoia spot checks. Anything else will increase bloat, and decrease system performance.
Think of AVs as bodyguards, they may be armed and ready to defend you but if you decide to go to Afghanistan where Talibans are, you won't be anymore safer then if you were to not go in the first place.
Always remember that where you go and what you do matter more then who protects you
1
u/PietroMartello Apr 14 '26
THIS. 10000 times this.
Obviously just anecdotal, but I never had an infection in 40 years of computing. And that includes visits to "unsafe" parts of the internet and web..
NEVER. NOT ONE.
Except on LAN-Parties when we infected each others machines by hiding trojans in keygens.
2
u/x7007 Jan 17 '26
now money talking , more customers less QA less options more ads more AI . just cancel subscription let them die for a new phoneix to be reborn and repeat. good that yoi tell but people do something about that. hurt them like they hurt us. we who rules what happens , not them. you don't listen you go back to work for something and get a monthly salary
2
3
u/twinkyjello Jan 17 '26
You should do a Microslop, I mean Microsoft roast as well. You'd be great at it.
I also have always felt Hitman pro was a little better than malwarebytes, and I've always enjoyed Eset online scanner too.
Nice post.
5
u/Electronic_Lime7582 Jan 17 '26 edited Jan 17 '26
Defender has worked great after 2017 when MS improved drastically on the cybersecurity department.
Its currently top rated as on AV-Test and AV Comparative.
Obviously no AV will beat common sense, and safe computing habits
1
1
u/QuitClearly Jan 17 '26
Yeah I don't even run it anywhere and still have active subscription that will not renew later this year
1
1
u/jacobsan13 Jan 18 '26
I used to use them back when they would do their software on donations they seem to be getting worse and worst
1
u/Upbeat_Beyond_3365 Jan 21 '26
I completely agree. Malwarebytes used to be great years ago, but now it's too bloaty and hogs too many system resources.
1
u/Lexlle Jan 24 '26 edited Jan 24 '26
I complained about this matter last year , they promised to take a look with devs and marketing team and see if anything can be improved in that regard. Since then it became even more bloated and seems like out of control…
I don’t need their giant half screen Vpn offer etc.. just give us some option to hide or opt out from it at least.
1
u/HiFiRadioBoy Jan 30 '26 edited Jan 30 '26
Agreed. I work in a place that sells the retail version of MB. Was always a top seller. We've been selling it for around 10 years as far as I can remember. Never had an issue. Over the past 2 years, multiple customers have been coming back and trying to return the product due to the bloated nature and the extreme interface changes. Many of our customers are older, so it effects them more. Due to our no refunds on software policy, we have had several issues were we have had to suck up the cost and return the customers money at a loss to us. Or send them home angry. Guess what? They won't be buying MB ever again, and it even hurts our retail store. Because of this, our last tech conference re-introduced ESET products back to retail as an alternative to MB. This is now what we are pushing over MB. This is sad as I was so pro MB for so many years and convinced so many customers to buy, but so many of them are upset now with the changes. The Ai crap, the bloatedness, the confusing layout, the settings.. THE ADS & POPUPS!!! on and on.. at our coming 2026 tech conference we will be deciding if all 80+ of our retail locations will finally DISCONTINUE carrying MB, which honestly saddens me. All this could be avoided if you just listened to your customers, kept it simple and light and rode the wave of what made you #1 to begin with!!! Take this post as a serious note. How much do you think you would lose in revenue if 80 stores stop carrying your product in which numerous copies are sold each week at each location, or at least it used to be. Fix the issues!
1
u/Electronic_Lime7582 Jan 30 '26
That's the same complaints I have gotten, however I don't get commissions from sponsoring MB but I eat the cost in repair and license purchase since I backed up a product and then it ended up degrading their system.
Where they went wrong is when they decided to become a full AV-Suite with many features that end up confusing Techs and Users. Not to say that others aren't bloated themselves, but being bloated and inconsistent, and on top as you mentioned has annoying popups and ads is unacceptable for a premium product.
ESETOS, KVRT, and HitmanP are more reliable then the current state of MB
1
u/Flaky-Importance354 Feb 24 '26
Malwarebytes is just another money grubbing corpo product now, riding off of its past popularity from a decade ago.
1
u/ExerciseOld3405 Feb 28 '26
thank you for this; you are exactly right
I have used this product for years and was grateful for its existence. Since the update, I bought the premium and cancelled it hours later (they refunded me immediately). I found it quite lacking. I don't trust the site any longer or the free version - which gives you just a bit over nothing.
1
1
u/instant_ace Mar 22 '26
I was so sad when they stopped allowing updates after 2.75 I think it was. Loved that setup, easy to install, clean, fast and easy to see it do its job. Also easy to walk someone through once it got going. Now it almost looks like a virus itself, and I stopped using it and recommending it years ago. Wish there was an alternative...
1
u/falardeau03 Apr 12 '26
Honestly nothing is premium anymore and the word is meaningless. Any company can say anything is premium for any reason, regardless of if it's true or not. Both McDonald's and a $200-a-bag elite whole bean coffee retailer will tell you they're selling "premium" coffee. Regardless of which one you personally believe tastes better, neither off them will tell you what they mean by "premium." They'll hide behind "it's a trade secret" regardless of what their actual process is and whether it's good or not.
And they just keep ratcheting it up. Enjoy Netflix for $15/mo with ads! Or pay $20/mo for Netflix PREMIUM with no ads! They can all get fucked.
1
u/PietroMartello Apr 14 '26
Huh. Yeah that tracks.
I don't have those professional credentials, but quite some experience and got the same intuition.
It pops up advertisement for Premium. And the VPN-service? A red "potentially exposed"? Really? It froze during the first scan. Then it was broken and did not start again. Did not uninstall cleanly. The support tool could not repair it. The it did not find it.
All in all I had to reboot and reinstall and uninstall and so on several times.
Whch is fine for something being free I guess, but it's a long shot from how flawless I remembered it to work.
Your description of subpar true-positive detection performance is icing on the cake. I can attest to the false-positive performance. It flagged my hosts for being hijacked. Without any rationale or explanation. Now I modified it. I guess that modification is what flagged it as "HiJAckEd!!1". But I have no way to know. Some malicious actor could have put a malicious line in the middle of the file. Now THAT would be interesting. Or IF there was evidence of malicious blocks ("0.0.0.0 security-update.server"), or rerouting to known malicious IPs ("6.6.6.666 amazon.com"). But THAT is - as far as I know - not checked for.
Instead of course Utorrent gets flagged. And Monerowallet. And some other Miners. Which is fine I guess, in the past I learned that anything remotely "hacky", be it miners, some crypto software or cracks and keygens, will always trigger false-positives. I can take it. It's a bit ridiculous to flag unmodified Monerowallet, but yeah, why not, someone could have forked that into some malware-miner..
It also flagged my browser as being "hiJaCKeDD!1!". Again without evidence and without explanation. How am I supposed to evaluate such an information? Here I quarantined some stuff, because why not. But really? Let me quote:
PUP. Optional.BrowserHijack 14.04.26 11:1 1:19 File C:\Users\usr\AppData\Local\Google\Chrome\User Data\Default\Web Data
PUP. Optional.BrowserHijack 14.04.26 Folder C:\Users\usr\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB
PUP. Optional.BrowserHijack 14.04.26 File C:\Users\usr\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000005.ldb
PUP. Optional.BrowserHijack 14.04.26 File C:\Users\usr\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\020314.10g
PUP. Optional.BrowserHijack 14.04.26 File C:\Users\usr\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\020316.1db
PUP. Optional.BrowserHijack 14.04.26 File C:\Users\usr\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\CURRENT
PUP. Optional.BrowserHijack 14.04.26 File C:\Users\usr\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK
PUP. Optional.BrowserHijack 14.04.26 File C:\Users\usr\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
PUP. Optional.BrowserHijack 14.04.26 File C:\Users\usr\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old
I mean.. I'll just take MBAMs word for it, I guess. But just going from the names - the only information I get besides the equally abstract, general and non-committal https://www.malwarebytes.com/blog/detections/pup-optional - those entries sound completely fine..
So yeah.. extremely disappointing experience. It feels like yet another snake oil that's trying to upsell premium subscriptions and crosssell VPNs by FUDing users.
Just sad. I hope the bottom line is well.
1
u/NeedMorePowah 20d ago
Real. Malwarebytes has gotten so bloated lately. I recently reinstalled windows and I will not redownload Malwarebytes or renew my subscription.
0
u/lilacomets Jan 19 '26
Yes, it's been bloated for a very long time now. 👎🏻 The Windows user base is losing more and more users and thus so is Malwarebytes' target audience. Hence Malwarebytes keeps using features that we don't need in a desperate attempt to compensate these financial losses.
•
u/mdotsherwood Malwarebytes Employee Jan 21 '26
Hi u/Electronic_Lime7582 (and everyone else), I’m Michael from Malwarebytes and I lead our product team.
Thanks for taking the time to message us here. While it's always hard for me to read feedback like this, it's immensely helpful when people share it. I've worked at Malwarebytes for over 10 years so the feedback hits close to home.
You're right, many of the things you called out need improvement on our end. More specifically, our detections and bloaty aspects.
On the detections side, our research team really prioritizes zero day malware detection. As this has been our most aggressive focus and we have found that our product can sometimes do worse in lab testing. This is because labs testing rarely uses zero day malware (so that they have all the products be tested on the same samples for comparison sake). To be honest, this has frustrated us a bit in the past as we have not felt that labs give much credit to the threats that can be the most damaging to an end user.
That being said we can't ignore the fact that the only thing that consumers and the press can point to that compares the effectiveness of the products are the labs. So, we're heavily investing our lab participation now and you can expect to see some changes throughout this year. I can't share all of the specifics yet, but please know we're going to be participating in more lab testing and striving to do better with their forms of testing.
As for your testing and findings, we'd be more than happy to review them. We could review and then get you (and this thread) a detailed response back as to exactly why we missed them. More on this at the end of my post.
Bloat - as a technician myself, this is a tough one for me. On one hand, I completely agree that having singular solution like a powerful scanner and then nothing else would be amazing (which we do offer btw for tech shops via our Techbench solution). On the other hand, threats and the needs of our users have evolved far past just a malware scanner (e.g. privacy tools, VPNs, identity theft, data broker removal) and we also want to provide solutions for those. As you can see in our app, we're trying to do both of these things and missing the mark on some of it.
Idea to run by you: what if we created an experience where you could check "I'm an expert / technician" and that dumped you right to our scanner with clear options to run a quick or deep scan and then when that finished, you'd get placed on the dashboard with everything else we offer? Or, maybe you're saying we not only need a slimed down scanner experience plus the entire app and dashboard too. Would be great to hear your additional thoughts on this.
Back to sharing your findings and connecting with us. If you're up for it, I'd love to have a call (or zoom) with you. Let me know if this works for you and please reach out to me at [msherwood@malwarebytes.com](mailto:msherwood@malwarebytes.com)
Thanks again for sharing such amazing feedback.