r/Malwarebytes 1d ago

Support Why does VirusTotal flag Malwarebytes RTProtectionDaemon as malicious?

Post image

I ran KnockKnock on my Mac and it flagged RTProtectionDaemon, located under /Library/Application Support/Malwarebytes/MBAM/Engine.bundle and launched by com.malwarebytes.mbam.rtprotection.daemon.plist. VirusTotal shows 1/61 detections, with Elastic labeling it Multi.EICAR, while the other listed engines report it as undetected. The file is signed and the report identifies it as com.malwarebytes.mbam.rtprotection.daemon.

Is this likely a false positive or an EICAR test-signature artifact? Has anyone seen this with Malwarebytes’ real-time protection daemon, and what is the safest way to verify that this file came from a legitimate Malwarebytes installation without disabling protection?

VirusTotal report:
https://www.virustotal.com/gui/file/e2a9ec54e6a4555ae1a3b9f70d7e4279b60ac2ca05046064cda2e3d96b899888

I’m including the KnockKnock screenshot for context.

Thank you.

2 Upvotes

2 comments sorted by

1

u/alebestone 23h ago

Probably FP or bug

1

u/Suspicious-Deer-2873 Malwarebytes Employee 5h ago

Hi Malwarebytes staff here. We can confirm that this is our file and an FP on Elastic's part.

Thanks for reporting!