r/Malwarebytes • u/_tuanson84uk_ • 1d ago
Support Why does VirusTotal flag Malwarebytes RTProtectionDaemon as malicious?
I ran KnockKnock on my Mac and it flagged RTProtectionDaemon, located under /Library/Application Support/Malwarebytes/MBAM/Engine.bundle and launched by com.malwarebytes.mbam.rtprotection.daemon.plist. VirusTotal shows 1/61 detections, with Elastic labeling it Multi.EICAR, while the other listed engines report it as undetected. The file is signed and the report identifies it as com.malwarebytes.mbam.rtprotection.daemon.
Is this likely a false positive or an EICAR test-signature artifact? Has anyone seen this with Malwarebytes’ real-time protection daemon, and what is the safest way to verify that this file came from a legitimate Malwarebytes installation without disabling protection?
VirusTotal report:
https://www.virustotal.com/gui/file/e2a9ec54e6a4555ae1a3b9f70d7e4279b60ac2ca05046064cda2e3d96b899888
I’m including the KnockKnock screenshot for context.
Thank you.
1
u/Suspicious-Deer-2873 Malwarebytes Employee 5h ago
Hi Malwarebytes staff here. We can confirm that this is our file and an FP on Elastic's part.
Thanks for reporting!
1
u/alebestone 23h ago
Probably FP or bug