Answer-first overview
Malwarebytes real-time protection not starting usually stems from service or driver issues, conflicting security software, damaged settings, or system resource limits. This evergreen guide offers the fastest path to diagnosis with prioritized, safe steps, clear decision points, and configuration checks that remain valid across current versions. Follow in order, confirm each fix, and avoid trial-and-error that can delay resolution.
How real-time protection works in Malwarebytes
Real-time protection in Malwarebytes combines a service process, a driver (filter manager) that scans file system activity, and scheduled scans. The service starts early in boot, loads the driver, and then monitors executes and file changes. If any component fails to start, is blocked, or is misconfigured, protection stays inactive even when the app shows as installed.
Key components behind the status
- Service process (mbam-service): Main controller for scheduled and real-time scans.
- Filter driver (mbamfh.sys on Windows): Low-level file system monitor.
- User interface (mbam-app): Shows status, allows manual scans and settings changes.
- Threat definitions and cloud checks: Essential for up-to-date detection.
Common causes when Malwarebytes real-time protection won’t start
Start with the simplest explanations that are most often confirmed by diagnostics:
- The service is stopped, delayed, or fails silently after a recent update.
- The filter driver is blocked by Windows, macOS security policies, or third-party drivers.
- Conflicts with other anti-malware or endpoint protection agents.
- Corrupted preferences or databases that prevent the service from initializing.
- Insufficient system privileges, expired licenses, or time changes affecting activation.
- OS updates or security software changes that reset settings or quarantine components.
Priority checklist: quick verification in under 2 minutes
Run these checks in order. Each item either confirms a healthy state or points to the next troubleshooting step.
| Check | Expected healthy state | What it tells you |
|---|---|---|
| Service status | Running (automatic startup) | If stopped, protection cannot start. |
| Driver load | Loaded without warnings in system logs | Driver load failures block real-time scanning. |
| Conflicting products | No other AV/EDR active | Mutually exclusive security software often disables both. |
| License and time | Active license; system clock within 1 day of NTP | Expired or time-skewed systems can block protection. |
| Recent updates | No recent OS or security product updates | Updates can reset policies or quarantine components. |
Step-by-step diagnostics on Windows
Confirm service and driver status
Open an elevated command prompt and run sc query mbam-service to verify the service state. In Windows, open Event Viewer and check System and Application logs for entries from mbam, mbamfh, or Filter Manager. Look for ACCESS DENIED, LoadImage error, or components blocked by Secure Boot or third-party drivers. Capture timestamps that align with when real-time protection failed to start.
Check for blocking security policies
Group Policy and Windows Defender Exploit Guard can block unsigned drivers. Review Settings → Privacy & security → Security info, and check Virus & threat protection settings under Manage settings. Confirm Tamper Protection is not preventing changes. On enterprise devices, inspect Local Computer Policy → Administrative Templates → Windows Components → Microsoft Defender for any enforced restrictions that also affect third-party filters.
Resolve driver conflicts
Temporarily disable or uninstall other anti-malware and EDR products. Use Programs and Features to fully uninstall prior antivirus products, then reboot before reinstalling Malwarebytes. For driver issues, run bcdedit /set testsigning off if test-signing was used, and check with driverquery /v /fi "imagename eq mbamfh.sys" to confirm the driver file is in the correct directory and digitally signed.
Step-by-step diagnostics on macOS
Confirm extension and daemon status
Open System Settings → Privacy & Security → Security and review any Malwarebytes entries under Allow. In Terminal, run sudo launchctl list | grep -i malware to verify the daemon is loaded. If blocked, approve the extension in Security & Privacy and reboot. Check Console.app for kernel or extension denials related to mbam or filter operations.
Address profile and admin controls
System extensions and MDM profiles can prevent load. Go to System Settings → Privacy & Security → Extensions and confirm the Malwarebytes extension is enabled. In Profiles (System Settings → General → Profiles), remove any device profiles that disable security products. For managed devices, consult your admin before changing policies.
Advanced remediation and repair
If standard restarts and service restarts do not resolve real-time protection not starting, proceed with controlled repair actions:
- Use the official uninstall tool to remove Malwarebytes, reboot, then reinstall the latest version from the official website.
- Rename or move the preferences folder (commonly %APPDATA%\Malwarebytes\Windows或 ~/Library/Application Support/Malwarebytes on macOS) to preserve logs while forcing clean defaults.
- Run Malwarebytes Anti-Malware in Safe Mode to rule out interference from third-party software.
- Review Application Event logs and Malwarebytes logs for exact error codes before contacting support; include these logs when opening a support case.
When to escalate to vendor support
Collect the following before reaching out: a timestamped screenshot of the status, relevant service and driver logs, recent Windows Event errors or macOS Console entries, steps already tried, and product version plus OS build. Escalate when the service starts but the driver fails to load, or when policies or MDM continue to block the components after local remediation attempts.
Prevention and long-term maintenance
Reduce recurrence by limiting unnecessary third-party security, approving extension changes promptly, keeping the OS and applications updated, and avoiding frequent toggles of real-time protection. Schedule weekly status checks for critical services and enable logging rotation so that historic issues are easier to diagnose.
Summary: clear actions for real-time protection not starting
When Malwarebytes real-time protection is not starting, verify the service and driver status first, then look for conflicts with other security products, policy blocks, or corrupted preferences. Use the priority checklist for fast diagnosis, follow OS-specific steps for safe remediation, and escalate with logs when local actions do not restore protection. Consistent maintenance and monitoring keep real-time protection reliable over time.