Malwarebytes scans a computer for malicious files and behavior, records detections, and can isolate a detected item so it no longer runs from its original location. A scan inspects the selected areas at that moment; real-time protection watches activity as it happens. This differs from deleting an unfamiliar file by hand because Malwarebytes applies detection rules, keeps a report, and can hold the item in quarantine for a later decision.
Choose the scan
A Threat Scan checks the locations where active threats commonly establish themselves. A Custom Scan lets the user choose drives and additional options, while a deeper workflow spends more time examining the system. Selecting every option does not make the result automatically better. It increases the amount of data and behavior the scan must process.
Rootkit detection belongs to the Custom Scan settings and makes the scan slower. Archive scanning also has a defined boundary: Malwarebytes examines archives only to a limited nesting depth, and it cannot inspect the contents of a password-protected archive. A clean result therefore does not certify files hidden behind an unknown archive password.
Detection needs a decision
Malwarebytes can quarantine every detected threat without asking first. An automatic restart option can finish removal work, but it becomes available only when automatic quarantine is active. This pairing matters on an unattended scan because a restart may close other open work even though the original scan started while the computer was idle.
Potentially unwanted programs and potentially unwanted modifications have separate treatment choices. Malwarebytes can ignore them, warn about them, or treat them as malware. These categories can include software or settings that the user installed deliberately, so the warning state gives the user a chance to read the item name and location before removal.
Quarantine is reversible
Quarantine can hold a file, folder, application, or program away from its original working location. The Detection History page lists those items and separates Restore from Delete. Restore returns a trusted item so it can work again. Delete removes the quarantined copy from the computer, after which Malwarebytes cannot restore it.
A false positive needs more than an impatient click. Restoring a known item can also add it to the Allow list so the same detection does not immediately quarantine it again. That choice should follow an identity check because the exclusion remains effective during later protection and scans.
Allow list scope
The Allow list can exempt a file, folder, application, website, or a previously detected exploit. An exemption tells Malwarebytes to stop applying the relevant block to that item; it does not prove the item is safe. A folder exclusion also covers more content than one file, so a narrow rule reduces the amount of protection removed.
Malwarebytes can export the Allow list to a JSON backup and restore it later. Restoring the backup permanently replaces the current list rather than merging old and new entries. A rule added after the backup will disappear unless it also exists in the restored file.
Two scanners can collide
Malwarebytes can run beside another antivirus, but the two products may inspect or block each other’s components. The conflict can slow the computer or interfere with Real-Time Protection. The documented fix uses mutual exclusions: the other antivirus ignores Malwarebytes components, and Malwarebytes ignores the other antivirus. Those exclusions need exact paths rather than a broad system-drive rule, which would hide unrelated files from inspection.






