Fix it now
Malwarebytes Premium Security is a resident protection product with a wider feature list than its reputation suggests, including firewall control on Windows. The real decision is not whether it can be your only antivirus but what happens to Microsoft Defender when it registers itself as one, because Windows disables Defender rather than running both.
- Buy it if you want a light protection product that is unusually strict about adware and bundled junk and unusually good at cleaning a machine that is already misbehaving.
- Buy it if you are the person who fixes everyone else’s laptops and wants the same tool resident afterwards rather than only on a USB stick.
- Buy it if the scam-focused components appeal: Scam Guard, Text Protection, Call Protection and the Digital Footprint Scanner are all in the published list.
- Skip it if all you ever wanted was the manual scanner, because the free build still does on-demand scans and Browser Guard is free too.
- Skip it if you expect a full suite. There is no backup and no parental control, and the password function is not part of this product.
- Decide deliberately whether it registers as your antivirus, because that choice decides whether Microsoft Defender stays on.
Do not disable the Windows Security Center Service to run two engines at once. Microsoft states that this leads to conflicts, impacts performance and is not supported.
If you have decided, you can stop here. If you want the Defender question answered properly, the next section is the one to read.
Why it happens
Malwarebytes spent years as the tool people ran after something had already got through, and that history still shapes what buyers expect. The free build is a manual scanner: you open it, it scans, it removes what it finds, then it sits idle. Premium Security is the same detection work made resident, and the published component list is longer than the reputation implies.
On the vendor’s own product page, Premium Security carries web protection, malware and PUP protection, ransomware protection, exploit protection and brute force protection; a scam group made up of Trusted Advisor, Scam Guard, the Digital Footprint Scanner, Text Protection and Call Protection; webcam monitoring, remote desktop monitoring and a privacy settings checker; and a set of system tools including Firewall Control, a file shredder, system tweaks and a junk cleaner. Firewall Control is described as filtering network traffic to protect the device from unauthorised access, and it is Windows-only. Any review telling you this product has no firewall is out of date.
Features vary by operating system, which Malwarebytes says plainly. Exploit and brute force protection are Windows concepts, Call Protection is a phone feature, and the desktop and mobile clients are not the same application. Plans run from one device up to twenty across Windows, Mac, Android and iOS, so a mixed household draws from one pool.
Browser Guard is the part people miss. It is free, it works in Chrome, Firefox, Safari and Edge without the paid client, and it blocks ads and trackers, malicious sites, phishing, credit card skimmers, cookie banners and scams. If web filtering is the reason you were going to subscribe, install the free extension first and see whether you still want to.
Now the part that decides how you should install it. Microsoft’s own documentation is explicit: on Windows 10 or 11 that is not onboarded to Defender for Endpoint, installing a non-Microsoft antivirus puts Microsoft Defender Antivirus into disabled mode automatically. Passive mode – the arrangement where Defender keeps doing routine work underneath another product – requires onboarding to Defender for Endpoint, which a home PC is not. Microsoft records one exception: on Windows 11 with Smart App Control enabled you may see Defender go into passive mode rather than staying disabled, and Microsoft says that is not the same as passive mode on an onboarded device. Outside that case the outcome on a home machine is binary: Defender active, or Defender disabled.
That kills a piece of advice that circulates widely: run Malwarebytes over the top and let Defender handle routine scanning underneath. On a home Windows machine that is not what happens. If Malwarebytes registers with the Windows Security Center as your antivirus, Defender switches itself off; if it does not register, Defender stays on and you have two products with real-time components on the same files. Malwarebytes publishes a help article on Windows Security Center registration, so the behaviour is something the product exposes – check the current setting in the client rather than trusting a menu path you remember.
One thing Microsoft is clear about, and it is the workaround you are most likely to find elsewhere: disabling the Windows Security Center Service stops Defender noticing the other product and leaves both active. Microsoft says that this can lead to conflicts, will impact performance and is not supported. Do not do it.
Full reference
What the free build gives you, and what the licence adds
| Capability | Free build | Premium Security |
|---|---|---|
| On-demand scan and removal | Yes | Yes |
| Browser Guard extension | Yes, free and standalone | Yes |
| Real-time malware, PUP and ransomware protection | No | Yes |
| Web protection in the client | No | Yes |
| Exploit and brute force protection (Windows) | No | Yes |
| Scam Guard, Text Protection, Call Protection | No | Yes |
| Digital Footprint Scanner and privacy settings checker | No | Yes |
| Firewall Control (Windows) | No | Yes |
| Webcam and remote desktop monitoring | No | Yes |
| File shredder, system tweaks, junk cleaner | No | Yes |
Malwarebytes’ own framing is that the free build is for cleaning up after an attack that has already damaged a device and the paid product is what stops them happening. That is a fair description of the difference, and it is also the reason the free build has outlived several generations of competitors: as a rescue tool it is genuinely good.
Deciding how it sits beside Microsoft Defender
| Arrangement | What Windows does | When it makes sense |
|---|---|---|
| Malwarebytes registers as the antivirus | Microsoft Defender Antivirus is disabled automatically | You want one resident engine and you have chosen this one |
| Malwarebytes does not register | Defender stays active; two products run real-time components | You want Defender’s engine as the primary and Malwarebytes’ layers on top |
| Windows Security Center Service disabled | Both stay active because Defender cannot see the other product | Never. Microsoft states this is not supported |
Microsoft also documents the recovery path, which is worth knowing: Defender re-enables itself automatically if the non-Microsoft product expires, is uninstalled, or otherwise stops providing real-time protection. A lapsed subscription therefore does not leave the machine unprotected, though it does leave it protected by something other than what you paid for.
The strengths that are genuinely its own
- Remediation. The removal engine is built to unpick an infection that is already established – scheduled tasks, service entries, browser hijacks and the registry residue ordinary scanners leave behind because it is technically inert.
- Potentially unwanted programs. Toolbars, aggressive registry cleaners, driver updater rackets and bundleware get flagged where a mainstream suite would shrug. Most readers will count that a feature; if you rely on a niche utility, expect to write an exclusion.
- The scam components. Text Protection, Call Protection and Scam Guard address the way people actually lose money now, which is not the same problem as file-based malware.
- Weight. It installs fewer background services than a full suite because it is doing less: no mail scanner, no optimiser running constantly, no backup engine.
Testing evidence, and what this review will not tell you
This review quotes no laboratory score, in either direction. Results move between rounds, vendors enter and leave test panels, and a figure quoted without its date and methodology is worse than no figure. If independent testing is part of your decision, read the most recent published round yourself from a body you trust, and read the false positive column as closely as the detection column – for a product this strict about unwanted software, that column is the interesting one.
Licensing and how seats are counted
- Plans run from one device to twenty, drawn from one pool across Windows, Mac, Android and iOS.
- Coverage is not identical on every platform. Confirm which features your specific devices get rather than assuming the desktop list applies to a phone.
- Subscriptions renew automatically unless you turn that off, and renewal terms are set separately from introductory ones across this whole market.
- Moving a seat between machines is an account operation – deactivate the old device – rather than a new purchase.
When a licence is the actual fix
If Malwarebytes Premium Security is the right shape for your machines, Arco supplies it as an electronic licence across the standard device counts and terms. Tell us how many devices you actually need to cover, including the phones and tablets you had not counted, and we will confirm which plan size fits rather than selling you seats you will never activate. The more useful conversation is the Defender one: decide before installation whether you want Malwarebytes to be the registered antivirus, because Windows will disable Microsoft Defender if it is, and there is no supported arrangement where both run real-time protection with the Security Center switched off.
Questions people ask about this
Can Malwarebytes Premium Security be my only antivirus?
Yes. It carries real-time file, web, behaviour, ransomware and exploit protection, plus firewall control on Windows, and it registers with Windows as your antivirus if you let it. Whether it should be is a judgement about what you want from the product: it is stronger on remediation and unwanted software than most, and it is not a suite with backup and parental controls.
Do I need to pay if I only scan occasionally?
No, and it is worth saying plainly. Malwarebytes describes the free build as a cleanup tool for attacks that have already damaged a device – it scans and removes on demand – and Browser Guard is a free extension that works on its own in Chrome, Firefox, Safari and Edge. If you never want resident protection, the subscription buys you nothing you will use.
Will it conflict with Microsoft Defender?
Not if you choose deliberately. Microsoft documents that on a home Windows 10 or 11 machine, installing a non-Microsoft antivirus disables Microsoft Defender Antivirus automatically – disabled, not the passive mode that needs Defender for Endpoint onboarding. The one exception Microsoft names is Windows 11 with Smart App Control enabled, where Defender may go passive instead. If you prefer Defender to stay active, stop Malwarebytes registering as the system antivirus. Do not disable the Windows Security Center Service to force both on: Microsoft states that is unsupported.
Does it include a firewall?
On Windows, yes. Malwarebytes lists Firewall Control among the system tools, described as filtering network traffic to protect the device from unauthorised access. It is one of the features that varies by operating system, so do not expect it on a Mac or a phone.
Is the PUP detection too aggressive?
It is aggressive on purpose, and that is one of the main reasons people choose it. The cost is an occasional flag on a legitimate but badly behaved utility. Allow the specific item rather than loosening the policy globally, which is the change people regret.
