Reporting a false positive
Scanners sometimes flag legitimate files — installers with unusual packers, niche utilities and older drivers are frequent offenders. A false positive is worth reporting, but only after you have checked it really is one.
First, confirm it is wrong
- Did you obtain the file from the developer's own site, or from a mirror or bundle?
- Does a second opinion scan agree with the detection?
- Is the detection name generic, or does it name a specific known family?
Cracks, keygens and repackaged installers are usually detected correctly. Those are not false positives.
What to include in a report
Vendors need the detection name, the product and database version, the file itself or its hash, and where you downloaded it from. Keep the file in quarantine while you wait rather than restoring it.
Exclusions are a last resort
An exclusion switches off checking for that path permanently, which is a real risk if the file is later replaced. Prefer waiting for a corrected database update. Background on how detection works is in our antivirus basics guide.
Malware-Bytes.net is an independent information resource about malware protection for Windows. We are not Malwarebytes, and this site is not the official Malwarebytes website or support channel. Malwarebytes is a trademark of Malwarebytes Inc.