How-To

How to Manually Scan for Malware with Windows Defender in Windows 11

5 min read Editorial

Windows Defender, now branded as Microsoft Defender Antivirus, runs automatically in the background to block threats before they reach your system. However, there will be moments when you suspect a hidden infection, notice unusual behavior, or want to verify your PC is completely clean. Running a manual malware scan gives you direct control over how deeply Windows inspects your files, and it takes only a few minutes to complete.

Before You Start: Make sure your PC is connected to the internet so Defender can download the latest virus definitions. If you are using Windows 11 Pro, Enterprise, or Education, Group Policy settings might restrict manual scan options, so you will need administrator approval to proceed.

Step 1: Open Windows Security

  1. Press the Windows key on your keyboard. You will see the Start menu expand across the bottom of your screen. Type Windows Security and click the matching app at the top of the search results. This launches the dedicated security dashboard that centralizes all of your protection settings. If the app fails to open, restart your computer and try again, or run a system file check by typing sfc /scannow in an elevated Command Prompt.

Step 2: Navigate to Virus & Threat Protection

  1. Locate the Virus & threat protection tile on the main dashboard. It usually sits in the top left corner with a green checkmark icon. Click directly on that tile to expand the detailed protection menu. You will now see a section labeled Current threats, which displays the status of your real-time protection and shows the date of your last scan. If the tile is missing or grayed out, your organization may have handed control over to a third-party antivirus or a mobile device management policy.

Step 3: Choose Your Scan Type

  1. Click the Scan options link beneath the Quick scan button. Windows Defender will present a new screen listing four distinct scan methods. The Quick scan checks only the areas where malware typically hides, such as memory, startup folders, and system directories. The Full scan inspects every file on every drive, which takes considerably longer but catches deeply buried threats. The Custom scan lets you pick specific folders, drives, or files to inspect, which is useful when you suspect a particular download caused the issue. The Microsoft Defender Offline scan restarts your PC and runs a pre-boot check to remove rootkits that load before Windows starts.

Step 4: Start the Scan and Monitor Progress

  1. Select your preferred scan type and click the Scan now button. A progress bar will appear, showing the percentage of files scanned and an estimated time remaining. You can continue using your PC during a Quick scan, but heavy tasks like gaming or video editing may slow down noticeably because Defender prioritizes its own scanning threads. If the scan stalls at a certain percentage for more than an hour, press Ctrl + Shift + Esc to open Task Manager, locate the Windows Security service, and restart it. Do not force-close the scan window, as that can leave your system in an inconsistent security state and may trigger false positive alerts on your next boot.
A clean Windows 11 settings screen showing the Virus & threat protection menu with scan options clearly visible on a mod
The scan options screen inside Windows Security.

Step 5: Review Results and Take Action

  1. Wait for the scan to finish and read the Threat details section. If Defender found nothing, you will see a green confirmation message stating your device is protected. If it detected suspicious files, click the down arrow next to each item to view its classification and the action Defender already took. You can choose to Quarantine, Remove, or Allow the file, though quarantining is the safest middle ground for uncertain items. When you finish reviewing, click Close to return to the main protection dashboard.

Troubleshooting Common Scan Failures

Sometimes the scan will not start, will crash mid-process, or will refuse to remove a detected threat. Here are the most frequent roadblocks and how to clear them.

Advertisement
  • Scan refuses to launch or shows error 0x80070005. This permission error usually means another security program is blocking Defender. Open Settings, go to Privacy & security > Windows Security, and toggle off the conflicting antivirus, or uninstall it entirely. After switching programs, restart your PC and try the scan again.
  • Defender keeps turning itself off after a manual scan. If you see a message saying your protection is managed by your organization, check your Group Policy editor by pressing Win + R, typing gpedit.msc, and navigating to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Look for the Turn off Microsoft Defender Antivirus policy and ensure it is set to Not configured.
  • Quarantined files reappear after a restart. This indicates a persistent threat that reinstalls itself from a scheduled task or startup entry. Open Task Scheduler, expand the library, and look for suspicious Microsoft Defender entries. Disable any task that references the quarantined file, then run another Full scan to confirm the threat is gone.

Pro Tip: Schedule a weekly Quick scan through the Scan options menu instead of waiting for suspicious behavior. You can set it to run at a specific time each week, which keeps your system consistently clean without requiring daily manual intervention.

Final Tips for Ongoing Protection

Manual scanning is a powerful diagnostic tool, but it works best alongside consistent habits. Keep Windows Update active so you receive the latest security patches, and avoid downloading software from unverified sources. If you frequently visit high-risk websites, consider enabling Smart App Control in Windows 11 to block unverified executables before they run. For enterprise environments, sync your manual scan results with Microsoft Defender for Endpoint to get centralized threat intelligence across all managed devices.

A laptop screen displaying a completed Windows Defender scan with a green checkmark and a list of quarantined items read
Scan complete screen showing detected threats and protection status.

Have you ever caught a hidden threat by running a manual Defender scan, or do you rely entirely on real-time protection? Share your experience in the comments below.

Over to you: Have you ever caught a hidden threat by running a manual Defender scan, or do you rely entirely on real-time protection?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement