Even with real-time protection running in the background, Windows Defender does not automatically check every file on your drive. Periodic manual scans catch hidden threats, dormant trojans, and suspicious startup items that slip past background monitoring. This guide shows you exactly how to trigger a manual malware scan using the built-in Windows Security app, choose the right scan type for your situation, and handle the results without guessing.
Before You Start: Make sure you are signed in with an administrator account, as standard accounts cannot modify security settings. Keep your PC connected to the internet so Defender can download the latest virus definitions before scanning. Close unnecessary applications to free up system resources and speed up the scan process.
Step 1: Open Windows Security
Click the Start button and type Windows Security, then select the app from the results. You can also press Win + I to open Settings, navigate to Privacy & security, and click Windows Security. The app opens with a dashboard of colorful tiles representing different protection categories. If you see a notification banner at the top of the window, click it to review any pending alerts before proceeding.
Step 2: Navigate to Virus & threat protection
Locate and click the Virus & threat protection tile on the main dashboard. This tile sits near the top of the Windows Security home screen and usually displays a green shield icon. Clicking it opens a detailed panel that shows your current protection status, last scan date, and cloud-delivered protection settings. The right side of this panel contains the scan controls you will use in the next step.

Step 3: Select your preferred scan type
Click the Scan options link located directly beneath the Quick scan button. Windows Defender offers four distinct scan modes, each designed for different threat scenarios. Quick Scan checks running processes, startup items, and key system folders for known malware signatures. Full Scan examines every file on all connected drives, which takes longer but catches deeply hidden threats. Custom Scan lets you pick specific folders or drives to check, ideal for external storage devices. Windows Defender Offline Scan restarts your PC and runs the scan before Windows loads, which bypasses active malware that tries to hide itself. Choose the option that matches your current situation and click Scan now.
Pro Tip: If you suspect a stubborn infection that refuses to die after a standard scan, run the Offline Scan at least once a month. It runs in a pre-boot environment where most malware cannot interfere with its operations.
Step 4: Start the scan and monitor progress
Confirm your selection when prompted and allow the scan to run without interrupting it. A progress bar appears alongside an estimated time remaining, which varies based on your drive size and scan type. During the process, Defender quarantines suspicious files automatically and queries Microsoft’s cloud database for the latest threat intelligence. You can minimize the window to keep working, but do not close the app or force a restart while a Full or Offline scan is active, as that may corrupt the scan log.

Step 5: Review results and handle detected threats
When the scan finishes, click Scan completed to view the full results page. Defender lists every detected item with its threat name, severity level, and current action taken. Items marked as Quarantined are isolated and cannot execute, while items marked as Removed are permanently deleted. Click the Quarantine history link at the bottom of the page if you need to restore a file you accidentally blocked or submit a hidden file to Microsoft for analysis. If the scan reports no threats but your PC still behaves strangely, run a second scan using a different mode or consider using a dedicated removal tool for the specific infection.
Troubleshooting common issues
Manual scans occasionally fail to start or produce incomplete results. The following fixes address the most frequent failure points.
- Scan will not start or shows an error code: Open an elevated Command Prompt by searching for
cmdin Start, right-clicking the result, and selecting Run as administrator. Typenet stop WinDefendand press Enter, then typenet start WinDefendand press Enter. Return to Windows Security and try the scan again. - Definitions appear outdated: Click Check for updates under Virus & threat protection settings. If the download fails, switch to a different Wi-Fi network or temporarily disable any third-party firewall that might block Microsoft’s update servers.
- Third-party antivirus is interfering: Windows Defender automatically disables itself when another security suite is active. Open that suite, locate its scanner settings, and choose to run a manual scan from within that program instead. You cannot run two real-time antivirus engines simultaneously.
Running a manual malware scan takes only a few minutes and gives you direct control over your system’s security posture. Pair this habit with regular Windows updates and cautious download practices, and your PC will stay protected against both known and emerging threats. If you ever need to restore files from quarantine, remember that Defender keeps them for thirty days by default before permanent deletion.
Over to you: Have you ever caught a hidden threat using a full scan, or do you rely on real-time protection alone?



