How-To

How to Manually Scan for Malware with Windows Defender in Windows 11

5 min read Editorial

Even with automatic protection enabled, your Windows 11 PC can occasionally pick up unwanted software or encounter a threat that slips past routine checks. Running a manual malware scan gives you direct control over when and how your system gets inspected. Whether you suspect a suspicious download or want to verify your PC’s health after a software update, this guide walks you through the exact process.

Before You Start: Ensure you are signed in with an administrator account. You will also need an active internet connection so Windows can download the latest virus definitions before the scan begins.

Step 1: Open the Windows Security app

Click the Start button and type Windows Security, then select the app from the results. You can also press Win + I to open Settings, navigate to System > Windows Security, and launch it from there. This central hub houses all of Microsoft’s built-in protection tools, including the scanning engine you need for this task.

Advertisement

Once the app opens, you will see a dashboard displaying the current status of your firewall, account protection, and virus scanning. If you see a green checkmark next to Virus & threat protection, your real-time monitoring is active and ready to assist with the manual scan.

Step 2: Navigate to Virus & threat protection

Click on the Virus & threat protection tile in the main dashboard. This action opens a new pane dedicated specifically to threat detection settings, update history, and scan options. You will notice a section labeled Current threats that shows whether any issues were found during the last scan.

This screen also displays your protection history and allows you to manage exclusions. If you recently installed a program that triggers false alarms, you can adjust those settings here. For now, focus on the Scan options link located just below the current threats area.

Step 3: Select your preferred scan type

Click the Scan options link to view the available scanning methods. Windows Defender offers four distinct modes, each designed for different scenarios. You will see Quick scan, which checks startup programs, running processes, and common threat locations in roughly 15 to 20 minutes. Full scan examines every file and running program on all drives, which can take several hours depending on your storage capacity.

The Custom scan option lets you pick specific folders or drives to inspect, which is useful if you only suspect a particular directory is compromised. Finally, Windows Defender Offline scan restarts your PC into a secure environment to hunt for deeply embedded rootkits that standard scans cannot reach. Choose the option that matches your current situation and click Scan now.

Close-up shot of a Windows 11 Settings screen showing the Virus & threat protection Scan options menu with four highligh
The Scan options menu displays all available Windows Defender scanning methods.

Step 4: Allow the scan to run and monitor progress

Wait while Windows Defender begins inspecting your system files. A progress bar will appear, showing the percentage completed and an estimated time remaining. During this phase, you might notice your computer running slightly slower as the scanner accesses disk sectors and checks running processes against its malware database.

Do not close the Windows Security window or force a restart while the scan is active. Interrupting the process can leave your system in an inconsistent state and may require you to run the scan again. If you need to use your PC for light tasks, you can minimize the window, but keep an eye on the status indicator.

Step 5: Review the scan results

Once the scan finishes, Windows Defender will display a summary of findings. If no threats were detected, you will see a message stating that your device is protected and up to date. You can then close the window and continue using your PC normally.

If the scanner identifies suspicious files or known malware, it will list each item along with the action it took. You will see options to Quarantine, which isolates the file so it cannot execute, or Remove, which permanently deletes the threat. Review the list carefully before confirming any actions, especially if you recognize the file name.

Laptop screen showing a Windows Security scan results page with a green shield icon and a list of quarantined files, vie
Scan results display detected threats and recommended cleanup actions.

Step 6: Take action on detected threats

Click the arrow next to each detected item to expand detailed information. You will see the file path, threat type, and the specific action Windows Defender recommends. If you are unsure whether a file is legitimate, search the exact threat name in a trusted security database before choosing to remove it.

After reviewing the list, click Apply all or select individual items and choose your preferred action. Windows Defender will process the requests and update the protection status. If a threat refuses to be removed, the scanner will display a message indicating that the file is currently in use and suggest a reboot to complete the cleanup.

Troubleshooting common scan issues

Scan definitions are outdated or failing to update. If the scan warns you about old definitions, click Scan options > Update definitions inside the Virus & threat protection pane. Ensure your Wi-Fi or Ethernet connection is stable, then wait for the download to finish. If updates continue to fail, run wuauclt /updatenow in an elevated Command Prompt to force Windows Update to sync.

Third-party antivirus software is blocking the scan. Windows Defender automatically disables itself when another security suite is active. To run a manual scan, you must temporarily pause or uninstall the competing antivirus program. Navigate to the third-party app’s settings, locate the real-time protection toggle, and turn it off. Once you finish scanning, re-enable your preferred security software immediately.

The scan freezes or crashes during the Full scan. This usually indicates corrupted system files or a failing storage drive. Open an elevated Command Prompt and run sfc /scannow to repair protected system files. If the issue persists, check your disk health using chkdsk C: /f /r and schedule a drive diagnostic to rule out hardware failure.

Pro Tip: For stubborn infections that survive a standard reboot, schedule a Windows Defender Offline scan through the same Scan options menu. This forces your PC to restart into a locked-down environment where rootkits cannot hide, giving the scanner a clear path to remove deeply embedded threats.

Running manual scans regularly keeps your Windows 11 environment secure and helps you catch issues before they escalate. By following these steps, you can confidently inspect your system and remove unwanted software without relying on third-party tools. Keep your definitions updated and use the offline scan option when standard protection falls short.

Over to you: Which scan type do you rely on most when checking your PC for threats?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement