How-To

How to Manually Scan for Malware in Windows 11 Using Defender

4 min read Editorial

Running a manual malware scan through Windows Defender gives you direct control over how your system checks for threats. While Windows Security automatically runs scheduled scans in the background, a manual scan lets you investigate suspicious behavior, verify a downloaded file, or clear up lingering issues after a third-party antivirus removal. This guide walks you through the exact steps to launch a manual scan, choose the right scan type for your situation, and interpret the results.

Before You Start: Make sure you are signed in with a standard or administrator account on Windows 11. If you recently uninstalled a third-party security suite, Windows Defender should have activated automatically, but you can verify this inside Windows Security before proceeding.

Step 1: Open Windows Security

Click the Start button and type Windows Security, then select the app from the results. This launches the central hub where Microsoft Defender Antivirus lives. You will see a large window displaying your protection status for virus threats, firewall, browser safety, and device performance. If you prefer a keyboard shortcut, you can press Win + I to open Settings, then navigate to Privacy & security > Windows Security to reach the same screen.

Advertisement

Step 2: Navigate to Virus & threat protection

Click the Virus & threat protection tile in the center of the Windows Security dashboard. This section controls all scanning options and update settings. You will see a summary of your last scan date, current protection status, and a prominent link labeled Virus & threat protection settings. This is the gateway to launching a new scan.

Step 3: Choose your scan type

Click the Scan options link located beneath the last scan summary. Windows Defender offers four distinct scan modes, each designed for different scenarios. A Quick scan checks startup regions, memory, and frequently accessed folders, which usually completes in under fifteen minutes. A Full scan examines every file and running program on your drives, taking several hours depending on storage size. A Custom scan lets you pick specific folders or drives to investigate, while the Microsoft Defender Offline scan restarts your PC to check for deep-rooted threats that activate during normal Windows operation. Select the option that matches your current need.

Step 4: Start the manual scan

Click the Scan now button at the top of the Scan options page. Windows Defender will immediately begin analyzing your system. You will see a progress bar and a status message indicating which files or processes are currently being checked. During a Full or Offline scan, your PC may run slower than usual because Defender is actively reading and evaluating data across your storage drives. Do not force-shut down the computer while the scan is running, as interrupting the process can leave your system in an inconsistent state.

Step 5: Review the scan results

Wait for the progress bar to reach one hundred percent, then examine the threats list. If Defender finds nothing, you will see a message confirming that your device is protected and no threats were detected. If items are flagged, click Show details to view the threat name, severity level, and location. You will then be presented with action buttons such as Quarantine, Remove, or Allow on device. Quarantining isolates the file so it cannot execute, while Remove permanently deletes it. If you recognize the file as a legitimate program, choose Allow on device to add it to the exclusion list.

Pro Tip: If you suspect a specific folder is infected, skip the Full scan and use a Custom scan instead. Pointing Defender directly at the suspicious directory saves time and reduces unnecessary system load while still catching the threat.

Troubleshooting common scan issues

Even straightforward scanning tasks can run into roadblocks. Here are the most frequent problems and how to resolve them.

  • Scan will not start or immediately closes: Another antivirus program may still be active in the background. Open Control Panel > Programs and Features, locate any third-party security suite, and completely uninstall it. Restart your PC, then return to Windows Security and try again.
  • Windows Defender appears disabled: Group policy or registry edits can sometimes turn off Defender in corporate or customized environments. Press Win + R, type regedit, and navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender. If you see a DisableAntiSpyware DWORD set to 1, double-click it and change the value to 0. Restart your computer and check Windows Security again.
  • Scan reports the same threat repeatedly: Malware often reinstalls itself using scheduled tasks or startup entries. After quarantining the detected item, open Task Manager with Ctrl + Shift + Esc, go to the Startup tab, and disable anything unfamiliar. Run another Full scan to confirm the threat stays removed.

Final tips for ongoing protection

  • Run a Quick scan once a week to catch newly downloaded threats before they spread.
  • Keep Windows Update enabled so Defender receives the latest virus definition updates automatically.
  • Use the Offline scan only when standard scans fail to clear stubborn infections.
  • Check the Protection history tab regularly to stay aware of what Defender blocks or quarantines.

Have you ever caught a hidden threat by running a manual Defender scan, or do you rely on third-party antivirus software instead? Share your experience in the comments below.

Over to you: Do you run manual Defender scans regularly, or do you prefer third-party antivirus software?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement