Orca IT Solutions

Security Basics

Run a virus scan with what you already have

Windows Security is already installed, already updated and already scanning in the background. This guide shows you how to run each scan type deliberately, where to read the results, and what to do when something turns up. A Quick scan takes a few minutes.

🛡 Built Into Windows No Purchase Needed💰 Windows 11 and 10 Offline Scan Included

Before You Scan

The scanner you already own

Windows Security, the product behind it known as Microsoft Defender Antivirus, is included with every current Windows installation and updates itself alongside Windows.

Most people scan reactively, after something has already gone wrong. That is fine, and it is worth knowing that Windows Security is scanning quietly on its own the whole time. Running a manual scan is about deliberately checking a specific thing: a machine that started behaving strangely, a file someone sent you, or a PC that has been off for months.

There are three scans worth knowing. A Quick scan checks the locations where threats normally live and finishes fast. A Full scan reads every file on the drive and can run for hours, so it suits an overnight run. A Microsoft Defender Offline scan restarts the PC and scans before Windows loads, which is how it catches things that hide from a scanner running inside a live session.

One caution before you start. A clean scan result is genuinely reassuring, but it is not proof of a clean machine. Browser notification spam, scam pop-ups, unwanted toolbars, stolen sign-in sessions and router level tampering all produce symptoms that look like infection while passing an antivirus scan cleanly. If the behavior continues after a clean result, that is exactly the point at which our virus and spyware removal work starts.

Never call a number from a pop-up

A full screen warning claiming your PC is infected, with a phone number and a countdown, is the scam itself. Real security software does not ask you to call anyone. Close the browser, run the scan below, and if the page will not close, restart the PC.

Step By Step

Scan the machine properly

Start with the Quick scan. Escalate to a Full scan or an Offline scan only if the symptoms continue or the Quick scan finds something.

01

Open Windows Security

Select Start, type Windows Security and open the app. You can also reach it through Settings > Privacy & security > Windows Security > Open Windows Security. The home screen shows a row of shield cards, each with a green tick when it is healthy.

02

Go to Virus & threat protection

Select Virus & threat protection, the first card. The top of the page shows Current threats and when the last scan ran. If a yellow or red warning is showing here, read it before you scan, because it may be telling you protection is turned off.

03

Run a Quick scan

Select Quick scan. A progress count of scanned files appears and it usually finishes within a few minutes. You can keep working while it runs. When it is done it reports either no current threats or a list of what it found.

04

Open Scan options for the deeper scans

Select Scan options under the Quick scan button. You get Quick scan, Full scan, Custom scan and Microsoft Defender Offline scan. Custom scan is the one to use when you want to check a single folder or a USB stick rather than the whole machine.

05

Run a Full scan when you have time

Choose Full scan and select Scan now. It reads every file on every drive and can take several hours on a large disk. Start it at the end of the day. The PC can be used while it runs, though everything will feel slower.

06

Use the Offline scan for anything stubborn

Save all open work first. Choose Microsoft Defender Offline scan and select Scan now. Windows restarts, scans from a clean environment before the desktop loads, and restarts again into Windows. It takes roughly fifteen minutes and the screen will look unfamiliar while it runs, which is normal.

07

Read Protection history and act on it

Back on the Virus & threat protection page, select Protection history. Every detection, block and action is listed with a date. Open any entry marked as needing action and choose Remove, then restart the PC and run one more Quick scan to confirm it is gone.

Worth Knowing

Getting the most from Windows Security

Settings that matter, a mistake that causes real damage, and how to tell whether you are actually clean.

Never run two antivirus products at once

Two real time scanners fight over the same files, which produces freezes, slow boots and false alarms. Windows handles this by stepping Microsoft Defender Antivirus back to passive mode when another product registers itself. If you are removing an old paid product, uninstall it from Settings > Apps > Installed apps and use the vendor removal tool if fragments remain.

Check that protection is actually on

On the Virus & threat protection page, select Manage settings under Virus & threat protection settings. Real-time protection, Cloud-delivered protection and Automatic sample submission should all be on. Real-time protection switches itself back on after a short time if something turned it off temporarily.

Turn on unwanted app blocking

Go to App & browser control > Reputation-based protection settings and turn on Potentially unwanted app blocking. This catches the bundled toolbars, browser hijackers and optimizer junk that ride along with free downloads, which is a category traditional virus scanning often lets through.

Consider ransomware protection carefully

Under Virus & threat protection there is Ransomware protection and inside it Controlled folder access, which stops unrecognized apps writing to your Documents and Pictures folders. It is effective and it also blocks legitimate software that saves files, so turn it on knowing you may need to allow apps through it. It is not a substitute for a real backup.

A clean scan is not a clean bill of health

If the browser opens pages you did not ask for, search results redirect, notifications appear from sites you never visited, or accounts are being accessed from elsewhere, none of that necessarily shows up in a scan. Check browser extensions and notification permissions, and get a second opinion before assuming it is fine.

After a real infection, change passwords elsewhere

If something genuinely got in, change important passwords from a different device rather than the affected one, starting with email and banking. Then let us look at what was exposed. That is part of a proper removal and cleanup, not an optional extra.

Virus scanning questions

Do I still need to buy antivirus software?

For most home users and small offices, Windows Security is a sound baseline and needs no purchase. Paid products mainly add management, reporting and support features that matter more across a fleet of machines. What protects people most is careful behavior, current updates and working backups, not the brand of scanner.

The scan found something and removed it. Am I finished?

Restart, run a second Quick scan, and check Protection history to confirm nothing is still pending. If the same detection keeps returning after removal, something is putting it back and a Microsoft Defender Offline scan is the next step. Repeated returns after that need hands on the machine.

How long does a Full scan take?

It depends on how many files you have and how fast the drive is, and it ranges from under an hour to most of a night. There is no benefit in watching it. Start it when you are finished for the day and read Protection history in the morning.

Windows Security says protection is turned off. Why?

Usually because another antivirus product is installed and has taken over, which is expected behavior. Occasionally it means something disabled it deliberately, which is a genuine warning sign. Check Settings > Apps > Installed apps for a security product you recognize. If there is none, treat the machine as suspect.

Can a virus survive reinstalling Windows?

The overwhelming majority cannot, and a clean installation with a wiped drive is the most reliable reset there is. The rare exceptions live in firmware and are unusual outside targeted attacks. Before any reinstall, get your data off first, because that step is where files are most often lost.

Scan came back clean and the PC still feels wrong?

That gap is where most real infections live. We check the browser, the startup items and the network side, not only the file system.

Get It Checked

Talk to Your Pod

If you think something got through, do not wait for the scan to agree.

Call (602) 677-0779. We clean infected machines properly, check what was exposed, and tell you which passwords need changing and in what order.

(602) 677-0779

Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced

Same-day response No long contracts Flat, honest pricing Five-star service

Get your free IT consultation

A few details and your pod gets right back to you, usually the same business day.

Spam-protected with a quick CAPTCHA. Your message goes straight to our team in Gilbert. We only use your details to help with your request. Never sold, never shared.