This guide is for a personal Windows 11 computer where Microsoft Defender Antivirus is the active protection provider. It explains a bounded check, not a complete incident investigation. Open Windows Security independently from the Start menu, not from a pop-up, then look at Virus & threat protection. A scan result is one piece of evidence. It does not establish that every possible problem is absent, and it does not replace urgent help when files are being encrypted, money is at risk or the drive is failing.
Start here
Start with the active protection
Confirm which protection provider is active before interpreting a Windows Security result.
Check the active sourceOpen Windows Security independently and confirm whether Microsoft Defender Antivirus is active or another provider has taken over.Read this part
Run one bounded inspectionUse Virus & threat protection and Quick scan as a limited check when the computer and data are stable.Read this part
Record the result accuratelyNote the time, scan type, completion state, detection and action status without restoring or allowing an unknown file.Read this part
Confirm the protection source
Open Start, search for Windows Security and open it independently. Select Virus & threat protection. Check whether Microsoft Defender Antivirus is active. A third-party antivirus product may replace active Defender protection; if that is what Windows reports, use that provider’s support and do not switch protection off or install multiple antivirus products to compare them.
Under Virus & threat protection updates, open Protection updates and Check for updates when the device is safe to keep online. These are security intelligence updates. Do not reconnect a device isolated for a suspected active incident just to update it.
Source: Microsoft’s Windows Security virus and threat protection guidance.
Read the scan result
When the computer is stable and there is no active ransomware, data-loss or financial incident, select Quick scan under Current threats in Virus & threat protection and let it finish. Scan options also offers Full (broader file coverage), Custom (selected files/folders) and Offline (restarts outside normal Windows). Follow Microsoft’s instructions before choosing an additional scan. None is mandatory simply because a warning appeared in a browser.
Record whether the scan completed or was interrupted, its type and time, and whether it reported a detection or action. A completed Quick scan is not the same as a full investigation. No detection is not a universal clean verdict, particularly where the concern involves an installed tool, a compromised account or a hardware problem.
If irreplaceable data is already unreadable or the drive sounds or behaves as though it is failing, seek help first. Do not keep scanning a deteriorating device as a routine experiment.
Use Protection history carefully
Open Protection history in Windows Security to read event cards; administrator access may be needed for threat details. The labels are not interchangeable: an item may be quarantined, blocked, require action, or show that remediation is incomplete. “Remediation incomplete” needs attention; it is not the same as a completed action.
Do not restore or allow an unknown file, create an exclusion, or bypass an administrator prompt just to make the alert disappear. Automatic quarantine can affect a file that an application expects, so note the file or application context and obtain qualified help if the consequence is unclear. Keep the record private and omit passwords or unnecessary personal information.
Microsoft explains the Protection history statuses. History is retained for a limited period, so an empty list does not prove that nothing happened.
| Record | Why it matters |
|---|---|
| Time and scan type | Places the result in context. |
| Completed or interrupted | Shows whether the check ran to its stated end. |
| Detection and action status | Separates a report from a completed response. |
Use these notes when contacting the protection provider or an independent specialist. Keep track of unresolved actions as well as completed ones.
What to read next
If you’d rather have local help, see our virus and malware diagnosis help.