Pick the scan for the question
A quick scan checks common locations. A full scan is broader and can take considerably longer. A custom scan checks a selected path. Start with current signatures and an understanding of whether Defender is active or another antivirus is responsible for protection.
If a computer may be actively compromised, scanning is one part of incident response. Do not run a suspicious file just to see whether the scanner notices it.
Update and start
Open an elevated Windows PowerShell window. These examples are separate choices, not a list to run all at once.
Update-MpSignature
Start-MpScan -ScanType QuickScanFor a planned broader check:
Start-MpScan -ScanType FullScanFor a specific existing folder:
Start-MpScan -ScanType CustomScan -ScanPath 'C:\Users\Public\Downloads'Replace the path with the actual folder you intend to examine. Avoid choosing a shared business-data location without considering performance and your incident process.
Check completion and findings
Open Windows Security and inspect Protection history. Also query the completion fields:
Get-MpComputerStatus | Select-Object QuickScanStartTime,
QuickScanEndTime, FullScanStartTime, FullScanEndTimeCompare with the time you started the scan. Submitting a command is not the same as verifying completion. Custom-scan results need review through protection history or the relevant operational logs; do not assume a full-scan timestamp will represent them.
Handle a detection deliberately
Read the detected item, location and action. Follow the approved quarantine or removal process. Do not restore a blocked file merely because an application stopped working. If it is a work computer, retain useful information for IT and assess whether credentials or other systems may be affected.
Common problems
A full scan can slow a busy computer, so schedule it sensibly. A different active antivirus may make Defender scanning unavailable. Policy can restrict actions. Resolve the actual error rather than switching off protections or adding broad exclusions.
What a clean scan tells you
It tells you no threat was detected by that scan with those signatures and capabilities. It does not prove that stolen passwords, unauthorised cloud access or every unknown threat has been addressed. Review the original symptom and account activity as well.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.