Why an offline scan sees what a normal scan misses
A regular Defender scan runs inside Windows, side by side with every other process on the machine. Modern malware exploits exactly that: it runs with the same privileges, hooks the very APIs an antivirus uses to enumerate files, and simply hides its own body from the scan. An offline scan removes that home advantage — the PC reboots into a minimal, trusted environment built on Windows RE, your full Windows never loads, and the infection never gets a chance to run. From there Defender reads the disk directly and sees everything: boot records, locked files, disguised copies.
This scan targets the nastiest category of threats: rootkits and bootkits that anchor themselves below the running system, and self-defending malware that kills antivirus processes on sight. It is not a deeper version of the quick scan — the disk is the same, but the vantage point is one the infection cannot reach. That difference is the entire point of the reboot.
- A quick or full scan reports a clean PC, yet pop-ups, a hijacked homepage or unknown processes keep coming back
- The same threat reappears in Protection history after every reboot, no matter how many times you remove it
- Defender itself misbehaves: it turns itself off, its options are greyed out, or real-time protection keeps dying
- Files were encrypted or renamed in bulk — classic ransomware behavior — and the machine must be disinfected first
- The browser redirects searches and injects ads although every scan comes back clean
- You ran a dubious free utility as administrator and want certainty that nothing settled in
How to launch the scan
Open Windows Security — Settings → Privacy & security → Windows Security, or simply type windows security in Start — and go to Virus & threat protection → Scan options. Scroll down to Microsoft Defender offline scan, select it and press Scan now; expect a UAC confirmation. Save your work and plug the laptop in first: the PC restarts immediately, shows a Defender progress screen for roughly 15 minutes and reboots back to the lock screen on its own. Do not hold the power button during the scan — interrupting it will not damage your files, but you will have to start over.
The command-line route does the same job: an elevated PowerShell running Start-MpWDOScan schedules the offline scan and reboots the machine. If a third-party antivirus is installed and active, Defender switches to passive mode, and the offline option disappears from the list. That is expected behavior rather than a bug, and it applies to every Defender scan option alike.
After the reboot: reading the results
When the scan finishes, the PC restarts into Windows and shows a summary of what was found; the details remain in Virus & threat protection → Protection history. If anything was detected and removed, treat it as the beginning of the cleanup, not the end: uninstall the programs that brought the infection in, review browser extensions and homepage settings, and check what launches at startup. Because malware that ran with administrator rights may have touched system files, a follow-up sfc /scannow is a cheap sanity check.
There is no reason to run offline scans on a schedule — they cost a reboot and a quarter of an hour. Run one on suspicion instead: strange behavior combined with a clean regular scan is precisely the case this tool was built for. Before starting, update Defender’s definitions (Virus & threat protection → Protection updates → Check for updates) so the offline pass works with fresh signatures.
Questions and Answers
How long does a Microsoft Defender offline scan take?
Usually about 15 minutes including the restart, and 20–25 on a slow HDD. You cannot use the PC while it runs.
Does an offline scan delete personal files?
No. It quarantines or removes only what it identifies as malicious — documents, photos and programs stay untouched.
Why is the Microsoft Defender offline scan option missing?
Almost always because a third-party antivirus is active, so Defender runs in passive mode. Uninstall or disable the other antivirus and the option returns.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]