Three ways to run a targeted scan
Real-time protection already inspects files as they download and open, but a manual, on-demand scan of a specific object is still worth knowing. It is the right move when a fresh archive from the internet looks suspicious, when you want certainty about an old folder of cracked installers, or when someone sent you a file that “their antivirus says is fine”. The engine and definitions are the same as in the scheduled scans — what changes is the scope and the timing.
- Right-click scan — the quickest way to check one downloaded file before you open it
- Custom scan — when a whole folder or a specific drive needs checking
- MpCmdRun.exe — command-line scanning of files and folders, handy in scripts and batch files
- PowerShell Start-MpScan — the same custom scan from an elevated console
Step by step: the right-click scan
Open File Explorer and navigate to the file — Downloads, in the typical case. On Windows 11, right-click it, choose “Show more options” (or press Shift+F10), and click “Scan with Microsoft Defender”; on Windows 10 the entry sits in the first menu directly. A Windows Security window opens, runs the scan, and reports the result: “No current threats. No threats found…” for a clean pass, or a list of findings with Clean actions when something turned up.
For folders, the UI route is Windows Security → Virus & threat protection → Scan options → Custom scan → Scan now, then select the folder in the picker. Note that this picker works with folders and drives only — single files are exactly what the right-click scan exists for. Both scans use the current definitions, so if the file arrived today, first run Protection updates → Check for updates; scanning with week-old signatures is how “clean” results mislead people.
Command line and what happens when a threat is found
For automation, an elevated Command Prompt or PowerShell runs the same check without any clicks: "%ProgramFiles%\Windows Defender\MpCmdRun.exe" -Scan -ScanType 3 -File "C:\path\to\file.zip" returns exit code 0 when nothing was found, and PowerShell offers Start-MpScan -ScanType CustomScan -ScanPath "C:\some\folder". The -ScanType 3 flag means “custom scan of exactly what I pointed at”; wrap paths with spaces in quotes.
When Defender does find a threat, it usually cleans or quarantines it on the spot and shows what it did; the full record, including the option to Restore a false positive, lives in Virus & threat protection → Protection history. Resist the urge to hit Allow on a file you merely suspect — restoring should be reserved for things you can verify. And if the same threat keeps returning or the scan refuses to finish, that is the moment for a Microsoft Defender offline scan rather than a fourth re-scan.
Questions and Answers
Why is “Scan with Microsoft Defender” missing from the right-click menu?
Two usual reasons: on Windows 11 the entry hides behind “Show more options” in the new context menu, and when a third-party antivirus is installed, Defender steps back and the entry disappears entirely.
How do I scan a single folder in Windows Security?
Virus & threat protection → Scan options → Custom scan → Scan now, then pick the folder. The picker works with folders and drives, not single files — for one file use the right-click scan.
Can I check a file for viruses before opening it?
Yes — that is precisely what the right-click scan is for. Real-time protection checks files on download too, but a manual scan with current definitions is the reliable last look before you open an archive from an unknown source.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]