What Is Microsoft Defender Offline Scan and When to Use It

Logeshwaran

Open Windows SecurityVirus & threat protectionScan optionsMicrosoft Defender Offline scanScan now. Save your work first — the PC restarts straight away and takes about fifteen minutes.

Now the reason it exists, which is more unsettling than most people expect.

Some malware is genuinely invisible to a normal scan — and not because the scanner is weak.

A normal scan asks Windows what is on the disk. A rootkit compromises Windows itself. So when Defender asks "what files are in this folder?", the answer comes back from a system that has been altered to leave the malware's own files out of the list. The scanner is working perfectly and being lied to by the thing it has to ask.

You cannot fix that from inside Windows, because the compromised part is doing the answering. So the Offline scan does not ask Windows anything. It restarts your PC into a separate, trusted environment, reads the disk directly while the malware is not running, and restarts back with the results.

That is why the same detection can keep coming back no matter how many times you remove it — and why this one scan is the thing that finally stops it.

⚡ Quick Answer

Where: Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan.

Nothing to download. It is built into Windows 10 and 11. Guides telling you to burn a CD or make a USB stick are describing a version that no longer exists.

Run it when: a detection keeps returning, Defender cannot remove something, Windows Security will not open, or scans come back clean while the machine clearly misbehaves.

Results: no summary appears afterwards. Check Protection history. This confuses everybody.

Your files are safe. It is a scan, not a reset. Nothing is reinstalled and nothing is erased.

The Detection That Came Back Four Times

A customer brought Jake a desktop that Defender kept cleaning and kept finding again. Same detection name, same removal, same confirmation that the threat had been dealt with — and then a day or two later the notification would appear once more.

He had done everything sensibly. He removed it each time. He ran a full scan, which took most of a Sunday and reported the machine clean afterwards. He installed a second scanner for a second opinion, which found nothing at all. By the fourth cycle he had concluded that Defender was broken, or possibly that his PC was.

Neither was true, and the full scan finding nothing was the clue — though it looks like the opposite of one.

Jake ran an Offline scan. Fifteen minutes, one restart, and the machine has been clean since.

What the customer wanted to know afterwards was reasonable: if a full scan reads every file on the disk, and this thing was on the disk, how did a six-hour scan miss what a fifteen-minute one found?

Ethan answered that one himself when Jake put it to him: "Because the full scan asked Windows for the list of files, and Windows left that one off. It's not that the scanner didn't look hard enough. It looked exactly where it was told to, at a list it was handed by something that had already been got at. You can't audit a company using books the accountant is writing."

That is the whole idea, and everything else on this page follows from it.

Why a Running Windows Cannot Be Trusted to Look

When any antivirus scans your disk, it does not read the platters directly. It asks Windows. It requests a list of files in a folder, then asks for the contents of each one, and Windows answers.

That arrangement is fine as long as Windows is telling the truth. A rootkit is malware built specifically to make it stop.

It embeds itself deeply enough to intervene in those answers. When something asks for the contents of a folder, the rootkit removes its own entries before the list is handed back. When something asks whether a particular process is running, the answer omits it. The scanner receives a clean, complete, entirely false picture — and reports the machine as healthy, correctly, based on what it was told.

This is why a full scan can take six hours and find nothing while something is plainly wrong. Duration does not help. Reading more files does not help, because the file list itself is the thing being edited.

The only way out is to stop asking the compromised system. So the Offline scan restarts your PC into the Windows Recovery Environment — a small, separate, trusted copy of Windows that lives on its own partition — and scans the main installation from there, as an outsider looking in. The rootkit is not running. It is just a file on a disk, with nothing to hide behind.

Microsoft's own description of what it targets is worth knowing: malware that attempts to bypass the Windows shell, including rootkits and infections of the master boot record. Those are precisely the things a running Windows cannot be relied upon to report.

The Four Situations Worth Using It For

Situation Why an ordinary scan will not settle it
The same detection keeps returningSomething still running is putting it back, and that something is not being seen
Defender finds it but cannot remove itThe file is locked or protected while Windows is running
Windows Security will not open or scanDisabling the security tools is one of the first things malware does
Clear symptoms, every scan cleanExactly what a successful rootkit looks like from inside Windows

One honest caution on that fourth row, because it sends people down the wrong path more often than the right one: a slow, odd-behaving PC with clean scans is far more often unwanted software than a rootkit. Browser extensions, bundled "optimizers" and startup clutter produce the same symptoms and are enormously more common. Check those first — our guide to scanning with Defender covers what a clean result actually tells you and where to look instead.

Use the Offline scan when the evidence genuinely points at something hiding, not as a reflex whenever a machine feels slow.

Running It

  1. Save everything and close your programs. The restart happens immediately after you click, with no further warning.
  2. Plug in a laptop. Fifteen minutes outside Windows with no battery management is not the moment to find out how much charge you had.
  3. Open Windows Security, choose Virus & threat protection, then Scan options.
  4. Select Microsoft Defender Offline scan and click Scan now. Confirm the restart prompt.
  5. Leave it alone. The machine restarts into a plain blue recovery screen and scans. Around fifteen minutes, then it restarts back into Windows on its own.
  6. Check Protection history for the results, because nothing will tell you what happened.

Step five is where people go wrong, and it is worth being firm about. The recovery environment has a minimal interface. It can sit on the same percentage for several minutes at a time, and there is no reassuring detail. That is the interface being basic, not the scan being stuck. Do not hold the power button because it looks idle — interrupting a scan that is partway through removing something is how a manageable problem becomes an unbootable machine.

Finding Out What It Did

Your PC restarts into Windows and behaves as though nothing happened. No summary, no notification, no report. Most people conclude the scan failed to run.

It ran. The results are in Windows SecurityVirus & threat protectionProtection history, alongside every other detection. Anything found and removed is listed there with a timestamp matching the scan.

An empty history is a real answer too. It means nothing hidden was found, and combined with clean ordinary scans that is reasonably strong evidence the machine is not infected — which redirects you, usefully, toward unwanted software and startup clutter.

If it did find and remove something, the scan is the beginning of the job rather than the end of it. Work through this:

  1. Run an ordinary quick scan to confirm the machine is now clean with Windows running normally.
  2. Change your passwords from a different device — a phone, another computer, anything but the machine that was infected. Email first, because everything else can be reset through it. Then banking, then anything with money attached.
  3. Sign out of all sessions where the service offers it. A changed password does not always end sessions that are already open elsewhere.
  4. Turn on two-step verification anywhere it is offered and you have not already. This is the single change that makes a stolen password stop mattering.
  5. Watch your accounts for a fortnight. Not anxiously, just check statements and sign-in alerts rather than assuming the removal closed the matter.

Step two is the one people skip and it is the one that matters most. Something with enough access to conceal itself from Windows had enough access to record what you typed. The file has been removed; whatever it collected before that has not been.

And do it from another device rather than the cleaned one. Not because the cleaning probably failed, but because "probably" is doing more work in that sentence than you want it to when the alternative costs you five minutes on a phone.

When It Will Not Run

What happens Cause Fix
The option is not in Scan optionsA third-party antivirus is active, so Defender has stepped asideRemove it with the maker's own removal tool, then restart
It restarts normally, no scanThe recovery environment is disabled or damagedRun reagentc /info then reagentc /enable as administrator
Windows Security will not open at allThe app or its service is damaged, possibly deliberatelyRepair system files with DISM then SFC, then try again
The scan starts and the PC reboots partwayHardware fault, overheating, or failing diskCheck drive health before assuming malware
It completes but the detection still returnsSomething is reinstating it from outside the diskRead the next section — this is the rare serious case

Row three is worth pausing on. If Windows Security itself has been disabled, that is not a coincidence — switching off the security tools is one of the first things malicious software does. Our guide to the Windows Resource Protection repair-service error covers getting the repair tools running again when something has interfered with the service they depend on.

What It Cannot Do

The Offline scan is the strongest tool Defender has, and it is worth being straight about where it stops.

It cannot always reach firmware. A very small category of malware lives in the motherboard's firmware rather than on the disk, which means it survives the Offline scan, a full format and a clean reinstall of Windows. This is genuinely rare on home machines and disproportionately talked about, but it is the honest answer to "what if it comes back after everything".

It is not a general repair tool. It removes malicious files. It does not undo the damage they caused, restore settings they changed, or fix Windows components they broke. Those are separate jobs, and a machine that has been genuinely compromised often needs several of them.

It does not touch unwanted software you agreed to install. Toolbars, optimizers and bundled extras are not malware in the strict sense and often are not removed, which is why an Offline scan can come back clean on a machine that is obviously misbehaving.

And the honest position on when to stop repairing: if detections persist after a successful Offline scan, an ordinary scan and a clean reinstall, the sensible move is to stop cleaning and rebuild — new installation, files restored from a backup made before the trouble started, passwords changed from a different device. That is a bad afternoon, and it is a better outcome than months of uncertainty about whether the machine is yours.

Ethan's rule, which Jake repeats to customers who want to keep fighting: "There's a point where cleaning costs more than rebuilding, and the tell is when you've stopped being able to explain what's happening. If you can't say what it is, you can't say it's gone."

Why This Replaced the Safe Mode Advice

For years the standard advice for a stubborn infection was to boot into Safe Mode and scan from there. It was reasonable advice and you will still find it everywhere.

The problem is that Safe Mode still runs Windows. It loads a reduced set of drivers and services, which is enough to sideline most ordinary programs — but anything embedded deeply enough to intercept file listings is still loaded, still running, and still able to conceal itself. Against the exact category of malware you would boot into Safe Mode to catch, it offers less than it appears to.

The Offline scan does not start Windows at all. That is a genuinely different situation rather than a lighter version of the same one.

Safe Mode remains useful for plenty of other things — removing a program that will not uninstall, undoing a driver, getting into a machine that will not start normally — and our guide to entering Safe Mode covers those. For something hiding, use the Offline scan instead.

What This Page Said in 2016

The original version of this post explained where to find Windows Defender Offline and how to launch it, and at the time that was genuinely useful information — because it was a different product delivered a different way.

In that era it was a separate download. You fetched an installer from Microsoft, wrote it to a CD or a USB stick on a working computer, and booted the infected machine from that media. It was the right approach for the problem, and it was enough of a production that most people never used it.

It is now built into Windows and it is a button. Same idea, none of the preparation.

That change is why so much advice about this tool is confusing today. A large number of guides still describe the download-and-burn process, which sends readers looking for an installer that is no longer offered, and leaves them concluding the feature has been removed when it has in fact become far easier to use. If you have gone looking for that download and failed to find it, nothing was wrong with your searching.

Your Questions, Answered Straight

What is Microsoft Defender Offline scan?

It is a scan that runs before Windows loads. Your PC restarts into the Windows Recovery Environment, scans the disk from there, and restarts back into Windows with the results. Because Windows is not running, malware that hides inside Windows cannot hide from it.

Why can some malware hide from a normal scan?

Because a normal scan asks Windows what is on the disk, and a rootkit compromises Windows itself. When the scanner asks what files are in a folder, the answer comes back with the malware's own files quietly omitted. The scanner is working correctly and being told a lie by the system underneath it.

When should I run an Offline scan?

When the same detection keeps returning after you remove it, when Defender cannot remove something it found, when Windows Security itself will not open or run, or when the machine misbehaves in ways that suggest an infection while every ordinary scan comes back clean. Those four situations are what it exists for.

How do I run a Microsoft Defender Offline scan?

Open Windows Security, choose Virus & threat protection, click Scan options, select Microsoft Defender Offline scan, then click Scan now. Save your work first, because the machine restarts immediately. The whole thing takes around fifteen minutes.

How long does the Offline scan take?

Around fifteen minutes on most machines, including the restarts at each end. It is far quicker than a full scan because it targets the areas where hidden malware lives rather than reading every file on the disk. Leave the machine alone while it runs and do not power it off.

Do I need to download anything first?

No, and this is where most older guides mislead people. It used to be a separate download you wrote to a CD or USB stick before you could use it. On Windows 10 and Windows 11 it is built in, and it is a button inside Windows Security. If a guide tells you to make bootable media, it is describing a version that no longer exists.

Will I lose any files during the scan?

No. It is a scan rather than a repair or a reset, and your documents, photos and programs are untouched. The only things removed are items identified as malicious, and even those are usually quarantined rather than deleted so they can be recovered if it turns out to be a mistake.

Where do I see the results afterwards?

In Windows Security, under Virus & threat protection, open Protection history. The Offline scan's findings appear there like any other detection. There is no summary screen when the machine restarts, which is why people assume it did not run — check Protection history rather than waiting to be told.

The screen looked frozen during the scan. Is that normal?

Yes. The recovery environment shows a plain screen with minimal feedback and can appear to sit still for long stretches. That is the interface being basic rather than the scan being stuck. Give it the full fifteen minutes at least, and do not hold the power button because it looks idle.

Is this the same as scanning in Safe Mode?

No, and it is better. Safe Mode still runs Windows, just with fewer drivers and services, so anything embedded deeply enough is still loaded and can still conceal itself. The Offline scan does not start Windows at all, which is a genuinely different situation and the reason it replaced the old Safe Mode advice.

What if the Offline scan option is missing?

It usually means a third-party antivirus has taken over, since Defender steps aside when another product is active. It can also be missing if the recovery environment is damaged or disabled. Check whether another security product is installed first, because that is the far more common of the two.

The PC restarted normally instead of scanning. Why?

The recovery environment did not start, usually because it is disabled or its partition is damaged. From an administrator Command Prompt, reagentc /info reports whether it is enabled and reagentc /enable attempts to switch it back on. If that fails, the recovery environment needs repairing before the scan can work.

Can it remove a rootkit completely?

Often, and that is exactly what it is built for. What it cannot always reach is malware living in firmware rather than on the disk, which survives even a full reinstall. That is rare on home machines. If detections persist after a successful Offline scan and a clean reinstall, firmware is the remaining explanation.

Should I run it regularly as a precaution?

No. It is a targeted tool for a specific suspicion, not routine maintenance, and running it monthly on a healthy machine achieves nothing beyond fifteen minutes of downtime. Quick scans plus real-time protection are the routine. This is what you reach for when something is genuinely wrong.

What should I do after it finds and removes something?

Run an ordinary quick scan to confirm the machine is clean, then change the passwords for anything important from a different device. If something was running on your PC with enough access to hide itself, it had enough access to capture what you typed, and that matters more than the file that has now been removed.

Does this work the same on Windows 11 and Windows 10?

Yes. The option sits in the same place under Scan options, the scan behaves identically, and the results appear in Protection history on both. The feature was previously called Windows Defender Offline, which is why some menus and older articles use that name for the same thing.

Revision note. Originally published December 2016, when Windows Defender Offline was a separate download you wrote to a CD or USB stick before you could use it. Rewritten August 22, 2026 for Windows 11 and Windows 10, where it is built in and takes one click. That change is why so much advice about this tool is now confusing, and it is why the page needed rebuilding rather than updating. New here: why a running Windows cannot be trusted to report what is on its own disk, the four situations that actually justify the scan, where the results hide afterwards, an honest account of what it cannot reach, and why it replaced the old Safe Mode advice. If you have run it and are unsure what the result means, please write in with what Protection history shows — that is usually the whole answer. And if you have been hunting for a download that no longer exists: nothing was wrong with your searching, the product simply moved.

Related