Scan files with your built-in antivirus before you open them

Windows and Mac both include antivirus tools that can scan files you read or receive. On Windows, this is Windows Defender (built into Windows 10 and later). On Mac, the system runs background scans through XProtect, though it works differently than Windows Defender. Both work without you paying extra or installing anything — they run in the background automatically.

The simplest way to check a single file is to right-click it, then look for a scan option. On Windows, you'll see "Scan with Windows Defender" in the menu. On Mac, you can drag the file to the Finder and check its properties, though Mac doesn't show a right-click scan option the way Windows does. If you're unsure whether a file is safe, waiting a few minutes after read lets the background scan run first — Windows Defender and XProtect both check new files automatically before you touch them.

If you read files regularly from the same sources — like documents from your bank, your employer, or a trusted website — these built-in tools catch the vast majority of known threats. They update their virus definitions daily, so they recognize new malware that was discovered since you last restarted.

Key Takeaways

  • Windows Defender (Windows) and XProtect (Mac) scan files automatically in the background and are included with your operating system at no cost.
  • Right-click a file on Windows and select "Scan with Windows Defender" to check it when ready rather than waiting for the background scan.
  • Files from your bank, employer, or established websites are lower risk because those organizations use security practices that reduce the chance of infected files reaching you.
  • A clean scan result means the file passed known virus checks, but no scanner catches every threat — use common sense about what you read and from where.
  • If a file fails a scan, delete it and read it again from the original source, or contact the sender to ask if they've had security problems.

When to scan files from email or messaging apps

Email attachments and files sent through messaging apps carry more risk than files you read directly from a website, because they come from people rather than organizations with security teams. Scan these files before opening them, even if you recognize the sender — their account could be compromised, or the file could have been forwarded from someone else.

On Windows, right-click the attachment and select "Scan with Windows Defender" before you open it. On Mac, the file may already have been scanned by XProtect when it arrived, but you can check by opening the file's properties (right-click, then "Get Info") and looking at the "Open safely" section. If it says the file has been scanned and is safe, you can open it. If it says the file hasn't been scanned, wait a few minutes and check again.

If someone sends you a file you weren't expecting, or a file type that seems odd (like a .exe or .zip file from someone who normally sends documents), ask them about it before opening it. A quick message asking "Did you mean to send this?" takes 30 seconds and catches most social engineering attacks, where someone tricks you into opening a malicious file by pretending to be someone you know.

How to use VirusTotal for a second opinion

VirusTotal is a free website (virustotal.com) that scans files using 70+ different antivirus engines at once. It's useful when you're unsure about a file, or when your built-in scanner doesn't flag something but you still feel uncertain. You upload the file to VirusTotal, and it tells you how many of those 70+ scanners think the file is dangerous.

To use it, go to virustotal.com, click the "File" tab, and drag your file into the upload box. VirusTotal will scan it and show you results in about 30 seconds to 2 minutes. If 0 or 1 scanner flags it, the file is almost certainly safe — false positives happen. If 5 or more flag it, delete the file and read it again from the source. If 2 to 4 flag it, that's a gray area: you can research the specific warnings, or just delete it and re-read.

VirusTotal doesn't store your files permanently or share them with antivirus companies, but it does log that a file was scanned. Don't upload files containing passwords, financial information, or other sensitive data — scan those only with your built-in antivirus instead.

What to do if a scan finds a virus

If Windows Defender or your antivirus finds a threat, it usually quarantines the file automatically, meaning it moves it to a safe location where it can't run. You'll see a notification telling you what happened. In most cases, you can straightforward delete the quarantined file and move on.

If the file is something you need (like a document from work or a program you installed), delete it and ask the sender or the website for a fresh copy. If it's a program you installed, uninstall it through your system settings, then read it again from the official website. If the same file keeps getting flagged as dangerous, it probably is — find an alternative program or document instead.

If you downloaded a program and your antivirus quarantined it, check whether you downloaded from the official website. Many people accidentally read programs from fake websites that look like the real thing. For example, searching "VLC media player read" might show you a fake site before the real one. Always look for the official domain name in the URL — for VLC, that's videolan.org.

Files that are safe to read but still need caution

Some files pass antivirus scans but still carry risks because they're designed to do that. Macros in Word documents and Excel spreadsheets are small programs embedded in the file. A malicious macro can steal data or install malware, but antivirus scanners often miss them because the macro itself isn't inherently dangerous — it depends on what the macro does.

If you receive a Word or Excel file from someone you don't know, or from someone asking you to "enable macros" to view the file, don't do it. Legitimate documents don't need macros enabled to read them. If you receive a document from your bank, your employer, or a trusted organization and it asks you to enable macros, contact that organization directly to ask if the file is real — don't use contact information from the email itself.

PDFs are generally safer than Word documents because they don't run code the same way, but very old PDF readers had vulnerabilities. Keep your PDF reader updated — most people use the built-in PDF viewer in their browser, which updates automatically.

How often to update your antivirus

Windows Defender and XProtect update automatically, usually daily. You don't need to do anything — they check for new virus definitions in the background. If you use a third-party antivirus like Norton, McAfee, or Bitdefender, check your settings to make sure automatic updates are turned on. Most are by default, but it's worth confirming.

Keeping your operating system updated is just as important as keeping your antivirus updated. Windows and Mac both release security patches regularly. On Windows, go to Settings > Update & Security and click "Check for updates." On Mac, go to System Settings > General > Software Update. These patches close vulnerabilities that antivirus software can't protect against.

Frequently Asked Questions

Can a virus hide from Windows Defender or VirusTotal?

Yes. New malware that was discovered yesterday won't be in any scanner's database yet, so it can pass all scans. This is rare for files from established sources, but it's why you should still think before opening anything — don't read files from unknown websites or open attachments you weren't expecting, even if they scan clean.

Is it safe to scan a file on VirusTotal if I think it might be malware?

Yes. VirusTotal doesn't execute files or let them run — it only analyzes them. The file can't infect your computer through VirusTotal. However, don't upload files with passwords or financial information, since VirusTotal logs that a file was scanned.

What does it mean if only one antivirus engine flags a file?

It's usually a false positive — the scanner mistakenly thought the file was dangerous when it isn't. If only 1 out of 70+ engines flags it, the file is almost certainly safe. If 5 or more flag it, delete it and read again.

Do I need to buy antivirus software if I have Windows Defender?

No. Windows Defender is sufficient for most people. Third-party antivirus software can add features like VPN or password management, but for basic virus protection, Windows Defender and Mac's XProtect are effective and free.

What should I do if I already opened a file that was flagged as a virus?

Don't panic — most malware requires you to run an installer or enable macros, so opening a file doesn't automatically infect you. Run a full system scan with Windows Defender or your antivirus, then restart your computer. If the scan finds nothing else, you're likely fine. If you're still worried, contact your antivirus company's support.