Yes, Windows Defender scans for malware, but not all of it

Windows Defender is the built-in antivirus program on Windows computers. It runs in the background and scans files when you read them, when you open them, and on a schedule you can set. It catches many common threats — viruses, trojans, worms, and some ransomware — but it does not catch everything. Malware authors write new variants constantly, and Defender's detection lags behind the newest threats by hours or days.

The program works by comparing files against a database of known malicious code. When you read something or open a file, Defender checks it against that database. If the file matches a known threat, Defender quarantines it (moves it to a locked folder where it cannot run). If the file is new or modified in a way Defender has not seen before, it may slip through.

Key Takeaways

  • Windows Defender scans files automatically when you read and open them, and runs scheduled full scans you can customize.
  • It catches viruses, trojans, worms, and many ransomware variants, but misses newly created malware and heavily obfuscated threats.
  • Defender alone is not enough protection if you visit risky websites, open email attachments from strangers, or read files from untrusted sources.
  • You can see what Defender found by opening Windows Security and checking the Virus & threat protection history.
  • Real-time protection is on by default, but you should verify it is enabled and check that scheduled scans are running weekly.

How Windows Defender's scanning actually works

Windows Defender runs three types of scans. Real-time protection watches every file you read or open and checks it when ready. Quick scans check the folders where malware most often hides — your Downloads folder, temporary files, and the Windows startup locations — and usually finish in a few minutes. Full scans check every file on your hard drive and can take an hour or more depending on how much you have stored.

By default, Defender runs a quick scan every week on Wednesday at 2 a.m. You can change that schedule or run a scan manually whenever you want. To start a manual scan, open the Windows Security app (search for it in the Start menu), click "Virus & threat protection," then click "Scan options" and choose Quick scan, Full scan, or Custom scan. A custom scan lets you pick a specific folder to check.

When Defender finds something, it quarantines the file automatically in most cases. You can see what it found by opening Windows Security, clicking "Virus & threat protection," scrolling down to "Virus & threat protection history," and clicking "See full history." That page shows you every threat Defender detected, when it found it, and what action it took.

What Windows Defender catches and what it does not

Defender is effective against known malware — threats that have been around long enough for Microsoft to add them to its database. That includes most common viruses, trojans that steal passwords, worms that spread through email, and many ransomware families. If malware has been in the wild for weeks or months, Defender probably knows about it.

Defender struggles with zero-day malware — brand-new threats that no antivirus has seen before. Malware authors release new variants constantly, and there is a window of hours or days before Defender's database updates to catch them. During that window, the malware can infect your computer. Defender also misses malware that is heavily obfuscated (disguised or encrypted in ways that hide its true purpose) and some sophisticated ransomware that uses advanced techniques to avoid detection.

Defender does not protect you from user error. If you read a file that looks like a Word document but is actually a trojan, and you open it, Defender may not stop it before it runs. If you type your password into a fake login page, Defender cannot prevent that. If you click a link in a phishing email, Defender cannot undo the damage. Your own choices matter more than any antivirus program.

Real-time protection and what it actually does

Real-time protection is the feature that watches your computer constantly. When you read a file, Defender scans it before it finishes downloading. When you open a file, Defender scans it before the program that opens it can run. When a program tries to modify system files, Defender checks whether that modification looks malicious. This happens in the background without you seeing it most of the time.

Real-time protection is on by default on Windows 10 and Windows 11, but you should verify it is actually running. Open Windows Security, click "Virus & threat protection," and look for "Real-time protection." If it says "On," you are protected. If it says "Off," click the toggle to turn it back on. Some older antivirus programs or system utilities can turn off real-time protection without asking you, so it is worth checking occasionally.

When Windows Defender is not enough

Defender alone is adequate protection if you are careful about what you read and where you go online. But if you regularly visit risky websites, open email attachments from people you do not know, read files from untrusted sources, or click links in messages from strangers, Defender will not catch everything that gets through.

Some people add a second antivirus program for extra protection, though this can slow your computer down and sometimes cause conflicts. A better approach is to use Defender as your baseline and add other protections: keep Windows and all your programs updated, use a password manager so you do not reuse passwords, enable two-factor authentication on important accounts, and think before you click. Malware needs you to do something — read a file, open an attachment, click a link — so your own judgment is your strongest defense.

How to check if Defender is actually protecting you

Open Windows Security by searching for it in the Start menu. Click "Virus & threat protection." You should see "Real-time protection" listed as "On." Below that, you should see "Virus & threat protection updates" with a recent date — if the date is more than a week old, click "Check for updates" to read the latest threat definitions.

Scroll down to "Virus & threat protection history" and click "See full history." If Defender has found threats on your computer, they will be listed here with dates and actions taken. If the list is empty, either your computer is clean or Defender has not detected anything yet. An empty history does not mean you are definitely safe — it means nothing has matched Defender's database.

You can also run a manual scan to verify Defender is working. Click "Scan options," choose "Quick scan," and click "Scan now." The scan should take a few minutes. When it finishes, it will tell you how many files it checked and whether it found anything. This does not test whether Defender catches new malware, but it confirms the scanning engine is running.

Frequently Asked Questions

Does Windows Defender slow down my computer?

Real-time protection uses some processing power, but modern computers handle it easily. You may notice a slowdown during a full scan, especially on older machines, but that only happens when you run the scan manually or during the scheduled weekly scan. If your computer feels much slower after turning on Defender, something else is probably wrong.

Can I turn off Windows Defender if I have another antivirus program?

You should not run two antivirus programs at the same time — they conflict with each other and can actually make your computer less find. If you install another antivirus, it will usually turn off Defender automatically. If it does not, you can disable Defender in Windows Security, but only if you are certain the other program is active and protecting you.

What does it mean when Defender says a file is "suspicious"?

Suspicious means Defender is not certain the file is malicious, but something about it looks wrong — maybe it is a new file, or it behaves like malware even though it does not match a known threat exactly. Defender will usually quarantine suspicious files. If you are sure the file is safe, you can restore it from quarantine, but be cautious with files from untrusted sources.

How often does Windows Defender update its threat database?

Microsoft updates Defender's database multiple times per day, usually without you noticing. Windows downloads and installs these updates automatically through Windows Update. You can check when the last update happened by opening Windows Security and looking at the date next to "Virus & threat protection updates."

Will Windows Defender protect me from ransomware?

Defender catches many known ransomware families, but not all of them. New ransomware variants appear regularly, and there is always a window where Defender does not recognize them yet. Defender also includes ransomware protection features that monitor for suspicious file encryption, but this is not foolproof. Your best defense against ransomware is keeping backups of important files on a separate drive or cloud service.