Malwarebytes Scanner
The scanner is the core of the Windows application. Understanding which scan checks what saves a lot of time — most people run the slowest scan when a targeted one would answer the question in three minutes.
Scan types on Windows
| Scan | What it checks | Typical duration |
|---|---|---|
| Threat scan | Memory, startup items, registry, and the folders malware normally uses | 3–15 minutes |
| Custom scan | Folders or drives you choose, with optional rootkit checking | Depends on selection |
| Hyper scan | Memory and startup objects only (paid tier) | Under a minute |
The threat scan is the sensible default. A full custom scan over every file on a large drive is mostly redundant, because malware that is inert inside an archive cannot execute until it is extracted — and at that point the resident protection or the next threat scan sees it.
Turning on rootkit scanning
Rootkit checking is off by default because it lengthens scans. If a machine behaves strangely after cleanup — detections that reappear, drivers you do not recognize, network traffic at idle — enable it in Settings → Scan and Detections and run a threat scan again.
Reading the results
Results list each detection with its type and location. Names beginning with PUP or PUM indicate potentially unwanted programs and modifications rather than outright malware; some of them are toolbars or bundled utilities you may have installed deliberately. Everything else should normally be quarantined.
- Trojan / Backdoor: quarantine immediately and reboot
- Adware: quarantine, then reset browser settings
- PUP: review the file path before deciding
- Ransom: quarantine, disconnect the PC from the network, and check for encrypted files
Quarantine and restore
Quarantined items are moved into an encrypted store where they cannot execute. They stay recoverable, which matters when a detection is a false positive — a developer tool or a niche utility flagged by heuristics. Review quarantine before you delete it permanently, then empty it once the machine has been stable for a few days. The virus removal guide covers what to do when detections keep coming back.
Frequently asked questions
How long does a Malwarebytes scan take?
A threat scan usually finishes in three to fifteen minutes. Custom scans across a full drive can take an hour or more depending on file count and drive speed.
Should I scan in Safe Mode?
Only when a normal scan cannot remove something or the malware blocks the application from starting. Safe Mode with Networking prevents most persistence mechanisms from loading.
Why does the same detection come back after a reboot?
Something is re-creating it — usually a scheduled task, a service, or a second copy that the scan did not reach. Enable rootkit scanning and scan again from Safe Mode.
Malware-Bytes.net is an independent information resource about malware protection for Windows. We are not Malwarebytes, and this site is not the official Malwarebytes website or support channel. Malwarebytes is a trademark of Malwarebytes Inc.