Top  
Newsletter 03/27/2022 Back to Contents
A printable PDF of this article is available here.

Windows Defender's Secret (I think) Weapon: The Offline Scan

When Windows Defender first came available, the application was a poorly received free download from Microsoft.  This was a few years before Windows Defender came integrated into Windows.  There was for me, however, one unique feature of Windows Defender: The Offline Scan.

When the Offline Scan was first available one had to download a file, and have that file saved to a bootable CD ort DVD.  The process was clumsy and slow; but did, in fact, work.  It scanned the computer BEFORE WINDOWS STARTED.  The Offline Scan is a work around against a simple fact of malware scanning.  A file in use cannot be scanned.  So if the malware has fooled Windows into thinking the malware file(s) are need for Windows, then those system files will not be scanned.  There are also viruses that startup before Windows.  These malware files are called root kits.  Scanning before Windows might allow for some detections that otherwise would remain as FUD.

To keep FUD in check, please backup your data files before you begin here.

To access the Offline Scan, first start Windows Security by double clicking the Windows Security in the Notification Area by the clock.

 

Next Click Virus & Threat Protection.

Next, click Scan Options from the Virus & Threat Protection Screen. 

 

Select Windows Defender Offline scan, and then click the Scan now button.

 

After the scan is complete, and your PC restarts, you might want to revisit the Dispatch post on Protection History.

The Protection History list will show what Windows Defender found in previous scans and what actions it took.  Items you might see listed:
PUPS (Potentially Unwanted Programs)  Usually adware but can be hostile

Trojan a type of Virus that allows other attackers into your computer*

Worm a type virus that self replicates*

Or might just say Virus.  * notes consider reformatting, at least.

Back to Top previous post  next post