Software tower · floor

How to remove malware from computer when a scan says clean

How to remove malware from computer is a question with a crowded first page and a missing answer. The crowded part is which scanner to run. The missing part is the one people actually come back for: the scan finished, it found nothing, and the machine is still wrong.

Microsoft publishes four separate reasons that happens. Each has a fix, and none of them is running the scan again.

It is on the allowed list

cause 1

“The Allowed threats page shows a list of items that Windows Security has identified as threats, but that you have chosen to allow. Windows Security won’t take any actions against threats you’ve allowed.

Something was allowed once, and the scan has been honouring that ever since.

It sits in an exclusion

cause 2

Exclusions only apply to real-time scanning with Microsoft Defender Antivirus. Any scheduled scans with Microsoft Defender Antivirus, or third-party antimalware products, might still scan them.”

Microsoft’s own advice on writing one: “use the full path and file name … This makes it less likely that malware could use the same filename as a trusted and excluded process.”

There is no room to remove it

cause 3

“Microsoft Defender Antivirus requires disk space to remove and quarantine malware files. It might be prevented from completely removing a threat if there isn’t enough available space on your PC.”

A full disk is not a detection problem. It is a removal problem, and it is published.

Something reinstalls it

cause 4

“In some cases, redetection of the same malware is due to an undetected malware component constantly, quietly, reinstalling the detected malware. The malware is typically reinstalled, and redetected, right after you restart your PC.

The tell is the timing: it comes back at the restart, every time.

None of those four is a failure of detection, and that is why repeating the scan does not help. Two of them are settings you or something else changed, one is a disk that is too full to quarantine anything, and one is a second piece of malware the scanner never saw. Checking the allowed list and the exclusion list takes two minutes and rules out half the possibilities before you spend an hour on anything else.

The fourth has a signature you can recognise without any tool: if the same thing is found again immediately after every restart, Microsoft’s published explanation is a component that is still there and still reinstalling it. That is the point at which an offline scan stops being optional.

Microsoft ranks its own tools, and the first page shows the weaker one
On the scanning page: “For the most complete scan, run Microsoft Defender Offline.” What it does: “Microsoft Defender Offline will load and perform a quick scan of your PC in the Windows Recovery Environment” — and, from the Windows Security page, “this happens after a restart, without loading Windows”.
On the Malicious Software Removal Tool, which is the one Microsoft page ranking for this question:
  • It is strictly a post-infection removal tool.
  • “The tool removes only specific prevalent malicious software. Specific prevalent malicious software is a small subset of all the malicious software that exists today.”
  • It does not remove spyware.
  • “This scan can take several hours … However, mapped network drives are not scanned.”
  • “If the tool is more than 215 days (7 months) out of date, the tool displays a dialog box that recommends that you download the latest version.”

Read those together and the practical instruction writes itself. The tool Google shows you is the one Microsoft describes as narrow; the one Microsoft calls most complete is already on the machine and is not on that first page at all. Its path is Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan. It runs before Windows loads, which is the point: nothing that hides inside a running Windows gets to hide from it.

It is worth being exact about why that ranking matters here rather than treating it as trivia. The Malicious Software Removal Tool is genuinely useful and Microsoft genuinely publishes it — but Microsoft also writes, in its own words, that it handles “a small subset” of what exists, that it “does not remove spyware”, and that it is “strictly a post-infection removal tool”. A reader who arrives from that page and runs it can come away believing the machine has been cleared by the manufacturer, when the manufacturer has described the tool’s limits three times on the page they were reading.

The Mac side of this question has a shorter answer, and the shortness is itself the finding.

On a Mac the action Apple describes is automatic, and its trigger is opening the app: “If macOS detects known malware, your Mac notifies you that the app can’t be opened and moves it to the Trash.”

Two things follow from that sentence, and both matter. First, the trigger is an attempt to open something, not a scan you can start — there is no user-run sweep being described here. Second, moved to the Trash is still on the disk until the Trash is emptied. Apple also documents the neighbouring case, where the verdict is harsher: “If macOS detects that software has malicious content or its authorization has been revoked for any reason, your Mac notifies you that the app will damage your computer.” Separately, Apple does publish a removal tool a person can download — but it targets one 2012 malware family and states its requirement as “OS X Lion without Java installed”, which is not an answer for a Mac in 2026.

Two more published details worth knowing before you change anything. Adding another antivirus is not adding a second layer: “If you install a compatible non-Microsoft antivirus program Microsoft Defender antivirus will automatically turn itself off.” It is a swap, not a reinforcement. And if you go looking for the switches and cannot move them, that is by design: “If tamper protection is turned on, you’ll need to turn it off before you can turn Real-time protection off.” On recovering what was damaged, Microsoft’s instruction is restoration rather than repair: “whenever possible, restore your files from backups generated before the infection and stored in an external location” — and about the removal tool itself, “some data loss is possible during this process”.

So the order that follows from the documentation, rather than from any product: check the allowed list, check the exclusions, check free disk space, and note whether the thing returns at restart. Then run the offline scan — the one Microsoft calls most complete, from the security app already installed. Then, if files were damaged, restore rather than repair.

A note on where this question gets answered. The first page of results is three antivirus companies, a community thread, a federal consumer agency, a university security office, and one Microsoft page — the one Microsoft itself describes as narrow. None of the results read for this page contains the four published reasons a clean scan can be wrong, which is the question that brings people back a second time.

What this page will not do is tell you whether your machine is infected. Everything above is a set of published checks and their sources; the verdict is what the checks return, not something a page can assert from here.

It will not rank the antivirus products, including the free ones. That takes controlled testing against live samples, this site has not done it, and the organisations that do it publish their method.

And it will not tell you a reinstall is always the answer. Microsoft documents removal, quarantine and restoration from backup, and none of its pages read here treats wiping the machine as the first move.

Where to start

Three ways in. If a scan has already come back clean, take the first.

“It found nothing and something is still wrong.”
Four published reasons — it is on the allowed list
“It keeps coming back after every restart.”
That has a name — something reinstalls it
“Which scan should I actually run?”
Microsoft ranks its own — microsoft ranks its own tools

Four blind spots

An allowed threat, an exclusion, a disk with no room to quarantine, and an undetected component that reinstalls. All four are published, all four survive a repeated scan.

Which scan

Microsoft names the most complete scan on one page and publishes the narrow tool on another. The first page of results shows the second one.

On a Mac

What Apple describes is automatic, triggered by opening an app, and ends in the Trash rather than in a wipe. There is no user-run sweep in these pages.

What this tower will not do

It will not rank antivirus products. That needs controlled testing against live samples, and this site has not done it.

It will not tell you to install a second scanner alongside Windows Security. Microsoft states that installing another one turns its own off, so that is a swap and should be a decision.

It will not treat wiping the machine as step one. Microsoft documents removal, quarantine and restoration from backup, in that order, and skipping to a reinstall loses data the documentation does not ask you to lose.

And it carries no affiliate links, which in the security category means declining the highest commissions on this island. What holds instead is simple: the four causes, the tool ranking and the Mac behaviour above are all quoted from Microsoft or Apple directly, and no product on this page has been tested by anyone here.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 23 August 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.