Free Malware Scanners for Windows That Find Things
Quick answer: Keep one resident antivirus running all the time, and use a second on-demand scanner only when you suspect an infection. Microsoft Defender Offline Scan is the most underused tool on Windows for exactly this and it is already installed. Never install two real-time scanners at once.
The question behind "what is the best free malware scanner" is usually one of two very different questions: what should protect me continuously, or what should I run right now because something feels wrong. They have different answers.
Resident versus on-demand, and why it matters
Resident protection runs constantly, inspecting files as they are opened and processes as they start. You need exactly one. Two resident scanners fight over file locks, flag each other's quarantine folders, and produce a machine that is slower and less reliable than either alone.
On-demand scanners only run when you launch them. They do not hook into the system continuously, so you can safely keep several installed as second opinions.
This distinction resolves the most common mistake I see: someone worried about a possible infection installs a second full antivirus suite, and now has two resident engines and a new problem on top of the original one.
For which resident scanner to run, our Defender comparison covers the cases where the built-in one is sufficient and where paying buys something real.
Start with the scanner you already have
Microsoft Defender Offline Scan is the strongest free option for a suspected infection and almost nobody uses it.
It reboots the machine into a minimal Windows environment and scans before the operating system fully loads. That matters because rootkits and the more capable info-stealers actively hide from scanners running inside a live Windows session. Scanning from outside that session removes the advantage.
Windows Security, Virus and threat protection, Scan options, then Microsoft Defender Antivirus (offline scan), then Scan now. It takes about fifteen minutes and the machine restarts.
If you only do one thing from this article when you suspect an infection, do this.
Second-opinion scanners worth having
These are on-demand tools, safe to run alongside a resident antivirus.
Malwarebytes Free. The default recommendation for a reason. Its free tier is on-demand only, which is exactly what you want as a second opinion, and it catches adware and potentially unwanted programs that traditional antivirus deliberately ignores. Decline the premium trial at install if you want it staying on-demand.
ESET Online Scanner. Runs from a small downloadable stub, uses a well-regarded engine, and leaves nothing resident behind. Good when you want a one-off opinion without adding software to the machine permanently.
Kaspersky Virus Removal Tool. Technically strong scanner. Be aware of the geopolitical context and the US government advisories regarding Kaspersky products before installing it on a work machine. On a personal machine it is a competent tool and the choice is yours to make knowingly.
Sophos Scan and Clean. Aimed squarely at the case where malware is actively blocking your usual antivirus from running. Portable and no installation required.
A note on the category generally: several products marketed as free malware scanners are themselves the potentially unwanted software they claim to find. Download from the vendor's own domain, never from an aggregator, and be sceptical of anything you first heard about via a pop-up telling you that you are infected. Our PC optimization guide covers the same problem in the tune-up category, where the ratio of legitimate tools to junk is considerably worse.
How to actually scan a machine you think is infected
Order matters here.
1. Disconnect from the network if you suspect data theft or ransomware. Unplug the ethernet, turn off wifi. This stops exfiltration and stops ransomware reaching network shares.
2. Do not reboot yet if you are seeing ransomware behaviour specifically. Some families complete encryption on restart.
3. Run Defender Offline Scan. As above. This is your best single shot.
4. Run one second-opinion on-demand scanner after the offline scan completes.
5. Change your passwords from a different device. This is the step people skip and it is frequently the most important one. If an info-stealer was resident, it has already taken your browser-saved credentials and session cookies, and cleaning the machine does not un-steal them. Our four-hour response plan for a leaked password is the sequence to work through, and the order matters more than the speed.
6. Check what starts with Windows. Task Manager's Startup tab, and Task Scheduler. Persistence is usually established in one of those two.
When to stop scanning and reinstall
There is a point where continuing to clean is the wrong call, and recognising it early saves a lot of time.
Reinstall Windows if: the machine had a genuine rootkit, or ransomware executed, or scans keep finding new items after apparently successful cleanings, or you use the machine for online banking or work and cannot tolerate residual doubt.
Modern Windows makes this far less painful than it used to be. Settings, System, Recovery, Reset this PC, and choose Remove everything with the cloud download option so the installation media is fresh rather than the possibly-tampered local image.
The honest framing: a scanner tells you what it recognised. It cannot tell you that nothing else is present. For a machine that mattered, reinstalling converts an unknown into a known.
What free scanners will not do
They will not recover encrypted files. Removing ransomware stops further damage; it does not decrypt what is already gone. Only backups do that.
They will not tell you what was taken. No consumer scanner reconstructs exfiltration.
They will not protect you in real time on a free tier, in most cases. That is the paid upsell, and it is also the thing Defender already does at no cost.
The bottom line
One resident scanner, always. Defender is a perfectly respectable choice for that role. Add on-demand second opinions only when something feels wrong, run the offline scan first because it is both the most capable option and already installed, and change your passwords from a clean device afterwards whatever the scan says.
Frequently Asked Questions
Can I run two antivirus programs at once?
Not two resident ones. They conflict over file access, quarantine each other's files and degrade performance for no security gain. You can safely combine one resident antivirus with as many on-demand scanners as you like, because on-demand tools only run when launched.
Is Malwarebytes free good enough?
As a second-opinion on-demand scanner, yes, and it is particularly good at adware and potentially unwanted programs that mainstream antivirus tolerates. It is not a replacement for resident protection on the free tier, since free Malwarebytes does not scan in real time. Pair it with Defender rather than treating it as a substitute.
What is the difference between a virus scan and an offline scan?
A normal scan runs inside your live Windows session, where sophisticated malware can hide from it or interfere with it. An offline scan reboots into a minimal environment and scans before Windows fully starts, which strips away that ability to hide. Use offline scanning whenever you genuinely suspect infection rather than routinely.
My antivirus says the machine is clean but it still behaves oddly. Now what?
Run an offline scan and one different-vendor on-demand scanner, since engines have different blind spots. If both come back clean, consider non-malware explanations: failing storage, thermal throttling, or a bad driver update all produce symptoms people read as infection. Persistent oddness after clean scans on an important machine is a reasonable trigger for a reinstall.
Do I need a malware scanner if I have Windows Defender?
Not continuously. Defender is a credible resident antivirus and running a second resident engine alongside it is counterproductive. Keeping one on-demand scanner available for the day something feels wrong is sensible, and Defender's own offline scan already covers the hardest case.