We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Independent operating guide · current Emsisoft help, console and product documentation checked August 7, 2026

Emsisoft Scans, Schedules, Quarantine and Logs

The hard part isn't finding the Scan button. It's choosing a scope that matches the risk, proving a scheduled job actually ran, preserving a reversible quarantine decision and reading the report before the evidence disappears.

Scan scope decodedMissed jobs explainedQuarantine firstLogs preserved

Quick answer: run Malware Scan for the normal infection check, Quick Scan for active programs and traces on a trusted system, and Custom Scan for all drives, archives or another precise scope. Update before scheduled work, quarantine uncertain detections, then verify the result in Logs → View details before restoring or deleting anything.

Choose the scan by what you need to prove

Emsisoft's live help center still groups the Windows scanner into Quick, Malware and Custom Scan. Those names aren't three quality levels. They're three different scopes. The wrong choice can produce a perfectly clean report that never examined the disk, archive or inactive file you were worried about.

ScanWhat the official help says it checksUse it whenDon't assume
Quick ScanActive programs and malware tracesFast check on a trusted/fresh systemIt covered every file or drive
Malware ScanPlaces malware typically infectsRoutine infection check; best for most usersIt's a literal all-files scan
Custom ScanUser-selected folders/drives and scan objectsExtra drives, dormant files, archives, mail stores, precise repeatable jobsDefaults match your attached storage
Scheduled ScanQuick, Malware or Custom on a triggerRepeatable maintenance and unattended endpointsA schedule proves completion

The official scan-type guide calls Malware Scan the best choice for most users. That's our default too. A full-drive forensic question belongs to Custom Scan; a stubborn infection belongs to a broader incident response, not an endless loop of Quick Scans.

This operating sequence is grounded in the current Emsisoft help index and its Windows controls. Emsisoft now has a Mac agent, but the public scan articles don't establish pixel-for-pixel parity with the current Mac interface. Use the same decision logic on Mac, then verify the controls exposed by the installed build or Management Console rather than copying a Windows click path blindly.

Quick Scan: active programs and traces, not every file

Quick Scan is useful when you need a fast answer about what is active now. Emsisoft says it scans active programs and checks for malware traces and suggests it when the system is known to be clean—for example, during setup of a fresh, trustworthy Windows installation. That wording matters: it isn't the vendor's primary recommendation for a suspicious, long-used PC.

Use Quick Scan after an update when you have a low-risk reason to check running activity, or as a fast first pass before a deeper job. It can also confirm that an endpoint responds and produces a report. Don't use a clean Quick Scan to declare an unknown download, disconnected archive, secondary disk or USB collection safe because those objects may not be in scope.

When Quick Scan finds something, stop treating it as a shortcut. Preserve the path and diagnosis, quarantine rather than delete if the classification isn't certain, and run the appropriate Malware or Custom Scan after the endpoint is updated. The result is a lead, not a substitute for scope.

Malware Scan: the sensible default for most people

Malware Scan examines the locations that malware typically infects and is Emsisoft's stated best choice for most users. It's the right starting point after installation, after a credible alert, when a computer starts behaving strangely, or when you want a routine health check without manually configuring every drive and object type.

“Best for most users” doesn't mean “guaranteed to read every byte.” The mode is optimized around active infection paths. If your question is whether an old external backup contains dormant executables, whether a ZIP collection is clean or whether an Outlook data file should be scanned, build a Custom Scan that explicitly includes that target.

Let the scan finish before taking action on the diagnosis list. Emsisoft exposes pause, resume and stop controls, but an aborted run isn't a completed negative result. Record the start/finish events and open the detailed scan report; the word clean only has meaning next to a completed scope and current detection state.

Custom Scan is Emsisoft's full-system and special-scope tool

Emsisoft doesn't need a button literally named Full Scan for a full-system job to exist. Its Management Console guide says the default Custom Scan configuration represents a full-system scan including all drives. Still, “default” isn't an inventory: before starting, confirm every internal, external and removable volume you intend to test is present and selected.

The Custom Scan guide allows folders to be added and removed, memory and malware-trace checks to be toggled, and advanced file types to be included. Archive scanning covers formats such as ZIP, RAR and CAB; email-data scanning covers supported mail stores; NTFS alternate data streams expose hidden streams; PUP detection broadens the classification beyond outright malware.

Each option has a cost. Archives and mail stores can substantially increase time, and scanning a folder while leaving system-wide memory/traces enabled answers two questions at once. If you need a repeatable evidence set, save the scan settings file, name it for the scope and date, and load the same configuration later. A saved profile is only useful if drive letters and mount points haven't changed.

For a USB drive, update first, attach the drive without opening its contents and choose it explicitly. For a second-opinion cleanup workflow, our Home versus Emergency Kit guide explains when the portable scanner is the better tool. Don't run two resident antivirus products as though overlapping real-time engines were a deeper Custom Scan.

Update first, define the scope, then decide the completion action

A useful scan starts before the progress bar. Confirm that the endpoint is online, protection is current and the product is attached to the expected workspace. Record what triggered the check, which disks are connected, and whether the goal is active-infection detection, dormant-file discovery, a removable-drive check or proof of routine maintenance.

For scheduled work, Emsisoft's Windows schedule guide can check for updates before scanning when the previous update is more than 30 minutes old. Keep that enabled unless the schedule itself is triggered after an online update. An update failure should be visible in Logs and resolved before a clean scan is treated as current evidence.

Choose the completion action deliberately. The scanner settings offer Report only, Report only plus shutdown, Quarantine detections, and Quarantine detections plus shutdown. For an unfamiliar machine or business endpoint, Report only preserves human review; automatic quarantine is defensible when containment matters and you understand the operational impact. Automatic Delete isn't the normal safe path.

If BitLocker, backups, database workloads or large mail archives are involved, arrange an appropriate maintenance window. A scan isn't a backup. If restoration of a critical file would be difficult, make sure the application and data recovery path exists before starting an aggressive unattended job.

Build a schedule that can actually run

The Windows scheduling dialog separates When from What. When can be an interval within a time window, a fixed time on daily/weekly/monthly recurrence, or an event such as PC startup or online update; Emsisoft's tutorial also describes USB insertion. What selects Quick, Malware or Custom Scan and its performance, PUP and completion behavior.

SettingPractical defaultWhy it matters
EnabledOnA saved disabled tile never runs
Scan typeMalware Scan weekly; Custom for a defined full scopeMatches routine risk without pretending Quick covers disks
Update before scanningOnRefreshes detections if last update is over 30 minutes old
Run missed scan on next startupOn for laptopsHandles machines that were off at the planned time
Scan silentlyOn only when Logs are reviewedReduces disruption but hides progress
Performance impactReduced priority during work hoursTrades speed for usability
CompletionReport only or Quarantine, never blind deletionPreserves review/recovery path

A credible home baseline is a weekly Malware Scan at a time the computer is usually awake, with Update before scanning and Run missed scans enabled. Add a periodic Custom Scan if you keep external disks or archives that aren't covered by normal activity. Daily full-drive scans are usually noise and resource cost unless the threat model or policy genuinely requires them.

After saving, use Run now once. This confirms that the scope, permissions and performance settings work before you trust the next scheduled timestamp. Then inspect the resulting Scan Start, Scan Finish and detailed report in Logs. A future date on a schedule tile isn't proof that the previous run completed.

Why a scheduled scan can appear to be missing

Start with Logs, not the notification history. Emsisoft says unattended scans can run with no Windows user logged in; when no administrator is logged in, the result is saved to the scan log. With one administrator logged in, the Scanner window may appear; with multiple administrators, notifications are handled differently. A silent successful job can therefore look like “nothing happened.”

If the PC was off, Run missed scans on next startup must be enabled. Even then, Emsisoft documents a catch: the missed scan doesn't start if more than one third of the time before the next scan interval has already passed. A weekly job has more recovery room than a frequent interval job. This is expected scheduler logic, not necessarily a broken service.

SymptomCheckLikely explanation/action
No popupLogs and Scan FinishUnattended/silent result may be log-only
PC was offRun missed scansEnable it; note the one-third interval rule
Job remains future-datedEnabled and recurrenceTile may be disabled or recurrence misread
Gaming/full-screen sessionGame/Silent Mode settingSchedule may be deliberately suppressed
After-update trigger never firesUpdate events/errorsFix update connectivity or choose a clock time
Remote scan doesn't startDevice stateOffline devices can't accept an immediate scan
Custom job completes too fastSelected drives/settingsScope may no longer match drive letters

Use Run now after every material edit, then wait for the detailed report. If the job still fails, export Logs before changing multiple settings at once. One controlled change plus a timestamp is diagnosable; a dozen toggles followed by Clear Logs destroys the sequence support needs.

Control scan impact without turning the scan into theater

Emsisoft's Windows scanner describes two performance choices: highest priority for best speed and reduced priority for improved multitasking. The help text says reduced priority leaves two CPU cores for other work. The exact runtime depends on CPU, storage, cache state, file count, archive/mail options and simultaneous workload, so a universal “Emsisoft scan takes X minutes” number isn't responsible.

Use high priority inside a maintenance window when completion time matters. Use reduced priority on a working laptop or office endpoint, then accept the longer runtime. If a Custom Scan of archives and mail data is too heavy, move it to a better window rather than silently removing the objects you actually needed to inspect.

Closing the visible scanner window doesn't necessarily stop an unattended scan; Emsisoft says the job can continue and the animated tray magnifier indicates activity. Pause when you must temporarily reclaim resources. Stop only when the scope or operational impact is wrong, and label the resulting report as aborted rather than clean.

For install and platform problems, use our Emsisoft setup guide and platform-support matrix. High CPU, stalled scans and product repair have their own troubleshooting spoke so this page can stay focused on correct scan operation and evidence.

At the result screen, preserve reversibility and context

The diagnosis list isn't a command to delete everything. Emsisoft lets you select/deselect findings, invert the selection, open the file location, add selected objects to exclusions, submit a false alert, quarantine or delete. The detected-threat guide recommends Quarantine selected because it retains the only normal recovery path for a false detection.

ActionEffectUse whenMain risk
QuarantineDisables object in encrypted storageDefault for uncertain or malicious findingsCritical app/file may remain unavailable
DeletePermanently removes selected dataConfirmed malware after evidence/recovery checkNo product restore path
RestoreReturns object to original locationDetection verified falseReactivates genuine malware
False detectionSubmits item for lab reviewKnown vendor file or credible false positiveNot an instant local verdict
Add to exclusionsStops matching scan scope from flagging itemOnly after verificationCreates a blind spot
View reportOpens detailed scan logEvery consequential resultNone; preserve/export it

Capture the exact path, diagnosis, time, scan type and action before remediation. A detection inside a browser cache, email attachment, archive, another antivirus product's quarantine or synchronized folder has a different recurrence path. The name alone rarely explains why it appeared again.

If the computer holds business-critical or irreplaceable data, don't improvise. Quarantine preserves time for verification. Delete only when the item is confirmed, the operational owner agrees and the recovery/incident record is sufficient.

Quarantine is a reversible containment state, not a trash folder

Emsisoft workflow from update and scan through quarantine, re-scan, restore or delete and log export
Editorial evidence workflow. Quarantine is reversible containment; Delete is permanent; the detailed log makes the outcome explainable.

Emsisoft describes quarantine as an encrypted container that makes the object inaccessible and harmless while preserving it for analysis or a possible false-positive recovery. No file is sent merely because it's quarantined. Submission to the lab is a separate choice, which matters for privacy-sensitive files.

The Management Console guide says quarantined objects can be re-scanned after online updates, while Advanced Settings exposes Always, Ask or Never for Quarantine re-scan after updates. Re-scan all is also available manually. This catches cases where corrected signatures no longer classify a safe file as malware.

Keep enough context to understand each object: original path, device, detection, first/last seen time, related alert and whether the endpoint is still online. Quarantine isn't proof that persistence is gone. A browser sync, installer, archive or compromised process may recreate another copy at the same or a new path.

Restore only after verification; Delete only when recovery is no longer needed

Restore puts the object and its settings back at the original location. That's exactly what you want for a confirmed false detection and exactly what you don't want for genuine malware. Verify the publisher/source, digital signature, expected hash or vendor release, Emsisoft's response and surrounding incident before restoring.

Emsisoft's false-detection route can submit the quarantined item to its lab and says users can restore after the file is found safe and whitelisted. Adding an exclusion before that decision can let the same unknown object run immediately. The next Emsisoft spoke goes deeper into false positives and exclusions; this page keeps the operational boundary simple: contain, verify, then restore.

Delete is irreversible inside Emsisoft. Use it when the detection is confirmed and you no longer need the sample for support, incident evidence or recovery. If a quarantined object came from an archive or synchronized location, delete/clean the source and examine the recurrence chain too; removing one contained copy may not remove the producer.

After either decision, update, run the appropriate follow-up scan and read the report. A successful Restore shouldn't immediately trigger the same unresolved detection. A successful Delete shouldn't be followed by a new copy from startup, task scheduling, browser sync or another endpoint.

Logs turn a scan from a feeling into evidence

Emsisoft's Logs guide describes a timeline with Date, Component, Action and Details. Search finds text across the component/action/detail columns, filters narrow the component and action, Export saves a text file, and View details on a Scan entry opens the detailed report. An Update entry's View details lists updated components and size.

For a missed job, filter around the planned time and look for update, Scan Start, Scan Finish, detection, quarantine and error events. For a repeated detection, compare the original path and action with the new event. For performance complaints, record the scan type, start/finish, scope and simultaneous workload rather than reporting only that “Emsisoft was slow.”

Export before using Clear. The Clear button removes the list you need to reconstruct the sequence, and factory-default operations may also clear logs/counters. Give exported evidence a useful filename such as `device-scan-2026-08-07.txt`, store it with the detailed report and note the device/build/time zone.

A scan report isn't a universal clean certificate. It proves what that product/build and detection state reported for that scope at that time. Preserve those boundaries in support tickets and incident notes; otherwise a later reader can't distinguish Malware Scan, Quick Scan, Custom all-drives or an aborted run.

Remote scans and quarantine depend on endpoint state

The Management Console guide can start Quick, Malware and Custom scans, inspect device logs and manage quarantine. It also draws a hard state boundary: when a device is offline, policy edits can wait to synchronize, but an administrator can't start a malware scan or change quarantined objects immediately.

That makes the command path asynchronous. Confirm the correct workspace/device, its last update and online state, issue the scan, then wait for start/finish evidence. A clicked remote command isn't the same as an endpoint-completed scan. If the device stays offline, preserve the queued intent and investigate connectivity rather than issuing duplicates.

Console reports and audit logs are useful for fleet trends, but retention depends on plan and report type. Export or save a snapshot when the event has legal, operational or incident value. Don't assume a cloud dashboard will preserve raw detail forever.

Permissions also matter. The console guide says ordinary local users can run scans and decide on alerts/quarantine under Basic access, while administrators have full access. In managed environments, align local permission policy with who is allowed to restore, exclude or permanently delete a detection.

If the same malware returns, identify the producer—not just the copy

A repeated name after quarantine can mean several different things: the original action failed, the source archive wasn't cleaned, a browser or cloud sync restored it, another endpoint copied it back, or a persistence mechanism recreated the file. Compare timestamps and paths. “Same detection” at a different path is often a second source, not a failed quarantine container.

Don't restore the item to test whether it's dangerous. Don't add a broad folder exclusion to silence the alert. Update, contain the new copy, preserve both detailed reports and inspect startup, scheduled tasks, downloads, extensions, mail attachments, network shares and sync history that match the path.

If Emsisoft reports that an object can't be removed safely or automatically, use its supported malware-removal route. A difficult infection can require expert diagnostics; running the same scan ten times doesn't add ten times the confidence. Disconnect risky activity and protect credentials/data as the incident requires.

Community threads are useful for discovering confusion—especially the tendency to mix Emsisoft Emergency Kit with the installed Home product—but not for inventing a universal cure. The product's report, the exact system state and current vendor guidance remain the evidence.

A practical Emsisoft scanning baseline

For a normal Windows home PC, keep real-time protection and updates enabled, run one Malware Scan after installation, schedule a weekly Malware Scan for a time the computer is usually awake, enable Update before scanning and Run missed scans on next startup, and review Logs after the first scheduled run. Add a Custom all-drives scan when new external storage or a credible dormant-file risk enters scope.

For a managed endpoint, define the schedule in the intended policy group, select Report only or Quarantine according to response ownership, test Run now on a pilot device, confirm the endpoint reports online and export/snapshot material events. Keep restore/delete permissions narrow and document exceptions. A schedule that nobody reviews is automation without assurance.

After any detection, follow the same chain: preserve context, quarantine, update, re-scan, verify, then restore or delete and export the report. The product itself is evaluated in our current Emsisoft review; this guide deliberately owns the day-to-day scanner workflow.

Emsisoft scans, schedules, quarantine and logs FAQ

Which Emsisoft scan should I run?

Use Malware Scan for the normal infection check; Emsisoft calls it the best choice for most users. Quick Scan checks active programs and malware traces, so it's useful for a fast check on a trusted or freshly installed system. Use Custom Scan when you need additional drives, archives, email data files, NTFS alternate data streams or a saved repeatable scope.

Does Emsisoft have a full system scan?

Emsisoft doesn't label the main button Full Scan. A Custom Scan can represent a full-system job when all drives and the relevant scan objects/settings are selected; the Management Console guide says the default Custom Scan settings represent a full-system scan including all drives. Review the scope before assuming every attached disk or archive is included.

How do I schedule an Emsisoft scan?

In the Windows protection app, open Scan & Clean and Scheduled Scans, add a new scan, then define When and What. Choose an interval, fixed time or event trigger; select Quick, Malware or Custom Scan; enable Update before scanning, set performance and completion behavior, confirm Enabled, and save. The current public help doesn't establish identical local controls on Mac, so verify the actual Mac build or use its managed policy options.

Why did my scheduled Emsisoft scan not run?

First check that the schedule is enabled and inspect Logs rather than relying on a popup. A PC that was off needs Run missed scans on next startup, and Emsisoft says a missed job won't run if more than one third of the interval before the next scheduled job has already passed. Game/Silent Mode, an offline endpoint, a different trigger and a scan saved to logs without an administrator logged in can also explain the apparent miss.

Should I quarantine or delete an Emsisoft detection?

Quarantine is the safer first action because Emsisoft stores the object in an encrypted container, prevents access and preserves a recovery path. Delete is permanent. Keep the item quarantined while you verify the path, signature, source and detection with Emsisoft; restore only after a suspected false detection is cleared.

Does Emsisoft automatically re-scan quarantine?

Emsisoft provides a Quarantine re-scan after updates setting with Always, Ask and Never choices, and its Management Console guide says quarantined objects can be re-scanned after online updates. You can also use Re-scan all manually. A changed detection result is evidence to review, not permission to restore blindly.

Where are Emsisoft scan reports?

Open Logs and filter for Scanner/Scan events. The event list exposes Date, Component, Action and Details; View details on the relevant scan opens the detailed report. Export the log as a text file before clearing it, and preserve any report or console snapshot needed for support or an incident record.

Can an Emsisoft scan run when nobody is logged in?

Yes. Emsisoft says scheduled scans can run unattended even when no Windows user is logged on. If no administrator is logged in, the result is saved to the scan log rather than presented in an interactive scan window, which is why Logs is the first place to verify completion.

Can I scan a USB drive with Emsisoft?

Yes. Use Custom Scan and include the removable drive, or create an event-based scheduled scan after a USB storage device is inserted if that trigger is available in the current Windows build. Update first, avoid opening files before the check completes, and confirm the drive letter and scope because removable-drive letters can change.

What if Emsisoft finds the same malware again after quarantine?

Check whether the log shows the same original path, a new copy, a browser sync/download, an archive or a persistence mechanism recreating the file. Don't repeatedly restore it or declare the PC clean because one scan completed. Preserve the report, disconnect risky activity if necessary and use Emsisoft's supported malware-removal route when automatic quarantine can't finish the job.

Bottom line: scope, reversibility and evidence

Malware Scan is the right default for most Emsisoft users. Quick Scan answers a narrower active-program question, while Custom Scan owns full-drive and advanced-object work. A reliable schedule updates first, survives missed laptop windows, exposes completion in Logs and never converts silence into proof.

When something is found, quarantine buys time and preserves recovery; Delete removes that option. Re-scan after updates, restore only a verified false detection, and export the event plus detailed report before clearing anything. That six-step discipline makes the result useful to the person at the keyboard, an administrator and support.