We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Intego field guide · checked August 7, 2026

Intego VirusBarrier Scans, Schedules and Quarantine

A Full Scan isn't always the best scan, a calendar entry doesn't prove the Mac was awake, and quarantine isn't deletion. This guide separates ONE, X9 and the free Scanner so every choice—and every follow-up—matches the product actually installed.

ONE/X9/Scanner separatedNo invented scan timesExternal-drive limits mappedQuarantine action ≠ proof

Quick answer: Run one Full Scan after installing paid VirusBarrier because real-time protection doesn't retroactively inspect every existing file. After that, choose Quick for routine high-risk locations and Custom or targeted scanning for a download, folder or mounted drive. ONE schedules Full or Quick daily, weekly or monthly; X9 must be awake and logged in when its schedule arrives. A detection isn't finished when it enters quarantine: review the exact action for ONE, X9 or the free Scanner, then prove repair or removal with a follow-up scan and history or log.

Start with the product matrix, not a generic VirusBarrier tutorial

Intego currently has three operational models. ONE puts antivirus controls into the unified subscription app; X9 keeps the traditional VirusBarrier application and its separate logs/preferences; the free App Store Scanner is on-demand and sandboxed. They share detection technology and familiar names, but not identical scan buttons, schedules or quarantine actions.

GenerationProtection and scan modelScheduleQuarantine actions documented now
Intego ONEReal-time plus Full, Quick, Custom and ONE ScanFull or Quick; daily, weekly or monthlyRepair, Ignore, Trust
VirusBarrier X9Real-time plus Full, Quick and targeted file/folder/disk/volume scansBasic Daily/Weekly; Advanced adds monthly, targets and multiple jobsRepair, Delete, Trust
Free VirusBarrier ScannerNo real-time; manual scans and current-user-accessible locationsDaily Maximum, Essential or DisabledRestore & Repair, Delete, Done; Option reveals Restore without Repair

If the installed generation is unclear, identify it before acting on a detection. Our ONE versus X9 guide maps the suite transition, while the free Scanner comparison explains why App Store scanning isn't background protection. Product identity is the first safety control because an X9 button name can mean something the ONE interface doesn't even expose.

Choose the smallest scan that answers the question

“Run Full Scan” is easy advice, but it can hide useful evidence. If one downloaded installer is suspicious, a targeted scan answers that question faster and preserves the path. If the scanner just gained Full Disk Access or has never inspected the existing Mac, Full is the right baseline. Quick is the routine health check between those cases.

QuestionBest starting scanWhyEscalate when
New paid installation or restored MacFullInspects files that real-time protection never saw arriveAny detection or incomplete location appears
Routine check after current updatesQuickFocuses on vendor-defined high-risk system areasSymptoms or detections point outside that scope
One download, app, folder or mounted driveCustom/targetedCreates a clean question, path and resultThe item executed or related files appear elsewhere
Detection may have persisted or spreadFull after immediate containmentChecks beyond the original pathThe same item returns after repair/restart
Full appears frozenQuick, then controlled targetsSeparates engine failure from archive/device scopeEven Quick can't progress or complete

Don't compare scan names by elapsed time alone. A current Quick scope can change with malware patterns and definition updates, and a Full run may add mounted volumes that were absent yesterday. Record scan type, selected locations, definition timestamp and mounted storage so two runs are actually comparable.

Intego ONE: Full, Quick, Custom and ONE Scan have distinct jobs

Intego's current ONE Antivirus guide defines Full Scan as the startup disk plus all locally mounted disks. Quick Scan checks key system areas such as Downloads and temporary folders. Custom Scan targets an application, file or folder from the dashboard, drag-and-drop accessory or Finder's “Scan for Malware with Intego ONE” action.

ONE Scan is the quick-start route from Home or the tray. The guide describes a result such as Actively Protected or Threats Detected; it doesn't define the feature as merely a scan without a schedule. Use it for a quick immediate check, but choose the named Full or Custom path when you need documented scope.

Real-Time Protection monitors content as it is written or opened. That's essential for new activity, yet it can't prove every file that existed before installation was examined. A first Full Scan closes that evidence gap; later Custom scans are better for a newly attached drive or single questionable installer because the resulting history is easier to interpret.

VirusBarrier X9: separate real-time, Quick, Full and targeted scanning

The current X9 scanning guide says Real-Time Scanner checks files when they're created, copied, modified or saved. It doesn't retrospectively scan every old file, which is why Intego recommends a Full Scan after installation and after definition updates.

X9 can scan a file, folder, disk or volume on demand. Quick Scan appears when the whole computer is selected, and Intego can change the locations behind it as threat patterns change. That makes Quick useful but not a fixed miniature Full Scan. If a support case depends on one path, select that path and preserve the result rather than guessing what Quick covered that day.

A Full run can continue without a visible Task Manager window, depending on preferences. Use the X9 log to distinguish “window hidden” from “scan stopped.” The log also captures start, cancellation, completion, detections, repairs and changes to quarantine or Trusted Files, so it's stronger evidence than a progress window screenshot.

The free Scanner's Maximum mode still has a user-access boundary

The free Scanner manual is explicit: there's no real-time protection. You can scan a selected item by drag-and-drop or menu, and configure a daily Maximum or Essential scan, but the App Store sandbox and current user's permissions determine which locations the app can inspect.

Maximum means all files available to the current user, not an administrator-grade sweep of every account. Essential focuses on common infection locations. Grant each intended location deliberately and read any access error; a “clean” result can't vouch for a folder the scanner never opened.

Low Priority makes the Mac more responsive by allowing the scan to take longer. That can be a sensible choice for a periodic check, but it isn't a detection-quality setting and shouldn't be used to compare the free utility's elapsed time with paid ONE or X9. The existing free-versus-paid guide covers the upgrade decision; here the important boundary is that on-demand evidence expires as new files arrive.

Run the first baseline scan with a reproducible scope

Before the first Full Scan, finish updates, confirm the product has the necessary macOS permissions, connect only the drives you intend to include and keep a laptop on power. Our macOS compatibility and Full Disk Access guide provides the permission proof; the installation guide owns authenticated setup and activation.

Record the application and definition versions, mounted volumes, archive/Windows-malware preferences and start time. Start Full, confirm the scanned-file counter advances, and let the Mac remain logged in and awake. Normal variation is expected; a fixed “it should finish in two hours” promise would ignore the file set, storage and scan options that actually control the work.

At completion, save the history or log row: scan type, date/time, duration, location/file count, detection count and final state. If a mounted drive or protected folder was skipped, the run isn't a universal clean bill. Resolve the missing scope or document it before using the baseline for later comparisons.

Schedule ONE around a real awake window

ONE can schedule Full or Quick scans daily, weekly or monthly. In the Antivirus schedule area, create the job, choose the scan type, cadence, day where relevant and exact time, then check the displayed next run. A frequent Quick plus a less frequent Full is usually more practical than overlapping long Full jobs, but the right cadence depends on how often the Mac is used and what enters it.

Choose a time when the Mac is normally on, logged in and not about to close its lid. A desktop can use a quiet working period; a laptop often needs an evening slot while connected to power. The schedule is a plan, not proof. After the first trigger, open Antivirus History and confirm a Scheduled event actually started and completed.

Edit or remove obsolete jobs instead of stacking replacements. If the user travels across time zones, changes sleep habits or disconnects the external drive a Full job was expected to cover, recheck the next-run time and scope. A clean schedule design has one accountable purpose per job and one history entry that proves it happened.

X9 scheduled scans don't wake a sleeping Mac

Intego's scheduled-scan support note says VirusBarrier doesn't wake the computer. The Mac must be powered on and awake. Don't rely on an old tutorial's Energy Saver screen or install an unrelated keep-awake utility just to make a vague schedule work; set a window that matches the current Mac's ordinary use and verify it in the log.

Basic X9 scheduling offers Daily or Weekly. The X9 manual's Advanced mode adds monthly jobs, specific files or folders, multiple schedules and a Computer target that covers folders for all users. That flexibility also creates overlap risk: two broad jobs can contend for storage and leave the operator unsure which result belongs to which scope.

Name each job by purpose in your own record—weekly computer baseline, daily Downloads, monthly external archive—and keep the Mac awake for the first run. Task Manager may be configured not to appear, so a missing window isn't failure. The decisive evidence is a completed scheduled entry in the X9 log with the expected target and time.

External drives need three separate rules: mounted data, Time Machine and NTFS

ONE Full Scan includes locally mounted disks, which can turn an ordinary baseline into a much larger job. When the question is “is this external drive clean?”, a Custom scan of that drive creates clearer evidence and avoids silently adding every other mounted device. Confirm the disk remains mounted and readable through completion.

VirusBarrier X9 has two documented exceptions. Since version 10.9.62, Time Machine backup volumes are intentionally hidden because Apple's permissions prevent dependable repair or deletion inside backups and older scans returned incomplete. An HFS+ disk may still expose ordinary data outside Backups.backupdb; a missing backup volume isn't proof the drive disconnected or X9 broke.

X9 also intentionally ignores Boot Camp and NTFS volumes due Intego's documented macOS NTFS-driver crash risk. Don't force the Mac scanner into the Windows partition. Boot Windows and scan that volume with a current Windows security product. These two exceptions are X9-specific; we don't transfer them to ONE or the free Scanner without matching current evidence.

Archives and Windows-malware detection change work, not certainty

Intego's Unarchiving explanation describes a decompress-to-temporary, scan and recompress cycle. Seeing “Unarchiving” for a while is therefore not automatically a freeze. X9 documents a default 60-second archive timeout; files extracted before that timeout are still scanned, so the result needs nuance rather than a blanket “the archive was clean.”

The vendor's scan-duration guide names file count/type, archives, Windows-malware detection, external volumes and Low Priority as variables. No responsible guide can turn those into one deadline. Watch the current path or file counter, storage activity and whether a controlled Quick or target scan can complete.

Temporarily disabling archive scanning or Windows-malware detection can isolate the scope of a stuck X9 run. It also reduces coverage. Windows malware may not execute on macOS, but the Mac can store and pass it to a Windows user. Record every diagnostic switch, restore the intended setting, and run a focused follow-up on the suspect archive or folder instead of treating the faster run as equivalent evidence.

A completed history or log entry is the scan receipt

ONE Antivirus History records file count, date/time, duration, scan type or location and identified threats, with search and filters for Full, Quick, Custom and Scheduled activity. That's the place to verify the first scheduled run, distinguish a canceled scan from a completed one and connect a detection to its actual scope.

X9's log is broader: it records scan starts, cancellations and finishes, results, real-time state, detections, corrupted files, repair events, quarantine or trust changes and definition updates. A grey action or empty quarantine list makes more sense when the log shows automatic quarantine followed by repair. Export or screenshot only the relevant rows and redact private paths before sending them elsewhere.

Evidence needs a chain: current definitions before the run, known scope, a completed final state and a follow-up after any action. “The alert disappeared” is weak because an item may have been ignored, trusted, moved or hidden by a filter. A clean targeted scan plus a clean wider scan when warranted, backed by history, supports the conclusion.

Quarantine is isolation while you decide—not the final verdict

Both current ONE and X9 documentation say detections can be quarantined automatically. The point is to separate the item from normal use while preserving a decision path. Quarantine doesn't by itself mean the file was deleted, repaired, harmless or proven malicious; those conclusions require the action and follow-up evidence.

Don't panic-delete a document or trust an installer on name recognition alone. Record the detection name, original path, publisher/signature context, scan type and time. If the item is private, licensed or business-sensitive, don't upload it to a public multi-engine service simply because a forum suggested it. The next dedicated false-positive spoke will cover vendor submission and Trusted Files in depth.

Community discussions commonly blur quarantine and deletion, but current vendor manuals are the operational source. They also show why generic advice is dangerous: ONE's Ignore doesn't change the file, while X9's Delete does; Trust creates an exclusion, while Repair attempts to restore a safe state.

Repair, Delete, Ignore and Trust: use the right action matrix

ActionWhere documentedWhat it doesSafe use
RepairONE and X9; free uses Restore & RepairAttempts a safe state; may remove malicious content/file/app depending on detectionDefault resolution for a confirmed or plausible threat when offered
DeleteX9 and free ScannerRemoves the selected quarantined itemAfter verifying the path and that no required clean data must be recovered
IgnoreONERemoves the entry from the quarantine list without changing the fileNot a safe shortcut; use only with a separately justified disposition
Trust / Safe ListONE and X9Declares the item safe and excludes it from future scansOnly after a false-positive investigation; remove exclusion to rescan
Restore without RepairFree Scanner via Option keyReturns the file and adds it to Trusted FilesOnly for a verified false positive, never to silence an unknown alert

ONE's current guide notes that Repair can delete a malicious file, uninstall a problematic application or remove malicious Office macros. That's broader than “clean this document,” so close active work and verify what disappeared afterward. Ignore is particularly easy to misunderstand: removing the row isn't remediation.

For X9, a grey Quarantine button can mean the item is already isolated. Open the panel, review the file and use Repair or Delete. Bulk Repair All or Delete All exists, but item-by-item review is safer when personal documents, business paths or multiple detection classes are mixed together.

Handle a VirusBarrier detection safely in ten steps

Intego detection workflow from quarantine and review to repair or delete, followed by verification, with Trust marked as an exclusion
Editorial action map, not a literal ONE or X9 screen. Trust is deliberately shown as an exclusion branch rather than the normal remediation route.
  1. Freeze the evidence. Leave the detected item in quarantine while you record the product generation, detection name, original path, scan type, date and exact available actions.
  2. Confirm updates and scope. Verify the Intego application and definitions are current and identify whether the result came from real-time, Full, Quick, Custom or a scheduled scan.
  3. Review the file context. Check whether the path and publisher fit an intentional installation, whether the item is private or business-sensitive, and whether more than one file was detected.
  4. Keep Trust off by default. Don't use Trust, Safe List or Restore without Repair merely to make the alert disappear; these routes create an exclusion or return the file.
  5. Choose the generation-specific action. In ONE, use Repair for a detected threat; in X9 choose Repair or Delete after review; in the free Scanner use Restore & Repair or Delete as appropriate.
  6. Restart when the action doesn't settle. If the item remains or the control is unavailable, restart the Mac before repeating destructive actions so pending removal can complete.
  7. Run a focused follow-up. Scan the original location and any related installer, archive, mounted volume or application bundle to verify that the immediate source is no longer detected.
  8. Run the necessary wider scan. Use Full Scan when the detection could have executed, persisted or spread beyond one path; keep the Mac awake and external scope intentional.
  9. Read history or logs. Confirm the follow-up completed, the detection count is zero or explained, and the repair, delete or quarantine event appears with the expected timestamp.
  10. Escalate persistent or uncertain cases. Send Intego support a redacted evidence packet when the same detection returns, an item can't be repaired or deleted, or a legitimate file may be a false positive.

Intego's current X9 repair article recommends restart followed by Full Scan when an item can't be removed or repaired. If it no longer appears after that sequence, the vendor treats the delayed action as successful; we still keep the scan/log receipt because an empty panel alone doesn't explain whether the file was repaired, deleted or excluded.

If the same detection returns, don't alternate Trust, Delete and Repair at random. Preserve the new timestamp/path, check whether an installer, sync service, browser download or mounted archive is recreating the item, and escalate with a redacted packet. Reappearance after a verified action is new evidence about the source, not a reason to hide the alert.

When a scan stalls or ends incomplete, isolate one variable at a time

The current X9 stuck-scan guide starts with environment and scope: keep the Mac logged in and awake, compare Quick with Full, disconnect external devices, and test archive or Windows-malware settings. Those are diagnostic branches, not permanent performance recommendations.

ObservationControlled testWhat it suggestsRequired follow-up
Quick completes; Full stops near one pathTarget that folder/file separatelyContent or permission-specific scopeInvestigate path; don't blindly exclude it
Full completes after external disks disconnectReconnect one drive and target itDevice, format or content issueCheck disk health/readability and separate scan evidence
Run advances with archive scan offTarget the named archive/extracted contentsDecompression, size or archive corruptionRestore coverage and inspect source safely
Run advances with Windows detection offTarget cross-platform files after re-enablingWindows-signature workload or problem fileRestore coverage before sharing with Windows users
Even Quick can't completeUpdate/restart; check competing security toolsEngine, resource or software conflictPreserve logs; use supported reinstall or vendor support

ONE's current scanner troubleshooting also names resource exhaustion, multiple security/cleaner products and hardware or overheating problems. Update ONE, restart and remove competing real-time overlap before assuming the longest file is malware. If one location consistently freezes, an exclusion may help prove where the problem lives, but it doesn't prove that location is safe; inspect it separately and remove the diagnostic exclusion.

Use EICAR for a safe reaction test—never live malware

Intego publishes an official VirusBarrier EICAR test. The EICAR organization describes its test file as a safe way to observe antivirus behavior without using real malware, and Intego says VirusBarrier detects it as Multi/Eicar. Follow those official paths rather than copying strings from an anonymous post.

A useful test proves the entire local chain: the current product detects the test, creates the expected alert/quarantine event, exposes the correct generation-specific action, and records the event in history or log. Remove the test through the normal product action and confirm the follow-up. It doesn't measure real-world detection breadth or replace independent lab results in our full Intego review.

Never download live malware to “see what happens,” disable macOS platform security for a test or use a confidential file as a public upload sample. Safe verification is repeatable and disposable; it shouldn't create a second incident while diagnosing the first.

Intego VirusBarrier scans and quarantine FAQ

Which Intego scan should I run first?

After a new paid installation, run Full Scan once because real-time protection doesn't retrospectively inspect every old file. Use Quick Scan for routine checks of high-risk areas and Custom or targeted scans for one download, folder or mounted drive. The free Scanner is on-demand only, so its periodic scan is the protection event rather than a supplement to real-time scanning.

What is ONE Scan in Intego ONE?

ONE Scan is the quick-start scan available from the ONE Home view or tray. The current vendor guide treats it as a fast way to launch an antivirus check and reports either an actively protected or threats-detected result. It shouldn't be redefined as simply a scan without a schedule.

Does Intego Full Scan check external drives?

Intego ONE says Full Scan covers the startup disk and locally mounted disks. VirusBarrier X9 can scan selected disks and volumes, but current X9 intentionally omits Time Machine backup volumes and Boot Camp or NTFS volumes under documented conditions. Select one external drive with Custom or targeted scanning when you need clean scope evidence.

Will a scheduled VirusBarrier scan wake my Mac?

No for VirusBarrier X9: Intego says the Mac must be powered on and awake, so schedule the job for a normal active window and verify completion in the log. ONE also needs a practical awake window; don't assume a calendar entry proves a scan ran. Keep laptops on power for a long Full Scan.

Why does VirusBarrier say Unarchiving for so long?

Archive inspection can involve decompressing content to a temporary location, scanning it and recompressing it. That stage can be slow without being frozen. Compare Quick and Full behavior, note whether progress changes, and temporarily disable archive scanning only as a diagnostic branch; restore the setting and scan the relevant content afterward.

What does Intego quarantine actually do?

Quarantine isolates a detected item so it can't be treated like an ordinary file while you decide the next action. It isn't the same as deletion, successful repair or proof of a false positive. Keep the item isolated, record its path and detection, take the generation-specific action, then verify with a follow-up scan and history or log.

What is the difference between Repair, Delete, Ignore and Trust?

Repair tries to return the system or file to a safe state; X9 and the free Scanner also expose Delete. ONE's Ignore removes the item from the quarantine list without changing the file. Trust, Safe List and the free Scanner's Restore without Repair exclude or return an item and should be reserved for a separately verified false positive.

Why is the Quarantine button grey in VirusBarrier X9?

It can be grey because X9 already quarantined the detection automatically. Open the Quarantine panel, review the item and use Repair or Delete there. If the action doesn't settle, restart and run a Full Scan; use the resulting scan and log evidence rather than the missing list entry alone.

How long should an Intego Full Scan take?

There's no trustworthy universal duration. File count and type, archives, Windows-malware detection, external volumes, storage health and Low Priority can change it substantially. Watch whether the scanned-file count or path advances and compare a controlled Quick or targeted scan instead of declaring failure after an arbitrary number of minutes.

Can I safely test VirusBarrier without real malware?

Yes. Intego documents the harmless EICAR antivirus test file and says VirusBarrier detects it as Multi/Eicar. Use the official vendor or EICAR instructions, never a live sample, and verify the event in quarantine and history. Don't use a public upload service for private or confidential files.

Bottom line: every scan needs a question and a receipt

Use Full to establish or restore broad coverage, Quick for routine high-risk locations and Custom or targeted scanning when one file, folder or drive is the question. Schedule jobs for real awake windows, keep external storage scope deliberate and treat archive or Windows-malware switches as temporary diagnostics with documented coverage loss.

Then finish the detection. Quarantine is the safe pause; Repair or Delete is the generation-specific decision; Trust is an exclusion, not a cure. A clean follow-up scan plus the matching history or log entry is the receipt that turns a disappearing alert into defensible evidence.