We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Antivirus workflow guide · Current vendor documentation and MacKeeper 7.7 checked August 8, 2026

MacKeeper Antivirus Scans, Quarantine and Adware

The button labeled Start Scan is the easy part. The hard part is knowing what MacKeeper actually scanned, whether a detection was contained, and why an Adware Cleaner result needs a different decision from an ordinary malware finding.

Version 7.7 contextHome-folder scope clarifiedQuarantine vs Notify separatedAdware and PUA context included

Quick answer: MacKeeper's default Antivirus scan is described in the body of its current help article as scanning the Home folder, even though the section heading says “entire Mac.” Use Custom Scan for chosen files, folders or a mounted external drive; use the Finder Services command when it's available; and treat Real-Time Protection as an open-time check rather than a historical scan of every dormant file. By default, detections go to Quarantine. Switching to Notify means MacKeeper reports them without automatic containment. Adware Cleaner is a separate tool for adware, malicious installers and potentially unwanted applications, not another name for Antivirus, StopAd or Safe Cleanup.

MacKeeper's “full scan” wording hides a Home-folder scope

The first question isn't how long a scan takes. It's what the scan was asked to cover. MacKeeper's current Antivirus help article, updated June 12, 2026, has a section heading about scanning the entire Mac. The instructions directly below say the standard Antivirus scan checks the Home folder. Those statements aren't equivalent, so we use the narrower, operational description.

Your Home folder contains Desktop, Documents, Downloads, Pictures and much of the user-level application data that matters in an everyday infection. It doesn't automatically mean every mounted disk, every other user account, every protected system location and every archive was inspected. A clean result is evidence about the scope that actually ran, not a certificate for the whole machine.

This distinction also explains why search results and third-party reviews can sound inconsistent. Some call MacKeeper's single Start Scan control a full scan, while others say the product offers only one scan type. The current vendor workflow is more useful than either shorthand: there's a default Home-folder run, a Custom Scan for selected targets, a Finder Services route, and Real-Time Protection for files as they open.

MacKeeper's live download page identifies version 7.7, released July 2026. The Antivirus article still labels itself version 6.0 despite its 2026 update. Follow the current concepts and use the controls visible in your installed 7.7 build; don't expect every label or pixel to match an older illustration.

Choose the narrowest scan that answers the question

A broad scan isn't automatically the best first move. If the concern is a new installer in Downloads, scanning that file and its folder gives a faster, more interpretable answer. If an external drive arrived from another computer, select that volume. If there's no specific trigger and you want a baseline, run the default Home-folder scan after verifying permissions.

RouteDocumented scopeBest useWhat it doesn't prove
Start ScanHome folderGeneral user-file baselineEvery disk and protected location was checked
Custom ScanFiles and folders you addDownloads, project folder, external volumeAnything outside the chosen targets was checked
Finder ServicesSelected Finder itemOne suspicious file or folderThe contextual command appears on every macOS build
Real-Time ProtectionFiles when openedContinuous interception of active file useDormant files on every attached drive were retrospectively scanned

Write down the question before clicking. “Did this downloaded package trigger a detection?” calls for a file or folder target. “What is in my user data?” fits the default scan. “Is this backup drive worth trusting?” calls for a custom volume scan plus normal caution when opening unknown files. Clear scope prevents a green result from growing into a claim the software never made.

Avoid invented scan-time expectations. MacKeeper says duration depends on the number and size of files and the Mac's performance. File count, encryption, archives, storage health and background load can all change the experience. A useful comparison records the target and circumstances; “mine took seven minutes” without scope tells another reader almost nothing.

Check Full Disk Access before trusting an unexpectedly shallow result

macOS privacy controls affect what a security tool can inspect. MacKeeper's current Antivirus guidance asks for the Real-Time Protection system extension plus Full Disk Access for two entries: MacKeeper Real-Time Protection and MacKeeper. If those states are missing or disagree with the app, a fast clean scan may reflect reach rather than the absence of unwanted files.

Don't turn this page into a permission-repair marathon. Our MacKeeper macOS compatibility and Full Disk Access guide separates the current 7.7 requirement, Apple silicon and Intel support, the system extension, both Full Disk Access entries and managed-Mac restrictions. Use that diagnostic when protection stays off, settings are greyed out or protected locations appear to be skipped.

Permissions aren't a reason to weaken the Mac. Ordinary setup shouldn't require disabling System Integrity Protection, reducing Apple silicon startup security or pasting a broad privacy reset from a forum. Grant only the current signed components requested through the app's official route, relaunch if prompted, then confirm status inside Antivirus.

Once the state is healthy, run a small known folder first. That proves the controls, progress and result surface are behaving before you commit to a larger target. It also gives you a baseline for what a normal completed scan looks like on that Mac without pretending it's a universal benchmark.

How to run and interpret the default Antivirus scan

Open MacKeeper, select Antivirus and use Start Scan. The vendor says the current file path can be displayed while the scan advances. Let the run finish, note the target implied by the interface and save the final result if you're troubleshooting. Don't eject drives, move the selected folder or close the app halfway through and then treat a partial run as clean.

The default route makes sense after a first install, after repairing protection permissions, or when symptoms involve user-level files and there's no single suspect. It's also a reasonable follow-up after removing an unwanted application, because related downloads and user data often live below Home. It isn't a substitute for checking a particular external drive that was never selected.

If the scan finds nothing, interpret that result with the date, version, scope and permission state attached. “MacKeeper 7.7 completed the documented Home-folder scan with current permissions and reported no detection” is a defensible statement. “The Mac is guaranteed clean” isn't. No consumer scanner observes every account compromise, malicious browser notification, configuration profile or remote-session abuse.

If the scan finds something, stop looking at the total count and record each detection name and path. The path distinguishes a browser download from an installed application component, an email attachment, an archive copy or a file on another volume. That context drives the next action more reliably than a red color or generic threat count.

Use Custom Scan for Downloads, projects and external drives

MacKeeper documents three ways to populate Custom Scan: choose items with the plus control, drag files or folders into the target area, and use Command while selecting more than one item. That lets you create a focused question without mixing unrelated locations. Add the installer and its containing download folder, for example, rather than scanning every photo library because one package looked suspicious.

For an external hard drive or USB volume, mount it normally and confirm Finder can read it. Add the volume or the relevant folder as the Custom Scan target, keep it attached until completion and inspect whether the displayed path belongs to that device. Eject only after the scan and any file operations finish. If the drive disconnects or sleeps, rerun the intended target rather than trusting an ambiguous completion screen.

Encrypted volumes must be unlocked for their contents to be available. Damaged filesystems, inaccessible folders and archives with unsupported or password-protected contents can also limit inspection. A scanner can't analyze bytes the operating system doesn't expose. Record any warning instead of reducing the outcome to clean or infected.

External media deserves a two-stage habit: scan before opening unknown files, then keep Real-Time Protection healthy while you work with them. The custom scan looks at the selected contents now; the real-time layer can respond when a file is opened later. Neither replaces provenance. A signed installer from an official vendor page is easier to reason about than the same filename from a download mirror.

Finder Services and Real-Time Protection solve different problems

The Antivirus guide documents a contextual Finder route: select a file or folder, open Services and choose Scan for Viruses with MacKeeper. It's useful when the question begins in Finder and you don't want to assemble a broader Custom Scan. macOS can hide or reorder Services entries, so treat this as a documented option rather than a promise that the same menu appears on every release.

If the command is missing, use Custom Scan instead of trying random extension resets. Confirm MacKeeper is current and installed through the official route. A missing convenience item doesn't by itself prove the engine or real-time protection is broken; the in-app scan is the controlling fallback.

Real-Time Protection checks files as they open. That's valuable because many threats become relevant at execution or access time, but it doesn't mean every dormant file on a backup drive was already inspected. Opening every unknown file to “make real-time scan it” would create the risk the protection is meant to reduce. Use an on-demand target first.

The product's default detection action applies to both on-demand and real-time findings, according to the vendor: threats go to Quarantine unless Antivirus Settings has been changed to Notify. That shared action doesn't make the scan modes identical. One starts from a chosen scope; the other responds to file access over time.

After a detection, preserve the path and containment state

A useful detection record has four parts: the name MacKeeper assigned, the full path, the apparent source and the action taken. Save those before deleting anything. If the file came from an installer, note the download URL and whether it was the vendor's official domain. If it belongs to work software or a personal project, preserve enough context to avoid destroying the only copy.

MacKeeper says detections are automatically moved to Quarantine under the default setting. That's a containment decision, not a final judgment about every related component. The detected file may have arrived with a launch agent, browser extension, altered setting or second payload. Conversely, a legitimate niche tool can sometimes match a behavioral rule. Quarantine buys review time for both possibilities.

Don't upload confidential documents or proprietary binaries to a public multi-engine scanner as a reflex. Such services can be useful for a non-sensitive public installer, but confidentiality, file-sharing terms and false positives still matter. For private material, start with the path, code signature where available, publisher source and vendor support rather than turning the sample public.

If the detection interrupted an active process, leave the Mac offline from sensitive accounts until you understand the event. A quarantined download that was never opened is a different risk from a credential stealer that ran before detection. The result name alone can't reconstruct the timeline.

Quarantine contains the item; Notify doesn't

MacKeeper's default is the safer general-purpose choice: detected items are moved into Quarantine. From there, the interface offers Restore or permanent Delete. The original location no longer behaves as if the file were freely available, and you have a review boundary before irreversible action.

Antivirus Settings can change infected-item handling to Notify. In that mode, MacKeeper says detections remain in Scan Results and aren't automatically blocked or quarantined. The older/currently maintained help flow says result items are selected by default for action, with individual deselection available. Selection in a results list isn't containment; the underlying file remains outside Quarantine until you act.

SettingAutomatic resultMain benefitMain risk
QuarantineDetection is containedCreates time to inspect and chooseA needed file may stop working until reviewed
NotifyDetection appears in Scan Results, not containedManual control for an expert workflowThe detected item remains available and may still run

Notify isn't a harmless preference for fewer pop-ups. It changes the security outcome. Use it only if you deliberately want to adjudicate detections and can tolerate the file remaining in place. On a family or shared Mac, default Quarantine is easier to explain and less dependent on someone reading every alert correctly.

If you discover the app has been in Notify mode, review unresolved Scan Results and rerun the relevant scope after restoring default containment. Don't assume earlier notifications were blocked. The exact history matters: identify whether any reported file was opened, moved or deleted outside MacKeeper.

Keep, restore and delete are evidence decisions

Keep an uncertain file in Quarantine while you identify it. This is especially appropriate for a business application, a custom script, a personal archive or an installer whose provenance you can still verify. Quarantine isn't clutter that must be emptied immediately. Its purpose is to separate urgency from irreversible action.

Restore only when the evidence supports a false positive or a needed, understood risk. Permanent deletion is appropriate when the file is unwanted, the source is untrusted and you have preserved anything legitimately needed. Neither action should be selected merely because every row arrived preselected.

The next cluster page, not this one, owns the deeper false-positive workflow: code-signature checks, trusted-app decisions, vendor submission, repeated detections and a careful restore. Here the boundary is simple. Preserve name, path and source; leave uncertainty contained; don't erase the only evidence; and don't restore a file solely because one public scanner reports fewer detections.

After permanent deletion, check for related behavior rather than celebrating an empty list. A removed installer doesn't reverse browser notification permission, a login item or a profile it already created. A removed component can also be regenerated by its parent application. The file result and the persistence mechanism are separate objects.

Adware Cleaner is separate from Antivirus, StopAd and Safe Cleanup

The current MacKeeper EULA defines Adware Cleaner as monitoring for and removing adware, malicious installers and potentially unwanted applications. That's a useful current boundary. The dedicated Adware Cleaner guide is older—February 2022 and version 6.0—so use it for the workflow and concepts, not a pixel-perfect 7.7 interface map.

Adware Cleaner isn't StopAd. StopAd operates as a Safari or Chrome extension to block ads and trackers while browsing. It's also not Safe Cleanup, which concerns storage such as caches and other removable clutter. An advertisement on a webpage, an installed adware component and an old cache file are three different objects and deserve three different tools.

MacKeeper surfacePrimary jobTypical evidenceDon't confuse it with
AntivirusMalware scanning and real-time file checksDetection name, file path, quarantine stateStorage cleanup
Adware CleanerAdware, malicious installers and PUA reviewApplication, component, installer and behaviorEvery ad seen online
StopAdBrowser ad and tracker blockingExtension state and site behaviorRemoving an installed unwanted app
Safe CleanupReclaiming storageCache, language and other cleanup categoriesMalware classification

The older guide says to open Adware Cleaner, start a scan, review found items and delete them; it also describes real-time adware monitoring and a Trusted Applications list. Verify the present labels before following screenshots from 2022. A current concept can survive while the control has moved.

MacKeeper's old article says deleting all detected adware is completely safe. We don't repeat that absolute. The existence of a Trusted Applications mechanism shows why context matters: a PUA or adware classification can involve consent, bundling, aggressive promotion or changed settings, not only a clearly malicious binary.

Review adware and PUA results by consent, source and behavior

MacKeeper's published malicious-software criteria describe behaviors that can place software in adware or potentially unwanted categories: bundling without clear consent, intimidation, browser hijacking, unwanted setting changes, impersonated prompts, spam or ad-click activity, and components designed to hide or resist removal. These are more informative than a generic “annoying app” label.

Ask three questions. Did you knowingly choose the software? Did the installer clearly disclose the bundled behavior? Did the application change the browser, startup, notifications or search settings beyond what you accepted? A program can be functional and still be unwanted because consent was weak or removal is obstructed. Another can be unfamiliar but required by a legitimate package.

For each result, record the application and component path, publisher or installer source, when it appeared, and the symptom that prompted the scan. Inspect browser extensions, notification permissions and login items that correspond to it. Don't add an item to Trusted Applications merely to make the warning disappear; trust should follow identification and a reason to keep it.

If removal breaks a wanted workflow, leave the item contained and investigate rather than repeatedly restoring and rescanning. If the application is unwanted, uninstall its parent through the normal route when possible, remove the detected components, and reverse browser or startup changes separately. A scanner can remove a file without understanding every preference the installer changed.

Rescan the affected scope, then inspect symptoms outside that scope

After quarantine or deletion, repeat the smallest scan that covers the original path. If the detection came from Downloads, rescan that folder. If it came from an external volume, keep the drive mounted and rescan the same target. If a real-time alert appeared when an application opened, close the application, preserve the record and check its installed components before testing it again.

A repeated detection can mean the parent app recreates the file, a synced folder downloads it again, an archive still contains a copy or a browser restores an extension. It doesn't automatically mean MacKeeper failed to delete the first object. Compare paths and timestamps instead of treating matching labels as proof of one continuous file.

A clean focused rescan plus persistent symptoms tells you to inspect another layer. Browser pop-ups may be website notification permission; a changed homepage may be an extension or managed preference; an app reopening at login may be a login item; a fake virus warning may exist only in a web page. Antivirus, Adware Cleaner and StopAd overlap around the user's complaint but don't observe the same thing.

When escalation is necessary, give support the MacKeeper version, macOS version, scan route and target, exact detection name and path, containment action, repeat result and screenshots with personal data removed. That record is far more actionable than “scan did nothing.” For overall product strengths, lab context and bundle tradeoffs, keep the broader judgment on our MacKeeper review; for installation state use the MacKeeper setup guide; and for plan decisions use the pricing and renewal guide.

MacKeeper scans, quarantine and adware FAQ

Does MacKeeper have a full scan?

MacKeeper's help article uses a heading that says it can scan the entire Mac, but the instructions underneath say the default Antivirus scan checks the Home folder. Treat that as the documented default scope, not proof of a literal whole-disk scan. Use Custom Scan for another folder, selected files or a mounted external drive, and verify Full Disk Access if protected locations appear to be skipped.

How do I scan a specific file or folder with MacKeeper?

Open Antivirus, choose Custom Scan, then add the file or folder with the plus control or drag it into the target area. The vendor also documents a Finder Services command named Scan for Viruses with MacKeeper for a selected item, although its visibility can vary with macOS and the installed component.

Can MacKeeper scan an external hard drive or USB drive?

A mounted external volume can be selected as a Custom Scan target. Confirm the drive is readable, select the relevant folder or volume and let the scan finish before ejecting it. Real-Time Protection alone shouldn't be treated as evidence that every file already stored on the drive has been examined.

What does MacKeeper do when it finds malware?

MacKeeper says the default Antivirus action moves detections from an on-demand scan or Real-Time Protection into Quarantine. Quarantine contains the item while you review its name, path and source. Antivirus Settings can instead use Notify, but Notify leaves the item outside automatic containment and requires a deliberate action in Scan Results.

Is a quarantined MacKeeper file deleted?

No. Quarantine is an isolated review state, not permanent deletion. MacKeeper provides Restore and Delete actions. Keep an uncertain item contained while you establish what it is, especially if it belongs to business software, a personal project or an installer you may need to verify.

Should I change MacKeeper from Quarantine to Notify?

Usually not unless you understand the tradeoff and want to adjudicate every detection manually. Notify doesn't automatically block or quarantine detected items, so the file remains where it was while the result appears in Scan Results. Default Quarantine gives most people a safer pause between detection and permanent action.

Is MacKeeper Adware Cleaner the same as Antivirus?

No. Antivirus handles malware detections and real-time file checks. Adware Cleaner is a separate surface for adware, malicious installers and potentially unwanted applications. StopAd is the browser ad and tracker blocker, while Safe Cleanup removes storage clutter; neither should be used as a synonym for Adware Cleaner.

Is it safe to delete every Adware Cleaner result?

Review first. MacKeeper's older guide selects detected items by default and uses very confident deletion language, but PUA judgments can depend on consent, bundling and whether you intentionally installed the program. Record the app, path, installer source and browser changes before permanent deletion, and keep uncertain items contained or trusted only after verification.

Why did a MacKeeper scan finish unusually fast?

A short scan can be legitimate when the selected target is small, but it can also mean you ran a narrow Custom Scan or the default Home-folder scan rather than the scope you expected. Check the selected path, file count where shown and Full Disk Access state before treating the result as comprehensive.

What should I do if MacKeeper says the scan is clean but symptoms remain?

Don't repeat the same scan indefinitely. Check whether the symptom belongs to a browser extension, notification permission, login item, configuration profile or unwanted application rather than a file the Antivirus scan covers. Run a focused rescan after any action, then inspect the affected layer and seek support with the exact path, detection name and screenshots if the behavior persists.

Verdict: scope first, containment second, deletion last

MacKeeper's scan workflow makes sense once the labels are translated into operational scope. Start Scan means the documented Home-folder baseline, Custom Scan answers a selected-file, folder or external-drive question, Finder Services is a contextual convenience, and Real-Time Protection checks files as they open. None should quietly inherit the promises of the others.

Keep default Quarantine unless you deliberately accept that Notify reports without automatic containment. Record name, path and source before an irreversible action. Then treat Adware Cleaner and PUA findings as a consent-and-behavior review, separate from browser ad blocking and storage cleanup. A clean rescan is useful evidence; the best diagnosis also checks whether the original symptom belongs to a browser, startup, profile or account layer outside the scan you ran.