Malwarebytes Scan Types Explained: Quick, Threat, Custom, Deep and Rootkit
Threat and Quick aren't the same scan. Deep Scan is Windows-only. Rootkit checking is a separate Custom Scan setting. Pick the job first, then the scope.
Quick answer: Run a Threat Scan for the normal broad check and weekly paid schedule. Use Quick Scan for memory and startup triage, then follow any detection with Threat Scan. Use Custom Scan for a known file, folder, application or external drive, or when you deliberately need a selected whole-device job. Use Deep Scan only on Windows after a real detection or credible compromise; Malwarebytes doesn't offer it on Mac. Rootkit checking isn't another name for Deep Scan: it's a separate Windows Custom Scan option, unavailable on ARM devices, and it can add hours. Android's deep-scanner toggle is another platform-specific feature, while iOS can't run a malware scan.
Choose the Malwarebytes scan by job, not by the scariest name
A normal check begins with Threat Scan. It covers the common system locations Malwarebytes associates with active threats and persistence, and it's the vendor's recommended scheduled mode. A larger scan isn't automatically a better first response because broader scope can consume hours without improving the answer to the question you actually have.
Quick Scan is triage for memory and startup programs. Custom Scan is a location and options tool: select a suspicious folder, external drive or broader Windows scope. Deep Scan is an intensive Windows-only investigation Malwarebytes recommends after blocking or detecting malware. Rootkit checking is another switch inside Windows Custom Scan, not a secret fifth depth setting.
| Your question | Start with | What it doesn't prove |
|---|---|---|
| Is there likely malware in normal persistence locations? | Threat Scan | That every byte and offline boot component was inspected |
| Is something active in memory or at startup? | Quick Scan, then Threat Scan if positive | That the rest of the file system is clean |
| Is this download, folder or drive suspicious? | Custom Scan or context-menu scan | That unrelated system locations are clean |
| Did the Windows PC just block or remove real malware? | Threat Scan, then Deep Scan if justified | That accounts and sessions weren't stolen |
| Is a Windows rootkit specifically plausible? | Custom Scan with rootkit option on supported non-ARM hardware | That every bootkit or firmware threat is excluded |
If you only remember one rule, remember the escalation ladder: targeted or normal scan first, wider and more intensive scan when evidence justifies it. Our full Malwarebytes review judges the protection product; this page owns the scan decision and its platform boundaries.
Threat, Quick, Custom, Deep and rootkit are five different concepts
The current official scan-types article lists Threat, Custom and Quick scans on Windows and macOS. It adds Deep Scan on Windows only. Malwarebytes' Windows settings documentation separately exposes Scan for rootkits as an optional Custom Scan control.
Search results often collapse those names into “quick,” “full” and “deep.” That shorthand creates three mistakes. Threat and Quick are treated as the same mode, Deep is transferred to Mac, and rootkit scanning is assumed to run whenever a scan sounds exhaustive. None matches the current public documentation.
The names describe different axes. Threat and Quick describe predefined locations. Custom describes user-selected scope and controls. Deep describes an intensive Windows engine path. Rootkit describes a special detection option. Selecting every checkbox inside Custom can make it longer than Deep without making the modes technically identical.
Current platform and entitlement matrix
Windows offers Threat, Quick, Custom and Deep. Current documentation says Quick Scan is limited to paid Windows users, while manual scanning remains available in free mode through the normal scan flow. Scheduled scans require paid access. Deep Scan was introduced in Windows version 5.3.5.204 in July 2025.
Mac offers Threat, Quick and Custom. Quick Scan is available to all Mac users, but scheduled scans are paid. Android has its own manual scanner, schedules and a deep-scanner toggle. iOS can't scan for malware. The Malwarebytes Free versus Premium guide owns the complete entitlement matrix.
| Scan or setting | Windows | macOS | Android | iOS/iPadOS |
|---|---|---|---|---|
| Threat Scan | Yes | Yes | Different mobile scanner | No malware scan |
| Quick Scan | Paid | All users | Not the desktop mode | No malware scan |
| Custom Scan | Yes, locations and options | Yes, selected folder/app/directory/drive | Different controls | No malware scan |
| Deep Scan | Yes | No | Different deep-scanner toggle | No malware scan |
| Rootkit option | Custom Scan, non-ARM | Not documented | Not the Windows option | No malware scan |
| Schedule | Paid | Paid | Trial/paid | Not applicable to malware scanning |
Threat Scan is the right default for most people
Threat Scan checks common computer locations where malware, malicious programs and persistence are likely to appear. Malwarebytes doesn't define it as a byte-for-byte sweep of every connected drive. Its strength is prioritization: memory, system and persistence areas can answer “is this machine actively compromised?” faster than reading cold archives.
Paid users receive a weekly Threat Scan schedule by default according to current scan-type documentation. The run and schedule guide also recommends weekly scanning or a scan after downloading a new application. Free users can start manual scans.
Use Threat Scan after a Web Protection block when the destination may have delivered a file, after an unexpected installer, or when Quick Scan finds something. If the scan is clean and there's no credible exposure, jumping immediately to rootkit and multi-drive scanning often adds anxiety rather than evidence.
Don't call Threat Scan “the quick scan” merely because it can finish quickly. Quick Scan is a separate named mode with a narrower memory/startup scope. That distinction is essential when interpreting reports and comparing times.
Quick Scan checks memory and startup programs
Quick Scan looks at the device's memory and programs configured to start with the operating system. It's faster and less comprehensive than Threat Scan. This makes it useful for triage when a process is behaving strangely, startup has changed, or you need a rapid first look before a meeting or shutdown.
Malwarebytes explicitly recommends running Threat Scan after Quick Scan detects malware. The narrower mode can identify an active clue without mapping the rest of the common threat locations. Treat a positive Quick Scan as the beginning of an incident sequence, not the whole cleanup.
On Windows, Quick Scan is a paid feature in current documentation. On Mac, it's available to all users. A search result that promises a free Windows Quick Scan may be describing an older interface, using “quick” generically or confusing it with the free manual Threat Scan.
A clean Quick Scan doesn't clear a suspicious download folder, external drive or dormant archive. Use Custom Scan for the known object or Threat Scan for the normal broader check.
Custom Scan answers a location-specific question
Custom Scan lets the user choose what and where to scan. Windows exposes a file tree and additional scan settings. Mac opens Finder so the user can select a folder, application, directory or drive. The platform workflows share the name but not every option.
Choose Custom when the suspicion has a location: a downloaded ZIP, a project directory, a mounted backup, an external SSD, a copied application or a folder named by another alert. A narrowly selected scan can produce a clearer report than a whole-device job because the result is tied to the exposure.
On scheduled Windows Custom Scan, current documentation says skipping the folder-selection step can scan the entire device. That's the closest official route to what many users call a “full scan,” but the selected settings still matter. A whole-device Custom Scan with archives and rootkits isn't the same engine description as Deep Scan.
Long scope isn't free. Terabytes of media, virtual-machine disks, development caches or backups can turn a Custom Scan into an overnight job. Select the relevant data and preserve the exact configuration with the report.
Deep Scan is a Windows-only incident-response escalation
The current Deep Scan article says the mode checks system locations against Malwarebytes' most comprehensive malware database and uses advanced detection techniques. It consumes more resources and can affect performance for longer than other scans.
Malwarebytes recommends Deep Scan after malware has been blocked or removed. The Windows 5.3.5 release note introduced it on July 28, 2025 and described the trigger as blocking or removing a large number of threats. It isn't positioned as the everyday reassurance button.
The current path is Scanner three-dot menu, Advanced Scan, Deep Scan. Once complete, the system-tray icon flashes and the report becomes available. Save the result before changing exclusions or uninstalling the product.
Don't transfer Deep Scan to macOS because a 2026 competitor review calls it a full Mac scan. Malwarebytes' own current scan-types article marks it Windows-only. Our Malwarebytes for Mac review keeps Mac scan behavior separate.
Deep Scan and “Full Scan” aren't interchangeable names
“Full Scan” is useful everyday language but not a precise current desktop button in the Malwarebytes documentation we checked. Some reviewers use it for Deep Scan; some users mean a Custom Scan with every drive selected. Support conversations use “full Custom Scan” when discussing added rootkit and drive choices.
Deep Scan is an intensive Windows engine path with a vendor-defined incident trigger. Custom Scan is a scope-and-options path. A Custom Scan can include all drives, memory, registry/startup, archives and rootkit rules where supported. That can be broader in selected storage while still being a different mode.
Ask for the report's Scan Type and settings instead of asking whether someone “ran a full scan.” Two people can answer yes while one ran Deep Scan on the Windows system and the other scanned ten terabytes of external media with Custom Scan. Their time and meaning aren't comparable.
Rootkit checking is a separate Windows Custom Scan option
The current Windows scan-settings page puts Scan for rootkits under Custom Scan. Malwarebytes describes rootkits as files on local disks hidden from the operating system and warns that turning on the setting slows scanning.
The documentation doesn't say Deep Scan automatically includes the Custom Scan rootkit option. We therefore don't tell readers that Deep means rootkit. If rootkit suspicion is the actual reason for scanning, choose Custom Scan, enable the documented option on supported hardware, record it and expect a long run.
Rootkit suspicion should come from evidence: a detection naming rootkit behavior, unexplained low-level persistence, security tooling being disabled in a reproducible way, or guidance from incident-response support. A browser pop-up saying “rootkit found” is more likely a scam than a diagnosis.
A July 2026 r/Malwarebytes thread shows users jumping from a clean reinstall to fear of bootkits and worms. Community replies can help frame questions, but a consumer scan can't prove that every firmware or boot compromise is absent.
Rootkit scanning is unavailable on ARM-based Windows devices
Malwarebytes' current Windows settings page explicitly says Scan for rootkits isn't available on ARM-based devices. That includes the growing class of Windows PCs built around ARM processors. The absence of the toggle is therefore not necessarily a broken installation or missing subscription.
Don't download an old anti-rootkit utility to force an unsupported driver onto a modern ARM system. Update Windows and Malwarebytes, run the supported Threat or Deep path as appropriate, and contact official support if a credible low-level compromise remains.
Processor architecture is different from Windows edition. A device can run Windows 11 and still be ARM. Check System → About → System type before following x64-specific instructions. The Windows 11 antivirus guide covers broader compatibility choices.
Windows archive scanning goes two levels deep and can't open passwords
When Scan within archives is enabled, current Windows documentation lists ZIP, 7z, RAR, CAB and MSI and says inspection goes up to two levels deep. A deeply nested archive can therefore contain material beyond the documented inspection boundary. The report should be read with that limit.
Password-protected archives can't be scanned because Malwarebytes doesn't have the key. Don't disable the password or extract an unsolicited archive merely to let antivirus inspect it. Verify the sender and purpose first, then extract only in a safe location when the content is expected.
Large compressed backups and development dependencies can expand the work dramatically. If the exposure is one downloaded archive, scan that object and, after trusted extraction, scan the extracted folder. A whole-disk archive scan may be a poor first use of time.
Archive scanning is one example of why file count and byte count don't equal protection quality. One container can hold thousands of files, while large media files may contribute gigabytes with little executable relevance. Compare scope and settings, not only the progress counter.
Memory, registry and startup options answer different persistence questions
Custom Scan on Windows can include memory objects allocated by processes, drivers and applications. It can also scan registry and startup items that launch when the device starts. Those settings overlap with Quick and Threat priorities but give the user explicit control inside a chosen custom job.
Memory scanning is useful when the concern is active behavior. Registry and startup scanning is useful when the concern is persistence after reboot. Neither is a reason to select every storage drive. Start with the threat mechanism, then add the locations it can use.
Deep Scan's public documentation refers to system locations, a comprehensive database and advanced techniques, but it doesn't publish a checkbox-by-checkbox equivalence with Custom Scan. Don't invent one. When you need an auditable configuration, Custom Scan's visible settings are easier to record.
PUP and PUM settings are policy decisions, not all-or-nothing malware
Windows Custom Scan can ignore, warn about or treat potentially unwanted programs and potentially unwanted modifications as malware. PUPs can include bundled software, aggressive advertising tools and utilities whose behavior conflicts with a security-conscious user's expectation. PUMs can represent unwanted system changes.
Malwarebytes recommends treating these detections as malware in its Custom Scan instructions. That's a reasonable protective default, but permanent deletion should still follow identification. An administrator tool, browser policy or intentionally modified setting may be legitimate in one environment and unwanted in another.
Quarantine first when uncertain. It blocks the item while preserving a restoration path. Don't add an unknown PUP or PUM to the Allow list just because a scan interrupted work. The separate quarantine spoke will own the deeper false-positive workflow after it's built.
Scan a specific file or folder without building a large Custom Scan
The current file and folder guide supports context-menu scanning. On Windows, right-click a file, folder or external drive and choose Scan with Malwarebytes. On Mac, right-click a folder in Finder and choose the same command.
This is the fastest way to check a known download before opening it. Confirm the context-menu entry belongs to the verified current Malwarebytes installation, run the scan and open the product report. A clean result lowers one risk; it doesn't make a pirated or impersonated installer trustworthy.
Windows added the current context-menu route in version 5.3.0.186 in May 2025. If the command is missing, update Malwarebytes, confirm the normal install completed and use Custom Scan while troubleshooting. Don't install an unrelated shell extension to recreate the menu.
For suspicious adware rather than a conventional file, compare Malwarebytes AdwCleaner. Its role and interface are separate from the main desktop scan types.
External drives can be scanned, but terabytes need a plan
Windows can scan an external drive from File Explorer or select it in Custom Scan. Mac Custom Scan can select a connected drive through Finder. Neither route means every external drive is automatically scanned whenever mounted unless a current schedule explicitly targets it.
Before starting, check capacity, connection, drive health and sleep settings. A slow USB HDD with millions of small files and archives can take many hours. Scanning several backup drives at once makes it harder to identify which device or file caused a stall.
Start with the folder involved in the exposure. Widen to the full drive if the source or file path is unknown. Disconnect other storage that isn't part of the job, but never unplug the drive being scanned or written without stopping safely.
A January 2026 community thread asked whether to scan seven to ten terabytes with rootkit options. It's a useful example of scope inflation: external data scanning and a Windows rootkit investigation are different questions and should usually be separated.
Mac offers Threat, Quick and Custom—never current Deep Scan
Current Mac scan types are Threat, Quick and Custom. Malwarebytes says Mac scans can be faster because they focus on locations likely to contain threats and avoid rescanning unchanged files. A short Mac Threat Scan isn't automatically broken or superficial.
Quick Scan checks memory and startup programs. Custom Scan, added to the Mac 5.x line in October 2025, can target a folder, application, directory or connected drive. Current public documentation doesn't expose the Windows rootkit toggle on Mac.
Several current competitor articles call Deep Scan a Mac mode. That contradicts Malwarebytes' June 2026 scan-types article, which labels Deep Scan as Windows-only. We follow the primary source and keep Windows test times out of the Mac conclusion.
Mac permissions also affect visibility. Paid real-time protection requires the current Full Disk Access and extension grants, while a custom selection can prompt for document access. Our Mac review explains those boundaries and the current independent-lab gap.
Android's deep scanner isn't Windows Deep Scan
The current Android scan guide offers a setting named Use deep scanner during full scan. Malwarebytes says it adds deeper rules and full scans of system apps, with increased time. It lives inside Android scanning settings.
That phrase doesn't create the Windows Deep Scan mode on a phone. Android scans packages and files through mobile APIs and permissions. Windows Deep Scan uses a desktop engine path and Windows system locations. Compare each against its platform documentation.
Android also offers scan-after-reboot, scan-after-update, power-saving and charge-only controls, plus paid/trial schedules. The Malwarebytes Mobile Security review covers those settings, current mobile lab evidence and a 2026 scheduled-scan fix.
If an Android scan takes hours, save the current item and logs before reinstalling. A July 2026 mobile issue can resemble a Windows long scan in search results but requires a different diagnostic route.
iPhone and iPad can't run a Malwarebytes malware scan
Apple's app sandbox prevents a third-party iOS security app from inspecting the operating system and other applications like a Windows, Mac or Android scanner. Apple's current iOS app-security architecture describes code signing and controls that keep an app from compromising other apps or the rest of the system. Malwarebytes states that no malware scanner is available on iOS. There's no Quick, Threat, Custom, Deep or rootkit mode to unlock with a higher tier.
The iOS app instead provides Web Protection, Ad Blocking, text and call filtering, Scam Guard and optional VPN or identity features according to device and plan. A “scan” label on an iPhone may refer to a digital-footprint or scam check, not device malware.
Don't follow a website that asks you to install a profile or grant remote access to perform an iPhone virus scan. Use Apple's platform guidance and the iPhone security guide for the controls that are technically possible.
Scheduled scans are paid, and Smart Scan means idle timing
Current Windows and Mac scheduling is available to paid users. Both platforms can schedule Threat, Quick or Custom scans. Windows offers start date, time and frequency, plus an idle-time Smart Scan choice. Smart Scan in this context is a scheduling condition, not another malware scan type.
Windows advanced schedule options can quarantine all threats, restart to complete removal and scan within archives. Automatic restart depends on automatic quarantine being enabled. Don't schedule an unattended restart during work or a critical overnight process without understanding that dependency.
Mac schedules can automatically quarantine threats and control PUP handling. The vendor recommends keeping Ignore PUPs off. Select folders explicitly for scheduled Custom Scan and verify that mounted drives are present when the job starts.
After creating a schedule, check the first report. A configured schedule isn't evidence that it ran, survived sleep or found the intended storage. Keep the last successful date and scan type visible.
Weekly is a reasonable default; events matter more than rituals
Malwarebytes recommends weekly scanning or scanning after downloading a new application. Paid Threat Scan defaults to weekly. That cadence is reasonable for a normal maintained computer with real-time protection, but exposure-driven scans can matter more than adding daily full jobs.
Run a targeted scan before opening a questionable file, and run Threat Scan after a credible web or application exposure. Run Deep Scan after a real Windows detection or incident evidence. Use rootkit scanning when the threat model supports it, not every Sunday for reassurance.
Free users can create a simple habit: update the app, run Threat Scan after risky activity and record detections. Malwarebytes also documents an optional free monthly Windows scan; it's a baseline reminder, not a substitute for an exposure-driven check. Paid users should confirm real-time layers are active so a schedule isn't carrying the entire protection burden.
If recurring scans consume too much time, reduce unnecessary scope instead of disabling all checks. A weekly Threat Scan plus targeted file scans can be more useful than a monthly multi-drive job nobody allows to finish.
There's no honest universal Malwarebytes scan time
Scan duration depends on type, selected locations, file count, storage speed, archives, rootkit setting, current load, operating system, app version and whether files changed. A reviewer who completed Deep Scan in fourteen minutes on one Windows test rig didn't establish your scan time.
Mac Threat Scans can be unusually brief because the engine focuses on likely locations and avoids unchanged files. Windows Custom Scans can take hours across large HDDs. A rootkit-enabled whole-device scan can be longer still. Android scan time follows another set of package, storage and battery conditions.
Record a baseline on your own machine: scan type, options, items, elapsed time and app version. A later scan that's dramatically slower under the same conditions is diagnostic information. Comparing a Quick Scan to a rootkit-enabled Custom Scan isn't.
Don't use scanned-item counts to rank antivirus products. Engines count archives, registry objects, processes and cached data differently. Detection evidence and correct scope matter more than the largest counter.
A long scan isn't automatically stuck
A scan may spend a long time on a large archive, damaged file, slow external drive, rootkit phase or dense tree of small files while the counter changes slowly. First record the current item, phase, elapsed time, storage activity and whether the app still responds.
Check the scan configuration. Rootkit scanning and multi-drive Custom scope are the first suspects in current community threads. Exclude neither blindly; decide whether each belongs to the actual investigation. If not, stop and rerun a smaller supported scope.
A June 2026 r/Malwarebytes report describes a seven-hour scan and SSD heat. Official support said rootkit scanning can significantly increase time and advised stopping and sharing diagnostics. That's a troubleshooting path, not proof that seven hours is normal.
Update Malwarebytes before reproducing, restart when safe and run the same relevant scope once. If it stalls at the same object, use the official Windows Support Tool log workflow and open a private support case. Repeated clean installs can erase the chronology without fixing a damaged file or drive.
CPU, disk use and heat require a safety threshold
Deep, rootkit and broad Custom Scans are resource-intensive by design. High utilization during a bounded scan isn't automatically a fault. Sustained thermal throttling, drive errors, system freezing, battery swelling, unexpected shutdowns or unsafe temperatures are reasons to stop.
Put a laptop on a hard ventilated surface, connect trusted power if appropriate and pause other heavy work. Don't leave an unstable machine unattended for days merely because a forum reply said “let it cook.” Protect hardware and data first.
On an HDD, mechanical latency and millions of small files can dominate. On an SSD, throughput is higher but controller temperature and competing I/O still matter. Scan only the relevant external drive or folder before expanding to every backup.
If normal Threat Scan suddenly causes persistent resource problems, the issue may belong to product performance rather than scope. Compare another current scan under the same conditions, save logs and test after an update before uninstalling.
Stop or cancel through the app; don't kill the process first
If the Malwarebytes interface offers Stop or Cancel, use it. That gives the scanner a chance to close files, record the partial event and release resources. Force-quitting or powering off is a last resort for an unresponsive or unsafe system.
Before stopping, capture the scan type, settings, current item and time. A partial scan isn't a clean result, so the report should never be used to say the device passed. Resolve the scope, heat, drive or application problem and rerun the appropriate mode later.
If the machine is unstable after stopping, restart and check storage health before launching another intensive scan. A failing drive can look like antivirus slowness and may need backup and hardware diagnosis before more reads.
Scan reports turn a spinner into evidence
The current scan-report guide says reports contain scan type, detections, date and time and are stored for up to 30 days. Malwarebytes' newer Windows Detection History page confirms that scan and real-time events share the history view and that Windows can export TXT. Mac can view the report in the application.
Save a Windows report before changing exclusions, uninstalling or opening a support case. If removal becomes necessary, follow our complete Malwarebytes uninstall guide only after preserving the evidence. Redact usernames, local paths, email addresses and license information before posting publicly, while keeping detection names and useful file hashes or paths.
The report identifies whether “full scan” meant Threat, Quick, Custom or Deep and whether rootkit scanning was enabled. It also helps compare a repeated stall. Without it, scan-time anecdotes are difficult to interpret.
Reports age out, so preserve incident evidence promptly. If the Scanner or Reports control is missing after an update, confirm that the application itself is current and correctly installed with our Malwarebytes installation guide. Don't reinstall before saving any report you still need.
After a detection, quarantine first and widen intelligently
Malwarebytes normally quarantines detected threats under current settings. Quarantine isolates the item so it can't continue its normal activity while preserving a review path. Save the report, note whether the detection came from a scan or real-time protection and restart if removal requires it.
Follow a positive Quick Scan with Threat Scan. After a meaningful Windows detection or many removed threats, consider Deep Scan. Use Custom Scan for related folders, drives or archives named by the incident. Add rootkit rules only when the evidence supports them.
If the detection is an infostealer, banking Trojan or remote-access tool, device cleanup is only one workstream. From a clean device, revoke sessions, change passwords, rotate API keys and contact financial institutions as relevant. A later clean Deep Scan can't undo stolen credentials.
Compare the broader response in our malware removal guide. Keep offline backups and avoid reconnecting sensitive storage until the incident scope is understood.
Restore and allow only after independent verification
The current quarantine documentation allows a trusted item to be restored and optionally excluded from future detection. Deleting a quarantined item is permanent. That makes quarantine the safer first action when certainty is low.
Verify publisher, signature, origin, hash and whether a current vendor build exists. An unusual administrative tool can be legitimate, but a crack, loader or unsigned update from a forum has a much weaker trust basis. Don't restore simply because the program is useful.
An Allow list suppresses future warnings and can turn a judgment mistake into persistent exposure. Malwarebytes' current Allow list documentation explicitly says to add an item only when you're certain it's harmless. Remove old exceptions after updates and review backups before importing an Allow list onto another device. Context belongs with the exception.
Community support can read a redacted report, but only official detection analysis should decide a disputed product false positive. Don't upload proprietary or personal files to a public scanner without authority.
A clean scan doesn't clear every suspicious symptom
A clean Threat, Custom or Deep result says the selected engine and scope didn't find a detection at that time. It doesn't prove a password was never phished, a browser session wasn't stolen, a remote account is safe or every boot and firmware component is clean.
Classify the symptom. Browser redirects may come from an extension or notification permission. High CPU may come from a legitimate application or failing drive. Account logins require session and credential review. Network issues may belong to DNS, proxy or VPN settings.
If suspicious behavior persists, collect Malwarebytes diagnostics and operating-system evidence rather than repeating increasingly large scans. The current infection guidance sends unresolved cases to Support with diagnostic logs.
For browser-only concerns, review Malwarebytes Browser Guard. For a Mac-specific issue, use the Mac review. For a mobile concern, use the mobile review. The right platform route matters more than a “deepest scan” slogan.
Practical scan recommendations by scenario
| Scenario | First scan | Escalation | Avoid |
|---|---|---|---|
| Downloaded an unknown Windows installer but didn't run it | Context-menu or Custom Scan on the file/folder | Threat Scan if anything is detected or executed | Opening it to see what happens |
| Unexpected startup process or memory behavior | Quick Scan | Threat Scan, report and process investigation | Calling a clean Quick result a full clearance |
| Web Protection blocked a malicious site | Threat Scan if a file or action may have occurred | Custom Scan downloads; account review for phishing | Deep/rootkit scan with no exposure evidence |
| Windows malware was blocked or removed | Threat Scan and save report | Deep Scan; Custom related locations | Deleting evidence before follow-up |
| Credible rootkit indicator on x64 Windows | Custom Scan with rootkit option | Official support or incident response | Assuming Deep automatically includes it |
| External backup contains a suspicious folder | Custom Scan that folder | Full drive if origin/path is unknown | Scanning every backup plus rootkits as one job |
| Mac needs a second opinion | Threat Scan | Custom selected app/folder/drive | Looking for a Mac Deep Scan button |
| Android phone concern | Android Scan now | Deep-scanner setting when justified, logs/support | Following Windows scan instructions |
These are starting points, not guarantees. Update Malwarebytes and the operating system first when the device is stable enough. Preserve a real detection and account timeline before experimenting with exclusions or clean tools.
If repeated scanning is the only reason you keep Malwarebytes, compare its free and paid roles and renewal price. Our pricing guide and Bitdefender comparison help decide whether another engine or subscription model fits better.
Final decision: start normal, escalate with evidence
Threat Scan is the everyday answer. Quick Scan is memory and startup triage. Custom Scan is for a location or a documented set of Windows options. Deep Scan is a Windows-only post-detection escalation. Rootkit scanning is a separate non-ARM Windows Custom Scan setting with a substantial time cost.
Mac users get Threat, Quick and Custom—not Deep. Android's deep-scanner toggle isn't Windows Deep Scan, and iOS can't run a malware scan. Those platform boundaries remove most of the confusion found in current search results.
Use reports to preserve what actually ran. Quarantine before deleting, verify before allowing, and separate device cleanup from account recovery. If you run Microsoft protection alongside Malwarebytes, check both our Malwarebytes vs Windows Defender comparison and Microsoft's current explanation of Defender behavior with another security product installed. A ten-hour scan isn't more reassuring if it answers the wrong question.
Malwarebytes scan types FAQ
Which Malwarebytes scan should I run?
Use Threat Scan for a normal broad check. Use Quick Scan for memory and startup triage, Custom Scan for a named file, folder or drive, and Windows Deep Scan after a real detection or credible compromise. Add rootkit scanning only when that specific risk is plausible.
Is Malwarebytes Threat Scan the same as Quick Scan?
No. Quick Scan checks memory and startup programs and is less comprehensive. Threat Scan checks common locations where threats live and is the normal scheduled scan. If Quick Scan finds malware, Malwarebytes recommends following it with Threat Scan.
Is Malwarebytes Deep Scan a full scan?
Deep Scan is Malwarebytes' Windows-only intensive named mode, but “full scan” isn't a precise current product name. A Custom Scan can target selected or whole-device locations and can add rootkit and other options, so the two jobs aren't interchangeable.
Does Malwarebytes Deep Scan check for rootkits?
Don't assume it does. Current Malwarebytes documentation exposes Scan for rootkits as a separate Windows Custom Scan setting. The company doesn't document it as an automatic Deep Scan component, and the option is unavailable on ARM-based Windows devices.
Why is Malwarebytes rootkit scan taking so long?
Rootkit scanning adds intensive rules and can greatly increase the time needed, especially with large HDDs, many files, archives or multiple drives. Record the scan stage and settings; stop and collect diagnostics if time, heat or responsiveness becomes unsafe.
Can Malwarebytes Deep Scan a Mac?
No. Current Malwarebytes documentation lists Deep Scan as Windows-only. Mac offers Threat, Quick and Custom scans. A Mac Custom Scan can target a folder, application, directory or connected drive, but it doesn't become Windows Deep Scan.
Can Malwarebytes scan an external hard drive?
Yes. On Windows, right-click a drive and choose Scan with Malwarebytes or select it in Custom Scan. On Mac, use Advanced scans and Custom Scan to select the connected drive. Time depends on drive size, speed, files and options.
Does Malwarebytes scan ZIP and RAR archives?
Windows can scan supported archives such as ZIP, 7z, RAR, CAB and MSI up to two levels deep when archive scanning is enabled. Password-protected archives can't be inspected, so extract them only when the source is trusted and scan the contents separately.
Can I stop a Malwarebytes scan safely?
Yes when the interface offers Stop or Cancel, especially if heat, disk errors or system instability appear. Save the scan type, stage and settings first. A partial scan isn't a clean result, so resolve the cause and rerun an appropriate scope later.
What should I do after Malwarebytes finds something?
Save or export the report, quarantine the item, restart if removal requires it and run the recommended follow-up scan. Verify unknown or potentially unwanted detections before permanent deletion or allowing them. Change credentials separately if an infostealer or account compromise is possible.
