McAfee Free Scanners: Stinger, GetSusp or Malware Cleaner?
Four free tools share an old brand history but do four different jobs. This guide maps the right one to the incident and shows where each scanner stops.
Quick answer: Use Trellix Stinger for targeted detection and repair of threats it explicitly covers; use Trellix GetSusp to find and optionally submit suspicious files when the installed antivirus misses the behavior; use McAfee Security Scan Plus only to assess protection gaps because it can't remove viruses; use McAfee Malware Cleaner for a broader consumer cleanup after backup. Download only from the current McAfee or Trellix owner, verify the digital signature, review report/quarantine settings before deletion, and finish with one current resident antivirus. A clean result from any one of these tools doesn't prove the whole Windows PC is clean.
Short answer: choose by job, not by the McAfee name
Use Trellix Stinger when you need a portable tool aimed at a defined set of prevalent threats. Use Trellix GetSusp when the computer behaves as though it's infected but the installed antivirus finds nothing and you need suspicious-file evidence. Use McAfee Security Scan Plus only to assess whether antivirus, firewall and web-protection gaps exist; it doesn't remove malware. Use McAfee Malware Cleaner for the broader consumer cleanup path, after backing up and accepting that it may change files, registry entries and browser settings.
None of the four is a free replacement for a current resident antivirus. A portable scanner sees a moment in time, Security Scan Plus mostly reports posture, and GetSusp is closer to evidence collection than automatic remediation. Keep Microsoft Defender Antivirus or one properly licensed third-party product providing real-time protection after the incident is over.
Why the names say both McAfee and Trellix in 2026
Search results still call Stinger and GetSusp “McAfee tools” because that's how millions of users learned their names and how old download URLs were branded. The current Trellix free-tools catalog now owns and documents both utilities. Current binaries can still contain McAfee-era file names, folders or certificates, so a mixed label isn't automatically evidence of a fake.
Security Scan Plus remains on McAfee's consumer website, and Malware Cleaner remains part of McAfee's consumer cleanup material. That split matters when verifying a download or seeking support. Stinger and GetSusp should lead to Trellix-controlled pages; Security Scan Plus and Malware Cleaner should lead to McAfee-controlled pages. A random “McAfee Stinger 2026” download portal isn't a safer shortcut.
The four-tool decision map
The most common mistake is to download whichever name sounds strongest. Stinger isn't a full-disk second opinion against every current family, GetSusp doesn't promise to disinfect everything it calls suspicious, and Scan Plus can't remove the threat it warns about. Malware Cleaner has the broadest consumer cleanup intent but also the greatest potential to alter the machine.

If you can't describe the job yet, begin with the resident antivirus's quick scan, then a full scan and finally an offline scan when persistence is suspected. Our malware symptom guide separates infection signals from ordinary crashes, storage pressure and browser-notification spam before another utility is introduced.
Stinger vs GetSusp vs Security Scan Plus vs Malware Cleaner
| Tool | Primary job | Can remove? | Install? | Network role | Main limit |
|---|---|---|---|---|---|
| Trellix Stinger | Targeted detection and repair | Yes, for configured threats | No; portable executable | GTI reputation improves context | Not a full antivirus |
| Trellix GetSusp | Find and collect suspicious files | Not its primary promise | No; portable executable | GTI lookups and optional submissions | Evidence needs interpretation |
| McAfee Security Scan Plus | Assess security posture | No | Yes | Checks protection and web-security state | Reports gaps and recommends products |
| McAfee Malware Cleaner | Consumer malware and adware cleanup | Yes | Run-on-demand executable | Fresh copy needed for current detection | Can change files, registry and browsers |
“Can remove” isn't the same as “safe to run without review.” Stinger's default repair action, high GTI sensitivity and Malware Cleaner's wider cleanup can affect legitimate material after a false positive. A backup and a readable log are part of the tool, even when the interface calls the process one click.
Nor does “portable” mean offline. GetSusp works best with Trellix Global Threat Intelligence lookups, and its normal workflow may upload a report or selected suspicious files. Stinger also uses GTI File Reputation and network heuristics. Download on a known-clean device when the suspect PC can't safely browse, but understand which checks will lose context without a network.
None of these tools replaces real-time antivirus
Trellix states this directly for Stinger: it detects and removes specific threats and isn't a substitute for full antivirus protection. GetSusp is a diagnostic collector. McAfee says Security Scan Plus doesn't remove viruses. Malware Cleaner can remediate an incident, but McAfee says it doesn't update automatically, so an old copy becomes an old snapshot.
Continuous protection watches file creation, process behavior, downloads and other activity between manual scans. Keep one resident product active, not two competing products with overlapping drivers. Our current Microsoft Defender assessment explains when the built-in protection is enough and where a paid suite adds value.
Before running any cleaner: preserve a way back
Back up irreplaceable documents, photos, project files and recovery keys before a removal tool changes the system. Don't back up obviously executable malware into a folder you plan to open casually. A versioned cloud or disconnected external copy helps with ordinary file loss; ransomware recovery requires a copy the infected machine can't rewrite.
Save work and note the current symptoms, detection names, paths and timestamps. Photograph a screen if the machine can't safely make a screenshot, but never publish license keys or personal paths. If a business device contains regulated data or evidence of intrusion, stop improvising and involve its administrator or incident-response owner.
Download only from the current vendor route
Use the live Trellix Stinger page or Trellix GetSusp page, not a software mirror, sponsored result or forum attachment. The current Trellix download directory showed fresh 32-bit and 64-bit Stinger builds dated July 2026 when we checked.
For Security Scan Plus, use McAfee's current assessment page. For Malware Cleaner, follow a link from current McAfee support, legal or product material rather than searching for the executable name. Attackers know that people seeking a virus remover are willing to run an administrator-level file.
Verify the file before granting administrator rights
Right-click the downloaded executable, open Properties, inspect Digital Signatures and confirm the publisher belongs to Trellix/McAfee and Windows reports a valid signature. A familiar icon or file name proves nothing. Microsoft's Sigcheck documentation offers a more technical way to inspect signatures and hashes without launching the file.
Record a cryptographic hash when the vendor publishes one or when transferring a verified file between machines. Don't upload a private suspicious document to a public multiscanner merely to compare hashes; public submission can share the file with security vendors. Signature failure, an unexpected publisher or a browser warning about the download source is a reason to stop, not click through.
Disconnect carefully, not reflexively
Disconnect a confirmed infected machine from ordinary networks when it may be stealing data, spreading laterally or receiving commands. Keep the clean download device separate. If the scan relies on cloud reputation, reconnect only through a controlled network after preserving evidence and understanding what the tool will transmit.
A blanket offline rule can make GetSusp less informative because GTI lookups are central to its design. Conversely, staying online while an infostealer is active can expose more sessions. The right order is risk-dependent: isolate first for active compromise, collect the needed tools safely, then allow only the connectivity required for a controlled scan.
A safe scanner workflow has four gates
Download from the current owner, verify the signed file, scan with a reversible first action and recover through logs and follow-up testing. Those gates matter more than the brand on the button. A cleaner that deletes first and explains later leaves the user unable to distinguish successful remediation from a damaged legitimate application.

Recovery includes more than restoring a false positive. It means confirming the resident antivirus is active, changing exposed credentials from a clean device and testing whether the original symptom returns. The CISA StopRansomware guidance reinforces the value of offline, encrypted backups and an incident plan before a destructive event.
These are Windows tools, not a cross-platform scanner pack
Stinger, GetSusp, Security Scan Plus and Malware Cleaner target Windows. Don't copy the executables to a Mac, Chromebook, iPhone or Android phone and expect a useful scan. Each platform has different application permissions, persistence mechanisms and built-in protection, so a Windows result says nothing about a second device.
For other devices, use the relevant platform path: our McAfee for Mac review, McAfee Android review, McAfee iPhone review and McAfee Chromebook guide explain what a security app can actually inspect. An iPhone browser scare, for example, is usually not solved by a Windows executable.
A USB “rescue scanner” is useful only if the copy is current
A portable executable is convenient for a response drive, but its age matters. Stinger receives new builds, GetSusp depends on current reputation and Malware Cleaner doesn't update itself. Treat the USB as transport for a freshly verified file, not a permanent museum of security tools.
Use a clean computer to replace the executable and record its hash before each incident. Write-protect the drive when practical, and never connect a response drive back to a clean system while autorun-like behavior or unknown shortcuts remain. A bootable rescue environment or Defender Offline is a different tool because it scans outside the suspect Windows session.
High CPU during a scan is expected; a frozen PC isn't
On-demand scanners deliberately read many files and query reputation, so CPU, disk and fan activity can rise. Close heavy applications, keep a laptop on power and allow the first controlled scan to finish. Don't run Stinger, Malware Cleaner and a full Defender scan simultaneously just to save time.
If the UI stops updating, the log stops growing and disk activity remains flat for an extended period, capture the last path and error before forcing a restart. Our McAfee high-resource guide separates normal scan load from a stuck service or repeated background loop.
Managed business endpoints need an approved response path
GetSusp and Stinger both expose ePO-oriented options, but that doesn't authorize an employee to run them on a company laptop. A sample submission can transfer proprietary code or client documents, while rootkit scanning can update components on a Trellix endpoint. The security team should choose the package, command line, submission policy and evidence location.
Preserve chain of custody when legal or disciplinary consequences are possible. Record the hash, acquisition source, operator, time, configuration and output. Consumer advice to “try another scanner” isn't an incident-response procedure for a fleet, and a personal McAfee review isn't a substitute for the organization's endpoint standard.
Trellix Stinger: current status in July 2026
Stinger is active. Trellix's page documents the tool, and its download center was publishing new executables in July 2026. The word “McAfee” persists in old names and paths, but the current vendor identity is Trellix. That current activity is stronger evidence than a download portal's stale version number.
The support matrix on the same page is less current than the binaries: it lists Windows releases through older Windows 10 generations and doesn't make a clean modern Windows 11 promise. Don't turn a fresh file date into an unsupported compatibility claim. GetSusp explicitly lists Windows 11; Stinger should be tested on the exact build, with a recovery point and current vendor notes.
When Stinger is the right tool
Stinger fits a known or strongly suspected threat that appears in its in-app Threat List, a quick targeted check of persistence locations, or a portable response kit where a full suite can't be installed. Trellix says it scans running processes, loaded modules, registry, WMI and malware persistence directories by default to keep the job focused.
It's also useful when a support engineer specifically asks for its log or when an organization already has a documented Stinger procedure. It's a poor first choice for the vague request “scan every byte for every current threat.” A clean Stinger result means its configured engines found nothing actionable in the selected scope, not that the computer is proven clean.
How to run Stinger without turning one click into a gamble
Download the correct 32-bit or 64-bit current build, verify the signature and place it in a dedicated folder so its configuration and logs remain easy to find. Open Advanced settings before the first scan. Confirm targets, rootkit preference, GTI sensitivity and the action on detection rather than accepting a repair default you haven't reviewed.
For an uncertain machine, the conservative first pass is report-only or quarantine where available, followed by review. Trellix specifically recommends report-only when raising GTI sensitivity to High or Very High. Once the detection name, path and file role make sense, remediation can be deliberate rather than automatic.
Stinger's default scan is intentionally narrow
The default targets favor active processes and common persistence locations. That design makes Stinger faster than a full-drive scan, but it also explains why a dormant file in an archive, secondary drive or unusual folder may not be visited. Use Customize my scan when the suspected path is known or the incident involves another volume.
Don't add every mounted backup and network share without thinking. A cleanup tool that repairs or quarantines across shared storage can expand the blast radius of a false positive. Scan the system volume first, review the result, then add a specific location with a reason.
Repair, quarantine and report are different decisions
Trellix says Stinger repairs infected files by default. Repair can mean cleaning content, deleting an object or taking another engine-specific action, so read the log rather than assume the original remains untouched. Quarantine is preferable when a legitimate-looking file needs investigation or easy restoration.
Report-only is the safest discovery mode at aggressive sensitivity, but it doesn't neutralize a live threat. If the machine is actively compromised, keep it isolated while reviewing. Our McAfee scan, quarantine and exclusions guide explains why an exclusion should be narrow, temporary and based on evidence rather than frustration.
GTI sensitivity changes the false-positive tradeoff
Stinger uses Trellix Global Threat Intelligence File Reputation and network heuristics at Medium by default. Higher sensitivity can surface less-certain objects, which is useful during an investigation but raises the cost of automatic action. Treat “suspicious” and “confirmed malicious” as different confidence levels.
When a business executable, unsigned internal tool or newly built utility is flagged, capture the detection name, hash, signature and Stinger log before deleting it. Check the publisher and the file's expected path from a clean device. Don't whitelist an unknown file merely because a workflow depends on it.
Rootkit scanning is available, but not enabled by default
Trellix documents optional rootkit target scanning. Enabling it can update VSCore components on a Trellix-protected endpoint, and Trellix disables the feature in the ePO package by default to avoid pushing that change across thousands of machines. That's a meaningful side effect, not a decorative checkbox.
On a personal PC, use the rootkit option only after backup and when the symptom justifies deeper inspection. On a managed endpoint, follow the administrator's procedure. Microsoft Defender Offline may be the clearer consumer route when the concern is malware hiding while Windows is running.
Stinger logs and quarantine are part of the result
Stinger stores logs by default near the executable and exposes them through its Log tab. Trellix documents quarantine under C:\Quarantine\Stinger. Keep the log until the machine has passed follow-up scans and normal applications have been tested.
A detection screenshot without the path, action and engine message isn't enough to make a recovery decision. Record whether the object was repaired, deleted, quarantined or merely reported. If a system component stops working, that history provides a route to restoration and vendor support.
Why Stinger can miss malware you know is there
Trellix's own FAQ says Stinger only detects specific threats. The file may fall outside the current Threat List, sit outside the selected target, be packed in an unsupported form or rely on behavior that a targeted signature tool doesn't observe. A miss doesn't mean the symptom was imaginary.
Escalate from Stinger to the resident antivirus's full and offline scans, a current second-opinion tool or a clean reinstall when evidence remains strong. Our Windows 11 malware-removal guide covers the full response path instead of chaining random scanners until one produces a scary result.
Trellix GetSusp: current status and purpose
GetSusp is an active, free Trellix diagnostic tool delivered as a single executable. It combines local heuristics with GTI reputation to identify suspicious files that an installed product may not classify. The current vendor page documents GUI, command-line and ePO modes plus Windows 11 support.
Its job is triage and collection, not a promise to disinfect a machine automatically. GetSusp can assemble suspect material, produce reports and submit selected evidence to Trellix. That makes it useful when “something is wrong” but also makes privacy and interpretation central to safe use.
How GetSusp decides what deserves attention
The GetSusp 6.0 product guide says the tool uses heuristics and GTI File Reputation to compare executables, URLs and supported documents with cloud intelligence. It can collect suspicious files into a password-protected ZIP and submit the package for analysis.
Reputation isn't a binary truth machine. A rare internal executable may be unknown because few systems have seen it, while a newly signed malicious file can initially inherit trust signals. Read “unknown,” “suspicious” and “known malicious” as different categories and add path, signature, prevalence and behavior before acting.
GetSusp's scope has precise limits
The guide says GetSusp identifies suspicious executables, URLs and document files, while scripts, media and other formats are unsupported. It also says malware normally needs to be running or associated with a registry startup entry to be identified, and rootkit scanning is unsupported. Those limits explain many clean results.
A three-minute diagnostic scan is useful precisely because it doesn't inspect everything like a forensic image. Use it to find leads, not to certify the device. If browser redirects come from a malicious extension, a scheduled task or an account-side setting outside its scope, the report can be clean while the problem remains.
GetSusp can submit suspicious files, so review the preference first
The product guide says “Submit results to Trellix” and “Report all scanned files” are selected by default in the documented interface. In online mode, report files and selected suspicious material can be zipped and uploaded over HTTPS. Open Preferences before scanning sensitive work, legal, medical or personal documents.
GetSusp allows the user to review identified files and remove material from the archive before upload, or run with submission disabled and share later. That's the safer route when data ownership is unclear. A work device may require approval before any sample leaves the organization, even for security analysis.
GetSusp privacy: the report contains more than a verdict
Trellix documents collection of environment information, installed Trellix product details, execution date and suspected-file data. The report and sample package can reveal usernames in paths, internal application names, document metadata and other context. A password-protected ZIP protects transit handling, but it doesn't erase the decision to disclose its contents.
Review the log and archive from an account with authority to share them. Don't post the ZIP or its password in a public forum. When only a hash or URL is needed, submit the minimum evidence that answers the question rather than the whole suspicious folder.
What to do with GetSusp results
Start with known-malicious classifications, then examine suspicious and unknown objects by path, publisher, signature and relationship to the symptom. A random executable in a temporary startup location deserves more concern than an unsigned tool in a controlled development folder, but neither label alone settles the case.
Preserve the report, isolate confirmed malicious files through the resident antivirus or a supported response process, and rescan after remediation. If Trellix requests a sample, use the tool's controlled submission route. Don't delete Windows components by hand because a reputation category looked alarming.
When GetSusp returns nothing or can't submit
Confirm that the machine has the connectivity needed for GTI lookups, the current executable can write its report folder and the suspected behavior is active. Proxy filtering, TLS inspection or blocked outbound traffic can impair reputation queries and submission. Capture the exact error instead of repeatedly relaunching as administrator.
A clean report may reflect a scope boundary rather than a clean system. Run the resident full scan, examine startup and browser extensions, and consider Defender Offline for persistent behavior. Our McAfee troubleshooting guide covers the installed consumer suite; GetSusp errors belong to Trellix's tool path.
McAfee Security Scan Plus: an assessment, not a virus remover
McAfee's current page defines Security Scan Plus as a free security assessment. It checks whether the Windows PC has gaps around antivirus, online privacy and firewall protection, then recommends ways to strengthen the setup. The same FAQ says plainly that it doesn't remove viruses.
This distinction changes the response to a warning. A red status tile can mean the installed antivirus is disabled, outdated or not recognized; it doesn't prove Security Scan Plus found an infected file. Open Windows Security or the resident product and inspect its own protection status and detection history before buying anything.
What Security Scan Plus actually checks
The tool evaluates key protection areas and can run automatically or on a schedule. It's closer to a posture checker and product recommender than an independent malware laboratory. The useful question is whether its finding identifies a real gap you can verify elsewhere.
Its public compatibility list currently stops at Windows 10 and older Windows releases. Even though users report seeing it on Windows 11, we won't convert installation anecdotes into a current support promise. On Windows 11, the built-in Windows Security dashboard is the primary place to confirm antivirus and firewall state.
Why Security Scan Plus appeared after another download
A live McAfee application page says the user installed Security Scan Plus “as part of your recent software download.” Historically, partner installers offered it alongside unrelated software. That doesn't make the signed McAfee program malware, but it explains why a person may not remember choosing it.
Check Installed apps by install date and review what else arrived that day. Remove unwanted optional software through Windows rather than calling every bundled component an infection. Future installers deserve a custom or advanced path so optional offers can be declined before they become a cleanup task.
Should you keep Security Scan Plus?
Keep it only if its scheduled assessment provides a clear benefit and you understand that it doesn't remediate malware. A current resident antivirus and Windows Security already expose protection status, so many users gain little from another scheduled notification layer. Removing Scan Plus doesn't remove Microsoft Defender or an unrelated antivirus.
Before uninstalling, confirm the exact product name. McAfee Security Scan Plus isn't the same as McAfee Total Protection, WebAdvisor or a paid McAfee+ subscription. Our WebAdvisor guide and complete McAfee uninstall guide cover those separate components.
How to uninstall Security Scan Plus normally
Microsoft's current Windows uninstall guidance starts with Settings → Apps → Installed apps → McAfee Security Scan Plus → Uninstall. If Settings can't remove the desktop program, open Control Panel → Programs → Programs and Features and run its uninstall entry there.
Restart after the uninstaller finishes, then confirm the entry, scheduled task and startup notification are gone. Don't manually delete McAfee folders first; that can leave a broken uninstall registration. If another McAfee product remains, verify it still opens and updates before removing any shared-looking component.
If the uninstall button is hidden, clipped or does nothing
Community reports and a detailed Security Scan Plus uninstall analysis document a high-DPI dialog that can hide or disable the visible button. Try Control Panel, move focus with Tab and activate the selected control with Space, or temporarily reduce display scaling so the full dialog is visible.
If the registration is corrupted, use Microsoft's Program Install and Uninstall troubleshooter. Don't assume MCPR will solve this component; the troubleshooting reference specifically notes that McAfee's general removal tool may not remove Security Scan Plus.
McAfee Malware Cleaner: the current consumer cleanup branch
McAfee's current malware-removal guidance points consumers toward Malware Cleaner after a full scan still leaves infection concerns. McAfee Support also describes it as a free Windows tool for malware, adware, viruses and unwanted pop-ups, available without requiring a paid McAfee subscription.
That makes Malware Cleaner the closest of these tools to a broad consumer “scan and clean” utility. It's still on-demand, not resident protection, and it doesn't automatically update. Download a fresh copy for each incident rather than keeping an old executable on a USB drive for years.
Malware Cleaner can make wider system changes
McAfee Support material says a completed run can delete infected files, change registry entries, reset supported browsers and request a restart. Its official Malware Cleaner walkthrough also describes a pre-change snapshot and an Undo changes option after reboot when changes were made. Verify those controls in the current build before relying on them because support screens can change.
A browser reset can disable extensions, restore search or startup settings and disrupt a customized environment even when saved passwords and cookies are preserved. Export bookmarks and note required extensions first. Read the Summary screen before restarting so you know which changes must be tested or reversed.
How to use Malware Cleaner more safely
Back up, download a fresh official copy, verify its signature, close work and review the license and privacy notice. Start Scan & Clean only when you accept that the tool can alter the system. Stay present for the summary instead of treating the scan like a background speed test.
After restart, test browsers, network access, office software and the application connected to any detection. Use Undo only after recording the summary and understanding the security consequence of restoration. Then run a current resident full or offline scan because one cleaner can't prove persistence is gone.
Don't confuse Malware Cleaner with the Virus Protection Pledge
Malware Cleaner is a tool; McAfee's Virus Protection Pledge is a conditional service and refund promise. The current McAfee legal terms require a qualifying paid product and other conditions, including automatic renewal, for pledge eligibility.
Running the free cleaner doesn't create a refund right, and a cleaner failure doesn't mean every file can be recovered. McAfee's terms exclude important categories of data damage. Backups remain the protection against deleted or encrypted personal files; support service isn't a substitute.
Six real situations and the best first tool
If an administrator names a prevalent threat and Stinger lists it, use Stinger in report or quarantine mode first. If the resident antivirus is quiet but a suspicious process persists, use GetSusp to collect evidence. If Scan Plus only says protection is weak, verify the actual antivirus and firewall rather than running a cleaner blindly.
If a home PC has adware, browser resets and unwanted changes, Malware Cleaner is the McAfee consumer route after backup. If malware returns after removal, use Defender Offline. If files are being encrypted or accounts are actively accessed, disconnect and prioritize incident containment over trying every free utility.
Suspected password stealer: cleanup is only half the job
Disconnect the affected PC, preserve evidence and scan from a controlled state. Stinger may catch a known family, GetSusp may identify suspicious executables and Malware Cleaner may remove associated changes. None can revoke cookies or passwords already stolen before detection.
From a known-clean device, change the email password first, then banking, cloud storage and other high-value accounts; revoke active sessions and add MFA. Our McAfee identity-protection review explains monitoring and recovery services, while the True Key guide covers securing or migrating stored credentials.
Ransomware activity: stop scanning and contain first
If filenames are changing, ransom notes appear or a shared drive is being modified, disconnect network cables and Wi-Fi immediately. Don't keep the machine online to improve a cloud scan. Preserve encrypted files and ransom notes; deleting the payload doesn't decrypt data already changed.
Use a qualified incident-response or restoration process, especially for business systems. A targeted scanner can help identify the family later, but it shouldn't be the first action while encryption spreads. Test backups from a clean environment before reconnecting the original device.
One pop-up says “five viruses”: verify the source first
A browser notification or full-screen page can imitate McAfee without any McAfee program installed. Don't click its phone number, Renew button or Allow prompt. Close the tab or browser, inspect notification permissions and run Windows Security from the Start menu.
Security Scan Plus can also produce genuine assessment alerts, but it still doesn't remove malware. Our McAfee fake-pop-up guide shows the browser, installed-app and subscription checks that separate a web scam from a real product message.
After any detection: read the evidence before declaring victory
Record the detection name, full path, action, hash, time and scanner version. Confirm whether the file was active, quarantined, repaired or deleted. A detection inside a browser cache has a different consequence from a credential stealer launched at startup.
Run a second scan after restart, update Windows and browsers, and test the exact symptom. Review startup items, extensions and scheduled tasks when the problem involved persistence. A quiet desktop after one reboot is encouraging, but it isn't equivalent to a clean follow-up result.
When a legitimate file is quarantined
Don't restore it merely because an application stopped working. Verify the publisher signature, expected install path, source and hash from a clean device, then seek vendor confirmation. A trojanized installer can carry a familiar application name while living in the wrong folder.
If the evidence supports a false positive, restore through the scanner's quarantine interface and submit the file to the correct vendor channel. Add the narrowest temporary exception needed, then remove it after definitions update. Broad exclusions such as Downloads, AppData or the entire system drive create a durable security hole.
If symptoms continue after Stinger or Malware Cleaner
Run the current resident antivirus full scan, then its offline mode. Check whether the symptom is account-side, browser-side or network-side rather than local malware. A changed search engine, compromised email rule or malicious router DNS setting can survive a clean file scan because the problem lives elsewhere.
When multiple supported tools agree the machine is compromised and repair repeatedly fails, a clean Windows reinstall from official media may be safer than endless manual deletion. Back up data, not unknown executables, and rotate credentials from a clean device. Preserve licenses and recovery keys before wiping.
Microsoft Defender Offline is the best built-in escalation
Microsoft's Defender Offline guidance explains that Windows restarts into the recovery environment and scans without loading the normal operating system. That makes it harder for persistent malware to hide or defend itself.
Save work before selecting the offline option because the PC restarts. Results appear later in Windows Security's Protection history. Our dedicated Defender Offline guide covers the preparation, BitLocker key check and result review in more detail.
Microsoft Safety Scanner is the closer portable alternative
Microsoft Safety Scanner is a portable, manually triggered malware-removal tool for Windows. Microsoft says it expires ten days after download, which forces a fresh copy with current security intelligence. Like Stinger, it doesn't replace real-time antivirus.
Use it when a current Microsoft second opinion is preferable to installing another suite. The detailed log lives at %SYSTEMROOT%\debug\msert.log. Don't keep an old msert.exe as an emergency kit without redownloading it.
Keep one resident antivirus, not a stack of competing suites
Portable tools can coexist because they don't remain active in the same way, but installed real-time suites may disable Defender or collide with one another. Choose one resident engine, confirm it's active after cleanup and remove expired trials that no longer provide the protection you think they do.
Our Defender enable/disable guide explains passive mode and third-party registration. If McAfee was removed, verify Defender's Real-time protection, cloud-delivered protection and definitions instead of assuming Windows restored every setting automatically.
Do Stinger and GetSusp conflict with installed antivirus?
They're designed as on-demand utilities and usually run alongside a resident product, but concurrent scans can contend for the same file, increase CPU and trigger mutual detections of quarantined samples. Pause scheduling rather than disabling all protection blindly, and never open a quarantined file to “test” it.
Corporate endpoint controls may block unsigned or unapproved portable executables even when the vendor is legitimate. Don't bypass policy. Ask the administrator to approve the current hash, use the ePO package or collect evidence through the organization's supported endpoint tool.
Community reports show friction, not product prevalence
A May 2026 Security Scan Plus removal thread describes an unwanted companion install and difficulty removing it. Older Reddit and Microsoft discussions repeat clipped uninstall windows and Control Panel workarounds. They help explain what a user sees, but they can't establish how often every installation fails.
We don't repeat “McAfee is a virus” as a technical conclusion. Security Scan Plus is signed vendor software with a current official page, though its bundling and promotional behavior can be unwanted. Criticism is most useful when it names the exact behavior: optional installation, scheduled prompts, diagnostic-only function or broken uninstall UI.
Where to get help without calling a scam number
Use links from the current McAfee Support or Trellix domain and the tool's own signed interface. Never call a phone number from a browser warning, unsolicited pop-up or search ad. Official support doesn't need remote access merely to tell you whether Stinger is a current Trellix utility.
Prepare the tool version, Windows version, signature publisher, detection name, path, action and log. For a paid McAfee account, the plans and renewal guide explains entitlement checks, while the cancellation guide separates billing from malware removal.
When a different vendor's second opinion makes more sense
Using a second engine can be reasonable when the resident product found nothing and the symptom remains, but choose a current reputable on-demand tool rather than installing another full suite. Our McAfee alternatives guide compares resident products by evidence and need; it isn't a recommendation to run several of them at once.
Malwarebytes Free and AdwCleaner are common consumer options for on-demand cleanup, particularly around unwanted programs and browsers. Our AdwCleaner review explains its current scope and quarantine workflow. A second opinion should answer a specific unresolved question, then leave one resident protector in charge.
Final verdict: four useful tools, four narrow promises
Stinger remains a useful targeted remover, GetSusp a useful suspicious-file investigator, Security Scan Plus a limited posture checker and Malware Cleaner the broader McAfee consumer cleanup option. The combined page matters because the brand names hide those boundaries. Choosing the wrong tool can produce a false sense of safety or unnecessary system changes.
Download from the current owner, verify the signature, back up, begin with report or quarantine when confidence is uncertain, and preserve logs. Finish with one current resident antivirus and an offline scan when persistence is plausible. A safe incident response isn't the scanner with the most dramatic name; it's the sequence that contains damage and leaves a recoverable system.
McAfee Free Scanner FAQ
Is McAfee Stinger still available in 2026?
Yes. Stinger is now a Trellix free tool, and the official Trellix download center published current 32-bit and 64-bit builds in July 2026. Download it through Trellix, verify the digital signature and don't rely on old McAfee-branded mirror pages.
Is McAfee Stinger a full antivirus?
No. Trellix says Stinger detects and removes specific threats and isn't a substitute for full antivirus protection. Its default scope is intentionally focused, so a clean result doesn't certify every file or behavior on the PC.
What is the difference between Stinger and GetSusp?
Stinger is a targeted detector and remover for threats covered by its engine and Threat List. GetSusp uses heuristics and Trellix GTI reputation to identify, report and optionally submit suspicious files when an installed product may have missed them; automatic disinfection isn't its primary promise.
Does GetSusp upload files to Trellix?
It can. The documented interface selects result submission by default and can upload report ZIPs and chosen suspicious files over HTTPS. Review Preferences and the candidate archive first, especially on work or privacy-sensitive computers, and disable submission when you lack authority to share the files.
Does McAfee Security Scan Plus remove viruses?
No. McAfee describes it as a security assessment that checks antivirus, online-privacy and firewall gaps, then recommends improvements. Verify warnings in Windows Security or the resident antivirus before treating a posture alert as a malware detection.
Why did McAfee Security Scan Plus install itself?
McAfee's live application page says it may be installed as part of another recent software download. It's an official McAfee product, not proof of infection, but the optional bundle can be unwanted. Review Installed apps by date and decline optional offers in future installers.
How do I remove McAfee Security Scan Plus?
Use Windows Settings under Apps and Installed apps, or Control Panel under Programs and Features when Settings doesn't work. If the uninstall dialog is clipped, use keyboard Tab and Space or adjust display scaling. Microsoft's program uninstall troubleshooter can repair a broken registration; MCPR may not remove this component.
Is McAfee Malware Cleaner free?
Current McAfee support material describes Malware Cleaner as a free Windows cleanup tool that doesn't require a paid subscription. Download a fresh official copy for each incident because the standalone cleaner doesn't automatically update, and keep real-time antivirus afterward.
Can I run Stinger or GetSusp with Microsoft Defender?
They're on-demand portable utilities and commonly run alongside a resident product, but simultaneous scans can compete for files and resources. Keep Defender or one third-party antivirus as the resident layer, avoid opening quarantined samples and follow organizational policy on managed devices.
What should I do if all scanners say the PC is clean but symptoms continue?
Check whether the problem is a browser notification, extension, compromised online account, router setting or ordinary software fault. Then run the resident full scan and Microsoft Defender Offline. Persistent confirmed compromise may justify a clean Windows reinstall and credential rotation from a clean device.