Panda Dome Scans, Quarantine and Exclusions
A detection isn't the end of the workflow. You still need to know what Panda scanned, what it isolated, whether the file is genuinely malicious, and what future protection an exclusion removes. This guide keeps those decisions separate so a false positive doesn't become data loss—and a real threat doesn't become an allowlist entry.

Quick answer: Use Critical areas for a fast first check, Custom for one file/folder, Full for broad disk and memory coverage, and Scheduled scans for routine work. Keep Panda online when practical so Collective Intelligence can classify current threats. Quarantine first; don't restore or exclude until the exact item, source and vendor evidence support a false positive. Panda’s consumer help says default malware removal occurs after seven days, suspicious items may stay pending, and PUP/adware can wait indefinitely. Delete is irreversible; broad exclusions reduce all future protection in their scope.
The safe workflow in one minute
Record the alert before changing anything: detection name, exact path or URL, time, Panda version, action taken and the process that triggered it. If Panda has already quarantined the item, leave it isolated while you verify. Update Panda, choose the smallest scan that answers the immediate question, and save the resulting report. A label without a path and timeline is weak evidence.
Next decide whether the alert is confirmed malware, suspicious pending classification, a potentially unwanted program, or a plausible false positive. Restore only when a trusted source, expected file behavior and vendor/developer evidence align. Delete only when the item is replaceable or backed up and the detection is credible. Create an exclusion only after restoration still produces a known false detection—and make that exclusion as narrow and temporary as possible.
If the alert returns, investigate the source rather than repeating the same button. A scheduled task, browser extension, synced archive, installer cache, USB drive or active process can recreate an item after quarantine. Our Panda review explains why its current false-alarm record makes this disciplined workflow especially important.
Critical areas, Full and Custom answer different questions
Panda’s official Windows scanning help provides three manual routes. Critical areas examines folders most likely to contain active malware and is the fast first pass. Full scan covers disk drives, memory and the broader PC. Custom scan targets a chosen file or folder. Windows Explorer also offers a right-click scan.
| Scan route | Use it when | What it doesn't prove |
|---|---|---|
| Critical areas | Fresh suspicious behavior, quick first response | Every archive, secondary drive or user file is clean |
| Full scan | Broad baseline, post-incident review, unknown scope | Accounts, router, cloud storage and every external device are safe |
| Custom scan | One download, folder, project or mounted device | The rest of the machine is clean |
| Explorer right-click | Fast check before opening a known item | Its action settings match every other scan route |
| Scheduled scan | Repeatable routine coverage | Real-time protection is active between schedules |
Don't run Full by reflex when Custom will answer whether one downloaded installer triggers the same detection. Conversely, don't use one clean custom result to close an incident involving unknown persistence. Choose scope from the question, not from which button sounds strongest.
Manual scans don't replace real-time protection
Panda says its on-access protection scans files that are opened or run, while manual and scheduled scans revisit stored content. A clean manual result therefore means “nothing matched in this scope at this time,” not “the protection stack is healthy.” Confirm Panda is registered as the active Windows security provider, real-time protection is enabled, updates completed and the last scan produced a readable report. Our Windows Defender review explains what should happen to the built-in provider after Panda registers.
Keep the computer connected to the Internet when practical. Panda explicitly recommends this so Collective Intelligence can contribute current cloud classification. That doesn't mean leaving an actively compromised machine free to communicate. If you observe live credential theft, remote control or suspicious outbound traffic, isolate the connection, preserve evidence and reconnect only through a controlled remediation route.
Don't install several real-time antivirus engines to “double-check” at once. Drivers, file locks and competing remediation actions can produce failures that look like infection. A compatible on-demand second opinion is different from two registered real-time providers. Our installation guide covers provider registration and conflict checks.
Schedule scans for coverage you can actually maintain
Panda’s scheduled-scan introduction says the product can run scans automatically by time or frequency. The main scan help adds that scheduled tasks can define frequency, scanned items and exclusions. A useful schedule has a clear scope, runs while the device is normally awake and connected, and leaves enough time to finish.
For a typical Windows PC, real-time protection plus a periodic targeted or full task is more useful than daily full scans that are canceled or collide with backups. Laptops that sleep overnight need a daytime window. Large developer, media or virtual-machine folders may require a separate plan, but excluding them wholesale isn't the default answer.
Review the report after the first scheduled run and after major storage changes. Confirm duration, scanned items, skipped content, detections and whether the task completed. “Scheduled” is only an intention until the machine has actually run it.
Before a Full scan, preserve the things remediation can change
Save open work, connect the laptop to power and pause heavy disk jobs. Verify that important documents have a current backup that isn't merely another synchronized copy on the same account. Record free disk space and update status. If an alert already named a business application or driver, preserve its official installer, version and vendor release information before Panda removes associated files.
Don't manually move the suspected file around the PC, email it to yourself or copy it to several cloud folders. That expands the incident and can trigger repeated detections. Leave quarantine isolated. If the file isn't quarantined, avoid executing it and use a controlled, access-restricted evidence location.
Never upload confidential company files, customer data, private keys or unreleased software to a public multi-engine scanning service. A hash lookup or vendor support case may be appropriate; public file submission can disclose the file to multiple security vendors. The safest evidence package starts with metadata, source and checksum, not indiscriminate uploading.
Read the result as a chain of evidence, not a red badge
Capture the detection family, classification, original path, action, timestamp and triggering process. Then identify whether the item was executed, merely stored, embedded in an archive, attached to email or found on removable media. A quarantined `.lnk` file on a USB drive creates different follow-up work from an executable launched from a user profile at startup.
Check whether Panda says neutralized, quarantined, disinfected, removed, blocked connection or unresolved. These aren't synonyms. A blocked URL request can leave no local file. Quarantine isolates content but doesn't prove the persistence mechanism is gone. Disinfection may modify and return a file. An unresolved item needs escalation rather than reassurance.
Keep one incident log. Multiple screenshots with cropped paths are harder to reason about than a short timeline. If support becomes necessary, the report, hash, source URL, product version and reproducible steps give Panda or the software developer something testable.
Panda quarantine has three documented retention paths
The consumer quarantine help says neutralized threats remain isolated while Panda analyzes them. If classified as malware, the product removes the item automatically after seven days in the default documented flow. Suspicious files remain for a reasonable period while classification continues. Adware and other potentially unwanted programs remain indefinitely until the user decides.
Advanced settings can change automatic malware emptying to three days, one week, one month or never. Panda says that timer applies to detected malware, not suspicious files. A screenshot taken today can therefore show an item that disappears later without a manual Delete. Preserve details promptly if you need to challenge a detection.
Quarantine isn't a backup folder. It's an isolation and decision area controlled by the security product. Don't rely on indefinite retention for the only copy of a legitimate file. If a false positive is plausible, retrieve the official installer or clean source separately and open a vendor case before the retention window ends.
Restore, delete or exclude: use a decision gate

Ask four questions. Is the source trusted and expected? Does the file’s identity match the vendor release? Can the behavior be reproduced without relying on the antivirus label? Has Panda or the developer classified it? If any answer remains unclear, keep quarantine and investigate.
A real threat goes to Delete after the source and persistence are addressed. A verified false positive can be restored, then narrowly excluded only if current Panda classification still blocks it. A potentially unwanted program is a policy decision: even when not classic malware, its bundling, advertising, data collection or system changes may justify removal.
A false positive needs more than “I recognize the filename”
Attackers reuse familiar names and paths. Verify the publisher signature, source domain, file version, checksum from an authoritative release when available, install context and expected network/process behavior. Reproduce on a noncritical test system if the file matters. Contact the software developer and Panda through the official support route; don't rely on one anonymous “safe” reply.
AV-Comparatives recorded 27 false alarms for Panda Free Antivirus 23.0 in its February–May 2026 whole-product test. That doesn't make every Panda alert false. It does mean false-positive handling is a routine operational requirement, especially around development tools, drivers, game utilities and uncommon installers. Our Free versus paid guide keeps that evidence separate from feature upselling.
A community false-positive question illustrates the right instinct—check with the developer or vendor—but doesn't verify any other file. Evidence is item-specific. Preserve the exact hash and detection rather than citing a similar filename.
Restore only after you know what comes back
Panda says Restore returns the file or program to its original location and may also restore associated files used by the program. That can be necessary when a legitimate application was broken, but it increases the scope beyond one highlighted row. Note the original path, close the application and back up important work before restoring.
Keep real-time protection active. Restore, confirm the associated files, and check the live exclusion list before execution. Panda’s consumer help describes exclusions separately; enterprise Panda documentation may automatically list restored items as excluded, but consumer readers shouldn't assume identical console behavior. Verify the actual installed product.
After Panda or the developer updates classification, remove any temporary exclusion, update the product and rescan the exact file plus its parent folder. The workflow ends when protection can remain enabled without hiding a broad path.
Delete is irreversible and can remove associated files
The consumer help warns that Delete can't be undone and also removes associated files. Before clicking, confirm that the detection doesn't belong to a needed signed application, preserve the incident details and make sure a clean installer or backup exists when appropriate. Quarantine buys time specifically so this decision doesn't need to be impulsive.
Deletion also doesn't repair every cause. Remove the malicious download source, browser permission, startup entry, scheduled task, extension, compromised account or USB autorun route that recreated it. Update the operating system and affected application. Then scan the original location and the source media again.
If the deleted item was executed and credentials may have been exposed, scanning is only one track. From a known-clean device, change affected passwords, revoke sessions and review recovery methods. Antivirus cleanup can't invalidate stolen credentials.
Build the narrowest exclusion and give it an expiry
Panda’s advanced settings help permits exclusions for a file, folder or extension. Prefer one exact signed file. A folder excludes everything later placed there. An extension such as a document or executable type can blind scans across unrelated content and is rarely defensible for a home PC.
| Exclusion | Risk | Safer control |
|---|---|---|
| Exact file | Replacement at same path may inherit trust | Verify signature/hash and review after updates |
| Application folder | Any dropped file can avoid scanning | Exclude only the exact component if possible |
| Download/temp folder | High-risk incoming content becomes invisible | Never use as a routine exclusion |
| File extension | All matching files lose coverage | Avoid unless vendor provides a documented case |
| Network/share path | Many users and files can enter scope | Fix permissions/workflow and narrow the target |
Document owner, reason, exact path, detection name, support case and review date. Remove the exclusion after a Panda definition or application update resolves the false positive. An allowlist without an owner becomes permanent security debt.
Advanced scan settings can change both evidence and risk
Panda documents PUP detection, behavioral blocking, behavioral analysis, compressed-file scanning, ask-before neutralization, a cloud-classification execution wait, reports and quarantine retention. It recommends keeping behavioral blocking and analysis enabled. Disabling them to make one application run changes more than the scan result. The paid-plan comparison explains which controls belong to the wider tiers.
Compressed-file scanning has separate on-demand and on-access controls. An archive can appear clean when its contents weren't inspected under the chosen route, then trigger when extracted. Record these settings when two scans disagree. Don't password-protect or repackage a suspicious file merely to bypass inspection.
Ask before neutralizing is disabled by default, and Panda says it doesn't affect Windows Explorer right-click scans. An older community ask-before discussion shows why users want control after driver/tool disruption, but it doesn't establish current false-positive frequency. The cloud wait applies to executable files and can be configured from 10 to 60 seconds, with 30 seconds documented as default.
Repeated detections mean the source or request is still happening
A March 2026 Panda community report describes the same URL alert appearing several times per second immediately after boot. The thread doesn't establish whether the cause was malicious persistence, a legitimate background request or a product defect. It does show why excluding the URL would erase the most useful symptom.
Match alert timestamps to startup applications, Task Scheduler, browser extensions/service workers, notification permissions, DNS/network utilities and recent installs. Inspect the process named in Panda’s event details. Update Panda, reboot once, reproduce with browsers closed and run Critical areas plus a custom scan of the implicated path.
If the file itself returns, check synchronized folders, archives, backup restore jobs, installer caches and removable media. If only the alert returns, capture the destination and initiating process. Escalate with logs when the event continues after the source is disabled; don't randomly delete system files.
A quarantined USB shortcut doesn't close the incident
A community USB `.lnk` case asks whether immediate quarantine means the PC is safe. Isolation reduces immediate risk, but the answer depends on whether the shortcut ran, whether autorun or a script executed, and whether the USB or PC contains a persistence source.
Keep the drive disconnected after evidence is recorded. Scan the PC’s critical areas and relevant user/startup paths, then scan the USB from a controlled system. Show file extensions and inspect unexpected shortcuts rather than opening them. Back up only necessary documents, not unknown executables or scripts, before reformatting infected removable media when appropriate.
Panda’s USB protection and Rescue Kit are valuable but different. USB scanning inspects removable content; a rescue USB boots a machine that can't start normally. Our Cloud Cleaner and Rescue Kit guide covers the recovery route without confusing it with routine quarantine.
Android uses Uninstall, Exclude or Close—not Windows quarantine
Panda’s Android scanning help says Scan now checks installed apps and files after the required permission is granted. When it detects an app, Uninstall is the recommended action. Exclude prevents future scan alerts for that app. Close merely postpones the decision, so the threat appears again later.
Before excluding, verify the app’s Play Store/developer identity, package, signing and install source. A familiar display name isn't enough. Report suspected false positives through Technical support in the Panda Android menu so classification can reach Collective Intelligence.
iOS doesn't expose the same file-scanning and quarantine model as Windows. Don't follow Windows folder-exclusion instructions on an iPhone. Our Android and iPhone security guides separate platform capabilities.
If a scan stalls, diagnose scope before adding exclusions
Record the percentage, elapsed time, current path if visible, disk activity, free space and whether progress truly stopped. Large archives, virtual disks, backups and slow external drives can hold one percentage for a long time. Connect power and avoid forcing shutdown while the disk is active.
Update Panda, reboot, run Critical areas, then custom-scan the parent folders around the apparent stall. Check disk health and Windows errors. Temporarily disconnect nonessential external drives only after safely stopping the scan. Don't exclude the stuck folder until you know whether the cause is corruption, inaccessible permissions, an archive bomb, a product conflict or ordinary volume.
If Panda itself closes, protection won't enable, or resource use remains abnormal outside scanning, preserve logs and move to the troubleshooting workflow rather than weakening scan coverage. A scan-performance issue and a false positive are separate problems.
Escalate to Rescue Kit or Cloud Cleaner when normal scans can't answer
Panda’s Rescue Kit help separates a bootable rescue USB from advanced detection with Panda Cloud Cleaner. Use the bootable route when malware prevents normal startup. Use Cloud Cleaner as a deeper second-opinion/disinfection path when the installed product can't resolve the incident.
Create rescue media on a clean computer, preserve necessary data first and read every deletion decision. An aggressive deep-clean tool can also flag uncommon legitimate content. Our activation and account guide explains why access to product records should be preserved before major recovery work.
Escalate to Panda’s official support form when classification remains unclear, quarantine can't restore a verified file, alerts recur without an identifiable source, or product health fails. Don't call numbers copied from search snippets or pop-ups. Use the official site reached from My Panda or Panda’s own support domain.
Panda Dome scans and quarantine FAQ
Which Panda Dome scan should I run first?
Use Critical areas for a fast first check after a suspicious event, Custom for one file, folder or download, and Full when you need broad coverage of disks and memory. Use a scheduled scan for routine coverage. A machine that can't boot or remains suspicious after normal scans belongs in the Rescue Kit or Cloud Cleaner workflow.
What is the difference between Critical areas and Full scan?
Critical areas targets folders and locations where malware is most likely to be active, so it's faster. Full scan examines disks, memory and broader PC contents and can take much longer. Neither replaces real-time protection, and a full scan doesn't prove every account, browser or external device is clean.
Should Panda Dome be online during a scan?
Yes when practical. Panda recommends an Internet connection so the scan can use current Collective Intelligence cloud classification. If the machine is actively communicating with an attacker, isolate that network activity first and preserve evidence; reconnect only through a controlled remediation workflow.
How long does Panda keep files in quarantine?
Panda’s consumer help says confirmed malware is removed automatically after seven days in the default documented flow. Suspicious files can remain while classification continues, and adware or other potentially unwanted programs can remain indefinitely until you decide. Advanced settings can change malware auto-emptying to three days, a week, a month or never.
Is it safe to restore a file from Panda quarantine?
Only after you establish a credible false-positive case. Verify the exact path, source, signature, expected behavior and vendor evidence. Panda warns that restoration is at your risk, returns the item to its original location and can restore associated program files. Keep real-time protection enabled and rescan after vendor classification changes.
What happens when I delete a quarantined file?
Panda says Delete also removes associated files and can't be undone. Confirm the detection belongs to malware rather than a legitimate application component, preserve a backup or installer where appropriate, and record the detection details before permanent deletion.
How do I exclude a file or folder in Panda Dome?
In the Windows consumer product, open advanced antivirus settings and use Exclusions to add the narrowest exact file or folder. Panda also permits extension exclusions, but those are much broader. Document the reason and review date, then remove the exclusion after the vendor fixes the false positive.
Why does Panda keep detecting the same file or URL?
The source may still be active: a startup item, scheduled task, browser extension, background app, synced archive, installer cache, USB device or repeated network request. Record the exact alert and process, update Panda, run a targeted scan and investigate the source. Don't hide a repeated alert with a blanket exclusion.
What does Panda Dome for Android do after a detection?
Panda’s Android help offers Uninstall, Exclude or Close. Uninstall is the recommended action for a detected app. Exclude suppresses future scans, while Close postpones the choice and the detection returns later. Suspected false positives should be reported through Technical support inside the app.
Can I ask Panda before it quarantines a virus?
The Windows advanced settings document an Ask before neutralizing option for on-access detections, disabled by default. Panda says it doesn't affect scans launched by right-clicking a file in Windows Explorer. Enabling prompts increases the chance of a risky user decision, so use it only when you can evaluate alerts promptly.
Verdict: quarantine buys time—use it
The safest default isn't Restore or Delete. It's isolation while you establish scope and identity. Choose the scan that answers the current question, preserve the report, then decide from the source, path, behavior and vendor evidence.
Restore a verified false positive, delete confirmed malware after addressing its source, and exclude only the narrowest required item with an expiry. When the same alert returns, investigate what recreated or requested it. Hiding the symptom isn't remediation.