TotalAV Scans and Quarantine: Verify Before You Restore
Quick, Full System, Custom and Smart scans answer different questions. This guide turns a detection into a controlled decision: contain it, record evidence, verify without executing, submit a suspected false positive and close any exclusion you temporarily create.

Quick answer: Run Quick Scan for routine high-risk locations, Full System Scan after credible exposure or persistent symptoms, Custom Scan for a chosen file, folder or drive, and Smart Scan when you want a mixed security/privacy/maintenance overview. Leave uncertain detections quarantined. Restore only after source, path, signature, hash and vendor evidence align; use a narrow temporary exclusion only when a verified file must work before the signature is corrected.
TotalAV scan types at a glance
TotalAV's current scan customization guide documents Quick Scan and Full System Scan, while its settings and AV-Comparatives product check also expose custom and scheduled choices. Smart Scan is the front-door overview seen in current product reviews and on Android. The names overlap in purpose but not scope, so “the scan was clean” is incomplete unless the scan type, completion state, date and engine status are known.
| Scan | Best question | Use when | Don't assume |
|---|---|---|---|
| Quick | Are common high-risk locations showing known threats? | Routine check, recent update | Every file was examined |
| Full System | Does broader local coverage find more? | First setup, confirmed threat, persistent symptoms | No malware can exist |
| Custom | Is this selected object or location detected? | Download, USB, project folder | Unselected areas were checked |
| Smart | What security, privacy and maintenance findings need review? | Dashboard overview | All findings are malware |
Choose the scan that matches the incident
Start from the event. A newly downloaded installer from a known publisher calls for source and signature checks plus a Custom Scan. A malicious attachment that executed, a newly found infostealer or symptoms across the machine justify Full System Scan and account-security work. A routine concern without evidence can begin with Quick Scan, while Smart Scan helps inventory unlike categories.

Quick Scan: useful triage, limited scope
TotalAV's current instructions describe Quick Scan as a fast check and estimate roughly five to ten minutes. Treat that duration as vendor guidance, not a promise. CPU, drive speed, file count, archive settings and background activity change the result. A five-minute scan that finishes is more informative than a one-minute scan stopped early, but neither substitutes for the broader scope when exposure warrants it.
Use Quick Scan after a definition update, for a routine concern or as the first triage step while you preserve evidence. Record how many objects were scanned and whether the status says completed. A clean Quick Scan means no detection within the completed scope under the current definitions and settings; it doesn't prove every file, boot component, cloud placeholder or external drive was examined.
Full System Scan: broader, not omniscient
TotalAV calls its System Scan or Full System Scan the more in-depth desktop option and warns it can take a while. Run it after first installation, after a confirmed malicious execution, when Quick Scan finds a threat, or when credible symptoms persist. Finish updates first, connect laptops to power and schedule the work so an avoidable shutdown doesn't produce an incomplete result.
No full scan proves absolute absence. Encrypted archives, unsupported files, offline cloud content, permissions and new evasive threats can limit any engine. If a high-risk incident involved stolen credentials or remote access, scan completion is only one containment step; change passwords from a known-clean device and review sessions as covered in our infostealer protection guide.
Custom Scan: the right tool for a known object
Use Custom Scan when the question has a path: a downloaded installer, email attachment saved to disk, USB drive, shared folder or developer build directory. Select the exact object or location displayed in the current interface. Don't claim an external drive was checked unless it was mounted, selectable and included in the completed result.
Custom scope is also safer for repeat testing after an update because it avoids launching a full machine scan for one file. It isn't permission to execute the sample. A malicious file can remain dormant while scanned and become dangerous when opened; verify it without running it on the production computer.
Smart Scan mixes unlike findings
Current reviews describe Smart Scan as a combination of malware, privacy, security and performance or junk checks. That's convenient for a dashboard overview and easy to misread. A tracking cookie, temporary file, weak setting and quarantined executable don't share urgency. Open the malware section first and keep the maintenance findings in the separate System Tune-Up guide.
On Android, TotalAV's current support says Smart Scan checks potential malware by default and lets the user customize additional items. iPhone is different: TotalAV explicitly says its iOS app doesn't run an antivirus. Use our iPhone security guide for platform-appropriate controls rather than copying desktop scan instructions.
Schedule scans around completion, not anxiety
TotalAV's current schedule page lets desktop users choose scan type, frequency, day and time; older/current surfaces also mention file types, start/end times and exclusions. Schedule at a time the machine is normally on, connected to power and not performing backups, video exports or large builds. A daily full scan that's repeatedly interrupted is less useful than a realistic weekly run plus continuous protection.
Real-time protection and manual scans are different layers. TotalAV's current protection guide says premium real-time protection watches files that are downloaded, used or opened; manual scans review selected scope at a chosen time. Our Free versus paid guide explains why an on-demand clean result doesn't prove continuous background protection.
A stopped scan is incomplete, not clean
TotalAV provides a Stop button during a scan. Use it when the wrong scope was started, the computer is overheating or critical work can't wait, but label the result honestly. Items examined before stopping may still generate detections; unexamined scope has no verdict.
Restart with the appropriate scan when conditions are stable. If every scan stalls at the same file or percentage, record the path, time and resource state instead of repeatedly forcing termination. Preserve logs and use official support rather than deleting the apparent problem file; our malware removal guide explains when a second-opinion or offline workflow is more appropriate.
What TotalAV quarantine means
TotalAV's current quarantine page says a detected virus is moved into its vault, where the item is isolated, and offers restore or permanent deletion. Think of quarantine as containment plus time. The file isn't a working document or executable while isolated, but its presence is still evidence: name, original path, detection, timestamp and surrounding incident help decide what happened.
The vendor's page sometimes uses absolute language about quarantined files causing no further harm. Operationally, keep TotalAV updated and don't manipulate the vault outside the app. If the product is damaged or removed, recoverability may change. Back up irreplaceable clean data and record quarantine details before reinstalling the antivirus.
Review quarantine before Restore or Delete
Sort by incident, not by filename alone. Record the exact original path, filename and extension, detection family, time, file size and the action that preceded detection. Ask whether the file came from a verified vendor, package manager, work system, email, crack, random mirror or browser download. A familiar name in an unexpected folder is more suspicious than the same name in its normal signed location.
Permanent deletion can't be undone through TotalAV. Confirm that the file is malicious or has a trusted recovery source before deleting. Restore only after evidence supports safety; don't restore simply because an app stopped working, and never execute the restored file as the test.
How to verify a suspected false positive
A false positive is a safe file detected as malicious. Start by updating TotalAV and rescanning the quarantined item or a clean copy obtained from the original publisher. Then verify the exact download domain, package version, digital signature and hash. A valid signature raises confidence that the publisher signed those bytes, but it doesn't make every signed program trustworthy or rule out a compromised certificate.
Check whether the publisher acknowledges the hash or detection and whether the file changes on a fresh official download. Don't trust a forum reply that says a filename is “a Windows file.” `rundll32.exe`, for example, is a legitimate Windows name that malware can imitate from another path. The current r/techsupport TotalAV case is useful as a decision example, not proof that every file with that name is safe.
Safe quarantine and false-positive path
Leave the item contained while collecting evidence. Update the engine, verify the source and signature, compare a local hash with known publisher or analysis records and submit the sample to TotalAV. Only then choose restore or delete. If work can't wait after strong verification, use the smallest temporary exclusion and remove it after the vendor corrects the verdict.

VirusTotal: hash lookup first, confidential files never
Multi-engine context can reveal whether several vendors recognize the same hash, but engine counts aren't a jury. New safe software can trigger heuristic labels; new malware can initially show few detections. Search the SHA-256 hash before uploading. A hash lookup shares an identifier rather than the document contents and may already find an existing analysis.
VirusTotal's standard service and Private Scanning are different products. Its published privacy history explains that standard samples may be stored and shared within the security ecosystem. Never upload contracts, tax records, medical files, source code, credentials, private photos or proprietary builds to a public scanner. Use the original publisher, an approved enterprise/private service or TotalAV's submission route.
Submit a false positive to TotalAV
TotalAV's current sample-submission guide accepts undetected malicious files, false-positive files and URLs. For a file, it instructs users to create a ZIP, RAR, 7z or TAR archive and password-protect it with infected, then select the correct submission type and upload it. Include the detection name, product version, source URL, publisher, expected behavior and why you believe the verdict is wrong.
Only submit material you're authorized to share. The password is a handling convention, not encryption strong enough to make a confidential document safe for disclosure. Save the case or confirmation and wait for corrected security intelligence; don't create a permanent broad exclusion because a submission is pending.
Restore only after confidence, then rescan
TotalAV's quarantine page exposes Restore for Windows and macOS and warns to use it only when the file is known safe. Restore to the original location only when that location is appropriate and protected. If the original came from an untrusted mirror, delete it and download a clean current copy from the publisher instead.
After restoration, update TotalAV and scan the exact file again. Verify the application launches and that no companion detections appear, but don't treat successful launch as proof of safety. If the vendor hasn't corrected the signature, isolate the workflow or use the narrow temporary exclusion described below.
Delete when maliciousness or replaceability is clear
Delete an item when evidence supports malware, the file is unwanted, or a trusted clean replacement exists. Preserve incident details first if credentials, remote access or business data may be involved. A deleted payload doesn't reverse information theft or persistence elsewhere.
For personal documents infected by file-altering malware, deleting the only copy may destroy recoverable content. Keep the item quarantined while restoring from a clean backup or consulting a specialist. TotalAV's permanent-delete warning is literal: the vault can't undo that choice.
Every exclusion is a protection gap
TotalAV's scan settings document folders and files excluded from scanning. Microsoft states the general security principle plainly in its current exclusion guidance: every exclusion lowers defenses and should resolve a specific verified problem. The same risk logic applies regardless of antivirus brand.
Prefer an exact verified file over a whole folder, a folder over a drive, and never exclude broad user profiles, Downloads, temporary folders, script types or system directories for convenience. Microsoft's consumer antivirus FAQ likewise says to exclude a file only when you're absolutely sure it isn't infected. Avoid process exclusions unless the vendor documents the semantics; a process exception can affect files that process opens and create a much wider gap than its name suggests.
Create a temporary exclusion with an exit condition
Write down the file hash, path, publisher, reason, approver and removal date. Add the smallest scope only after preserving a clean copy and submitting the false positive. Keep web, behavior and other protection layers active. If the file updates itself, the hash or bytes may change and the original verification no longer covers the new build.
Remove the exclusion after TotalAV updates its verdict or the application vendor ships a corrected build. Rescan the path and inspect the exclusion list monthly. An exception created for one incident shouldn't survive for years as invisible policy debt.
What real community cases can and can't prove
A current r/antivirus Portal 2 case reports game files quarantined and replies treating the event as a suspected false positive. Another user reported a `rundll32.exe` detection after a definition update. These cases show why game updates, system filenames and new signatures need verification; they don't establish TotalAV's overall false-positive rate or authorize restoration on another computer.
Independent measurement is better for rate claims. AV-Comparatives' February–May 2026 Real-World Protection Test reported TotalAV with no false positives in that specific web-threat test, while another test set or local developer build can behave differently. Our current TotalAV review separates test sets and dates. Never turn one result into “TotalAV never has false positives.”
Before the first scan: update, identify the active provider and preserve evidence
Install from the verified account or direct vendor route described in our TotalAV setup guide, then let the application and security intelligence update before judging a detection. On Windows, confirm which antivirus is registered as the active real-time provider; two competing real-time engines can create performance and remediation confusion. Don't uninstall another provider or erase quarantine history until the intended handoff is clear.
If the incident began with a blocked website rather than a local file, preserve the URL and block-page details and follow the WebShield blocked-site workflow. A website allow list and a malware-scan exclusion are different controls. Keep the suspected download contained, disconnect removable media if necessary and record what happened before a cleanup tool or reinstall removes useful evidence.
Keep a small incident record
Record date, device, TotalAV version, definition state, scan type, completion state, scanned-object count, detection, path, hash, source and action. Add screenshots without exposing confidential content. This record makes support useful and prevents a restored file from becoming an unexplained recurring alert.
For a work computer, follow the organization's security team instead of self-restoring or adding exclusions. Central policy, evidence retention and legal duties can override a consumer workflow. Personal users can keep the same discipline in a simple note stored away from the suspected file.
TotalAV scans, quarantine and exclusions FAQ
Which TotalAV scan should I run?
Use Quick Scan for a routine check of common high-risk locations, Full System Scan after a confirmed threat, first setup or persistent symptoms, and Custom Scan for a specific download, folder or removable drive. Smart Scan is a mixed dashboard check that can include malware, privacy and maintenance findings; it isn't automatically a deeper malware scan than Full System Scan.
How long does a TotalAV scan take?
TotalAV says a Quick Scan may take about 5–10 minutes, but hardware, file count, archives, background work and settings can change that substantially. The vendor gives no dependable universal Full System time. Compare scanned objects and completion state, not another reviewer's stopwatch.
Does a clean TotalAV Quick Scan mean my computer is safe?
No. Quick Scan deliberately checks a narrower set of common locations. A clean result means no detection in the scope completed with the current engine and settings. Run Full System Scan when exposure or symptoms justify broader coverage, and remember that no antivirus scan proves the absence of every threat.
What does TotalAV quarantine do?
Quarantine isolates a detected item so it can't be used normally while you investigate. TotalAV lets users restore or permanently delete selected items. Leave an uncertain file quarantined, record its path and detection, update the engine and verify the file before choosing either irreversible deletion or restoration.
How do I restore a file from TotalAV quarantine?
Open Quarantine, select the item and use Restore only after you have strong evidence it's safe. Verify the trusted source, exact path, publisher signature, hash and current vendor verdict first. After restoration, use the narrowest temporary exclusion only if necessary and remove it when TotalAV corrects the detection.
How do I report a TotalAV false positive?
Use TotalAV's official sample-submission route. Its current instructions say to package the file in ZIP, RAR, 7z or TAR format and password-protect it with infected, then identify the submission as a false positive and explain the source and behavior. Don't email or publicly upload a confidential document.
Should I check a quarantined file with VirusTotal?
A hash lookup can be useful without uploading the file. Standard VirusTotal submissions may be stored and shared within the security ecosystem, so never upload personal, confidential or proprietary material. Use the software publisher and TotalAV submission route, an approved organizational service or a private-scanning product when confidentiality matters.
Are TotalAV exclusions safe?
An exclusion is a deliberate gap where scanning is reduced or skipped. Use one only for a verified false positive or documented compatibility need. Prefer an exact file over a folder, a folder over a drive, and a temporary exception over a permanent one; record the reason and remove it after correction.
Can I delete everything in TotalAV quarantine?
Don't bulk-delete until you review filenames, paths, detection names and business value. Permanent deletion can't be undone from TotalAV. Keep uncertain items isolated, preserve evidence and backups, and confirm that an important system, game or work file has a recovery source before deleting it.
Does TotalAV scan iPhone files for viruses?
No. TotalAV's current help explicitly says its iOS app doesn't run an antivirus. Its iPhone tools serve different web, privacy and maintenance roles. Android has a platform-specific Smart Scan, while desktop Quick, Full System, Custom and quarantine instructions shouldn't be copied to iOS.
Verdict: quarantine first, confidence before restore
TotalAV provides the controls a consumer antivirus needs: narrow and broad scans, scheduling, quarantine, restore, permanent deletion and a vendor submission route. The software can't supply the missing context about where a file came from, whether it contains confidential data or why an organization trusts it. That judgment stays with the user or security team.
Choose scan scope honestly, let scans finish and treat Smart Scan's categories separately. Leave uncertain files quarantined, verify without executing, submit suspected errors and make exclusions exact, temporary and documented. A restored file plus a forgotten folder exclusion isn't a solved false positive; a corrected verdict and closed protection gap is.