We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Trend Micro operations guide · Windows and Mac · Consumer products · Updated August 2, 2026

Trend Micro Scans, Quarantine, Exclusions and False Positives

The Scan button is the easy part. The consequential choices come after a detection: whether to leave a file isolated, delete it, prove it's clean, restore it or create an exception that Trend Micro will ignore next time. This guide keeps those decisions separate, gives each scan a useful job and prevents a possible false positive from becoming a permanent security gap.

Scan choice by incidentRestore only after verificationTemporary narrow exceptions

Safe sequence: update Trend Micro, choose the scan that matches the concern, read the detection name and action in Security Report, then leave an uncertain file quarantined. For a likely false positive, preserve the original path and hash, verify the official source and digital signature, check behavior, and submit it to Trend Micro. Restore only after clean evidence. If an exception is temporarily necessary, allow one exact file or signed executable—not Downloads, Temp, a whole drive or every .exe file—and remove it after reclassification.

Choose the scan that answers the question you have

Trend Micro's current Windows scan guide separates Quick, Full and Custom Scan. Quick checks directories where threats commonly hide. Full examines every file and folder it can reach. Custom focuses on the file or folder you select. None is automatically “best”: the useful scan is the smallest one that still covers the suspected boundary, followed by a broader scan when evidence points beyond it.

Update Trend Micro before comparing results. A detection made with old components and a clean result after an update aren't equivalent observations. Also preserve context: what changed, which download or attachment preceded the warning, whether files were renamed, and whether the alert repeated after restart. The scan is one evidence source inside the wider health check described in our Trend Micro review.

SituationFirst scanWhyNext step
Routine check, no symptomsQuickLikely hiding places with less disruptionReview results; no scan loop
First scan after installFullEstablish a broad baselineSchedule later routine scans
One download or folderRight-click or CustomTargets the known objectVerify source before opening
External driveCustomKeeps scope on that mediaDon't autorun unknown content
Recurring alerts or changed filesFullConcern may cross locationsIncident response if symptoms persist

Use Quick Scan for routine checks and minor concerns

Open Trend Micro and use the arrow beside Scan, then choose Quick Scan. It examines areas where malware commonly hides rather than traversing every accessible file. This is a sensible routine check when real-time protection is active, or after a low-confidence concern such as an unwanted browser download that was blocked before opening. Wait for Scan Results and record both files scanned and threats resolved instead of treating the completion animation as the result.

A clean Quick Scan narrows the evidence; it doesn't certify a downloaded executable, prove a browser account wasn't stolen or inspect every archive on every drive. If the concern is one specific file, verify and target that file. If files changed, the same alert returns or a suspicious process persists, move to Full Scan and incident checks rather than running Quick repeatedly.

Use Full Scan for a baseline or broader incident boundary

Full Scan checks every file and folder Trend Micro can access. Run it after first installation when you want a baseline, after confirmed malware cleanup, or when unrelated symptoms suggest the concern isn't limited to one download. It takes longer and creates more CPU and storage activity. Schedule it for a time when the computer can stay powered and avoid measuring performance while another backup, game update or disk-heavy task runs.

More coverage isn't the same as proof of safety. Targeted malware, account compromise and malicious activity through trusted processes may require other evidence. If Full Scan repeatedly stalls or consumes abnormal resources, preserve the stage and file path before force-closing it; verify the installed build and current components with our Trend Micro setup guide. Don't add the stalled folder to exclusions just to make the progress bar finish.

Use Custom or right-click scanning for a known object

Custom Scan is the right tool for an external drive, a project folder, a downloaded archive or a location another security alert named. Select only the intended path and confirm removable media didn't mount with automatic execution. On Windows, Trend Micro's current scan instructions also support right-clicking a specific file or folder and choosing Scan for Security Threats.

A pre-open right-click scan is useful, but it sees the file as it exists now. An installer can later download components, a document can invoke a vulnerable application, and an archive can contain encrypted or nested content the first check couldn't fully inspect. Verify the source and signer before execution, keep the target application patched and watch the first run. Don't interpret one clean context-menu result as a guarantee about everything the software will fetch.

Trend Micro Quick Full Custom right-click and scheduled scan choices by security situation
Choose the scan by scope. Keep real-time protection active, and don't use repeated scanning as a substitute for verifying an unknown file.

Schedule scans around real use, not anxiety

Current Windows settings expose Scheduled Scans under Settings → Security & Tuneup Controls. The official consumer settings page allows a Quick or Full Scan on a specific schedule. Choose a time when the device is usually on and not under heavy load. A weekly Full Scan that never runs because the laptop sleeps is less useful than a realistic Quick schedule plus deliberate Full Scans after meaningful events.

Real-time protection remains the continuous layer. Scheduled scanning revisits the system with current patterns and broader coverage; it doesn't compensate for turning real-time protection off between runs. Review the last successful scan rather than assuming the calendar entry executed. If the machine belongs to a family member, explain what a detection notification means before an unattended schedule creates pressure to click Restore or Trust.

Don't disable real-time protection to rescue a file

When a program won't run, forum advice often jumps to “turn the antivirus off.” That changes the security state for every process while proving almost nothing about the detected file. Leave the item quarantined, collect its identity and use the restore workflow only after verification. If a controlled test is necessary, use an isolated environment appropriate to the risk—not the everyday computer with banking sessions and synced files.

For one verified business application, a precise temporary exception is narrower than disabling the product. Even then, monitor the first run and remove the exception when a corrected build or Trend Micro reclassification arrives. The Folder Shield guide explains the parallel problem of granting write access to protected data; neither exception mechanism should be widened just to silence prompts.

Read the detection name, action and path before deciding

After the scan, open Security Report and Security Threats. Capture the detection name, original path, time, action and product component. A file that was quarantined, a program blocked by behavior monitoring and a website stopped by web reputation don't share the same recovery route. Search results frequently mix those controls, which is why copying an Apex One quarantine command into a consumer Windows installation is unsafe and usually irrelevant.

Trend Micro's current Windows log guide says Last Scan records show detailed results and actions, while scan records are retained in the backend for one year and can't be manually removed. Preserve the relevant details now. A screenshot should hide usernames, client names and private paths; a text note can keep a sanitized path, hash and detection without exposing personal data.

Quarantine is a holding state, not a verdict

Quarantine isolates a detected object from normal use. Leave an uncertain file there while you investigate. Don't browse protected Trend Micro storage, rename internal quarantine objects or delete random files by hand. Those actions can destroy evidence and make the product's Restore or Delete state disagree with what remains on disk. Use Security Report and the supported controls.

If the file is clearly unwanted and no dependent application needs it, the product's removal action is appropriate after the detection context is understood. If it may be a false positive, don't delete the only recoverable copy before recording its original path, publisher and hash. Quarantine can't repair documents already encrypted or undo a stolen account. When damage exists outside the isolated object, move to incident response rather than debating one file.

Understand File Removed and Suspicious File Blocked

Trend Micro's File Removed page points to More details, the Logs window and Restore for a file the user believes is safe. Its sequence then adds the file to the Exception List. That final step matters: the next scan may ignore the object. Treat the exception as a separate risk decision, not as an automatic companion to every restore.

The Suspicious File Blocked notice is even more explicit: Open File places the item in the Exception List so it won't be blocked next time. Don't click Open merely to inspect it. Verify the source, identity and behavior first. If the prompt followed an unsolicited attachment, crack, remote-support session or unexpected script, keep it blocked and investigate.

Verify a suspected false positive before restore

Start with provenance. Download a fresh copy only from the publisher's authenticated domain or signed update channel. Compare the file name, version, size and published hash when the vendor provides one. On Windows, inspect Digital Signatures and the certificate chain; on Mac, confirm the expected developer identity. A valid signature proves who signed that exact file and whether it changed after signing. It doesn't prove the publisher itself is trustworthy, but a missing or invalid signature on normally signed software is a strong stop signal.

Then check context and behavior. Did you initiate the download? Does the parent process make sense? Does the file create persistence, spawn PowerShell, contact unrelated domains, modify security settings or encrypt documents? One detection on a public multi-scanner may be a false positive, but it can also be the first signal on a new targeted sample. Ten detections don't replace analysis either. Counts are context, not a vote that makes the file safe.

Submit the sample through Trend Micro's current virus-sample route and keep the ticket number. The consumer false-positive page specifically directs users to submit detected files for analysis. Where work can wait, keep the item quarantined until Trend Micro or the original vendor provides a clean reclassified result or corrected build.

Keep confidential files out of public multi-scanners

Don't upload client documents, proprietary executables, licensed software, tax records or files containing personal data to a public analysis service unless policy and ownership explicitly allow it. Samples may be shared with security partners and researchers. A hash search is less revealing but only useful when the exact file has already been seen; changing one byte creates a different hash.

Prefer the software vendor's published hash and signature, your organization's approved sandbox, or Trend Micro's support submission under the applicable terms. If you use a public service for a non-sensitive file, save the report URL and scan time rather than relying on a screenshot of a detection count. Engines update and results can change; the provenance and behavior remain essential.

Trend Micro false-positive verification workflow from evidence and file identity through vendor submission restore and temporary exception
Restoration belongs after source, identity and behavior checks. Stop the false-positive workflow when encryption, account changes or recurring detections suggest an incident.

Restore a verified file on Windows

Trend Micro's current consumer false-positive instructions use this path: open Trend Micro, click Security Report, choose Security Threats, select the file, click Restore, read the warning and confirm Yes. The warning is justified. Restore makes the object available again; it doesn't validate it.

  1. Preserve the record. Save the detection, path, hash, source and time without exposing private data.
  2. Verify identity and behavior. Check official origin, signature, expected hash and what the process attempted.
  3. Submit the suspected false positive. Keep the Trend Micro ticket and the software vendor's response.
  4. Restore only after clean evidence. Don't open it immediately from a security warning.
  5. Retest deliberately. Scan the restored copy and monitor the expected application action.
  6. Remove temporary trust. Delete the exception after reclassification or a corrected build.

If the original path no longer exists or the file is part of a replaced application, reinstall a fresh signed build instead of restoring an old component. If the file reappears after deletion, the alert returns under another path or additional files are affected, stop. That pattern suggests persistence, an updater conflict or an incident broader than one false positive.

Keep the Mac scan and exception path separate

Trend Micro's current Mac scan guide also exposes Full, Quick and Custom choices, but the interface and OS permissions differ from Windows. Don't use a Windows Security Report screenshot as proof of the Mac path. Confirm the installed consumer product and current macOS labels before restoring or excluding anything.

For scan exclusions, the current Mac Exception List path opens Trend Micro Antivirus → Scans → Change Settings → Scans → Edit the List beside File Not Scanned. Add a file, folder or file type with the plus control and remove it with minus. File-type exclusions are especially broad: excluding an executable or document type can hide unrelated threats across many locations, so prefer one exact file or narrow folder when unavoidable.

Add a narrow temporary exception on Windows

Open Trend Micro → Settings → Exception Lists → Programs/folders → Add, then browse to the exact verified item. Trend Micro's July 2025 consumer instructions warn that carelessly added exceptions make the computer more prone to threats. Apply the change, test only the required action and record the owner, reason and review date.

Prefer a single signed executable or exact file. Don't exclude Downloads, Temp, AppData, a user profile root, the whole system drive, PowerShell, a script host or every file with a common extension. A folder exception usually covers everything that later lands there, including an attacker's replacement. If the application updates to another path, verify the new binary rather than widening the old rule.

Don't widen the exception when detection continues

A file can still trigger because its path changed, another helper executable performs the action, a different protection component blocks it or the exception didn't apply correctly. Trend Micro's current article on items still detected after addition says the backend database entry may not be correct and directs users to technical support. Gather Security Report details, component versions, the precise path and a verified sample.

Don't stack file, folder, extension and process exclusions until the warning disappears. That erases the evidence about which control is acting and can expose unrelated data. Remove failed experimental entries, return to a known configuration and escalate with logs. The account and devices guide helps verify the licensed installation before a repair or reinstall.

Switch from false-positive recovery to incident response

Stop restoring when documents are encrypted or renamed, account sessions change unexpectedly, multiple unrelated detections appear, files return after removal or an unknown process creates persistence and outbound connections. Keep suspicious items isolated. Disconnect affected shared storage and sync only when doing so won't destroy evidence, and confirm backup state from a known-clean device before attaching recovery media.

Don't assume a clean scan means the incident is over. Change exposed credentials from a separate trusted device, review account sessions and MFA, and check whether cloud synchronization propagated changed files. Preserve logs and detection names for professional support. Recovery comes after containment and scope, not before.

Close the loop after reclassification or a clean build

When Trend Micro reclassifies the sample or the publisher releases a corrected signed build, update patterns, remove the temporary exception and scan the replacement. Confirm the application works without global trust. Delete old installers and restore points only according to a tested recovery policy; don't erase every artifact before the result and business data are verified.

Review Exception Lists periodically. Every entry should have a recognizable owner, current path and reason. Remove software that no longer exists and rules created for one-time troubleshooting. A short list makes future alerts understandable and prevents yesterday's workaround from becoming tomorrow's malware path.

Scan and recovery completion checklist

  • Current components: Trend Micro finished updating before the scan.
  • Right scope: Quick, Full, Custom or right-click matched the concern.
  • Evidence saved: detection, action, path, time, source and hash are recorded.
  • Unknown stays isolated: no restore happened just to inspect the file.
  • Identity verified: official source, signature, hash and behavior support a clean verdict.
  • Vendor submission: suspected false positives were sent through the current Trend Micro route.
  • Exception is narrow: one exact item, a documented owner and a removal date.
  • No incident signals: encryption, account changes, recurrence and persistence were ruled out.

A green checklist means the decision is traceable, not infallible. Leave room to reverse it. Keep the ticket, remove temporary exclusions and prefer a newly signed vendor build over restoring a questionable old binary indefinitely.

Need a different Trend Micro task? Return to the Trend Micro guide hub for current plans, setup, platform, feature, troubleshooting, billing and removal routes.

Trend Micro scans, quarantine and exclusions FAQ

Which Trend Micro scan should I run?

Use Quick Scan for routine checks of likely hiding places, Full Scan after first install or when detections and symptoms recur, and Custom Scan for a particular drive or folder. Right-click scanning is useful for one downloaded file or folder. Keep real-time protection on regardless of the manual scan you choose.

What is the difference between Quick Scan and Full Scan?

Quick Scan targets directories where malware is most likely to hide and finishes sooner. Full Scan examines every file and folder Trend Micro can access, so it takes longer and creates more disk activity. A Full Scan provides broader coverage but doesn't prove an unknown file is safe.

Is a quarantined file still dangerous?

Quarantine is designed to isolate the detected object so it can't operate normally. Leave an uncertain item there while you investigate rather than opening it or manually searching protected storage. Quarantine reduces immediate access; it doesn't determine whether the detection was correct or restore damaged files.

How do I restore a file removed by Trend Micro?

On current Windows consumer products, open Trend Micro, choose Security Report, open Security Threats, select the item and choose Restore. Confirm only after verifying the file is clean. Preserve the detection name, original path, hash and source first, then submit a suspected false positive to Trend Micro.

How can I tell whether a Trend Micro detection is a false positive?

Verify that the file came from an official source, matches the expected publisher signature or vendor hash, performs the expected task and shows no unexplained parent process, persistence or network behavior. Check the exact detection and submit the sample to Trend Micro. One or two multi-scanner results alone don't prove either safety or malware.

Does restoring a file make it safe?

No. Restore changes where the file is available; it doesn't validate the file. Trend Micro explicitly warns not to restore unless you're sure it's clean. Restore only after collecting evidence, checking identity and source, and preferably receiving vendor analysis or a corrected clean build.

How do I add an exclusion in Trend Micro on Windows?

Open Trend Micro, choose Settings, open Exception Lists, select Programs/folders and add the exact verified file or program with Browse. Apply the change, test it and remove the exception after Trend Micro reclassifies the file or the vendor publishes a corrected build. Avoid broad folders and file extensions.

Why is a file still detected after I added it to the Exception List?

The path may have changed, the application may use another helper executable, the item may be blocked by a different Trend Micro component or the Exception List backend entry may not have applied correctly. Don't keep widening the exclusion. Record the detection component and contact current Trend Micro support with logs and the verified sample.

Should I upload a suspected file to VirusTotal?

Only if the file contains no confidential, licensed, client or personal data and sharing is permitted. A public multi-scanner can add context, but detection counts aren't a verdict. Prefer the software publisher's signature or hash and Trend Micro's official sample-submission route for private or sensitive files.

When should I stop treating a detection as a false positive?

Switch to incident response when files are encrypted or renamed, accounts change unexpectedly, detections recur after removal, multiple unrelated processes trigger alerts or the computer shows unexplained persistence and network activity. Keep items quarantined, isolate affected access and verify backups before restoring anything.

Scan for evidence, restore only with evidence

Use Quick for routine checks, Full for a broad baseline or recurring symptoms, and Custom or right-click scanning when the object is known. Then read what Trend Micro actually did. Quarantine buys time; it doesn't force you to choose between permanent deletion and blind trust in the alert window.

A safe false-positive recovery is deliberate: preserve, verify, submit, restore, retest and remove temporary trust. If encryption, account changes or persistence appear, leave that path and handle an incident. The goal isn't to make the warning disappear—it's to return one clean file to work without teaching the antivirus to ignore the next threat.