Webroot scans, quarantine and schedules
The “right” scan depends on which Webroot app is installed and what you're trying to prove. Match the scan to the question, understand why a schedule can move, and treat quarantine as a safe holding area rather than a delete button.

Fast answer: SecureAnywhere for Windows normally uses Deep for routine scans and offers Quick, Full and Custom choices. Total Protection for Windows instead exposes Quick, System, Full and Custom. Both schedule daily scans; Mac has fewer manual choices. If Webroot detects something, leave it in quarantine until the file is verified. Deletion is permanent, while restoration can suppress later detection.
Choose the scan that answers the current question
Start with the problem, not the biggest-sounding button. A quick active-area check is useful after an uncertain download or when you need an immediate status. The edition's normal daily scan is the practical routine. A full scan earns its extra time when another tool reported a problem, several partitions or connected drives matter, a quick scan didn't clear a warning, or dormant files need broader coverage.
A custom scan is better when the suspicious location is known. Scanning one downloaded folder, archive or removable drive gives a faster, more interpretable result than repeatedly launching a broad scan. It doesn't replace real-time protection or the scheduled scan, because malware can load from places outside the selected path.
Don't run Webroot and another real-time antivirus scan simultaneously just to feel more certain. Two scanners can compete for the same files, distort performance and make a “stuck” diagnosis meaningless. If a second opinion is justified, finish the first scan and use a trusted on-demand method afterward.
The seven-step sequence below works across editions while leaving the product-specific buttons to their own sections.
Identify SecureAnywhere or Total Protection
Read the installed product name and operating system before choosing a scan. SecureAnywhere and Total Protection use different scan labels, and their Mac versions expose fewer manual choices than Windows.
Choose the narrowest scan that answers the question
Use Quick for an immediate active-area check, the edition's normal Deep or scheduled scan for routine coverage, Full for all local files or drives, and Custom for a known folder or file.
Run the scan without starting a second real-time antivirus
Launch the scan from SecureAnywhere's main page or Total Protection's Virus Protection panel. Let one security product perform the active scan and keep the device powered and connected.
Set a schedule that the device can actually meet
Choose a time when the computer is normally awake and plugged in. Review missed-scan-at-boot, battery, full-screen and one-hour randomization controls before treating a delayed scan as a failure.
Review the final status, report and scan log
Check duration, scanned items, detections and pending actions. Save the scan log before changing anything when Webroot Support may need to diagnose an unexpected detection or failed scan.
Leave an uncertain item contained in quarantine
Quarantined items are disabled. Keep an uncertain file contained while you verify its publisher, origin and classification; don't restore it merely because an application stopped working.
Restore or delete only after verification
Restore only a confirmed legitimate file and understand that SecureAnywhere may stop detecting the restored item. Permanently delete only a confirmed threat because deletion can't be undone.
SecureAnywhere and Total Protection use different scan names
Webroot's current support library covers both the classic SecureAnywhere interface and the newer Total Protection application. The names overlap but don't map one-to-one. Read the installed product name before following a screenshot or assuming that “System” and “Deep” are equivalent.
| Scan | SecureAnywhere for Windows | Total Protection for Windows | Best use |
|---|---|---|---|
| Quick | Surface scan of active memory; may miss inactive malware | System files and files active, queued or likely to load in memory | Fast immediate check |
| System | Not the documented consumer scan label | System files only | Focused operating-system check |
| Deep | Analytical broad-threat scan; normal main-panel/tray default | Not the current manual label | Routine SecureAnywhere coverage |
| Full | All local hard drives | All files on the system; may exceed an hour | Partitions, dormant files, suspected infection |
| Custom | Selected files and folders | Selected files and folders | Known download, folder or drive |
SecureAnywhere on Mac defaults to Full. Total Protection on Mac also offers only Full as a manual scan; its Realtime Shield supplies continuous protection in the background. A quick Windows tutorial should therefore never be copied verbatim to a Mac.
These are logical coverage modes, not promises that every run reads every byte on a drive. Webroot combines file, memory, behavior and cloud classification. Duration alone can't prove that the wrong scan ran.
Run an immediate scan in Webroot SecureAnywhere
For the normal SecureAnywhere scan, open the application and choose Scan My Computer. Windows also exposes Scan Now when the tray icon is right-clicked. Webroot's current scanning article says the Windows default is Deep, while the Mac default is Full.
To choose a different Windows type, open SecureAnywhere, select the gear beside PC Security and choose Custom Scan. The official scan-type guide presents Quick, Full, Deep and Custom in that window. Choose the type, add a path when using Custom and start the scan.
A manual scan opens a progress window. Hiding that window doesn't cancel the scan. Scheduled scans can run silently, which explains why the computer may show a recent scan even though no large window appeared.
If a Quick scan follows an earlier infection and the main screen stays red, Webroot says a Full or Deep scan may be needed to clear the condition. Don't keep repeating Quick and assume the color is only cosmetic; review the pending detection and use the broader supported scan.
Run Quick, System, Full or Custom in Total Protection
Open Total Protection, select Virus Protection and choose the required scan. The current Total Protection instructions list Quick, Full and System from the manual screen; the detailed scanner panel also documents Custom for selected folders and files.
Quick focuses on likely active areas. System narrows the work to system files. Full covers all files and can take more than an hour depending on used storage. Custom is the precise choice when a download, project folder or mounted location is the concern.
Total Protection for Mac has only a manual Full Scan. The application describes continuous checking through Realtime Shield as the standard background layer rather than a separate manual “standard” button. Don't disable that shield simply because a Full scan is running.
The progress view shows elapsed time and detections. A Full scan can be cancelled, but cancellation doesn't establish that the files already checked were clean enough to answer the original question. If the scan was started because infection was suspected, rerun it at a time the device can stay powered.
Use Full Scan when the extra breadth changes the decision
Webroot recommends considering Full when Quick failed to find a suspected infection, several partitions are in use, programs or data haven't been scanned recently, another antivirus flagged a problem, or a dormant threat is plausible. A broad scan is also reasonable after a confirmed detection to make sure the cleanup didn't leave related material.
In Total Protection, open Virus Protection and Start full scan. After completion, choose View to inspect results; the final report lists scan time, file count and threats. Webroot's Full Scan guidance warns that large data sets and connected drives can extend the run to several hours.
“Full” still describes the product's supported coverage logic. It isn't a forensic sector-by-sector disk image, a guarantee that an encrypted archive was opened, or proof that a boot-time threat can't exist. If symptoms continue after a clean result, preserve logs and use support or a trusted offline/on-demand escalation rather than endlessly repeating the same scan.
A full scan every day is rarely the best way to fix uncertainty. Keep real-time protection and the product's normal schedule active; add Full when it answers a specific risk or post-detection question.
Use Custom Scan for a known file, folder or drive
In SecureAnywhere for Windows, open PC Security, Custom Scan, select Custom and add the file or folder. In Total Protection, use Virus Protection's Custom option. Choose the smallest location that contains the item and include the enclosing folder when an archive or installer creates several files.
A targeted scan is useful for a download, a USB drive, a project received from another person or a directory that triggers suspicious behavior. It's also easier to reproduce: the same path can be rescanned after an updated classification without consuming the time of a full-disk run.
Don't restore a quarantined item merely so it can be custom-scanned again in its original location. Leave it contained while checking the publisher and official classification. The next false-positive spoke owns the full allow/block and submission workflow; this page keeps the immediate quarantine decision safe.
If Custom returns clean but the application still behaves suspiciously, the concern may involve a process, script, browser extension or another path outside the selected folder. Run the edition's normal broader scan and review real-time detections rather than treating a narrow clean result as a whole-device verdict.
Set a reliable SecureAnywhere scan schedule
SecureAnywhere normally schedules a daily scan near the time it was installed. To change it, open Advanced Settings, Scheduler and Scan Schedule. The official schedule guide exposes frequency, time and behavior controls.
Choose a time when the computer is normally awake. “When resources are available” generally means the scan can begin within an hour rather than at the exact minute. The randomization option can also shift a scheduled scan by up to an hour to use resources more efficiently.
Review four suppressors: scan after boot when the computer was off at the scheduled time; avoid battery power; avoid a full-screen application or game; and hide the progress window. These settings explain most reports that Webroot ran unexpectedly after login, never appeared on screen or skipped a laptop session.
SecureAnywhere offers a scheduled Quick instead of Deep. Webroot recommends leaving that option deselected so scheduled Deep scans search across threat types and locations. A user can still launch Quick manually when a fast check is appropriate.
Disabling scheduled scans removes an important verification layer and shouldn't be a performance shortcut. Move the time, use the battery/full-screen controls and investigate abnormal load first. The Webroot review discusses where lightweight operation is a strength and where independent protection evidence needs context.
Schedule Total Protection from Virus Protection
Total Protection runs scans every day according to Virus Protection → Schedule. The current scanner panel says Scheduled Scan defines when a Full scan occurs and whether its progress window is visible or hidden. Summary Report has a separate schedule for automated reporting.
Pick a plugged-in window when large storage and connected drives can remain available. If the job is a Full scan, don't schedule it at the same time as backup, system optimization or another security scan. Separating heavy tasks makes performance predictable and keeps a slow scan diagnosable.
Total Protection for Mac provides the manual Full option and a simplified scanner interface. The background Realtime Shield remains responsible for standard continuous protection. On a Mac that sleeps overnight, schedule around actual awake time rather than assuming the task will run while the lid is closed.
Use Reports to verify that the schedule produced completed activity instead of relying on memory. A hidden progress window is a presentation choice; report history and the next-scan state are the evidence that the job ran.
A late, missed or surprise scan is often a schedule rule
First compare Last Scan, Next scan and the configured time. SecureAnywhere says Next scan is generally 24 hours from the last manual or automatic scan, so launching a manual check can move the displayed countdown. That's different from the scheduler service being broken.
If the computer was off, a scan-on-next-boot option can trigger within about an hour after startup. If the laptop was on battery or a game/movie occupied full screen, the skip controls can defer the run. Resource-aware and randomization settings can add their own one-hour window.
When no completed scan appears after the device stayed awake beyond those windows, confirm that scheduled scanning remains enabled, restart Webroot and the device, and launch a manual normal scan. Save a scan log before reinstalling or resetting settings. The complete uninstall guide should be used only after ordinary schedule and support checks fail.
Don't infer a missed scan solely from a missing pop-up. SecureAnywhere scheduled scans and Total Protection scans with hidden progress can run silently. The report, last-scan timestamp and threat state are stronger evidence.
Read the result, pending actions, reports and scan logs
SecureAnywhere's main interface lists Last Scan, duration, Next scan, Total scans, Threats removed and subscription time. A green state means no current intervention is required; yellow or red can mean a potential threat, critical item or unresolved shield state. Read the actual message instead of treating every color as the same malware result.
Total Protection uses green for secure, orange for scans with pending actions and red for disabled shields. Its Reports view can separate Realtime, On-Demand, Application and Web Threat Shield findings across summary, pie and history views. Open the page icon beside a report to see details and available quarantine actions.
For SecureAnywhere, save the latest log from the Windows tray menu with Save a Scan Log or from Utilities, Reports in the full interface. On Mac, use Utilities, Reports, Save Scan Log. Webroot's log instructions describe it as useful evidence for support.
Save the log before restoring, deleting, resetting detection rules or reinstalling. Include the scan type, start time, duration, product edition and operating system in a support ticket. A screenshot of “0 threats” without those details can't explain a scan that stopped early or checked the wrong scope.
Quarantine is the safe default, not an emergency to empty
Webroot says quarantined items are disabled and can't harm the computer while contained. Its SecureAnywhere quarantine guidance doesn't recommend routine deletion. Compression limits storage use, while retention preserves the option to recover a false positive or support analysis.
| Action | When it fits | Main consequence |
|---|---|---|
| Leave contained | Uncertain classification or no operational need for the file | Item remains disabled and recoverable |
| Restore | Publisher, origin and classification confirm a legitimate file | Returns to original location; SecureAnywhere may stop detecting it |
| Exclude & Restore | Verified legitimate Total Protection detection requiring an exclusion | Restores and creates a scanning exception |
| Delete permanently | Confirmed threat with no diagnostic or recovery value | Can't be undone; Webroot recommends support guidance |
On SecureAnywhere for Windows, open PC Security and Quarantine. On Mac, open Mac Security and Quarantine. Total Protection exposes Quarantine from Virus Protection and can offer Manage Quarantine from report details. Select the exact record rather than clearing everything in bulk.
Test whether legitimate programs still work while the uncertain file remains contained. If a program fails, that's a reason to investigate the item—not proof that it's safe. Malware can be bundled with a legitimate-looking installer or required by a compromised application.

After a detection, preserve evidence and confirm cleanup
When SecureAnywhere recognizes a threat, it normally moves the item to quarantine and runs another scan. If it asks about an unfamiliar item, Webroot recommends blocking it when uncertain. Don't uncheck removal merely because the filename resembles a program you use.
Record the detection name, original path, scan type and time. Let the follow-up scan complete, then check that the interface no longer shows pending action. A detection in a browser cache, download folder and system location can require different follow-up even when the threat name is the same.
If credentials may have been exposed, change them from a known-clean device after containment, starting with email and password-manager access. Review active sessions and multi-factor settings. An antivirus quarantine doesn't reverse data already sent to an attacker.
Run the broader supported scan when the initial detection came from Quick or a narrow Custom path. If symptoms continue, save logs and contact official support. Repeated restore-and-rescan cycles can hide the evidence that classification or cleanup is failing.
Treat a possible false positive as a verification job
Don't restore solely because an application stopped launching. Verify the file's original download source, digital signature, publisher and version. Compare its hash only through a trusted vendor or analysis process that doesn't expose confidential files. Keep the item in quarantine during that work.
SecureAnywhere says a restored item will no longer be detected during later scans unless its detection rules are changed. Total Protection can combine Exclude & Restore. That makes restoration a policy decision, not a harmless preview.
Use the dedicated false-positive spoke for allow/block controls and submitting a mistaken classification once it's published. Until then, preserve the scan log and use official Webroot support. Don't create a broad folder exclusion to rescue one unverified executable.
When a business-critical file is involved, obtain a clean copy from the publisher and test it in a controlled environment. The fact that many users need the same file can increase urgency, but it doesn't establish safety.
Diagnose a slow, stuck or high-CPU scan before disabling protection
Confirm the scan type and current file. A Full scan across large drives can run for hours; a Deep or Quick scan has a different baseline. Connected drives, large archives, development dependency trees and another backup or antivirus job can extend the same phase.
Keep the computer plugged in, close unnecessary heavy applications and stop any second manual security scan. Don't disable Realtime Shield as a generic speed fix. If the progress count continues changing, allow the run to finish and compare its duration with the next scan under similar conditions.
If progress and the scanned-file count don't change for an extended period, capture the screen, save a log if available, note the path and cancel only when the edition supports it. Restart, update through the official application and run a normal scan once. Repeated freezes at the same file are more useful to support than a vague “high CPU” report.
Check the schedule for a missed-scan-at-boot surprise or overlap with optimization, backup and game launch. The pricing and renewal guide and plan comparison help identify which extra components might be scheduled in the installed bundle.
If the app itself is corrupted, use the verified installation guide and preserve the account/keycode details before reinstalling. Don't jump to cleanup tools while an active detection remains unresolved.
Give Total Protection for Mac the Full Disk Access it needs
Webroot says Total Protection for Mac requires Full Disk Access to scan files and quarantine threats effectively. If the app reports limited access or a Full scan can't cover expected locations, open System Settings, Privacy & Security and Full Disk Access.
Enable the current Webroot Total Protection entry, authenticate with Touch ID or the Mac password and allow the app to quit and reopen. If the entry is missing, add the official application from the Applications folder. Webroot's current Mac permission guide documents that sequence.
Full Disk Access is powerful. Confirm that the app came from the verified Webroot account or installer before granting it. A similarly named download from a search advertisement shouldn't receive system-wide file access.
Classic SecureAnywhere and Total Protection have different interfaces, so match the product name before looking for the same buttons. If a permission remains unavailable under a managed Mac profile, the organization administrator must change the policy.
Webroot scan, schedule and quarantine FAQ
What is the difference between a Webroot Quick, Deep and Full scan?
In SecureAnywhere for Windows, Quick checks active memory, Deep is the normal analytical scan for broad threat types, and Full checks all local hard drives. Total Protection uses Quick, System, Full and Custom instead. Don't translate the names between editions as if their buttons and scope were identical.
Does Webroot run scans automatically?
Yes. SecureAnywhere and Total Protection currently document daily automatic scanning. SecureAnywhere normally schedules near the installation time, while Total Protection uses Virus Protection > Schedule. Battery, full-screen, missed-boot and resource-aware settings can change when the scan is actually observed.
How do I run a full scan with Webroot?
In Total Protection, open Virus Protection and choose Start full scan or Full Scan. In SecureAnywhere for Windows, open PC Security, choose Custom Scan and select Full. SecureAnywhere for Mac and Total Protection for Mac use Full as their manual scan type.
Why did my scheduled Webroot scan run late?
A resource-available choice or the randomize-by-up-to-one-hour setting can delay the start. The scan can also wait after the computer was off, skip battery power or wait until a full-screen application closes. A manual scan may reset the Next scan timer, so review the schedule before assuming the service failed.
Can I use the computer while Webroot is scanning?
Usually yes. Scheduled scans can run silently and can be configured to avoid full-screen work or battery power. If performance is poor, don't run a second antivirus scan simultaneously; note the current file, elapsed time and scan type, then use the troubleshooting checks in this guide.
Is a quarantined file still dangerous?
Webroot states that quarantined items are disabled and can't harm the computer while contained. Leaving an uncertain item in quarantine is safer than restoring it. Permanent deletion isn't required for containment and removes the option to recover a false positive.
Should I delete everything in Webroot quarantine?
No. Webroot doesn't recommend routine deletion of quarantined items. Keep them contained until programs have been tested and the classification is clear. Delete only a confirmed threat when recovery is unnecessary, because permanent deletion can't be reversed.
How do I restore a file from Webroot quarantine?
Open the edition's Quarantine view, select the item and choose Restore. In Total Protection, report details can offer Exclude & Restore. Restore only after verifying the file; SecureAnywhere says a restored item will no longer be detected during later scans unless its detection rules change.
Where are Webroot scan logs?
SecureAnywhere on Windows exposes Save a Scan Log from the tray menu and also through Utilities > Reports in the full interface. On Mac, use Utilities > Reports > Save Scan Log. Total Protection stores reports under Virus Protection > Reports with summary, history and detail views.
Why can Webroot not scan every file on my Mac?
Total Protection for Mac needs Full Disk Access to scan and quarantine effectively. Open System Settings > Privacy & Security > Full Disk Access, enable the current Webroot Total Protection entry, authorize the change and allow the app to quit and reopen. Don't grant access to an installer from an unofficial source.
Bottom line: scan with intent and leave uncertainty contained
Identify the edition before choosing Quick, System, Deep, Full or Custom. Set the daily schedule around the device's actual awake and powered hours, then use reports and logs—not pop-up memory—to confirm that it ran.
When Webroot finds something, quarantine buys time safely. Verify before restoring, delete only when the threat is confirmed and recovery is unnecessary, and preserve evidence whenever the scan or classification behaves unexpectedly.