G Data Antivirus watches files and running activity for malware, checks selected storage on demand, and isolates suspicious material in quarantine. It works at the system level rather than cleaning a browser history or tuning performance. The background monitor examines activity as it happens, while manual and scheduled scans read files that may already exist on the computer. G Data Antivirus can block or quarantine a detected file; it does not guarantee that every damaged document can be reconstructed afterward.
Monitor and scans
The virus monitor runs in the background and checks activity without waiting for a full scan. An idle scan uses quiet periods to examine stored material. Manual checks target a narrower question: the complete set of local drives, memory and startup items, a chosen directory, removable media, or a rootkit search.
Those scan types are not interchangeable. Memory and startup checking concentrates on active processes and automatically started components. It does not replace a scan of saved data. A removable-media scan can inspect a USB drive or disc, but G Data Antivirus cannot disinfect a read-only disc because the storage does not permit a write. The detection can still appear in the report.
Inside quarantine
Quarantine stores a suspicious file in an encrypted area where it cannot continue ordinary access to the rest of the system. The file remains in the condition in which the scanner found it. The user can later request disinfection, delete it, or restore and allow it when a behavior detection was incorrect.
Restoring a false positive solves one problem and can create another if the file was actually malicious. Adding an item to the allow list also changes future handling. G Data Antivirus will stop applying the same behavior decision to that item, so the file identity and source need review before an exception becomes permanent.
Cloud decisions
Local scanning does not mean that every decision stays entirely on the computer. Malware checks can send hashes, file size, paths, installation identifiers, and other technical details to G DATA servers for assessment. An optional information-sharing program can transfer suspicious files and associated paths when enabled. The setting can be declined, but that choice differs from turning off the protection engine itself.
Web protection and anti-phishing checks can send visited URLs for reputation assessment. This lets the product block a dangerous destination before a downloaded file starts. It also means that enabling those modules changes what connection information leaves the computer. A user who needs a strict privacy boundary should review those modules rather than assume that an antivirus scan only reads local bytes.
Updates matter
Signatures describe known malicious patterns, while behavior monitoring looks for suspicious actions. G Data Antivirus updates its detection material and program components regularly. A computer kept offline for a long period can still run a scan, but its signature set cannot know about threats added after the last successful update.
A high-priority scan can consume enough processor and storage activity to slow other work. Scheduling larger checks outside active hours reduces that collision. Pausing a scan postpones completion; it does not turn the partially examined files into a clean bill of health. The final result only describes the areas that G Data Antivirus actually reached.






