Bitdefender Free Antivirus checks files and running activity for known malicious behavior, then blocks, removes, or isolates items that match its detection rules. Real-time protection works as the computer accesses files, while a manual scan reads the locations selected by the user. Bitdefender Free Antivirus does not repair unrelated Windows faults or prove that every unfamiliar file is safe. Its result describes what the installed detection engine found during that check.
Live scanning
The protection shield examines accessed files and supported content before the action completes. This catches a file when it opens or runs instead of waiting for a scheduled full scan. The shield can also inspect scripts and supported Office content. A detection can stop the file before the user sees the expected application window.
Real-time protection depends on current threat information and the protection components remaining active. Turning off a shield to make one file run changes the protection state for more than that single click unless the user restores it. A false positive needs review through the detection record rather than a permanent global disable.
Full scans
The documented System Scan path opens Protection, then Antivirus, then Scans. A full pass can take an hour or longer according to the amount of stored data and the computer’s hardware. The first scan may also take longer because Bitdefender Free Antivirus has not yet established the same local scan history.
Stopping the scan early leaves the unread portion unchecked during that run. A completion message does not mean Bitdefender Free Antivirus disinfected every item automatically. The scan log can list unresolved detections that still need a user decision or another removal path.
Custom scans
A custom scan narrows the work to selected folders or drives. It can also use a schedule. This is useful for a download archive or another location that changes often, but it does not replace a system scan when the question concerns the whole computer. Choosing one folder excludes locations outside that selection from that custom job.
Scanning a compressed archive can identify content that the user has not extracted. Deleting or isolating an entire archive can also remove legitimate files stored beside the detected one. The scan log and item path matter before the user treats the archive name as the exact malicious file.
Quarantine
Quarantine separates a detected item so it cannot operate from its original path. The quarantine list keeps the detection name, location, and available actions. Restoring a file returns it to the system, and a protected destination can require administrator permission.
Bitdefender Free Antivirus can create an exception for a restored item. That exception prevents later scans from checking the excluded path in the ordinary way, so it should follow a confirmed false positive rather than convenience. Another setting can permanently delete quarantined files after thirty days. Once that setting removes the only copy, Restore cannot recover it from quarantine.
Manual decisions
Depending on the detection, Bitdefender Free Antivirus can disinfect, delete, or move the item to quarantine. Disinfection attempts to remove malicious content while retaining the file. Delete removes the file, and quarantine keeps an isolated copy. The available action depends on what the engine found; not every infected file can survive disinfection.
A threat that stays active during normal Windows operation may resist ordinary removal. On supported systems, Rescue Environment restarts into a separate removal workflow so the malicious process cannot keep the same Windows lock. This step interrupts the normal session and needs a restart, so unsaved work should not remain open when the user begins it.






