Microsoft Safety Scanner is a portable malware scanner for a manual second check on a Windows computer. The user downloads one executable, starts it, chooses a scan scope, and reviews anything it detects. Microsoft Safety Scanner can remove supported malware found during that run. It does not install a permanent antivirus service, watch new files in real time, filter web traffic, or keep itself ready for the next incident.
A manual check
The scanner is useful when a computer needs an additional on-demand examination or when the normal security interface cannot complete a requested scan. It runs inside the current Windows session and uses Microsoft’s current detection package embedded in the download. Starting it does not disable another antivirus product, though two security scans running at the same time can compete for disk access and make both jobs slower.
Microsoft Safety Scanner is a single downloaded file rather than an installed desktop application. It may not appear in the Start menu after the window closes. Remember the save location if another scan is planned soon. Deleting that executable removes the scanner; there is no normal uninstall sequence because no persistent service remains.
Ten-day expiry
Each copy expires ten days after its download. That limit keeps an old executable from presenting stale detection data as a current scan. When the period passes, Microsoft Safety Scanner requires a new download rather than a small definition update.
This behavior matters for rescue USB drives and support folders. A copy prepared weeks before an incident may launch only to report that it has expired. Download a fresh copy on a clean, connected computer when the affected machine cannot retrieve it safely. Keeping an expired copy does not create background protection during the gap.
Choose the scope
A quick scan examines common infection locations and the active areas most likely to contain running malware. It reduces the wait, but it does not mean that every file on every attached drive received inspection. A full scan reads a much broader set of files and can take considerably longer on large or slow storage.
A custom scan limits attention to a chosen location. That can answer a focused question about one folder or removable drive, but it can miss a component stored elsewhere. Select full scope when the symptom has no clear source and time permits it. If malware keeps returning after removal, repeating the same running-system scan may not solve a threat that hides from the active operating environment; an offline scan or dedicated recovery process may be necessary.
Find the result
Microsoft Safety Scanner shows a result at the end and writes more detailed activity to the msert.log file inside the Windows debug folder. The log can identify what the scanner detected and what action it attempted when the final screen gives too little detail. A detection name describes the threat family or behavior; it does not automatically explain how the file reached the computer.
Removal can affect a file that another component expects, and some actions may need a restart before Windows finishes them. Save open work before a long remediation scan. If a business system depends on the detected file, record the path and detection name before deleting evidence needed for later investigation.
Protection limits
Microsoft Safety Scanner ends its work when the manual run ends. It does not monitor later downloads, apply account protections, or repair every setting a threat changed. Confirm that the installed security product is active after the scan, update Windows, and review browser extensions or startup entries when the incident involved them.
A clean result means the current scanner found no supported detection in the areas it examined. It does not prove that the computer contains no malicious code. Scan scope, current detection coverage, encrypted containers, and inaccessible files all affect what an on-demand scanner can inspect.






