Antivirus alerts - what to do
Summary
This guide helps you troubleshoot and resolve: Antivirus alerts - what to do. Follow the steps below to fix the issue.
Quick Tip: Need immediate assistance? đź’» Open a Ticket
Common Causes
Understanding Antivirus Alerts
Note: The steps in this article apply to both Windows 10 and Windows 11. Where the user interface differs, the description highlights the variation.
What are they?
Windows Security (built into Windows 10/11) protects your computer from viruses, malware, ransomware and other threats. When it detects a risk, it displays an alert.
Types of alerts
- Virus detected – malicious software found.
- Threat blocked – dangerous activity was stopped.
- Firewall blocked an app – an app tried to access the network.
- Suspicious activity – something looks wrong.
- Ransomware protection – Windows detected ransomware behaviour.
- Controlled Folder Access alert – an app attempted to modify a protected folder.
What to Do When You See an Alert
If it says “Threat detected” or “Virus detected”
- Do not panic. The alert may already have blocked the threat.
- Click the alert to view details.
- Follow the recommended action:
- Quarantine – isolate the file (recommended).
- Remove – delete the file completely.
- Allow – only if you are certain the file is safe.
- Run a full scan to ensure no further threats remain.
If Windows deletes a file
- The file was likely malicious.
- Check the Recycle Bin only if you must recover it, but be aware this can re‑introduce the threat.
- In most cases, it is safer to let Windows keep the file removed.
Warning: Restoring a deleted file without confirming it is safe may lead to re‑infection.
If a program is blocked by the firewall
- Determine whether the program was attempting to access the internet.
- Confirm if the program was recently installed.
- If the program is trusted, you can allow it through the firewall.
- Open Settings > Privacy & security > Windows Security.
- Select Firewall & network protection.
- Choose Allow an app through firewall and adjust the settings as needed.
Ransomware or Controlled Folder Access alerts
- Read the alert details to identify the blocked app or file.
- If the app is trusted, add it to the Controlled folder access – Allowed apps list:
- Open Settings > Privacy & security > Windows Security.
- Select Virus & threat protection > Ransomware protection.
- Click Manage ransomware protection, then Allow an app through Controlled folder access.
- If you are unsure, keep the block in place and contact your IT support team.
Submitting a suspicious file to Microsoft for analysis
- Open Windows Security > Virus & threat protection.
- Click Protection history.
- Locate the file in question, then select Submit sample.
- Follow the on‑screen prompts to send the file to Microsoft.
Temporarily disabling real‑time protection for troubleshooting
- Open Settings > Privacy & security > Windows Security.
- Select Virus & threat protection.
- Click Manage settings under Real‑time protection.
- Toggle Real‑time protection to Off. Remember to turn it back On when finished.
Note: Disabling real‑time protection reduces your security posture; only do this for a brief, controlled test.
Running a Manual Scan
Quick scan
- Press
Win + Ito open Settings, then select Privacy & security. - Choose Windows Security > Virus & threat protection.
- Click Quick scan.
Full scan
- Navigate to the same location as for a quick scan.
- Select Scan options.
- Choose Full scan and click Scan now.
- Allow 30–60 minutes for the scan to complete.
Note: Keep your virus definitions up to date via How to update Windows or by selecting “Check for updates” in the Virus & threat protection settings.
If You Think It’s a False Alarm
- Was the file downloaded from the internet?
- Was it attached to an email?
- If you are unsure, search the filename online.
- You can submit the file to Microsoft for analysis (see “Submitting a suspicious file to Microsoft” above).
Common False Positives
- Legitimate programmes that modify system files.
- Cracked software.
- Very old applications.
- Unusual file names.
How to View Quarantined Items
- Open Windows Security > Virus & threat protection.
- Click “Protection history”.
- Review the items that were blocked or quarantined.
Best Practices
- Keep Windows Security turned on.
- Do not install two antivirus programmes simultaneously; they can conflict.
- Keep Windows updated – see How to update Windows.
- Avoid clicking suspicious links in emails.
- Download software only from trusted sources – see How to protect your PC with built‑in Windows Security features.
- If performance slows, refer to Computer running slow.
Installing a Third‑Party Antivirus
Windows Security provides comprehensive protection for most users. If you choose to install another antivirus solution, Windows Security will automatically disable its real‑time protection while the third‑party product is active; you can re‑enable Windows Security after the third‑party product is removed.
- Ensure the new antivirus is approved by your organisation – see How to manage software licences and avoid compliance issues.
- After installation, run a full scan with the new product.
- Consider using Windows Defender Offline scan for stubborn or boot‑time threats.
Tip: An offline scan can detect malware that hides when Windows is running.
When to Get Professional Help
- You cannot remove a threat.
- Your computer behaves unusually.
- You are unsure whether a file is safe.
- Alerts continue to appear despite following the steps above.
If you need assistance, open a ticket.
Still Having Issues?
Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.
đź’» Open a Ticket
đź’» Open a Ticket