Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start by checking which antivirus is protecting the PC, then run a scan in Windows Security and review Protection history. If you still suspect compromise, use Microsoft Defender Offline and inspect its event log. A clean scan is useful evidence, but it cannot prove that an unknown PowerShell command caused no harm; the command itself and what happened on the device matter.

1. Check which antivirus is protecting Windows

Before relying on a Microsoft Defender scan, confirm whether Defender is the active antivirus provider. Open Windows Security and select Virus & threat protection. Check the security provider shown there. If another antivirus product is listed as the provider, check its status and use its scanning and detection history as well.

For a PowerShell status check, open PowerShell and run Get-MpComputerStatus. Review the AMRunningMode field. Microsoft documents values including Normal, Passive, EDR Block Mode, and SxS Passive Mode; Passive or side-by-side status means Defender may not be the primary antivirus product. See Microsoft’s Get-MpComputerStatus reference and its overview of Defender Antivirus status in Windows.

2. Run a scan and review Protection history

  1. Open Windows Security and select Virus & threat protection.
  2. Choose a scan option and run a scan. A quick scan is a reasonable first check; choose a full scan if you want Windows to examine the device more broadly.
  3. After the scan, open Protection history. Expand any relevant detection card and follow the action guidance Windows displays. Do not allow a detected item unless you have reliable grounds to identify it as a false positive.

Protection history records Microsoft Defender Antivirus detections and actions, potentially unwanted apps that were removed, and some key services that are turned off. Microsoft says detailed threat information requires administrator privileges, and that the history retains events for two weeks. An empty history or a scan with no detection does not establish that the PC is clean. See Microsoft’s Protection history guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you prefer PowerShell, Microsoft documents Update-MpSignature to update Defender security intelligence and Start-MpScan for quick, full, or custom scans. Get-MpThreatDetection can show active and past detections recorded by Defender, but it cannot show that no undetected threat exists. Use the Microsoft Defender PowerShell reference for the cmdlet details.

3. Use Microsoft Defender Offline if suspicion remains

Microsoft Defender Offline scans from a trusted environment outside the normal Windows kernel. Microsoft describes it as useful against malware that attempts to bypass the Windows shell, including rootkits. It is an additional detection step, not a guarantee that an incident is resolved.

  1. Save your work and close open programs; the scan restarts the device.
  2. In Windows Security, go to Virus & threat protection > Scan options > Microsoft Defender Offline scan, then start the scan.
  3. After Windows restarts, check Protection history for the result and any detections.

Microsoft says the scan takes about 15 minutes, though actual duration can vary. An elevated PowerShell session can also start it with Start-MpWDOScan; Microsoft Learn describes the cmdlet as one that “starts a Windows Defender offline scan.” The built-in scan is available through Windows Security or PowerShell on supported Windows versions; a separate USB drive is not required for that process. See Microsoft’s Defender Offline instructions and the Start-MpWDOScan reference.

4. Review Defender’s event log for context

Event Viewer can show Defender detections, actions, and configuration changes that Windows recorded. Open Event Viewer and navigate to Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Event ID 1117: Microsoft documents this as an action taken to protect the machine.
  • Event ID 5007: a Defender configuration change. An unexpected change is a reason to investigate what changed and when, but it is not, by itself, proof of malware.
  • Event ID 2030: an informational event indicating that an Offline scan was configured for the next reboot.

Interpret entries alongside the scan result and what was happening on the PC; a logged configuration change alone does not identify who or what made it. See Microsoft’s Defender event ID reference.

5. Decide what to do about the suspicious command

Windows Security tools can tell you what Defender detected and recorded, but they cannot establish what an unspecified PowerShell command executed on your particular computer. Preserve the exact command text and any available context about when and where you ran it. Avoid running additional unverified commands copied from websites.

If this is a work or school device, contact your organization’s IT team. If you see signs of continued account or device compromise, seek help from a qualified incident responder rather than treating a clean scan as proof that nothing happened.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When a USB drive is—and is not—relevant

Microsoft documents bootable Defender Offline media for Windows 7 SP1 and Windows 8.1, and recommends creating it on a PC that is not infected because malware may interfere with creating the media. That legacy-media procedure is distinct from the built-in Offline scan available through Windows Security or PowerShell on supported Windows versions. For the latter, you do not need to buy or prepare a USB drive. See Microsoft’s instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.