MS Scan show impacted files during scan but show all good at the end of the scan?

Peter Crafts 60 Reputation points
2026-06-28T00:09:53.99+00:00

I ran a MS Security scan and watched, toward the end of the scan I saw 48 infected files indicated. When the scan completed, I have the following from the system regarding my scan and the infected files - "The scan completed successfully and no viruses, spyware and other potentially unwanted software were detected." It says nothing of what happened to the 48 files. Can someone shed some light?

Microsoft Security | Microsoft Defender | Other
0 comments No comments

Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2026-06-29T13:33:20.91+00:00

This is normal behavior by Microsoft Animalware software but not very well documented by the Microsoft Security Team.  

If Microsoft Defender indicates no detections found at the end of it's scan and there are no items listed in quarantined upon completion, that typically means Defender completed it's scan and determined all scanned files were not malware related. If is not unusual for Defender (or any other security software) to suspect and warn about possible threats during a scan (a preliminary status indication) but later determine the file(s) were not an actual confirmed threat(s) upon completion.   

Near the end of the scanning process the scanner automatically performs a MAPS (Microsoft Active Protection Service) query via Internet connection with the Microsoft Cloud Servers where the file(s) is checked against signature updates in the master database. If actual malware is not confirmed by the Microsoft Cloud Server, the scan summary final results will indicate "No infection found...Successfully Submitted MAPS Report" despite the scanner's initial findings of possible malware.  

I explain in more detail in Microsoft Security products indicates detected files during scan but does not show anything after completion (Post #22).

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

Answer accepted by question author
EmilyS_726 27,470 Reputation points Volunteer Moderator
2026-06-28T04:11:45.36+00:00

Was it the Safety Scanner? This behavior of the Microsoft Safety Scanner is actually completely normal.

All of the findings during the scan are potential/suspicious ones. Think of it as the scanner are marking those so that at the final phase, it can check them against virus definition. This is where the scanner will perform a MAPS (Microsoft Active Protection Service" request to connect to the cloud server, and to upload these initial findings for confirmation. This is why you received a different total number. If it came back with nothing, it means the scan went through finding no threats.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

Answer accepted by question author

AI answer

2026-06-28T00:10:07.63+00:00

During a Microsoft Defender Antivirus scan, items can be flagged as “impacted” or “infected” while the scan is still running, but the final result message only reports what remains as a threat after remediation.

What likely happened in this case:

  1. Threats were detected and then cleaned/quarantined during the scan
    • When Defender detects malicious or potentially unwanted software, it can automatically remove or quarantine those files based on its policies.
    • After those actions succeed, the scan summary may report: “no viruses, spyware and other potentially unwanted software were detected”, meaning no active threats remain, not that nothing was ever found.
  2. How to confirm what happened to those 48 files Use one or more of these methods to see the detailed results:
    • Windows Security (Threat history / Quarantine)
      In Windows 10 and above:
      1. Select Start > Settings > Update & Security > Windows Security > Virus & threat protection.
      2. Under Current threats, select Threat history.
      3. Under Quarantined threats, select See full history.
        There you can review items that were detected and quarantined, and see whether they were removed or are still in quarantine.
    • Microsoft Defender portal / Alerts (for managed/enterprise devices)
      1. Sign in to the Microsoft Defender portal.
      2. Go to Incidents & alerts > Alerts.
        Detected threats from scans are listed here with details and actions taken.
    • Event Viewer (local device logs)
      Check the Microsoft Defender Antivirus event IDs related to scans:
      • Event ID 1000 – scan started
      • Event ID 1001 – scan finished
      • Event ID 1002 – scan stopped before finishing
        These events, along with threat detection events, help confirm whether the scan completed and what actions were taken.
    • Intune / Endpoint security reports (if managed via Intune)
      In the Intune admin center, go to Reports > Endpoint security > Microsoft Defender Antivirus > Detected malware to see detected items and execution state.
  3. Why the summary can say “no threats” after showing infections
    • The on-screen counter during the scan shows detections in progress.
    • The final message reflects post-action status (after removal/quarantine). If all detected items were successfully handled, the system reports that no threats remain.

To fully understand what happened to those 48 files, review the Threat history / Quarantined threats in Windows Security or, in an enterprise environment, the Alerts in the Defender portal.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

2 people found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Peter Crafts 60 Reputation points
    2026-06-29T23:14:29.1566667+00:00

    Thank very much for filling me in on the post scan activities, put my mind at ease.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.