The fastest way to check a file for viruses
The simplest method is to upload the file to VirusTotal, a free scanning service that checks your file against 70+ antivirus engines at once. Go to virustotal.com, drag your file into the upload box, and wait 30 seconds to two minutes. You'll see a report showing whether any of those engines detected a threat. This works for documents, images, videos, executables, and compressed files.
VirusTotal doesn't store your file permanently by default — it scans and deletes it. However, if you're scanning something extremely sensitive, read their privacy policy first or use the alternative methods below instead.
If you use Windows, you can also right-click any file, select "Scan with Windows Defender", and let the built-in antivirus check it. On Mac, the system runs a basic check automatically when you first open a downloaded file, though you can force a deeper scan using third-party tools like ClamXav if you're concerned.
Key Takeaways
- VirusTotal scans files against 70+ antivirus programs for free and takes two minutes or less.
- Windows Defender (built into Windows) can scan individual files without uploading them anywhere.
- A single antivirus detection doesn't always mean danger — false positives happen, especially with newly created files.
- Never open a file you don't recognize, even if it scans clean, because no scanner catches everything.
- Scanning a file before opening it is most useful for email attachments, downloads from unfamiliar websites, and files shared by people you don't know well.
When a file shows up as infected
If VirusTotal shows detections, look at which antivirus engines flagged it and what they called it. If only one or two engines out of 70 detected something, and they gave it a generic name like "Trojan.Generic" or "PUA" (Potentially Unwanted Application), it's often a false positive — a harmless file that triggered an overly sensitive rule.
If 10 or more engines agree on a detection, or if they all use the same specific name (like "Emotet" or "Trickbot"), the file is almost certainly malicious. Delete it and don't open it. If multiple engines flag it but disagree on what it is, research the specific detection names — search for "[detection name] false positive" to see whether other people have reported the same file as safe.
Be especially cautious with executable files (.exe, .msi, .bat, .scr) and scripts (.ps1, .vbs, .js). Even if they scan clean, only run them if you trust the source completely. Antivirus software is good at catching known threats, but new malware variants appear constantly.
Scanning files you already have on your computer
If you want to check files that are already stored on your device without uploading them to VirusTotal, use your built-in antivirus. On Windows, open Windows Defender (search for "Windows Security" in the Start menu), click "Virus & threat protection", then "Scan options". Choose "Custom scan", select the folder or files you want to check, and let it run.
On Mac, install a free tool like ClamXav or use the command line if you're comfortable with it. Most Mac users don't need to scan files manually because macOS checks downloads automatically, but ClamXav gives you more control if you want it.
For a thorough check of your entire system, schedule a full scan during a time when you won't need your computer — these can take 30 minutes to several hours depending on how much data you have. Weekly or monthly full scans are reasonable if you download files frequently or visit unfamiliar websites.
Why one antivirus isn't enough
No single antivirus catches every threat. They use different detection methods: some look for known malware signatures (like a fingerprint), others watch for suspicious behavior, and some use machine learning to spot new variants. A file might slip past one engine but get caught by another.
This is why VirusTotal's multi-engine approach is useful — if a file passes 69 engines but one flags it, you have more confidence it's safe. If 20 engines flag it and 50 don't, you have a harder decision, but the weight of evidence matters. The more engines that agree, the more likely the detection is real.
That said, antivirus software is a safety net, not a may provide. The best protection is still common sense: don't open attachments from people you don't know, don't download files from suspicious websites, and don't run executables unless you're certain of the source.
Files that are hard to scan
Some files are tricky to scan because they're compressed or encrypted. A .zip or .rar file can be scanned as-is, but antivirus engines may not be able to look inside it if it's password-protected. If you receive a password-protected archive from someone you don't know, ask them why it's encrypted before you open it — legitimate files are usually sent unencrypted.
Macro-enabled documents (.docm, .xlsm) are another gray area. VirusTotal will scan them, but the malware might only activate when you open the file in Microsoft Word or Excel and enable macros. If you receive a .docm file unexpectedly, disable macros before opening it (Word and Excel prompt you to do this automatically). If you need the macros to work, make sure you trust the sender first.
What to do if you've already opened something suspicious
If you opened a file before scanning it and now you're worried, don't panic. Most malware requires you to take an additional action — clicking a link, entering a password, or allowing a program to install. Simply opening a document or image rarely causes infection on its own.
Run a full antivirus scan on your computer to see if anything was installed. If your antivirus finds something, quarantine it (your antivirus will offer this option) and follow the removal steps. If nothing is found but you're still concerned, change your passwords for sensitive accounts like email and banking, especially if the file looked like a phishing attempt.
If you opened an executable file (.exe) or allowed a program to install, the risk is higher. Run a full scan immediately, and consider using a second antivirus tool like Malwarebytes (free version available) to double-check. If you see suspicious activity afterward — unexpected toolbars, changed homepage, slow performance — that's a sign something got through.
Building a scanning habit
You don't need to scan every file you download. Focus on the ones that matter: email attachments from people you don't know, files from unfamiliar websites, and anything that seems out of place. A resume from a recruiter you didn't contact, an invoice from a company you don't do business with, or a "package delivery" notification — these are worth 30 seconds of scanning time.
Set a simple rule: if you're even slightly unsure about a file, scan it before opening it. VirusTotal takes less time than reading an email, and it costs nothing. The goal isn't paranoia — it's making one small decision that takes seconds and can prevent hours of cleanup if something goes wrong.
Frequently Asked Questions
Is VirusTotal safe to use with sensitive files?
VirusTotal doesn't store files by default, but they are temporarily processed by their servers. If you're scanning something with confidential information, read their privacy policy or use Windows Defender's local scan instead. For most people, VirusTotal is safe and widely trusted by security professionals.
Can antivirus miss a virus?
Yes. Antivirus software catches known threats and some new ones, but sophisticated malware can evade detection. This is why you should also avoid opening files from untrusted sources, even if they scan clean. Scanning is one layer of protection, not the only one.
What does "PUA" or "PUP" mean on a scan report?
PUA stands for Potentially Unwanted Application — software that's not necessarily malicious but might be annoying or intrusive, like adware or browser toolbars. Whether to remove it is your choice. If it came bundled with something you installed, you can usually uninstall it from your Control Panel or Settings.
Should I scan files on my phone?
Android phones can be scanned using antivirus apps like Malwarebytes or Avast, though the built-in Google Play Protect offers basic protection. iPhones rarely need scanning because iOS is more locked down, but you can use antivirus apps if you want extra assurance. For most phone users, avoiding untrusted app stores is more important than scanning.
How often should I run a full system scan?
If you download files regularly or visit unfamiliar websites, a weekly or monthly full scan is reasonable. If you mostly use your computer for email and browsing known sites, monthly is fine. Schedule scans during times you won't need your computer, since they can slow things down.