A small or nearly empty USB drive can be scanned quickly. A large drive containing thousands of files should usually produce meaningful coverage counters. If a “full scan” ends almost instantly and reports zero files, do not assume that speed means the drive is clean.
Verify what the scanner actually traversed. Time alone is a weak signal; the selected root, file and directory counts, access errors, exclusions, and completion status are much more informative.
Start with the selected root
Confirm that the scanner received the drive you intended. On Windows, a drive root normally appears as E:\, F:\, and so on. A folder with a similar label or a stale drive letter is not the same target.
Reconnect the drive and compare its label and capacity in File Explorer. Do not rely on the letter from a previous session because Windows can assign a different one.
Compare scan counts with the drive
A complete report should include at least:
- directories traversed;
- files inspected;
- shortcuts examined;
- findings;
- access errors;
- reparse points skipped;
- safety-limit status;
- complete or incomplete status.
If File Explorer shows gigabytes of used space but the scanner reports zero files, investigate. There may be a path-normalization bug, a permission problem, an unsupported file system, or a result from the wrong root.
Check access errors
Windows can deny access to a directory even when the rest of a drive is readable. A scanner should continue where safe, count the error, and mark the result incomplete when the missing area affects coverage.
“No findings” and “could not read part of the drive” are different outcomes. The second requires a follow-up decision—such as changing permissions, scanning from an appropriate account, or using another trusted scanner.
Understand reparse points
Reparse points can redirect traversal to another location. Security scanners often skip them to avoid leaving the selected root, following loops, or scanning an unrelated volume. A skipped reparse point is not the same as an ordinary directory.
The report should count real skips accurately. If every normal folder is reported as a reparse point, the traversal logic is probably wrong.
Look for limits and exclusions
Scanners may enforce maximum files, depth, elapsed time, or memory use. Those limits protect the computer, but the result must not be presented as complete when a limit stops traversal.
Also review:
- whether “quick scan” was selected by mistake;
- whether filters excluded most file types or folders;
- whether the drive disconnected or went offline;
- whether an allow list hid expected shortcut findings;
- whether another application locked the drive.
Cross-check with a second scan
Run a Microsoft Defender custom scan of the same drive. Defender and a shortcut-focused scanner inspect different signals, so the results are complementary rather than interchangeable.
In Shortcut Remover 8.0.0, the full-scan result exposes directory, file, shortcut, access-error, reparse-skip, and safety-limit information. The release also includes a fix for Windows volume-root handling that previously could turn a root such as C:\ into an invalid doubled-separator form and end the scan before traversal.
A practical verification checklist
- Confirm the drive letter, label, and capacity.
- Select Full scan.
- Keep the drive connected until the final result appears.
- Compare file and directory counts with the amount of data you expect.
- Review access errors, skipped reparse points, and safety-limit status.
- Treat an incomplete result as incomplete, even when no suspicious shortcut was found.
- Cross-check the same drive with Microsoft Defender.
A fast scan is not automatically wrong. A result with implausible coverage and no explanation is. Prefer scanners that make the difference visible.
Related: Scan a USB drive without opening files and recover safely when USB files appear as shortcuts.
