Antivirus basics: a short guide for non-specialists
The background you need to evaluate any security product, in about ten minutes. No product recommendations on this page. Last updated 24 September 2026.
1. What malware actually is
“Malware” is an umbrella term for software written to act against the interests of the person running it. The main families behave very differently, and a product’s effectiveness against one says little about the others.
| Family | What it does | How it usually arrives |
|---|---|---|
| Ransomware | Encrypts your files and demands payment for the key | A malicious attachment or download; an unpatched internet-facing service |
| Infostealer | Harvests saved passwords, session cookies, crypto wallets and sends them on | Cracked software, fake installers, malicious browser extensions |
| Trojan / loader | Poses as something useful, then installs the real payload | Downloads from unofficial sources |
| Adware / PUP | Injects advertising, hijacks search, resists removal | Bundled with free software installers |
| Rootkit | Hides other malware from the operating system and from scanners | Usually a second-stage payload, not a first infection |
| Spyware / stalkerware | Monitors activity, keystrokes, location | Physical access to the device; malicious apps |
2. The order of operations that actually keeps you safe
If you do only some of this, do it in this order. The list is deliberately ordered by effect, not by how much anyone can sell you.
- Apply updates. Operating system, browser, and anything exposed to the internet. A large share of successful attacks use a flaw that was patched months earlier. This costs nothing.
- Use a unique password for every account, stored in a password manager. This is what stops one breach becoming five.
- Turn on two-factor authentication, starting with your email account, because email can reset everything else.
- Keep a backup you can restore from — ideally one copy that is not permanently connected to the machine. This is the only reliable answer to ransomware.
- Run a malware scanner. Your operating system probably already has one. A paid one may be better; it is the fifth item on this list, not the first.
- Slow down on anything urgent. Urgency is the most reliable signal of fraud. See our section on phishing.
3. Free versus paid
The honest summary is that the gap is narrower than advertising suggests and wider than cynicism suggests.
Built-in protection — Microsoft Defender on Windows, XProtect and Gatekeeper on macOS, Play Protect on Android — is real protection, enabled by default, and it competes in the same independent tests as the paid products. For a careful user on an up-to-date machine it covers a great deal.
What a paid suite adds is mostly convenience and breadth: one dashboard across several devices, a second detection engine from a different vendor, and bundled tools such as a password manager and a VPN. Whether that is worth the subscription depends entirely on whether you would otherwise obtain those tools separately.
4. Vocabulary worth knowing before you read a product page
- Zero-day — a vulnerability with no patch available yet. Used loosely in marketing to mean “new”.
- Real-time protection — scanning continuously as files are opened and processes run, rather than only on demand.
- False positive — clean software wrongly blocked. Labs count this against a product; marketing rarely mentions it.
- Heuristic — a rule of thumb for spotting something suspicious without recognising it exactly.
- Sandbox — an isolated environment where code runs without being able to affect the rest of the system.
A longer list is in the glossary.
5. Signs that a security product page is not being straight with you
- A scan that runs in your browser and finds infections. A web page cannot scan your computer.
- A countdown timer on the price.
- “Award-winning” with no award named and no date.
- A test score with no laboratory, no round and no link.
- Any guarantee of complete protection.
- An “antivirus” for iPhone that claims to scan for viruses — the platform does not permit it.
Those signals apply to publishers as much as to vendors. They are the standards we hold ourselves to in our editorial policy.