Advertising disclosure: this site is funded by partner commissions on other pages. This page contains no partner link. How this site is funded.
sorentis.onlineIndependent consumer security guides

Antivirus basics: a short guide for non-specialists

The background you need to evaluate any security product, in about ten minutes. No product recommendations on this page. Last updated 24 September 2026.

1. What malware actually is

“Malware” is an umbrella term for software written to act against the interests of the person running it. The main families behave very differently, and a product’s effectiveness against one says little about the others.

Common malware families and what they are trying to achieve.
FamilyWhat it doesHow it usually arrives
RansomwareEncrypts your files and demands payment for the keyA malicious attachment or download; an unpatched internet-facing service
InfostealerHarvests saved passwords, session cookies, crypto wallets and sends them onCracked software, fake installers, malicious browser extensions
Trojan / loaderPoses as something useful, then installs the real payloadDownloads from unofficial sources
Adware / PUPInjects advertising, hijacks search, resists removalBundled with free software installers
RootkitHides other malware from the operating system and from scannersUsually a second-stage payload, not a first infection
Spyware / stalkerwareMonitors activity, keystrokes, locationPhysical access to the device; malicious apps

2. The order of operations that actually keeps you safe

If you do only some of this, do it in this order. The list is deliberately ordered by effect, not by how much anyone can sell you.

  1. Apply updates. Operating system, browser, and anything exposed to the internet. A large share of successful attacks use a flaw that was patched months earlier. This costs nothing.
  2. Use a unique password for every account, stored in a password manager. This is what stops one breach becoming five.
  3. Turn on two-factor authentication, starting with your email account, because email can reset everything else.
  4. Keep a backup you can restore from — ideally one copy that is not permanently connected to the machine. This is the only reliable answer to ransomware.
  5. Run a malware scanner. Your operating system probably already has one. A paid one may be better; it is the fifth item on this list, not the first.
  6. Slow down on anything urgent. Urgency is the most reliable signal of fraud. See our section on phishing.

3. Free versus paid

The honest summary is that the gap is narrower than advertising suggests and wider than cynicism suggests.

Built-in protection — Microsoft Defender on Windows, XProtect and Gatekeeper on macOS, Play Protect on Android — is real protection, enabled by default, and it competes in the same independent tests as the paid products. For a careful user on an up-to-date machine it covers a great deal.

What a paid suite adds is mostly convenience and breadth: one dashboard across several devices, a second detection engine from a different vendor, and bundled tools such as a password manager and a VPN. Whether that is worth the subscription depends entirely on whether you would otherwise obtain those tools separately.

4. Vocabulary worth knowing before you read a product page

A longer list is in the glossary.

5. Signs that a security product page is not being straight with you

Those signals apply to publishers as much as to vendors. They are the standards we hold ourselves to in our editorial policy.