Malware reaches the device via download, attachment or malicious site
Most infections start with an ordinary action: opening an email attachment, downloading a cracked program, or clicking a link on a compromised site. The file or script that arrives is not always obviously harmful — malware is often bundled inside something that looks legitimate, which is why file scanning exists at all rather than just warning labels.
Once the file executes, it can alter system files, install additional payloads, or run quietly in the background. A device that suddenly runs slower, generates pop-ups, or drains battery faster than usual is showing one of the more common symptoms, though slowdowns alone don't confirm infection.
This is where the two detection styles differ. Older antivirus tools rely on signatures — a database of known malware fingerprints — to flag a file as malicious. Newer engines add heuristics (looking for suspicious code patterns even without a matching signature) and behavioural monitoring (watching what a running process actually does, such as trying to encrypt large numbers of files rapidly, a hallmark of ransomware). A product that only does signature matching will miss brand-new threats; one that adds behavioural monitoring can catch them at the cost of occasionally flagging legitimate software that behaves unusually.
When a scan or real-time monitor flags a file, it typically has three fates:
- Quarantine — the file is isolated so it can't run, but not deleted, in case it's a false positive or you need to recover data from it.
- Delete — appropriate once you're confident the detection is accurate and the file has no legitimate use.
- Ignore/allow — reserved for confirmed false positives, such as a system tool flagged by an overly aggressive heuristic.
If a scan repeatedly finds the same infection after removal, or if the system won't boot cleanly, a reinstall of the operating system is usually the safer fix than continuing to fight the infection file by file.
A phishing email or scam message imitates a trusted sender
Phishing doesn't rely on malicious code at all — it relies on a convincing fake. The message imitates a bank, delivery service, or colleague closely enough that the recipient clicks through without checking the sender address or the link destination.
The click usually lands on a page built to look like a real login or payment form. If web or scam protection is active, the browser or security suite compares the URL against a list of known malicious sites and blocks the page before it loads — this is why link-checking has become as central to "antivirus" as file scanning, even though it doesn't involve a virus at all.
Credentials only stay safe if that check happens before the user types anything. That's the main reason modern suites bundle scam and phishing protection alongside traditional scanning: file-based malware and credential theft are different threats that need different mechanisms, and a tool built only to scan downloaded files won't catch a fake login page.
Reader asks whether built-in protection is enough
Whether Microsoft Defender is sufficient depends more on how you use a device than on the product itself. Defender ships with Windows and provides continuous scanning at no extra cost, and Microsoft's own support guidance frames the choice as depending on your risk profile and what extra features you need, rather than declaring one option universally better than the other, per Microsoft's own guidance.
A reasonable way to decide:
| Situation | Likely adequate | Worth paying for a suite |
|---|---|---|
| Single Windows device, cautious browsing habits, keeps OS patched | Defender alone | — |
| Multiple devices (phone, tablet, PC) needing one licence | — | Suite with multi-device coverage |
| Frequent public Wi-Fi use | — | Suite with VPN included |
| Wants scam/phishing text and call detection | — | Suite with dedicated scam protection |
| Wants ransomware file rollback | — | Suite with rollback feature |
Free tiers, including Defender, generally cover the baseline: real-time file scanning and basic web filtering. What they withhold varies by paid suite but commonly includes ransomware rollback, dedicated scam-call/text detection, VPN access, and priority support — features that matter more to some users than others, which is why "do I need paid antivirus" doesn't have one universal answer.
A few practical rules apply regardless of which product is chosen:
- Run only one real-time antivirus engine at a time — two active scanners commonly conflict over file access and can slow the system more than either would alone.
- Uninstall the previous antivirus completely (most vendors publish a dedicated removal tool) before installing a new one, rather than just disabling it.
- Keep the OS itself patched; antivirus catches what patched vulnerabilities would otherwise let through, and neither substitutes for the other, a point general security guidance makes about layered protection rather than single-tool reliance.
- On iOS, traditional file-scanning antivirus doesn't function the way it does on Windows or Android, because Apple's sandboxing model restricts apps from scanning other apps' files — so "antivirus" apps on iOS mostly cover phishing links, Wi-Fi safety checks, and breach alerts rather than file scanning.
Antivirus software as a category
Antivirus software is the umbrella term for any program built to detect, block and remove malicious software on a device — desktop, laptop, phone or tablet. Licence counts are almost always sold per device rather than per household, which matters when comparing a single-PC free tool against a suite priced to cover a phone, tablet and laptop under one plan.
The category has broadened well past what the name suggests. "Antivirus" originally meant tools built to catch self-replicating viruses specifically; today the same products handle ransomware, spyware, phishing links and, increasingly, scam text and call detection, none of which are viruses in the strict sense but all of which fall under the same installed program.
What to check before installing anything
Before adding a new security tool, confirm what's already running. Check Windows Security settings to see whether Defender is active, remove any expired trial antivirus completely using the vendor's removal utility, and decide — based on the table above — whether the gap you're filling is detection itself or one of the extra services layered on top of it. That decision, not the length of a features list, is what should drive the purchase.
