Tecnologia

How to Prevent Computer Viruses on Your Device

A computer user at a desk with a slow-loading Windows PC showing lagging windows and a spinning loading cursor

Malware reaches the device via download, attachment or malicious site

Antivirus software running a malware scan with a progress bar and threat detection results displayed

Malware gets onto a computer the same way most unwanted software does: a user downloads a file, opens an email attachment, or lands on a site that triggers a drive-by install. Once that code executes, it can alter system files, copy itself into other programs, or quietly run in the background — which is often the first sign something is wrong, since infected machines tend to slow down or behave erratically as the malicious process competes for resources.

A security suite catches this in one of two ways: a background (real-time) scanner that checks files the moment they're written to disk, or a scheduled scan that works through the whole drive on a timer. When either one flags a match against known malicious code, the program moves to contain it rather than just reporting it. Kaspersky's guidance on removing an infection walks through this containment step: the software isolates the file in a quarantine folder so it can't run or spread further, then gives the user the option to delete it outright or restore it if the detection turns out to be a false positive.

The loop doesn't end at removal. Antivirus vendors push out definition updates — new signatures that describe the latest known threats — specifically so that a variant caught once gets blocked automatically everywhere else running the same software. Skipping updates is effectively the same as not scanning at all, since a scanner can only recognize what its definitions describe.

A phishing email or scam message imitates a trusted sender

A suspicious phishing email in an inbox claiming to be from a bank with a fake login link

A phishing message works by looking like it came from a bank, a delivery service, or a coworker, which is exactly why file scanning alone doesn't stop it — there's no malicious file, just a convincing link. The user clicks through to a page built to look like a real login or payment form and types in credentials that go straight to the attacker.

This is why modern security suites bundle web or scam protection alongside the traditional virus scanner: a browser extension or network filter checks the destination URL against lists of known malicious or newly registered phishing domains before the page even loads. CNET's overview of protecting a Windows PC notes that this link-checking layer has become as central to a security package as the scanner itself, because stolen credentials and financial fraud now outpace file-based infections as a way accounts get compromised.

When that filter works as intended, the browser blocks the page outright or throws an interstitial warning, and the account details never reach the attacker. It's a narrower kind of protection than a full scan — it only catches destinations already flagged as malicious — but it covers a threat vector that antivirus definitions were never built to address.

Reader asks whether built-in protection is enough

Windows ships with Microsoft Defender running by default, and for a lot of users that's a defensible stopping point rather than a compromise. The honest answer depends less on brand preference and more on three concrete factors: how the device is used, whether independent testing labs rate Defender's detection comparably to paid alternatives, and whether the extra features in a paid suite — VPN, identity monitoring, scam-call blocking — solve a problem the user actually has.

Factor Defender / built-in Paid third-party suite
Core malware detection Free, enabled by default, updates automatically Usually comparable detection rates in independent lab tests
Web/phishing filtering Limited, mostly browser-dependent Often included as a dedicated module
Extras (VPN, scam detection, backup) Not included Common in mid- and top-tier plans
Multi-device licensing One device at a time, OS-specific Single licence often covers phone, tablet, and PC
Support Community/Microsoft support channels Phone or chat support usually included

For someone who mostly browses, emails, and avoids downloading unverified software, the baseline scanner plus cautious habits can be enough. For a household covering several device types, or anyone handling sensitive financial accounts, the multi-device licensing and scam-detection layer in a paid plan earns its cost. Either way, the rule that matters more than brand choice is running exactly one antivirus engine at a time — two real-time scanners fighting over the same files tends to cause conflicts and false positives rather than added protection — and uninstalling the old one completely through its own uninstaller before installing a replacement. Keeping the operating system itself patched matters just as much as the scanner, since many infections exploit vulnerabilities that a software update would have already closed.

Operating system

Which protections apply to a device depends heavily on which operating system it runs. Windows and macOS both support traditional file-based antivirus scanning because both allow third-party software to inspect the file system and run background processes with elevated permissions.

Android follows a similar model to desktop operating systems, allowing installed security apps to scan files and monitor app permissions. iOS does not: Apple's sandboxing model keeps apps isolated from each other and from the file system, so an iPhone or iPad cannot run a traditional virus scan the way a laptop can. Protection on iOS instead comes from the built-in app review process, Safari's fraud warnings, and user caution around links and app permissions rather than an installed scanner. Anyone shopping for "antivirus" for an iPhone should know that what's being sold is largely web filtering and account monitoring, not the kind of file scan a desktop product performs.

Antivirus software

Antivirus software detects malicious code using three overlapping techniques, and understanding which one is doing the work explains why some products catch brand-new threats and others only catch familiar ones. Signature-based detection compares a file against a database of known malware fingerprints — fast and reliable, but blind to anything not yet catalogued. Heuristic detection looks for code patterns and structures typical of malware even without an exact signature match, catching some new variants at the cost of occasional false positives. Behavioral monitoring watches what a running program actually does — modifying system files, encrypting large batches of documents, contacting unfamiliar servers — and intervenes based on that activity rather than the file's identity.

A product described as having "real-time protection" is typically running all three layers continuously rather than relying only on a periodic signature scan. That's the meaningful difference between free and paid tiers of the same vendor's software: free versions often include signature-based scanning but withhold the full real-time web filtering, ransomware rollback, and behavioral monitoring that sit in the paid tier, along with live support.

Computer virus

A computer virus, in the narrow sense, is self-replicating code that attaches itself to legitimate files or programs and spreads when those files are copied, shared, or executed. It's one category under the broader umbrella of malware, which also includes worms, trojans, spyware, and ransomware — but it's the original class of threat that antivirus software was built to catch, and the reason the term "antivirus" stuck even as the software's job expanded to cover everything else.

Online scams

Online scams are fraud attempts delivered by text, phone call, or web page rather than by a malicious file, and they rely on social engineering rather than code execution. A fake package-delivery text, a spoofed tech-support call, or a cloned shopping site all fall into this category. Several modern security suites now bundle scam detection — flagging suspicious SMS links or screening calls against known scam numbers — alongside their traditional malware scanning, reflecting how much of the current threat landscape runs through deception rather than infection.

Malware scan

A malware scan is an inspection of files and running processes against known threat signatures and behavioral rules, run either on demand or on a schedule set by the user. Running one regularly matters less than knowing what to do with the result, since a scan that finds something and gets ignored provides no protection at all.

When a scan flags a file, there are generally three paths:

  1. Quarantine — the safest default. The file is isolated so it can't execute, which buys time to check whether the detection is legitimate before deleting anything important.
  2. Delete — appropriate once the file is confirmed malicious or isn't something the user recognizes or needs; quarantined files that sit unresolved for weeks are usually safe to remove outright.
  3. Reinstall the OS — the safer fix when an infection has already altered system files, when repeated scans keep flagging the same location, or when ransomware has encrypted data, since some malware can survive partial removal by hiding in startup processes a scanner doesn't fully reach.

False positives happen most often with heuristic detection, where legitimate but unusually-behaving software — certain developer tools, some older freeware — gets flagged incorrectly. Kaspersky's removal guide recommends restoring a quarantined file only after checking it against the vendor's own documentation or a second scanning tool, rather than assuming every detection is accurate.

What are 7 types of computer viruses?

Computer viruses are generally grouped by how they attach to and spread through a system rather than by what damage they cause. The categories commonly referenced across security guidance include:

  • File infector viruses — attach to executable program files and activate when the program runs.
  • Boot sector viruses — embed in the startup sector of a drive and load before the operating system does.
  • Macro viruses — hide inside document macros, commonly in office file formats, and run when the document is opened.
  • Polymorphic viruses — rewrite their own code slightly with each infection to evade signature-based detection.
  • Resident viruses — install themselves into system memory and keep running even after the original infected program closes.
  • Multipartite viruses — combine file-infecting and boot-sector behavior to spread through more than one method at once.
  • Direct action viruses — execute a single task immediately on activation (such as corrupting specific files) rather than staying resident.

What are the 5 most common ways to get a computer virus?

Most infections trace back to a small set of entry points, and nearly all of them involve the user taking some action rather than a system being silently breached. The most frequently cited paths include:

  • Email attachments and links from spoofed or compromised senders.
  • Pirated or cracked software downloaded from unofficial sources, which frequently bundles hidden payloads.
  • Infected USB drives or external media plugged in without scanning first.
  • Malicious or compromised websites that trigger drive-by downloads without an explicit click.
  • Fake software updates or pop-up prompts disguised as legitimate system alerts.

TeamViewer's guidance on avoiding computer viruses points to outdated software as a common thread across several of these — many infections exploit a vulnerability that a pending security patch would have already closed, which is part of why keeping the OS updated matters as much as running a scanner.

What are the 5 popular computer anti-viruses?

Rather than rank products, it's more useful to know the categories buyers typically choose between: a free built-in option (Microsoft Defender on Windows), a free third-party scanner with limited extras, a paid single-device suite with real-time web and ransomware protection, a paid multi-device suite bundling a VPN and identity monitoring, and a business/enterprise tier with centralized management across many machines. Independent testing labs publish comparative detection rates for named products within these tiers, and that lab data — not marketing claims — is the only reliable way to compare one against another, since detection rates can shift between test cycles as both malware and the software itself change.

Before picking any product, check which tier actually includes real-time web filtering and ransomware rollback rather than just on-demand scanning, since that's usually the line between a free and paid version of the same name.

Run one scan now with whatever's already installed, confirm it's set to update automatically, and check that it's the only real-time scanner running on the device.

Related on this site