Lesson 1 of 7
What does antivirus software actually do?
Before deciding whether you need antivirus, it helps to know what it is for. This lesson explains the work it does in the background, using everyday terms, and is honest about where that work stops.
The basic job: noticing harmful software
The word "virus" is older than most of the programs it now describes. Today, security people tend to say malware, short for malicious software, which covers any program written to do something its victim would not agree to. That might mean copying files, locking them and demanding payment, showing unwanted advertising, recording what you type, or quietly using your computer to attack someone else.
Antivirus software is a program that runs on your device and tries to notice malware before it can do that work. When it finds something, it usually blocks it from running, moves it somewhere it cannot cause harm, or removes it. Most products then tell you what happened, in a notification inside the program itself.
That is the whole idea. Everything else in this lesson is detail about how the noticing is done, because the method affects what antivirus can and cannot catch.
How antivirus recognises a harmful program
There are a few broad approaches, and modern products combine them. You do not need to remember the names, but knowing they exist will make product descriptions easier to read.
- Known patterns (often called signatures)
- The oldest method. Security companies study malware they have already found and record features that identify it. The antivirus compares files on your device with that list. It is reliable for known threats and less useful for brand-new ones, which is why the list is updated often, sometimes many times a day.
- Behaviour monitoring
- Instead of asking "have I seen this file before?", the software watches what programs do. A program that suddenly starts rewriting hundreds of documents, for example, may be stopped even if nobody has seen it before.
- Reputation and cloud lookups
- Many products send a short fingerprint of an unfamiliar file to the vendor's servers to ask whether it is widely used and trusted, or rare and suspicious. This is one reason antivirus products have privacy policies worth reading.
- Web and download checks
- Some products also check web addresses and downloaded files against lists of known harmful sites. Browsers such as Chrome, Edge, Firefox and Safari do similar checks of their own.
No single method catches everything. The combination is what gives modern antivirus its usefulness, and it is also why the independent testing organisations mentioned in lesson four test products against both well-known and newly discovered samples.
What antivirus does well
Antivirus is at its best with the kind of threat that arrives as a file or program. Typical examples include an email attachment that is not what it claims to be, a download from a website you do not know, or a USB stick that has been plugged into an infected computer. In each case there is something concrete on the device to examine, and that is exactly what antivirus is built to examine.
It also helps as a safety net. Most of us occasionally click before we think. A well-maintained antivirus product, or the protection built into the operating system, gives you a second chance when that happens.
Finally, a good product handles the boring work automatically: it updates itself, scans on a schedule, and stays out of the way. A product that interrupts you constantly is not necessarily protecting you better. Often it is just noisier.
What antivirus cannot do
This part matters most, because product marketing in this category sometimes blurs it.
Things antivirus is not designed to stop
- A person being persuaded. If someone on the phone convinces you to transfer money or install a remote-access tool yourself, antivirus has nothing to block, because you did it willingly.
- A reused password. If a password you use on several sites leaks from one of them, criminals can try it on the others. That happens on someone else's server, not on your device.
- An out-of-date device. Antivirus is not a substitute for security updates. A flaw in the operating system is fixed by the update, not by scanning.
- Lost files. Antivirus may stop some ransomware, but it is not a backup. If your files matter, keep a copy elsewhere.
None of this means antivirus is pointless. It means it should be understood as one layer. The National Cyber Security Centre's household guidance on Own Your Online puts updates, strong passwords, two-step verification and backups alongside it, and those are habits rather than products.
Do phones get viruses?
Phones can be targeted by malware, but the risks look different from those on a laptop. Both Android and iPhone keep apps separated from one another and from the core of the system, and both rely heavily on their official app stores, which check apps before listing them. The bigger everyday risks on a phone tend to be scam text messages, fake login pages and apps installed from outside the official store.
That is why phone security products often focus on checking links and web pages rather than scanning files. Lesson two looks at what Android and iPhone include before you add anything.
Words you will meet in product descriptions
When you start reading about specific products, these terms come up often. Here is what each one usually means.
- Real-time protection
- The software checks files as they are opened, downloaded or run, rather than only during a scheduled scan.
- Quarantine
- A locked area where suspicious files are moved so they cannot run. You can usually restore a file from quarantine if it was flagged by mistake.
- False positive
- When a harmless file is wrongly flagged as harmful. Every product makes some of these; fewer is better.
- Firewall
- A filter on network connections that can block unwanted traffic in or out of the device. Windows and macOS both include one.
- Security suite
- A bundle that adds other tools, such as a password manager, a VPN, parental controls or identity monitoring, to the antivirus itself.
Why antivirus updates itself so often
New malware appears constantly, and older malware is changed to avoid detection. For antivirus to recognise what is current, it needs current information. That is why products download updates in the background, often several times a day, and why a product that has stopped updating, perhaps because a trial has ended, offers much less protection than its icon suggests.
The same principle applies to the device itself. Operating system updates close security gaps that malware might otherwise use. An antivirus product and the operating system are maintained separately, so both need to keep updating. When you check a device, look at both: is the security software current, and is the system itself up to date? If either answer is no, fixing it is usually a quick, free and worthwhile step.
Taking stock before the next lesson
If you remember one thing from this lesson, make it this: antivirus looks for harmful software on your device, and it is good at that, but most of the protection you need also depends on updates, passwords and judgement. In the next lesson, we look at the antivirus protection your device very likely already has, and how to confirm that it is turned on.
Try this before lesson two
Find out which operating system and version your main computer and phone are running. On Windows, search for "About your PC". On a Mac, choose About This Mac from the Apple menu. On a phone, look under Settings, then About. You will use the answer in the next lesson.