Antivirus Basics
Antivirus software scans files and running processes on a PC, comparing them against known threat signatures and, in modern products, watching for suspicious behavior even when no signature matches. It's the most familiar layer of Windows security, but it's also the most misunderstood — many users assume it covers far more ground than it actually does.
Two detection approaches
- Signature-based detection — matches files against a database of known malware, fast and reliable for identified threats
- Behavior-based (heuristic) detection — flags programs based on what they do, such as encrypting many files quickly or modifying registry startup keys
Signature-based detection alone misses brand-new or modified malware until the database updates. Behavior-based detection catches more novel threats but can occasionally flag legitimate software that behaves unusually.
What antivirus does well
Antivirus is genuinely effective against known malware families: trojans, worms, and common adware that match existing signatures or well-understood behavior patterns. Real-time scanning also blocks a file the moment it's written to disk or executed, which stops many infections before they fully install.
What it doesn't cover
- Social engineering — antivirus can't stop you from voluntarily handing over a password
- Data already exposed through a breach or through doxxing
- Unpatched vulnerabilities — a fully updated antivirus doesn't compensate for an outdated operating system
- Weak or reused passwords, which require a password manager, not a scanner
Choosing between built-in and third-party tools
Windows Security is free, built in, and adequate for many users as a baseline. Dedicated tools add extras: Malwarebytes, for example, emphasizes detection of adware and potentially unwanted programs that some antivirus engines treat as lower priority. See our free antivirus comparison for how the no-cost options differ in practice.
Frequently asked questions
Do I need both Windows Security and a third-party antivirus?
Running two real-time engines at once can cause performance conflicts. Many users instead run one real-time antivirus and use a second tool, like Malwarebytes Free, for occasional manual scans.
Why did my antivirus miss an infection?
Signature-based engines can miss malware that's brand new or has been slightly modified to evade detection, which is why layered, behavior-based scanning has become standard.
Is free antivirus actually safe to use?
Reputable free antivirus tools from established companies provide real protection; the caution is mainly around unfamiliar 'free' tools bundled with other downloads.
Malware-Bytes.net is an independent information resource about malware protection for Windows. We are not Malwarebytes, and this site is not the official Malwarebytes website or support channel. Malwarebytes is a trademark of Malwarebytes Inc.