Malware · guide

What is anti-virus software, and do you need one?

By Alberto Gulotta · Updated · 15 min read

What is anti-virus software: a program that scans files and memory against a list of known malware signatures, then quarantines or deletes what matches. Two things follow, and both come from public agencies rather than sellers — it cannot find what is not yet on the list, and you probably already have one.

How signature-based antivirus works, and the gap it leaves CISA describes antivirus as scanning files or memory for patterns based on the signatures or definitions of known malware. Because it relies on signatures, it can only detect malware that has known characteristics, which leaves a gap between the moment new malware circulates and the moment vendors add a signature for it. THE MECHANISM, AND WHAT IT CANNOT REACH It scans “files or your computer’s memory” for patterns Against a list “signatures or definitions of known malware” So the list decides what is not on it is not found CISA states the consequence rather than leaving it implied “You will still be susceptible to malware that circulates before the anti-virus vendors add their signatures, so continue to take other safety precautions as well.” AI Tools Primer · figure
This is why a clean scan is a narrower result than it feels like, and it comes from a government agency rather than a competitor. Figure drawn by AI Tools Primer.

What it does, described by someone not selling it

The NCSC’s definition is the plain one: “an antivirus product is a program designed to detect and remove viruses and other kinds of malicious software from your computer or laptop”, and such products “work by detecting, quarantining and/or deleting malicious code”.

CISA describes the method underneath, and one label on that page belongs beside every sentence taken from it: CISA files it as “Archived Content” and says of the archive that it “contains outdated information that may not reflect current policy or programs” — released 30 June 2009, revised 27 September 2019. What is quoted here is the mechanism and the limit of the mechanism, not a current recommendation. Antivirus software “scans files or your computer’s memory for certain patterns that may indicate the presence of malicious software”, and it “looks for patterns based on the signatures or definitions of known malware”. That is the whole mechanism in one sentence: a list of known things, and a comparison against it. It is also why the updates matter more than the brand — a scanner with a stale list is checking against last month’s problems.

There are two ways scanning happens, and CISA names both: automatic scans, where the software watches specific files or directories in real time, and manual scans, which matter if yours does not check new files by itself. CISA’s practical instruction for that case is worth keeping: save and scan email attachments or downloads “rather than opening them directly from the source”.

The limit that comes with the method, stated by CISA rather than implied

A definition that stops at “it detects and removes malware” leaves the reader believing something stronger than is true. CISA does not stop there, and this is the sentence to carry away from the whole page:

“Because it relies on signatures, anti-virus software can only detect malware that has known characteristics… You will still be susceptible to malware that circulates before the anti-virus vendors add their signatures, so continue to take other safety precautions as well.”

Read carefully, that is a statement about a window in time. Something new exists before it is catalogued, and during that interval a scanner is not weak — it is looking for the wrong thing entirely. It is the reason a clean scan means “nothing on the list was found” rather than “there is nothing here”, and the reason the phrase “other safety precautions” is in a government advisory rather than a disclaimer.

The NCSC makes the same point from a different direction in its device guidance, where it notes that signature scanning has been limited by “advances in malware and changes in underlying platforms”, and that many of the risks traditional antivirus once handled “are now mitigated by default when the correct settings are implemented at the operating system level”. Neither agency is telling you not to use one. Both are telling you what it is and is not doing.

Do you need to install one? Two answers, and they are not the same

This is where the question usually leads, and the honest answer depends on the device rather than on the product.

On a computer, you probably already have one. The NCSC puts it simply: antivirus software “is often included for free within the operating systems that run Windows and Apple computers”, and “if you make sure that this built-in antivirus is switched on, you’ll instantly be safer”. The first step is a check, not a purchase.

And if you are considering adding a second, the NCSC gives the warning the sellers do not: “separate antivirus products won’t always work alongside the built-in antivirus software and could even stop it from working completely”. It is the same conclusion its device guidance reaches in stronger words — running more than one product on a device gives “minimal” benefit and the products “may conflict with each other”.

The same passage covers the trial that came with your laptop. New computers “often come with a trial version of a separate antivirus product installed (such as McAfee, Norton and Avast)”, and “when the trial version expires, you’ll have to pay (or register) to continue using it”. Worth knowing before the reminders start, because the decision is then between paying and going back to the one that was already there.

On a phone or tablet, the NCSC’s answer is one word. To its own question — do I need antivirus products on my smartphone and tablet — it answers: “No, provided that you only install apps and software from official stores such as Google Play and the Apple App Store.” The condition is the whole of it, and it is a condition about your habits rather than about a product.

Do you need to add one? The answer differs by device, and both answers here come from the National Cyber Security Centre’s published guidance, read on 9 September 2026.
DeviceWhat is already thereAdd a separate product?
Windows or Mac computer Antivirus is “often included for free within the operating systems” Switch the built-in one on first. A separate product may not work alongside it.
Smartphone or tablet A reviewed app store, and automatic updates “No, provided that you only install apps and software from official stores”
A new computer with a trial pre-installed McAfee, Norton or Avast, on a clock Decide before it expires: “you’ll have to pay (or register) to continue using it”

And if you are choosing anyway, what actually differs

CISA is refreshingly unromantic about the choice, and it is the paragraph most likely to save someone an afternoon: “anti-virus software typically performs the same types of functions, so your decision may be driven by recommendations, particular features, availability, or price”, and “regardless of which package you choose, installing any anti-virus software will increase your level of protection”.

Which reframes the comparison. If the core function is broadly common, what you are choosing between is the surrounding material — a VPN, a password manager, a breach lookup, a family dashboard — and the price of the bundle. Those are ordinary purchasing questions, and they are answerable without a ranking.

CISA also covers what happens when something is found, and the variation is worth expecting: “sometimes the software will produce a dialog box alerting you that it has found malware and ask whether you want it to ‘clean’ the file”, while “in other cases, the software may attempt to remove the malware without asking you first”. Knowing which yours does is more useful than knowing its score, because it decides whether a silent disappearance is normal behaviour or a symptom.

One last piece of CISA advice has aged into something broader than antivirus: “resist believing alarmist emails claiming that the ‘worst virus in history’ or the ‘most dangerous malware ever’ has been detected” — those, it says, “are usually hoaxes”. The medium has moved to pop-ups and browser pages, and the instruction still holds.

Two public answers to the same question, written years apart CISA’s page was released in June 2009 and revised in September 2019, and describes signature scanning as the way antivirus works. The National Cyber Security Centre’s guidance answers no to whether a smartphone or tablet needs an antivirus product, provided apps come only from official stores, and warns that a separate product may stop the built-in one from working. SAME QUESTION, TWO PUBLIC AGENCIES, DIFFERENT EMPHASIS CISA released 30 June 2009, revised 27 September 2019 explains the mechanism: signatures, definitions, and their limit NCSC answers the practical question: turn on the one you have and for phones and tablets, “No, provided that you only install apps and software from official stores” Neither contradicts the other. Together they say: this is what it does, and here is where it is already doing it — which is the answer the question is usually asking for. AI Tools Primer · figure
Both were on the first page of results; neither of the two is a company with a product to sell. Figure drawn by AI Tools Primer.

The short version, by situation

Each line is what the two public agencies say, rather than a recommendation of ours.

You have a Windows PC or a Mac and no separate product You already have antivirus; the useful action is confirming it is switched on. Adding a second one may stop the first from working, on the NCSC’s own account.
You have a phone or a tablet No, provided apps come only from the official stores and everything updates automatically. That is the NCSC’s answer to its own question, condition included.
You are wondering whether a scan settles it It settles less than it appears to. Signature scanning finds “malware that has known characteristics”, so a clean result means nothing on the list was found — which is why CISA tells you to keep taking other precautions.

Why this page quotes two governments and no vendors. Three of the five best-known answers to this question are published by companies that sell security software or services, and the summary above them cites three more of the same kind. None of that is dishonest, and the definitions they give are broadly the ones above. But three sentences on this page would not appear in any of them, because no vendor has an occasion to write them: that a scanner cannot find what has no signature yet, that a second product may stop the first from working, and that a phone with apps from the official store needs nothing added. CISA and the NCSC wrote all three, and both were already on the first page of results.

Where this leads next. If the question behind the question is whether something is wrong right now, how to tell if your computer has a virus sorts the signs that mean something from the ones that do not, and removing malware from a computer is the sequence. If it is about a specific product, is MBAM safe works through what one of them collects and what Windows switches off to make room for it.

Where to start

Three ways in.

“What does it actually do?”
The mechanism — what it does
“Does it catch everything?”
CISA on the gap — the limit
“Do I need to buy one?”
Two answers by device — do you need one

The questions this one usually comes from

Almost nobody asks what antivirus is in the abstract. These are the situations underneath.

The devices where the answer is different

What can be installed decides what a scanner could even do, and that varies by system.

Questions people also ask

What are examples of antivirus software?

The NCSC names three that commonly arrive pre-installed as trials on new computers — McAfee, Norton and Avast — and notes that antivirus is “often included for free within the operating systems that run Windows and Apple computers”. This page does not rank them.

Do I need anti-virus software on my phone?

The NCSC answers its own version of this question with “No, provided that you only install apps and software from official stores such as Google Play and the Apple App Store”, and adds that apps and the device itself should update automatically.

How do I know if my computer has antivirus software?

On Windows, open Windows Security and look under Virus & threat protection, where the registered providers are listed. The NCSC’s point is that on Windows and Apple computers one is usually present already, so the check is whether it is switched on.

Does antivirus catch everything?

No, and CISA says so in the same page that explains how it works: because it relies on signatures it “can only detect malware that has known characteristics”, leaving you “susceptible to malware that circulates before the anti-virus vendors add their signatures”.

Should I install a second antivirus for a second opinion?

The NCSC advises against it: “separate antivirus products won’t always work alongside the built-in antivirus software and could even stop it from working completely”, and elsewhere that running more than one gives minimal benefit and may cause conflicts.

What is the difference between antivirus and anti-malware?

In practice little. CISA treats them as the same category, describing anti-virus software as “sometimes more broadly referred to as anti-malware software”. The distinction is mostly a marketing one rather than a technical boundary.

Not covered here. It does not rank antivirus products or name a best one. CISA’s own position is that anti-virus software “typically performs the same types of functions”, and a real comparison would need paid licences and controlled testing.

It does not cover business or managed environments, where the choice is made by policy and the considerations are different ones entirely.

And it does not cover what to do once something has been found. That is removing malware from a computer, which starts where a detection ends. What holds instead is simple: the mechanism and its signature limitation are quoted from CISA’s page including the dates it carries, the answers on whether a computer or a phone needs a product are quoted from the National Cyber Security Centre, no vendor page is used as a source and the page says why, and it gives no ranking because CISA’s own view is that these products perform the same types of functions.

Sources

  1. CISA — Understanding Anti-Virus Software, released 30 June 2009 and revised 27 September 2019: that anti-virus software scans files or memory for patterns based on the signatures or definitions of known malware; the distinction between automatic and manual scans and the advice to save and scan attachments rather than open them directly; that products typically perform the same types of functions so the choice may come down to features, availability or price; the two ways software responds when it finds something; and the statement that because it relies on signatures it can only detect malware with known characteristics, leaving you susceptible to malware that circulates before signatures are added — www.cisa.gov, read 9 September 2026.
  2. National Cyber Security Centre — What is an antivirus product? Do I need one?: the definition of an antivirus product and that such products work by detecting, quarantining and/or deleting malicious code; that antivirus is often included free within the operating systems running Windows and Apple computers and that switching the built-in one on makes you instantly safer; that separate products will not always work alongside the built-in software and could stop it working completely; the note on pre-installed trials from McAfee, Norton and Avast expiring; and the answer that smartphones and tablets do not need an antivirus product provided apps come only from official stores — www.ncsc.gov.uk, read 9 September 2026.
  3. National Cyber Security Centre — Antivirus and other security software, Device security guidance: that signature-based scanning has been limited in effectiveness by advances in malware and changes in underlying platforms; that many risks traditional antivirus protected against are now mitigated by default at operating-system level; and that running more than one antivirus product on a device gives minimal benefit and may cause the products to conflict — www.ncsc.gov.uk, read 9 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 9 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.