What is antivirus software and how does it work?

Antivirus software has evolved a lot recently, and we need it more than ever

what is antivirus software antivirustock01
Yui Mok - PA Images/GettyImages

You’ve probably been hearing about antivirus software as long as you’ve had a computer. It’s been a staple of almost every pre-built PCs since the early 90s, and if you ask your friendly, neighborhood ‘IT guy’ how to protect your system, invariably they’ll suggest you have some sort of antivirus solution in place. If you use best practices for staying safe online like not clicking on links or attachments in emails, not visiting dodgy websites, and sticking to curated app stores on your mobile devices, your antivirus may simply operate in the background not seeming to do much, even though it does.

But what is antivirus software, and how does it work? There are a number of definitions and depending on which company you go to for their security solution, their tactics for targeting malicious applications like viruses and ransomware can be quite different. Being well-versed in what these sorts of tools can do is the best way to make an informed choice about the best antivirus software for you or your small business.

What is antivirus?

Antivirus software, or as it’s more commonly known today, anti-malware software, is a tool that looks for applications that run on your PC (or smartphone) that shouldn’t be there. It uses a number of methods to differentiate between that Word document you’re editing and a nasty piece of software that’s going to throw up annoying pop up adverts or steal your bank details. It can even spot when otherwise legitimate applications have been hijacked by a virus.

Some antivirus software uses “live” protection to automatically block such viruses and malware from running at all, even stopping you visiting websites or opening emails that may have viruses attached to them. Others, known as remediation tools, offer scanning functionality only, and must be run in order to clean up a malware infection after it has taken hold.

When antivirus software finds a malicious program on your system it will typically offer options for quarantining it — making it unable to operate as intended — or delete it entirely. Although getting rid of them makes sure your system is cleaned from the infection, quarantining does have some benefit in that it makes it easier for the antivirus software companies to analyze the threat and potentially alter their antivirus solution to be more capable of defending against it in the future.

Do you need antivirus software?

Modern operating systems come with a number of built-in protections like firewalls or Windows Defender, to help prevent viruses from taking hold on your system. If you’re careful with how you use your devices and steer clear of links, attachments, and dodgy websites, or even operate on a virtual machine, then you may well be safe from most virus threats.

That said, there are threats out that even the most well-prepared PC or mobile user can’t prepare for. Sometimes legitimate download servers are hijacked and flaws in the Wi-Fi network you connect to could leave you vulnerable in other ways entirely. Having a robust antivirus solution that runs alongside all of the modern operating system and browser protections is a great first step in protecting yourself and your system. At worst, it provides peace of mind that you should be protected against nasty threats like ransomware, and at best, it halts those threats in their tracks should you stumble across them as you venture forth online.

You don’t always have to pay for it, as there are great free antivirus applications out there. However, we’d recommend you have at least one of them running on all your devices, just to make sure you at least have the basic protections in place.

Which antivirus should you choose?

Choosing the right antivirus is much like any other technological decision — it very much depends on you. There are tools that are great remediation scanners, others with plenty of preemptive protective measures, and some that do more than just block malware attacks. But there are some that are worth recommending over others to help you get started. After all, downloading just any old security software can sometimes put you at even greater risk.

Some of our favorite antivirus programs include the likes of BitDefender’s Antivirus Free Edition and Avast Free Antivirus. Out of the premium solutions, MalwareBytes is one of the best, offering protections against all sorts of threats, as well as active web protection to help you avoid dodgy websites entirely.

If you’re looking for the best Mac Antivirus, here are some of our favorites.

How does antivirus work?

Antivirus software has changed a lot over the years. While the earliest iterations of it were bespoke programs designed to specifically target individual viruses, today there are millions upon millions of different pieces of malicious software out there. To combat that ever-evolving threat, antivirus software has changed and expanded in scope. The best anti-malware solutions today use a combination of different tactics to help protect your PC and MacOS desktops, as well as your smart devices and networks.

Here are the three methods antivirus software most commonly use:


The most tried, tested, and reactionary of the methods used to combat viruses and other malware, signature-based detection looks for the specific digital code of a virus and if it spots it, quarantines or deletes it. Think of it like a virus’ fingerprint. The upside to it is that once a virus has been identified it can be added to a signature database which is stored locally or in the cloud and then accessed when scanning a system for threats. The downside to it is that it’s not very useful for brand new threats. It requires at least one person or system to be attacked by the malicious software and identify it before everyone else can be protected against it.

With hundreds of thousands of new viruses being created every day, more is needed to keep modern systems safe. That’s why, although MalwareBytes’ free tool provides mere signature scanning, its premium versions do much more.

Behavioral detection

A more modern technique for tracking down known and unknown viruses and malware is behavioral detection. Instead of looking at what a piece of software is, behavior monitoring looks at what software does. The way a human might operate certain programs, or the operating system like Windows or MacOS may perform certain functions is quantifiable and relatively well-defined. Viruses and other malicious programs, however, tend to perform certain functions which aren’t typical of a user.

Malware might attempt to shut down or bypass anti-virus solutions on the system. It might try to make it so that it runs every time you startup your system without asking, or contact an external server to download other malicious software to your system. Behavioral analysis looks for software attempting to perform these functions and even at the potential for applications to perform them, once again quarantining or deleting them as they are detected.

Although there is greater potential for false positives with behavioral detection than signatures, it’s a crucial component in the antivirus puzzle. Ransomware attacks that encrypt files and demand payment to unlock them, require a very fast response and signatures alone would be unlikely to be able to stop it. Behavioral detection however, like that offered by BitDefender, can spot encryption and halt it in its tracks, even rolling back any encrypting it has done in some cases.

Machine learning

Teaching computers how to do something has always been difficult and time-consuming, but machine learning allows computers to teach themselves in a much more efficient manner. That’s exactly what machine learning in antivirus leverages in order to provide another important layer in modern anti-malware protections.

Antivirus software that uses machine learning can analyze the code of applications and decide based on its understanding of malicious and benign programs, whether that particular piece of software is dangerous or not. It’s effectively an artificial intelligence solution and when used in conjunction with other security protocols has proved extremely effective at combating threats new and old. In some cases, companies like Cylance are using it as their only antivirus solution, though most offer a more rounded toolset.

Machine learning does require internet connectivity so that it can leverage the power of cloud-connected databases of information which it then draws from to detect malicious software. However, it can evolve and adjust far quicker than the more human curated methods of antivirus protections and that helps keep the most modern solutions up to date with the ever-evolving threat landscape.


Turn your iPad into a display for your new Mac Mini with this workaround

The folks at Luna Display have figured out a workaround which lets you get the best of both worlds and use Wi-Fi and an adapter in order to turn your iPad into a display for the 2018 Mac Mini.

Windows Update not working after October 2018 patch? Here’s how to fix it

Windows update not working? It's a more common problem than you might think. Fortunately, there are a few steps you can take to troubleshoot it and in this guide we'll break them down for you, step by step.

Here's why 64-bit (not 32-bit) dominates modern computing

Today's computing world isn't the same as it once was. With 64-bit processors and operating systems replacing the older 32-bit designs, we look at what 32-bit vs. 64-bit really means for you.

These are the 5 best free antivirus apps to protect your MacBook

Malware protection is more important than ever, even if you eschew Windows in favor of Apple's desktop platform. Thankfully, protecting your machine is as easy as picking from the best free antivirus apps for Mac suites.

The 100 best Android apps turn your phone into a jack-of-all-trades

Choosing which apps to download is tricky, especially given how enormous and cluttered the Google Play Store has become. We rounded up 100 of the best Android apps and divided them neatly, with each suited for a different occasion.

Latest SMS breach could allow hackers access to your online accounts

A new security breach that exposed more than 26 million text messages could be a huge nightmare for users relying on two-factor authentication. Many of the SMS on the database contained security codes and account reset links.

Microsoft’s Windows 10 Mail client goes freemium with the introduction of ads

Microsoft Windows Insiders are finding a nasty surprise inside the Mail app on the latest Windows 10 preview build in the form of banner ads. These ads will appear in the Mail app regardless of the webmail service you use.

All the best Apple MacBook deals for Black Friday 2018

Shoppers looking for a new Apple laptop could find huge savings on a new MacBook come Black Friday. Retailers are offering discounts as much as $650 on select MacBook, MacBook Air, and MacBook Pro models this holiday season.

Apple discontinues AirPort Extreme, Time Capsule as it exits Wi-Fi router business

Apple is now officially no longer in the router business. The company had already stopped selling the AirPort Express, and now its retail stores and websites have stopped offering the AirPort Extreme and Time Capsule.

Secure your Excel documents with a password by following these quick steps

Excel documents are used by people and businesses all over the world. Given how often they contain sensitive information, it makes sense to keep them from the wrong eyes. Thankfully, it's easy to secure them with a password.

Lost your router? Here's how to find its IP address to help track it down

Changing the login information for your router isn't always easy, that's why so many have that little card on the back. But in order to use it, you need to know where to go. Here's how to find the IP address of your router.

PDF to JPG conversion is quick and easy using these simple methods

Converting file formats can be an absolute pain, but it doesn't have to be. We've put together a comprehensive guide on how to convert a PDF to JPG, no matter which operating system you're running.

Crypto hangover could take blame for Nvidia’s potential GeForce RTX 2060 delay

Nvidia's delay in announcing a ship date for its GeForce RTX 2060 GPU could be due to a burst in the cryptocurrency mining bubble. Executives blamed the crypto hangover for an oversupply of inventory on existing GTX 1060 cards,

Save $900 on the ThinkPad X1 Carbon and more with Lenovo’s Cyber Monday sales

In the latest set of holiday sales, Lenovo is heavily discounting its fifth-generation ThinkPad X1 Carbon and other popular Windows laptops and 2-in-1s for the holiday shopping season.