Antivirus &
malware
What is actually the difference between viruses, ransomware, spyware and trojans — and do you really need to pay for antivirus? We walk through the seven types of malware (including infostealers, perhaps today's biggest threat to private individuals), the six most common ways in, and give an honest assessment of the protection you already have.
Seven types of malware
"Virus" has become the everyday word for everything — but the types differ, and the most dangerous ones today are not the most famous:
Viruses & worms
The classics: code that spreads itself, via files (viruses) or networks (worms). Rarer as a standalone category today — but worm techniques live on in ransomware outbreaks.
Trojans
Pretend to be something useful — a game, a "codec", a pirated copy — and open the door for other things when you run them.
Ransomware
Encrypts your files and demands payment. Against private individuals, often fully automated. The best defence isn't antivirus but backups (episode 9).
Infostealers
Perhaps today's biggest threat to private individuals. Lightning-fast programs that vacuum the computer for saved passwords, crypto wallets — and session cookies: the small files that keep you logged in. With a stolen session cookie the attacker logs in as you without a password and sometimes past 2FA. The harvest is sold in bulk.
Spyware & stalkerware
Monitors in secret: keystrokes, microphone, location. Stalkerware is often installed by someone close to you with physical access to the device.
Adware
Hijacks the browser with ads and redirects. More annoying than dangerous — but often a door-opener for worse.
Rootkits & bot clients
Hide deep in the system and turn your computer into an obedient member of a botnet — episode 1's "raw material" in practice.
Six ways in
- Phishing attachments and links — still route number one (episode 4).
- Pirated software and "cracks" — a large share of infostealer infections arrive via downloaded games, programs and cheats. The free program cost you your passwords.
- Malvertising and fake download sites — ads leading to counterfeit downloads of popular software; often at the top of search results.
- Unpatched vulnerabilities — episode 5. No click required.
- USB and physical access — found or "borrowed" memory sticks, plus stalkerware installed by someone close.
- Fake support — "Microsoft calling" asking for remote control, or a popup ordering you to install "the update". Microsoft never calls.
Windows Defender — an honest review
The protection built into Windows (Microsoft Defender) now performs at the top tier in independent tests at AV-TEST and AV-Comparatives. It's free, always updated, and unobtrusive. For most private individuals, Defender is enough — with three caveats:
- The ransomware protection is off by default. Enable "Controlled folder access" under Windows Security → Virus & threat protection → Ransomware protection settings.
- Web and phishing protection is tied to SmartScreen and works best in Edge; in other browsers it relies more on the browser's own protection and your own eye (episode 7).
- No extras bundle. Paid suites bundle VPNs, identity monitoring and password managers — but you've already solved those parts better, piece by piece, in this course.
Recommendations per platform
| Platform | Recommendation | Cost |
|---|---|---|
| Windows | Microsoft Defender with ransomware protection enabled. If you want paid protection with more layers, Bitdefender is a reputable choice. | Free · paid suites ~€30–70/yr |
| macOS | Built-in XProtect/Gatekeeper go a long way. Supplement on suspicion with Malwarebytes as an on-demand scanner. | Free |
| Android | Google Play Protect + apps only from the Play Store. Sideloading is the real risk (episode 8). | Free |
| iPhone/iPad | Classic antivirus doesn't exist and isn't needed — the platform's sandbox model does the job. The threats on iOS are phishing and stolen passwords, not viruses. | Free |
Notice the pattern: good behaviour beats expensive software. No pirated copies, no downloads outside official sources, an updated system — and the free protection does the rest.
Signs of infection — and what to do then
Warning signs: the fan racing at idle, new toolbars or redirected searches, friends receiving messages you didn't send, unknown logins, the antivirus switched off without your knowledge, or ransom notes on the screen.
- Disconnect from the internet. That stops ongoing theft and spread.
- Run a full scan with Defender (offline scan) and/or Malwarebytes.
- Change passwords from another, clean device — starting with email. Assume everything saved in the browser is stolen, including active sessions: log out "all devices" on important accounts.
- Ransomware? Don't pay. Check No More Ransom — the police collaboration has free decryption tools for many variants. More in episode 16.
- If doubt remains: reinstall the system. Drastic but definitive — and with the backups from episode 9, it's an afternoon, not a catastrophe.
Sources
Want to dig deeper? These are the sources behind this episode.
- AV-TEST — av-test.org — independent antivirus testing.
- AV-Comparatives — av-comparatives.org — independent antivirus testing.
- Microsoft — Microsoft Defender Antivirus — documentation.
- CISA — Malware, Phishing, and Ransomware — overview and advice.
- Malwarebytes — malwarebytes.com — on-demand scanner for Windows/Mac.
- Bitdefender — bitdefender.com — paid option for Windows.
- Google — Google Play Protect — Android's built-in protection.
- Apple — Apple Platform Security — the security model in iOS/macOS.
- Europol et al. — No More Ransom — free decryption tools.
- Wikipedia — Kaspersky Lab — summary of bans and warnings.
- CERT-SE — cert.se — Swedish alerts on ongoing malware campaigns.
- ENISA — Threat Landscape — malware and infostealers in the EU threat picture.
Episode 7 — Browser security
HTTPS, cookies, tracking — and which extensions actually help.