The Cybersecurity Course · Episode 6
Read time ~9 min · No prior knowledge

Antivirus &
malware

What is actually the difference between viruses, ransomware, spyware and trojans — and do you really need to pay for antivirus? We walk through the seven types of malware (including infostealers, perhaps today's biggest threat to private individuals), the six most common ways in, and give an honest assessment of the protection you already have.

Contents
  1. Seven types of malware
  2. Six ways in
  3. Windows Defender — an honest review
  4. Recommendations per platform
  5. Signs of infection — and what to do then
  6. Sources

Seven types of malware

"Virus" has become the everyday word for everything — but the types differ, and the most dangerous ones today are not the most famous:

Viruses & worms

The classics: code that spreads itself, via files (viruses) or networks (worms). Rarer as a standalone category today — but worm techniques live on in ransomware outbreaks.

Trojans

Pretend to be something useful — a game, a "codec", a pirated copy — and open the door for other things when you run them.

Ransomware

Encrypts your files and demands payment. Against private individuals, often fully automated. The best defence isn't antivirus but backups (episode 9).

Infostealers

Perhaps today's biggest threat to private individuals. Lightning-fast programs that vacuum the computer for saved passwords, crypto wallets — and session cookies: the small files that keep you logged in. With a stolen session cookie the attacker logs in as you without a password and sometimes past 2FA. The harvest is sold in bulk.

Spyware & stalkerware

Monitors in secret: keystrokes, microphone, location. Stalkerware is often installed by someone close to you with physical access to the device.

Adware

Hijacks the browser with ads and redirects. More annoying than dangerous — but often a door-opener for worse.

Rootkits & bot clients

Hide deep in the system and turn your computer into an obedient member of a botnet — episode 1's "raw material" in practice.

Six ways in

Windows Defender — an honest review

The protection built into Windows (Microsoft Defender) now performs at the top tier in independent tests at AV-TEST and AV-Comparatives. It's free, always updated, and unobtrusive. For most private individuals, Defender is enough — with three caveats:

The Kaspersky warning Kaspersky's products have performed well technically — but the company operates under Russian jurisdiction, and the US among others has banned its sale while several European authorities advise against it. An antivirus has total insight into your computer; the jurisdiction of that insight is a security decision. Our line: choose something else.

Recommendations per platform

PlatformRecommendationCost
WindowsMicrosoft Defender with ransomware protection enabled. If you want paid protection with more layers, Bitdefender is a reputable choice.Free · paid suites ~€30–70/yr
macOSBuilt-in XProtect/Gatekeeper go a long way. Supplement on suspicion with Malwarebytes as an on-demand scanner.Free
AndroidGoogle Play Protect + apps only from the Play Store. Sideloading is the real risk (episode 8).Free
iPhone/iPadClassic antivirus doesn't exist and isn't needed — the platform's sandbox model does the job. The threats on iOS are phishing and stolen passwords, not viruses.Free

Notice the pattern: good behaviour beats expensive software. No pirated copies, no downloads outside official sources, an updated system — and the free protection does the rest.

Signs of infection — and what to do then

Warning signs: the fan racing at idle, new toolbars or redirected searches, friends receiving messages you didn't send, unknown logins, the antivirus switched off without your knowledge, or ransom notes on the screen.

  1. Disconnect from the internet. That stops ongoing theft and spread.
  2. Run a full scan with Defender (offline scan) and/or Malwarebytes.
  3. Change passwords from another, clean device — starting with email. Assume everything saved in the browser is stolen, including active sessions: log out "all devices" on important accounts.
  4. Ransomware? Don't pay. Check No More Ransom — the police collaboration has free decryption tools for many variants. More in episode 16.
  5. If doubt remains: reinstall the system. Drastic but definitive — and with the backups from episode 9, it's an afternoon, not a catastrophe.
Next time Most of what you do on a computer now happens in the browser — which makes it both the target and the shield. Episode 7: what the HTTPS padlock actually promises, cookies and tracking, and which extensions genuinely help.

Sources

Want to dig deeper? These are the sources behind this episode.

  1. AV-TEST — av-test.org — independent antivirus testing.
  2. AV-Comparatives — av-comparatives.org — independent antivirus testing.
  3. Microsoft — Microsoft Defender Antivirus — documentation.
  4. CISA — Malware, Phishing, and Ransomware — overview and advice.
  5. Malwarebytes — malwarebytes.com — on-demand scanner for Windows/Mac.
  6. Bitdefender — bitdefender.com — paid option for Windows.
  7. Google — Google Play Protect — Android's built-in protection.
  8. Apple — Apple Platform Security — the security model in iOS/macOS.
  9. Europol et al. — No More Ransom — free decryption tools.
  10. Wikipedia — Kaspersky Lab — summary of bans and warnings.
  11. CERT-SE — cert.se — Swedish alerts on ongoing malware campaigns.
  12. ENISA — Threat Landscape — malware and infostealers in the EU threat picture.
Next episode

Episode 7 — Browser security

HTTPS, cookies, tracking — and which extensions actually help.