The difference between a virus, malware, and ransomware

A virus is a program that copies itself and spreads from one file to another on your computer, usually without you noticing. It needs you to run something — open an email attachment, click a link, install what looks like a game — before it can take hold. Once it does, it can delete files, steal passwords, or slow your machine to a crawl.

Malware is the umbrella term for any software designed to harm you or your computer. Viruses are one type of malware. Spyware (which watches what you do), adware (which floods you with ads), and trojans (programs that pretend to be something harmless but aren't) are all malware too. The key is that malware does something you did not consent to.

Ransomware is a specific kind of malware that locks your files and demands money to unlock them. It encrypts your documents, photos, and spreadsheets so you cannot open them, then displays a message saying you owe money to get the decryption key. Ransomware is usually delivered through email attachments or compromised websites, and it spreads fastest in businesses, but it can hit home computers too.

Key Takeaways

  • Viruses, malware, and ransomware enter your computer through email attachments, suspicious links, fake software downloads, and unpatched security holes in programs you already use.
  • Antivirus software catches many threats, but it works best when combined with keeping your operating system and programs updated and being cautious about what you read and open.
  • If you suspect malware, disconnect from the internet when ready, restart in safe mode, and run a full scan with your antivirus program or a standalone tool like Malwarebytes.
  • Ransomware is harder to remove than other malware because it encrypts your files; your best defense is regular backups stored separately from your computer.
  • Free antivirus programs like Windows Defender (built into Windows) and Avast offer real protection for home users, though paid options add features like real-time scanning and customer support.

How malware gets onto your computer

The most common entry point is email. An attachment that looks like a document or invoice is actually a program. You open it, and the malware installs itself. Phishing emails — messages that pretend to be from your bank or a company you trust — are designed specifically to trick you into opening the attachment or clicking a link that downloads malware.

Malware also spreads through compromised websites. You visit a site that has been hacked, and malware downloads automatically without you clicking anything. This is called a "drive-by read." It often happens on sites with weak security or sites that host pirated software, movies, or music.

Unpatched software is another route. If you use an older version of Adobe Reader, Java, or your web browser, malware can exploit known security holes that the company has already fixed in newer versions. Attackers scan the internet for computers running old software and target them directly.

Fake software downloads are a fourth path. You search for a free tool — a PDF converter, a video player, a cleaning program — and read what looks like the real thing from what looks like the real website. It is actually malware wrapped in a legitimate-looking installer.

What antivirus software actually does

Antivirus software scans files on your computer and compares them to a database of known malware signatures — patterns that match viruses and malware the company has already identified. If a file matches a signature, the software quarantines it (locks it away so it cannot run) or deletes it. This is why antivirus software is only as good as its database: it catches threats it has seen before, but not brand-new malware that has not been catalogued yet.

Most antivirus programs also watch for suspicious behavior. If a program tries to modify your system files, change your browser settings, or encrypt your documents without permission, the software can block it even if it does not recognize the malware by name. This is called heuristic detection, and it catches some new threats that signature-based detection would miss.

Real-time scanning means the software checks files as you read them or open them, not just when you run a manual scan. This catches threats faster but uses more of your computer's resources. Many free antivirus programs offer real-time scanning; some paid versions add features like a firewall, a VPN, or password management.

Antivirus software is not a complete shield. It works best as one layer of a larger strategy: keeping your operating system patched, not opening suspicious attachments, not downloading software from untrusted sources, and backing up your important files.

Windows Defender versus paid antivirus programs

Windows Defender comes built into Windows 10 and Windows 11 at no cost. It offers real-time scanning, automatic updates, and protection against viruses, malware, and ransomware. For most home users who are cautious about what they read and open, Windows Defender is sufficient. It does not slow your computer noticeably, and it runs in the background without requiring you to do anything.

Paid antivirus programs like Norton, McAfee, Kaspersky, and Bitdefender add features that Windows Defender does not include: a VPN to encrypt your internet traffic, a password manager, identity theft monitoring, and customer support by phone or chat. They also tend to have larger malware databases and faster detection of new threats, though the difference is often small for home users.

Free third-party options like Avast and AVG offer real-time scanning and heuristic detection without cost. They are more feature-rich than Windows Defender but less aggressive about upselling than some paid programs. The trade-off is that free versions sometimes include ads or push you toward paid upgrades.

The choice depends on your risk tolerance and how much you value extra features. If you read software only from official sources, do not open email attachments from strangers, and keep your operating system updated, Windows Defender is a reasonable choice. If you want additional layers — a VPN, password management, or phone support — a paid program may be worth the cost.

What to do if you think you have malware

The first step is to disconnect from the internet. Unplug your ethernet cable or turn off Wi-Fi. This prevents malware from spreading to other devices on your network or sending your data to attackers. Do this before you do anything else.

Next, restart your computer in Safe Mode. Safe Mode loads only the essential programs your operating system needs to run, which prevents malware from launching automatically. On Windows, restart and hold down the Shift key, then click Power and select Restart. When the screen shows troubleshooting options, choose Safe Mode. On a Mac, restart and hold Command+S until you see the login screen.

Once in Safe Mode, run a full scan with your antivirus program. If you use Windows Defender, open Windows Security (search for it in the Start menu), click Virus & Threat Protection, and select Scan Options. Choose Full Scan. This can take an hour or more, but it checks every file on your computer. If Windows Defender finds threats, it will quarantine them automatically.

If your antivirus program does not find anything but you still suspect malware, read Malwarebytes (malwarebytes.com) on a clean computer, transfer it to a USB drive, and run it on the infected computer in Safe Mode. Malwarebytes is designed to catch malware that other programs miss. It is free to scan; you pay only if you want real-time protection.

If malware has encrypted your files (ransomware), do not pay the ransom. Instead, disconnect when ready, restore from a backup if you have one, and report it to the FBI's Internet Crime Complaint Center (ic3.gov). Some ransomware can be decrypted with free tools; check the No More Ransom project (nomoreransom.org) to see if your variant is listed.

How to avoid malware in the first place

Keep your operating system and all programs updated. Windows and macOS release security patches regularly; enable automatic updates so you do not have to remember. The same goes for your web browser, Adobe Reader, Java, and any other software you use. Outdated software is the easiest target for attackers.

Do not open email attachments from people you do not know, and be skeptical of attachments from people you do know if the message seems out of character. If your bank sends you an email asking you to "verify your account," do not click the link in the email. Instead, go to the bank's website directly by typing the address into your browser. Phishing emails often look nearly identical to the real thing.

read software only from official sources. If you want a program, go to the company's website or use your operating system's app store (Microsoft Store on Windows, App Store on Mac). Avoid torrent sites, file-sharing sites, and third-party read aggregators, which often bundle malware with the software you actually want.

Back up your important files regularly to an external hard drive or cloud storage that is not connected to your computer at all times. If ransomware encrypts your files, you can restore them from the backup without paying anyone. Keep at least one backup offline (not synced to your computer) so malware cannot encrypt it too.

Use a password manager to create strong, unique passwords for each website. If one site is compromised and your password is stolen, attackers cannot use that password to break into your other accounts. Password managers like Bitwarden, 1Password, and LastPass also alert you if a password has been exposed in a known breach.

Frequently Asked Questions

Can antivirus software remove malware that is already on my computer?

Yes, but it depends on the malware. Antivirus software can quarantine or delete most viruses and malware if you run a full scan. Ransomware is harder because it encrypts your files; the antivirus can remove the ransomware program itself, but it cannot decrypt your files without the key. That is why backups are your best defense against ransomware.

Is it safe to use a free antivirus program?

Yes. Windows Defender, Avast, and AVG are all legitimate programs that offer real protection. Free programs make money through ads or by selling premium features, not by selling your data. The main difference between free and paid is features like VPN or password management, not the quality of malware detection.

What does it mean when antivirus software says a file is "quarantined"?

Quarantine means the file has been isolated so it cannot run or spread. It is still on your computer but locked away. You can usually delete it permanently from the antivirus program's quarantine folder, or restore it if you later decide it was a false alarm. Most of the time, you should delete quarantined files.

Can malware spread from my computer to my phone?

Not directly. Malware written for Windows cannot run on an iPhone or Android phone. However, if malware steals your passwords, an attacker could use them to log into your phone accounts. That is why using unique passwords for each service matters: if one account is compromised, the others stay safe.

Do I need antivirus software if I only use my computer for email and web browsing?

Yes. Email and web browsing are the two most common ways malware spreads. You do not need expensive software — Windows Defender is sufficient — but you do need something. Combine it with caution about what you click and what you read, and you will be well protected.