Antivirus glossary, A to Z

Each entry gives a working definition first, then, where it helps, a short worked example or a note on how the word tends to be used in product descriptions. Links lead to the longer explainers on this site or to the official source.

A

Adware
Software whose main purpose is to show advertising, often by changing browser settings, adding toolbars or opening pop-ups. Some adware is merely annoying; some also gathers browsing data. Security products commonly place it in the PUP category rather than treating it as outright malware, which is why a setting for "detect potentially unwanted programs" may need to be switched on to catch it.
Antivirus
Software that looks for, blocks and removes malicious software. The name dates from a time when viruses were the main concern; modern products deal with every kind of malware. See malware types explained for the full range.
Auto-renewal
A subscription setting under which the vendor charges your saved payment method at the end of each term unless you switch it off. It is common for software sold online. The price on renewal may differ from the first-term price, so check both. Covered in detail on the subscription terms page.

B

Behaviour monitoring
A detection method that watches what programs do while they run, rather than what their files look like. A program that suddenly starts rewriting hundreds of documents in quick succession, for example, behaves the way ransomware does, whatever its file contains. Explained further on the detection page.
Botnet
A network of compromised computers or devices controlled remotely, usually without their owners noticing, and used together to send spam, attack websites or spread more malware. Each member device is sometimes called a "bot" or "zombie".
Browser protection
A general label for features that check the websites you visit or the files you download against lists of known harmful addresses. Modern browsers include some of this themselves; security products may add their own layer through an extension. The label covers quite different things from one vendor to the next, so look for a description of what is actually checked.

C

Cloud lookup
A check in which the security software sends a fingerprint of a file (a hash) or a web address to the vendor's servers to see whether it is already known to be safe or harmful. It lets a product react to new threats without waiting for a full update, and it means some information about your files leaves your device. Vendors describe this in their privacy documentation.
Credential stuffing
An attack that takes usernames and passwords leaked from one service and tries them automatically on many others. It works because people reuse passwords. Antivirus software does little against it; unique passwords and multi-factor authentication do a great deal.

D

Definition update
A download that refreshes the list of signatures a product uses to recognise known malware. Also called a signature update or virus definitions. Most products fetch them automatically several times a day; a product that cannot update for a long period loses much of its usefulness.
Drive-by download
Malware delivered by a web page, typically through a flaw in an out-of-date browser or plug-in, without the visitor choosing to download anything. Keeping the browser and operating system updated is the main defence; this is why software updates appear in almost every official security checklist.

E

Encryption
Scrambling data so that only someone with the right key can read it. Encryption protects you when it is used on your behalf, such as on a banking website, and harms you when ransomware uses it against your files.
Exclusion
A file, folder or program that you tell your security software to ignore. Exclusions are sometimes needed to stop repeated false positives on legitimate software, but every exclusion is a blind spot. Add them sparingly and remove them when they are no longer needed.
Exploit
Code or a technique that takes advantage of a flaw (a vulnerability) in software to make it do something its makers did not intend. An exploit is the method; malware is often the payload it delivers.

F

False negative
Harmful software that a product fails to detect. No product achieves zero false negatives, which is why official guidance pairs security software with updates, backups and careful habits rather than treating any one tool as sufficient.
False positive
A harmless file or website wrongly flagged as dangerous. False positives are an unavoidable side-effect of detecting new threats by their characteristics rather than their identity. A procedure for dealing with one is on the detection page.
Firewall
A filter on network traffic that allows or blocks connections according to rules. Windows and macOS both include one. Some security suites replace or extend the built-in firewall with their own; a standalone antivirus product may not include one at all.

H

Hash
A short, fixed-length value calculated from a file's contents, acting as a fingerprint. Change one byte of the file and the hash changes completely. Security tools use hashes to recognise files they have seen before without having to compare the whole file.
Heuristic analysis
Detection based on suspicious characteristics or rules of thumb, rather than an exact match with known malware. It can catch new variants that have no signature yet, at the cost of more false positives.
Worked example. A downloaded file claims to be a PDF but is actually a program, is packed to hide its contents, and tries to add itself to the list of things that start with Windows. None of those facts alone proves it is harmful; together they are the kind of pattern a heuristic rule scores as suspicious.

K

Keylogger
Software or hardware that records keystrokes, typically to capture passwords and card numbers. Software keyloggers are a form of spyware.

L

Licence
Your permission, under the vendor's terms, to install and use the software. Antivirus licences are usually limited by number of devices and by time. "One-device licence" means exactly that: installing on a second device generally needs a second licence or a higher tier. See subscription terms.

M

Malware
Short for malicious software: any program written to damage, spy on, extort or otherwise act against the person using the device. Viruses, worms, trojans, ransomware and spyware are all types of malware. They are compared side by side on the malware types page.
Multi-factor authentication (MFA)
Signing in with something in addition to a password, such as a code from an app, a text message or a physical security key. The National Cyber Security Centre's Own Your Online guidance for households recommends turning it on for important accounts. It protects accounts in situations where antivirus software has no role at all.

O

On-demand scan
A scan you start yourself or schedule, as opposed to real-time protection. A "quick scan" checks the places malware most often hides; a "full scan" checks every file and takes much longer.

P

Patch
An update that fixes a flaw in software. Installing patches promptly closes the holes that exploits use, and is one of the most effective security steps a household can take.
Phishing
A message, usually an email, that pretends to come from a trusted organisation in order to get you to reveal information, pay money or open something harmful. Variants by text and phone have their own names. All are explained on the scam terms page.
PUP (potentially unwanted program)
Software that is not clearly malicious but that most people would not knowingly want: bundled toolbars, aggressive "PC optimiser" tools, browser hijackers and similar. Vendors also use the terms PUA (potentially unwanted application) and greyware. Because PUPs are often installed with technical consent hidden in an installer, products usually detect them separately and sometimes only if you switch the option on.

Q

Quarantine
A protected holding area where a security product moves a suspicious file so that it cannot run. The file can be restored if the detection turns out to be wrong, or deleted once you are satisfied it is harmful.

R

Ransomware
Malware that encrypts files or locks a device and demands payment for their release. Ransomware incidents can be reported to the National Cyber Security Centre through its reporting page. Offline or versioned backups are the most reliable way to recover without dealing with the attacker.
Real-time protection
Continuous checking of files as they are created, opened, downloaded or run. Also called on-access scanning. It is the part of an antivirus product that works without you doing anything, and the part most worth leaving switched on.
Remote access tool
Software that lets someone control a computer from elsewhere. It has legitimate uses in IT support. Scammers persuade people to install it so they can take control of the machine; the tool itself is often not flagged as malware, because it is legitimate software being misused.
Rootkit
Malware designed to hide itself, or other malware, deep in the operating system so that ordinary tools cannot see it. Removal can require specialist tools or a full reinstall.

S

Sandbox
An isolated environment in which a suspicious file can be run and observed without being able to affect the real system. Some security products use sandboxing to decide whether an unknown program is safe. Mobile operating systems also sandbox every app as a matter of design.
Scareware
Software or web pages that use alarming, false warnings — fake scan results, flashing alerts, claims that your device is compromised — to frighten people into paying for something or installing malware. A genuine security product's notifications appear within your operating system, not inside a web page you happened to visit. Further detail is on the scam terms page.
Signature
A pattern, such as a hash or a distinctive sequence of bytes, that identifies a specific piece of known malware. Signature matching is fast and accurate for known threats and blind to brand-new ones, which is why products combine it with heuristics and behaviour monitoring.
Spyware
Malware that secretly collects information — keystrokes, browsing, messages, location — and sends it to someone else. Covered on the malware types page.

T

Trojan
Malware disguised as something useful or harmless, such as a free utility, a cracked game or a document, which relies on the user to run it. Unlike a virus or worm, a trojan does not spread by itself.
Two-step verification
A common consumer name for multi-factor authentication, particularly where the second step is a code.

W

Web filtering
Blocking access to websites by category or by reputation. Security products use it to block known harmful sites; parental control tools use it to block categories of content.
Worm
Malware that spreads by itself from device to device over a network, without needing anyone to open a file. Worms typically exploit unpatched flaws, which is another reason updates matter.

Z

Zero-day
A software flaw that attackers know about before the software's maker has released a fix — the maker has had "zero days" to respond. Signature-based detection cannot recognise an attack that has never been seen, so defences against zero-days rely on behaviour monitoring, sandboxing and limiting what software is allowed to do.

A note on vendor-specific names. Security vendors often give their own branded names to standard techniques. A branded feature name usually maps onto one or more of the general terms above, and the vendor's documentation normally explains which. When two products seem to offer different things, translating the branded names back into these general terms is often the quickest way to compare them.