Home · Guides · Antivirus
Decision hub
Antivirus under constraints
For people who need a straight answer on paid endpoint security vs built-in protection — especially on Windows households — without scareware popups or “PC repair” side quests.
Affiliate disclosure: When partner programs are accepted, recommendations may use tracked partner links. We may earn a commission at no extra cost to you. See disclosure. Example brands below are not a live ranking; links are placeholders.
Junkware filter: This vertical is a minefield. We will not promote keyshops, fake cleaners, or brands with strong scareware / repairware reputation — regardless of commission attractiveness.
Who this is for
- Windows users (or mixed households) deciding if Defender + browser hygiene is enough.
- Families that want one license covering multiple PCs without mystery “optimizer” bundles.
- People cleaning up after a scare and want reputable tools — not the first ad result.
- Fully updated Mac, low-risk browsing, disk encryption on — paid AV is often optional.
- You’re shopping because a random popup said you’re infected — stop; don’t buy the popup’s product.
- You need MDM/EDR for a company fleet — different product class entirely.
- Your real problem is reused passwords and phishing — start with password hygiene.
Constraint checklist
- OS & baseline already on Windows Security / Defender, SmartScreen, macOS XProtect/Gatekeeper, automatic updates. Paid AV starts from this baseline, not zero.
- Risk behavior Piracy sites, random “codec” installs, shared family PC, or high-phishing email volume change the value of extra layers.
- Real-time protection vs on-demand Always-on vs occasional scanner. Most people need real-time; second scanners can conflict — don’t stack blindly.
- Performance budget Old laptops hate heavy suites. Lightweight reputable > bloated “total security” skins.
- Multi-device licensing How many Windows/Mac/Android seats, and whether mobile is actually used.
- Feature honesty Firewall skins, VPN trials, password managers, and “dark web monitoring” are often upsells. Score only features you’ll enable.
- Independent testing signals Look for sustained lab testing presence — not a single screenshot in an ad. We won’t invent test scores we didn’t check.
- Price ceiling & renewal Day-1 promo vs year-2 price. Commodity AV is rarely worth max-tier bundles.
- Reputation gate Hard fail: scareware UX, fake infection counts, aggressive browser hijacks, gray-market keys.
Dimensions that matter
Baseline first
Updated OS protections are the floor. Paid tools are incremental, not a substitute for patches.
Behavior risk
Who uses the PC and how they install software predicts need better than fear ads.
Performance cost
A suite that makes a family laptop unusable gets uninstalled — security regresses to zero.
Bundle skepticism
VPN + cleaner + “identity” add-ons should win on their own hubs, not ride along automatically.
Second-opinion role
On-demand scanners can help after a scare; stacking two real-time engines can fight each other.
Reputation hard-fail
If the business model looks like panic, it’s out — even with a shiny landing page and strong EPC.
How Hexento decides
Default posture: built-in + updates + browser discipline is enough for many low-risk users. Paid picks must clear the reputation gate, then match OS, seats, and performance constraints. Partner EPC never overrides a junkware fail. See methodology.
Result shape: “stay with built-in,” “add reputable real-time on Windows,” or “targeted second-opinion scanner” — with explicit bundle features to ignore.
Illustrative fits Not a live ranking
Known-brand examples for vertical substance. Not ordered by quality or payout.
Microsoft Defender (built-in)
Often fits: updated Windows 10/11 machines with moderate risk and users who won’t tolerate heavy suites.
No affiliate — honest optionMalwarebytes illustrative
Often fits: malware-focused protection / second-opinion workflows after a scare; confirm real-time tier vs on-demand needs.
Watch: what exactly the SKU enables; don’t assume free scanner ≡ full real-time.
Partner link pendingESET illustrative
Often fits: users who want lighter-weight reputable protection and will read which home SKU they need.
Watch: “internet security” bundling vs plain antivirus.
Partner link pendingNorton / McAfee / AVG class illustrative
Role: wide retail distribution. Evaluate bloat, renewal pricing, pre-install baggage, and whether you want the suite at all.
Watch: brand familiarity ≠ automatic recommend; year-two pricing surprises.
Partner link pendingExplicit non-slots
Keyshops, MacKeeper-class reputation risks, fake cleaners, “Reimage your PC” repairware — out of methodology on purpose.
Will not promoteFailure modes we care about
- Popup-driven purchasing — malware’s cousin is the ad that sells the cure.
- Suite bloat uninstall — performance pain → user disables protection entirely.
- Double real-time stacking — conflicting agents, mysterious breakage, false sense of “more = better.”
- Ignoring the human layer — AV can’t fix admin passwords on shared family accounts or random USB habits alone.
- Gray-market keys — cheap “lifetime” codes that vanish; also a trust and malware vector.
FAQ
Is Windows Defender actually enough?
For many updated, moderate-risk users, yes. Paid tools become more interesting with higher-risk behavior, multi-PC family chaos, or after incidents — not because a homepage said “PC at risk.”
Do Macs need antivirus?
Often optional for careful users on current macOS. Risk isn’t zero, but the Windows-scare script usually doesn’t transfer 1:1. Behavior and updates still dominate.
Should I run two antivirus engines?
Don’t run two real-time engines by default. A reputable on-demand second opinion can be useful; simultaneous always-on suites often fight.
Why refuse high-paying junk brands?
Because trust is the product. One scareware recommendation poisons the brand and should fail network quality review anyway. See methodology.
Related
VPN · Password managers · Data removal & privacy ops · Pickguard · Methodology