Advertising disclosure: this page carries partner links. If you buy through one, Bovama stav s.r.o. earns a commission from the vendor — the price you pay is unchanged. How this site is funded.
Security software explained

Norton AntiVirus Plus: what it actually includes — and how to judge any antivirus

Why you are seeing this page

This article is advertising-funded. The buttons marked partner link lead to the vendor through an affiliate programme, and Bovama stav s.r.o. is paid a commission on sales made that way. That funding pays for the writing and hosting; it does not buy a favourable verdict, and everything below that can be checked has been checked against the vendor’s own documentation, which is cited at the end.

We are not Norton and we cannot sell, service or cancel a Norton subscription. Read the full funding disclosure.

Marketing pages for security software tend to blur the line between what you are buying and what the vendor sells one tier up. This page separates the two for Norton AntiVirus Plus, explains how modern detection works, and gives you a method for checking any antivirus claim yourself.

The short version

  • Norton AntiVirus Plus covers one device, not a household.
  • It includes real-time malware protection, a Smart Firewall, a Password Manager and 2 GB of cloud backup on Windows.
  • It does not include Secure VPN, Dark Web Monitoring, SafeCam or parental controls. Those belong to the Norton 360 tiers.
  • The advertised first-year price is promotional; the subscription renews automatically at the vendor’s then-current rate unless you turn that off.
  • No antivirus product replaces updates, unique passwords and a tested backup.

Everything above comes from the vendor’s own product page. Where our description and Norton’s own information diverge, Norton’s information prevails — features and terms change without notice.

Why home devices are targets

There is a persistent belief that criminals only go after companies. In practice, a home computer is a target precisely because it is cheap to attack at scale. Attacks on individuals are not hand-crafted; they are sent to millions of addresses at once, and a fraction of a percent success rate is enough to make the campaign profitable.

The volume involved is easy to underestimate. The AV-TEST Institute, an independent German testing laboratory, states that it registers over 450,000 new malicious programs and potentially unwanted applications every day. That figure counts distinct samples, not distinct campaigns — a single family of malware can generate thousands of variants automatically, precisely so that any scanner relying on a list of known files falls behind.

That is the core problem a modern security product has to solve: the thing arriving on your machine has very often never been seen before by anybody.

How malware actually arrives

Almost every consumer infection starts with a route that requires one human decision. Understanding the four common routes tells you more about your own risk than any product comparison.

Diagram: four entry routes for malware - an email attachment or link, a fake or cracked download, a malicious advert or hacked website, and a removable or shared drive - all leading to a central device, and from there to outcomes such as encrypted files, stolen passwords, a hijacked banking session, botnet membership and resold access.
Figure 1. The four routes that account for most consumer infections, and what typically follows. Original diagram produced for this page; no vendor material is reproduced.

Notice what all four have in common: the decisive moment is a person clicking, running or allowing something. Security software exists to catch what gets past that moment — not to make the moment irrelevant.

How a scanner reaches a verdict

“Antivirus” is a misleading name for what these products now do. Comparing files against a list of known malware is only the first and least interesting step.

Diagram: a five-stage pipeline. A file arrives, is compared against known malware signatures, is examined by heuristics without being run, is watched for suspicious behaviour while running, and finally receives a verdict of allow, quarantine or block. A cloud reputation lookup feeds the middle three stages.
Figure 2. The stages a file passes through before a security product decides what to do with it. Original diagram produced for this page.

Signatures

A signature is a fingerprint of a file already identified as malicious. Matching is fast and produces almost no false alarms, but by definition it only catches what somebody has already analysed. Against 450,000 new samples a day, signatures alone are a rear-guard action.

Heuristics and static analysis

Here the file is examined without being executed: is the code compressed or obfuscated in a way normal software is not, does it import functions typically used to inject code into other processes, is it signed and by whom, does the internal structure match a known malware toolkit? This can flag something genuinely new, and it is also where false positives begin.

Behaviour monitoring

The most valuable layer in practice. The program is allowed to run while the security product watches what it does: rewriting large numbers of documents in quick succession, adding itself to the startup sequence, disabling recovery options, contacting an address nobody has ever contacted before. Ransomware is usually caught here rather than by signature, because the behaviour is distinctive even when the file is brand new.

Cloud reputation

The product asks the vendor’s service what is known about this exact file: how old it is, how many other users have it, whether it is signed by a recognised publisher. A file first seen twenty minutes ago on a handful of machines is treated very differently from one that has existed for three years on millions. This is also why security software makes network requests of its own, and why some of them contain file hashes — something worth reading the vendor’s privacy documentation about.

What Norton AntiVirus Plus includes

The following is taken from Norton’s own product page for this tier, consulted on 21 September 2026. Vendors change packaging often, so treat it as a snapshot and check the vendor’s page before you buy.

Norton AntiVirus Plus compared with the higher Norton 360 tiers, as packaged on Norton’s site in September 2026. Packaging and device counts vary by region and over time.
FeatureAntiVirus PlusNorton 360 tiers
Real-time malware protectionYesYes
Smart FirewallYesYes
Password ManagerYesYes
Cloud backup (PC)2 GBMore, varies by tier
Secure VPNNoYes
Dark Web MonitoringNoYes
SafeCam (webcam protection)NoYes
Parental controlsNoDeluxe and above
Devices covered1Several, varies by tier

See the current package and price

Feature lists and prices are set by the vendor and change frequently. The only authoritative source is the vendor’s own page.

Open Norton’s product page partner link

Partner link. If you buy after following it, Bovama stav s.r.o. receives a commission from the vendor. You pay exactly the same price as you would by going to the vendor directly, and the commission does not change what is written on this page.

What it does not include

This matters because the absent features are exactly the ones most heavily advertised by the security industry as a whole, and it is easy to assume they come with any paid subscription.

A note on where this page came from

An earlier version of this article claimed that Norton AntiVirus Plus included a VPN, dark-web identity monitoring and multi-device coverage. It does not. Those claims have been removed and the corrections are listed in full further down this page.

Why one product is never enough

Security is layered, and buying software only reinforces one of the layers. The other four are free.

Diagram: five nested layers of protection. From outside in - the user's own habits, the home network, the operating system, security software, and at the centre the user's data protected by backups. A legend names each layer with an example.
Figure 3. Where a security subscription sits among the things that actually protect you. Original diagram produced for this page.

If you are deciding how to spend an hour improving your security, turning on automatic updates, enabling two-factor authentication on your e-mail account and setting up a backup will all do more than any change of antivirus product. That is not an argument against buying one; it is an argument against treating it as the whole job.

How to read independent lab tests

Vendors quote lab results selectively, so it is worth knowing how the labs actually score. We do not reproduce specific scores here, because they change with every test round and a figure copied from a marketing page is worthless by the time you read it. Go to the source instead:

Three things to keep in mind. First, the top ten products are usually separated by a fraction of a percentage point, which is not a meaningful difference for a home user. Second, a product tested well two years ago tells you little about today. Third, some vendors decline to participate in some tests, so an absence from a table is not a failure.

Built-in protection versus a paid suite

Any honest discussion has to mention that Windows 10 and 11 ship with Microsoft Defender Antivirus enabled at no extra cost, and that it is submitted to the same independent laboratories as the paid products. Recent macOS, iOS and Android releases also include their own protective mechanisms.

So what does paying add? Realistically: a firewall with a friendlier interface, a password manager, some cloud backup, web and scam filtering that works across browsers, support you can contact, and a single console when you have several devices. Whether those are worth an annual fee depends on you, not on a detection-rate table. What a paid suite does not add is immunity — and if the extra features it adds are ones you already have elsewhere, the honest answer is that you may not need it.

The one setup to avoid is running two real-time scanners at once. They interfere with each other and can leave you worse protected than either alone. Installing a third-party product normally stands Microsoft Defender down automatically; removing the third-party product should reactivate it, and it is worth checking that it did.

Price, renewal and refunds

We do not quote prices on this page. They differ by country and currency, change frequently, and the figure that matters is the one shown to you at checkout. What is worth understanding is the structure, which is consistent across the industry:

Check the current terms yourself

Price, renewal rate, refund window and device count are all set by the vendor and shown at checkout. Read them there before you commit.

View the vendor’s current terms partner link

Partner link. If you buy after following it, Bovama stav s.r.o. receives a commission from the vendor. You pay exactly the same price as you would by going to the vendor directly, and the commission does not change what is written on this page.

Scams that imitate antivirus vendors

Security brands are among the most heavily impersonated in fraud, precisely because a warning about your security is designed to make you act quickly. The fake “your subscription has expired” e-mail is a fixture of the genre.

Diagram: a mock fraudulent renewal e-mail with five numbered markers, and a key explaining each one - the sender domain is not the vendor's, the message invents a 24-hour deadline, the greeting has no name, the visible link text does not match the actual destination, and the message asks for card details outside the vendor's own site.
Figure 4. A constructed example, not a real message: no genuine e-mail, logo or address is reproduced. Original diagram produced for this page.

Two habits defeat nearly all of these. Never act on the link in the message — open a new tab and type the vendor’s address yourself, then check your subscription in your account. And treat any unexpected phone number in a security warning as hostile: “tech support” fraud depends on getting you to call, after which you will be talked into granting remote access.

What antivirus cannot do

An honest list of limits is more useful than another list of features:

Diagram: the 3-2-1 backup rule - three copies of anything you cannot lose, on two different kinds of storage, with one copy kept off-site or disconnected, plus a reminder that a backup only counts once a file has been successfully restored from it.
Figure 5. The 3-2-1 rule. The only measure that still works after an attack has succeeded. Original diagram produced for this page.

Who this fits

It fits someone protecting a single Windows PC who wants real-time protection, a firewall with a clear interface and a password manager in one subscription, and who would rather have a vendor to contact than manage several free tools.

It fits less well a household with several devices — a multi-device Norton 360 tier or a competing family licence is the sensible comparison there — or anyone who specifically wants a VPN or identity monitoring, neither of which is in this tier. If you already use a standalone password manager and a real backup service, a large part of what you would be paying for is duplicated.

What we corrected

This page replaces an earlier version that contained claims we could not support. In line with our editorial policy, the changes are listed rather than quietly made:

  1. Removed the claim that Norton AntiVirus Plus includes a secure VPN. It does not; that is a Norton 360 feature.
  2. Removed the claim that it includes identity theft protection with dark web monitoring, including monitoring of government identity numbers. It does not.
  3. Removed the claim of multi-device support covering “phone, tablet and computer with one subscription”. The tier covers one device.
  4. Qualified the cloud backup description: it is 2 GB and PC-only, not an unlimited store for “your most important files”.
  5. Removed “detection rate among the best in the industry” and “consistently scores highly”, which were unattributed. Replaced with an explanation of how to read the laboratories’ own published results.
  6. Replaced “millions of new malware variants launched every day” with AV-TEST’s published figure of over 450,000 new malicious programs and PUAs per day.
  7. Attributed the money-back guarantee and gave its stated length (60 days) rather than implying an open-ended promise, and noted the conditions.
  8. Removed the unsupported claim that the product has no noticeable performance impact; performance is one of the categories the laboratories measure and readers should check it there.
  9. Removed the “Reader Stories” framing and the “reader-submitted story” footer. Nothing on this site is reader-submitted, and presenting advertising as a reader account is misleading.
  10. Added the absent trademark disclaimer, publisher identity, byline, date and sources.

If you find something here that is still wrong, please tell us and we will correct it and say that we did.

Sources

None of the links above is a partner link, and we earn nothing from them. The two buttons on this page marked partner link are the only monetised links here.

If this page helped you decide

Using the button below is the way to support the site. It costs you nothing and takes you to the vendor, where the current price and terms are shown.

Go to Norton AntiVirus Plus partner link

Partner link. If you buy after following it, Bovama stav s.r.o. receives a commission from the vendor. You pay exactly the same price as you would by going to the vendor directly, and the commission does not change what is written on this page.

Independence and accuracy

This article was written by Andrew Bailey for Bovama stav s.r.o. and was not reviewed, approved or paid for by the vendor. Product details were taken from the vendor’s own published material on 21 September 2026 and can change at any time. In case of any divergence between this page and the vendor’s own information, the vendor’s information prevails.

Norton and Norton AntiVirus Plus are trademarks of Gen Digital Inc. or its affiliates. This site is not affiliated with, endorsed by or sponsored by Gen Digital Inc.