Step 4 of 6 · Threat Guard path

Installing and the first hour of setup

Most of the complaints people have about security software — the computer became slow, it blocked something harmless, two products argued with each other — start in the first hour. This step is the procedure that avoids them.

Prepare Remove Install Update Configure
The order matters: removing what is already there before installing anything new prevents the most common problem of all.

Before you start

  • Make sure a current backup exists. Any operation that touches system components is a reasonable moment to have one, and step five covers how to keep one properly.
  • Know the administrator password for the device. An install that stalls half-finished because nobody can authorise it leaves a machine in a worse state than before.
  • Have the licence details or account credentials to hand, in the confirmation email from the vendor rather than in a link from anywhere else.
  • Set aside an uninterrupted hour for the first device. Subsequent devices take minutes.
  • Close your work and save everything. A restart is likely, and it may not be optional.

The procedure

  1. Remove the previous security product first, completely. Two real-time scanners on one machine is the classic cause of slowness, freezes and strange file errors, because each inspects what the other is doing. Uninstall the old product through the operating system's normal applications list. Many vendors also publish a dedicated removal tool that clears the drivers and services a normal uninstall leaves behind — use the one from that vendor's own site if it exists. If you are moving away from a suite that was pre-installed when the computer was new, this step is the one that makes the difference.
  2. Restart before installing anything. The removal is usually not finished until the machine has restarted, even when nothing prompts you. Install on top of a half-removed product and you inherit both problems.
  3. Download only from the vendor's own domain. Type the vendor's address by hand or use your own bookmark. Do not use a search advertisement, a download portal, or a link in an email that arrived unexpectedly. On phones and tablets, install from the official app store for the platform and check that the publisher name matches the vendor.
  4. Read each installer screen instead of clicking through. Installers commonly offer extras: a browser extension, a changed default search engine, a new home page, a second product. Each is a choice, and you can decline any of them and add it later if you decide you want it.
  5. Let it update before it scans. A freshly installed product carries whatever definitions were in the installer package. The first thing it should do is fetch current ones; if it does not do so on its own, trigger the update manually, then confirm the update date shown in the interface.
  6. Run one full scan, once. The first full scan establishes a clean baseline for a machine whose history you may not know. It can take hours on a large drive. Start it when you do not need the computer, let it finish, then read the result rather than dismissing the summary.
  7. Check that real-time protection is on. It is the component that actually prevents infection. Confirm it is enabled rather than assuming the installer enabled it, and confirm it again after any restart in the first few days.
  8. Set a scan schedule you will not fight with. A weekly quick scan at a time the machine is on and idle is realistic. A daily full scan on a laptop that lives on battery is not, and it is the setting people disable in irritation two weeks later, usually along with everything else.
  9. Configure notifications down to the useful minimum. Most products default to telling you about everything, including successful updates and promotional offers for higher tiers. Turn off what you will not act on. A product that interrupts constantly is a product whose genuine warnings get dismissed reflexively.
  10. Add the extras deliberately, one at a time. If the subscription includes a password manager or a VPN, set them up as separate projects, days apart, when you have attention for them. Importing every stored browser password into a new manager in the same hour you installed the scanner is how people end up locked out of things.
  11. Record the renewal date and the price. Put both in your calendar with a reminder a fortnight before, alongside a note of where the subscription is managed. This is the single administrative habit that prevents an unwanted charge and a support conversation.
  12. Repeat on the other devices in the licence. Do the phones and tablets too. A licence covering five devices that is installed on one is not protecting the other four, and mobile installs are usually the quickest part of the whole exercise.

About exclusions

Every product lets you exclude a file, folder or process from scanning. It is occasionally necessary — a development tool or a large media library that the scanner slows to a crawl. Treat each exclusion as a deliberate hole: add it for a specific path, write down why, and review the list when you next change machines. A folder excluded years ago for a program you no longer use is an invisible gap in whatever you are paying for.

When something goes wrong in the first week

The machine has become noticeably slower. Check for a second security product still present. Then check whether a full scan is running in the background — the first one often is. If neither explains it, look at the scan schedule and at whether an aggressive scanning mode was enabled by default.

Something legitimate has been quarantined. False positives happen, particularly with small utilities and anything unsigned. Do not simply disable protection. Use the product's quarantine screen to restore the specific item, and if the vendor offers a submission process for a wrongly detected file, use it — that is how the detection gets corrected for everybody.

A website or app has stopped working. Web filtering and firewall components are the usual cause. Turn the single relevant component off briefly to confirm, then add a specific exception rather than leaving the component off.

The product will not activate. Sign in on the vendor's site directly, confirm the subscription is active and which devices are registered against it, and remove a device you no longer own if the seats are full. Do not follow activation links from emails you did not expect.

Two things never to do during setup

Never install a security product from a link in an unexpected message, however plausible, and never ring a phone number that appears in a warning on a web page. Support fraud of this kind is a persistent problem, and Scamwatch documents the current patterns at scamwatch.gov.au.

Never let anyone you did not contact first take remote control of your computer to "fix" or "install" something. If you need remote help, you initiate the call through the number published on the vendor's own site.

What finished looks like

On each device: one security product, real-time protection on, definitions current, a schedule that suits the way the device is used, notifications trimmed, and no leftover fragments of a previous product. In your calendar: the renewal date and the price you expect to pay. In your records: where the subscription is managed and which account it belongs to.

That is the software half done. The half that does more work for less money is next.