We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Free-vs-paid decision guide · App Store listing, Scanner manual, current ONE labs and macOS access rules checked August 6, 2026

Intego VirusBarrier Scanner vs Paid: What the Free App Misses

The free VirusBarrier Scanner is a useful Mac malware checker, not a free copy of Intego ONE. It can run manual and daily scans, inspect dragged files and quarantine detections, but it can't watch new files in real time and it sees only the locations macOS lets it access. Here is the practical line between a second-opinion scan and continuous paid protection.

Free means no subscriptionNo real-time scannerPermissions define coverageONE lab scores kept separate

Quick answer: Keep the free Scanner for occasional checks, suspicious downloads or a second opinion when you're willing to verify scan scope. Buy paid ONE when files arrive frequently, continuous monitoring matters or you want the application firewall. Current 2026 lab results belong to paid ONE 1.2/1.2.3; neither AV-TEST nor AV-Comparatives names the App Store Scanner in the results we verified.

Free VirusBarrier Scanner vs paid ONE: the short verdict

The free app is worthwhile if you understand its job. Apple's current Mac App Store listing identifies it as free, Mac-only software that scans Mac and Windows malware, updates definitions, schedules daily checks and quarantines or deletes dangerous files. There's no renewal clock to manage.

The missing layer is prevention between scans. Intego's Scanner manual explicitly says the App Store app can't automatically inspect new or modified files in real time. Paid ONE adds that background protection and a two-way application firewall, which is a meaningful difference for a Mac that regularly handles downloads, email attachments, shared files or sensitive work.

Start with the free app when the need is occasional and specific. Move to paid protection because the risk model changed, not because an upsell button exists. Our full Intego review owns the paid product verdict, while the ONE pricing guide owns the current 18-combination rate table.

Exact capability matrix: detection window, scope and extras

CapabilityFree VirusBarrier ScannerPaid Intego ONEWhy it matters
Price modelFree Mac App Store appRecurring subscriptionFree has no renewal; ONE pricing varies by tier, term and Mac count.
Manual scansYesYesBoth can inspect a chosen file, folder or volume.
Scheduled scansDaily scheduleYesA schedule reduces forgetfulness but doesn't close the time gap.
Real-time file protectionNoYesONE can inspect files as they're created, copied, changed or saved.
Application firewallNoYes, every tierONE can allow, block or ask about app network connections.
Scan scopeUser-granted, readable locationsBroader system protection after required permissionsA clean result is only as broad as the actual accessible scope.
Mac + Windows malwareYesYesWindows detections help prevent passing infected files to PCs.
Quarantine/repair/deleteYesYesDetection still needs a careful remediation decision.
Current 2026 labsNo directly named result foundONE 1.2/1.2.3 testedPaid scores can't be silently inherited by the free app.
Cleanup/VPNNoSmartClean in Advanced; VPN in CompleteThese are tier extras, not malware-detection upgrades.

The free app isn't “bad ONE.” It's a narrower utility built around periodic inspection. Intego's current ONE tier table makes Essential the paid security baseline because it contains both Antivirus and Firewall; Advanced and Complete only become better values when their added SmartClean or VPN module replaces something you already use.

Intego free Scanner capabilities and missing real-time protection compared with paid ONE
Editorial capability map based on current Apple, Intego and lab documentation. The comparison table above remains the accessible source of record.

What the free Scanner actually does well

Scanner covers more than a one-button sweep, despite the current App Store listing's small 15.1 MB listed size. You can choose all accessible files, common malware locations or a specific item, drag a suspicious file or volume into the app, schedule daily scans, update definitions before scanning and manage trusted exclusions. It looks for both Mac and Windows malware, useful when a Mac shares archives or attachments with Windows users.

The current manual says definitions are checked before each scan or every six hours. It also lets you scan only new and changed files after the first pass, inspect archives and lower scan priority when you want the Mac to remain responsive. Those are sensible controls for an occasional scanner.

“Maximum Protection” is an unfortunate label because it describes a scan mode, not continuous protection. It scans accessible files belonging to the current user and selected volumes; it doesn't transform the sandboxed App Store utility into a background antivirus service.

A daily schedule isn't the same as real-time protection

Suppose a malicious installer lands at 10:00 and the daily scan runs at 21:00. Scanner may find the file later, but it doesn't inspect the new arrival at download time or before launch merely because a schedule exists. A user can close that gap manually by scanning the file before opening it, but the safety step depends on memory and judgment.

Paid ONE's Antivirus module monitors file activity in the background. Intego describes the paid real-time scanner as checking files created, copied, modified or saved, while the free manual states that its App Store build can't do this. The distinction is architectural, not a marketing adjective.

A clean on-demand result is also a timestamp. It says nothing was detected in the scanned, readable scope with the definitions and settings used at that moment. It doesn't promise that a later download will be stopped, that an unscanned folder is clean or that a browser scam will be blocked.

App Sandbox means “whole Mac” needs a scope check

The App Store listing says Scanner can access only locations explicitly granted to it and recommends granting the entire disk for maximum coverage. Intego's manual is more precise: Maximum scans accessible files except other users' files, and Essential scans user-approved locations where malware is commonly installed. macOS permissions can also limit removal.

Apple's App Sandbox documentation explains why. A sandboxed app can receive access to a file or folder selected through a system panel, including nested items, but normal file permissions and access-control lists can still deny individual objects. The button label can't override the operating system.

Before trusting a clean result, note the selected volume, the number of files scanned, any skipped/incomplete status and which user account ran the scan. A fast “finished” screen with zero or unexpectedly few files is a failed coverage check, not reassuring evidence.

Current lab scores belong to paid ONE, not the free Scanner

The current favorable result is AV-TEST's March 2026 Mac cycle, where Intego ONE 1.2.3 earned 6/6 for protection, 6/6 for performance and 6/6 for usability. The tested product and version are named, so the result supports paid ONE.

AV-Comparatives' May 2026 review tested ONE Complete 1.2 and measured 96.7% Mac-malware protection, 94% potentially unwanted application detection, 100% Windows-malware detection and no false alarms on its clean-app set. It also recorded no malicious/fraudulent-site protection in the tested product. That mixed result is important context for a paid purchase.

Neither current lab page names VirusBarrier Scanner 1.3. Intego's 2017 launch article said the free app used the then-current VirusBarrier X9 detection engine, but a nine-year-old generation comparison can't prove engine parity with ONE in 2026. We therefore don't place the 18/18 badge or 96.7% figure on the free app.

Macworld's February 2025 review reported more than six million files scanned in under 15 minutes on one M2 MacBook Pro, 27 samples quarantined and DazzleSpy missed. That's useful hands-on evidence about one setup, not a controlled lab percentage or a universal speed promise.

Scanner supplements XProtect and Gatekeeper; it doesn't replace them

macOS already has several security layers. Apple's Platform Security guide says notarization checks software submitted by developers, Gatekeeper verifies launch policy and revocation information, and XProtect detects, blocks and remediates known malware with regularly updated signatures plus behavioral analysis.

VirusBarrier Scanner adds a user-controlled inspection path for files, folders and volumes. It doesn't own Apple's notarization or execution-policy decisions, and Apple doesn't provide the same broad user-facing full-disk scan workflow. Keep automatic security data updates, Gatekeeper and XProtect enabled whether you choose free Scanner or paid ONE.

The community debate is real but binary answers aren't helpful. A recent r/MacOS discussion includes both “built-in protection is enough” and “periodic second-opinion scan” views. Risk depends on where software comes from, whether warnings are bypassed, what data the Mac holds and how quickly a user needs prevention rather than after-the-fact detection.

Scanner has a lower OS floor, but Tahoe support isn't established

The current App Store listing requires macOS 10.13 or later and shows Scanner version 1.3. Its visible release note names macOS Sonoma compatibility, not Tahoe. An installation floor isn't the same as a current compatibility guarantee across every later major release.

Intego's Tahoe compatibility article lists paid VirusBarrier 10.9.99, NetBarrier and other X9 components, but not VirusBarrier Scanner. One 2026 Reddit comment says the Scanner doesn't work on Tahoe; we treat that as a warning to verify, not official proof. A Tahoe user should check the live App Store compatibility section and Intego support before relying on Scanner.

A separate 2025 community report describes Scanner immediately reaching “Finishing” without scanning on Sequoia 15.6. One report doesn't establish a widespread defect, but it reinforces the operational rule: verify files scanned and scope after any macOS upgrade. Paid ONE has a higher stated floor of macOS 12.4, 8 GB RAM and 2 GB storage, so “paid” doesn't automatically mean it fits an older Mac.

Run the first free scan so the result can be trusted

  1. Install only from Apple's listing. Confirm the seller is INTEGO and don't use look-alike download pages.
  2. Open About first. Record Scanner version and the malware-definition date, then allow the update check to finish.
  3. Start with a known folder. Select Downloads or another readable location and confirm that the file count increases.
  4. Choose scope deliberately. Use Essential for a quick common-location check or Maximum only after granting the intended volumes.
  5. Keep the Mac awake. A scheduled or manual scan can't finish while the Mac is asleep.
  6. Save the result. Record duration, files scanned, skipped/incomplete notices and detection paths.
  7. Escalate when the stakes are high. A known account compromise, active data theft or persistent system tampering needs incident response, not repeated consumer scans.

Don't start by trusting the entire disk. Grant the least scope needed for the question, verify that it works, then expand deliberately. The app can remember user-selected access; review and revoke permissions later if the scanner is no longer needed.

Quarantine is a holding area, not a final diagnosis

Scanner automatically moves detected files into quarantine, then offers Restore & Repair, Delete or no immediate action. The manual says repair removes malicious content and returns the file, while delete removes it. Leaving the item quarantined buys time to verify the path and detection name without putting it back into use.

The most dangerous control is Restore without Repair. Intego says this path also adds the item to Trusted Files, which prevents future scanning. Use it only after the publisher, signature, hash or a vendor false-positive review supports the conclusion; a familiar filename by itself is weak evidence.

Trusted exclusions can apply to a folder or volume and all subfolders. Never exclude broad areas merely to make scans faster. If an essential application is detected, preserve the alert and obtain a clean installer from the publisher rather than trusting the entire application folder.

Suspicious downloads, email and external drives are the free app's best use cases

Drag-and-drop scanning is the free app's most practical habit. Before opening an unsigned installer, archive or attachment, save it without launching, update Scanner, then drag the file into the window. A clean result lowers uncertainty but doesn't override Gatekeeper warnings, an invalid signature or an untrusted source.

Scanner can look for Windows malware that can't run natively on macOS. That still matters when files are sent to a PC, stored on a shared drive or forwarded to a Windows user. Treat the Windows detection as a carrier-prevention benefit, not proof that the Mac itself was compromised.

External volumes need explicit selection and may contain Time Machine data, archives or permission boundaries that make a scan slow or incomplete. Scan a newly received USB drive before copying files, but don't add the entire backup volume to Trusted Files simply because repeated scanning is inconvenient.

The free Scanner is enough for a narrow, low-frequency job

Free is a reasonable choice for a current, fully updated Mac whose owner installs from the App Store or known signed publishers, doesn't bypass macOS warnings and wants an occasional second opinion. It also fits someone who receives one suspicious file and can remember to scan it before opening.

It's less convincing as the only extra layer for a family Mac, a machine used by a less technical person or a workflow full of plugins, archives, email attachments and third-party installers. The issue isn't that scheduled scans are worthless; the issue is that people execute files between schedules.

Our free antivirus guide compares other no-cost options and their real-time limits. A Mac-specific shortlist belongs in the best Mac antivirus guide, where detection, performance and platform features are compared on the same current evidence.

Use Scanner as a second opinion, but keep one real-time engine

Because the free app has no real-time scanner, it can serve as an occasional second opinion beside Apple's protections or a different paid antivirus. Avoid simultaneous full scans because both tools can compete for storage and each may quarantine an item while the other is reading it. Note which product generated each alert.

Don't run two paid real-time antivirus engines together. They can duplicate file hooks, slow I/O and interfere with quarantine or system-extension state. Pick one continuous provider, then use a non-real-time tool only when the main scan is idle.

Intego's Scanner manual recommends uninstalling the App Store app after upgrading to paid VirusBarrier X9. The wording predates ONE, but the cleanest current setup is still one Intego protection path: confirm ONE is active, run its initial scan, preserve any needed Scanner history, then remove the free app rather than keeping duplicate manual workflows.

If Scanner finishes instantly or misses a location, test coverage before reinstalling

Start with evidence: app version, macOS version, definition date, selected path, files scanned and any incomplete/skipped notice. Re-select a small known-readable folder, confirm that its count advances, keep the Mac awake and test with archives disabled if a specific compressed file stalls the scan. Don't use a clean reinstall as the first move because it can erase useful state without fixing permissions.

A Sequoia 15.6 community report describes scans jumping immediately to “Finishing” despite reinstall attempts. That report can't prove cause or prevalence, but it shows why “completed” must be paired with a credible file count. If a small accessible folder also scans zero files, submit the evidence to Intego support.

When an external disk fails, test an internal folder and another readable volume before blaming the engine. When removal fails, check whether the current account can modify the detected path and leave the file quarantined. Avoid terminal deletion advice copied from forums unless Intego support has identified the exact Scanner container and target.

The free app's privacy label is modest but self-reported

Apple's current privacy panel says usage data and diagnostics may be collected without being linked to identity. It also states that the developer supplied the disclosure and Apple hasn't verified it. That's more precise than claiming the scanner collects “nothing” or that App Store review audits every privacy statement.

The listing doesn't show enough ratings for an overview, so star-score social proof would be weak. Intego's manual offers a support-ticket path even for Scanner, which is useful when a permissions or compatibility issue can't be reproduced in a readable test folder. Never send malware samples that contain private documents until support explains the secure submission route.

Intego VirusBarrier Scanner vs paid FAQ

Is Intego VirusBarrier Scanner really free?

Yes. The current US Mac App Store listing identifies VirusBarrier Scanner as a free Mac-only app, with no purchase or subscription required for its manual and daily scheduled scans. It isn't a free trial of Intego ONE, and it doesn't include ONE's real-time protection or firewall.

Does the free VirusBarrier Scanner have real-time protection?

No. Intego's Scanner manual explicitly says Mac App Store limitations prevent the app from automatically scanning new or recently changed files in real time. It can run manual or scheduled scans, so protection exists only when an accessible location is actually scanned.

Can VirusBarrier Scanner scan the whole Mac?

It can scan the current user's accessible files and user-selected volumes, but App Store sandboxing and macOS permissions define the true scope. Maximum Protection still excludes files belonging to other users, and a scan can't inspect or repair a location the current account hasn't allowed it to access.

Is Intego's free Scanner as good as paid Intego ONE?

They overlap in on-demand malware scanning, but they aren't equivalent protection products. Paid ONE adds real-time file monitoring and an application firewall, while higher tiers add SmartClean or VPN. Current 2026 lab results name ONE 1.2/1.2.3, not the free App Store Scanner.

Do AV-TEST and AV-Comparatives test the free VirusBarrier Scanner?

The current results we verified don't name the free Scanner. AV-TEST tested Intego ONE 1.2.3 in March 2026, and AV-Comparatives tested ONE Complete 1.2 in May 2026. Those results are useful for evaluating paid ONE but can't be transferred to Scanner.

Does VirusBarrier Scanner work on macOS Tahoe?

Don't assume it does. The App Store listing requires macOS 10.13 or later, but its visible version 1.3 note names Sonoma. Intego's Tahoe compatibility article lists paid VirusBarrier X9 and other X9 components but doesn't list VirusBarrier Scanner, so current Scanner support for Tahoe is unconfirmed.

Can I use VirusBarrier Scanner with another antivirus?

A non-real-time scanner can be useful as a second opinion, but avoid simultaneous full scans and never run two paid real-time antivirus engines together. Close or pause the other product's on-demand scan, verify which tool quarantined an item, and keep only one continuous protection provider.

What should I do if VirusBarrier Scanner finds malware?

Leave the item quarantined, record the detection name and full path, update definitions and rescan the relevant scope. Repair or delete only after you understand what the file is and preserve needed evidence. Don't use Restore without Repair unless a credible false-positive check supports it, because that action also trusts the file.

Why does VirusBarrier Scanner finish without scanning files?

First verify the number of files scanned, the selected location and the permissions granted to the app. Re-select the folder or volume, keep the Mac awake, update the app and definitions, and try a smaller known-readable folder. If it still completes immediately, save the app/macOS versions and screen evidence for Intego support rather than assuming the clean result is valid.

When is paid Intego ONE worth buying?

Paid ONE makes sense when files arrive often, the Mac handles sensitive work, more than one person uses it, or continuous prevention and outbound connection control matter. Essential is the security baseline; choose Advanced or Complete only when SmartClean or Intego VPN replaces a tool you'd otherwise use.

Bottom line: free scanning is useful, but its boundaries are the product

VirusBarrier Scanner earns a place as a free, focused Mac utility. It checks chosen files and volumes, schedules daily scans, updates definitions and gives the user a quarantine workflow without a subscription. For a careful person with a low-frequency scanning need, that's real value.

It isn't continuous protection. App Store sandboxing limits scope, current lab scores belong to paid ONE, and Tahoe compatibility isn't established by the sources we found. Choose free when you can control the scan moment and verify coverage; choose paid ONE when protection must happen before you remember to click Scan.