What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Computer viruses spread by attaching copies of themselves to other programs or files; they run when the infected host is opened, executed, or otherwise triggered. The word “virus” is also often used informally for malware in general. This list separates five virus forms from four related threats—worms, Trojans, ransomware, and spyware—that are malware but are not necessarily viruses.
What makes malware a virus?
A virus needs a host. NIST defines a computer virus as malicious software that propagates by modifying other programs to include a copy of itself; the copy runs when the infected program is invoked. Some viruses can also be triggered by an event. In contrast, a worm is self-contained and can spread without attaching to a host program, while a Trojan relies on deception and does not spread by itself. NIST’s virus glossary and NIST SP 800-83 Rev. 1 describe these distinctions.
The first five entries below are virus forms classified by what they infect or how they operate. The final four are related malware categories; their names describe how they spread or what they do, not necessarily a virus-style replication method.
Five forms of computer virus
1. File infector virus
A file infector attaches to an executable program. When someone runs the infected program, the virus may run as well and attempt to infect other executable files. Sharing or copying an infected program can give it another opportunity to reach a host.
#1 Best Overall
- ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
2. Boot-sector virus
A boot-sector virus targets startup information on a drive, such as its master boot record, or the boot sector of removable media. It can activate as the computer starts from the infected drive or media. The target is startup data rather than an ordinary document or application.
3. Multipartite virus
A multipartite virus combines file-infection and boot-sector characteristics. Because it can use more than one location or kind of host, it may have more than one route to activate or spread—for example, through an infected program and through startup data.
Rank #2
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
4. Macro virus
A macro virus is malicious code written as a macro in an application document or template. Handling or opening the infected document can activate the macro, depending on the application and its settings. Infected documents can then be shared with other people. NIST defines a macro virus as a virus encoded as a macro in a document and activated when the document is handled; NIST’s macro-virus glossary and Microsoft Learn’s malware descriptions explain this pattern.
5. Scripting virus
A scripting virus infects scripts—sets of instructions interpreted by a scripting language or operating-system service. It can run when an infected script is executed, and may spread when that script is copied or shared. Unlike a file infector that targets an executable program, its host is a script.
Recommended Free Tools
Rank #3
- ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
Four related malware threats often called viruses
6. Worm
A worm is a self-contained program that can propagate without attaching itself to another program. Depending on the worm, routes can include email, messaging, file sharing, network shares, or removable drives. That ability to spread independently is the key distinction from a virus. Microsoft Learn describes these common routes.
7. Trojan horse
A Trojan horse masquerades as something harmless or legitimate to persuade someone to install or run it. It does not self-propagate. Once active, it may steal information, install other malware, or give an attacker access. Its defining feature is deception, not infection of a host file or automatic spread.
Rank #4
- SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
- SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
- ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
- ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.
8. Ransomware
Ransomware encrypts files or otherwise blocks access to them, then demands payment or another action. “Ransomware” describes a malicious effect, not a specific replication form: a ransomware incident does not by itself establish that the malware is a virus. Paying does not guarantee that files will be restored. Microsoft Learn describes ransomware among its malware categories.
9. Spyware
Spyware is installed secretly to collect information without the user’s knowledge. The term describes covert information gathering, not a particular way of replicating; spyware is not necessarily a virus. This definition is distinct from ordinary analytics or ad-supported software, which should not be labeled spyware without evidence of covert collection. See the NIST spyware glossary.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBest Value
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
How the nine categories differ
| Category | Host or basis | Typical activation or spread | Virus? |
|---|---|---|---|
| File infector | Executable program | Running, copying, or sharing an infected program | Yes |
| Boot-sector | Drive startup record or removable-media boot sector | Starting from infected media or a drive with infected startup data | Yes |
| Multipartite | Files and boot-sector locations | More than one host or activation route | Yes |
| Macro | Application document or template | Handling or opening the infected document | Yes |
| Scripting | Script interpreted by a language or system service | Executing or sharing the infected script | Yes |
| Worm | No host program required | Self-propagation through available channels such as messaging or network shares | No |
| Trojan horse | Appears to be legitimate software | Someone is persuaded to install or run it; it does not self-propagate | No |
| Ransomware | Defined by blocking access to data or systems | Its delivery and spread depend on the specific malware | Not necessarily |
| Spyware | Defined by secret collection of information | Its delivery and spread depend on the specific malware | Not necessarily |
What to do about prevention and a suspected infection
These categories explain broad patterns, not a diagnosis of a particular device. Prevention and incident response depend on the device, software, and whether it is personally or organizationally managed. NIST’s 2013 guide to malware prevention and incident handling is foundational guidance, not current product-specific instructions.
- Use security and recovery instructions from the device maker, software vendor, or your organization’s IT team when they apply to your system.
- If you suspect a work or school device is infected, contact its IT or security team for the organization’s incident process rather than improvising cleanup steps.
- A separate backup can help with recovery, but it does not prevent infection or remove malware. An external drive kept offline between backups is one possible way to keep a separate copy.
- Avoid downloading cleanup tools from unverified sites or running unfamiliar executables; use guidance from a relevant, trusted provider.
NIST’s malware prevention and handling page provides historical context and was updated in 2021; device-specific vendor or organizational instructions are more appropriate for decisions about a particular incident.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

