Malware
Virus
Virus is malware that attaches its code to other programs or files and runs when the host does. It needs something to infect, and it spreads when infected files are shared.
How it is measured
Detect by scanning for signatures and for changes to executables: modified sizes, appended code, altered entry points, or documents with macros that write to other documents. File-integrity monitoring on program files and a known-good hash list make infection visible.
Look at the spread pattern. A true virus follows files: shared drives, USB sticks, uploaded documents. It does not scan the network for new hosts the way a worm does.
Worked example
A print shop's shared folder holds 400 Word templates. An employee opens one with a macro that, on open, copies itself into every .docm in the folder. Two days later 380 templates carry the macro and each has grown by 11 KB.
Restoring the templates from last week's backup and disabling macros from the internet fixes it. The infection never left the folder, because the macro needed a document to ride in.
How it differs
Malware covers all hostile code. A virus is the file-infecting kind that requires a host and a person or process to run it. A worm moves by itself over the network, so the same shared-folder situation with a worm would show up on other machines without anyone opening a file.
Common errors
Using 'virus' for every threat. Cleaning one infected file and leaving the rest. Assuming only .exe files can be hosts. Blocking the macro and forgetting the other copies on USB drives. Restoring from a backup taken after the infection.
In practice
Keep clean offline copies of templates and installers, block macros from untrusted sources, and scan shared drives on a schedule. When one infected file turns up, assume the others in that folder are infected until a scan says otherwise.