Malware
Worm
Worm is malware that copies itself to other machines on its own, usually through a network weakness, with no one opening a file. Its growth is the harm even before it carries a payload.
How it is measured
Watch for spread: the same file or process appearing on many hosts in a short window, scanning traffic from internal machines to many addresses on one port, and first-seen times that follow network adjacency. Plot infected hosts by time.
Find the propagation route: an exposed service, an unpatched flaw, shared credentials, or a writable network share. Containment means cutting that route as well as cleaning the hosts.
Worked example
At a small clinic, three workstations show a process named svch0st.exe within 20 minutes. Firewall logs show each of them probing TCP 445 on every address in the /24. Patch records show the three machines were missing a file-sharing update that the other 17 had.
The clinic unplugs the switch uplink, pulls the three machines, and patches them offline. Without finding the port 445 scanning, they would have cleaned and reconnected machines that infected each other again within an hour.
How it differs
Malware is the umbrella. A worm is the self-spreading kind. A virus needs a host file and a person's action, while a worm uses a network hole. A botnet is what you may have after a worm infects many machines under one controller.
Common errors
Cleaning machines without cutting the network path. Reconnecting hosts before patching. Sharing local admin passwords across machines. Allowing SMB or remote desktop from untrusted networks. Judging the outbreak by the first machine seen.
In practice
Segment your network, close unneeded file-sharing and remote desktop ports, and patch internet- and LAN-facing services quickly. Use unique local admin passwords. In an outbreak, isolate first, then patch, then clean.