Malware types explained for CompTIA A+ Core 2
Malware types are one of the highest-yield topics on the CompTIA A+ Core 2 exam, and they matter even more on your first day at a help desk. Security is one of the two heaviest domains on Core 2 (220-1202), and the exam expects you to name a threat from its behavior, then know how to clean it up. This guide walks through every major malware type: how it spreads, what it does, and the one tell that gives it away. If you are still deciding where to start, the CompTIA A+ certification is the usual first step, and this is core Core 2 material.
Why malware types show up all over Core 2 security
Because two objectives lean on them directly. On the current Core 2 exam (220-1202), objective 2.4 asks you to recognize each malware type and pick the right tool to detect, remove, and prevent it, and objective 2.6 covers the step-by-step removal process.
Security is one of the two heaviest domains on Core 2, worth 28% of your score, tied with Operating Systems. So this is not a corner you can skip. The good news is that malware types get easier to hold in your head once you stop memorizing definitions and start sorting each one two ways: how it spreads, and what it does once it lands. Almost every question rewards that habit.
The A+ objectives name a specific list, including virus, boot sector virus, trojan, rootkit, spyware, stalkerware, ransomware, keylogger, cryptominer, fileless malware, and adware or potentially unwanted programs. A few others in this guide, worm, botnet and zombie, and logic bomb, lean more toward Security+ (SY0-701 Domain 2.0), but they round out the mental model and often share the same tells. Learn them all once and both exams get easier.
How do viruses, worms, and trojans spread?
By three different routes. A virus needs you to open an infected file, a worm needs no help at all and copies itself across the network, and a trojan tricks you into installing it, which is why so many start with social engineering attacks.
That spread mechanism is the fastest way to tell these three apart on the exam and on the job. Look at how the infection moved before you look at what it did.
- Virus: attaches itself to a file or program and only runs when someone opens that host. It can corrupt or delete data, and the boot sector variant named on objective 2.4 hides in the drive's startup code. Tell: files that change size, programs that will not launch, or antivirus flagging a known signature.
- Worm: copies itself across a network with no user action, usually by exploiting an unpatched vulnerability. It eats bandwidth and can drop other payloads. Tell: sudden network slowdowns, and the same infection appearing on many machines within minutes.
- Trojan: poses as software you want, so you install it yourself. Once inside, it opens a backdoor or drops more malware. Tell: a cracked app or a surprise installer, new processes you do not recognize, and outbound connections to unfamiliar addresses.
What do ransomware, spyware, keyloggers, and adware actually do?
They extort, watch, record, or nag. Ransomware locks you out of your own files, spyware and keyloggers quietly steal what you type and where you go, and adware buries you in ads. For this group, the payload is the identifier, so focus on what happens after the infection lands.
These four are the ones a help desk sees most often, because they turn a quiet infection into an obvious business problem.
- Ransomware: encrypts your files or locks the screen, then demands payment. It usually arrives through a phishing attachment or an exposed remote-access service. Tell: documents renamed with strange extensions, and a ransom note you did not create.
- Spyware: quietly collects browsing habits, logins, and other data, then ships it out. Stalkerware, added in the V15 objectives, is a targeted personal form of it. Tell: browser redirects, new toolbars, and a machine that feels slower for no clear reason.
- Keylogger: records every keystroke to capture passwords and card numbers. It can be software or a physical device. Tell: an unknown background process, or a small adapter plugged between the keyboard cable and the USB port, so check the hardware too.
- Adware: buries the system in ads and hijacks searches, often bundled as a potentially unwanted program (PUP). It is more nuisance than disaster, but it is still a foothold. Tell: pop-ups, a changed homepage, and ads injected into pages that never had them.
The stealthy ones: rootkits, fileless malware, botnets, cryptominers, and logic bombs
These hide, borrow trusted tools, or wait for a trigger, which is exactly what makes them hard to catch. A clean antivirus scan does not mean a clean machine, so for this group you learn to trust behavior over a signature.
You will meet all of these on the job even if only some are named on the A+ list. Worm, botnet, and logic bomb show up more on Security+, but the reasoning is the same: watch what the system does when nobody is asking it to do anything.
- Rootkit: buries itself deep in the operating system or firmware to hide its own presence and grant lasting privileged access. Tell: antivirus comes up clean while the machine clearly misbehaves. Removal often means an offline scan or a full reimage.
- Fileless malware: runs in memory using trusted built-in tools like PowerShell, so it leaves little on disk for signature scanners to find. Tell: scripting tools launching when no one asked them to. Behavior-based detection catches what file scans miss.
- Botnet and zombie: a compromised machine, the zombie, is remote-controlled as one node in a larger network, the botnet, and used for spam, mining, or denial-of-service attacks. Tell: heavy CPU and network use while the machine sits idle.
- Cryptominer: hijacks your CPU or GPU to mine cryptocurrency for someone else, also called cryptojacking. Tell: fans running full blast, a hot and sluggish machine, and high processor use with no visible program behind it.
- Logic bomb: dormant code set to trigger on a condition, such as a date or an employee being removed from payroll. It is often planted by an insider. Tell: it is hard to catch before it fires, so watch for unexplained scheduled tasks or code tied to a condition.
How do you detect and remove malware at a help desk?
You verify, isolate, clean, and then teach. Detection leans on the right tools: endpoint detection and response (EDR), antivirus and anti-malware, an email security gateway, and software firewalls, with managed options like MDR and XDR in larger shops.
Signature-based antivirus still catches known viruses and trojans, while behavior-based EDR is what flags fileless malware and a rootkit acting up. When you actually clean a machine, CompTIA wants you to follow one ordered process, the same one you can rehearse in the Help Desk Simulator before you ever touch a real ticket. Several steps are Windows-specific, which is one more reason to know how the major operating systems differ. The best-practice removal process in objective 2.6 runs ten ordered steps:
The order is not decoration, and the exam tests it. Quarantine comes before remediation so nothing spreads while you work, System Restore goes off before you clean and back on only after, and educating the user lands last because it sticks best once the machine is healthy again. Miss the sequence and you can reinfect the very restore point you were trying to protect.
- Investigate and verify the malware symptoms, so you are not chasing a hardware or configuration problem by mistake.
- Quarantine the infected system: disconnect it from the network and any removable media so the infection cannot spread.
- Disable System Restore in Windows, so you do not save the malware into a restore point.
- Remediate the infected system, the umbrella step that the next two actions carry out.
- Update the anti-malware software so it is working from the newest definitions.
- Use the right scan and removal techniques, dropping into safe mode or the Windows preinstallation environment for stubborn infections.
- Reimage or reinstall the operating system when the machine cannot be reliably cleaned. This is the step the retired seven-step process folded away, and it is now called out on its own.
- Schedule scans and run updates so the same thing does not walk back in.
- Re-enable System Restore and create a fresh, clean restore point.
- Educate the end user, because most infections start with a click, not a code exploit.
Study the behavior, not just the name
You do not need a perfect dictionary of malware types in your head. You need two reliable questions: how did it spread, and what does it do now that it is here. Sort every threat that way and the whole list stops feeling like a wall of vocabulary. A virus and a worm both replicate, but one waits for you and the other does not. A rootkit and a cryptominer both hide, but one covers its tracks and the other steals your processor. Pair that habit with the ten-step removal process until it is muscle memory, practice a few infected-machine tickets in the simulator, and objective 2.4 and 2.6 turn into easy points. Better still, you walk into your first help desk job already thinking the way the work demands.
Sources
- CompTIA. CompTIA A+ Core 2 (220-1202) Exam Objectives. Official objectives PDF: domain 2.0 Security weighting and the malware objectives (2.4 types and tools, 2.6 removal steps).
- Professor Messer. Malware - CompTIA A+ 220-1202 - 2.4. Free training video for objective 2.4; corroborates the A+ malware type list and detection tools.
- Professor Messer. Removing Malware - CompTIA A+ 220-1202 - 2.6. Walks the seven best-practice malware removal steps in objective 2.6.
- NIST. malware - Glossary. Authoritative definition of malware used for the framing in this guide.
- CompTIA. CompTIA Security+ (SY0-701) Certification. Malware types also map to Security+ Domain 2.0, useful if you continue past A+.
Who writes this, and who checks it

Nick writes and edits these posts. AI helps with research, outlines, and first drafts. Nick reviews the draft before it goes live, and he is the only reviewer, so this is one person checking his own work. That catches a lot and it misses some.
When a post turns out to be wrong, the fix and the date it happened go on the corrections log, in public, including the ones nobody outside noticed. We do not use confidential, recalled, or leaked exam content. These posts are written from CompTIA's published objectives and authoritative technical sources. The AI policy has the longer version.
LinkedIn ↗