Notifications
Clear all

Virus names

5 Posts
3 Users
0 Reactions
661 Views
(@adamd)
Eminent Member
Joined: 19 years ago
Posts: 46
Topic starter  

Does anyone know of a decent reference for virus naming conventions used by different anti-virus software vendors?


   
Quote
hogfly
(@hogfly)
Reputable Member
Joined: 21 years ago
Posts: 287
 

To my knowledge, such a thing doesn't exist for cross reference. Each vendor should have their own convention listing such as Symantec's.

http//www.symantec.com/security_response/virusnaming.jsp


   
ReplyQuote
(@adamd)
Eminent Member
Joined: 19 years ago
Posts: 46
Topic starter  

To my knowledge, such a thing doesn't exist for cross reference. Each vendor should have their own convention listing such as Symantec's.

http//www.symantec.com/security_response/virusnaming.jsp

this is the whole problem ..there is no way to cross reference the names between vendors

what also shits me is vendors like Sophos have removed all virus/trojan details from their site and there is no way to find out what other vendors call their viruses.

I didnt want to have to have 5 or six different anti-virus programs installed just to get the reported names from each, I was happy with just 2 or 3.

*waves fist at stupid anti-virus industry*


   
ReplyQuote
hogfly
(@hogfly)
Reputable Member
Joined: 21 years ago
Posts: 287
 

Yes, and you're not alone in thinking this way. Many vendors will identify what other vendors call the same malware. For instance trojan.mebroot is identified as sinowal on the symantec site, because other vendors refer to it as sinowal. I've unfortunately found that googling the malware name is the best way to cross reference a name because it will identify multiple vendor generated identities.
Sometimes threat expert will cross reference them. There's no need to install 5-6 programs. I simply submit the sample to virustotal to see what other vendors call something.


   
ReplyQuote
(@Anonymous 6593)
Guest
Joined: 17 years ago
Posts: 1158
 

this is the whole problem ..there is no way to cross reference the names between vendors

There are methods – they may not in wide use, though. One method that seems to be promising is the CME (http//cme.mitre.org/), but it is targeted to 'high-profile threats'.


   
ReplyQuote
Share: