Author Topic: One hint about "Win32:Trojan-gen" detection names...  (Read 2685 times)

0 Members and 1 Guest are viewing this topic.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
One hint about "Win32:Trojan-gen" detection names...
« on: June 30, 2006, 09:27:30 PM »
Is there any chance that you could rename "Win32:Trojan-gen" into Win32:Generic Malware (followed by {UPX!}, {Other} etc. where needed like it's already in use now).
I know you selected this name some time ago but now i'm seeing lots of stuff under the word "trojan" and just doesn't look right.
For example there is some bot that's named Trojan-gen, and some toolbar is named like this, and some trojan is named like this and there is some other adware component also named like this, not to mention bunch of other minor malware. They aren't "trojans" but word Generic Malware would fit there really well. What do you think? I'm sure you have capabilities of renaming the VPS entries on global scale right?

I know it's "just a cosmetic" thing but still, it looks far more professional and better describes detected stuff than just "Win32:Trojan-gen". Even though it doesn't describes anything in the right meaning of the word hehe ;D I mean you know what you're dealing right away when you hear word Generic Malware. Generic Malware would mean like "it's just some generic crap, nothing to worry about" where Trojan-gen sounds like "omg crap i have a trojan on my PC, i'm doomed" (we all know how big reputation trojans have...). Though in this example we were dealing with just some minor threat, a part of some adware crap. See what i mean?

Anyway, i really hope you'll follow this advice :)

EDIT:
I forgot to mention the same for Win32:Adware-gen.
Win32:Generic Adware would sound much much better.
Same applies to all similar categories, you all know which are these...
« Last Edit: June 30, 2006, 09:34:36 PM by RejZoR »
Visit my webpage Angry Sheep Blog

mauserme

  • Guest
Re: One hint about "Win32:Trojan-gen" detection names...
« Reply #1 on: July 01, 2006, 04:22:11 PM »
I always thought trojan-gen meant something like "this is a trojan identified through a generic detection so we can't give you the specific name".

Is it really just generic in the sense of being mundane, unimportant stuff?

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: One hint about "Win32:Trojan-gen" detection names...
« Reply #2 on: July 01, 2006, 06:17:54 PM »
Pretty much yes, though not always. Well i thought it's generic detection at first too (because of -gen sufix), but i later found out it's just malware without name, because they simply don't bother naming it for example like Trojan-0000001,Trojan-0000002,Trojan-0000003,Trojan-0000004 etc...

Makes sense, though i'd prefer naming scheme i suggested in first post of this thread...
Visit my webpage Angry Sheep Blog

mauserme

  • Guest
Re: One hint about "Win32:Trojan-gen" detection names...
« Reply #3 on: July 01, 2006, 09:03:06 PM »
... i'd prefer naming scheme i suggested in first post of this thread...

Yeah - it might keep some of us from making silly assumptions  ::)

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: One hint about "Win32:Trojan-gen" detection names...
« Reply #4 on: July 03, 2006, 09:35:41 AM »
I'm also hoping for comment from Alwil guys ;)
Visit my webpage Angry Sheep Blog