Author Topic: Detection or Generic?  (Read 4394 times)

0 Members and 1 Guest are viewing this topic.

LunarWolf

  • Guest
Detection or Generic?
« on: January 06, 2011, 02:33:39 PM »
Recently, I submitted 2 files to avast which I know are rogues. Before submitting, there was no detection from avast. But after submission and a VPS update, the rogues are detected as Win32:Trojan-gen.

So is it a generic/heuristic detection or a signature detection?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Detection or Generic?
« Reply #1 on: January 06, 2011, 02:44:10 PM »
Quote
Win32:Trojan-gen.
Generic

yongsua

  • Guest
Re: Detection or Generic?
« Reply #2 on: January 06, 2011, 03:55:03 PM »
May i know mostly Avast! names the viruses as "Win32"?

LunarWolf

  • Guest
Re: Detection or Generic?
« Reply #3 on: January 06, 2011, 04:16:25 PM »
Then how do I know it is heuristics?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Detection or Generic?
« Reply #4 on: January 06, 2011, 05:03:45 PM »
May i know mostly Avast! names the viruses as "Win32"?

Because in most cases they are specific to windows 32bit, many other AVs also use this sort of prefix.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Detection or Generic?
« Reply #5 on: January 06, 2011, 05:28:31 PM »
« Last Edit: January 06, 2011, 05:30:12 PM by Pondus »

LunarWolf

  • Guest
Re: Detection or Generic?
« Reply #6 on: January 07, 2011, 12:48:22 PM »
Then how do I know it is heuristics?
See the link in post #2   http://www.wilderssecurity.com/showthread.php?t=280190

I am not asking about the difference between heuristics/genenric/behaviour.

What I am asking is how do I know what type of detection is avast detecting when they said Win32:Trojan-gen?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Detection or Generic?
« Reply #7 on: January 07, 2011, 02:45:34 PM »
All those with -gen are generally (couldn't help myself) generic. Heuristic detections tend to have a [Heur] suffix after them. Or in the case of anti-rootkit detections have it mentioned in the alert window, e.g. detection made using heuristic methods, or words to that effect.
« Last Edit: January 07, 2011, 02:47:09 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Detection or Generic?
« Reply #8 on: January 07, 2011, 03:09:29 PM »
Quote
What I am asking is how do I know what type of detection is avast detecting when they said Win32:Trojan-gen?
Or does he mean type of malware.......it does say Trojan

LunarWolf

  • Guest
Re: Detection or Generic?
« Reply #9 on: January 09, 2011, 01:34:33 PM »
What I am asking, is it a signature detection?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Detection or Generic?
« Reply #10 on: January 09, 2011, 01:52:26 PM »
What I am asking, is it a signature detection?

Yes.
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

LunarWolf

  • Guest
Re: Detection or Generic?
« Reply #11 on: January 09, 2011, 03:02:12 PM »
Then why not give it a name? Why use -gen?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Detection or Generic?
« Reply #12 on: January 09, 2011, 03:30:58 PM »
Because the signature (generic) is designed to detect multiple variants of malware 'trojans in this case.' For a detection to be given a specific signature/name first a sample must be received/analysed, a signature and name produced and included in the next VPS.

This all takes time and the generic signatures serve an important purpose in detecting new variants that might otherwise not be detected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security