Virus Names

 

A virus' name is generally assigned by the first researcher to encounter the beast. The problem is that multiple researchers may encounter a new virus in parallel which often results in multiple names.

What's in a name? When it comes to viruses it's a matter of identification to the general public. An anti-virus program does not really need the name of a virus as it identifies it by its characteristics. But, while giving a virus a name helps the public at large it also serves to confuse them since the names given to a particular beast can differ from anti-virus maker to anti-virus maker.

How? Why? Much as they would like to, the virus writers do not get to name their beasts. Some have tried by putting obvious text into the virus but most of the anti-virus companies tend to ignore such text (mostly to spite the virus writers). And, any virus writer that insists on a particular name has to identify themselves in the process--something they usually don't want to do. So, the anti-virus companies control the virus naming process. But, that leads to the naming problem.

Viruses come into various anti-virus companies around the world at various times and by various means. Each company analyzes the virus and assigns a name to it for tracking purposes. While there is cooperation between companies when new viruses are identified, that cooperation often takes a back seat to getting a product update out the door so the anti-virus company's customers are protected. This delay allows alternate names to enter the market. Over time these are often standardized or, at least, cross-referenced in listings; but that does not help when the beast makes its first appearance.

This problem/confusion will continue. One practical and well documented example of how it affects a real-world virus listing can be seen at the WildList site on the page...

http://www.wildlist.org/naming.htm

One attempt at bringing some order to the naming problem is Ian Whalley's VGrep [registration required  to view page]. VGrep attempts to collect all of the various virus names and then correlates them into a single searchable list. While useful, there is, again, the lag time necessary to collect and correlate the data.

So, get used to viruses having different names. As Shakespeare said...

What's in a name? That which we call a rose
By any other name would smell as sweet...

Another attempt is the database at VirusPool which "...tries to put information from all known infections and antivirus creators into one place so you can compare names and results." I wish them the best of luck.

A new site to try to correlate malware names: CME - Common Malware Enumeration. CME provides single, common identifiers to new virus threats to reduce public confusion during malware outbreaks. CME is not an attempt to solve the challenges involved with naming schemes for viruses and other forms of malware, but instead aims to facilitate the adoption of a shared, neutral indexing capability for malware.

Finally, some vendors have largely given up with naming specific malware and resorting to generic names for the type of malware (e.g., Troj/Agent). The malware is being generated faster than the naming system can reasonably keep up. Look for this to probably continue. Of course, this will then mean changes to the specific methods of disinfection as you would no longer be able to download a specific disinfector for a named beast. Time will tell how this develops.

Summary

  • Virus naming is a function of the anti-virus companies. This results in different names for new viruses.
  • Different names can cause confusion for the public but not anti-virus software which looks at the virus, not its "name."
  • There are different sites that attempt to correlate the various virus names for you.

 

Up Introduction to Viruses Up
Previous Next
Number of Viruses   How Serious are Viruses?

Comments (8)

Simon
Said this on 2009-06-22 At 11:15 am
I am trying to acertain if a yann chit tal is a virus? It has attached itself as the file name to all music & picture files.
DaBoss
Said this on 2009-06-22 At 12:40 pm
The best way to find out would be to scan the system with anti-virus software. A Google search on the term brings up the name of a Myanmar love song and one entry that would indicate that behavior is related to a virus.

Do the search and scan the system.
simon
Said this on 2009-06-22 At 04:46 pm
Thanks

I havn't picked it up with any anti virus software - I suppose I will just have to keep working at it.

Thanks again
Simon
Said this on 2009-06-23 At 07:05 am
What was the name of the anti-virus software you mentioned
DaBoss
Said this on 2009-06-23 At 05:12 pm
I did not mention one. The thread Google brings up is here...

http://myanmaritpros.com/forum/topic/show?id=1445004%3ATopic%3A106986
Simon
Said this on 2009-06-23 At 03:51 pm
what antivirus do you recomend? Please I am getting desperate !!!!!!
DaBoss
Said this on 2009-06-23 At 05:15 pm
I don't recommend any specific AV programs. See the AV page in the tutorial for a listing of many you can choose from (take the Miscellaneous Pages link in the left side menu).

And, comments in this thread have drifted way beyond the page purpose so further along these lines will not be allowed. Please keep topics in comments to the topic of the page itself. Thank you.
Simon
Said this on 2009-06-24 At 11:35 pm
Thank you. Sorry if I went out the the scope I am relitavely new to this virus stuff.
Post a Comment
* Your Name:
* Your Email:
(not publicly displayed)
Reply Notification:
Approval Notification:
Website:
* Security Image:
Security Image Generate new
Copy the numbers and letters from the security image:
* Message: