Why antivirus programs give one threat different names

•Ransomware•Ugnius Kiguolis

Antivirus companies name threats independently, each with its own format, so one file can carry dozens of different names on VirusTotal. The part that tells you most is the type (for example Trojan, PWS, Ransom or PUA); the family name is useful only when it is a real family rather than a generic label such as GenericKD, Agent or HEUR.

Why one threat has many names

There is no central registry that assigns malware names. Each security company analyses samples on its own, often within minutes of first seeing them, and gives each one a name before anyone knows which family it belongs to. When a family later gets a widely used name, older detections are not always renamed.

Names also differ because detections differ. One engine recognises a file by an exact signature and names the family. Another flags it because it behaves like ransomware and gives a behaviour name. A third uses machine learning and returns a generic verdict with no family at all. Several vendors license the same engine from another company, so the same label can appear under different brand names.

Microsoft's own documentation notes that security software providers sometimes use different names for the same malware family. The practical result: a detection name is a hint about what a file is, not an identifier you can expect to match across products.

How to read Microsoft Defender names

Microsoft Defender, built into Windows 11 and Windows 10, follows the CARO (Computer Antivirus Research Organization) naming scheme. A full name has this shape:

Type:Platform/Family.Variant!Suffix

Take Trojan:Win32/Wacatac.B!ml, a name readers often ask about, as an example:

  • Type (Trojan) says what the threat does. This is the most important part.
  • Platform (Win32) says where it runs: an operating system such as Win32 or Win64, a script language such as JS, VBS, PowerShell or AutoIt, .NET code (MSIL), or Office macros (O97M, X97M).
  • Family (Wacatac) groups samples with common traits or authors.
  • Variant (B) is a letter assigned in sequence to each distinct version: .AF comes after .AE.
  • Suffix (!ml) begins with an exclamation mark. Microsoft states only that such suffixes are indicators used internally; common ones seen by users include !ml and !MTB. Do not read more into them than that.

Microsoft's type words

Microsoft groups its types into three tiers, and the tier tells you how worried to be.

  • Malware: Backdoor, Constructor, DDoS, Exploit, HackTool, Joke, PWS (password stealer), Ransom, Rogue (fake security software), Spammer, Spoofer, Trojan, TrojanClicker, TrojanDownloader, TrojanNotifier, TrojanProxy, TrojanSpy, VirTool, Virus, Worm.
  • Unwanted software: Adware, BrowserModifier, Misleading, MonitoringTool, Program, SoftwareBundler, UwS. These change settings or behave badly but are not built to steal or destroy.
  • Potentially unwanted applications (PUA): PUA, App, PUAAdvertising, PUATorrent, PUAMiner, PUAMarketing, PUABundler, PUADlManager. Usually bundled or ad-driven software with a poor reputation.
  • Others: Tampering (tools that lower device security), Vulnerable and VulnerableDriver (legitimate but exploitable software), Behavior (something suspicious was done, rather than a file found) and Tool.

So PWS:Win32/... is a password stealer and needs the account steps in information stealers, BrowserModifier:Win32/... is a hijacker you remove from the browser, and PUA:Win32/... is unwanted software you can usually uninstall normally. A Behavior:Win32/... alert means Defender stopped an action, so look at the file it names.

Kaspersky, ESET, Malwarebytes and other formats

Kaspersky

Kaspersky names follow [Prefix:]Behaviour.Platform.Name[.Variant], for example Trojan-PSW.Win32.Family.abc. The behaviour part plays the role of Microsoft's type: Trojan-Ransom, Trojan-PSW (password stealer), Trojan-Spy, Trojan-Banker, Trojan-Downloader, Trojan-Dropper, Backdoor, Worm, Virus. The optional prefix shows which part of the product detected it: HEUR: for the heuristic analyser and PDM: for the proactive defence (behaviour) module.

The prefix not-a-virus: marks adware, riskware and similar software that is legal but may be unwanted, such as not-a-virus:AdWare.Win32... or not-a-virus:RiskTool.Win32.... It is Kaspersky's way of saying this is not malicious in the strict sense, while still warning you.

ESET

ESET names look like Win32/Filecoder.ABC (ransomware), Win32/PSW.Agent..., MSIL/Spy.Agent... or JS/Adware.... Many detections are written as a variant of a family, for example a variant of Win32/Adware.X potentially unwanted application, which means the file resembles a known family closely enough to match. ESET separates potentially unwanted applications, which include adware, bundlers, toolbars, registry cleaners and proxyware, from potentially unsafe applications, which are legitimate commercial tools such as remote access programs that attackers could misuse.

Malwarebytes

Malwarebytes uses the category PUP.Optional for potentially unwanted programs, for example PUP.Optional.Manuals. Optional means you decide whether to remove it. Other categories include Adware, Trojan, Ransom, Spyware, Backdoor and RiskWare, and Malware.AI followed by an ID number is a name created automatically for unknown threats found with machine-learning techniques, without a family name.

Generic labels from other engines

  • Trojan.GenericKD.<number>, Gen:Variant... and Gen:Heur... come from the Bitdefender engine, which several other products license.
  • HEUR/AGEN... is a generic detection from Avira.
  • Trojan.Generic, Win32.Trojan.Agent, Generic.mg, ML.Attribute... and Malicious (score: NN) are generic or machine-learning verdicts from various vendors.

A generic label means the engine is confident the file is bad, or at least suspicious, but did not match it to a family. It does not tell you what the file does.

Reading VirusTotal results and detection ratios

VirusTotal runs a file or URL through more than 70 antivirus engines and other tools and shows every engine's verdict. The headline number, such as 45/72, is the count of engines that flagged it out of the engines that scanned it.

Read the ratio with care:

  • A high ratio with consistent type words (most engines say ransomware, or most say stealer) is a strong signal.
  • A low ratio is not proof of safety. Brand-new malware is often flagged by only a few engines in its first hours or days.
  • A low ratio made up mostly of generic or machine-learning labels on a little-known program can be a false positive, especially for small developers' tools, game mods and unsigned software.
  • Ratios change over time. A file that scored 3 today can score 40 next week. Note the date of the analysis; our guides always state the date we checked.
  • Adware and unwanted programs often get mixed results, because vendors draw the line between unwanted and acceptable differently.

VirusTotal itself warns that its engines are command-line versions, so they will not behave exactly like the full desktop products, which may also use behaviour monitoring. Its results are not a ranking of antivirus quality.

Before uploading, think about privacy. VirusTotal shares scan reports with its community, and the contents of submitted files may be shared with premium customers. Do not upload personal documents, tax files or anything confidential; searching by the file's hash is a safe alternative when you only need the result.

Which name to look at

When one file has many names, use this order:

  1. The name from the antivirus on your own PC, usually Microsoft Defender. It is the one your guide or support forum will search for.
  2. The type word, which most engines agree on even when family names differ: ransomware, password stealer, trojan downloader, adware, PUA.
  3. A named family that several engines share. If three vendors say the same family, that is likely the right one.
  4. Generic names last. They confirm that something is wrong but not what.

On 2-spyware.com, every removal guide lists the Microsoft Defender name where known and a few names from other engines, with the date we looked them up, so you can match your alert to the right guide. When names conflict, the guide follows the family that the evidence supports, not the most frequent label.

False positives: when the antivirus is wrong

A false positive is a harmless file detected as malicious. It happens most often with new or rarely downloaded programs, unsigned tools from small developers, game mods, scripts that automate Windows, and installers made with less common packaging tools. Cracks, keygens and activators are not false positives, even when a forum says so: many carry real payloads, and Microsoft detects licence circumvention tools as HackTool.

How to judge a detection

  • Where did the file come from? A download from the developer's official site is more likely to be a false positive than a file from a forum, a video description or a torrent.
  • Is it digitally signed by the developer? Right-click the file, open Properties and look for a Digital Signatures tab.
  • What type of detection is it? A generic or machine-learning label from one engine is weaker evidence than a named PWS or Ransom detection from several.
  • What does the developer say? Many publish notices about known false positives.

Microsoft Defender SmartScreen's Windows protected your PC message is not a detection. It means the file is unknown or rarely downloaded, not that it is malicious.

Restoring a file and reporting the mistake

If you are confident a file is safe, you can restore it from Windows Security > Virus & threat protection > Protection history, where each detection has an option to allow or restore. Avoid adding broad exclusions such as a whole drive or the Downloads folder; malware relies on exactly that.

Report the error so the detection is fixed for everyone. Microsoft accepts files through its Security Intelligence submission portal, where you choose whether you are a home user, an enterprise customer or a software developer and mark the submission as an incorrect detection. Other vendors have their own forms; developers can usually find them on the vendor's support site.

Common myths about detection names

Different names mean different threats

Usually not. The same file can be Trojan:Win32/... at Microsoft, Trojan.GenericKD... at another vendor and HEUR:Trojan.Win32.Generic at a third. Compare hashes, not names, when you need to know whether two detections are the same file.

Generic means harmless

A generic name says the engine did not name a family, not that the threat is mild. Many serious infections are first detected generically.

not-a-virus or PUA means I can ignore it

These labels mark software that is legal but often unwanted: adware, bundlers, miners, remote tools. Check what it is and whether you installed it. If you did not, remove it; see potentially unwanted programs.

If only one engine detects it, it is a false positive

Sometimes it is; sometimes that engine is simply first. Look at the type of detection and the file's source before deciding.

Frequently asked questions

What does Trojan:Win32/Wacatac.B!ml mean?

It is a Microsoft Defender name in the CARO format. Trojan is the type, meaning a program that hides its real purpose; Win32 means it runs on Windows; Wacatac is the family name Microsoft uses; B is the variant; and !ml is a suffix that Microsoft describes only as an internal indicator. Microsoft uses this name for a wide range of files, so it does not tell you exactly what the file does. Check where the file came from, quarantine or remove it, and run a Microsoft Defender offline scan. If it came from a crack or an unknown download, treat it as real and follow our guide to trojans and loaders.

What does PUA mean in Microsoft Defender?

PUA stands for potentially unwanted application. Microsoft uses it for software that is not malware but has a poor reputation or unwanted behaviour, such as bundlers that install extra programs, adware, torrent clients, cryptocurrency miners and marketing tools. Names start with PUA:, PUAAdvertising:, PUABundler:, PUAMiner: and similar. If you did not knowingly install the program, remove it; if you did and you trust it, you can allow it in Protection history. Turning on Potentially unwanted app blocking under Windows Security > App & browser control > Reputation-based protection stops many of these at download.

What does not-a-virus mean in Kaspersky?

Kaspersky puts the prefix not-a-virus: in front of detections for legal software that may still be unwanted or risky: adware, riskware such as remote administration and password tools, and similar programs. An example is not-a-virus:AdWare.Win32.<name>. The prefix means the program is not malicious in the strict sense, not that it is safe to keep. If you did not install the program on purpose, or it shows ads, changes your browser or runs at startup without your consent, remove it. If it is a tool you use deliberately, you can exclude it in Kaspersky's settings.

What is PUP.Optional in Malwarebytes?

PUP.Optional is the category Malwarebytes uses for potentially unwanted programs: software that is not classic malware but that many users would not want, such as bundled toolbars, adware, aggressive system optimisers and download managers. The word Optional reflects that you decide whether to remove it. The part after it is the program or family, for example PUP.Optional.Manuals. If you do not recognise the program or it came bundled with something else, quarantine it. If it is something you installed knowingly and use, you can leave it.

Why does VirusTotal show different results from my antivirus?

VirusTotal runs command-line versions of each engine, which, as VirusTotal itself notes, do not behave exactly like the full desktop products. Desktop antivirus may block a file through behaviour monitoring or cloud reputation even if the scanner on VirusTotal does not flag it, and the reverse also happens. Engines are updated at different times, so results change over the hours and days after a file first appears. Vendors also draw different lines for adware and unwanted programs. Use VirusTotal as a second opinion, look at the type words most engines agree on, and note the date of the analysis.

How do I report a false positive to Microsoft?

Use the Microsoft Security Intelligence file submission page at microsoft.com/en-us/wdsi/filesubmission. Choose whether you are submitting as a home customer, an enterprise customer or a software developer, upload the file, and select that you believe it is incorrectly detected. Include the detection name shown in Protection history. Microsoft analyses the file and updates its definitions if it agrees. Meanwhile, you can restore the file from Protection history if you are confident it is safe. Avoid disabling real-time protection or excluding whole folders while you wait.

About the author

Ugnius Kiguolis, Owner and editor of 2-spyware.com. Ugnius Kiguolis owns and edits 2-spyware.com and is responsible for its Windows security guides. Every page he signs is checked against current vendor, law-enforcement and Microsoft sources before it is published and again when the facts change.

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year