VIRUS NAME LIBRARY

APK virus name library

Every detection (virus) name that has come up in VendorGuard APK scans, each with its own page: what each part of the name means, how the vendor words the warning, how severe it is and what to do about it.

Detection names: 0

No detection names yet.

How to read a detection name

Engines build detection names in a fixed format: dot-separated parts that go from general to specific, with a slash between names when an app matches more than one. Taking Android.Virus.Gray.Poker.A.WLDB.LuckyCashGame:

PartTypeMeaning
AndroidPlatformAndroid app, i.e. an APK package.
VirusCategoryVirus class: the engine files it under viruses or malware. Followed by Gray it means grayware rather than a destructive virus.
GrayCategoryGrayware: between a normal app and malware; typical of gambling, adult content, fraud, deceptive billing and bundled promotion.
PokerFamily / samplePoker / card games: card and board game apps, often related to gambling.
AVariantVariant letter: versions of the same family are lettered in sequence.
WLDBCategory codeProbably the pinyin initials of 网络赌博 (online gambling): gambling and betting apps.
LuckyCashGameFamily / sampleFamily or sample name that tells apart different apps or code traits within the same category.

FAQ

What is a detection name?

A detection name (virus name) is the label a security engine gives a flagged package, naming the platform, the risk category and the family. When a phone’s security app or app store warns about a “risky app” or a “virus”, such a name is usually behind it.

What does a detection starting with Android.Virus.Gray mean?

Gray means grayware: not necessarily destructive code, but considered harmful to users’ interests, e.g. gambling, adult content, fraud, deceptive billing or bundled promotion. The family name and tags after it give the specific reason.

Is every detection a virus?

No. Detections at the “Risk” level are mostly grayware or policy calls; “Virus” means malicious code or high-risk behavior. False positives happen too, so you can re-scan or appeal to the vendor.

What should a developer do about a false positive?

Check the detection name and the vendor’s warning, review third-party SDKs, packers, permissions and content for what triggers it, appeal through that vendor’s developer platform, and re-scan on VendorGuard once the appeal is accepted.