home *** CD-ROM | disk | FTP | other *** search
/ Freelog 11 / Freelog011.iso / Extra / Antivir / NavScan / 0526i16.exe / whatsnew.txt < prev   
Text File  |  2000-05-26  |  19KB  |  343 lines

  1. **********************************************************************
  2. **                                                                  **
  3. **  What's New in the NAV Virus Definitions Files      WHATSNEW.TXT **
  4. **                                                                  **
  5. **  Symantec AntiVirus Research Center (SARC)          May 26 ,2000 **
  6. **                                                                  **
  7. **********************************************************************
  8. This document contains the following topics:
  9.  
  10.  * Virus Alerts
  11.  * New Technologies
  12.  * Changes Incorporated Into This Update
  13.  * Enabling Scanning Features
  14.  * Additional Information
  15.  
  16. **********************************************************************
  17. ** Virus Alerts                                                     **
  18. **********************************************************************
  19. VBS.LoveLetter, a new worm which has been wide-spread since May 4th,
  20. is detected by this definitions set.  
  21.  
  22. The ten most commonly reported viruses, worldwide:
  23.  
  24.     1  VBS.LoveLetter.A
  25.     2  WScript.KakWorm
  26.     3  VBS.Network
  27.     4  W95.CIH
  28.     5  Happy99.Worm
  29.     6  Worm.ExploreZip
  30.     7  W97M.ColdApe
  31.     8  W97M.Ethan
  32.     9  W97M.Melissa
  33.    10  WM.Cap
  34.  
  35. **********************************************************************
  36. ** New Technologies                                                 **
  37. **********************************************************************
  38.  
  39. DATE         Technologies Added
  40. ----         ------------------
  41. 8/19/98    * Excel heuristics which detect and repair new and unknown
  42.              macro viruses in Excel 95 & 97 documents.
  43.  
  44. 9/16/98    * Added repair for encrypted Excel 97 documents.
  45.  
  46. 10/21/98   * Heuristics to detect AOL Password Stealer Trojans.
  47.            * WORD Heuristics improvement to increase detection rate.
  48.  
  49. 12/17/98   * Macro Exclusion Engine to speed up the scanning for Word
  50.              and Excel documents.
  51.            * PowerPoint engine to scan PowerPoint related viruses.
  52.              To enable this technology please read "Enabling/Disabling
  53.              PowerPoint Scanning" section later in this document.
  54.  
  55. 02/18/99   * Detection and repair of macro viruses in Word and Excel
  56.              2000 documents.
  57.  
  58. 05/15/99   * Added repair for PowerPoint viruses.
  59.            * Improved heuristics to detect more WORD 97 related
  60.              viruses.
  61.  
  62. 06/10/99   * Menu repair technology for WORD macro viruses that change
  63.              command bar customizations in NORMAL.DOT.
  64.  
  65. 07/12/99   * Added support for scanning of Ichitaro 8/9 documents.
  66.              (Ichitaro is a Japanese word processing program).
  67.  
  68. 08/19/99   * Added detection and repair for embedded documents inside
  69.              PowerPoint 97.
  70.  
  71. 11/22/99   * Added detection and repair for Trojans embedded in OLE
  72.              files, such as Windows scrap files and MS Office
  73.              documents.
  74.            * Added detection for viruses which infect Microsoft
  75.              Project documents (P98M.Corner.A, for example).
  76.  
  77. 02/10/00   * Added support for scanning of UNIX executables.
  78.            * Added detection for infected Visio documents.
  79.  
  80. **********************************************************************
  81. ** Changes Incorporated Into This Virus Definitions Update          **
  82. **********************************************************************
  83. New virus definitions:
  84.  
  85.         Virus Name                Infection Type          Week added
  86.         ----------                --------------          ----------
  87.         911BAT.Worm.B             File infector           05/04/00
  88.         Backdoor.Asylum           File infector           05/09/00
  89.         Backdoor.Eclypse          File infector           05/04/00
  90.         Backdoor.Fantasy          File infector           05/04/00
  91.         Backdoor.Frenzy           File infector           05/09/00
  92.         Backdoor.Muie             File infector           05/09/00
  93.         backdoor.netbus.12        File infector           05/09/00
  94.         Backdoor.Ping.C           File infector           05/04/00
  95.         Backdoor.Poly             File infector           05/04/00
  96.         Backdoor.PolyDrop         File infector           05/04/00
  97.         Backdoor.Prosiak          File infector           04/24/00
  98.         Backdoor.Tasmer           File infector           04/24/00
  99.         Backdoor.Wincrash         File infector           05/09/00
  100.         Beard.Trojan              File infector           05/04/00
  101.         CLRC.554                  File infector           05/04/00
  102.         ConCon.Trojan             File infector           05/15/00
  103.         DrZip.512                 File infector           05/22/00
  104.         FEC(b)                    Boot infector           05/04/00
  105.         FEC.Dropper               File infector           05/04/00
  106.         GIP.Trojan                File infector           05/22/00
  107.         ICQ.PWS.Trojan            File infector           05/09/00
  108.         Intd.Leprosy.TheThing     File infector           05/04/00
  109.         IRC.Csr.Worm              File infector           05/04/00
  110.         Leonard.1179              File infector           04/24/00
  111.         Linux.DDoS.MStream        File infector           05/22/00
  112.         Movie.Pif.Worm.B          File infector           05/09/00
  113.         MSU_A.271                 File infector           04/24/00
  114.         Netsphere.Trojan          File infector           05/04/00
  115.         O97M.Hopper.U             File infector           05/04/00
  116.         097M.CyberNet.A           File infector           05/22/00
  117.         PWS.Hooker.Trojan         File infector           05/04/00
  118.         PWSteal.Coced.Trojan      File infector           04/24/00
  119.         PWSteal.LoveLetter        File infector           05/04/00
  120.         Rfpmgrtoet.Trojan         File infector           04/24/00
  121.         Solaris.DDoS.MStream      File infector           05/22/00
  122.         Stoned.HM (db)            Boot infector           05/09/00
  123.         TinyOpts.Trojan           File infector           04/24/00
  124.         Trojan.Aleph.B            File infector           04/24/00
  125.         Trojan.Bat.Format.FR      File infector           05/09/00
  126.         Trojan.Call911            File infector           05/04/00
  127.         Trojan.Platan.G           File infector           04/24/00
  128.         Trojan.Rhino              File infector           04/24/00
  129.         Trojan.WinDac             File infector           05/04/00
  130.         Unix.LoveLetter           File infector           05/15/00
  131.         VBS.Fool.B                File infector           04/24/00
  132.         VBS.LoveLetter.(HTM)      File infector           05/05/00
  133.         VBS.LoveLetter.A          File infector           05/04/00
  134.         VBS.LoveLetter.A(1)       File infector           05/05/00
  135.         VBS.LoveLetter.B(1)       File infector           05/05/00
  136.         VBS.LoveLetter.C(1)       File infector           05/05/00
  137.         VBS.LoveLetter.E          File infector           05/08/00
  138.         VBS.LoveLetter.E(1)       File infector           05/08/00
  139.         VBS.LoveLetter.E(2)       File infector           05/08/00
  140.         VBS.LoveLetter.E(3)       File infector           05/08/00
  141.         VBS.LoveLetter.F          File infector           05/08/00
  142.         VBS.LoveLetter.F(1)       File infector           05/08/00
  143.         VBS.LoveLetter.F(2)       File infector           05/08/00
  144.         VBS.LoveLetter.F(3)       File infector           05/08/00
  145.         VBS.LoveLetter.G          File infector           05/08/00
  146.         VBS.LoveLetter.G(1)       File infector           05/08/00
  147.         VBS.LoveLetter.G(2)       File infector           05/08/00
  148.         VBS.LoveLetter.G(3)       File infector           05/08/00
  149.         VBS.LoveLetter.H          File infector           05/08/00
  150.         VBS.LoveLetter.I          File infector           05/08/00
  151.         VBS.LoveLetter.K          File infector           05/08/00
  152.         VBS.LoveLetter.L          File infector           05/08/00
  153.         VBS.LoveLetter.M          File infector           05/08/00
  154.         VBS.LoveLetter.N          File infector           05/08/00
  155.         VBS.LoveLetter.O          File infector           05/08/00
  156.         VBS.LoveLetter.P          File infector           05/08/00
  157.         VBS.LoveLetter.Q          File infector           05/08/00
  158.         VBS.LoveLetter.R          File infector           05/08/00
  159.         VBS.LoveLetter.S          File infector           05/08/00
  160.         VBS.LoveLetter.variant    File infector           05/05/00
  161.         VBS.MP3Free.A             File infector           05/22/00
  162.         VBS.MP3Free.A(2)          File infector           05/15/00
  163.         VBS.NewLove.A             File infector           05/18/00
  164.         VCG.Belka                 File infector           05/22/00
  165.         W32.Android.Worm          File infector           05/22/00
  166.         W32.Blink.8192            File infector           05/15/00
  167.         W32.Cargo.B.Int           File infector           05/22/00
  168.         W32.Demo.Worm             File infector           05/22/00
  169.         W32.Dengue                File infector           04/24/00
  170.         W32.Dolly.14848.Mirc      File infector           05/15/00
  171.         W32.Headline.Worm.Int     File infector           05/04/00
  172.         W32.Hellfire.Mirc         File infector           05/22/00
  173.         W32.HLLO.ZMK.30030        File infector           05/22/00
  174.         W32.HLLP.Cramb            File infector           05/04/00
  175.         W32.HLLP.Cramb.B          File infector           05/22/00
  176.         W32.HLLP.Gotem.Int        File infector           05/15/00
  177.         W32.HLLP.Hetis.34304      File infector           05/04/00
  178.         W32.HLLP.This.16896       File infector           05/22/00
  179.         W32.Magic.1922            File infector           05/22/00
  180.         W32.Mirc.25088.Worm       File infector           04/24/00
  181.         W32.Mypics.Worm.36352     File infector           05/09/00
  182.         W32.PrettyPark.L.Worm     File infector           04/24/00
  183.         W32.PrettyPark.M.Worm     File infector           04/24/00
  184.         W32.PrettyPark.N.Worm     File infector           04/24/00
  185.         W32.PrettyPark.O.Worm     File infector           05/04/00
  186.         W32.RainSong.3891         File infector           05/15/00
  187.         W32.Riccy.A               File infector           05/22/00
  188.         W32.Riccy.B               File infector           05/22/00
  189.         W32.Riccy.C               File infector           05/22/00
  190.         W32.Silver.Mirc           File infector           05/22/00
  191.         W32.Southpark.Worm        File infector           05/15/00
  192.         W32.Stupid.C              File infector           04/24/00
  193.         W32.Tasmer.46395          File infector           05/15/00
  194.         W95.Grenp.2804            File infector           05/04/00
  195.         W95.Icer.541              File infector           04/24/00
  196.         W95.Kala.7620             File infector           05/15/00
  197.         W95.Payk                  File infector           04/24/00
  198.         W95.Sab.753               File infector           05/04/00
  199.         W95.Santana.1104          File infector           04/24/00
  200.         W95.Segax.1136            File infector           04/24/00
  201.         W95.Sexy.384              File infector           04/24/00
  202.         W95.Shaitan.3550          File infector           05/22/00
  203.         W95.SillyWR.Gen           File infector           05/04/00
  204.         W95.Smash                 File infector           04/24/00
  205.         W95.ZOM                   File infector           05/22/00
  206.         W95.Zomb.432              File infector           05/22/00
  207.         W97M.Blink.8192.A         File infector           05/15/00
  208.         W97M.Eight941.G           File infector           05/09/00
  209.         W97M.Eight941.H           File infector           05/09/00
  210.         W97M.Eight941.I           File infector           05/15/00
  211.         W97M.Foster               File infector           04/24/00
  212.         W97M.Heels.A              File infector           05/15/00
  213.         W97M.IJK.C                File infector           04/24/00
  214.         W97M.LCM                  File infector           05/04/00
  215.         W97M.LoveDrop             File infector           05/22/00
  216.         W97M.Lupi.C               File infector           05/04/00
  217.         W97M.MARKER.BZ            File infector           04/24/00
  218.         W97M.MARKER.CA            File infector           04/24/00
  219.         W97M.MARKER.CB            File infector           05/09/00
  220.         W97M.Marker.CR            File infector           05/09/00
  221.         W97M.MARKER.CS            File infector           05/15/00
  222.         W97M.Marker.CT            File infector           05/22/00
  223.         W97M.Marker.S             File infector           05/22/00
  224.         W97M.Melissa.BG           File infector           05/26/00
  225.         W97M.Onex.A               File infector           04/24/00
  226.         W97M.OutlookWorm.Gen      File infector           05/26/00
  227.         W97M.Shab                 File infector           05/09/00
  228.         W97M.Shining.A            File infector           05/15/00
  229.         W97M.Sprite               File infector           05/22/00
  230.         W97M.Thus.S               File infector           04/24/00
  231.         W97M.Thus.T               File infector           05/04/00
  232.         W97M.Thus.U               File infector           05/04/00
  233.         W97M.Thus.V               File infector           05/22/00
  234.         W97M.Ucase                File infector           05/09/00
  235.         W97M.VMPCK1.DH            File infector           05/04/00
  236.         W97M.VMPCK1.DJ            File infector           05/09/00
  237.         W97M.XYZ.A                File infector           05/04/00
  238.         Win.Ph33r.1418            File infector           04/24/00
  239.         Winfig.Trojan             File infector           05/04/00
  240.         X97M.Automat.AH           File infector           05/04/00
  241.         X97M.Automat.AJ           File infector           05/15/00
  242.         X97M.Automat.AK           File infector           05/15/00
  243.         X97M.Automat.AM           File infector           05/22/00
  244.         X97M.Laroux.KV            File infector           05/26/00
  245.         X97M.OutlookWorm.Gen      File infector           05/26/00
  246.         XM.Automat.AG             File infector           04/24/00
  247.         XM.Automat.AI             File infector           05/09/00
  248.         XM.Automat.AL             File infector           05/15/00
  249.         Zhit.1654                 File infector           05/04/00
  250.         Zombie.3592               File infector           05/22/00
  251.  
  252. Name Changes:
  253.  
  254.         Old Virus Name            New Virus Name          Date changed
  255.         --------------            --------------          ------------
  256.         Backdoor.Psychward.b   to Backdoor.Psychward      05/15/00
  257.         VBS.NewLove.A2(gen 1)  to VBS.NewLove.A2(Gen 1)   05/22/00
  258.         W32.Magic.7045.B       to W32.Magic.7045.Gen      05/22/00
  259.  
  260.  
  261.  
  262. Deletions:
  263.  
  264.         Virus Name                Infection Type          Date removed
  265.         ----------                --------------          ------------
  266.         Joshi Dropper             Boot infector           05/04/00
  267.         Narcosis (d)              File infector           05/04/00
  268.         X97M.Automat.AJ           File infector           05/22/00
  269.         XM.Automat.AL             File infector           05/22/00
  270.  
  271.  
  272. **********************************************************************
  273. **  Enabling Scanning Features                                      **
  274. **********************************************************************
  275.  
  276. Several scanning features can be enabled through the use of an INF 
  277. configuration file.  For NAV for Windows 95/NT version 4.x and later, 
  278. or NAV for OS/2, this configuration file should be called NAVEX15.INF
  279. and should be placed in the directory where NAV is installed (i.e.,
  280. C:\Program Files\Norton AntiVirus).  For NAV for Netware version 4.x,
  281. the file should be called NAVEX15.INF and should be placed in the 
  282. directory where NAV 4.x is installed (i.e., sys:system\navnlm). For
  283. NAV for Windows 95/NT version 2.0, NAV 4.x for Windows 3.1/DOS,
  284. NAVIEG 1.x, or NAVFW 1.x, the file should be named NAVEX.INF and
  285. should be placed in the directory where NAV is installed (i.e., C:\NAV).
  286. If this configuration file does not exist, create one in the appropriate
  287. directory if you want to change the default settings.
  288.  
  289. To enable a scanning feature for a particular component, one or more 
  290. entries need to be added to the configuration file under the correct
  291. section.  For each platform there is a corresponding section that is used 
  292. in the INF file.  Below is a table of section names and platforms.
  293.  
  294. Section Name    Platform
  295. ------------    --------
  296. NAVW32          Windows 95/98/NT
  297. NAVAP           Windows 95/98/NT Auto-Protect
  298. NAVDX           DOS
  299. NAVNLM          Netware
  300. NAVWIN          Windows 3.1
  301. NAVOS2          OS/2
  302. NAVAIX          AIX
  303. NAVSOL          Solaris
  304.  
  305. Entries are case insensitive.  Below is a description of possible 
  306. entries.
  307.  
  308. 1. Files can be excluded from scans by the NAVEX engine.  To exclude a
  309. specific file from the NAVEX engine scan, add an entry with the full
  310. path and file name.  This is case insensitive.  No wildcards are allowed.
  311. To exclude multiple files, add a separate entry for each file.  To exclude
  312. a file, add an entry like the one below where <PATH> is the full path
  313. and file name.
  314.         ExcludeFile = <PATH>
  315.  
  316. 2. Files within a directory can be excluded from scans by the NAVEX engine.
  317. To exclude all files within a directory, add an entry with the full 
  318. directory path.  This is case insensitive.  No wildcards are allowed.  This
  319. does not exclude files located in subdirectories of the specified 
  320. directory.  To exclude multiple directories, add a separate entry for each
  321. directory. To exclude a directory, add an entry like the one below where
  322. <DIRECTORY> is the full path.
  323.         ExcludeDirectory = <DIRECTORY>
  324.  
  325. The following example of an INF configuration file excludes two files, 
  326. NOSCAN.EXE and BIGFILE.DOC, from NAVEX scans for the Windows 95/98/NT 
  327. scanner.  It excludes the D:\PRIVATE directory from Windows 95/98/NT 
  328. Auto-Protect.
  329.  
  330. [NAVW32]
  331. ExcludeFile = C:\PROGRAM FILES\NOSCAN.EXE
  332. ExcludeFile = C:\TEMP\BIGFILE.DOC
  333.  
  334. [NAVAP]
  335. ExcludeDirectory = D:\PRIVATE
  336.  
  337. **********************************************************************
  338. **    Additional Information                                        **
  339. **********************************************************************
  340.  
  341. Additional information regarding this virus definitions update can be
  342. found in UPDATE.TXT and TECHNOTE.TXT.
  343.