home *** CD-ROM | disk | FTP | other *** search
/ DOS/V Power Report 2000 June / VPR0006B.BIN / ANTI_VIR / NOR_DEF / 0327i32.exe / whatsnew.txt < prev    next >
Text File  |  2000-03-27  |  19KB  |  345 lines

  1. **********************************************************************
  2. **                                                                  **
  3. **  What's New in the NAV Virus Definitions Files      WHATSNEW.TXT **
  4. **                                                                  **
  5. **  Symantec AntiVirus Research Center (SARC)        March 27 ,2000 **
  6. **                                                                  **
  7. **********************************************************************
  8. This document contains the following topics:
  9.  
  10.  * Virus Alerts
  11.  * New Technologies
  12.  * Changes Incorporated Into This Update
  13.  * Enabling Scanning Features
  14.  * Additional Information
  15.  
  16. **********************************************************************
  17. ** Virus Alerts                                                     **
  18. **********************************************************************
  19. The ten most commonly reported viruses, worldwide:
  20.  
  21.     1  W97M.Class
  22.     2  XM.Laroux
  23.     3  O97M.Tristate
  24.     4  W95.CIH
  25.     5  Happy99.Worm
  26.     6  WM.Cap
  27.     7  W97M.ColdApe
  28.     8  W97M.Ethan
  29.     9  W97M.Melissa
  30.    10  Worm.ExploreZip
  31.  
  32. **********************************************************************
  33. ** New Technologies                                **
  34. **********************************************************************
  35.  
  36. DATE         Technologies Added
  37. ----         ------------------
  38. 8/19/98    * Excel heuristics which detect and repair new and unknown
  39.              macro viruses in Excel 95 & 97 documents.
  40.  
  41. 9/16/98    * Added repair for encrypted Excel 97 documents.
  42.  
  43. 10/21/98   * Heuristics to detect AOL Password Stealer Trojans.
  44.            * WORD Heuristics improvement to increase detection rate.
  45.  
  46. 12/17/98   * Macro Exclusion Engine to speed up the scanning for Word
  47.              and Excel documents.
  48.            * PowerPoint engine to scan PowerPoint related viruses.
  49.              To enable this technology please read "Enabling/Disabling
  50.              PowerPoint Scanning" section later in this document.
  51.  
  52. 02/18/99   * Detection and repair of macro viruses in Word and Excel
  53.              2000 documents.
  54.  
  55. 05/12/99   * Added repair for PowerPoint viruses.
  56.            * Improved heuristics to detect more WORD 97 related
  57.              viruses.
  58.  
  59. 06/10/99   * Menu repair technology for WORD macro viruses that change
  60.              command bar customizations in NORMAL.DOT.
  61.  
  62. 07/12/99   * Added support for scanning of Ichitaro 8/9 documents.
  63.              (Ichitaro is a Japanese word processing program).
  64.  
  65. 08/19/99   * Added detection and repair for embedded documents inside
  66.              PowerPoint 97.
  67.  
  68. 11/22/99   * Added detection and repair for Trojans embedded in OLE
  69.              files, such as Windows scrap files and MS Office
  70.              documents.
  71.            * Added detection for viruses which infect Microsoft
  72.              Project documents (P98M.Corner.A, for example).
  73.  
  74. 02/10/00   * Added support for scanning of UNIX executables.
  75.            * Added detection for infected Visio documents.
  76.  
  77. **********************************************************************
  78. ** Changes Incorporated Into This Virus Definitions Update        **
  79. **********************************************************************
  80. New virus definitions:
  81.  
  82.         Virus Name                Infection Type          Week added
  83.         ----------                --------------          ----------
  84.         Backdoor.BladeRunner      File infector          03/27/00
  85.         Backdoor.BrainSpy         File infector           03/06/00
  86.         Backdoor.Grab             File infector          03/27/00
  87.         Backdoor.Komut            File infector           03/17/00
  88.         Backdoor.Krass            File infector          03/27/00
  89.         Backdoor.NetMetro         File infector           02/29/00
  90.         Backdoor.Nightmare.a      File infector           02/29/00
  91.         Backdoor.NssKill          File infector           03/06/00
  92.         Backdoor.SBD              File infector           03/13/00
  93.         Backdoor.Senna            File infector          03/27/00
  94.         Backdoor.SubSeven21       File infector           02/29/00
  95.         Backdoor.TapiTroj         File infector           03/06/00
  96.         Bloodhound.Test           File infector           02/29/00
  97.         Giggles.Trojan            File infector          03/27/00
  98.         Infector.Trojan           File infector           03/17/00
  99.         IRC.Worm.Overnuke         File infector           02/29/00
  100.         Istanbul.1349             File infector           03/13/00
  101.         Istanbul.1397             File infector           03/13/00
  102.         Istanbul.1397 (x)         File infector           03/13/00
  103.         Jokiev.1918               File infector           02/29/00
  104.         Jokiev.1918 (m)           File infector           02/29/00
  105.         Js.JudgeDay               File infector           03/06/00
  106.         Linux.Backdoor.IN         File infector           03/17/00
  107.         Linux.Bliss.A             File infector           03/17/00
  108.         Linux.Bliss.B             File infector           03/17/00
  109.         Linux.Silv5444            File infector           03/17/00
  110.         Movie.Pif.Worm            File infector           03/17/00
  111.         NTMonitor.Trojan          File infector           03/13/00
  112.         O97M.Exceller.A           File infector          03/27/00
  113.         Opera (VXD)               File infector           02/29/00
  114.         Shifter.1295              File infector          03/27/00
  115.         Shifter.1295 (x)          File infector          03/27/00
  116.         Solaris.DoS.stacheld.s    File infector           03/17/00
  117.         SSR.19071                 File infector           03/13/00
  118.         SubSeven.Dropper          File infector           03/13/00
  119.         Termite.9100              File infector           02/29/00
  120.         Trojan.Bat.Erase          File infector           03/06/00
  121.         Trojan.Bat.HDKill         File infector          03/27/00
  122.         Trojan.FreeLinkX          File infector           03/06/00
  123.         Trojan.Masterlock         File infector           03/13/00
  124.         Trojan.Win32.Nukem        File infector           02/29/00
  125.         Unix.Bash                 File infector           03/17/00
  126.         Unix.Dumb.A               File infector           03/17/00
  127.         Unix.Dumb.B               File infector           03/17/00
  128.         Unix.Gift                 File infector           03/17/00
  129.         Unix.Jaded                File infector           03/17/00
  130.         Unix.ls                   File infector           03/17/00
  131.         Unix.Penguin              File infector           03/17/00
  132.         Unix.PSite                File infector           03/17/00
  133.         VBS.Orochi                File infector           03/17/00
  134.         VBS.Story                 File infector           03/13/00
  135.         W2K.Infis.4608            File infector           02/22/00
  136.         W32.AOC.3650              File infector           03/13/00
  137.         W32.AOC.3676              File infector          03/27/00
  138.         W32.Azaco.B.Worm          File infector           03/06/00
  139.         W32.Bolzano.5396.G1       File infector           03/13/00
  140.         W32.Cabdrop.4096          File infector           03/13/00
  141.         W32.Cholera.B.Worm        File infector          03/27/00
  142.         W32.Cholera.C.Worm        File infector          03/27/00
  143.         W32.CTX.7017              File infector           03/13/00
  144.         W32.ExploreZip.E.Worm     File infector           03/13/00
  145.         W32.HLLO.29128            File infector           03/13/00
  146.         W32.HLLP.Bora.11264       File infector          03/27/00
  147.         W32.HLLP.Bora.Mirc        File infector          03/27/00
  148.         W32.HLLP.Semisoft.G       File infector           03/13/00
  149.         W32.IIS.Worm              File infector           03/13/00
  150.         W32.Inrar.B               File infector          03/27/00
  151.         W32.Jane.Worm             File infector           03/06/00
  152.         W32.Lunatik.Worm          File infector           03/06/00
  153.         W32.Melting.Worm          File infector           03/13/00
  154.         W32.Nazka.Int             File infector           03/13/00
  155.         W32.Orochi.5420           File infector          03/27/00
  156.         W32.Orochi.5420 (mIRC)    File infector           03/17/00
  157.         W32.PrettyPark.E.Worm     File infector           03/06/00
  158.         W32.PrettyPark.F.Worm     File infector           03/06/00
  159.         W32.PrettyPark.G.Worm     File infector           03/06/00
  160.         W32.PrettyPark.Gen        File infector           03/13/00
  161.         W32.PrettyPark.H.Worm     File infector           03/13/00
  162.         W32.PrettyPark.I.Worm     File infector           03/13/00
  163.         W32.Refer.2939            File infector          03/27/00
  164.         W32.Spit.B                File infector          03/27/00
  165.         W32.Teddybear.Worm        File infector           03/13/00
  166.         W32.Unicle.A.Worm         File infector           03/06/00
  167.         W32.Unicle.B.Worm         File infector           03/06/00
  168.         W32.WinExt.B.Worm         File infector           03/13/00
  169.         W95.Arianne.1022          File infector           03/06/00
  170.         W95.Arianne.1022.Int      File infector           03/13/00
  171.         W95.Boza.2220.Int         File infector          03/27/00
  172.         W95.DoS.Trinoo            File infector           02/22/00
  173.         W95.Fosoforo.Int          File infector           03/06/00
  174.         W95.Invir                 File infector           03/13/00
  175.         W95.Matrix.3597           File infector          03/27/00
  176.         W95.Matrix.3597.TR        File infector          03/27/00
  177.         W95.Matrix.3597.TR (2)    File infector          03/27/00
  178.         W95.Merinos.1763          File infector           03/13/00
  179.         W95.Mmorf.1348            File infector           03/06/00
  180.         W95.Orez.6287             File infector           03/06/00
  181.         W95.Priest.1454           File infector          03/27/00
  182.         W95.Priest.1486           File infector          03/27/00
  183.         W95.Priest.1495           File infector          03/27/00
  184.         W95.Priest.1521           File infector           03/06/00
  185.         W95.Score.B               File infector           03/13/00
  186.         W95.Sexy.156              File infector           03/13/00
  187.         W95.Shoerec.9216          File infector           03/06/00
  188.         W95.Shoerec.9216.Tr       File infector           03/06/00
  189.         W95.SillyW.431            File infector           03/13/00
  190.         W95.SK (com)              File infector          03/27/00
  191.         W95.SK (com2)             File infector           03/13/00
  192.         W95.SK.380                File infector           03/13/00
  193.         W95.SK.428                File infector           03/13/00
  194.         W95.Tecata.1761           File infector          03/27/00
  195.         W95.VIP.4309.B            File infector          03/27/00
  196.         W95.Weird.C               File infector          03/27/00
  197.         W95.Weird.C.Backdoor      File infector          03/27/00
  198.         W95.Ylang.1536            File infector           03/13/00
  199.         W95.Ylang.1536.A          File infector          03/27/00
  200.         W95.Yurn.1652.Int         File infector           03/06/00
  201.         W97M.Bablas.G             File infector          03/27/00
  202.         W97M.Bablas.N             File infector          03/27/00
  203.         W97M.Bablas.Q             File infector           03/06/00
  204.         W97M.Bablas.R             File infector           03/06/00
  205.         W97M.Bablas.S             File infector           03/13/00
  206.         W97M.Cakes                File infector           02/29/00
  207.         W97M.Ciao.A               File infector          03/27/00
  208.         W97M.Class.EJ             File infector          03/27/00
  209.         W97M.Claudio              File infector           03/17/00
  210.         W97M.Eight941.E           File infector           02/29/00
  211.         W97M.FS.B.Ru              File infector           03/17/00
  212.         W97M.IJK                  File infector           03/17/00
  213.         W97M.Invkay               File infector           03/06/00
  214.         W97M.KAPSYAW              File infector          03/27/00
  215.         W97M.Killer               File infector           03/06/00
  216.         W97M.Lenni.A              File infector          03/27/00
  217.         W97M.Lupi.B               File infector           03/13/00
  218.         W97M.MARKER.BQ            File infector           03/13/00
  219.         W97M.MARKER.BV            File infector           03/13/00
  220.         W97M.Marker.BW            File infector          03/27/00
  221.         W97M.Marker.CH            File infector           02/29/00
  222.         W97M.Melissa.M.Var2       File infector           02/29/00
  223.         W97M.Michael.B            File infector           03/06/00
  224.         W97M.Nidoc                File infector           03/13/00
  225.         W97M.Ocard                File infector           02/29/00
  226.         W97M.Opey.P               File infector          03/27/00
  227.         W97M.SMAC.D               File infector           03/13/00
  228.         W97M.Stun                 File infector           03/17/00
  229.         W97M.Thus.N               File infector           02/29/00
  230.         W97M.Thus.O               File infector           03/13/00
  231.         W97M.Thus.Q               File infector          03/27/00
  232.         W97M.Titch                File infector           02/29/00
  233.         W97M.Titch.E              File infector          03/27/00
  234.         W97M.Verlor.E             File infector          03/27/00
  235.         W97M.Wrench.E             File infector          03/27/00
  236.         W98.Matyas.664            File infector           03/06/00
  237.         Win.Pada.2290             File infector           02/29/00
  238.         WM.Inexist.C              File infector           03/13/00
  239.         X97M.Automat.AE           File infector           03/17/00
  240.         X97M.Base.B               File infector           03/06/00
  241.         X97M.BMV                  File infector           03/13/00
  242.         X97M.DIVI.E               File infector           03/17/00
  243.         X97M.Manalo               File infector           03/06/00
  244.         X97M.Tegrat.A             File infector          03/27/00
  245.  
  246.  
  247. Name Changes:
  248.  
  249.         Old Virus Name            New Virus Name          Date changed
  250.         --------------            --------------          ------------
  251.         Bloodhound.Test        to Nutcracker.Ab2 (sys)    03/13/00
  252.         REU.1367               to Istanbul.1367           03/13/00
  253.         REU.1367 Gen ( 1 )     to Istanbul.1367 ( x )     03/13/00
  254.         W32.AOC.3650           to W32.AOC.3649            03/17/00
  255.         W95.Ylang.1536         to W95.Ylang.1536.B        03/17/00
  256.         W97M.Class.Ej          to W97M.Panther.Family     03/13/00
  257.         W97M.Marker.CE         to W97M.Marker.BY          03/13/00
  258.         W97M.Thus              to W97M.Thus.Variant       03/13/00
  259.         W97M.THUS.J            to W97M.THUS.M             03/13/00
  260.         W97M.Thus.L            to W97M.Thus.P             03/13/00
  261.         W97M.THUS.M            to W97M.THUS.J             03/13/00
  262.         W97M.Titch             to W97M.Titch.D            03/13/00
  263.         W97M.Wrench.A          to W97M.Wrench.C           03/13/00
  264.         X97M.Shan              to X97M.Jini.intd          03/13/00
  265.  
  266. Deletions:
  267.  
  268.         Virus Name                Infection Type          Date removed
  269.         ----------                --------------          ------------
  270.         Istanbul.1349             File infector           03/13/00
  271.         Virus-101 (Gen1)          File and Boot infector  02/29/00      
  272.         WuChing.Boot.Dropper      Boot infector           03/06/00
  273.  
  274. **********************************************************************
  275. **    Enabling Scanning Features                            **
  276. **********************************************************************
  277.  
  278. Several scanning features can be enabled through the use of an INF 
  279. configuration file.  For NAV for Windows 95/NT version 4.x and later, 
  280. or NAV for OS/2, this configuration file should be called NAVEX15.INF
  281. and should be placed in the directory where NAV is installed (i.e.,
  282. C:\Program Files\Norton AntiVirus).  For NAV for Netware version 4.x,
  283. the file should be called NAVEX15.INF and should be placed in the 
  284. directory where NAV 4.x is installed (i.e., sys:system\navnlm). For
  285. NAV for Windows 95/NT version 2.0, NAV 4.x for Windows 3.1/DOS,
  286. NAVIEG 1.x, or NAVFW 1.x, the file should be named NAVEX.INF and
  287. should be placed in the directory where NAV is installed (i.e., C:\NAV).
  288. If this configuration file does not exist, create one in the appropriate
  289. directory if you want to change the default settings.
  290.  
  291. To enable a scanning feature for a particular component, one or more 
  292. entries need to be added to the configuration file under the correct
  293. section.  For each platform there is a corresponding section that is used 
  294. in the INF file.  Below is a table of section names and platforms.
  295.  
  296. Section Name    Platform
  297. ------------    --------
  298. NAVW32          Windows 95/98/NT
  299. NAVAP           Windows 95/98/NT Auto-Protect
  300. NAVDX           DOS
  301. NAVNLM          Netware
  302. NAVWIN          Windows 3.1
  303. NAVOS2          OS/2
  304. NAVAIX          AIX
  305. NAVSOL          Solaris
  306.  
  307. Entries are case insensitive.  Below is a description of possible 
  308. entries.
  309.  
  310. 1. Files can be excluded from scans by the NAVEX engine.  To exclude a
  311. specific file from the NAVEX engine scan, add an entry with the full
  312. path and file name.  This is case insensitive.  No wildcards are allowed.
  313. To exclude multiple files, add a separate entry for each file.  To exclude
  314. a file, add an entry like the one below where <PATH> is the full path
  315. and file name.
  316.         ExcludeFile = <PATH>
  317.  
  318. 2. Files within a directory can be excluded from scans by the NAVEX engine.
  319. To exclude all files within a directory, add an entry with the full 
  320. directory path.  This is case insensitive.  No wildcards are allowed.  This
  321. does not exclude files located in subdirectories of the specified 
  322. directory.  To exclude multiple directories, add a separate entry for each
  323. directory. To exclude a directory, add an entry like the one below where
  324. <DIRECTORY> is the full path.
  325.         ExcludeDirectory = <DIRECTORY>
  326.  
  327. The following example of an INF configuration file excludes two files, 
  328. NOSCAN.EXE and BIGFILE.DOC, from NAVEX scans for the Windows 95/98/NT 
  329. scanner.  It excludes the D:\PRIVATE directory from Windows 95/98/NT 
  330. Auto-Protect.
  331.  
  332. [NAVW32]
  333. ExcludeFile = C:\PROGRAM FILES\NOSCAN.EXE
  334. ExcludeFile = C:\TEMP\BIGFILE.DOC
  335.  
  336. [NAVAP]
  337. ExcludeDirectory = D:\PRIVATE
  338.  
  339. **********************************************************************
  340. **    Additional Information                        **
  341. **********************************************************************
  342.  
  343. Additional information regarding this virus definitions update can be
  344. found in UPDATE.TXT and TECHNOTE.TXT.
  345.