home *** CD-ROM | disk | FTP | other *** search
- **********************************************************************
- ** **
- ** What's New in the NAV Virus Definitions Files WHATSNEW.TXT **
- ** **
- ** Symantec AntiVirus Research Center (SARC) July 12,2000 **
- ** **
- **********************************************************************
- This document contains the following topics:
-
- * Virus Alerts
- * New Technologies
- * Changes Incorporated Into This Update
- * Enabling Scanning Features
- * Additional Information
-
- **********************************************************************
- ** Virus Alerts **
- **********************************************************************
- VBS.LoveLetter, a new worm which has been wide-spread since May 4th,
- is detected by this definition set.
-
- The ten most commonly reported viruses, worldwide:
-
- 1 VBS.LoveLetter.A
- 2 WScript.KakWorm
- 3 VBS.Network
- 4 W95.CIH
- 5 Happy99.Worm
- 6 Worm.ExploreZip
- 7 W97M.ColdApe
- 8 W97M.Ethan
- 9 W97M.Melissa
- 10 WM.Cap
-
- **********************************************************************
- ** New Technologies **
- **********************************************************************
-
- DATE Technologies Added
- ---- ------------------
- 8/19/98 * Excel heuristics which detect and repair new and unknown
- macro viruses in Excel 95 & 97 documents.
-
- 9/16/98 * Added repair for encrypted Excel 97 documents.
-
- 10/21/98 * Heuristics to detect AOL Password Stealer Trojans.
- * WORD Heuristics improvement to increase detection rate.
-
- 12/17/98 * Macro Exclusion Engine to speed up the scanning for Word
- and Excel documents.
- * PowerPoint engine to scan PowerPoint related viruses.
- To enable this technology please read "Enabling/Disabling
- PowerPoint Scanning" section later in this document.
-
- 02/18/99 * Detection and repair of macro viruses in Word and Excel
- 2000 documents.
-
- 05/15/99 * Added repair for PowerPoint viruses.
- * Improved heuristics to detect more WORD 97 related
- viruses.
-
- 06/10/99 * Menu repair technology for WORD macro viruses that change
- command bar customizations in NORMAL.DOT.
-
- 07/12/99 * Added support for scanning of Ichitaro 8/9 documents.
- (Ichitaro is a Japanese word processing program).
-
- 08/19/99 * Added detection and repair for embedded documents inside
- PowerPoint 97.
-
- 11/22/99 * Added detection and repair for Trojans embedded in OLE
- files, such as Windows scrap files and MS Office
- documents.
- * Added detection for viruses which infect Microsoft
- Project documents (P98M.Corner.A, for example).
-
- 02/10/00 * Added support for scanning of UNIX executables.
- * Added detection for infected Visio documents.
-
- **********************************************************************
- ** Changes Incorporated Into This Virus Definitions Update **
- **********************************************************************
- New virus definitions:
-
- Virus Name Infection Type Week added
- ---------- -------------- ----------
- BAT.Rhapsody File infector 06/22/00
- BackOrifice2k.Cfg File infector 06/12/00
- Backdoor.Admire File infector 06/22/00
- Backdoor.DGS File infector 07/12/00
- Backdoor.DGSDrop File infector 07/12/00
- Backdoor.DU File infector 06/12/00
- Backdoor.Explorer32 File infector 06/22/00
- Backdoor.Fof File infector 06/12/00
- Backdoor.GateCrasher File infector 06/12/00
- Backdoor.ICQ.Syphillis File infector 06/12/00
- Backdoor.Millenium File infector 06/22/00
- Backdoor.NSSX File infector 06/29/00
- Backdoor.NetBus.svr File infector 06/12/00
- Backdoor.Netbus.cli File infector 06/29/00
- Backdoor.Netbus.drop File infector 06/12/00
- Backdoor.OneTime File infector 06/22/00
- Backdoor.Onliner File infector 06/12/00
- Backdoor.Rat.Client File infector 06/29/00
- Backdoor.Satan File infector 06/12/00
- Backdoor.Silence File infector 06/12/00
- Backdoor.WinMap File infector 06/22/00
- Backdoor.WinMapClient File infector 06/22/00
- Crash.Trojan File infector 06/22/00
- Dummr.Trojan File infector 07/12/00
- HLP.Dream File infector 06/12/00
- HTML.StartMe File infector 06/12/00
- ICQ.Trojan File infector 06/22/00
- INI.Aphex File infector 06/12/00
- IRC.SRVCP.Trojan File infector 06/29/00
- IRC.Trojan.Fabio File infector 06/22/00
- Ini.Scrambler File infector 06/12/00
- JS.Aphex File infector 06/12/00
- KillMe.1997 File infector 07/12/00
- KillMe.1997 (x) File infector 07/12/00
- KillMe.1997 (x1) File infector 07/12/00
- O97M.SweetestThing File infector 07/12/00
- PP97M.Scene File infector 07/12/00
- PWSteal.Winup File infector 06/12/00
- Serbian.Trojan File infector 06/12/00
- Shnaz.Trojan.A File infector 06/22/00
- Simpsons.Trojan File infector 06/22/00
- SubSeven.B File infector 07/12/00
- TD.1536.B File infector 06/12/00
- TD.1536.B (2) File infector 06/12/00
- Trojan.Nariz File infector 06/22/00
- Trojan.Smile File infector 06/22/00
- VBS.Aphex File infector 06/12/00
- VBS.Independence File infector 06/29/00
- VBS.Jer(htm) File infector 07/12/00
- VBS.Jer(htm) (2) File infector 07/12/00
- VBS.Jer(htm) (3) File infector 07/12/00
- VBS.Osterhase File infector 06/29/00
- VBS.Plan.A File infector 06/12/00
- VBS.Stages File infector 06/16/00
- VBS.Timofonica File infector 06/12/00
- VCL.Viral_Mess.(enc) File infector 07/12/00
- W32.Dilber.Worm File infector 07/12/00
- W32.Dream File infector 06/12/00
- W32.Gara.Dr File infector 07/12/00
- W32.HLLO.Job.22528 File infector 06/12/00
- W32.HLLP.Semisoft.H File infector 07/12/00
- W32.HLLP.Semisoft.I File infector 07/12/00
- W32.HLLW.Tress File infector 06/22/00
- W32.Henky.8888 File infector 06/29/00
- W32.Knight.2350 File infector 06/22/00
- W32.Mypics.B.Worm File infector 07/12/00
- W32.Mypics.Worm (zip) File infector 07/12/00
- W32.Mypics.Worm (zip2) File infector 07/12/00
- W32.NHKR.A.Worm File infector 07/12/00
- W32.NHKR.B.Worm File infector 07/12/00
- W32.Pokey.Worm File infector 06/22/00
- W32.RainSong.3925 File infector 06/29/00
- W32.Silver.B.Mirc File infector 06/12/00
- W32.TheSpy.A.Mirc File infector 06/12/00
- W32.TheSpy.B.Mirc File infector 06/12/00
- W32.Wolf.4096.A File infector 07/12/00
- W95.Alpha.842 File infector 06/29/00
- W95.FYS.1728.Int File infector 06/12/00
- W95.Hooy.8192 File infector 06/12/00
- W95.Hooy.8192.Dr File infector 06/12/00
- W95.I13.12288.B.Int File infector 07/12/00
- W95.Merinos.1849 File infector 07/12/00
- W95.NB.Worm File infector 06/12/00
- W95.Smash (SYS) File infector 06/22/00
- W95.Zomb.Gen File infector 07/12/00
- W95.Zperm.A File infector 06/22/00
- W95.Zperm.A.Dr File infector 07/12/00
- W95.Zperm.B File infector 06/22/00
- W95.Zperm.B.Dr File infector 07/12/00
- W97M.Aleja5.Remnants File infector 07/12/00
- W97M.Bablas.AD File infector 06/22/00
- W97M.Bablas.AE File infector 06/29/00
- W97M.Bablas.AF File infector 06/29/00
- W97M.Bablas.AG File infector 07/12/00
- W97M.Bablas.AH File infector 07/12/00
- W97M.Bablas.AI File infector 07/12/00
- W97M.Bablas.int File infector 06/29/00
- W97M.Barras File infector 07/12/00
- W97M.Beth.A File infector 06/12/00
- W97M.Bobo File infector 07/12/00
- W97M.Bobo.int File infector 06/22/00
- W97M.Contec.A File infector 07/12/00
- W97M.DIVI.I File infector 06/22/00
- W97M.Eight941.K File infector 06/22/00
- W97M.Goober.C File infector 06/29/00
- W97M.Homer File infector 06/12/00
- W97M.Marker.BO File infector 06/12/00
- W97M.Marker.BX File infector 06/22/00
- W97M.Marker.EF File infector 07/12/00
- W97M.Michael File infector 07/12/00
- W97M.NSI.B File infector 06/12/00
- W97M.Nova.E File infector 06/29/00
- W97M.Odious.C File infector 06/29/00
- W97M.Passbox.I File infector 06/22/00
- W97M.Relax File infector 06/29/00
- W97M.Service.B File infector 06/22/00
- W97M.Shepmah.B File infector 06/22/00
- W97M.Sherlock File infector 06/22/00
- W97M.Smaller.A File infector 06/12/00
- W97M.Stealth.A File infector 06/29/00
- W97M.Surround.Varian File infector 06/19/00
- W97M.Thus.AB File infector 07/12/00
- W97M.Thus.X File infector 06/22/00
- W97M.Thus.Y File infector 06/22/00
- W97M.Thus.Z File infector 07/12/00
- W97M.Tips.A File infector 07/12/00
- W97M.Trap File infector 06/29/00
- W97M.VMPCK1.AY File infector 07/12/00
- W97M.VMPCK1.BZ File infector 07/12/00
- W97M.VMPCK1.DI File infector 06/12/00
- W97M.VMPCK1.DK File infector 06/22/00
- W97M.VMPCK1.DL File infector 06/29/00
- Win.HLLP.Sector File infector 06/12/00
- Win.HLLP.Sector.Gen File infector 06/12/00
- Win.Pada.B.Int File infector 06/12/00
- Worms.Trojan.Intended File infector 06/12/00
- X97M.DIVI.J File infector 06/22/00
- X97M.DIVI.K File infector 06/22/00
- X97M.Divi.L File infector 07/12/00
- X97M.Hongo.B File infector 06/22/00
- X97M.Looksn.B File infector 07/12/00
- X97M.Manalo.I File infector 06/22/00
- X97M.Obvious.A File infector 06/29/00
- X97M.Toraja.C File infector 06/12/00
- XM.Laroux.TV File infector 06/29/00
- XM.SlimCow.A File infector 06/29/00
-
-
- Name Changes:
-
- Old Virus Name New Virus Name Date changed
- -------------- -------------- ------------
- W95.Fosforo.Int to W95.Fosforo 06/22/00
- W97M.Aquil to W97M.Heels.B 06/22/00
- W95.Rinim.431 to W95.Rinim.Gen 07/12/00
-
- Deletions:
-
- Virus Name Infection Type Date removed
- ---------- -------------- ------------
-
-
- **********************************************************************
- ** Enabling Scanning Features **
- **********************************************************************
-
- Several scanning features can be enabled through the use of an INF
- configuration file. For NAV for Windows 95/NT version 4.x and later,
- or NAV for OS/2, this configuration file should be called NAVEX15.INF
- and should be placed in the directory where NAV is installed (i.e.,
- C:\Program Files\Norton AntiVirus). For NAV for Netware version 4.x,
- the file should be called NAVEX15.INF and should be placed in the
- directory where NAV 4.x is installed (i.e., sys:system\navnlm). For
- NAV for Windows 95/NT version 2.0, NAV 4.x for Windows 3.1/DOS,
- NAVIEG 1.x, or NAVFW 1.x, the file should be named NAVEX.INF and
- should be placed in the directory where NAV is installed (i.e., C:\NAV).
- If this configuration file does not exist, create one in the appropriate
- directory if you want to change the default settings.
-
- To enable a scanning feature for a particular component, one or more
- entries need to be added to the configuration file under the correct
- section. For each platform there is a corresponding section that is used
- in the INF file. Below is a table of section names and platforms.
-
- Section Name Platform
- ------------ --------
- NAVW32 Windows 95/98/NT
- NAVAP Windows 95/98/NT Auto-Protect
- NAVDX DOS
- NAVNLM Netware
- NAVWIN Windows 3.1
- NAVOS2 OS/2
- NAVAIX AIX
- NAVSOL Solaris
-
- Entries are case insensitive. Below is a description of possible
- entries.
-
- 1. Files can be excluded from scans by the NAVEX engine. To exclude a
- specific file from the NAVEX engine scan, add an entry with the full
- path and file name. This is case insensitive. No wildcards are allowed.
- To exclude multiple files, add a separate entry for each file. To exclude
- a file, add an entry like the one below where <PATH> is the full path
- and file name.
- ExcludeFile = <PATH>
-
- 2. Files within a directory can be excluded from scans by the NAVEX engine.
- To exclude all files within a directory, add an entry with the full
- directory path. This is case insensitive. No wildcards are allowed. This
- does not exclude files located in subdirectories of the specified
- directory. To exclude multiple directories, add a separate entry for each
- directory. To exclude a directory, add an entry like the one below where
- <DIRECTORY> is the full path.
- ExcludeDirectory = <DIRECTORY>
-
- The following example of an INF configuration file excludes two files,
- NOSCAN.EXE and BIGFILE.DOC, from NAVEX scans for the Windows 95/98/NT
- scanner. It excludes the D:\PRIVATE directory from Windows 95/98/NT
- Auto-Protect.
-
- [NAVW32]
- ExcludeFile = C:\PROGRAM FILES\NOSCAN.EXE
- ExcludeFile = C:\TEMP\BIGFILE.DOC
-
- [NAVAP]
- ExcludeDirectory = D:\PRIVATE
-
- **********************************************************************
- ** Additional Information **
- **********************************************************************
-
- Additional information regarding this virus definitions update can be
- found in UPDATE.TXT and TECHNOTE.TXT.
-