home *** CD-ROM | disk | FTP | other *** search
- **********************************************************************
- ** **
- ** What's New in the NAV Virus Definitions Files WHATSNEW.TXT **
- ** **
- ** Symantec Security Response September 02, 2003 **
- ** **
- **********************************************************************
-
- This document contains the following topics:
-
- * Virus Alerts
- * New Technologies
- * Changes Incorporated Into This Update
- * Additional Information
-
-
- **********************************************************************
- ** Virus Alerts **
- **********************************************************************
-
- The ten most commonly reported viruses for July 2003, worldwide:
-
- 1 W32.Bugbear.B@mm
- 2 W32.Klez.H@mm
- 3 W32.Sobig.E@mm
- 4 HTML.Redlof.A
- 5 IRC Trojan
- 6 Trojan Horse
- 7 JS.Fortnight.C
- 8 W95.Hybris.Worm
- 9 JS.Exception.Exploit
- 10 Backdoor.Trojan
-
-
- **********************************************************************
- ** New Technologies **
- **********************************************************************
-
- DATE Technologies Added
- ---- ------------------
-
- 08/02/01 * Engine Update 08/02/01
- * All products that use the NAVEX 1.5 architecture
- (in other words, most major Symantec products released over
- the last 3 - 4 years) will receive the new functionality.
- * This enhanced technology provides improved script scanning
- as well as more proactive detection of unknown script-based
- threats.
-
-
- **********************************************************************
- ** Changes Incorporated Into This Virus Definitions Update **
- **********************************************************************
-
- DATE
- ----
-
- New virus definitions (sorted by Virus Name):
-
- Virus Name Infection Type Date added
- ---------- -------------- ---------
- AntiFort.1509 File infector 09/02/03
- AntiFort.1509 (1) File infector 09/02/03
- AntiWin.2305 File infector 09/02/03
- BAT.Disom.Worm File infector 09/02/03
- Backdoor.AntiLam.20.Q File infector 09/02/03
- Backdoor.Djump File infector 09/02/03
- Backdoor.IRC.Bobbins File infector 08/26/03
- Backdoor.IRC.Hatter File infector 08/28/03
- Backdoor.IRC.Lade File infector 08/26/03
- Backdoor.IRC.RPCBot.B File infector 08/25/03
- Backdoor.IRC.RPCBot.C File infector 08/29/03
- Backdoor.Nibu.B File infector 09/02/03
- Backdoor.Pspider.310.b File infector 09/02/03
- Backdoor.Ranck File infector 08/26/03
- Backdoor.Sheldor File infector 08/29/03
- Backdoor.Sokacaps File infector 09/02/03
- Backdoor.Urat.b File infector 08/27/03
- Backdoor.Wollf.16 File infector 08/27/03
- Bloodhound.IU.01 File infector 08/28/03
- Bloodhound.IU.02 File infector 08/28/03
- Bloodhound.IU.03 File infector 08/28/03
- EICAR Test String(new) File infector 08/28/03
- Face.1281 File infector 08/26/03
- Galle.782 File infector 08/26/03
- Glonp.3165 File infector 08/26/03
- Glonp.3165(1) File infector 08/26/03
- Gubbins.529 File infector 08/26/03
- Gubbins.529(1) File infector 08/26/03
- Gubbins.529(2) File infector 08/26/03
- Gubbins.529(3) File infector 08/26/03
- Hacktool.DCOMScan File infector 08/26/03
- Hamster.546 File infector 08/26/03
- Hamster.546(1) File infector 08/26/03
- Hcarry.850 File infector 08/26/03
- Heavy.761 File infector 08/28/03
- Heavy.761(1) File infector 08/28/03
- Heavy.761(2) File infector 08/28/03
- Heavy.761(3) File infector 08/28/03
- Heavy.761(4) File infector 08/28/03
- Heavy.761(5) File infector 08/28/03
- Hinder.380 File infector 08/28/03
- Hinder.380(1) File infector 08/28/03
- Ink.3200 File infector 08/26/03
- Lavi.792 File infector 08/26/03
- LoveHate.594 File infector 08/25/03
- LoveHate.595 File infector 08/25/03
- MBA.Remiform File infector 08/28/03
- PWSteal.Lemir.D File infector 08/25/03
- Parde.1144 File infector 08/25/03
- Parde.1307 File infector 08/25/03
- Ply.3769 File infector 08/25/03
- SMM.gen File infector 08/28/03
- SSR.19071 File infector 08/28/03
- Test.Pam32Req File infector 08/28/03
- Trivial.1388 File infector 08/28/03
- Trivial.1388(1) File infector 08/28/03
- Trivial.2400 File infector 08/28/03
- Trivial.2400(1) File infector 08/28/03
- Trivial.67.a File infector 08/26/03
- Trivial.67.a(1) File infector 08/26/03
- Trojan.Fwin File infector 09/02/03
- Trojan.Gaslide File infector 08/26/03
- UU_Worm.417 File infector 08/28/03
- UU_Worm.417 (2) File infector 08/28/03
- UU_Worm.417 (3) File infector 08/28/03
- UU_Worm.439 File infector 08/28/03
- UU_Worm.439 (2) File infector 08/28/03
- UU_Worm.439 (3) File infector 08/28/03
- UU_Worm.441 File infector 08/28/03
- UU_Worm.441 (2) File infector 08/28/03
- UU_Worm.441 (3) File infector 08/28/03
- VBS.Nugi File infector 09/02/03
- VBS.Omsee.gen File infector 08/26/03
- VBS.PPSweep.Worm File infector 08/26/03
- VS.1536 File infector 08/29/03
- VS.1726 File infector 08/29/03
- VS.1776 File infector 08/29/03
- W32.Bigfairy.A@mm File infector 09/02/03
- W32.Blaster.E.Worm File infector 08/29/03
- W32.Blaster.F.Worm File infector 09/02/03
- W32.Denit.Worm File infector 08/27/03
- W32.HLLW.Astef File infector 08/27/03
- W32.HLLW.Blaxe File infector 09/02/03
- W32.HLLW.Deborms.D File infector 08/28/03
- W32.HLLW.Lacon@mm File infector 08/29/03
- W32.HLLW.Lehs@mm File infector 09/02/03
- W32.HLLW.Raleka File infector 08/27/03
- W32.Hartco@mm File infector 08/29/03
- W32.Hopalong@mm File infector 08/26/03
- W32.Kwbot.P.Worm File infector 08/28/03
- W32.Mapson.D.Worm File infector 09/02/03
- W32.Nolor.B@mm File infector 08/26/03
- W32.Pandem.C.Worm File infector 09/02/03
- W32.Sobig.F.Dam File infector 08/26/03
- W32.Waxpow.Worm File infector 09/02/03
- W32.Yodo@mm File infector 09/02/03
- W97M.Nixta.Trojan File infector 08/29/03
- W97M.Omsee.B File infector 08/26/03
- W97M.Ragaga.A File infector 08/26/03
- X97M.Rippet File infector 09/02/03
-
- New virus definitions (sorted by Date added):
-
- Virus Name Infection Type Date added
- ---------- -------------- ----------
- AntiFort.1509 File infector 09/02/03
- AntiFort.1509 (1) File infector 09/02/03
- AntiWin.2305 File infector 09/02/03
- BAT.Disom.Worm File infector 09/02/03
- Backdoor.AntiLam.20.Q File infector 09/02/03
- Backdoor.Djump File infector 09/02/03
- Backdoor.Nibu.B File infector 09/02/03
- Backdoor.Pspider.310.b File infector 09/02/03
- Backdoor.Sokacaps File infector 09/02/03
- Trojan.Fwin File infector 09/02/03
- VBS.Nugi File infector 09/02/03
- W32.Bigfairy.A@mm File infector 09/02/03
- W32.Blaster.F.Worm File infector 09/02/03
- W32.HLLW.Blaxe File infector 09/02/03
- W32.HLLW.Lehs@mm File infector 09/02/03
- W32.Mapson.D.Worm File infector 09/02/03
- W32.Pandem.C.Worm File infector 09/02/03
- W32.Waxpow.Worm File infector 09/02/03
- W32.Yodo@mm File infector 09/02/03
- X97M.Rippet File infector 09/02/03
- Backdoor.IRC.RPCBot.C File infector 08/29/03
- Backdoor.Sheldor File infector 08/29/03
- VS.1536 File infector 08/29/03
- VS.1726 File infector 08/29/03
- VS.1776 File infector 08/29/03
- W32.Blaster.E.Worm File infector 08/29/03
- W32.HLLW.Lacon@mm File infector 08/29/03
- W32.Hartco@mm File infector 08/29/03
- W97M.Nixta.Trojan File infector 08/29/03
- Backdoor.IRC.Hatter File infector 08/28/03
- Bloodhound.IU.01 File infector 08/28/03
- Bloodhound.IU.02 File infector 08/28/03
- Bloodhound.IU.03 File infector 08/28/03
- EICAR Test String(new) File infector 08/28/03
- Heavy.761 File infector 08/28/03
- Heavy.761(1) File infector 08/28/03
- Heavy.761(2) File infector 08/28/03
- Heavy.761(3) File infector 08/28/03
- Heavy.761(4) File infector 08/28/03
- Heavy.761(5) File infector 08/28/03
- Hinder.380 File infector 08/28/03
- Hinder.380(1) File infector 08/28/03
- MBA.Remiform File infector 08/28/03
- SMM.gen File infector 08/28/03
- SSR.19071 File infector 08/28/03
- Test.Pam32Req File infector 08/28/03
- Trivial.1388 File infector 08/28/03
- Trivial.1388(1) File infector 08/28/03
- Trivial.2400 File infector 08/28/03
- Trivial.2400(1) File infector 08/28/03
- UU_Worm.417 File infector 08/28/03
- UU_Worm.417 (2) File infector 08/28/03
- UU_Worm.417 (3) File infector 08/28/03
- UU_Worm.439 File infector 08/28/03
- UU_Worm.439 (2) File infector 08/28/03
- UU_Worm.439 (3) File infector 08/28/03
- UU_Worm.441 File infector 08/28/03
- UU_Worm.441 (2) File infector 08/28/03
- UU_Worm.441 (3) File infector 08/28/03
- W32.HLLW.Deborms.D File infector 08/28/03
- W32.Kwbot.P.Worm File infector 08/28/03
- Backdoor.Urat.b File infector 08/27/03
- Backdoor.Wollf.16 File infector 08/27/03
- W32.Denit.Worm File infector 08/27/03
- W32.HLLW.Astef File infector 08/27/03
- W32.HLLW.Raleka File infector 08/27/03
- Backdoor.IRC.Bobbins File infector 08/26/03
- Backdoor.IRC.Lade File infector 08/26/03
- Backdoor.Ranck File infector 08/26/03
- Face.1281 File infector 08/26/03
- Galle.782 File infector 08/26/03
- Glonp.3165 File infector 08/26/03
- Glonp.3165(1) File infector 08/26/03
- Gubbins.529 File infector 08/26/03
- Gubbins.529(1) File infector 08/26/03
- Gubbins.529(2) File infector 08/26/03
- Gubbins.529(3) File infector 08/26/03
- Hacktool.DCOMScan File infector 08/26/03
- Hamster.546 File infector 08/26/03
- Hamster.546(1) File infector 08/26/03
- Hcarry.850 File infector 08/26/03
- Ink.3200 File infector 08/26/03
- Lavi.792 File infector 08/26/03
- Trivial.67.a File infector 08/26/03
- Trivial.67.a(1) File infector 08/26/03
- Trojan.Gaslide File infector 08/26/03
- VBS.Omsee.gen File infector 08/26/03
- VBS.PPSweep.Worm File infector 08/26/03
- W32.Hopalong@mm File infector 08/26/03
- W32.Nolor.B@mm File infector 08/26/03
- W32.Sobig.F.Dam File infector 08/26/03
- W97M.Omsee.B File infector 08/26/03
- W97M.Ragaga.A File infector 08/26/03
- Backdoor.IRC.RPCBot.B File infector 08/25/03
- LoveHate.594 File infector 08/25/03
- LoveHate.595 File infector 08/25/03
- PWSteal.Lemir.D File infector 08/25/03
- Parde.1144 File infector 08/25/03
- Parde.1307 File infector 08/25/03
- Ply.3769 File infector 08/25/03
-
- Name Changes (sorted by Old Virus Name):
-
- Old Virus Name New Virus Name Date changed
- -------------- -------------- ------------
- Backdoor.Clt to W32.Cult 08/18/03
- Backdoor.IRC.Lade to W32.Lade 08/26/03
- Backdoor.SubSeven.2.15 to Backdoor.SubSeven215 07/29/03
- Backdoor.VB.ff to Backdoor.Himba 08/29/03
- Bin.Auto.AWK to PS-MPC.335 08/18/03
- Bin.Auto.BBF to PS-MPC.729 08/04/03
- Boot.Face to Face (b) 07/31/03
- Face (b) to Boot.Face 08/04/03
- Hacktool.WDAV.Exploit to Hacktool.WDSat.Exploit 07/08/03
- MBA.Remiform to MpB.Kynel.A 08/28/03
- NOSTARDAMUS.1087 to Nostardamus.1087 07/23/03
- NOSTARDAMUS.2188 to Nostardamus.2188 07/23/03
- NOSTARDAMUS.2220 to Nostardamus.2220 07/23/03
- NOSTARDAMUS.2255 to Nostardamus.2255 07/23/03
- Nostardamus.1087 to NOSTARDAMUS.1087 07/24/03
- Nostardamus.2188 to NOSTARDAMUS.2188 07/24/03
- Nostardamus.2255 to NOSTARDAMUS.2255 07/24/03
- PS-MPC.335 to Bin.Auto.AWK 08/18/03
- PS-MPC.729 to Bin.Auto.BBF 08/04/03
- VBS.Quocus@mm to W32.HLLW.Egar 07/23/03
- VBS.Quocus@mm.int to VBS.Quocus.int 08/07/03
- VBS.Wimpey to VBS.Wimpey@mm 07/21/03
- W32.Akosw@mm to W32.Israz@mm 07/11/03
- W32.Anar.Worm to Win32.Anar.Worm 07/10/03
- W32.Babybear@mm.int to W32.Babybear.int 07/28/03
- W32.Cult to Backdoor.Clt 08/18/03
- W32.Darby.Worm to W32.HLLW.Darby 08/29/03
- W32.Fomur.B to W32.Fomur 08/25/03
- W32.HLLW.Aldem@mm to W32.Ronoper.B@mm 07/03/03
- W32.HLLW.Egar to W32.Egar.int 07/30/03
- W32.HLLW.Etaug@mm to VBS.Quocus@mm 07/18/03
- W32.HLLW.Kabak to W32.HLLW.Kabak.Int 08/18/03
- W32.HLLW.Kabak.Int to W32.HLLW.Kabak 08/08/03
- W32.HLLW.Malicou to W32.HLLW.Nulut 08/26/03
- W32.HLLW.Shydy.C to W32.HLLW.Shynet 08/28/03
- W32.HLLW.Shynet to W32.HLLW.Shydy.C 08/28/03
- W32.HLLW.Symten to W32.Symten@mm 07/18/03
- W32.HLLW.Yodo to W32.HLLW.Yodidoo 09/02/03
- W32.HLLW.Yodo.B to W32.HLLW.Yodi 09/02/03
- W32.Israz@mm to W32.Akosw@mm 07/24/03
- W32.Jantic.C@mm to W32.Jantic.F@mm 07/17/03
- W32.MutantQSix to W32.Sadon.867 07/10/03
- W32.Mutantq6 to W32.MutantQSix 07/09/03
- W32.Nuf.A to W32.Nuffy.A 08/08/03
- W32.Nuffy.A to W32.Nuf.A 08/18/03
- W32.Squirm@mm to W32.Pandem.B.Worm 08/21/03
- W32.Symten@mm to W32.HLLW.Symten@mm 07/21/03
- W32.Yaha.V@mm to W32.Yaha.Z@mm 07/10/03
- W32.Yaha.Z@mm to W32.Yaha.V@mm 07/10/03
- Win32.Anar.Worm to W32.Anar.Worm 07/10/03
-
- Name Changes (sorted by Date changed):
-
- Old Virus Name New Virus Name Date changed
- -------------- -------------- ------------
- W32.HLLW.Yodo to W32.HLLW.Yodidoo 09/02/03
- W32.HLLW.Yodo.B to W32.HLLW.Yodi 09/02/03
- Backdoor.VB.ff to Backdoor.Himba 08/29/03
- W32.Darby.Worm to W32.HLLW.Darby 08/29/03
- MBA.Remiform to MpB.Kynel.A 08/28/03
- W32.HLLW.Shydy.C to W32.HLLW.Shynet 08/28/03
- W32.HLLW.Shynet to W32.HLLW.Shydy.C 08/28/03
- Backdoor.IRC.Lade to W32.Lade 08/26/03
- W32.HLLW.Malicou to W32.HLLW.Nulut 08/26/03
- W32.Fomur.B to W32.Fomur 08/25/03
- W32.Squirm@mm to W32.Pandem.B.Worm 08/21/03
- Backdoor.Clt to W32.Cult 08/18/03
- Bin.Auto.AWK to PS-MPC.335 08/18/03
- PS-MPC.335 to Bin.Auto.AWK 08/18/03
- W32.Cult to Backdoor.Clt 08/18/03
- W32.HLLW.Kabak to W32.HLLW.Kabak.Int 08/18/03
- W32.Nuffy.A to W32.Nuf.A 08/18/03
- W32.HLLW.Kabak.Int to W32.HLLW.Kabak 08/08/03
- W32.Nuf.A to W32.Nuffy.A 08/08/03
- VBS.Quocus@mm.int to VBS.Quocus.int 08/07/03
- Bin.Auto.BBF to PS-MPC.729 08/04/03
- Face (b) to Boot.Face 08/04/03
- PS-MPC.729 to Bin.Auto.BBF 08/04/03
- Boot.Face to Face (b) 07/31/03
- W32.HLLW.Egar to W32.Egar.int 07/30/03
- Backdoor.SubSeven.2.15 to Backdoor.SubSeven215 07/29/03
- W32.Babybear@mm.int to W32.Babybear.int 07/28/03
- Nostardamus.1087 to NOSTARDAMUS.1087 07/24/03
- Nostardamus.2188 to NOSTARDAMUS.2188 07/24/03
- Nostardamus.2255 to NOSTARDAMUS.2255 07/24/03
- W32.Israz@mm to W32.Akosw@mm 07/24/03
- NOSTARDAMUS.1087 to Nostardamus.1087 07/23/03
- NOSTARDAMUS.2188 to Nostardamus.2188 07/23/03
- NOSTARDAMUS.2220 to Nostardamus.2220 07/23/03
- NOSTARDAMUS.2255 to Nostardamus.2255 07/23/03
- VBS.Quocus@mm to W32.HLLW.Egar 07/23/03
- VBS.Wimpey to VBS.Wimpey@mm 07/21/03
- W32.Symten@mm to W32.HLLW.Symten@mm 07/21/03
- W32.HLLW.Etaug@mm to VBS.Quocus@mm 07/18/03
- W32.HLLW.Symten to W32.Symten@mm 07/18/03
- W32.Jantic.C@mm to W32.Jantic.F@mm 07/17/03
- W32.Akosw@mm to W32.Israz@mm 07/11/03
- W32.Anar.Worm to Win32.Anar.Worm 07/10/03
- W32.MutantQSix to W32.Sadon.867 07/10/03
- W32.Yaha.V@mm to W32.Yaha.Z@mm 07/10/03
- W32.Yaha.Z@mm to W32.Yaha.V@mm 07/10/03
- Win32.Anar.Worm to W32.Anar.Worm 07/10/03
- W32.Mutantq6 to W32.MutantQSix 07/09/03
- Hacktool.WDAV.Exploit to Hacktool.WDSat.Exploit 07/08/03
- W32.HLLW.Aldem@mm to W32.Ronoper.B@mm 07/03/03
-
- Deletions (sorted by Virus Name):
-
- Virus Name Infection Type Date removed
- ---------- -------------- ------------
- Backdoor.IRC.Hatter File infector 08/28/03
- Bloodhound.IU.01 File infector 08/28/03
- Bloodhound.IU.02 File infector 08/28/03
- Bloodhound.IU.03 File infector 08/28/03
- EICAR Test String(new) File infector 08/28/03
- Heavy.761 File infector 08/28/03
- Heavy.761(1) File infector 08/28/03
- Heavy.761(2) File infector 08/28/03
- Heavy.761(3) File infector 08/28/03
- Heavy.761(4) File infector 08/28/03
- Heavy.761(5) File infector 08/28/03
- Hinder.380 File infector 08/28/03
- Hinder.380(1) File infector 08/28/03
- SMM.gen File infector 08/28/03
- SSR.19071 File infector 08/28/03
- Test.Pam32Req File infector 08/28/03
- Trivial.1388 File infector 08/28/03
- Trivial.1388(1) File infector 08/28/03
- Trivial.2400 File infector 08/28/03
- Trivial.2400(1) File infector 08/28/03
-
- Deletions (sorted by Date removed):
-
- Virus Name Infection Type Date removed
- ---------- -------------- ------------
- Backdoor.IRC.Hatter File infector 08/28/03
- Bloodhound.IU.01 File infector 08/28/03
- Bloodhound.IU.02 File infector 08/28/03
- Bloodhound.IU.03 File infector 08/28/03
- EICAR Test String(new) File infector 08/28/03
- Heavy.761 File infector 08/28/03
- Heavy.761(1) File infector 08/28/03
- Heavy.761(2) File infector 08/28/03
- Heavy.761(3) File infector 08/28/03
- Heavy.761(4) File infector 08/28/03
- Heavy.761(5) File infector 08/28/03
- Hinder.380 File infector 08/28/03
- Hinder.380(1) File infector 08/28/03
- SMM.gen File infector 08/28/03
- SSR.19071 File infector 08/28/03
- Test.Pam32Req File infector 08/28/03
- Trivial.1388 File infector 08/28/03
- Trivial.1388(1) File infector 08/28/03
- Trivial.2400 File infector 08/28/03
- Trivial.2400(1) File infector 08/28/03
-
-
- **********************************************************************
- ** Additional Information **
- **********************************************************************
- Additional information regarding this virus definitions update can be
- found in UPDATE.TXT and TECHNOTE.TXT.
-
-