home *** CD-ROM | disk | FTP | other *** search
- **********************************************************************
- ** **
- ** What's New in the NAV Virus Definitions Files WHATSNEW.TXT **
- ** **
- ** Symantec Security Response December 18, 2002 **
- ** **
- **********************************************************************
-
- This document contains the following topics:
-
- * Virus Alerts
- * New Technologies
- * Changes Incorporated Into This Update
- * Additional Information
-
-
- **********************************************************************
- ** Virus Alerts **
- **********************************************************************
-
- The ten most commonly reported viruses, worldwide:
-
- 1 W32.Bugbear@mm
- 2 W32.Klez.H@mm
- 3 W32.Opaserv.Worm
- 4 Trojan Horse
- 5 W95.Hybris.worm
- 6 W32.Datom.Worm
- 7 W95.Spaces.1445
- 8 W32.Klez.E@mm
- 9 W32.Yaha.F@mm
- 10 W95.CIH
-
-
- **********************************************************************
- ** New Technologies **
- **********************************************************************
-
- DATE Technologies Added
- ---- ------------------
-
- 08/02/01 * Engine Update 08/02/01
- * All products that use the NAVEX 1.5 architecture
- (in other words, most major Symantec products released over
- the last 3 - 4 years) will receive the new functionality.
- * This enhanced technology provides improved script scanning
- as well as more proactive detection of unknown script-based
- threats.
-
-
- **********************************************************************
- ** Changes Incorporated Into This Virus Definitions Update **
- **********************************************************************
-
- DATE
- ----
-
- New virus definitions (sorted by Virus Name):
-
- Virus Name Infection Type Date added
- ---------- -------------- ---------
- AA.716 File infector 12/18/02
- Aardwolf.448 File infector 12/18/02
- Alaper.b.ow File infector 12/16/02
- Backdoor.Backage File infector 12/17/02
- Backdoor.Hatckel File infector 12/05/02
- Backdoor.Hethat File infector 12/16/02
- Backdoor.Lanfiltrator File infector 12/11/02
- Backdoor.Lolok File infector 12/05/02
- Backdoor.Mapsy File infector 12/06/02
- Backdoor.Miranda File infector 12/09/02
- Backdoor.Remohak.16 File infector 12/17/02
- Backdoor.Revrs.Client File infector 12/13/02
- Backdoor.Skun File infector 12/05/02
- Backdoor.StealthEye File infector 12/05/02
- Backdoor.Theef.C File infector 12/09/02
- Backdoor.VB.CH File infector 12/11/02
- Backdoor.Vmz File infector 12/18/02
- Carbuncle.623 File infector 12/06/02
- DVT.294 File infector 12/06/02
- DVT.295 File infector 12/06/02
- Dutch_Tiny.245.int File infector 12/17/02
- Fanatik.1089 File infector 12/06/02
- Fanatik.2085 File infector 12/06/02
- Fanatik.2540 File infector 12/11/02
- HLLC.IOCOM.5371 File infector 12/11/02
- HLLC.Rider.6000.a File infector 12/11/02
- HLLC.Rider.6000.b File infector 12/11/02
- HLLO.Gala.7216 File infector 12/13/02
- HLLO.Gotov.5488 File infector 12/11/02
- HLLO.Yes.4864 File infector 12/13/02
- HLLO.Zero.6368 File infector 12/13/02
- Havji.492 File infector 12/18/02
- JS.Reven@mm File infector 12/09/02
- Kusys.1637 File infector 12/17/02
- Lexotran.int File infector 12/17/02
- Lucky.a.int File infector 12/17/02
- Nomad.1212 File infector 12/16/02
- Nomad.1293 File infector 12/16/02
- Nomad.884 File infector 12/16/02
- Nomad.962 File infector 12/16/02
- Odessa.664 File infector 12/18/02
- PHP.Invoc File infector 12/05/02
- PWSteal.Fender File infector 12/09/02
- Silly.81.ow File infector 12/17/02
- SillyC.192.b File infector 12/17/02
- SillyC.193.C File infector 12/17/02
- SillyC.240.e File infector 12/17/02
- SillyC.241.b File infector 12/17/02
- Tiny.412 File infector 12/10/02
- Trinidad.1104 File infector 12/05/02
- Trinidad.355 File infector 12/05/02
- Trivial.Worf File infector 12/10/02
- Trojan.Downloader.Cile File infector 12/13/02
- Trojan.Nuke.Readme File infector 12/05/02
- Trojan.PSW.LionDumper File infector 12/13/02
- Trojan.Poldo File infector 12/18/02
- Trojan.TEF File infector 12/05/02
- VBS.Pica@m File infector 12/10/02
- VBS.Pipped.Irc File infector 12/11/02
- VBS.Scape@mm File infector 12/11/02
- VBS.Snow@mm File infector 12/09/02
- W32.Achoo.2987 File infector 12/05/02
- W32.Appix.H.Worm File infector 12/17/02
- W32.Cicho File infector 12/11/02
- W32.HLLC.Nasus File infector 12/06/02
- W32.HLLC.Warray File infector 12/18/02
- W32.HLLW.Disager File infector 12/11/02
- W32.HLLW.Lioten File infector 12/17/02
- W32.HLLW.Shower File infector 12/05/02
- W32.Heovin@mm File infector 12/06/02
- W32.Holar.C@mm File infector 12/05/02
- W32.Lamin File infector 12/09/02
- W32.Notfam@mm File infector 12/09/02
- W32.Opaserv(win.ini) File infector 12/09/02
- W32.Titog.Worm File infector 12/17/02
- W32.Tulu File infector 12/16/02
- W32.Wahwah@mm File infector 12/05/02
- W32.Xilon.Trojan File infector 12/18/02
- W32.Yaha.H@mm File infector 12/16/02
- W32.Yaha.J@mm File infector 12/16/02
- W97M.Aida.B File infector 12/05/02
- W97M.HungrySys File infector 12/16/02
- W97M.Killhack.B File infector 12/16/02
- W97M.Maverick.int File infector 12/17/02
- W97M.Minimal.M.int File infector 12/05/02
- W97M.Oldguy.C.int File infector 12/05/02
- W97M.PGPSteal.Trojan File infector 12/05/02
- W97M.QWERTY File infector 12/16/02
- W97M.Quiet.int File infector 12/17/02
- W97M.Surlaw File infector 12/05/02
- W97M.Tulu File infector 12/16/02
- W97M.Ump.int File infector 12/05/02
- X97M.Delta.int File infector 12/05/02
- X97M.Feng.A.Trojan File infector 12/09/02
- X97M.Laroux.WM File infector 12/18/02
- X97M.Taign.int File infector 12/05/02
- Zorm.408(x) File infector 12/05/02
- Zorm.459 File infector 12/06/02
- Zorm.509 File infector 12/06/02
- Zorm.535 File infector 12/06/02
-
- New virus definitions (sorted by Date added):
-
- Virus Name Infection Type Date added
- ---------- -------------- ----------
- AA.716 File infector 12/18/02
- Aardwolf.448 File infector 12/18/02
- Backdoor.Vmz File infector 12/18/02
- Havji.492 File infector 12/18/02
- Odessa.664 File infector 12/18/02
- Trojan.Poldo File infector 12/18/02
- W32.HLLC.Warray File infector 12/18/02
- W32.Xilon.Trojan File infector 12/18/02
- X97M.Laroux.WM File infector 12/18/02
- Backdoor.Backage File infector 12/17/02
- Backdoor.Remohak.16 File infector 12/17/02
- Dutch_Tiny.245.int File infector 12/17/02
- Kusys.1637 File infector 12/17/02
- Lexotran.int File infector 12/17/02
- Lucky.a.int File infector 12/17/02
- Silly.81.ow File infector 12/17/02
- SillyC.192.b File infector 12/17/02
- SillyC.193.C File infector 12/17/02
- SillyC.240.e File infector 12/17/02
- SillyC.241.b File infector 12/17/02
- W32.Appix.H.Worm File infector 12/17/02
- W32.HLLW.Lioten File infector 12/17/02
- W32.Titog.Worm File infector 12/17/02
- W97M.Maverick.int File infector 12/17/02
- W97M.Quiet.int File infector 12/17/02
- Alaper.b.ow File infector 12/16/02
- Backdoor.Hethat File infector 12/16/02
- Nomad.1212 File infector 12/16/02
- Nomad.1293 File infector 12/16/02
- Nomad.884 File infector 12/16/02
- Nomad.962 File infector 12/16/02
- W32.Tulu File infector 12/16/02
- W32.Yaha.H@mm File infector 12/16/02
- W32.Yaha.J@mm File infector 12/16/02
- W97M.HungrySys File infector 12/16/02
- W97M.Killhack.B File infector 12/16/02
- W97M.QWERTY File infector 12/16/02
- W97M.Tulu File infector 12/16/02
- Backdoor.Revrs.Client File infector 12/13/02
- HLLO.Gala.7216 File infector 12/13/02
- HLLO.Yes.4864 File infector 12/13/02
- HLLO.Zero.6368 File infector 12/13/02
- Trojan.Downloader.Cile File infector 12/13/02
- Trojan.PSW.LionDumper File infector 12/13/02
- Backdoor.Lanfiltrator File infector 12/11/02
- Backdoor.VB.CH File infector 12/11/02
- Fanatik.2540 File infector 12/11/02
- HLLC.IOCOM.5371 File infector 12/11/02
- HLLC.Rider.6000.a File infector 12/11/02
- HLLC.Rider.6000.b File infector 12/11/02
- HLLO.Gotov.5488 File infector 12/11/02
- VBS.Pipped.Irc File infector 12/11/02
- VBS.Scape@mm File infector 12/11/02
- W32.Cicho File infector 12/11/02
- W32.HLLW.Disager File infector 12/11/02
- Tiny.412 File infector 12/10/02
- Trivial.Worf File infector 12/10/02
- VBS.Pica@m File infector 12/10/02
- Backdoor.Miranda File infector 12/09/02
- Backdoor.Theef.C File infector 12/09/02
- JS.Reven@mm File infector 12/09/02
- PWSteal.Fender File infector 12/09/02
- VBS.Snow@mm File infector 12/09/02
- W32.Lamin File infector 12/09/02
- W32.Notfam@mm File infector 12/09/02
- W32.Opaserv(win.ini) File infector 12/09/02
- X97M.Feng.A.Trojan File infector 12/09/02
- Backdoor.Mapsy File infector 12/06/02
- Carbuncle.623 File infector 12/06/02
- DVT.294 File infector 12/06/02
- DVT.295 File infector 12/06/02
- Fanatik.1089 File infector 12/06/02
- Fanatik.2085 File infector 12/06/02
- W32.HLLC.Nasus File infector 12/06/02
- W32.Heovin@mm File infector 12/06/02
- Zorm.459 File infector 12/06/02
- Zorm.509 File infector 12/06/02
- Zorm.535 File infector 12/06/02
- Backdoor.Hatckel File infector 12/05/02
- Backdoor.Lolok File infector 12/05/02
- Backdoor.Skun File infector 12/05/02
- Backdoor.StealthEye File infector 12/05/02
- PHP.Invoc File infector 12/05/02
- Trinidad.1104 File infector 12/05/02
- Trinidad.355 File infector 12/05/02
- Trojan.Nuke.Readme File infector 12/05/02
- Trojan.TEF File infector 12/05/02
- W32.Achoo.2987 File infector 12/05/02
- W32.HLLW.Shower File infector 12/05/02
- W32.Holar.C@mm File infector 12/05/02
- W32.Wahwah@mm File infector 12/05/02
- W97M.Aida.B File infector 12/05/02
- W97M.Minimal.M.int File infector 12/05/02
- W97M.Oldguy.C.int File infector 12/05/02
- W97M.PGPSteal.Trojan File infector 12/05/02
- W97M.Surlaw File infector 12/05/02
- W97M.Ump.int File infector 12/05/02
- X97M.Delta.int File infector 12/05/02
- X97M.Taign.int File infector 12/05/02
- Zorm.408(x) File infector 12/05/02
-
- Name Changes (sorted by Old Virus Name):
-
- Old Virus Name New Virus Name Date changed
- -------------- -------------- ------------
- BAT.Junkboat@mm to W32.Enerlam.2774 12/05/02
- Backdoor.Dumba to Trojan.Dumba 09/23/02
- Backdoor.Floodnet to Backdoor.Endool 11/13/02
- Bin.Auto.AZL to PS-MPC.535.B 09/13/02
- Cruiser.1120 to Cruiser.1120.Int 11/26/02
- Dik.1393 to Dik.1393.Int 11/26/02
- HLLC.HappyFlowers to W32.HLLC.Happylow 09/11/02
- IRC.Pelic.Worm to VBS.Pelic.Worm 10/02/02
- Lonig.INT to Lonig.Kit 11/26/02
- Syst.1665 to AOD.385.B 10/28/02
- TAVC.Jazva to Jazva.686 11/26/02
- Trojan.Imiserv to Backdoor.Imiserv 09/19/02
- Trojan.PWS.QQPass.gKb6 to Trojan.PWS.QQPass.C 10/18/02
- VBS.Likun@mm to VBS.Likun 11/05/02
- VBS.Pica@m to VBS.Pica@mm 12/11/02
- VBS.Thambl to VBS.Lavra.B.Worm 09/12/02
- W32.Alcarys.H to W32.HLLP.Flate 09/11/02
- W32.Alcatap.Worm to W32.Hobble.F@mm 11/08/02
- W32.Alpoor.6144 to W32.HLLP.Alpoor 09/20/02
- W32.Appix.H.Worm to Backdoor.OptixPro.10.b 12/18/02
- W32.Efno.Worm to W32.HLLW.Efno 09/16/02
- W32.Fanta.B.Worm to Fanta.Trojan.Dr 11/06/02
- W32.Fanta.worm to Fanta.Trojan 11/06/02
- W32.Gezak to W32.Prodvin 11/06/02
- W32.HLLO.Mario to W32.HLLO.Marion 11/08/02
- W32.HLLO.Samand to W32.HLLC.Samand 10/10/02
- W32.HLLP.Alpoor to W32.HLLP.Flate.C 09/25/02
- W32.HLLW.Smilex to W32.Stupid.D 11/08/02
- W32.Holar.C@mm to W32.Galil@mm 12/05/02
- W32.Jonbarr.B@mm to W32.Jonbarr.C@mm 11/12/02
- W32.Manex.Worm to W32.HLLW.Manex 11/12/02
- W32.Protex.Worm to W32.Duksten.B@mm 10/24/02
- W32.Seesix.Worm to W32.HLLP.VB.14336.C 11/04/02
- W32.Topsec.Worm to W32.Topsec 10/14/02
- W32.Tossed@mm to HLLW.Tossed@mm 11/06/02
- W32.Walcomp to W32.HLLC.Happylow 09/13/02
- W32.Wun.Irc to W32.Wuno.Irc 11/08/02
- W95.CIH.1094 to W95.CIH.1106 11/20/02
- W95.Sleepyhead to W95.Sleepyhead.5632 10/22/02
- W97M.QWERTY to W97M.WERTY 12/17/02
- W97M.Swatch to W97M.Spwatch 12/04/02
- W97M.Thus.bi to W97M.Thus.BI 11/19/02
-
- Name Changes (sorted by Date changed):
-
- Old Virus Name New Virus Name Date changed
- -------------- -------------- ------------
- W32.Appix.H.Worm to Backdoor.OptixPro.10.b 12/18/02
- W97M.QWERTY to W97M.WERTY 12/17/02
- VBS.Pica@m to VBS.Pica@mm 12/11/02
- BAT.Junkboat@mm to W32.Enerlam.2774 12/05/02
- W32.Holar.C@mm to W32.Galil@mm 12/05/02
- W97M.Swatch to W97M.Spwatch 12/04/02
- Cruiser.1120 to Cruiser.1120.Int 11/26/02
- Dik.1393 to Dik.1393.Int 11/26/02
- Lonig.INT to Lonig.Kit 11/26/02
- TAVC.Jazva to Jazva.686 11/26/02
- W95.CIH.1094 to W95.CIH.1106 11/20/02
- W97M.Thus.bi to W97M.Thus.BI 11/19/02
- Backdoor.Floodnet to Backdoor.Endool 11/13/02
- W32.Jonbarr.B@mm to W32.Jonbarr.C@mm 11/12/02
- W32.Manex.Worm to W32.HLLW.Manex 11/12/02
- W32.Alcatap.Worm to W32.Hobble.F@mm 11/08/02
- W32.HLLO.Mario to W32.HLLO.Marion 11/08/02
- W32.HLLW.Smilex to W32.Stupid.D 11/08/02
- W32.Wun.Irc to W32.Wuno.Irc 11/08/02
- W32.Fanta.B.Worm to Fanta.Trojan.Dr 11/06/02
- W32.Fanta.worm to Fanta.Trojan 11/06/02
- W32.Gezak to W32.Prodvin 11/06/02
- W32.Tossed@mm to HLLW.Tossed@mm 11/06/02
- VBS.Likun@mm to VBS.Likun 11/05/02
- W32.Seesix.Worm to W32.HLLP.VB.14336.C 11/04/02
- Syst.1665 to AOD.385.B 10/28/02
- W32.Protex.Worm to W32.Duksten.B@mm 10/24/02
- W95.Sleepyhead to W95.Sleepyhead.5632 10/22/02
- Trojan.PWS.QQPass.gKb6 to Trojan.PWS.QQPass.C 10/18/02
- W32.Topsec.Worm to W32.Topsec 10/14/02
- W32.HLLO.Samand to W32.HLLC.Samand 10/10/02
- IRC.Pelic.Worm to VBS.Pelic.Worm 10/02/02
- W32.HLLP.Alpoor to W32.HLLP.Flate.C 09/25/02
- Backdoor.Dumba to Trojan.Dumba 09/23/02
- W32.Alpoor.6144 to W32.HLLP.Alpoor 09/20/02
- Trojan.Imiserv to Backdoor.Imiserv 09/19/02
- W32.Efno.Worm to W32.HLLW.Efno 09/16/02
- Bin.Auto.AZL to PS-MPC.535.B 09/13/02
- W32.Walcomp to W32.HLLC.Happylow 09/13/02
- VBS.Thambl to VBS.Lavra.B.Worm 09/12/02
- HLLC.HappyFlowers to W32.HLLC.Happylow 09/11/02
- W32.Alcarys.H to W32.HLLP.Flate 09/11/02
-
- Deletions (sorted by Virus Name):
-
- Virus Name Infection Type Date removed
- ---------- -------------- ------------
- BAT911.Worm File infector 11/05/02
- Bin.Auto.CAQ File infector 12/04/02
- HLLO.Gotov.5488 File infector 12/11/02
- JS.WindowBomb File infector 09/26/02
- VBS.Breberka@mm File infector 10/29/02
- VBS.Draft@mm File infector 10/29/02
- VBS.Futonik@mm File infector 10/29/02
- W32.Compo File infector 10/21/02
- W32.HLLC.Happylow File infector 09/13/02
- W32.Hotlix.Worm File infector 11/12/02
- W32.Wahwah@mm File infector 12/09/02
- W97M.Pane File infector 10/11/02
-
- Deletions (sorted by Date removed):
-
- Virus Name Infection Type Date removed
- ---------- -------------- ------------
- HLLO.Gotov.5488 File infector 12/11/02
- W32.Wahwah@mm File infector 12/09/02
- Bin.Auto.CAQ File infector 12/04/02
- W32.Hotlix.Worm File infector 11/12/02
- BAT911.Worm File infector 11/05/02
- VBS.Breberka@mm File infector 10/29/02
- VBS.Draft@mm File infector 10/29/02
- VBS.Futonik@mm File infector 10/29/02
- W32.Compo File infector 10/21/02
- W97M.Pane File infector 10/11/02
- JS.WindowBomb File infector 09/26/02
- W32.HLLC.Happylow File infector 09/13/02
-
-
- **********************************************************************
- ** Additional Information **
- **********************************************************************
- Additional information regarding this virus definitions update can be
- found in UPDATE.TXT and TECHNOTE.TXT.
-
-