********************************************************************** ** ** ** What's New in the NAV Virus Definitions Files WHATSNEW.TXT ** ** ** ** Symantec Security Response March 11, 2004 ** ** ** ********************************************************************** This document contains the following topics: * Virus Alerts * New Technologies * Changes Incorporated Into This Update * Additional Information ********************************************************************** ** Virus Alerts ** ********************************************************************** The ten most commonly reported viruses for February 2004, worldwide: 1 Trojan Horse 2 W32.Mydoom.A@mm 3 W32.Netsky.B@mm 4 W32.HLLW.Gaobot.gen 5 W32.Bugbear.B@mm 6 Downloader.MSCache 7 W32.Dumaru.Y@mm 8 Trojan.ByteVerify 9 Download.Trojan 10 IRC Trojan ********************************************************************** ** New Technologies ** ********************************************************************** DATE Technologies Added ---- ------------------ 08/02/01 * Engine Update 08/02/01 * All products that use the NAVEX 1.5 architecture (in other words, most major Symantec products released over the last 3 - 4 years) will receive the new functionality. * This enhanced technology provides improved script scanning as well as more proactive detection of unknown script-based threats. ********************************************************************** ** Changes Incorporated Into This Virus Definitions Update ** ********************************************************************** DATE ---- New virus definitions (sorted by Virus Name): Virus Name Infection Type Date added ---------- -------------- --------- Adware.Annoyance File infector 03/11/04 Adware.FindemNow File infector 02/29/04 Adware.Iefeats File infector 03/05/04 Adware.LSPP File infector 03/08/04 Adware.NetOptimize.B File infector 02/23/04 Adware.Raxums File infector 02/23/04 Adware.Tickerbar File infector 02/28/04 Backdoor.Blarul File infector 02/23/04 Backdoor.IRC.Aladinz.L File infector 02/23/04 Backdoor.IRC.Aladinz.M File infector 02/25/04 Backdoor.IRC.Loonbot File infector 02/26/04 Backdoor.Kaitex.E File infector 02/23/04 Backdoor.Lyshell File infector 02/28/04 Backdoor.Ratal File infector 02/25/04 Bloodhound.Exploit.7 File infector 02/25/04 DDoS.Trojan File infector 02/24/04 Dialer.Greencard File infector 03/09/04 Dialer.Juicyteen File infector 02/28/04 Dialer.PornPaq.B File infector 02/23/04 Dialer.Switchdialer.B File infector 03/08/04 Downloader.Botten File infector 02/23/04 Downloader.Qbot File infector 03/10/04 Hacktool.DBomb File infector 02/26/04 Hacktool.Misoska File infector 02/26/04 Hacktool.Misoska.B File infector 02/27/04 Java.StartPage File infector 02/23/04 PWSteal.Bancos.E File infector 02/26/04 PWSteal.Banpaes.C File infector 03/05/04 PWSteal.Tarno.B File infector 02/26/04 SecurityRisk.KeyFilter File infector 02/23/04 Spyware.Apropos File infector 03/08/04 Spyware.SpyBuddy File infector 03/08/04 Trojan.Bookmarker.F File infector 02/29/04 Trojan.Gipma File infector 03/10/04 Trojan.Ibiza File infector 02/27/04 Trojan.Reur.B File infector 03/08/04 Trojan.Simcss.B File infector 03/10/04 Trojan.Tilser File infector 02/27/04 Trojan.Vavico File infector 03/08/04 VBS.Delete.Trojan.B File infector 03/08/04 VBS.Guatam File infector 03/09/04 VBS.Herpie File infector 03/09/04 W32.Baygar File infector 03/11/04 W32.Beagle.C@mm File infector 02/27/04 W32.Beagle.E@mm File infector 02/28/04 W32.Beagle.F@mm File infector 02/29/04 W32.Beagle.F@mm tr File infector 03/02/04 W32.Beagle.G@mm File infector 02/29/04 W32.Beagle.H@mm File infector 03/01/04 W32.Beagle.I@mm File infector 03/02/04 W32.Beagle.J@mm File infector 03/02/04 W32.Beagle.K@mm File infector 03/03/04 W32.Bizex.Worm File infector 02/24/04 W32.Cone.B@mm File infector 02/29/04 W32.Cone.C@mm File infector 03/09/04 W32.Cone.D@mm File infector 03/10/04 W32.Cone@mm File infector 02/23/04 W32.Dedler.Worm File infector 03/09/04 W32.Dref@mm File infector 02/25/04 W32.Gobi File infector 03/11/04 W32.HLLO.Vogad File infector 03/10/04 W32.HLLW.Cult.P@mm File infector 02/29/04 W32.HLLW.Evianc File infector 02/28/04 W32.HLLW.Heycheck File infector 03/08/04 W32.HLLW.Moega.AP File infector 02/28/04 W32.HLLW.Reur.B File infector 03/08/04 W32.HLLW.Smeagol File infector 03/09/04 W32.HLLW.Syney@mm.int File infector 02/24/04 W32.HLLW.Vizzy File infector 03/10/04 W32.Haltura@mm File infector 03/10/04 W32.Hiton@mm File infector 03/02/04 W32.Keco@mm File infector 03/08/04 W32.Longbe@mm File infector 03/10/04 W32.Maddis File infector 02/28/04 W32.Mercur@mm File infector 03/10/04 W32.Mockbot.A.Worm File infector 02/25/04 W32.Myant.Worm File infector 02/29/04 W32.Mydoom.G@mm File infector 03/02/04 W32.Mydoom.H@mm File infector 03/03/04 W32.Netsky.C@mm File infector 02/24/04 W32.Netsky.D@mm File infector 03/01/04 W32.Netsky.E@mm File infector 03/01/04 W32.Netsky.F@mm File infector 03/03/04 W32.Netsky.G@mm File infector 03/05/04 W32.Netsky.H@mm File infector 03/05/04 W32.Netsky.I@mm File infector 03/08/04 W32.Netsky.J@mm File infector 03/08/04 W32.Netsky.K@mm File infector 03/08/04 W32.Netsky.L@mm File infector 03/09/04 W32.Netsky.M@mm File infector 03/10/04 W32.Netsky.dam File infector 02/25/04 W32.Relayer.Worm File infector 03/09/04 W32.Sober.D@mm File infector 03/08/04 W32.Sober.D@mm!zip File infector 03/09/04 W32.Wenru@mm File infector 03/10/04 W32.Wormic File infector 03/09/04 W97M.Lashko.A File infector 03/01/04 W97M.Sxe.C File infector 03/03/04 W97M.Trug.B File infector 03/09/04 X97M.Kbase File infector 03/03/04 New virus definitions (sorted by Date added): Virus Name Infection Type Date added ---------- -------------- ---------- Adware.Annoyance File infector 03/11/04 W32.Baygar File infector 03/11/04 W32.Gobi File infector 03/11/04 Downloader.Qbot File infector 03/10/04 Trojan.Gipma File infector 03/10/04 Trojan.Simcss.B File infector 03/10/04 W32.Cone.D@mm File infector 03/10/04 W32.HLLO.Vogad File infector 03/10/04 W32.HLLW.Vizzy File infector 03/10/04 W32.Haltura@mm File infector 03/10/04 W32.Longbe@mm File infector 03/10/04 W32.Mercur@mm File infector 03/10/04 W32.Netsky.M@mm File infector 03/10/04 W32.Wenru@mm File infector 03/10/04 Dialer.Greencard File infector 03/09/04 VBS.Guatam File infector 03/09/04 VBS.Herpie File infector 03/09/04 W32.Cone.C@mm File infector 03/09/04 W32.Dedler.Worm File infector 03/09/04 W32.HLLW.Smeagol File infector 03/09/04 W32.Netsky.L@mm File infector 03/09/04 W32.Relayer.Worm File infector 03/09/04 W32.Sober.D@mm!zip File infector 03/09/04 W32.Wormic File infector 03/09/04 W97M.Trug.B File infector 03/09/04 Adware.LSPP File infector 03/08/04 Dialer.Switchdialer.B File infector 03/08/04 Spyware.Apropos File infector 03/08/04 Spyware.SpyBuddy File infector 03/08/04 Trojan.Reur.B File infector 03/08/04 Trojan.Vavico File infector 03/08/04 VBS.Delete.Trojan.B File infector 03/08/04 W32.HLLW.Heycheck File infector 03/08/04 W32.HLLW.Reur.B File infector 03/08/04 W32.Keco@mm File infector 03/08/04 W32.Netsky.I@mm File infector 03/08/04 W32.Netsky.J@mm File infector 03/08/04 W32.Netsky.K@mm File infector 03/08/04 W32.Sober.D@mm File infector 03/08/04 Adware.Iefeats File infector 03/05/04 PWSteal.Banpaes.C File infector 03/05/04 W32.Netsky.G@mm File infector 03/05/04 W32.Netsky.H@mm File infector 03/05/04 W32.Beagle.K@mm File infector 03/03/04 W32.Mydoom.H@mm File infector 03/03/04 W32.Netsky.F@mm File infector 03/03/04 W97M.Sxe.C File infector 03/03/04 X97M.Kbase File infector 03/03/04 W32.Beagle.F@mm tr File infector 03/02/04 W32.Beagle.I@mm File infector 03/02/04 W32.Beagle.J@mm File infector 03/02/04 W32.Hiton@mm File infector 03/02/04 W32.Mydoom.G@mm File infector 03/02/04 W32.Beagle.H@mm File infector 03/01/04 W32.Netsky.D@mm File infector 03/01/04 W32.Netsky.E@mm File infector 03/01/04 W97M.Lashko.A File infector 03/01/04 Adware.FindemNow File infector 02/29/04 Trojan.Bookmarker.F File infector 02/29/04 W32.Beagle.F@mm File infector 02/29/04 W32.Beagle.G@mm File infector 02/29/04 W32.Cone.B@mm File infector 02/29/04 W32.HLLW.Cult.P@mm File infector 02/29/04 W32.Myant.Worm File infector 02/29/04 Adware.Tickerbar File infector 02/28/04 Backdoor.Lyshell File infector 02/28/04 Dialer.Juicyteen File infector 02/28/04 W32.Beagle.E@mm File infector 02/28/04 W32.HLLW.Evianc File infector 02/28/04 W32.HLLW.Moega.AP File infector 02/28/04 W32.Maddis File infector 02/28/04 Hacktool.Misoska.B File infector 02/27/04 Trojan.Ibiza File infector 02/27/04 Trojan.Tilser File infector 02/27/04 W32.Beagle.C@mm File infector 02/27/04 Backdoor.IRC.Loonbot File infector 02/26/04 Hacktool.DBomb File infector 02/26/04 Hacktool.Misoska File infector 02/26/04 PWSteal.Bancos.E File infector 02/26/04 PWSteal.Tarno.B File infector 02/26/04 Backdoor.IRC.Aladinz.M File infector 02/25/04 Backdoor.Ratal File infector 02/25/04 Bloodhound.Exploit.7 File infector 02/25/04 W32.Dref@mm File infector 02/25/04 W32.Mockbot.A.Worm File infector 02/25/04 W32.Netsky.dam File infector 02/25/04 DDoS.Trojan File infector 02/24/04 W32.Bizex.Worm File infector 02/24/04 W32.HLLW.Syney@mm.int File infector 02/24/04 W32.Netsky.C@mm File infector 02/24/04 Adware.NetOptimize.B File infector 02/23/04 Adware.Raxums File infector 02/23/04 Backdoor.Blarul File infector 02/23/04 Backdoor.IRC.Aladinz.L File infector 02/23/04 Backdoor.Kaitex.E File infector 02/23/04 Dialer.PornPaq.B File infector 02/23/04 Downloader.Botten File infector 02/23/04 Java.StartPage File infector 02/23/04 SecurityRisk.KeyFilter File infector 02/23/04 W32.Cone@mm File infector 02/23/04 Name Changes (sorted by Old Virus Name): Old Virus Name New Virus Name Date changed -------------- -------------- ------------ Backdoor.Fxdoor to Tcl.Sendrak 01/18/04 Backdoor.Hazzer to Trojan.Hazzer 12/18/03 Backdoor.Lolok.B to W97M.Tebit 01/22/04 Backdoor.NetTrash to W32.HLLW.Nettrash 01/14/04 HTML.Bother.3180 to VBS.Bother.3180 02/13/04 HTML.Bother.3180.dr to VBS.Bother.3180.dr 02/13/04 HTML.Davinia.B.dam to VBS.Davinia.B.dam 02/13/04 HTML.Davinia.dam to VBS.Davinia.dam 02/13/04 HTML.Enel.3787 to VBS.Enel.3787 02/13/04 HTML.Enel.3787 (2) to VBS.Enel.3787 (2) 02/13/04 HTML.NoWarn.1921 to VBS.NoWarn.1921 02/13/04 HTML.NoWarn.1921 (2) to VBS.NoWarn.1921 (2) 02/13/04 HTML.Offline.1152 to VBS.Offline.1152 02/13/04 HTML.Panamas to VBS.Panamas 02/13/04 HTML.Prepend to VBS.Prepend 02/13/04 HTML.Prepender to VBS.Prepender 02/13/04 HTML.Pswform.trojan to VBS.Pswform.trojan 02/13/04 HTML.Reality to VBS.Reality 02/13/04 HTML.Reality.B to VBS.Reality.B 02/13/04 HTML.Reality.D to VBS.Reality.D 02/13/04 HTML.Redir.1152 to VBS.Redir.1152 02/13/04 HTML.Redlof.A to VBS.Redlof.A 02/13/04 HTML.Rumbile to VBS.Rumbile 02/13/04 HTML.StartMe to JS.StartMe 02/13/04 HTML.Tipsy.1969 to JS.Tipsy.1969 02/13/04 Hacktool.X-Scan to Hacktool.XScan 01/19/04 MHTML.Redir.Exploit to MHTMLRedir.Exploit 12/12/03 PWSteal.Leox to W32.HLLW.Leox 01/19/04 PWSteal.RTCW to Backdoor.NetTrash 01/13/04 Trojan.Conspy to Adware.Conspy 02/11/04 Trojan.Dalfer to Joke.Apeldorn 01/12/04 Trojan.Dalfer.B to Adware.Smartsearch 01/12/04 Trojan.Dalfer.C to W32.Spybot.WI 01/18/04 Trojan.Dalfer.C to W97M.Twopey.E 01/15/04 Trojan.Narat to Adware.Mpgcom 01/05/04 VBS.Nohat@mm@int to VBS.Nohat@mm.int 02/11/04 W32.Alua@mm to W32.Beagle.B@mm 02/17/04 W32.Beagle.F@mm tr to W32.Beagle.F@mm(zip) 03/03/04 W32.Beagle.F@mm(zip) to W32.Beagle@mm!zip 03/03/04 W32.Gase to W32.Gase.intd 12/30/03 W32.HLLW.Gaobot.EZ to W32.HLLW.Gaobot.FB 01/05/04 W32.HLLW.Rolog to W32.Letin 02/05/04 W32.Mertian@mm to W32.Mertian.Worm 12/15/03 W32.Mimail.R@mm to W32.Mimail.S@mm 01/29/04 W32.Novarg.A@mm to W32.Mydoom.A@mm 02/04/04 W32.Rusty@mm to W32.Rusty@m 02/16/04 W32.Yenik.A.Worm to W32.Yenik.A@mm 02/10/04 W97M.Chameleon.B to W97M.Chameleon.I 02/12/04 W97M.Gedza to O97M.Gedza 01/22/04 X97M.Gedza to VBS.Vaper@mm 01/22/04 Name Changes (sorted by Date changed): Old Virus Name New Virus Name Date changed -------------- -------------- ------------ W32.Beagle.F@mm tr to W32.Beagle.F@mm(zip) 03/03/04 W32.Beagle.F@mm(zip) to W32.Beagle@mm!zip 03/03/04 W32.Alua@mm to W32.Beagle.B@mm 02/17/04 W32.Rusty@mm to W32.Rusty@m 02/16/04 HTML.Bother.3180 to VBS.Bother.3180 02/13/04 HTML.Bother.3180.dr to VBS.Bother.3180.dr 02/13/04 HTML.Davinia.B.dam to VBS.Davinia.B.dam 02/13/04 HTML.Davinia.dam to VBS.Davinia.dam 02/13/04 HTML.Enel.3787 to VBS.Enel.3787 02/13/04 HTML.Enel.3787 (2) to VBS.Enel.3787 (2) 02/13/04 HTML.NoWarn.1921 to VBS.NoWarn.1921 02/13/04 HTML.NoWarn.1921 (2) to VBS.NoWarn.1921 (2) 02/13/04 HTML.Offline.1152 to VBS.Offline.1152 02/13/04 HTML.Panamas to VBS.Panamas 02/13/04 HTML.Prepend to VBS.Prepend 02/13/04 HTML.Prepender to VBS.Prepender 02/13/04 HTML.Pswform.trojan to VBS.Pswform.trojan 02/13/04 HTML.Reality to VBS.Reality 02/13/04 HTML.Reality.B to VBS.Reality.B 02/13/04 HTML.Reality.D to VBS.Reality.D 02/13/04 HTML.Redir.1152 to VBS.Redir.1152 02/13/04 HTML.Redlof.A to VBS.Redlof.A 02/13/04 HTML.Rumbile to VBS.Rumbile 02/13/04 HTML.StartMe to JS.StartMe 02/13/04 HTML.Tipsy.1969 to JS.Tipsy.1969 02/13/04 W97M.Chameleon.B to W97M.Chameleon.I 02/12/04 Trojan.Conspy to Adware.Conspy 02/11/04 VBS.Nohat@mm@int to VBS.Nohat@mm.int 02/11/04 W32.Yenik.A.Worm to W32.Yenik.A@mm 02/10/04 W32.HLLW.Rolog to W32.Letin 02/05/04 W32.Novarg.A@mm to W32.Mydoom.A@mm 02/04/04 W32.Mimail.R@mm to W32.Mimail.S@mm 01/29/04 Backdoor.Lolok.B to W97M.Tebit 01/22/04 W97M.Gedza to O97M.Gedza 01/22/04 X97M.Gedza to VBS.Vaper@mm 01/22/04 Hacktool.X-Scan to Hacktool.XScan 01/19/04 PWSteal.Leox to W32.HLLW.Leox 01/19/04 Backdoor.Fxdoor to Tcl.Sendrak 01/18/04 Trojan.Dalfer.C to W32.Spybot.WI 01/18/04 Trojan.Dalfer.C to W97M.Twopey.E 01/15/04 Backdoor.NetTrash to W32.HLLW.Nettrash 01/14/04 PWSteal.RTCW to Backdoor.NetTrash 01/13/04 Trojan.Dalfer to Joke.Apeldorn 01/12/04 Trojan.Dalfer.B to Adware.Smartsearch 01/12/04 Trojan.Narat to Adware.Mpgcom 01/05/04 W32.HLLW.Gaobot.EZ to W32.HLLW.Gaobot.FB 01/05/04 W32.Gase to W32.Gase.intd 12/30/03 Backdoor.Hazzer to Trojan.Hazzer 12/18/03 W32.Mertian@mm to W32.Mertian.Worm 12/15/03 MHTML.Redir.Exploit to MHTMLRedir.Exploit 12/12/03 Deletions (sorted by Virus Name): Virus Name Infection Type Date removed ---------- -------------- ------------ Backdoor.Aphexdoor File infector 01/28/04 Backdoor.Ciadoor.b File infector 11/24/03 Backdoor.Regate File infector 12/01/03 Dialer.Dcon File infector 11/24/03 HTML.Davinia File infector 02/13/04 HTML.Davinia.B File infector 02/13/04 HTML.Press File infector 02/13/04 PWSteal.Blade.Trojan File infector 12/02/03 Trojan.Bookmarker.E File infector 01/28/04 Trojan.Xombe File infector 01/09/04 W32.HLLW.Bandie File infector 11/24/03 W32.HLLW.Freity@mm File infector 11/24/03 W32.HLLW.Gaobot.HY File infector 01/28/04 W32.HLLW.Gaobot.gen File infector 11/24/03 W32.HLLW.Xbotor File infector 11/24/03 W32.Headout File infector 11/24/03 W32.IRCBot.C File infector 01/28/04 W32.Mydoom.B@mm File infector 01/28/04 W32.Titog.L.Worm File infector 01/09/04 Wimp.1430 File infector 01/28/04 Deletions (sorted by Date removed): Virus Name Infection Type Date removed ---------- -------------- ------------ HTML.Davinia File infector 02/13/04 HTML.Davinia.B File infector 02/13/04 HTML.Press File infector 02/13/04 Backdoor.Aphexdoor File infector 01/28/04 Trojan.Bookmarker.E File infector 01/28/04 W32.HLLW.Gaobot.HY File infector 01/28/04 W32.IRCBot.C File infector 01/28/04 W32.Mydoom.B@mm File infector 01/28/04 Wimp.1430 File infector 01/28/04 Trojan.Xombe File infector 01/09/04 W32.Titog.L.Worm File infector 01/09/04 PWSteal.Blade.Trojan File infector 12/02/03 Backdoor.Regate File infector 12/01/03 Backdoor.Ciadoor.b File infector 11/24/03 Dialer.Dcon File infector 11/24/03 W32.HLLW.Bandie File infector 11/24/03 W32.HLLW.Freity@mm File infector 11/24/03 W32.HLLW.Gaobot.gen File infector 11/24/03 W32.HLLW.Xbotor File infector 11/24/03 W32.Headout File infector 11/24/03 ********************************************************************** ** Additional Information ** ********************************************************************** Additional information regarding this virus definitions update can be found in UPDATE.TXT and TECHNOTE.TXT.