home *** CD-ROM | disk | FTP | other *** search
- **********************************************************************
- ** **
- ** What's New in the NAV Virus Definitions Files WHATSNEW.TXT **
- ** **
- ** Symantec AntiVirus Research Center (SARC) July 12, 1999 **
- ** **
- **********************************************************************
- This document contains the following topics:
-
- * Virus Alerts
- * New Technologies
- * Changes Incorporated Into This Update
- * Enabling/Disabling PowerPoint Scanning
- * Additional Information
-
- **********************************************************************
- ** Virus Alerts **
- **********************************************************************
- The ten most commonly reported viruses, worldwide:
-
- 1 W97M.Class
- 2 XM.Laroux
- 3 O97M.Tristate
- 4 W95.CIH
- 5 Happy99.Worm
- 6 WM.Cap
- 7 W97M.ColdApe
- 8 W97M.Ethan
- 9 W97M.Melissa
- 10 Worm.ExploreZip
-
- **********************************************************************
- ** New Technologies **
- **********************************************************************
-
- DATE Technologies Added
- ---- ------------------
- 8/19/98 * Excel heuristics which detect and repair new and unknown
- macro viruses in Excel 95 & 97 documents.
-
- 9/16/98 * Added repair for encrypted Excel 97 documents.
-
- 10/21/98 * Heuristics to detect AOL Password Stealer Trojans.
- * WORD Heuristics improvement to increase detection rate.
-
- 12/17/98 * Macro Exclusion Engine to speed up the scanning for Word
- and Excel documents.
- * PowerPoint engine to scan PowerPoint related viruses.
- To enable this technology please read "Enabling/Disabling
- PowerPoint Scanning" section later in this document.
-
- 02/18/99 * Detection and repair of macro viruses in Word and Excel
- 2000 documents.
-
- 05/12/99 * Added repair for PowerPoint viruses.
- * Improved heuristics to detect more WORD 97 related
- viruses.
-
- 06/10/99 * Menu repair technology for WORD macro viruses that change
- command bar customizations in NORMAL.DOT.
-
- 07/12/99 * Added support for scanning of Ichitaro 8/9 documents.
- (Ichitaro is a Japanese word processing program).
-
-
- **********************************************************************
- ** Changes Incorporated Into This Virus Definitions Update **
- **********************************************************************
- New virus definitions:
-
- Virus Name Infection Type Week added
- ---------- -------------- ----------
- ACG.B File infector 07/12/99
- Airwalker.300 File infector 07/12/99
- Airwalker.303 File infector 07/12/99
- Airwalker.384 File infector 07/12/99
- Airwalker.385 File infector 07/12/99
- Airwalker.386 File infector 07/12/99
- Ala-eh.2279 File infector 07/12/99
- Alladin.1827 File infector 06/28/99
- Anna.734 File infector 07/12/99
- Anna.734 Gen(1) File infector 07/12/99
- AnsJovis.12695 File infector 07/12/99
- AOL.PWSteal.32512 File infector 06/28/99
- Apadana.1500 File infector 07/12/99
- Appender.1210 File infector 06/21/99
- Atb.1522 File infector 07/12/99
- Avvaddon.1100 File infector 07/12/99
- AZD Trojan File infector 07/12/99
- Backdoor.Netbus.153 File infector 07/12/99
- Backdoor.Netbus.153 2 File infector 07/12/99
- Backdoor.Netbus.153 3 File infector 07/12/99
- BackOrifice2K.Inst File infector 07/12/99
- BackOrifice2K.Inst(2) File infector 07/12/99
- BackOrifice2K.Inst(3) File infector 07/12/99
- BackOrifice2K.Inst(4) File infector 07/12/99
- BackOrifice2K.Inst2 File infector 07/12/99
- BackOrifice2K.Inst2(2) File infector 07/12/99
- BackOrifice2K.Inst2(3) File infector 07/12/99
- BackOrifice2K.Inst2(4) File infector 07/12/99
- BackOrifice2K.Trojan File infector 07/10/99
- BackOrifice2K.Trojan File infector 07/12/99
- Beast.B.Trojan File infector 06/21/99
- BIOS.Password.Trojan File infector 06/21/99
- BitAddict.432 File infector 07/12/99
- Block.246 File infector 07/12/99
- Bowl.135 File infector 07/12/99
- Bowl.754 File infector 07/12/99
- Bowl.756 File infector 07/12/99
- Burglar.1150 (Gen1) File infector 06/21/99
- Burglar.1150 (Gen1) 2 File infector 06/21/99
- BW.GR.Borg.1002 File infector 07/12/99
- BW.GR.Borg.1047 File infector 07/12/99
- BW.GR.Borg.912 File infector 07/12/99
- BW.GR.Borg.922 File infector 07/12/99
- BW.GR.Borg.927 File infector 07/12/99
- BW.GR.Borg.932 File infector 07/12/99
- BW.GR.Borg.937 File infector 07/12/99
- BW.GR.Borg.942 File infector 07/12/99
- BW.GR.Borg.947 File infector 07/12/99
- BW.GR.Borg.952 File infector 07/12/99
- BW.GR.Borg.957 File infector 07/12/99
- BW.GR.Borg.967 File infector 07/12/99
- BW.GR.Borg.972 File infector 07/12/99
- BW.GR.Borg.977 File infector 07/12/99
- BW.GR.Borg.982 File infector 07/12/99
- BW.GR.Borg.987 File infector 07/12/99
- BW.GR.Borg.992 File infector 07/12/99
- BW.GR.Borg.997 File infector 07/12/99
- BW.GR.Drole.790 File infector 07/12/99
- BW.GR.Drole.796 File infector 07/12/99
- BW.GR.Drole.801 File infector 07/12/99
- BW.GR.Drole.806 File infector 07/12/99
- BW.GR.Drole.811 File infector 07/12/99
- BW.GR.Drole.816 File infector 07/12/99
- BW.GR.Drole.821 File infector 07/12/99
- BW.GR.Drole.826 File infector 07/12/99
- BW.ROET.753 File infector 07/12/99
- Chad.307 File infector 07/12/99
- Coconut.2015 File infector 07/12/99
- Coconut.2071 File infector 07/12/99
- Coconut.2324 File infector 07/12/99
- Companion.Friendb.330 File infector 06/01/99
- Crash.475 File infector 06/28/99
- CVM.1367 File infector 07/12/99
- CyberTech.581 File infector 07/12/99
- Daffodil.525 File infector 07/12/99
- DBO-3 (b) Boot infector 06/01/99
- DELEK.2070 File infector 07/12/99
- DELFI.1800 File infector 07/12/99
- DELFI.2000 File infector 07/12/99
- DELFI.2300 File infector 07/12/99
- DEMENTIA.4207.C File infector 07/12/99
- Derwolf.2219 File infector 06/01/99
- Derwolf.2219 (2) File infector 06/01/99
- DIR2.A.V File infector 07/12/99
- DIR2.A.X File infector 07/12/99
- DIR2.A.Y File infector 07/12/99
- DISN.1516 File infector 07/12/99
- Dosinfo.Worm File infector 07/02/99
- Dosinfo.Worm 2 File infector 07/02/99
- DOTT.3969 File infector 07/12/99
- DREG.0465 File infector 07/12/99
- DREG.0510 File infector 07/12/99
- DREG.0581 File infector 07/12/99
- DREG.0883 File infector 07/12/99
- DREG.1232 File infector 07/12/99
- DREG.2365 File infector 07/12/99
- Drizzle.1600 File and Boot infector 07/12/99
- DVC.336 File infector 07/12/99
- Dying Oath.cav.268 File infector 07/12/99
- Dying Oath.cav.270 File infector 07/12/99
- Emperor File and Boot infector 06/01/99
- Explore.59904 File infector 07/12/99
- Explore.59904 2 File infector 07/12/99
- Explore.59904 3 File infector 07/12/99
- Explore.59904 4 File infector 07/12/99
- Explore.59904 5 File infector 07/12/99
- Fake Server Trojan File infector 06/21/99
- Fake Server Trojan 2 File infector 06/21/99
- Fake Server Trojan 3 File infector 06/21/99
- Fake Server Trojan 4 File infector 06/21/99
- Fayte.494 File infector 07/02/99
- Fayte.494 (2) File infector 07/02/99
- Gene.454 File infector 06/28/99
- Gift.1630 File infector 06/28/99
- Goma.1002 File infector 06/01/99
- Goma.743 File infector 06/01/99
- Hack Server Trojan File infector 06/21/99
- Hack Server Trojan 2 File infector 06/21/99
- Hack Server Trojan 3 File infector 06/21/99
- Hack Server Trojan 4 File infector 06/21/99
- Hack Svr v1 Trojan File infector 06/28/99
- Hack Svr v1 Trojan 2 File infector 06/28/99
- Hack Svr v1 Trojan 3 File infector 06/28/99
- Hack Svr v1 Trojan 4 File infector 06/28/99
- Hack v1.0 Trojan File infector 06/28/99
- Hack v1.0 Trojan 2 File infector 06/28/99
- Hack v1.0 Trojan 3 File infector 06/28/99
- Hack v1.0 Trojan 4 File infector 06/28/99
- Hack v1.12 Trojan File infector 06/21/99
- Hack v1.12 Trojan 2 File infector 06/21/99
- Hack v1.12 Trojan 3 File infector 06/21/99
- Hack v1.12 Trojan 4 File infector 06/21/99
- Hack'a'Tack Trojan File infector 06/21/99
- Hack'a'Tack Trojan 2 File infector 06/21/99
- Hack'a'Tack Trojan 3 File infector 06/21/99
- Hack'a'Tack Trojan 4 File infector 06/21/99
- Heathen.12288(DLL) File infector 06/21/99
- HKILL.1468 File infector 06/28/99
- HKILL.1468 (2) File infector 06/28/99
- HKILL.997 File infector 06/28/99
- HLLO.13112 File infector 07/12/99
- HLLO.13112(2) File infector 07/12/99
- HLLO.2229 File infector 06/28/99
- HLLO.2229(2) File infector 06/28/99
- HLLO.2400 File infector 06/28/99
- HLLO.2400(2) File infector 06/28/99
- HLLO.2673 File infector 06/28/99
- HLLO.2673(2) File infector 06/28/99
- HLLO.9000 File infector 07/12/99
- HLLO.9000(2) File infector 07/12/99
- HLLO.DVPG.4128 File infector 06/28/99
- HLLO.DVPG.4128(2) File infector 06/28/99
- HLLO.Maniac.5946 File infector 06/01/99
- HLLO.Maniac.5946 (2) File infector 06/01/99
- HLLP.3678 File infector 06/28/99
- HLLP.3678(2) File infector 06/28/99
- HLLP.4384 File infector 07/12/99
- HLLP.4384(2) File infector 07/12/99
- HLLP.4631 File infector 06/28/99
- HLLP.4631(2) File infector 06/28/99
- HLLP.4754 File infector 06/28/99
- HLLP.4754(2) File infector 06/28/99
- HLLP.5062 File infector 06/28/99
- HLLP.5062(2) File infector 06/28/99
- HLLP.7616 File infector 06/28/99
- HLLP.7616(2) File infector 06/28/99
- HLLP.8080 File infector 06/28/99
- HLLP.8080(2) File infector 06/28/99
- HLLP.Jurasic.6227 File infector 06/28/99
- HLLP.Jurasic.6227(2) File infector 06/28/99
- HLLP.PPZ.8586 File infector 06/28/99
- HLLP.PPZ.8586(2) File infector 06/28/99
- HLLT.4156 File infector 07/12/99
- HLLT.4156(2) File infector 07/12/99
- HLLT.4423 File infector 07/12/99
- HLLT.4423(2) File infector 07/12/99
- HLLT.4754 File infector 06/28/99
- HLLT.4754(2) File infector 06/28/99
- HLLT.7909 File infector 07/12/99
- HLLT.7909(2) File infector 07/12/99
- HLLT.8297 File infector 07/12/99
- HLLT.8297(2) File infector 07/12/99
- Infector.5864 File infector 06/28/99
- Istanbul.1385 File infector 06/01/99
- Istanbul.1385 (x) File infector 06/01/99
- Jackie2.5743 File infector 06/21/99
- Jackie2.5743 (2) File infector 06/21/99
- Jacklyn.12301 File infector 06/21/99
- Jacklyn.12301 (2) File infector 06/21/99
- Jags.394 File infector 06/01/99
- JAP_HAL (b) Boot infector 06/01/99
- Ktcp.200 File infector 06/28/99
- KTCP.200 Trojan File infector 07/12/99
- KTCP.200 Trojan 2 File infector 07/12/99
- KuSuMah.3967 File infector 06/01/99
- KuSuMah.4268 (x) File infector 06/01/99
- Lazarus.2222 File infector 06/01/99
- Magichole.512 File infector 06/01/99
- Mahon.1372 File infector 06/01/99
- MARK.1024 File infector 07/12/99
- MBD.1258 File infector 07/12/99
- Messiah.4535 (x) File infector 07/02/99
- MiniMad.346 File infector 07/12/99
- MiniMad.347 File infector 07/12/99
- MiniMad.349.B File infector 07/12/99
- MiniMad.350 File infector 07/12/99
- Miny.200 File infector 07/12/99
- Miny.222 File infector 07/12/99
- Miny.237 File infector 07/12/99
- Miny.512 File infector 07/12/99
- MinyO.433 File infector 07/12/99
- Mora.2725 File infector 07/12/99
- MUR.3449.B File infector 07/12/99
- Mwin.a File infector 06/28/99
- Mwin.a (2) File infector 06/28/99
- Mwin.b File infector 06/28/99
- Mwin.b (2) File infector 06/28/99
- Nanjing.1284 File infector 07/12/99
- NAX.1402 File infector 07/12/99
- Nephew.3758 File infector 06/01/99
- Nephew.3758 (2) File infector 06/01/99
- Nephew.3758 (x) File infector 06/01/99
- Nephew.3758 (x2) File infector 06/01/99
- NEPT.938 File infector 07/12/99
- New_Model.533 File infector 07/12/99
- Nilz.1000.Dropper File infector 07/12/99
- Ninja.1264 File infector 06/28/99
- Nipple.823 File infector 06/01/99
- Nipple.823 (2) File infector 06/01/99
- November 17.768.B (x) File infector 06/28/99
- NPOX.1634 File infector 07/12/99
- NPOX.1641 File infector 07/12/99
- O97M.Shiver.G File infector 07/12/99
- PM Trojan File infector 06/21/99
- PM Trojan (2) File infector 06/21/99
- PM Trojan (3) File infector 06/21/99
- PM Trojan (4) File infector 06/21/99
- PM Trojan (DLL) File infector 06/21/99
- PM Trojan (DLL) (2) File infector 06/21/99
- PM Trojan (DLL) (3) File infector 06/21/99
- PM Trojan (DLL) (4) File infector 06/21/99
- PM Trojan (OCX) File infector 06/21/99
- PM Trojan (OCX) (2) File infector 06/21/99
- PM Trojan (OCX) (3) File infector 06/21/99
- PM Trojan (TIM) File infector 06/21/99
- PM Trojan (TIM) File infector 07/07/99
- PM Trojan (TIM) (2) File infector 06/21/99
- PM Trojan (TIM) (3) File infector 06/21/99
- Predator.1879 (x) File infector 07/12/99
- Radioactive.873 File infector 07/02/99
- Reizfaktor (Bat) File infector 06/01/99
- Reizfaktor (inf) File infector 06/01/99
- Reizfaktor (inf2) File infector 06/01/99
- Retro.974 File infector 06/01/99
- Retro.974 (2) File infector 06/01/99
- Retro.974 (3) File infector 06/01/99
- Sillyrce.400 File infector 07/12/99
- Sillyrce.400 (x) File infector 07/12/99
- Slam.Hunter.253 File infector 06/28/99
- SP1 Basic.Trojan File infector 06/01/99
- SP1 Basic.Trojan (2) File infector 06/01/99
- Sphinx.2534 File infector 06/28/99
- Stardot.1100 File infector 07/07/99
- TARO.DumbVir File infector 07/12/99
- Termite.5000.B File infector 06/21/99
- Termite.C File infector 06/21/99
- Tie.512 File infector 07/12/99
- Trivial.52.b File infector 06/21/99
- Trivial.53.f File infector 06/21/99
- Trivial.55.d File infector 06/21/99
- Trivial.58 File infector 06/21/99
- Trivial.59 File infector 07/12/99
- Trivial.59.b File infector 06/21/99
- Trivial.77.b File infector 07/12/99
- Trivial.81.b File infector 07/12/99
- Typer.215 File infector 06/28/99
- V.1906 File infector 06/21/99
- VBS.Freelink File infector 07/02/99
- VGPSI.193 File infector 07/12/99
- Viva.752 File infector 06/01/99
- VS.944 File infector 07/12/99
- W95.Weird File infector 07/12/99
- W95.Weird.Dropper File infector 07/12/99
- W97M.Aleja File infector 07/12/99
- W97M.Botschafter File infector 07/12/99
- W97M.Chack.Y File infector 07/12/99
- W97M.Class.DN File infector 06/21/99
- W97M.CopyTemp.intd File infector 06/01/99
- W97M.Creeper File infector 07/12/99
- W97M.Daydream.A File infector 06/01/99
- W97M.Ethan.B File infector 07/12/99
- W97M.Heathen.12288.A File infector 06/21/99
- W97M.Hopper.Q.Int File infector 07/12/99
- W97M.Iis.H File infector 06/28/99
- W97M.IRCJack.A File infector 06/21/99
- W97M.JulyKiller File infector 07/02/99
- W97M.KillGood.Trojan File infector 06/21/99
- W97M.Mago.A File infector 06/28/99
- W97M.Melissa.I File infector 06/21/99
- W97M.Melissa.M File infector 07/12/99
- W97M.MFV File infector 06/21/99
- W97M.NiceDay.AB File infector 06/28/99
- W97M.No_va.D File infector 06/01/99
- W97M.Password.A File infector 06/28/99
- W97M.Password.B File infector 07/02/99
- W97M.Reizfaktor File infector 06/01/99
- W97M.Steak.A File infector 06/21/99
- W97M.Steak.B File infector 06/21/99
- W97M.VMPCK1.BK File infector 07/02/99
- WM.Automat.BK File infector 07/02/99
- WM.Mental.I File infector 07/12/99
- WM.NPAD.FAMILY File infector 07/12/99
- WM.Prizm.A File infector 06/28/99
- WM.WAZZU.FAMILY File infector 07/12/99
- WuChing.Boot.Dropper Boot infector 06/01/99
- X97M.Automat.BF File infector 07/02/99
- X97M.NEG.D File infector 07/12/99
- XM.Automat.BI File infector 07/02/99
- XM.Automat.FS File infector 07/12/99
- XM.Automat.GQ File infector 07/12/99
- XM.Automat.HE File infector 07/12/99
- XM.Laroux.HQ File infector 06/01/99
- XM.Modul File infector 07/12/99
- XM.Sugar File infector 07/02/99
- Zasta.2546 File infector 06/28/99
- Zasta.2546 (2) File infector 06/28/99
- Zhu.1743 File infector 07/12/99
- Zohr.4160 File infector 06/01/99
- Zorm.573 File infector 06/01/99
- Zuca.677 File infector 07/12/99
- Name Changes:
-
- Old Virus Name New Virus Name Date changed
- -------------- -------------- ------------
- Bleem.Trojan to Fake Bleem Trojan 06/28/99
- Gene.454 to Gene.454.b 06/28/99
-
- Deletions:
-
- Virus Name Infection Type Date removed
- ---------- -------------- ------------
- Antiwin.633.B File infector 07/12/99
- AOL Trojan Buddy File infector 06/21/99
- AOL Trojan Buddy 2 File infector 06/21/99
- AOL Trojan Buddy 3 File infector 06/21/99
- WM.Automat.BK File infector 07/12/99
- Bupt.1279 File infector 06/01/99
- Laufwerk File infector 06/21/99
- PM Trojan (TIM) File infector 07/02/99
- PS-MPC.Mudshark File infector 06/01/99
- Stardot.1100 File infector 07/02/99
- VirDem.824 File infector 06/01/99
- Virogen.Asexual (2) File infector 06/28/99
- WM.Automat.Q File infector 06/28/99
- X97M.Automat.BF File infector 07/12/99
- XM.Automat.BI File infector 07/12/99
-
- **********************************************************************
- ** Enabling/Disabling PowerPoint Scanning **
- **********************************************************************
- PowerPoint Scanning is now enabled by default and can be optionally
- disabled. However, you may want to verify that files with
- PowerPoint extensions will be scanned by making sure that your
- NAV options have both ".PPT" and ".POT" in the list of extensions
- to scan.
-
- To disable PowerPoint scanning in NAV for Windows 95/NT
- version 4.x or NAV for OS/2, a text file named NAVEX15.INF should
- be placed in the directory where NAV 4.x or NAV 5.x is installed
- (i.e., C:\Program Files\Norton AntiVirus).
-
- To disable PowerPoint scanning in NAV for Netware version 4.x, a text
- file named NAVEX15.INF should be placed in the directory where NAV
- 4.x is installed (i.e., sys:system\navnlm).
-
- To disable PowerPoint scanning in NAV for Windows 95/NT version 2.0,
- NAV 4.x for Windows 3.1/DOS, NAVIEG 1.x, or NAVFW 1.x a text file
- named NAVEX.INF should be placed in the directory where NAV is
- installed (i.e., C:\NAV).
-
- The contents of the text file, NAVEX15.INF or NAVEX.INF, determine
- which components of NAV have PowerPoint scanning disabled.
-
- To disable PowerPoint scanning for a particular component, use the
- following table to determine the lines to add to the text file.
- PowerPoint scanning can be disabled for more than one component if
- needed by adding the required lines for the desired components.
-
- +---------------------+--------------------------+--------------------+
- |Windows 95/NT scanner|Windows 95/NT auto-protect|DOS scanner |
- +---------------------+--------------------------+--------------------+
- |[NAVW32] |[NAVAP] |[NAVDX] |
- |PowerPointScanning=0 |PowerPointScanning=0 |PowerPointScanning=0|
- +---------------------+--------------------------+--------------------+
-
- +----------------------+--------------------+--------------------+
- |Windows 3.1 scanner/AP|Netware scanner |OS/2 scanner/AP |
- +----------------------+--------------------+--------------------+
- |[NAVWIN] |[NAVNLM] |[NAVOS2] |
- |PowerPointScanning=0 |PowerPointScanning=0|PowerPointScanning=0|
- +----------------------+--------------------+--------------------+
-
- To enable PowerPoint scanning for a component, delete the lines
- added for that component from the NAVEX15.INF or NAVEX.INF file.
-
- **********************************************************************
- ** Additional Information **
- **********************************************************************
- SARC has equipped Norton AntiVirus with a new feature called
- "Infestation Mode." If a large number of new or unknown viruses
- is found on the system during a scan, Norton AntiVirus will
- automatically enable its highest level of detection. This gives
- users the most comprehensive protection in cases where a viral
- infestation may have been detected. If you would like to disable
- this feature, you can do so by following these instructions:
-
- 1. Create a text File called NAVEX15.INF in your Norton AntiVirus
- directory,e.g., C:\Program Files\Norton AntiVirus. If this file
- already exist go to step two.
-
- 2. Place the following lines in this File on the left-hand margin:
-
- [NAVW32]
- infestmode=0
-
- [NAVDX]
- infestmode=0
-
- 3. Save the File.
-
-
- Additional information regarding this virus definitions update can be
- found in UPDATE.TXT and TECHNOTE.TXT.
-