home *** CD-ROM | disk | FTP | other *** search
/ Chip 2000 May / Chip_2000-05_cd1.bin / servis / Aviry / NAV / 0403i32.exe / whatsnew.txt < prev    next >
Text File  |  2000-04-03  |  19KB  |  351 lines

  1. **********************************************************************
  2. **                                                                  **
  3. **  What's New in the NAV Virus Definitions Files      WHATSNEW.TXT **
  4. **                                                                  **
  5. **  Symantec AntiVirus Research Center (SARC)        April 03 ,2000 **
  6. **                                                                  **
  7. **********************************************************************
  8. This document contains the following topics:
  9.  
  10.  * Virus Alerts
  11.  * New Technologies
  12.  * Changes Incorporated Into This Update
  13.  * Enabling Scanning Features
  14.  * Additional Information
  15.  
  16. **********************************************************************
  17. ** Virus Alerts                                                     **
  18. **********************************************************************
  19. The ten most commonly reported viruses, worldwide:
  20.  
  21.     1  W97M.Class
  22.     2  XM.Laroux
  23.     3  O97M.Tristate
  24.     4  W95.CIH
  25.     5  Happy99.Worm
  26.     6  WM.Cap
  27.     7  W97M.ColdApe
  28.     8  W97M.Ethan
  29.     9  W97M.Melissa
  30.    10  Worm.ExploreZip
  31.  
  32. **********************************************************************
  33. ** New Technologies                                **
  34. **********************************************************************
  35.  
  36. DATE         Technologies Added
  37. ----         ------------------
  38. 8/19/98    * Excel heuristics which detect and repair new and unknown
  39.              macro viruses in Excel 95 & 97 documents.
  40.  
  41. 9/16/98    * Added repair for encrypted Excel 97 documents.
  42.  
  43. 10/21/98   * Heuristics to detect AOL Password Stealer Trojans.
  44.            * WORD Heuristics improvement to increase detection rate.
  45.  
  46. 12/17/98   * Macro Exclusion Engine to speed up the scanning for Word
  47.              and Excel documents.
  48.            * PowerPoint engine to scan PowerPoint related viruses.
  49.              To enable this technology please read "Enabling/Disabling
  50.              PowerPoint Scanning" section later in this document.
  51.  
  52. 02/18/99   * Detection and repair of macro viruses in Word and Excel
  53.              2000 documents.
  54.  
  55. 05/12/99   * Added repair for PowerPoint viruses.
  56.            * Improved heuristics to detect more WORD 97 related
  57.              viruses.
  58.  
  59. 06/10/99   * Menu repair technology for WORD macro viruses that change
  60.              command bar customizations in NORMAL.DOT.
  61.  
  62. 07/12/99   * Added support for scanning of Ichitaro 8/9 documents.
  63.              (Ichitaro is a Japanese word processing program).
  64.  
  65. 08/19/99   * Added detection and repair for embedded documents inside
  66.              PowerPoint 97.
  67.  
  68. 11/22/99   * Added detection and repair for Trojans embedded in OLE
  69.              files, such as Windows scrap files and MS Office
  70.              documents.
  71.            * Added detection for viruses which infect Microsoft
  72.              Project documents (P98M.Corner.A, for example).
  73.  
  74. 02/10/00   * Added support for scanning of UNIX executables.
  75.            * Added detection for infected Visio documents.
  76.  
  77. **********************************************************************
  78. ** Changes Incorporated Into This Virus Definitions Update        **
  79. **********************************************************************
  80. New virus definitions:
  81.  
  82.         Virus Name                Infection Type          Week added
  83.         ----------                --------------          ----------
  84.         Backdoor.BladeRunner      File infector          03/27/00
  85.         Backdoor.BrainSpy         File infector           03/06/00
  86.         Backdoor.Grab             File infector          03/27/00
  87.         Backdoor.HackTack.120     File infector          04/03/00
  88.         Backdoor.Komut            File infector           03/17/00
  89.         Backdoor.Krass            File infector          03/27/00
  90.         Backdoor.NssKill          File infector           03/06/00
  91.         Backdoor.Psychward.b      File infector          04/03/00
  92.         Backdoor.SBD              File infector           03/13/00
  93.         Backdoor.Senna            File infector          03/27/00
  94.         Backdoor.SubSeven22       File infector          03/31/00
  95.         Backdoor.TapiTroj         File infector           03/06/00
  96.     BAT.Chode.Worm            File infector          03/31/00
  97.         Giggles.Trojan            File infector          03/27/00
  98.         Infector.Trojan           File infector           03/17/00
  99.         Irok.Trojan.Worm          File infector          04/03/00
  100.         Istanbul.1349             File infector           03/13/00
  101.         Istanbul.1397             File infector           03/13/00
  102.         Istanbul.1397 (x)         File infector           03/13/00
  103.         Js.JudgeDay               File infector           03/06/00
  104.         Linux.Backdoor.IN         File infector           03/17/00
  105.         Linux.Bliss.A             File infector           03/17/00
  106.         Linux.Bliss.B             File infector           03/17/00
  107.         Linux.Silv5444            File infector           03/17/00
  108.         Movie.Pif.Worm            File infector           03/17/00
  109.         NTMonitor.Trojan          File infector           03/13/00
  110.         O97M.Exceller.A           File infector          03/27/00
  111.         Shifter.1295              File infector          03/27/00
  112.         Shifter.1295 (x)          File infector          03/27/00
  113.         Solaris.DoS.stacheld.s    File infector           03/17/00
  114.         SSR.19071                 File infector           03/13/00
  115.         SubSeven.Dropper          File infector           03/13/00
  116.         Trojan.Bat.Erase          File infector           03/06/00
  117.         Trojan.Bat.HDKill         File infector          03/27/00
  118.         Trojan.FreeLinkX          File infector           03/06/00
  119.         Trojan.Masterlock         File infector           03/13/00
  120.         Unix.Bash                 File infector           03/17/00
  121.         Unix.Dumb.A               File infector           03/17/00
  122.         Unix.Dumb.B               File infector           03/17/00
  123.         Unix.Gift                 File infector           03/17/00
  124.         Unix.Jaded                File infector           03/17/00
  125.         Unix.ls                   File infector           03/17/00
  126.         Unix.Penguin              File infector           03/17/00
  127.         Unix.PSite                File infector           03/17/00
  128.         VBS.IROK                  File infector          04/03/00
  129.         VBS.Orochi                File infector           03/17/00
  130.         VBS.Story                 File infector           03/13/00
  131.         W32.AOC.3650              File infector           03/13/00
  132.         W32.AOC.3676              File infector          03/27/00
  133.     W32.ASpam.Trojan      File infector           04/03/00
  134.     W32.ASpam.Trojan.B      File infector           04/03/00
  135.         W32.Azaco.B.Worm          File infector           03/06/00
  136.         W32.Bolzano.5396.G1       File infector           03/13/00
  137.         W32.Cabdrop.4096          File infector           03/13/00
  138.         W32.Cholera.B.Worm        File infector          03/27/00
  139.         W32.Cholera.C.Worm        File infector          03/27/00
  140.         W32.CTX.7017              File infector           03/13/00
  141.         W32.ExploreZip.E.Worm     File infector           03/13/00
  142.         W32.HLLO.29128            File infector           03/13/00
  143.         W32.HLLP.Bora.11264       File infector          03/27/00
  144.         W32.HLLP.Bora.Mirc        File infector          03/27/00
  145.         W32.HLLP.Semisoft.G       File infector           03/13/00
  146.         W32.IIS.Worm              File infector           03/13/00
  147.         W32.Inrar.B               File infector          03/27/00
  148.         W32.Jane.Worm             File infector           03/06/00
  149.         W32.Lunatik.Worm          File infector           03/06/00
  150.         W32.Melting.Worm          File infector           03/13/00
  151.         W32.Nazka.Int             File infector           03/13/00
  152.         W32.Orochi.5420           File infector          03/27/00
  153.         W32.Orochi.5420 (mIRC)    File infector           03/17/00
  154.         W32.PrettyPark.E.Worm     File infector           03/06/00
  155.         W32.PrettyPark.F.Worm     File infector           03/06/00
  156.         W32.PrettyPark.G.Worm     File infector           03/06/00
  157.         W32.PrettyPark.Gen        File infector           03/13/00
  158.         W32.PrettyPark.H.Worm     File infector           03/13/00
  159.         W32.PrettyPark.I.Worm     File infector           03/13/00
  160.         W32.Refer.2939            File infector          03/27/00
  161.         W32.Spit.B                File infector          03/27/00
  162.         W32.Teddybear.Worm        File infector           03/13/00
  163.         W32.Unicle.A.Worm         File infector           03/06/00
  164.         W32.Unicle.B.Worm         File infector           03/06/00
  165.         W32.Weird (gen1)          File infector          04/03/00
  166.         W32.Weird (gen1_2)        File infector          04/03/00
  167.         W32.Weird (gen1_3)        File infector          04/03/00
  168.         W32.Weird (gen1_4)        File infector          04/03/00
  169.         W32.WinExt.B.Worm         File infector           03/13/00
  170.         W95.Arianne.1022          File infector           03/06/00
  171.         W95.Arianne.1022.Int      File infector           03/13/00
  172.         W95.Boza.2220.Int         File infector          03/27/00
  173.         W95.Fosoforo.Int          File infector           03/06/00
  174.         W95.Invir                 File infector           03/13/00
  175.         W95.Matrix.3597           File infector          03/27/00
  176.         W95.Matrix.3597.TR        File infector          03/27/00
  177.         W95.Matrix.3597.TR (2)    File infector          03/27/00
  178.         W95.Merinos.1763          File infector           03/13/00
  179.         W95.Mmorf.1348            File infector           03/06/00
  180.         W95.Orez.6287             File infector           03/06/00
  181.         W95.Priest.1454           File infector          03/27/00
  182.         W95.Priest.1486           File infector          03/27/00
  183.         W95.Priest.1495           File infector          03/27/00
  184.         W95.Priest.1521           File infector           03/06/00
  185.         W95.Score.B               File infector           03/13/00
  186.         W95.Sexy.156              File infector           03/13/00
  187.         W95.Shoerec.9216          File infector           03/06/00
  188.         W95.Shoerec.9216.Tr       File infector           03/06/00
  189.         W95.SillyW.431            File infector           03/13/00
  190.         W95.SK (com)              File infector          03/27/00
  191.         W95.SK (com2)             File infector           03/13/00
  192.         W95.SK.380                File infector           03/13/00
  193.         W95.SK.428                File infector           03/13/00
  194.         W95.Tecata.1761           File infector          03/27/00
  195.         W95.VIP.4309.B            File infector          03/27/00
  196.         W95.Weird.C               File infector          03/27/00
  197.         W95.Weird.C.Backdoor      File infector          03/27/00
  198.         W95.Ylang.1536            File infector           03/13/00
  199.         W95.Ylang.1536.A          File infector          03/27/00
  200.         W95.Yurn.1652.Int         File infector           03/06/00
  201.         W97M.Bablas.G             File infector          03/27/00
  202.         W97M.Bablas.K             File infector          04/03/00
  203.         W97M.Bablas.N             File infector          03/27/00
  204.         W97M.Bablas.Q             File infector           03/06/00
  205.         W97M.Bablas.R             File infector           03/06/00
  206.         W97M.Bablas.S             File infector           03/13/00
  207.         W97M.Bablas.T             File infector          04/03/00
  208.         W97M.Bablas.U             File infector          04/03/00
  209.         W97M.Bablas.V             File infector          04/03/00
  210.         W97M.Buendia              File infector          04/03/00
  211.         W97M.Ciao.A               File infector          03/27/00
  212.         W97M.Class.EJ             File infector          03/27/00
  213.         W97M.Claudio              File infector           03/17/00
  214.         W97M.CViper               File infector          04/03/00
  215.         W97M.FS.B.Ru              File infector           03/17/00
  216.         W97M.IJK                  File infector           03/17/00
  217.         W97M.IJK.B                File infector          04/03/00
  218.         W97M.Invkay               File infector           03/06/00
  219.         W97M.KAPSYAW              File infector          03/27/00
  220.         W97M.Killer               File infector           03/06/00
  221.         W97M.Lenni.A              File infector          03/27/00
  222.         W97M.Lupi.B               File infector           03/13/00
  223.         W97M.MARKER.BQ            File infector           03/13/00
  224.         W97M.MARKER.BV            File infector           03/13/00
  225.         W97M.Marker.BW            File infector          03/27/00
  226.         W97M.Michael.B            File infector           03/06/00
  227.         W97M.MXFile.C             File infector          04/03/00
  228.         W97M.Nidoc                File infector           03/13/00
  229.         W97M.Opey.P               File infector          03/27/00
  230.         W97M.Proverb.A            File infector          04/03/00
  231.     W97M.Service          File infector          04/03/00
  232.         W97M.SMAC.D               File infector           03/13/00
  233.         W97M.Stun                 File infector           03/17/00
  234.         W97M.Thus.O               File infector           03/13/00
  235.         W97M.Thus.Q               File infector          03/27/00
  236.         W97M.Thus.R               File infector          04/03/00
  237.         W97M.Titch.E              File infector          03/27/00
  238.         W97M.Verlor.E             File infector          03/27/00
  239.         W97M.Wrench.E             File infector          03/27/00
  240.         W97M.Wrench.Family        File infector          04/03/00
  241.         W98.Matyas.664            File infector           03/06/00
  242.         Win32.Weird.Dropped       File infector          04/03/00
  243.         WM.Inexist.C              File infector           03/13/00
  244.         X97M.Automat.AE           File infector           03/17/00
  245.         X97M.Base.B               File infector           03/06/00
  246.         X97M.BMV                  File infector           03/13/00
  247.         X97M.DIVI.E               File infector           03/17/00
  248.         X97M.Looksn               File infector          04/03/00
  249.         X97M.Manalo               File infector           03/06/00
  250.         X97M.Tegrat.A             File infector          03/27/00
  251.  
  252.  
  253. Name Changes:
  254.  
  255.         Old Virus Name            New Virus Name          Date changed
  256.         --------------            --------------          ------------
  257.         Bloodhound.Test        to Nutcracker.Ab2 (sys)    03/13/00
  258.         REU.1367               to Istanbul.1367           03/13/00
  259.         REU.1367 Gen ( 1 )     to Istanbul.1367 ( x )     03/13/00
  260.         W32.AOC.3650           to W32.AOC.3649            03/17/00
  261.         W95.Ylang.1536         to W95.Ylang.1536.B        03/17/00
  262.         W97M.Class.Ej          to W97M.Panther.Family     03/13/00
  263.         W97M.Marker.CE         to W97M.Marker.BY          03/13/00
  264.         W97M.Thus              to W97M.Thus.Variant       03/13/00
  265.         W97M.THUS.J            to W97M.THUS.M             03/13/00
  266.         W97M.Thus.L            to W97M.Thus.P             03/13/00
  267.         W97M.THUS.M            to W97M.THUS.J             03/13/00
  268.         W97M.Titch             to W97M.Titch.D            03/13/00
  269.         W97M.Wrench.A          to W97M.Wrench.C           03/13/00
  270.         X97M.Shan              to X97M.Jini.intd          03/13/00
  271.         X97M.Tegrat.A          to X97M.Tracker            04/03/00
  272.  
  273. Deletions:
  274.  
  275.         Virus Name                Infection Type          Date removed
  276.         ----------                --------------          ------------
  277.         Istanbul.1349             File infector           03/13/00
  278.         WuChing.Boot.Dropper      Boot infector           03/06/00
  279.  
  280. **********************************************************************
  281. **    Enabling Scanning Features                            **
  282. **********************************************************************
  283.  
  284. Several scanning features can be enabled through the use of an INF 
  285. configuration file.  For NAV for Windows 95/NT version 4.x and later, 
  286. or NAV for OS/2, this configuration file should be called NAVEX15.INF
  287. and should be placed in the directory where NAV is installed (i.e.,
  288. C:\Program Files\Norton AntiVirus).  For NAV for Netware version 4.x,
  289. the file should be called NAVEX15.INF and should be placed in the 
  290. directory where NAV 4.x is installed (i.e., sys:system\navnlm). For
  291. NAV for Windows 95/NT version 2.0, NAV 4.x for Windows 3.1/DOS,
  292. NAVIEG 1.x, or NAVFW 1.x, the file should be named NAVEX.INF and
  293. should be placed in the directory where NAV is installed (i.e., C:\NAV).
  294. If this configuration file does not exist, create one in the appropriate
  295. directory if you want to change the default settings.
  296.  
  297. To enable a scanning feature for a particular component, one or more 
  298. entries need to be added to the configuration file under the correct
  299. section.  For each platform there is a corresponding section that is used 
  300. in the INF file.  Below is a table of section names and platforms.
  301.  
  302. Section Name    Platform
  303. ------------    --------
  304. NAVW32          Windows 95/98/NT
  305. NAVAP           Windows 95/98/NT Auto-Protect
  306. NAVDX           DOS
  307. NAVNLM          Netware
  308. NAVWIN          Windows 3.1
  309. NAVOS2          OS/2
  310. NAVAIX          AIX
  311. NAVSOL          Solaris
  312.  
  313. Entries are case insensitive.  Below is a description of possible 
  314. entries.
  315.  
  316. 1. Files can be excluded from scans by the NAVEX engine.  To exclude a
  317. specific file from the NAVEX engine scan, add an entry with the full
  318. path and file name.  This is case insensitive.  No wildcards are allowed.
  319. To exclude multiple files, add a separate entry for each file.  To exclude
  320. a file, add an entry like the one below where <PATH> is the full path
  321. and file name.
  322.         ExcludeFile = <PATH>
  323.  
  324. 2. Files within a directory can be excluded from scans by the NAVEX engine.
  325. To exclude all files within a directory, add an entry with the full 
  326. directory path.  This is case insensitive.  No wildcards are allowed.  This
  327. does not exclude files located in subdirectories of the specified 
  328. directory.  To exclude multiple directories, add a separate entry for each
  329. directory. To exclude a directory, add an entry like the one below where
  330. <DIRECTORY> is the full path.
  331.         ExcludeDirectory = <DIRECTORY>
  332.  
  333. The following example of an INF configuration file excludes two files, 
  334. NOSCAN.EXE and BIGFILE.DOC, from NAVEX scans for the Windows 95/98/NT 
  335. scanner.  It excludes the D:\PRIVATE directory from Windows 95/98/NT 
  336. Auto-Protect.
  337.  
  338. [NAVW32]
  339. ExcludeFile = C:\PROGRAM FILES\NOSCAN.EXE
  340. ExcludeFile = C:\TEMP\BIGFILE.DOC
  341.  
  342. [NAVAP]
  343. ExcludeDirectory = D:\PRIVATE
  344.  
  345. **********************************************************************
  346. **    Additional Information                        **
  347. **********************************************************************
  348.  
  349. Additional information regarding this virus definitions update can be
  350. found in UPDATE.TXT and TECHNOTE.TXT.
  351.