home *** CD-ROM | disk | FTP | other *** search
- **********************************************************************
- ** **
- ** What's New in the NAV Virus Definitions Files WHATSNEW.TXT **
- ** **
- ** Symantec AntiVirus Research Center (SARC) May 10, 1999 **
- ** **
- **********************************************************************
- This document contains the following topics:
-
- * Virus Alerts
- * New Technologies
- * Changes Incorporated Into This Update
- * Enabling/Disabling PowerPoint Scanning
- * Additional Information
-
- **********************************************************************
- ** Virus Alerts **
- **********************************************************************
- The fifteen most commonly reported viruses, worldwide:
-
- 1 XM.Laroux
- 2 WM.Concept
- 3 XM.Extra
- 4 WM.Cap
- 5 W97M.Class
- 6 WM.CopyCap
- 7 NYB
- 8 AntiCMOS.A
- 9 Stealth_Boot.B
- 10 W95.CIH
- 11 XF.Paix
- 12 Stoned.Empire.Monk
- 13 AntiExe
- 14 Form.A
- 15 WM.Wazzu
-
- **********************************************************************
- ** New Technologies **
- **********************************************************************
-
- DATE Technologies Added
- ---- ------------------
- 8/19/98 * Excel heuristics which detect and repair new and unknown
- macro viruses in Excel 95 & 97 documents.
-
- 9/16/98 * Added repair for encrypted Excel 97 documents.
-
- 10/21/98 * Heuristics to detect AOL Password Stealer Trojans.
- * WORD Heuristics improvement to increase detection rate.
-
- 12/17/98 * Macro Exclusion Engine to speed up the scanning for Word
- and Excel documents.
- * PowerPoint engine to scan PowerPoint related viruses.
- To enable this technology please read "Enabling/Disabling
- PowerPoint Scanning" section later in this document.
-
- 02/18/99 * Detection and repair of macro viruses in Word and Excel
- 2000 documents.
-
- **********************************************************************
- ** Changes Incorporated Into This Virus Definitions Update **
- **********************************************************************
- New virus definitions:
-
- Virus Name Infection Type Week added
- ---------- -------------- ----------
- ANTICOM.8535 File infector 04/26/99
- AntiPascal.583 File infector 04/19/99
- AntiPascal.653 File infector 04/19/99
- ARCV.1060 (1) File infector 04/08/99
- ARCV.1060 (2) File infector 04/08/99
- ARCV.1060 (x) File infector 04/08/99
- ARCV.1060.Dropper File infector 04/08/99
- AWME.1206 File infector 04/26/99
- Bel.2124 File infector 04/26/99
- Bleem.Trojan File infector 04/08/99
- Bloodhound.NeuralBoot Boot infector 04/08/99
- Bloodhound.NeuralMBR Boot infector 04/08/99
- BO.Speakeasy.DLL File infector 04/19/99
- BO.Speakeasy.DLL (2) File infector 04/19/99
- BO.Speakeasy.DLL (3) File infector 04/19/99
- Bolero.1039 File infector 04/19/99
- Bootache.2048 File infector 04/26/99
- Bupt.C (b) Boot infector 04/19/99
- Burglar.1365 (1) File infector 04/19/99
- Burglar.1365 (2) File infector 04/19/99
- Camilo.dd.378 File infector 05/03/99
- Carbuncle.621 File infector 04/26/99
- Carbuncle.621 (2) File infector 04/26/99
- Carbuncle.621 (3) File infector 04/26/99
- Carbuncle.621 (4) File infector 04/26/99
- DarkCowboy.2484 File infector 04/08/99
- DarkCowboy.2484 (2) File infector 04/08/99
- DarkCowboy.2484 E (2) File infector 04/19/99
- DarkCowboy.2484 EXE File infector 04/19/99
- Dikshev.119 File infector 04/19/99
- Dreg-Based File infector 04/19/99
- Erdem.421 File infector 04/26/99
- ExeHeader.Cluster.277 File infector 04/19/99
- Extrano.6702 File infector 04/26/99
- Extrano.6702 (2) File infector 04/26/99
- Fair.2102 (1) File infector 04/19/99
- Fair.2102 (2) File infector 04/19/99
- Fair.2102 (x) File infector 04/19/99
- Fairz.1936 File infector 04/19/99
- Fairz.1936 (x) File infector 04/19/99
- Fp5.2000 File infector 04/26/99
- Helloween.1377 File infector 04/19/99
- HLLC.6052 (1) File infector 04/08/99
- HLLC.6052 (2) File infector 04/08/99
- HLLC.7200 File infector 04/19/99
- HLLC.7200 (2) File infector 04/19/99
- HLLC.DosInfo.52480 File infector 04/19/99
- HLLC.URI.39196 File infector 04/19/99
- HLLO.7808 File infector 04/19/99
- HLLO.7808 (2) File infector 04/19/99
- HLLO.Julius.40932 File infector 04/19/99
- HLLO.Julius.40932 (2) File infector 04/19/99
- HLLO.Julius.40932 (3) File infector 04/19/99
- HLLO.Killer.17179 File infector 04/19/99
- HLLO.Killer.17179 (2) File infector 04/19/99
- HLLO.Killer.17179 (3) File infector 04/19/99
- HLLP.5000 File infector 04/26/99
- HLLP.5000 (2) File infector 04/26/99
- HLLP.5400 File infector 04/26/99
- HLLP.5400 (2) File infector 04/26/99
- HLLP.5968 File infector 04/19/99
- HLLP.5968 (2) File infector 04/19/99
- HLLP.8308 File infector 04/19/99
- HLLP.8308 (1) File infector 04/19/99
- HLLP.8308 (Gen1) File infector 04/19/99
- HLLP.Banshee.4349 File infector 04/19/99
- HLLP.Banshee.4349 (2) File infector 04/19/99
- HLLP.Bishkek.4160 File infector 04/26/99
- HLLP.Bishkek.4160 (2) File infector 04/26/99
- HLLP.Bishkek.4170 File infector 04/26/99
- HLLP.Bishkek.4170 (2) File infector 04/26/99
- HLLP.Bishkek.4240 File infector 04/26/99
- HLLP.Bishkek.4240 (2) File infector 04/26/99
- HLLP.Bob.10752 File infector 04/26/99
- HLLP.Bob.10752 (2) File infector 04/26/99
- HLLP.Brian.4933 File infector 04/19/99
- HLLP.Brian.4933 (2) File infector 04/19/99
- HLLP.Buka.6998 File infector 04/26/99
- HLLP.Buka.6998 (2) File infector 04/26/99
- HLLP.Buka.6998 (3) File infector 04/26/99
- HLLP.Grab.5728 File infector 04/19/99
- HLLP.Grab.5728 (2) File infector 04/19/99
- HLLP.HTC File infector 04/19/99
- HLLP.HTC (2) File infector 04/19/99
- HLLP.Inna.6640.A File infector 04/26/99
- HLLP.Inna.6640.A (2) File infector 04/26/99
- HLLP.Inna.6640.C File infector 04/26/99
- HLLP.Inna.6640.C (2) File infector 04/26/99
- HLLP.Kasienka File infector 05/03/99
- HLLP.Kasienka (2) File infector 05/03/99
- HLLP.Kobr.9488 File infector 04/19/99
- HLLP.Kobr.9488 (2) File infector 04/19/99
- HLLP.Kornik.5658a File infector 04/19/99
- HLLP.Kornik.5658a (2) File infector 04/19/99
- HLLP.Kornik.5658a (3) File infector 04/19/99
- HLLP.KRILE.5776 File infector 04/26/99
- HLLP.KRILE.5776(2) File infector 04/26/99
- HLLP.Light.4917a File infector 04/19/99
- HLLP.Light.4917a (2) File infector 04/19/99
- HLLP.Light.4917a (3) File infector 04/19/99
- HLLP.Lithua File infector 05/03/99
- HLLP.Lithua (2) File infector 05/03/99
- HLLP.Nazi.8000.B File infector 04/26/99
- HLLP.Nazi.8000.B (2) File infector 04/26/99
- HLLP.PPZ.7864 File infector 04/26/99
- HLLP.PPZ.7864 (2) File infector 04/26/99
- HLLP.PPZ.8516 File infector 04/26/99
- HLLP.PPZ.8516 (2) File infector 04/26/99
- HLLP.PPZ.8516 (u) File infector 04/26/99
- HLLP.PPZ.8516 (u2) File infector 04/26/99
- HLLP.Rangel.5000 File infector 04/19/99
- HLLP.Rangel.5000 (2) File infector 04/19/99
- HLLP.Rangel.5000 (3) File infector 04/19/99
- HLLP.Renia.6253 File infector 04/19/99
- HLLP.Renia.6253 (2) File infector 04/19/99
- HLLP.Renia.6253 (3) File infector 04/19/99
- HLLP.Romeo.5248 File infector 04/19/99
- HLLP.Romeo.5248 (2) File infector 04/19/99
- HLLP.Sabot.41961 (2) File infector 04/26/99
- HLLP.Saboteur.41961 File infector 04/26/99
- HLLP.Slonik.9787 File infector 04/26/99
- HLLP.Slonik.9787 (2) File infector 04/26/99
- HLLP.Taras.4884 File infector 04/26/99
- HLLP.Taras.4884 (2) File infector 04/26/99
- HLLP.Taras.5046 File infector 04/26/99
- HLLP.Taras.5046 (2) File infector 04/26/99
- HLLP.UX142.7200 File infector 04/26/99
- HLLP.UX142.7200 (2) File infector 04/26/99
- I13.Camilo.247 File infector 04/26/99
- I13.Camilo.380 File infector 04/26/99
- I13.Litera.2126 File infector 04/26/99
- I13.Tolkien (b) Boot infector 04/26/99
- IMMUNE.536 (1) File infector 04/19/99
- IMMUNE.536 (2) File infector 04/19/99
- Implant.6144 File infector 04/26/99
- Implant.6144 (x) File infector 04/26/99
- Implant.6200 File infector 04/26/99
- Implant.6200 (x) File infector 04/26/99
- IOS.1290 File infector 04/19/99
- Jacky.1107 (Gen1) File infector 05/10/99
- Jam.1295 File infector 04/19/99
- Jerkin.333 File infector 04/08/99
- Jeru.Tarapa.B (1) File infector 04/08/99
- Jeru.Tarapa.B (2) File infector 04/08/99
- Jeru.Tarapa.B (x1) File infector 04/08/99
- Jeru.Tarapa.B (x2) File infector 04/08/99
- Keypress.1522 (x) File infector 04/26/99
- KSENIA.3599 File infector 04/26/99
- leo.328 File infector 04/08/99
- leo.328 (2) File infector 04/08/99
- LHA.dmb File infector 04/19/99
- LHA.dmb (1) File infector 04/19/99
- Lizard.5150 (VXD) File infector 04/08/99
- Lizard.5150 (VXD) (2) File infector 04/08/99
- LUCE.3600 File infector 04/08/99
- Lucifer.Boot Boot infector 04/19/99
- Lung.mp.2589 (b) File and Boot infector 04/19/99
- Marina.902 File infector 04/19/99
- Markiz.1560 File infector 04/26/99
- Mini (COM) File infector 04/26/99
- Mini.B File infector 04/26/99
- Monday.Worm File infector 04/19/99
- Monday.Worm (2) File infector 04/19/99
- Monday.Worm (3) File infector 04/19/99
- Naff.821 File infector 04/26/99
- Natas.4826 (b) Boot infector 04/26/99
- NetBus v2.0 File infector 04/26/99
- NetBus v2.0 (2) File infector 04/26/99
- NetBus v2.0 (3) File infector 04/26/99
- Nuke.Howard.Dropper File infector 04/08/99
- Nuke.Marauder.Dropper File infector 04/08/99
- O97M.Shiver.E File infector 04/19/99
- O97M.Shiver.F File infector 04/19/99
- OBJ.150 File infector 04/26/99
- Opic.1712 (2) File infector 04/19/99
- Orifice.Addon.Trojan File infector 04/08/99
- Poful.5392 File infector 04/19/99
- Poful.5392 (2) File infector 04/19/99
- Poful.5392 (3) File infector 04/19/99
- Poful.5392 (4) File infector 04/19/99
- Poful.5392 (5) File infector 04/19/99
- PresidentB.1504 File infector 04/19/99
- Pusher.374 File infector 04/26/99
- Senda.4162 File and Boot infector 05/10/99
- Senda.4162 (b) File and Boot infector 05/10/99
- Senda.4162 (m) File and Boot infector 05/10/99
- SillyBP.1f81 (b) Boot infector 04/19/99
- SILLYC.110.B File infector 04/26/99
- SILLYC.834 File infector 04/26/99
- SILLYC.Overwriter File infector 04/26/99
- SillyOC.247.A File infector 04/26/99
- SillyOC.247.C File infector 04/26/99
- SillyOrce.132 File infector 04/26/99
- Simple.IncorrectDOS File infector 04/08/99
- Simple.Nazareth File infector 05/03/99
- Small.104.b File infector 04/08/99
- Sysm.348 File infector 04/26/99
- Taek.2119 File infector 04/26/99
- Taipan.438.C File infector 04/19/99
- Tiny.273 File infector 04/08/99
- Tiny.273 (2) File infector 04/08/99
- TPK.Anti-Stoned (b) Boot infector 04/19/99
- Treb.1426 File infector 04/26/99
- Trial.768 File infector 04/26/99
- Trivial.77 File infector 04/08/99
- Trojan Generator File infector 04/19/99
- Trojan_21653 File infector 04/26/99
- V.1061 File infector 04/19/99
- V.544 File infector 04/08/99
- V.768.B File infector 04/19/99
- Vien.623 (2) File infector 04/08/99
- Voodoo.3081 File infector 04/26/99
- Voodoo.3081 (2) File infector 04/26/99
- Voodoo.3081 (3) File infector 04/26/99
- W31.NEHeader File infector 04/26/99
- W32.Apathy File infector 04/08/99
- W32.Heretic File infector 04/08/99
- W32.Heretic (DLL) File infector 04/08/99
- W32.Heretic (DLL) (2) File infector 04/08/99
- W32.Heretic (DLL) (3) File infector 04/08/99
- W32.Idyllwild File infector 04/08/99
- W32.Maya File infector 04/08/99
- W32.Redemption File infector 04/08/99
- W32.VB File infector 04/08/99
- W95.Apparition File infector 05/10/99
- W95.CrazyPunk File infector 04/26/99
- W95.CrazyPunk (2) File infector 04/26/99
- W95.Emotion File infector 05/10/99
- W95.Emotion (2) File infector 05/10/99
- W95.Fono (b) File and Boot infector 04/08/99
- W95.Giri File infector 05/10/99
- W95.HPS (Gen1) File infector 05/03/99
- W95.HPS (Gen1) (2) File infector 05/03/99
- W95.Levi File infector 05/10/99
- W95.Lud.Jadis File infector 04/08/99
- W95.Lud.Jez File infector 05/10/99
- W95.Mad.2736 File infector 04/08/99
- W95.Murky.390 File infector 04/08/99
- W95.Powerful File infector 05/10/99
- W95.Regswap File infector 04/08/99
- W95.Tentacle.2048 File infector 05/10/99
- W95.Twinny File infector 04/08/99
- W95.Uwaga File infector 04/08/99
- W95.Voodoo File infector 05/10/99
- W95.Yabran File infector 04/26/99
- W95.Yabran (Gen1) File infector 05/10/99
- W95.Zerg File infector 04/26/99
- W97M.APMRS File infector 04/26/99
- W97M.Astia.D File infector 04/19/99
- W97M.Caligula.B File infector 04/26/99
- W97M.Carrier.C File infector 04/26/99
- W97M.Carrier.E File infector 04/26/99
- W97M.Carrier.F File infector 04/26/99
- W97M.Colombia.A File infector 04/26/99
- W97M.Counter.D File infector 04/08/99
- W97M.DWMVCK1.H File infector 04/19/99
- W97M.IIS.E File infector 04/26/99
- W97M.ITSC File infector 04/19/99
- W97M.Joy File infector 04/08/99
- W97M.Model File infector 04/19/99
- W97M.Nail File infector 04/08/99
- W97M.NewHope.A:TW File infector 04/08/99
- W97M.Nottice.Family File infector 05/03/99
- W97M.NSI.A File infector 05/10/99
- W97M.Opey.C File infector 04/19/99
- W97M.Opey.Variant File infector 04/26/99
- W97M.Parasit File infector 04/26/99
- W97M.SWLABS.AB File infector 04/08/99
- W97M.Swlabs.V File infector 04/08/99
- W97M.UCK.C File infector 04/26/99
- W97M.Uscam.A File infector 04/26/99
- W97M.VMPCK1.BJ File infector 05/03/99
- W97M.VMPCK1.HOB99 File infector 04/26/99
- W97M.VMPCK1.MANUELA File infector 04/26/99
- W97M.VMPCK1.PERFECT File infector 04/26/99
- W97M.VP.A File infector 04/19/99
- Win.Padania File infector 05/10/99
- WM.CRIstall File infector 04/26/99
- WM.Decept (Damaged) File infector 05/03/99
- WM.Errorsoft.A File infector 04/26/99
- WM.External.Update File infector 04/08/99
- WM.Giant.A File infector 04/26/99
- WM.K302.A File infector 04/26/99
- WM.Minimal.SendKeys File infector 04/08/99
- WM.MVG.A File infector 04/26/99
- WM.Over.A File infector 04/26/99
- WM.UCK.A File infector 04/26/99
- WM.UCK.B File infector 04/26/99
- X97M.Laroux.IU File infector 04/26/99
- X97M.VCX.E File infector 05/10/99
- XM.Bulet File infector 04/08/99
- XM.GTHOMSNZ File infector 04/08/99
- YELET.2098 File infector 04/19/99
- Zamol.4358 (b) Boot infector 04/19/99
- ZhengZhou.3576.A (b) Boot infector 04/26/99
- Zombie.747 File infector 04/26/99
- Zombie.747(2) File infector 04/26/99
- ZY[X].3474 File infector 05/10/99
- ZY[X].3474 (2) File infector 05/10/99
- ZY[X].3474 (SYS) File infector 05/10/99
-
- Name Changes:
-
- Old Virus Name New Virus Name Date changed
- -------------- -------------- ------------
- DarkCowboy.2484 to DarkCowboy.2484 COM 04/19/99
- DarkCowboy.2484 (2) to DarkCowboy.2484 C (2) 04/19/99
- Howard to Nuke.Howard.967 04/08/99
- Marauder.860.B to Nuke.Marauder.860 04/08/99
- P3IDthief.Trojan to P3IDthief.Trojan.Demo 05/03/99
- Tentacle to W95.Tentacle.1958 05/03/99
- Vien.622 to Vien.622 (1) 04/08/99
- Vien.623 (2) to Vien.622 (2) 04/08/99
- W95.Marburg.B to W95.Marburg 04/08/99
- W97M.Melissa.Intended to W97M.Melissa.Variant 04/26/99
- Werewolf.1367 to Werewolf.1361.B 05/10/99
- Werewolf.1367 (2) to Werewolf.1361 (2) 05/10/99
- Werewolf.1367 (3) to Werewolf.1361 (3) 05/10/99
-
- Deletions:
-
- Virus Name Infection Type Date removed
- ---------- -------------- ------------
- ARCV.X-3B File infector 04/08/99
- Helloween.1377 File infector 04/19/99
- HLL.Kasienka File infector 05/03/99
- HLL.Kasienka (2) File infector 05/03/99
- HLLO.7808 File infector 04/08/99
- Toys.Companion.5000 File infector 04/26/99
- Toys.Companion.5000(2) File infector 04/26/99
-
- **********************************************************************
- ** Enabling/Disabling PowerPoint Scanning **
- **********************************************************************
- PowerPoint Scanning is now enabled by default and can be optionally
- disabled. However, you may want to verify that files with
- PowerPoint extensions will be scanned by making sure that your
- NAV options have both ".PPT" and ".POT" in the list of extensions
- to scan.
-
- To disable PowerPoint scanning in NAV for Windows 95/NT
- version 4.x or NAV for OS/2, a text file named NAVEX15.INF should
- be placed in the directory where NAV 4.x or NAV 5.x is installed
- (i.e., C:\Program Files\Norton AntiVirus).
-
- To disable PowerPoint scanning in NAV for Netware version 4.x, a text
- file named NAVEX15.INF should be placed in the directory where NAV
- 4.x is installed (i.e., sys:system\navnlm).
-
- To disable PowerPoint scanning in NAV for Windows 95/NT version 2.0,
- NAV 4.x for Windows 3.1/DOS, NAVIEG 1.x, or NAVFW 1.x a text file
- named NAVEX.INF should be placed in the directory where NAV is
- installed (i.e., C:\NAV).
-
- The contents of the text file, NAVEX15.INF or NAVEX.INF, determine
- which components of NAV have PowerPoint scanning disabled.
-
- To disable PowerPoint scanning for a particular component, use the
- following table to determine the lines to add to the text file.
- PowerPoint scanning can be disabled for more than one component if
- needed by adding the required lines for the desired components.
-
- +---------------------+--------------------------+--------------------+
- |Windows 95/NT scanner|Windows 95/NT auto-protect|DOS scanner |
- +---------------------+--------------------------+--------------------+
- |[NAVW32] |[NAVAP] |[NAVDX] |
- |PowerPointScanning=0 |PowerPointScanning=0 |PowerPointScanning=0|
- +---------------------+--------------------------+--------------------+
-
- +----------------------+--------------------+--------------------+
- |Windows 3.1 scanner/AP|Netware scanner |OS/2 scanner/AP |
- +----------------------+--------------------+--------------------+
- |[NAVWIN] |[NAVNLM] |[NAVOS2] |
- |PowerPointScanning=0 |PowerPointScanning=0|PowerPointScanning=0|
- +----------------------+--------------------+--------------------+
-
- To enable PowerPoint scanning for a component, delete the lines
- added for that component from the NAVEX15.INF or NAVEX.INF file.
-
- **********************************************************************
- ** Additional Information **
- **********************************************************************
- SARC has equipped Norton AntiVirus with a new feature called
- "Infestation Mode." If a large number of new or unknown viruses
- is found on the system during a scan, Norton AntiVirus will
- automatically enable its highest level of detection. This gives
- users the most comprehensive protection in cases where a viral
- infestation may have been detected. If you would like to disable
- this feature, you can do so by following these instructions:
-
- 1. Create a text File called NAVEX15.INF in your Norton AntiVirus
- directory,e.g., C:\Program Files\Norton AntiVirus. If this file
- already exist go to step two.
-
- 2. Place the following lines in this File on the left-hand margin:
-
- [NAVW32]
- infestmode=0
-
- [NAVDX]
- infestmode=0
-
- 3. Save the File.
-
-
- Additional information regarding this virus definitions update can be
- found in UPDATE.TXT and TECHNOTE.TXT.
-