home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
PC World 1999 July
/
PCWorld_1999-07_cd.bin
/
software
/
Antiviry
/
nav16
/
0607i16.exe
/
WHATSNEW.TXT
< prev
Wrap
Text File
|
1999-06-07
|
22KB
|
374 lines
**********************************************************************
** **
** What's New in the NAV Virus Definitions Files WHATSNEW.TXT **
** **
** Symantec AntiVirus Research Center (SARC) June 7, 1999 **
** **
**********************************************************************
This document contains the following topics:
* Virus Alerts
* New Technologies
* Changes Incorporated Into This Update
* Enabling/Disabling PowerPoint Scanning
* Additional Information
**********************************************************************
** Virus Alerts **
**********************************************************************
The ten most commonly reported viruses, worldwide:
1 W97M.Class
2 XM.Laroux
3 O97M.Trisate
4 W95.CIH
5 Happy99.Worm
6 WM.Cap
7 W97M.ColdApe
8 W97M.Ethan
9 W97M.Marker
10 W97M.Melissa
**********************************************************************
** New Technologies **
**********************************************************************
DATE Technologies Added
---- ------------------
8/19/98 * Excel heuristics which detect and repair new and unknown
macro viruses in Excel 95 & 97 documents.
9/16/98 * Added repair for encrypted Excel 97 documents.
10/21/98 * Heuristics to detect AOL Password Stealer Trojans.
* WORD Heuristics improvement to increase detection rate.
12/17/98 * Macro Exclusion Engine to speed up the scanning for Word
and Excel documents.
* PowerPoint engine to scan PowerPoint related viruses.
To enable this technology please read "Enabling/Disabling
PowerPoint Scanning" section later in this document.
02/18/99 * Detection and repair of macro viruses in Word and Excel
2000 documents.
05/12/99 * Added repair for PowerPoint viruses.
* Improved heuristics to detect more WORD 97 related
viruses.
**********************************************************************
** Changes Incorporated Into This Virus Definitions Update **
**********************************************************************
New virus definitions:
Virus Name Infection Type Week added
---------- -------------- ----------
AOL Trojan 1 File infector 06/07/99
AOL Trojan 2 File infector 06/07/99
AOL Trojan 3 File infector 06/07/99
AOL Trojan 4 File infector 06/07/99
AOL Trojan 5 File infector 06/07/99
AOL Trojan 6 File infector 06/07/99
AOL Trojan 7 File infector 06/07/99
AOL Trojan 8 File infector 06/07/99
AOL Trojan 9 File infector 06/07/99
AOL Trojan Buddy File infector 06/07/99
AOL Trojan Buddy 2 File infector 06/07/99
AOL Trojan Buddy 3 File infector 06/07/99
AOL Trojan Winsyst File infector 06/07/99
AOL Trojan Winsyst 2 File infector 06/07/99
AOL Trojan Winsyst 3 File infector 06/07/99
Backdoor.SubSeven File infector 06/07/99
BackdoorG-DLL.Trojan File infector 06/07/99
BAT.Bingo.1963 File infector 05/12/99
BAT.Combat.736 File infector 05/12/99
BAT.Combat.737 File infector 05/12/99
BAT.FRET.1023 File infector 05/12/99
BAT.GRUNCH.1189 File infector 05/12/99
BAT.HIGHJAQ.1400 File infector 05/12/99
BAT.HOLOCAST.1362 File infector 05/12/99
BAT.HOLOCAST.1655 File infector 05/12/99
BAT.MDMA.990 File infector 05/12/99
Bloodhound.Hybrid File infector 05/12/99
Boza.D File infector 05/12/99
Camilo.dd.378 File infector 05/03/99
Companion.Friendb.330 File infector 06/01/99
CS.Galadriel File infector 05/12/99
CS.Galadriel (2) File infector 05/12/99
CS.Galadriel (3) File infector 05/12/99
DBO-3 (b) Boot infector 06/01/99
Derwolf.2219 File infector 06/01/99
Derwolf.2219 (2) File infector 06/01/99
Devcon.8824 File infector 05/12/99
Djifx.2372 File infector 05/24/99
Elsa.857 File infector 05/24/99
Emperor File and Boot infector 06/01/99
EXEHDR.BANE.256.C File infector 05/12/99
EXEHDR.CLUST.384.C File infector 05/12/99
EXEHDR.EM.250 File infector 05/12/99
FCL.2044 File infector 06/07/99
FCL.2044 (2) File infector 06/07/99
FCL.2044 (3) File infector 06/07/99
Goma.1002 File infector 06/01/99
Goma.743 File infector 06/01/99
HLLC.4480 File infector 05/24/99
HLLC.4480 (2) File infector 05/24/99
HLLC.4528 File infector 06/07/99
HLLC.4528(2) File infector 06/07/99
HLLC.4544 File infector 05/24/99
HLLC.4544 (2) File infector 05/24/99
HLLO.4317.B File infector 05/12/99
HLLO.C-VIRUS.4601 File infector 05/12/99
HLLO.C-VIRUS.5924 File infector 05/12/99
HLLO.Maniac.5946 File infector 06/01/99
HLLO.Maniac.5946 (2) File infector 06/01/99
HLLP.5192 File infector 06/07/99
HLLP.5192(2) File infector 06/07/99
HLLP.9700 File infector 05/24/99
HLLP.9700 (2) File infector 05/24/99
HLLP.9700 (3) File infector 05/24/99
HLLP.DThought.13120 File infector 05/24/99
HLLP.DThought.13120.B File infector 05/24/99
HLLP.GROSSER File infector 05/24/99
HLLP.GROSSER (2) File infector 05/24/99
HLLP.Kasienka File infector 05/03/99
HLLP.Kasienka (2) File infector 05/03/99
HLLP.Krile.5017 File infector 05/24/99
HLLP.Lithua File infector 05/03/99
HLLP.Lithua (2) File infector 05/03/99
HLLT.Krile.5017 File infector 05/24/99
HLLW.8560 File infector 06/07/99
HLLW.8560(2) File infector 06/07/99
Istanbul.1385 File infector 06/01/99
Istanbul.1385 (x) File infector 06/01/99
Jacky.1107 (Gen1) File infector 05/10/99
Jags.394 File infector 06/01/99
JAP_HAL (b) Boot infector 06/01/99
K2PS.Trojan File infector 05/12/99
KID.256 File infector 05/12/99
KuSuMah.3967 File infector 06/01/99
KuSuMah.4268 (x) File infector 06/01/99
Lazarus.2222 File infector 06/01/99
Lilith(2) Boot infector 05/12/99
Lucky.487 File infector 05/24/99
Magichole.512 File infector 06/01/99
Mahon.1372 File infector 06/01/99
Moloch(2) Boot infector 05/12/99
Nephew.3758 File infector 06/01/99
Nephew.3758 (2) File infector 06/01/99
Nephew.3758 (x) File infector 06/01/99
Nephew.3758 (x2) File infector 06/01/99
Netbus 2.01 Trojan 1 File infector 06/07/99
Netbus 2.01 Trojan 10 File infector 06/07/99
Netbus 2.01 Trojan 11 File infector 06/07/99
Netbus 2.01 Trojan 12 File infector 06/07/99
Netbus 2.01 Trojan 13 File infector 06/07/99
Netbus 2.01 Trojan 14 File infector 06/07/99
Netbus 2.01 Trojan 15 File infector 06/07/99
Netbus 2.01 Trojan 2 File infector 06/07/99
Netbus 2.01 Trojan 3 File infector 06/07/99
Netbus 2.01 Trojan 4 File infector 06/07/99
Netbus 2.01 Trojan 5 File infector 06/07/99
Netbus 2.01 Trojan 6 File infector 06/07/99
Netbus 2.01 Trojan 7 File infector 06/07/99
Netbus 2.01 Trojan 8 File infector 06/07/99
Netbus 2.01 Trojan 9 File infector 06/07/99
Nipple.823 File infector 06/01/99
Nipple.823 (2) File infector 06/01/99
PrettyPark.Worm File infector 06/07/99
PS-MPC.Mudshark File infector 06/07/99
PVW (Gen1) File infector 05/24/99
Reizfaktor (Bat) File infector 06/01/99
Reizfaktor (inf) File infector 06/01/99
Reizfaktor (inf2) File infector 06/01/99
Retro.852 File infector 05/24/99
Retro.974 File infector 06/01/99
Retro.974 (2) File infector 06/01/99
Retro.974 (3) File infector 06/01/99
Senda.4162 File and Boot infector 05/10/99
Senda.4162 (b) File and Boot infector 05/10/99
Senda.4162 (m) File and Boot infector 05/10/99
SillyC.315 File infector 05/24/99
SillyC.352 File infector 05/24/99
SillyC.999 File infector 05/24/99
SillyC.999 (Gen1) File infector 05/24/99
SILLYOC.106.A File infector 05/12/99
SILLYOC.186.B2 File infector 05/12/99
SillyOE.Scorn File infector 05/24/99
Simple.Nazareth File infector 05/03/99
SP1 Basic.Trojan File infector 06/01/99
SP1 Basic.Trojan (2) File infector 06/01/99
Trivial.123.b File infector 05/24/99
Trivial.60.E File infector 05/24/99
Trivial.60.F File infector 05/24/99
Trivial.84.b File infector 05/24/99
Troi.926 File infector 06/07/99
Troi.926 (2) File infector 06/07/99
Ugly.4893 File infector 05/12/99
VirDem.824 File infector 06/07/99
Viva.752 File infector 06/01/99
Vojager.512 File infector 05/24/99
W95.Apparition File infector 05/10/99
W95.Emotion File infector 05/10/99
W95.Emotion (2) File infector 05/10/99
W95.Enumiacs File infector 05/12/99
W95.Enumiacs (EXE) File infector 05/12/99
W95.Enumiacs (EXE) 2 File infector 05/12/99
W95.Enumiacs (EXE) 3 File infector 05/12/99
W95.Giri File infector 05/10/99
W95.Highway File infector 05/12/99
W95.Highway (DLL) File infector 05/12/99
W95.Highway (DLL) 2 File infector 05/12/99
W95.Highway (DLL) 3 File infector 05/12/99
W95.HPS (Gen1) File infector 05/03/99
W95.HPS (Gen1) (2) File infector 05/03/99
W95.Levi File infector 05/10/99
W95.Lud.Jez File infector 05/10/99
W95.Niko File infector 05/12/99
W95.Obsolete File infector 05/12/99
W95.Powerful File infector 05/10/99
W95.Ruff File infector 05/12/99
W95.Savior File infector 05/12/99
W95.Tentacle.2048 File infector 05/10/99
W95.Voodoo File infector 05/10/99
W95.Yabran (Gen1) File infector 05/10/99
W95.Zombie.B File infector 05/24/99
W97M.CopyTemp.intd File infector 06/01/99
W97M.Daydream.A File infector 06/01/99
W97M.Jedi.G File infector 05/24/99
W97M.MAMM.A File infector 05/12/99
W97M.MDMA.BV File infector 05/12/99
W97M.Mimir.A File infector 05/12/99
W97M.Nottice.Family File infector 05/03/99
W97M.No_va.D File infector 06/01/99
W97M.NSI.A File infector 05/10/99
W97M.Reizfaktor File infector 06/01/99
W97M.VMPCK1.BJ File infector 05/03/99
Win.Padania File infector 05/10/99
WM.Automat.H File infector 05/12/99
WM.Automat.Q File infector 05/24/99
WM.Decept (Damaged) File infector 05/03/99
WM.Mentes.E File infector 06/07/99
Worm.ExploreZip File infector 06/07/99
WuChing.Boot.Dropper Boot infector 06/01/99
X97M.Laroux.JF File infector 05/24/99
X97M.PTH File infector 05/24/99
X97M.VCX.E File infector 05/10/99
XM.Cpot.intd File infector 05/24/99
XM.Friend.B File infector 06/07/99
XM.Laroux.HQ File infector 06/01/99
XM.Laroux.HR File infector 06/07/99
Zohr.4160 File infector 06/01/99
Zorm.265 File infector 05/24/99
Zorm.573 File infector 06/01/99
ZY[X].3474 File infector 05/10/99
ZY[X].3474 (2) File infector 05/10/99
ZY[X].3474 (SYS) File infector 05/10/99
Name Changes:
Old Virus Name New Virus Name Date changed
-------------- -------------- ------------
Explore666.59932 to Explore666.59392 06/07/99
Explore666.59932(2) to Explore666.59392(2) 06/07/99
P3IDthief.Trojan to P3IDthief.Trojan.Demo 05/03/99
Tentacle to W95.Tentacle.1958 05/03/99
Werewolf.1367 to Werewolf.1361.B 05/10/99
Werewolf.1367 (2) to Werewolf.1361 (2) 05/10/99
Werewolf.1367 (3) to Werewolf.1361 (3) 05/10/99
Deletions:
Virus Name Infection Type Date removed
---------- -------------- ------------
Bupt.1279 File infector 06/01/99
Djifx.2372 File infector 05/12/99
FCL.2044 File infector 06/07/99
FCL.2044 (2) File infector 06/07/99
FCL.2044 (3) File infector 06/07/99
HLL.Kasienka File infector 05/03/99
HLL.Kasienka (2) File infector 05/03/99
JAP_HAL (b) Boot infector 06/07/99
November 17.768.B (x) File infector 06/07/99
PS-MPC.Mudshark File infector 06/01/99
PVW (Gen1) File infector 05/12/99
VirDem.824 File infector 06/01/99
WM.Automat.H File infector 05/24/99
**********************************************************************
** Enabling/Disabling PowerPoint Scanning **
**********************************************************************
PowerPoint Scanning is now enabled by default and can be optionally
disabled. However, you may want to verify that files with
PowerPoint extensions will be scanned by making sure that your
NAV options have both ".PPT" and ".POT" in the list of extensions
to scan.
To disable PowerPoint scanning in NAV for Windows 95/NT
version 4.x or NAV for OS/2, a text file named NAVEX15.INF should
be placed in the directory where NAV 4.x or NAV 5.x is installed
(i.e., C:\Program Files\Norton AntiVirus).
To disable PowerPoint scanning in NAV for Netware version 4.x, a text
file named NAVEX15.INF should be placed in the directory where NAV
4.x is installed (i.e., sys:system\navnlm).
To disable PowerPoint scanning in NAV for Windows 95/NT version 2.0,
NAV 4.x for Windows 3.1/DOS, NAVIEG 1.x, or NAVFW 1.x a text file
named NAVEX.INF should be placed in the directory where NAV is
installed (i.e., C:\NAV).
The contents of the text file, NAVEX15.INF or NAVEX.INF, determine
which components of NAV have PowerPoint scanning disabled.
To disable PowerPoint scanning for a particular component, use the
following table to determine the lines to add to the text file.
PowerPoint scanning can be disabled for more than one component if
needed by adding the required lines for the desired components.
+---------------------+--------------------------+--------------------+
|Windows 95/NT scanner|Windows 95/NT auto-protect|DOS scanner |
+---------------------+--------------------------+--------------------+
|[NAVW32] |[NAVAP] |[NAVDX] |
|PowerPointScanning=0 |PowerPointScanning=0 |PowerPointScanning=0|
+---------------------+--------------------------+--------------------+
+----------------------+--------------------+--------------------+
|Windows 3.1 scanner/AP|Netware scanner |OS/2 scanner/AP |
+----------------------+--------------------+--------------------+
|[NAVWIN] |[NAVNLM] |[NAVOS2] |
|PowerPointScanning=0 |PowerPointScanning=0|PowerPointScanning=0|
+----------------------+--------------------+--------------------+
To enable PowerPoint scanning for a component, delete the lines
added for that component from the NAVEX15.INF or NAVEX.INF file.
**********************************************************************
** Additional Information **
**********************************************************************
SARC has equipped Norton AntiVirus with a new feature called
"Infestation Mode." If a large number of new or unknown viruses
is found on the system during a scan, Norton AntiVirus will
automatically enable its highest level of detection. This gives
users the most comprehensive protection in cases where a viral
infestation may have been detected. If you would like to disable
this feature, you can do so by following these instructions:
1. Create a text File called NAVEX15.INF in your Norton AntiVirus
directory,e.g., C:\Program Files\Norton AntiVirus. If this file
already exist go to step two.
2. Place the following lines in this File on the left-hand margin:
[NAVW32]
infestmode=0
[NAVDX]
infestmode=0
3. Save the File.
Additional information regarding this virus definitions update can be
found in UPDATE.TXT and TECHNOTE.TXT.