home *** CD-ROM | disk | FTP | other *** search
/ PC World 1999 August / PCWorld_1999-08_cd.bin / Software / Antiviry / nav32 / 0707i32.exe / WHATSNEW.TXT < prev    next >
Text File  |  1999-07-07  |  26KB  |  433 lines

  1. **********************************************************************
  2. **                                                                  **
  3. **  What's New in the NAV Virus Definitions Files      WHATSNEW.TXT **
  4. **                                                                  **
  5. **  Symantec AntiVirus Research Center (SARC)          July 7, 1999 **
  6. **                                                                  **
  7. **********************************************************************
  8. This document contains the following topics:
  9.  
  10.  * Virus Alerts
  11.  * New Technologies
  12.  * Changes Incorporated Into This Update
  13.  * Enabling/Disabling PowerPoint Scanning
  14.  * Additional Information
  15.  
  16. **********************************************************************
  17. ** Virus Alerts                                                     **
  18. **********************************************************************
  19. The ten most commonly reported viruses, worldwide:
  20.  
  21.     1  W97M.Class
  22.     2  XM.Laroux
  23.     3  O97M.Tristate
  24.     4  W95.CIH
  25.     5  Happy99.Worm
  26.     6  WM.Cap
  27.     7  W97M.ColdApe
  28.     8  W97M.Ethan
  29.     9  W97M.Melissa
  30.    10  Worm.ExploreZip
  31.  
  32. **********************************************************************
  33. ** New Technologies                                                 **
  34. **********************************************************************
  35.  
  36. DATE         Technologies Added
  37. ----         ------------------
  38. 8/19/98    * Excel heuristics which detect and repair new and unknown
  39.              macro viruses in Excel 95 & 97 documents.
  40.  
  41. 9/16/98    * Added repair for encrypted Excel 97 documents.
  42.  
  43. 10/21/98   * Heuristics to detect AOL Password Stealer Trojans.
  44.            * WORD Heuristics improvement to increase detection rate.
  45.  
  46. 12/17/98   * Macro Exclusion Engine to speed up the scanning for Word
  47.              and Excel documents.
  48.            * PowerPoint engine to scan PowerPoint related viruses.
  49.              To enable this technology please read "Enabling/Disabling
  50.              PowerPoint Scanning" section later in this document.
  51.  
  52. 02/18/99   * Detection and repair of macro viruses in Word and Excel
  53.              2000 documents.
  54.  
  55. 05/12/99   * Added repair for PowerPoint viruses.
  56.            * Improved heuristics to detect more WORD 97 related
  57.              viruses.
  58.  
  59. 06/10/99   * Menu repair technology for WORD macro viruses that change
  60.              command bar customizations in NORMAL.DOT.
  61.  
  62. **********************************************************************
  63. ** Changes Incorporated Into This Virus Definitions Update            **
  64. **********************************************************************
  65. New virus definitions:
  66.  
  67.         Virus Name                Infection Type          Week added
  68.         ----------                --------------          ----------
  69.         Abbas.1100                File infector           06/10/99
  70.         Alladin.1827              File infector           06/28/99
  71.         AOD.385                   File infector           06/10/99
  72.         AOD.385 (2)               File infector           06/10/99
  73.         AOL Trojan 1              File infector           06/07/99
  74.         AOL Trojan 2              File infector           06/07/99
  75.         AOL Trojan 3              File infector           06/07/99
  76.         AOL Trojan 4              File infector           06/07/99
  77.         AOL Trojan 5              File infector           06/07/99
  78.         AOL Trojan 6              File infector           06/07/99
  79.         AOL Trojan 7              File infector           06/07/99
  80.         AOL Trojan 8              File infector           06/07/99
  81.         AOL Trojan 9              File infector           06/07/99
  82.         AOL Trojan Buddy          File infector           06/07/99
  83.         AOL Trojan Buddy 2        File infector           06/07/99
  84.         AOL Trojan Buddy 3        File infector           06/07/99
  85.         AOL Trojan Winsyst        File infector           06/07/99
  86.         AOL Trojan Winsyst 2      File infector           06/07/99
  87.         AOL Trojan Winsyst 3      File infector           06/07/99
  88.         AOL.PWSteal.32512         File infector           06/28/99
  89.         Appender.1210             File infector           06/21/99
  90.         Backdoor.SubSeven         File infector           06/07/99
  91.         BackdoorG-DLL.Trojan      File infector           06/07/99
  92.         Beast.B.Trojan            File infector           06/21/99
  93.         BIOS.Password.Trojan      File infector           06/21/99
  94.         Burglar.1150 (Gen1)       File infector           06/21/99
  95.         Burglar.1150 (Gen1) 2     File infector           06/21/99
  96.         Companion.Friendb.330     File infector           06/01/99
  97.         Crash.475                 File infector           06/28/99
  98.         DBO-3 (b)                 Boot infector           06/01/99
  99.         Derwolf.2219              File infector           06/01/99
  100.         Derwolf.2219 (2)          File infector           06/01/99
  101.         Dosinfo.Worm              File infector           07/02/99
  102.         Dosinfo.Worm 2            File infector           07/02/99
  103.         Emperor                   File and Boot infector  06/01/99
  104.         Fake Server Trojan        File infector           06/21/99
  105.         Fake Server Trojan 2      File infector           06/21/99
  106.         Fake Server Trojan 3      File infector           06/21/99
  107.         Fake Server Trojan 4      File infector           06/21/99
  108.         Fayte.494                 File infector           07/02/99
  109.         Fayte.494 (2)             File infector           07/02/99
  110.         FCL.2044                  File infector           06/07/99
  111.         FCL.2044 (2)              File infector           06/07/99
  112.         FCL.2044 (3)              File infector           06/07/99
  113.         Gene.454                  File infector           06/10/99
  114.         Gene.454                  File infector           06/28/99
  115.         Gift.1630                 File infector           06/28/99
  116.         Goma.1002                 File infector           06/01/99
  117.         Goma.743                  File infector           06/01/99
  118.         Hack Server Trojan        File infector           06/21/99
  119.         Hack Server Trojan 2      File infector           06/21/99
  120.         Hack Server Trojan 3      File infector           06/21/99
  121.         Hack Server Trojan 4      File infector           06/21/99
  122.         Hack Svr v1 Trojan        File infector           06/28/99
  123.         Hack Svr v1 Trojan 2      File infector           06/28/99
  124.         Hack Svr v1 Trojan 3      File infector           06/28/99
  125.         Hack Svr v1 Trojan 4      File infector           06/28/99
  126.         Hack v1.0 Trojan          File infector           06/28/99
  127.         Hack v1.0 Trojan 2        File infector           06/28/99
  128.         Hack v1.0 Trojan 3        File infector           06/28/99
  129.         Hack v1.0 Trojan 4        File infector           06/28/99
  130.         Hack v1.12 Trojan         File infector           06/21/99
  131.         Hack v1.12 Trojan 2       File infector           06/21/99
  132.         Hack v1.12 Trojan 3       File infector           06/21/99
  133.         Hack v1.12 Trojan 4       File infector           06/21/99
  134.         Hack'a'Tack Trojan        File infector           06/21/99
  135.         Hack'a'Tack Trojan 2      File infector           06/21/99
  136.         Hack'a'Tack Trojan 3      File infector           06/21/99
  137.         Hack'a'Tack Trojan 4      File infector           06/21/99
  138.         Hal-Com.2862              File infector           06/10/99
  139.         HBR.135                   File infector           06/10/99
  140.         Heathen.12288(DLL)        File infector           06/21/99
  141.         HKILL.1468                File infector           06/28/99
  142.         HKILL.1468 (2)            File infector           06/28/99
  143.         HKILL.997                 File infector           06/28/99
  144.         HLLC.4528                 File infector           06/07/99
  145.         HLLC.4528(2)              File infector           06/07/99
  146.         HLLO.2229                 File infector           06/28/99
  147.         HLLO.2229(2)              File infector           06/28/99
  148.         HLLO.2400                 File infector           06/28/99
  149.         HLLO.2400(2)              File infector           06/28/99
  150.         HLLO.2673                 File infector           06/28/99
  151.         HLLO.2673(2)              File infector           06/28/99
  152.         HLLO.DVPG.4128            File infector           06/28/99
  153.         HLLO.DVPG.4128(2)         File infector           06/28/99
  154.         HLLO.Maniac.5946          File infector           06/01/99
  155.         HLLO.Maniac.5946 (2)      File infector           06/01/99
  156.         HLLP.3678                 File infector           06/28/99
  157.         HLLP.3678(2)              File infector           06/28/99
  158.         HLLP.4631                 File infector           06/28/99
  159.         HLLP.4631(2)              File infector           06/28/99
  160.         HLLP.4754                 File infector           06/28/99
  161.         HLLP.4754(2)              File infector           06/28/99
  162.         HLLP.5062                 File infector           06/28/99
  163.         HLLP.5062(2)              File infector           06/28/99
  164.         HLLP.5192                 File infector           06/07/99
  165.         HLLP.5192(2)              File infector           06/07/99
  166.         HLLP.7616                 File infector           06/28/99
  167.         HLLP.7616(2)              File infector           06/28/99
  168.         HLLP.8080                 File infector           06/28/99
  169.         HLLP.8080(2)              File infector           06/28/99
  170.         HLLP.Jurasic.6227         File infector           06/28/99
  171.         HLLP.Jurasic.6227(2)      File infector           06/28/99
  172.         HLLP.PPZ.8586             File infector           06/28/99
  173.         HLLP.PPZ.8586(2)          File infector           06/28/99
  174.         HLLT.4754                 File infector           06/28/99
  175.         HLLT.4754(2)              File infector           06/28/99
  176.         HLLW.8560                 File infector           06/07/99
  177.         HLLW.8560(2)              File infector           06/07/99
  178.         Infector.5864             File infector           06/28/99
  179.         Istanbul.1385             File infector           06/01/99
  180.         Istanbul.1385 (x)         File infector           06/01/99
  181.         Jackie2.5743              File infector           06/21/99
  182.         Jackie2.5743 (2)          File infector           06/21/99
  183.         Jacklyn.12301             File infector           06/21/99
  184.         Jacklyn.12301 (2)         File infector           06/21/99
  185.         Jags.394                  File infector           06/01/99
  186.         JAP_HAL (b)               Boot infector           06/01/99
  187.         JDC.1165                  File infector           06/10/99
  188.         JDC.1165 (2)              File infector           06/10/99
  189.         JDC.1165 (3)              File infector           06/10/99
  190.         Jessica.1261              File infector           06/10/99
  191.         Jessica.1261 (x)          File infector           06/10/99
  192.         Ktcp.200                  File infector           06/28/99
  193.         KuSuMah.3967              File infector           06/01/99
  194.         KuSuMah.4268 (x)          File infector           06/01/99
  195.         Lazarus.2222              File infector           06/01/99
  196.         Magichole.512             File infector           06/01/99
  197.         Mahon.1372                File infector           06/01/99
  198.         Messiah.4535 (x)          File infector           07/02/99
  199.         Mwin.a                    File infector           06/28/99
  200.         Mwin.a (2)                File infector           06/28/99
  201.         Mwin.b                    File infector           06/28/99
  202.         Mwin.b (2)                File infector           06/28/99
  203.         Nelson.226                File infector           06/10/99
  204.         Nephew.3758               File infector           06/01/99
  205.         Nephew.3758 (2)           File infector           06/01/99
  206.         Nephew.3758 (x)           File infector           06/01/99
  207.         Nephew.3758 (x2)          File infector           06/01/99
  208.         Netbus 2.01 Trojan 1      File infector           06/07/99
  209.         Netbus 2.01 Trojan 10     File infector           06/07/99
  210.         Netbus 2.01 Trojan 11     File infector           06/07/99
  211.         Netbus 2.01 Trojan 12     File infector           06/07/99
  212.         Netbus 2.01 Trojan 13     File infector           06/07/99
  213.         Netbus 2.01 Trojan 14     File infector           06/07/99
  214.         Netbus 2.01 Trojan 15     File infector           06/07/99
  215.         Netbus 2.01 Trojan 2      File infector           06/07/99
  216.         Netbus 2.01 Trojan 3      File infector           06/07/99
  217.         Netbus 2.01 Trojan 4      File infector           06/07/99
  218.         Netbus 2.01 Trojan 5      File infector           06/07/99
  219.         Netbus 2.01 Trojan 6      File infector           06/07/99
  220.         Netbus 2.01 Trojan 7      File infector           06/07/99
  221.         Netbus 2.01 Trojan 8      File infector           06/07/99
  222.         Netbus 2.01 Trojan 9      File infector           06/07/99
  223.         Ninja.1264                File infector           06/28/99
  224.         Nipple.823                File infector           06/01/99
  225.         Nipple.823 (2)            File infector           06/01/99
  226.         Nomad.1022                File infector           06/10/99
  227.         November 17.768.B (x)     File infector           06/28/99
  228.         Onkelz.527.c              File infector           06/10/99
  229.         PM Trojan                 File infector           06/21/99
  230.         PM Trojan (2)             File infector           06/21/99
  231.         PM Trojan (3)             File infector           06/21/99
  232.         PM Trojan (4)             File infector           06/21/99
  233.         PM Trojan (DLL)           File infector           06/21/99
  234.         PM Trojan (DLL) (2)       File infector           06/21/99
  235.         PM Trojan (DLL) (3)       File infector           06/21/99
  236.         PM Trojan (DLL) (4)       File infector           06/21/99
  237.         PM Trojan (OCX)           File infector           06/21/99
  238.         PM Trojan (OCX) (2)       File infector           06/21/99
  239.         PM Trojan (OCX) (3)       File infector           06/21/99
  240.         PM Trojan (TIM)           File infector           07/07/99
  241.         PM Trojan (TIM)           File infector           06/21/99
  242.         PM Trojan (TIM) (2)       File infector           06/21/99
  243.         PM Trojan (TIM) (3)       File infector           06/21/99
  244.         PrettyPark.Worm           File infector           06/07/99
  245.         PS-MPC.Mudshark           File infector           06/07/99
  246.         Radioactive.873           File infector           07/02/99
  247.         Reizfaktor (Bat)          File infector           06/01/99
  248.         Reizfaktor (inf)          File infector           06/01/99
  249.         Reizfaktor (inf2)         File infector           06/01/99
  250.         Restive.543               File infector           06/10/99
  251.         Retro.974                 File infector           06/01/99
  252.         Retro.974 (2)             File infector           06/01/99
  253.         Retro.974 (3)             File infector           06/01/99
  254.         Saboteur.1391             File infector           06/10/99
  255.         Slam.Hunter.253           File infector           06/28/99
  256.         Snake.787                 File infector           06/10/99
  257.         Snake.787 (2)             File infector           06/10/99
  258.         Snake.787 (3)             File infector           06/10/99
  259.         SP1 Basic.Trojan          File infector           06/01/99
  260.         SP1 Basic.Trojan (2)      File infector           06/01/99
  261.         Sphinx.2534               File infector           06/28/99
  262.         Stardot.1100              File infector           07/07/99
  263.         Termite.5000.B            File infector           06/21/99
  264.         Termite.C                 File infector           06/21/99
  265.         Tosha.3314                File infector           06/10/99
  266.         Trivial.52.b              File infector           06/21/99
  267.         Trivial.53.f              File infector           06/21/99
  268.         Trivial.54.c              File infector           06/10/99
  269.         Trivial.55.d              File infector           06/21/99
  270.         Trivial.56.b              File infector           06/10/99
  271.         Trivial.56.c              File infector           06/10/99
  272.         Trivial.57                File infector           06/10/99
  273.         Trivial.58                File infector           06/21/99
  274.         Trivial.59.b              File infector           06/21/99
  275.         Troi.926                  File infector           06/07/99
  276.         Troi.926 (2)              File infector           06/07/99
  277.         Typer.215                 File infector           06/28/99
  278.         V.1906                    File infector           06/21/99
  279.         VBS.Freelink              File infector           07/02/99
  280.         VCL.156                   File infector           06/10/99
  281.         VirDem.824                File infector           06/07/99
  282.         Viva.752                  File infector           06/01/99
  283.         W97M.Class.DN             File infector           06/21/99
  284.         W97M.CopyTemp.intd        File infector           06/01/99
  285.         W97M.Daydream.A           File infector           06/01/99
  286.         W97M.Heathen.12288.A      File infector           06/21/99
  287.         W97M.Iis.H                File infector           06/28/99
  288.         W97M.IIS.I                File infector           06/10/99
  289.         W97M.IRCJack.A            File infector           06/21/99
  290.         W97M.JulyKiller           File infector           07/02/99
  291.         W97M.KillGood.Trojan      File infector           06/21/99
  292.         W97M.Mago.A               File infector           06/28/99
  293.         W97M.Melissa.I            File infector           06/21/99
  294.         W97M.MFV                  File infector           06/21/99
  295.         W97M.Nail.A               File infector           06/10/99
  296.         W97M.NiceDay.AB           File infector           06/28/99
  297.         W97M.No_va.D              File infector           06/01/99
  298.         W97M.Password.A           File infector           06/28/99
  299.         W97M.Password.B           File infector           07/02/99
  300.         W97M.Reizfaktor           File infector           06/01/99
  301.         W97M.Steak.A              File infector           06/21/99
  302.         W97M.Steak.B              File infector           06/21/99
  303.         W97M.VMAN.A               File infector           06/10/99
  304.         W97M.VMPCK1.BK            File infector           07/02/99
  305.         WM.Automat.BK             File infector           07/02/99
  306.         WM.CBA.B                  File infector           06/10/99
  307.         WM.Mentes.E               File infector           06/07/99
  308.         WM.Prizm.A                File infector           06/28/99
  309.         Worm.ExploreZip           File infector           06/07/99
  310.         WuChing.Boot.Dropper      Boot infector           06/01/99
  311.         X97M.Automat.BF           File infector           07/02/99
  312.         X97M.Flyaway.A            File infector           06/10/99
  313.         XM.Automat.BI             File infector           07/02/99
  314.         XM.Friend.B               File infector           06/07/99
  315.         XM.Laroux.C               File infector           06/10/99
  316.         XM.Laroux.HQ              File infector           06/01/99
  317.         XM.Laroux.HR              File infector           06/07/99
  318.         XM.Sugar                  File infector           07/02/99
  319.         XM.Trasher.Cobra          File infector           06/10/99
  320.         XM.Trasher.Enigma         File infector           06/10/99
  321.         XM.Trasher.Freezer        File infector           06/10/99
  322.         Zasta.2546                File infector           06/28/99
  323.         Zasta.2546 (2)            File infector           06/28/99
  324.         Zohr.4160                 File infector           06/01/99
  325.         Zorm.573                  File infector           06/01/99
  326.  
  327. Name Changes:
  328.  
  329.         Old Virus Name            New Virus Name          Date changed
  330.         --------------            --------------          ------------
  331.         Bleem.Trojan           to Fake Bleem Trojan       06/28/99
  332.         Explore666.59932       to Explore666.59392        06/07/99
  333.         Explore666.59932(2)    to Explore666.59392(2)     06/07/99
  334.         Gene.454               to Gene.454.b              06/28/99
  335.  
  336. Deletions:
  337.  
  338.         Virus Name                Infection Type          Date removed
  339.         ----------                --------------          ------------
  340.         AOL Trojan Buddy          File infector           06/21/99
  341.         AOL Trojan Buddy 2        File infector           06/21/99
  342.         AOL Trojan Buddy 3        File infector           06/21/99
  343.         Bupt.1279                 File infector           06/01/99
  344.         FCL.2044                  File infector           06/07/99
  345.         FCL.2044 (2)              File infector           06/07/99
  346.         FCL.2044 (3)              File infector           06/07/99
  347.         JAP_HAL (b)               Boot infector           06/07/99
  348.         Laufwerk                  File infector           06/21/99
  349.         November 17.768.B (x)     File infector           06/07/99
  350.         PM Trojan (TIM)           File infector           07/02/99
  351.         PS-MPC.Mudshark           File infector           06/01/99
  352.         Stardot.1100              File infector           07/02/99
  353.         VirDem.824                File infector           06/01/99
  354.         Virogen.Asexual (2)       File infector           06/28/99
  355.         WM.Automat.Q              File infector           06/28/99
  356.  
  357. **********************************************************************
  358. **    Enabling/Disabling PowerPoint Scanning                            **
  359. **********************************************************************
  360. PowerPoint Scanning is now enabled by default and can be optionally
  361. disabled.  However, you may want to verify that files with
  362. PowerPoint extensions will be scanned by making sure that your
  363. NAV options have both ".PPT" and ".POT" in the list of extensions
  364. to scan.
  365.  
  366. To disable PowerPoint scanning in NAV for Windows 95/NT
  367. version 4.x or NAV for OS/2, a text file named NAVEX15.INF should
  368. be placed in the directory where NAV 4.x or NAV 5.x is installed
  369. (i.e., C:\Program Files\Norton AntiVirus).
  370.  
  371. To disable PowerPoint scanning in NAV for Netware version 4.x, a text
  372. file named NAVEX15.INF should be placed in the directory where NAV
  373. 4.x is installed (i.e., sys:system\navnlm).
  374.  
  375. To disable PowerPoint scanning in NAV for Windows 95/NT version 2.0,
  376. NAV 4.x for Windows 3.1/DOS, NAVIEG 1.x, or NAVFW 1.x a text file
  377. named NAVEX.INF should be placed in the directory where NAV is
  378. installed (i.e., C:\NAV).
  379.  
  380. The contents of the text file, NAVEX15.INF or NAVEX.INF, determine
  381. which components of NAV have PowerPoint scanning disabled.
  382.  
  383. To disable PowerPoint scanning for a particular component, use the
  384. following table to determine the lines to add to the text file.
  385. PowerPoint scanning can be disabled for more than one component if
  386. needed by adding the required lines for the desired components.
  387.  
  388. +---------------------+--------------------------+--------------------+
  389. |Windows 95/NT scanner|Windows 95/NT auto-protect|DOS scanner         |
  390. +---------------------+--------------------------+--------------------+
  391. |[NAVW32]             |[NAVAP]                   |[NAVDX]             |
  392. |PowerPointScanning=0 |PowerPointScanning=0      |PowerPointScanning=0|
  393. +---------------------+--------------------------+--------------------+
  394.  
  395. +----------------------+--------------------+--------------------+
  396. |Windows 3.1 scanner/AP|Netware scanner         |OS/2 scanner/AP |
  397. +----------------------+--------------------+--------------------+
  398. |[NAVWIN]              |[NAVNLM]            |[NAVOS2]            |
  399. |PowerPointScanning=0  |PowerPointScanning=0|PowerPointScanning=0|
  400. +----------------------+--------------------+--------------------+
  401.  
  402. To enable PowerPoint scanning for a component, delete the lines
  403. added for that component from the NAVEX15.INF or NAVEX.INF file.
  404.  
  405. **********************************************************************
  406. **    Additional Information                                            **
  407. **********************************************************************
  408. SARC has equipped Norton AntiVirus with a new feature called
  409. "Infestation Mode."  If a large number of new or unknown viruses
  410. is found on the system during a scan, Norton AntiVirus will
  411. automatically enable its highest level of detection.  This gives
  412. users the most comprehensive protection in cases where a viral
  413. infestation may have been detected.  If you would like to disable
  414. this feature, you can do so by following these instructions:
  415.  
  416. 1. Create a text File called NAVEX15.INF in your Norton AntiVirus
  417.    directory,e.g., C:\Program Files\Norton AntiVirus. If this file
  418.    already exist go to step two.
  419.  
  420. 2. Place the following lines in this File on the left-hand margin:
  421.  
  422. [NAVW32]
  423. infestmode=0
  424.  
  425. [NAVDX]
  426. infestmode=0
  427.  
  428. 3. Save the File.
  429.  
  430.  
  431. Additional information regarding this virus definitions update can be
  432. found in UPDATE.TXT and TECHNOTE.TXT.
  433.