home *** CD-ROM | disk | FTP | other *** search
/ PC World Plus! (NZ) 2000 September / PCWORLD_PLUS.iso / patch / 0605i32.exe / whatsnew.txt < prev    next >
Text File  |  2000-06-05  |  18KB  |  337 lines

  1. **********************************************************************
  2. **                                                                  **
  3. **  What's New in the NAV Virus Definitions Files      WHATSNEW.TXT **
  4. **                                                                  **
  5. **  Symantec AntiVirus Research Center (SARC)          June 05,2000 **
  6. **                                                                  **
  7. **********************************************************************
  8. This document contains the following topics:
  9.  
  10.  * Virus Alerts
  11.  * New Technologies
  12.  * Changes Incorporated Into This Update
  13.  * Enabling Scanning Features
  14.  * Additional Information
  15.  
  16. **********************************************************************
  17. ** Virus Alerts                                                     **
  18. **********************************************************************
  19. VBS.LoveLetter, a new worm which has been wide-spread since May 4th,
  20. is detected by this definition set.  
  21.  
  22. The ten most commonly reported viruses, worldwide:
  23.  
  24.     1  VBS.LoveLetter.A
  25.     2  WScript.KakWorm
  26.     3  VBS.Network
  27.     4  W95.CIH
  28.     5  Happy99.Worm
  29.     6  Worm.ExploreZip
  30.     7  W97M.ColdApe
  31.     8  W97M.Ethan
  32.     9  W97M.Melissa
  33.    10  WM.Cap
  34.  
  35. **********************************************************************
  36. ** New Technologies                                                 **
  37. **********************************************************************
  38.  
  39. DATE         Technologies Added
  40. ----         ------------------
  41. 8/19/98    * Excel heuristics which detect and repair new and unknown
  42.              macro viruses in Excel 95 & 97 documents.
  43.  
  44. 9/16/98    * Added repair for encrypted Excel 97 documents.
  45.  
  46. 10/21/98   * Heuristics to detect AOL Password Stealer Trojans.
  47.            * WORD Heuristics improvement to increase detection rate.
  48.  
  49. 12/17/98   * Macro Exclusion Engine to speed up the scanning for Word
  50.              and Excel documents.
  51.            * PowerPoint engine to scan PowerPoint related viruses.
  52.              To enable this technology please read "Enabling/Disabling
  53.              PowerPoint Scanning" section later in this document.
  54.  
  55. 02/18/99   * Detection and repair of macro viruses in Word and Excel
  56.              2000 documents.
  57.  
  58. 05/15/99   * Added repair for PowerPoint viruses.
  59.            * Improved heuristics to detect more WORD 97 related
  60.              viruses.
  61.  
  62. 06/10/99   * Menu repair technology for WORD macro viruses that change
  63.              command bar customizations in NORMAL.DOT.
  64.  
  65. 07/12/99   * Added support for scanning of Ichitaro 8/9 documents.
  66.              (Ichitaro is a Japanese word processing program).
  67.  
  68. 08/19/99   * Added detection and repair for embedded documents inside
  69.              PowerPoint 97.
  70.  
  71. 11/22/99   * Added detection and repair for Trojans embedded in OLE
  72.              files, such as Windows scrap files and MS Office
  73.              documents.
  74.            * Added detection for viruses which infect Microsoft
  75.              Project documents (P98M.Corner.A, for example).
  76.  
  77. 02/10/00   * Added support for scanning of UNIX executables.
  78.            * Added detection for infected Visio documents.
  79.  
  80. **********************************************************************
  81. ** Changes Incorporated Into This Virus Definitions Update          **
  82. **********************************************************************
  83. New virus definitions:
  84.  
  85.         Virus Name                Infection Type          Week added
  86.         ----------                --------------          ----------
  87.         Backdoor.Asylum           File infector           05/09/00
  88.         Backdoor.Eclipse          File infector           06/05/00
  89.         Backdoor.Frenzy           File infector           05/09/00
  90.         Backdoor.GDoor            File infector           05/30/00
  91.         Backdoor.Muie             File infector           05/09/00
  92.         backdoor.netbus.12        File infector           05/09/00
  93.         Backdoor.RipClient        File infector           06/05/00
  94.         Backdoor.Servidor         File infector           05/30/00
  95.         Backdoor.Wincrash         File infector           05/09/00
  96.         Bat.Winstart_II.511       File infector           05/30/00
  97.         ConCon.Trojan             File infector           05/15/00
  98.         DrZip.512                 File infector           05/22/00
  99.         GIP.Trojan                File infector           05/22/00
  100.         HTML.DayDream2            File infector           06/05/00
  101.         ICQ.PWS.Trojan            File infector           05/09/00
  102.         JPEG.Trojan               File infector           05/30/00
  103.         Linux.DDoS.MStream        File infector           05/22/00
  104.         Maze.Trojan               File infector           05/30/00
  105.         Movie.Pif.Worm.B          File infector           05/09/00
  106.         O97M.CyberNet.A           File infector           05/22/00
  107.         PriceDoc.Trojan           File infector           05/30/00
  108.         Solaris.DDoS.MStream      File infector           05/22/00
  109.         Stoned.HM (db)            Boot infector           05/09/00
  110.         Trojan.Ansibomb           File infector           05/30/00
  111.         Trojan.Bat.Format.FR      File infector           05/09/00
  112.         Unix.LoveLetter           File infector           05/15/00
  113.         VBS.CoolNote              File infector           05/30/00
  114.         VBS.Fireburn.A            File infector           05/30/00
  115.         VBS.Gnutella              File infector           06/05/00
  116.         VBS.LoveLetter.AD         File infector           06/05/00
  117.         VBS.LoveLetter.E          File infector           05/08/00
  118.         VBS.LoveLetter.E(1)       File infector           05/08/00
  119.         VBS.LoveLetter.E(2)       File infector           05/08/00
  120.         VBS.LoveLetter.E(3)       File infector           05/08/00
  121.         VBS.LoveLetter.F          File infector           05/08/00
  122.         VBS.LoveLetter.F(1)       File infector           05/08/00
  123.         VBS.LoveLetter.F(2)       File infector           05/08/00
  124.         VBS.LoveLetter.F(3)       File infector           05/08/00
  125.         VBS.LoveLetter.G          File infector           05/08/00
  126.         VBS.LoveLetter.G(1)       File infector           05/08/00
  127.         VBS.LoveLetter.G(2)       File infector           05/08/00
  128.         VBS.LoveLetter.G(3)       File infector           05/08/00
  129.         VBS.LoveLetter.H          File infector           05/08/00
  130.         VBS.LoveLetter.I          File infector           05/08/00
  131.         VBS.LoveLetter.K          File infector           05/08/00
  132.         VBS.LoveLetter.L          File infector           05/08/00
  133.         VBS.LoveLetter.M          File infector           05/08/00
  134.         VBS.LoveLetter.N          File infector           05/08/00
  135.         VBS.LoveLetter.O          File infector           05/08/00
  136.         VBS.LoveLetter.P          File infector           05/08/00
  137.         VBS.LoveLetter.Q          File infector           05/08/00
  138.         VBS.LoveLetter.R          File infector           05/08/00
  139.         VBS.LoveLetter.S          File infector           05/08/00
  140.         VBS.Lowjo                 File infector           05/30/00
  141.         VBS.MP3Free.A             File infector           05/22/00
  142.         VBS.MP3Free.A(2)          File infector           05/15/00
  143.         VBS.NewLove.A             File infector           05/18/00
  144.         VBS.Scrambled             File infector           05/30/00
  145.         VBS.Zuke.Worm             File infector           06/05/00
  146.         VCG.Belka                 File infector           05/22/00
  147.         W32.Android.Worm          File infector           05/22/00
  148.         W32.Blink.8192            File infector           05/15/00
  149.         W32.Cargo.B.Int           File infector           05/22/00
  150.         W32.Demo.Worm             File infector           05/22/00
  151.         W32.Dolly.14848.Mirc      File infector           05/15/00
  152.         W32.Ghost.1667            File infector           06/05/00
  153.         W32.Guorm.Worm            File infector           06/05/00
  154.         W32.Hellfire.Mirc         File infector           05/22/00
  155.         W32.HLLO.ZMK.30030        File infector           05/22/00
  156.         W32.HLLP.Cramb.B          File infector           05/22/00
  157.         W32.HLLP.Gotem.Int        File infector           05/15/00
  158.         W32.HLLP.Scrambler.A      File infector           06/05/00
  159.         W32.HLLP.Scrambler.B      File infector           06/05/00
  160.         W32.HLLP.This.16896       File infector           05/22/00
  161.         W32.Magic.1922            File infector           05/22/00
  162.         W32.Mypics.Worm.36352     File infector           05/09/00
  163.         W32.RainSong.3891         File infector           05/15/00
  164.         W32.Rhapsody.Gen          File infector           06/05/00
  165.         W32.Riccy.A               File infector           05/22/00
  166.         W32.Riccy.B               File infector           05/22/00
  167.         W32.Riccy.C               File infector           05/22/00
  168.         W32.Segax.Gen             File infector           05/30/00
  169.         W32.Silver.Mirc           File infector           05/22/00
  170.         W32.Southpark.Worm        File infector           05/15/00
  171.         W32.Tasmer.46395          File infector           05/15/00
  172.         W95.CIH.1103.Int          File infector           05/30/00
  173.         W95.CIH.1297.Int          File infector           05/30/00
  174.         W95.Kala.7620             File infector           05/15/00
  175.         W95.Shaitan.3550          File infector           05/22/00
  176.         W95.ZOM                   File infector           05/22/00
  177.         W95.ZOM.Gen               File infector           05/30/00
  178.         W95.Zomb.432              File infector           05/22/00
  179.         W97M.Aquil                File infector           05/30/00
  180.         W97M.Bablas.AA            File infector           06/05/00
  181.         W97M.Bablas.AB            File infector           06/05/00
  182.         W97M.Bablas.AC            File infector           06/05/00
  183.         W97M.Bablas.W             File infector           05/30/00
  184.         W97M.Bablas.X             File infector           05/30/00
  185.         W97M.Bablas.Z             File infector           06/05/00
  186.         W97M.Balblas.Y            File infector           05/30/00
  187.         W97M.Blink.8192.A         File infector           05/15/00
  188.         W97M.Candle.B             File infector           05/30/00
  189.         W97M.Claud.B              File infector           05/30/00
  190.         W97M.Claud.C              File infector           06/05/00
  191.         W97M.Claudio.B            File infector           05/30/00
  192.         W97M.DogHack              File infector           05/30/00
  193.         W97M.Donkey               File infector           05/30/00
  194.         W97M.Eight941.G           File infector           05/09/00
  195.         W97M.Eight941.H           File infector           05/09/00
  196.         W97M.Eight941.I           File infector           05/15/00
  197.         W97M.Eight941.J           File infector           06/05/00
  198.         W97M.FF.A                 File infector           06/05/00
  199.         W97M.Fly                  File infector           05/30/00
  200.         W97M.Groov.F              File infector           05/30/00
  201.         W97M.Heels.A              File infector           05/15/00
  202.         W97M.Lafs.B               File infector           06/05/00
  203.         W97M.LoveDrop             File infector           05/22/00
  204.         W97M.Marker.BB            File infector           05/30/00
  205.         W97M.MARKER.CB            File infector           05/09/00
  206.         W97M.Marker.CR            File infector           05/09/00
  207.         W97M.MARKER.CS            File infector           05/15/00
  208.         W97M.Marker.CT            File infector           05/22/00
  209.         W97M.Marker.CU            File infector           05/30/00
  210.         W97M.Marker.CX            File infector           06/05/00
  211.         W97M.Marker.CZ            File infector           06/05/00
  212.         W97M.Marker.Intend        File infector           05/30/00
  213.         W97M.Marker.S             File infector           05/22/00
  214.         W97M.Melissa.BG           File infector           05/26/00
  215.         W97M.Opey.D               File infector           05/30/00
  216.         W97M.OutlookWorm.Gen      File infector           05/26/00
  217.         W97M.Shab                 File infector           05/09/00
  218.         W97M.Shining.A            File infector           05/15/00
  219.         W97M.Sprite               File infector           05/22/00
  220.         W97M.Stand                File infector           05/30/00
  221.         W97M.Thus.K               File infector           06/05/00
  222.         W97M.Thus.V               File infector           05/22/00
  223.         W97M.Thus.W               File infector           05/30/00
  224.         W97M.Ucase                File infector           05/09/00
  225.         W97M.Verlor (dropped)     File infector           05/30/00
  226.         W97M.VMPCK1.DJ            File infector           05/09/00
  227.         W97M.Vortex               File infector           05/30/00
  228.         WM.Berau                  File infector           06/05/00
  229.         X97M.Automat.AJ           File infector           05/15/00
  230.         X97M.Automat.AK           File infector           05/15/00
  231.         X97M.Automat.AM           File infector           05/22/00
  232.         X97M.Divi.G               File infector           05/30/00
  233.         X97M.Divi.H               File infector           06/05/00
  234.         X97M.HJB                  File infector           06/05/00
  235.         X97M.Laroux.KV            File infector           05/26/00
  236.         X97M.Laroux.KW            File infector           05/30/00
  237.         X97M.Laroux.TT            File infector           06/05/00
  238.         X97M.Manalo.H             File infector           06/05/00
  239.         X97M.OutlookWorm.Gen      File infector           05/26/00
  240.         X97M.Permnt.A             File infector           06/05/00
  241.         XM.Automat.AI             File infector           05/09/00
  242.         XM.Automat.AL             File infector           05/15/00
  243.         Zombie.3592               File infector           05/22/00
  244.  
  245.  
  246. Name Changes:
  247.  
  248.         Old Virus Name            New Virus Name          Date changed
  249.         --------------            --------------          ------------
  250.         Backdoor.Psychward.b   to Backdoor.Psychward      05/15/00
  251.         VBS.NewLove.A2(gen 1)  to VBS.NewLove.A2(Gen 1)   05/22/00
  252.         W32.Inrar.B            to W32.Inrar.Gen           05/30/00
  253.         W32.Magic.7045.B       to W32.Magic.7045.Gen      05/22/00
  254.  
  255.  
  256. Deletions:
  257.  
  258.         Virus Name                Infection Type          Date removed
  259.         ----------                --------------          ------------
  260.         Joshi Dropper             Boot infector           05/04/00
  261.         Narcosis (d)              File infector           05/04/00
  262.         X97M.Automat.AJ           File infector           05/22/00
  263.         XM.Automat.AL             File infector           05/22/00
  264.  
  265.  
  266. **********************************************************************
  267. **  Enabling Scanning Features                                      **
  268. **********************************************************************
  269.  
  270. Several scanning features can be enabled through the use of an INF 
  271. configuration file.  For NAV for Windows 95/NT version 4.x and later, 
  272. or NAV for OS/2, this configuration file should be called NAVEX15.INF
  273. and should be placed in the directory where NAV is installed (i.e.,
  274. C:\Program Files\Norton AntiVirus).  For NAV for Netware version 4.x,
  275. the file should be called NAVEX15.INF and should be placed in the 
  276. directory where NAV 4.x is installed (i.e., sys:system\navnlm). For
  277. NAV for Windows 95/NT version 2.0, NAV 4.x for Windows 3.1/DOS,
  278. NAVIEG 1.x, or NAVFW 1.x, the file should be named NAVEX.INF and
  279. should be placed in the directory where NAV is installed (i.e., C:\NAV).
  280. If this configuration file does not exist, create one in the appropriate
  281. directory if you want to change the default settings.
  282.  
  283. To enable a scanning feature for a particular component, one or more 
  284. entries need to be added to the configuration file under the correct
  285. section.  For each platform there is a corresponding section that is used 
  286. in the INF file.  Below is a table of section names and platforms.
  287.  
  288. Section Name    Platform
  289. ------------    --------
  290. NAVW32          Windows 95/98/NT
  291. NAVAP           Windows 95/98/NT Auto-Protect
  292. NAVDX           DOS
  293. NAVNLM          Netware
  294. NAVWIN          Windows 3.1
  295. NAVOS2          OS/2
  296. NAVAIX          AIX
  297. NAVSOL          Solaris
  298.  
  299. Entries are case insensitive.  Below is a description of possible 
  300. entries.
  301.  
  302. 1. Files can be excluded from scans by the NAVEX engine.  To exclude a
  303. specific file from the NAVEX engine scan, add an entry with the full
  304. path and file name.  This is case insensitive.  No wildcards are allowed.
  305. To exclude multiple files, add a separate entry for each file.  To exclude
  306. a file, add an entry like the one below where <PATH> is the full path
  307. and file name.
  308.         ExcludeFile = <PATH>
  309.  
  310. 2. Files within a directory can be excluded from scans by the NAVEX engine.
  311. To exclude all files within a directory, add an entry with the full 
  312. directory path.  This is case insensitive.  No wildcards are allowed.  This
  313. does not exclude files located in subdirectories of the specified 
  314. directory.  To exclude multiple directories, add a separate entry for each
  315. directory. To exclude a directory, add an entry like the one below where
  316. <DIRECTORY> is the full path.
  317.         ExcludeDirectory = <DIRECTORY>
  318.  
  319. The following example of an INF configuration file excludes two files, 
  320. NOSCAN.EXE and BIGFILE.DOC, from NAVEX scans for the Windows 95/98/NT 
  321. scanner.  It excludes the D:\PRIVATE directory from Windows 95/98/NT 
  322. Auto-Protect.
  323.  
  324. [NAVW32]
  325. ExcludeFile = C:\PROGRAM FILES\NOSCAN.EXE
  326. ExcludeFile = C:\TEMP\BIGFILE.DOC
  327.  
  328. [NAVAP]
  329. ExcludeDirectory = D:\PRIVATE
  330.  
  331. **********************************************************************
  332. **    Additional Information                                        **
  333. **********************************************************************
  334.  
  335. Additional information regarding this virus definitions update can be
  336. found in UPDATE.TXT and TECHNOTE.TXT.
  337.