home *** CD-ROM | disk | FTP | other *** search
-
- Update report of Thunderbyte Anti-Virus utilities.
- Prefixes:
- '-' indicates a change that does not require user attention.
- '->' indicates a modification that requires user attention, such as a
- change in program invocation, etc.
-
-
- 7.02 Product update
- -------------------
-
- General notes:
- - Almost 600 new signatures added!
-
- -> The Security.Doc file for PGP authenticy verification
- will now be created by using our company key: ESaSS.PGP.
- This key is signed by my Veldman.PGP key which is
- distributed for a long time now: so you can confirm that
- the new ESaSS.PGP key is valid.
-
- - There are some new entries in TBAV.FAQ
-
-
- TbScan:
- -> If TbScan detects a virus, the menu option 'Continue' has been
- replaced by 'Scan next'. Consequently, you have to press 'S'
- rather than 'C' to scan the next file. This change was necessary
- to assign the 'C' to a new menu option...
-
- - Cleaning of macro viruses! Yes, it is there, included in the
- scanner itself. If TbScan detects a virus which it is able to
- clean, it will offer an additional 'Clean' menu entry.
- Currently, only macro viruses can be cleaned this way.
-
- - TbScan no longer scans .XLT and .XLS files. There is no virus
- that infects these macro files.
-
-
- TbScanX:
- -> Option 'wild' has been removed. TbScanX now only searches for
- viruses which have been found 'in the wild'. Viruses have the
- 'wild flag' set if they are listed in Joe Wells 'Wildlist'.
- This list is frequently updated with information from all
- major anti-virus vendors and specialists. Note that TbScanX
- now uses significantly less memory than before.
-
-
- TBAV:
- - Previous versions of the TBAV menu shell didn't recognize the
- 'NoAutoHr' option in the TBAV.INI file. This problem is now
- solved.
-
-
- Viruses:
- - Summary:
- - A total of 587 additions were made in the signature database:
- - 94 viruses had a name change only
- - 37 viruses had a signature change to improve detection or
- to detect new variants. Some of these viruses had a change
- of name as well
- - 1 trojan signature has been added
- - 58 bootsectorvirus signatures have been added
- - 389 filevirus signatures have been added
- - 8 WordMacro virus signatures have been added
-
- - The next viruses had a change of name only:
-
- From: To:
- ------------ ------------
- _304 Vector.304
- _351 SillyCR.351
- 15_Years 15_Years.A
- Amber BW.701
- Andromeda Andromeda.1140
- Andy BW.609
- Anti-mit Anti_MIT.770.A
- AP AP.I
- Arcv.X-3b Arcv.1060.A
- Argyle {1} Argyle.2761 {1}
- Argyle {2} Argyle.2761 {2}
- Ari John.1962
- Arianna Arianna.3375
- Asexual Offspring.1520
- Bit_Addict Bit_Addict.477
- Bops Startdot.892
- BW.1001 BW.556/1001/1272
- BW.Archer BW.799
- BW.Lotek BW.859
- CancerBero SillyC.190.A
- Da'boys Da'boys.A/C
- Dead Bit_Addict.790
- Dead.1362 Bit_Addict.790
- Deaf.1119 BW.1119
- DEI.1780 {com} DEI {com}
- DEI.1780 {exe} DEI.1780
- Dementia BW.512
- Demon.348 Satyricon.348
- Disk_Killer Disk_Killer.A
- Dream Dream.2000/2012
- Eliza Eliza.1193
- Esto 15_Years
- Floyd BW.502/732
- Ginger.Rainbow.2351 {mbr} Ginger.2351 {mbr}
- Ginger.Rainbow.2351 Ginger.2351
- Gomer BW.687
- H-Andromeda.758 Andromeda.758
- Hasita J&M.A
- Lame Lame.2350
- Leech Leech.1024
- Lemem Lehigh
- Mayberry.Goober BW.828
- Mayberry.Jethro BW.475
- Mayberry.MSCrump BW.758
- Mayberry.Opy BW.409
- Mayberry.Velm BW.402
- Mazur Mazur.1125
- Meta Meta.2048.A
- MMIR MMIR.278-393
- MMIR.Das_Boot MMIR.423
- Monstor.311 BW.311
- MTZ {1} MTZ.1907
- MTZ.1_0 MTZ.910
- MTZ.3_0 MTZ.2624
- Nado.814 Nado.841
- Necro_Dementia Dementia.4207
- NRLG NRLG.666-1038
- Number.510 Mephisto.510
- Number.615 Mephisto.615
- Number.654 Mephisto.654
- Number.914/928/937/938 Mephisto.914/928/937/938
- Number.1000 Mephisto.1000
- Number.1242 Mephisto.1242
- Nygus Nygus.752/757
- Offspring.05 Offspring.711
- Offspring.07 Offspring.1294
- Offspring.081 Offspring.1127
- One13th Vice_3.One13th
- Pinworm Pinworm.2150
- Pysk.unknown Pysk.1536
- Riot.Eternity.562-600 Eternity.562-600
- Riot.Doom Mephisto.815
- Saram Sarampo.1371
- Satyricon Satyricon.360
- Shira Meta.2048.B
- Shutdown Shutdown.644
- Signs Signs.720
- StarDot.789 {1} StarDot.789.A/B
- StarDot.789 {2} StarDot.789.C
- Stoned.Azusa Stoned.Azusa.A
- Storm Storm {1}
- Tequila.A {1} Tequila.2468.A {1}
- Tequila.A {2} Tequila.2468.A {2}
- Tequila.B Tequila.2468.B/D
- Tiny.Ghost Tiny.330
- Tokyo Tokyo.1258
- Trivial.27 Trivial.27.A
- Trivial.40 Trivial.40.B/D
- TVIR Void.2340
- Twister Twister.451/1015/1767
- V.6000 Mammoth.6000
- Vice Vice_4.HackMaster.1197
- Virogen Offspring.1673
- Wire.3518 One_Half.3518
-
- - The next viruses had the indicated changes:
-
- AMI.A/B -> 1701AMI.1701 changed name + signature
- Blue_Nine.925/1725 bytes changed signature
- Burger.405 variant detection
- BW.756 -> BW.372/756 changed name + variant detection
- Caustic_Grip -> Caustic.601 changed name + signature
- Clouds.718 changed signature
- Fax_Free.Mecojoni.1536 variant detection
- Ghost.Blinky -> Blinky.1302 changed name + variant detection
- Hi.671/806/833 -> changed name + variant detection
- Hi.671/802/806/833
- Ieronim.512 -> Ieronim.512/560 changed name + variant detection
- Ieronim.1492 -> changed name + variant detection
- Ieronim.1492/1596
- Lame.435 changed signature
- Little_Brother -> changed name + variant detection
- Little_Brother.299-361
- Predator {germ} variant detection
- Predator.1070/1072 changed name + variant detection
- Natas.4740-4988 changed name + variant detection
- Necropolis.A -> changed name + variant detection
- Necropolis.1963.A/B/D
- Overdoze.816/930/996 variant detection
- Rajaat -> Rajaat.679/700 changed name + variant detection
- Rajaat.287 -> Rajaat.287/443 changed name + variant detection
- Rajaat.856 -> Rajaat.856/871 changed name + variant detection
- Rocket.623 changed signature
- Rodolf -> Rodolf.4096.A/B changed name + variant detection
- Tigre.1800 variant detection
- Titanium.844 changed signature
- Trivial.26 -> Trivial.23/26 changed name + variant detection
- Trojector -> Trojector.1463 changed name + variant detection
- Ultra-Violet.3319 -> UVR.3319 changed name + signature
- VBasic.5120 changed name + variant detection
- VFSI -> VFSI.426/427/437 changed name + variant detection
- Vlad.653 variant detection
- Wanderer -> Wanderer.411/484 changed name + variant detection
- WordMacro/Colors variant detection
-
- - Added trojan signatures:
-
- PKZIP 3.00B
-
- - Added bootsector signatures:
-
- 15_Years.B
- AP.J/K/M
- Asteriks
- Auger
- Black_Worm
- Catman
- Cekov
- Cicada
- Crepate.1944 {mbr}
- Da'boys.B
- Darkelf
- Devil
- Disk_Killer.B
- Exe_Bug.Hooker.D
- Fishu
- Form.F
- Fowl.3072 {mbr}
- Half
- Hemlock.3183 {mbr}
- IL
- Intruder
- J&M.B
- Judagor
- Keypress_UFO
- Light
- MacGyver.4112 {mbr}
- Mammoth.6000 {mbr} {1}
- Mammoth.6000 {mbr} {2}
- NCTU
- NRLG {mbr}
- NTMY.1722 {mbr}
- Nutcracker.2000.A/B {mbr}
- Nutcracker.2725 {mbr}
- Nutcracker.2890 {mbr}
- Nutcracker.2900 {mbr}
- Nutcracker.3100 {mbr}
- Nutcracker.3472 {mbr}
- Nutcracker.3500 {mbr}
- Pathfinder
- Purcyst
- Purple
- Rajaat.518 {mbr}
- Seagull.448
- Sepultura
- Spirit
- Stealth_Boot.F
- Sierra
- Stoned.Azusa.B
- Stoned.Kenya
- Stoned.Zuzana
- SyBDisk
- Tango
- Turboman
- Virgo
- Wet.B
- XIVLO.2248 {mbr}
- XORboot
- Zeus
-
- - Added file virus signatures:
-
- _451
- _553
- _1317
- _1320
- 4_Seasons.1514
- A-OD.571
- Abraxas.1304
- Asahi.1045
- Alert.675
- Alfa.3072
- Alfo.1536
- Andris.683
- Andromeda.725
- Andromeda.800
- Andromeda.1024
- Andromeda.1536
- Anti_MIT.764
- Anti_MIT.770.B
- Arg.1206
- Arianna.2864
- Arianna.3426
- Asmodeus.1168
- Arcv.571
- Arcv.800
- Arcv.1060.B
- Argyle.2761 {3}
- AOS
- AT.160
- Australian_Parasite.205
- Australian_Parasite.320
- Australian_Parasite.990
- Bin.466
- Boot_Exe.204
- Boot_Exe.205.B
- Boot_Exe.205.C
- Boot_Exe.207
- Boot_Exe.453.A
- Boot_Exe.453.B
- Boot_Exe.453.C
- Buffalo.486
- BV.Parasite.Check
- BV.Parasite.Format
- BV.Parasite.Peli
- BV.Parasait.Resident
- BW.410
- BW.474
- BW.525
- BW.740
- BW.754
- BW.811
- BW.1027
- Cantando.857
- Chemist.265
- Clisti.1024
- Conjurer.181
- Conjurer.277
- Conjurer.312
- Creat.795
- Critter.1015
- Danish_Tiny.390
- Darkrev.1024
- Datafire.1080
- DBCE.3403
- DEI.1456/1526
- DEI.1634
- DEI.1792
- DEI.1948
- Deino.1000
- Die.385
- Die.666
- DIR-II.1024.BC
- Dream.548
- DvD.455
- Ear.405
- Estionia.400
- Eliza.1282
- Eternity.410
- Eternity.411
- Eternity.599
- ExeHdr.448
- Exunt.148
- Face.2521 {1}
- Face.2521 {2}
- Fizzle.313
- Flag3.1901
- Fowl.3072
- Future.3180
- Garfio.1000
- GCAE.2520
- Glupak.393
- Glupak.847
- Glupak.890
- Gonads.1781
- Gondor.3072
- Good_Doctor.2528
- Greedy.1106
- Gripe.1985
- HDZZ.566
- Hi.680/764
- HLLC.12304
- HLLP.16470
- HLLP.17414
- Hole.476
- Hue.482
- Insane.186
- Insane.197
- Insert.247
- Ioe.239
- IVir.109
- IVir.127
- IVP.338
- IVP.374
- IVP.592
- IVP.674.B
- IVP.986
- IVP.1017
- Ivy.454/568
- Jerusalem.1448
- Johnny Angle.826
- Johnny Angle.955
- Junkie.1308
- Khizhnjak.509
- Korean_Stranger.709
- Kouser.1648
- L'Amour.3420
- LoadHi.1467
- Leprosy.5120
- Lesson_I.208
- Letter_H.446
- Letter_H.665
- Lion.3531
- Lover.602
- LR1.2884
- Marbas.1303
- Marbas.1313
- Mayhem.457
- Mazur.2541
- MDS.331
- Meta.2048.C
- MMIR.411
- MMIR.444
- MonAmi.1059/1066
- Morgot.823
- MZV.333
- Nado.584
- Nado.584 {germ}
- Nado.759
- Necropolis.1963.C
- Nostradamus.2247
- NRLG.1096
- NTMY.1722
- Nuker.1982 {1}
- Nuker.1982 {2}
- Nuker.3536 {1}
- Nuker.3536 {2}
- Nutcracker.1015
- Nutcracker.2000.A
- Nutcracker.2000.B
- Nutcracker.2244
- Nutcracker.2293
- Nutcracker.2725
- Nutcracker.2900
- Nutcracker.3100
- Nutcracker.3500
- Nygus.397
- Obid.555
- Offspring.1130
- Offspring.1134
- Offspring.1138
- Offspring.1555
- Offspring.1666
- Ogwo.446
- Oolong.1380
- Open.1569
- Oppressor.509
- Orce.71
- Overdoze.1033
- Ox.475
- Pfeifer.1504
- Pinworm.2040
- Pinworm.2371
- Pinworm.2566
- Pinworm.2585
- Pinworm.2780
- Plague.2647
- Polish.1769
- PressReset.607
- PSFL.1005
- PS-MPC.331.B
- PS-MPC.405.B
- PS-MPC.665
- PS-MPC.783
- PS-MPC.808
- Punisher.1632
- PVW.1063
- Pysk.2464
- Quaver.500
- Quid.656
- Rael.3211
- RagDoll.942
- Rajaat.197
- Rajaat.518
- Rajaat.730
- Rape.1882
- Rape.486
- Reedcat.928
- Rescue.3423
- Retailer.1522
- Riot.1435
- Roohi.2048
- Russel.3072
- Salamander.940
- SanLoreno.1025
- Santana.665
- Saratov.1790
- Satyricon.335
- SayNay.5115
- SE.1853
- Shutdown.698
- Signs.615
- SillyC.109
- SillyC.110
- SillyC.184
- SillyC.190.B
- SillyC.254.B
- SillyC.339
- SillyC.432
- SillyC.478
- SillyCR.59
- SillyCR.119
- SillyCR.125
- SillyCR.152
- SillyCR.192
- SillyCR.403
- SillyOR.49/50
- SillyOR.60
- SillyOR.66.A
- SillyOR.66.B/70
- SillyOR.68
- SillyOR.69
- SillyOR.76.B
- SillyOR.77
- SillyOR.98
- SillyOR.99
- SillyOR.102
- SillyOR.107
- SillyOR.122
- SillyOR.131
- SillyOR.144
- SillyOR.177
- Sirius.4608
- Sister.792
- Skater.571/697
- Slaughter.512
- Slop.253
- Slost.596
- Sova.4096
- Slow_Format.699
- Small.58
- SMVB.708
- Sochi.703
- Sofar {1}
- Sofar {2}
- Sofia.528
- Solar.100
- Solar.102
- Solar.122
- Soldier.545/547/557
- Soldier.1480
- Sorry.256
- Stalkerx.650
- Stardot.1101
- Storm {2}
- Struck.731
- Sunset.5824
- SVirus.332
- Swass.442
- SZA.1864
- Tanpro.524
- Tea.1024
- Tequila.2468.C
- Tequila.2468.D
- Terra.1027
- Tet.409
- That.618
- ThreeE.384
- Tiawan.1455
- Tigre.1116
- Timid.245
- Timid.289
- Tiny.137
- Tiso.940
- Titanium.844
- Today.477
- Tokyo.1068
- Trivial.18
- Trivial.26.C
- Trivial.27.C
- Trivial.27.E
- Trivial.29
- Trivial.37
- Trivial.40.H
- Trivial.42.I
- Trivial.80
- Trivial.132
- Trivial.201
- Trivial.214.A
- Trivial.214.B
- Trivial.284
- Trojector.1561
- TS.1235
- TT.712
- TVED.780
- TVPO.3654
- TVPO.3654 {germ}
- Twister.12288/16384
- UESTC.888
- Uncured.767
- Underdog.1443
- Undergrade.1500
- Undershove.439
- Union.1531
- Unruly.1121
- Unskip.1908
- Unsnared.814
- UsePascal.2564
- UU.1200
- Variable_Worm.913
- VCC.265
- VCC.270/300
- VCC.353
- VCC.550
- VCC.571
- VCC.377
- VCC.408/506/556/886
- VCC.433
- VCC.510
- VCL.342
- VCL.512
- VCL.952
- VCL.2037
- VCLComp.279
- VCLComp.316
- VCLComp.325
- VCLO.206
- VCLO.267/466
- VCLO.288
- VCLO.302
- VCode.1633
- VCode.2262
- VD.1664
- Vector.441
- Vesna.1000
- Vesna.1700
- Vesna.1833
- Vice_1.Sample
- Vice_2.Firecide
- Vice_2.Iceburn/Icemelt
- Vice_5.3952
- Vienna.348
- Vienna.486
- Vienna.521
- Vienna.566
- Vienna.573
- Vienna.583
- Vinchuca.925
- Vinn.1620/1658 {com}
- Vinn.1620/1658 {exe}
- Void.1886
- Vulcan.496
- Waria.479
- WCWA.998
- WereWolf.1208
- WereWolf.1500
- WinSurfer
- WinTiny.174
- WMA.678
- WormSign.1710
- WRZod.1043
- XIVLO.2248
- Xora.1024
- Xram.1355
- XTC.2153/2169
- Xuxa.1656
- You.1186
- Zmiana.1016
- Zmiana.1224
- Zor.836
- ZZ.412
-
- - Added macro virus signatures:
-
- WordMacro/Boom
- WordMacro/Date
- WordMacro/Divina
- WordMacro/Friends
- WordMacro/Guess
- WordMacro/Nop
- WordMacro/Pheeew
- WordMacro/Telefonica
-
-