Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4228
DAT Release Date 10/09/2002
Threats Detected 61789
New Detections 226
Enhanced Detections 245

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Fleming.worm Low-Profiled Low-Profiled
Cytron Low-Profiled Low-Profiled

New Detections:

Program (10)
   (2)
    Generator.Perm
    Generated.Perm
  - (1)
    Distributed.net
  Client (1)
    Distributed.net.client
  Dialer (2)
    PornDial-89
    PornDial-43
  Joke (1)
    Hacked joke
  Remote Access (2)
    Tool-SynSpy
    BackDoor-ALA
  Win32 (1)
    Generated.KME
Trojan (32)
  Application extension (1)
    PWS-Pksob.dll
  Denial Of Svc (1)
    Linux/DDoS-Kaiten
  Disk erasing (1)
    QZap232
  Downloader (1)
    PWS-Pksob.ldr
  Dropper (4)
    Bat/abc.dr
    PWS-PKsob.dr
    BackDoor-ALE.dr
    BackDoor-AFI.dr
  Exploit (2)
    UNIX/Exploit-Rogue
    Linux/Exploit-SSL
  Internet Relay Chat (1)
    IRC-Sporkbot
  Linux (3)
    Linux/ESPaker
    Linux/ESKDEartsd
    Linux/ESDos-Xchat
  Malware Tool (2)
    Kit-Virugen
    Kit-Gichty
  Password Stealer (1)
    PWS-Pksob
  Plugin component (1)
    BackDoor-AHB.plugin
  Remote Access (8)
    BackDoor-ABB
    BackDoor-ALC
    BackDoor-ALH
    Backdoor-ALG
    BackDoor-ALF
    BackDoor-ALE
    BackDoor-ALD
    BackDoor-AHB.vxd
  Script (3)
    Bat/abd
    Bat/abc
    BackDoor-ALE.bat
  Spyware (1)
    Cytron
  Win32 (1)
    SMSBone
  Worm (1)
    Linux/Mighty.worm
Virus (184)
   (47)
    Wildthing.567
    Vienna.648x
    Mte.Encroacher.715
    Hymn.2144.b
    Hymn.1962.d
    Hymn.1962.b
    Horse.1776
    Horse.1594
    Horse.1576
    Horse.1160
    Horse.1154b
    Dark Avenger.2271
    Dark Avenger.1865.d
    Dark Avenger.1687dr
    Dark Avenger.1803
    Dark Avenger.1687
    Dark Avenger.1459
    Dark Avenger.1018
    Danish Tiny
    BootDr220
    Auspar.369b
    Xany.475
    Xany.127
    Hymn.2144.c
    Hymn.2144.a
    Hymn.1962.c
    Hymn.1962.a
    Horse.1158
    Horse.1154a
    Dark Avenger.1865.e
    Dark Avenger.1459dr
    BootDr219
    Xany.361
    Taurus.586
    SW.504
    QRes.1198
    OC/bv
    Mainman
    Levitate.800
    Leapfrog.519
    Lame.2030
    Helloween.2470a
    Flashlight.966
    Cocaine.664
    Atomant.2143
    Acceptance.309
    Hackware.3199
  Boot (1)
    Hurt
  Damaged (13)
    Vienna.1000.dam
    Vienna.828.dam
    MPC.1684.dam
    Pacman.dam
    Danish Tiny.163.dam
    Ninja.dam
    Morgot.823.dam
    Grunt.346.dam
    Bifurcator.1648.dam
    W32/Shaitan.3550.dam
    Anthrax.dam
    W32/Shorm.dam
    W32/Bugbear.dam
  Damaged Worm (1)
    W32/Opaserv.worm.dam
  Dropper (60)
    Univ/p.dr
    Univl/a.dr
    Zombie.Hello.dr
    Wildthing.dr
    Werewolf.1500.c.dr
    MPC.603.dr
    MDMA.dr
    Leech.dr
    IVP.Darlene.dr
    IVP.479.dr
    Iceland.dr
    Greets.3000.dr
    BW.Mayberry.dr
    Akuku.dr
    Willy.dr
    Vacsina.dr
    Ultimate.dr
    Taurus.dr
    Stinkfoot.dr
    Scitzo.dr
    Vienna.dr
    Uruguay.dr
    Syslock.dr
    MPC.Sorlec.dr
    MPC.577.dr
    IVP.596.dr
    Eight Tunes.dr
    BW.Gateway.dr
    Ash.dr
    Zero.dr
    WW.217.dr
    Voices.dr
    Slug.dr
    Rape.dr
    Rael.dr
    Pusher.dr
    Pombero.dr
    PME.dr
    Phoenix.dr
    Persecute.dr
    Perfume.dr
    ParInt.dr
    Ox.dr
    Morgot.dr
    Minsk.dr
    Midin.dr
    Keyb.dr
    Iron Maiden.dr
    Haifa.dr
    Guerilla.dr
    Fog.dr
    Evolution.dr
    Cosmin.dr
    Backform.dr
    AWME.dr
    Ambo.dr
    W95/Roma.b.dr
    Maverick.1536.dr
    Jinx.674.dr
    Anthrax.dr
  Dropper Parasitic (1)
    Cluster.cav.dr
  Dropper Unpacked (1)
    Phoenix.dr.unp
  E-mail worm (2)
    W32/Hobbit.c@MM
    W32/Hobbit.b@MM
  Email (3)
    W32/Indor.c@MM
    W32/Indor.b@MM
    W32/Indor.a@MM
  Generic (3)
    ParInt.GR
    VBS/Gichty.gen
    W32/Hobbit.gen
  Generic Overwriting (1)
    W32/Hadefix.ow.gen
  Generic Worm (2)
    W32/Spear.worm.gen
    W32/Lich.worm.gen
  Intended (4)
    VBS/Cocau.a.intd
    W32/Npe.intd
    W97M/Mary.intd.e
    W97M/Mary.intd.d
  Internet Worm (3)
    W32/Cazinat.worm.b
    W32/Fleming.worm
    W32/Cazinat.worm.a
  Malware Tool (1)
    HLL.DNazi.Kit
  Overwriting (3)
    HLL.ow.7216
    W32/Hadefix.ow.g
    W32/Hadefix.ow.f
  Parasitic (5)
    Frodo.apd
    Danish Tiny.apd
    Ultra Fire.apd
    Lesson.apd
    After.266.apd
  Script (5)
    VBS/Cocau.c
    Bat/abb
    Bat/aba
    W32/Trilisa.bat
    QZap232.bat
  Win32 (13)
    W32/HLL.ow.Elitiamo
    W32/Varra
    W32/Shaitan.3392intd
    W32/Shaitan.3482
    W32/Shaitan.3390
    W32/Shaitan.3550
    W32/Lemo
    W32/Hezhi.c
    W32/Hatter
    W32/Flatei
    W32/Flatei.5125
    W32/Flatei.5632
    W32/Appix.php
  Win9x (4)
    W95/CTX.10853
    W95/CTX.6886
    W95/Uwaga.3237
    W95/Ramdile
  Worm (11)
    W32/Zaka.worm.p
    W32/Tefuss.worm
    W32/Spear.worm.d
    W32/Spear.worm.f
    W32/Kotef.worm
    W32/EnerKaz.worm.h
    W32/EnerKaz.worm.g
    W32/EnerKaz.worm.f
    W32/Dax.worm
    W32/Cazinat.worm
    W32/Bare.worm.e

Enhanced Detections:

Trojan (33)
   (1)
    Helloween
  Application extension (8)
    PWS-Templar.dll
    PWS-Johar.dll
    AntiSpam.b.dll
    PWS-Pricol.dll
    AntiSpam.c.dll
    AntiSpam.a.dll
    PWS-EQ.dll
    PWS-EX.dll
  Damaged (1)
    Kruls.dam
  Downloader (1)
    Downloader-Y
  Dropper (4)
    AntiSpam.c.dr
    AntiSpam.a.dr
    AntiSpam.b.dr
    PWS-AO.dr
  Internet Relay Chat (1)
    IRC-Bleh
  Password (1)
    Pws-CK
  Password Stealer (6)
    PWS-Pricol
    PWS-EX
    PWS-EQ
    PWS-CI
    PWS-AO
    PWS-CC
  Remote Access (6)
    BackDoor-AJL
    BackDoor-WN
    BackDoor-ST
    BackDoor-JL
    BackDoor-AHB
    BackDoor-AFI
  Script (2)
    JS/Dooler
    BackDoor-AF.bat
  Server (1)
    BackDoor-ABB.svr
  Win32 (1)
    Kruls
Virus (212)
   (150)
    Trigger.2500
    Zombie.1993
    Intmaster.1349
    GrnCat.1588
    Zombie
    Zombie.1823
    Merlin.4230
    Jest
    Intmaster.1878
    Intmaster.1872
    Intmaster.1351
    Holms.6161
    GrnCat.1819
    Grog.1089
    GiMon.dd
    GCAE.Lucky Seven.3400
    GCAE.2915
    GCAE.2580
    GCAE.2558
    Fish6.3584.b
    Fish6.3584
    EVC.b
    EVC.a
    Emmie.2496
    Emmie.2620
    Emmie.2604
    GCAE
    Emmie.1739
    Elf.9000
    Elf.3675
    Elf.3458
    Elf.3400
    Elf.3290
    Elf.3187
    Elf.3187dr
    Elf.2815
    Elf.2731
    Elf.2656
    Elf.2218
    Dune
    DSME.Connie.3140
    DSME.2200
    DSME.Apex.2893
    DSCE.MD
    Crow.1475
    Crow.1453
    Crow
    CLME.Ming.2027
    CLME.Ming.1952
    CLME.Ming.1951
    CLME.Ming.1950
    Civil War.560
    Civil War.344
    Civil War.342
    Civil War.302j
    Civil War.302i
    Civil War.302h
    Civil War.302g
    Civil War.302f
    Civil War.302e
    Civil War.302d
    Civil War.302c
    Civil War.302b
    Civil War.302a
    Civil War.299
    Civil War.266
    Civil War.262
    Civil War.250
    Chad.759
    Cascade.George.1701
    Cascade.Formiche.6258
    Cascade.ssr.1701
    Cascade.1701.ca
    Cascade.1621
    Cascade.1491
    BW.Mut.2055
    BW.Delima.1283
    Asmodeous.1833
    Asmodeous.1829
    ARCV.1183
    ARCV.Payrise.874
    ARCV.827.b
    ARCV.827.a
    ARCV.795
    ARCV.Ice.750
    ARCV.Ice.734
    ARCV.644
    ARCV.642
    ARCV.Payrise.897
    ARCV.Ice.746
    ARCV.742
    ARCV.731
    ARCV.743
    ARCV.678
    ARCV.639b
    ARCV.639a
    ARCV.441
    ARCV.670
    ARCV.339
    Arara.x
    Arara.1054
    Andromeda.1536d
    Andromeda.1536b
    Alive.4608e
    Alicino.39722
    Alicino.962
    Vanq
    Slug.872
    Persecute.3375
    MPC.1045
    Model.533
    Midin.b.838
    Midin.b.783
    Midin.b.775
    Midin.a.765
    Midin.a.760
    Maverick.1536.e
    Maverick.1536.g
    Maverick.1536.c
    Maverick.1536.a
    Andromeda.1536a
    Alicino
    Alicino.1307
    Slug.880
    Maverick.1536.f
    Maverick.1536.d
    Maverick.1536.b
    Kumoro.1194
    Guerilla
    CHCC.2662
    Charlie.1536
    Chaos.1181q
    Bifurcator.1648
    AWME
    Ambo.796
    BW.Mbry.Barney.496
    BW.Mbry.Barney.495
    BW.Mbry.Barney.491
    BW.Mbry.Barney.358
    BW.Mbry.Barney.477
    Ontario.512.j
    Ontario.512.i
    Ontario.512.h
    Mutint.603.app
    Minsk.1075.b
    Donkey.10240.app
    Dichotomy.app.571
    Dichotomy.app.569
    Dichotomy.app.567
    Cod.775.app
  Application extension (1)
    W32/Wide.dll
  Companion (1)
    W32/Nan.cmp.89600
  Configuration settings (1)
    VBS/Slug.ini
  Damaged (4)
    ARCV.399.dam
    Arara.1054.dam
    Ultimate.419.dam
    Popcorn.300.dam
  Demonstration (3)
    DSME.Demo.b
    DSME.Demo.a
    DSCE.Demo.3250
  Dropper (15)
    Trigger.dr
    Fish6.3584.dr
    Fish6.dr
    EVC.dr
    Cascade.1701.ca.dr
    ARCV.1183.dr
    ARCV.670.dr
    APE.dr
    SGWW.Bomber.dr
    MF.dr
    Lame.dr
    Trident.dr
    W32/Zmist.dr
    W32/Bolzano.irc.dr
    Univ/ow.d.dr
  Dropper Intended (4)
    W32/Hatred.dr.intd
    W32/Hatred.dr.c.intd
    W32/Hatred.dr.b.intd
    W32/Hatred.dr.a.intd
  Email (1)
    W32/Melting@M
  File Infector (5)
    Emmie.2702
    W32/Flatei.5129
    CLME.Ming.1528
    Malaise
    Leapfrog
  Generic (3)
    Arara.GR
    Ultimate.GR
    W95/Dengue.gen
  Heuristic (2)
    New VB EMail Worm
    New Year.1356
  HTML (1)
    HTML/ow
  Intended (3)
    W97M/Mary.intd.b
    W97M/Mary.intd.a
    W97M/Mary.intd.c
  Joke (2)
    Big Joke.1069
    Big Joke.1068
  Overwriting (1)
    OPA.ow
  Parasitic (3)
    Cluster.cav
    W32/HLLP.63488
    W32/HLLP.186368
  Script (3)
    Babyfly
    VBS/Slug
    Bat/fz
  Win32 (4)
    W32/Butool
    W32/CTX
    W32/Thespy.c
    W32/Flatei.6154
  Win9x (1)
    W95/Legacy
  Worm (4)
    W32/Klasd.worm.a
    W32/Klasd.worm.b
    W32/EnerKaz.worm.c
    W32/Klasd.worm.c