Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4232
DAT Release Date 11/06/2002
Threats Detected 62223
New Detections 91
Enhanced Detections 465

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Braid.a@MM Low-Profiled Low-Profiled
W32/Oror.e@MM Low-Profiled Low-Profiled
VBS/Sucop Low-Profiled Low-Profiled

New Detections:

Program (5)
  Joke (2)
    Delay joke
    QScreen5 joke
  Malware Tool (1)
    PWCrack-HTTPBrute
  Tool (2)
    Sniff-AssIP
    Tool-Embedder
Trojan (39)
   (2)
    Locker
    Bomba
  Configurator (2)
    MultiDropper-AR.cfg
    MultiDropper-EM.cfg
  Downloader (1)
    Downloader-BN
  Dropper (3)
    MultiDropper-EM
    MultiDropper-EL
    Predator.drpd
  File Deletion (1)
    Qdel296
  Generic (3)
    BackDoor-MD.gen
    BackDoor-BT.gen
    BackDoor-EE.gen
  Keylogger (1)
    Keylog-Sinred
  Linux (1)
    Linux/Shadoor
  Malware Tool (2)
    OC/by.kit
    Spam-HRVG
  Password Stealer (6)
    PWS-Trial
    PWS-SvenX
    PWS-Klepto
    PWS-Tenfg
    PWS-Ourgame
    PWS-Kervar
  Remote Access (8)
    BackDoor-AME
    BackDoor-AMF
    BackDoor-FN
    Linux/Backdoor-ssl.scanner
    Linux/Backdoor-ssl.brute
    BackDoor-AMG
    BackDoor-KJ
    BackDoor-BT
  Script (4)
    Bat/abl
    Bat/abk
    VBS/Flood.bh
    VBS/Stuck
  Tool (1)
    Tool-Apher
  Win32 (4)
    AIM-Phader
    MouseMunch
    IPCScan
    AVKill-R
Virus (47)
   (4)
    Medical.189d
    Vector.441
    Roki.189
    Vector.304
  Configuration settings (1)
    W32/Oror.ini
  Configuration settings Dropp (1)
    W32/Oror.ini.dr
  Dropper (2)
    W32/Tator.dr
    W95/Ramdile.dr
  Dropper Worm (1)
    W32/Kamil.worm.b.dr
  E-mail worm (3)
    W32/Oror.e@MM
    VBS/VBSWG.aw@MM
    MSIL/Gaze@MM
  Email (5)
    VBS/VBSWG@MM
    MSIL/Generic@MM
    W32/Braid@MM
    W32/Amani@MM
    W32/Kitro.m@MM
  File Infector (1)
    W32/Braid.a@MM
  Generic (1)
    W32/Tator.gen
  Heuristic (1)
    New Malware.b
  Intended (1)
    VBS/Gleion.intd
  Open Share Worm (1)
    W32/MouseMunch.worm
  Parasitic (2)
    Vector.441.apd
    Vector.304.apd
  Script (8)
    JS/Sdan
    Bat/Nahata
    W32/Kamil.b.bat
    JS/Alcaul
    Perl/Vamp
    VBS/Lavra
    VBS/Cray
    W32/Appix.reg
  Source code (1)
    W32/Sponge.src
  VbScript (2)
    VBS/Sucop
    VBS/Sucop
  Win32 (3)
    W32/Sleepy
    W32/Appix
    W32/Integr.1112
  Win9x (2)
    W95/Thorin.10705
    W95/Score.a
  Worm (7)
    W32/Appix.f@MM
    W32/STD.f.worm
    W32/Foxma.worm.d
    W32/STD.e.worm
    W32/Kamil.worm.b
    W32/Foxma.worm.e
    W32/Buzzard.worm

Enhanced Detections:

Program (4)
  Macro (1)
    WM/Auge
  Malware Tool (3)
    PWCrack-Dragon
    PWCrack-Decoder
    PWCrack-Diamond
Trojan (193)
   (3)
    CGILogger-A
    Uploader
    CSC/CST
  Application extension (1)
    PWS-GA.dll
  Configurator (2)
    ICQ-Pager-E.cfg
    ICQ-Pager-B.cfg
  Disk erasing (79)
    QZap112
    QZap192
    QZap190
    QZap188
    QZap183
    QZap175
    QZap171
    QZap168
    QZap154
    QZap146
    QZap141
    QZap138
    QZap129
    QZap126
    QZap119
    QZap117
    QZap176
    QZap173
    QZap104
    QZap102
    QZap69
    QZap67
    QZap65
    QZap63
    QZap62
    QZap61
    QZap57
    QZap55
    QZap50
    QZap42
    QZap38
    QZap36
    QZap34
    QZap33
    QZap31
    QZap29
    QZap28
    QZap27
    QZap25
    QZap23
    QZap22
    QZap21
    QZap19
    QZap18
    QZap17
    QZap15
    QZap12
    QZap10
    QZap6
    QZap1
    QZap189
    QZap186
    QZap179
    QZap178
    QZap167
    QZap148
    QZap144
    QZap139
    QZap134
    QZap127
    QZap122
    QZap118
    QZap116
    QZap101
    QZap68
    QZap66
    QZap64
    QZap58
    QZap56
    QZap48
    QZap47
    QZap37
    QZap32
    QZap30
    QZap26
    QZap24
    QZap20
    QZap11
    QZap7
  DOS (1)
    QDel157
  Dropper (2)
    VBS/MultiDropper-DZ
    BackDoor-LT.dr
  File deleting (81)
    QDel173
    QDel170
    QDel161
    QDel158
    QDel171
    QDel169
    QDel156
    QDel155
    QDel154
    QDel153
    QDel149
    QDel147
    QDel146
    QDel145
    QDel144
    QDel143
    QDel142
    QDel138
    QDel137
    QDel132
    QDel131
    QDel129
    QDel119
    QDel112
    QDel109
    QDel107
    QDel103
    QDel102
    QDel99
    QDel98
    QDel96
    QDel95
    QDel94
    QDel93
    QDel86
    QDel85
    QDel84
    QDel81
    QDel80
    QDel77
    QDel75
    QDel66
    QDel65
    QDel63
    QDel62
    QDel61.pif
    QDel60
    QDel59
    QDel58
    QDel57
    QDel53
    QDel51
    QDel48
    QDel45
    QDel44
    QDel43
    QDel33
    QDel31
    QDel27
    QDel23
    QDel21
    QDel130
    QDel116
    QDel100
    QDel64
    QDel38
    QDel29
    QDel28
    QDel19
    QDel16
    QDel15
    QDel12
    QDel11
    QDel9
    QDel8
    QDel6
    QDel5
    QDel4
    QDel3
    QDel2
    QDel1
  ICQ Messaging (5)
    ICQ-Pager-E
    ICQ-Pager-D
    ICQ-Pager-B
    ICQ-Pager-F
    ICQ-Pager-A
  Internet Relay Chat (1)
    IRC-MetBot
  Macro (4)
    W97M/Zmk.d
    WM/Stupid
    WM/Balu
    WM/FormatC
  Password Stealer (1)
    PWS-GG
  Remote Access (1)
    BackDoor-AC
  Script (6)
    VBS/Chango
    Bat/ShareC
    VBS/Funtime
    QDel43.bat
    QDel119.bat
    IRC/Drimwa.bat
  Self-extracting archive (2)
    QDel61.sfx
    QDel59.sfx
  Win32 (4)
    WinHawk
    Mazdai
    Destructive.a
    AX/DirRename
Virus (268)
   (5)
    Carnage.621
    Prime.1164
    CSC/CSV.a
    APM/Minimal
    APM/GreenStripe
  Damaged (1)
    WM/Twno.dam
  Disk erasing (1)
    QZap169
  Dropper (1)
    VBS/Godog.dr
  Email (12)
    W32/Kitro.k@MM
    W32/Kitro.i@MM
    W32/Kitro.f@MM
    W32/Kitro.b@MM
    W32/Kitro.a@MM
    W32/Kitro.l@MM
    W32/Kitro.j@MM
    W32/Kitro.h@MM
    W32/Kitro.d@MM
    W32/Kitro.g@MM
    W32/Kitro.e@MM
    W32/Kitro.c@MM
  File Infector (2)
    Sarcoma.1328
    QZap14
  Generic (4)
    VBS/Gichty.gen
    WM/Talon.gen
    WM/Nova.gen
    W32/Sadquote.gen
  Intended (11)
    WM/Ultras.intd.c
    WM/Ultras.intd.b
    WM/Ultras.intd.a
    WM/Minimal.ah.intd
    WM/Minimal.ag.intd
    WM/Minimal.aq.intd
    WM/Alex.e.intd
    WM/Alex.c.intd
    WM/Alex.b.intd
    WM/Goblin.intd
    WM/Alex.a.intd
  Internet Relay Chat (4)
    IRC/Mypic
    IRC/Minder
    IRC/Mojo
    IRC/Nodog
  Macro (221)
    WM/Ammy
    WM/MVDK1.A
    WM/Counter.A
    WM/Munch.A
    WM/SWITCHER.G
    WM/IMPOSTER.E
    WM/INEXIST.A
    WM/PESAN.B
    WM/NUCLEAR.T
    WM/EMT.A
    WM/OBLOM.D
    WM/OBLOM.C
    WM/OBLOM.A
    WM/SCHUMANN.B
    WM/SCHUMANN.A
    WM/Lucy.A
    WM/GOLDSECRET.A
    WM/CONCEPT.BB
    WM/NOPRINT.A
    WM/SAFWAN.A
    WM/ANT.B
    WM/SHOWOFF.AC
    WM/SHOWOFF.R
    WM/TALON.A
    WM/TALON.G
    WM/TALON.E
    WM/TALON.C
    WM/TALON.B
    WM/Niknat.A
    WM/BABY.A
    WM/SHOWOFF.G
    WM/Leonor.a
    non-viable WM/Cap
    WM/Yaka.b
    WM/Yaka.a
    WM/Wompie
    WM/Wompat
    WM/Want
    WM/Vicis
    WM/Vicinity
    WM/VHDL.b
    WM/Varmint.a
    WM/Vampire.m
    WM/Vampire.l
    WM/Vampire.h
    WM/Vampire.f
    WM/Vampire.d
    WM/Vampire.c
    WM/Vampire.b
    WM/Vampire.a
    WM/Ultimo
    WM/UglyKid
    WM/Uck
    WM/Twno.g
    WM/Twno.f
    WM/Twno.j
    WM/Twno.b
    WM/Twno.ar
    WM/Twno.ap
    WM/Twno.am
    WM/Twno.al
    WM/Twno.ak
    WM/Twno.ag
    WM/Twno.ad
    WM/Twno.ab
    WM/Twno.aa
    WM/Twno.z
    WM/Twno.y
    WM/Twno.x
    WM/Twno.w
    WM/Twno.q
    WM/Twno.o
    WM/Twno.n
    WM/Twno.l
    WM/Twno.i
    WM/Twno.c
    WM/Twno.d
    WM/Triple
    WM/Tribute.a
    WM/Trap.d
    WM/Trap.b
    WM/Th
    WM/Th.a
    WM/VHDL.a
    WM/Vampire.i
    WM/Vampire.g
    WM/Vampire.e
    WM/Twno.h
    WM/Twno.an
    WM/Twno.ai
    WM/Twno.ah
    WM/Twno.ae
    WM/Twno.ac
    WM/Twno.v
    WM/Twno.k
    WM/Twno.a
    WM/Twno.e
    WM/Tunguska
    WM/Tribute.b
    WM/Trash
    WM/Trap.c
    WM/Trap.a
    WM/Th.b
    WM/Techno
    WM/Tamago.e
    WM/Talon.h
    WM/Talon.f
    WM/Talon.d
    WM/Talon.n
    WM/Talon.l
    WM/Switcher.a
    WM/Superstitious
    WM/Stall
    WM/Slow
    WM/Silvina
    WM/Showoff.ck
    WM/Showoff.cd
    WM/Showoff
    WM/Schumann.c
    WM/Schumann.u
    WM/Schumann.m
    WM/Sam.b
    WM/Safwan.b
    WM/Rellik
    WM/Rapi
    WM/Ramses
    WM/Quick
    WM/President
    WM/Pig.f
    WM/Pig.e
    WM/Pig.d
    WM/Pig.g
    WM/Pig.c
    WM/Pig.b
    WM/Pig.a
    WM/Percent
    WM/Pelo
    WM/Oblom.i
    WM/Oblom.h
    WM/Oblom.g
    WM/Oblom.f
    WM/Oblom.b
    WM/Noprint.b
    WM/Niknat.d
    WM/Niknat.b
    WM/Narmol
    WM/MVDK2
    WM/Munch.b
    WM/Muck
    WM/Mota
    WM/Minimal.aj
    WM/Minimal.ai
    WM/Minimal.av
    WM/Minimal.at
    WM/Minimal.as
    WM/Minimal.ar
    WM/Minimal.u
    WM/Mess
    WM/Mercado.a
    WM/Mercado
    WM/Mental
    WM/Mensagem
    WM/Matey
    WM/Mark.a
    WM/Marbles
    WM/Malaria
    WM/Lucy.b
    WM/Killuf.b
    WM/KillDOS
    WM/Karatka
    WM/Innuendo
    WM/Imposter
    WM/Mercado.e
    WM/Mercado.d
    WM/Mark.c
    WM/Mark.b
    WM/Leonor.b
    WM/Lamah
    WM/Killuf.a
    WM/Jerm
    WM/Inexist.b
    WM/Hunter
    WM/Hunter.a
    WM/Hot.b
    WM/Header
    WM/Gsis.a
    WM/Fries
    WM/FiveA
    WM/Fehler
    WM/Eraser.p
    WM/Epidemic.a
    WM/Epidemic.b
    WM/EMT.c
    WM/Dracula
    WM/Decaf
    WM/Cabeza.a
    WM/Breaktime
    WM/Ant.e
    WM/Ant.f
    WM/Ant.c
    WM/Angus
    WM/Katty
    WM/Hunter.b
    WM/Hou
    WM/Hot.a
    WM/Gurre
    WM/Gsis.b
    WM/GoldSecret.b
    WM/Goblin.b
    WM/Gnomo
    WM/Gier
    WM/Epidemic.c
    WM/ENFK
    WM/EMT.b
    WM/Dust
    WM/Cabeza.b
    WM/Bumble.b
    WM/Armadillo
    WM/Antiwazzu
    WM/Ant.d
    WM/Ant.a
  Malware Tool (2)
    NGV.kit
    WM/MVDK1.Kit
  Overwriting (1)
    HLL.ow.3328
  Script (2)
    VBS/Abbum
    VBS/Antipedo
  Win9x (1)
    W95/Score