Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4235
DAT Release Date 11/27/2002
Threats Detected 62464
New Detections 214
Enhanced Detections 153

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Korvar Low-Profiled Low-Profiled
QDel350 Low-Profiled Low-Profiled

New Detections:

Program (10)
   (1)
    VMag/mut
  Adware (1)
    Adware-Tronix
  Dialer (2)
    PornDial-100
    PornDial-99
  Downloader (1)
    Downloader-BR
  Process (1)
    ProcKill-T
  Remote Access (1)
    BackDoor-ANE
  Tool (2)
    Tool-AutoPol
    Tool-DNSMast
  Win31 (1)
    PhoneTag
Trojan (63)
   (1)
    AHADisk
  - (1)
    Hide Minimized
  Configuration settings (2)
    Bat/abe.ini
    Spexam.ini
  Configurator (10)
    ProcKill-Q.cfg
    MultiDropper-ET.cfg
    MultiDropper-ES.cfg
    MultiDropper-ER.cfg
    MultiDropper-EP.cfg
    MultiDropper-EO.cfg
    MultiDropper-EN.cfg
    IRC-Contact.cfg
    Downloader-BP.cfg
    Downloader-BG.cfg
  Disk erasing (1)
    QZap299
  Downloader (2)
    Downloader-BP
    Downloader-BQ
  Dropper (9)
    Bat/acl.dr
    MultiDropper-ET
    MultiDropper-ES
    MultiDropper-ER
    MultiDropper-EQ
    MultiDropper-EP
    MultiDropper-EO
    MultiDropper-EN
    Hide Minimized.dr
  File Deletion (1)
    QDel350
  Generic (2)
    MultiDropper-ER.gen
    BackDoor-AMZ.gen
  Malware Tool (1)
    YOFVG.kit
  Plugin component (1)
    BackDoor-ANF.plugin
  ProcKill (13)
    ProcKill-H
    ProcKill-F
    ProcKill-S
    ProcKill-Q
    ProcKill-P
    ProcKill-M
    ProcKill-L
    ProcKill-K
    ProcKill-J
    ProcKill-F.cln
    ProcKill-D
    ProcKill-C
    ProcKill-O
  Remote Access (7)
    IRC/Flood.c.dr
    BackDoor-ANF
    BackDoor-ANG
    BackDoor-ANC
    BackDoor-ANB
    BackDoor-AMZ
    BackDoor-AMW
  Script (8)
    Bat/bek
    Bat/acp
    Bat/acn
    Bat/hdk13
    Bat/ago
    Bat/aco
    Bat/acm
    W32/Hunch.bat
  Server (1)
    BackDoor-ANF.svr
  Win32 (3)
    Spexam
    Sear
    KeySpy-Cmon
Virus (141)
   (66)
    Seventh-Son.326b
    Seventh-Son.282
    Werewolf.1450.c
    VICE4b.4189
    Swedish.441a
    Swedish.459f
    Seventh-Son.326a
    Seventh-Son.333c
    Seventh-Son.284f
    Seventh-Son.284a
    Seventh-Son.271b
    Seventh-Son.268
    Jeru.Sunday.1633d
    Jeru.Pipi.x
    Jeru.1525a
    Intmaster.1340
    BootDr225
    Willow.1662
    VCCd.538a
    VCCa.264a
    Thunder.892
    Shadow.1187
    Para.dd.1499
    Lucy.5286b
    Seventh-Son.327
    Seventh-Son.344
    Seventh-Son.333d
    Seventh-Son.333b
    Seventh-Son.254
    Seventh-Son.253
    Seventh-Son.283
    Seventh-Son.331
    Seventh-Son.473b
    Seventh-Son.473a
    Seventh-Son.440
    Seventh-Son.428
    Seventh-Son.426
    Seventh-Son.424
    Seventh-Son.350b
    Seventh-Son.350a
    Seventh-Son.334
    Seventh-Son.333
    Seventh-Son.332c
    Seventh-Son.332b
    Seventh-Son.332a
    Seventh-Son.286
    Seventh-Son.284e
    Seventh-Son.284d
    Seventh-Son.284c
    Seventh-Son.284b
    Seventh-Son.281
    Seventh-Son.271a
    Npox.1839
    Jeru.Sunday.1633c
    Jeru.1525b
    Jeru.1390
    Cascade.1704.y
    Alive.3800
    Yosha.272
    VCCa.264b
    QDrag.x
    Para.1499
    Meihua.1491
    Antigus
    Alabama.1560
    HLL.Bigbug.9500b
  Boot (2)
    Jordi
    Hunk
  Companion (1)
    Offspring.cmp.1306
  Configuration settings (2)
    HLL.BigBug.ini
    W32/Indor.ini
  Damaged (4)
    Maverick.2048.dam
    Thunder.892.dam
    Maverick.1536.dam
    W32/Magistr.dam
  Dropper (7)
    Bat/cod.dr
    Alive.3800.dr
    Tardy.503.dr
    W32/Fosforo.dr.c
    W32/Chiton.i.dr
    W32/Chiton.h.dr
    W32/Chiton.g.dr
  Dropper multipartite (1)
    Red Vixen.mp.dr.3590
  Dropper Overwriting (1)
    JS/Frist.ow.dr
  Dropper Parasitic (1)
    Funked.cav.e.dr
  E-mail worm (1)
    W32/GOP.j@MM
  Email (7)
    W32/Hobbit.e@MM
    W32/Hobbit.f@MM
    W32/Rebec@MM
    W32/Chet.d@MM
    W32/BadCode@MM
    W32/Appix.j@MM
    W32/Appix.i@MM
  Generic (2)
    VBS/VBSWG2.gen
    VBS/DDV.gen
  Generic Worm (1)
    W32/Zaka.worm.gen
  Intended (2)
    VBS/Charmand.intd
    W97M/Noodle.intd
  Macro (1)
    W97M/Padania
  multipartite (2)
    Red Vixen.mp.3590
    Kuarahy.mp.4640
  Overwriting Script (1)
    JS/Frist.ow.bat
  Parasitic (6)
    Squisher.cav.397
    W95/Radix.cav.402a
    Funked.cav.e
    W95/Radix.cav.402b
    W95/Radix.cav.403
    W95/Argos.cav.334
  Script (12)
    VBS/Sucop.a
    VBS/Horty.e
    Bat/mos
    Bat/lia
    Bat/lia.5a
    Bat/cod.174
    Bat/btg.vbs
    Bat/acl
    VBS/Sucop.b
    VBS/Reality
    VBS/Jsepace
    Bat/cod.169
  Win32 (9)
    W32/Fosforo.c
    W32/Seppuku.e
    W32/Enerlam
    W32/Dexter.g
    W32/Chiton.i
    W32/Chiton.h
    W32/Chiton.g
    W32/Cargo.e
    W32/Cargo.d
  Win9x (1)
    W95/Evil.e
  Worm (11)
    W32/Korvar
    W32/Pluto.A@MM
    W32/Amazex.b.worm
    W32/Amazex.a.worm
    VBS/Lolo.worm
    W32/Osapex.a.worm
    W32/Zaka.worm.s
    W32/Sachiel.worm.e
    W32/Osapex.b.worm
    W32/Foxma.worm.g
    W32/Foxma.worm.f

Enhanced Detections:

Program (2)
   (1)
    V3RES
  Win32 (1)
    Serv-U Daemon
Trojan (22)
   (1)
    Prinspi
  Configurator (2)
    MultiDropper-AC.cfg
    MultiDropper-Z.cfg
  Downloader (1)
    Downloader-BG
  Dropper (1)
    AVKill-B.dr
  Generic (1)
    BackDoor-AMT.gen
  Linux (1)
    Linux/Flooder.pong
  Macro (1)
    W97M/Cobra.a1
  Partition (1)
    HideMBR.b
  Remote Access (3)
    Backdoor-ALY
    BackDoor-AMJ
    BackDoor-AGP
  Script (2)
    Bat/Inreg
    Bat/pd
  Unix (1)
    Unix/Galore
  Win32 (7)
    AVKill-R
    AVKill-O
    AVKill-N
    AVKill-I
    AVKill-G
    AVKill-E
    AVKill-A
Virus (129)
   (40)
    Uruguay.4b
    Uruguay.3c
    Uruguay.3a
    Uruguay.2721
    Uruguay.4a
    Uruguay.3b
    Uruguay.2458
    Werewolf.1193
    Werewolf.1192
    VCL.829
    Jeru.1552c
    Jeru.1552b
    Jeru.1552a
    Jeru.1349dr
    Devil's Dance.941
    Wildy.354
    Wild.289
    VME
    Riverco.2959
    Risto.3210
    Riot.Multiplex
    Riot.MMIR
    PE.40
    Oracle.997
    Grad
    Genesis.295
    BootDr197
    BootDr196
    AntiCPAV.2061
    Antibase.1900
    AntiAVP.959
    Amber.3104
    Alia.1023
    Alad.2293
    Swedish.441
    Whiplash.4592
    VCCd.538
    Lucy.5286
    Locust.1456
    Bigbug.9500
  Com file (1)
    Holup.com
  Companion (4)
    HLL.cmp.8071
    Offspring.cmp.1294
    Offspring.cmp.1285
    Bigbug.cmp.8820
  Damaged (2)
    Devil's Dance.941.dam
    Orion Mobius.dam
  Damaged multipartite (1)
    Coup.2052.mp.dam
  Dropper (5)
    Bat/fz.dr
    VCL.dr.NED.Test
    VCL.dr.JFK
    FitW.4096.dr
    Bat/p.dr
  Dropper multipartite Parasit (2)
    Chloride.mp.cav.480.c.dr
    Chloride.mp.cav.480.b.dr
  Email (2)
    W32/Appix.a@MM
    W32/Appix.h@MM
  File Infector (3)
    Plastique
    Uruguay
    Albania
  Generic (1)
    VBS/Bulb.gen
  Intended (1)
    W97M/Mary.intd.e
  Macro (3)
    W97M/NiceDay
    W97M/Fury
    W97M/Alcarys
  Malware Tool (1)
    BV.kit
  multipartite (20)
    Coup.mp.1957
    Civil.mp.6672.i
    Civil.mp.6672.h
    Civil.mp.6672.g
    Civil.mp.6672.f
    Civil.mp.6672.e
    Civil.mp.6672.d
    Civil.mp.6672.j
    Civil.mp.6672.c
    Civil.mp.6672.b
    Civil.mp.6672.a
    Chiche.mp.1436
    Changsha.mp.3072
    CCBB.mp.2221
    CCBB.mp.1410
    Carnival.mp.2346
    Cancer.mp.2528
    Blinky.mp.1302
    Clisti.mp.1025
    CB.mp.450
  multipartite Parasitic (3)
    Chloride.mp.cav.480.c
    Chloride.mp.cav.480.b
    Chloride.mp.cav.480.a
  Overwriting (1)
    Alaper.ow
  Script (18)
    W32/Trilisa.vbs
    W32/Trilisa.bat
    W32/Appix.reg
    Bat/g.4
    Bat/g.3
    Bat/g.6b
    Bat/g.6a
    Bat/g.3b
    Bat/g.3a
    Bat/g.2
    Bat/g.1
    Bat/g.5b
    Bat/g.5a
    Bat/ah
    BigBug.bat
    Holup.bat
    Bat/g.dbg
    Bat/d
  Source code (2)
    Bat/g.2.src
    Bat/g.4.src
  Win32 (8)
    W32/Appix.php
    W32/Appix
    W32/Dexter.f
    W32/Dexter.e
    W32/Dexter.d
    W32/Dexter.c
    W32/Dexter.b
    W32/Dexter.a
  Win9x (4)
    W95/Evil.d
    W95/Evil.c
    W95/Evil.b
    W95/Evil.a
  Worm (7)
    W32/Appix.d@MM
    W32/Appix.f@MM
    W32/Appix.b@MM
    W32/Appix.c@MM
    Bat/bsw
    W32/Foxma.worm.c
    W32/Foxma.worm.e