Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4237
DAT Release Date 12/11/2002
Threats Detected 62742
New Detections 185
Enhanced Detections 85

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (13)
   (1)
    XString
  Application extension (1)
    GhostKeyLog.dll
  Configurator (1)
    SkServer.cfg
  Dialer (4)
    PornDial-105
    PornDial-102
    PornDial-104
    PornDial-103
  Dropper (1)
    PornDial-104.dr
  HTTP/FTP Trans. (1)
    SlimFTP
  Remote Access (1)
    HanumanDaemon
  Win32 (3)
    SkServer.srv
    Hanuman Daemon
    GhostKeyLog
Trojan (83)
   (5)
    Sphinx
    QMem1
    Loshara
    Faker
    Explosive
  Adware (1)
    Poldo
  Application extension (2)
    PWS-IntPack.dll
    BackDoor-ABT.dll
  Configurator (2)
    MultiDropper-EW.cfg
    Keylog-SCLog.cfg
  Disk erasing (2)
    QZap300
    QZap301
  Dropper (5)
    Bat/qz10.dr
    MultiDropper-EX
    BackDoor-AKN.dr
    BackDoor-ZH.dr
    MultiDropper-EW
  Exploit (2)
    Exploit-CT/Calendar
    Exploit-RootBug
  File deleting (15)
    QDel311
    QDel310
    QDel309
    QDel308
    QDel307
    QDel306
    QDel305
    QDel304
    QDel303
    QDel302
    QDel301
    QDel355
    QDel353
    QDel354
    QDel352
  Malware Tool (2)
    W32/Iwing.kit
    Kit-FakeGen
  Password Stealer (6)
    PWS-Helof
    PWS-IntPack
    PWS-Hidep
    PWS-Petitlam
    PWS-LWPW
    PWS-Hidukel
  Remote Access (2)
    BackDoor-ANL
    BackDoor-Sub7.Upd
  Script (26)
    VBS/Zeber
    JS/Recycled
    JS/Pursue
    Bat/FormatCQU
    Bat/tec
    Bat/mar
    Bat/qz11
    Bat/qz8
    Bat/qd7
    Bat/qd5
    Bat/ew2
    Bat/dt14
    Bat/dt12
    Bat/dt10
    Bat/dt8
    Bat/qz10
    Bat/qz9
    Bat/qz7
    Bat/qd6
    Bat/qd4
    Bat/qd3
    Bat/qd1
    Bat/ew1
    Bat/dt13
    Bat/dt11
    Bat/dt9
  Self-extracting archive (1)
    Keylog-SCLog.sfx
  Spyware (2)
    Spy-Hiddukel
    Keylog-SCLog
  StartPage (2)
    StartPage-D
    StartPage-E
  Trojan (2)
    Backdoor-ANK
    Backdoor-ANM
  Win32 (6)
    AdClicker-K
    Reboot-T
    AdClicker-J
    AdClicker-L
    Spy-GScreen
    QReg-7
Virus (89)
   (15)
    Zombie/a
    Merlin.4329
    Jeru.1733
    Gaurang
    BootDr230
    BootDr229
    Alicino.237
    Patia.2565
    Logen
    Goma.741
    Evil.303
    Coconut.2031
    BigBang.346
    HLLT.8192
    HLL.4672
  Boot (1)
    Evul.c
  Damaged (4)
    W95/Klunky.dam
    WM/Alliance.dam
    W95/Atav.2073.dam
    W97M/Sat.dam.d
  Dropper (4)
    Ambulance.815.dr
    Voodoo.dr
    Bat/pam.dr
    W32/Doser.4539.dr
  Email (12)
    VBS/Heather.c@MM
    VBS/Heather.b@MM
    VBS/Heather.a@MM
    VBS/Chick.m@M
    W32/Netav.f@MM
    W32/Duksten.g@MM
    Condric.b@MM
    W32/Pluto.b@MM
    W32/Lamecada.c@MM
    W32/Burnox@MM
    W32/Alcop.an@MM
    Condric.a@MM
  File Infector (1)
    W32/HLLP.Hantaner.worm
  Generic (2)
    VBS/Codworm.gen
    MacOS/T4.gen
  Intended (2)
    X97M/Brandy.intd
    Wg.intd
  Internet Relay Chat (1)
    IRC/Backdoor.d
  Macintosh (3)
    MacOS/ANTI.b
    MacOS/SevenDust.e
    MacOS/ANTI.a
  Macro (1)
    W97M/Wazzu.cj
  Malware Tool (1)
    Butt.kit
  P2P Worm (1)
    W32/Titog.worm
  Parasitic (4)
    Smart.cav.264
    HLLP.10000c
    W32/HLLP.Yellor.b
    W32/HLLP.Yellor.a
  Script (11)
    JS/Winclose
    VBS/Renergy
    VBS/Heather.bat
    VBS/Dilan.e
    Bat/Antireg
    Bat/red
    Bat/pam
    Bat/meu
    Bat/man
    Bat/dic
    W32/Heffer.reg
  Source code (1)
    W32/Badtrans.src
  Win32 (6)
    W32/Klinge.a
    W32/Heffer.app
    W32/Bluple
    W32/Maya.4108
    W32/Klinge.b
    W32/Evyl.h
  Win9x (3)
    W95/Bytesv.1439
    W95/Atav.2073
    W95/Eak
  Worm (16)
    W32/Walrain.worm.a
    W32/Selfoner.worm
    W32/MagicCall.worm.c
    W32/Loxar.worm.b
    W32/Kelino.worm.c
    W32/Heffer.worm.c
    W32/Heffer.worm.a
    W32/Walrain.worm.b
    W32/Usen.a.worm
    W32/Sytro.worm.au
    W32/Nilit.c.worm
    W32/Loxar.worm.d
    W32/Kelino.worm.d
    W32/Heffer.worm.b
    W32/Godev.worm
    MSIL/Bikini.worm.b

Enhanced Detections:

Trojan (16)
  - (1)
    False JPEG
  Disk erasing (1)
    QZap52
  Dropper (1)
    Bat/zz.dr
  File Deletion (1)
    QDel254
  Generic (1)
    BackDoor-AMV.gen
  Heuristic (1)
    New Dropper for IRC
  Keylogger (1)
    Keylog-SCKeyLog
  Password Stealer (1)
    PWS-Aquafish
  ProcKill (1)
    ProcKill-G
  Remote Access (1)
    BackDoor-YE
  Script (6)
    Bat/aci
    Bat/ach
    Bat/rh
    Reg/Haltwin
    Reg/BSB
    Bat/zz
Virus (69)
   (37)
    Merlin
    Fu Manchu.2080b
    Alive.3000
    Alive.4000
    Alive.3400
    Alive.2340
    Alive.2000
    Alive.3800
    Fu Manchu.2080l
    Nature
    Lapiddan.dd
    Cannibal.1312
    Cannabis.1029
    Caibua.2262
    ByteWipe.1204
    Buzzy.548
    Bogy.794
    BitAddict
    MacHC/TwoTunes
    Marbas
    Apparition
    Zombie.a
    Fu Manchu.2080j
    Fu Manchu.2080h
    Fu Manchu.2080f
    Fu Manchu.2080d
    Fu Manchu.2076c
    Fu Manchu.2080k
    Fu Manchu.2080i
    Fu Manchu.2080g
    Fu Manchu.2080e
    Fu Manchu.2080c
    Fu Manchu.2080a
    Fu Manchu.2078b
    Fu Manchu.2078a
    Fu Manchu.2076b
    Fu Manchu.2076a
  Boot (1)
    Evul
  Companion (3)
    DeadKnight.cmp
    Bigg.cmp.17000+
    HLL.cmp.8064
  Dropper (3)
    Uruguay.dr
    Caibua.2262.dr
    Fu Manchu.2080a.dr
  E-mail worm (1)
    W32/Lamecada.a@MM
  Email (7)
    W32/Netav.c@MM
    W32/Netav.a@MM
    W32/Netav.d@MM
    W32/Netav.b@MM
    W32/Lamecada.b@mm
    W32/Netav.e@MM
    VBS/Heather@MM
  File Infector (2)
    Bobo
    Democracy
  Generic (1)
    MacOS/nVIR.gen
  Heuristic (1)
    New Script.b
  Macro (1)
    W97M/Newhope.gen
  multipartite (2)
    Vecna.mp.1401
    Vecna.mp.1475
  Parasitic (1)
    Buzzy.cav.548
  Script (5)
    Bat/qc
    Bat/ev
    Bat/we
    Bat/un
    Bat/Kit
  Win9x (3)
    W95/Bytesv.1481
    W95/Bytesv.1391
    W95/Darkmill
  Worm (1)
    W32/Usen.worm