Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4238
DAT Release Date 12/18/2002
Threats Detected 62790
New Detections 93
Enhanced Detections 49

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Lolol.c.worm Low-Profiled Low-Profiled

New Detections:

Program (9)
  - (1)
    SkServer
  Configurator (1)
    Tool-Exter.cfg
  Dialer (1)
    PornDial-107
  PornDialer (2)
    PornDial-108
    PornDial-106
  Remote Access (1)
    BackDoor-ANN
  Tool (2)
    Tool-SIN
    Tool-Exter
  Win32 (1)
    CallDall
Trojan (26)
   (2)
    ICQPager-I
    ExitWin-B
  Application extension (1)
    Keylog-Spider.dll
  Client (1)
    Backdoor-AKW.cli
  Downloader (1)
    PWS-Datei
  Dropper (6)
    MultiDropper-EZ
    MultiDropper-FB
    BackDoor-AMI.dr
    MultiDropper-EY
    BackDoor-ANJ.dr
    Backdoor-AKW.dr
  File Deletion (1)
    QDel356
  Flooder (2)
    FDoS-ShockWav
    FDoS-DAP
  Internet Relay Chat (1)
    IRC-Caid
  Keylogger (1)
    Keylog-Small
  Password Stealer (1)
    PWS-Chalex
  Remote Access (2)
    BackDoor-AKW
    BackDoor-ANO
  Script (1)
    VBS/Rots
  Server (1)
    Backdoor-AKW.svr
  Spyware (1)
    Keylog-Spider
  Unix (1)
    Unix/Sumo
  Win32 (2)
    ShareAll-D
    Fotki
  Worm (1)
    W32/Flita.worm
Virus (58)
  Damaged Intended (1)
    W95/Henky.intd.dam
  Dropper (2)
    W32/Lamebyte.dr
    W32/Alcop.ao.dr
  E-mail worm (2)
    Backdoor-ANU
    W32/Yaha.j@MM
  Email (10)
    W32/Sysnom.g@MM
    W32/Oror.l@MM
    W32/Hermes.e@MM
    W32/Hermes.c@MM
    W32/Hermes.b@MM
    W32/Hermes.a@MM
    W32/Fbound.e@MM
    W32/Duksten.h@MM
    W32/Chet.e@MM
    W32/Hermes.d@MM
  Email Generic (1)
    Kondrik.gen@MM
  Generic Worm (3)
    W32/Eggnog.worm.gen
    W32/Shower.worm.gen
    W32/Cloner.worm.gen
  Intended (1)
    VBS/Chick.n.intd
  Macro (3)
    WM/Anarchy.5838
    WM/Anarchy.6093
    W97M/Tema
  Overwriting (1)
    W32/Butool.b.ow
  P2P Worm (1)
    W32/Lolol.c.worm
  Parasitic (2)
    W32/HLLP.Karimex
    W32/HLLP.Hantaner
  Script (1)
    VBS/Nilit
  Win32 (11)
    W32/Alcop.ao
    W32/Cervan
    W32/NGVCK.d.3072
    W32/Yaha.j
    W32/VGrass
    W32/Frethem.u
    W32/Cherich.b
    W32/Cherich.a
    W32/Cblade.b
    W32/Butool.a
    W32/Lamebyte
  Worm (19)
    W32/Gaobot.worm.gen
    W32/Amazex.h.worm
    W32/Amazex.f.worm
    W32/Amazex.g.worm
    W32/Lolol.e.worm
    W32/Tborr.worm
    W32/Lolol.a.worm
    W32/FunkyPic.worm
    W32/Erbot.worm.b
    W32/Erbot.worm.a
    W32/Cloner.worm.b
    W32/Cloner.worm.a
    W32/Lolol.d.worm
    W32/Lolol.b.worm
    W32/Kelino.a.worm
    W32/Heovin.worm
    W32/Cloner.worm.c
    W32/Bonny.worm
    W32/QQPass.worm

Enhanced Detections:

Internet Worm (1)
  Win32 (1)
    W32/Frethem.l@MM
Program (1)
   (1)
    Oeminfo
Trojan (12)
  Password Stealer (1)
    PWS-GF
  Plugin component (1)
    Exploit-Sechole.plugin
  Remote Access (3)
    BackDoor-GM
    Backdoor-AKW.help
    BackDoor-ANH
  Script (2)
    JS/Pursue
    VBS/MemEat
  Trojan (2)
    Backdoor-ANK
    Backdoor-ANM
  Win32 (3)
    ExitWin
    ShareAll.c
    AVKill-B
Virus (35)
  - (2)
    W32/Frethem.r
    W32/Frethem.p
  Configuration settings (1)
    BAT/BWG.ini
  Dropper Intended (1)
    W32/Cervan.dr.intd
  E-mail (1)
    W32/Fbound.c@MM
  E-mail worm (4)
    W32/Frethem.m@MM
    W32/Frethem.o@MM
    W32/Frethem.k@MM
    W32/Frethem.n@MM
  Email (8)
    W97M/Hlam@MM
    W32/Sysnom.e@MM
    W32/Sysnom.c@MM
    W32/Sysnom.b@MM
    W32/Sysnom.a@MM
    W32/Fbound.d@MM
    W32/Fbound.b@MM
    W32/Fbound.a@MM
  Email Generic (1)
    W32/Fbound.gen@MM
  Intended (1)
    Wg.intd
  Internet Relay Chat (1)
    IRC/Backdoor.d
  Macintosh (1)
    MacOS/SysX
  Macro (2)
    Navrhar.12888
    Wg.12288
  P2P Worm (1)
    W32/Titog.worm
  Script (3)
    VBS/Dilan.e
    PHP/Sysbat.sys
    PHP/Sysbat.bat
  Win32 (4)
    W32/Frethem.s
    W32/Frethem.j
    W32/Frethem.t
    W32/Sysnom.f
  Worm (4)
    W32/Kelino.worm.b
    W32/Kelino.worm.a
    W32/Kelino.worm.c
    W32/Kelino.worm.d