Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4239
DAT Release Date 12/23/2002
Threats Detected 62932
New Detections 138
Enhanced Detections 52

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Yaha.k@MM Medium Medium
W32/Opaserv.worm.m Low-Profiled Low-Profiled
W32/Lioten.worm Low-Profiled Low-Profiled

New Detections:

Program (46)
  - (1)
    Starr
  Application extension (1)
    Realtime_Spy.dll
  Demonstration (5)
    Demo-ProofComp
    Demo-LeakTest.102
    Demo-LeakTest.101
    Demo-LeakTest.12
    Demo-LeakTest.11
  Dialer (10)
    PornDial-112
    PornDial-116
    PornDial-114
    PornDial-111
    PornDial-110.a
    PornDial-117
    PornDial-115
    PornDial-113
    PornDial-110.b
    PornDial-109
  Dropper (1)
    Tool-Xscan.dr
  Joke (1)
    Grenadier joke
  Keylogger (1)
    Keylog-Blazing
  Malware Tool (17)
    VTool/rap
    VTool/mfg
    VTool/hop
    VTool/hhg
    VTool/evo
    VTool/ari
    VTool/adb
    VTool/vco
    VTool/pru
    VTool/mex
    VTool/hid
    VTool/evs
    VTool/bin
    VTool/ape
    PWCrack-WS_FTP
    PWCrack-MSNPass
    PWCrack-KPass
  Plugin component (1)
    Tool-Xscan.plugin
  Remote Access (1)
    PWCrack-KerbCrack
  Script (1)
    PWCrack-WS_FTP.bat
  Tool (3)
    Tool-SMail
    Tool-Xscan
    Tool-DLL_Injector
  Win32 (3)
    Realtime_Spy
    Crack-Floop
    AnonIRC
Trojan (60)
  - (1)
    JS/Offiz
  Application extension (2)
    QQSpy.dll
    IRC/Flood.bk.dll
  Client (1)
    BackDoor-ANF.cli
  Configuration settings (1)
    BackDoor-MU.ini
  Demonstration (1)
    JS/Exploit-DialogArg.demo
  Denial Of Svc (2)
    FDoS-IcmpSin
    IRC/Flood.bk
  Disk erasing (1)
    QZap302
  Downloader (1)
    BackDoor-AOB.dldr
  Dropper (2)
    IRC/Flood.bl.dr
    IRC/Flood.bk.dr
  Exploit (6)
    Unix/Scoreboard
    Linux/Exploit-CrisCras
    Linux/Exploit-Honeymoon
    Unix/Exploit-LuckRoot
    UNIX/Exploit-Sapdb
    Linux/Exploit-Kiddo
  File deleting (2)
    QDel357
    QDel358
  File Deletion (1)
    Qdel106 trojan
  Flooder (1)
    FDoS-STU
  Generic (4)
    BackDoor-AOC.gen
    BackDoor-AOA.gen
    VB-BackDoor1.gen
    VB-BackDoor2.gen
  Internet Relay Chat (1)
    IRC/Flood.bl
  Keylogger (1)
    KeyLog-MSN_X3
  Malware Tool (5)
    Spam-AnonNS
    Spam-MassMail
    Spam-NetSend
    Spam-Robis
    PWCrack-Glock
  mIRC client (2)
    IRC/Flood.bl.mirc
    IRC/Flood.bk.mirc
  Partition (1)
    Daxa
  Password Stealer (1)
    PWS-Grobbug
  Remote Access (13)
    ManifestDest
    BackDoor-AOC
    BackDoor-AOB
    BackDoor-AOA
    BackDoor-ANZ
    BackDoor-ANS
    BackDoor-ANR
    BackDoor-ANF.utl
    Backdoor-AOD
    BackDoor-ANX
    BackDoor-ANW
    BackDoor-ANV
    BackDoor-ANP
  Script (1)
    Bat/avk
  Unix (2)
    Unix/Orifice2K
    UNIX/xpl-LuckRoot
  Win32 (7)
    StealthBatch
    SMSPager-A
    KeySpy-Dolan
    Felino
    Socks_Proxy
    Reboot-U
    CreateExt
Virus (32)
   (4)
    YD.2984
    Archiver.d
    MacHC/WormFood
    HLLT.3333
  Configuration settings (1)
    W32/Bonny.ini
  Damaged (1)
    W32/HLLP.Hantaner.dam
  Dropper (1)
    Civil War.dr
  Dropper Parasitic (1)
    W95/Vlades.cav.dr
  E-mail worm (1)
    W32/Yaha.k@MM
  Email (5)
    W32/Nimda.q@MM
    W32/Merkur.a@MM
    W32/Kameral@MM
    VBS/Ottovon@MM
    W32/Merkur.b@MM
  Intended Worm (1)
    W32/Zaka.worm.intd
  Internet Worm (2)
    W32/Opaserv.worm.m
    W32/Lioten.worm
  Remote Access (1)
    Backdoor-ANQ
  Script (3)
    Bat/kuh
    Ultra Fire.bat
    VBS/Lamika
  Win32 (1)
    W32/Yaha.k
  Win9x (1)
    W95/Murkry.398a
  Worm (9)
    W32/Erdine.worm
    W32/Kilonce.worm.c
    W32/Amazex.i.worm
    W32/RunDoom.worm
    W32/Sytro.worm.aw
    W32/Tsys.worm
    W32/Sytro.worm.av
    W32/Lolol.worm
    W32/Bored.worm

Enhanced Detections:

Program (3)
  Application extension (1)
    PWCrack-Revealer.dll
  Remote Access (1)
    ServU_Daemon
  Win32 (1)
    Optimizator
Trojan (35)
  Application extension (10)
    BackDoor-WX.dll
    BackDoor-SP.dll
    UBSpws.dll
    PWS-Phreaker.dll
    BackDoor-QI.dll
    Firtal.dll
    BackDoor-QE.dll
    BackDoor-EX.dll
    PWS-Coced.dll
    BackDoor-AJW.dll
  Downloader (1)
    Anita
  Dropper (1)
    QDel297.dr
  File deleting (1)
    QDel106
  File Deletion (1)
    QDel297
  Flooder (3)
    FDoS-Icmp_Sin
    FDoS-Icmp_Rc8
    FDoS-Icmp_Bomb
  JavaScript (1)
    JS/FakeHost
  Password (1)
    PWS-Logmod
  Password Stealer (1)
    PWS-SharaQQ
  Plugin component (4)
    BackDoor-JX.plugin
    BackDoor-FK.plugin
    Backdoor-VO.plugin
    Orifice.plugin
  Remote Access (2)
    BackDoor-VD
    BackDoor-FT
  Win32 (9)
    SPing
    CD_Die
    DoS-Oob_Killwin
    DoS-Oob_Imiko
    DoS-Irc_Warclone
    DoS-Irc_Frozen
    DoS-Igmp_Awak
    DoS-Icmp_Paroxysm
    DoS-Icmp_Beer
Virus (14)
   (4)
    Three Tunes.1784
    Yak.1878
    Xmas Tree Worm
    Xmas Tree
  Damaged (1)
    W95/KME.dam
  Macro (3)
    WM/Daniel.c
    WM/Daniel.b
    WM/Daniel.a
  Parasitic (1)
    Ultra Fire.apd
  Win9x (5)
    W95/KME.c
    W95/KME.b
    W95/KME.a
    W95/Score.b
    W95/Murkry.398