Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4247
DAT Release Date 02/12/2003
Threats Detected 64686
New Detections 143
Enhanced Detections 45

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
AdwareDropper-A Low-Profiled Low-Profiled
W32/Gool.worm Low-Profiled Low-Profiled
W32/SQLSlammer.worm Low-Profiled Low-Profiled

New Detections:

Internet Worm (2)
  P2P Worm (1)
    W32/Gool.worm
  SQL worm (1)
    W32/SQLSlammer.worm
Program (29)
  Adware (3)
    Adware-Cantfind
    Adware-Hotlink
    Adware-Homepage
  Dialer (2)
    PornDial-146
    PornDial-145
  Malware Tool (17)
    VTool/wag
    VTool/tun
    VTool/rda3
    VTool/obj1
    VTool/fvc
    VTool/fis
    VTool/duk5
    VTool/cmo
    VTool/vla1
    VTool/sth
    VTool/obj2
    VTool/mag5
    VTool/fmt
    VTool/duk6
    VTool/csc
    VTool/4byte
    PWCrack-WCOM
  Win32 (7)
    WVTool/rht
    WVTool/epr5
    WVTool/epr3
    WVTool/spn2
    WVTool/epr6
    WVTool/epr4
    WVTool/eax
Trojan (72)
   (5)
    Killwin
    Perry
    Keycopy
    B2C.Sol
    AntiMD
  Adware (1)
    AdwareDropper-A
  Configurator (2)
    Iroffer.cfg
    Xin.cfg
  Configurator Dropper (1)
    Iroffer.cfg.dr
  Denial Of Svc (2)
    DDoS-Smurf
    FDoS-Wping
  Disk erasing (1)
    QZap309
  Downloader (1)
    Downloader-BU
  Dropper (3)
    Bat/dt19.dr
    Bat/rat.dr
    IRC-Demfire.dr
  Exploit (2)
    Exploit-IISInjector
    UNIX/Exploit-LogWatc
  File deleting (4)
    QDel324
    QDel327
    QDel326
    QDel325
  Flooder (2)
    FDoS-LANKill
    FDoS-ARPKill
  Generic (1)
    AdClicker-C.gen
  Malware Tool (5)
    Easy.kit
    Bat/mch3.kit
    Bat/mch1.kit
    Bat/mch4.kit
    Bat/mch2.kit
  mIRC client (1)
    IRC-Demfire.mirc
  Parasitic (1)
    Bat/rat.apd
  Password (1)
    PWS-NTSMB
  Password Stealer (1)
    PWS-AIMScreen
  Remote Access (10)
    IRC-Emoz
    IRC-Demfire
    IRC/Backdoor.g
    BackDoor-APW
    BackDoor-APV
    BackDoor-APU
    BackDoor-APT
    BackDoor-APJ.srv
    BackDoor-AFZ
    Linux/BackDoor-GMM
  Script (23)
    IRC-Demfire.bat
    Bat/wfu
    Bat/qd37
    Bat/qd34
    Bat/qd32
    Bat/rot
    Bat/ren1
    Bat/qz16
    Bat/qz15
    Bat/qd39
    Bat/qd38
    Bat/qd36
    Bat/qd33
    Bat/qd31
    Bat/mkd1
    Bat/dt20
    Bat/cra
    Bat/qd30
    Bat/kbd
    Bat/dt19
    Bat/dt18
    Keylog-Chota.bat
    DDoS-SQLhuc.bat
  Win32 (4)
    Xin
    He4Hook
    He4Hook.sys
    APStrojan.tp
  Worm (1)
    W32/Steph.worm
Virus (40)
   (9)
    Vienna.648.app
    Acid.1024
    Tiny.137
    Mick.343
    Dseven
    Sovfam
    Gruk.2772
    Demon.371
    HLLT.7838
  Client Worm (1)
    W32/Gool.worm.cli
  Configurator Worm (1)
    W32/Gool.worm.cfg
  Damaged (4)
    Univ.a.dam
    Vienna.dam
    WM/Goldfish.dam
    WM/Demon.dam
  Email (2)
    W32/Deev.b@MM
    W32/Deev.a@MM
  File Infector (1)
    W32/Atcpa
  Generic (1)
    VBS/Dismissed.gen
  HTML document (1)
    W32/Lirva.c.htm
  Intended (1)
    VBS/Chick.o.intd
  Internet Worm (1)
    JS/Fortnight.b@M
  Macro (1)
    W97M/Opey.bg
  Overwriting (1)
    Bt.ow/btg
  P2P Worm (1)
    W32/Browney.a.worm
  Parasitic (2)
    Univ/g.apd
    HLLP.8563b
  Script (1)
    HLLW.4173.bat
  Win32 (2)
    W32/Bagif
    W32/Sobig.eml
  Worm (10)
    VBS/Cian
    W32/Discoball.worm
    HLLW.4173
    W32/Sahay.worm.a
    W32/Onewol.worm
    W32/Loxar.worm.e
    W32/Sahay.worm.b
    W32/Felic.worm
    W32/Eissa.worm
    Claytron.worm

Enhanced Detections:

Program (3)
   (1)
    DriveNuke
  Malware Tool (1)
    VTool/paw3
  Win32 (1)
    WVTool/spn
Trojan (14)
   (3)
    HPI
    Driner
    Yam
  Client (1)
    BackDoor-AFZ.cli
  Configurator (1)
    MultiDropper-EW.cfg
  Dropper (1)
    MultiDropper-EW
  File deleting (1)
    QDel368
  Internet Relay Chat (1)
    IRC/Flood.bo
  Remote Access (2)
    BackDoor-DB
    BackDoor-AHM
  Script (3)
    Bat/abz
    Bat/kd
    Bat/kc
  Server (1)
    BackDoor-AFZ.svr
Virus (28)
   (5)
    SmallME.961
    SmallME.955
    DIW.377b
    PE
    Keypress.Ufo
  Application extension (1)
    W32/Oror.dll
  Configuration settings (1)
    VBS/FreeNet.ini
  Dropper (2)
    W95/Zerg.dr
    W95/Xine.dr
  E-mail (1)
    VBS/Chick.c@M
  E-mail worm (5)
    VBS/Chick.e@M
    VBS/Chick.h@M
    VBS/Chick.g@M
    VBS/Chick.d@M
    VBS/Chick.f@M
  Email (3)
    VBS/Chick.j@M
    VBS/Chick.i@M
    VBS/Chick.m@M
  Generic (1)
    Jedem.GR
  Intended (3)
    VBS/Chick.l.intd
    VBS/Chick.k.intd
    VBS/Chick.n.intd
  Macro (2)
    WM/Demon
    WM/Navrhar.12888
  Parasitic (1)
    HLLP.8563
  VbScript (1)
    VBS/Dismissed
  VBScript worm (2)
    VBS/Chick.a@M
    VBS/Chick.b@M