Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4248
DAT Release Date 02/19/2003
Threats Detected 65332
New Detections 173
Enhanced Detections 110

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Internet Worm (3)
  E-mail worm (1)
    W32/Ixas@MM
  P2P Worm (1)
    W32/Achar.worm
  Worm (1)
    W32/Gant.gen@MM
Joke (1)
  - (1)
    Train joke
Program (47)
   (2)
    WVTool/qre
    KeySpy-MSKS
  - (2)
    VText-AntiTBAV
    ZeroPopup
  Adware (1)
    Adware-RedSwoosh
  Application extension (2)
    KeySpy-MSKS.dll
    KeySpy-KeyRecord.dll
  Demonstration (1)
    Demo-VirSim
  Dialer (1)
    PornDial-147
  Joke (1)
    Train joke
  Malware Tool (19)
    VTool/vio2
    VTool/sch
    VTool/rah
    VTool/oh1
    VTool/mag6
    VTool/imr
    VTool/dec
    VTool/av11
    VTool/ASM
    VTool/arcv
    VTool/spe
    VTool/rep
    VTool/rab3
    VTool/nuk
    VTool/ivl
    VTool/duk7
    VTool/b2c
    VTool/av10
    VTool/av9
  Parasitic (1)
    W32/Cic.apd
  Tool (2)
    Tool-AnsiCheck
    Tool-AntiMacgyver
  Win32 (15)
    WVTool/zin
    WVTool/rlk
    WVTool/nom
    WVTool/lda
    WVTool/imp
    WVTool/icp
    WVTool/epr7
    WVTool/duk
    WVTool/cre2
    WVTool/cre1
    WVTool/bas
    WVTool/ata
    WVTool/rg0
    NetSVC
    KeySpy-KeyRecord
Trojan (40)
  - (1)
    Kather
  Configurator (2)
    MultiDropper-FK.cfg
    MultiDropper-FI.cfg
  Downloader (4)
    Downloader-BW
    Downloader-BY
    Downloader-BX
    Downloader-BV
  Dropper (5)
    BackDoor-AQA.dr
    BackDoor-FP.dr
    Bat/qd36.dr
    MultiDropper-FK
    MultiDropper-FJ
  Exploit (1)
    UNIX/Exploit-Fprot
  File deleting (1)
    QDel371
  Flooder (1)
    Linux/FDoS-Synk
  Generic (1)
    PWS-Mewey.gen
  Malware Tool (3)
    Nuke-NTKill
    NTRootKit-A
    Kit-Kpwc
  Password (1)
    PWS-SCKeylog
  Password Stealer (1)
    PWS-Malog
  ProcKill (4)
    ProcKill-AC
    ProcKill-AA
    ProcKill-AB
    ProcKill-AD
  Remote Access (6)
    BackDoor-AQA
    BackDoor-AQC
    BackDoor-APY
    BackDoor-AQB
    BackDoor-APZ
    BackDoor-APX
  Script (6)
    NTRootKit-B.bat
    VBS/Thelo
    VBS/Nawps
    Bat/hik
    JS/Swappie
    Bat/frz
  Spam (1)
    Tellafriend
  Win31 (1)
    Boxfull
  Win32 (1)
    Malicious
Virus (82)
   (9)
    VCL.Dome.556
    Jeru.1808.i
    Akuku.927
    Crazy Imp.1402a
    Reverse.948
    Probe
    Light.284
    Crazy Imp.1402b
    Basrun.5145
  Application extension (1)
    IRC-Defused.dll
  Damaged (2)
    TPE.1.4.dam
    W32/Demig.dam
  Dropper (4)
    W95/Whalg.dr
    MPC.478b.dr
    XRes.dr
    VCM.670.dr
  Email (10)
    W32/BackZat.f@MM
    W16/Yoyks@MM
    W32/Serot@MM
    W32/Generic@MM
    W32/Yano@MM
    W32/Wangy.b@MM
    W32/Wangy.a@MM
    W32/Gant@MM
    W32/Cherich.e@MM
    W16/Kondrik@MM
  Email Generic (1)
    W32/Deev.gen@MM
  Floppy Worm (1)
    W32/Proget.worm.b
  Generic (2)
    W32/Blinkom.gen
    VBS/Notice.gen
  Generic Worm (1)
    W32/STD.worm.gen
  Intended (5)
    W32/Cic.intd
    JS/Oagos.intd
    JS/Monion.intd
    VBS/Outblack.intd
    W97M/Outblack.intd
  Internet Worm (1)
    W32/Maax@MM
  Macro (2)
    W97M/Bablas
    WM/Box.j
  Malware Tool (2)
    W32/Yano.kit
    W97M/MWVCKC.Kit
  multipartite (1)
    FitW.mp.7953
  Script (3)
    VBS/FatCat
    VBS/Cic
    Kondrik
  Unix (5)
    UNIX/Kru
    UNIX/Chifier
    UNIX/Hoakin
    UNIX/Corona
    UNIX/Bud
  Win32 (9)
    W32/Cic.b
    W32/Cic.a
    W32/Yahoxer
    W32/Freebid
    W32/Chatter
    W32/Picsys
    W32/NGVCK.5041
    W32/Naid
    W32/Lames
  Win9x (1)
    W95/Whalg
  Worm (22)
    W32/HScr.worm
    W32/Lovgate.a@M
    W32/Blitzdung.worm
    W32/STD.g.worm
    W32/Proget.worm.a
    W32/Gemel.worm.c
    W32/Gemel.worm.a
    W32/Eissa.worm.a
    W32/Bebars.worm
    W32/Ronoper.worm.e
    W32/Ronoper.worm.d
    W32/Ronoper.worm.c
    W32/Ronoper.worm.b
    W32/Ronoper.worm.a
    W32/Nilit.j.worm
    W32/Nilit.i.worm
    W32/Nilit.h.worm
    W32/Lovgate.worm
    W32/Gemel.worm.d
    W32/Gemel.worm.b
    W32/Eissa.worm.b
    MacOS/AutoStart.worm.h

Enhanced Detections:

Internet Worm (1)
  P2P Worm (1)
    W32/Cult.worm
Malware (1)
  Trojan (1)
    PWS-Likun
Program (23)
   (1)
    BlackStone
  Adware (3)
    Adware-Cantfind
    Adware-Hotlink
    Adware-Homepage
  Demonstration (1)
    ADE.demo
  Dialer (9)
    PornDial10
    PornDial11
    PornDial9
    PornDial8
    PornDial7
    PornDial6
    PornDial5
    PornDial4
    PornDial2
  Dropper (1)
    Tool-Xscan.dr
  Joke (1)
    Fake-Format joke
  Malware Tool (1)
    VTool/vio
  Plugin component (1)
    Tool-Xscan.plugin
  Win31 (1)
    Idle Toolz
  Win32 (4)
    Hanuman Daemon
    TrojSimul
    Mierun
    NoZone Mutex
Trojan (30)
  Application extension (5)
    PWS-ICQHole.b.dll
    NTHack.dll
    PWS-ICQHole.e.dll
    PWS-ICQHole.d.dll
    PWS-ICQHole.a.dll
  Configurator (3)
    BackDoor-AB.cfg
    PWS-Likun.cfg
    MultiDropper-EC.cfg
  Configurator Dropper (1)
    Iroffer.cfg.dr
  Dropper (3)
    MultiDropper-FI
    MultiDropper-EC
    Grador.dr
  Keylogger (2)
    KeyLog-SSKC
    Keylog-Sinred
  Linux (1)
    Linux/Mstream
  Password (2)
    PWS-NTSMB
    PWS-BP
  Password Stealer (7)
    PWS-ICQHole.d
    PWS-ICQHole.c
    PWS-ICQHole.b
    PWS-ICQHole.a
    PWS-Realis
    PWS-DG
    PWS-Mumed
  Remote Access (2)
    NTHack
    BackDoor-YN
  Win32 (4)
    Keytrap
    Cool
    Orifice.sniff
    QQSpy
Virus (55)
   (29)
    TPE.1.4.Cofshop.a
    TPE.1.4.Girafe.f
    TPE.1.4.Girafe.d
    TPE.1.4.Girafe.b
    TPE.1.4.Nondes
    TPE.1.4.Poetcode
    TPE.1.4.Adin
    TPE.1.4.2680
    TPE.1.4.YB1
    TPE.1.4.WildLick
    TPE.1.4.Eccles
    TPE.1.4.Cofshop.b
    TPE.1.4.Girafe.g
    TPE.1.4.Girafe.e
    TPE.1.4.Girafe.c
    TPE.1.4.Girafe.a
    TPE.1.4.Youba
    TPE.1.4.Bosnia
    Before.1196
    Thunder.892
    Beavis
    War.901
    Tiffany
    Crude.936
    CriCri.4249
    Bauman.2203
    Beethoven.2752
    Civil War.901
    Tad2a.350
  Damaged (3)
    Anthrax.dam
    Thunder.892.dam
    Blurp.4733.dam
  Dropper (2)
    W32/FunLove.dr
    Foetus.dr
  Email (3)
    W32/Kameral.c@MM
    W32/Kameral.b@MM
    W32/Kameral.a@MM
  File Infector (2)
    CRIMINAL
    Vicious
  Generic (1)
    Vienna.GR
  Intended (2)
    W32/Chatter.intd
    VBS/Tripple.intd
  Malware Tool (1)
    Thunder.kit
  Parasitic (2)
    W32/Elkern.cav.b
    W32/Elkern.cav.a
  Win32 (2)
    W32/Oporto
    W32/Kifie
  Worm (8)
    MacOS/AutoStart.worm.g
    MacOS/AutoStart.worm.f
    MacOS/AutoStart.worm.e
    MacOS/AutoStart.worm.d
    MacOS/AutoStart.worm.c
    MacOS/AutoStart.worm.a
    MacOS/AutoStart.worm.b
    W32/Onewol.worm