Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4251
DAT Release Date 03/05/2003
Threats Detected 66669
New Detections 167
Enhanced Detections 125

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Yaha.p@MM Low-Profiled Low-Profiled

New Detections:

Internet Worm (1)
  E-mail worm (1)
    W32/Chowl@MM
Program (32)
   (4)
    Generator.Mime
    WVTool/pun
    WVSource
    VBSource
  Dialer (1)
    PornDial-151
  Malware Tool (12)
    VTool/obj13
    VTool/obj12
    VTool/str
    VTool/sor
    VTool/ptc
    VTool/obj16
    VTool/obj15
    VTool/obj14
    VTool/kag
    VTool/duk8
    VTool/aco
    VTool/arb
  Tool (8)
    LittleSister
    Tool-QQPassO
    Tool-QQExpl
    Tool-InnSteel
    Tool-CGITest
    Tool-AngelsRevenge
    Tool-HMH
    Tool-DarkICQ
  Win32 (7)
    WVTool/yod
    WVTool/wms
    WVTool/seg
    WVTool/igm
    WVTool/gho
    WVTool/adb
    PortWatch
Trojan (49)
   (2)
    Flood.h
    Winsex.d
  Application extension (1)
    BackDoor-AKM.dll
  Configurator (1)
    Downloader-CC.cfg
  Dialer (1)
    PornDial-152
  Downloader (5)
    Downloader-CE
    Downloader-CC
    Downloader-CA
    Downloader-CD
    Downloader-CB
  Dropper (2)
    Kit-SennaSpy.dr
    SennaSpy2001.dr
  Exploit (13)
    Exploit-AVBO
    Linux/Exploit-SendMail
    PHP/Exploit-PHP
    PHP/Exploit-IIS
    UNIX/Exploit-Cpanel
    Exploit-PoP3Trap
    Exploit-SqlHack
    Exploit-Beavuh
    UNIX/Exploit-Webmin
    UNIX/Exploit-Sircd
    UNIX/Exploit-FireRun
    Exploit-NetMust
    Exploit-IISUrlEnc
  Flooder (4)
    IRC/FDoS-DarkShark
    FDoS-IRCDcc
    FDoS-Winskill
    FDoS-PortTerm
  Generic (1)
    PWS-Crazy.gen
  Malware Tool (5)
    Spam-HateYou
    Nuke-Neonun
    Spam-Kubik
    Spam-ICQMass
    Kit-ByteMagic
  Password (2)
    PWS-Aileen
    BackDoor-AQO
  Password Stealer (2)
    PWS-Ghost
    PWS-HackSoft
  Remote Access (4)
    Backdoor-AQK
    BackDoor-AQL
    BackDoor-AQN
    BackDoor-AQM
  Script (4)
    Bat/wcl
    VBS/DDoS-iFrameNet.a
    W32/Chowl.bat
    IRC/Flood.ap.bat
  Win32 (2)
    Jzinx
    Generic Nuker
Virus (85)
   (6)
    Krad
    Goma.580
    Shy-Demon
    MacHC/Independance
    MacHC/Crudshot
    MacHC/Blink
  Companion (1)
    Offspring.cmp.1550
  Dropper (3)
    Zorm/g.1203b.dr
    Zorm/g.1203a.dr
    Zorm/g.1193.dr
  Dropper Worm (1)
    Bat/hwi.worm.dr
  E-mail (1)
    W32/Oror.ad@MM
  Email (33)
    W32/BleBla.d@MM
    W32/Oror.f@MM
    W32/Oror.d@MM
    W32/Oror.c@MM
    W32/Oror.h@MM
    W32/Oror.i@MM
    W32/Oror.g@MM
    W32/Oror.k@MM
    W32/Oror.j@MM
    W32/Oror.n@MM
    W32/Oror.m@MM
    W32/Oror.o@MM
    W32/Oror.t@MM
    W32/Oror.z@MM
    W32/Oror.y@MM
    W32/Oror.x@MM
    W32/Oror.aj@MM
    W32/Oror.ah@MM
    W32/Oror.ae@MM
    W32/Oror.ac@MM
    W32/Oror.v@MM
    W32/Oror.q@MM
    W32/Deev.c@MM
    W32/Oror.ak@MM
    W32/Oror.r@MM
    W32/Oror.ai@MM
    W32/Oror.af@MM
    W32/Oror.aa@MM
    W32/Oror.w@MM
    W32/Oror.s@MM
    W32/Oror.p@MM
    W32/Merkur.c@MM
    W32/Duksten.m@MM
  Email Generic (1)
    W32/Chowl.gen@MM
  Floppy Worm (1)
    W32/Rackum.worm
  Generic Worm (1)
    W32/Gemel.worm.gen
  Heuristic (1)
    New Malware.c
  Intended (2)
    W32/Poter.intd
    W32/Triplix.intd
  Internet Worm (2)
    W32/Yaha.q@MM
    W32/Yaha.p@MM
  Macro (2)
    X97M/Rawo
    X97M/Morx
  Malware Tool (1)
    W97M/VMPCK1.Kit
  Script (2)
    JS/Zeeap
    VBS/Netlog
  Win32 (3)
    W32/Retroy
    W32/Felix
    W32/Lirva.txt
  Worm (24)
    W32/Randon.worm
    W32/Kwbot.worm.f
    W32/Kwbot.worm.e
    W32/Kwbot.worm.d
    W32/Zokrim.worm
    W32/Zackfoo.worm
    W32/Rimnod.worm.b
    W32/EnerKaz.worm.m
    Linux/Slapper.worm
    W32/Steph.c.worm
    W32/Picsys.worm.a
    W32/Loxar.worm.f
    W32/Kwbot.worm.b
    W32/Kwbot.worm.a
    W32/Gemel.worm.f
    W32/EnerKaz.worm.o
    W32/Breat.worm
    Linux/Slapper.worm.e
    W32/Rimnod.worm.c
    W32/Rimnod.worm.a
    W32/Picsys.worm.b
    W32/Gemel.worm.e
    W32/EnerKaz.worm.p
    W32/EnerKaz.worm.n

Enhanced Detections:

Trojan (23)
   (5)
    Winsex.b
    Winsex.a
    Advent-nw
    Winsex.c
    CGIPager-A.cgi
  Client (1)
    Mac/BackDoor-Sub7.cli
  Configurator (1)
    Mac/BackDoor-Sub7.cfg
  Denial Of Svc (1)
    Nuke-Pepsik
  Dropper (1)
    Spam-Anonym.dr
  Dropper Malware Tool (1)
    SennaSpy.kit.dr
  Generic (1)
    BackDoor-Senna.gen
  Malware Tool (4)
    Nuke-Nukeit
    Nuke-AdvancedHack
    Kit-SennaSpy
    Nuke-Smurf
  Remote Access (3)
    BackDoor-Z
    BackDoor-AOA
    BackDoor-YW
  Script (3)
    VBS/Seeker
    Bat/hwi
    JS/Recursive
  Server (1)
    Mac/BackDoor-Sub7.svr
  Win32 (1)
    Mail-DepthCharge
Virus (102)
   (50)
    Guben.1094
    BW
    Pixel.i
    Alabama.1560
    MacHC/Pickle
    MacHC/SpyVirus
    Birgit.310
    MacHC/WormFood
    Amz.802
    Pixel.892
    Zorm/g.1203b
    Zorm/g.1203a
    Zorm/g.1193
    Vienna.367
    Pixel.Rosen.131
    Pixel.Hydra.472
    Pixel.Hydra.371
    Pixel.Flea
    Pixel.Cheef
    Pixel.Hydra.1670
    Pixel.877
    Pixel.748
    Pixel.j
    Pixel.g
    Pixel.f
    Pixel.d
    Pixel.277
    Pixel.b
    Odessa.716b
    Odessa.b
    Odessa.a
    Pixel.h
    Pixel.747
    Pixel.581
    Pixel.e
    Pixel.299e
    Pixel.c
    Odessa.c
    Fu-Manchu.2076c
    Sirius.979
    ShiftObj.983
    ShiftObj.758
    ShiftObj.676
    PHX
    HateV.559
    DG
    Ace.1872
    Avalanche
    Goma
    Unfo.9594
  Companion (5)
    Offspring.cmp.1681x
    Offspring.cmp.1673
    Offspring.cmp.1681
    Offspring.cmp.1551
    Hellspawn.cmp
  Dropper (3)
    Ukraine.dr
    Pixel.747.dr
    Intmaster.dr
  Dropper Parasitic (1)
    W32/Compo.cav.145.dr
  E-mail (1)
    W32/Porkis@MM
  Email (3)
    W32/Merkur.a@MM
    W32/Merkur.b@MM
    W32/Serot@MM
  Email Worm (4)
    W32/ExploreZip.worm.pak.e@M
    W32/ExploreZip.worm.pak.d@M
    W32/ExploreZip.worm.pak.b@M
    W32/ExploreZip.worm.pak.a@M
  File Infector (5)
    Casino.2330
    Jack
    Leech
    Omega.440
    Sterculius
  Floppy Worm (1)
    W32/Axatak.worm
  Generic Worm (1)
    Linux/Slapper.worm.gen
  Intended (1)
    W32/Deev.intd
  Internet Worm (4)
    Linux/Slapper.worm.a
    Linux/Slapper.worm.b
    Linux/Slapper.worm.c
    Linux/Slapper.worm.d
  Macintosh (2)
    MacHC/Merryxmas
    MacHC/ThreeTunes
  multipartite (8)
    Anthrax.mp.1024
    Ginger.Orsam.mp.x
    Ginger.Orsam.mp.2628
    Ginger.Orsam.mp.2620b
    Ginger.Orsam.mp.2616
    Ginger.Orsam.mp.2624
    Ginger.Orsam.mp.2620a
    Autumnal.mp.3072
  Overwriting (4)
    UNIX/Gobleen.ow
    Odessa.ow
    Odessa.ow.297
    Odessa.ow.440
  Script (1)
    W32/SirCam.bat
  Unix (1)
    Unix/Append.a
  Win32 (1)
    W32/Shiba
  Worm (6)
    W32/Kwbot.worm
    W32/Gemel.worm.c
    W32/Gemel.worm.a
    W32/Gemel.worm.d
    W32/Gemel.worm.b
    W32/Bonet.worm