Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4252
DAT Release Date 03/12/2003
Threats Detected 67330
New Detections 196
Enhanced Detections 352

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Deloder.worm Low-Profiled Low-Profiled
W32/Bibrog.c@MM Low-Profiled Low-Profiled
W32/Nicehello@MM Low-Profiled Low-Profiled

New Detections:

Program (24)
  - (2)
    PrcView
    MotherboardMonitor
  Dialer (2)
    PornDial-154
    PornDial-153
  Malware Tool (12)
    VTool/rme
    VTool/obj19
    VTool/obj17
    VTool/joy
    VTool/xmp
    VTool/unk
    VTool/obj18
    VTool/moh
    VTool/flo
    VTool/duk9
    VTool/dpl
    VTool/ans
  Tool (1)
    Tool-Teso212
  Win32 (7)
    PhoenixScan
    NetSpy
    WVTool/vgen
    WVTool/tro
    WVTool/run
    WVTool/dw
    WVTool/bec
Trojan (85)
   (1)
    Tef/Dcp
  Client (1)
    BackDoor-AQQ.cli
  Configurator (3)
    DDoS-Prodex.cfg
    DDoS-DDoSer.cfg
    BackDoor-AQQ.cfg
  Disk erasing (1)
    QZap311
  Downloader (1)
    Downloader-CF
  Dropper (5)
    BackDoor-ARG.dr
    MultiDropper-FL
    Bat/oem2.dr
    Bat/oem1.dr
    MultiDropper-FM
  Exploit (2)
    UNIX/Exploit-Typo
    UNIX/Exploit-DSR
  Flooder (7)
    FDoS-AdvMSN
    FDoS-AngryPing
    FDoS-Faceless
    FDoS-MrUDP
    FDoS-Sharft
    FDoS-ICQkuf
    FDoS-ShelPing
  Generic (3)
    W32/Stealth.gen
    PWS-MSNFake.gen
    BackDoor-AQR.gen
  Malware Tool (10)
    Nuke-WinTCPKill
    Nuke-TSKNuke
    Nuke-AOLExp
    Nuke-TSKNuke.irc
    Nuke-NSNuke
    Nuke-QQ
    Nuke-Crasher
    Nuke-AIC
    Kit-JSG
    Kit-Herpes
  Password Stealer (3)
    PWS-Jiang
    Linux/PWS-Lala
    PWS-Fastlit
  Process (2)
    ProcKill-AE
    ProcKill-AF
  Remote Access (16)
    Backdoor-AQP
    IRC-Pitchfork
    BackDoor-AQT
    BackDoor-ARG
    BackDoor-WF
    BackDoor-AQW
    BackDoor-AQS
    BackDoor-AQZ
    BackDoor-AQY
    BackDoor-AQX
    BackDoor-AQV
    BackDoor-AQU
    BackDoor-ALI.sys.b
    Linux/Backdoor-ssl
    Unix/BackDoor-Gloomy.b
    Unix/BackDoor-Gloomy.a
  Script (25)
    Bat/loop3
    Bat/kru
    Bat/dt23
    Bat/dt21
    Bat/tbo
    Bat/scw
    Bat/qz20
    Bat/qz19
    Bat/qz18
    Bat/qz16.sub
    Bat/qd54
    Bat/qd52
    Bat/qd51
    Bat/qd44
    Bat/qd43
    Bat/qd41
    Bat/qd40
    Bat/qd31.sub
    Bat/oem2
    Bat/oem1
    Bat/loop4
    Bat/dt99
    Bat/dt22
    Bat/bel
    Bat/rat.sub
  Server (1)
    BackDoor-AQQ.svr
  Spyware (1)
    KeyLog-Kerlib
  VbScript (1)
    VBS/Fourcourse
  Win32 (2)
    DDoS-Prodex
    DDoS-DDoSer
Virus (87)
   (19)
    Mr.Div.1100
    Mr.Ra.1039
    Mr.Ra.1000a
    Mr.Ravl.962
    Zipper.2779
    SSR.1520
    Kusys
    HLLT.9680
    VCL.Dome
    Mr.Dof.1000
    Mr.Ra.1000b
    Mr.Ravl.983
    Jeru.Sunday.1647
    Terror
    HLLT.8368
    HLLT.6688
    HLLT.5968
    HLLT.5728
    HLLT.3792
  Application extension (1)
    W32/Lovgate.dll
  Companion (1)
    W16/Lodex.cmp
  Damaged (3)
    Mr.Dof.dam
    Mr.Ravl.dam
    W32/Haless.dam
  Dropper (5)
    Lorenzo.9214.dr
    Inferno.dr
    Nutcracker.2620.dr
    W32/LDE.dr.c
    W32/DeadBear.dr
  Dropper Worm (2)
    W32/SQLSlammer.worm.dr
    W32/Gool.worm.dr
  E-mail worm (3)
    W32/Jantic.a@MM
    W32/Nicehello@MM
    W32/Nomis.worm
  Email (1)
    W32/Daboom@MM
  Email Generic (1)
    W32/Bibrog.gen@MM
  Generic (1)
    VBS/Herpes.gen
  Generic Worm (1)
    W32/Fantast.worm.gen
  Intended (3)
    W32/DeadBear.intd
    W95/Boza.g.intd
    W95/Babylonia.intd
  Internet Worm (4)
    W32/Sddrop.worm
    W32/Bibrog.c@MM
    W32/Bibrog.b@MM
    W32/AimVen.worm
  Linux (1)
    Linux/Gildo
  Malware Tool (1)
    VBS/FVBSWG.Kit
  Overwriting (1)
    W32/Cewalk.ow
  Parasitic (1)
    W32/HLLP.18431c
  Script (2)
    Bat/Betta
    Bat/pwo
  Unix (3)
    UNIX/Corona.a
    Unix/Kenkra
    UNIX/Corona.b
  Win32 (4)
    W32/Isis
    W32/Tweder
    W32/Missu
    W32/LDE.c
  Win9x (2)
    W95/Caw.1493
    W95/Zhymn.c
  Worm (27)
    W32/Deloder.worm
    W32/Opaserv.worm.u
    W32/Opaserv.worm.s
    W32/Amazex.k.worm
    W32/Opaserv.worm.v
    W32/Opaserv.worm.t
    W32/Sunelo.worm.b
    W32/Loxar.worm.h
    W32/Loxar.worm.g
    W32/Fantast.worm.e
    W32/Fantast.worm.c
    W32/EnerKaz.worm.q
    W32/CodeRed.worm.f
    VBS/FVBSWG.worm
    W32/Zokrim.worm.b
    W32/Zokrim.worm.a
    W32/Zackfoo.worm.c
    W32/Zackfoo.worm.b
    W32/Zackfoo.worm.a
    W32/Sunelo.worm.a
    W32/Speedup.d.worm
    W32/Shakirapics.worm
    W32/Nimrod.worm
    W32/Iglamer.worm
    W32/Fantast.worm.d
    W32/Evom.worm
    W32/CodeRed.worm

Enhanced Detections:

Joke (2)
  Process (1)
    EPOC/Lights
  Settings Change (1)
    EPOC/BadInfo
Program (178)
   (3)
    WVSource
    VBSource
    EPOC/Ghost.b
  Downloader (1)
    MP3Search.ldr
  Malware Tool (172)
    VTool/src3
    VTool/rap
    VTool/hop
    VTool/hhg
    VTool/evo
    VTool/ari
    VTool/vco
    VTool/pru
    VTool/mex
    VTool/hid
    VTool/evs
    VTool/bin
    VTool/ape
    VTool/mbc1
    VTool/xxe
    VTool/vzu
    VTool/vgn3
    VTool/vgn1
    VTool/vct4
    VTool/vem
    VTool/vct2
    VTool/tre
    VTool/xax
    VTool/voi
    VTool/vgn2
    VTool/vct3
    VTool/vct1
    VTool/tpe2
    VTool/tpe1
    VTool/siz
    VTool/sic
    VTool/sfx
    VTool/sbr2
    VTool/sbr1
    VTool/sal
    VTool/rng
    VTool/rdc
    VTool/rda2
    VTool/rda1
    VTool/rab1
    VTool/paw1
    VTool/nsp
    VTool/hwi
    VTool/duk2
    VTool/dav
    VTool/dat2
    VTool/dab
    VTool/tfi
    VTool/paw2
    VTool/gfx
    VTool/exp
    VTool/duk1
    VTool/dat3
    VTool/dat1
    VTool/cou
    VTool/c2t
    VTool/bur
    VTool/b2p
    VTool/azc
    VTool/api
    VTool/ant
    VTool/act3
    VTool/act2
    VTool/act1
    VTool/pwr
    VTool/par
    VTool/gps
    VTool/cry1
    VTool/scv1
    VTool/wid
    VTool/tpr1
    VTool/tbs1
    VTool/sig
    VTool/rsi
    VTool/omo
    VTool/nlg
    VTool/ndc
    VTool/hwi2
    VTool/fpa
    VTool/duk4
    VTool/dis
    VTool/dai2
    VTool/cry3
    VTool/av6
    VTool/av4
    VTool/av2
    VTool/drm2
    VTool/dli
    VTool/x2b
    VTool/tpr2
    VTool/svd
    VTool/smt
    VTool/sci
    VTool/pep
    VTool/nlv
    VTool/ngd
    VTool/kir
    VTool/hla
    VTool/ffi
    VTool/duk3
    VTool/dai3
    VTool/dai1
    VTool/av5
    VTool/av3
    VTool/av1
    VTool/tpu
    VTool/src2
    VTool/src1
    VTool/pre
    VTool/pol2
    VTool/mte
    VTool/mad
    VTool/hai
    Vtool/cbt
    VTool/av7
    VTool/src5
    VTool/src4
    VTool/pol3
    VTool/pol1
    VTool/msg
    VTool/irw
    Vtool/dgm
    VTool/ato
    VTool/zom2
    VTool/zco
    VTool/xxx
    VTool/scv3
    VTool/scv2
    VTool/rag
    VTool/av8
    VTool/mya
    VTool/inv
    VTool/wag
    VTool/tun
    VTool/rda3
    VTool/fvc
    VTool/fis
    VTool/duk5
    VTool/jed
    VTool/dpm
    VTool/att
    VTool/vla1
    VTool/sth
    VTool/duk6
    VTool/4byte
    VTool/vio2
    VTool/sch
    VTool/oh1
    VTool/imr
    VTool/dec
    VTool/av11
    VTool/ASM
    VTool/rep
    VTool/rab3
    VTool/nuk
    VTool/ivl
    VTool/duk7
    VTool/b2c
    VTool/av10
    VTool/av9
    VTool/phi
    VTool/obj11
    VTool/str
    VTool/sor
    VTool/ptc
    VTool/kag
    VTool/duk8
    VTool/aco
    VTool/arb
    VTool/zom1
    VTool/vio1
    VTool/drm1
  Tool (1)
    Tool-DLL_Injector
  Win32 (1)
    WVTool/gpa5
Trojan (49)
   (2)
    Nutcracker.2620.dd
    Exploit/VCard
  Client (1)
    BackDoor-UO.cli
  Configurator (1)
    BackDoor-UO.cfg
  Dropper (2)
    MultiDropper-CO
    BackDoor-BU.dr
  Exploit (1)
    Exploit-CT/Calendar
  File deleting (1)
    QDel101
  File Deletion (1)
    QDel104
  HTML (1)
    HTML/Suar
  Internet Relay Chat (1)
    IRC/Flood.ad
  Malware Tool (1)
    Spam-Orivion
  Password (1)
    PWS-MSNCrack
  Password Stealer (1)
    PWS-QQEye
  Remote Access (4)
    BackDoor-BL
    Backdoor-AFC
    IRC/Backdoor.g
    BackDoor-BU
  Script (27)
    W32/Cyseq.bat
    Bat/abr
    Bat/dw
    Bat/dt20
    Bat/vo
    Bat/ue
    Bat/rx
    Bat/loo2
    Bat/loo1
    Bat/aaz
    Bat/aay
    Bat/aax
    Bat/aap
    Bat/zw
    Bat/zt
    Bat/zn
    Bat/zm
    Bat/zj
    Bat/wx
    Bat/wl
    Bat/wi
    Bat/wb
    Bat/vt
    Bat/vs
    Bat/uf
    Bat/sk
    Bat/rr
  Server (1)
    BackDoor-UO.svr
  Win32 (3)
    Sub7-Spoof
    Tetris
    Piduts
Virus (123)
   (40)
    ADI
    Jeru.Sunday.1728c
    Jeru.Sunday.1728a
    Jeru.Sunday.1682
    Jeru.Sunday.1631e
    Jeru.Sunday.1631c
    Jeru.Sunday.1631a
    Jeru.Sunday.1728b
    Jeru.Sunday.1689
    Jeru.Sunday.1639
    Jeru.Sunday.1631f
    Jeru.Sunday.1631d
    Jeru.Sunday.1631b
    Jeru.Sunday.1624
    Jeru.Sunday.1633a
    Jeru.Sunday.1633b
    Nroff/Victum
    Jeru.1536
    Jeru.Sunday.1633d
    Jeru.Sunday.1633c
    Begu.3033
    Light.284
    7thSon
    YD.1049.c
    Slowly
    Dir-II
    BootDr65
    Zyr
    Worker.4819
    Worker
    TenPastThree
    Public Enemy.429
    Nekorb.805
    Nekorb.805.auto.tro
    Nekorb.805.tro
    Irate
    Hoodoo.4456
    Hoodoo.2614
    Hoodoo.2604
    Leo
  Companion (1)
    VCL.cmp
  Damaged (1)
    Linux/Etap.d.dam
  Dropper (5)
    Scitzo.dr
    Trout.dr
    W95/Yurn.dr
    Howard.dr
    Pofu.dr
  Email (1)
    W16/Yoyks@MM
  Email Worm (5)
    W32/Sytro.worm.ad@MM
    W32/Sytro.worm.ab@MM
    W32/Sytro.worm.ac@MM
    W32/Sytro.worm.aa@MM
    W32/Sytro.worm.am@MM
  File Infector (2)
    Dutch Tiny
    Kela
  Generic (5)
    HLLT.Witam.GR
    X97M/Laroux.nw.gen
    W95/Segax.gen
    W95/Ordy.gen
    W95/Anxiety.gen
  Generic Worm (1)
    W32/Lich.worm.gen
  Intended (1)
    W32/Triplix.intd
  Linux (1)
    Linux/Etap.d
  multipartite (2)
    Playgame.mp
    Kiev.mp
  Parasitic (2)
    HLLP.Sector
    Pure.cav
  Unix (2)
    UNIX/Kru
    Unix/Prep
  Win32 (1)
    W32/Retroy
  Win9x (6)
    W95/Zhymn.a
    W95/Zhymn.b
    W95/Mssu.c
    W95/Mssu.a
    W95/Mssu.b
    W95/MSpawn.4608
  Worm (47)
    W32/Sytro.worm.al
    W32/Sytro.worm.ak
    W32/Sytro.worm.aj
    W32/Sytro.worm.ah
    W32/Sytro.worm.ag
    W32/Sytro.worm.af
    W32/Sytro.worm.z
    W32/Sytro.worm.ai
    W32/Sytro.worm.ae
    W32/Sytro.worm.y
    W32/Sytro.worm.x
    W32/Sytro.worm.w
    W32/Sytro.worm.u
    W32/Sytro.worm.s
    W32/Sytro.worm.q
    W32/Sytro.worm.o
    W32/Sytro.worm.m
    W32/Sytro.worm.k
    W32/Sytro.worm.i
    W32/Sytro.worm.g
    W32/Sytro.worm.e
    W32/Sytro.worm.c
    W32/Sytro.worm.a
    W32/Sytro.worm.v
    W32/Sytro.worm.t
    W32/Sytro.worm.r
    W32/Sytro.worm.p
    W32/Sytro.worm.n
    W32/Sytro.worm.l
    W32/Sytro.worm.j
    W32/Sytro.worm.h
    W32/Sytro.worm.f
    W32/Sytro.worm.d
    W32/Sytro.worm.b
    W32/Sytro.worm.as
    W32/Sytro.worm.ar
    W32/Sytro.worm.aq
    W32/Sytro.worm.ap
    W32/Sytro.worm.ao
    W32/Sytro.worm.an
    W32/Sytro.worm.at
    W32/Sytro.worm.au
    W32/Sytro.worm.aw
    W32/Sytro.worm.av
    W32/Fantast.worm.b
    Claytron.worm
    W32/Steph.c.worm