Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4253
DAT Release Date 03/19/2003
Threats Detected 67993
New Detections 209
Enhanced Detections 99

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Neroma.a@MM Low-Profiled Low-Profiled
W32/Ganda@MM Low-Profiled Low-Profiled

New Detections:

Internet Worm (1)
  Worm (1)
    W32/Deborm.worm.gen
Program (55)
   (1)
    Whipe
  - (1)
    Dialer-RAS.a.gen
  Adware (1)
    Adware-IEDriver
  Dialer (2)
    Dialer-RAS.aj
    Dialer-RAS.ak
  Dropper (1)
    Adware-IEDriver.dr
  Exploit (1)
    Demo-Opera
  Generic (34)
    Dialer-RAS.v.gen
    Dialer-RAS.ae.gen
    Dialer-RAS.ai.gen
    Dialer-RAS.ag.gen
    Dialer-RAS.ac.gen
    Dialer-RAS.aa.gen
    Dialer-RAS.y.gen
    Dialer-RAS.w.gen
    Dialer-RAS.u.gen
    Dialer-RAS.s.gen
    Dialer-RAS.q.gen
    Dialer-RAS.o.gen
    Dialer-RAS.n.gen
    Dialer-RAS.m.gen
    Dialer-RAS.ah.gen
    Dialer-RAS.af.gen
    Dialer-RAS.ad.gen
    Dialer-RAS.ab.gen
    Dialer-RAS.z.gen
    Dialer-RAS.x.gen
    Dialer-RAS.t.gen
    Dialer-RAS.r.gen
    Dialer-RAS.p.gen
    Dialer-RAS.l.gen
    Dialer-RAS.j.gen
    Dialer-RAS.h.gen
    Dialer-RAS.f.gen
    Dialer-RAS.d.gen
    Dialer-RAS.b.gen
    Dialer-RAS.k.gen
    Dialer-RAS.i.gen
    Dialer-RAS.g.gen
    Dialer-RAS.e.gen
    Dialer-RAS.c.gen
  Malware Tool (5)
    VTool/sep
    VTool/sea
    VTool/pin
    VTool/av12
    VTool/ren
  Process (1)
    CloseProc
  Tool (1)
    AnalogX-Proxy
  Win31 (1)
    HideApp
  Win32 (6)
    MpAdvert
    WVTool/redh
    MSN-Tnhbot
    LopAdvert
    WVTool/rpa
    WVTool/gtkph
Trojan (78)
  Application extension (1)
    BackDoor-ARO.dll
  Configurator (2)
    FUD.cfg
    MultiDropper-FN.cfg
  Denial Of Svc (1)
    IRC/Flood.br
  Disk erasing (1)
    QZap312
  Downloader (1)
    Downloader-BW.b
  Dropper (4)
    MultiDropper-FN
    Downloader-BY.dr
    PWS-FF.dr
    BackDoor-ARL.dr
  Exploit (6)
    Exploit-MS03-007
    Exploit-IIS.cmd
    Exploit-Frame.js
    Exploit-Frame.link
    Exploit-Frame
    Exploit-IIS.iisdie
  File Deletion (1)
    QDel373
  Flooder (12)
    FDoS-RoomKill
    FDoS-Destiny
    FDoS-Mega
    FDoS-BlakBlud
    FDoS-MrType
    FDoS-ChiBoy
    FDoS-UnaBomb
    FDoS-BamaBoy
    FDoS-Xoox
    FDoS-DanDan
    FDoS-WarPing
    FDoS-Hasist
  Generic (4)
    MultiDropper-FM.gen
    BackDoor-AQY.gen
    VB-QDel.gen
    BackDoor-AQU.gen
  Intended (1)
    VBS/Splatflat.intd
  Internet Relay Chat (1)
    IRC/Flood.bs
  Malware Tool (2)
    UNIX/Spam-SMS.Chung
    Kit-PVBSWG
  Password (2)
    JS/PWS-WebLog
    PWS-Gfint
  Password Stealer (9)
    PWS-Pirt
    PWS-FixErr
    PWS-Geef
    PWS-Faker
    PWS-AolEk
    PWS-PWCollecter
    PWS-InstPic
    PWS-Coun
    PWS-AimForge
  Remote Access (10)
    BackDoor-ARX
    BackDoor-ARL
    BackDoor-ARO
    BackDoor-ARN
    BackDoor-ARH
    BackDoor-ARD
    BackDoor-AQR
    BackDoor-ARI
    BackDoor-ARF
    BackDoor-ARB
  Script (12)
    VBS/Splatflat
    VBS/Swade
    VBS/Kvpe
    VBS/Hackool
    Bat/zz1
    Bat/qd65
    Bat/nom2
    Bat/hbu
    W32/Lamado.bat
    Bat/sad
    Bat/dt25
    BackDoor-ARO.bat
  Win32 (7)
    AnalogX-Proxy.ldr
    IeThief.b
    IeThief.a
    DiskFill-G
    Spy-KeyList
    IPCaller
    FUD
  Worm (1)
    IRC/Flood.bq
Virus (75)
   (23)
    Dark Apoc.1016c
    Spice.2125c
    Jeru.1854a
    Jeru.Sunday.1636b
    Jeru.1733b
    Jeru.1720
    Shadow.4063
    VICE.630
    Spice.1441
    Jeru.1672
    Jeru.Sunday.1636a
    Jeru.1733a
    BootDr240
    Auspar.292a
    BootDr239
    Vulcan
    QDrag.y
    Apl.480
    HLLT.8938b
    HLLT.9776
    HLLT.4997
    Flanker.867
    Crucifixion.2916
  Application extension (1)
    W32/Initx.dll
  Boot (2)
    Gloop
    Fidel.b
  Damaged (2)
    Liberty.dam
    Stoned.dam
  Demonstration (1)
    DSME.Demo.d
  Dropper (2)
    Dark Apoc.dr
    W32/Deborm.dr
  E-mail (2)
    W32/Kindal@MM
    W32/Ganda@MM
  E-mail worm (4)
    W32/Generic.a@MM
    W32/Miniman@MM
    W32/Neroma.b@MM
    W32/Holar.d@MM
  Email (7)
    VBS/Ypsan@MM
    VBS/Renalo.b@MM
    VBS/Renalo.a@MM
    W32/Lovgate.e@M
    W32/Lamado@MM
    W32/Ixas.b@MM
    W32/Ixas.a@MM
  Email Generic (1)
    W32/Gibe.gen@MM
  HTML document (1)
    W32/Lamado.htm
  Intended (1)
    JS/Spalm.intd
  Internet Worm (2)
    W32/Neroma.a@MM
    W32/Bibrog.d@MM
  Macro (2)
    X97M/Jal
    A97M/AccessiV.e
  Malware Tool (2)
    W97M/Sops.Kit.c
    WM/MWVCK.Kit.c
  multipartite (2)
    Matthew.mp.3037e
    Civil.mp.6672.k
  Overwriting (1)
    HLL.ow.7538
  Parasitic (2)
    HLLP.7136c
    HLLP.6816
  Script (12)
    Fanatik.bat.2540
    Fanatik.bat.2085
    VBS/Somie
    JS/Roncha
    VBS/Nobleman
    Bat/Liberte
    Bat/zz4
    Bat/xop.579
    Bat/xop.360a
    Bat/mid
    Bat/luc
    W32/Gant@MM.bat
  Win32 (2)
    W32/Tosep
    W32/Ganda
  Worm (3)
    W32/DuckTest.worm
    W32/Initx.worm
    W32/Deborm.worm

Enhanced Detections:

Malware (1)
  Denial Of Svc (1)
    DDoS-SQLhuc
Program (2)
  Malware Tool (1)
    VTool/adb
  Win32 (1)
    Parallaxis.Spider
Trojan (18)
  AOL Password (1)
    APSTrojan.tq
  Application extension (1)
    W95/Manyx.dll
  Configuration settings (1)
    VBS/Dismissed.ini
  Configurator (1)
    MultiDropper-EH.cfg
  Downloader (1)
    Downloader-O
  Dropper (3)
    MultiDropper-EH
    MultiDropper-FL
    MultiDropper-FM
  JavaScript (1)
    JS/SetZone
  Malware Tool (1)
    Kit-Kpwc
  Password Stealer (1)
    PWS-SPS
  Remote Access (2)
    BackDoor-PL
    BackDoor-AQU
  Script (4)
    Bat/hdk13
    Bat/ero
    Bat/bel
    JS/Deltree
  Win32 (1)
    Drone
Virus (78)
   (31)
    Alicia.c
    Alicia.b
    Alicia.a
    XTxcluded.802
    HLLT.8938
    HLL.sub.5632
    Jeru.1390
    Spice.2125a
    ARCV.More
    Morphine.3500.c
    Prague.330
    Auspar.292
    Shy-Demon
    Carpe Diem
    Attitude
    XTAC.1564
    Spice.2131
    Spice.1619
    Spice.1440
    Jeru.2208
    ARCV.Scroll.800
    Spice.2125b
    Spice.2123
    Spice.1451
    Xtar.1605
    Opic
    Lame.207
    Apocalypse.1685
    Light
    Jeru.1854
    Rest.1588
  Boot (4)
    WelcomB
    SeeYou
    SVS
    Fidel
  Demonstration (1)
    RTP.Demo.1b
  Dropper (2)
    W32/Mincer.dr
    Sniggle.dr
  Dropper multipartite (1)
    Kuarahy.mp.dr
  E-mail worm (1)
    W32/Bibrog.a@MM
  Email (1)
    VBS/Metacol@MM
  File Infector (1)
    Split
  Generic (2)
    IRC/Hchik.gen
    VBS/Devolve.gen
  Internet Worm (2)
    W32/Bibrog.c@MM
    W32/Bibrog.b@MM
  Macro (14)
    WM/ERASER.L
    WM/ERASER.K
    WM/ERASER.F
    WM/ERASER.E
    WM/ERASER.H
    WM/Eraser.o
    WM/Eraser.b
    WM/Eraser.n1
    WM/Eraser.m
    WM/Eraser.j
    WM/Eraser.i
    WM/Eraser.g
    WM/Eraser.c
    WM/Eraser.a
  Malware Tool (2)
    WM/MWVCK.Kit.a
    WM/MWVCK.Kit.b
  Multi-Partite (1)
    BNut.mp.cav.448
  multipartite (6)
    Angela.mp
    Kampana.mp.3445
    Kuarahy.mp
    Uranus.mp.2080
    Uranus.mp.2050
    Uranus.mp.2048
  Parasitic (1)
    HLLP.4859b.Light
  Script (5)
    HLL.sub.5632.bat
    Bat/xop.850
    Bat/fm
    VBS/Metacol
    Bat/xop.360
  Win32 (1)
    W32/Mincer
  Win9x (2)
    W95/Beast.b
    W95/Beast.a