Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4255
DAT Release Date 04/02/2003
Threats Detected 69155
New Detections 140
Enhanced Detections 182

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Internet Worm (1)
  E-mail worm (1)
    W32/Lanet@MM
Joke (1)
  Win32 (1)
    Butterfly joke
Program (16)
   (1)
    RealSpy
  Adware (1)
    Adware-IntDel
  Dialer (1)
    PornDial-157
  Joke (3)
    WM/Auge joke
    W97M/Sant joke
    Asder joke
  Keylogger (1)
    Keylog-M4log
  Malware Tool (8)
    VTool/vgn4
    VTool/mos
    VTool/fmt2
    VTool/ded
    VTool/ama
    VTool/delsys
    VTool/ans2
    VTool/1ma
  Win32 (1)
    KeySpy-FPSpy
Trojan (42)
   (1)
    Neutron
  Application extension (1)
    Keylog-SCLog.dll
  Client (1)
    BackDoor-ASB.cli
  Configurator (4)
    BackDoor-AQF.cfg
    Downloader-AA.cfg
    BackDoor-ASC.cfg
    BackDoor-ASB.cfg
  Downloader (1)
    Downloader-BW.c
  Generic (3)
    BackDoor-ANG.gen
    PWS-Barok.gen
    BackDoor-ASB.gen
  Password (1)
    PWS-WMPatch
  Password Stealer (3)
    PWS-Skyflower
    PWS-Benkill
    PWS-Neman
  Plugin component (1)
    BackDoor-AOP.plugin
  Remote Access (9)
    BackDoor-ASC
    BackDoor-ASB
    BackDoor-ASI
    BackDoor-ASE
    BackDoor-ASD
    BackDoor-ASG
    BackDoor-ASJ
    BackDoor-ASF
    PHP/BackDoor-AOP
  Script (11)
    VBS/Seeker.x
    Bat/sof
    Bat/qd66
    Bat/penc
    Bat/juj
    Bat/dt27
    VBS/Seeker.w
    JS/Seeker.v
    Bat/zz99
    Bat/wash
    Bat/lia.6
  Server (3)
    BackDoor-ASC.svr
    BackDoor-ASB.svr
    BackDoor-AQF.svr
  Uploader (1)
    Uploader-D.b
  Win32 (2)
    Kit-Verg
    ConCon
Virus (80)
   (1)
    Alicino.331
  Companion (2)
    W32/Parrot.cmp
    Bat/zek.cmp
  Damaged (2)
    W32/Ganda.dam
    W95/Dream.dam
  Dropper (4)
    W32/Spit.dr
    W95/Quza.dr
    Bat/xpe.drp
    W32/Hatter.dr
  Email (13)
    W32/Anaph@MM
    W32/Scrambler.j@MM
    W32/Oror.am@MM
    W32/Oror.an@MM
    W32/Hermes.f@MM
    W32/Alcop.aq@MM
    W32/Scrambler.i@MM
    W32/Pepex@MM
    W32/Oror.ap@MM
    W32/Oror.al@MM
    W32/Oror.ao@MM
    W32/Gift@MM
    W32/Alcop.ap@MM
  Email Generic (1)
    W32/Myparty.gen@MM
  Generic (1)
    W95/Quza.gen
  Generic Worm (1)
    W32/Buffy.worm.gen
  Macro (1)
    X97M/Toraja
  P2P Worm (1)
    W32/Reader.worm
  Parasitic (2)
    W32/HLLP.Emesix
    W32/HLLP.36864
  Script (22)
    Bat/qz999
    Bat/mtl
    Bat/lia.4b
    Bat/h2t1
    Bat/ctt.b
    Bat/ctt.d
    Bat/crz.1284
    Bat/bug.560a
    VBS/Leer
    Bat/xop
    Bat/wis
    Bat/sy2
    Bat/sy1
    Bat/lia.4a
    Bat/hol
    Bat/fqu
    Bat/ctt.c
    Bat/ctt.a
    Bat/crz.1289
    Bat/bug.560b
    Bat/abb.b
    Bat/abb.a
  Win32 (8)
    W32/Spit.d
    W32/Spit.b
    W32/Opaserv.x
    W32/Triplix
    W32/Spit.c
    W32/Spit.a
    W32/Primcol
    W32/Ipamor.c
  Win9x (4)
    W95/Quza.b
    W95/Poshkill.1348
    W95/Quza.a
    W95/CIH.1103g
  Worm (17)
    W32/Deborm.worm.q
    W32/Amazex.n.worm
    W32/Amazex.l.worm
    W32/Amazex.m.worm
    W32/Randon.worm.j
    W32/Goalweb.worm
    W32/Dabrat.worm
    VBS/Ytunfun.worm
    W32/GenericIRC.worm
    W32/Yoof.worm
    W32/Winur.worm.c
    W32/Varun.worm
    W32/Sysmed.worm
    W32/Rbit.worm
    W32/Bare.worm.g
    W32/Lepha.worm
    Gygax.worm

Enhanced Detections:

Internet Worm (1)
  mIRC Worm (1)
    IRC/Simpsalapim
Program (99)
   (8)
    WVTool/pol7
    WVTool/twi
    WVtool/tha
    WVTool/see
    WVTool/mat
    WVTool/qre
    WVTool/pun
    WVTool/dkm
  Demonstration (1)
    WM/Beef.demo
  Malware Tool (3)
    VTool/fmt
    VTool/rht
    VTool/ans
  Partition (1)
    April
  Win31 (2)
    WVTool/sen
    WVTool/clz
  Win32 (84)
    WVTool/gpa7
    WVTool/isp
    WVTool/iml
    WVTool/hpr
    WVTool/fvw
    WVTool/twv
    WVTool/eyb
    WVTool/deb
    WVTool/mdp
    WVTool/lpf
    WVTool/jef
    WVTool/etr
    WVTool/zom
    WVTool/tsv
    WVTool/suk
    WVTool/mua
    WVTool/mxc
    WVTool/lj2
    WVTool/gsh1
    WVTool/gpa4
    WVTool/gpa2
    WVTool/gpa1
    WVTool/dla
    WVTool/dev
    WVTool/cry
    WVTool/cdr
    WVTool/bla
    WVTool/lj1
    WVTool/sed
    WVTool/hok
    WVTool/gpa8
    WVTool/gmh2
    WVTool/kyg
    WVTool/gpa6
    WVTool/gcp
    WVTool/dpg
    WVTool/pol6
    WVTool/pol4
    WVTool/pol2
    WVTool/pol5
    WVTool/pol3
    WVTool/mme2
    WVTool/tra
    WVTool/epr2
    WVTool/epr1
    WVTool/ede
    WVTool/rht
    WVTool/epr5
    WVTool/epr3
    WVTool/spn2
    WVTool/epr6
    WVTool/epr4
    WVTool/eax
    WVTool/zin
    WVTool/rlk
    WVTool/nom
    WVTool/lda
    WVTool/imp
    WVTool/icp
    WVTool/epr7
    WVTool/duk
    WVTool/cre2
    WVTool/cre1
    WVTool/bas
    WVTool/ata
    WVTool/rg0
    WVTool/yod
    WVTool/wms
    WVTool/igm
    WVTool/gho
    WVTool/adb
    WVTool/mme1
    WVTool/spn1
    WVTool/pol1
    WVTool/gsh2
    WVTool/gmh1
    WVTool/tro
    WVTool/run
    WVTool/dw
    WVTool/bec
    WVTool/redh
    WVTool/rpa
    WVTool/gtkph
    WVTool/xasm
Trojan (26)
   (4)
    SoD
    Ansibomb.e
    Ansibomb.a
    Ansibomb.b
  Client (1)
    BackDoor-AOP.cli
  Configurator (1)
    BackDoor-AOP.cfg
  Downloader (1)
    Downloader-AA
  Dropper (1)
    PWS-HTool.dr
  Malware Tool (1)
    Spam-Kubik
  Password (1)
    PWS-HTool
  Remote Access (4)
    BackDoor-AOP.inst
    BackDoor-ADT
    BackDoor-ALM
    BackDoor-LK
  Script (9)
    Bat/abh
    Bat/abg
    Bat/abj
    Bat/pfv
    Bat/dt14
    Bat/zz2
    Bat/kam
    Bat/tc
    Bat/jy
  Uploader (1)
    Uploader-D.a
  Win32 (2)
    Sevgi
    XPlain
Virus (56)
  Companion (1)
    Bat/grem.cmp
  Damaged (1)
    W95/Infinite.dam
  Dropper (5)
    Bat/crz.dr
    W95/Infinite.dr.c
    W95/Infinite.dr.b
    W95/Infinite.dr.a
    Bat/t.dr
  E-mail (2)
    W32/Wanor@MM
    W32/Aplore@MM
  E-mail worm (1)
    VBS/Grimgram@MM
  Email (2)
    W32/Generic@MM
    W32/Dilbert@MM
  Email Generic (1)
    W32/Duksten.gen@MM
  Intended (2)
    W32/Poter.intd
    W32/Anaph.4279.intd
  Internet Worm (1)
    JS/Spth
  Malware Tool (1)
    Duke/SMF.kit
  multipartite (4)
    Yesmile.mp
    XIVLO.mp.2248
    Wire.mp.3518
    Winstart.mp.768
  Parasitic (1)
    W95/Infinite.cav.a
  Script (28)
    Bat/mos
    Bat/lia
    Bat/lia.5a
    Bat/dic2
    Bat/arh
    Bat/zz4
    Bat/luc
    Duh.bat
    Bat/lia.dbg
    Bat/lia.4
    Bat/lia.7
    Bat/lia.3
    Bat/lia.6b
    Bat/lia.6a
    Bat/lia.3b
    Bat/lia.3a
    Bat/lia.2
    Bat/lia.1
    Bat/lia.5b
    Bat/fut
    Bat/crz.1414
    Bat/crz.1286
    Bat/crz.1262
    Bat/ci
    Bat/yi
    Bat/mu
    Bat/mu.b
    Bat/mu.a
  Source code (1)
    Bat/lia.2.src
  Win9x (3)
    W95/Poshkill.1398
    W95/Poshkill.1445
    W95/Infinite.b
  Worm (2)
    W32/Buffy.worm.c
    W32/Sytro.worm.ax