Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4260
DAT Release Date 04/30/2003
Threats Detected 71421
New Detections 494
Enhanced Detections 207

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Lovelorn@MM Low-Profiled Low-Profiled

New Detections:

- (1)
  - (1)
    W32/Coronex.worm.b
Internet Worm (1)
  Worm (1)
    W32/Spybot.worm.gen
Malware (1)
  Denial Of Svc (1)
    FDoS-Drincl
Program (32)
   (7)
    VObj10
    VObj9
    VObj8
    VObj5
    VObj12
    VObj7
    VObj4
  - (1)
    VObj
  Application extension (2)
    ILookup.dll
    Keylog-Panteras.dll
  Dialer (4)
    PornDial-170
    PornDial-171
    PornDial-169
    PornDial-168
  Dropper (2)
    Keylog-Panteras.dr
    ILookup.dr
  Malware Tool (11)
    VTool/tpe3
    Generator.Mime.kit
    VTool/tai
    VTool/rmn
    VTool/rkt2
    VTool/rkt1
    VTool/ivp
    VTool/hll
    VTool/hku
    VTool/40Hex
    Generator.DSCE.kit
  PornDialer (1)
    PornDial-167
  Remote Access (1)
    BackDoor-ATH
  Spyware (2)
    Keylog-Perfect
    Keylog-Panteras
  Tool (1)
    SuperSpy
Trojan (56)
   (1)
    FaithNoMore
  Application extension (2)
    PWS-Gina.dll
    PWS-Hiddu.dll
  Configurator (4)
    MultiDropper-FT.cfg
    MultiDropper-FR.cfg
    MultiDropper-FQ.cfg
    BackDoor-ATC.cfg
  Disk erasing (2)
    QZap316
    QZap251
  Downloader (4)
    Downloader-BW.d
    Downloader-CJ
    Downloader-CI
    Downloader-CH
  Dropper (9)
    Downloader-AB.dr
    Bat/dt32.dr
    MultiDropper-FU
    MultiDropper-FT
    MultiDropper-FS
    MultiDropper-FR
    MultiDropper-FQ
    MultiDropper-FP
    BackDoor-ATM.dr
  Exploit (4)
    UNIX/Exploit-Snort.191
    UNIX/Exploit-Xeneo
    JS/Exploit-IndexRun
    Exploit-Abuse
  File deleting (1)
    QDel380
  File Deletion (1)
    QDel379
  Flooder (1)
    FDoS-WinPopUp
  Generic (4)
    BackDoor-ATF.gen
    MultiDropper-FT.gen
    BackDoor-ATN.gen
    BackDoor-AMU.gen
  Heuristic (1)
    B2C.NewMafia
  Internet Relay Chat (1)
    IRC/Flood.by
  Keylogger (1)
    KeyLog-Stealth
  Password Stealer (4)
    PWS-MLD
    PWS-Hiddu
    PWS-FFast
    PWS-Cheeky
  Remote Access (10)
    BackDoor-ATG
    BackDoor-ATF
    BackDoor-ATD
    BackDoor-ATO
    BackDoor-ATN
    BackDoor-ATM
    BackDoor-ATL
    BackDoor-ATK
    BackDoor-ATJ
    UNIX/BackDoor-Syslog
  Script (3)
    VBS/Rebeq
    Bat/hel
    Bat/dt32
  Server (1)
    BackDoor-ATC.svr
  Spyware (1)
    Keylog-Perfect.dr
  Win32 (1)
    ICQPager-M
Virus (403)
   (352)
    Nov17.768
    Black Jec
    Backfont.765
    Timid.382a
    Timid.306b
    HLL.39423
    BootDr245
    Satanbug
    Korea-Curse.1653.f
    Jeru.1888d
    Jeru.664
    GCAE.3600
    Fu-Manchu.2080m
    WW
    VW.1085
    Permutan.544
    Helloween.1376l
    HateV.524a
    Youth
    Youth.577
    Youth.555.a
    Vienna.644
    Vacsina.1269
    Vacsina.1212a
    USTC.919
    Tumen.1092
    Timid.310
    Timid.431
    Timid.497c
    Timid.497a
    Timid.309
    Timid.513b
    Pixel.845
    Jeru.1540
    Jeru.679
    Jeff.812
    Anticad.3004c
    Piter.529
    Pinc.e
    Helloween.1182a
    Youth.581
    Youth.555.b
    Xany.181
    Vacsina.1339
    Vacsina.1212b
    Vacsina.1206
    Tiny-DI
    Timid.557
    Timid.526
    Timid.497b
    Timid.382b
    Timid.371b
    Timid.371a
    Timid.320
    Timid.313
    Timid.306d
    Timid.306c
    Timid.306a
    Timid.305b
    Timid.305a
    Timid.303b
    Timid.302b
    Timid.301c
    Timid.301a
    Timid.300a
    Timid.299
    Timid.298c
    Timid.298a
    Timid.297e
    Timid.297c
    Timid.297a
    Timid.290e
    Timid.290c
    Timid.290a
    Timid.288
    Timid.245
    Tanpro
    Sunny.2288
    Shanghai.4077
    Seventh Son.327
    Seventh Son.333c
    Seventh Son.254
    Seventh Son.283
    Seventh Son.473b
    Seventh Son.440
    Seventh Son.426
    Seventh Son.350b
    Seventh Son.334
    Seventh Son.332c
    Seventh Son.332a
    Seventh Son.284e
    Seventh Son.284c
    Seventh Son.284b
    Seventh Son.284a
    Seventh Son.281
    Seventh Son.271b
    Seventh Son.268
    Selfex.1472
    Prague.512b
    Prague.496
    Prague.321d
    Prague.321c
    Prague.321b
    Prague.321a
    Timid.305c
    Timid.303a
    Timid.302a
    Timid.301b
    Timid.300b
    Timid.298b
    Timid.297f
    Timid.297d
    Timid.297b
    Timid.295
    Timid.290d
    Timid.290b
    Timid.289
    Timid.263
    Seventh Son.344
    Seventh Son.333b
    Seventh Son.253
    Seventh Son.331
    Seventh Son.473a
    Seventh Son.428
    Seventh Son.424
    Seventh Son.350a
    Seventh Son.333
    Seventh Son.332b
    Seventh Son.286
    Seventh Son.284d
    Seventh Son.271a
    Prague.512a
    Prague.318
    Prague.317
    Prague.253b
    Prague.253a
    Prague.249b
    Prague.249a
    Peach.887
    Oldyank.2051b
    Oldyank.2051a
    Oldyank.1961h
    Oldyank.1961g
    Oldyank.1961f
    Oldyank.1961e
    Oldyank.1961d
    Oldyank.1961c
    Oldyank.1961b
    Oldyank.1961a
    Oldyank.1847
    Oldyank.1835
    Oldyank.1755d
    Oldyank.1755
    Oldyank.1641
    Nympho.787
    Nov17.864
    Nov17.855a
    Nov17.800c
    Nov17.800b
    Nov17.706a
    Karin.1090
    June16th.879
    Hero.506
    Grune.1241
    Game
    Flash.749
    Flash.688
    FJYD.969
    FF.1536.d
    FF.1536.PinA
    FF.1536.PinF
    FF.1536.PinE
    FF.1536.PinB
    FF.1536.PinI
    FF.1536.PinH
    FF.1536.PinG
    FF.1536.PinD
    FF.1536.PinC
    FF.1536.c
    FF.1536.a
    Doom.1519x
    DM.400.a
    DM.330
    Diamond.1110
    Diamond.1063
    Dark Avenger.ag
    Dark Avenger.m
    Dark Avenger.l
    Dark Avenger.Singapore
    Dark Avenger.k
    Dark Avenger.j
    Dark Avenger.1832b
    Oldyank.1624
    Nov17.880
    Nov17.855b
    Nov17.800a
    Nov17.706b
    Nov17.690
    Mich.924
    Lemming.2029
    July13
    George.978
    Flash.695
    FF.1536.PinK
    FF.1536.Picell
    FF.1536.e
    FF.1536.b
    Doom
    Doom.1504
    DM.400.b
    Dark Avenger.1449
    Dark Avenger.n
    Dark Avenger.1813
    Dark Avenger.i
    Dark Avenger.1802a
    Dark Avenger.HLT
    Dark Avenger.1693
    Dark Avenger.h
    Dark Avenger.g
    Dark Avenger.f
    Dark Avenger.1947
    Dark Avenger.ai
    Dark Avenger.aj
    Dark Avenger.e
    Dark Avenger.d
    Dark Avenger.c
    Dark Avenger.b
    Dark Avenger.a
    Dark Avenger.1803b
    Dark Avenger.1803a
    Dark Avenger.1841d
    Dark Avenger.1841c
    Dark Avenger.1841b
    Dark Avenger.1841a
    Dark Avenger.1803c
    Dark Avenger.1849
    Dark Avenger.1802b
    Dark Avenger.1792
    Dark Avenger.1800u
    Dark Avenger.1800s
    Dark Avenger.1800q
    Dark Avenger.1800o
    Dark Avenger.1801c
    Dark Avenger.1801a
    Dark Avenger.1832
    Dark Avenger.2136b
    Dark Avenger.1365
    Dark Avenger.1690
    Dark Avenger.1530a
    Danish Tiny.163m
    Danish Tiny.333g
    Danish Tiny.245
    Danish Tiny.163k
    Danish Tiny.163j
    Danish Tiny.163i
    Danish Tiny.207a
    Danish Tiny.319
    Danish Tiny.333f
    Danish Tiny.334
    Danish Tiny.161
    Danish Tiny.163e
    Danish Tiny.333c
    Danish Tiny.333b
    Danish Tiny.311b
    Danish Tiny.333a
    Danish Tiny.263b
    Danish Tiny.263a
    Danish Tiny.311a
    Danish Tiny.476b
    Danish Tiny.163g
    Danish Tiny.163f
    Danish Tiny.289
    Danish Tiny.163d
    Danish Tiny.284a
    Danish Tiny.180
    Danish Tiny.163b
    Danish Tiny.333d
    Danish Tiny.256
    Danish Tiny.163a
    Danish Tiny.251a
    Dark Avenger.1800ah
    Dark Avenger.1728
    Dark Avenger.1800v
    Dark Avenger.1800t
    Dark Avenger.1800r
    Dark Avenger.1800p
    Dark Avenger.1801d
    Dark Avenger.1801b
    Dark Avenger.1805
    Dark Avenger.1808
    Dark Avenger.1783
    Dark Avenger.1797d
    Dark Avenger.2136a
    Dark Avenger.1000
    Dark Avenger.1530b
    Danish Tiny.163l
    Danish Tiny.207b
    Danish Tiny.163h
    Danish Tiny.270
    Danish Tiny.311c
    Danish Tiny.164
    Danish Tiny.312
    Danish Tiny.476a
    Danish Tiny.284c
    Danish Tiny.284b
    Danish Tiny.287
    Danish Tiny.163c
    Danish Tiny.286
    Danish Tiny.177
    Danish Tiny.333e
    Danish Tiny.1000
    Danish Tiny.191
    Danish Tiny.251b
    Creeper
    Creeper.297
    Creeper.294
    Creeper.252.b
    Creeper.252.a
    Coib.702
    Carioca.951
    Bomb.1492
    Black Monday.781
    Backfont.896
    Backfont.821
    Backfont.905
    Andromeda
    Andromeda.661
    Andromeda.713b
    Andromeda.772
    Andromeda.771
    Andromeda.725
    Andromeda.800
    Andromeda.758c
    Andromeda.749
    Alabama.1560.b
    HLLT.5400c
    HLLT.5602c
    HLLT.Weed.5850h
    HLLT.Weed.5850f
    HLL.5088
    HLL.4601
    Backfont.900
    ATB.1522b
    Andromeda.713a
    Andromeda.826
    Andromeda.758d
    Andromeda.758a
    Alabama.1560.c
    Alabama.1560.a
    ABAP/Rapid
    HLLT.Weed.5850g
    HLLT.Weed.4080
  Damaged (4)
    Tiny-DI.dam
    Diamond.1063.dam
    Dark Avenger.1801e.dam
    Dark Avenger.dam
  Dropper (15)
    Univ.dr
    Black Monday.dr
    Piter.dr
    GCAE.3600.dr
    Walker.3846.dr
    Honi.dr
    Ear-Homecoming.dr
    Zbug.dr
    FF.1536.PinG.dr
    MGTU.273.dr
    Dark Avenger.1801e.dr
    Creeper.252.dr
    HLLP.7360.dr
    W32/Lovelorn.dr
    Predator.c.dr
  Email (4)
    W32/Bajar@MM
    W32/Sint@MM
    W32/Avoner@MM
    VBS/Kivi@M
  File Infector (1)
    W32/Yourde
  Generic (8)
    Zbug.GR
    Tic.GR
    Suriv.GR
    Nina.GR
    MGTU.GR
    Friday13.GR
    Kalah.GR
    Guess.GR
  Internet Worm (1)
    W32/Lovelorn@MM
  multipartite (2)
    Invisible.mp.2927
    Anticad.mp.4096.q
  Parasitic (3)
    HLLP.10894
    HLLP.7582
    HLLP.Feci.7000
  Win31 (1)
    BootDr244
  Win32 (1)
    W32/Jits
  Worm (11)
    W32/Sory.worm
    W32/Randon.worm.m
    W32/Randon.worm.k
    W32/Gammes.worm
    W32/Winur.worm.e
    W32/Winur.worm.d
    W32/Sddrop.worm.e
    W32/Randon.worm.l
    W32/Opex.worm
    W32/Goalweb.worm.a
    W32/Demspy.worm

Enhanced Detections:

Program (20)
   (1)
    Generator.MtE
  Configurator (1)
    SkServer.cfg
  Malware Tool (17)
    VTool/obj13
    VTool/obj1
    VTool/hig
    VTool/obj2
    VTool/obj10
    VTool/obj6
    VTool/obj12
    VTool/obj3
    VTool/obj16
    VTool/obj15
    VTool/obj14
    VTool/obj19
    VTool/obj17
    VTool/obj18
    VTool/obj/mpc
    VTool/obj21
    VTool/obj20
  Win32 (1)
    SkServer.srv
Trojan (18)
   (1)
    HLL.Big
  Client (2)
    BackDoor-ASR.cli
    BackDoor-ASW.cli
  Configurator (1)
    Downloader-BH.cfg
  Downloader (2)
    Downloader-BH
    Downloader-BU
  Internet Relay Chat (1)
    IRC/Flood.ba.hidewin
  Internet Worm (1)
    Pokey
  mIRC client (1)
    IRC/Flood.ba.mirc
  Password (1)
    Grador
  Password Stealer (2)
    PWS-GinaStub
    PWS-Benkill
  Remote Access (3)
    BackDoor-ASR
    BackDoor-ABB
    BackDoor-ARP
  Script (1)
    Bat/qd75
  Server (1)
    BackDoor-ASR.svr
  Settings Change (1)
    SWCall
Virus (169)
   (20)
    BootDr100
    MPC
    HLL.6146
    Weed.11700
    Weed.17550b
    Weed.17550a
    HLL.Mimicry
    Danish Tiny.162
    Danish Tiny.310
    Danish Tiny.308
    Pixel.a
    HateV.524
    Keypress.1495
    BootDr206
    VRN
    Literatura.dd.2126
    Korea-Curse.1653.e
    Joan
    Helloween.1182
    Feci.6000
  Client (1)
    W32/HLLP.BackDoor.Yai.cli
  Companion (2)
    HLL.cmp.3431
    HLL.cmp.4045
  Companion multipartite (2)
    Princept.mp.cmp.973
    Snafu.mp.cmp
  Damaged (2)
    W32/Yaha.g.dam
    W32/Haless.dam
  Damaged multipartite (2)
    Rex.mp.1637.dam
    PTC.mp.dam
  Dropper (4)
    Literatura.dr
    W95/Henky.Chakan.dr
    Jerusalem.dr
    Hope.4080.dr
  Dropper multipartite (2)
    Alar.mp.dr
    PTC.mp.dr
  Email (6)
    W32/Cholera@MM
    W32/Haiku@MM
    W32/Excuse@MM
    W32/Gant@MM
    VBS/LoveLetter.h@MM
    W32/Hybris@MM
  Email Generic (2)
    W32/Higuy.gen@MM
    W32/IceCube.gen@M
  File Infector (9)
    Hero
    Highlander
    Macedonia.400
    Shanghai
    Traceback
    USSR
    Pirates Hat.2360
    ADA
    W95/Halen
  Generic (1)
    W95/Hillary.gen
  Generic Worm (1)
    W32/Gemel.worm.gen
  Heuristic (2)
    New Win32.g
    New MSVB P2P worm
  multipartite (63)
    USTC.mp
    Invisible.mp.3223b
    Invisible.mp.3223a
    Ugly.mp
    Traka.mp
    Res.mp
    Prowler.mp
    Flip.mp.2153c
    Flip.mp.2153a
    Flip.mp.2351
    Flip.mp.2153d
    Flip.mp.2153b
    Avenge.mp.1344
    Tchechen.mp.1988
    WMA.mp.451
    WMA.mp.448b
    WMA.mp.448a
    WMA.mp.426
    WMA.mp.425
    WMA.mp.424
    Zaraza.mp
    Yonder.mp.7697
    Unapt.mp.1526
    Tyson.mp.4292
    Tequila.mp.2494
    Tequila.mp.2469
    Tequila.mp.2468f
    Tequila.mp.2468d
    Tequila.mp.2468c
    Tequila.mp.2468e
    Tequila.mp.2468b
    Tequila.mp.2468a
    TEDY.mp.4350
    Talon.mp.1979.b
    Talon.mp.1979.a
    StealthBoot.mp.3080
    Starship.mp.2632
    Sphinx.mp.2751
    Sochi.mp.703
    Smut.mp.938
    Shrapnel.mp.6067
    Serg.mp.874
    Sepultura.mp.2135
    Samara.mp.1536
    Rex.mp.1637
    Renegade.mp.4946
    Renegade.mp.4509
    Rasek.mp.1492
    Rasek.mp.1489b
    Rasek.mp.1489a
    Rasek.mp.1490
    Rasek.mp.1310
    Raiden.mp.1433
    Quiz.mp.1024
    QMU.mp.1513
    Prowler.mp.1543dr
    Tequila.mp
    Smile.mp
    Pres.mp.1504
    Alar.mp.4270
    Alar.mp.4873
    Alar.mp.5088
    Alar.mp.4625
  multipartite Parasitic (5)
    BootEXE.mp.cav
    Stalker.mp.cav.382
    Stalker.mp.cav.320
    Stalker.mp.cav.310
    Rimie.mp.cav
  Overwriting (3)
    W32/HLL.ow.24579
    W32/HLL.ow.14848
    W32/HLL.ow.Jetto
  P2P Worm (3)
    W32/Reader.worm
    W32/Winur.worm.a
    W32/Winur.worm.b
  Parasitic (16)
    HLLP.7360
    HLLP
    W32/HLLP.Giwin.g
    W32/HLLP.Giwin.f
    W32/HLLP.Giwin.e
    W32/HLLP.Giwin.d
    W32/HLLP.Giwin.c
    W32/HLLP.Giwin.b
    W32/HLLP.Giwin.a
    W32/HLLP.32767.b
    W32/HLLP.32767.a
    Prion.cav
    W32/HLLP.34818
    W32/HLLP.20480
    W32/HLLP.16986b
    W32/HLLP.16986a
  Script (1)
    Bat/fe
  Source code (1)
    W97M/Vibisi.src
  VbScript (1)
    VBS/Fool
  Win32 (8)
    W32/Hll.12355
    W32/HLL.28471
    W32/Henky.Tanzen
    W32/Hellfire
    W32/Glyn.b
    W32/Glyn.a
    W32/Hamlet
    W32/Haless.1127
  Win9x (5)
    W95/Henky.Chakan.12312
    W95/Henky.Chakan.12316
    W95/Horn.2223b
    W95/Horn.2223a
    W95/Greenpea
  Worm (7)
    W32/Pony.worm.a
    W32/Nhkr.worm.a
    W32/Pony.worm.b
    W32/Nhkr.worm.b
    W32/Goalweb.worm
    W32/Winur.worm.c
    W32/Rbit.worm