Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4245
DAT Release Date 01/29/2003
Threats Detected 63605
New Detections 200
Enhanced Detections 187

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
Sadhound Low-Profiled Low-Profiled
W32/Sdbot.18976 Low-Profiled Low-Profiled

New Detections:

Malware (1)
  Denial Of Svc (1)
    DDoS-SQLhuc
Program (36)
   (1)
    WVTool/pol7
  - (1)
    Closer
  Adware (1)
    Downloader-BT
  Application extension (1)
    ScreenCapture.dll
  Dialer (2)
    PornDial-101.b
    PornDial-101.a
  Keylogger (1)
    Keylog-Payklog
  Malware Tool (21)
    VTool/src3
    VTool/tpu
    VTool/src2
    VTool/src1
    VTool/pre
    VTool/pol2
    VTool/mte
    VTool/mad
    VTool/hai
    Vtool/cbt
    VTool/av7
    VTool/vio
    VTool/src5
    VTool/src4
    VTool/pol3
    VTool/pol1
    VTool/msg
    VTool/irw
    Vtool/dgm
    VTool/bvs
    VTool/ato
  Tool (1)
    Tool-CGIScan
  Win31 (1)
    WVTool/clz
  Win32 (6)
    WVTool/pol6
    WVTool/pol4
    WVTool/pol2
    WVTool/pol5
    WVTool/pol3
    WVTool/mme2
Trojan (70)
   (1)
    Winsex.c
  - (2)
    W32/Sdbot.18976
    KeyLog-TweakPan
  Application extension (2)
    BackDoor-APK.dll
    BackDoor-AMR.dll
  Client (1)
    BackDoor-APJ.cli
  Configuration settings (1)
    ManifestDest.ini
  Configurator (1)
    BackDoor-APJ.cfg
  Downloader (1)
    Downloader-BO.c
  Dropper (8)
    Sadhound
    Downloader-BO.dr.b
    BackDoor-AGS.dr
    Bat/spt.dr
    MultiDropper-FG
    MultiDropper-FF
    PWS-DupWin.dr
    BackDoor-Y.dr
  Exploit (3)
    Linux/Exploit-Da2
    Linux/Shinject
    Exploit-Jill
  File deleting (8)
    QDel367
    QDel366
    QDel361
    QDel368
    QDel364
    QDel363
    QDel362
    QDel365
  Flooder (2)
    FDoS-AutoAttack
    FDoS-Leeter
  Java Applet (1)
    JV/Guestbook
  Linux (1)
    Linux/Shinject.v04
  Malware Tool (2)
    Spam-AlienBmb
    Kit-Zysangel
  Password (1)
    W32/Liku
  Password Stealer (3)
    PWS-PWKiller
    PWS-Kukel
    PWS-Bendi
  ProcKill (5)
    ProcKill-Y
    ProcKill-W
    ProcKill-V
    ProcKill-U
    ProcKill-X
  Remote Access (8)
    BackDoor-API
    BackDoor-ALI
    BackDoor-APK
    Backdoor-APH
    BackDoor-ANF.log
    BackDoor-ALI.sys
    BackDoor-ALI.srv
    BackDoor-KE
  Script (4)
    Bat/qd11
    Bat/wag
    Bat/qz13
    IRC/Flood.ba.bat
  StartPage (1)
    StartPage-F
  Win32 (14)
    AdClicker-N
    AutoAccept
    Spy-ZZsoft
    Renamer.b
    MSNPranker
    Mecool
    KillAppl
    IPGetter
    Halloway
    Blakhal
    Reboot-W
    Fakelogin
    Ashcan
    APCrack
Virus (93)
   (10)
    Eternal-Blaze
    Werewolf.685b
    Werewolf.684b
    BootDr234
    Lorenzo.9214
    Bobo.513
    Basvir.478
    Werewolf.685a
    Werewolf.684a
    Dark Avenger.1028
  Application extension (1)
    W32/Netspree.dll
  Companion (1)
    W32/Hide.cmp
  Dropper (12)
    Hymn.dr
    Worker.dr
    Birgit.dr
    Bat/hny.dr
    Bat/cbt1.dr
    Bat/cbb.dr
    Bat/alc1.dr
    W95/RainSong.4262.b.dr
    W95/RainSong.4262.a.dr
    Werewolf.685b.dr
    W95/Zerg.dr
    W95/Xine.dr
  Email (10)
    W32/BackZat.d@MM
    W32/Sowsat.e@MM
    W32/Sowsat.d@MM
    W32/Yougdos@MM
    W32/Kameral.c@MM
    W32/Kameral.b@MM
    W32/Kameral.a@MM
    W32/Duksten.l@MM
    W32/Duksten.k@MM
    W32/Cherich.d@MM
  Email Generic (2)
    W32/Sowsat.gen@MM@MM
    W32/BackZat.gen@MM
  Generic Worm (1)
    W32/Kazmor.worm.gen
  Intended (2)
    VBS/Dasbud.intd
    W32/Chatter.intd
  Internet Relay Chat (2)
    IRC/Yougdos
    IRC/Eroc
  Internet Worm (2)
    W32/Netspree.worm
    W32/Pkasa@MM
  Macro (1)
    W97M/Ant
  Malware Tool (1)
    Bat/hbb.kit
  mIRC Worm (1)
    W32/Eroc.worm
  Parasitic (1)
    W95/Radix.cav.436
  Script (21)
    Bat/shk
    Bat/tns
    VBS/Bian
    Bat/pef2
    Bat/ora
    Bat/hny
    Bat/duk
    Bat/dic2
    Bat/damn
    Bat/cic
    Bat/bgo
    Bat/arh
    VBS/Zulu.vbs.a
    Bat/wst
    Bat/obs
    Bat/mel
    Bat/cbt2
    W32/Yougdos.bat
    W32/Yougdos.reg
    W32/Buffy.bat
    W32/Netspree.bat
  Win32 (5)
    W32/Porex.a
    W32/Kifie
    W32/BinHe.c
    W32/BinHe.b
    W32/BinHe.a
  Win9x (2)
    W95/RainSong.4262.b
    W95/RainSong.4262.a
  Word document (6)
    Bat/wav.doc
    Bat/hny.doc
    Bat/gom.doc
    Bat/duk.doc
    Bat/a.doc
    Bat.a.2151.doc
  Worm (12)
    W32/Posam.worm
    W32/Amazex.j.worm
    W32/Nilit.g.worm
    W32/Titog.worm.e
    W32/Osapex.c.worm
    W32/Socay.worm
    W32/Legend.worm
    W32/Kazmor.worm.g
    W32/Grexon.worm
    W32/Dormer.worm.d
    W32/Buffy.worm
    W32/Nevereg.worm

Enhanced Detections:

Internet Worm (1)
  Open Share Worm (1)
    W32/Ultimax.worm
Program (7)
  Configurator (1)
    Tool-Exter.cfg
  Script (2)
    Bat/ack
    Bat/ace
  Source code (1)
    Generator.SRCG non
  Tool (1)
    Tool-Exter
  Win32 (2)
    WVTool/mme
    WVTool/pol
Trojan (35)
  Client (1)
    BackDoor-ANF.cli
  Configurator (2)
    BackDoor-KE.cfg
    PWS-Zombie.cfg
  Dropper (6)
    MultiDropper-FB
    BackDoor-SP.dr
    IRC/Flood.bd.dr
    Hide Minimized.dr
    Prova.dr
    MultiDropper-CH
  Generic (2)
    VBS/Concon.gen
    Fluxay.gen
  JavaScript (1)
    Unsafe JS
  Malware Tool (1)
    VBS/RunScript.Kit
  mIRC client (1)
    IRC/Flood.bd.mirc
  Password (1)
    PWS-MSNSteal
  Password Stealer (2)
    PWS-Zombie
    PWS-DupWin
  Plugin component (1)
    BackDoor-ANF.plugin
  Remote Access (4)
    BackDoor-AQ
    BackDoor-ANF.utl
    BackDoor-TL
    BackDoor-Y
  Script (7)
    Bat/abc
    Bat/abi
    Bat/acg
    Bat/acf
    Bat/acc
    Bat/acb
    Bat/aca
  Server (2)
    BackDoor-ANF.svr
    BackDoor-KE.svr
  Trojan (1)
    Prova
  Win32 (2)
    Reboot-V
    SysMan
  Worm (1)
    W32/Fix.12288@M
Virus (144)
   (5)
    MF
    BootDr229
    Evil-Spirit.1710
    Hymn.c
    Auspar
  - (2)
    W32/Frethem.q
    Evem.666
  Application extension (3)
    W32/Roach.dll
    W32/Dupator.dll
    W95/Dream.dll
  Boot (1)
    Satria
  Companion (3)
    W32/Egolet.cmp.b
    W32/Egolet.cmp.a
    W32/Crash.cmp
  Damaged (7)
    W32/Magistr.dam3
    W32/Darling.dam
    W32/Magistr.a.dam5
    W32/Magistr.dam2
    W32/Magistr.b.dam1
    W32/Magistr.a.dam1
    W32/Magistr.dam4
  Dropper (11)
    Bat/cod.dr
    W32/Gara.dr
    W95/RainSong.4386.dr
    W95/RainSong.4036.dr
    W32/Flee.dr
    Bat/mr.dropped
    Bat/dv.dr
    Bat/bf.dr.x
    Bat/bf.dr.1494
    Bat/ab.dr
    Bat/bf.dr.3516
  Dropper Overwriting (1)
    W32/Gacy.ow.dr
  E-mail worm (2)
    W32/Frethem.f@MM
    W32/DeltaD@MM
  Email (15)
    W32/Duksten.f@MM
    W32/Duksten.a@MM
    W32/Duksten.g@MM
    W32/Duksten.i@MM
    W2K/Outa@MM
    W32/Frethem.i@MM
    W32/Frethem.h@MM
    W32/Frethem.g@MM
    W32/Frethem.e@MM
    W32/Frethem.d@MM
    W32/Frethem.c@MM
    W32/Frethem.b@MM
    W32/Frethem.a@MM
    W32/Fayaz@MM
    W32/Creepy.b@MM
  Email Generic (1)
    W32/CryptoLab.gen@MM
  File Infector (1)
    W32/Fix.36864@M
  Generic (2)
    W32/Eva.gen
    W32/HLLP.8192.gen
  HTML document (5)
    VBS/Zulu.htm.b
    VBS/Zulu.htm.a
    VBS/Zulu.htm.f
    VBS/Zulu.htm.e
    VBS/Zulu.htm.d
  Intended (2)
    W32/Darling.intd
    W95/Lorez.intd
  Internet Worm (1)
    W32/Creepy.a@MM
  Malware Tool (1)
    Bat/l.kit
  multipartite (1)
    Doomm.mp
  Overwriting (1)
    W32/Gacy.ow
  Parasitic (2)
    W32/HLLP.53764
    W32/Elkern.cav.c
  Script (44)
    W32/Chiton.f.bat
    VBS/Lavra
    Bat/ab.2645
    Bat/BWG.vbs
    Bat/dic
    Bat/ae
    Bat/j.473
    Bat/r
    Bat/k
    Bat/j.475
    VBS/Zulu.vbs.b
    Bat/cod
    VBS/Zulu.vbs.g
    VBS/Zulu.vbs.f
    VBS/Zulu.vbs.d
    VBS/Voodoo.2312
    VBS/FWSV.d
    Bat/ms
    Bat/mm
    Bat/ma
    Bat/jg
    Bat/je
    Bat/hi
    Bat/dv.1414
    Bat/dv.1267
    Bat/dv.1286
    Bat/dv.1262
    Bat/bs
    Bat/bi
    Bat/bf (tail)
    Bat/bf.3516
    Bat/bf.1811
    Bat/bf.1876
    Bat/bf.1495
    Bat/ai.tmp
    Bat/ab.2711
    Bat/l.1295
    Bat/l.600
    Bat/mr
    Bat/bf.1497
    Bat/bf.1494
    Bat/ai
    Bat/l.601
    Bat/l.560
  Win32 (9)
    W32/Chiton.f.eml
    W32/Porex
    W32/BinHe!tool
    W32/Ghost
    W32/Eva.c
    W32/Eva.b
    W32/Eva.a
    W32/Enerzip
    W32/Flee
  Win9x (10)
    W95/Drol.5484
    W95/Drol.5337b
    W95/Drol.5337a
    W95/Dream
    W95/Lorez.c
    W95/Lorez.b
    W95/Lorez.a
    W95/Heretic
    W95/Cvirus.176128
    W95/Cvirus.311296
  Worm (14)
    W32/Fantast.worm.a
    W32/Flechal.worm
    W32/Fami.worm
    W32/Decencia.worm
    W32/Beavuh.worm
    W32/Titog.worm.b
    W32/Titog.worm.c
    W32/Kazmor.worm.f
    W32/Kazmor.worm.d
    W32/Kazmor.worm.e
    W32/Kazmor.worm.c
    W32/Kazmor.worm.b
    W32/Kazmor.worm.a
    W32/Dissed.worm