Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4267
DAT Release Date 05/28/2003
Threats Detected 73409
New Detections 163
Enhanced Detections 93

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Fakerr@MM Low-Profiled Low-Profiled
W32/Vote.k@MM Low-Profiled Low-Profiled
W32/Cayam.worm!p2p Low-Profiled Low-Profiled

New Detections:

Internet Worm (2)
  E-mail worm (1)
    W32/Cayam.worm!p2p
  P2P Worm (1)
    W32/Generic.worm!p2p
Program (38)
   (5)
    Sniff-Orifice
    Picture-Reich
    Picture-Nag
    Picture-Moby
    Picture-Atmosphere
  Adware (2)
    Adware-PornKings
    Adware-RBlast
  Demonstration (1)
    Demo-Zombie
  Downloader (1)
    Adware-SRNG.dldr
  Dropper (1)
    Adware-RBlast.dr
  Joke (1)
    FakeDOS joke
  Malware Tool (4)
    VTool/pci
    PWCrack-NTCrack
    PWCrack-Netbus
    PWCrack-Abel.rmv
  PornDialer (1)
    PornDial-177
  Settings Change (1)
    Delshare
  Spam (1)
    Adware-Ezula
  Tool (8)
    HideRun
    CPUhog
    Crack-DTNetscan
    Tool-RemoteProcess
    Tool-RemoteKill
    Tool-ElimGVir
    Tool-AppToService
    Tool-Antigen
  Win32 (12)
    FakeFormat
    VText-Progenic
    Spoof-Subuster
    Spoof-FakeBO
    Spector.rmv
    Sockets.rmv
    Sniff-IPAttack
    PortScan-SQL.Debug
    PortScan-FireBall
    PortScan-BThreads
    BackOrifice.rmv
    Portscan-BOPinger
Trojan (59)
   (1)
    ASP/Raph
  - (1)
    IRC/Flood.tool
  Application extension (1)
    BackDoor-AUN.dll
  Damaged (1)
    BillyPie.dam
  Demonstration (1)
    Kit-Revert.demo
  Disk erasing (1)
    QZap252
  Downloader (1)
    Downloader-CM
  Dropper (4)
    QZap252.dr
    JS/Startpage-K.dr
    Keylog-Spider.dr
    BackDoor-AUQ.dr
  Exploit (3)
    Exploit-IFrame
    UNIX/Exploit-IEHK
    Exploit-FrameZone
  File deleting (2)
    QDel387
    QDel386
  Flooder (3)
    FDoS-Cybwar
    FDoS-Chat
    FDoS-PacketStorm
  Generic (1)
    BackDoor-AUO.gen
  ICQ Messaging (1)
    ICQ-Vize
  Internet Relay Chat (3)
    IRC-Neds
    IRC/BackDoor.h
    IRC-Xen
  JavaScript (1)
    JS/StartPage.dr
  Malware Tool (6)
    Kit-Residuo
    Kit-MBC
    Kit-IPVCK
    Kit-GenVirus
    Kit-G2
    Kit-NJ-DLK1
  mIRC client (1)
    IRC/Flood.cd.mirc
  Password Stealer (2)
    PWS-Pudorate
    PWS-PassDumper
  Remote Access (9)
    BackDoor-ATM.gen
    Unix/BackDoor-Ping
    BackDoor-AUS
    BackDoor-AUR
    BackDoor-AUQ
    BackDoor-AUO
    BackDoor-AUN
    BackDoor-AUM
    Backdoor-Sub7.finder
  Script (1)
    VBS/DDoS-iFrameNet.c
  Source code (1)
    Unix/BackDoor-Ping.src
  Source code Worm (1)
    Linux/Adore.worm.src
  StartPage (1)
    StartPage-K
  VbScript (1)
    VBS/Vmort
  Win31 (2)
    Proscrol
    APStrojan.tt
  Win32 (9)
    IRC/Flood.cd
    SMSFlood-Atak
    Nuclearprank
    Mail-Zerop
    ICQPager-O
    ICQPager-N
    Fup
    AddShare-B
    AddShare-A
Virus (64)
   (1)
    Freza
  Application extension Worm (1)
    W32/Lastas.worm.dll
  Configuration settings (1)
    W32/Menthol.ini
  Dropper (2)
    W32/Nicolam.dr
    W95/Navrhar.12888.dr
  E-mail worm (4)
    W32/Naco.b@MM
    W32/Fakerr@MM
    W32/Duksten.o@MM
    W32/Naco.a@MM
  Email (19)
    W32/Zokrim.r@MM
    W32/Zokrim.q@MM
    W32/Zokrim.c@MM
    W32/Zokrim.b@MM
    W32/Zokrim.a@MM
    W32/Bibrog@MM
    W32/Pkasa.b@MM
    W32/Pkasa.a@MM
    W32/Naco.c@MM
    W32/Menthol@MM
    W32/Maax.e@MM
    W32/Maax.d@MM
    W32/Maax.c@MM
    W32/Fourseman.f@MM
    W32/Fourseman.e@MM
    W32/Fourseman.d@MM
    W32/Fourseman.c@MM
    W32/Fourseman.b@MM
    W32/Fourseman.a@MM
  Email Generic (2)
    W32/Zokrim.gen@MM
    W32/Wangy.gen@MM
  Email Generic Worm (1)
    W32/Zokrim.worm.gen@MM
  Generic (1)
    W32/Stepan.gen
  Internet Worm (3)
    W32/Holar.h@MM
    W32/HLLP.Vampore.worm
    W32/Vote.k@MM
  Macro (2)
    A97M/Barama
    W97M/Stenic
  Overwriting (1)
    W32/Soder.ow
  P2P Worm (1)
    W32/Tarit.worm
  Parasitic (2)
    W32/HLLP.Tamin
    W32/HLLP.Porner
  Script (5)
    VBS/Rettub.bat
    Bat/Hellotmp
    VBS/Ereal
    JS/Damar
    W32/Naco.bat
  VbScript (1)
    VBS/Rettub
  Win32 (5)
    W32/Stepan.d
    W32/Stepan.b
    W32/Mooder.b
    W32/Mooder.a
    W32/CoverMe
  Win9x (1)
    W95/CIH.1003i
  Worm (11)
    W32/Randon.worm.n
    W32/GenericP2P.worm
    W32/Vampore.worm
    W32/Titog.worm.i
    W32/Sddrop.worm.g
    W32/Nilit.l.worm
    W32/Mexer.worm
    W32/Lastas.worm
    W32/Fasong.worm
    W32/Busan.worm
    W32/Afx.worm

Enhanced Detections:

Program (7)
  Keylogger (1)
    Keylog-Blazing
  Win32 (6)
    Spoof-Smoke
    SRScanner
    PortWatch
    SQL-Browser
    SQL-Ping
    PortScan-Pest
Trojan (16)
   (1)
    CleanBK
  - (1)
    AddShare
  Adware (1)
    AdwareDropper-A
  Configurator (3)
    IRC-Contact.cfg
    MultiDropper-FN.cfg
    Downloader-AE.cfg
  Dropper (2)
    MultiDropper-DN
    MultiDropper-FW
  Exploit (1)
    Exploit-FbsdHack
  File deleting (2)
    QDel336
    QDel382
  Flooder (1)
    FDoS-Octopus
  Malware Tool (1)
    Nuke-WinTCPKill
  Remote Access (2)
    BackDoor-AMA
    BackDoor-Sub7.PwdCh
  Win32 (1)
    RATCracker
Virus (70)
   (19)
    Cocaine.664
    YD.1049
    YD.1049.e
    YD.1049.d
    YD.1049.b
    YD.1049.a
    ABAP/Rapid
    Zombie.2553
    Xany.162
    VP.333
    Voyager.315
    UVC.596
    UVC.589
    UVC.559
    UVC.552
    UVC.512
    Tron.514
    Tron.512b
    Tron.512a
  Damaged (3)
    W32/Fosforo.dam
    W95/CIH.dam
    Anti-Pascal.dam
  Dropper (1)
    W32/Lamebyte.dr
  E-mail (1)
    W32/Naver@MM
  Email (6)
    W32/MyPower.b@MM
    W32/MyPower.a@MM
    W32/Plex@MM
    W32/Gink@MM
    W32/Maax.b@MM
    W32/Maax.a@MM
  Generic (1)
    W32/Moridin.gen
  Internet Worm (3)
    W32/Supova.worm
    JS/Fortnight.b@M
    W32/Nymph.gen@MM
  Macro (1)
    W97M/Splash
  Parasitic (2)
    W32/HLLP.Gotem
    Senorita.apd
  Script (1)
    W32/Nilit.bat
  Win32 (20)
    W95/Rainsong.3891
    W32/Henky.Sanaz.1624
    W32/Fosforo.a
    W32/Henky.Sanaz.1652
    W32/Fosforo.b
    W32/Pate.c.tmp
    W32/Pate.a.tmp
    W32/Pate.b.tmp
    W32/MyPower.c
    W32/HLL.Flor
    W32/Fosforo.c
    W32/Lamebyte
    FakeN
    W32/Jethro
    W32/Lamin
    W32/Fosforo.d
    W32/TryMem
    W32/Ghotex
    W32/Tabeci
    W32/Stepan
  Win9x (10)
    W95/RainSong.3925.a
    W95/RainSong.4036
    W95/RainSong.4386
    W95/RainSong.3956.b
    W95/RainSong.3956.a
    W95/RainSong.3925.b
    W95/Ramdile
    W95/Bodgy
    W95/RainSong.4262.b
    W95/RainSong.4262.a
  Worm (2)
    W32/GenericIRC.worm
    W32/Howeem.worm