Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4272
DAT Release Date 06/18/2003
Threats Detected 74780
New Detections 230
Enhanced Detections 112

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Internet Worm (1)
  Open Share Worm (1)
    W32/Sluter.worm
Program (24)
   (1)
    Generated.XX
  Dropper (1)
    Generic Dialer.dr
  Malware Tool (16)
    HTool/ahk
    VTool/mgl
    VTool/kry2
    VTool/e2p
    HTool/syp
    HTool/sms
    HTool/sbc
    HTool/qfz
    HTool/pup
    HTool/pfx
    HTool/mmn
    HTool/icq
    HTool/bki
    HTool/nts
    HTool/lnx
    HTool/der
  Script (2)
    Tool/zz4
    Tool/zz3
  Tool (2)
    Attacker
    Tool-HGet
  Win32 (2)
    Passrec
    FXScanner
Trojan (80)
   (12)
    UBuster
    Skinhead
    Nonstop
    Hamara.b
    FixOOB.b
    FixIt.a
    Ansibomb.c
    Skism
    Nona.6432
    Fixit.b
    Bomba.b
    Slamkey
  - (1)
    Adware-SSF.dr
  Application extension (3)
    Keylog-Kjie.dll
    PWS-IM.dll
    BackDoor-AVN.dll
  Client (1)
    Trojan Sockets.cli
  Configurator (1)
    BackDoor-AVQ.cfg
  Disk erasing (3)
    QZap326
    QZap324
    QZap325
  Downloader (1)
    Downloader-BW.e
  Dropper (8)
    MultiDropper-GK
    MultiDropper-GJ
    MultiDropper-GI
    Burper.dr
    IRC/Flood.cj.dr
    IRC/Flood.ci.dr
    MultiDropper-GH
    PWS-Kedad.dr
  Flooder (1)
    FDoS-FPack
  Generic (5)
    MultiDropper-DN.gen
    BackDoor-AKZ.gen
    PWS-Yipper.gen
    BackDoor-AVR.gen
    BackDoor-AVN.gen
  Internet Relay Chat (3)
    IRC/Flood.cj
    IRC/Flood.ci.hidewin
    IRC/Flood.ci
  Malware Tool (1)
    W97M/WOTD.kit
  mIRC client (1)
    IRC/Flood.ci.mirc
  Password (1)
    PWS-Winter
  Password Stealer (1)
    PWS-Kedad
  Remote Access (6)
    BackDoor-AVR
    BackDoor-AVO
    BackDoor-AVM
    BackDoor-AVL
    BackDoor-AVQ
    BackDoor-AVN
  Script (25)
    Bat/mkd5
    Nonstop.bat
    VBS/Sapik
    VBS/Nevec.b
    JS/Disboard
    Bat/tub
    Bat/qz40
    Bat/qz38
    Bat/qz36
    Bat/qd85
    Bat/pun
    VBS/Nevec.a
    Bat/wbl
    Bat/rge
    Bat/qz39
    Bat/qz37
    Bat/qz34
    Bat/qd84
    Bat/oki
    Bat/kbd2
    Bat/ccd
    W32/Zokrim.bat
    W32/Sorin.bat
    W32/Fankr.bat
    XM/Trasher.bat
  Win32 (6)
    Keylog-Kjie
    Aileen
    Voldemort
    VB.Cracko
    Digicard
    Burper
Virus (125)
   (10)
    Timish.2132
    Teraz.4004
    Cathinone.1818
    Winter
    SMirror.482
    Cowa.2408c
    HLLT.5968b
    Teraz.2717
    Sverdlov.512
    Cowa.2408d
  Application extension (1)
    W32/Nofear.dll
  Damaged (2)
    MPC.940.dam
    Haifa.dam
  Dropper (7)
    Tenbytes.dr
    Group.dr
    Bat/Mumu.dr
    Dir-II.Dragon.dr
    Cathinone.1818.dr
    Tentatrickle.10496.dr
    W32/Lamzan.dr
  Dropper Generic multipartite (1)
    Tchechen.mp.gen.dr
  Dropper Worm (2)
    W32/Spybot.worm.dr
    W32/Restud.dr.worm
  E-mail (1)
    W32/Danvee@MM
  E-mail worm (1)
    W32/Fourseman.g@MM
  Email (11)
    W32/Miriam@MM
    W32/BackZat.j@MM
    W32/BackZat.h@MM
    W32/Apbot@MM!DDoS
    W32/BackZat.i@MM
    W32/Oror.ar@MM
    W32/Holar.i@MM
    W32/Yaha.u@MM
    W32/Nofear@MM
    W32/Naco.f@MM
    W32/Delanab@MM
  Email Generic (1)
    W32/Oror.gen@MM
  Generic Worm (1)
    W32/Sunelo.worm.gen
  Intended (1)
    W32/Lamzan.intd
  Internet Worm (1)
    W32/Nofear.a@MM
  Macro (3)
    WM/Swlabs
    XM/Trasher
    A97M/Lovely
  Parasitic (4)
    Univ/r.apd
    HLLP.6416c
    HLLP.6416b
    W32/HLLP.Kroter
  Script (4)
    VBS/Traxsev
    Bat/Paspec
    Bat/ipw
    W32/Miriam.vbs
  Win32 (4)
    W32/NGVCK.7342
    W32/Miriam.lnk
    W32/Tenrobot.c
    W32/Bildan
  Worm (70)
    W32/Spybot.worm.ec
    W32/Spybot.worm.ea
    W32/Spybot.worm.dy
    W32/Spybot.worm.dx
    W32/Spybot.worm.du
    W32/Spybot.worm.dt
    W32/Spybot.worm.dq
    W32/Spybot.worm.gh
    W32/Spybot.worm.gf
    W32/Spybot.worm.fp
    W32/Spybot.worm.fn
    W32/Spybot.worm.fl
    W32/Spybot.worm.fj
    W32/Spybot.worm.fh
    W32/Spybot.worm.ex
    W32/Spybot.worm.dz
    W32/Spybot.worm.dv
    W32/Spybot.worm.ei
    W32/Sorin.worm
    W32/Spybot.worm.gb
    W32/Spybot.worm.ez
    W32/Spybot.worm.ey
    W32/Spybot.worm.ew
    W32/Spybot.worm.ev
    W32/Spybot.worm.es
    W32/Spybot.worm.er
    W32/Spybot.worm.eq
    W32/Spybot.worm.ep
    W32/Spybot.worm.eo
    W32/Spybot.worm.en
    W32/Spybot.worm.em
    W32/Spybot.worm.el
    W32/Spybot.worm.ek
    W32/Spybot.worm.ej
    W32/Spybot.worm.eh
    W32/Spybot.worm.eg
    W32/Spybot.worm.ef
    W32/Spybot.worm.ee
    W32/Spybot.worm.ge
    W32/Spybot.worm.gd
    W32/Spybot.worm.gc
    W32/Spybot.worm.ga
    W32/Spybot.worm.fz
    W32/Spybot.worm.fy
    W32/Spybot.worm.fw
    W32/Spybot.worm.fv
    W32/Spybot.worm.fu
    W32/Spybot.worm.ft
    W32/Spybot.worm.fs
    W32/Spybot.worm.fr
    W32/Spybot.worm.fq
    W32/Spybot.worm.fo
    W32/Spybot.worm.fm
    W32/Spybot.worm.fk
    W32/Spybot.worm.fi
    W32/Spybot.worm.fg
    W32/Spybot.worm.et
    W32/Spybot.worm.ed
    W32/Spybot.worm.dw
    W32/Spybot.worm.ds
    W32/Fankr.worm
    W32/Videmi.worm
    W32/Ronoper.worm.i
    W32/Randex.worm.a
    W32/Well.worm
    W32/Restud.a.worm
    W32/Randex.worm.b
    W32/Potomac.worm
    W32/Bildan.worm
    W32/Girls.worm

Enhanced Detections:

Internet Worm (1)
  Worm (1)
    W32/Auric@MM
Malware (1)
  Win32 (1)
    IRC-Vup
Program (40)
   (1)
    Spy-RedSpider
  - (1)
    Starr
  Adware (1)
    Adware-SSF
  Application extension (2)
    GhostKeyLog.dll
    ScreenCapture.dll
  Downloader (1)
    PornDial-155.ldr
  Flooder (1)
    FDoS-DelPing
  Malware Tool (5)
    VTool/fak
    Vtool/zzz2
    VTool/zzz1
    VTool/efl
    HTool/ipcsa
  Plugin component (1)
    Firehole.plugin
  Remote Access (1)
    HanumanDaemon
  Spam (1)
    Spam-LanxQQ
  Tool (4)
    SuperSpy
    Tool-Arpkill
    Tool-AnsiCheck
    Tool-AntiMacgyver
  Win31 (1)
    HideApp
  Win32 (20)
    Fldwatch
    Gsmfree
    Silent Watch
    ShowPassword
    RMRemove
    GhostKeyLog
    IdentDaemon
    Hhproxy
    Sub7-Logger
    ShareSniffer
    RemoteXS
    RemoteSaucer
    RemoteGUI
    Htthost
    GameDoor
    FTPback
    Firehole
    FakeWin
    ShellSpawn
    RMInfo
Trojan (17)
   (6)
    Bomba
    Hamara
    FixOOB
    Flopdie
    FixIt
    KillCMOS.i
  Dropper (1)
    IRC-Vup.dr
  Internet Relay Chat (1)
    IRC-ScnBot
  Password Stealer (1)
    PWS-Benfgame
  Remote Access (3)
    BackDoor-AKT
    BackDoor-AUP
    BackDoor-AMB
  Script (3)
    Bat/n
    Bat/kbd
    JS/Seeker.p
  Win32 (2)
    Mail-Zerop
    Reboot-d
Virus (53)
   (11)
    HLLT.5968
    Tenbytes dr
    Cowa.2408b
    Cowa.2408a
    Cowa.2389b
    Cowa.2389a
    Cowa.2322c
    Cowa.2322b
    Cowa.2322a
    Cowa.2298
    Cowa.2193
  Configuration settings (1)
    W32/Menthol.ini
  Damaged Overwriting (1)
    HLL.ow.ExeKilla.dam
  Dropper (2)
    Burglar.dr
    Sodo.dr
  Dropper Worm (1)
    W32/Kamil.worm.b.dr
  E-mail worm (3)
    W32/Oror.e@MM
    W32/Oror.b@MM
    W32/Oror.a@MM
  Email (11)
    W32/Oror.d@MM
    W32/Oror.c@MM
    W32/Oror.g@MM
    W95/SouthPark@MM
    W32/Oror.t@MM
    W32/Oror.ak@MM
    W32/Oror.r@MM
    W32/Oror.am@MM
    W32/Oror.an@MM
    W32/Oror.ap@MM
    W32/Oror.al@MM
  Email Generic (2)
    W32/Oror.gen.c@MM
    W32/Oror.gen.b@MM
  File Infector (1)
    Sad
  Generic Worm (2)
    W32/Taripox.worm.gen
    W32/Cult.worm.gen
  Macro (1)
    W97M/Moebius
  Multi-Partite (1)
    Tchechen.mp
  Overwriting (2)
    W32/Yopper.ow
    HLL.ow.ExeKilla
  Parasitic (2)
    HLLP.6416
    HLLP.4879
  Script (3)
    W32/Netspree.bat
    VBS/Lenti
    Bat/bc
  VbScript (1)
    VBS/Rettub
  Worm (8)
    W32/Posam.worm
    W32/Kamil.worm.b
    W32/Goalweb.worm.a
    W32/Druagz.worm
    W32/Beong.worm
    W32/Fasong.worm
    W32/Afx.worm
    W32/Goalweb.worm.b