Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4281
DAT Release Date 07/30/2003
Threats Detected 77468
New Detections 181
Enhanced Detections 205

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (27)
   (3)
    VObj3
    Generated.XXX
    Generator.GCAE
  Adware (3)
    Adware-WMS
    Adware-Wink
    Adware-SpyBlast
  Application extension (1)
    MP3Search.dll
  Demonstration (1)
    Demo-AVHoles
  Generic (2)
    Dialer-RAS.ay.gen
    Dialer-RAS.az.gen
  Joke (1)
    Buttons.b joke
  Malware Tool (13)
    HTool/RNK
    VTool/xp1
    VTool/who
    VTool/wer
    VTool/tpe4
    VTool/ste
    VTool/mbg
    VTool/hex
    VTool/fxi
    VTool/av15
    VTool/av14
    VTool/av13
    HTool/ind
  Tool (1)
    Tool-MSNBomb
  Win32 (2)
    Portscan-Auha
    MegaMailer
Trojan (80)
   (7)
    Screen
    Glare
    Battra
    Stroppy
    PMS
    EraseC
    B2E/cct
  Application extension (1)
    Keylog-Fearless.dll
  Downloader (2)
    Downloader-CY
    Downloader-DJ
  Dropper (6)
    PWS-Bancos.dr
    BackDoor-AJW.dr
    IRC/Flood.cs.dr
    MultiDropper-GU
    FDoS-UDPFlood.dr
    BackDoor-TW.dr
  Exploit (11)
    Exploit-DcomRpc
    Exploit-ObjectBuffer
    Exploit-WKey4
    Exploit-RpcTiXi
    Exploit-AutoAttack
    Exploit-IIS.Fpreg
    UNIX/Exploit-Elm
    Exploit-ThcSql
    Exploit-JNuke
    Exploit-IIS.Hmd
    Exploit-AixFtpd
  Flooder (13)
    FDoS-RSeries
    FDoS-Anonmail.10
    FDoS-SpecEd
    FDoS-VSimple
    FDoS-MSpalmer
    FDoS-LSky
    FDoS-FMB
    FDoS-SMSBomb
    FDoS-MBomb
    FDoS-IBomber
    FDoS-DrBlast
    FDoS-AIMSlipassa
    FDoS-Ath0
  Generic (3)
    Keylog-Fearless.gen
    PWS-QQcv.gen
    FDoS-Flooder.gen
  Internet Relay Chat (2)
    IRC/SpyBuild
    IRC/Flood.cs
  Keylogger (1)
    Keylog-Fin
  Malware Tool (6)
    Nuke-VB
    Spam-Mobi
    Spam-AliS
    Nuke-Duke
    Nuke-Xobo
    NTRootKit-A.sys
  Malware Tool Script (1)
    VBS/Rahc.kit.vbs
  Password Stealer (8)
    PWS-Executant
    PWS-Tamla
    PWS-Furi
    PWS-Easyget
    PWS-ABounce
    PWS-XPPass
    PWS-Sucity
    PWS-Kamuflao
  Remote Access (6)
    Backdoor-AXR
    IRC-BBot
    BackDoor-AXP
    BackDoor-AXS
    BackDoor-AXU
    BackDoor-AXO
  Script (3)
    JS/Seeker.ad
    Bat/dt43
    Bat/ren3
  Source code (1)
    Exploit-CIOS.src
  Unix (1)
    Unix/Sillysh
  Win32 (8)
    Generic Delphi
    PassKill
    Westell
    Dir-5
    Myxq
    AddUser
    Tagrecall
    Monst
Virus (74)
   (35)
    DM.400c
    Jerusalem.ee
    Jerusalem.ed
    Jeru.2081
    Jerusalem.eg
    Jerusalem.eb
    Jerusalem.ec
    Jerusalem.eh
    Jeru.1735
    Jerusalem.et
    Jerusalem.er
    Jerusalem.ep
    Jerusalem.en
    Jerusalem.el
    Jerusalem.ej
    MPC.Skel.747
    Jerusalem.eu
    Jerusalem.es
    Jerusalem.eq
    Jerusalem.eo
    Jerusalem.em
    Jerusalem.ek
    Jerusalem.ei
    Jerusalem.ef
    Jerusalem.ea
    Jeru.xx
    DLG.367
    BootDr253
    Viking.1000
    Slovakia.3106
    OC/gro5
    Milen.400
    Coprite
    BootDr254
    Arg.1532
  Companion (1)
    Bat/cyb.cmp
  Configuration settings (1)
    JS/Rugkan.ini
  Damaged (1)
    W32/Alcop.dam
  Damaged Parasitic (1)
    W32/Elkern.cav.c.dam
  Dropper (4)
    DM.445.dr
    DM.400.dr
    Kampana.dr
    W95/Blakan.dr
  Email Generic (2)
    W32/Cherich.gen@MM
    W32/Ardurk.gen@MM
  Generic (1)
    W32/Faker.gen
  Generic Worm (2)
    W32/Sdbot.worm.gen.a
    W32/Sdbot.worm.gen
  Internet Worm (1)
    W32/Pandem.worm
  Peer To Peer Worm (1)
    W32/Spear.worm.l!p2p
  Script (10)
    Bat/Trash
    VBS/Jome
    Bat/swi.380
    Bat/bmb
    JS/Rugkan.bat
    JS/Rugkan
    Bat/Muzhu
    VBS/Ioana
    Bat/swi.378
    VBS/Arikash.b
  Win32 (5)
    W32/Stepan.j
    W32/Stepan.i
    W32/Maya.4207
    W32/Greatsat
    W32/Arikash.b
  Worm (9)
    W32/Spybot.worm.kn
    W32/Spybot.worm.kl
    W32/Spybot.worm.km
    W32/Spybot.worm.ko
    W32/Titog.worm.j
    W32/Sany.worm
    W32/Randon.worm.o
    W32/Alcop.ax.worm
    W32/Nilit.o.worm

Enhanced Detections:

Internet Worm (2)
  P2P Worm (1)
    W32/Gool.worm
  Win32 (1)
    W32/Storm.worm
Program (51)
   (18)
    Generated.GCAE2
    Generated.MtE
    Generated.RSE
    Generated.D-Phantom
    Generator.Enth
    Generated.VLAD
    Generated.Trash1
    Generator.Trash1
    Generator.SMM
    Generated.SMEG
    Generated.NED
    Generated.GPE
    Generator.DPE
    Generated.DMU
    Generator.MOF
    Generated.XX
    ZAPass
    Yalta.vxd
  - (2)
    VText-AntiTBAV
    ZeroPopup
  Adware (1)
    WNAD
  Exploit (7)
    Exploit-CipT
    Exploit-WinAttk
    Exploit-DarkSpot
    Exploit-Domina
    Exploit-NetScan
    Exploit-IpcScan
    Exploit-Unicode
  Generic (1)
    Dialer-TAPI.a.gen
  Malware Tool (4)
    VTool/sta
    VTool/atr
    VTool/duk9
    VTool/draw
  Password (1)
    Winspy
  Source code (2)
    Generated.SRCG
    Generator.SRCG
  Tool (4)
    Tool-Zombie
    Tool-VBSCrypt
    Tool-InnSteel
    Tool-AngelsRevenge
  Vulnerability (1)
    ZoneClick
  Win32 (10)
    WinZapper
    Generator.KME
    Generated.KME
    Virtual-FTP
    Wyrvis
    UsrPatch
    Yalta
    Viewer-Orifice2K
    Tool/tro
    W32/Nosys
Trojan (54)
   (2)
    GayPorn
    ABAP/Cadabra
  Application extension (2)
    BackDoor-AQF.dll
    PWS-Jiang.dll
  Configurator (1)
    Downloader-CL.cfg
  Denial Of Svc (1)
    IRC/Flood.bv
  Disk erasing (1)
    QZap251
  Downloader (3)
    PWS-Pksob.ldr
    Downloader-CL
    Downloader-CP
  Exploit (2)
    Exploit-GetAdmin
    Exploit-IIS.Hack
  File deleting (3)
    QDel167
    QDel397
    QDel393
  Flooder (2)
    FDoS-Auflood
    FDoS-FakePing
  Generic (8)
    BackDoor-AMO.gen
    BackDoor-ALO.gen
    PWS-Mewey.gen
    PWS-Crazy.gen
    PWS-MSNFake.gen
    BackDoor-AGL.gen
    BackDoor-RB.gen
    PWS-Yipper.gen
  Internet Relay Chat (2)
    IRC/Flood.ao
    IRC/Flood.bx
  Malware Tool (4)
    VBS/Rahc.Kit
    Dreg.Kit
    Spam-FZ
    Spam-ZBomber
  Password Stealer (5)
    PWS-Pksob
    PWS-AIMScreen
    PWS-Fastlit
    PWS-Hiddu
    PWS-QQHack
  Remote Access (3)
    BackDoor-AHS
    BackDoor-AFJ
    BackDoor-VE
  Script (7)
    Virri5.bat
    Bat/hel
    W97M/Opey.bg.bat
    VBS/Stoping
    Bat/dady
    Bat/od
    Bat/nz
  Trojan (1)
    QDel391
  Win32 (7)
    SocksProxy
    Smile
    Spy-Hidukel
    LockDown
    Rixi
    Del-403
    HLS.15
Virus (98)
   (8)
    Lame.2030
    HLL.9504
    DM.400.a
    DM.330
    DM.400.b
    OC/gro4
    Arg.2956
    Metro.665
  - (1)
    W32/Zexam.dam
  Boot (3)
    Flame
    Chaos
    Kilroy
  Client Worm (1)
    W32/Gool.worm.cli
  Configurator Worm (1)
    W32/Gool.worm.cfg
  Dropper (7)
    Ultimate.dr
    W32/Sabia.dr
    Bat/ly.dr
    Mumbler.dr
    Munich.2355.dr
    W32/PetTick.dr
    Kampana.dr.3784
  Dropper Worm (1)
    W32/Gool.worm.dr
  E-mail worm (1)
    W32/APost@MM
  Email (3)
    W32/Sysclock@MM
    W32/Urbe@MM
    VBS/Rimko@MM
  Email Generic (2)
    W32/Lohack.gen@MM
    W32/Mypics.gen@MM
  File Infector (3)
    DM.310
    Arab.834
    W95/Heathen.b
  Generic (2)
    W95/Fabi.gen
    IRC/Delarm.gen
  Generic Peer To Peer Worm (1)
    W32/Sytro.worm.gen!p2p
  Generic Worm (2)
    W32/Tefuss.worm.gen
    W32/Gool.worm.gen
  HTML document (1)
    W32/BleBla.htm
  Intended (1)
    W32/Faker.intd
  Internet Relay Chat (3)
    IRC/Etty
    IRC/Delarm
    IRC/Taxif
  Internet Worm (3)
    W32/Israz.worm
    W32/Hybris.gen@MM
    W32/Crackly@MM
  mIRC Worm (1)
    W32/Hokilo.worm
  Multi-Partite (1)
    W32/Demig
  multipartite (4)
    Kara.mp
    Natas.mp.4826
    Natas.mp.4788
    Kazakhstan.mp.2352
  Overwriting (1)
    W32/HLL.ow.9728
  Script (7)
    Bat/ad
    Bat/gro
    Bat/SBVM
    VBS/Hides
    Bat/ce
    Mumbler.bat
    Bat/ag
  Unix (1)
    UNIX/Sshworm
  Win32 (19)
    W32/VXL
    W32/Maya.4114
    W32/Maya.4254dr
    W32/Maya.4161dr
    W32/Sandra
    W32/Maya.4108
    W32/Netol
    W32/Faker.g
    W32/Faker.f
    W32/Faker.e
    W32/Faker.d
    W32/Faker.b
    Pyros.2384
    W32/Maya.4608
    W32/Lykov
    W32/Maya.4153
    W32/Maya.4106b
    W32/Maya.4113
    W32/Maya.4106a
  Win9x (8)
    W95/Suk
    W95/Blakan
    W95/CIH.remnants
    W95/Bonk
    W95/Fabi.15978
    W95/Fabi.512
    W95/Fabi.15930a
    W95/Fabi.15930b
  Worm (12)
    W32/Kitro@MM
    W32/Yobe.worm
    IRC/Fruit.worm.b
    W32/Bumdoc.worm
    W32/Kamar.worm
    IRC/Flib.worm
    W32/Bebars.worm
    W32/MonCher.worm.a
    IRC/Fruit.worm.c
    IRC/Fruit.worm.a
    W32/MonCher.worm.b
    W32/Nople.worm