Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4289
DAT Release Date 08/27/2003
Threats Detected 79181
New Detections 225
Enhanced Detections 87

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
VBS/Flipe Low Low-Profiled

New Detections:

Internet Worm (2)
  - (1)
    W32/Raleka.worm
  E-mail worm (1)
    W32/Yodo.a@MM
Malware (1)
  Denial Of Svc (1)
    FDoS-CgiBomber
Program (15)
  Adware (2)
    Adware-Gohip
    Adware-CWS
  Generic (1)
    Dialer-RAS.bg.gen
  Keylogger (1)
    Keylog-SC.inst
  Malware Tool (8)
    VTool/arcv2
    HTool/pwcr
    HTool/pdec
    HTool/nha
    HTool/mut
    HTool/lol
    HTool/ewp
    HTool/abp
  Win32 (3)
    RalSvc
    TFTPD32
    HideStart
Trojan (88)
   (15)
    Vixenish
    UVid
    Nikademus
    Judy
    Gag
    Aries
    Apex
    Water
    Virri10.rn
    TTB
    Matrix
    Boo-Boo
    Singer
    DoS-Meteor
    Memeater
  Configuration settings (1)
    BAT/Gygabat.ini
  Denial Of Svc (1)
    Linux/DDoS-Ferlect
  Dialer (1)
    PornDial-181
  Downloader (6)
    Downloader-DV
    Downloader-DS
    Downloader-DT
    Dialer-RAS.d.ldr
    Rapix.dldr
    Downloader-DU
  Dropper (7)
    BackDoor-AYH.dr
    Keylog-Keylf.dr
    MultiDropper-HE
    MultiDropper-HD
    MultiDropper-HF
    PWS-Zombie.dr
    BackDoor-AJQ.dr
  Flooder (23)
    FDoS-Liammaps
    FDoS-Tyapo
    FDoS-Maiman
    FDoS-Psycho
    FDoS-Xbmail
    FDoS-Upjours
    FDoS-Steffan
    FDoS-Soddf
    FDoS-OobBelle
    FDoS-ICQAur
    FDoS-Hropac
    FDoS-Fatalex
    FDoS-Cloaok
    FDoS-Backer
    FDoS-Ashiyane
    FDoS-Winping
    FDoS-Typhono
    FDoS-Mailsender
    FDoS-Imafraid
    FDoS-Icgmp
    FDoS-Foxers
    FDoS-Dink
    FDoS-Floed
  Generic (1)
    PWS-QQ.gen
  Intended (1)
    MultiDropper-CE.intd
  Internet Relay Chat (4)
    IRC/Opice
    IRC/Flood.cz
    IRC-SpyAgent
    IRC/Rootbot
  Java Applet (2)
    JV/Poordoor
    JV/Incon
  Keylogger (1)
    Keylog-Sentinl
  Linux (1)
    SunOS/DDoS-Tfn
  Malware Tool (6)
    Spam-SmtpCli
    Nuke-Sqlnuke
    Nuke-Lockhoo
    Nuke-Ixnuke
    NTRootKit-E
    Kit-Swog
  Password (1)
    Keylog-Keylf
  Password Stealer (4)
    PWS-Mesgra
    PWS-Dimon
    PWS-Silent
    PWS-Dirwal
  Remote Access (3)
    BackDoor-AYH
    BackDoor-AYG
    BackDoor-AYI
  Script (3)
    BAT/Gygabat
    Singer.bat
    NTRootKit-E.reg
  VbScript (1)
    VBS/Flipe
  Win32 (6)
    Synkiller
    Uploader-F
    Rapix
    DDoS-Indel
    DDoS-Starpack
    DDoS-Desex
Virus (119)
   (11)
    Alabama.1560.f
    Youth.555.c
    Marky.478
    KOV.1913
    KOV.1913dr
    Helloween.1376m
    Eat-Spice
    Saboteur.1391
    Kakashka
    HeaderBug
    BootDr256
  Application extension (1)
    W32/Sowsat.dll
  Damaged (1)
    Eat-Spice.dam
  Dropper (18)
    W95/Fiasko.dr
    RTP.dr
    Ontario.dr
    Tadib.dr
    Eat-Spice.dr
    W32/Triplix.dr
    W32/Spelac.dr
    W32/Sowsat.g.dr
    W32/Seppuku.f.dr
    W95/Repus.191.dr
    W95/Repus.162.dr
    W95/Repus.232.dr
    Bat/mel.dr.1873
    W32/Toto.dr
    W32/Seppuku.a.dr
    W95/Repus.167.dr
    W95/Murkry.dr
    W95/Harry.dr
  E-mail worm (2)
    W32/Panoil.b@MM
    W32/Dumaru.c@MM
  Email (3)
    W32/Dumaru.b@MM
    W32/Dumaru.d@MM
    W32/Yodo@MM
  Email Generic (1)
    W32/Sobig.gen@MM
  File Deletion (1)
    w32/moe-test
  Generic (1)
    W97M/Lily.gen
  Generic Worm (2)
    VBS/Kergez.worm.gen
    W32/Kergez.worm.gen
  Macro (11)
    W97M/Wazzu.gu
    W97M/Wazzu.gw
    W97M/Wazzu.gx
    W97M/Quiet
    W97M/Minimal.aw
    W97M/Minimal.he
    W97M/Matem
    WM/Simple
    W97M/Wazzu.hg
    W97M/Wazzu.gy
    W97M/Wazzu.hi
  multipartite Worm (1)
    W32/Spybot.worm.mp
  Parasitic (6)
    Lehigh.cav
    HLLP.10240
    W95/Shown.cav.c
    W95/Noise.cav.417
    W95/Noise.cav.492
    W95/Noise.cav.400
  Peer To Peer Worm (1)
    W32/Kabak.worm!p2p
  Script (3)
    Bat/pef4
    W32/Habrack.vbs
    W32/Habrack.bat
  Unpacked (1)
    HLLP.xx.unp
  Win32 (21)
    W32/VCK.3037
    W32/NGVCK.a.4031
    W32/Dumaru
    W32/Triplix.c
    W32/Toto
    W32/Seppuku.f
    W32/NGVCK.a.1455
    W32/NGVCK.a.3427
    W32/Nachi.http
    W32/Zaprom
    W32/Triplix.d
    W32/Spelac
    W32/Sality.d
    W32/NGVCK.a.5216
    W32/NGVCK.a.1364
    W32/NGVCK.a.2522
    W32/NGVCK.1364dr
    W32/Kespy.b
    W32/Kespy.a
    W32/Cidu
    W32/Alcop.ay
  Win9x (7)
    W95/Fiasko.2496
    W95/Repus.191
    W95/Repus.162
    W95/Tolone
    W95/Repus.167
    W95/Repus.232
    W95/Fraz.992
  Worm (27)
    W32/Spybot.worm.mn
    W32/Spybot.worm.ne
    W32/Spybot.worm.ng
    W32/Spybot.worm.nb
    W32/Spybot.worm.mz
    W32/Spybot.worm.mx
    W32/Spybot.worm.mv
    W32/Spybot.worm.mt
    W32/Spybot.worm.mo
    W32/Spybot.worm.mi
    W32/Spybot.worm.nc
    W32/Spybot.worm.ms
    W32/Spybot.worm.mq
    W32/Spybot.worm.mm
    W32/Spybot.worm.ml
    W32/Spybot.worm.mk
    W32/Spybot.worm.nf
    W32/Spybot.worm.na
    W32/Spybot.worm.my
    W32/Spybot.worm.mw
    W32/Spybot.worm.mu
    W32/Spybot.worm.mj
    W32/Spybot.worm.mh
    W32/Spybot.worm.nd
    W32/Redro.worm
    W32/Baloon.worm
    W32/Kergez.worm

Enhanced Detections:

Program (3)
  Malware Tool (1)
    HTool/nord
  Remote Access (1)
    RemoXec
  Win32 (1)
    MSKILL
Trojan (12)
  - (1)
    Stealther
  Application extension (1)
    BackDoor-AOT.dll
  Dropper (1)
    Downloader-DQ.dr
  Internet Relay Chat (1)
    IRC/Flood.cv
  Malware Tool (2)
    Kit-Kagra
    Spam-EBomb
  Remote Access (2)
    BackDoor-AJQ
    BackDoor-AXB
  Win32 (4)
    Dir-5
    Dir-6
    Dir-3
    DoS-Smurf
Virus (72)
   (8)
    Weird
    MtE
    Comz
    Apl.480
    WPCB
    Joan.dd
    Eat-Spice.381
    Comz.1798
  Boot (1)
    XRCV.d
  Companion (1)
    Baby.cmp.b
  Configuration settings (1)
    JS/Rugkan.ini
  Damaged (2)
    W32/Sobig.dam
    Jerusalem.dam
  Dropper (9)
    Fog.dr
    W95/Darkside.dr
    CriCri.dr
    W32/Arikash.dr
    RTP.4838.dr
    WPCB.dr
    Bat/mel.dr.3516
    Bat/mel.dr.x
    Bat/mel.dr.1494
  Dropper Parasitic (2)
    W95/Shown.cav.dr
    W95/Noise.cav.dr
  Email (1)
    W32/Sheng@MM
  File Infector (2)
    Idle
    Anti-Pascal
  Generic (3)
    W97M/Wazzu.gr
    W95/Sledge.gen
    UNIX/Owr.gen
  Intended (1)
    VBS/Fasan.intd
  Internet Worm (1)
    W32/Pandem.worm
  Macro (27)
    W97M/Wazzu.fu
    W97M/Wazzu.bw
    W97M/Wazzu.bv
    W97M/Wazzu.ft
    W97M/Wazzu.gf
    W97M/Wazzu.gd
    W97M/Wazzu.gb
    W97M/Wazzu.hd
    W97M/Wazzu.hb
    W97M/Wazzu.bu
    W97M/Astia.ab
    W97M/Wazzu.he
    W97M/Wazzu.gi
    W97M/Wazzu.ge
    W97M/Wazzu.gc
    W97M/Wazzu.fy
    W97M/Wazzu.hc
    W97M/Wazzu.gs
    W97M/Wazzu.fs
    W97M/Wazzu.gt
    W97M/Wazzu.gp
    W97M/Wazzu.hh
    W97M/Wazzu.ax
    W97M/Wazzu.cb
    W97M/Wazzu.gv
    W97M/Wazzu.ch
    WM/Swlabs
  Malware Tool (1)
    PP97M/PMG.Kit
  multipartite (2)
    Aust.mp.1024a
    Marzia.Demian.mp
  Parasitic (5)
    Danish Tiny.apd
    W95/Noise.cav.414
    W95/Noise.cav.399
    W95/Shown.cav.b
    W95/Shown.cav.a
  Script (2)
    JS/Rugkan.bat
    JS/Rugkan
  Win32 (1)
    W32/Arikash
  Win9x (2)
    W95/Repus.256
    W95/Fraz.993