Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4295
DAT Release Date 09/24/2003
Threats Detected 80489
New Detections 174
Enhanced Detections 142

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Yaha.af@MM Low-Profiled Low-Profiled

New Detections:

Malware (9)
  Denial Of Svc (5)
    FDoS-Qweek
    FDoS-Byrunner
    FDoS-Keke
    Nuke-Kod.b
    FDoS-Ebomb
  Exploit (4)
    Exploit-Realser
    Linux/Exploit-Wuftp
    Exploit-Mrc
    Exploit-Wuloit
Program (17)
   (1)
    VObj24
  Adware (1)
    ClearSearch.dldr
  Application extension (1)
    Keylog-Syshsti.dll
  Generic (7)
    Dialer-RAS.bt.gen
    Dialer-RAS.br.gen
    Dialer-RAS.bu.gen
    Dialer-RAS.bs.gen
    Dialer-RAS.bq.gen
    Dialer-RAS.bp.gen
    Dialer-RAS.bo.gen
  Keylogger (1)
    Keylog-Syshsti
  Malware Tool (2)
    HTool/cra
    HTool/bru
  Win32 (4)
    SrvAny
    SkSockServer
    RemAdm-BCZero
    PassDump.b
Trojan (65)
   (10)
    UReboot.c
    Mojo
    Terminate2
    SMS-Bomb
    Makerdr
    LammerBuster2
    FTU
    Flood.SMS
    Filemaker.b
    CAU
  Client (1)
    BackDoor-AYZ.cli
  Configurator (1)
    BackDoor-AYZ.cfg
  Disk erasing (1)
    QZap337
  Downloader (1)
    Downloader-EF
  Dropper (3)
    MultiDropper-HL
    Exploit-M03-032.dr
    IRC/Flood.cg.dr
  Exploit (11)
    Exploit-LocalMail
    Exploit-DotNetScn
    Exploit-IISm
    Exploit-Wuloit.b
    Exploit-Wordperf
    Exploit-RpcTime
    Exploit-Realser.b
    Exploit-Php
    Exploit-Bbsxp.b
    Exploit-Bbsxp
    Exploit-Njob
  File deleting (6)
    QDel346
    QDel345
    QDel344
    QDel349
    QDel348
    QDel347
  Flooder (7)
    FDoS-Btnbomb
    FDoS-Aslike
    FDoS-FpPws32
    FDoS-SSPing
    FDoS-RpcMassive
    FDoS-Rmfms
    FDoS-Msncha
  Internet Relay Chat (2)
    IRC/Flood.df
    IRC/Flood.de
  Keylogger (2)
    Keylog-Tjm
    Keylog-IMSDN
  Malware Tool (2)
    JavaScript.kit
    Bat/polyhell.kit
  Password Stealer (1)
    PWS-Rysoft
  Remote Access (2)
    BackDoor-AZA
    BackDoor-AYY
  Script (10)
    HTML/Debeski
    VBS/Passer
    Bat/txp
    Bat/skl
    Bat/qd117
    Bat/omn
    Bat/eqz
    Bat/dt49
    Bat/chick
    IRC/Flood.vbs
  Server (1)
    BackDoor-AYZ.svr
  Win32 (4)
    AdClicker-V
    Uploader-I
    SMSFlood-Azrael
    Generic Del
Virus (83)
   (6)
    BootDr259
    BootDr258
    Keypress.1243
    Jeru.1812c
    Close.656
    BootDr260
  Application extension (3)
    W32/Pate.b.dll
    W32/Pate.c.dll
    W32/Pate.a.dll
  Client (1)
    W32/Colevo.cli
  Companion (4)
    W32/HLL.cmp.406528
    W32/Belod.cmp.8192.c
    W32/Parrot.cmp.b
    W32/Parrot.cmp.a
  Damaged (6)
    YD.dam
    Murphy.dam
    Tenbytes.dam
    SVC.dam
    Innox.dam
    Grazie.dam
  Dropper (6)
    Univ/q.dr
    Linux/Diesel.dr.970intd
    Involuntary.dd.dr
    Linux/Diesel.dr.962intd
    W32/Sowsat.i.dr
    W32/Sowsat.dr
  Dropper Script (1)
    Univ.bat/99.dr
  Dropper Worm (1)
    Univ.worm.dr
  E-mail (1)
    W32/Yaha.af@MM
  E-mail worm (2)
    W32/Lehs@MM
    W32/Vybab@MM
  Email (10)
    W32/Sowsat.i@MM
    W32/Dumaru.l@MM
    W32/Dumaru.m@MM
    W32/Yodo.d@MM
    W32/Torvil@MM
    W32/Poff@MM
    W32/Hermon@MM
    W32/Dumaru.n@MM
    W32/Colevo.a@MM
    W32/Askar@MM
  Email Generic (1)
    W32/Colevo.gen@MM
  Generic Worm (1)
    W32/Raleka.worm.gen
  Internet Worm (1)
    W32/Panoil.d@MM
  JavaScript (1)
    JS/Dogost.intd
  Linux (2)
    Linux/Spork.4096
    Linux/Alaeda
  Malware Tool (1)
    HLL.DeadByte.kit
  Overwriting (1)
    HLL.ow.2800
  Parasitic (4)
    W32/HLLP.Dahorse
    W32/HLLP.33789
    W32/HLLP.18431f
    W32/HLLP.18431e
  Peer To Peer (5)
    W32/Splint!p2p
    W32/Mettemar!p2p
    W32/HLLP.Savno!p2p
    W32/Dani!p2p
    W32/Harex!p2p
  Peer To Peer Worm (4)
    W32/Licia.worm!p2p
    W32/Irkaz.worm!p2p
    W32/Kevor.worm!p2p
    MSIL/Crdoet.worm!p2p
  Script (4)
    W32/Lehs.bat
    W32/Raleka.bat
    W32/Kevor.vbs
    W32/Parrot.bat
  VbScript (2)
    Kit-SMWG
    Bleeb.kit
  Win32 (3)
    W32/Wun.1696
    W32/Rufoll.a
    W32/Delfer
  Worm (12)
    W32/Stinbot.worm.b
    W32/Spybot.worm.ot
    W32/Tzet.worm.d
    W32/Gaobot.worm.ah
    W32/Gaobot.worm.ag
    W32/Gaobot.worm.af
    W32/Gaobot.worm.ae
    W32/Moklo.worm
    W32/Stinbot.worm.a
    W32/Osapex.d.worm
    W32/Fiancee.worm
    W32/Denit.worm

Enhanced Detections:

Malware (1)
  Denial Of Svc (1)
    FDoS-Drincl
Program (12)
   (5)
    VObj12
    VObj18
    VObj17
    VObj3
    VObj19
  Remote Access (6)
    BackDoor-ALA
    BackDoor-ANE
    BackDoor-ANN
    BackDoor-AJE
    BackDoor-RV.rmv
    BackDoor-AEV
  Win32 (1)
    Passdump
Trojan (41)
   (8)
    Sphinks
    Psysend
    Pokemon
    QHA
    Psychosis
    Primitive
    Filemaker
    Looper
  Application extension (1)
    BackDoor-AWW.dll
  Client (1)
    BackDoor-ASB.cli
  Configurator (1)
    BackDoor-ASB.cfg
  Disk erasing (2)
    QZap185
    QZap123.c
  Downloader (2)
    Downloader-ED
    Downloader-CC
  Dropper (2)
    BackDoor-BL.dr
    BackDoor-UK.dr
  File Deletion (1)
    Enimen
  Flooder (1)
    FDoS-HLife
  Generic (1)
    VBS/RunScript.gen1
  Internet Relay Chat (1)
    IRC/Flood.cs
  Malware Tool (4)
    AnsiBomb.kit
    Nuke-WinNuke2
    Nuke-Sqlnuke
    Nuke-Kod
  ProcKill (1)
    ProcKill-A
  Remote Access (4)
    BackDoor-AGS
    BackDoor-NY
    BackDoor-AVB
    BackDoor-YD
  Script (1)
    VBS/Iwill
  Server (1)
    BackDoor-ASB.svr
  Win32 (9)
    SMSFlood-Norinc
    SMSFlood-HellSMS
    SMSFlood-MBK
    SMSFlood-Simple
    SMSFlood-Samurai
    SMSFlood-Fusion
    SMSFlood-Mehm
    SMSFlood-Sharft
    SPrem
Virus (88)
   (61)
    Taurus.586
    Jeru.1845
    Jeru.1347a
    Jeru.1347b
    Jeru.2437
    Jeru.2128
    Jeru.2000
    Jeru.1888b
    Jeru.1888a
    Jeru.1846
    Jeru.1813
    Jeru.1808b
    Jeru.1808a
    Jeru.1807c
    Jeru.1807b
    Jeru.1807a
    Jeru.1692
    Jeru.1637
    Jeru.1605
    Jeru.1596
    Jeru.1568
    Jeru.1535
    Jeru.1524
    Jeru.1523c
    Jeru.1523b
    Jeru.1523a
    Jeru.1511
    Jeru.1508
    Jeru.1348b
    Jeru.1348a
    Jeru.1525a
    Jeru.1525b
    Jeru.1807d
    Jeru.1888c
    Jeru.1733b
    Jeru.1720
    Jeru.1733a
    Jeru.1888d
    Jeru.2081
    Jeru.1328
    Jeru.1735
    Jeru.1829
    Jeru.1808d
    Jeru.1705a
    Jeru.1636a
    Jeru.1705b
    Jeru.1636b
    Jeru.2080
    Jeru.1808k
    Jeru.1808j
    Jeru.1808i
    Jeru.1808g
    Jeru.1808e
    Jeru.1808h
    Jeru.1808f
    Jeru.1845b
    Jeru.1808c
    BootDr57
    Involuntary dd
    Jeru.1812a
    Jeru.1812b
  Boot (2)
    Denzuk 2
    Denzuk 1
  Damaged (2)
    Ambulance.793.dam
    Carnage.dam
  Dropper (5)
    Civil War.dr
    W32/Hatter.dr
    Kemerovo.dr
    W32/Sowsat.g.dr
    Linux/Diesel.dr.969
  E-mail worm (1)
    W32/Yaha.gen@MM
  Email (1)
    W32/Sowsat.h@MM
  Email Generic (1)
    W32/BackZat.gen@MM
  File Infector (1)
    Murphy
  Java Applet (1)
    JV/BeanHive
  Malware Tool (1)
    Bat/bvg.kit
  multipartite (1)
    Crazy Eddie.mp
  P2P Worm (1)
    VBS/Sludge.worm
  Script (2)
    W32/Crackly.vbs
    VBS/Bleeb
  Win32 (5)
    W32/Hatter
    W32/Rufoll
    W32/Wun.1699
    W32/Wun.1727
    W32/Anies.b
  Worm (3)
    W32/Osapex.a.worm
    W32/Osapex.b.worm
    W32/Osapex.c.worm