Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4296
DAT Release Date 10/01/2003
Threats Detected 80744
New Detections 137
Enhanced Detections 165

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Smibag.worm Low-Profiled Low-Profiled
QHosts-1 Low-Profiled Low-Profiled

New Detections:

Program (13)
   (2)
    VObj25
    VObj26
  Application extension (1)
    Keylog-Hothook.dll
  Malware Tool (7)
    VTool/uri
    VTool/tut
    VTool/mav
    VTool/macro
    VTool/ftp
    VTool/av17
    VTool/av16
  ProcKill (2)
    ProcKill-AN
    ProcKill-AO
  Spyware (1)
    Spyware-LoverSpy
Trojan (44)
   (3)
    Del-408
    Dirs-7
    Del-407
  - (2)
    StartPage-U
    QHosts-1
  Application extension (2)
    PWS-Jimal.dll
    PWS-Mirhunt.dll
  Configurator (1)
    PWS-IN.cfg
  Denial Of Svc (1)
    UNIX/FDoS-Aggin
  Disk erasing (1)
    QZap338
  Downloader (1)
    DownLoader-EG
  Dropper (6)
    MultiDropper-HM
    VBS/Vicety.dr
    QHosts-1.dr
    Downloader-EG.dr
    BackDoor-AOP.dr
    W32/Snac.dr
  Exploit (1)
    Exploit-Overnasm
  Internet Relay Chat (1)
    IRC/Flood.dg
  Java Applet (1)
    JV/Vigilante
  Keylogger (1)
    Keylog-LfzMph
  Malware Tool (2)
    Kit-SME
    PWCrack-Destrip
  Password (1)
    PWS-QQ.gen.b
  Password Stealer (6)
    VBS/PWS-Buddy
    PWS-Mirhunt
    PWS-Jimal
    PWS-IN
    PWS-Allight
    PWS-Gamer
  ProcKill (1)
    ProcKill-AM
  Remote Access (6)
    Backdoor-AZF
    UNIX/RootKit-L
    BackDoor-AZD
    BackDoor-AZE
    BackDoor-AZC
    BackDoor-AZB
  Script (5)
    JS/CardStealer.Scotia
    Bat/weird
    Bat/hogy
    Bat/antifa
    Bat/qd119
  Win32 (2)
    Jkid
    Vicety
Virus (80)
   (11)
    NcCrush
    VCG.7057
    Ontario.512.k
    Daubique.519
    Lucretia
    Terror.921b
    VICE.xx
    Lorz.340
    Justice.1249
    Justice.1242b
    Justice.1242a
  Application extension Worm (1)
    W32/Smibag.worm.dll
  Companion (2)
    W32/HLL.cmp.Nosyst
    W32/Egolet.cmp.c
  Configuration settings (1)
    Bat/kir.ini
  Damaged (10)
    W32/Swen.dam
    Univ/f.dam
    Taiwan.708.dam
    Keypress.dam
    Viros.429.dam
    Meihua.dam
    Avispa.dam
    Talon.dam
    Frost.dam
    W32/Levex.dam
  Dropper (7)
    NRLG.b.dr
    VCG.7057.dr
    W32/Seppuku.h.dr
    W32/Seppuku.g.dr
    Bat/mappy.dr
    W32/Seppuku.dr
    W32/Levex.dr
  Dropper Worm (1)
    W32/Smibag.worm.dr
  Email (5)
    W32/Pkasa.d@MM
    W32/Delanab.c@MM
    W32/Delanab.a@MM
    W32/Delanab.b@MM
    W32/Hopa@MM
  Internet Worm (2)
    W32/Smibag.worm
    W32/Zezer.worm.gen
  Macro (1)
    XF/Sic.gen
  Overwriting (1)
    W32/HLL.ow.Zush
  Peer To Peer Worm (2)
    W32/Specx.worm.b!p2p
    W32/Specx.worm.a!p2p
  Script (6)
    Bat/mappy
    W32/Blah.bat
    Bat/Antif
    Bat/inf
    Bat/bgo.1911
    VBS/Hopa
  Win32 (14)
    W32/Wratch.b
    W32/Wratch.a
    W32/Seppuku.i
    W32/Seppuku.h
    W32/Sality.e
    W32/NGVCK.a.926
    W32/NGVCK.2296dr
    W32/Levex
    W32/Badaya
    W32/Triplix.e
    W32/Seppuku.g
    W32/NGVCK.a.1352
    W32/NGVCK.a.2266
    W32/Cuydoc
  Win9x (1)
    W95/Dedo.a
  Worm (15)
    W32/Spybot.worm.oz
    W32/Opaserv.worm.ac
    W32/Opaserv.worm.ad
    W32/Spybot.worm.oy
    W32/Spybot.worm.ox
    W32/Unfair.worm
    W32/Randon.worm.r
    W32/Infober.worm
    W32/Deborm.worm.ah
    W32/Acinti.a.worm
    W32/Randon.worm.q
    W32/Imponex.worm
    W32/Blah.worm
    W32/Arequipa.worm.c
    W32/Grez.worm

Enhanced Detections:

Internet Worm (1)
  E-mail worm (1)
    W32/Sobig.b@MM
Program (10)
   (10)
    VObj4
    VObj22
    VObj21
    VObj20
    VObj16
    VObj15
    VObj13
    VObj2
    VObj23
    VObj24
Trojan (78)
   (1)
    BrowseEvt
  AOL Password (1)
    APStrojan.gen
  Application extension (1)
    BackDoor-AYC.dll
  Client (4)
    BackDoor-APJ.cli
    BackDoor-FR.cli
    BackDoor-FP.cli
    BackDoor-AC.cli
  Configurator (2)
    BackDoor-FP.cfg
    BackDoor-APJ.cfg
  Demonstration (2)
    W32/KME.demo
    Exploit-DcomRpc.2.demo
  Downloader (2)
    BackDoor-AAY.ldr
    BackDoor-Sub7.ldr
  Dropper (8)
    BackDoor-FK.dr
    BackDoor-AYC.dr
    BackDoor-IH.dr
    BackDoor-FA.dr
    BackDoor-J.dr
    BackDoor-UI.dr
    BackDoor-QZ.dr
    BackDoor-IM.dr
  Exploit (2)
    Exploit-DcomRpc.2
    Exploit-IIS.Crash
  Internet Relay Chat (5)
    IRC/Flood.bd
    IRC/Flood.an
    IRC/Flood.Winhelp
    IRC/Flood.cq
    IRC/Flood.dc
  Malware Tool (5)
    W32/Unis.kit
    W32/PGN.kit
    W32/Lamchi.kit
    Kit-ShellCode
    Nuke-TSKNuke
  Password Stealer (2)
    W32/Recerv.pws
    PWS-HE
  Remote Access (38)
    BackDoor-ADI
    BackDoor-API
    BackDoor-AMH
    BackDoor-FP.svr
    Backdoor-FK.svr
    BackDoor-RP
    BackDoor-WK
    BackDoor-N
    BackDoor-JA
    BackDoor-RF
    BackDoor-ADZ
    BackDoor-AMK
    BackDoor-AMM
    BackDoor-FK
    BackDoor-AOG
    BackDoor-CB
    BackDoor-AZ
    BackDoor-IH
    BackDoor-DZ
    BackDoor-APL
    JV/BackDoor-KBD
    BackDoor-AHI
    BackDoor-AFN
    BackDoor-AAR
    BackDoor-AAQ
    BackDoor-AAM
    BackDoor-YK
    BackDoor-VR
    BackDoor-US
    BackDoor-TF
    BackDoor-TA
    BackDoor-Sub7.icq
    BackDoor-AC.util
    BackDoor-AFU
    BackDoor-ADG
    BackDoor-ZR
    BackDoor-XS
    BackDoor-UL
  Script (1)
    BackDoor-Sub7.regen
  Server (3)
    BackDoor-DV.svr
    BackDoor-AC.svr
    BackDoor-FR.svr
  Win32 (1)
    ElfNotify
Virus (76)
   (4)
    Scitzo
    Tardy
    Sting.710
    Manuel
  Boot (6)
    Dodgy
    Unashamed
    Empire Monkey
    Ping-Pong
    Pop
    Hiwag
  Companion (2)
    W32/HLL.cmp.406528
    EIC-TF.cmp
  Damaged (1)
    Univ/a.dam
  Dropper (7)
    Zombie.dr
    Vacsina.dr
    W32/Seppuku.b.dr
    W95/Fono.dr
    W32/Lovelorn.dr
    W32/Seppuku.f.dr
    W32/Seppuku.a.dr
  E-mail (1)
    W32/Oror.ad@MM
  E-mail worm (2)
    W32/Sobig.c@MM
    W32/Sobig.a@MM
  Email (29)
    W32/Oror.f@MM
    W32/Oror.h@MM
    W32/Oror.i@MM
    W32/Oror.k@MM
    W32/Oror.j@MM
    W32/Oror.n@MM
    W32/Oror.m@MM
    W32/Oror.o@MM
    W32/Oror.z@MM
    W32/Oror.y@MM
    W32/Oror.x@MM
    W32/Oror.aj@MM
    W32/Oror.ah@MM
    W32/Oror.ae@MM
    W32/Oror.ac@MM
    W32/Oror.v@MM
    W32/Oror.q@MM
    W32/Oror.ai@MM
    W32/Oror.af@MM
    W32/Oror.aa@MM
    W32/Oror.w@MM
    W32/Oror.s@MM
    W32/Oror.p@MM
    W32/Oror.ao@MM
    W32/Oror.aq@MM
    W32/Pkasa.b@MM
    W32/Pkasa.a@MM
    W32/Oror.ar@MM
    W32/Pkasa.c@MM
  Email Generic (3)
    W32/Oror.gen@MM
    W32/Oror.gen.a@MM
    W32/Sobig.gen@MM
  Floppy Worm (1)
    W32/Acinti.worm
  Generic (1)
    W32/Gara.gen
  Intended (1)
    W32/Seppuku.intd
  Internet Worm (2)
    W32/Sobig.d@MM
    W32/Sobig.f@MM
  Peer To Peer Worm (1)
    W32/Silka.worm!p2p
  Script (4)
    W32/Updatr.vbs
    Bat/bgo
    Bat/kir
    VBS/Grez
  Win9x (1)
    W95/Dedo
  Worm (10)
    W32/Chainsaw.worm
    W32/Opaserv.worm.j
    W32/Opaserv.worm.g
    W32/Opaserv.worm.c
    W32/Opaserv.worm.b
    W32/Opaserv.worm.ab
    W32/Opaserv.worm.z
    W32/Opaserv.worm.y
    W32/Opaserv.worm.x
    W32/Arequipa.worm.b