Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4299
DAT Release Date 10/22/2003
Threats Detected 81664
New Detections 184
Enhanced Detections 200

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
PWS-Mafia Low-Profiled Low-Profiled
JS/Flea@M Low-Profiled Low-Profiled

New Detections:

Program (20)
   (2)
    Nulled-Out
    Quarantine Message
  Adware (6)
    Adware-KeenValue
    Adware-Adsincontext
    Adware-WinShow
    Adware-Lop
    Adware-SearchSquire
    Adware-Adshooter
  Downloader (1)
    Adware-WinShow.dldr
  Dropper (1)
    Adware-Lop.dr
  Generic (2)
    Dialer-RAS.ca.gen
    Dialer-RAS.cb.gen
  Joke (2)
    Illumin joke
    Apex joke
  Keylogger (1)
    KeyLog-SpyChild
  Proxy (1)
    Proxy-MPX
  Settings Change (1)
    Adware-XPlugin
  Spyware (1)
    Spyware-IamBigBro
  Tool (1)
    Tool-Virwiz
  Win32 (1)
    RpcDcom.c
Trojan (78)
   (7)
    Viral-God
    Porno2
    SergSoft
    PhactV
    ChickenECR
    Ariadna
    Sabin
  - (4)
    Del-409
    JV/Zaak
    MouseLog-Ladora
    JV/Goplanet
  Application extension (2)
    IRC-Sdbot.dll
    BackDoor-ACH.dll
  Configurator (1)
    MultiDropper-HP.cfg
  Damaged (1)
    Ariadna.dam
  Demonstration (3)
    Exploit-IFrame.demo
    Exploit-ListBox.demo
    Exploit-DcomRpc.b.demo
  Downloader (2)
    Downloader-ES
    Downloader-ER
  Downloader Generic (1)
    Proxy-Daemonize.dldr.gen
  Dropper (17)
    MultiDropper-HU
    MultiDropper-HV
    MultiDropper-HQ
    Serv-U.dr
    MultiDropper-HT
    MultiDropper-HW
    Unix/MakeUnsafe.dr
    MultiDropper-HX
    MultiDropper-HR
    Unix/BackDoor-Asp.dr
    MultiDropper-HS
    MultiDropper-HP
    MultiDropper-HO
    MultiDropper-GP.b
    BackDoor-BAU.dr
    BackDoor-BAO.dr
    IRC-Myst.dr
  Exploit (5)
    Exploit-HelpOverflow
    Exploit-RegThreat
    Exploit-Nt4All
    Exploit-Leoboard
    Exploit-DcomRpc.b
  Flooder (1)
    FDoS-GCS
  HTML (1)
    HTML/FakeLogon
  Internet Relay Chat (1)
    IRC-Myst
  Keylogger (1)
    Keylog-Jetos
  Macro (1)
    W97M/Sinix
  Malware Tool (3)
    Spam-Mbomb
    Nuke-NetNuker
    Spam-HMail
  Password (3)
    PWS-Bugmaf
    PWS-Mafia
    PWS-Bancban
  Password Stealer (5)
    PWS-Sina
    PWS-ProAgent
    PWS-IO
    PWS-Dafdaf.k
    PWS-Qover
  Process (1)
    ProcKill-AS
  Remote Access (8)
    Linux/BackDoor-Suki
    BackDoor-BAU
    BackDoor-BAS
    BackDoor-BAQ
    BackDoor-BAP
    BackDoor-BAO
    BackDoor-BAR
    BackDoor-BAN
  Script (2)
    Bat/gunit
    Vis.bat
  Server (1)
    BackDoor-ALI.svr
  StartPage (1)
    StartPage-V
  Win32 (6)
    Enocider
    ICQPager-P
    Restina
    Wikin
    Flystudio
    ExitWin-D
Virus (86)
   (18)
    Prude.405
    Phardera
    Gloomy
    Cascade.1560dr
    ARCV.Anna.757
    Zortech.834
    Sinful
    ShiftObj
    Seginus
    Ruwa.1031
    Renho
    Preteen.1118
    OC/retch
    Kerstin
    BootDr168
    Beethoven.750
    Alien.793
    A2KM/Tenoir
  Application extension (1)
    W32/Gnome.dll
  Damaged (1)
    Akuku.dam
  Dropper (6)
    AntiMIT.dr
    Filip.dr
    Bat/abm.dr
    W95/Thorin.dr
    W32/Chiton.dr
    MultiDropper-GP.a
  E-mail (1)
    W32/Holar.l@MM
  E-mail worm (1)
    JS/Flea@M
  Email (13)
    W32/Valha@MM
    W32/Napsin@MM
    W32/Julk@MM
    W32/Holar.n@MM
    W32/Gnome.b@MM
    W32/Anaph.12291@MM
    W32/Waber.c@MM
    W32/Waber.b@MM
    W32/Waber.a@MM
    W32/Nofear.u@MM
    W32/Holar.j@MM
    W32/Gnome.a@MM
    W32/Colbat@MM
  Internet Relay Chat (2)
    Thorin!irc
    IRC/Noflood
  Internet Worm (4)
    W32/Alphx.worm.a
    W32/Sexer.worm
    W32/Headout
    W32/Torvil.d@MM
  Joke (1)
    Thorin joke
  Linux (1)
    Linux/Ovets
  Macro (3)
    W97M/Bablas.EF
    P97M/Phlaco
    W97M/HeavyDut
  P2P Worm (1)
    W32/Reur.worm!p2p
  Peer To Peer (1)
    W32/Habaku!p2p
  Peer To Peer Worm (2)
    W32/Spear.worm.m!p2p
    W32/Anfiz.worm!p2p
  Script (3)
    W32/Habaku.bat
    VBS/Wodem
    W32/Aplch.bat
  Unix (1)
    Unix/SafeJ
  Win31 (4)
    W16/Kodzer
    W16/Klon.12800
    W16/Klon.13824
    W16/Klon.13056
  Win32 (7)
    W32/Randex.d
    W32/Foxis
    W32/Nachi!tftpd
    W32/Cist
    W32/Chiton.q
    W32/Chiton.o
    W32/Lykov.c
  Win9x (3)
    W95/Thorin.8921
    W95/Thorin.9554
    W95/Thorin.11788
  Worm (12)
    W32/Spybot.worm.qk
    W32/Spybot.worm.qb
    W32/Spybot.worm.pz
    W32/Spybot.worm.qf
    W32/Randon.worm.w
    W32/Randon.worm.x
    W32/Spybot.worm.qg
    W32/Spybot.worm.qe
    W32/Spybot.worm.qc
    W32/Spybot.worm.qh
    W32/Hartco.worm
    W32/Alphx.worm

Enhanced Detections:

Internet Worm (1)
  Internet Worm (1)
    Linux/Cheese.worm
Malware (1)
  Denial Of Svc (1)
    FDoS-Csium
Program (2)
  - (1)
    IGetNet.dr
  Application extension (1)
    W32/Inmota.dll
Trojan (107)
   (1)
    Nightmare
  Application extension (1)
    BackDoor-ALI.dll
  Configurator (1)
    MultiDropper-HN.cfg
  Demonstration (1)
    JS/Exploit-OVC.demo
  Dropper (4)
    Generic Dropper
    IRC/Flood.bu.dr
    BackDoor-ATP.dr
    MultiDropper-HN
  Exploit (1)
    JS/Exploit-OVC
  Flooder (57)
    FDoS-OpDos
    FDoS-Devilos
    FDoS-DKBoom
    FDoS-FReK
    FDoS-MSNFast
    FDoS-P2k
    FDoS-EvilPing
    FDoS-Deface
    FDoS-IRCSpam
    FDoS-Fury
    FDoS-KillZone
    FDoS-Metamorp
    FDoS-Blurred
    FDoS-Overload
    FDoS-ShockWav
    FDoS-DAP
    FDoS-STU
    FDoS-MK3
    FDoS-Blitz20
    FDoS-Wako10
    FDoS-Wako21
    FDoS-LANKill
    FDoS-ARPKill
    FDoS-Rebirth
    FDoS-OIcqDov
    FDoS-NetKill
    FDoS-PortTerm
    FDoS-AdvMSN
    FDoS-Faceless
    FDoS-MrUDP
    FDoS-Sharft
    FDoS-ICQkuf
    FDoS-ShelPing
    FDoS-RoomKill
    FDoS-Destiny
    FDoS-Mega
    FDoS-BlakBlud
    FDoS-MrType
    FDoS-ChiBoy
    FDoS-UnaBomb
    FDoS-BamaBoy
    FDoS-Xoox
    FDoS-DanDan
    FDoS-WarPing
    FDoS-Hasist
    FDoS-Kalibre
    FDoS-ToyBox
    FDoS-AddMngr
    FDoS-WinPopUp
    FDoS-UDPBomb
    FDoS-NetDem
    FDoS-DarkDB
    FDoS-Fofeet
    FDoS-Raptof
    FDoS-FPack
    FDoS-Silent
    FDoS-TNet
  Generic (1)
    FDoS-MSN.gen
  Internet Relay Chat (1)
    IRC/Flood.bu.hidewin
  Java Applet (1)
    JV/Vigilante
  Keylogger (1)
    KeyLog-IllLog
  Password (2)
    BackDoor-AQO
    PWS-DafDaf.a
  Password Stealer (11)
    PWS-Ges
    PWS-Dafdaf.i
    PWS-Dafdaf.h
    PWS-Dafdaf.g
    PWS-Dafdaf.f
    PWS-Dafdaf.e
    PWS-Dafdaf.d
    PWS-Dafdaf.c
    PWS-Dafdaf.b
    PWS-Ghost
    PWS-IL
  Plugin component (1)
    IRC/Flood.ak.plugin
  ProcKill (1)
    ProcKill-AQ
  Remote Access (13)
    BackDoor-BAM
    BackDoor-UK.gen
    BackDoor-ALI.sys
    BackDoor-APJ.srv
    BackDoor-ALI.sys.b
    BackDoor-ALI.sys.c
    BackDoor-ATP
    BackDoor-AWA.srv
    BackDoor-XU
    BackDoor-AWT.srv
    BackDoor-AFF
    BackDoor-AZI.srv
    BackDoor-BAL
  Script (3)
    Bat/abm
    Bat/ qd47
    Bat/ qd46
  Spyware (1)
    Spy-Hiddukel
  Win32 (5)
    OptixKiller
    ConCon
    NudeQ
    Gaslide
    Uploader-H
Virus (89)
   (21)
    ARCV.Anna.745b
    ARCV.Anna.745a
    ARCV.Anna.742
    ARCV.Anna.737
    ARCV.Anna.737dr
    ARCV.Anna.745c
    ARCV.Anna.740
    ARCV.Anna.734
    ARCV.Anna.740dr
    ARCV.Anna.734dr
    W31/Klon.1776
    ARCV.Anna.748
    Tess
    OC/spl
    Gluk
    BootDr165
    Alien.733.b
    Alien.733.a
    Andromeda.1536c.1536c
    Wood Goblin.dd.4506
    Vis
  Boot (1)
    Marburg/Segi
  Companion (1)
    W32/Azaco.cmp
  Configuration settings (1)
    VBS/Gaggle@MM.ini
  Damaged (5)
    W95/Babylonia@M.dam
    VCL.846.dam
    Xany.160.dam
    W32/Magistr.dam
    W97M/Bablas.dam
  Dropper (11)
    Univ.dr
    ARCV.Anna.745c.dr
    ARCV.Anna.745a.dr
    ARCV.Anna.742.dr
    ARCV.Anna.745b.dr
    Sailor-Venus.dr
    W32/Rebec@MM.dr
    ARCV.Anna.748.dr
    BW.dr
    Khizhnjak.dr
    W31/DrRave.dr
  Dropper multipartite (1)
    Implant.mp.dr
  Email (5)
    W32/Generic.b@MM
    W32/Nool@M.b
    W32/Nool@M.a
    W32/Torvil@MM
    MSIL/Freity@MM
  File Infector (3)
    Leprosy
    MacGyver
    W32/Magistr.b@MM
  Generic (1)
    W32/Pesin.gen
  Generic Worm (3)
    W32/Kelino.worm.gen
    W32/Warpi.worm.gen
    W32/Renol.worm.gen
  Intended (1)
    VBS/Lam@MM.intd
  Internet Worm (1)
    W32/Nachi.worm
  Macro (1)
    W97M/Stenic
  Malware Tool (1)
    OC/spl.kit
  multipartite (6)
    Ginger.mp.c
    Ginger.mp.a
    Ginger.mp.2774
    Ginger.mp.3075
    Ginger.mp.2782
    Ginger.mp.2691
  Overwriting (1)
    Univ.ow/b
  Parasitic (1)
    W31/DrRave.cav.145
  Peer To Peer Worm (12)
    W32/Spear.worm.j!p2p
    W32/Spear.worm.h!p2p
    W32/Spear.worm.d!p2p
    W32/Spear.worm.b!p2p
    W32/Spear.worm.k!p2p
    W32/Spear.worm.i!p2p
    W32/Spear.worm.g!p2p
    W32/Spear.worm.f!p2p
    W32/Spear.worm.e!p2p
    W32/Spear.worm.c!p2p
    W32/Spear.worm.a!p2p
    W32/Spear.worm.l!p2p
  Script (3)
    W32/Repah@MM.vbs
    W32/Gant@MM.bat
    Gonesoft.bat
  Win32 (4)
    W32/Chiton.b
    W32/Chiton.m
    W32/Randex.a
    W32/Randex.b
  Win9x (4)
    W95/Thorin.10705
    W95/Coke.22231
    W95/Thorin.11956
    W95/Thorin.11932
  Worm (1)
    W32/Magistr.a@MM