Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4300
DAT Release Date 10/29/2003
Threats Detected 81923
New Detections 163
Enhanced Detections 82

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Sober.a@MM Low-Profiled Low-Profiled

New Detections:

Internet Worm (1)
  P2P Worm (1)
    W32/Franriv.worm
Program (15)
  Adware (3)
    Adware-Verticity
    Adware-BB
    Adware-eUniverse
  Configurator (1)
    SmallHTTP.cfg
  Demonstration (1)
    Demo-MS03-043
  Dialer (2)
    PornDial-183
    PornDial-182
  Dropper (1)
    PornDial-182.dr
  Joke (1)
    Brickwin joke
  Malware Tool (2)
    VTool/lobo
    HTool/vgen
  Process (1)
    DispTime
  Win32 (3)
    Patch-EZ
    SckRedir
    SmallHTTP
Trojan (54)
   (3)
    Encry
    B2C.Nazi
    Minotaur
  - (2)
    Proxy-Hino
    IRC/Flood.dk
  Configurator (2)
    Downloader-EZ.cfg
    BackDoor-BAV.cfg
  Downloader (9)
    Downloader-EW
    Downloader-EU
    Downloader-EV
    Downloader-EX
    Downloader-FB
    Downloader-ET
    Downloader-FC
    Downloader-EZ
    Downloader-EY
  Dropper (8)
    MultiDropper-IB
    MultiDropper-HZ
    MultiDropper-IC
    MultiDropper-IA
    MultiDropper-HY
    Zap-329.dr
    PWS-Mob.dr
    SunOS/BackDoor-RK.dr
  E-mail (1)
    Proxy-Regate
  Exploit (1)
    Exploit-MS03-043
  File deleting (1)
    B2E.QDel3
  Flooder (1)
    FDoS-MassMsg
  Generic (3)
    PWS-LegMir.gen.b
    PWS-LegMir.gen
    Downloader-DN.gen
  Keylogger (1)
    KeyLog-Jingt
  Malware Tool (1)
    Spam-Kalsit
  Password (1)
    PWS-Mob
  PornDialer (2)
    QDial15
    QDial16
  Proxy (2)
    Proxy-Hino.b
    Proxy-Hino.c
  Remote Access (6)
    BackDoor-BAV
    BackDoor-BBB
    BackDoor-BBG
    BackDoor-BAX
    BackDoor-BAY
    BackDoor-BAW
  Script (6)
    VBS/Mommka
    JS/Kowov
    Bat/Boogy
    Bat/scar
    Bat/rka
    IRC/Flood.bat.e
  Trojan (1)
    StartPage-W
  Win32 (3)
    AdClicker-X
    Strica
    Sprocit
Virus (93)
   (39)
    VCL.316
    IVP.644
    Flex.493
    SunDevil.690
    SafeHex.118
    Ridge
    Nobody.670
    Gruesome.229
    Gipsy.362
    Clown.257
    BootDr265
    BootDr263
    Blinker.512
    Bear.1433
    Baron-Rojo.589
    AntiCARO
    Alien
    Zoom.1243
    Poodle.1414
    MPS-OPC
    Macedonia.1024
    DSME.Connie.2800
    Droge
    Tiddler.176
    SMM
    Rolf.1376
    Pontevedra.1822
    Ploppo.600
    Nitrate.875
    Klingon.786
    Grouch
    Gipsy.304
    Dragalina
    DK.739
    Buttmunch
    BootDr264
    Bass
    BackStabber
    Andytwo
  Boot (1)
    Eastern
  Companion (2)
    HLL.cmp.27904
    W32/Zerogav.cmp
  Damaged Worm (1)
    W32/Randex.worm.c.dam
  Dropper (7)
    Ridge.dr
    MTES.dr
    MPC.715.dr
    DSME.Connie.2800.dr
    Traip.dr
    SMM.dr
    MDA.dr
  Dropper Worm (1)
    W32/Sdbot.worm.dr
  E-mail (1)
    W32/Marque.worm
  Email (8)
    W32/Sowsat.g@MM
    W32/Dumaru.r@MM
    W32/Sober@MM
    W32/Duksten.p@MM
    W32/Tici@MM
    W32/Scrambler.m@MM
    W32/Scrambler.l@MM
    W32/Noala.a@MM
  Email Generic (1)
    W32/Holar.gen@MM
  HTML document (2)
    W32/Vote.htm
    W32/Lirva.htm
  Intended (1)
    W32/Lifort.intd
  Internet Worm (3)
    W32/Petch.worm!irc
    W32/Noala.b@MM
    W32/Sober.a@MM
  Macro (1)
    W97M/Shore.r
  Malware Tool (1)
    GV1.kit
  Overwriting (1)
    Sinusitis.ow.482
  Peer To Peer (1)
    W32/Mantas!p2p
  Peer To Peer Worm (2)
    W32/Cocker.worm!p2p
    W32/Dism.worm!p2p
  Script (4)
    VBS/Domiz
    Bat/Mumu
    Zap-329
    VBS/Daol
  Win32 (6)
    W32/Infeme
    W32/Sober.eml
    W32/Sakao
    W32/Numrok
    W32/Emeres
    W32/Caes
  Worm (10)
    W32/Holar.r@MM
    W32/Spybot.worm.qu
    W32/Spybot.worm.qs
    W32/Spybot.worm.qr
    W32/Randon.worm.y
    W32/Randon.worm.z
    W32/Spybot.worm.qt
    W32/Orida.worm
    W32/Bebars.worm.c
    W32/Daol.worm

Enhanced Detections:

Malware (1)
  Exploit (1)
    Exploit-ODREV
Program (2)
   (2)
    with fishy extension
    Nulled-Out
Trojan (21)
   (2)
    Radish
    Porno
  - (1)
    Del-409
  Application extension (1)
    Downloader-EP.dll
  Configurator (1)
    MultiDropper-EU.cfg
  Denial Of Svc (1)
    IRC/FDoS-ShowDown
  Downloader (5)
    JS/Cisp
    Downloader-EF
    Proxy-Daemonize.ldr
    Downloader-EP
    Proxy-Daemonize.dldr
  Dropper (2)
    MultiDropper-EU
    Proxy-Daemonize.dr
  Internet Relay Chat (1)
    IRC/SpyBuild
  Malware Tool (1)
    VBS/Wshvc.Kit
  Process (1)
    ProcKill-AS
  Remote Access (2)
    Linux/Backdoor-Excedoor
    BackDoor-AYV
  Script (3)
    IRC/Flood.ba.bat
    JS/Dista
    VBS/Exposed
Virus (58)
   (22)
    GhostDog
    BootDr160
    Sticks
    Relax
    Werewolf
    Ripe
    VCL.Kinnison
    Kerstin
    Wishes
    BW.Gateway.372
    Wolfman.2064
    OC/ag
    Ness
    BootDr21
    Baron-Rojo.573.tro
    Abomb
    Zorm/h
    DSME.Connie.2708
    MTES.Megadeath
    Menem.1179
    Baron-Rojo.576
    Baron-Rojo.573
  Boot (2)
    Tornado
    Uniform
  Com file (1)
    MTES.Coma
  Damaged (2)
    Baron-Rojo.576.dam
    MTES.dam
  Dropper (8)
    Mutagen.dr
    W95/KME.dr
    Minicorp.dr
    VCL.Kinnison.dr
    Ballbreaker.dr
    Nigro.dr
    Lucky.dr
    Hemlock.dr.3183
  Dropper Overwriting (1)
    Univ.ow/b.dr
  Dropper Worm (1)
    W32/Smibag.worm.dr
  Email (2)
    W32/Dumaru.h@MM
    W32/Dumaru.n@MM
  File Infector (3)
    Naughty Hacker
    Panic
    Shake
  Generic (2)
    IRC/Clickit.gen
    VBS/Happy.gen
  Linux (1)
    Linux/Glaurung
  Macintosh (1)
    MacOS/SevenDust
  Macro (1)
    W97M/VMPCK1
  Overwriting (1)
    HLL.ow
  Parasitic (2)
    W95/Zofo.cav.848
    W95/Zofo.cav.850
  Script (1)
    W32/Vote.vbs
  Universal (1)
    Univ/t
  Win32 (3)
    W32/Sankey
    W32/Nachi!tftpd
    W32/Rexli
  Worm (3)
    W32/Fiancee.worm
    W32/Dhaka.worm
    Linux/Lion.worm.a