Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4302
DAT Release Date 11/05/2003
Threats Detected 82187
New Detections 219
Enhanced Detections 165

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (36)
   (1)
    Generator.GCAE2
  - (1)
    Proxy-OSS
  Adware (8)
    Adware-BetterInet
    Adware-CommonName
    Adware-Rfwnad
    Adware-Bic
    Adware-eUniverse
    Adware-MyWay
    Adware-UCSearch
    Adware-TradeExit
  Application extension (1)
    Generic Dialer.dll
  Dropper (1)
    Adware-XPlugin.dr
  Malware Tool (14)
    VTool/vdi
    VTool/unix
    VTool/sva2
    VTool/jsi
    VTool/bun
    VTool/av18
    HTool/bbs
    VTool/vct5
    VTool/tde
    VTool/sva
    VTool/slu
    VTool/java
    VTool/brain
    HTool/bdp
  Process (1)
    ProcKill-Term
  Script (1)
    Delshare.c
  Spyware (1)
    Spyware-DCToolbar
  Tool (2)
    Tool-SchedExec
    Tool-IPCScan
  Win32 (5)
    PassDump.c
    Morphine-Encrypted
    Delshare.b
    Delshare.a
    RSBG
Trojan (63)
   (4)
    LammerBuster3
    B2C.QD1
    Hang
    Ansibomb.creator
  Application extension (4)
    ProcKill-AT.dll
    BackDoor-BBN.dll
    BackDoor-BBL.dll
    BackDoor-BAZ.dll
  Configuration settings (1)
    IRC-Uhil.ini
  Configurator (1)
    Downloader-FD.cfg
  Downloader (7)
    Downloader-FH
    Downloader-FE
    Downloader-FD
    BackDoor-BBG.dldr
    Downloader-FG
    Downloader-FF
    Downloader-CY.b
  Dropper (5)
    BackDoor-BBD.dr
    IRC/Flood.dm.dr
    MultiDropper-IG
    MultiDropper-IF
    MultiDropper-ID
  Exploit (1)
    UNIX/Exploit-GeekLog
  Generic (1)
    PWS-NetMail.gen
  HTML (1)
    HTML/NatScam
  Internet Relay Chat (4)
    IRC/Flood.dm.iroffer
    IRC/Flood.da
    IRC/Flood.dm
    IRC/Flood.dl
  Keylogger (1)
    Keylog-SoftMu
  Password Stealer (3)
    PWS-Rapass
    PWS-IP
    PWS-QQPlus
  ProcKill (2)
    ProcKill-AU
    ProcKill-AT
  Remote Access (13)
    BackDoor-Kutex
    BackDoor-BBI
    BackDoor-BBA
    BackDoor-BBQ
    BackDoor-BBM
    BackDoor-BBL
    BackDoor-BBE
    BackDoor-BAZ
    BackDoor-BBN
    BackDoor-BBK
    BackDoor-BBH
    BackDoor-BBF
    BackDoor-BBD
  Script (4)
    Bat/foyn
    Bat/qz58
    JV/GoPlanet.reg
    IRC/Flood.bat.f
  Server (1)
    BackDoor-QQ.svr
  StartPage (3)
    StartPage-X
    StartPage-Z
    StartPage-Y
  Win31 (1)
    Moulard
  Win32 (6)
    Del-412
    Del-411
    HDKiller.b
    DDoS-AcidX
    Zayan
    Del-410
Virus (120)
   (37)
    UniTula
    Ontario.512.l
    Hymn.1962.e
    Vbasic.5120.t
    OC/bls
    Milena.599
    Maradona
    Werewolf.1500
    Trident.560
    Ontario.512.m
    Mte.Encroacher
    Grog.Crackers
    Wasp.1614a
    Tudor
    Slug.1152
    Kwlud
    Helloween.1842
    Ender
    Crazy-Imp.1402a
    Clau
    Bass.c
    Bass.a
    Emmie
    Cascade.George
    Weird.1200
    Wasp.1552
    Tush.932
    Tron
    Jumpy
    Green Dragon.878
    Deadman.576
    Cramp
    Bass.b
    BootDr269
    BootDr267
    BootDr268
    BootDr266
  Boot (4)
    LeapYear
    Cripes
    Floopy
    Chinque
  Companion (2)
    Offspring.cmp
    HLL.cmp.4320
  Damaged (1)
    W32/Grand.dam
  Dropper (16)
    PHX.dr
    YD.dr
    Murphy.David.dr
    Mike.dr
    Civil War.901.dr
    Carioca.951.dr
    Andromeda.dr
    Malaga.dr
    Linux/Rike.dr
    ARCV.Reaper.dr
    VCS.989.dr
    Berserker.dr
    Blinky.dr
    W95/Bagif.dr
    W32/Sankey.c.dr
    MultiDropper-IE
  Dropper multipartite (1)
    Plagiarist.mp.dr
  Email (6)
    W32/Mimail.h@MM
    W32/Mimail.g@MM
    W32/Mimail.f@MM
    W32/Mimail.d@MM
    W32/Mimail.b@MM
    W32/Lerok@MM
  Email Generic (1)
    W32/MyPower.gen@MM
  Generic (2)
    W32/Sankey.gen
    W95/Bytesv.gen
  Generic Worm (1)
    W32/Sexer.worm.gen
  Internet Relay Chat (2)
    W32/Fubot!irc
    IRC/Muzik.f
  Linux (1)
    Linux/Rike
  P2P Worm (1)
    W32/Bereb.worm!p2p
  Parasitic (1)
    W32/HLLP.Savno
  Peer To Peer (2)
    W32/Repad!p2p
    W32/Grand!p2p
  Script (5)
    VBS/Oldspot
    VBS/Massac
    VBS/Eskal
    JS/Sinop
    W32/Remabl.bat
  Win32 (7)
    W32/Generic.b
    W32/Lme.c
    W32/Yasv.924a
    W32/Triplix.f
    W32/Sankey.c
    W32/Remabl
    W32/Hortiga.c
  Win9x (3)
    W95/Bagif
    W95/Tecata.b
    W95/Tecata.a
  Worm (27)
    W32/Spybot.worm.qz
    W32/Spybot.worm.qw
    W32/Spybot.worm.qv
    W32/Spybot.worm.rl
    W32/Spybot.worm.rj
    W32/Spybot.worm.rg
    W32/Spybot.worm.re
    W32/Gaobot.worm.bf
    W32/Israz.worm.b
    W32/Israz.worm.a
    W32/Remabl.worm
    W32/Spybot.worm.rn
    W32/Spybot.worm.rm
    W32/Spybot.worm.rc
    W32/Spybot.worm.qx
    W32/Spybot.worm.rk
    W32/Spybot.worm.rf
    W32/Spybot.worm.rd
    W32/Spybot.worm.rb
    W32/Spybot.worm.ra
    W32/Spybot.worm.qy
    W32/Spybot.worm.ri
    W32/Nogard.worm
    W95/NB.worm.c
    W32/Marjor.worm
    W32/Bebars.worm.b
    W32/Bebars.worm.a

Enhanced Detections:

Internet Worm (1)
  Win32 (1)
    W32/Benjamin.worm
Program (3)
   (1)
    Quarantine Message
  Malware Tool (2)
    VTool/tbs2
    VTool/unk
Trojan (21)
  - (1)
    JS/Brent
  Client (1)
    MacOS/BackDoor-Sub7.cli
  Configurator (1)
    MacOS/BackDoor-Sub7.cfg
  Downloader (1)
    Downloader-FC
  Exploit (1)
    Linux/Exploit-SSL
  File deleting (1)
    QDel351
  Generic (1)
    Downloader-DN.gen
  Password (1)
    Generic PWS
  Password Stealer (1)
    PWS-DOB
  Remote Access (8)
    BackDoor-ATM.gen
    BackDoor-APN
    BackDoor-Sub7.cgi
    BackDoor-AUM
    BackDoor-BQ
    BackDoor-AVU
    BackDoor-AYK
    BackDoor-BBG
  Script (1)
    VBS/Sigrey
  Server (2)
    BackDoor-NM.svr
    MacOS/BackDoor-Sub7.svr
  StartPage (1)
    StartPage-A
Virus (140)
   (46)
    Markiz.1972
    Andryushka.3568
    Supervisor
    Hymn.1962.d
    Hymn.1962.c
    Whale.9216
    Novsev.1006
    Murphy.Goblin dr
    Novsev.1007
    Werewolf.1427
    Crazy Imp.1445b
    Crazy Punk.500
    Crazy Imp.1445a
    Crazy Imp.1402a
    Crazy Imp.1402b
    Mr.Div.1100
    Mr.Ra.1039
    Mr.Ra.1000a
    Mr.Ravl.962
    Mr.Dof.1000
    Mr.Ra.1000b
    Mr.Ravl.983
    Berserker
    Carioca.951
    Markiz.1560
    CNTV.2630
    V2PX.y
    Loren.1387
    A2KM/Retro
    Renho
    MPS-OPC
    DSME.Connie.2800
    Zombie/b
    Werewolf.1450b
    MPC.1022
    Vbasic.5120.i
    BootDr3
    RA.1574
    Werewolf.1450a
    Werewolf.1450c
    MPC.665
    Vbasic.5120.e
    TV.730
    Supervisor.2906
    Face.2521
    BootDr1
  Application extension (1)
    W32/Nofear.dll
  Companion (2)
    W32/HLL.cmp.169472
    Lockjaw.cmp
  Configuration file (1)
    Inf/Ultras
  Damaged (2)
    Mr.Dof.dam
    Mr.Ravl.dam
  Damaged Worm (1)
    W32/Randex.worm.c.dam
  Demonstration (1)
    HPE.Demo
  Dropper (18)
    Univ/h.dr
    Vienna.dr
    SMEG.dr
    Auspar.dr
    W32/Silcer.dr
    Nostar.dr
    Trurl.dr
    Casino.2330.dr
    NoFrills.dr
    W95/Ylang.dr
    Nov17.dr
    Univ/q.dr
    DSME.Connie.2800.dr
    MDA.dr
    Proto.dr
    Hypervisor.dr
    Zhengxi.dr
    IRC/Muzik.dr
  Dropper Intended (1)
    W32/NGVCK.d.dr.intd
  Dropper multipartite (1)
    Playgame.mp.dr
  Dropper Overwriting (1)
    Univ.ow/d.dr
  E-mail worm (2)
    W32/Naco.b@MM
    W32/Naco.a@MM
  Email (4)
    W32/Toal@MM
    W32/Naco.c@MM
    W32/Naco.e@MM
    W32/Naco.f@MM
  Email Generic (2)
    W32/Bibrog.gen@MM
    W32/Naco.gen@MM
  Email Generic Worm (1)
    W32/Zokrim.worm.gen@MM
  File Infector (5)
    Linux/Brunfly
    Keypress
    Pinworm
    Vor
    TV
  Generic (6)
    W95/Ylang.1536.gen
    W32/Bolzano.gen.b
    W32/Graps.gen
    W32/Silcer.gen
    MPC.GR3
    Wasp.GR
  Generic Peer To Peer Worm (1)
    W32/Gemel.worm.gen!p2p
  Generic Worm (1)
    W32/STD.worm.gen
  Internet Worm (3)
    W32/Naco.d@MM
    W32/Graps.worm
    W32/InvalidSSL@MM
  Linux (3)
    Linux/Gildo
    Linux/Spork.4096
    Linux/Alaeda
  Macro (1)
    W97M/Minimal.bq
  Malware Tool (2)
    Pofu.Kit
    VCS.kit.German
  multipartite (2)
    Plagiarist.mp.2051
    Plagiarist.mp.2014
  Peer To Peer (1)
    W32/HLLP.Savno!p2p
  Peer To Peer Worm (2)
    W32/Gammes.worm!p2p
    W32/Duload.worm.c!p2p
  Script (2)
    VBS/Yova
    Yoyo.bat
  VbScript (1)
    VBS/Soraci
  Win32 (14)
    W32/Crypto
    W32/Whitebait.gen@MM
    W32/Lme.7018
    W32/Lme.2883
    W32/Yasv.924
    W32/NGVCK.d.3072
    W32/NGVCK.d.3587
    W32/NGVCK.d.3582
    W32/Neoval
    W32/NGVCK.7342
    W32/Silcer.b
    W32/Silcer.c
    W32/Lykov.c
    W32/Flying.b
  Win9x (6)
    W95/Ylang.1536dr
    W95/Ylang.1024
    W95/Mad.2736b
    W95/Mad.2667
    W95/Mad.2806
    W95/Mad.2736a
  Worm (6)
    W32/Bored.worm.a
    W32/Bored.worm.b
    W32/Sysdil.worm
    W32/Randex.worm.c
    W32/Fibot.worm
    W32/Blah.worm