Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4307
DAT Release Date 12/03/2003
Threats Detected 83138
New Detections 214
Enhanced Detections 178

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Mimail.l@MM Low-Profiled Low-Profiled

New Detections:

Program (44)
   (2)
    Tool/fmt
    Cloner
  Adware (6)
    Adware-Look2Me
    Adware-Gator
    Adware-ToolbarCC
    Adware-POP
    Adware-StatBlaster
    Adware-Doumi
  Dialer (1)
    PornDial-187
  Generic (2)
    Dialer-RAS.cf.gen
    Dialer-RAS.cg.gen
  Internet Relay Chat (1)
    IRC-Bircd
  Keylogger (2)
    Keylog-Msto
    Keylog-ActiveKey
  Malware Tool (11)
    VTool/isr
    VTool/ebo
    VTool/dvl
    HTool/ssd
    HTool/csp
    HTool/IGMPNuke
    HTool/AOSFlooder
    VTool/jun
    VTool/duk14
    VTool/c2b
    HTool/sat
  Script (1)
    Tool/cnup
  StartPage (1)
    StartPage-AD
  Tool (14)
    Tool-Nmap
    Htool/kgn2
    Tool-MacTime
    Tool-Revert
    Tool-HLPDump
    Tool-Analyze
    Tool-Podonok
    Tool-PGP2TXT
    Tool-RSAKey
    Tool-Tracer
    Tool-PsybncScan
    Tool-PGPDump
    Tool-TXT2DEN
    Tool-Huff
  Win32 (3)
    Nmap
    Picture-Spanska
    Medload
Trojan (79)
   (6)
    Flopdie.b
    Vein
    Byte-Three
    THC-TBC
    Generic Dropper.b
    Deshack
  - (2)
    StartPage-AD.dr
    Bedrill
  Application extension (1)
    Keylog-Stawin.dll
  Configuration settings (1)
    Proxy-DistNet.ini
  Dialer (1)
    JS/Exploit-DialogExp
  Disk erasing (4)
    QZap349
    QZap347
    QZap350
    QZap348
  Downloader (2)
    Downloader-FN
    VBS/PWS-QQ.dldr
  Dropper (4)
    MultiDropper-IN
    PWS-Bancban.dr
    PWS-AceMast.dr
    Proxy-DistNet.dr
  Exploit (8)
    JS/Exploit-Findeath
    JS/Exploit-Linkiller
    Exploit-WsBaseUrl
    JS/Exploit-BodyRef
    JS/Exploit-SaveRef
    Exploit-ViaSWFurl
    JS/Exploit-BadParent
    JS/Exploit-AutoScan
  File deleting (1)
    B2E.QDel4
  Flooder (1)
    FDos-LionSec
  Internet Relay Chat (1)
    IRC-Ibot
  JavaScript (1)
    JS/AdClicker-AB
  Keylogger (1)
    Keylog-Yaha
  Malware Tool (2)
    THC.kit
    Kalips.kit
  Password (1)
    PWS-Sagic
  Password Stealer (3)
    PWS-Abaxo
    PWS-GoldBalance
    PWS-AceMast
  Proxy (1)
    Proxy-DistNet
  Remote Access (3)
    BackDoor-CAI
    BackDoor-CAJ
    BackDoor-CAH
  Script (27)
    VBS/Phreal
    Bat/blj
    VBS/Noex
    Bat/qz67
    Bat/qz64
    Bat/loop14
    Bat/hid
    Bat/dt66
    Bat/dt65
    Bat/cml
    JS/Teve
    Bat/qz66
    Bat/qz65
    Bat/qz63
    Bat/qd149
    Bat/qd148
    Bat/qd147
    Bat/qd146
    Bat/qd145
    Bat/qd144
    Bat/qd143
    Bat/msp
    Bat/msk
    Bat/hotmail
    Bat/fdae
    Bat/dt67
    Bat/coc
  Win32 (8)
    DoS-Tenthose
    Keylog-Laz
    Keylog-Stawin
    Uploader-K
    Spvr
    HackerDefender.sys
    HackDefender
    Generic Dropper.a
Virus (91)
   (7)
    Danish Tiny.233
    HLL.4096b
    Shadow.1684
    Guppy.152g
    Basrun.5113
    HLL.4432
    HLL.3920
  Application extension (5)
    W32/Stepan.dll
    W32/Wide.dll.d
    W32/Wide.dll.b
    W32/Wide.dll.c
    W32/Wide.dll.a
  Boot dropper (1)
    BtDr.Necrophilia
  Companion (1)
    W32/Gogo.cmp
  Damaged (4)
    W32/Gaobot.dam
    W95/Tolone.dam
    X97M/Extras.dam
    W95/Ilmx.dam
  Damaged Worm (1)
    W32/Spybot.worm.dam
  Dropper (9)
    W95/Drol.dr
    Point.dr
    VCL.408.dr
    KSV.1308.dr
    Kontragapi.dr
    Bat/qsc.dr
    W32/Projet.dr
    W32/Swen.dr
    VBS/Spy-Tofger.dr
  E-mail (3)
    W32/Mimail.m@MM
    W32/Memas@MM
    W32/Mimail.l@MM
  Email (4)
    W32/Sowsat.n@MM
    W32/Mimail.k@MM
    W32/BleBla.e@MM
    W32/Noala.d@MM
  Email Generic (3)
    W16/Redteam.gen@MM
    W32/Hunch.gen@MM
    W32/Sdbot.gen@MM
  Generic (1)
    W95/Henky.Henze.gen
  Internet Relay Chat (1)
    W32/Matrixmovie!irc
  Internet Worm (2)
    W32/Alphx.worm.gen
    W32/Lazi
  Macro (11)
    W97M/Twno.be
    W97M/Twno.d
    W97M/Twno.ar
    W97M/Twno.ak
    W97M/Twno.af
    W97M/Twno.a
    W97M/Unhas
    W97M/Twno.ae
    W97M/Twno.aj
    W97M/Twno.ac
    W97M/Hana
  Overwriting (1)
    HLL.ow.3968b
  Parasitic (1)
    HLLP.5000c
  Peer To Peer (1)
    W32/Zire!p2p
  Peer To Peer Worm (2)
    W32/Specx.worm.e!p2p
    W32/Reckus.worm.c!p2p
  Script (3)
    VBS/Zimac
    VBS/Postie
    Bat/qsc
  Unix (1)
    UNIX/Dakness
  Unpacked (1)
    HLLP.5000c.unp
  Win32 (12)
    W32/Parakid
    W32/Stepan.k
    W32/Wide.8238
    W32/Rikenar.d
    W32/Blandie!txt
    W32/Zire!bat
    W32/Wide.7910
    W32/Widare
    W32/Rikenar.c
    W32/Projet
    W32/Netop
    W32/Apler
  Win9x (1)
    W95/Beast.c
  Worm (15)
    W32/Spybot.worm.tr
    W32/Spybot.worm.tq
    W32/Spybot.worm.tm
    W32/Tzet.worm.e
    W32/Spybot.worm.ub
    W32/Spybot.worm.tp
    W32/Spybot.worm.sz
    HLLW.9360
    W32/Propaganda.worm
    W32/Niconor.worm
    W32/Kuksec.worm
    W32/Bolgimo.worm
    W32/Xbotor.worm
    W32/Cragard.worm
    W32/Amivid.worm

Enhanced Detections:

Internet Worm (1)
  P2P Worm (1)
    W32/Specx.worm
Program (14)
  Application extension (1)
    CyDoor.dll
  Malware Tool (13)
    VTool/cdw
    HTool/wrt11
    HTool/wrt10
    HTool/wrt9
    HTool/wrt8
    HTool/wrt7
    HTool/wrt6
    HTool/wrt5
    HTool/wrt4
    HTool/wrt3
    HTool/wrt2
    HTool/wrt1
    VTool/av19
Trojan (31)
   (11)
    THCK-TC.e
    THCK-TC.d
    THCK-TC.c
    THCK-TC
    THCK-TC.f
    QRabid
    Genesis
    Froggie
    Benediction
    Jan
    THCK
  Application extension (2)
    PWS-Wexd.dll
    PWS-Mirhunt.dll
  Demonstration (1)
    Kit-Revert.demo
  Dropper (5)
    MultiDropper-CE
    BackDoor-AJX.dr
    MultiDropper-CM
    PWS-HackSoft.dr
    PWS-Mir.dr
  Exploit (3)
    JS/Exploit-FileProxy
    JS/Exploit-Search
    Exploit-HTA.Behind
  File deleting (1)
    QDel360
  Malware Tool (2)
    Kit-Revert
    Flooder.kit
  Password Stealer (1)
    PWS-QQDrag
  Remote Access (1)
    BackDoor-UT
  Script (3)
    VBS/Appchild
    Bat/qd121
    Bat/dt64
  Trojan (1)
    Notech.dll
Virus (132)
   (7)
    Generated.Spirit.b
    Danish Tiny
    HLL.4096
    Logen
    Kontragapi.2290
    Milena.599
    Kontragapi.2274
  Boot (1)
    Chinque
  Companion (3)
    Offspring.cmp.1138
    Offspring.cmp.1135
    Offspring.cmp.1127
  Damaged (4)
    W97M/Minimal.dam
    VBS/Redlof.dam
    Univ/r.dam
    W16/WinVik.dam
  Dropper (6)
    W32/Wide.dr
    Pinhead.dr
    W32/Alisa.dr
    Nightmare.dr
    Vbasic.5120.dr
    W32/Sowsat.dr
  Dropper Script (2)
    Univ.bat/a.dr
    Univ.bat/a.drp
  E-mail worm (1)
    W32/Nicehello@MM
  Email (4)
    VBS/Redlof.a@M
    W32/Noala.a@MM
    W32/Noala.c@MM
    W32/Ameter@M
  Email Generic (1)
    JS/Fortnight.gen@M
  File Infector (2)
    W32/Hezhi.b
    POJER.4028
  Generic (3)
    W97M/Minimal.gen
    W95/Rekoj.gen
    W16/WinVik.gen
  Intended (3)
    W97M/Minimal.bh.intd
    VBS/Redlof.intd
    X97M/Papa.a.intd
  Internet Relay Chat (2)
    IRC-Fyle
    IRC/Mooze.b
  Internet Worm (2)
    W32/Noala.b@MM
    JS/Fortnight@M
  Macro (58)
    X97M/Papa.b@MM
    W97M/Minimal.bu
    W97M/Comical@MM
    W97M/Minimal.bs
    W97M/Minimal.at
    W97M/Minimal.ax
    W97M/Minimal.bj
    W97M/Minimal.v
    W97M/Minimal.bg
    W97M/Minimal.be
    W97M/Minimal.bc
    W97M/Minimal.ba
    W97M/Minimal.ay
    W97M/Minimal.an
    W97M/Minimal.am
    W97M/Minimal.ad
    W97M/Minimal.w
    W97M/Minimal.r
    W97M/Minimal.m
    W97M/Minimal.i
    W97M/Minimal.q
    W97M/Minimal
    W97M/Minimal.o
    W97M/Minimal.j
    W97M/Minimal.f
    W97M/Minimal.d
    W97M/Minimal.b
    W97M/Minimal.bv
    W97M/Minimal.bt
    W97M/Minimal.au
    W97M/Minimal.x
    W97M/Minimal.bf
    W97M/Minimal.bd
    W97M/Minimal.bb
    W97M/Minimal.az
    W97M/Minimal.ap
    W97M/Minimal.ao
    W97M/Minimal.al
    W97M/Minimal.ak
    W97M/Minimal.z
    W97M/Minimal.s
    W97M/Minimal.p
    W97M/Minimal.n
    W97M/Minimal.l
    W97M/Minimal.h
    W97M/Minimal.aa
    W97M/Minimal.u
    W97M/Minimal.t
    W97M/Minimal.k
    W97M/Minimal.g
    W97M/Minimal.e
    W97M/Minimal.c
    W97M/Minimal.a
    W97M/Minimal.bm
    W97M/Minimal.gv
    W97M/Minimal.ch
    W97M/Minimal.aw
    W97M/Minimal.he
  Overwriting (1)
    HLL.ow.3968
  Parasitic (1)
    HLLP.5000a
  Peer To Peer Worm (6)
    W32/Licia.worm!p2p
    W32/Specx.worm.b!p2p
    W32/Specx.worm.a!p2p
    W32/Specx.worm.c!p2p
    W32/Specx.worm.d!p2p
    W32/Speedup.worm.d!p2p
  Remote Access (1)
    BackDoor-AJX
  Script (3)
    VBS/Rock
    Perl/Rans
    VBS/Bacil
  Trojan (1)
    Futs
  Unpacked (1)
    HLLP.5000a.unp
  Win32 (17)
    New Win32.g6
    W32/Resur.a
    W32/Hezhi.a
    W32/Hezhi.c
    W32/Wide.8366
    W32/Wide.8135a
    W32/Wide.8135b
    W32/Wide.8225
    W32/Bluple
    W32/Zonit
    W32/MlFree
    W32/PetTick.ae
    W32/Resur.f
    W32/Resur.e
    W32/Resur.d
    W32/Resur.c
    W32/Resur.b
  Win9x (1)
    W95/Henky.Henze
  Worm (1)
    W32/Legend.worm