Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4309
DAT Release Date 12/17/2003
Threats Detected 83647
New Detections 168
Enhanced Detections 66

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (18)
  Adware (4)
    Adware-WinEssential
    Adware-Fuel
    Adware-Adroar
    Adware-BreatheLife
  Downloader (1)
    Dialer-RAS.ce.dldr
  Dropper (2)
    Adware-TopMoxie.dr
    Adware-NetPals.dr
  Generic (3)
    Dialer-RAS.cl.gen
    Dialer-RAS.cj.gen
    Dialer-RAS.ck.gen
  Joke (2)
    CDNutz joke
    BadPrank joke
  Malware Tool (2)
    HTool/MS03-049
    HTool/DCYY
  Script (2)
    Spyware-LoverSpy.bat
    Delshare.e
  Tool (1)
    Clearlogs
  Win32 (1)
    Delshare.f
Trojan (74)
  - (1)
    QHosts-2
  Application extension (2)
    BackDoor-CAR.dll
    Exploit-DcomRpc.dll
  Application extension Generi (1)
    PWS-Sincom.dll.gen
  Downloader (5)
    Downloader-FW
    Downloader-FV
    Downloader-FT
    GenDrop.Dldr-BO
    JS/Downloader-FU
  Dropper (3)
    IRC/Flood.dt.dr
    MultiDropper-IS
    IRC/Flood.ds.dr
  Dropper Script (1)
    Serv-U.dr.bat
  Exploit (10)
    Exploit-EFCommander
    Exploit-Dameware
    Perl/Exploit-Dcom
    Exploit-Messer
    Exploit-Mediar
    Exploit-Ciskill
    Exploit-AccControl
    UNIX/Exploit-WebEye
    Perl/Exploit-Imapdog
    Exploit-IISWDav.b
  Flooder (3)
    FDoS-Atho.g
    FDOS-UNF
    FDoS-SMSCoco
  Generic (4)
    GenDrop.gen
    Downloader-FN.gen
    Exploit-IISWDav.gen
    JS/AdClicker-AB.gen
  Internet Relay Chat (6)
    IRC/Flood.dw
    IRC/Flood.dv
    IRC/Flood.dt
    IRC/Flood.dt.hidewin
    IRC/Flood.ds
    IRC/Flood.du
  Joke (1)
    MemJoke
  Malware Tool (2)
    Linux/RootKit-M
    PWS-QQPass.b.kit
  Password Stealer (5)
    PWS-QQPass.b
    PWS-RSW
    PWS-JingPass
    PWS-AimSyn
    PWS-Nabla
  ProcKill (4)
    ProcKill-BF
    ProcKill-BE
    ProcKill-BD
    ProcKill-BC
  Proxy (1)
    Proxy-MCP
  Remote Access (7)
    BackDoor-CAP
    BackDoor-CAX
    BackDoor-CAU
    BackDoor-CAS
    BackDoor-CAQ
    BackDoor-CAV
    BackDoor-CAT
  Script (1)
    GenDrop.Mimail
  Settings Change (1)
    Startpage-AI
  StartPage (1)
    StartPage-AH
  Win32 (15)
    Funboy
    ExitWin-G
    AccLock
    AdClicker-AC
    RunStud
    DiskFill-K
    Slayvax
    Saster
    Rannoc
    Hackubomb
    Zap-330
    Del-420
    Del-419
    ExitWin-F
    Timese
Virus (76)
  Companion (2)
    W32/Peana.cmp.a
    W32/Peana.cmp.b
  Dropper (3)
    W95/Markj.b.dr
    W95/Markj.a.dr
    IRC/Trash.dr
  E-mail (1)
    W32/Scold@MM
  Email (3)
    W32/Scrambler.p@MM
    W32/Lacon@MM
    W32/Fregit.c@MM
  Email Generic (1)
    W32/Noala.gen@MM
  Generic (1)
    SRCG.gen
  Generic Peer To Peer Worm (1)
    W32/Duload.worm.gen!p2p
  Generic Worm (1)
    W32/Sinis.worm.gen
  Internet Worm (2)
    W32/Tzet.worm.f
    W32/Vesser.worm.b
  Parasitic (1)
    W32/HLLP.Nity.c
  Script (2)
    Bat/Goho
    Bat/Meduna
  Win32 (10)
    W32/Lazi.c
    W32/Lazi.a
    W32/Lazi.b
    W32/Seppuku.j
    W32/Lutor
    W32/Cebe
    W32/Younga.4433a
    W32/Lovgate.c
    W32/Ennumi
    W32/Dabyrev
  Win9x (1)
    W95/Feeling.1107intd
  Worm (47)
    W32/Gaobot.worm.dx
    W32/Jubon.worm
    W32/Spybot.worm.uw
    W32/Spybot.worm.ur
    W32/Pix.worm.c
    W32/Randon.worm.ad
    W32/Spybot.worm.ua
    W32/Spybot.worm.ty
    W32/Spybot.worm.uo
    W32/Spybot.worm.uu
    W32/Spybot.worm.us
    W32/Spybot.worm.un
    W32/Spybot.worm.up
    W32/Spybot.worm.tz
    W32/Gaobot.worm.dv
    W32/Gaobot.worm.dt
    W32/Gaobot.worm.do
    W32/Gaobot.worm.dm
    W32/Gaobot.worm.dh
    W32/Gaobot.worm.dq
    W32/Gaobot.worm.dp
    W32/Spybot.worm.um
    W32/Spybot.worm.ux
    W32/Spybot.worm.uv
    W32/Spybot.worm.ut
    W32/Spybot.worm.tx
    W32/Pix.worm.d
    W32/Spybot.worm.uq
    W32/Gaobot.worm.eb
    W32/Gaobot.worm.ec
    W32/Gaobot.worm.ea
    W32/Gaobot.worm.dz
    W32/Gaobot.worm.dy
    W32/Gaobot.worm.dw
    W32/Gaobot.worm.du
    W32/Gaobot.worm.ds
    W32/Gaobot.worm.dn
    W32/Spybot.worm.vh
    W32/Randon.worm.ae
    W32/Mumu.d.worm
    W32/Kober.worm
    W32/Audience.worm.a
    W32/Rirc.worm
    W32/Randon.worm.af
    W32/HLLP.Fove.worm
    W32/Audience.worm.b
    W32/Anav.worm

Enhanced Detections:

Program (1)
  - (1)
    WebHancer
Trojan (33)
   (2)
    Gnu5
    Generic PWS.c
  Application extension (1)
    BackDoor-ASL.dll
  Configurator (2)
    PWS-LamLite.cfg
    Generic PWS.c.cfg
  Downloader (3)
    Downloader-DH
    Downloader-DS
    Downloader-FU
  Dropper (5)
    Generic PWS.c.dr
    BackDoor-ATV.dr
    PWS-QQThief.dr
    PWS-QQCave.dr
    MultiDropper-IM
  Exploit (3)
    Exploit-WsBaseUrl
    Exploit-IISWDav
    Exploit-Mircer
  Generic (1)
    BackDoor-AOY.gen
  Palm (1)
    PalmOS/Vapor
  Password (1)
    PWS-Mafia
  Password Stealer (4)
    PWS-W
    PWS-LamLite
    PWS-BStroj
    PWS-QQThief
  Remote Access (3)
    BackDoor-ASL
    BackDoor-ATV
    BackDoor-AOY
  Script (1)
    IRC/Flood.bat.d
  Trojan (1)
    StartPage-W
  Win32 (5)
    Keylog-Laz
    DiabloCheat
    Del-405
    AdClicker-U
    Delwin
Virus (32)
   (1)
    Avispa.2048
  Damaged (4)
    W32/Bolzano.2564.dam
    W32/Bolzano.5396b.dam
    W32/Bolzano.5396.dam
    Avispa.dam
  Dropper (1)
    Bat/Mumu.dr
  E-mail worm (4)
    W32/Yaha.k@MM
    W32/Yaha.l@MM
    W32/Yaha.m@MM
    W32/Yaha.j@MM
  Email (2)
    W32/Yaha.o@MM
    W32/Yaha.r@MM
  Generic (1)
    Exploit-DcomRpc.g.gen
  Internet Relay Chat (1)
    IRC/Hamster
  Internet Worm (6)
    W32/Tzet.worm
    W32/Petch.worm!irc
    W32/Yaha.x@MM
    W32/Yaha.y@MM
    W32/Yaha.q@MM
    W32/Yaha.p@MM
  JavaScript (1)
    JS/Xilos
  Win32 (11)
    W32/Seppuku.d
    W32/Seppuku.b
    W32/Seppuku.c
    W32/Seppuku.a
    W32/Anar
    W32/Seppuku.e
    W32/Younga.4433
    W32/Seppuku.f
    W32/Seppuku.i
    W32/Seppuku.h
    W32/Seppuku.g