Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4364
DAT Release Date 06/02/2004
Threats Detected 91110
New Detections 92
Enhanced Detections 533

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Korgo.worm.g Low-Profiled Low-Profiled
W64/Rugrat Low-Profiled Low-Profiled

New Detections:

Program (5)
  Downloader (1)
    Downloader-KV
  Malware Tool (2)
    HTool/Scan-MS04-011
    PWCrack-BeatLM
  Tool (1)
    Tool-GetOS
  Win32 (1)
    PortScan-Ghirai
Trojan (53)
   (2)
    Generic Downloader.e
    APStrojan.tw
  Application extension (2)
    StartPage-DH.dll
    PWS-Cookie.dll
  Configurator (1)
    BackDoor-CFC.cfg
  Downloader (14)
    Downloader-KS
    Downloader-KQ
    Downloader-KO
    Downloader-KL
    Downloader-KI
    Downloader-KG
    Downloader-JY.dldr
    AdClicker-O.dldr
    Downloader-KR
    Downloader-KN
    Downloader-KM
    Downloader-KK
    Downloader-KH
    Downloader-KF
  Dropper (7)
    Spy-Idwi.dr
    MultiDropper-KO
    IRC/Flood.ee.dr
    Downloader-KP
    JS/Spy-Peep.dr
    MultiDropper-KM.b
    IRC-Rabagi.dr
  Flooder (1)
    FDoS-Sudden
  Generic (2)
    FDoS-ICQ.gen
    IRC-Mtron.gen
  Internet Relay Chat (4)
    IRC-Scanbot
    IRC-Rabagi
    IRC-Mtron
    IRC/Flood.ek
  Keylogger (1)
    Keylog-Muhack
  Password Stealer (1)
    PWS-Cookie
  Remote Access (4)
    BackDoor-CFA
    BackDoor-CFC.srv
    BackDoor-CFB
    BackDoor-CFG
  Script (2)
    Downloader-KM.bat
    JS/Harnig
  Settings Change (2)
    StartPage-BQ
    StartPage-DL
  StartPage (4)
    StartPage-DK
    StartPage-DG
    StartPage-DI
    StartPage-DH
  Win32 (6)
    QHosts-10
    LogOff
    Generic StartPage.c
    DDoS-MobileBomb
    DDoS-Boxed
    FakeSecure
Virus (34)
   (8)
    Hermanos.2777
    Polimer.512
    Elcon.424
    Retribution.1663
    Kosti.558
    Jinx
    Elcon.550
    Elcon.374
  Damaged Worm (1)
    W32/Sddrop.worm.dam
  Dropper (1)
    W32/Jeefo.dr
  Email (4)
    W32/Plage.c@M
    W32/Netsup@MM
    W32/Dumaru.av@MM
    W32/Bagle@MM!vbs
  File Infector (1)
    W64/Rugrat
  Generic Worm (1)
    W32/Winfig.worm.gen
  HTML document (1)
    VBS/Zulu.htm.i
  Script (2)
    VBS/Nyar
    W32/StingFake.bat
  Win32 (8)
    W32/Polybot.bf
    W32/NGVCK.a.2134
    W32/Dumaru.au
    W32/StingFake
    W32/Polybot.bg
    W32/Polybot.be
    W32/Polybot.bd
    W32/Polybot.bc
  Worm (7)
    W32/Parparo.worm
    W32/Randon.worm.aw
    W32/Gaobot.worm.pp
    W32/Korgo.worm.g
    W32/Korgo.worm.e
    W32/Korgo.worm.f
    W32/Golo.worm

Enhanced Detections:

Program (284)
   (12)
    T-Utility
    Friend Greeting.eml
    FormatD
    Crack-Invircible
    BlackStone
    Durell
    Crack-Generic
    AntiDW
    Yalta.vxd
    NetBusPro
    Reset
    RemAdm-ANE
  - (13)
    Dsnif
    Iroffer
    Reboot-E
    PrcView
    Free-Scratch-Cards
    Closer
    HideWindow
    Starr
    VText-AntiTBAV
    Pepe-bar
    IMIServ.download
    Friend Greeting
    Dlder
  Adware (19)
    Adware-TopMoxie
    Adware-PortalScan
    Adware-Surfbar
    Adware-Superbar
    Adware-Look2Me
    Adware-HotBar
    Adware-SAHAgent
    Adware-BetterInet
    Adware-CWS
    Downloader-BT
    Adware-FreeComm
    Adware-Apropos
    Adware-Cantfind
    Adware-Hotlink
    Adware-Homepage
    Adware-WMS
    Adware-StatBlaster
    Adware-WildMedia
    Adware-JimHelp
  Application extension (3)
    PWCrack-Revealer.dll
    IMIServ.dll
    ERunAsX.dll
  Client (2)
    NetbusPro.cli.pak
    CyberSensor.cli
  Configurator (1)
    Tool-Exter.cfg
  Demonstration (5)
    Demo-VirSim
    Demo-WallBreaker
    Demo-AdoRead50x
    Demo-AVHoles
    Joke-Demo-Finjokan
  Downloader (4)
    Downloader-FL
    Downloader-AZ
    IdentDaemon.ldr
    Downloader-JV
  Dropper (4)
    PWCrack-Cain.dr
    Adware-BetterInet.dr
    NetBusPro.dr
    Kim.dr
  Exploit (3)
    Exploit-GkWarez
    Demo-Opera
    Exploit-Agressor
  Flooder (2)
    FDoS-Dros
    FDoS-DelPing
  Generic (2)
    Dialer-RAS.db.gen
    Exploit-MIME.gen.c
  HTML document (1)
    IMIServ.html
  ICQ Messaging (1)
    ICQ-Info
  Internet Relay Chat (1)
    IRC-Proxy
  Joke (72)
    Joke-XMovie
    Joke-Wobbling
    Joke-Uglyface
    Joke-Trembler
    Joke-Stupid.70
    Joke-Spinner
    Joke-Snowman
    Joke-SmallP.c
    Joke-SmallP.a
    Joke-SlipperyMouse
    Joke-Slider
    Joke-Rjump
    Joke-QScreen5
    Joke-Perdido
    Joke-Paranoia
    Joke-PamPrj
    Joke-Ohnee
    Joke-MovingMouse
    Joke-Monopoly
    Joke-Monday
    Joke-MouseShoot
    Joke-MessageMate
    Joke-Madcow
    Joke-LikeWind
    Joke-Langweil
    Joke-Stup
    Joke-StressRelief
    Joke-StarWars
    Joke-SmallP.b
    Joke-Rabbit
    Joke-Myosotis
    Joke-MewII
    Joke-Farce
    Joke-FakeReboot
    Joke-EjectCD
    Joke-ComputerShock
    Joke-Buttons.b
    Joke-BrokenDisk
    Joke-Amigo
    Joke-3Pigs
    Joke-Ktest
    Joke-Jkozd
    Joke-Irritan
    Joke-IQTest
    Joke-Idot
    Joke-IconScroll
    Joke-IconDance
    Joke-Habar
    Joke-Grenadier
    Joke-Geschenk
    Joke-Flipped
    Joke-Flash-Itest
    Joke-Flash-Ghost
    Joke-FakeFormat.h
    Joke-FakeFormat.f
    Joke-FakeFormat.a
    Joke-DTReg
    Joke-Drunk
    Joke-Delay
    Joke-Cursor
    Joke-CokeGift
    Joke-CD-Argen
    Joke-Buttons
    Joke-Bros
    Joke-Boxes
    Joke-BlueSprite
    Joke-Badgame
    Joke-Autodestruct
    Joke-AddRem
    Joke-WinError
    Joke-Ttub
    Joke-TinyP
  Keylogger (5)
    Keylog-WinPass
    KeyLog-Phantom
    Keylog-Typ0
    Keylog-DGS
    Keylog-ABSpy
  Malware Tool (21)
    Kit-Vanquish
    PWCrack-Dragon
    PWCrack-Decoder
    PWCrack-Diamond
    PWCrack-HTTPBrute
    PWCrack-WinPWL
    PWCrack-Stoler
    PWCrack-SQLBrute
    PWCrack-ZIPBrute
    Nuke-KillIC
    PWCrack-Snitch
    HTool/RNK
    PWCrack-RA2x
    PWCrack-ICQ99
    PWCrack-PWLCrack
    PWCrack-DanS
    PWCrack-LPR
    PWCrack-L0phtCrack
    PWCrack-JBld
    PWCrack-CuteFTP
    HTool/Client
  Password (4)
    PWCrack-Leecher
    PWDump
    PWCrack-PWLView
    PWCrack-Cain
  Plugin component (2)
    Firehole.plugin
    CyberSensor.plugin.plugin
  Self-extracting archive (1)
    InstallRite.sfx
  Server (2)
    ControlTotal.svr
    IMIServ.svr
  Source code (1)
    LoveYou.src
  Spam (1)
    Spam-LanxQQ
  Spyware (3)
    Keylog-Perfect
    KeyLog-KeyRecord
    Spyware-Ssppyy
  Tool (30)
    Reboot-X
    PWCrack-Xavior
    FireDaemon
    Sniff-AssIP
    Tool-Nmap
    Tool-Teardrop
    Tool-Upadmin
    Tool-DllPatch
    Tool-NetCat
    Tool-DLLInjector
    Tool-Zombie
    Tool-Embedder
    Tool-Exter
    Tool-SMail
    Tool-Sub7Stealer
    Tool-Smbcrack4
    Tool-Redhack
    Tool-QQmdao
    Tool-Piaoyes
    Tool-Linklooker
    Tool-Arpkill
    Tool-Check4C
    Tool-AnsiCheck
    Tool-AntiMacgyver
    Tool-MSNBomb
    Linux/Tool-Elfwrsec
    Tool-Hpot
    Tool-PsybncScan
    Tool-PEintro
    Tool-HDProtectCrack
  Vulnerability (1)
    ZoneClick
  Win31 (3)
    Kim
    HideApp
    IdleToolz
  Win32 (65)
    PhoenixScan
    FindPass
    Aldscan
    Spoof-ICQPort
    Demo-LeakTest
    Restsec
    PortScan-SuperScan
    WinZapper
    Lophtcrack
    Optimizator
    TSADBOT
    WinSniff
    Silent Watch
    ShowPassword
    RMRemove
    UsrPatch
    Crack-Floop
    TrojSimul
    DFTP-Server
    Spoof-Smoke
    Blackbox
    NetSVC
    Parallaxis.Spider
    IdentDaemon
    MpAdvert
    MSN-Tnhbot
    LopAdvert
    NetShare
    Hhproxy
    WinGuardian
    AsGoodBye
    ShareSniffer
    RemoteXS
    Htthost
    FTPback
    Firehole
    ShellSpawn
    NT-RemoteCon
    Yalta
    Viewer-Orifice2K
    W32/Nosys
    PortScan-Auha
    Aardcook
    Jolt
    Exitwinc
    QWHack
    IMIServer.download
    ERunAsX
    RemAdm-RemoteAdmin
    Outbound
    NoZoneMutex
    Crack-CuteFTP
    Generic HTool.a
    StealthMail
    SmmSniff.DNS
    SmmSniff
    RemoConChubo
    BigBrother
    Restrict
    RemAdm-RemoteAnythng
    RemAdm-RV.rmv
    PassDump.a
    Grador.foto
    Crack-Diablo
    CyberSensor.spy
Trojan (128)
   (2)
    FormatA
    Uploader-N
  - (1)
    Adshow
  Application extension (4)
    BackDoor-AXJ.dll
    Spy-Hiddukel.dll
    Spy-Idwi.dll
    BackDoor-AGB.dll
  Client (1)
    BackDoor-RP.cli
  Configurator (2)
    BackDoor-RP.cfg
    MultiDropper-GK.cfg
  Demonstration (1)
    Exploit-BMP.demo
  Dialer (1)
    QDial22
  Downloader (2)
    Downloader-DH.b
    Proxy-Mitglieder
  Downloader Generic (1)
    Proxy-FBSR.gen.dldr
  Dropper (10)
    VBS/Inor
    AdClicker-O.dr
    PWS-Bancban.dr
    BackDoor-ACH.dr
    BackDoor-Sub7.dr
    BackDoor-BL.dr
    BackDoor-FK.dr
    RemoteAdmin.dr
    PWS-Mir.dr
    MultiDropper-KM
  Exploit (3)
    Exploit-ByteVerify
    Exploit-MS04-011
    Exploit-BMP.dldr
  Flooder (1)
    FDoS-Icgmp
  Generic (4)
    JS/Seeker.gen.m
    Proxy-FBSR.gen
    Exploit-Lsass.g.gen
    Spy-Tofger.gen.a
  Internet Relay Chat (2)
    IRC/Rootbot
    IRC-SpSpy
  Java Applet (1)
    JV/Shinwow
  JavaScript (1)
    JS/Loop
  Macro (1)
    A97M/AcceV
  Password (6)
    PWS-Bancos
    PWS-Wexd
    PWS-Bancban
    HTML/Ebscam
    BackDoor-AOT
    PWS-GWGhost
  Password Stealer (2)
    PWS-Harvester
    PWS-Banker
  Proxy (1)
    Proxy-DistNet
  Remote Access (60)
    BackDoor-ACH
    Backdoor-AOK
    BackDoor-AXJ
    BackDoor-KL
    Backdoor-Q
    BackDoor-SP
    BackDoor-BL
    BackDoor-ZT
    Keylog-Briss
    BackDoor-AMB
    BackDoor-AJW
    BackDoor-AIO
    BackDoor-AKX
    BackDoor-AKC
    BackDoor-AGB
    BackDoor-ABK
    BackDoor-GO
    BackDoor-WO
    BackDoor-OG
    BackDoor-ZE
    BackDoor-VP
    BackDoor-DP
    BackDoor-AFM
    BackDoor-GG
    BackDoor-PB
    BackDoor-HS
    BackDoor-FF
    BackDoor-Sub7
    BackDoor-AQ
    Backdoor-JZ
    Backdoor-KZ
    Backdoor-QN
    Backdoor-EE
    BackDoor-YQ
    BackDoor-CAZ
    BackDoor-N
    BackDoor-AGV
    BackDoor-AC
    BackDoor-DB
    BackDoor-FN
    BackDoor-ANJ
    BackDoor-FK
    BackDoor-FT
    BackDoor-KT
    BackDoor-DI
    BackDoor-DZ
    BackDoor-BD
    BackDoor-US
    BackDoor-BAW
    BackDoor-LE
    BackDoor-AEN
    BackDoor-YA
    BackDoor-AS
    BackDoor-ACP
    BackDoor-WX
    BackDoor-WG
    BackDoor-DV
    BackDoor-X
    BackDoor-P
    BackDoor-BCY
  Script (4)
    VBS/SevenC
    New CardStealer
    IRC/Flood.bat.f
    BackDoor-BQ.bat
  Server (3)
    BackDoor-WF.svr
    BackDoor-RP.svr
    BackDoor-KT.svr
  Settings Change (1)
    KillCMOS
  VbScript (1)
    JS/IEstart.gen
  Win32 (11)
    Generic PWS.e
    Generic PWS.a
    Spy-Idwi
    AdClicker-W
    HackerDefender
    Generic Downloader.c
    IRC-Sdbot
    Generic VB.b
    Generic PWS.f
    CleanIISLog
    AdClicker-AN
  Worm (1)
    IRC/Flood.bq
Virus (121)
   (14)
    Mirea
    Pixel.Hydra
    Murphy.1614c
    Murphy.1614b
    Murphy.1250e
    Murphy.1008
    Keypress.1744
    Keypress.1232r
    Keypress.1232d
    Keypress.1232a
    Mad.1680
    Mad.2311
    Disillusion.1108
    Mirea.1953
  Application extension Worm (2)
    W32/MoFei.worm.dll
    W32/Tumbi.worm.dll
  Damaged (5)
    W32/Sober.dam
    W32/Gaobot.dam
    Mad.dam
    W32/Lovgate.dam
    W32/Kuang.dam
  Dropper (6)
    Univ/a.dr
    Keypress.1232a.dr
    Keypress.1232d.dr
    Taipan.dr
    W32/Kuang.dr
    Univ.topsy.dropped
  E-mail (2)
    W32/Swen@MM
    W32/Dumaru.ad@MM
  E-mail worm (4)
    W32/Lovgate.f@M
    W32/Generic.a@MM
    W32/Dumaru.y@MM
    W32/Lovgate.ab@MM
  Email (22)
    W32/Dumaru.aa@MM
    W32/Dumaru.z@MM
    W32/Lovgate.b@M
    W32/Lovgate.g@M
    W32/Lovgate.m@M
    W32/Lovgate.n@M
    W32/Dumaru.af@MM
    W32/Dumaru.ab@MM
    W32/Dumaru.ag@MM
    W32/Dumaru.ae@MM
    W32/Dumaru.ah@MM
    W32/Lovgate.q@MM
    W32/Lovgate.p@MM
    W32/Lovgate.v@M
    W32/Lovgate.t@MM
    W32/Lovgate.u@MM
    W32/Lovgate.w@M
    W32/Lovgate.aa@MM
    W32/Dumaru.al@MM
    W32/Dumaru.ak@MM
    W32/Dumaru.aj@MM
    W32/Dumaru.ai@MM
  Email Generic (1)
    W32/Plage.gen@M
  File Infector (3)
    Cobra.400
    Tony
    DM.310
  Generic (2)
    Exploit-DcomRpc.g.gen
    W32/Kuang.gen
  Generic Worm (4)
    W32/Gaobot.worm.gen.d
    W32/Spybot.worm.gen.k
    W32/Wozer.worm.gen
    W32/Korgo.worm.gen
  Heuristic (1)
    New Script.ext
  Internet Worm (3)
    W32/Sddrop.worm
    W32/Spybot.worm.lz
    W32/Gbot.worm
  Macro (1)
    W97M/CZero
  mIRC Worm (1)
    W32/Protoride.worm
  Open Share Worm (1)
    W32/Dedler.worm.gen
  Overwriting (1)
    Univ.ow/e
  Parasitic (4)
    W32/HLLP.Philis.d
    W32/HLLP.Philis.c
    W32/HLLP.Philis.b
    W32/HLLP.Philis.a
  Script (2)
    VBS/Generic
    VBS/Mita
  Universal (3)
    Univ/a
    Univ/g
    Univ/j
  VbScript (1)
    New Script
  VBScript worm (1)
    JS/Kak@M
  Win32 (10)
    W32/Jeefo
    W32/Lovgate
    W32/Kuang.f
    W32/Dumaru.as
    W32/Dumaru.ar
    W32/Dumaru.aq
    W32/Dumaru.ap
    W32/Dumaru.ao
    W32/Dumaru.an
    W32/Dumaru.am
  Worm (27)
    W32/Gaobot.worm
    W32/MoFei.worm
    W32/Lovgate.l@M
    W32/Lovgate.a@M
    W32/Lovgate.c@M
    W32/Spybot.worm.aax
    W32/Spybot.worm.qu
    W32/Spybot.worm.ob
    W32/Spybot.worm.hf
    W32/Generic.worm.b
    W32/Lovgate.s@MM
    W32/Lovgate.x@MM
    W32/Spybot.worm.ago
    W32/Spybot.worm.aaq
    W32/Spybot.worm.vc
    W32/Spybot.worm.si
    W32/Spybot.worm.qt
    W32/Spybot.worm.pp
    W32/Spybot.worm.md
    W32/Spybot.worm.lx
    W32/Spybot.worm.dn
    W32/Morph.worm
    W32/Korgo.worm.d
    W32/Korgo.worm.c
    W32/Korgo.worm.b
    W32/Korgo.worm.a
    W32/Pinom.worm!backdoor