Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4365
DAT Release Date 06/09/2004
Threats Detected 91591
New Detections 118
Enhanced Detections 305

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Plexus.a@MM Low-Profiled Low-Profiled

New Detections:

Program (23)
  Adware (2)
    Adware-Roings
    Adware-Qoolaid
  Dialer (5)
    Dialer-204
    Dialer-203
    Dialer-202
    Dialer-201
    Tool-Dialupass
  Generic (1)
    Dialer-RAS.dd.gen
  Keylogger (1)
    KeyLog-Amecisco.sys
  Malware Tool (7)
    VTool/muit
    VTool/av42
    VTool/ifng
    HTool/kker
    HTool/halock
    VTool/pgrb
    HTool/dl&r
  Proxy (1)
    Proxy-FatalError
  Spyware (1)
    Spyware-PWCapture
  StartPage (1)
    StartPage-VipCrib
  Tool (4)
    Tool-SysInfo
    Tool-ProcKill
    Tool-Console
    Tool-SpeedTest
Trojan (48)
   (3)
    AntiNAV
    AIM-Lowdown
    FakeNetstat.B
  Application extension (4)
    BackDoor-CFI.dll
    Keylog-Isapass.dll
    AdClicker-AF.dll
    BackDoor-CFK.dll
  Dialer (1)
    QDial23
  Downloader (10)
    Downloader-LB
    Downloader-KW
    JS/Keylog-Briss.ldr
    Downloader-LC
    Downloader-KZ
    Downloader-KX
    Downloader-KU
    Downloader-LA
    Downloader-KY
    Downloader-KT
  Dropper (4)
    MultiDropper-KR
    MultiDropper-KP
    BackDoor-CFD.dr
    MultiDropper-KQ
  Exploit (1)
    Exploit-DirTraversal
  Flooder (1)
    FDoS-Boxer
  Password Stealer (1)
    PWS-Respa
  Remote Access (9)
    BackDoor-CFM
    BackDoor-CFL
    BackDoor-CFK
    BackDoor-BDC
    BackDoor-CFJ
    BackDoor-CFH
    BackDoor-CFE
    BackDoor-CFD
    BackDoor-BDB
  Script (5)
    Bat/qz128
    Bat/mkd27
    Bat/basta
    JS/Relink
    HTML/Debeski.bat
  StartPage (5)
    StartPage-DP
    StartPage-DN
    StartPage-DO
    StartPage-DM
    StartPage-DC!hosts
  Trojan (1)
    Reboot-AF
  Win32 (3)
    Rutop
    Mail-Pimp
    Generic Dropper.c
Virus (46)
   (1)
    Ktd.359
  Application extension (1)
    Exploit-Lsass.dll
  Companion (2)
    HLL.cmp.14009
    W32/Intrust.cmp
  Damaged (1)
    W32/Sober.g.dam
  Dropper (1)
    Minirow.dr
  Dropper Generic (1)
    StartPage-DM.dr.gen
  Dropper Worm (1)
    W32/Sdbot.worm.dr
  Email (6)
    W32/Shutface@MM
    W32/Plexus.c@MM
    W32/Netsky.af@MM
    W32/Bugbear.i@MM
    W32/Plexus.d@MM
    W32/Plexus.b@MM
  Email Generic (2)
    W32/Plexus.gen@MM
    W32/Pereban.gen@MM
  Generic Internet Relay Chat (1)
    W32/Dansh.worm.gen!irc
  Generic Worm (6)
    W32/Svoy.worm.gen
    W32/Silva.worm.gen
    W32/Sdbot.worm.gen.p
    W32/Sdbot.worm.gen.q
    W32/Randbot.worm.gen.h
    W32/Nullpole.worm.gen
  Intended (1)
    W97M/Bihand.intd
  Internet Worm (2)
    W32/Plexus.a@MM
    W32/Dansh.worm!irc
  Macro (1)
    WM/Nowoc
  Parasitic (2)
    HLLP.5540
    HLLP.5296
  Win32 (5)
    W32/Porex.d
    W32/Polybot
    W32/Polybot.bh
    W32/Plexus!hosts
    W32/Bagle!proxy
  Worm (12)
    W32/Korgo.worm.i
    W32/Yesenio.worm!vbs
    W32/Yesenio.worm
    W32/Randon.worm.ay
    W32/Randon.worm.ax
    W32/Korgo.worm.k
    W32/Korgo.worm.j
    W32/Korgo.worm.o
    W32/Korgo.worm.n
    W32/Korgo.worm.l
    W32/Korgo.worm.m
    W32/Korgo.worm.h

Enhanced Detections:

Internet Worm (9)
  E-mail worm (6)
    W32/Netsky.i@MM
    W32/Netsky.b@MM
    W32/Netsky.t@MM
    W32/Netsky.s@MM
    W32/Netsky.c@MM
    W32/Netsky.a@MM
  P2P Worm (2)
    W32/Generic.worm!p2p
    W32/Gool.worm
  Worm (1)
    W32/Polybot.gen!irc
Program (31)
   (1)
    Suspicious IFrame.b
  - (2)
    RemoteProcessLaunch
    Cometsystems
  Adware (8)
    Adware-TVMedia
    Adware-Websearch
    Adware-BHO.gen
    Adware-SearchAid
    Adware-Virtumondo
    Adware-CnsMin
    Adware-ISTbar
    Adware-Lop
  Dialer (1)
    Dialer-Generic
  Exploit (1)
    Exploit-WebDAV
  Keylogger (1)
    Keylog-Amecisco
  Remote Access (1)
    ServU-Daemon
  Spyware (1)
    Spyware-LoverSpy
  Tool (14)
    Tool-AVPX
    Tool-Pervert
    Tool-PGP2TXT
    Tool-RSAKey
    Tool-Tracer
    Tool-PGPDump
    Tool-TXT2DEN
    Tool-Huff
    Tool-AVPOffset
    Tool-VecnaLink
    Tool-Chiton
    Tool-IRXPro
    Tool-DumpAIT
    Tool-FTransf
  Win32 (1)
    Packed mIRC Client
Trojan (89)
   (2)
    Generic BackDoor.d
    Zpass
  - (1)
    IRC/Flood.mirc
  Application extension (4)
    Downloader-DA.dll
    PWS-Wexd.dll
    NetBus.dll
    BackDoor-CDF.dll
  Client (2)
    NetBus.Pro.cli
    NetBus.cli
  Configurator (2)
    MultiDropper-EU.cfg
    NetBus.cfg
  Denial Of Svc (2)
    IRC/Flood
    IRC/Flood.i
  Downloader (9)
    Downloader-EH
    Downloader-DA
    Downloader-EA
    Downloader-DA.b
    Downloader-FP
    Downloader-JH
    StartPage-BS.dldr
    Downloader-KL
    Downloader-JW
  Dropper (10)
    IRC-Sdbot.dr
    Backdoor-AWQ.dr
    MultiDropper-IY
    IRC/Flood.ba.dr
    MultiDropper-EU
    BackDoor-AMQ.dr
    PWS-Watsn.dr
    MultiDropper-KG
    JS/Zecho.dr
    Downloader-KP
  Exploit (4)
    Exploit-ObjectData
    VBS/Psyme
    Exploit-IFrame
    Exploit-MhtRedir.gen
  Generic (7)
    Exploit-DcomRpc.gen
    PWS-Bancban.gen.b
    Exploit-URLSpoof.gen
    IRC/Flood.gen.b
    Keylog-Stawin.gen
    BackDoor-BAC.gen
    PWS-LegMir.gen.e
  Heuristic (2)
    New BackDoor6b
    New BackDoor6a
  Internet Relay Chat (6)
    IRC/Flood.c
    IRC/Flood.b
    IRC-Contact
    IRC/Flood.ba.hidewin
    IRC/Flood.j
    IRC-Brewbot
  Keylogger (1)
    Keylog-Dingxa
  mIRC client (1)
    IRC/Flood.ba.mirc
  Password (5)
    PWS-Moneykeeper
    PWS-LegMir
    PWS-Watsn
    PWS-LDPinch
    PWS-Iyus
  Proxy (1)
    Proxy-Agent.a
  Remote Access (12)
    BackDoor-AMQ
    BackDoor-AKM
    BackDoor-AOP
    BackDoor-BAC
    Backdoor-AWQ
    BackDoor-BCB
    Netbus.svr
    BackDoor-RS
    BackDoor-AOZ
    BackDoor-CCH
    BackDoor-CFG
    BackDoor-CER
  Script (7)
    Univ.script/99a
    JS/AdClicker-AF
    HTML/Debeski
    Bat/kbd3
    Bat/qz111
    JS/Harnig
    Bat/avk29
  Server (1)
    NetBus.Pro.svr
  Settings Change (1)
    StartPage-DL
  StartPage (1)
    StartPage-DC
  Win32 (8)
    IRC/Flood.cm
    Generic Downloader.a
    Generic BackDoor.b
    Reg/Seeker
    Keylog-Stawin
    Generic BackDoor.f
    Generic MSVC
    Myxq
Virus (176)
   (1)
    Vinnitsa
  Client Worm (1)
    W32/Gool.worm.cli
  Configurator Worm (1)
    W32/Gool.worm.cfg
  Damaged (3)
    W32/Netsky.q.dam
    W32/Netsky.c.dam
    W32/Polybot.dam
  Damaged Worm (2)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
  Dropper Worm (1)
    W32/Gool.worm.dr
  E-mail (10)
    W32/Netsky.w@MM
    W32/Netsky.u@MM
    W32/Netsky.g@MM
    W32/Netsky.l@MM
    W32/Netsky.k@MM
    W32/NetSky.h@MM
    W32/Netsky.v@MM
    W32/Netsky.y@MM
    W32/Netsky.z@MM
    W32/Netsky.ab@MM
  E-mail worm (10)
    W32/Netsky.n@MM
    W32/Netsky.j@MM
    W32/Netsky.o@MM
    W32/Netsky.x@MM
    W32/Netsky.e@MM
    W32/Netsky.f@MM
    W32/Netsky.d@MM
    W32/Bagle.z@MM
    W32/Bagle.aa@MM
    W32/Netsky.ac@MM
  Email (2)
    W32/TopSec@MM
    W32/Netsky.ad@MM
  Email Generic (2)
    W32/Dumaru.gen@MM
    W32/Netsky.gen@MM
  Email Worm (1)
    W32/Netsky.aa@MM
  Generic Worm (22)
    W32/Sdbot.worm.gen.b
    W32/Keco.worm.gen
    W32/Sdbot.worm.gen
    W32/Spybot.worm.gen.e
    W32/Gaobot.worm.gen.k
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/Gaobot.worm.gen.l
    W32/Spybot.worm.gen.d
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.o
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.g
    W32/Randbot.worm.gen.d
    W32/Randbot.worm.gen.b
    W32/Gaobot.worm.gen.r
    W32/Gaobot.worm.gen.h
  Heuristic (2)
    New AOL
    New Malware.b
  Internet Relay Chat Worm (1)
    W32/Rosya.worm!irc
  Internet Worm (3)
    W32/Polybot.l!irc
    W32/Gaobot.worm.ali
    W32/Gaobot.worm.gen.q
  Overwriting (2)
    Univ.ow/a
    W32/Enterus.ow
  Script (2)
    Bat/a
    VBS/Bacil
  Universal (3)
    Univ/d
    Univ.topsy
    Univ.prepend
  VbScript (1)
    VBS/Zeha
  VBScript worm (1)
    VBS/Redlof@M
  Win32 (100)
    New Poly Win32
    New Win32
    W32/NGVCK.a.7397
    W32/NGVCK.a.8809
    W32/NGVCK.a.4768
    W32/NGVCK.a.2404
    W32/NGVCK.a.2280
    W32/NGVCK.a.1365
    W32/NGVCK.a.2389
    W32/NGVCK.a.4907
    W32/NGVCK.a.3072a
    W32/NGVCK.a.1934
    W32/NGVCK.a.3560
    W32/NGVCK.a.2522/2537
    W32/NGVCK.a.2342
    W32/NGVCK.a.2218
    W32/NGVCK.a.2754
    W32/NGVCK.a.9412
    W32/NGVCK.a.1947
    W32/NGVCK.a.1416
    W32/NGVCK.a.3072b
    W32/NGVCK.a.1988
    W32/NGVCK.a.2092
    W32/NGVCK.a.2651
    W32/NGVCK.a.1056
    W32/NGVCK.a.2751
    W32/NGVCK.a.9632
    W32/NGVCK.a.1107
    W32/NGVCK.a.1700
    W32/NGVCK.a.3146
    W32/NGVCK.a.3250
    W32/NGVCK.a.1455
    W32/NGVCK.a.3427
    W32/NGVCK.a.5216
    W32/NGVCK.a.1364
    W32/NGVCK.a.2522
    W32/NGVCK.a.926
    W32/NGVCK.a.1352
    W32/NGVCK.a.2266
    W32/NGVCK.a.919
    W32/NGVCK.a.1840
    W32/Generic.d
    W32/Polybot.ag
    W32/NGVCK.a.968
    W32/Polybot.v
    W32/Polybot.t
    W32/Polybot.s
    W32/Polybot.r
    W32/Polybot.q
    W32/Polybot.o
    W32/Polybot.n
    W32/Polybot.m
    W32/Polybot.k
    W32/Polybot.j
    W32/Polybot.i
    W32/Polybot.h
    W32/Polybot.g
    W32/Polybot.f
    W32/Polybot.e
    W32/Polybot.c
    W32/Polybot.a
    W32/Polybot.u
    W32/Polybot.d
    W32/Polybot.b
    W32/Polybot.ae
    W32/Polybot.ac
    W32/Polybot.aa
    W32/Polybot.y
    W32/Polybot.w
    W32/Polybot.ad
    W32/Polybot.ab
    W32/Polybot.z
    W32/Polybot.x
    W32/NGVCK.a.5675
    W32/Polybot.af
    W32/Polybot.am
    W32/Polybot.aj
    W32/Polybot.an
    W32/Polybot.al
    W32/Polybot.ai
    W32/Polybot.bf
    W32/NGVCK.a.2134
    W32/Polybot.bb
    W32/Polybot.ba
    W32/Polybot.bg
    W32/Polybot.be
    W32/Polybot.bd
    W32/Polybot.bc
    W32/Polybot.az
    W32/Polybot.ay
    W32/Polybot.ax
    W32/Polybot.av
    W32/Polybot.aw
    W32/Polybot.au
    W32/Polybot.as
    W32/Polybot.aq
    W32/Polybot.ao
    W32/Polybot.at
    W32/Polybot.ar
    W32/Polybot.ap
  Win9x (2)
    W95/CTX.10853
    W95/CTX.6886
  Worm (3)
    W32/Bizex.worm!dldr
    W32/Dedler.worm
    W32/Korgo.worm.g