Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4368
DAT Release Date 06/23/2004
Threats Detected 92380
New Detections 107
Enhanced Detections 312

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (10)
  Dialer (1)
    Dialer-206
  Downloader (1)
    Adware-Websearch.dldr
  Generic (1)
    Dialer-RAS.dg.gen
  Proxy (1)
    Proxy-Thrap
  StartPage (1)
    StartPage-MSearch
  Tool (3)
    Tool-DeepFreeze
    Tool-ProxiesR
    Tool-Cookie
  Win32 (2)
    RemAdm-CafeCup
    PortScan-Zzbc
Trojan (63)
   (2)
    Veto
    RemoteAdmin!cfg
  Application extension (2)
    Proxy-Redirector.dll
    Keylog-Mpi.dll
  Configurator (1)
    BackDoor-CFX.cfg
  Demonstration (2)
    JS/Exploit-DialogArg.b.demo
    JS/Exploit-DialogArg.a.demo
  Downloader (8)
    Downloader-LQ
    Downloader-LO
    Downloader-LM
    Downloader-LL
    Downloader-LK
    Downloader-LP
    Downloader-LN
    VBS/BackDoor-BCB.dldr
  Generic (8)
    JS/Stealus.gen
    JS/Exploit-DialogArg.gen
    Proxy-Cidra.gen.b
    Keylog-Stawin.gen.b
    PWS-Tamla.gen
    Systhread.gen
    AFXrootkit.gen
    PWS-LDPinch.gen
  Internet Relay Chat (1)
    IRC/Rabagi
  Keylogger (5)
    Keylog-Personal
    Keylog-Ybad
    Keylog-Mpi
    Keylog-Bicas
    Keylog-Sters
  Malware Tool (1)
    PWS-QQPass.c.kit
  Password Stealer (1)
    PWS-QQPass.c
  Proxy (1)
    Proxy-Malxa
  Remote Access (9)
    BackDoor-CGD
    BackDoor-CFY
    BackDoor-CFW
    BackDoor-BDE
    BackDoor-BDD
    BackDoor-CX
    BackDoor-CGC
    BackDoor-CGA
    Backdoor-CGB
  Script (1)
    Kaland.bat
  StartPage (9)
    StartPage-EB!hosts
    StartPage-EA
    StartPage-DW
    StartPage-DV
    StartPage-DU!text
    StartPage-DY
    StartPage-EB
    StartPage-DZ
    StartPage-DX
  Win32 (12)
    Winkick
    SrvEnum
    QUrl-2
    Del-455
    ICQPager-T
    DDoS-Ferlect
    AdClicker-AP
    ProcInfo
    Generic Keylogger.b
    Kaland
    DDoS-PPPLink
    AdClicker-AO
Virus (34)
   (3)
    SymbOS/Cabir.rsc
    SymbOS/Cabir.b
    SymbOS/Cabir.a
  Damaged (1)
    W32/Bugbear.19196.dam
  Dropper (1)
    VBS/Dismissed.dr
  Email (5)
    W32/Bugbear.19196@MM
    W32/Bugbear.41788@MM
    W32/Alcop.bk@MM
    W32/Alcop.bj@MM
    W32/Bugbear.69916@MM
  Generic Worm (1)
    W32/Sdbot.worm.gen.s
  Internet Worm (1)
    W32/Korgo.worm.r
  Parasitic (2)
    W32/HLLP.27707
    W32/HLLP.15881
  Peer To Peer (2)
    W32/Ourtime!p2p
    W32/Joot!p2p
  Win32 (7)
    W32/Polybot.bo
    W32/Polybot.bn
    W32/Polybot.bm
    W32/Polybot.bl
    W32/Polybot.bk
    W32/FunLove.3626
    W32/Bugbear.17916intd
  Worm (11)
    W32/Spidere.worm
    W32/Randon.worm.ba
    W32/Randon.worm.az
    W32/Nachi.worm.m
    W32/Korgo.worm.u
    W32/Korgo.worm.t
    W32/Korgo.worm.s
    W32/Decon.worm
    W32/Korgo.worm.p
    W32/Setclo.worm
    W32/Korgo.worm.q

Enhanced Detections:

Internet Worm (4)
  E-mail (1)
    W32/Bagle.gen@MM
  P2P Worm (1)
    W32/Spybot.worm.lk
  Win32 (1)
    New Worm
  Worm (1)
    W32/Polybot.gen!irc
Malware (1)
  Win32 (1)
    Exploit-Mydoom
Program (47)
   (3)
    NDotNet
    Suspicious IFrame.b
    RedSwoosh
  - (1)
    Starr
  Adware (4)
    Adware-BHO.gen
    Adware-Gator
    Adware-Lop
    Adware-OMI
  Application extension (1)
    Spyware-SafeSurf.dll
  Dialer (1)
    Dialer-Generic
  Downloader (1)
    Downloader-BR
  Generic (1)
    Keylog-Perfect.gen
  Malware Tool (1)
    HTool/kker
  Remote Access (1)
    ServU-Daemon
  Spyware (1)
    Spyware-SafeSurf
  Tool (30)
    HideRun
    Tool-Haxor
    Tool-Telnet
    Tool-BODec
    Tool-MacTime
    Tool-Revert
    Tool-HLPDump
    Tool-Analyze
    Tool-AVPX
    Tool-Podonok
    Tool-Pervert
    Tool-QQPassO
    Tool-QQExpl
    Tool-IconHnt
    Tool-CGIScan
    Tool-AutoPol
    Tool-DNSMast
    Tool-AIMRV
    Tool-ZPacker
    Tool-PEStat
    Tool-ZMist
    Tool-COM2UUE
    Tool-CGAGF
    Tool-Jumin
    Tool-Netacess
    Tool-IRXPro
    Tool-MLDE32
    Tool-SNTPTest
    Tool-InfElf
    Tool-PEWrSec
  Win32 (2)
    Delshare.f
    Xwxload
Trojan (136)
   (4)
    Generic PWS.b
    Generic BackDoor.d
    Generic Keylogger
    Tool/QQAtack
  - (3)
    IRC-Deport
    StartPage-B
    AdClicker
  Application extension (4)
    Keylog-Spider.dll
    AFXrootkit.dll
    PWS-Narod.dll
    Keylog-Stawin.dll
  Configurator (3)
    ICQPager-E.cfg
    ICQPager-K.cfg
    PWS-AIMFake.cfg
  Demonstration (2)
    JS/Exploit-DialogArg.demo
    Exploit-DcomRpc.b.demo
  Downloader (4)
    Downloader-BI
    Downloader-EW
    Downloader-EX
    HackerDefender.dldr
  Dropper (4)
    PWS-Bancos.dr
    AFXrootkit.dr
    PWS-Bancban.dr
    PWS-Mir.dr
  Dropper Generic (1)
    IRC-Sdbot.dr.gen
  Dropper Script (1)
    Seeker.reg.dr
  Exploit (5)
    VBS/Psyme
    Exploit-MhtRedir.gen
    Exploit-DcomRpc.b
    JS/Exploit-DialogArg.b
    JS/Exploit-DialogArg.a
  Generic (8)
    Proxy-Cidra.gen
    VBS/IEstart.gen.f
    Exploit-URLSpoof.gen
    PWS-Bancos.gen
    IRC/Flood.gen.c
    StartPage-AI.gen
    PWS-Bancban.gen.c
    PWS-LegMir.gen.e
  Heuristic (2)
    New Malware.d
    Unsafe Bat
  Internet Relay Chat (1)
    IRC-Dalixy
  JavaScript (1)
    JS/CardStealer
  Keylogger (2)
    Keylog-Sabood
    Keylog-Jetos
  Parasitic (1)
    Qhosts.apd
  Password (8)
    PWS-Bancos
    PWS-Narod
    PWS-LegMir
    PWS-Msnfake
    PWS-LDPinch
    PWS-Bancban
    PWS-WebMoney.gen
    PWS-Iyus
  Password Stealer (7)
    PWS-Mir
    PWS-QQPass.b
    PWS-Fakeyah
    PWS-AIMFake
    PWS-Tamla
    PWS-Cookie
    PWS-Etry
  Proxy (1)
    Proxy-FBSR
  Remote Access (10)
    BackDoor-ACH
    IRC/Flood.c.dr
    BackDoor-CCL
    BackDoor-AKM
    BackDoor-AVW
    BackDoor-BAC
    BackDoor-QW
    BackDoor-AOZ
    BackDoor-CFA
    BackDoor-CFL
  Script (3)
    New CardStealer
    VBS/ShareEnable
    VBS/Thoza
  Server (2)
    Orifice2K.svr
    Backdoor-ARR.svr
  Settings Change (2)
    Startpage-N
    StartPage-G
  Spam (1)
    AIM-Lowdown
  Spyware (1)
    Keylog-Spider
  StartPage (30)
    StartPage-CM
    StartPage-AM
    StartPage-AK
    StartPage-AH
    StartPage-S
    StartPage-P
    StartPage-J
    StartPage-D
    StartPage-AL
    StartPage-AJ
    StartPage-AE
    StartPage-X
    StartPage-R
    StartPage-O
    StartPage-L
    StartPage-I
    StartPage-E
    StartPage-AZ
    StartPage-Z
    StartPage-BE
    StartPage-BD
    StartPage-BH
    StartPage-BM
    StartPage-BY
    StartPage-BV
    StartPage-BU
    StartPage-BZ
    StartPage-DE
    StartPage-DC
    StartPage-DU
  Win32 (25)
    Generic VB
    Generic Downloader.b
    Proxy-Cidra
    Generic BackDoor.b
    Reg/Seeker
    HackerDefender
    Generic BackDoor.f
    ICQPager-P
    IRC-Sdbot
    ICQPager-R
    ICQPager-Q
    ICQPager-F
    ICQPager-E
    ICQPager-D
    ICQPager-H
    He4Hook
    He4Hook.sys
    ICQPager-K
    Generic BackDoor.c
    ICQPager-N
    Generic Del
    ICQPager-S
    Generic FDoS.b
    DDoS-Boxed
    HaScreen
Virus (124)
  Application extension (1)
    W32/Bugbear.b.dll
  Companion (1)
    Spartak.cmp.2000
  Damaged (3)
    W32/Netsky.q.dam
    W32/Lovgate.dam
    W32/Alcop.dam
  Damaged Worm (4)
    W32/Randbot.worm.dam
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Dropper (2)
    W32/Alcop.ao.dr
    W32/FunLove.dr
  E-mail (1)
    W32/Alcop.a@MM
  E-mail worm (3)
    W32/Lovgate.f@M
    W32/Generic.a@MM
    W32/Lovgate.ab@MM
  Email (52)
    W32/Alcop.ak@MM
    W32/Alcop.ah@MM
    W32/Alcop.af@MM
    W32/Alcop.ad@MM
    W32/Alcop.ac@MM
    W32/Alcop.ab@MM
    W32/Alcop.aa@MM
    W32/Alcop.z@MM
    W32/Alcop.w@MM
    W32/Alcop.v@MM
    W32/Alcop.u@MM
    W32/Alcop.s@MM
    W32/Alcop.r@MM
    W32/Alcop.q@MM
    W32/Alcop.o@MM
    W32/Alcop.m@MM
    W32/Alcop.k@MM
    W32/Alcop.i@MM
    W32/Alcop.g@MM
    W32/Alcop.e@MM
    W32/Alcop.am@MM
    W32/Alcop.ai@MM
    W32/Alcop.ag@MM
    W32/Alcop.ae@MM
    W32/Alcop.y@MM
    W32/Alcop.x@MM
    W32/Alcop.t@MM
    W32/Alcop.p@MM
    W32/Alcop.n@MM
    W32/Alcop.l@MM
    W32/Alcop.j@MM
    W32/Alcop.h@MM
    W32/Alcop.f@MM
    W32/Alcop.b@MM
    W32/Alcop.d@MM
    W32/Alcop.c@MM
    W32/Alcop.an@MM
    W32/Lovgate.b@M
    W32/Lovgate.g@M
    W32/Alcop.aq@MM
    W32/Alcop.ap@MM
    W32/Lovgate.m@M
    W32/Lovgate.n@M
    W32/Alcop.bh@MM
    W32/Alcop.bi@MM
    W32/Lovgate.q@MM
    W32/Lovgate.p@MM
    W32/Lovgate.v@M
    W32/Lovgate.t@MM
    W32/Lovgate.u@MM
    W32/Lovgate.w@M
    W32/Lovgate.aa@MM
  Generic Worm (18)
    W32/Sdbot.worm.gen.a
    W32/Sluter.worm.gen
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/Gaobot.worm.gen.l
    W32/Sdbot.worm.gen.d
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Randbot.worm.gen.a
    W32/Sdbot.worm.gen.o
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.g
    W32/Korgo.worm.gen
    W32/Gaobot.worm.gen.h
  Heuristic (1)
    New Malware.b
  HTML document (1)
    Cybesh.html
  Internet Worm (2)
    W32/Gaobot.worm.ali
    W32/Gaobot.worm.gen.q
  Linux (1)
    Linux/Debilove.10714
  Macro (1)
    W97M/Coke.22231.a
  Overwriting (1)
    W32/Alcop.ow
  Peer To Peer (1)
    W32/Generic.c!p2p
  Script (1)
    Bat/Ioana
  VbScript (1)
    New Script
  Win32 (6)
    W32/Bagif
    New Poly Win32
    New Win32
    W32/Lovgate
    W32/Alcop.ay
    W32/Gobi
  Win9x (1)
    W95/Coke.22231
  Worm (22)
    W32/Lovgate.l@M
    W32/Lovgate.a@M
    W32/Lovgate.c@M
    W32/Alcop.bg.worm
    W32/Generic.worm.b
    W32/Lovgate.s@MM
    W32/Lovgate.x@MM
    W32/Kazaver.worm
    W32/Alcop.aw.worm
    W32/Alcop.au.worm
    W32/Alcop.av.worm
    W32/Alcop.at.worm
    W32/Alcop.ax.worm
    W32/Alcop.az.worm
    W32/Alcop.ba.worm
    W32/Alcop.bc.worm
    W32/Alcop.bb.worm
    W32/Alcop.bf.worm
    W32/Dedler.worm
    W32/Korgo.worm.i
    W32/Korgo.worm.k
    W32/Korgo.worm.j