Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4374
DAT Release Date 07/07/2004
Threats Detected 93236
New Detections 85
Enhanced Detections 385

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (15)
   (1)
    Tool/fmt6
  Adware (1)
    BackDoor-BDJ
  Joke (4)
    Joke-Welvi
    Joke-Winshoot
    Joke-Melter
    Joke-Assi
  Malware Tool (3)
    VTool/x14
    HTool/getl
    HTool/pid
  Script (5)
    Tool/fmt10
    Tool/fmt8
    Tool/ftp
    Tool/fmt9
    Tool/fmt7
  Tool (1)
    Tool-IISConfig
Trojan (37)
   (3)
    Irdet
    Bionet
    Hypnoice
  Application extension (1)
    BackDoor-CCL.dll
  Disk erasing (3)
    QZap362
    QZap361
    QZap363
  Downloader (9)
    Downloader-ME
    Downloader-MC
    Downloader-MA
    Downloader-MF
    Downloader-MD
    Downloader-MB
    Downloader-LZ
    Downloader-LX
    Downloader-LW
  Flooder (1)
    FDoS-Spabot
  Heuristic (2)
    New BackDoor7a
    New BackDoor7b
  Password Stealer (1)
    PWS-Vipgsm
  Proxy (1)
    Proxy-Pcheck
  Remote Access (6)
    BackDoor-CGO
    BackDoor-BDI
    BackDoor-CGP
    BackDoor-CGM
    BackDoor-BDH
    BackDoor-CFB
  Script (8)
    Bat/dt130
    Bat/qz132
    Bat/qd245
    Bat/dt131
    Bat/qz133
    Bat/qz131
    Bat/qd244
    Bat/inetp
  StartPage (1)
    StartPage-DU!chm
  Win32 (1)
    Generic BackDoor.k
Virus (33)
   (5)
    Cesspool.kod
    Presspower.328
    SymbOS/Cabir
    Die-Hard.3999
    Cesspool.10768
  Damaged Worm (1)
    W32/Protoride.worm.dam
  E-mail worm (1)
    W32/Lovgate.af@MM
  Email (4)
    W32/Bugbear.41404@MM
    W32/Mydoom.m@MM
    W32/Lovgate.af@MM!zip
    W32/Holar.s@MM
  Email Generic (1)
    W32/MyWife.gen@MM
  Generic (2)
    W32/Bagle.gen!vbs
    W32/Mkar.gen
  Generic Worm (4)
    W32/Sdbot.worm.gen.u
    W32/Sdbot.worm.gen.t
    W32/Israz.worm.gen
    W32/Fesber.worm.gen
  Internet Relay Chat (1)
    IRC-Xevol!zip
  Linux (1)
    Linux/Metis.4096
  Script (1)
    Bat/nih
  Win32 (11)
    W32/Wallon!html
    W32/Onver
    W32/NGVCK.b.3501
    W32/Ingax.656
    W32/Ingax.528
    W32/Ingax.720
    W32/Ingax.580
    W32/Ingax.504
    W32/Gastro
    W32/Calgary
    W32/Banof
  Worm (1)
    W32/Sykel.worm

Enhanced Detections:

Internet Worm (1)
  E-mail (1)
    W32/Bagle.gen@MM
Malware (1)
  Exploit (1)
    Exploit-CodeBase
Program (10)
  - (1)
    RemAdm-PSKill
  Demonstration (1)
    W97/Exploit-SpyField.demo
  Downloader (3)
    Downloader-BR
    Adware-Lop.dldr
    Downloader-JS
  Dropper (1)
    Adware-Lop.dr
  Joke (1)
    Toadie joke
  PornDialer (1)
    Dialer-Generic
  Remote Access (1)
    ServU-Daemon
  Win32 (1)
    Generic HTool.a
Trojan (204)
   (9)
    Generic PWS.b
    Generic BackDoor.d
    Sucker
    Nuravo
    Concord
    Two-and-a-Half
    LammerBuster2
    AdClicker-AJ
    QHosts-1!hosts
  - (4)
    Stealther
    AdClicker-O
    Click-1
    AIM-Canbot
  Application extension (10)
    BackDoor-CBB.dll
    CoreFlood.dll
    BackDoor-AXJ.dll
    Spy-Tofger.dll
    PWS-Narod.dll
    PWS-LDPinch.dll
    Spy-Antaz.dll
    Keylog-Fearless.dll
    Spy-Merries.dll
    Keylog-MXX.dll
  Client (1)
    BackDoor-CBB.cli
  Configurator (1)
    BackDoor-CBB.cfg
  Denial Of Svc (1)
    DDoS-Ferlect
  Disk erasing (1)
    QZap251
  Downloader (18)
    Downloader-DB
    Downloader-DC
    Downloader-GJ
    Downloader-BU
    Downloader-CP
    Downloader-CR
    Downloader-CS
    Downloader-CZ
    Downloader-FP
    Downloader-HV
    Downloader-HW
    Downloader-IF
    Downloader-KL
    Downloader-LV
    Downloader-LY
    VBS/BackDoor-BCB.dldr
    StartPage-BT.dldr
    Downloader-JW
  Dropper (11)
    Downloader-DM
    PWS-Bancos.dr
    Multidropper-GN
    MultiDropper-GS
    AdClicker-O.dr
    PWS-Bancban.dr
    MultiDropper-GP.d
    MultiDropper-DC
    MultiDropper-CM
    MultiDropper-EY
    MultiDropper-JQ
  Dropper Generic (1)
    IRC-Sdbot.dr.gen
  Exploit (20)
    Exploit-Sfind
    VBS/Psyme
    Exploit-DarkKnight
    Exploit-ByteVerify
    Exploit-IFrame
    Exploit-Dameware
    Exploit-MhtRedir.gen
    Exploit-IIS.Xploit
    Exploit-GetAdmin
    Exploit-Messer
    Exploit-Mediar
    Exploit-Ciskill
    Exploit-AccControl
    Exploit-SqlExp
    Exploit-Orcler
    JS/Exploit-DDay
    Exploit-JNuke
    Exploit-Overnasm
    Exploit-Nt4All
    Exploit-LHA Overflow
  File deleting (6)
    QDel364
    QDel363
    QDel397
    QDel393
    QDel383
    QDel347
  Flooder (8)
    FDoS-RSeries
    FDoS-UDPFlood
    FDoS-Xexe
    FDoS-Daniel
    FDoS-Botmail
    FDoS-IrocsK
    FDoS-MWanted
    FDoS-LSky
  Generic (23)
    PWS-Bancban.gen.b
    Downloader-GG.gen
    VB-BackDoor.a.gen
    Keylog.gen
    Keylog-Fearless.gen
    MultiDropper-ER.gen
    AdClicker-C.gen
    MultiDropper-FM.gen
    VB-QDel.gen
    MultiDropper-FT.gen
    BackDoor-AVW.gen
    FDoS-Flooder.gen
    PWS-AIMFake.gen
    JS/Seeker.gen.h
    PWS-Bancos.gen
    Exploit-ObjectData.gen
    Keylog-Stawin.gen
    Spam-Shadow.gen
    StartPage-AI.gen
    W32/Sdbot.gen.r
    BackDoor-AXJ.gen
    Spy-Tofger.gen.b
    Spy-Tofger.gen.a
  Heuristic (3)
    New BackDoor6b
    New BackDoor6a
    New BackDoor6c
  Internet Relay Chat (8)
    IRC/Flood.c
    IRC/Flood.cg
    IRC/Flood.cl
    IRC/Flood.ac
    IRC-Botty
    IRC/Flood.cz
    IRC-Tjspec
    IRC-Xevol
  Java Applet (1)
    JV/Shinwow
  Keylogger (4)
    Keylog-Fin
    Keylog-Pantap
    Keylog-Sters
    Keylog-MXX
  Linux (5)
    Linux-Wiween
    Linux-LnxKerExp
    Linux-BsdKerExp
    Linux-nRg
    Linux-Polite
  Malware Tool (9)
    Nuke-VB
    Kit-JSG
    Kit-Herpes
    Nuke-Ebeg
    Spam-FZ
    Spam-AliS
    NTRootKit-A.sys
    Nuke-Lockhoo
    NTRootKit-E
  Password (5)
    PWS-Bancos
    PWS-Narod
    PWS-LDPinch
    Keylog-Lodis
    PWS-MSNCrack
  ProcKill (1)
    ProcKill-AK
  Remote Access (12)
    BackDoor-ACH
    Woodcot
    BackDoor-ABM
    BackDoor-AZV
    BackDoor-AWM
    BackDoor-CCL
    BackDoor-AVW
    BackDoor-AXY
    BackDoor-BAC
    BackDoor-SS
    BackDoor-JY
    BackDoor-TC
  Script (1)
    IIS/BackDoor-ACE
  Server (2)
    Orifice2K.svr
    BackDoor-WF.svr
  Spyware (2)
    Keylog-Spider
    Keylog-Yeehah
  StartPage (2)
    StartPage-CQ.gen
    StartPage-CP
  Trojan (2)
    QDel391
    QDel392
  VbScript (1)
    VBS/Vmort
  Win32 (32)
    Enocider
    Generic VB
    IRC/Flood.cm
    W32/Bagle.x!proxy
    Generic BackDoor.b
    Del-437
    HackerDefender
    Generic FDoS
    Generic BackDoor.f
    Generic Delphi
    Sarka
    Kility
    DDoS-Slack
    Uploader-E
    Provera
    QKey5
    LockDown
    Rixi
    OpenCD
    DiskFill-I
    DRevenge
    Niuzu
    Del-403
    Generic VB.b
    Generic Del
    SysCenter
    Generic FDoS.b
    Spy-Merries
    Del-446
    DDoS-Boxed
    AdClicker-AO
    Generic QHosts.a
Virus (169)
   (3)
    SymbOS/Cabir.b
    SymbOS/Cabir.a
    HLLT.7504b
  Application extension (1)
    W32/Demig.dll
  Damaged (2)
    W32/Gaobot.dam
    W32/Lovgate.dam
  Damaged Worm (3)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Dropper (4)
    W95/Rinim.476.dr
    W32/Sankey.c.dr
    W32/Projet.dr
    Satan.dr
  Dropper Worm (2)
    W32/Spybot.worm.dr
    W32/Dedler.worm.dr
  E-mail (9)
    W32/Oror.ad@MM
    W32/Mydoom.b@MM
    W32/Mydoom.h@MM
    W32/Mydoom.e@MM
    W32/Bagle.b@MM
    W95/Linong@MM
    W32/PetTick@MM
    W32/Bagle.ad@MM
    W32/Mydoom.k@MM
  E-mail worm (13)
    W32/Lovgate.f@M
    W32/Bagle.q@MM
    W32/Bagle.t@MM
    W32/Bagle.u@MM
    W32/Mydoom.g@MM
    W32/Mydoom.f@MM
    W32/Bagle.r@MM
    W32/Bagle.s@MM
    W32/Bagle.z@MM
    W32/Bagle.aa@MM
    W32/Lovgate.ad@MM
    W32/Lovgate.ab@MM
    A2KM/Sadip@MM
  Email (56)
    W32/Mydoom.i@MM
    W32/Oror.f@MM
    W32/Oror.h@MM
    W32/Oror.i@MM
    W32/Oror.k@MM
    W32/Oror.j@MM
    W32/Oror.n@MM
    W32/Oror.m@MM
    W32/Oror.o@MM
    W32/Lovgate.b@M
    W32/Oror.z@MM
    W32/Oror.y@MM
    W32/Oror.x@MM
    W32/Oror.aj@MM
    W32/Oror.ah@MM
    W32/Oror.ae@MM
    W32/Oror.ac@MM
    W32/Oror.v@MM
    W32/Oror.q@MM
    W32/Oror.ai@MM
    W32/Oror.af@MM
    W32/Oror.aa@MM
    W32/Oror.w@MM
    W32/Oror.s@MM
    W32/Oror.p@MM
    W32/Lovgate.g@M
    W32/Oror.ao@MM
    W32/Oror.aq@MM
    W32/Lovgate@M
    W32/Lovgate.m@M
    W32/Oror.ar@MM
    W32/Lovgate.n@M
    W32/Mydoom.j@MM
    W32/Bagle.a@MM
    W32/Lovgate.q@MM
    W32/Lovgate.p@MM
    W32/Lovgate.v@M
    W32/Lovgate.t@MM
    W32/Lovgate.r@MM!zip
    W32/Lovgate.u@MM
    W32/Lovgate.w@M
    W32/Lovgate.x@MM!zip
    W32/Lovgate.aa@MM!zip
    W32/Lovgate.aa@MM
    W32/Lovgate.ac@MM
    W32/Lovgate.v@MM
    W32/Lovgate.ae@MM
    W32/Mydoom.a@MM
    W32/Stopin.a@MM
    W32/Stopin.d@MM
    W32/Stopin.c@MM
    W32/Stopin.b@MM
    W32/Mydoom.l@MM
    W32/Lovgate.z@MM!zip
    W32/Lovgate.ad@MM!zip
    W32/Lovgate.ab@MM!zip
  Email Generic (4)
    W32/Cherich.gen@MM
    W32/Oror.gen@MM
    W32/Oror.gen.a@MM
    VBS/Gorum.gen@MM
  Email Worm (1)
    W32/Evaman@MM
  Generic (1)
    W32/Sankey.gen
  Generic Worm (19)
    W32/Sdbot.worm.gen
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/Spybot.worm.gen.a
    W32/Gaobot.worm.gen.l
    W32/Spybot.worm.gen.g
    W32/Tumbi.worm.gen.b
    W32/Sdbot.worm.gen.d
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.o
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.g
    W32/Gaobot.worm.gen.r
    W32/Gaobot.worm.gen.h
  Heuristic (1)
    New P2P Worm
  HTML document (3)
    Cybesh.html
    Moridin.html
    VBS/Gorum.htm
  Intended (1)
    W95/Henky.intd
  Internet Relay Chat (3)
    IRC/Generic
    W32/Wandol!irc
    W32/Diam!irc
  Internet Worm (1)
    W32/Gaobot.worm.ali
  Macro (1)
    W97M/Coke.22231.a
  mIRC Worm (2)
    W32/Protoride.worm
    W32/Hokilo.worm
  Overwriting (1)
    Univ.ow/a
  Peer To Peer (1)
    W32/Generic.c!p2p
  Peer To Peer Worm (1)
    W32/Sdbot.worm!p2p
  Source code (1)
    W97M/Heathen.src
  Universal (1)
    Univ/j
  Win32 (19)
    W32/Ingax.568dr
    W32/Chiton.d
    W32/Henky.Tanzen
    W32/Lovgate
    W32/Ingax.840
    W32/Ingax.568
    W32/Ingax.644
    W32/Sankey.c
    W32/Projet
    W32/Generic.d
    W32/Ingax.640dr
    W32/Chiton.t
    W32/Chiton.u
    W32/Sankey.b
    W32/Sankey.a
    W32/Ingax.644dr
    W32/Ingax.496dr
    W32/Ingax.856dr
    W32/Ingax.840dr
  Win9x (1)
    W95/Coke.22231
  Worm (14)
    W32/Gaobot.worm
    W32/Lovgate.l@M
    W32/Lovgate.a@M
    W32/Lovgate.c@M
    W32/Generic.worm.b
    W32/Lovgate.s@MM
    W32/Lovgate.x@MM
    W32/Flechal.worm
    IRC/Flib.worm
    W32/Kwbot.worm.b
    W32/Kwbot.worm.a
    W32/Bajos.worm.b
    W32/Dedler.worm
    W32/Kwbot.worm.c