Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4376
DAT Release Date 07/14/2004
Threats Detected 93646
New Detections 106
Enhanced Detections 375

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Atak@MM Low-Profiled Low-Profiled

New Detections:

Program (8)
   (2)
    NDotNet
    Generic HTTP
  Dialer (1)
    Dialer-208
  Dropper (1)
    Spyware-WebHancer.dr
  Generic (1)
    Dialer-RAS.dh.gen
  Joke (1)
    Joke-BrowserBlinker
  Script (2)
    Tool/fmt12
    Tool/fmt11
Trojan (50)
   (1)
    Destructive.y
  Application extension (2)
    Downloader-MM.dll
    BackDoor-CGT.dll
  Application extension Generi (1)
    BackDoor-AXJ.dll.gen
  Dialer (1)
    QDial24
  Downloader (10)
    Downloader-ML
    Downloader-MJ
    Downloader-MH
    Downloader-MP
    Downloader-MN
    Downloader-MM
    Downloader-MO
    Downloader-MK
    Downloader-MI
    Downloader-MG
  Dropper (3)
    BackDoor-CGR.dr
    MultiDropper-KT
    Downloader-IU.dr
  Exploit (9)
    Exploit-Utilman
    Exploit-IIS.ThcLame
    JS/Exploit-InjScript
    Exploit-IIS.SSLBuff
    Exploit-SMBUnix
    Exploit-Aluigi
    Exploit-ICQ.Blackice
    PHP/Exploit-Pavuk
    Exploit-IIS4
  Flooder (1)
    FDoS-Pongfr
  Generic (1)
    Downloader-MP.gen
  Malware Tool (2)
    Kit-CompVCK
    Spam-Blackhawk
  Password Stealer (1)
    PWS-Bolvila
  Proxy (1)
    Proxy-BlackMailer
  Remote Access (5)
    BackDoor-CGT.bak
    BackDoor-CGR
    BackDoor-CGQ
    BackDoor-CGT
    Perl/BackDoor-BDK
  Script (3)
    Bat/qd246
    VBS/Lovuk
    JS/Seeker.ag
  StartPage (2)
    StartPage-ED
    StartPage-DB!hosts
  Win32 (7)
    QHosts-12
    IPPager-B
    AdClicker-AR
    Spy-PKaz
    QReg-10
    QHosts-13
    Uploader-Q
Virus (48)
   (4)
    Menuet/Xymo
    HLLT.5658c
    PeaceKeeper.3980
    HLLT.8528
  Damaged (1)
    W32/Lovgate.x.dam
  Damaged Worm (1)
    W32/Nachi.worm.b.dam
  Dropper (1)
    W32/Gobi.dr
  E-mail (2)
    W32/Atak@MM
    W32/Lovgate.ah@MM
  E-mail worm (1)
    W32/Lovgate.aj@MM
  Email (3)
    W32/Lovgate.ai@MM!zip
    W32/Lovgate.aj@MM!zip
    W32/Hardoc@MM
  Email Worm (1)
    W32/Lovgate.ai@MM
  Generic (4)
    W32/Krepper.gen
    W32/Delf.gen
    W32/Samex.gen
    W32/Poffer.gen
  Generic Internet Relay Chat (1)
    W32/Pakota.gen!irc
  Generic Overwriting (1)
    W32/Pipper.ow.gen
  Generic Worm (1)
    W32/Sdbot.worm.gen.v
  Macro (1)
    W97M/Nobody
  Parasitic (1)
    W32/HLLP.20606
  Peer To Peer (2)
    W32/Momac!p2p
    W32/Retal!p2p
  Script (3)
    Bat/ibbm2
    Bat/pill
    Bat/exw18
  Win32 (12)
    W32/Nakrom
    W32/Dumaru.aw
    W32/Polybot.bs
    W32/Trance
    W32/Sality.k
    W32/Sality.i
    W32/Puce
    W32/Dobom
    W32/Nuts
    W32/Lasbat
    W32/Polybot.br
    W32/Sality.j
  Win9x (2)
    W95/Henky.Morgue.f
    W95/Henky.Morgue.e
  Worm (6)
    W32/Lemoor.worm
    W32/Korgo.worm.z
    W32/Korgo.worm.x
    W32/Jared.worm
    W32/Korgo.worm.y
    W32/Korgo.worm.w

Enhanced Detections:

Internet Worm (4)
  E-mail worm (1)
    W32/Wukill.worm
  mIRC Worm (1)
    New IRC
  P2P Worm (2)
    W32/Generic.worm!p2p
    W32/Spybot.worm.lk
Malware (2)
  Denial Of Svc (1)
    FDoS-Phasma
  Exploit (1)
    Exploit-CodeBase
Program (13)
  - (1)
    KeyHook.dll
  Demonstration (1)
    Generated.Zombie
  Dialer (2)
    Dialer-198
    Dialer-206
  Generic (2)
    Keylog-Perfect.gen
    ServU-Daemon.gen
  PornDialer (1)
    Dialer-Generic
  Remote Access (1)
    ServU-Daemon
  Win32 (5)
    IdentDaemon
    SQL-Browser
    RemAdm-RemoteAdmin
    AdwareDropper-B
    Generic HTool.a
Trojan (159)
   (2)
    Generic PWS.b
    QHosts-1!hosts
  Application extension (5)
    CoreFlood.dll
    Spy-Tofger.dll
    DDoS-Decill.dll
    Proxy-Mitglieder.dll
    PWS-Dolche.dll
  Configurator (1)
    ServU.cfg
  Denial Of Svc (1)
    IRC/Flood.i
  Downloader (8)
    JS/Cisp
    Proxy-Mitglieder
    Downloader-IU
    Downloader-FG
    ServU.ldr
    AdClicker-AF.dldr
    Downloader-LM
    Downloader-KN
  Dropper (11)
    MultiDropper-GK
    CoreFlood.dr
    VBS/Inor
    PWS-Bancos.dr
    MultiDropper-FD
    PWS-Bancban.dr
    MultiDropper-IY
    VBS/MultiDropper-DZ
    BackDoor-AMQ.dr
    ServU.dr
    VBS/Qdial22.dr
  Exploit (7)
    Exploit-DcomRpc
    VBS/Psyme
    Exploit-URLSpoof
    Exploit-IFrame
    Exploit-MhtRedir.gen
    Exploit-Nocnoc
    Exploit-IIS.cmd
  Flooder (1)
    FDoS-SMSBomb
  Generic (11)
    PWS-Bancban.gen.b
    JS/Seeker.gen.b
    FDoS-Yahoo.gen
    JS/Seeker.gen.h
    PWS-Bancos.gen
    PWS-Bancban.gen.c
    JS/Seeker.gen.a
    JS/IEstart.gen.b
    PWS-Bancos.gen.b
    HackerDefender.gen
    JS/Seeker.gen.n
  Heuristic (6)
    New Downloader
    New BackDoor6b
    New BackDoor6a
    New BackDoor7a
    New BackDoor7b
    New BackDoor6c
  HTML (1)
    HTML/CrashIE
  Internet Relay Chat (2)
    IRC/Flood.c
    IRC-Xevol
  Java Applet (1)
    JV/Shinwow
  JavaScript (1)
    JS/CardStealer
  Linux (12)
    Linux/DoS-Halflife
    Linux/DoS-Hestra
    Linux/DoS-Neon
    Linux/DoS-Melt
    Linux/DoS-Kod
    Linux/DoS-Targ
    Linux/DoS-Darkwar
    Linux/DoS-Scut
    Linux/DoS-Chrome
    Linux/DoS-Sprite
    Linux/DoS-Nocwage
    Linux/DoS-Hella
  Malware Tool (49)
    Spam-BBMail
    Spam-Mimer
    Spam-Charlie
    Spam-Banan
    Spam-Mekanin
    Spam-MFraud
    Spam-FMBomb
    Spam-FMail
    Spam-VDX
    Spam-Stone
    Spam-Sabotage
    Spam-Paramail
    Spam-Emboz
    Spam-EmBomb
    Spam-DMB
    Spam-MCSpam
    Spam-BotSin
    Spam-AnonIM
    Spam-AIMSpam
    Spam-Swyque
    Spam-Pocztyl
    Spam-AdvMail
    Spam-Mobikill
    Spam-Scythe
    Spam-ZPSM
    Spam-AnonMail
    Spam-MailIt
    Spam-HRVG
    Spam-Bomber
    Spam-AnonNS
    Spam-NetSend
    Spam-Robis
    Spam-QMailer
    Spam-Hunter
    Spam-AlienBmb
    Spam-HateYou
    Spam-ICQMass
    Spam-Avril
    Spam-ICQ.Mach
    Spam-ICQ.Nexz
    Spam-Shock
    Spam-XYN
    Spam-Sheker
    Spam-Grad
    Spam-Aneg
    Spam-Bombita
    Spam-Mbomb
    Spam-Alpha
    Spam-Slat
  Password (1)
    HTML/Ebscam
  Password Stealer (1)
    PWS-Dolche
  Remote Access (3)
    Backdoor-AQK
    Backdoor-EE
    BackDoor-AOZ
  Script (14)
    Univ.script/99a
    JS/AdClicker-AF
    VBS/SevenC
    JS/Seeker.o
    JS/DDoS-Yams
    VBS/Seeker.x
    VBS/Seeker.w
    JS/Seeker.y
    JS/Seeker.z
    VBS/IEStart
    Bat/dt130
    JS/Seeker.q
    JS/Harnig
    VBS/Asank
  StartPage (2)
    StartPage-DB
    StartPage-DU
  Win32 (19)
    Generic VB
    Generic Downloader.a
    Reg/Seeker
    Generic FDoS
    Generic BackDoor.f
    Generic Delphi
    Generic Downloader.c
    DDoS-Asm
    HackerDefender.sys
    Generic Nuker
    Generic BackDoor.c
    Generic Del
    IPSpoofer-B
    Generic MultiDropper.a
    Generic VB.c
    DDoS-Boxed
    Generic BackDoor.k
    DoS-OobImiko
    Generic QHosts.a
Virus (197)
   (1)
    OC/vcl
  Companion (1)
    W32/HLL.cmp.Nosyst
  Damaged (3)
    W32/Netsky.q.dam
    W32/Lovgate.dam
    W32/Kuang.dam
  Damaged Parasitic (1)
    W32/Elkern.cav.c.dam
  Damaged Worm (3)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Defaced document Worm (1)
    W32/CodeRed.worm.a.defaced
  Downloader Worm (1)
    W32/Wallon.worm.dldr
  Dropper (1)
    W32/Akez.dr
  E-mail (5)
    W32/Mimail.m@MM
    W32/Mimail.l@MM
    W32/Mimail.t@MM
    W32/Dumaru.ad@MM
    W32/Mydoom.k@MM
  E-mail worm (10)
    W32/Lovgate.f@M
    W32/Mimail.e@MM
    W32/Mimail.gen@MM
    W32/Lehs@MM
    W32/Mimail.c@MM
    W32/Mimail.p@MM
    W32/Dumaru.y@MM
    W32/Lovgate.ad@MM
    W32/Lovgate.af@MM
    W32/Lovgate.ab@MM
  Email (52)
    W32/Mimail.h@MM
    W32/Mimail.g@MM
    W32/Mimail.f@MM
    W32/Dumaru.aa@MM
    W32/Dumaru.z@MM
    W32/Mydoom.i@MM
    W32/Mimail.o@MM
    W32/Mimail.n@MM
    W32/Mimail.d@MM
    W32/Mimail.b@MM
    W32/Mimail.k@MM
    W32/Mimail.a@MM
    W32/Lovgate.b@M
    W32/Lovgate.g@M
    W32/Lovgate.m@M
    W32/Lovgate.n@M
    W32/Smilex@MM
    W32/Waber.c@MM
    W32/Waber.b@MM
    W32/Waber.a@MM
    W32/Noala.a@MM
    W32/Noala.c@MM
    W32/Noala.d@MM
    W32/Dumaru.af@MM
    W32/Dumaru.ab@MM
    W32/Dumaru.ag@MM
    W32/Dumaru.ae@MM
    W32/Dumaru.ah@MM
    W32/Lovgate.q@MM
    W32/Lovgate.p@MM
    W32/Lovgate.v@M
    W32/Lovgate.t@MM
    W32/Lovgate.r@MM!zip
    W32/Lovgate.u@MM
    W32/Lovgate.w@M
    W32/Lovgate.x@MM!zip
    W32/Lovgate.aa@MM!zip
    W32/Lovgate.aa@MM
    W32/Lovgate.ac@MM
    W32/Lovgate.v@MM
    W32/Lovgate.ae@MM
    W32/Mydoom.m@MM
    W32/Lovgate.af@MM!zip
    W32/Mydoom.l@MM
    W32/Lovgate.z@MM!zip
    W32/Dumaru.av@MM
    W32/Lovgate.ad@MM!zip
    W32/Dumaru.al@MM
    W32/Dumaru.ak@MM
    W32/Dumaru.aj@MM
    W32/Lovgate.ab@MM!zip
    W32/Dumaru.ai@MM
  Email Generic (4)
    W32/Sober.gen@MM
    W32/Noala.gen@MM
    W32/Mydoom.gen@MM
    W32/Pereban.gen@MM
  Email Worm (1)
    W32/Lovgate.ag@MM
  Generic (5)
    Bat/BWG.gen
    W32/Graps.gen
    W32/Slaman.gen
    W32/Faker.gen
    W32/Kuang.gen
  Generic Worm (19)
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/CodeRed.worm.gen
    W32/Hopalon.worm.gen
    W32/Sachiel.worm.gen
    W32/Gaobot.worm.gen.l
    W32/Spybot.worm.gen.h
    W32/Spybot.worm.gen.g
    W32/Leox.worm.gen
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.o
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.u
    W32/Korgo.worm.gen
    W32/Gaobot.worm.gen.h
  Heuristic (1)
    New P2P Worm
  Intended (1)
    W32/Dropbox.intd
  Internet Relay Chat (1)
    IRC/Ahack
  Internet Worm (6)
    W32/Tzet.worm
    W32/Alphx.worm.a
    W32/Noala.b@MM
    W32/Gaobot.worm.ali
    W32/Korgo.worm.r
    W32/Gaobot.worm.gen.q
  Malware Tool (1)
    VCL.kit
  mIRC Worm (1)
    W32/Generic.worm!irc
  Overwriting (5)
    W32/HLL.ow.ANT.e
    W32/HLL.ow.ANT.d
    W32/HLL.ow.ANT.c
    W32/HLL.ow.ANT.a
    W32/HLL.ow.ANT.b
  Parasitic (1)
    W32/HLLP.Remcom
  Peer To Peer Worm (3)
    W32/Waxi.worm!p2p
    W32/Losiram.worm!p2p
    W32/Dextro.worm!p2p
  Script (1)
    VBS/Generic
  Universal (1)
    Univ/c
  VbScript (2)
    Unsafe Script
    New Script
  Win32 (27)
    New Win32.g1
    New Poly Win32
    W32/Sober.eml
    New Win32
    W32/Chiton.d
    W32/Akez
    W32/Chir.eml
    W32/Lovgate
    W32/Slaman.a
    W32/Emlinf
    W32/Cist
    W32/Generic.d
    W32/Kamika
    W32/Nimda.http
    W32/Chiton.t
    W32/Chiton.u
    W32/Kuang.f
    W32/Dumaru.au
    W32/Vesic
    W32/Banof
    W32/Dumaru.as
    W32/Dumaru.ar
    W32/Dumaru.aq
    W32/Dumaru.ap
    W32/Dumaru.ao
    W32/Dumaru.an
    W32/Dumaru.am
  Worm (38)
    W32/Lovgate.l@M
    W32/Lovgate.a@M
    W32/Lovgate.c@M
    W32/Lovgate.s@MM
    W32/Lovgate.x@MM
    W32/IIS.worm
    W32/CodeGreen.worm
    W32/Beavuh.worm
    W32/CodeRed.worm.f
    W32/CodeRed.worm.a
    W32/Wallon.worm
    W32/Icasur.worm
    W32/Labirint.worm
    W32/Kergez.worm
    W32/Moklo.worm
    W32/Apove.worm.c
    W32/Apove.worm.b
    W32/Orida.worm
    W32/Daol.worm
    W32/Autex.worm
    W32/Antonio.worm
    W32/Flopcop.worm
    W32/Hotas.worm
    W32/Azha.worm
    W32/Windang.worm
    W32/Moulo.worm
    W32/CodeRed.worm.c
    W32/CodeRed.worm.d
    W32/CodeRed.worm.b
    W32/Dedler.worm
    W32/Korgo.worm.u
    W32/Korgo.worm.t
    W32/Korgo.worm.s
    W32/Korgo.worm.i
    W32/Korgo.worm.v
    W32/Korgo.worm.k
    W32/Korgo.worm.p
    W32/Korgo.worm.q