Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4380
DAT Release Date 07/21/2004
Threats Detected 94340
New Detections 221
Enhanced Detections 342

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Atak.b@MM Low-Profiled Low-Profiled

New Detections:

Program (8)
   (1)
    AddUser-F
  Dialer (1)
    Dialer-RAS.di
  Downloader (1)
    Downloader-MR
  Tool (1)
    Tool-KrimNot
  Win32 (4)
    RemAdm-InCtrl
    RemAdm-WinUpNet
    FPipe
    Delshare.i
Trojan (44)
   (3)
    AdClicker-AT
    AdClicker-AS
    AdClicker-AU!hosts
  Application extension (3)
    AdClicker-AU.dll
    BackDoor-CGU.dll
    StartPage-EF.dll
  Application extension Generi (1)
    PWS-Bancban.dll.gen
  Downloader (4)
    Downloader-MU
    Downloader-MS
    Downloader-MT
    Downloader-MQ
  Dropper (7)
    PWS-WebMoney.dr.a
    IRC/Flood.el.dr
    MultiDropper-KW
    MultiDropper-KU
    IRC-Mutin.dr
    MultiDropper-KV
    VBS/QDial22.dr
  Exploit (3)
    Exploit-InvCSS
    Linux/Exploit-Gildo
    Linux/Exploit-A
  File deleting (1)
    B2E/QDel6
  Internet Relay Chat (1)
    IRC/Flood.el
  Proxy (1)
    Proxy-Dfsmgr
  Remote Access (5)
    BackDoor-CGS
    Linux/BackDoor-Promptte
    BackDoor-CGW
    BackDoor-CGU
    Linux/BackDoor-Oboy
  Script (10)
    Bat/ftpd
    Bat/bried
    BackDoor-CGW.bat
    Bat/qz134
    Bat/qd247
    Bat/chic
    Bat/ank
    Bat/FtpDown
    Bat/qd248
    Tutto.bat
  StartPage (2)
    StartPage-EF
    StartPage-EE
  Win32 (3)
    Tutto
    Del-456
    AdClicker-AU
Virus (169)
   (129)
    Xany.314
    Wormsign
    VCL.Quake.627
    Smallpox.740
    Sepultura.206
    Rubbit.3285a
    Redarc.665
    Redarc.386
    Piz.2036
    Piz.1176
    Paraguay.1650
    Jeru.1280
    Harlot.5632g
    Harlot.5632e
    Harlot.5632b
    Harlot.5632a
    Harlot.5632d
    Harlot.5632c
    Harlot.4096
    Harlot.738
    Golgi.820
    Golgi.608
    Golgi.605
    Golgi.467
    Golgi.385
    Exun
    Evul.805
    Delta
    Deadhead.1000c
    Deadhead.1000b
    Deadhead.1000a
    Deadhead.992
    Batman.6144
    Andy
    Zogzog.915
    Yard.448
    XRCE.822
    VCM.364
    TYGD.3072
    Tgasc.354
    Suela.1042
    SizOrt.1141
    Second Half.333
    Reminder.521
    Reminder.402
    Rake.975
    QRes.224b
    PP.2344
    Pick.843
    Ninny.316
    Lurker.546
    Kim.1000
    Jura
    July14.512
    Jet.544
    Enigma.1624
    DV.1895
    Doom.1249
    Dictum.646
    Danny.872
    Black-Daddy.1321.b
    Beeper.957
    Basho.431
    April.748
    AntiCachacha.400
    ADT.1778
    ADT.1126
    A2KM/Lea
    Omsk
    Nauti.1873
    Mutant.1778
    Mind.1758
    Megadeath.665
    LLO.281
    Lightness.1628
    IOS.1290
    Gee Zee.464
    Fire.2154
    Abdo.307
    PP1
    Kadav.506
    Hider.599
    Gu.1594
    Five Mins.891
    Devil.600
    Drava
    Crypt.818
    Black-Daddy.1321.a
    Beda.609
    Atom.580
    Antiwin.2305
    Angry.2132
    ADT.1765
    ADT.1107
    Aardwolf
    YD.1961
    Touch.1798
    Slowdog.2000
    Rubbit.3285b
    Rubbit.3164
    Redarc.623
    Queen Bee
    Piz.2025
    Paraguay.2618
    Orinoco
    Iam
    Harlot.5632h
    Harlot.5632f
    Harlot.1280
    Deadhead.1000d
    Blind.549
    ARCV.330
    Arianna.3076
    Zwick.505
    Yoni.659
    XRF
    Uxpro.1318
    TTQ.1009
    Tea Party.1609
    Reminder.400
    Quiz.494
    QRes.224a
    Pick.1034
    Nympho
    Nekr.2546
    Nady
    Moonlock.493
    Mehr.786
    Knave
  Boot (1)
    Spyryted
  Boot dropper (2)
    BtDr.Spyryted
    BtDr.Asterisk
  Damaged (3)
    July14.512.dam
    Wormsign.1710.dam
    VS.944.dam
  Downloader (1)
    Downloader-MV
  Dropper (4)
    Harlot.dr
    Evul.805.dr
    ARCV.330.dr
    WinCE/Duts.1520.dr
  E-mail worm (1)
    W32/Atak.b@MM
  Email (2)
    W32/Atak.c@MM
    W32/Atak.a@MM
  Email Generic (1)
    W32/Atak.gen@MM
  Generic (2)
    W32/Bagle!eml.gen
    Won.GR
  Generic Worm (1)
    W32/Gorm.worm.gen
  Linux (2)
    Linux/Thebe
    Linux/Cassini
  Macro (1)
    W97M/VGV
  Parasitic (2)
    Pick.843.cav
    WinCE/Duts.1520
  Script (5)
    Bat/Tiba
    Bat/Dolsat
    VBS/DDoS-Wife
    W32/Bagle.vbs
    W97M/Evow.bat
  Win32 (8)
    W32/Polybot.bw
    W32/Polybot.bu
    W32/Sober.g!zip.eml
    W32/Polybot.bx
    W32/Polybot.bv
    W32/Polybot.bt
    W32/Sality.l
    W32/Fugor
  Worm (4)
    W32/Randon.worm.bc
    W32/Korgo.worm.ab
    W32/Randon.worm.bb
    W32/Korgo.worm.aa

Enhanced Detections:

Internet Worm (9)
  E-mail worm (6)
    W32/Netsky.i@MM
    W32/Netsky.b@MM
    W32/Netsky.t@MM
    W32/Netsky.s@MM
    W32/Netsky.c@MM
    W32/Netsky.a@MM
  VbScript (1)
    VBS/Generic@MM
  Win32 (1)
    New Worm
  Worm (1)
    W32/Polybot.gen!irc
Malware (1)
  Exploit (1)
    Exploit-CodeBase
Program (11)
   (4)
    VObj10
    VObj9
    VObj8
    VObj7
  Dialer (1)
    Dialer-Generic.b
  Downloader (1)
    PosX
  PornDialer (1)
    Dialer-Generic
  Remote Access (1)
    ServU-Daemon
  Win32 (3)
    HiddenRun
    RemAdm-RemoteAdmin
    SimpelFTP
Trojan (118)
   (5)
    Generic PWS.b
    Sunset
    Plasming
    Generic Keylogger
    Generic Downloader.e
  - (1)
    AdClicker-O
  Application extension (1)
    PWS-LDPinch.dll
  Configurator (2)
    MultiDropper.cfg
    MultiDropper-JG.cfg
  Demonstration (1)
    JS/Exploit-DialogArg.a.demo
  Denial Of Svc (1)
    IRC/Flood.ba
  DOS (1)
    Unsafe COM
  Downloader (4)
    AdClicker-AF.dldr
    Downloader-MA
    JS/Keylog-Briss.ldr
    Downloader-KZ
  Dropper (3)
    PWS-Bancos.dr
    PWS-LegMir.dr
    Downloader-AE.dr
  Exploit (31)
    VBS/Psyme
    Exploit-ByteVerify
    Linux/Exploit-SendMail
    Linux/Exploit-Bind
    Linux/Exploit-Cgiexp
    Linux/Exploit-Kerio
    Linux/Exploit-Shellcode
    Linux/Exploit-Freeze
    Linux/Exploit-Sqlexp
    Linux/Exploit-Adminer
    Linux/Exploit-Ciscer
    Linux/Exploit-Mulexp
    Linux/Exploit-BOrifice
    Linux/Exploit-Httpd
    Linux/Exploit-Gdslock
    Linux/Exploit-TearDrop
    Linux/Exploit-OpenSSH
    Linux/Exploit-Nhttpd
    Linux/Exploit-Modgz
    Linux/Exploit-SSPing
    Linux/Exploit-Openssl
    Linux/Exploit-Imspd
    Linux/Exploit-Rsync
    Linux/Exploit-Apache
    Exploit-MhtRedir.gen
    Linux/Exploit-Su
    Exploit-MS03-007
    Linux/Exploit-Vertex
    Exploit-Utilman
    JS/Exploit-DialogArg.b
    JS/Exploit-DialogArg.a
  File deleting (1)
    QDel365
  Generic (9)
    VBS/IEstart.gen.e
    VBS/IEstart.gen.f
    PWS-Bancban.gen.b
    Keylog.gen
    PWS-Bancos.gen
    Exploit-ObjectData.gen
    DDoS-Asm.gen
    W32/Sdbot.gen.r
    PWS-LegMir.gen.e
  Malware Tool (1)
    PWS-QQSender.kit
  Parasitic (1)
    Qhosts.apd
  Password (6)
    PWS-Bancos
    PWS-Sincom
    PWS-LDPinch
    PWS-Bancban
    HTML/Ebscam
    PWS-WebMoney.gen
  Password Stealer (2)
    PWS-QQSender
    PWS-Bamer
  Proxy (1)
    Proxy-FBSR
  Remote Access (14)
    Backdoor-CAK
    BackDoor-AZV
    BackDoor-UK.gen
    Linux/BackDoor-Cym
    Linux/BackDoor-Note.b
    Linux/BackDoor-Note.a
    Linux/BackDoor-Small
    BackDoor-AOZ
    BackDoor-CDV
    BackDoor-CGV
    BackDoor-OR
    BackDoor-ACR
    BackDoor-CAK.eml
    BackDoor-CGT
  Script (3)
    Univ.script/99a
    JS/Harnig
    Bat/avk31
  Spam (1)
    AIM-Lowdown
  StartPage (1)
    StartPage-DC
  Win32 (28)
    Generic VB
    IRC/Flood.cm
    AdClicker-AA
    AdClicker-V
    AdClicker-Q
    AdClicker-Y
    AdClicker-T
    AdClicker-N
    AdClicker-K
    Generic Downloader.a
    Generic BackDoor.b
    AdClicker-AI
    Generic BackDoor.h
    AdClicker-J
    Generic Delphi
    AdClicker-AF
    AdClicker-L
    AdClicker-AE
    DDoS-Asm
    Generic BackDoor.c
    Generic VB.b
    QHosts-9
    AdClicker-AK
    AdClicker-AL
    Kaland
    AdClicker-AN
    Generic BackDoor.j
    Generic QHosts.a
Virus (203)
   (13)
    OC/vcl
    Supervisor
    MPC
    MtE
    Light
    Lesson
    Menuet/Xymo
    YD.1905
    Vas.GFT.2153
    Spanska
    Paraguay
    First.343
    WS
  Application extension (1)
    W32/Finaldo.dll
  Damaged (5)
    W32/Netsky.q.dam
    W32/Lovgate.dam
    W32/Netsky.c.dam
    W32/Polybot.dam
    W32/Lovgate.x.dam
  Damaged Worm (3)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Defaced document Worm (1)
    W32/CodeRed.worm.a.defaced
  Dropper (5)
    Suriv.dr
    Univ/a.dr
    Univ/j.dr
    Univ/r.dr
    Rael.dr
  E-mail (12)
    W32/Netsky.w@MM
    W32/Netsky.q@MM
    W32/Netsky.u@MM
    W32/Netsky.g@MM
    W32/Netsky.l@MM
    W32/Netsky.k@MM
    W32/NetSky.h@MM
    W32/Netsky.v@MM
    W32/Netsky.y@MM
    W32/Netsky.z@MM
    W32/Netsky.ab@MM
    W32/Lovgate.ah@MM
  E-mail worm (13)
    W32/Lovgate.f@M
    W32/Netsky.n@MM
    W32/Netsky.j@MM
    W32/Netsky.o@MM
    W32/Netsky.x@MM
    W32/Netsky.e@MM
    W32/Netsky.f@MM
    W32/Netsky.d@MM
    W32/Netsky.ac@MM
    W32/Lovgate.ad@MM
    W32/Lovgate.af@MM
    W32/Lovgate.aj@MM
    W32/Lovgate.ab@MM
  Email (17)
    W32/Lovgate.b@M
    W32/Lovgate.g@M
    W32/Lovgate.m@M
    W32/Lovgate.n@M
    W32/Lovgate.q@MM
    W32/Lovgate.p@MM
    W32/Lovgate.v@M
    W32/Lovgate.t@MM
    W32/Lovgate.u@MM
    W32/Lovgate.w@M
    W32/Netsky.ad@MM
    W32/Lovgate.aa@MM
    W32/Lovgate.ac@MM
    W32/Lovgate.v@MM
    W32/Lovgate.ae@MM
    W32/Hardoc@MM
    W32/Netsky.af@MM
  Email Worm (3)
    W32/Netsky.aa@MM
    W32/Lovgate.ai@MM
    W32/Lovgate.ag@MM
  File Infector (5)
    Ionkin
    Golgi.465
    Deicide
    Sistor
    Hati.648
  Generic (2)
    W32/Slaman.gen
    X97M/Laroux.au.gen
  Generic Worm (25)
    W32/Sdbot.worm.gen
    W32/Spybot.worm.gen.e
    W32/Gaobot.worm.gen.k
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/CodeRed.worm.gen
    W32/Spybot.worm.gen.i
    W32/Spybot.worm.gen.a
    W32/Gaobot.worm.gen.l
    W32/Tumbi.worm.gen.b
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.o
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.g
    W32/Sdbot.worm.gen.u
    W32/Sdbot.worm.gen.t
    W32/Sdbot.worm.gen.p
    W32/Sdbot.worm.gen.q
    W32/Gaobot.worm.gen.h
  Internet Worm (5)
    W32/Sdbot.worm
    W32/Polybot.l!irc
    W32/Gbot.worm
    W32/Gaobot.worm.ali
    W32/Gaobot.worm.gen.q
  mIRC Worm (1)
    W32/Protoride.worm
  MS Office Suite (1)
    VBA/Generic.src
  Script (1)
    Bat/flm
  Universal (3)
    Univ/b
    Univ/a
    Univ/j
  VbScript (1)
    New Script
  Win32 (73)
    New Poly Win32
    New Win32
    W32/Paps
    W32/Lovgate
    W32/Slaman.a
    W32/Generic.d
    W32/Polybot.ag
    W32/Polybot.v
    W32/Polybot.t
    W32/Polybot.s
    W32/Polybot.r
    W32/Polybot.q
    W32/Polybot.o
    W32/Polybot.n
    W32/Polybot.m
    W32/Polybot.k
    W32/Polybot.j
    W32/Polybot.i
    W32/Polybot.h
    W32/Polybot.g
    W32/Polybot.f
    W32/Polybot.e
    W32/Polybot.c
    W32/Polybot.a
    W32/Polybot.u
    W32/Polybot.d
    W32/Polybot.b
    W32/Polybot.ae
    W32/Polybot.ac
    W32/Polybot.aa
    W32/Polybot.y
    W32/Polybot.w
    W32/Polybot.ad
    W32/Polybot.ab
    W32/Polybot.z
    W32/Polybot.x
    W32/Polybot.af
    W32/Polybot.am
    W32/Polybot.aj
    W32/Polybot.an
    W32/Polybot.al
    W32/Polybot.ai
    W32/Polybot.bs
    W32/Polybot.bo
    W32/Polybot.bn
    W32/Polybot.bm
    W32/Polybot.bl
    W32/Polybot.bk
    W32/Polybot.bf
    W32/Polybot.bq
    W32/Polybot.bp
    W32/Polybot.br
    W32/Polybot.bb
    W32/Polybot.ba
    W32/Polybot.bg
    W32/Polybot.be
    W32/Polybot.bd
    W32/Polybot.bc
    W32/Polybot.bh
    W32/Polybot.bj
    W32/Polybot.bi
    W32/Polybot.az
    W32/Polybot.ay
    W32/Polybot.ax
    W32/Polybot.av
    W32/Polybot.aw
    W32/Polybot.au
    W32/Polybot.as
    W32/Polybot.aq
    W32/Polybot.ao
    W32/Polybot.at
    W32/Polybot.ar
    W32/Polybot.ap
  Worm (13)
    W32/Lovgate.l@M
    W32/Lovgate.a@M
    W32/Lovgate.c@M
    W32/Lovgate.s@MM
    W32/Lovgate.x@MM
    W32/CodeRed.worm.f
    W32/CodeRed.worm.a
    W32/CodeRed.worm.c
    W32/CodeRed.worm.d
    W32/CodeRed.worm.b
    W32/Dedler.worm
    W32/Lemoor.worm
    W32/Yesenio.worm