Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4383
DAT Release Date 08/04/2004
Threats Detected 95980
New Detections 241
Enhanced Detections 296

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Evaman.c@MM Low-Profiled Low-Profiled

New Detections:

Internet Worm (1)
  - (1)
    W32/Mydoom.p@MM
Program (58)
   (12)
    VSource.par
    VMag37
    VMag35
    VMag33
    Tool/tas99
    VMag99
    VMag36
    VMag34
    Tool/sec2
    Tool/sec3
    Tool/sec
    Tool/fmt14
  Dropper (1)
    HTool/HBTool.dr
  Generic (2)
    Dialer-RAS.dk.gen
    Dialer-RAS.dj.gen
  Joke (1)
    Joke-Azuelo
  Malware Tool (30)
    VTool/hop
    HTool/HBTool
    VTool/zyx
    VTool/wdu
    VTool/tiny
    VTool/tas10
    VTool/tas7
    VTool/tas4
    VTool/tas3
    VTool/tas2
    VTool/tas
    VTool/tap
    VTool/sca
    VTool/pyr
    VTool/mkt
    VTool/mak
    VTool/kuang2
    VTool/expl2
    VTool/asm4
    PWCrack-RockXp
    VTool/mfa
    VTool/kyg2
    VTool/dvl2
    VTool/asm5
    VTool/aed
    HTool/rrs
    HTool/samp
    HTool/osq
    HTool/kgn4
    HTool/jav
  Proxy (1)
    Proxy-Safemail
  Script (10)
    VMag16
    Tool/dsme
    Tool/mak
    Tool/mac1
    Tool/ldru
    Tool/cnup2
    Tool/bvd
    Tool/bcc3
    Tool/avc
    Tool/bcc2
  Win32 (1)
    AdClicker-AY
Trojan (74)
  Application extension (2)
    BackDoor-CHI.dll
    Keylog-Memento.dll
  Client (1)
    BackDoor-CHJ.cli
  Configurator (1)
    MultiDropper-LB.cfg
  Demonstration (2)
    JS/Exploit-OnUnload.demo
    JS/Exploit-DragDrop.demo
  Dialer (1)
    QDial25
  Downloader (13)
    Downloader-NK
    Downloader-NN
    Downloader-NL
    Downloader-NJ
    Downloader-NH
    Downloader-NF
    Downloader-NC
    Downloader-NM
    Downloader-NI
    Downloader-NG
    Downloader-NE
    Downloader-ND
    Downloader-NB
  Dropper (2)
    MultiDropper-LB
    Downloader-NE.dr
  Exploit (6)
    Exploit-WebDav.f
    Exploit-WebDav.e
    Exploit-WebDav.d
    Exploit-WebDav.c
    Exploit-WebDav.b
    Exploit-WebDav.a
  Keylogger (2)
    Keylog-Small.b
    Keylog-Memento
  Malware Tool (3)
    Nuke-Medal
    PWS-IT.kit
    Nuke-BomberMan
  Password Stealer (1)
    PWS-IT
  Proxy (1)
    Proxy-StealthRedir
  Remote Access (10)
    BackDoor-CHI
    BackDoor-CHJ.srv
    BackDoor-CHH
    BackDoor-CHG
    BackDoor-CHE
    BackDoor-CHD
    BackDoor-CHB
    BackDoor-CGZ
    BackDoor-TW!chm
    BackDoor-CHA
  Script (14)
    Bat/qd253
    Bat/qd251
    Bat/klw9
    Bat/Lubog
    JS/AdClicker-AO
    Bat/qd256
    Bat/qd255
    Bat/qd254
    Bat/qd252
    Bat/qd250
    JS/Ploit
    BAT/Motuk
    VBS/FtpDown
    Bat/Bock
  Source code (4)
    Keylog-Small.b.src
    Linux/DDoS-Shaft.src
    MultiDropper-LB.src
    Nuke-Medal.src
  StartPage (4)
    StartPage-EK
    StartPage-EJ
    StartPage-EI
    StartPage-EH
  Win32 (7)
    AdClicker-AX
    Smith
    QDesktop-1
    PatchLsass
    ICQPager-U
    W32/Sober.i
    BadFirm
Virus (108)
   (38)
    SMVB
    Odessa.451
    Npox.1483a
    Ever Willing.699
    XRCE
    Xdog.1500
    UB
    TPS.658
    Renegade.1176
    QRes.704
    Paws.690
    Nafig.990
    Mecdon.1470
    Lyli.480
    Kissed.2384a
    Hooks
    Guhha.337
    Flashlight
    Etop.750
    Etop.621
    Etop.580
    Npox.1483b
    Bams.2240
    Xindy.4322
    Tip
    Terronia
    Seat.1868
    Pamyat
    Metallica
    Mad.1108
    Kissed.2384b
    Joe.589
    Etop.577
    Erdem.425
    Dox.3339
    Dear.1436
    CFSK.918
    AD
  Application extension (1)
    W32/Mydoom.dll
  Damaged (1)
    Ace.1872.dam
  Damaged Parasitic (3)
    DarthVader.cav.344.c.dam
    DarthVader.cav.344.a.dam
    DarthVader.cav.344.b.dam
  Dropper (6)
    DarthVader.dr
    Bumblebee.dr
    Terronia.dr
    Pamyat.dr
    Kissed.dr
    PCOgre.dr
  E-mail (1)
    W32/Evaman.c@MM
  Email (6)
    W32/Mydoom.p@MM!zip
    W32/Mydoom.q@MM
    W32/Lovgate.al@MM
    W32/Mabutu.b@MM!zip
    W32/Lovgate.am@MM
    W32/Bugbear.h@MM!zip
  Generic Worm (2)
    W32/Sdbot.worm.gen.x
    W32/Neblso.worm.gen
  Linux (2)
    Linux/Adrastea
    Linux/Amalthea
  multipartite (1)
    Arianna.mp.3076
  Parasitic (38)
    Hobbit.cav.422
    Gadfly.cav.646
    DarthVader.cav.344.b
    Bumblebee.cav.478
    VVM.cav.207
    VVM.cav.205c
    VVM.cav.205a
    Virion.cav.245
    Pip.cav.207
    NMSG.cav
    Ming.cav.360
    Infill.cav.304
    Funk.cav.692
    IOWE.cav.261
    Grog.cav.304
    Gadfly.cav.629
    Dikshev.cav
    DarthVader.cav.344.c
    DarthVader.cav.344.a
    Bumblebee.cav.480
    Bumblebee.cav
    VVM.cav.205b
    VVM.cav.204
    Phoenix.cav.256
    NOKI.cav.448
    NLA.cav.383
    Morality.cav.424
    Exe.cav.384
    Ebb.cav.378
    Ebb.cav.313
    Dragon.cav.400
    Bosco.cav
    Bob.cav.488
    Belorussia.cav.463
    Belorussia.cav.459
    Antia.cav.348
    Antia.cav.333
    Antia.cav.313
  Peer To Peer Worm (1)
    W32/Lemb.worm!p2p
  PowerPoint Macro (2)
    PP97M/Yesi
    PP97M/Amatch
  Remote Access (1)
    W32/Backdoor-CFB
  Script (2)
    VBS/Outcold
    VBS/Chopum
  Win32 (1)
    W32/Bagle.eml!dam
  Worm (2)
    W32/Randon.worm.bd
    W32/ChristA.worm

Enhanced Detections:

Internet Worm (2)
  P2P Worm (1)
    W32/Generic.worm!p2p
  Win32 (1)
    New Worm
Malware (2)
  Exploit (1)
    Exploit-CodeBase
  Win32 (1)
    Nuke-DFM
Program (17)
   (5)
    VSource
    VMag12
    with fishy extension
    VObj1
    Vmag2
  - (2)
    Proxy-OSS
    HideWindow
  Application extension (1)
    PSpy.dll
  Configuration settings (1)
    Joke-DXDlg-FTP.ini
  Dialer (1)
    Dialer-Generic.b
  Malware Tool (3)
    PWCrack-Rainbow
    VTool/mex
    VTool/sme
  PornDialer (1)
    Dialer-Generic
  Remote Access (1)
    ServU-Daemon
  Win32 (2)
    LaSta
    HideExec
Trojan (136)
   (2)
    Generic PWS.b
    Generic BackDoor.d
  - (3)
    IRC/Flood.bi
    IRC/Flood.mirc
    AdClicker
  Application extension (5)
    AFXrootkit.dll
    Downloader-DA.dll
    PWS-LegMir.dll
    BackDoor-WB.dll
    Keylog-MXX.dll
  Application extension Generi (1)
    BackDoor-AXJ.dll.gen
  Client (1)
    BackDoor-Sub7.cli
  Configuration settings (1)
    HackerDefender.ini
  Configurator (5)
    PWS-Sagic.cfg
    BackDoor-Sub7.cfg
    ICQPager-E.cfg
    ICQPager-K.cfg
    Downloader-CL.cfg
  Demonstration (1)
    Exploit-DcomRpc.b.demo
  Downloader (9)
    Proxy-Mitglieder
    Downloader-HZ
    Downloader-GK
    Downloader-EX
    Downloader-CL
    Downloader-JH
    Downloader-MM
    Downloader-LG
    Downloader-KT
  Downloader Generic (1)
    Proxy-FBSR.gen.dldr
  Dropper (8)
    PWS-Bancos.dr
    AFXrootkit.dr
    PWS-LegMir.dr
    BackDoor-Sub7.dr
    MultiDropper-IY
    BackDoor-CGX.dr
    MultiDropper-IM
    Downloader-JD.dr
  E-mail (1)
    W32/Sober.h
  Exploit (11)
    Exploit-DcomRpc
    VBS/Psyme
    Exploit-URLSpoof
    Exploit-ByteVerify
    Exploit-ContentType
    Exploit-MhtRedir.gen
    Exploit-MS04-022
    Exploit-WebDAV
    Exploit-IISWDav
    Exploit-DcomRpc.b
    Exploit-IISWDav.b
  Flooder (1)
    FDoS-Aslike
  Generic (13)
    Exploit-CodeBase.gen
    IRC/Flood.gen.b
    Exploit-URLSpoof.gen
    FDoS-MSN.gen
    PWS-Bancos.gen
    Exploit-IISWDav.gen
    Proxy-Mitglieder.gen
    BackDoor-WB.gen.b
    Proxy-FBSR.gen
    BackDoor-BAC.gen
    Exploit-MS04-011.gen
    AFXrootkit.gen
    PWS-LegMir.gen.e
  Heuristic (2)
    New Malware.d
    New BackDoor7b
  HTML (1)
    JS/Winbomb
  Internet Relay Chat (4)
    IRC/Flood.c
    IRC/Flood.dv
    IRC-Mutin
    IRC/Flood.ej
  Keylogger (1)
    Keylog-MXX
  Malware Tool (15)
    Nuke-Hosp
    Nuke-Elite
    Nuke-DieModem
    Nuke-Click
    Nuke-Hangping
    Nuke-Divine
    Nuke-BlueFire
    Nuke-AOLExp
    Nuke-QQ
    Nuke-Crasher
    Nuke-AIC
    Nuke-Duke
    Nuke-Xobo
    Nuke-NetNuker
    Kalips.kit
  Password (4)
    PWS-Bancos
    PWS-LegMir
    PWS-Sagic
    Keylog-Lodis
  Password Stealer (4)
    PWS-MLD
    PWS-RedZone
    PWS-Tamla
    PWS-Banker
  Plugin component (1)
    BackDoor-Sub7.plugin
  Proxy (1)
    Proxy-Agent.a
  Remote Access (10)
    BackDoor-AZV
    BackDoor-CCL
    BackDoor-AWQ.b
    BackDoor-ATB
    BackDoor-CHC
    BackDoor-Sub7
    Backdoor-EE
    BackDoor-AET
    BackDoor-OR
    BackDoor-CES
  Script (3)
    Univ.script/99a
    Bat/FtpDown
    Bat/nod
  Source code (1)
    Exploit-UtilMan.src
  StartPage (1)
    StartPage-CP
  Win32 (25)
    Generic VB
    Lolaweb
    Generic BackDoor.b
    Reg/Seeker
    HackerDefender
    IPScan
    Generic Downloader.c
    AdClicker-AF
    ICQPager-P
    ICQPager-R
    ICQPager-Q
    ICQPager-F
    ICQPager-E
    ICQPager-D
    ICQPager-H
    StealthBatch
    ICQPager-K
    ICQPager-N
    ICQPager-S
    Tuoraw.b
    Generic VB.c
    MultiDropper-LA
    Generic StartPage.c
    ICQPager-T
    Generic QHosts.a
Virus (139)
   (13)
    Xany
    Bob.448a
    Odessa.716
    Npox.1723
    CyberShadow
    XRCE.604
    Darth-Vader.344
    Harmware.3716
    Harmware.3515
    Tiny
    Nympho.787
    Tiny.135
    Nympho
  Damaged (5)
    Harmware.dam
    W32/Etap.dam
    W32/Lovgate.dam
    W32/Bagle.dam
    W32/Lovgate.x.dam
  Damaged Worm (3)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Dropper (2)
    Univ/j.dr
    W32/Wratch.dr
  E-mail (7)
    W32/Mydoom.b@MM
    W32/Mydoom.h@MM
    W32/Mydoom.e@MM
    W32/Mydoom.o@MM
    W32/Mabutu.b@MM
    W32/Lovgate.ah@MM
    W32/Mydoom.k@MM
  E-mail worm (8)
    W32/Lovgate.f@M
    W32/Generic.a@MM
    W32/Mydoom.g@MM
    W32/Mydoom.f@MM
    W32/Lovgate.ad@MM
    W32/Lovgate.af@MM
    W32/Lovgate.aj@MM
    W32/Lovgate.ab@MM
  Email (25)
    W32/Mydoom.i@MM
    W32/Lovgate.r@MM
    W32/Toal@MM
    W32/Lovgate.b@M
    W32/Lovgate.g@M
    W32/Lovgate.m@M
    W32/Lovgate.n@M
    W32/Mydoom.j@MM
    W32/Lovgate.q@MM
    W32/Lovgate.p@MM
    W32/Lovgate.v@M
    W32/Lovgate.t@MM
    W32/Lovgate.u@MM
    W32/Lovgate.w@M
    W32/Lovgate.aa@MM
    W32/Lovgate.ak@MM
    W32/Mydoom.o@MM!zip
    W32/Lovgate.ac@MM
    W32/Lovgate.v@MM
    W32/Lovgate.ae@MM
    W32/Mydoom.a@MM
    W32/Mydoom.m@MM
    W32/Mydoom.l@MM
    W32/Bagle@MM!vbs
    W32/Bugbear.i@MM
  Email Generic (1)
    W32/Mydoom.gen@MM
  Email Worm (2)
    W32/Lovgate.ai@MM
    W32/Lovgate.ag@MM
  Generic (4)
    W32/Stepan.gen
    W32/Etap.gen
    W32/Bolzano.gen.b
    W32/Sdbot.gen.r
  Generic Worm (17)
    W32/Gaobot.worm.gen.d
    W32/Spybot.worm.gen.e
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.i
    W32/Gaobot.worm.gen.l
    W32/Spybot.worm.gen.g
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.o
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.t
    W32/Sdbot.worm.gen.p
  Heuristic (5)
    New P2P Worm
    New Malware.b
    New Win32.g4
    New Win32.tls
    Unsafe VBS
  Internet Worm (1)
    W32/Gaobot.worm.gen.q
  Macro (1)
    P97M/Phlaco
  mIRC Worm (2)
    W32/Generic.worm!irc
    W97M/Wally.worm
  Overwriting (1)
    Univ.ow/a
  Parasitic (2)
    Bob.cav.448b
    W32/HLLP.15881
  Peer To Peer (1)
    W32/Generic.c!p2p
  Script (1)
    VBS/Gedza
  Universal (2)
    Univ/f
    Univ/j
  Win32 (29)
    New Win32.g5
    New Win32.g6
    New Win32.g1
    New Win32.g3
    New Win32.g2
    New Win32.s
    W32/Bagif
    New Poly Win32
    W32/Stepan.k
    W32/Stepan.j
    W32/Stepan.i
    W32/Stepan.f
    W32/Stepan.d
    W32/Stepan.b
    W32/Deemo.b
    W32/Deemo.a
    W32/Mydoom.f!zip
    New Win32
    W32/Zmist.gen
    W32/Zmist.a
    W32/Etap.d
    W32/Lovgate
    W32/Wratch.b
    W32/Wratch.a
    W32/Generic.b
    W32/Generic.d
    W32/Mydoom.g!zip
    W32/Mydoom.h!zip
    W32/Wallon!html
  Worm (7)
    W32/Lovgate.l@M
    W32/Lovgate.a@M
    W32/Lovgate.c@M
    W32/Lovgate.s@MM
    W32/Lovgate.x@MM
    W32/Dedler.worm
    W32/Gaobot.worm.pp