Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4385
DAT Release Date 08/11/2004
Threats Detected 97156
New Detections 181
Enhanced Detections 521

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (60)
   (14)
    WndManage
    VMag48
    VMag40
    VMag38
    Tool/mirc
    VMag46
    VMag44
    VMag42
    VMag47
    VMag45
    VMag43
    VMag41
    VMag39
    Tool/kgn2
  Dialer (1)
    Dialer-211
  Generic (1)
    Dialer-RAS.dl.gen
  Malware Tool (32)
    PWCrack-MailBRu
    PWCrack-WWWHack
    HTool/BatCrypt
    Nuke-BMurder
    VTool/tas25
    VTool/tas23
    VTool/tas19
    VTool/tas17
    VTool/tas15
    VTool/tas13
    VTool/tas11
    VTool/tas8
    VTool/tas5
    VTool/av44
    HTool/msf
    PWCrack-MCon
    PWCrack-Chanserv
    PWCrack-Hotmail
    Htool/Huc
    VTool/tas99
    VTool/tas24
    VTool/tas22
    VTool/tas20
    VTool/tas18
    VTool/tas16
    VTool/tas12
    VTool/tas9
    VTool/tas6
    VTool/tas21
    VTool/tas14
    VTool/bmb
    VTool/av43
  Script (5)
    Tool/pisda
    Tool/dzd
    Tool/cln
    Tool/des
    Tool/bwu
  Tool (6)
    Tool-Fxmake
    Tool-AOL.Gag
    Tool-Cerberos
    Tool-Domina
    Tool-Fasong
    Tool-Frank
  Win32 (1)
    PortScan-ScannersToy
Trojan (80)
   (3)
    Coff
    B2E/nul
    CGIPager-C
  Application extension (2)
    PWS-Ges.dll
    BackDoor-CHJ.dll
  Configurator (3)
    CGIPager-C.cfg
    BackDoor-CDC.cfg
    IPPager-C.cfg
  Disk erasing (2)
    QZap365
    QZap364
  Downloader (3)
    Downloader-NS
    Downloader-NR
    Downloader-NP
  Dropper (3)
    SymbOS/QDial26.dr
    Bat/prom.g.dr
    BackDoor-BDV.dr
  Exploit (7)
    Exploit-ServU
    Exploit-Messenger
    Exploit-Orenosv
    Exploit-IIS.Ida
    Exploit-Locator
    Exploit-Imail
    Exploit-SQLInj
  Flooder (2)
    FDoS-Punish
    FDoS-ICQ.NWG
  HTML (1)
    HTML/Ebscam.eml
  Internet Relay Chat (2)
    IRC/Flood.en
    IRC/Flood.eo
  Keylogger (2)
    Keylog-Gobi
    Keylog-Melcarr
  Malware Tool (10)
    Spam-Uhbx
    Spam-AEnima
    Nuke-Nukeit.ad
    Nuke-BrosTeam
    Kit-ZeroGrav
    Kit-Mht
    Spam-NiMing
    Nuke-Unreal
    Nuke-Hackeru
    Kit-Yosux
  Password Stealer (2)
    PWS-Msl
    PWS-Drozo
  PDA Device (1)
    SymbOS/QDial26
  Proxy (1)
    Proxy-CyArmy
  Remote Access (17)
    WinCE/BackDoor-CHK
    BackDoor-CHM
    BackDoor-BDV
    BackDoor-BDT
    BackDoor-BDR
    BackDoor-BDN
    VBS/BackDoor-BDM
    BackDoor-BDM
    Linux/BackDoor-Regile
    BackDoor-CHL
    BackDoor-CDC
    BackDoor-BDW
    BackDoor-BDS
    BackDoor-BDQ
    BackDoor-BDP
    BackDoor-BDO
    Bat/BackDoor-BDM
  Script (12)
    Bat/qz137
    Bat/qz136
    Bat/qd257
    Bat/ping
    Bat/mkd28
    Bat/dt132
    Bat/avk32
    JS/Zerolin
    Bat/qz138
    Bat/pass
    Bat/Tecal
    BAT/Noxi
  StartPage (3)
    StartPage-EM
    StartPage-EN
    StartPage-EL
  Win32 (4)
    Reboot-AH
    Generic FDoS.e
    Regger
    Mail-Litter
Virus (41)
   (10)
    Dipper.1021
    PP2
    HLL.Almet
    HLL.Dieter
    HLL.3936
    PHB.display
    Dark Node
    Vanitas.2040
    Staf.2083
    SEEG.458
  Companion (1)
    HLL.cmp.16667
  Companion Dropper (1)
    HLL.cmp.666.drp
  Downloader (1)
    Downloader-NQ
  Downloader Worm (1)
    W32/Myfip.worm.ldr
  Dropper (2)
    Codex.107.drp
    Cesspool.kod.drpd
  E-mail (1)
    W32/Saros@MM
  Email (7)
    W32/Mydoom.r@MM!zip
    W32/Evaman.b@MM
    W32/Evaman.a@MM
    W32/Neveg.b@MM
    W32/Volage@MM
    W32/Plexus.e@MM
    W32/Neveg.a@MM
  Email Generic (1)
    W32/Evaman.gen@MM
  Generic (1)
    Monster.GR
  Script (2)
    Bat/prom.h
    VBS/Yeno
  Win32 (4)
    W32/Dumaru.ax
    W32/Bagle.ap
    W32/Bagle.an
    W32/Bagle.ao
  Worm (9)
    HLLW.Codex.36011
    HLLW.Cesspool.10560
    HLLW.Cesspool.5296
    W32/Randon.worm.bf
    W32/Randon.worm.be
    W32/Myfip.worm
    Bat/Hobat.worm
    W32/Stewon.worm
    W32/Darce.worm

Enhanced Detections:

Internet Worm (3)
  - (1)
    W32/Mydoom.p@MM
  SQL worm (1)
    W32/SQLSlammer.worm
  VbScript (1)
    VBS/Generic@MM
Malware (3)
  Denial Of Svc (1)
    FDoS-Csium
  Exploit (1)
    Exploit-CodeBase
  Win32 (1)
    Nuke-DFM
Program (88)
   (36)
    VSource
    VMag32
    VMag30
    VMag28
    VMag26
    VMag24
    VMag20
    VMag18
    VMag15
    VMag14
    VMag12
    VMag10
    VMag5
    VMag31
    VMag29
    VMag25
    VMag23
    VMag21
    VMag19
    VMag17
    VMag13
    VMag11
    VMag9
    VMag4
    Simulated Virus
    VMag37
    VMag35
    VMag33
    VMag36
    VMag34
    VMag8
    VMag6
    Vmag2
    VMag1
    VMag7
    VMag3
  Adware (1)
    Adware-Holistyc
  Dialer (1)
    Dialer-192
  Downloader (1)
    PosX
  Generic (1)
    Dialer-RAS.by.gen
  Joke (1)
    Joke-Amigo
  Malware Tool (7)
    VTool/rmn
    VTool/tas10
    VTool/tas7
    VTool/tas4
    VTool/tas3
    VTool/tas2
    VTool/tas
  PornDialer (1)
    Dialer-Generic
  Remote Access (1)
    ServU-Daemon
  Script (1)
    VMag16
  Tool (32)
    Tool-Haxor
    Tool-Telnet
    Tool-BODec
    Tool-MacTime
    Tool-Revert
    Tool-HLPDump
    Tool-Analyze
    Tool-AVPX
    Tool-Podonok
    Tool-Pervert
    Tool-QQPassO
    Tool-QQExpl
    Tool-IconHnt
    Tool-CGIScan
    Tool-AutoPol
    Tool-DNSMast
    Tool-AIMRV
    Tool-ZPacker
    Tool-PEStat
    Tool-ZMist
    Tool-COM2UUE
    Tool-CGAGF
    Tool-Jumin
    Tool-Netacess
    Tool-Piaoyes
    Tool-IRXPro
    Tool-MLDE32
    Tool-SNTPTest
    Tool-InfElf
    Tool-PEWrSec
    Tool-ProxiesR
    Tool-Cookie
  Win32 (5)
    iGetNet
    Reboot-AA
    SrvAny
    RemAdm-RemoteAdmin
    Keygen-Orion
Trojan (295)
   (3)
    Generic PWS.b
    Generic BackDoor.d
    B2C/AVKill
  - (3)
    IRC/Flood.bc
    IRC-Deport
    StartPage-B
  Application extension (6)
    CoreFlood.dll
    Spy-Tofger.dll
    StartPage-EF.dll
    PWS-Wexd.dll
    BackDoor-ACH.dll
    PWS-Banker.dll
  Application extension Droppe (1)
    W32/Bagle.dll.dr
  Application extension Generi (1)
    BackDoor-AXJ.dll.gen
  Configurator (3)
    PWS-Sagic.cfg
    Downloader.cfg
    PWS-AIMFake.cfg
  Damaged (1)
    BackDoor-CA.dam
  Demonstration (1)
    JS/Exploit-DialogArg.a.demo
  Downloader (6)
    Downloader-DS
    ServU.ldr
    Downloader-NL
    Downloader-NI
    Downloader-LZ
    Downloader-KN
  Dropper (9)
    VBS/Inor
    PWS-Bancos.dr
    PWS-LegMir.dr
    BackDoor-ACH.dr
    IRC/Flood.cl.dr
    MultiDropper-IM
    W97M/PWS-Hooker.dr
    MultiDropper-KR
    BackDoor-ASB.dr
  Dropper Generic (1)
    IRC-Sdbot.dr.gen
  Exploit (11)
    VBS/Psyme
    Exploit-MS03-043
    Exploit-ByteVerify
    Exploit-IFrame
    Exploit-Dameware
    Exploit-MS04-007
    Exploit-MhtRedir.gen
    Exploit-IIS.Print
    Exploit-IIS.SSLBuff
    JS/Exploit-DialogArg.b
    JS/Exploit-DialogArg.a
  File deleting (1)
    QDel366
  Flooder (62)
    FDoS-SkyFire
    FDoS-MSNCrash
    FDoS-OpDos
    FDoS-Devilos
    FDoS-DKBoom
    FDoS-FReK
    FDoS-MSNFast
    FDoS-P2k
    FDoS-EvilPing
    FDoS-Deface
    FDoS-IRCSpam
    FDoS-Fury
    FDoS-KillZone
    FDoS-Metamorp
    FDoS-Blurred
    FDoS-Overload
    FDoS-ShockWav
    FDoS-DAP
    FDoS-STU
    FDoS-MK3
    FDoS-Blitz20
    FDoS-Wako10
    FDoS-Wako21
    FDoS-LANKill
    FDoS-ARPKill
    FDoS-Rebirth
    FDoS-OIcqDov
    FDoS-NetKill
    FDoS-PortTerm
    FDoS-AdvMSN
    FDoS-Faceless
    FDoS-MrUDP
    FDoS-Sharft
    FDoS-ICQkuf
    FDoS-ShelPing
    FDoS-RoomKill
    FDoS-Destiny
    FDoS-Mega
    FDoS-BlakBlud
    FDoS-MrType
    FDoS-ChiBoy
    FDoS-UnaBomb
    FDoS-BamaBoy
    FDoS-Xoox
    FDoS-DanDan
    FDoS-WarPing
    FDoS-Hasist
    FDoS-Kalibre
    FDoS-ToyBox
    FDoS-AddMngr
    FDoS-WinPopUp
    FDoS-UDPBomb
    FDoS-NetDem
    FDoS-DarkDB
    FDoS-Fofeet
    FDoS-Raptof
    FDoS-FPack
    FDoS-Silent
    FDoS-TNet
    FDoS-GCS
    FDoS-Smurf
    FDoS-Spabot
  Generic (10)
    BackDoor-AGS.gen
    VBS/IEstart.gen.e
    JS/IEstart.gen.d
    PWS-Bancban.gen.b
    IRC/Flood.gen.b
    JS/Seeker.gen.m
    PWS-Bancos.gen
    VBS/RunScript.gen2
    BackDoor-BAC.gen
    Spy-Tofger.gen.b
  Heuristic (2)
    New Malware.d
    New BackDoor7b
  HTML (1)
    JS/Winbomb
  Internet Relay Chat (9)
    IRC/Flood.eb
    IRC/Flood.cl.hidewin
    IRC/Flood.c
    IRC/Flood.dt
    IRC/Flood.cl
    IRC-Contact
    IRC/Flood.f
    IRC/Flood.ap
    IRC-Botty
  JavaScript (1)
    JS/CardStealer
  Malware Tool (66)
    Spam-BBMail
    Spam-Mimer
    Spam-Charlie
    Spam-Banan
    Spam-Mekanin
    Spam-MFraud
    Spam-FMBomb
    Spam-FMail
    Spam-VDX
    Spam-Stone
    Spam-Sabotage
    Spam-Paramail
    Spam-Emboz
    Spam-EmBomb
    Spam-DMB
    Spam-MCSpam
    Spam-BotSin
    Spam-AnonIM
    Spam-AIMSpam
    Spam-Swyque
    Spam-Pocztyl
    Spam-AdvMail
    Spam-Mobikill
    Spam-Scythe
    Spam-ZPSM
    Spam-AnonMail
    Spam-MailIt
    Spam-HRVG
    Spam-Bomber
    Nuke-Hosp
    Nuke-Elite
    Nuke-DieModem
    Nuke-Click
    Nuke-Hangping
    Nuke-Divine
    Nuke-BlueFire
    Spam-AnonNS
    Spam-NetSend
    Spam-Robis
    Spam-QMailer
    Spam-Hunter
    Spam-AlienBmb
    Spam-HateYou
    Spam-ICQMass
    Nuke-AOLExp
    Nuke-QQ
    Nuke-Crasher
    Nuke-AIC
    Spam-Avril
    Spam-ICQ.Mach
    Spam-ICQ.Nexz
    Spam-Shock
    Spam-XYN
    Spam-Sheker
    Spam-Grad
    Spam-Aneg
    Spam-Bombita
    Nuke-Duke
    Nuke-Xobo
    Spam-Mbomb
    Nuke-NetNuker
    Spam-Alpha
    Nuke-Medal
    Nuke-BomberMan
    Spam-Blackhawk
    Spam-Slat
  Password (8)
    PWS-Bancos
    PWS-Narod
    PWS-LegMir
    PWS-QQPass
    PWS-Wexd
    PWS-LDPinch
    BackDoor-AQO
    PWS-Sagic
  Password Stealer (5)
    PWS-Ges
    PWS-AIMFake
    PWS-Banker
    PWS-YAHFake
    PWS-Bolvila
  Remote Access (24)
    BackDoor-AXJ
    BackDoor-AZV
    BackDoor-ASB
    BackDoor-AMQ
    BackDoor-CCL
    BackDoor-AMU
    Linux/BackDoor-Cym
    Linux/BackDoor-Note.b
    Linux/BackDoor-Note.a
    Linux/BackDoor-Small
    BackDoor-AOP
    BackDoor-CBC
    BackDoor-CDY
    BackDoor-BCT
    BackDoor-BCB
    Linux/BackDoor-Promptte
    BackDoor-CHF
    BackDoor-UK
    BackDoor-AQC
    BackDoor-AET
    BackDoor-TC
    BackDoor-ABF
    BackDoor-CDV
    Linux/BackDoor-Oboy
  Script (7)
    Univ.script/99c
    Univ.script/99a
    New CardStealer
    VBS/Piky
    VBS/Bing
    JS/AdClicker-AO
    JS/Seeker.q
  Server (3)
    BackDoor-WF.svr.rmv
    BackDoor-WF.svr
    BackDoor-CA.svr
  Settings Change (2)
    Startpage-N
    StartPage-G
  Source code (1)
    MultiDropper-LB.src
  Spyware (1)
    Spy-Hiddukel
  StartPage (30)
    StartPage-CM
    StartPage-AM
    StartPage-AK
    StartPage-AH
    StartPage-S
    StartPage-P
    StartPage-J
    StartPage-D
    StartPage-AL
    StartPage-AJ
    StartPage-AE
    StartPage-X
    StartPage-R
    StartPage-O
    StartPage-L
    StartPage-I
    StartPage-E
    StartPage-AZ
    StartPage-Z
    StartPage-BE
    StartPage-BD
    StartPage-BH
    StartPage-BM
    StartPage-BY
    StartPage-BV
    StartPage-BU
    StartPage-BZ
    StartPage-DY
    StartPage-DE
    StartPage-DC
  VbScript (1)
    JS/IEstart.gen
  Win32 (15)
    Generic VB
    Reboot-Z
    IRC/Flood.cm
    Generic BackDoor.b
    Generic Delphi
    Generic BackDoor.e
    SennaSpy2001
    DDoS-Keybiz
    Generic PWS.g
    Smith
    PatchLsass
    Mail-Shock
    FillMem
    DDoS-Boxed
    QUrl-2
Virus (132)
   (5)
    needs more cleaning
    HLL
    HLL.Almat
    Monster
    Cesspool.10768
  Companion (2)
    HLL.cmp
    HLL.cmp.17754
  Damaged (2)
    W32/Bagle.dam
    W32/Zafi.b.dam
  Damaged Worm (2)
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Downloader (1)
    Downloader-MV
  Dropper (2)
    Univ/j.dr
    Univ/f.dr
  Dropper Worm (1)
    W32/SQLSlammer.worm.dr
  E-mail (12)
    W32/Mydoom.b@MM
    W32/Mydoom.h@MM
    W32/Mydoom.e@MM
    W32/Dumaru.ad@MM
    W32/Bagle.j@MM
    W32/Bagle.k@MM
    W32/Mydoom.o@MM
    W32/Evaman.c@MM
    W32/Bagle.af@MM
    W32/Bagle.ai@MM
    W32/Bagle.ad@MM
    W32/Mydoom.k@MM
  E-mail worm (14)
    W32/Bagle.n@MM
    W32/Bagle.p@MM
    W32/Bagle.q@MM
    W32/Bagle.t@MM
    W32/Dumaru.y@MM
    W32/Mydoom.g@MM
    W32/Mydoom.f@MM
    W32/Bagle.c@MM
    W32/Bagle.r@MM
    W32/Bagle.s@MM
    W32/Bagle.z@MM
    W32/Bagle.aa@MM
    W32/Bagle.ag@MM
    W32/Bagle.ah@MM
  Email (27)
    W32/Dumaru.aa@MM
    W32/Dumaru.z@MM
    W32/Mydoom.i@MM
    W32/Bagle.al@MM
    VBS/LoveLetter.cu@MM
    W32/Redrac@MM
    W32/Dumaru.af@MM
    W32/Dumaru.ab@MM
    W32/Dumaru.ag@MM
    W32/Dumaru.ae@MM
    W32/Mydoom.j@MM
    W32/Dumaru.ah@MM
    W32/Lovgate.v@M
    W32/Mydoom.p@MM!zip
    W32/Mydoom.o@MM!zip
    W32/Mydoom.a@MM
    W32/Mydoom.m@MM
    W32/Mydoom.l@MM
    W32/Dumaru.av@MM
    W32/Bagle@MM!vbs
    W32/Plexus.c@MM
    W32/Plexus.d@MM
    W32/Plexus.b@MM
    W32/Dumaru.al@MM
    W32/Dumaru.ak@MM
    W32/Dumaru.aj@MM
    W32/Dumaru.ai@MM
  Email Generic (4)
    VBS/Haptime.gen@MM
    W32/Mydoom.gen@MM
    W32/Bagle.gen@MM!pwdzip
    W32/Plexus.gen@MM
  Email Worm (1)
    W32/Mydoom.r@MM
  File Infector (1)
    HLL.CMP.CRAWEN
  Generic (6)
    VBS/Dismissed.gen
    VBS/LoveLetter.gen
    VBS/PIRCHdropper.gen
    VBS/MIRCdropper.gen
    W32/Sdbot.gen.r
    W32/Mkar.gen
  Generic Worm (14)
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gorm.worm.gen
    W32/Sdbot.worm.gen.w
    W32/Gaobot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.o
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.x
    W32/Sdbot.worm.gen.u
    W32/Sdbot.worm.gen.t
    W32/Sdbot.worm.gen.p
  Heuristic (4)
    New AOL
    New Malware.b
    New Script.c
    New Script.d
  Intended (1)
    W32/NGVCK.intd
  Internet Relay Chat (1)
    New IRC.b
  Internet Worm (5)
    W32/Sdbot.worm
    W32/Bagle.d@MM
    JS/Fortnight@M
    W32/Plexus.a@MM
    W32/Gaobot.worm.gen.q
  mIRC Worm (1)
    W32/Protoride.worm
  Open Share Worm (1)
    W32/Dedler.worm.gen
  Peer To Peer (1)
    W32/Generic.c!p2p
  PowerPoint Macro (1)
    PP97M/Yesi
  Remote Access (1)
    W32/Backdoor-CFB
  Script (2)
    VBS/Generic
    JS/Debt
  Universal (1)
    Univ/j
  VbScript (2)
    VBS/Loveletter@MM
    New VBS
  Win32 (13)
    W32/Bagle.o!proxy
    W32/Bagle.aj!proxy
    W32/Generic.d
    W32/Gobi
    W32/Dumaru.aw
    W32/Dumaru.au
    W32/Dumaru.as
    W32/Dumaru.ar
    W32/Dumaru.aq
    W32/Dumaru.ap
    W32/Dumaru.ao
    W32/Dumaru.an
    W32/Dumaru.am
  Worm (4)
    W32/Generic.worm.b
    W32/Frear.worm!txt
    W32/Dedler.worm
    W32/Jared.worm