Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4389
DAT Release Date 09/01/2004
Threats Detected 99465
New Detections 105
Enhanced Detections 547

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Heuristics (1)
  - (1)
    FSG
Program (56)
   (12)
    VMag27
    VSource/mad
    VSource/addv
    VMag54
    VMag52
    VMag51
    VMag50
    VSource/inf
    VMag55
    VMag53
    VMag49
    Tool/mvd
  Malware Tool (25)
    VTool/zbx
    VTool/tas40
    VTool/tas33
    VTool/tas31
    VTool/tas28
    VTool/tas26
    VTool/rpme
    VTool/retro
    VTool/mum
    VTool/hlv
    VTool/cof
    VTool/aav4
    HTool/tft
    HTool/sti
    HTool/msgr
    HTool/fap
    HTool/cop
    VTool/tas34
    VTool/tas32
    VTool/tas30
    VTool/tas27
    VTool/cre5
    VTool/av45
    VTool/99b
    HTool/plu
  Proxy (1)
    Proxy-Speednet
  Script (17)
    Tool/vmag2
    Tool/rem
    Tool/pas
    Tool/mtx
    Tool/mme
    Tool/fcli
    Tool/bcc7
    Tool/bcc6
    Tool/bcc5
    Tool/bat2
    Tool/xpeh
    Tool/vmag
    Tool/psex
    Tool/modem
    Tool/hwin
    Tool/cnup3
    Tool/bcc4
  Win32 (1)
    RemAdm-XNet
Trojan (22)
   (3)
    Generic.b3
    Generic.b2
    Generic.b
  Downloader (6)
    Downloader-OS
    Downloader-OO.txt
    Downloader-ON
    Downloader-OR
    Downloader-OO
    Downloader-OK
  Dropper (1)
    MultiDropper-LG
  Flooder (1)
    FDoS-MsgBoard
  Generic (1)
    FDoS-Spabot.gen
  Internet Relay Chat (1)
    IRC-Proubot
  Remote Access (3)
    Backdoor-CIB
    BackDoor-CIC
    Linux/BackDoor-Rooted
  Script (3)
    Bat/qd258
    Bat/loop22
    Bat/burn
  StartPage (2)
    StartPage-EW
    StartPage-EV
  Win32 (1)
    QHosts-14
Virus (26)
   (5)
    Chad.759
    Wonder.791
    Bughunter
    Busm.3072
    Enola
  Application extension (1)
    W32/HLLP.Tiniresu.dll
  Damaged (2)
    Chad.749.dam
    Life.1491.dam
  Damaged Worm (1)
    W32/Korgo.worm.v.dam
  Email (3)
    W32/Lovgate.ap@MM
    W32/Bugbear.i@MM!zip
    W32/Bugbear.i@MM
  Generic (2)
    W32/Bugfixer.gen
    W32/Bambo.gen
  Generic Worm (1)
    W32/Sdbot.worm.gen.y
  Parasitic (1)
    W32/HLLP.Tiniresu
  Peer To Peer (1)
    W32/Pikis!p2p
  Win32 (3)
    W32/Scard
    W32/Kdar
    W32/Dumaru.ay
  Worm (6)
    W32/Bagle.at@MM
    W32/Sdbot.worm!ftp
    W32/Opaserv.worm.am
    W32/Gislat.worm
    W32/Britney.worm
    W32/Aidid.worm

Enhanced Detections:

Internet Worm (1)
  E-mail worm (1)
    W32/Bugbear.gen@MM
Malware (1)
  Exploit (1)
    Exploit-CodeBase
Program (23)
   (2)
    VMag12
    Vmag2
  Adware (1)
    Downloader-GoldCas
  Dropper (1)
    Vundo.dr
  Internet Relay Chat (1)
    IRC-Bircd
  Macro (2)
    W97M/Perj
    W97M/Quitter
  Malware Tool (11)
    HTool/dialhk3
    VTool/fake
    VTool/tas2
    VTool/tas17
    VTool/tas15
    VTool/tas13
    VTool/tas8
    VTool/tas99
    VTool/tas20
    VTool/tas9
    VTool/tas6
  Remote Access (1)
    ServU-Daemon
  Script (3)
    Tool/bcc
    Tool/bcc3
    Tool/bcc2
  Win32 (1)
    LaSta
Trojan (86)
   (1)
    Phish-BankFraud.eml
  - (3)
    IRC/Flood.bi
    IRC/Flood.bc
    W32/Bagle.dll.dr
  Adware (1)
    Gpix
  Application extension (5)
    CoreFlood.dll
    PWS-Gina.dll
    PWS-Pasorot.dll
    W32/Dumaru.dll
    Keylog-MXX.dll
  Demonstration (1)
    JS/Exploit-DialogArg.a.demo
  Denial Of Svc (1)
    IRC/Flood.ba
  Downloader (2)
    Downloader-EW
    Downloader-OQ
  Dropper (8)
    VBS/Inor
    PWS-Bancos.dr
    PWS-Bancban.dr
    PWS-LegMir.dr
    BackDoor-CBT.dr
    BackDoor-CGX.dr
    IRC/Flood.bi.dr
    Keylog-Spider.dr
  Exploit (4)
    VBS/Psyme
    Exploit-ByteVerify
    JS/Exploit-DialogArg.b
    JS/Exploit-DialogArg.a
  Flooder (13)
    FDoS-Caraf
    FDoS-Kabub
    FDoS-Freekaz
    FDoS-MassMsg
    FDoS-Filter
    FDoS-Tyapo
    FDoS-Maiman
    FDoS-Psycho
    FDoS-Shab
    FDoS-Lanmen
    FDoS-Cybwar
    FDoS-Chat
    FDoS-Mandie
  Generic (9)
    Exploit-CodeBase.gen
    VBS/IEstart.gen.f
    Gaslide.gen
    PWS-Bancos.gen
    Perl/Exploit.gen
    PWS-Bancban.gen.c
    Exploit-MS04-011.gen
    JS/Exploit-DialogArg.gen
    PWS-LegMir.gen.e
  HTML document (1)
    BackDoor-AXJ.htm
  Internet Relay Chat (1)
    IRC/Flood.ap
  JavaScript (1)
    JS/CardStealer
  Keylogger (1)
    KeyLog-MXX
  MS-DOS Batch (1)
    IRC/Flood.bat
  Password (3)
    PWS-Bancos
    PWS-LDPinch
    PWS-Bancban
  Remote Access (11)
    IRC/Flood.c.dr
    Linux/BackDoor-Cym
    Linux/BackDoor-Note.b
    Linux/BackDoor-Note.a
    Linux/BackDoor-Small
    BackDoor-CBT
    Linux/BackDoor-Promptte
    Backdoor-EE
    BackDoor-UK
    Linux/BackDoor-Regile
    Linux/BackDoor-Oboy
  Script (7)
    Univ.script/99b
    Univ.script/99a
    Bat/btg
    JS/Zerolin
    Univ.script/98
    Bat/gotch
    VBS/Asank
  Spyware (1)
    Keylog-Perfect.dr
  StartPage (1)
    StartPage-CD
  Win32 (10)
    HackerDefender
    Generic BackDoor.h
    Uploader-M
    Mail-Shock
    Mail-Litter
    Generic BackDoor.l
    Generic VB.c
    Generic PWS.j
    W32/Nutshell
    FakeSecure
Virus (436)
   (1)
    APM/GreenStripe
  Damaged (50)
    W97M/Sat.dam.d
    W97M/Sat.dam.e
    Univ/f.dam
    W97M/Ethan.dam
    X97M/Hopper.dam.j
    W97M/Hopper.dam.c
    W97M/Hopper.dam.b
    X97M/Laroux.bo.dam
    XM/Laroux.cf.dam
    X97M/Jerk.dam
    W97M/Pri.dam
    W97M/Melissa.dam.a
    W97M/Ethan.dam.f
    W97M/Coldape.dam.f
    W97M/Coldape.dam.d
    W97M/Coldape.dam.b
    W97M/Class.dam.d
    W97M/Class.dam.a
    X97M/Hopper.dam.k
    X97M/Hopper.dam.h
    W97M/Hopper.dam.k
    W97M/Hopper.dam.j
    W97M/Hopper.dam.g
    W97M/Hopper.dam.e
    W97M/Hopper.dam.d
    W97M/Hopper.dam.a
    X97M/Laroux.e.dam
    XM/Laroux.do.dam
    XM/Laroux.bp.dam
    XM/Laroux.dam.au
    W97M/Sat.dam.c
    W97M/Sat.dam.a
    W97M/Marker.dam.e
    W97M/Marker.dam.c
    W97M/Marker.dam.a
    W97M/Ethan.dam.x
    W97M/Ethan.dam.a
    W97M/Groov.dam
    W97M/Brenda.dam.a
    W97M/Sat.dam.b
    W97M/Marker.dam
    W97M/Marker.dam.d
    W97M/Marker.dam.b
    W97M/Coldape.dam.g
    W97M/Coldape.dam.e
    W97M/Coldape.dam.c
    W97M/Coldape.dam.a
    W97M/Class.dam.b
    W97M/Steroid.dam
    W97M/Nottice.dam
  Damaged Worm (3)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Dropper (2)
    W97M/Hopper.q.dr
    VBS/FS.dr
  E-mail (3)
    W32/Dumaru.ad@MM
    W32/Bagle.aq@MM
    W32/Bagle.ai@MM
  E-mail worm (3)
    W32/Dumaru.y@MM
    W32/Bagle.ag@MM
    W32/Bagle.ae@MM
  Email (21)
    W32/Dumaru.aa@MM
    W32/Dumaru.z@MM
    W32/Dumaru.af@MM
    W32/Dumaru.ab@MM
    W32/Dumaru.ag@MM
    W32/Dumaru.ae@MM
    W32/Dumaru.ah@MM
    W32/Bugbear.h@MM!zip
    W32/Bugbear.f@MM
    W97M/Resume@MM
    X97M/Generic@MM
    W97M/Melissa.bf@MM
    W97M/Melissa.ap@MM
    W97M/Ftip@MM
    W97M/Afeto@MM
    W32/Dumaru.av@MM
    W32/Dumaru.al@MM
    W32/Dumaru.ak@MM
    W32/Dumaru.aj@MM
    W32/Bugbear.h@MM
    W32/Dumaru.ai@MM
  Email Generic (2)
    W32/Dumaru.gen@MM
    W97M/Melissa.gen@MM
  File Infector (1)
    CHAD
  Generic (56)
    W97M/Nottice.gen
    X97M/Laroux.nw.gen
    X97M/Barisada.gen
    X97M/Yawn.gen
    X97M/Sugar.f.gen
    X97M/Laroux.jh.gen
    X97M/Laroux.dx.gen
    XM/Laroux.cf.gen
    XM/Laroux.bx.gen
    X97M/Laroux.bp.gen
    XM/Laroux.bp.gen
    XM/Laroux.e.gen
    X97M/Laroux.a.gen
    X97M/Hidemod.gen
    W97M/Thus.gen
    W97M/Steroid.gen
    W97M/Murke.gen
    W97M/Marker.bn.gen
    W97M/Marker.z.gen
    X97M/Laroux.eo.gen
    X97M/Laroux.cf.gen
    X97M/Laroux.bx.gen
    X97M/Laroux.e.gen
    XM/Laroux.a.gen
    W97M/Polygen.gen
    W97M/Titch.a.gen
    W97M/Lupi.gen
    W97M/Locale.gen
    W97M/IIS.gen
    W97M/Hope.gen
    W97M/Evolution.gen
    W97M/Ethan.gen
    W97M/Jerk.gen
    W97M/VMPCK.gen
    W97M/Sherlok.gen
    W97M/Replog.gen
    W97M/Psycode.gen
    W97M/Pri.gen
    W97M/Panther.gen
    W97M/Assilem.gen
    W97M/Marker.ag.gen
    W97M/Marker.p.gen
    W97M/Lulung.gen
    W97M/Lime.gen
    W97M/Hill.gen
    W97M/Groov.gen
    W97M/Footer.gen
    W97M/FF.gen
    W97M/Ethan.f.gen
    W97M/Cont.gen
    W97M/ColdApe.gen
    W97M/Chameleon.gen
    CeCe.GR1
    CeCe.GR2
    X97M/Laroux.au.gen
    W32/Sdbot.gen.r
  Generic Malware Tool (1)
    W97M/HMVC.Kit.gen
  Generic Worm (22)
    W32/Sdbot.worm.gen
    W32/Spybot.worm.gen.e
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.f
    W32/Gaobot.worm.gen.l
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sasser.worm.gen
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.g
    W32/Sdbot.worm.gen.x
    W32/Sdbot.worm.gen.u
    W32/Sdbot.worm.gen.t
    W32/Korgo.worm.gen
    W32/Sdbot.worm.gen.p
    W32/Sdbot.worm.gen.q
    W32/Gaobot.worm.gen.h
  Heuristic (2)
    New Malware.b
    New W97M/Minimal
  Intended (3)
    XM/Trasher.b.intd
    XM/Trasher.a.intd
    W97M/Hope.l.intd
  Internet Worm (10)
    W32/Gaobot.worm.ali
    W32/Sasser.worm.b
    W32/Sasser.worm.c
    W32/Sasser.worm.d
    W32/Sasser.worm.a
    W32/Sasser.worm.e
    W32/Sasser.worm.f
    W32/Sasser.worm.g
    W32/Korgo.worm.r
    W32/Gaobot.worm.gen.q
  Macro (212)
    X97M/Laroux
    X97M/Yawn.n@MM
    XM/Laroux.AF
    XM/Laroux.AE
    XM/Laroux.V
    XM/LAROUX.H
    XM/Laroux.BP
    W97M/Ethan.a
    W97M/Caligula.a
    W97M/Class.Dam
    W97M/Ethan.d
    W97M/IIS.i
    W97M/Ethan.v
    W97M/Astia
    W97M/Marker.v
    W97M/Ethan.al
    W97M/Marker.gen
    X97M/Laroux.A
    W97M/ColdApe.A
    W97M/ColdApe.B
    W97M/Marker.o
    W97M/Hope.a
    W97M/Ethan.at
    W97M/Ethan.q
    W97M/Marker.x
    W97M/Marker.Q
    W97M/Turn
    W97M/Panther
    W97M/Ethan.aw
    W97M/Ethan.src
    W97M/Class.src
    W97M/Pri.q@MM
    W97M/Marker.bn
    W97M/Marker.ab.gen
    W97M/Panther.d
    W97M/Hope.p
    V5M/Radiant
    W97M/Melissa.ao@mm
    W97M/Ethan.bi
    W97M/IIS.e.gen
    W97M/Generic
    W97M/Class.el
    X97M/Laroux.e
    W97M/Class.i
    W97M/Class.f
    X97M/Jini.a1
    W97M/Generic.dam
    X97M/ADN.gen
    W97M/Ostrich.gen
    W97M/Marker.go
    X97M/Remeel
    W97M/Caligula.e
    W97M/Caligula.c
    W97M/Caligula.d
    W97M/Caligula.b
    X97M/Soldier
    XM/Compat
    W97M/Toraja
    XM/Trasher
    W97M/Twno.be
    W97M/Twno.d
    W97M/Twno.ar
    W97M/Twno.ak
    W97M/Twno.af
    W97M/Twno.a
    W97M/Twno.ae
    W97M/Twno.aj
    W97M/Twno.ac
    X97M/Generic
    X97M/Tristate
    X97M/Laroux.cn
    X97M/Laroux.cz
    XM/Laroux.k
    XM/Laroux.g
    XM/Laroux.dd
    XM/Laroux.n
    XM/Laroux.f
    W97M/VMPCK1.ax
    W97M/Marker.eb
    W97M/Marker.cr
    W97M/Marker.de
    W97M/Marker.cl
    W97M/Marker.cp
    W97M/Marker.ck
    W97M/Marker.cj
    W97M/Marker.aj
    W97M/Marker.am
    W97M/Marker.af
    VBA/Generic
    W97M/Tristate
    XM/Trasher.e
    XM/Trasher.d
    XM/Trasher.c
    X97M/Laroux.go
    XM/Laroux.cn
    X97M/Laroux.bp
    X97M/Laroux.ae
    XM/Laroux.cz
    XM/Laroux.j
    XM/Laroux.e
    X97M/Laroux.dd
    X97M/Laroux.bw
    X97M/Laroux.x
    X97M/Laroux.u
    X97M/Laroux.l
    X97M/Laroux.f
    X97M/Laroux.d
    X97M/Laroux.c
    X97M/Laroux.b
    XM/Laroux.gt
    XM/Laroux.db
    XM/Laroux.dy
    XM/Laroux.bw
    XM/Laroux.bk
    XM/Laroux.r
    XM/Laroux.o
    XM/Laroux.i
    XM/Laroux.c
    XM/Laroux.a
    W97M/Shiver
    VBA/Cats
    W97M/Proverb.o
    W97M/Outlaw
    W97M/NJ-DLK1.h
    W97M/MVDK1.a
    W97M/Mercy
    W97M/Marker.ad
    W97M/Marker.ac
    W97M/Marker.bg
    W97M/Marker.a
    W97M/IIS.f
    W97M/Hope.s
    W97M/Hope
    W97M/Hope.m
    W97M/Hope.k
    W97M/Hope.h
    W97M/Hope.g
    W97M/Hope.f
    W97M/Hope.d
    W97M/Hope.b
    W97M/FutureN
    W97M/Ethan.bs
    XM/Laroux.p
    XM/Laroux.d
    XM/Laroux.b
    VBA/Kolera
    W97M/Proverb.d
    W97M/Panther.e
    W97M/NJ-DLK1.a
    W97M/Marker.dq
    W97M/Marker.ft
    W97M/Marker.ay
    W97M/Marker.br
    W97M/Marker.bf
    W97M/Marker.n
    W97M/Marker.b
    W97M/IIS.h
    W97M/Hope.q
    W97M/Hope.u
    W97M/Hope.t
    W97M/Hope.r
    W97M/Hope.n
    W97M/Hope.j
    W97M/Hope.i
    W97M/Hope.e
    W97M/Hope.c
    W97M/Ethan.dg
    W97M/Ethan.da
    W97M/Ethan.cb
    W97M/Ethan.bx
    W97M/Ethan.ba
    W97M/Ethan.aj
    W97M/Ethan.ae
    W97M/Ethan.ab
    W97M/Ethan.aa
    W97M/Ethan.x
    W97M/Ethan.n
    W97M/Ethan.h
    W97M/ColdApe.aa
    W97M/ColdApe.t
    W97M/ColdApe.l
    W97M/ColdApe.j
    W97M/ColdApe.e
    W97M/ColdApe.d
    W97M/ColdApe.c
    W97M/Class.dh
    W97M/Class.cp
    W97M/Class.br
    W97M/Class.dt
    W97M/Class.ec
    W97M/Class.df
    W97M/Class.bs
    W97M/Class.s
    W97M/Class.bo
    W97M/Class.ey
    W97M/Class.cf
    W97M/Class.ce
    W97M/Ethan.cz
    W97M/Ethan.dc
    W97M/Ethan.cu
    W97M/Ethan.ct
    W97M/Ethan.w
    W97M/ColdApe.v
    W97M/Class.dm
    W97M/Class.eb
    W97M/Class.av
    W97M/Class.ao
    W97M/Class.ar
    W97M/Class.as
    W97M/Class.o
    W97M/Class
    W97M/Camel
  Malware Tool (2)
    W97M/Polygen.Kit
    W97M/Ump.Kit.c
  MAPI (1)
    W97M/Generic@mm
  Peer To Peer (1)
    W32/Generic.c!p2p
  PowerPoint Macro (1)
    PP97M/Tristate
  Script (1)
    VBS/Generic
  Source code (9)
    O97M/Shiver.src
    W97M/Verlor.src
    W97M/Marker.src.e
    W97M/Marker.src.c
    W97M/Marker.src.b
    W97M/Marker.src.a
    W97M/Marker.src.d
    W97M/Cont.src
    W97M/Coldape.src
  Universal (1)
    Univ/j
  Win32 (11)
    New Poly Win32
    W32/Dumaru.ax
    W32/Dumaru.aw
    W32/Dumaru.au
    W32/Dumaru.as
    W32/Dumaru.ar
    W32/Dumaru.aq
    W32/Dumaru.ap
    W32/Dumaru.ao
    W32/Dumaru.an
    W32/Dumaru.am
  Worm (17)
    W32/Generic.worm.b
    W32/Korgo.worm.ab
    W32/Korgo.worm.aa
    W32/Korgo.worm.ac
    W32/Arghast.worm
    W32/Korgo.worm.ad
    W32/Korgo.worm.z
    W32/Korgo.worm.x
    W32/Korgo.worm.y
    W32/Korgo.worm.u
    W32/Korgo.worm.t
    W32/Korgo.worm.s
    W32/Korgo.worm.i
    W32/Korgo.worm.v
    W32/Korgo.worm.k
    W32/Korgo.worm.p
    W32/Korgo.worm.q