Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4390
DAT Release Date 09/08/2004
Threats Detected 99978
New Detections 168
Enhanced Detections 291

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
Uploader-S Low-Profiled Low-Profiled

New Detections:

Internet Worm (1)
  Email Worm (1)
    W32/MyWife.c@MM
Program (29)
   (13)
    IMIServer
    VMag66
    VMag64
    VMag63
    VMag62
    VMag60
    VMag56
    Tool/lam
    VMag65
    VMag61
    VMag59
    Tool/uvp
    Tool/cof
  Dialer (2)
    Dialer-Generic.d
    Dialer-Generic.c
  Dropper (1)
    Keylog-Ardamax.dr
  Joke (1)
    Joke-MovingWindow
  Malware Tool (11)
    HTool/SQLExec
    Nuke-Nabber
    HTool/GetInjectProc
    VTool/obs
    VTool/ivp2
    HTool/ida
    VTool/rpme2
    VTool/luc
    VTool/fda
    VTool/aux
    HTool/cfd
  Script (1)
    Tool/dse
Trojan (59)
   (1)
    Ding-Ding
  Application extension (3)
    Uploader-S.dll
    PWS-Seny.dll
    BackDoor-CIO.dll
  Downloader (12)
    Downloader-PF
    Downloader-PE
    Downloader-PD
    Downloader-PA
    Downloader-OY
    Downloader-OW
    Downloader-OU
    Downloader-PB
    Downloader-OZ
    Downloader-OX
    Downloader-OV
    Downloader-OT
  Downloader Generic (1)
    Downloader-PG
  Dropper (6)
    MultiDropper-LJ
    MultiDropper-LI
    MultiDropper-LH
    StartPage-DP.dr
    PWS-Seny.dr
    BackDoor-CIJ.dr
  Exploit (3)
    UNIX/Exploit-Axis
    JS/Exploit-DragDrop.b
    Exploit-Syfi
  Flooder (3)
    JV/FDoS-BirdChat
    FDos-Servu
    FDoS-ChatAnywhere
  Internet Relay Chat (1)
    IRC-Mosey
  Keylogger (1)
    Keylog-YSpy
  Malware Tool (1)
    Nuke-PainKill
  Password Stealer (1)
    PWS-EyeOnIE
  Remote Access (13)
    BackDoor-CIO
    BackDoor-CIN
    BackDoor-CIL
    BackDoor-CIJ
    BackDoor-CII
    BackDoor-CIF
    BackDoor-CID
    BackDoor-BCB!chm
    BackDoor-CIM
    BackDoor-CIK
    BackDoor-CIG
    BackDoor-CIE
    BackDoor-CHY
  Source code (3)
    Nuke-PainKill.src
    JV/FDoS-BirdChat.src
    FDoS-ChatAnywhere.src
  Win32 (10)
    XCacher
    WitchDoc
    Uploader-S
    QLowZones-2
    QLowZones-1
    Generic StartPage.e
    Generic Dropper.d
    Colem
    AdClicker-BA
    AdClicker-BB
Virus (79)
   (46)
    Xany.411
    Xany.142
    Wilbur.e
    Riot.812
    Noon.1163
    Chaos-Year.1837
    Caco.3310.b
    Caco.2965
    Xexe.123
    Ncu-li.1689
    JTD.737
    FF.Mosq
    Yeke
    Xany.415b
    Xany.415a
    Xany.216c
    Wilbur
    Retaliator.1544
    Retaliator
    Phoenix.1226 dr
    Oolong
    Noon.1666
    Leda.820
    Chaos-Year.2005
    Caco.3310.a
    XRes.655
    Xexe.126
    Vimom.339
    Twinny.4855
    TPVO.Pitch.1329
    Tiny.247
    Terror.921i
    Rust.1710
    Nuc.518
    Nihil
    Hybris
    Dre.756
    Dark-Revenge.1024
    Cow.886
    Cawber.2138
    Cantando.857
    Boso.1388
    Deadman.192
    Carnivore.504
    Boso.1636
    Boso.1037
  Application extension (2)
    W32/MyWife.dll
    W32/Mydoom.t.dll
  Boot (1)
    EBase
  Boot dropper (1)
    BtDr.Ping
  Damaged (6)
    Keypress.Ufo.dam
    Maus.1888.dam
    Vienna.743.dam
    Amoeba.1392.dam
    Dre.756.dam
    Angra.dam
  Damaged Worm (2)
    W32/Korgo.worm.p.dam
    W32/Korgo.worm.s.dam
  Dropper (1)
    TPVO.Pitch.1329.dr
  Dropper multipartite (2)
    Neuroquila.mp.dr.b
    Neuroquila.mp.dr.a
  Email (1)
    W32/Mydoom.t@MM!zip
  Generic (1)
    W32/Zepp.gen
  Macro (1)
    W97M/Crappie
  Malware Tool (1)
    TMAK.kit
  multipartite (1)
    Necrosis.mp
  Overwriting (2)
    Dre.ow.192
    W32/Brof.ow
  Parasitic (1)
    Cow.886.cav
  Win32 (5)
    W32/Nofear
    W32/NGVCK.a.1222
    W32/Dumaru.ba
    W32/Cabanas.g
    W32/Bagle.au!troj
  Worm (5)
    W32/Mydoom.t@MM
    W32/Randon.worm.bi
    W32/Meedye.worm
    W32/Helex.worm
    W32/Cocoazul.worm

Enhanced Detections:

Internet Worm (2)
  - (1)
    W32/Mydoom.p@MM
  VbScript (1)
    VBS/Generic@MM
Malware (2)
  Exploit (2)
    Exploit-IIS.Crack
    Exploit-CodeBase
Program (36)
   (5)
    VMag54
    VMag51
    VMag50
    VMag55
    VMag49
  - (2)
    HideWindow
    IMIServer.download
  Adware (1)
    Adware-Lop
  Application extension (1)
    Vundo.dll
  Dialer (1)
    Dialer-Generic.b
  Downloader (2)
    Downloader-EAccel
    Adware-Lop.dldr
  Keylogger (1)
    Keylog-Ardamax
  Malware Tool (12)
    VTool/mis
    VTool/tas4
    VTool/tas17
    VTool/tas15
    VTool/tas8
    VTool/tas99
    VTool/tas20
    VTool/tas9
    VTool/tas6
    VTool/tas33
    VTool/tas26
    VTool/tas27
  Password (1)
    PWCrack-Cain
  PornDialer (1)
    Dialer-Generic
  Remote Access (1)
    ServU-Daemon
  Script (4)
    Tool/bcc2
    Tool/vmag2
    Tool/bcc5
    Tool/vmag
  Tool (1)
    Tool-MSNBomb
  Win32 (3)
    RemAdm-RemoteAdmin
    Vundo
    PShelter
Trojan (77)
   (3)
    Generic PWS.b
    Generic BackDoor.d
    Phish-BankFraud.eml
  - (2)
    Proxy-Hino
    IRC-Deport
  Application extension (4)
    CoreFlood.dll
    PWS-Gina.dll
    Spy-Tofger.dll
    PWS-Wexd.dll
  Configurator (1)
    PWS-IN.cfg
  Demonstration (1)
    JS/Exploit-DragDrop.b.demo
  Disk erasing (1)
    QZap66
  Downloader (6)
    Proxy-Mitglieder
    Downloader-AE
    Downloader-NI
    Downloader-OL
    Downloader-MP
    Downloader-LE
  Dropper (7)
    PWS-PPort.dr
    CoreFlood.dr
    PWS-Bancos.dr
    IRC/Flood.gen.dr
    BackDoor-ACH.dr
    BackDoor-AMQ.dr
    Spy-Tofger.dr
  Exploit (6)
    Exploit-DcomRpc
    Exploit-ObjectData
    VBS/Psyme
    Exploit-ByteVerify
    Exploit-MhtRedir.gen
    Exploit-Aluigi
  Generic (8)
    Exploit-DcomRpc.gen
    PWS-Bancban.gen
    PWS-Bancos.gen.c
    PWS-Bancos.gen
    Exploit-ObjectData.gen
    Downloader-MP.gen
    Spy-Tofger.gen.b
    PWS-LegMir.gen.e
  JavaScript (1)
    JS/CardStealer
  Malware Tool (3)
    Nuke-Medal
    Nuke-Unreal
    Bat/rbt.kit
  Password (6)
    PWS-Bancos
    PWS-LegMir
    PWS-Wexd
    PWS-LDPinch
    PWS-Bancban
    PWS-WMPatch
  Password Stealer (2)
    PWS-AIMScreen
    PWS-IN
  Proxy (3)
    Proxy-FBSR
    Proxy-Melt
    Proxy-Agent.a
  Remote Access (7)
    BackDoor-ACH
    BackDoor-AZV
    BackDoor-AMQ
    BackDoor-AKZ
    BackDoor-AVW
    BackDoor-BCB
    BackDoor-AZV.gen
  Script (1)
    Univ.script/99a
  Win32 (15)
    Generic Downloader.b
    Generic Downloader.a
    W32/Bagle.x!proxy
    HackerDefender
    Generic FDoS
    Generic BackDoor.f
    AdClicker-AF
    Generic BackDoor.c
    Generic VB.b
    Sporke
    Generic PWS.f
    Generic FDoS.c
    Generic MultiDropper.a
    Generic VB.c
    Ombush
Virus (174)
   (4)
    Mange-tout
    Xany.216
    Bobo.515
    Zune.2588
  Boot (1)
    BobZ
  Damaged (3)
    W32/Mydoom.dam
    W32/Lovgate.dam
    W32/Lovgate.x.dam
  Damaged Worm (4)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Korgo.worm.v.dam
    W32/Sdbot.worm.dam
  Dropper (4)
    Univ/a.dr
    Univ/j.dr
    Phoenix.dr
    Deadman.193.dr
  Dropper Worm (1)
    W32/Spybot.worm.dr
  E-mail (9)
    W32/Mydoom.b@MM
    W32/MyWife.a@MM
    W32/Mydoom.h@MM
    W32/Mydoom.e@MM
    W32/Dumaru.ad@MM
    W32/Mydoom.o@MM
    W32/Neveg.c@MM
    W32/Lovgate.ah@MM
    W32/Mydoom.k@MM
  E-mail worm (10)
    W32/Lovgate.f@M
    W32/Dumaru.y@MM
    W32/Bagle.u@MM
    W32/Mydoom.g@MM
    W32/Mydoom.f@MM
    W32/Mydoom.n@MM
    W32/Lovgate.ad@MM
    W32/Lovgate.af@MM
    W32/Lovgate.aj@MM
    W32/Lovgate.ab@MM
  Email (44)
    W32/Dumaru.aa@MM
    W32/Dumaru.z@MM
    W32/Mydoom.i@MM
    W32/Lovgate.r@MM
    W32/Lovgate.b@M
    W32/Lovgate.g@M
    W32/Lovgate.m@M
    W32/Lovgate.n@M
    W32/Dumaru.af@MM
    W32/Dumaru.ab@MM
    W32/Dumaru.ag@MM
    W32/Dumaru.ae@MM
    W32/Mydoom.j@MM
    W32/Dumaru.ah@MM
    W32/Mydoom.d@MM
    W32/Lovgate.q@MM
    W32/Lovgate.p@MM
    W32/Lovgate.v@M
    W32/Lovgate.t@MM
    W32/Lovgate.u@MM
    W32/Lovgate.w@M
    W32/MyWife.b@MM
    W32/Lovgate.al@MM
    W32/Neveg.b@MM
    W32/Volage@MM
    W32/Neveg.a@MM
    W32/Lovgate.aa@MM
    W32/Lovgate.ao@MM
    W32/Lovgate.an@MM
    W32/Lovgate.ak@MM
    W32/Lovgate.ac@MM
    W32/Lovgate.ae@MM
    W32/Mydoom.a@MM
    W32/Mydoom.m@MM
    W32/Mydoom.l@MM
    W32/Dumaru.av@MM
    W32/Mydoom@MM!zip
    W32/Mydoom.k@MM!zip
    W32/Mydoom.b@MM!zip
    W32/Mydoom.a@MM!zip
    W32/Dumaru.al@MM
    W32/Dumaru.ak@MM
    W32/Dumaru.aj@MM
    W32/Dumaru.ai@MM
  Email Generic (3)
    W32/Dumaru.gen@MM
    W32/Mydoom.gen@MM
    W32/MyWife.gen@MM
  Email Worm (3)
    W32/Mydoom.r@MM
    W32/Lovgate.ai@MM
    W32/Lovgate.ag@MM
  File Infector (5)
    Internal
    Bobo
    Phoenix
    Catherine.1365
    Chaos.1241
  Generic (1)
    W32/Sdbot.gen.r
  Generic Worm (19)
    W32/Spybot.worm.gen.e
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.f
    W32/Gaobot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.o
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.x
    W32/Sdbot.worm.gen.y
    W32/Sdbot.worm.gen.t
    W32/Korgo.worm.gen
    W32/Sdbot.worm.gen.p
    W32/Gaobot.worm.gen.h
  Heuristic (1)
    New Malware.b
  Internet Relay Chat (1)
    IRC/Generic
  Internet Worm (4)
    W32/Gaobot.worm.ali
    W32/Mydoom.s@MM
    W32/Korgo.worm.r
    W32/Gaobot.worm.gen.q
  Macro (1)
    W97M/Toot
  MS Office Suite (1)
    VBA/Generic.src
  Proxy (2)
    W32/Bagle.ak!proxy
    W32/Bagle.am!proxy
  Script (1)
    VBS/Generic
  Universal (4)
    Univ/f
    Univ/a
    Univ/g
    Univ/j
  Win32 (26)
    New Win32.g1
    New Poly Win32
    W32/Bagle.an!troj
    New Win32
    W32/Zmist.gen
    W32/Zmist.a
    W32/Lovgate
    W32/Cabanas.f
    W32/Cabanas.d
    W32/Cabanas.b
    W32/Cabanas
    W32/Cabanas.e
    W32/Cabanas.c
    W32/Cabanas.a
    W32/Dumaru.ax
    W32/Scard
    W32/Dumaru.ay
    W32/Dumaru.aw
    W32/Dumaru.au
    W32/Dumaru.as
    W32/Dumaru.ar
    W32/Dumaru.aq
    W32/Dumaru.ap
    W32/Dumaru.ao
    W32/Dumaru.an
    W32/Dumaru.am
  Worm (22)
    W32/MoFei.worm
    W32/Lovgate.l@M
    W32/Lovgate.a@M
    W32/Lovgate.c@M
    W32/Lovgate.s@MM
    W32/Lovgate.x@MM
    W32/Korgo.worm.ab
    W32/Korgo.worm.aa
    W32/Korgo.worm.ac
    W32/Myfip.worm
    W32/Korgo.worm.ad
    W32/Korgo.worm.z
    W32/Korgo.worm.x
    W32/Korgo.worm.y
    W32/Korgo.worm.u
    W32/Korgo.worm.t
    W32/Korgo.worm.s
    W32/Korgo.worm.i
    W32/Korgo.worm.v
    W32/Korgo.worm.k
    W32/Korgo.worm.p
    W32/Korgo.worm.q