Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4391
DAT Release Date 09/15/2004
Threats Detected 100508
New Detections 108
Enhanced Detections 161

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Mydoom.u@MM Low-Profiled Low-Profiled
W32/Mydoom.v@MM Low-Profiled Low-Profiled
W32/Mydoom.y@MM Low-Profiled Low-Profiled

New Detections:

Internet Worm (3)
  E-mail (2)
    W32/Mydoom.u@MM
    W32/Mydoom.v@MM
  Open Share Worm (1)
    W32/Protoride.worm
Program (7)
   (1)
    V-HTM
  Application extension (1)
    Keylog-Perfect.dll
  Downloader (1)
    Downloader-PI
  Generic (1)
    Dialer-RAS.dm.gen
  Malware Tool (1)
    HTool/Aldhack
  Tool (1)
    Tool-DnsSpoof
  Win32 (1)
    Track2Gen
Trojan (62)
   (2)
    AdClicker-AW
    Cocodrilo
  Application extension (1)
    AdClicker-BC.dll
  Disk erasing (2)
    QZap367
    QZap366
  Downloader (8)
    Downloader-PO
    Downloader-PM
    Downloader-PK
    Downloader-PH
    Downloader-PP
    Downloader-PN
    Downloader-PL
    Downloader-PJ
  Dropper (5)
    PWS-Trigi.dr
    MultiDropper-LK
    StartPage-EY.dr
    Reboot-AG.dr
    BackDoor-CIR.dr
  Exploit (1)
    Exploit-1Table
  Flooder (1)
    FDos-NightFlames
  Generic (3)
    JS/Exploit-DragDrop.b.gen
    Downloader-PO.gen
    PWS-Bancban.gen.d
  Internet Relay Chat (1)
    IRC-Naninf
  Keylogger (2)
    Keylog-YKL
    Keylog-MapName
  Malware Tool (1)
    Kit-Inor
  Password Stealer (2)
    PWS-Seny
    PWS-Trigi
  ProcKill (1)
    Prockill-BY
  Proxy (1)
    Proxy-Xmaib
  Remote Access (10)
    BackDoor-CEB.c
    BackDoor-CIR
    BackDoor-CIP
    BackDoor-CIW
    BackDoor-CIV
    BackDoor-CIU
    BackDoor-CIT
    BackDoor-CIS
    BackDoor-CEB.c.sys
    BackDoor-CEB.e
  Script (10)
    Bat/qd263
    Bat/qd262
    Bat/qd261
    Bat/qd260
    Bat/exw20
    Bat/Venim
    JS/Zerolin.eml
    Bat/qd259
    Bat/addu
    Erazor.bat
  StartPage (2)
    StartPage-EY
    StartPage-EX
  Win32 (9)
    Burny
    AdClicker-BC
    Reboot-AG
    Zap-332
    QHosts-15
    LynceBir
    Generic Keylogger.c
    Erazor
    Defacer
Virus (35)
   (5)
    HLLT.7612b
    HLLT.5973
    Unkm.544
    Tiny.182b
    HLLT.5997
  Damaged (3)
    Kurgan.948.dam
    W32/Netsky.d.dam
    W32/HLLP.53764.dam
  Dropper (1)
    W32/Notre.dr
  E-mail worm (2)
    W32/Mydoom.z@MM
    W32/Mydoom.ab@MM
  Email (6)
    W32/Mydoom.u@MM!zip
    W32/Mydoom.y@MM
    W32/Mydoom.x@MM
    W32/Evaman.d@MM
    W32/Mydoom.w@MM
    W32/Evaman.e@MM
  Generic (1)
    W32/Holar.gen
  Generic Worm (1)
    W32/Supova.worm!p2p.gen
  Macro (1)
    W97M/MJ
  Parasitic (2)
    HLLP.6304b
    W32/HLLP.20606a
  Peer To Peer (2)
    W32/Towers!p2p
    W32/HowRip!p2p
  Win32 (8)
    W32/Polybot.bz
    W32/Polybot.by
    W32/Notre
    W32/NGVCK.a.2712
    W32/Ingax.576
    W32/Dumaru.bb
    W32/Bagle.aw
    W32/Bagle.av
  Worm (3)
    W32/Spybot.worm
    W32/Shodi.worm.e
    W32/Randon.worm.bj

Enhanced Detections:

Internet Worm (1)
  - (1)
    W32/Mydoom.p@MM
Program (13)
   (1)
    IMIServer
  Adware (1)
    Adware-SRNG
  Dialer (3)
    Dialer-191
    Dialer-194
    Dialer-185
  DOS (1)
    CD20
  Exploit (1)
    Exploit-MS03-007.scan
  Generic (1)
    ServU-Daemon.gen
  Malware Tool (2)
    VTool/fake
    Nuke-Nabber
  Win32 (3)
    XShareZ
    Virtual Bouncer
    AdwareDropper-B
Trojan (65)
   (5)
    AdClicker-AT
    AdClicker-AS
    AdClicker-AV
    Generic Keylogger
    QReg-2
  - (2)
    AdClicker-O
    AdClicker-AZ
  Application extension (4)
    Keylog-Spider.dll
    Keylog-Fearless.dll
    Uploader-S.dll
    PWS-Banker.dll
  Demonstration (1)
    JS/Exploit-DragDrop.b.demo
  Denial Of Svc (1)
    IRC/Flood.br
  Downloader (3)
    Proxy-Mitglieder
    Downloader-NI
    Downloader-LV
  Dropper (2)
    MultiDropper-IY
    BackDoor-SP.dr
  Exploit (2)
    VBS/Psyme
    JS/Exploit-DDay
  File deleting (2)
    QDel367
    QDel368
  Flooder (1)
    FDoS-Lanxue
  Generic (3)
    PWS-Bancban.gen
    PWS-Bancban.gen.c
    PWS-Banker.gen
  Internet Relay Chat (1)
    IRC/Flood.ap
  Malware Tool (2)
    Kit-Sevenc
    Kit-PWG
  Password Stealer (2)
    PWS-Banker
    PWS-Banker!sys
  Remote Access (8)
    BackDoor-SP
    BackDoor-CEB
    BackDoor-AKD
    BackDoor-AET
    BackDoor-CGZ
    BackDoor-CHL
    BackDoor-CEB.b.sys
    BackDoor-CEB.b
  Spam (1)
    AIM-Lowdown
  Spyware (2)
    Keylog-Spider
    Keylog-Perfect.dr
  StartPage (2)
    StartPage-DH
    StartPage-DU
  Win32 (21)
    Generic PWS.e
    AdClicker-AA
    AdClicker-V
    AdClicker-Q
    AdClicker-Y
    AdClicker-T
    AdClicker-N
    AdClicker-K
    AdClicker-AI
    AdClicker-J
    Generic BackDoor.f
    AdClicker-L
    AdClicker-AE
    AdClicker-C
    Generic PWS.g
    AdClicker-AK
    AdClicker-AL
    Colem
    AdClicker-BA
    AdClicker-AN
    FakeSecure
Virus (82)
   (1)
    Wilbur
  Damaged Worm (1)
    W32/Spybot.worm.dam
  Dropper (1)
    Bat/Mumu.dr
  Dropper multipartite (2)
    Neuroquila.mp.dr.b
    Neuroquila.mp.dr.a
  Dropper Worm (1)
    W32/Dedler.worm.dr
  E-mail (9)
    W32/Mydoom.b@MM
    W32/Mydoom.h@MM
    W32/Mydoom.e@MM
    W32/Dumaru.ad@MM
    W32/Mydoom.o@MM
    W32/Bagle.aq@MM
    W32/Neveg.c@MM
    W32/Bagle.ai@MM
    W32/Mydoom.k@MM
  E-mail worm (6)
    W32/Dumaru.y@MM
    W32/Mydoom.g@MM
    W32/Mydoom.f@MM
    W32/Bagle.ag@MM
    W32/Mydoom.n@MM
    W32/Bagle.ae@MM
  Email (25)
    W32/Dumaru.aa@MM
    W32/Dumaru.z@MM
    W32/Mydoom.i@MM
    W95/Babylonia@M
    W32/Dumaru.af@MM
    W32/Dumaru.ab@MM
    W32/Dumaru.ag@MM
    W32/Dumaru.ae@MM
    W32/Mydoom.j@MM
    W32/Dumaru.ah@MM
    W32/Mydoom.d@MM
    W32/Mydoom.p@MM!zip
    W32/Mydoom.r@MM!zip
    W32/Neveg.b@MM
    W32/Volage@MM
    W32/Neveg.a@MM
    W32/Mydoom.o@MM!zip
    W32/Mydoom.a@MM
    W32/Mydoom.m@MM
    W32/Mydoom.l@MM
    W32/Dumaru.av@MM
    W32/Dumaru.al@MM
    W32/Dumaru.ak@MM
    W32/Dumaru.aj@MM
    W32/Dumaru.ai@MM
  Email Generic (1)
    W32/Mydoom.gen@MM
  Email Worm (1)
    W32/Mydoom.r@MM
  Generic (1)
    JS/Spth.gen
  Generic Worm (5)
    W32/Sdbot.worm.gen
    W32/Spybot.worm.gen.e
    W32/Spybot.worm.gen.f
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.o
  Intended (1)
    W95/Babylonia.intd
  Internet Worm (2)
    W32/Holar.h@MM
    W32/Mydoom.s@MM
  mIRC Worm (1)
    W32/Protoride.worm
  Parasitic (2)
    W32/HLLP.53764
    W32/HLLP.20606
  Peer To Peer Worm (1)
    W32/Supova.worm!p2p
  Universal (3)
    Univ/b
    Univ/c
    Univ.prepend
  Win32 (13)
    W32/Bagle.an!troj
    W32/Dumaru.ax
    W32/Dumaru.ay
    W32/Dumaru.ba
    W32/Dumaru.aw
    W32/Dumaru.au
    W32/Dumaru.as
    W32/Dumaru.ar
    W32/Dumaru.aq
    W32/Dumaru.ap
    W32/Dumaru.ao
    W32/Dumaru.an
    W32/Dumaru.am
  Worm (5)
    BAT/Mumu.worm
    W32/Fasong.worm
    W32/Tinny.worm
    W32/Bagle.at@MM
    W32/Mydoom.t@MM