Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4394
DAT Release Date 09/22/2004
Threats Detected 101138
New Detections 106
Enhanced Detections 266

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (12)
   (2)
    IE Page Replacement
    Vanquish
  Dialer (4)
    Dialer-216
    Dialer-214
    Dialer-213
    Dialer-215
  Downloader (2)
    Downloader-PW
    Downloader-PX
  Exploit (1)
    Exploit-SQLHello
  Tool (1)
    Tool-IconIns
  Win32 (2)
    RemAdm-BERS
    DDosPing
Trojan (59)
   (4)
    ServU.txt
    QHosts-16!hosts
    AdClicker-BD
    Spy-Timonist
  Application extension (3)
    PWS-Relax.dll
    BackDoor-CJF.dll
    BackDoor-AKD.dll
  Client (3)
    Escritorio.cli
    BackDoor-CJH.cli
    BackDoor-CJE.cli
  Demonstration (1)
    Exploit-MS04-028.demo
  Downloader (7)
    Downloader-PU
    Downloader-PY
    Downloader-PS
    Downloader-PQ
    Downloader-PV
    Downloader-PT
    Downloader-PR
  Dropper (4)
    BackDoor-CJD.dr
    BackDoor-CDQ.dr
    MultiDropper-LL
    PWS-Relax.dr
  Exploit (1)
    Exploit-VBAdata
  Flooder (1)
    FDoS-Telebomb
  Generic (4)
    AFXrootkit.gen.c
    AdClicker-AZ.gen
    PWS-Bancban.gen.e
    QLowZones-2.gen
  Internet Relay Chat (1)
    IRC-Apribot
  Keylogger (2)
    Keylog-Logit
    Keylog-Misifid
  Linux (1)
    Linux/Derfunf
  Malware Tool (1)
    Kit-VPack
  Password Stealer (2)
    PWS-Relax
    PWS-Mifeng
  ProcKill (1)
    ProcKill-BZ
  Proxy (1)
    Proxy-Foreva
  Remote Access (11)
    BackDoor-CJJ
    BackDoor-CJG
    BackDoor-CJC
    BackDoor-CJA
    BackDoor-CIY
    BackDoor-CJK
    BackDoor-CJI
    BackDoor-CJD
    BackDoor-CJB
    BackDoor-CIZ
    BackDoor-CIX
  Server (3)
    Escritorio.svr
    BackDoor-CJH.svr
    BackDoor-CJE.svr
  StartPage (2)
    StartPage-EZ
    StartPage-FA
  Win32 (6)
    Del-458
    Generic BackDoor.m
    QHosts-16
    Owned
    Generic Dropper.e
    ExitWin-I
Virus (35)
   (7)
    Tula.1656
    Nooki.3477
    Mask.2389
    Jaat.334
    Xuxa.1984
    Tula.1540
    Massacre
  Damaged (6)
    Jaat.336.dam
    W32/Plexus.dam
    W32/Netsky.p.dam
    W32/Maldal.dam
    Mixcode.510.dam
    Jaat.334.dam
  Dropper (2)
    W32/Sdbot.dr
    W32/Squirrel.dr
  E-mail worm (2)
    W32/Fightrub@MM
    W32/Pahac@MM
  Email (3)
    W32/Gilp@MM
    VBS/Cata@MM
    W32/Mydoom.ac@MM
  Generic (1)
    W32/Bagle.gen
  Generic Worm (2)
    W32/Sdbot.worm.gen.z
    W32/Randon.worm.gen
  Peer To Peer (1)
    VBS/Lamda!p2p
  Script (1)
    VBS/Jess
  Unix (2)
    UNIX/Kru.b
    UNIX/Kru.a
  Win32 (7)
    W32/Squirrel
    W32/Satin
    W32/Killis
    W32/Bagle.ax
    W32/Wilab
    W32/Henky.1492
    W32/Bagle.ay
  Worm (1)
    W32/Generic.worm.d

Enhanced Detections:

Internet Worm (3)
  E-mail (1)
    W32/Bagle.gen@MM
  SQL worm (1)
    W32/SQLSlammer.worm
  VbScript (1)
    VBS/Generic@MM
Malware (1)
  Exploit (1)
    Exploit-CodeBase
Program (46)
   (1)
    V-HTM
  Application extension (1)
    ILookup.dll
  Dropper (1)
    IMIServ.dr
  Generic (1)
    Keylog-Perfect.gen
  HTML document (1)
    IMIServ.html
  HTTP/FTP Trans. (1)
    Dustbunny
  PornDialer (1)
    Dialer-Generic
  Remote Access (1)
    ServU-Daemon
  Tool (37)
    Tool-Haxor
    Tool-Telnet
    Tool-BODec
    Tool-MacTime
    Tool-Revert
    Tool-HLPDump
    Tool-Analyze
    Tool-AVPX
    Tool-Podonok
    Tool-Pervert
    Tool-QQPassO
    Tool-QQExpl
    Tool-IconHnt
    Tool-CGIScan
    Tool-AutoPol
    Tool-DNSMast
    Tool-AIMRV
    Tool-ZPacker
    Tool-PEStat
    Tool-ZMist
    Tool-COM2UUE
    Tool-CGAGF
    Tool-Jumin
    Tool-Netacess
    Tool-Xscan
    Tool-IRXPro
    Tool-MLDE32
    Tool-SNTPTest
    Tool-InfElf
    Tool-PEWrSec
    Tool-Cerberos
    Tool-Domina
    Tool-Fasong
    Tool-Frank
    Tool-ProxyHun
    Tool-ProxiesR
    Tool-Cookie
  Win32 (1)
    Generic HTool.a
Trojan (133)
   (4)
    Generic BackDoor.d
    Phish-BankFraud.eml
    Generic.b2
    Generic Downloader.e
  - (2)
    StartPage-B
    Spam-GhostMail
  Application extension (7)
    CoreFlood.dll
    Downloader-DA.dll
    Spy-Tofger.dll
    BackDoor-CAY.dll
    BackDoor-CGX.dll
    BackDoor-BAC.dll
    PWS-QQPass.dll
  Configuration file (1)
    StartPage-DX!hosts
  Configuration settings (1)
    ServU.ini
  Configurator (2)
    Iroffer.cfg
    Belnow.cfg
  Downloader (8)
    Downloader-EW
    Downloader-DC
    Downloader-IF
    Downloader-NT
    Downloader-ON
    Downloader-PE
    Downloader-OV
    Downloader-KX
  Dropper (9)
    CoreFlood.dr
    VBS/Inor
    PWS-Bancos.dr
    PWS-Bancban.dr
    MultiDropper-GP.d
    Serv-U.dr
    MultiDropper-LJ
    Keylog-Dafunk.dr
    BackDoor-CFD.dr
  Exploit (4)
    JS/Exploit-FileProxy
    UNIX/Exploit-Aix5L
    Exploit-MS04-028
    Exploit-1Table
  Generic (7)
    APStrojan.gen18
    Exploit-CodeBase.gen
    PWS-Bancban.gen.b
    PWS-Bancos.gen.c
    PWS-Bancos.gen
    Perl/Exploit.gen
    Exploit-MS04-011.gen
  Internet Relay Chat (1)
    IRC/Flood.cv
  Malware Tool (1)
    Kit-XVGL
  Password (6)
    PWS-Bancos
    PWS-LegMir
    PWS-QQPass
    BackDoor-AQI
    PWS-LDPinch
    PWS-Bancban
  Proxy (1)
    Proxy-Xmaib
  Remote Access (17)
    BackDoor-ACH
    BackDoor-ABM
    BackDoor-AZV
    CoreFlood
    BackDoor-CAY
    BackDoor-BAC
    BackDoor-QW
    BackDoor-CGX
    Backdoor-EE
    BackDoor-YQ
    BackDoor-AOZ
    BackDoor-AZZ
    BackDoor-AZV.gen
    BackDoor-CIW
    BackDoor-CEB.e
    BackDoor-BDD
    BackDoor-ACP
  Script (5)
    Univ.script/99a
    New CardStealer
    ServU.bat
    JS/Zerolin
    FireD.bat
  Settings Change (2)
    Startpage-N
    StartPage-G
  StartPage (33)
    StartPage-CM
    StartPage-AM
    StartPage-AK
    StartPage-AH
    StartPage-S
    StartPage-P
    StartPage-J
    StartPage-D
    StartPage-AL
    StartPage-AJ
    StartPage-AE
    StartPage-X
    StartPage-R
    StartPage-O
    StartPage-L
    StartPage-I
    StartPage-E
    StartPage-AZ
    StartPage-Z
    StartPage-BE
    StartPage-BD
    StartPage-BH
    StartPage-BM
    StartPage-BY
    StartPage-BV
    StartPage-BU
    StartPage-BZ
    StartPage-EL
    StartPage-EO
    StartPage-EV
    StartPage-DY
    StartPage-DE
    StartPage-DC
  Unix (2)
    UNIX/Sorso
    Unix/Sillysh
  Win32 (20)
    Generic VB
    Generic BackDoor.b
    AdClicker-W
    HackerDefender
    Generic Downloader.c
    FuRootkit
    GirlFriend
    Belnow.b
    Belnow.a
    Belnow.c
    Generic MSVC
    Belnow.d
    Flystudio
    AdClicker-AX
    Regger
    Generic VB.c
    QLowZones-2
    Escritorio
    Reboot-AG
    DDoS-Boxed
Virus (83)
   (3)
    Coconut.2031
    Mixcode.510
    OS2/Rexis
  Application extension (1)
    W32/Roach.dll
  Application extension Worm (1)
    W32/Bizex.worm.dll
  Damaged (1)
    W32/Netsky.q.dam
  Damaged Worm (2)
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Dropper (1)
    W32/Maldal.j.dr
  Dropper Worm (1)
    W32/SQLSlammer.worm.dr
  E-mail (2)
    W32/Maldal.k@MM
    W32/Bagle.ad@MM
  E-mail worm (2)
    W32/Bagle.z@MM
    W32/Bagle.aa@MM
  Email (11)
    W32/Maldal.j@MM
    W32/Bagle.al@MM
    W32/Maldal.g@MM
    W32/Maldal.e@MM
    W32/Maldal.h@MM
    W32/Maldal.f@MM
    W32/Maldal.b@MM
    W32/Plexus.e@MM
    W32/Plexus.c@MM
    W32/Plexus.d@MM
    W32/Plexus.b@MM
  Email Generic (1)
    W32/Plexus.gen@MM
  Generic (4)
    VBS/Sflus.gen
    VBS/Cidco.gen
    W32/Lemoor.gen
    W32/Sdbot.gen.r
  Generic Worm (20)
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/Gorm.worm.gen
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.i
    W32/Gaobot.worm.gen.l
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.g
    W32/Sdbot.worm.gen.x
    W32/Sdbot.worm.gen.y
    W32/Sdbot.worm.gen.u
    W32/Sdbot.worm.gen.t
    W32/Sdbot.worm.gen.p
    W32/Gaobot.worm.gen.r
    W32/Gaobot.worm.gen.h
  Heuristic (1)
    New Malware.b
  Internet Worm (3)
    W32/Gaobot.worm.ali
    W32/Plexus.a@MM
    W32/Gaobot.worm.gen.q
  Linux (3)
    Linux/Adrastea
    Linux/Amalthea
    Linux/Mcmd
  Macro (1)
    W97M/Ostrich.gen
  Overwriting (1)
    W32/HLL.ow.Jetto
  P2P Worm (1)
    W32/Reur.worm!p2p
  Peer To Peer (1)
    W32/Generic.c!p2p
  Universal (2)
    Univ/a
    Univ/j
  Unix (1)
    UNIX/Prep
  VbScript (2)
    VBS/Soraci
    New Script
  Win32 (12)
    New Poly Win32
    W32/Maldal.a@MM
    W32/Maldal.d@MM
    W32/Hatter
    W32/TryMem
    W32/Generic.d
    W32/Sulpex
    W32/Bagle.ap
    W32/Bagle.as
    W32/Sulpex.b
    W32/Sulpex.a
    W32/Lasbat
  Worm (5)
    W32/Generic.worm.b
    W32/Maldal.c@MM
    W32/Leave.worm.j
    W32/Dedler.worm
    W32/Myfip.worm