Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4398
DAT Release Date 10/13/2004
Threats Detected 103749
New Detections 143
Enhanced Detections 242

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Joke (1)
  Joke (1)
    Joke-RainDrops
Program (8)
   (1)
    UnRealIRC
  Dialer (2)
    Dialer-222
    Dialer-RAS.dn
  Downloader (2)
    Virtual Bouncer.dldr
    Downloader-QP
  Malware Tool (2)
    PWCrack-OpenPass
    HTool/bin
  Tool (1)
    Tool-IdleUI
Trojan (53)
   (5)
    QHosts-19
    AdClicker-BF
    AdClicker-BE
    Share
    Crah
  Client (1)
    Linux/PWS-LinSpy.cli
  Damaged (1)
    Linux/Rootkit-Dica.dam
  Demonstration (5)
    Bat/Exploit-GrpConv.demo
    JS/Exploit-Shell.demo
    Exploit-ZIPName.demo
    Exploit-NetDDE.demo
    Exploit-Halftone.demo
  Downloader (11)
    Downloader-QU
    Downloader-QT
    Downloader-QS!ftp
    Downloader-QS
    Downloader-QQ
    Downloader-QO
    Downloader-QN
    Downloader-QM
    JS/Downloader-PP
    Downloader-QR
    Downloader-QV
  Dropper (2)
    MultiDropper-LR
    BackDoor-CJV.dr
  Email (1)
    W32/Berlity@MM
  Exploit (2)
    JS/Exploit-InsCtl
    Exploit-JPG.Crash
  Flooder (1)
    FDoS-Spabot
  Malware Tool (4)
    Linux/Rootkit-Knark.ko
    Linux/Rootkit-ArkD
    Linux/Rootkit-Skit
    Linux/Rootkit-Dica
  Password Stealer (5)
    PWS-Phong
    PWS-Leand
    PWS-LDPinch!zip
    PWS-Dolche.b
    PWS-Crtz
  Remote Access (8)
    Perl/Backdoor-Egg
    BackDoor-CJV
    BackDoor-CKA
    BackDoor-CJZ
    BackDoor-CJY
    BackDoor-CJX
    BackDoor-CJW
    BackDoor-CJU
  Script (3)
    Bat/qd267
    Bat/qd266
    Bat/qd264
  Win32 (4)
    QLowZones-3
    AdClicker-BI
    AdClicker-BG
    AdClicker-BH
Virus (81)
   (56)
    Batman.2236
    BACE.338
    Vienna.814
    Turbo.1129
    Shirley.4096
    Pandemonium
    Lame.1632
    Flu.1160
    Delta.1006
    YCTC.1975
    XRes.204
    XRCE.146
    Xchange.1066
    Weasel.3012
    Weasel.3008
    VLAD.550
    Uncouth
    Trap.2117
    Tally.259
    Squad.1299
    Slire.1462
    Shish.1142
    Search.308
    Scorpion.2278
    Ritz.1112b
    Ratboy.289b
    Potpi.696
    Modi.648
    Metall.557
    Mariner.5000
    Malatinec
    LX.1996
    Lisa.666
    Kill.578
    Jakarta.559
    Iwashere.710
    Ighty.1156
    Hypnotiser.1784
    HADI.6153
    Hackware.3791
    Galya.1000
    Galya.500
    Flavour
    FAOD.1433
    Fals.1181
    Drizzle.1600
    Dotter.4611
    Dither.1502
    Diego.1586
    Cleaner.937
    Cagliari
    Bombtest.554
    Bobby.613
    Batman.3372
    Batman.2844
    Batman.2240
  Damaged (9)
    W32/Bagle.ag.dam
    W32/Bagle.i.dam
    W32/Bagle.h.dam
    W32/Bagle.g.dam
    W32/Bagle.f.dam
    W32/Bagle.e.dam
    Ratboy.289b.dam
    Metall.557.dam
    Bobby.613.dam
  Dropper (2)
    Lame.1632.dr
    Bombtest.dr
  Dropper Worm (1)
    W32/Leox.worm.dr
  Email (2)
    W32/Mydoom.ad@MM
    W32/Lovgate.aq@MM
  Linux (1)
    Linux/Guile
  Script (3)
    Bat/Satana
    Bat/qd265
    Bat/bvg
  Win32 (3)
    W32/GregCenter
    W32/Darif
    W32/Bacros
  Worm (4)
    W32/Funner.worm
    Bat/Igador.worm
    W32/Licu.worm
    W32/Funner.worm!hosts

Enhanced Detections:

- (1)
  - (1)
    Unsafe Program
Internet Worm (4)
  - (1)
    W32/Mydoom.p@MM
  E-mail (2)
    W32/Mydoom.u@MM
    W32/Mydoom.v@MM
  Trojan (1)
    Linux/Adore.worm
Malware (1)
  Exploit (1)
    Exploit-CodeBase
Program (32)
   (4)
    PortScan-EvilEye
    VMag9
    YNotify
    WndManage
  - (1)
    KeyHook.dll
  Application extension (10)
    Keylog-Qover.dll
    Clearsearch.dll
    KeyLog-KeyRecord.dll
    W32/Inmota.dll
    Proxy-OSS.dll
    PSpy.dll
    Keylog-SARep.dll
    MXResolver.dll
    Tool-RemoteKill.dll
    Keylog-Perfect.dll
  Dialer (2)
    Dialer-191
    Dialer-Generic.b
  Downloader (2)
    Downloader-BR
    Downloader-NP
  Generic (1)
    Keylog-Perfect.gen
  Keylogger (2)
    Keylog-MSNMspy
    Keylog-StealthLogger
  Password (1)
    Keylog-Hoddle
  Plugin component (1)
    Tool-Xscan.plugin
  PornDialer (1)
    Dialer-Generic
  ProcKill (1)
    ProcKill-BR
  Remote Access (1)
    ServU-Daemon
  Spyware (2)
    Keylog-Perfect
    Keylog-KeyLoggerJ
  Win32 (3)
    SFind
    Virtual Bouncer
    RemAdm-RemoteAdmin
Trojan (77)
   (9)
    Generic PWS.b
    Generic BackDoor.d
    AdClicker-AT
    AdClicker-AS
    AdClicker-AW
    AdClicker-AV
    CGIPager-C
    Phish-BankFraud.eml
    QHosts-17!hosts
  - (1)
    AdClicker-O
  Application extension (4)
    BackDoor-CGX.dll
    W32/Dumaru.al.dll
    AdClicker-BA.dll
    PWS-Dolche.dll
  Configuration settings (1)
    ServU.ini
  Demonstration (1)
    JS/Exploit-DragDrop.b.demo
  Downloader (8)
    Proxy-Mitglieder
    Downloader-NI
    Downloader-QJ
    PWS-Bancban.dldr
    Downloader-MP
    Downloader-MA
    Downloader-JW
    Downloader-JU
  Dropper (1)
    IRC-Sdbot.dr
  Dropper Generic (1)
    IRC-Sdbot.dr.gen
  Exploit (2)
    Exploit-MhtRedir.gen
    Exploit-ZIP
  Generic (3)
    PWS-Bancos.gen.c
    FDoS-Spabot.gen
    JS/Exploit-DragDrop.b.gen
  Internet Relay Chat (1)
    IRC/Flood.ep
  Linux (5)
    Linux/Rootkit-Lrk
    Linux/Rootkit-FKit
    Linux/Rootkit-Knark
    Linux/PWS-Linspy
    Linux/BlackHole
  Password (3)
    PWS-LegMir
    PWS-LDPinch
    PWS-Bancban
  Remote Access (8)
    Backdoor-CAK
    BackDoor-AZV
    BackDoor-CCT
    BackDoor-CGX
    BackDoor-AOZ
    BackDoor-AZV.gen
    BackDoor-CJQ
    Linux/Backdoor-ICMP
  Script (1)
    Univ.script/99a
  Source code (1)
    Keylog-Small.b.src
  Spyware (1)
    Keylog-Perfect.dr
  Win32 (26)
    Generic VB
    AdClicker-AA
    AdClicker-V
    AdClicker-Q
    AdClicker-Y
    AdClicker-T
    AdClicker-N
    AdClicker-K
    HackerDefender
    AdClicker-AI
    Generic BackDoor.h
    AdClicker-J
    Tuoraw
    AdClicker-L
    AdClicker-AE
    Generic VB.b
    SrvAny
    AdClicker-AK
    Generic VB.c
    AdClicker-AL
    Generic StartPage.e
    AdClicker-BA
    Generic StartPage.c
    DDoS-Boxed
    AdClicker-AN
    QHosts-17
Virus (127)
   (4)
    Vienna.943b
    Vienna.906
    Vienna.817
    Fam.533
  Application extension (6)
    W32/Lamin.dll
    W32/Hiton.a.dll
    W32/Zecho.dll
    W32/MyWife.dll
    W32/Mydoom.t.dll
    W32/Delikon.dll
  Application extension Generi (1)
    W32/Hiton.dll.gen
  Application extension Worm (8)
    W32/Bobax.worm.dll
    W32/Bizex.worm.dll
    W32/Anig.worm.dll
    W32/Mota.worm.dll
    W32/Bobax.worm.d.dll
    W32/Bobax.worm.b.dll
    W32/Bobax.worm.c.dll
    W32/Bobax.worm.a.dll
  Damaged (2)
    W32/Lovgate.dam
    W32/Lovgate.x.dam
  Damaged Worm (3)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Dropper (1)
    Univ/j.dr
  E-mail (8)
    W32/Mydoom.b@MM
    W32/Mydoom.h@MM
    W32/Mydoom.e@MM
    W32/Mydoom.o@MM
    W32/Mabutu.a@MM
    W32/Mabutu.b@MM
    W32/Lovgate.ah@MM
    W32/Mydoom.k@MM
  E-mail worm (11)
    W32/Lovgate.f@M
    W32/Mydoom.g@MM
    W32/Mydoom.f@MM
    W32/Mydoom.z@MM
    W32/Mydoom.n@MM
    W32/Mydoom.ab@MM
    W32/Fightrub@MM
    W32/Lovgate.ad@MM
    W32/Lovgate.af@MM
    W32/Lovgate.aj@MM
    W32/Lovgate.ab@MM
  Email (28)
    W32/Mydoom.i@MM
    W32/Lovgate.r@MM
    W32/Lovgate.b@M
    W32/Lovgate.g@M
    W32/Lovgate.m@M
    W32/Lovgate.n@M
    W32/Mydoom.j@MM
    W32/Mydoom.d@MM
    W32/Lovgate.q@MM
    W32/Lovgate.p@MM
    W32/Lovgate.v@M
    W32/Lovgate.t@MM
    W32/Lovgate.u@MM
    W32/Lovgate.w@M
    W32/Lovgate.al@MM
    W32/Lovgate.aa@MM
    W32/Lovgate.ao@MM
    W32/Lovgate.an@MM
    W32/Lovgate.ak@MM
    W32/Mydoom.y@MM
    W32/Mydoom.x@MM
    W32/Mydoom.w@MM
    W32/Lovgate.ac@MM
    W32/Lovgate.ae@MM
    W32/Mydoom.a@MM
    W32/Mydoom.m@MM
    W32/Mydoom.l@MM
    W32/Mydoom.ac@MM
  Email Generic (2)
    W32/Mabutu.gen@MM
    W32/Mydoom.gen@MM
  Email Worm (3)
    W32/Mydoom.r@MM
    W32/Lovgate.ai@MM
    W32/Lovgate.ag@MM
  File Infector (2)
    Vampiro
    Vienna
  Generic (1)
    W32/Sdbot.gen.r
  Generic Worm (23)
    W32/Sdbot.worm.gen.b
    W32/Spybot.worm.gen.e
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.i
    W32/Gaobot.worm.gen.l
    W32/Sdbot.worm.gen.e
    W32/Spybot.worm.gen.g
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.g
    W32/Sdbot.worm.gen.x
    W32/Sdbot.worm.gen.y
    W32/Sdbot.worm.gen.u
    W32/Sdbot.worm.gen.t
    W32/Sdbot.worm.gen.v
    W32/Sdbot.worm.gen.p
    W32/Gaobot.worm.gen.h
  Internet Worm (5)
    W32/Sdbot.worm
    W32/Snapper@MM
    W32/Gaobot.worm.ali
    W32/Mydoom.s@MM
    W32/Gaobot.worm.gen.q
  Peer To Peer (1)
    W32/Generic.d!p2p
  Script (1)
    Bat/flm
  Universal (2)
    Univ/f
    Univ/j
  VbScript (2)
    Unsafe Script
    New Script
  Win32 (4)
    New Win32.g1
    New Win32
    W32/Lovgate
    W32/Longbe
  Worm (9)
    W32/MoFei.worm
    W32/Lovgate.l@M
    W32/Lovgate.a@M
    W32/Lovgate.c@M
    W32/Lovgate.s@MM
    W32/Lovgate.x@MM
    W32/Sluter.worm.e
    W32/Dedler.worm
    W32/Mydoom.t@MM