Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4404
DAT Release Date 11/03/2004
Threats Detected 106239
New Detections 118
Enhanced Detections 159

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (13)
   (8)
    Generic Downloader.i
    VSource/pas7
    Tool Source/crh2a
    VSource/crh2a
    Tool Source/crh1
    VMag/crh2a
    VMag67
    VSource/crh1
  Demonstration (1)
    Exploit-MixedMime.demo
  Malware Tool (1)
    HTool/Exp-MS04-022
  Tool (2)
    Tool-TrayURL
    HTool-RobinPE
  Win32 (1)
    QHosts-20
Trojan (37)
   (1)
    QHosts-21
  Client (1)
    NTRootKit-E.cli
  Demonstration (1)
    Exploit-MS04-022.demo
  Downloader (3)
    Downloader-RR
    Downloader-RQ
    Downloader-RP
  Downloader Generic (1)
    W32/Bagle.dldr
  Dropper (3)
    QHosts-21.dr
    BackDoor-CKR.dr
    BackDoor-CKB.dr
  Exploit (3)
    JS/Exploit-DragDrop.c
    Exploit-IIS.Danet
    Exploit-RealSkin
  Generic (1)
    PWS-Bancos.gen.e
  Keylogger (1)
    Keylog-Midgard
  Password Stealer (2)
    PWS-Junet
    PWS-Dozat
  Peer To Peer Worm (1)
    W32/Trist.worm!p2p
  ProcKill (1)
    ProcKill-CB
  Proxy (3)
    Proxy-Sistdin
    Proxy-Segig
    Proxy-Corpse
  Remote Access (8)
    BackDoor-CKV
    Backdoor-CKU
    BackDoor-CKT
    BackDoor-CKS
    BackDoor-CKR
    BackDoor-CKQ
    BackDoor-CKP
    BackDoor-CKO
  Script (1)
    PHP/Chaploit
  StartPage (1)
    StartPage-FJ
  Win32 (5)
    Subnix
    KillXP
    Generic StartPage.f
    FakeTet
    Generic Downloader.j
Virus (68)
   (48)
    Vacsina.2680
    Vacsina.2568
    Vacsina.1805
    Vacsina.1760
    Vacsina.1753
    Vacsina.700
    Urfydus.2631
    Tokyo.1258
    Tired.1740
    Squawk.852
    Spanish Fool.1417
    Semtex.1000c
    Semtex.1000b
    Semtex.1000a
    Semtex.686
    Semtex.619
    Semtex.515
    Noggin.1054
    MPS OPC.682
    Freddy.1870
    Europe
    Enola.2430
    Enola.1864b
    Enola.1864a
    Demolition.1585
    XRCV.335
    XRCV.330a
    ARCV.255
    ARCV.224
    Andromeda.1063
    Andromeda.1062
    Xexe.628
    Ufa.1201
    Terminator.2294
    SVS.526
    QRes.397
    Iper.1062
    Int78.547
    CLS.853
    Beware.442
    Baobab.739
    Baobab.732
    Baobab.1636
    Axe.1024
    AVA.600
    Antimon.1450
    Alex.1951
    YD.2505
  Configurator (1)
    W32/Pahac.cfg
  Dropper (6)
    Semtex.dr
    ARCV.255.dr
    Nines.dr
    Beware.dr
    Axe.dr
    Antimon.dr
  Email (3)
    W32/Salga.a@MM
    W32/Bagz.g@MM
    W32/Bagle@MM!cpl
  Intended (1)
    W32/Pahac.intd
  Linux (3)
    Linux/Xone
    Linux/Neox
    Linux/Nel
  Macro (1)
    W97M/Woah
  Win32 (1)
    W32/Labox
  Worm (4)
    W32/Sdbot.worm.tm
    W32/Pepbot.worm
    W32/Shodi.worm.f
    W32/Myfip.worm.h

Enhanced Detections:

Internet Worm (3)
  mIRC Worm (1)
    New IRC
  P2P Worm (1)
    W32/Spybot.worm.lk
  Win32 (1)
    New Worm
Program (17)
   (2)
    VMag12
    Vmag2
  - (3)
    Iroffer
    Proxy-OSS
    MotherboardMonitor
  Adware (4)
    Adware-180Solutions
    ClearSearch.dldr
    Adware-Gohip
    Adware-Gator
  Application extension (1)
    ILookup.dll
  Downloader (1)
    Virtual Bouncer.dldr
  Password (1)
    PWDump
  Process (1)
    ProcKill-T
  Win32 (4)
    iGetNet
    Packed mIRC Client
    Virtual Bouncer
    PowerScan
Trojan (57)
   (5)
    Generic PWS.b
    Generic BackDoor.d
    Generic PWS.c
    Phish-BankFraud.eml
    Share
  Configurator (1)
    Generic PWS.c.cfg
  Downloader (7)
    JS/Cisp
    Downloader-PE
    Downloader-RG
    Downloader-QT
    Downloader-PN
    Downloader-PS
    Downloader-LE
  Dropper (4)
    VBS/Inor
    IRC/Flood.gen.dr
    Generic PWS.c.dr
    BackDoor-BBD.dr
  Exploit (4)
    Exploit-ObjectData
    VBS/Psyme
    Exploit-MhtRedir.gen
    Exploit-ZIP.b
  Generic (5)
    AFXrootkit.gen.b
    DDoS-Kaiten.gen
    JS/IEstart.gen.c
    JS/Stealus.gen
    QLowZones-2.gen
  Linux (2)
    Linux/Fakepatch-A
    Linux/Rootkit-Lrk
  Password (1)
    PWS-LegMir
  Remote Access (13)
    BackDoor-ACH
    BackDoor-AZV
    BackDoor-CAC
    BackDoor-AWM
    BackDoor-AED
    BackDoor-UK
    BackDoor-AOZ
    BackDoor-AWI
    BackDoor-BBD
    BackDoor-CCH
    BackDoor-CKJ
    BackDoor-CIW
    BackDoor-CJK
  Script (1)
    Univ.script/99a
  Spyware (1)
    Keylog-Perfect.dr
  Win32 (13)
    Generic VB
    Generic Downloader.b
    Generic Downloader.a
    Generic BackDoor.b
    Generic Downloader.c
    Generic PWS.f
    Generic BackDoor.g
    Generic VB.c
    QLowZones-2
    AdClicker-BA
    Generic BackDoor.k
    Generic BackDoor.j
    Generic BackDoor.n
Virus (82)
   (14)
    Mr.Div.1100
    Mr.Ra.1039
    Mr.Ra.1000a
    Mr.Ravl.962
    Mr.Dof.1000
    Mr.Ra.1000b
    Mr.Ravl.983
    Vacsina.1269
    Vacsina.1212a
    Vacsina.1339
    Vacsina.1212b
    Vacsina.1206
    Better-World.1019
    ARCV.330
  - (1)
    W32/Bagle.bc@MM
  Damaged (3)
    W32/Netsky.q.dam
    Mr.Dof.dam
    Mr.Ravl.dam
  Damaged Worm (3)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Dropper (4)
    Univ/a.dr
    Univ/j.dr
    ARCV.330.dr
    Vacsina.dr
  E-mail (2)
    W32/Bagle.aq@MM
    W32/Bagle.ai@MM
  E-mail worm (7)
    W32/Bagle.bb@mm
    W32/Bagle.bd@MM
    W32/Bagz.d@MM
    W32/Bagz.e@MM
    W32/Bagle.ag@MM
    W32/Pahac@MM
    W32/Bagle.ae@MM
  Email (6)
    W32/Shodi.c@MM
    W32/Bagz.f@MM
    W32/Bagz.a@MM
    W32/Bagle.az@MM
    W32/Bagz.c@MM
    W32/Bagz.b@MM
  Email Generic (1)
    W32/Bagz.gen@MM
  File Infector (3)
    Generic
    Nines
    Quake.518
  Generic (1)
    W32/Bagle!eml.gen
  Generic Worm (17)
    W32/Spybot.worm.gen.e
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.f
    W32/Gaobot.worm.gen.l
    W32/Sdbot.worm.gen.e
    W32/Spybot.worm.gen.h
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.y
    W32/Sdbot.worm.gen.t
    W32/Sdbot.worm.gen.p
  Internet Worm (1)
    W32/Gaobot.worm.gen.q
  Universal (1)
    Univ/j
  VbScript (1)
    New Script
  Win32 (9)
    W32/Generic.d
    W32/Zelly
    W32/Zelly.a
    W32/Soach
    W32/GregCenter
    W32/Bagle.ba
    W32/Bagle.aw
    W32/Bagle.av
    W32/Bagz!proxy
  Worm (8)
    W32/Sorin.worm
    W32/Shodi.worm.a
    W32/Shodi.worm.b
    W32/Myfip.worm
    W32/Shodi.worm.d
    W32/Bagle.at@MM
    W32/Shodi.worm.e
    W32/Myfip.worm.g