Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4407
DAT Release Date 11/17/2004
Threats Detected 107936
New Detections 119
Enhanced Detections 439

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
W32/Golten.worm Low-Profiled Low-Profiled

New Detections:

Internet Worm (1)
  Exploit (1)
    W32/Cran.worm.a
Program (23)
   (12)
    Reboot-AI
    Picture-Cold
    VSource/pag
    Tool Source/crh2d
    VSource/crh2d
    Tool Source/crh2c
    VSource/crh2c
    VSource/cg
    VMag/crh2c
    Picture-Asylum
    Generic Downloader.l
    VMag/crh2d
  Demonstration (1)
    Demo-Fogazzi
  Dialer (1)
    Dialer-230
  Generic (2)
    Dialer-RAS.do.gen
    Dialer-RAS.dq.gen
  Joke (1)
    Joke-PlayMusic
  Keylogger (1)
    Keylog-Examinator
  ProcKill (1)
    ProcKill-KnlKillP
  Tool (4)
    Tool-NT110
    Htool-SetRun
    HTool-CrackSearch
    HTool-Aldhack
Trojan (49)
   (1)
    SID
  - (1)
    Vundo.dldr
  Application extension (1)
    BackDoor-ASB.b.dll
  Disk erasing (1)
    QZap368
  Downloader (11)
    Prutec
    Downloader-SF
    Downloader-SD
    Downloader-SC
    Downloader-SB
    Downloader-SA
    Downloader-DA.js
    Downloader-SG
    Downloader-SE
    Downloader-RZ
    Downloader-BW.i
  Dropper (3)
    Downloader-SH.dr
    StartPage-FO.dr
    Downloader-SB.dr
  Generic (1)
    QLowZones-7.gen
  Internet Relay Chat (1)
    IRC-Jakinch
  Macro (1)
    W97M/Richtemp
  Malware Tool (1)
    Bat/bvm.kit
  Password Stealer (1)
    PWS-RemotePassSteal
  Proxy (1)
    Proxy-Agent.c
  Remote Access (9)
    BackDoor-CLH
    BackDoor-CLF
    BackDoor-CLD
    BackDoor-CLB
    BackDoor-ASB.b
    BackDoor-CLG
    BackDoor-CLE
    BackDoor-CLC
    BackDoor-CLA
  Script (4)
    Bat/qd273
    JS/HiddenFrame
    W97M/Relax.bat
    Bat/sdwn3
  Spam (1)
    Spam-SMS.Vlasof
  StartPage (5)
    StartPage-FO
    StartPage-FM
    StartPage-DU!reg
    StartPage-FN
    StartPage-FL
  Win32 (6)
    Sevenma
    Hitnrun
    Beagooz
    Del-461
    AmStub
    Generic PWS.l
Virus (46)
   (1)
    Dine.240
  Application extension (1)
    W32/Mydoom.ae.dll
  Application extension Worm (1)
    W32/Goalweb.worm.dll
  Companion (2)
    HLL.cmp.Dope.txt
    W32/Aegi.cmp
  Damaged (1)
    W32/Crosser.dam
  Dropper (1)
    W32/Numrok.dr
  Email (3)
    W32/Yanz.a@MM
    W32/Mydoom.aa@MM
    W32/Scrambler.q@MM
  Email Generic (1)
    W32/Dilbert.gen@MM
  Exploit (1)
    Exploit-MS04-11
  Generic (1)
    W32/Neklace.gen
  Generic Worm (1)
    W32/Eyeveg.worm.gen
  Intended (1)
    Bat/BWG.intd
  Internet Worm (1)
    W32/Golten.worm
  Overwriting (2)
    W16/Gads.ow
    W32/Crosser.ow
  Parasitic (2)
    W32/HLLP.Zakk
    W32/HLLP.Shut
  Peer To Peer (3)
    W32/Waper!p2p
    W32/Doomka!p2p
    W32/Nocturnal!p2p
  Peer To Peer Worm (1)
    W32/Xoxo.worm!p2p
  Script (3)
    Perl/Morglum
    Bat/Dahap
    VBS/Mecoll.txt
  Win32 (10)
    W32/NGVCK.a.3989
    W32/NGVCK.a.3818
    W32/Tehni
    W32/NGVCK.a.3888
    W32/NGVCK.a.3746
    W32/Mohmed.b
    W32/Mohmed.a
    W32/IntTest.txt
    W32/Bluback
    W32/Bagle.be
  Worm (9)
    HLLW.9136
    W16/Splitter.worm
    W32/Korgo.worm.ag
    W32/Hitasin.worm
    W32/Cran.worm.a!ftp
    W32/Cran.worm.a!bat
    W32/Azag.worm
    HLLW.7904
    W32/Eyeveg.worm.e

Enhanced Detections:

Internet Worm (5)
  - (1)
    W32/Mydoom.p@MM
  E-mail (2)
    W32/Mydoom.u@MM
    W32/Mydoom.v@MM
  P2P Worm (1)
    W32/Generic.worm!p2p
  VbScript (1)
    VBS/Generic@MM
Malware (1)
  Exploit (1)
    Exploit-CodeBase
Program (154)
   (4)
    Dialer.inf
    VSource/crh2b
    Tool Source/crh2b
    VMag/crh2b
  - (5)
    Free-Scratch-Cards
    MotherboardMonitor
    HideWindow
    RemAdm-PSKill
    Cometsystems
  Adware (14)
    DSSAgent
    Adware-SaveNow
    Adware-PortalScan
    Adware-RBlast.dldr
    ClearSearch.dldr
    Adware-HotBar
    Adware-BHO.gen
    Downloader-GoldCas
    Dialer-197
    MP3Search
    Adware-Searchcentrix
    Adware-Apropos
    Adware-ISTBar
    Adware-Lop
  Application extension (9)
    Adware-Apropos.dll
    Adware-RBlast.dll
    Clearsearch.dll
    ILookup.dll
    MP3Search.dll
    Keylog-Syshsti.dll
    Keylog-Kana.dll
    Keylog-GSmon.dll
    Dialer-Generic.dll
  Configurator (1)
    HTool/Exp-MS04-028
  Dialer (12)
    Dialer-RAS.aj
    Dialer-198
    Dialer-RAS.di
    Dialer-RAS.as
    Dialer-192
    Dialer-194
    Dialer-211
    Dialer-gen
    Dialer-212
    Dialer-208
    Dialer-216
    Dialer-RAS.de
  Downloader (10)
    Downloader-BR
    PosX
    PosX.dldr
    Adware-POP.dldr
    Downloader-EAccel
    Adware-Lop.dldr
    Downloader-JS
    Downloader-KL
    Downloader-JV
    Downloader-PX
  Dropper (1)
    HTool/HBTool.dr
  Generic (18)
    Dialer-RAS.bw.gen
    Dialer-RAS.bb.gen
    Dialer-RAS.bd.gen
    Dialer-RAS.v.gen
    Dialer-RAS.cl.gen
    Dialer-RAS.d.gen
    Dialer-RAS.at.gen
    Dialer-RAS.ax.gen
    Dialer-RAS.bo.gen
    Dialer-RAS.cc.gen
    Dialer-RAS.ck.gen
    Keylog-Perfect.gen
    Dialer-RAS.cx.gen
    Dialer-RAS.cz.gen
    Dialer-RAS.dk.gen
    Dialer-RAS.dl.gen
    Dialer-RAS.dm.gen
    Dialer-RAS.dd.gen
  Internet Relay Chat (1)
    IRC-Bircd
  Joke (12)
    Joke-Wobbling
    Joke-Splash
    Joke-ScreenMates
    Joke-Onlygame
    Joke-MouseShoot
    Joke-MessageMate
    Joke-StressRelief
    Joke-IconScroll
    Joke-Geschenk
    Joke-Flipped
    Joke-Drunk
    Joke-Buttons
  Keylogger (3)
    Keylog-Kana
    Keylog-GSmon
    Keylog-Syshsti
  Malware Tool (30)
    HTool/thu
    Htool/Spoffer
    HTool/AFXSynScan
    HTool/MS03-049
    HTool/DCYY
    HTool/RNK
    HTool/Nitari
    Htool/Atomicx
    HTool/IGMPNuke
    HTool/AOSFlooder
    HTool/Logix
    Htool/Yallstarts
    HTool/HBTool
    HTool/BatCrypt
    Htool/Huc
    HTool/SQLExec
    Nuke-Nabber
    HTool/GetInjectProc
    HTool/Exp-MS04-032!gdi
    HTool/AntiAV.b
    HTool/Exp-MS04-028.b
    HTool/Scan-MS04-011
    Htool/Remcruft
    HTool/TCPR
    HTool/NXP
    Htool/9xRX
    HTool/PassList
    HTool/AntiAV.a
    HTool/Client
    HTool/RPC
  PornDialer (1)
    Dialer-Generic
  Process (1)
    ProcKill-Term
  ProcKill (2)
    ProcKill-BU
    ProcKill-Jkill
  Proxy (1)
    Proxy-Safemail
  Spyware (3)
    Keylog-Perfect
    Keylog-Kiirogaa
    Keylog-KeyLoggerJ
  Tool (9)
    FireDaemon
    Clearlogs
    Linux/Vtool-Infelf
    Tool-InnSteel
    Tool-AngelsRevenge
    Linux/Tool-Elfwrsec
    Tool-IPCScan
    Vtool-Blocks
    Tool-IdleUI
  Win32 (17)
    Renamed mIRC Client
    Reboot-AA
    BloodScroller
    HideExec
    Packed mIRC Client
    NT-RemoteCon
    PtWebdav
    Antipol
    Medload
    Xwxload
    RemAdm-RemoteAdmin
    RemAdm-ProcLaunch
    Remote Shutdown
    Keygen-XPStyle
    Track2Gen
    RunService
    EggDrop
Trojan (140)
   (4)
    Generic PWS.b
    Phish-BankFraud.eml
    APStrojan.sh
    Generic Downloader.e
  AOL Password (1)
    APStrojan.gen
  Application extension (8)
    CoreFlood.dll
    PWS-Hooker.dll
    BackDoor-BAC.dll
    IRC-Sdbot.dll
    IRC-Xdem.dll
    IRC-Subot.dll
    StartPage-DU.dll
    PWS-Dolche.dll
  Client (1)
    BackDoor-SA.cli
  Configurator (1)
    Iroffer.cfg
  Demonstration (1)
    Exploit-IframeBO.demo
  Denial Of Svc (4)
    IRC/Flood.bv
    IRC/Flood.br
    Linux/DDoS-Kaiten
    DoS-Winlock
  Downloader (9)
    JS/Cisp
    Downloader-SH
    Downloader-RL
    Downloader-RK
    Downloader-QN
    PWS-Bancban.dldr
    Downloader-PH
    Downloader-PP
    Downloader-PS
  Dropper (11)
    IRC/Flood.gen.dr
    AdClicker-O.dr
    PWS-Bancban.dr
    IRC/Flood.ba.dr
    IRC-Smallfeg.dr
    BackDoor-CKR.dr
    IRC/Flood.p.dr
    IconScroll.dr
    IRC-Cubot.dr
    IRC/Flood.o.dr
    BackDoor-CJV.dr
  Dropper Generic (1)
    IRC-Sdbot.dr.gen
  Exploit (16)
    Exploit-DcomRpc
    VBS/Psyme
    Exploit-MS03-043
    Exploit-ByteVerify
    Linux/Exploit-SendMail
    Exploit-MhtRedir.gen
    Linux/Amdcrash
    Linux/Rpcmountd
    Linux/Seclpd
    Linux/Exploit-Statdx
    Linux/Exploit-Su
    Linux/Exploit-Woot
    Exploit-MS03-043.DoS
    Exploit-MS04-011
    Exploit-IframeBO!shellcode
    Exploit-MhtRedir
  File deleting (3)
    QDel369
    QDel167
    QDel174
  Generic (6)
    APStrojan.gen18
    Exploit-CodeBase.gen
    IRC/Flood.gen.c
    StartPage-AI.gen
    BackDoor-BAC.gen
    QLowZones-2.gen
  Generic Plugin component (1)
    Orifice2K.plugin.gen
  Internet Relay Chat (9)
    IRC/Flood.em
    IRC/Flood.as
    IRC-Scanbot
    IRC-Dalixy
    IRC-Ipexec
    IRC-FK
    IRC-Cubot
    IRC-Exebot
    IRC/Flood.o.hidewin
  Linux (14)
    Linux/Flooder.pong
    Linux/Kaot
    Linux/Login.b
    Linux/IISattack
    Linux/Evilc
    Linux/Cyrax.b
    Linux/Cyberpaul
    Linux/Attack
    Linux/Backoor-Excedoor
    Linux/Mhttpd
    Linux/Kot
    Linux/Iisuxor
    Linux/Godog.lnk
    Linux/Cyrax.a
  Malware Tool (2)
    Linux/Rootkit-B
    Spam-Algus
  mIRC client (1)
    IRC/Flood.o.mirc
  Password (3)
    PWS-Bancos
    PWS-LegMir
    PWS-Bancban
  Password Stealer (2)
    PWS-Progent
    PWS-Hooker.vxd
  Plugin component (4)
    Orifice2K.plugin.butt
    Orifice2K.plugin.des
    Orifice2K.plugin.peep
    Orifice.plugin
  Remote Access (12)
    BackDoor-ACH
    BackDoor-AXJ
    BackDoor-BAM
    CoreFlood
    BackDoor-BAC
    BackDoor-AED
    Backdoor-EE
    Linux/BackDoor-ssl
    BackDoor-SQ
    BackDoor-SI
    BackDoor-CHV
    BackDoor-CJV
  Script (4)
    Univ.script/99a
    Bat/TTDK
    JS/Playball
    Downloader-QB.bat
  StartPage (1)
    StartPage-CQ.gen
  Win31 (5)
    APStrojan.sr
    APStrojan.sq
    APStrojan.sp
    APStrojan.so
    APStrojan.sm
  Win32 (16)
    Generic VB
    Generic PWS.a
    Generic Downloader.a
    Generic BackDoor.b
    HackerDefender
    Generic Downloader.c
    Perniw
    Generic VB.b
    Generic Del
    Generic PWS.f
    RC5-Dropper.c
    Vundo
    Generic VB.c
    QLowZones-2
    AdClicker-BA
    QLowZones-5
Virus (139)
  Application extension (8)
    W32/Mydoom.a.dll
    W32/Mydoom.dll
    W32/Mydoom.b.dll
    W32/Mydoom.e.dll
    W32/Mydoom.f.dll
    W32/Mydoom.h.dll
    W32/Mydoom.g.dll
    W32/Mydoom.k.dll
  Application extension Worm (2)
    W32/Spybot.worm.dll
    W32/Korgo.worm.ae.dll
  Boot dropper (1)
    BtDr.Wyx
  Damaged Worm (2)
    W32/Spybot.worm.dam
    W32/Sdbot.worm.dam
  Dropper (3)
    W32/NGVCK.dr
    BackDoor-FB.dr
    W32/Sankey.dr
  Dropper Worm (1)
    W32/Dedler.worm.dr
  E-mail (7)
    W32/Mydoom.b@MM
    W32/Mydoom.h@MM
    W32/Mydoom.e@MM
    W32/Mydoom.o@MM
    Exploit-MIME.gen
    W32/Mydoom.ah@MM
    W32/Mydoom.k@MM
  E-mail worm (5)
    W32/Generic.a@MM
    W32/Mydoom.g@MM
    W32/Mydoom.f@MM
    W32/Mydoom.z@MM
    W32/Mydoom.ab@MM
  Email (10)
    W32/Mydoom.i@MM
    W32/Dilbert@MM
    W32/Mydoom.j@MM
    W32/Mydoom.ag@M
    JS/Dawn@MM
    W32/Mydoom.x@MM
    W32/Mydoom.w@MM
    W32/Mydoom.a@MM
    W32/Mydoom.m@MM
    W32/Mydoom.l@MM
  Email Generic (3)
    W32/Lohack.gen@MM
    JS/Fortnight.gen@M
    W32/Mydoom.gen@MM
  Email Worm (1)
    W32/Mydoom.r@MM
  File Infector (1)
    MPB/Kynel
  Generic (4)
    Exploit-MIME.gen.exe
    VBS/Pie.gen
    Exploit-DcomRpc.g.gen
    W32/Mydoom.gen!eml
  Generic Overwriting (1)
    W32/Swog.ow.gen
  Generic Peer To Peer (1)
    W32/Antinny.gen!p2p
  Generic Worm (20)
    W32/Sdbot.worm.gen
    W32/Spybot.worm.gen.e
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.i
    W32/Spybot.worm.gen.f
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.x
    W32/Sdbot.worm.gen.y
    W32/Sdbot.worm.gen.z
    W32/Sdbot.worm.gen.t
    W32/Korgo.worm.gen
    W32/Sdbot.worm.gen.p
  Internet Worm (2)
    W32/Mydoom.s@MM
    W32/Gaobot.worm.gen.q
  Open Share Worm (1)
    W32/Eyeveg.worm.c
  Peer To Peer (1)
    Bat/Cobat!p2p
  Universal (1)
    Univ/j
  Win32 (54)
    New Win32.g1
    New Win32.s
    W32/Bagif
    W32/NGVCK.a.7397
    W32/NGVCK.a.8809
    W32/NGVCK.a.4768
    W32/NGVCK.a.2404
    W32/NGVCK.a.2280
    W32/NGVCK.a.1365
    W32/NGVCK.a.2389
    W32/NGVCK.a.4907
    W32/NGVCK.a.3072a
    W32/NGVCK.a.1934
    W32/NGVCK.a.3560
    W32/NGVCK.a.2522/2537
    W32/NGVCK.a.2342
    W32/NGVCK.a.2218
    W32/NGVCK.a.2754
    W32/NGVCK.a.9412
    W32/NGVCK.a.1947
    W32/NGVCK.a.1416
    W32/NGVCK.a.3072b
    W32/NGVCK.a.1988
    W32/NGVCK.a.2092
    W32/NGVCK.a.2651
    W32/NGVCK.a.1056
    W32/NGVCK.a.2751
    W32/NGVCK.a.9632
    W32/NGVCK.a.1107
    W32/Appix
    W32/NGVCK.a.1700
    W32/NGVCK.a.3146
    W32/NGVCK.a.3250
    W32/NGVCK.a.1455
    W32/NGVCK.a.3427
    W32/NGVCK.a.5216
    W32/NGVCK.a.1364
    W32/NGVCK.a.2522
    W32/NGVCK.a.926
    W32/NGVCK.a.1352
    W32/NGVCK.a.2266
    W32/NGVCK.a.919
    W32/Numrok
    W32/NGVCK.a.1840
    W32/Generic.d
    W32/NGVCK.a.968
    W32/Haltura
    W32/NGVCK.a.5675
    W32/NGVCK.a.1222
    W32/Zelly
    W32/NGVCK.a.2712
    W32/NGVCK.a.2134
    W32/Generic.Delphi
    W32/Crosser.a
  Worm (10)
    W32/Eyeveg.worm.b
    W32/Eyeveg.worm.a
    W32/Goalweb.worm.a
    W32/Goalweb.worm.b
    W32/Dedler.worm
    W32/Myfip.worm
    W32/Korgo.worm.ae
    W32/Mydoom.t@MM
    W32/Spybot.worm
    W32/Eyeveg.worm.d