Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4412
DAT Release Date 12/08/2004
Threats Detected 109850
New Detections 58
Enhanced Detections 315

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (11)
   (1)
    CRH3c
  Application extension (1)
    Keylog-Refog.dll
  Dialer (1)
    Dialer-234
  Joke (1)
    Joke-Panic
  Keylogger (1)
    Keylog-Refog
  ProcKill (1)
    ProcKill-PMaster
  Tool (4)
    Tool-SRunner
    Tool-Mydoom
    Tool-Qing
    Tool-Joekoe
  Win32 (1)
    AdClicker-BP
Trojan (36)
   (2)
    AdClicker-BQ
    AdClicker-BS
  Application extension (3)
    Keylog-Spycorpse.dll
    Keylog-Darto.dll
    IRC-SpyAli.dll
  Configurator (1)
    Keylog-Spycorpse.cfg
  Downloader (4)
    Downloader-SX
    Downloader-SV
    Downloader-SY
    Downloader-SW
  Dropper (4)
    Keylog-Darto.dr
    BackDoor-BAC.dr
    IRC-SpyAli.dr
    AdClicker-BS.dr
  Exploit (4)
    Exploit-MS04-019
    Linux/Exploit-Bysin
    Linux/Exploit-Moos
    Linux/Exploit-Nios
  Generic (2)
    BackDoor-CLO.gen
    BackDoor-CEO.gen
  Internet Relay Chat (1)
    IRC-SpyAli
  Keylogger (3)
    Keylog-Spycorpse
    Keylog-Exp
    Keylog-Darto
  Remote Access (5)
    BackDoor-CJK!txt
    BackDoor-CLS
    BackDoor-CLQ
    BackDoor-CLT
    BackDoor-CLR
  Script (1)
    IRC-SpyAli.bat
  Win32 (6)
    Uploader-V
    QPass-A
    QLowZones-8
    QFav-2
    BanBlock
    Generic Dropper.f
Virus (11)
  Application extension Generi (1)
    W32/Maslan.dll.gen
  Email (4)
    W32/Maslan.b@MM
    W32/Maslan.a@MM
    W32/Maslan.c@MM
    W32/Hobbit.g@MM
  Email Generic (1)
    W32/Maslan.gen@MM
  Generic Worm (1)
    W32/Gaobot.worm.gen.t
  Intended Worm (1)
    W32/Atak.e@MM
  Internet Relay Chat (1)
    W32/Maslan!irc
  Win32 (1)
    W32/Dumaru.bd
  Worm (1)
    W32/Banwor.worm

Enhanced Detections:

- (1)
  Adware (1)
    Adware-RVP
Internet Worm (2)
  P2P Worm (1)
    W32/Generic.worm!p2p
  Win32 (1)
    New Worm
Malware (1)
  Exploit (1)
    Exploit-CodeBase
Program (109)
   (3)
    VSource/crh99
    VSource/crh98
    CRH3b
  - (1)
    IGetNet.dr
  Adware (26)
    Adware-KeenValue
    Adware-Huntbar
    Adware-RBlast.dldr
    Adware-MemWatcher
    Adware-Superbar
    Adware-180Solutions
    Adware-Look2Me
    Adware-HotBar
    Adware-Websearch
    Adware-SideSearch
    Adware-PurityScan
    Adware-Verticity
    Adware-SRNG
    Adware-PopMonster
    Adware-Xupiter
    Adware-Nsupdate
    Adware-NSearch
    Adware-Fuel
    Adware-IntDel
    Adware-Lop
    Adware-POP
    Adware-WhenUSearch
    Adware-OMI
    Adware-ClickTrack
    Adware-TSADB
    Adware-Pribi
  Dialer (2)
    Dialer-RAS.di
    Dialer-233
  Downloader (6)
    Adware-XPlugin.dldr
    Adware-SRNG.dldr
    Adware-NS.dldr
    Adware-Lop.dldr
    Adware-Ezula.dldr
    Adware-Websearch.dldr
  Dropper (6)
    Adware-NetPals.dr
    Adware-RBlast.dr
    Adware-XPlugin.dr
    Adware-FreeComm.dr
    Uploader-R.dr
    Adware-Pribi.dr
  Generic (2)
    Dialer-RAS.cw.gen
    ServU-Daemon.gen
  Password (1)
    Winspy
  PornDialer (1)
    Dialer-Generic
  Remote Access (1)
    ServU-Daemon
  Settings Change (1)
    Adware-XPlugin
  Spam (1)
    Adware-Ezula
  Spyware (1)
    Spyware-DCToolbar
  Tool (56)
    Tool-Haxor
    Tool-NetCat
    Tool-Telnet
    Tool-BODec
    Tool-MacTime
    Tool-Revert
    Tool-HLPDump
    Tool-Analyze
    Tool-AVPX
    Tool-Podonok
    Tool-Pervert
    Tool-QQPassO
    Tool-QQExpl
    Tool-IconHnt
    Tool-CGIScan
    Tool-AutoPol
    Tool-DNSMast
    Tool-AIMRV
    Tool-ZPacker
    Tool-PEStat
    Tool-ZMist
    Tool-COM2UUE
    Tool-CGAGF
    Tool-Jumin
    Tool-Netacess
    Tool-PGP2TXT
    Tool-RSAKey
    Tool-Tracer
    Tool-PGPDump
    Tool-TXT2DEN
    Tool-Huff
    Tool-AVPOffset
    Tool-VecnaLink
    Tool-Chiton
    Tool-IRXPro
    Tool-MLDE32
    Tool-DumpAIT
    Tool-FTransf
    Tool-SNTPTest
    Tool-InfElf
    Tool-PEWrSec
    Tool-Cerberos
    Tool-Domina
    Tool-ServUCRC
    Tool-CACLs
    Tool-SetTime
    Tool-FileFake
    Tool-Fasong
    Tool-Frank
    Tool-ProxyHun
    Tool-ProxiesR
    Tool-Cookie
    Tool-IconIns
    Tool-SpeedTest
    Tool-UPolyX
    Tool-DiskInfo
  Win32 (1)
    LaSta
Trojan (104)
   (13)
    BDLogger
    Generic PWS.b
    Generic BackDoor.d
    AdClicker-AT
    AdClicker-AS
    AdClicker-AW
    AdClicker-AV
    AdClicker-BN
    Phish-BankFraud.eml
    AdClicker-BF
    AdClicker-BE
    Generic Downloader.e
    QLowZones-4
  - (1)
    AdClicker-O
  Application extension (3)
    Exploit-DcomRpc.dll
    W32/Dumaru.dll
    BackDoor-BAC.dll
  Demonstration (1)
    Exploit-MS04-028.demo
  Downloader (7)
    Downloader-DC
    Downloader-DZ
    JS/Exploit-MhtRedir.ldr
    Downloader-RE
    PWS-Bancban.dldr
    Downloader-PS
    Downloader-PR
  Dropper (9)
    PWS-Bancban.dr
    PWS-LDPinch.dr
    Bat/tenej.b2.dr
    Bat/tenej.b1.dr
    Downloader-SU.dr
    AdClicker-AS.dr
    MultiDropper-BF
    BackDoor-CLO.dr
    PWS-Banker.dr
  Exploit (5)
    Exploit-DcomRpc
    Exploit-MhtRedir.gen
    Exploit-MS04-011
    JS/Exploit-MhtRedir
    Exploit-MS04-028
  Generic (6)
    Exploit-CodeBase.gen
    JS/IEstart.gen.d
    BackDoor-AMU.gen
    BackDoor-BAC.gen
    HackerDefender.gen
    BackDoor-BAC.gen.b
  Internet Relay Chat (2)
    IRC/Flood.ap
    IRC-Rootbot
  Keylogger (1)
    Keylog-Gobi
  Linux (1)
    Linux/Fakepatch-A
  Malware Tool (1)
    Linux/Rootkit-D
  Password (3)
    PWS-Bancban
    PWS-WebMoney.gen
    PWS-Banker.d
  Password Stealer (2)
    PWS-PWKiller
    PWS-Banker
  Proxy (1)
    Proxy-Agent.c
  Remote Access (9)
    Backdoor-AQK
    BackDoor-BAC
    BackDoor-CGX
    BackDoor-KF
    BackDoor-AET
    BackDoor-AYK
    BackDoor-TC
    BackDoor-CLL
    BackDoor-ACR
  Script (2)
    Bat/tenej.b2
    Bat/tenej.b1
  Spyware (1)
    Keylog-Perfect.dr
  Win32 (36)
    AdClicker-AA
    AdClicker-V
    AdClicker-Q
    AdClicker-Y
    AdClicker-T
    AdClicker-N
    AdClicker-K
    Generic Downloader.a
    Generic BackDoor.b
    Reg/Seeker
    HackerDefender
    AdClicker-AI
    AdClicker-J
    Generic Delphi
    Generic Downloader.c
    AdClicker-L
    AdClicker-AE
    Generic PWS.g
    AdClicker-AK
    Generic Downloader.k
    AdClicker-BM
    AdClicker-AL
    ZapChast
    QLowZones-2
    AdClicker-BA
    QLowZones-3
    Generic Downloader.g
    Generic Downloader.f
    Generic Keylogger.c
    Generic BackDoor.k
    AdClicker-AN
    Generic BackDoor.j
    Generic Downloader.h
    QLowZones-5
    Generic BackDoor.o
    Generic BackDoor.n
Virus (98)
   (3)
    SymbOS/Cabir.b
    SymbOS/Cabir.a
    SymbOS/Cabir
  Application extension (1)
    W32/Stepan.dll
  Application extension Generi (1)
    W32/Bagle.dll.gen
  Boot (2)
    Int.40
    Int.C1
  Damaged (1)
    W32/Sober.dam
  Damaged Worm (2)
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Dropper (1)
    W32/FunLove.dr
  E-mail (2)
    W32/Dumaru.ad@MM
    W32/Neveg.c@MM
  E-mail worm (5)
    W32/Generic.a@MM
    W32/Dumaru.y@MM
    W32/Hobbit.c@MM
    W32/Hobbit.b@MM
    W32/Atak.b@MM
  Email (19)
    W32/Dumaru.aa@MM
    W32/Dumaru.z@MM
    W32/Hobbit.e@MM
    W32/Hobbit.f@MM
    W32/Hobbit.d@MM
    W32/Atak.c@MM
    W32/Atak.a@MM
    W32/Dumaru.af@MM
    W32/Dumaru.ab@MM
    W32/Dumaru.ag@MM
    W32/Dumaru.ae@MM
    W32/Dumaru.ah@MM
    W32/Neveg.b@MM
    W32/Neveg.a@MM
    W32/Dumaru.av@MM
    W32/Dumaru.al@MM
    W32/Dumaru.ak@MM
    W32/Dumaru.aj@MM
    W32/Dumaru.ai@MM
  Email Generic (1)
    W32/Atak.gen@MM
  File Infector (1)
    Generic
  Floppy Worm (1)
    W32/Rackum.worm
  Generic Worm (20)
    W32/Sdbot.worm.gen
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.f
    W32/Gaobot.worm.gen.l
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.k
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.g
    W32/Sdbot.worm.gen.x
    W32/Eyeveg.worm.gen
    W32/Sdbot.worm.gen.y
    W32/Sdbot.worm.gen.t
    W32/Gaobot.worm.gen.h
  Heuristic (2)
    New AOL
    New Malware.b
  Intended (1)
    W32/Hobbit.intd
  Internet Worm (5)
    W32/Sdbot.worm
    W32/Hobbit.a@MM
    W32/Gaobot.worm.ali
    W32/Atak.d@MM
    W32/Gaobot.worm.gen.q
  MS Office Suite (1)
    VBA/Generic.src
  Parasitic (5)
    W32/HLLP.Philis.d
    W32/HLLP.Philis.c
    W32/HLLP.Philis.f
    W32/HLLP.Philis.b
    W32/HLLP.Philis.a
  Peer To Peer (1)
    W32/Generic.c!p2p
  Peer To Peer Worm (1)
    W32/PMX.worm!p2p
  VbScript (1)
    New Script
  Win32 (18)
    New Win32.s
    W32/Bizex
    W32/Dumaru.ax
    W32/Scard
    W32/Dumaru.ay
    W32/Dumaru.ba
    W32/Zelly
    W32/Dumaru.bc
    W32/Dumaru.aw
    W32/Dumaru.bb
    W32/Dumaru.au
    W32/Dumaru.as
    W32/Dumaru.ar
    W32/Dumaru.aq
    W32/Dumaru.ap
    W32/Dumaru.ao
    W32/Dumaru.an
    W32/Dumaru.am
  Worm (3)
    W32/Hobbit.worm
    W32/Dedler.worm
    W32/Sdbot.worm!ftp