Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4428
DAT Release Date 02/16/2005
Threats Detected 116531
New Detections 106
Enhanced Detections 406

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (9)
   (3)
    VMag70
    Tool/fmt16
    WareOut
  Tool (3)
    Tool-ICQ.Keep
    Tool-Fport
    Tool-ICQ.SMK
  Win32 (3)
    Favadd
    ShopNav
    MicrooLap
Trojan (70)
   (9)
    Phish-BankFraud.eml.d
    Phish-BankFraud.eml.a
    Phish-BankFraud.eml.f
    Phish-BankFraud.eml.e
    Phish-BankFraud.eml.c
    Phish-BankFraud.eml.b
    QHosts-26
    HideProc
    Generic BackDoor.t
  Application extension (1)
    Spyre.dll
  Application extension Droppe (1)
    StartPage-DU.dll.dr
  Downloader (9)
    Downloader-VP
    Downloader-VO
    Downloader-VM
    Downloader-VQ
    Downloader-VN
    Downloader-VL
    Downloader-VK
    Downloader-VJ
    Downloader-VF
  Dropper (4)
    MultiDropper-MI
    Downloader-VK.dr
    BackDoor-ABM.dr
    MultiDropper-MH
  Exploit (1)
    Exploit-MS05-009
  File/Folder creator (1)
    QFile6
  Flooder (1)
    FDoS-Hitman
  Generic (1)
    PWS-Zaba.gen
  Intended (1)
    W97M/Noifi.intd
  Internet Relay Chat (1)
    IRC-Azur
  Joke (1)
    W32/Refaz!joke
  Keylogger (1)
    Keylog-Small.c
  Malware Tool (1)
    Spam-Rolling
  Password Stealer (2)
    PWS-Gadu
    PWS-Spawn
  ProcKill (2)
    ProcKill-CK
    ProcKill-CJ
  Remote Access (2)
    BackDoor-COB
    BackDoor-COA
  Script (16)
    Bat/qd285
    Bat/pchw2
    Bat/klw13
    Bat/klw12
    Bat/klw11
    Bat/dt143
    Bat/avk49
    Bat/sec
    Bat/qd286
    Bat/qd284
    Bat/mkd29
    Bat/klw10
    Bat/dt142
    Bat/dt141
    Bat/avk50
    Bat/NoShare
  StartPage (1)
    StartPage-GL
  Win32 (14)
    W32/Refaz!bat
    QHost-26
    IPPager-D
    Generic StartPage.h
    DDoS-Resod
    Spyre
    Liewar
    Generic Downloader.r
    Generic Downloader.q
    DDoS-Nil
    AdClicker-CA
    AdClicker-BZ
    Pokey.a
    Generic BackDoor.s
Virus (27)
   (4)
    HLLT.7290
    Timid.523
    HLLT.16410
    HLLT.5456
  Dropper (1)
    Bat/sdwn5.dr
  Email (1)
    W32/Chimo@MM
  Generic (1)
    W32/Dumaru.gen
  Generic Worm (4)
    W32/AimDes.worm.gen
    W32/Sdbot.worm.gen.ad
    W32/Lextas.worm.gen
    W32/Flopslene.worm.gen
  Intended (1)
    W32/Balog.intd
  Internet Worm (1)
    W32/Bropia.worm.n
  multipartite (1)
    SPTH.mp
  Script (1)
    Bat/lolife
  Unpacked (1)
    HLLT.16410.unp
  Win32 (6)
    W32/Bayan
    W32/Shodi!backdoor
    W32/Laris
    W32/Dumaru.bg
    W32/Deadcode
    W32/Bagle.bm
  Worm (5)
    W32/Bropia.worm.o
    W32/Shodi.worm.l
    W32/Refaz.worm
    W32/Bropia.worm.m
    W32/AimDes.worm

Enhanced Detections:

Virus (117)
   (4)
    Trout
    OC/ooch
    Dreg
    KDG.1200
  - (1)
    W32/Zexam.dam
  Application extension (1)
    New Win32.dll
  Damaged (1)
    W32/Netsky.q.dam
  Damaged Worm (8)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Korgo.worm.v.dam
    W32/Korgo.worm.p.dam
    W32/Korgo.worm.s.dam
    W32/Korgo.worm.aa.dam
    W32/Sdbot.worm.dam
    W32/Korgo.worm.ac.dam
  Dropper (3)
    W32/FunLove.dr
    W32/Astef.dr
    W32/Sdbot.dr
  E-mail (2)
    W32/Dumaru.ad@MM
    W32/Bagle.ad@MM
  E-mail worm (3)
    W32/Dumaru.y@MM
    W32/Bagle.z@MM
    W32/Bagle.aa@MM
  Email (14)
    W32/Dumaru.aa@MM
    W32/Dumaru.z@MM
    W32/Bagle.al@MM
    W32/Dumaru.af@MM
    W32/Dumaru.ab@MM
    W32/Dumaru.ag@MM
    W32/Dumaru.ae@MM
    W32/Dumaru.ah@MM
    VBS/Smwf@MM
    W32/Dumaru.av@MM
    W32/Dumaru.al@MM
    W32/Dumaru.ak@MM
    W32/Dumaru.aj@MM
    W32/Dumaru.ai@MM
  File Infector (1)
    W32/Idele
  Generic (1)
    W32/Bagle.gen
  Generic Worm (18)
    W32/Sdbot.worm.gen
    W32/Spybot.worm.gen.e
    W32/Gaobot.worm.gen.e
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.f
    W32/Gaobot.worm.gen.l
    W32/Gaobot.worm.gen.j
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.x
    W32/Gaobot.worm.gen.t
    W32/Sdbot.worm.gen.y
    W32/Sdbot.worm.gen.t
    W32/Korgo.worm.gen
  Heuristic (1)
    New Malware.b
  Internet Worm (4)
    W32/Bropia.worm.g
    W32/Bropia.worm.gen
    W32/Bropia.worm.d
    W32/Korgo.worm.r
  MS Office Suite (1)
    VBA/Generic.src
  Overwriting (1)
    R'lyeh.ow.1178
  Peer To Peer (1)
    W32/Multex!p2p
  Script (1)
    VBS/Umbriel.b
  VbScript (1)
    New Script
  Win32 (24)
    New Win32.g1
    W32/Zexam
    W32/Dumaru.ax
    W32/Bagle.ap
    W32/Dumaru.bf
    W32/Dumaru.bd
    W32/Bagle.as
    W32/Dumaru.ay
    W32/Dumaru.be
    W32/Dumaru.ba
    W32/Dumaru.bc
    W32/Bagle.bi
    W32/Dumaru.aw
    W32/Bagle.ax
    W32/Dumaru.bb
    W32/Dumaru.au
    W32/Dumaru.as
    W32/Dumaru.ar
    W32/Dumaru.aq
    W32/Dumaru.ap
    W32/Dumaru.ao
    W32/Dumaru.an
    W32/Dumaru.am
    W32/Bagle.ay
  Win9x (1)
    W95/Legacy
  Worm (25)
    W32/Korgo.worm.ab
    W32/Korgo.worm.aa
    W32/Korgo.worm.ac
    W32/Bropia.worm.e
    W32/Bropia.worm.f
    W32/Bropia.worm.k
    W32/Bropia.worm.i
    W32/Bropia.worm.l
    W32/Bropia.worm.j
    W32/Bropia.worm.h
    W32/Korgo.worm.ad
    W32/Bropia.worm.b
    W32/Bropia.worm.a
    W32/Bropia.worm.c
    W32/Korgo.worm.z
    W32/Korgo.worm.x
    W32/Korgo.worm.y
    W32/Korgo.worm.u
    W32/Korgo.worm.t
    W32/Korgo.worm.s
    W32/Korgo.worm.i
    W32/Korgo.worm.v
    W32/Korgo.worm.k
    W32/Korgo.worm.p
    W32/Korgo.worm.q
Trojan (221)
   (6)
    Generic BackDoor.d
    Pokey-B.txt
    AdClicker-BQ
    Generic.b3
    Generic.b2
    Generic.b
  Application extension (5)
    BackDoor-CAY.dll
    PWS-Banker.k.dll
    BackDoor-CNZ.dll
    StartPage-DU.dll
    AdClicker-BV.dll
  Configuration settings (1)
    ServU.ini
  Configurator (1)
    Downloader-BP.cfg
  Denial Of Svc (1)
    IRC/Flood.y
  Downloader (9)
    Downloader-BP
    JS/Exploit-MhtRedir.ldr
    Downloader-NI
    Downloader-SA
    Downloader-SE
    PWS-Bancban.dldr
    Downloader-PS
    Downloader-LI
    Downloader-GG!chm
  Dropper (9)
    PWS-Bancos.dr
    MultiDropper-BN
    RemoteAdmin.dr
    IRC/Flood.cs.dr
    W32/Snac.dr
    VBS/Cone.dr
    PWS-Seny.dr
    BackDoor-BDI.dr
    VBS/QDial22.dr
  Exploit (6)
    Exploit-DcomRpc
    VBS/Psyme
    Exploit-ByteVerify
    JS/Exploit-DragDrop
    Exploit-PNGfile
    JS/Exploit-MhtRedir
  Flooder (64)
    FDoS-SkyFire
    FDoS-MSNCrash
    FDoS-OpDos
    FDoS-Devilos
    FDoS-DKBoom
    FDoS-FReK
    FDoS-MSNFast
    FDoS-P2k
    FDoS-EvilPing
    FDoS-Deface
    FDoS-IRCSpam
    FDoS-Fury
    FDoS-KillZone
    FDoS-Metamorp
    FDoS-Blurred
    FDoS-Overload
    FDoS-ShockWav
    FDoS-DAP
    FDoS-STU
    FDoS-MK3
    FDoS-Blitz20
    FDoS-Wako10
    FDoS-Wako21
    FDoS-LANKill
    FDoS-ARPKill
    FDoS-Rebirth
    FDoS-OIcqDov
    FDoS-NetKill
    FDoS-PortTerm
    FDoS-AdvMSN
    FDoS-Faceless
    FDoS-MrUDP
    FDoS-Sharft
    FDoS-ICQkuf
    FDoS-ShelPing
    FDoS-RoomKill
    FDoS-Destiny
    FDoS-Mega
    FDoS-BlakBlud
    FDoS-MrType
    FDoS-ChiBoy
    FDoS-UnaBomb
    FDoS-BamaBoy
    FDoS-Xoox
    FDoS-DanDan
    FDoS-WarPing
    FDoS-Hasist
    FDoS-Kalibre
    FDoS-ToyBox
    FDoS-AddMngr
    FDoS-WinPopUp
    FDoS-UDPBomb
    FDoS-NetDem
    FDoS-DarkDB
    FDoS-Fofeet
    FDoS-Raptof
    FDoS-FPack
    FDoS-Silent
    FDoS-TNet
    FDoS-GCS
    FDoS-Smurf
    FDoS-Punish
    FDoS-ICQ.NWG
    FDoS-MsgFld
  Generic (5)
    BackDoor-EE.gen
    PWS-Hearty.gen
    DDoS-Kaiten.gen
    PWS-Bancos.gen
    JS/Exploit-MhtRedir.gen
  HTML document (1)
    BackDoor-AXJ.htm
  Internet Relay Chat (1)
    IRC/Flood.c
  Keylogger (1)
    Keylog-Sters
  Malware Tool (55)
    Spam-BBMail
    Spam-Mimer
    Spam-Charlie
    Spam-Banan
    Spam-Mekanin
    Spam-MFraud
    Spam-FMBomb
    Spam-FMail
    Spam-VDX
    Spam-Stone
    Spam-Sabotage
    Spam-Paramail
    Spam-Emboz
    Spam-EmBomb
    Spam-DMB
    Spam-MCSpam
    Spam-BotSin
    Spam-AnonIM
    Spam-AIMSpam
    Spam-Swyque
    Spam-Pocztyl
    Spam-AdvMail
    Spam-Mobikill
    Spam-Scythe
    Spam-ZPSM
    Spam-AnonMail
    Spam-MailIt
    Spam-HRVG
    Spam-Bomber
    Spam-AnonNS
    Spam-NetSend
    Spam-Robis
    Spam-QMailer
    Spam-Hunter
    Spam-AlienBmb
    Spam-HateYou
    Spam-ICQMass
    Spam-Avril
    Spam-ICQ.Mach
    Spam-ICQ.Nexz
    Spam-Shock
    Spam-XYN
    Spam-Sheker
    Spam-Grad
    Spam-Aneg
    Spam-Bombita
    Spam-MBomb
    Spam-Alpha
    Spam-Uhbx
    Spam-Aenima
    Bat/bvm.kit
    Spam-NiMing
    Spam-GZL
    Spam-Blackhawk
    Spam-Slat
  Password (4)
    PWS-Bancos
    PWS-LegMir
    PWS-LDPinch
    PWS-Bancban
  Password Stealer (11)
    PWS-GTThief
    Generic PWS.b
    PWS-HackSoft
    PWS-QQRob
    Generic PWS.h
    Generic PWS.g
    PWS-Zaba
    Generic PWS.j
    PWS-Banker.f
    PWS-Lineage
    PWS-Goldun
  Proxy (3)
    Proxy-FBSR
    Proxy-Agent.c
    Proxy-Piky
  Remote Access (14)
    BackDoor-ACH
    BackDoor-AXJ
    BackDoor-CAY
    BackDoor-QY
    BackDoor-CNB
    BackDoor-AXO
    BackDoor-AZZ
    BackDoor-CNZ
    BackDoor-CNS
    BackDoor-CDC
    Generic BackDoor.l
    BackDoor-CMQ
    BackDoor-CKA
    BackDoor-BDD
  Script (1)
    Pokey-B.bat
  StartPage (1)
    StartPage-DU
  Tool (1)
    Tool-Uptime
  Win32 (21)
    Generic Downloader.a
    HackerDefender
    Generic FDoS
    Generic Delphi
    Pokey-B
    KillFiles
    Generic Downloader.n
    Generic BackDoor.q
    Pandora
    Generic BackDoor.g
    Generic StartPage.b
    Generic Downloader.p
    Generic Downloader.k
    Generic BackDoor.r
    Vundo
    AdClicker-BR
    QLowZones-2
    AdClicker-BA
    DDoS-Boxed
    Generic BackDoor.i
    Generic Downloader.h
Malware (1)
  Denial Of Svc (1)
    FDoS-Csium
Program (67)
   (1)
    IE Page Replacement
  Adware (7)
    Adware-KeenValue
    IPSentry
    Adware-BHO.gen
    Adware-Gator
    Adware-Searchcentrix
    Adware-LoggerBuddy
    Adware-Softomate
  Application extension (1)
    Spyware-SafeSurf.dll
  Downloader (2)
    Adware-POP.dldr
    Adware-ClearSearch.dldr
  Dropper (2)
    Adware-BetterInet.dr
    Adware-abetterintrnt.dr
  Generic (3)
    Dialer-RAS.aw.gen
    Keylog-Perfect.gen
    Dialer-RAS.dd.gen
  HTML document (1)
    IMIServ.html
  Keylogger (1)
    Keylog-SC.inst
  Remote Access (1)
    BackDoor-ATH
  Tool (43)
    Tool-Haxor
    Tool-Telnet
    Tool-BODec
    Tool-MacTime
    Tool-Revert
    Tool-HLPDump
    Tool-Analyze
    Tool-AVPX
    Tool-Podonok
    Tool-Pervert
    Tool-QQPassO
    Tool-QQExpl
    Tool-IconHnt
    Tool-CGIScan
    Tool-AutoPol
    Tool-DNSMast
    Tool-AIMRV
    Tool-ZPacker
    Tool-PEStat
    Tool-ZMist
    Tool-COM2UUE
    Tool-CGAGF
    Tool-Jumin
    Tool-Netacess
    Tool-IRXPro
    Tool-MLDE32
    Tool-SNTPTest
    Tool-InfElf
    Tool-PEWrSec
    Tool-Cerberos
    Tool-Domina
    Tool-CPUInfo
    Htool-Huc
    Tool-FileFake
    Tool-Fasong
    Tool-Frank
    Tool-Joekoe
    Tool-ProxyHun
    Tool-Haxxor
    Tool-ProxiesR
    Tool-Cookie
    Tool-IconIns
    Tool-DiskInfo
  Win32 (5)
    iGetNet
    SFind
    W32/Nosys
    RemAdm-RemoteAdmin
    Rpcxss