Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4432
DAT Release Date 02/23/2005
Threats Detected 117143
New Detections 193
Enhanced Detections 268

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (85)
   (72)
    Tool/reboot
    Cookie-Zedo
    Cookie-Webstat
    Cookie-Valueclick
    Cookie-UGOr
    Cookie-TRB
    Cookie-Tickle
    Cookie-Targetnet
    Cookie-Sageanalyst
    Cookie-Roiservice
    Cookie-Revenue
    Cookie-Questionmarke
    Cookie-Nextag
    Cookie-Mgnetwork
    Cookie-Liveperson
    Cookie-Indiads
    Cookie-Imrworldwide
    Cookie-Humanclick
    Cookie-Fish4
    Cookie-Exitexchange
    Cookie-Doubleclick
    Cookie-Customcoupon
    Cookie-Clicktracks
    Cookie-Centrport
    Cookie-Cars
    Cookie-Bluestreak
    Cookie-Belointeract
    Cookie-Azcentral
    Cookie-Atdmt
    Cookie-Adserver
    Cookie-Adknowledge
    Cookie-360i
    Cookie-2O7
    Hacker's Choice
    Cookie-Zope
    Cookie-Zap2it
    Cookie-Versiontrack
    Cookie-Untd
    Cookie-Tribalfusion
    Cookie-Trafficmp
    Cookie-Scripps
    Cookie-RU4
    Cookie-Rightmedia
    Cookie-Real
    Cookie-Netshelter
    Cookie-Nandomedia
    Cookie-Mediaturf
    Cookie-Insightexpres
    Cookie-IGN
    Cookie-Gemius
    Cookie-Fastclick
    Cookie-Euniverseads
    Cookie-Cybermonitor
    Cookie-Clickedyclick
    Cookie-Casalemedia
    Cookie-Bravenet
    Cookie-Bfast
    Cookie-Belnk
    Cookie-Audiencematch
    Cookie-Atwola
    Cookie-Apn
    Cookie-Adrevolver
    Cookie-Ad-logics
    Cookie-Addesktop
    Cookie-247realmedia
    Cookie-Telegraph
    Cookie-Independent
    Cookie-Cneteu
    Cookie-Awrz
    Cookie-Affiliatefuel
    Cookie-Advance
    Cookie-Adtech
  Adware (2)
    Adware-IEToolBar
    Adware-HotSearchBar
  Application extension (1)
    Adware-IEToolBar.dll
  Dialer (1)
    Dialer-252
  Dropper (2)
    Adware-IEToolBar.dr
    Adware-Beginto.dr
  Heuristic (1)
    Cookie-News
  ICQ Messaging (1)
    ICQ-HPexploits
  Malware Tool (2)
    VTool/Unkrubb
    VTool/Demovir
  Self-extracting archive (1)
    WebCracker.sfx
  Tool (1)
    HTool-GetIn
  Win32 (1)
    ServNift
Trojan (52)
   (7)
    Poorsouls
    FSF
    BadExe
    B2C/rd1
    B2C/Delwin6
    B2C/Comoro
    Generic component
  Adware (1)
    Adware-Globosearch
  Application extension (3)
    PWS-GhettoGina.dll
    BackDoor-COH.dll
    BackDoor-AOP.dll
  Configurator (1)
    PWS-QQPass.cfg
  Disk erasing (1)
    QZap370
  Downloader (4)
    Downloader-VU
    Downloader-VT
    Downloader-VS
    Downloader-VR
  Dropper (6)
    MultiDropper-MJ
    Spam-Banan.dr
    PWS-Banker.k.dr
    BackDoor-COG.dr
    BackDoor-COD.dr
    BackDoor-AXU.dr
  Exploit (1)
    Exploit-SQL.UDF
  Generic (2)
    PWS-Banker.k.gen
    HackerDefender.gen.c
  Malware Tool (1)
    Nuke-Assault
  Password Stealer (2)
    PWS-IJ
    PWS-GhettoGina
  Proxy (1)
    Proxy-Agent.g
  Remote Access (6)
    BackDoor-COH
    BackDoor-COF
    BackDoor-COE
    BackDoor-COC
    BackDoor-AOP.txt
    BackDoor-COD
  Script (9)
    Bat/vms
    Bat/siln
    Bat/qd288
    Bat/qd287
    Bat/init
    bat/dt144
    Bat/avk51
    BackDoor-COG.reg
    Bat/billgo
  StartPage (2)
    StartPage-GN
    StartPage-GM
  Tool (1)
    Tool-MS05-009
  Win32 (4)
    Stuftrion
    Del-467
    EasySearch
    AdClicker-CD
Virus (56)
   (25)
    SRCG
    Scrambler.1139
    Scoot.1719
    Wonko
    Winko.1176
    Urphin.1632
    Piper
    Nucleii
    Crenko
    Cranko
    Clunko
    Clonko
    Clenko.1898
    Clanko
    Chunko.2003
    Chonko.600
    Chinko
    Chenko
    Chanko.125
    HLLT.4880
    HLL.Kornik
    HLLT.8910
    VCL.Sica.270
    Clinko
    HLLT.20621
  Companion (4)
    Offspring.cmp.1150
    HLL.cmp.3686
    HLL.cmp.3776
    HLL.cmp.3966
  Companion Dropper (2)
    Offspring.cmp.1150.dr
    Offspring.cmp.1142.dr
  Damaged (1)
    W32/Bagz.e.dam
  Dropper (5)
    Nomad.dr
    Yury.323.dr
    Neuropath.dr
    Hellspawn.dr
    Chunko.dr
  E-mail (1)
    W32/Mydoom.bf@MM
  Email (3)
    W32/Bagz.e@MM!zip
    W32/Mydoom.bf@MM!zip
    W32/Kipis.i@MM
  Generic (1)
    W32/Mydoom.gen!zip
  Internet Worm (1)
    W32/Bropia.worm.q
  Overwriting (2)
    Quesi.ow
    HLL.ow.8383b
  Parasitic (2)
    Grog.cav.475b
    Grog.cav.475a
  Win32 (1)
    Generic!Morphine
  Worm (8)
    W32/Generic.worm.h
    W32/Laris.worm
    W32/Eudor.worm
    W32/Bropia.worm.r
    W32/Doxpar.worm
    W32/Bropia.worm.s
    W32/Radebot.worm
    W32/Viric.worm

Enhanced Detections:

Internet Worm (4)
  E-mail (2)
    W32/Mydoom.u@MM
    W32/Mydoom.v@MM
  Open Share Worm (1)
    W32/Maddis.worm
  P2P Worm (1)
    W32/Generic.worm!p2p
Program (21)
   (3)
    Generator.WW
    VText.2d
    Cookie-DomSponor
  - (1)
    PrcView
  Adware (5)
    Adware-Huntbar
    Adware-BetterInet
    Adware-Searchcentrix
    Adware-Apropos
    Adware-Alexa
  Application extension (1)
    Dialer-Generic.dll
  Dropper (2)
    Adware-BetterInet.dr
    ILookup.dr
  Joke (1)
    Joke-DTReg
  Malware Tool (2)
    PWCrack-HTTPBrute
    VTool/fake
  PornDialer (1)
    Dialer-Generic
  Remote Access (1)
    ServU-Daemon
  Spyware (1)
    Spyware-Realtime-Spy
  Win32 (3)
    SmallHTTP
    RemAdm-RemoteAdmin
    RemAdm-ProcLaunch
Trojan (138)
   (7)
    Phish-BankFraud.eml.f
    Phish-BankFraud.eml.b
    Generic.b3
    Generic.b2
    Generic.b
    ServU.txt
    QHosts-1!hosts
  - (2)
    IRC-Deport
    StartPage-B
  Application extension (6)
    CoreFlood.dll
    Spy-Tofger.dll
    BackDoor-CAY.dll
    PWS-Banker.k.dll
    PWS-Iyus.dll
    PWS-Banker.dll
  Configurator (1)
    ProcKill-Q.cfg
  Downloader (6)
    Downloader-UU
    BackDoor-AXJ.dldr
    Downloader-QG
    Downloader-PS
    Downloader-PQ
    Downloader-GG!chm
  Dropper (6)
    Gaslide.dr
    IRC/Flood.di.dr
    MultiDropper-IY
    BackDoor-AOP.dr
    MultiDropper-MI
    MultiDropper-LO
  Dropper Generic (1)
    IRC-Sdbot.dr.gen
  Exploit (6)
    Exploit-DcomRpc
    Exploit-ByteVerify
    Exploit-FileName
    JS/Exploit-DragDrop
    Exploit-ByteVerify.a
    Exploit-ObscuredHtml
  Generic (6)
    PWS-Bancos.gen.c
    AFXrootkit.gen.b
    FDoS-MSN.gen
    PWS-Iyus.gen
    PWS-Bancos.gen.d
    JS/Exploit-BO.gen
  Internet Relay Chat (2)
    IRC/Flood.di
    IRC/Flood.c
  Keylogger (1)
    Keylog-Sters
  Password (4)
    PWS-Bancos
    PWS-LegMir
    PWS-LDPinch
    PWS-Iyus
  Password Stealer (3)
    Generic PWS.e
    Generic PWS.a
    PWS-Lineage
  Plugin component (1)
    IRC/Flood.ak.plugin
  Process (2)
    ProcKill-AE
    ProcKill-AF
  ProcKill (22)
    ProcKill-BW
    ProcKill-H
    ProcKill-F
    ProcKill-BT
    ProcKill-BO
    ProcKill-BJ
    ProcKill-AU
    ProcKill-AL
    ProcKill-AC
    ProcKill-AA
    ProcKill-S
    ProcKill-Q
    ProcKill-P
    ProcKill-M
    ProcKill-L
    ProcKill-K
    ProcKill-J
    ProcKill-F.cln
    ProcKill-D
    ProcKill-C
    ProcKill-CG
    ProcKill-BX
  Proxy (1)
    Proxy-Agent.c
  Remote Access (8)
    BackDoor-AXJ
    BackDoor-ABM
    BackDoor-AOP
    BackDoor-CEB.f
    Backdoor-CKU
    BackDoor-CEB.b
    BackDoor-CMQ
    BackDoor-BDD
  Script (1)
    Reg/LowZones
  Settings Change (2)
    Startpage-N
    StartPage-G
  StartPage (39)
    StartPage-CM
    StartPage-AM
    StartPage-AK
    StartPage-AH
    StartPage-S
    StartPage-P
    StartPage-J
    StartPage-D
    StartPage-AL
    StartPage-AJ
    StartPage-AE
    StartPage-X
    StartPage-R
    StartPage-O
    StartPage-L
    StartPage-I
    StartPage-E
    StartPage-AZ
    StartPage-Z
    StartPage-BE
    StartPage-BD
    StartPage-BH
    StartPage-BM
    StartPage-BY
    StartPage-BV
    StartPage-BU
    StartPage-BZ
    StartPage-GG
    StartPage-EL
    StartPage-FR
    StartPage-FV
    StartPage-EO
    StartPage-EV
    StartPage-FI
    StartPage-EZ
    StartPage-DY
    StartPage-DE
    StartPage-DC
    StartPage-FA
  Win32 (11)
    Generic BackDoor.b
    HackerDefender
    Generic BackDoor.e
    FURootkit
    Generic Dropper.a
    QLowZones-12
    Pokey.a
    QLowZones-2
    Generic StartPage.e
    Generic packed
    MSNPeriod
Virus (105)
   (9)
    Nomad.888
    Amber.3104
    Vienna.822
    Vienna.901
    Vienna.636
    Vienna.605
    Vienna.510
    VIP
    OC.666
  Boot dropper (1)
    BtDr.Michelangelo
  Companion (2)
    HLL.cmp
    Offspring.cmp.1142
  Damaged (1)
    W32/Pate.dam
  Damaged Worm (1)
    W32/Sdbot.worm.dam
  Dropper (7)
    Univ/a.dr
    Univ/f.dr
    Pamyat.dr
    CriCri.dr
    Offspring.dr
    W32/Pate.dr
    W32/Kipis.e.dr
  E-mail (8)
    W32/Mydoom.o@MM
    W32/Mydoom.be@MM
    W32/Mydoom.bb@MM
    W32/Mydoom.bc@MM
    W32/Mydoom.bd@MM
    W32/Derdero.a@MM
    W32/Mydoom.ap@MM
    W32/Mydoom.ae@MM
  E-mail worm (4)
    W32/Mimail.q@MM
    W32/Mydoom.n@MM
    W32/Mydoom.ab@MM
    W32/Kipis.b@MM
  Email (17)
    W32/Mydoom.d@MM
    W32/Mydoom.ba@MM
    W32/Mydoom.ay@MM
    W32/Kipis.g@MM
    W32/Kipis.f@MM
    W32/Mydoom.az@MM
    W32/Mydoom.ax@MM
    W32/Mydoom.af@MM
    W32/Mydoom.ad@MM
    W32/Bagz.a@MM!zip
    W32/Kipis.c@MM
    W32/Mydoom.ar@MM
    W32/Kipis.e@MM
    W32/Kipis.d@MM
    W32/Mydoom.y@MM
    W32/Bagz.d@MM!zip
    W32/Mydoom.ac@MM
  Email Generic (3)
    W32/Sober.gen@MM
    W32/Mydoom.gen@MM
    W32/Kipis.gen@MM
  Email Worm (2)
    W32/Mydoom.r@MM
    W32/Kipis.a@MM
  File Infector (1)
    Vienna
  Generic (3)
    SRCG.gen
    W32/Poebot.gen
    W32/Sdbot.gen.r
  Generic Worm (13)
    W32/Sdbot.worm.gen.a
    W32/Sdbot.worm.gen
    W32/Gaobot.worm.gen.e
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.f
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.o
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.ad
    W32/Gaobot.worm.gen.t
    W32/Sdbot.worm.gen.u
    W32/Sdbot.worm.gen.p
  Heuristic (1)
    New AOL
  Internet Worm (2)
    W32/Sdbot.worm
    W32/Bropia.worm.g
  MS Office Suite (1)
    VBA/Generic.src
  Overwriting (1)
    Univ.ow/a
  Parasitic (2)
    Grog.cav
    Grog.cav.474
  Script (2)
    Bat/mos
    Bat/dt137
  Universal (4)
    Univ/b
    Univ/f
    Univ/a
    Univ.topsy
  Win32 (7)
    New Win32
    W32/Pate.c
    W32/Pate.a
    W32/Deadcode
    W32/Generic.m
    W32/Generic.Delphi.a
    W32/Pate.d
  Worm (13)
    W32/Pate.b
    W32/Dedler.worm
    W32/Myfip.worm
    W32/Bropia.worm.f
    W32/Bropia.worm.k
    W32/Bropia.worm.i
    W32/Bropia.worm.l
    W32/Bropia.worm.j
    W32/Bropia.worm.h
    W32/Bropia.worm.o
    W32/Refaz.worm
    W32/Bropia.worm.p
    W32/Mydoom.t@MM