Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4489
DAT Release Date 05/11/2005
Threats Detected 126019
New Detections 96
Enhanced Detections 342

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (34)
  Adware (22)
    Adware-SurfBuddy
    Adware-SpeedBar
    Adware-SMAC
    Adware-Sipspi
    Adware-SimpleBar
    Adware-Shotech
    Adware-SearchFast
    Adware-RiverSoft
    JS/Adware-PurityScan
    Adware-StaticBuys
    Adware-Serch
    Adware-Ramm
    Adware-Powerreg
    Adware-Ndware
    Adware-NaviHelper
    Adware-MediaTickets
    Adware-MakeShortcut
    Adware-NeoToolbar
    Adware-NDotNet
    Adware-Megasearch
    Adware-MarketDart
    Adware-LookNSearch
  Application extension (4)
    Adware-SurfSideKick.dll
    Adware-Softomate.dll
    Adware-Ro2cn.dll
    Adware-OpenSite.dll
  Dropper (5)
    Adware-SrchEnh.dr
    Adware-SpySpotter.dr
    Adware-Slotch.dr
    Adware-Redalert.dr
    Adware-Ramm.dr
  Joke (1)
    Joke-Hearts
  Win32 (2)
    RageDNS
    PortScan-Petmar
Trojan (15)
  Application extension (2)
    BackDoor-CQK.dll
    Puper.dll
  Client (1)
    BackDoor-CRV.cli
  Configurator (1)
    BackDoor-CRU.cfg
  Demonstration (2)
    JS/Exploit-Favi.demo
    Exploit-MS05-024.demo
  Downloader (2)
    Downloader-AAP
    Downloader-AAO
  Generic (1)
    PWS-Banker.gen.r
  Malware Tool (1)
    Kit-Ultras
  Remote Access (2)
    BackDoor-CRV
    BackDoor-CRU
  Script (1)
    VBS/Zard
  Win32 (2)
    Puper
    Generic Dropper.m
Virus (47)
   (27)
    YD.2449
    Vienna.Windsor.1881a
    Trident.574
    Satan.785
    Satan.659
    Satan.612
    Satan.602
    Redarc.1374
    Odessa.735c
    MPC.848
    Jeru.1813x
    Jeru-h.1808e
    Jeru-h.1808d
    Jeru-h.1808c
    TeaParty.1609
    Sjortari.398
    Siskin.506
    OC/Revenger.512
    Norge.643
    Mirea.1800a
    Luce.1883
    Trident.633
    Oldyank.1662
    Mirea.1832c
    Mazur.2541.a
    Chelle.unk
    Brother.4100
  Boot dropper (1)
    BtDr.Exebug
  Companion (1)
    RPME.cmp.j
  Damaged (6)
    Retaliator.dam
    Tentatrickle.dam
    Panek.dam
    Pojer.dam
    OC/greg.dam
    Evil.108.dam
  Dropper (8)
    Olya.dr
    Npox.891.dr
    Siskin.dr
    Proto.1799.dr
    Pollute.545.dr
    Coca.576.dr
    Pollute.829.dr
    Coke.669.dr
  Email (1)
    W32/Antiman@MM
  Parasitic (1)
    Covina.apd
  Win32 (1)
    W32/Netsky.oMM
  Worm (1)
    W32/Kelvir.worm.bg

Enhanced Detections:

- (1)
  - (1)
    Adware-OverPro
Internet Worm (1)
  Win32 (1)
    New Worm
Program (34)
   (2)
    VObj9
    VObj18
  Adware (25)
    Adware-SaveNow
    Adware-PortalScan
    Adware-SubSearch
    Adware-MemWatcher
    Adware-SAHAgent
    Adware-SideSearch
    Adware-SafeSearch
    Adware-PurityScan
    Adware-SRNG
    Adware-SearchAid
    Adware-Nsupdate
    Adware-Lop
    Adware-SearchSquire
    Adware-OpenSite
    Adware-Slotch
    Adware-Redalert
    Adware-OMI
    Adware-ShopprReports
    Adware-SrchEnh
    Adware-SurfSideKick
    Adware-Softomate
    Adware-BroadCastPC
    Adware-Simbar
    Adware-Roings
    Adware-Qoolaid
  Downloader (1)
    Adware-SAHAgent.dldr
  Dropper (3)
    Adware-SAHAgent.dr
    Adware-BroadCastPC.dr
    Adware-Softomate.dr
  Spyware (1)
    Spyware-RemoteSpy
  Tool (1)
    HideRun
  Win32 (1)
    PortScan-Angry
Trojan (65)
   (3)
    Generic BackDoor.d
    Yam
    Generic.b3
  - (1)
    IRC/Flood.mirc
  Application extension (4)
    BackDoor-BAE.dll
    PWS-Legmir.dll
    BackDoor-CQM.dll
    BackDoor-ASB.c.dll
  Configurator (2)
    Downloader-GG.cfg
    MultiDropper-HN.cfg
  Denial Of Svc (1)
    IRC/Flood.bk
  Downloader (1)
    PWS-Banker.a.dldr
  Dropper (4)
    Adware-SubSearch.dr
    VBS/Inor
    MultiDropper-HN
    Downloader-JF.dr
  Exploit (1)
    Exploit-1Table
  Generic (4)
    PWS-Banker.gen.a
    HackerDefender.gen.c
    PWS-Banker.gen.i
    PWS-Banker.gen.o
  Heuristic (2)
    New Malware.f
    New Malware.h
  Password (1)
    PWS-LegMir
  Password Stealer (2)
    PWS-Banker.l
    PWS-Banker.a
  Proxy (2)
    Proxy-FBSR
    Proxy-Fireby
  Remote Access (19)
    BackDoor-AXJ
    BackDoor-ARR
    BackDoor-AWQ.b
    BackDoor-AVW
    BackDoor-BAC
    BackDoor-AKD
    BackDoor-CHC
    BackDoor-ANC
    BackDoor-FK
    BackDoor-CNQ
    BackDoor-CPI
    BackDoor-CPC
    BackDoor-CQL
    BackDoor-CQM
    BackDoor-CQZ
    Generic BackDoor.l
    BackDoor-CMG
    BackDoor-CKB
    Generic BackDoor.n
  Win32 (18)
    Generic BackDoor.b
    HackerDefender
    Generic BackDoor.h
    Generic BackDoor.f
    HackerDefender.sys
    Uploader-X
    Generic BackDoor.g
    Generic Downloader.p
    SpoofDNS
    QLowZones-12
    Generic BackDoor.r
    Spyre
    Generic PWS.o
    Generic QLowZones.a
    Generic BackDoor.u
    Generic Downloader.ab
    QLowZones-2
    DDoS-Boxed
Virus (241)
   (107)
    SME
    DGME
    Cocaine.664
    TPE.1.4.Cofshop.a
    TPE.1.4.Girafe.f
    TPE.1.4.Girafe.d
    TPE.1.4.Girafe.b
    TPE.1.4.Nondes
    TPE.1.4.Poetcode
    SMEG.V3
    SMEG.Queeg.b
    SMEG.Pathgen.b
    Redarc.1399
    TPE.1.4.Adin
    TPE.1.4.2680
    TPE.1.4.YB1
    TPE.1.4.WildLick
    TPE.1.4.Eccles
    TPE.1.4.Cofshop.b
    TPE.1.4.Girafe.g
    TPE.1.4.Girafe.e
    TPE.1.4.Girafe.c
    TPE.1.4.Girafe.a
    TPE.1.4.Youba
    TPE.1.4.Bosnia
    SMEG.Tri
    SMEG.Queeg.c
    SMEG.Queeg.a
    SMEG.Pathgen.a
    Lucky
    DJ-twenty
    Jeru.Yellow.1363
    Timid.382a
    Timid.306b
    Timid.513a
    Timid.310
    Timid.431
    Timid.497c
    Timid.497a
    Timid.309
    Timid.513b
    Tiny-DI
    Timid.557
    Timid.526
    Timid.497b
    Timid.382b
    Timid.371b
    Timid.371a
    Timid.320
    Timid.313
    Timid.306d
    Timid.306c
    Timid.306a
    Timid.305b
    Timid.305a
    Timid.303b
    Timid.302b
    Timid.301c
    Timid.301a
    Timid.300a
    Timid.299
    Timid.298c
    Timid.298a
    Timid.297e
    Timid.297c
    Timid.297a
    Timid.290e
    Timid.290c
    Timid.290a
    Timid.288
    Timid.245
    Timid.305c
    Timid.303a
    Timid.302a
    Timid.301b
    Timid.300b
    Timid.298b
    Timid.297f
    Timid.297d
    Timid.297b
    Timid.295
    Timid.290d
    Timid.290b
    Timid.289
    Timid.263
    Sodo.5142
    Sodo.4590
    Luce.4619
    Luce.3756
    Len.702
    City.1679
    Vienna.Windsor.1881
    Mirea.1800
    Mini.e
    Sodo.4556
    Phil
    Luce.4200
    Luce.3600
    Timid.306e
    Rael.3211b
    Metal.400
    Mazur.2541
    Tenbytes.1514
    Tenbytes.1411
    Sodo.4600
    Tenbytes.1431
    Tenbytes.1410
  Application extension Generi (1)
    W32/Bagle.dll.gen
  Boot (1)
    Ping-Pong
  Damaged (5)
    TPE.1.4.dam
    MPC.940.dam
    Intruder.dam
    Sodo.dam
    W32/Mytob.dam
  Damaged Worm (2)
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  Demonstration (1)
    SMEG.Demo.d
  Downloader Worm (1)
    W32/Bropia.worm.dldr
  Dropper (10)
    VCL.dr
    Suriv.dr
    Univ/a.dr
    Univ/j.dr
    Univ/r.dr
    Univ/o.dr
    Jeru.dr
    NRLG.dr
    W32/Pate.dr
    W32/Jeefo.dr
  E-mail (1)
    W32/Netsky.z@MM
  Email (26)
    W32/Mytob.ao@MM
    W32/Mytob.al@MM
    W32/Mytob.as@MM
    W32/Mytob.ap@MM
    W32/Mytob.p@MM
    W32/Mytob.i@MM
    W32/Mytob.k@MM
    W32/Mytob.r@MM
    W32/Mytob.c@MM
    W32/Mytob.m@MM
    W32/Mytob.q@MM
    W32/Mytob.h@MM
    W32/Mytob.j@MM
    W32/Mytob.l@MM
    W32/Mytob.o@MM
    W32/Mytob.u@MM
    W32/Mytob.t@MM
    W32/Mytob.x@MM
    W32/Mytob.w@MM
    W32/Mytob.y@MM
    W32/Mytob.ab@MM
    W32/Mytob.aa@MM
    W32/Mytob.ad@MM
    W32/Mytob.af@MM
    W32/Mytob.aj@MM
    W32/Mytob.z@MM
  Email Generic (1)
    W32/Mytob.gen@MM
  File Infector (2)
    ECW.570
    NPox
  Generic Worm (25)
    W32/Sdbot.worm.gen
    W32/Gaobot.worm.gen.e
    W32/Spybot.worm.gen.f
    W32/Sdbot.worm.gen.bg
    W32/Gaobot.worm.gen.bj
    W32/Spybot.worm.gen.bj
    W32/Gaobot.worm.gen.j
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.i
    W32/Sdbot.worm.gen.g
    W32/Kelvir.worm.gen
    W32/Sdbot.worm.gen.bd
    W32/Gaobot.worm.gen.bc
    W32/Gaobot.worm.gen.bw
    W32/Sdbot.worm.gen.bh
    W32/Sdbot.worm.gen.by
    W32/Sdbot.worm.gen.bj
    W32/Sdbot.worm.gen.bw
    W32/Gaobot.worm.gen.bh
    W32/Gaobot.worm.gen.bi
    W32/Gaobot.worm.gen.by
    W32/Sdbot.worm.gen.y
  Heuristic (1)
    New Malware.b
  Internet Worm (5)
    W32/Kelvir.worm.c
    W32/Kelvir.worm.b
    W32/Kelvir.worm.f
    W32/Bropia.worm.gen
    W32/Bropia.worm.d
  Malware Tool (2)
    VCL.kit
    BW.kit
  multipartite (7)
    Alar.mp.4270
    Hare.mp.7786
    Hare.mp.7610b
    Hare.mp.7786x
    Hare.mp.7610a
    Hare.mp.7750b
    Hare.mp.7750a
  Parasitic (1)
    NMSG.cav
  Universal (1)
    Univ/j
  Win32 (1)
    W32/Jeefo
  Worm (40)
    W32/Bropia.worm.e
    W32/Kelvir.worm.al
    W32/Kelvir.worm.ap
    W32/Kelvir.worm.an
    W32/Kelvir.worm.ao
    W32/Kelvir.worm.am
    W32/Kelvir.worm.ax
    W32/Kelvir.worm.az
    W32/Bropia.worm.ap
    W32/Dedler.worm
    W32/Kelvir.worm.ba
    W32/Kelvir.worm.ay
    W32/Kelvir.worm.e
    W32/Kelvir.worm.d
    W32/Kelvir.worm.g
    W32/Kelvir.worm.i
    W32/Kelvir.worm.k
    W32/Kelvir.worm.j
    W32/Bropia.worm.m
    W32/Kelvir.worm.a
    W32/Kelvir.worm.o
    W32/Kelvir.worm.n
    W32/Kelvir.worm.p
    W32/Kelvir.worm.s
    W32/Kelvir.worm.l
    W32/Kelvir.worm.m
    W32/Kelvir.worm.t
    W32/Kelvir.worm.q
    W32/Bropia.worm.ac
    W32/Kelvir.worm.w
    W32/Kelvir.worm.ak
    W32/Kelvir.worm.ab
    W32/Bropia.worm.ag
    W32/Kelvir.worm.ac
    W32/Bropia.worm.af
    W32/Kelvir.worm.aj
    W32/Kelvir.worm.ai
    W32/Bropia.worm.b
    W32/Bropia.worm.a
    W32/Bropia.worm.c