Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4508
DAT Release Date 06/07/2005
Threats Detected 129864
New Detections 37
Enhanced Detections 294

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (9)
   (1)
    QHosts-33!hosts
  Application extension (3)
    Adware-CWS.dll
    Adware-CraftSearch.dll
    Proxy-Daemonize.dll
  Dropper (3)
    Adware-NuggetSearch.dr
    Adware-BrowserAid.dr
    Adware-Apropos.dr
  Generic (1)
    Dialer-RAS.dt.gen
  StartPage (1)
    StartPage-CF.url
Trojan (11)
   (2)
    QHosts-34
    Arcbomb.rar
  Exploit (1)
    Exploit-MS02-061
  Flooder (1)
    IRC/FDoS-AutoBot
  Remote Access (2)
    BackDoor-CSQ
    BackDoor-CSP
  Win32 (5)
    Spy-Agent.d
    AdClicker-CX
    AdClicker-CV
    AdClicker-CW
    Generic AdClicker.a
Virus (17)
  Companion (1)
    W32/BCB.cmp
  Damaged (1)
    W32/Supova.dam
  E-mail (2)
    W32/Mytob.bw@MM
    W32/Mytob.bv@MM
  Email (3)
    W32/Mytob.by@MM
    W32/Mytob.bx@MM
    W32/Mytob.bz@MM
  Generic (2)
    W32/IRCbot.gen
    W32/Mytob.gen!eml
  Win31 (1)
    W16/Obor
  Win32 (6)
    W32/Bagle.ag
    W32/Bagle.i
    W32/Bagle.h
    W32/Bagle.g
    W32/Bagle.e
    W32/Bagle.f
  Worm (1)
    W32/Kelvir.worm.ch

Enhanced Detections:

Internet Worm (2)
  E-mail (1)
    W32/Mytob.bk@MM
  E-mail worm (1)
    W32/Wukill.worm
Malware (1)
  Exploit (1)
    Exploit-CodeBase
Program (124)
   (2)
    WareOut
    IMIServer
  - (2)
    Proxy-Daemonize
    IMIServ.download
  Adware (17)
    Adware-ISTbar.b
    Adware-180Solutions
    Adware-PromulGate
    Adware-BB
    Adware-BHO.gen
    Adware-CoolWebSearch
    Adware-Wink
    Adware-BestPhrases
    Adware-Lop
    Adware-BTS
    Adware-NaviPromo
    Adware-AZESearch
    Adware-MediaTickets
    Adware-Adlogix
    Adware-Aveo
    Adware-AccesMembre
    Adware-TopRebates
  Application extension (4)
    Adware-RBlast.dll
    IMIServ.dll
    Tool-ByShell.dll
    Adware-EliteBar.dll
  Downloader (2)
    Adware-POP.dldr
    Adware-ClearSearch.dldr
  Dropper (6)
    Adware-RBlast.dr
    IMIServ.dr
    Adware-ExactSearch.dr
    Adware-StatBlaster.dr
    Adware-Ezula.dr
    Adware-abetterintrnt.dr
  Internet Relay Chat (1)
    IRC-Bircd
  Keylogger (1)
    Keylog-Ardamax
  Server (1)
    IMIServ.svr
  Tool (86)
    Tool-Haxor
    Tool-Addbyte
    Tool-Telnet
    Tool-BODec
    Tool-MacTime
    Tool-Revert
    Tool-HLPDump
    Tool-Analyze
    Tool-AVPX
    Tool-Podonok
    Tool-Pervert
    Tool-QQPassO
    Tool-QQExpl
    Tool-IconHnt
    Tool-CGIScan
    Tool-AutoPol
    Tool-DNSMast
    Tool-AIMRV
    Tool-ZPacker
    Tool-PEStat
    Tool-ZMist
    Tool-COM2UUE
    Tool-CGAGF
    Tool-Jumin
    Tool-Netacess
    Tool-DLLInjector
    Tool-Arpkill
    Tool-CGITest
    Tool-DarkICQ
    Tool-AppToService
    Tool-Antigen
    Tool-AOL.Deceased
    Tool-PGP2TXT
    Tool-RSAKey
    Tool-Tracer
    Tool-PGPDump
    Tool-TXT2DEN
    Tool-Huff
    Tool-DFSG
    Tool-HideWind
    Tool-AVPOffset
    Tool-VecnaLink
    Tool-Chiton
    Tool-IRXPro
    Tool-MLDE32
    Tool-DumpAIT
    Tool-FTransf
    Tool-SNTPTest
    Tool-InfElf
    Tool-PEWrSec
    Tool-AOL.Gag
    Tool-Cerberos
    Tool-Domina
    Tool-CPUInfo
    Tool-AFXFireW
    Tool-ByShell
    Tool-WriteSec
    Tool-Proxy
    Tool-Confluenc
    Tool-ServEnum
    Tool-AOL.Invk
    Tool-Info
    Tool-ICQ.Keep
    Tool-ServUCRC
    Tool-CACLs
    Tool-SetTime
    Tool-FileFake
    Tool-Fport
    Tool-ICQ.SMK
    Tool-Fasong
    Tool-Frank
    Tool-BIN2ASM
    Tool-Qing
    Tool-Joekoe
    Tool-ProxyHun
    Tool-Haxxor
    Tool-DeepFreeze
    Tool-ProxiesR
    Tool-Cookie
    Tool-IconIns
    Tool-Dialupass
    Tool-Console
    Tool-SpeedTest
    Tool-BlackRain
    Tool-UPolyX
    Tool-DiskInfo
  Win32 (2)
    RemAdm-RemoteAdmin
    Favadd
Trojan (56)
   (3)
    Generic component
    AdClicker-AJ
    Generic BackDoor.bb
  - (1)
    BackDoor-AOU
  Application extension (1)
    BackDoor-CRX.dll
  Downloader (3)
    Downloader-VG
    Downloader-VX
    Downloader-GG!chm
  Downloader Generic (1)
    Proxy-FBSR.gen.dldr
  Dropper (7)
    BackDoor-ACH.dr
    IRC/Flood.cl.dr
    IRC/Flood.ba.dr
    Adware-Wink.dr
    MultiDropper-NE
    BackDoor-CKB.dr
    BackDoor-CEP.dr
  Exploit (1)
    VBS/Psyme
  Generic (3)
    Exploit-CodeBase.gen
    Proxy-FBSR.gen
    PWS-Banker.gen.bb
  Heuristic (4)
    New Malware.i
    New Malware.f
    New Malware.g
    New Malware.h
  Internet Relay Chat (4)
    IRC/Flood.cl.hidewin
    IRC/Flood.c
    IRC/Flood.cl
    IRC/Flood.ba.hidewin
  mIRC client (1)
    IRC/Flood.ba.mirc
  Password (2)
    PWS-LegMir
    PWS-LDPinch
  Password Stealer (2)
    Generic PWS.a
    PWS-Lineage
  Proxy (1)
    Proxy-Piky
  Remote Access (6)
    IRC/Flood.c.dr
    BackDoor-ARR
    BackDoor-AMQ
    BackDoor-ANC
    BackDoor-CPV
    BackDoor-CKB
  Server (1)
    BackDoor-ARR.svr
  Tool (2)
    Tool-Snatch
    Tool-Uptime
  Win32 (13)
    Generic BackDoor.b
    HackerDefender
    Generic Downloader.n
    Generic VB.b
    Puper
    Del-470
    Generic BackDoor.ba
    Generic Downloader.af
    AdClicker-CJ
    Generic QLowZones.a
    Generic Downloader.ab
    Generic BackDoor.w
    Generic Downloader.f
Virus (111)
  Damaged (1)
    W32/Mytob.dam
  Damaged Worm (3)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
    W32/Sdbot.worm.dam
  E-mail (7)
    W32/Mytob.be@MM
    W32/Mytob.bi@MM
    W32/Mytob.bj@MM
    W32/Mytob.bo@MM
    W32/Mytob.bl@MM
    W32/Mytob.br@MM
    W32/Mytob.bf@MM
  Email (49)
    W32/Mytob.b@MM
    W32/Mytob.a@MM
    W32/Mytob.ao@MM
    W32/Mytob.al@MM
    W32/Mytob.as@MM
    W32/Mytob.ap@MM
    W32/Mytob.at@MM
    W32/Mytob.aw@MM
    W32/Mytob.av@MM
    W32/Mytob.au@MM
    W32/Mytob.ba@MM
    W32/Mytob.bc@MM
    W32/Mytob.bb@MM
    W32/Mytob.bd@MM
    W32/Mytob.bg@MM
    W32/Mytob.bu@MM
    W32/Mytob.bq@MM
    W32/Mytob.bm@MM
    W32/Mytob.bn@MM
    W32/Mytob.p@MM
    W32/Mytob.i@MM
    W32/Mytob.k@MM
    W32/Mytob.r@MM
    W32/Mytob.e@MM
    W32/Mytob.c@MM
    W32/Mytob.m@MM
    W32/Mytob.g@MM
    W32/Mytob.bs@MM
    W32/Mytob.bt@MM
    W32/Mytob.bp@MM
    W32/Mytob.q@MM
    W32/Mytob.h@MM
    W32/Mytob.j@MM
    W32/Mytob.l@MM
    W32/Mytob.o@MM
    W32/Mytob.n@MM
    W32/Mytob.f@MM
    W32/Mytob.d@MM
    W32/Mytob.u@MM
    W32/Mytob.t@MM
    W32/Mytob.x@MM
    W32/Mytob.w@MM
    W32/Mytob.y@MM
    W32/Mytob.ab@MM
    W32/Mytob.aa@MM
    W32/Mytob.ad@MM
    W32/Mytob.af@MM
    W32/Mytob.aj@MM
    W32/Mytob.z@MM
  Email Generic (1)
    W32/Mytob.gen@MM
  Generic (1)
    W32/Poebot.gen
  Generic Worm (20)
    W32/Spybot.worm.gen.e
    W32/Gaobot.worm.gen.e
    W32/Sdbot.worm.gen.w
    W32/Spybot.worm.gen.f
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.m
    W32/Sdbot.worm.gen.x
    W32/Kelvir.worm.gen
    W32/Gaobot.worm.gen.u
    W32/Sdbot.worm.gen.ad
    W32/Sdbot.worm.gen.bd
    W32/Sdbot.worm.gen.by
    W32/Sdbot.worm.gen.bj
    W32/Sdbot.worm.gen.bw
    W32/Gaobot.worm.gen.by
    W32/Sdbot.worm.gen.y
    W32/Sdbot.worm.gen.z
    W32/Sdbot.worm.gen.t
  Internet Worm (4)
    W32/Sdbot.worm
    W32/Kelvir.worm.bh
    W32/Kelvir.worm.f
    W32/NoChod@MM
  Win32 (2)
    New Win32
    W32/Generic.Delphi.b
  Worm (23)
    W32/Kelvir.worm.al
    W32/Kelvir.worm.ap
    W32/Kelvir.worm.an
    W32/Kelvir.worm.ao
    W32/Kelvir.worm.am
    W32/Kelvir.worm.ax
    W32/Kelvir.worm.az
    W32/Kelvir.worm.ba
    W32/Kelvir.worm.ay
    W32/Kelvir.worm.bg
    W32/Kelvir.worm.e
    W32/Kelvir.worm.ca
    W32/Kelvir.worm.i
    W32/Mytob.worm!im
    W32/Kelvir.worm.o
    W32/Kelvir.worm.p
    W32/Kelvir.worm.l
    W32/Kelvir.worm.q
    W32/Kelvir.worm.w
    W32/Kelvir.worm.ac
    W32/Kelvir.worm.aj
    W32/Kelvir.worm.ai
    W32/Spybot.worm