Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4603
DAT Release Date 10/12/2005
Threats Detected 153000
New Detections 21
Enhanced Detections 149

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (4)
   (1)
    Tool/dirmore
  Malware Tool (1)
    VTool/fakez
  ProcKill (1)
    ProcKill-GXP
  Script (1)
    Tool/silence
Trojan (13)
   (2)
    Azag
    Swizzor
  - (2)
    PSPBrick
    DSTahen.a
  Application extension (1)
    PWS-RXJH.dll
  Downloader (2)
    Downloader-AGB
    Swizzor.dldr
  Dropper (1)
    Swizzor.dr
  Password Stealer (1)
    PWS-RXJH
  Script (2)
    Bat/avk74
    Bat/qd324
  Tool (1)
    Tool-FilWal
  Win32 (1)
    Lop
Virus (4)
   (1)
    MMCA.879
  Companion multipartite (1)
    GoldBug.mp.cmp.k
  Email (1)
    W32/Mytob.ge@MM
  Generic (1)
    W32/Chir.gen

Enhanced Detections:

Internet Worm (1)
  E-mail (1)
    W32/Bagle.gen@MM
Program (9)
  Adware (4)
    Adware-Lop
    Adware-SpySheriff
    Adware-NaviPromo
    Adware-Searchwords
  Downloader (1)
    Adware-Lop.dldr
  Dropper (1)
    Adware-Lop.dr
  Generic (1)
    Adware-Lop.gen
  Malware Tool (1)
    VTool/fake
  Tool (1)
    HideRun
Trojan (42)
   (4)
    Generic component
    ServU Install
    Generic BackDoor.bb
    Malformed Archive
  - (1)
    Bedrill
  Application extension (4)
    PWS-Gina.dll
    Puper.dll
    PWS-Vipgsm.dll
    BackDoor-CQM.dll
  Configuration settings (1)
    ServU.ini
  Downloader (2)
    Proxy-Mitglieder
    Downloader-ACV
  Dropper (2)
    Downloader-QG.dr
    AdClicker-AF.dr
  Exploit (1)
    Exploit-ObscuredHtml
  Generic (7)
    Generic Downloader.gen.be
    Exploit-URLSpoof.gen
    PWS-Banker.k.gen
    PWS-Banker.gen.ba
    PWS-Banker.gen.bb
    ServU-Daemon.gen.ba
    ServU-Daemon.gen.bb
  Heuristic (2)
    New Malware.u
    New Malware.h
  Password Stealer (2)
    PWS-Banker.ad
    PWS-Vipgsm
  Proxy (1)
    Proxy-Piky
  Remote Access (4)
    BackDoor-AWQ.b
    BackDoor-CQM
    Generic BackDoor.k
    BackDoor-CKB
  Win32 (11)
    Generic VB
    Generic Downloader.b
    Generic BackDoor.be
    Generic BackDoor.bc
    Generic BackDoor.ba
    Swizzor.gen
    Generic PWS.o
    Generic QLowZones.a
    Generic Downloader.ab
    Generic Packed
    DDoS-Boxed
Virus (97)
  AutoLisp (1)
    ALS/Bursted
  Damaged (1)
    W32/Mytob.dam
  Damaged Worm (2)
    W32/Spybot.worm.dam
    W32/Sdbot.worm.dam
  Email (58)
    W32/Mytob.ao@MM
    W32/Mytob.al@MM
    W32/Mytob.ew@MM
    W32/Mytob.fa@MM
    W32/Rontokbro.a@MM
    W32/Mytob.ft@MM
    W32/Mytob.fs@MM
    W32/Mytob.aw@MM
    W32/Mytob.fr@MM
    W32/Mytob.ba@MM
    W32/Rontokbro.b@MM
    W32/Mytob.bc@MM
    W32/Mytob.bb@MM
    W32/Mytob.bd@MM
    W32/Mytob.fu@MM
    W32/Mytob.fw@MM
    W32/Mytob.fv@MM
    W32/Mytob.bu@MM
    W32/Mytob.bq@MM
    W32/Mytob.by@MM
    W32/Mytob.cq@MM
    W32/Mytob.ck@MM
    W32/Mytob.fz@MM
    W32/Mytob.cw@MM
    W32/Mytob.p@MM
    W32/Mytob.i@MM
    W32/Mytob.k@MM
    W32/Mytob.r@MM
    W32/Mytob.m@MM
    W32/Mytob.bs@MM
    W32/Mytob.de@MM
    W32/Mytob.cb@MM
    W32/Mytob.do@MM
    W32/Mytob.dl@MM
    W32/Mytob.h@MM
    W32/Mytob.j@MM
    W32/Mytob.l@MM
    W32/Mytob.o@MM
    W32/Mytob.t@MM
    W32/Mytob.x@MM
    W32/Mytob.y@MM
    W32/Mytob.cr@MM
    W32/Mytob.cl@MM
    W32/Mytob.ci@MM
    W32/Mytob.cx@MM
    W32/Mytob.cy@MM
    W32/Mytob.dn@MM
    W32/Mytob.ei@MM
    W32/Mytob.aa@MM
    W32/Mytob.ad@MM
    W32/Mytob.dw@MM
    W32/Mytob.dv@MM
    W32/Mytob.du@MM
    W32/Mytob.aj@MM
    W32/Mytob.z@MM
    W32/Mytob.eg@MM
    W32/Mytob.em@MM
    W32/Mytob.en@MM
  Email Generic (2)
    W32/Rontokbro.gen@MM
    W32/Mytob.gen@MM
  Generic Worm (23)
    W32/Spybot.worm.gen.e
    W32/Sdbot.worm.gen.w
    W32/Sdbot.worm.gen.bg
    W32/Gaobot.worm.gen.bj
    W32/Opanki.worm.gen
    W32/Sdbot.worm.gen.ar
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.x
    W32/Sdbot.worm.gen.bk
    W32/Sdbot.worm.gen.bs
    W32/Spybot.worm.gen.o
    W32/Sdbot.worm.gen.bd
    W32/Sdbot.worm.gen.bh
    W32/Sdbot.worm.gen.bi
    W32/Sdbot.worm.gen.by
    W32/Sdbot.worm.gen.bj
    W32/Sdbot.worm.gen.bw
    W32/Gaobot.worm.gen.by
    W32/Sdbot.worm.gen.y
    W32/Sdbot.worm.gen.t
    W32/Bobax.worm.gen
    W32/Sdbot.worm.gen.bm
  Heuristic (1)
    New Script.ext
  multipartite (1)
    Pofu.mp
  Overwriting (1)
    Univ.ow/a
  Worm (7)
    W32/Bobax.worm.j
    W32/Bobax.worm.h
    W32/Bobax.worm.f
    W32/Bobax.worm.i
    W32/Bobax.worm.g
    W32/Opanki.worm
    W32/Bobax.worm.e