Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4640
DAT Release Date 11/30/2005
Threats Detected 162496
New Detections 24
Enhanced Detections 340

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (5)
   (1)
    Tool/av2
  Adware (1)
    Adware-Zquest
  Joke (1)
    Joke-ScreenRes
  Win32 (2)
    PrcViewer
    Clipsvr
Trojan (10)
   (1)
    Apropos
  Application extension (1)
    Spy-Loxxee.dll
  Downloader (3)
    Downloader-ARP
    Downloader-ARO
    Downloader-UA.f
  Malware Tool (1)
    RootKit-SMECore
  Proxy (1)
    Proxy-Agent.ag
  Tool (1)
    Tool-Sclist
  Win32 (2)
    Del-490
    DMeco
Virus (9)
   (2)
    Scram.1253
    Svir.512b
  Generic (2)
    W32/IRCbot.gen.f
    W32/Bagz.gen
  Peer To Peer (3)
    W32/Bugger!p2p
    W32/Platinum!p2p
    W32/Oost!p2p
  Script (1)
    Bat/evan
  Worm (1)
    W32/Miti.worm

Enhanced Detections:

- (1)
  Trojan (1)
    Haher
Malware (2)
  Exploit (1)
    Exploit-CodeBase
  Trojan (1)
    PWS-Likun
Program (45)
   (3)
    Benediction
    Generic PUP.a
    Generic PUP.b
  - (1)
    RemAdm-PSKill
  Adware (15)
    Adware-Virtumundo
    Adware-Superbar
    Adware-Look2Me
    Adware-Websearch
    Adware-PromulGate
    Adware-SideSearch
    Adware-Gain
    Adware-SearchAid
    Adware-Xupiter
    Adware-BlogCn
    Adware-WinAd
    Adware-Alexa
    Adware-DealHelper
    Adware-ClickSpring
    Adware-abetterintrnt
  Application extension (2)
    Clearsearch.dll
    Favadd.dll
  Dialer (2)
    Dialer-257
    Dialer-185
  Downloader (3)
    PosX
    PosX.dldr
    Adware-Websearch.dldr
  Dropper (8)
    Adware-NetPals.dr
    Adware-SideSearch.dr
    ILookup.dr
    Adware-BroadCastPC.dr
    Adware-SafeSurf.dr
    Adware-BkdSpace.dr
    Generic Adware.dr
    Adware-WinAd.dr
  Generic (1)
    Dialer-256.gen
  Keylogger (1)
    Keylog-Ardamax.dr
  Registry (1)
    ZapChast
  StartPage (1)
    StartPage-IG
  Tool (1)
    Tool-LogKill
  Win32 (6)
    iGetNet
    PortScan-Xray
    HideExec
    PortWatch
    RemAdm-ProcLaunch
    PortScan-Zzbc
Trojan (112)
   (5)
    Generic BackDoor.d
    Generic component
    Generic BackDoor.bb
    Generic.dc
    Generic.cb
  Adware (1)
    AdClicker-DI
  Application extension (4)
    BackDoor-BAC.dll
    PWS-Banker.j.dll
    Generic Proxy.dll
    Vundo.dll
  Client (3)
    BackDoor-AFZ.cli
    BackDoor-CPJ.cli
    IRC/BackDoor-Sub7.cli
  Configuration settings (1)
    HackerDefender.ini
  Configurator (1)
    PWS-Likun.cfg
  Downloader (5)
    Downloader-DC
    Downloader-WG
    PWS-Banker.dldr
    Downloader-AGF
    Downloader-AGE
  Dropper (3)
    BackDoor-AVW.dr
    BackDoor-AWQ.b.dr
    MultiDropper-OR
  Dropper Worm (1)
    W32/Sdbot.worm.dr
  Exploit (3)
    Exploit-ContentType
    Exploit-ObscuredHtml
    Exploit-MS03-037
  Generic (9)
    Generic Downloader.gen.be
    BackDoor-AVW.gen
    PWS-Banker.gen.ba
    PWS-Banker.gen.bb
    PWS-Banker.gen.j
    PWS-Banker.gen.i
    PWS-Banker.gen.g
    PWS-Banker.gen.t
    Downloader-ZQ.gen
  Generic Worm (1)
    W32/Sdbot.worm.gen.ax
  Heuristic (2)
    New Malware.n
    New Malware.j
  JavaScript (1)
    JS/CardStealer
  Macro (4)
    A97M/AcceV
    X97M/Darra.b
    W97M/Vipeep
    X97M/Darra.a
  Password (1)
    PWS-LegMir
  Password Stealer (4)
    Generic PWS.a
    PWS-Banker.af
    PWS-QQRob
    PWS-MMThief
  Plugin component (1)
    Orifice2K.plugin
  Proxy (3)
    Proxy-FBSR
    Proxy-Fireby
    Proxy-Piky
  Remote Access (11)
    BackDoor-ACH
    BackDoor-ARR
    BackDoor-AWQ.b
    BackDoor-AGB
    BackDoor-IP
    BackDoor-AFZ
    BackDoor-IQ.a
    BackDoor-IQ.b
    BackDoor-CPJ
    Generic BackDoor.k
    BackDoor-CKB
  Script (1)
    X97M/War.bat
  Server (3)
    Orifice2K.svr
    BackDoor-AFZ.svr
    BackDoor-ARR.svr
  Win32 (44)
    Generic VB
    Generic Downloader.b
    ServU-Daemon
    HackerDefender
    Generic BackDoor.f
    Generic Downloader.c
    AdClicker-AF
    Pokey.b
    Promises
    Generic BackDoor.e
    Orifice.sniff
    Orifice2K
    Dpbot
    Halloway
    HackerDefender.sys
    HideOut
    Drone
    Generic Downloader.ak
    DRevenge
    Generic VB.b
    Generic Downloader.ad
    Generic Downloader.p
    Puper
    Generic.d
    QHosts-44
    QLowZones-6
    SrchRedir
    Generic Downloader.u
    Generic AdClicker.b
    Generic PWS.o
    DNSChanger.a
    Generic Dropper.i
    Generic Downloader.ab
    DNSChanger.b
    Generic VB.c
    Druogna
    Generic Downloader.ac
    Generic.b
    Qoolaid
    Hangup
    GermanHolidays
    Project
    Generic Downloader.f
    Generic Downloader.h
Virus (180)
   (2)
    HLL.sub
    A2K/Walla
  Damaged (26)
    W32/Netsky.dam
    XM/Laroux.cf.dam
    XM/Laroux.dam.au
    W97M/Tristate.aw.dam
    X97M/Laroux.dam.ho
    XM/Laroux.dam.bp
    X97M/Laroux.dam.ae
    XM/Laroux.dam.af
    XM/Laroux.dam.k
    XM/Laroux.dam.j
    XM/Laroux.dam.g
    XM/Laroux.a.dam
    PP97M/Tristate.dam
    PP97M/Tristate.aw.dam
    W97M/Tristate.dam
    X97M/Laroux.dam.is
    X97M/Laroux.dam.bp
    X97M/Laroux.dam.cz
    X97M/Laroux.dam.e
    XM/Laroux.dam.cz
    XM/Laroux.dam.ae
    XM/Laroux.dam.e
    XF/Paix.dam
    A97M/Walla.dam
    X97M/Tristate.dam
    X97M/Tristate.aw.dam
  Damaged Generic (4)
    X97M/Laroux.dam.ho.gen
    X97M/Laroux.dam.e.gen
    XM/Laroux.dam.e.gen
    X97M/Laroux.dam.bp.gen
  Damaged Worm (1)
    W32/Sdbot.worm.dam
  Dropper (5)
    AM/Supersonic.dr.b
    AM/Supersonic.dr.a
    W32/Valla.dr
    AM/Supersonic.dr
    AM/AccessiV.dr
  E-mail (1)
    W32/Sober@MM!M681
  E-mail worm (2)
    W32/Bagz.d@MM
    W32/Bagz.e@MM
  Email (17)
    W32/Sober.k@MM!zip
    W32/Sober.p@MM!zip
    W32/Sober.d@MM!zip
    W32/Sober.e@MM!zip
    W32/Bagz.g@MM
    W32/Bagz.aa@MM
    W32/Sober.j@MM!zip
    W32/Sober.l@MM!zip
    W32/Sober.o@MM!zip
    W32/Bagz.f@MM
    W97M/Linda@MM
    W32/Bagz.a@MM
    X97M/War@MM
    X97M/Linda@MM
    W32/Sober.g@MM!zip
    W32/Bagz.c@MM
    W32/Bagz.b@MM
  Email Generic (3)
    W32/Rontokbro.gen@MM
    W32/Loosky.gen@MM
    W32/Bagz.gen@MM
  File Infector (2)
    W32/Valla.b
    W32/Valla.a
  Floppy (1)
    W32/Generic!floppy
  Generic (24)
    XM/Laroux.gen
    X97M/Barisada.gen
    X97M/Toraja.gen
    XM/Laroux.ho.gen
    W97M/Toraja.gen
    X97M/Yawn.gen
    X97M/Laroux.dx.gen
    XM/Laroux.e.gen
    X97M/Laroux.a.gen
    X97M/Laroux.e.gen
    XM/Laroux.a.gen
    X97M/Neg.e.gen
    X97M/Manalo.gen
    X97M/Hit.gen
    XF/Paix.gen
    W97M/Shiver.gen
    X97M/Divi.gen
    X97M/Laroux.au.gen
    X97M/Sugar.gen
    X97M/Laroux.ho.gen
    X97M/Laroux.dm.gen
    XM/Bulet.gen
    PP97M/Tristate.gen
    X97M/Shiver.gen
  Generic Worm (18)
    W32/IRCbot.worm.gen
    W32/Sdbot.worm.gen.as
    W32/Sdbot.worm.gen.br
    W32/Sdbot.worm.gen.bg
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.j
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.bk
    W32/Sdbot.worm.gen.bs
    W32/Sdbot.worm.gen.aw
    W32/Spybot.worm.gen.o
    W32/Sdbot.worm.gen.by
    W32/Sdbot.worm.gen.y
    W32/Sdbot.worm.gen.z
    W32/Sdbot.worm.gen.ac
    W32/Sdbot.worm.gen.t
    W32/Sdbot.worm.gen.q
  Heuristic (1)
    New Script.ext
  Intended (2)
    X97M/Bonker.b.intd
    X97M/Bonker.intd
  Internet Worm (1)
    W32/Sdbot.worm!MS05-039
  Macro (64)
    XF/Sic.gen
    X97M/Laroux
    XF/Paix.A
    XM/Laroux.AF
    XM/Laroux.AE
    XM/Laroux.V
    XM/LAROUX.H
    X97M/Laroux.DO
    X97M/Laroux.A
    X97M/Vcx.A
    X97M/Tristate.gen
    W97M/Tristate.gen
    X97M/Laroux.e
    XM/Ninja.a
    X97M/Laroux.ho
    X97M/Reten.gen
    X97M/Extras
    X97M/Laroux.is
    X97M/Laroux.ns
    W97M/Toraja.s
    XF/NetSnake.c
    X97M/Laroux.cz
    XM/Laroux.k
    XM/Laroux.g
    XM/Laroux.dd
    XM/Laroux.n
    XM/Laroux.f
    X97M/Laroux.ae
    XM/Laroux.cz
    XM/Laroux.j
    XM/Laroux.e
    X97M/Laroux.dd
    X97M/Laroux.bw
    X97M/Laroux.x
    X97M/Laroux.u
    X97M/Laroux.l
    X97M/Laroux.f
    X97M/Laroux.d
    X97M/Laroux.c
    X97M/Laroux.b
    XM/Laroux.gt
    XM/Laroux.db
    XM/Laroux.dy
    XM/Laroux.bw
    XM/Laroux.bk
    XM/Laroux.r
    XM/Laroux.o
    XM/Laroux.i
    XM/Laroux.c
    XM/Laroux.a
    XM/Laroux.p
    XM/Laroux.d
    XM/Laroux.b
    X97M/Xal.b
    X97M/Sugar.app
    XM/Laroux.ho
    X97M/Laroux.ei
    X97M/Bonker.c
    A97M/Walla
    X97M/Xal.a
    X97M/Manuela
    XM/Laroux.is
    X97M/Bonker.a
    remnants-X97M/Toraja
  Malware Tool (1)
    PP97M/PMG.Kit
  Script (1)
    Lupus.bat
  Win32 (4)
    W32/Valla.c
    W32/Generic.d
    W32/Valla.d
    W32/Generic!im