Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4682
DAT Release Date 01/25/2006
Threats Detected 173043
New Detections 20
Enhanced Detections 280

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (4)
  Dropper (1)
    Spyware-RaxSrch.dr
  Joke (1)
    Joke-FWEG
  Malware Tool (1)
    VTool/4096
  Win32 (1)
    Uploader-AB
Trojan (6)
  Dropper (2)
    ProcKill-DN.dr
    MultiDropper-PS
  Heuristic (1)
    New Malware.af
  ProcKill (1)
    ProcKill-DN
  Remote Access (1)
    BackDoor-CXG
  Win32 (1)
    Del-494
Virus (10)
   (2)
    SymbOS/PBsender.d!app
    HLL.8938
  Application extension (2)
    W32/HLLP.Tiniresu.b.dll
    W32/HLLP.Tiniresu.a.dll
  Downloader Worm (1)
    W32/Shellot.worm.dldr
  Dropper (1)
    Bat/Kads.dr
  Dropper Worm (1)
    W32/Shellot.worm.dr
  Parasitic (2)
    W32/HLLP.Tiniresu.a
    W32/HLLP.Tiniresu.b
  Script (1)
    Bat/Kads

Enhanced Detections:

Internet Worm (7)
  E-mail worm (6)
    W32/Netsky.i@MM
    W32/Netsky.b@MM
    W32/Netsky.t@MM
    W32/Netsky.s@MM
    W32/Netsky.c@MM
    W32/Netsky.a@MM
  Worm (1)
    W32/Polybot.gen!irc
Program (17)
   (1)
    VSource
  Adware (6)
    Adware-180SA
    Adware-ZangoSA
    Adware-Shorty
    Adware-ShopprReports
    Adware-TopRebates
    Adware-abetterintrnt
  Dialer (1)
    Dialer-211
  Dropper (1)
    Adware-abetterintrnt.dr
  Generic (1)
    Adware-Url.gen
  Joke (1)
    Joke-Elite
  Spyware (2)
    Keylog-Perfect
    Spyware-RaxSrch
  Tool (2)
    Clearlogs
    Tool-VBSCrypt
  Win32 (2)
    RemAdm-RemoteAdmin
    FastSearchWeb
Trojan (46)
   (2)
    AdClicker-DH
    Generic Downloader.ar
  - (1)
    Spam-Mailbot
  Application extension (3)
    BackDoor-CGX.dll
    PWS-Goldun.dll
    Proxy-Agent.af.dll
  Configurator (1)
    BackDoor-CTG.cfg
  DOS (1)
    Unsafe COM
  Downloader (4)
    Downloader-UJ
    PWS-Lineage.dldr
    Downloader-AFW
    Downloader-ATM
  Dropper (3)
    MultiDropper-IN
    MultiDropper-NU
    BackDoor-PC.dr
  Generic (3)
    AFXrootkit.gen.b
    HackerDefender.gen
    QLowZones-2.gen
  Heuristic (2)
    New Malware.aa
    New Malware.w
  Java Applet (1)
    JV/Generic
  Keylogger (1)
    Keylog-Fearless
  Password Stealer (1)
    PWS-Lineage!chm
  Proxy (2)
    Proxy-Agent.af
    Proxy-Piky
  Remote Access (9)
    IRC/Flood.c.dr
    BackDoor-AZV
    BackDoor-UK.gen
    BackDoor-UK
    BackDoor-PC
    BackDoor-COC
    BackDoor-PE
    BackDoor-CWW
    BackDoor-CKA
  Server (1)
    BackDoor-CTG.svr
  StartPage (2)
    StartPage-EK
    StartPage-FE
  Win31 (1)
    APStrojan
  Win32 (8)
    Tuoraw
    Generic MultiDropper.j
    HackerDefender.sys
    Generic Downloader.d
    Generic Downloader.y
    AdClicker-BZ
    QLowZones-2
    Generic Downloader.e
Virus (210)
   (3)
    SymbOS/PBsender.c!app
    SymbOS/PBsender.a!app
    SymbOS/PBsender.b!app
  Application extension (1)
    W32/Loosky.dll
  Damaged (6)
    W32/Netsky.q.dam
    W32/Netsky.c.dam
    W32/Polybot.dam
    W32/Netsky.p.dam
    W32/Netsky.d.dam
    W32/Bagle.dam
  Dropper (3)
    Pixel.dr
    W32/Polybot.dr
    W32/Loosky.dr
  E-mail (18)
    W32/Netsky.w@MM
    W32/Netsky.q@MM
    W32/Netsky.u@MM
    W32/Netsky.g@MM
    W32/Netsky.l@MM
    W32/Netsky.k@MM
    W32/Bagle.j@MM
    W32/NetSky.h@MM
    W32/Bagle.k@MM
    W32/Netsky.v@MM
    W32/Netsky.y@MM
    W32/Netsky.z@MM
    W32/Netsky.ab@MM
    W32/Mytob.bh@MM
    W32/MyWife.d@MM!M24
    W32/Netsky.ag@MM
    W32/Bagle.af@MM
    W32/Bagle.ad@MM
  E-mail worm (16)
    W32/Bagle.n@MM
    W32/Bagle.p@MM
    W32/Netsky.n@MM
    W32/Bagle.q@MM
    W32/Netsky.j@MM
    W32/Bagle.c@MM
    W32/Netsky.o@MM
    W32/Bagle.r@MM
    W32/Netsky.x@MM
    W32/Netsky.e@MM
    W32/Netsky.f@MM
    W32/Netsky.d@MM
    W32/Bagle.s@MM
    W32/Bagle.aa@MM
    W32/Netsky.ac@MM
    W32/Bagle.ah@MM
  Email (33)
    W32/Bagle.al@MM
    W32/Polybot@MM
    W32/Mytob.ak@MM
    W32/Mytob.am@MM
    W32/Mytob.ar@MM
    W32/Mytob.aq@MM
    W32/Mytob.ex@MM
    W32/Netsky.ad@MM
    W32/Mytob.gk@MM
    W32/Mytob.cu@MM
    W32/Mytob.ce@MM
    W32/Mytob.dg@MM
    W32/Mytob.dc@MM
    W32/Mytob.di@MM
    W32/Mytob.df@MM
    W32/Mytob.dj@MM
    W32/Mytob.v@MM
    W32/Mytob.u@MM
    W32/Mytob.cz@MM
    W32/Mytob.dm@MM
    W32/Mytob.ah@MM
    W32/Mytob.dq@MM
    W32/Mytob.dt@MM
    W32/Mytob.ag@MM
    W32/Mytob.an@MM
    W32/Mytob.ec@MM
    W32/Mytob.ef@MM
    W32/Netsky.ai@MM
    W32/Loosky.e@MM
    W32/Netsky.af@MM
    W32/Mytob.eo@MM
    W32/Mytob.er@MM
    W32/Mytob.ep@MM
  Email Generic (1)
    W32/Loosky.gen@MM
  Email Worm (1)
    W32/Netsky.aa@MM
  Generic (1)
    SymbOS/PBsender.gen!app
  Generic Peer To Peer (1)
    W32/Antinny.gen!p2p
  Generic Worm (1)
    W32/Spybot.worm.gen.n
  Internet Worm (2)
    W32/Polybot.l!irc
    W32/Bagle.d@MM
  VBScript worm (1)
    VBS/Redlof@M
  Win32 (122)
    W32/Bagle.o!proxy
    W32/Polybot.dh
    W32/Polybot.bw
    W32/Polybot.bu
    W32/Polybot.bx
    W32/Polybot.bv
    W32/Polybot.bt
    W32/Bagle.aj!proxy
    W32/Bagle.aa
    W32/Polybot.ag
    W32/Polybot.v
    W32/Polybot.t
    W32/Polybot.s
    W32/Polybot.r
    W32/Polybot.q
    W32/Polybot.o
    W32/Polybot.n
    W32/Polybot.m
    W32/Polybot.k
    W32/Polybot.j
    W32/Polybot.i
    W32/Polybot.h
    W32/Polybot.g
    W32/Polybot.f
    W32/Polybot.e
    W32/Polybot.c
    W32/Polybot.a
    W32/Polybot.u
    W32/Polybot.d
    W32/Polybot.b
    W32/Polybot.ae
    W32/Polybot.ac
    W32/Polybot.aa
    W32/Polybot.y
    W32/Polybot.w
    W32/Polybot.ad
    W32/Polybot.ab
    W32/Polybot.z
    W32/Polybot.x
    W32/Polybot.af
    W32/Polybot.am
    W32/Polybot.aj
    W32/Polybot.an
    W32/Polybot.al
    W32/Polybot.ai
    W32/Bagle.an
    W32/Polybot.cg
    W32/Netsky
    W32/Polybot.cu
    W32/Polybot.cs
    W32/Polybot.cv
    W32/Polybot.ct
    W32/Polybot.cx
    W32/Polybot.cw
    W32/Bagle.z
    W32/Polybot.cf
    W32/Polybot.cj
    W32/Polybot.ch
    W32/Polybot.cl
    W32/Polybot.ci
    W32/Bagle.az
    W32/Polybot.cy
    W32/Polybot.cn
    W32/Polybot.co
    W32/Polybot.cr
    W32/Bagle.ao
    W32/Polybot.cb
    W32/Polybot.cm
    W32/Polybot.cp
    W32/Polybot.da
    W32/Polybot.db
    W32/Polybot.cz
    W32/Polybot.dd
    W32/Polybot.cq
    W32/Polybot.dc
    W32/Polybot.de
    W32/Polybot.dg
    W32/Polybot.df
    W32/Polybot.dk
    W32/Loosky!pws
    W32/Polybot.dl
    W32/Polybot.dj
    W32/Loosky!proxy
    W32/Loosky!backdoor
    W32/Polybot.bz
    W32/Polybot.by
    W32/Polybot.cc
    W32/Polybot.ce
    W32/Polybot.cd
    W32/Bagle.bh
    W32/Polybot.bs
    W32/Polybot.bo
    W32/Polybot.bn
    W32/Polybot.bm
    W32/Polybot.bl
    W32/Polybot.bk
    W32/Polybot.bf
    W32/Polybot.bq
    W32/Polybot.bp
    W32/Polybot.br
    W32/Polybot.bb
    W32/Polybot.ba
    W32/Polybot.bg
    W32/Polybot.be
    W32/Polybot.bd
    W32/Polybot.bc
    W32/Polybot.bh
    W32/Polybot.bj
    W32/Polybot.bi
    W32/Polybot.az
    W32/Polybot.ay
    W32/Polybot.ax
    W32/Polybot.ca
    W32/Polybot.av
    W32/Polybot.aw
    W32/Polybot.au
    W32/Polybot.as
    W32/Polybot.aq
    W32/Polybot.ao
    W32/Polybot.at
    W32/Polybot.ar
    W32/Polybot.ap