Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

Latest Update
DAT Version 4757
DAT Release Date 05/08/2006
Threats Detected 189236
New Detections 21
Enhanced Detections 260

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (2)
  Win32 (2)
    VegasredCas
    RemAdm-ProcLaunch!171
Trojan (10)
  Demonstration (1)
    Exploit-NestedObj.demo
  Downloader (4)
    Downloader-AWB
    Downloader-AWA
    Downloader-AVZ
    Downloader-QO!mem
  Exploit (1)
    Exploit-NestedObj
  Keylogger (1)
    Keylog-Nofear
  Remote Access (1)
    BackDoor-CZQ
  Script (1)
    Bat/avk81
  Win32 (1)
    Del-503
Virus (9)
  Damaged (1)
    W32/Maya.dam
  Email (1)
    W32/Rabit@MM
  Worm (7)
    W32/Tahun.worm
    W32/RDevil.worm
    W32/MoonLight.worm
    W32/Loveme.worm
    W32/Bropia.worm.dd
    W32/Bropia.worm.dc
    W32/Liz.worm

Enhanced Detections:

Internet Worm (2)
  E-mail (2)
    W32/Kidala.b@MM
    W32/Kidala.a@MM
Program (11)
   (1)
    Generic PUP.a
  Adware (1)
    Adware-NaviPromo
  Dialer (1)
    Dialer-Generic.f
  Dropper (1)
    Spyware-SpyMyPC.dr
  Joke (1)
    Joke-LOL
  Keylogger (1)
    Keylog-MetaCodix
  Malware Tool (2)
    VTool/fake
    VTool/fakez
  Spyware (1)
    Spyware-SpyMyPC
  Win32 (2)
    Generic HTool.bb
    Winfixer
Trojan (88)
   (5)
    Generic Dropper.o
    Generic Downloader.o
    Generic BackDoor.bb
    Generic Proxy.h
    Painter
  - (1)
    Spam-Mailbot
  Application extension (4)
    BackDoor-AWQ.dll
    BackDoor-BAC.dll
    Puper.dll
    PWS-Goldun.dll
  Configurator (1)
    BackDoor-CEP.cfg
  Downloader (9)
    BackDoor-CMQ.dldr
    Downloader-ABB
    PWS-Banker.dldr
    Downloader-ABU
    Downloader-AVS
    Downloader-ZQ
    PWS-Banker.dldr.c
    Downloader-ARH
    Downloader-QO
  Dropper (7)
    PWS-LDPinch.dr
    BackDoor-AWQ.dr
    PWS-Hooker.dr
    Zquest.dr
    BackDoor-CEP.dr
    Puper.dr
    BackDoor-COC.dr
  Dropper Generic (1)
    AdClicker-C.gen.dr
  Exploit (2)
    JS/Exploit-DDay
    Exploit-ObscuredHtml
  Generic (5)
    Swizzor.gen
    PWS-Banker.gen.g
    PWS-Banker.gen.t
    BackDoor-CKB.sys.gen
    BackDoor-BAC.gen.b
  Generic Worm (1)
    W32/Sdbot.worm.gen.ax
  Heuristic (2)
    New Malware.f
    New Malware.ae
  Keylogger (1)
    Keylog-Logit
  Malware Tool (3)
    Spam-GWab
    NTRootKit-U
    Spam-DComServ
  Password (1)
    PWS-LDPinch
  Password Stealer (11)
    PWS-QQRob
    PWS-JA
    PWS-AOLPhish
    PWS-Banker.gen.ba
    PWS-RXJH
    PWS-Banker.gen.i
    PWS-Banker.gen.h
    PWS-Goldun.sys
    W32/Loosky!pws
    PWS-Banker.au
    PWS-Lineage
  Plugin component (1)
    BackDoor-JX.plugin
  ProcKill (1)
    ProcKill-DA
  Proxy (2)
    Proxy-FBSR
    Proxy-Raser
  Remote Access (9)
    BackDoor-AWQ.b
    BackDoor-AWQ
    BackDoor-ALD
    BackDoor-BAC.gen.d
    BackDoor-BAC.sys
    BackDoor-CMQ
    BackDoor-CES
    BackDoor-CKB
    BackDoor-CEP
  Script (1)
    IIS/BackDoor-ACE
  Server (1)
    BackDoor-CUR.svr
  StartPage (2)
    StartPage-HR
    StartPage-IW
  Win32 (17)
    DollarRevenue
    Systhread
    Generic BackDoor.c
    Puper
    Generic Downloader.s
    Generic Downloader.k
    Generic Dropper.p
    Swizzor
    Generic AdClicker.j
    Generic Downloader.aa
    Regger
    Zquest
    Generic Dropper.i
    Generic BackDoor.u
    Generic Downloader.ab
    Generic BackDoor.j
    Galapoper
Virus (159)
   (1)
    Oxfall.865
  Application extension (1)
    W32/Loosky.dll
  Boot (1)
    Dodgy
  Damaged (1)
    W32/Mytob.dam
  Downloader (1)
    W32/Loosky.dldr
  Dropper (1)
    W32/Loosky.dr
  Dropper Worm (1)
    W32/Kelvir.worm.dr
  E-mail (1)
    W32/Mytob.gr@MM
  Email (72)
    W32/Mytob.ao@MM
    W32/Mytob.al@MM
    W32/Mytob.ew@MM
    W32/Mytob.fa@MM
    W32/Mytob.ft@MM
    W32/Mytob.fs@MM
    W32/Mytob.aw@MM
    W32/Mytob.fr@MM
    W32/Mytob.ba@MM
    W32/Mytob.bc@MM
    W32/Mytob.bb@MM
    W32/Mytob.bd@MM
    W32/Mytob.id@MM
    W32/Mytob.fu@MM
    W32/Mytob.fw@MM
    W32/Mytob.fv@MM
    W32/Mytob.ge@MM
    W32/Mytob.go@MM
    W32/Mytob.bu@MM
    W32/Mytob.bq@MM
    W32/Mytob.by@MM
    W32/Mytob.cq@MM
    W32/Mytob.ck@MM
    W32/Mytob.fz@MM
    W32/Mytob.gf@MM
    W32/Mytob.gn@MM
    W32/Mytob.gp@MM
    W32/Mytob.cw@MM
    W32/Mytob.p@MM
    W32/Mytob.i@MM
    W32/Mytob.k@MM
    W32/Mytob.r@MM
    W32/Mytob.gm@MM
    W32/Mytob.gs@MM
    W32/Mytob.m@MM
    W32/Mytob.bs@MM
    W32/Mytob.de@MM
    W32/Mytob.cb@MM
    W32/Mytob.do@MM
    W32/Mytob.dl@MM
    W32/Mytob.h@MM
    W32/Mytob.j@MM
    W32/Mytob.l@MM
    W32/Mytob.o@MM
    W32/Mytob.t@MM
    W32/Mytob.x@MM
    W32/Mytob.y@MM
    W32/Mytob.cr@MM
    W32/Mytob.cl@MM
    W32/Mytob.ci@MM
    W32/Mytob.cx@MM
    W32/Mytob.cy@MM
    W32/Mytob.dn@MM
    W32/Mytob.ei@MM
    W32/Mytob.aa@MM
    W32/Mytob.ad@MM
    W32/Mytob.dw@MM
    W32/Mytob.dv@MM
    W32/Mytob.du@MM
    W32/Mytob.aj@MM
    W32/Mytob.z@MM
    W32/Mytob.hq@MM
    W32/Mytob.eg@MM
    W32/Mytob.ho@MM
    W32/Mytob.hn@MM
    W32/Mytob.hk@MM
    W32/Mytob.hm@MM
    W32/Mytob.hj@MM
    W32/Loosky.e@MM
    W32/Mytob.ha@MM
    W32/Mytob.em@MM
    W32/Mytob.en@MM
  Email Generic (3)
    W32/Mytob.gen@MM
    W32/Loosky.gen@mm
    W32/Feebs.gen@MM
  Generic (2)
    W32/Loosky.gen
    W32/Nopir.gen
  Generic Worm (4)
    W32/Sdbot.worm.gen.h
    W32/Kelvir.worm.gen
    W32/Sdbot.worm.gen.bh
    W32/Sdbot.worm.gen.ac
  Internet Worm (3)
    W32/Kelvir.worm.bh
    W32/Kelvir.worm.f
    W32/Bropia.worm.aj
  mIRC Worm (1)
    MIRC/Generic
  P2P Worm (1)
    W32/Bactera.worm!p2p
  Peer To Peer Worm (1)
    W32/Steam.worm!p2p
  Script Worm (1)
    W32/Crumpet.worm.bat
  Win32 (3)
    W32/Feebs!rootkit
    W32/Loosky!proxy
    W32/Loosky!backdoor
  Worm (60)
    W32/Kelvir.worm.eo
    W32/Kelvir.worm.ex
    W32/Kelvir.worm.al
    W32/Kelvir.worm.ap
    W32/Kelvir.worm.an
    W32/Bropia.worm.al
    W32/Bropia.worm.ak
    W32/Kelvir.worm.ao
    W32/Kelvir.worm.am
    W32/Bropia.worm.am
    W32/Kelvir.worm.ec
    W32/Kelvir.worm.ax
    W32/Bropia.worm.ao
    W32/Bropia.worm.an
    W32/Kelvir.worm.az
    W32/Kelvir.worm.ba
    W32/Kelvir.worm.ay
    W32/Bropia.worm.ar
    W32/Kelvir.worm.bg
    W32/Kelvir.worm.e
    W32/Bropia.worm.ba
    W32/Bropia.worm.az
    W32/Bropia.worm.ay
    W32/Bropia.worm.ax
    W32/Bropia.worm.bb
    W32/Crumpet.worm
    W32/Kelvir.worm.ca
    W32/Bropia.worm.bd
    W32/Kelvir.worm.ci
    W32/Kelvir.worm.i
    W32/Bropia.worm
    W32/Kelvir.worm.o
    W32/Kelvir.worm.p
    W32/Kelvir.worm.l
    W32/Kelvir.worm.ch
    W32/Bropia.worm.be
    W32/Bropia.worm.bg
    W32/Kelvir.worm.q
    W32/Kelvir.worm.w
    W32/Bropia.worm.bh
    W32/Kelvir.worm.cu
    W32/Kelvir.worm.da
    W32/Kelvir.worm.cz
    W32/Kelvir.worm.dd
    W32/Kelvir.worm.cq
    W32/Kelvir.worm.cv
    W32/Kelvir.worm.cx
    W32/Kelvir.worm.cy
    W32/Bropia.worm.ag
    W32/Kelvir.worm.ac
    W32/Kelvir.worm.aj
    W32/Kelvir.worm.ai
    W32/Bropia.worm.ah
    W32/Bropia.worm.ai
    W32/Kelvir.worm.db
    W32/Kelvir.worm.gc
    W32/Bropia.worm.bz
    W32/Bropia.worm.br
    W32/Kelvir.worm.dy
    W32/Bropia.worm.bs