Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

Latest Update
DAT Version 4785
DAT Release Date 06/15/2006
Threats Detected 197336
New Detections 33
Enhanced Detections 272

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (1)
  Tool (1)
    HTool-Injecter
Trojan (18)
   (7)
    SymbOS/Romride.a
    SymbOS/Multidropper.bv!sis
    SymbOS/Multidropper.bt!sis
    SymbOS/Romride.b
    SymbOS/Multidropper!sis
    SymbOS/Multidropper.bu!sis
    SymbOS/Arifat
  Downloader (2)
    Downloader-AWW
    JS/Downloader-AUD
  Exploit (7)
    Exploit-PPT
    Exploit-MS06-021.b
    Exploit-MS06-021.c
    Exploit-MS06-021.a
    Exploit-CHMChunk
    Exploit-ANIfile.b
    Exploit-MS05-001
  Generic (1)
    PWS-Banker.gen.bc
  Remote Access (1)
    BackDoor-DIN
Virus (14)
   (11)
    SymbOS/Mabir.b!sis
    SymbOS/Commwarrior.n!sis
    SymbOS/Cabir!ezboot.m
    SymbOS/Mabir.c!sis
    SymbOS/Mabir.b!app
    SymbOS/Mabir.c!app
    SymbOS/Mabir.b!ezboot
    SymbOS/Cabir!ezboot.g
    SymbOS/Cabir!intd
    SymbOS/Cabir.m!sis
    SymbOS/Cabir.g!sis
  Win32 (3)
    W32/Detnat.g
    W32/Detnat.e
    W32/Detnat.f

Enhanced Detections:

Trojan (83)
   (28)
    SymbOS/Skulls.ci
    SymbOS/Multidropper.bq!sis
    SymbOS/Multidropper.bo!sis
    SymbOS/Multidropper.bp!sis
    SymbOS/Multidropper.bs!sis
    SymbOS/Multidropper.br!sis
    SymbOS/Skulls.f
    SymbOS/Skulls.e
    SymbOS/Multidropper.bf!sis
    SymbOS/Multidropper.bj!sis
    SymbOS/Multidropper.bh!sis
    SymbOS/Multidropper.bn!sis
    Generic BackDoor.bb
    SymbOS/Flexispy
    SymbOS/Multidropper.bl!sis
    SymbOS/Multidropper.bk!sis
    SymbOS/Multidropper.bi!sis
    SymbOS/Multidropper.bg!sis
    SymbOS/Splashstall
    SymbOS/Skulls.g
    SymbOS/Skulls.h
    SymbOS/Skulls.i
    SymbOS/Skulls.cf
    SymbOS/Skulls.cg
    SymbOS/Skulls.c
    SymbOS/Skulls!aif
    SymbOS/Skulls.d
    SymbOS/Skulls.ca
  Application extension (2)
    PWS-QQRob.dll
    PWS-RXJH.dll
  Downloader (5)
    PWS-Banker.dldr.d
    Downloader-AWH
    PWS-Banker.dldr
    Downloader-ZQ
    Downloader-ASH
  Dropper (4)
    PWS-LDPinch.dr
    BackDoor-CVT.dr
    MultiDropper-NB
    Spam-DComServ.dr
  Exploit (6)
    Exploit-PNG
    JS/Exploit-DDay
    Exploit-ITSSHeap
    Exploit-MS06-014
    Exploit-MS06-027
    Exploit-CodeBase.chm
  Generic (7)
    PWS-Banker.gen.bb
    SymbOS/Skulls.gen
    PWS-Banker.gen.t
    RemAdm-RemoteAdmin.gen.ba
    ServU-Daemon.gen.ba
    PWS-Banker.gen.v
    Downloader-PO.gen
  Password (1)
    PWS-LDPinch
  Password Stealer (3)
    PWS-Banker.gen.ba
    PWS-Banker.bh
    PWS-WoW
  PDA Device (1)
    SymbOS/Skulls.a
  Proxy (2)
    Proxy-Agent.au
    Proxy-Soxx
  Remote Access (5)
    BackDoor-AWQ.b
    BackDoor-CZY
    Generic BackDoor.l
    BackDoor-CMQ
    BackDoor-CYY
  Spam (1)
    Spam-Loot
  Win32 (18)
    Generic Downloader.a
    Generic Delphi
    Generic Downloader.am
    Puper
    Generic Downloader.bl
    Generic Downloader.be
    Generic BackDoor.be
    Generic BackDoor.bd
    Generic BackDoor.ba
    Generic Dropper.ad
    Generic PWS.o
    Generic Dropper.i
    Generic BackDoor.u
    Generic Downloader.ab
    Generic VB.c
    Generic Downloader.f
    DDoS-Boxed
    Generic AdClicker.d
Virus (189)
   (69)
    SymbOS/Commwarrior.h!sis
    SymbOS/Cabir.x
    SymbOS/Cabir.ab
    SymbOS/Cabir!ezboot.ab
    SymbOS/Cabir.ab!sis
    SymbOS/Commwarrior.l!sis
    SymbOS/Cabir.ah!sis
    SymbOS/Cabir!lasco
    SymbOS/Commwarrior.b!sis
    SymbOS/Commwarrior.a!sis
    SymbOS/Cabir.v
    SymbOS/Cabir!ezboot.v
    SymbOS/Cabir.z!sis
    SymbOS/Commwarrior.j!sis
    SymbOS/Cabir.y
    SymbOS/Cabir!ezboot.y
    SymbOS/Cabir.ag
    SymbOS/Commwarrior.c!sis
    SymbOS/Commwarrior.m!sis
    SymbOS/Cabir!ezboot.ah
    SymbOS/Cabir.z
    SymbOS/Cabir!ezboot.w
    SymbOS/Cabir.w
    SymbOS/Cabir.ac
    SymbOS/Cabir.ac!sis
    SymbOS/Cabir!ezboot.ac
    SymbOS/Cabir!ezboot.e
    SymbOS/Cabir!ezboot.d
    SymbOS/Cabir!ezboot.c
    SymbOS/Cabir!ezboot
    SymbOS/Commwarrior.g!sis
    SymbOS/Commwarrior.i!sis
    SymbOS/Commwarrior.f!sis
    SymbOS/Cabir!ezboot.x
    SymbOS/Commwarrior.d!sis
    SymbOS/Commwarrior.e!sis
    SymbOS/Cabir.ae!sis
    SymbOS/Cabir.ae
    SymbOS/Cabir!ezboot.ae
    SymbOS/Cabir!ezboot.s
    SymbOS/Cabir!ezboot.o
    SymbOS/Cabir!ezboot.k
    SymbOS/Cabir!ezboot.f
    SymbOS/Cabir.k!sis
    SymbOS/Cabir.i!sis
    SymbOS/Cabir.b!sis
    SymbOS/Cabir!ezboot.ad
    SymbOS/Cabir!ezboot.ag
    SymbOS/Cabir.af!sis
    SymbOS/Cabir.g
    SymbOS/Cabir.f
    SymbOS/Cabir.b
    SymbOS/Cabir.a
    SymbOS/Cabir.ag!sis
    SymbOS/Cabir!ezboot.t
    SymbOS/Cabir!ezboot.r
    SymbOS/Cabir.m
    SymbOS/Cabir.k
    SymbOS/Cabir!ezboot.q
    SymbOS/Cabir!ezboot.p
    SymbOS/Cabir!ezboot.n
    SymbOS/Cabir.l!sis
    SymbOS/Cabir.j!sis
    SymbOS/Cabir.h!sis
    SymbOS/Cabir.u
    SymbOS/Cabir.ad
    SymbOS/Cabir.ad!sis
    SymbOS/Cabir.aa
    SymbOS/Cabir!ezboot.aa
  Damaged (2)
    W32/Mytob.dam
    SymbOS/Cabir.af.dam
  Damaged Worm (1)
    W32/Sdbot.worm.dam
  Dropper (2)
    SymbOS/Cabir.dr
    SymbOS/Cabir.dr!skulls
  E-mail (6)
    W32/Mytob.ig@MM
    W32/Mytob.gr@MM
    W32/Mytob.ih@MM
    W32/Mytob.ii@MM
    W32/Banwarum@MM
    W32/Banwarum.dll
  Email (72)
    W32/Mytob.ao@MM
    W32/Mytob.al@MM
    W32/Mytob.ew@MM
    W32/Mytob.ie@MM
    W32/Mytob.fa@MM
    W32/Mytob.ft@MM
    W32/Mytob.fs@MM
    W32/Mytob.aw@MM
    W32/Mytob.fr@MM
    W32/Mytob.ba@MM
    W32/Mytob.bc@MM
    W32/Mytob.bb@MM
    W32/Mytob.bd@MM
    W32/Mytob.id@MM
    W32/Mytob.fu@MM
    W32/Mytob.fw@MM
    W32/Mytob.fv@MM
    W32/Mytob.ge@MM
    W32/Mytob.go@MM
    W32/Mytob.bu@MM
    W32/Mytob.bq@MM
    W32/Mytob.by@MM
    W32/Mytob.cq@MM
    W32/Mytob.ck@MM
    W32/Mytob.fz@MM
    W32/Mytob.gf@MM
    W32/Mytob.gn@MM
    W32/Mytob.gp@MM
    W32/Mytob.cw@MM
    W32/Mytob.p@MM
    W32/Mytob.i@MM
    W32/Mytob.k@MM
    W32/Mytob.r@MM
    W32/Mytob.gm@MM
    W32/Mytob.gs@MM
    W32/Mytob.m@MM
    W32/Mytob.bs@MM
    W32/Mytob.de@MM
    W32/Mytob.cb@MM
    W32/Mytob.do@MM
    W32/Mytob.dl@MM
    W32/Mytob.h@MM
    W32/Mytob.j@MM
    W32/Mytob.l@MM
    W32/Mytob.o@MM
    W32/Mytob.t@MM
    W32/Mytob.x@MM
    W32/Mytob.y@MM
    W32/Mytob.cr@MM
    W32/Mytob.cl@MM
    W32/Mytob.ci@MM
    W32/Mytob.cx@MM
    W32/Mytob.cy@MM
    W32/Mytob.dn@MM
    W32/Mytob.ei@MM
    W32/Mytob.aa@MM
    W32/Mytob.ad@MM
    W32/Mytob.dw@MM
    W32/Mytob.dv@MM
    W32/Mytob.du@MM
    W32/Mytob.aj@MM
    W32/Mytob.z@MM
    W32/Mytob.hq@MM
    W32/Mytob.eg@MM
    W32/Mytob.ho@MM
    W32/Mytob.hn@MM
    W32/Mytob.hk@MM
    W32/Mytob.hm@MM
    W32/Mytob.hj@MM
    W32/Mytob.ha@MM
    W32/Mytob.em@MM
    W32/Mytob.en@MM
  Email Generic (1)
    W32/Mytob.gen@MM
  Generic (3)
    SymbOS/Commwarrior.gen!sis
    SymbOS/Cabir.gen!sis
    SymbOS/Cabir.gen
  Generic Worm (16)
    W32/Gaobot.worm.gen.g
    W32/Sdbot.worm.gen.bg
    W32/Spybot.worm.gen.bj
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.ca
    W32/Spybot.worm.gen.by
    W32/Sdbot.worm.gen.bs
    W32/Sdbot.worm.gen.bz
    W32/Sdbot.worm.gen.bo
    W32/Sdbot.worm.gen.bd
    W32/Sdbot.worm.gen.bh
    W32/Sdbot.worm.gen.bi
    W32/Sdbot.worm.gen.by
    W32/Sdbot.worm.gen.bj
    W32/Sdbot.worm.gen.bx
  PDA Device (16)
    SymbOS/Mabir.a!app
    SymbOS/Mabir.a!sis
    SymbOS/Cabir.e
    SymbOS/Cabir.c
    SymbOS/Cabir.h
    SymbOS/Cabir.d
    SymbOS/Cabir.t
    SymbOS/Cabir.r
    SymbOS/Cabir.p
    SymbOS/Cabir.n
    SymbOS/Cabir.l
    SymbOS/Cabir.s
    SymbOS/Cabir.q
    SymbOS/Cabir.o
    SymbOS/Cabir.i
    SymbOS/Cabir.j
  Win32 (1)
    W32/Detnat.d