Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

Latest Update
DAT Version 4803
DAT Release Date 07/10/2006
Threats Detected 200541
New Detections 14
Enhanced Detections 198

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (1)
  Dialer (1)
    Dialer-305
Trojan (8)
   (1)
    SymbOS/MultiDropper.bx!sis
  Application extension (1)
    PWS-Meen.dll
  Demonstration (1)
    Exploit-ImgProp.demo
  Dropper (1)
    FakeAlert-B.dr
  Exploit (1)
    Exploit-MS01-034
  Password Stealer (2)
    PWS-Wosate
    PWS-Meen
  Win32 (1)
    Spy-Agent.bd
Virus (5)
  Email (2)
    W32/Legsip.b@MM
    W32/Legsip.a@MM
  Win32 (1)
    W32/LastScene.f
  Worm (2)
    W32/Mandei.worm!dldr
    W32/Mandei.worm

Enhanced Detections:

Program (11)
  Adware (3)
    Adware-SearchAid
    Adware-PrecisionPop
    Adware-ClickSpring
  Dialer (2)
    Dialer-211
    Dialer-292
  Dropper (1)
    Adware-BB.dr
  Keylogger (1)
    Keylog-Ardamax.dr
  Password (1)
    Keylog-Hoddle
  PornDialer (1)
    Dialer-Generic
  Win32 (2)
    Winfixer
    Generic Dialer.ba
Trojan (86)
   (24)
    Generic.cf
    SymbOS/MultiDropper.bq!sis
    SymbOS/MultiDropper.bo!sis
    SymbOS/MultiDropper.bp!sis
    SymbOS/MultiDropper.bs!sis
    SymbOS/MultiDropper.br!sis
    SymbOS/MultiDropper.bf!sis
    Generic Downloader.bd
    SymbOS/MultiDropper.bw!intd
    Spy-Agent.n
    SymbOS/MultiDropper.bj!sis
    SymbOS/MultiDropper.bh!sis
    SymbOS/MultiDropper.bn!sis
    Generic BackDoor.bb
    SymbOS/MultiDropper.bv!sis
    SymbOS/MultiDropper.bt!sis
    SymbOS/MultiDropper!sis
    SymbOS/MultiDropper.bu!sis
    SymbOS/MultiDropper.bl!sis
    SymbOS/MultiDropper.bk!sis
    SymbOS/MultiDropper.bi!sis
    SymbOS/MultiDropper.bg!sis
    Spy-Agent.at
    Generic.f
  Adware (1)
    Zquest
  Application extension (1)
    Puper.dll
  Configurator (1)
    BackDoor-CEP.cfg
  Damaged (1)
    BackDoor-AWQ.b.dam
  Downloader (7)
    PWS-Banker.dldr
    Downloader-ABU
    BackDoor-ARR.dldr
    Downloader-ZQ
    PWS-Banker.dldr.c
    Downloader-AQW
    Downloader-ACV
  Dropper (8)
    PWS-Progent.dr
    AdClicker-EJ.dr
    BackDoor-AWQ.b.dr
    Zquest.dr
    BackDoor-CEP.dr
    BackDoor-COC.dr
    Spam-DComServ.dr
    BackDoor-ARR.dr
  Exploit (4)
    JS/Exploit-MS05-054
    Exploit-MS05-014
    Exploit-MS06-027
    Exploit-1Table
  Generic (4)
    PWS-Banker.gen.ad
    PWS-Banker.gen.bb
    PWS-Banker.gen.j
    PWS-Banker.gen.bc
  Generic Worm (1)
    W32/Sdbot.worm.gen.ax
  Heuristic (1)
    New Malware.h
  Keylogger (1)
    Keylog-Elt
  Malware Tool (1)
    NTRootKit-V
  Password Stealer (4)
    PWS-JA
    PWS-Banker.gen.ba
    PWS-Banker.gen.i
    PWS-WoW
  Proxy (2)
    Proxy-EasySearch
    Proxy-FBSR
  Remote Access (6)
    BackDoor-ARR
    BackDoor-AWQ.b
    BackDoor-CGX
    BackDoor-CSN
    BackDoor-CXJ
    BackDoor-CEP
  Win32 (19)
    DollarRevenue
    Generic Del
    Generic Del.e
    Generic Uploader.a
    FakeAlert-C
    Puper
    Del-502
    Generic BackDoor.be
    Generic BackDoor.ba
    Generic Downloader.y
    Generic PWS.o
    Generic QLowZones.a
    Generic BackDoor.u
    Generic Downloader.ab
    Generic AdClicker.p
    Spy-Agent.al
    Generic Dropper.w
    Generic StartPage.r
    Generic Downloader.g
Virus (101)
  AutoLisp (1)
    ALS/Bursted
  Dropper (1)
    W32/Donak.dr
  Dropper Email (1)
    W32/Mytob.dr@MM
  E-mail (9)
    W32/Mytob.be@MM
    W32/Mytob.bi@MM
    W32/Mytob.bj@MM
    W32/Mytob.bo@MM
    W32/Mytob.bl@MM
    W32/Mytob.br@MM
    W32/Mytob.bf@MM
    W32/Mytob.cg@MM
    W32/Mytob.ch@MM
  Email (67)
    W32/Mytob.hr@MM
    W32/Mytob.b@MM
    W32/Mytob.a@MM
    W32/Mytob.ev@MM
    W32/Mytob.at@MM
    W32/Rontokbro.a@MM
    W32/Mytob.ib@MM
    W32/Mytob.av@MM
    W32/Mytob.au@MM
    W32/Rontokbro.b@MM
    W32/Mytob.hy@MM
    W32/Mytob.fy@MM
    W32/Mytob.fw@MM
    W32/Mytob.fx@MM
    W32/Mytob.gg@MM
    W32/Mytob.gl@MM
    W32/Mytob.gj@MM
    W32/Mytob.gi@MM
    W32/Mytob.hs@MM
    W32/Mytob.bg@MM
    W32/Mytob.bx@MM
    W32/Mytob.cd@MM
    W32/Mytob.gd@MM
    W32/Mytob.gc@MM
    W32/Mytob.gb@MM
    W32/Mytob.ga@MM
    W32/Mytob.gf@MM
    W32/Mytob.gp@MM
    W32/Mytob.gq@MM
    W32/Mytob.bn@MM
    W32/Mytob.dh@MM
    W32/Mytob.r@MM
    W32/Mytob.e@MM
    W32/Mytob.c@MM
    W32/Mytob.gt@MM
    W32/Mytob.g@MM
    W32/Mytob.bt@MM
    W32/Mytob.bp@MM
    W32/Mytob.ct@MM
    W32/Mytob.cf@MM
    W32/Mytob.dd@MM
    W32/Mytob.ca@MM
    W32/Mytob.n@MM
    W32/Mytob.f@MM
    W32/Mytob.d@MM
    W32/Mytob.cs@MM
    W32/Mytob.dk@MM
    W32/Mytob.dz@MM
    W32/Mytob.eb@MM
    W32/Mytob.ds@MM
    W32/Mytob.ea@MM
    W32/Mytob.gu@MM
    W32/Mytob.gx@MM
    W32/Mytob.hq@MM
    W32/Mytob.ej@MM
    W32/Mytob.hp@MM
    W32/Mytob.gy@MM
    W32/Mytob.hf@MM
    W32/Mytob.gw@MM
    W32/Mytob.gz@MM
    W32/Mytob.hg@MM
    W32/Mytob.hh@MM
    W32/Mytob.hi@MM
    W32/Mytob.gv@MM
    W32/Mytob.he@MM
    W32/Mytob.es@MM
    W32/Mytob.eq@MM
  Email Generic (3)
    W32/Rontokbro.gen@MM
    JS/Feebs.gen.k@MM
    W32/Mytob.gen@MM
  Generic Worm (14)
    W32/Sdbot.worm.gen.bg
    W32/Sdbot.worm.gen.n
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.h
    W32/Sdbot.worm.gen.ca
    W32/Sdbot.worm.gen.bl
    W32/Spybot.worm.gen.p
    W32/Sdbot.worm.gen.bz
    W32/Sdbot.worm.gen.bo
    W32/Sdbot.worm.gen.bh
    W32/Sdbot.worm.gen.bi
    W32/Sdbot.worm.gen.by
    W32/Sdbot.worm.gen.bj
    W32/Sdbot.worm.gen.t
  Internet Worm (1)
    W32/Mytob.bk@MM
  Script Worm (1)
    W32/Donak.worm
  Win32 (1)
    W32/Generic.Delphi.b
  Worm (2)
    W32/RJump.worm
    W32/Mytob.worm!im