Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

Latest Update
DAT Version 4993
DAT Release Date 03/27/2007
Threats Detected 238967
New Detections 23
Enhanced Detections 287

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Trojan (14)
  Downloader (2)
    Downloader-BBG
    Downloader-BBF
  Dropper (2)
    Downloader-AZG.dr
    DNSChanger.f.dr
  Heuristic (8)
    New Malware.bq
    New Downloader.c
    New Malware.bs
    New Malware.bu
    New Malware.bv
    New Malware.bt
    New Malware.br
    New Downloader.d
  Win32 (2)
    DNSChanger.f
    W32/Stration!eml
Virus (9)
  Email (1)
    W32/Azzag@MM
  Heuristic (1)
    New Malware.bw
  Parasitic (7)
    W32/HLLP.Philis.is
    W32/HLLP.Philis.iq
    W32/HLLP.Philis.ir
    W32/HLLP.Philis.ip
    W32/HLLP.Philis.io
    W32/HLLP.Philis.im
    W32/HLLP.Philis.in

Enhanced Detections:

Program (6)
  Adware (4)
    Adware-Virtumondo
    Adware-LinkMaker
    Adware-Shorty
    Adware-Newweb
  Dropper (2)
    Adware-Boran.dr
    Adware-Virtumundo.dr
Trojan (79)
   (2)
    FakeAlert-G
    AdClicker-ES
  Application extension (3)
    PWS-Marim.dll
    Spy-Agent.ba.dll
    BackDoor-AZX.dll
  Downloader (14)
    W32/Bagle.ew
    Downloader-AXU
    W32/Bagle.cj
    Downloader-BAE
    Downloader-AZG
    PWS-WoW.dldr
    Downloader-AYN
    Downloader-AWX
    PWS-Banker.dldr
    Downloader-BAI!M711
    BackDoor-CVM.dldr
    Downloader-ASH
    Downloader-AXR
    Downloader-ARL
  Downloader Generic (1)
    W32/Bagle.dldr
  Dropper (5)
    PWS-LDPinch.dr
    PWS-Gamania.dr
    PWS-Lineage.dr
    PWS-WoW.dr
    BackDoor-CVM.dr
  Exploit (2)
    Exploit-CreateTxtRng
    Exploit-CVE2006-3730
  Generic (4)
    BackDoor-AZX.gen
    BackDoor-BAC.gen
    PWS-Banker.gen.g
    PWS-Banker.gen.e
  Heuristic (13)
    New RootKit
    New Malware.bi
    New Malware.bg
    New Malware.be
    New Malware.bo
    New Malware.bp
    New Malware.bn
    New Malware.bm
    New Malware.bl
    New Malware.bk
    New Malware.bh
    New Malware.bf
    New Malware.aq
  Internet Relay Chat (1)
    IRC/Generic Flooder
  Password (4)
    PWS-LegMir
    PWS-LDPinch
    Generic PWS
    PWS-LDPinch.dr!4f8fa1f
  Password Stealer (8)
    PWS-Gamania
    PWS-Marim
    PWS-Mesgra
    PWS-Banker
    PWS-Banker.gen.i
    PWS-LDPinch!6e51bf02
    PWS-WoW
    PWS-Lineage
  Proxy (1)
    Proxy-FBSR
  Remote Access (6)
    Generic BackDoor
    BackDoor-AWQ.b
    BackDoor-AWQ
    BackDoor-CZF
    BackDoor-DKA
    BackDoor-CVM
  Settings Change (1)
    Generic StartPage
  Spam (1)
    Spam-Mespam
  Trojan (1)
    Spy-Agent.ba
  Win32 (12)
    Generic MultiDropper.d
    Generic Downloader.d
    Generic Downloader.s
    Generic Downloader.af
    Uploader-AF
    Generic Dropper.p
    Generic PWS.o
    Generic Downloader.ab
    Vundo
    Generic Dropper.u
    Generic Downloader.g
    Generic Downloader.f
Virus (202)
  Damaged Worm (1)
    W32/Sdbot.worm.dam
  Downloader (4)
    W32/Bagle.ci
    W32/Bagle.ck
    W32/Bagle.cl
    W32/Bagle.cn
  Dropper (1)
    W32/HLLP.Philis.dr
  E-mail (1)
    W32/Bagle.fd@MM
  E-mail worm (2)
    W32/Bagle.fc@MM
    W32/Bagle.fb@MM
  Email (2)
    W32/Bagle.cd@MM
    W32/Bagle.ff@MM
  Email Generic (2)
    W32/Mytob.gen@MM
    JS/Feebs.gen.n@MM
  Generic (2)
    W32/HLLP.Philis.gr
    W32/Bagle.gen
  Generic Worm (3)
    W32/Sdbot.worm.gen.h
    W32/Spybot.worm.gen.p
    W32/Sdbot.worm.gen.q
  Internet Worm (1)
    W32/Sdbot.worm
  Parasitic (170)
    W32/HLLP.Philis.cj
    W32/HLLP.Philis.bs
    W32/HLLP.Philis.fq
    W32/HLLP.Philis.ga
    W32/HLLP.Philis.gd
    W32/HLLP.Philis.gz
    W32/HLLP.Philis.hk
    W32/HLLP.Philis.hr
    W32/HLLP.Philis.hx
    W32/HLLP.Philis.hv
    W32/HLLP.Philis.ea
    W32/HLLP.Philis.if
    W32/HLLP.Philis.cs
    W32/HLLP.Philis.cq
    W32/HLLP.Philis.em
    W32/HLLP.Philis.dg
    W32/HLLP.Philis.ih
    W32/HLLP.Philis.bw
    W32/HLLP.Philis.bu
    W32/HLLP.Philis.fz
    W32/HLLP.Philis.ef
    W32/HLLP.Philis.hh
    W32/HLLP.Philis.hf
    W32/HLLP.Philis.dy
    W32/HLLP.Philis.hz
    W32/HLLP.Philis.fa
    W32/HLLP.Philis.hc
    W32/HLLP.Philis.gh
    W32/HLLP.Philis.hd
    W32/HLLP.Philis.hq
    W32/HLLP.Philis.bv
    W32/HLLP.Philis.gx
    W32/HLLP.Philis.ex
    W32/HLLP.Philis.ez
    W32/HLLP.Philis.cl
    W32/HLLP.Philis.ha
    W32/HLLP.Philis.dx
    W32/HLLP.Philis.bq
    W32/HLLP.Philis.cm
    W32/HLLP.Philis.db
    W32/HLLP.Philis.dw
    W32/HLLP.Philis.da
    W32/HLLP.Philis.dv
    W32/HLLP.Philis.gq
    W32/HLLP.Philis.ho
    W32/HLLP.Philis.fj
    W32/HLLP.Philis.bm
    W32/HLLP.Philis.ca
    W32/HLLP.Philis.ic
    W32/HLLP.Philis.ib
    W32/HLLP.Philis.ia
    W32/HLLP.Philis.cz
    W32/HLLP.Philis.gi
    W32/HLLP.Philis.gf
    W32/HLLP.Philis.cr
    W32/HLLP.Philis.cp
    W32/HLLP.Philis.do
    W32/HLLP.Philis.dn
    W32/HLLP.Philis.ce
    W32/HLLP.Philis.cd
    W32/HLLP.Philis.by
    W32/HLLP.Philis.gv
    W32/HLLP.Philis.hj
    W32/HLLP.Philis.he
    W32/HLLP.Philis.fd
    W32/HLLP.Philis.fc
    W32/HLLP.Philis.gu
    W32/HLLP.Philis.hp
    W32/HLLP.Philis.ee
    W32/HLLP.Philis.ec
    W32/HLLP.Philis.eb
    W32/HLLP.Philis.dm
    W32/HLLP.Philis.hi
    W32/HLLP.Philis.ed
    W32/HLLP.Philis.ck
    W32/HLLP.Philis.bx
    W32/HLLP.Philis.gk
    W32/HLLP.Philis.gl
    W32/HLLP.Philis.ge
    W32/HLLP.Philis.en
    W32/HLLP.Philis.el
    W32/HLLP.Philis.fn
    W32/HLLP.Philis.hn
    W32/HLLP.Philis.eu
    W32/HLLP.Philis.et
    W32/HLLP.Philis.eq
    W32/HLLP.Philis.es
    W32/HLLP.Philis.er
    W32/HLLP.Philis.ep
    W32/HLLP.Philis.fl
    W32/HLLP.Philis.du
    W32/HLLP.Philis.dk
    W32/HLLP.Philis.di
    W32/HLLP.Philis.bp
    W32/HLLP.Philis.eh
    W32/HLLP.Philis.dt
    W32/HLLP.Philis.cy
    W32/HLLP.Philis.ej
    W32/HLLP.Philis.ei
    W32/HLLP.Philis.bt
    W32/HLLP.Philis.ch
    W32/HLLP.Philis.ci
    W32/HLLP.Philis.id
    W32/HLLP.Philis.il
    W32/HLLP.Philis.ie
    W32/HLLP.Philis.ij
    W32/HLLP.Philis.gn
    W32/HLLP.philis.hb
    W32/HLLP.Philis.hy
    W32/HLLP.Philis.ik
    W32/HLLP.Philis.ig
    W32/HLLP.Philis.gm
    W32/HLLP.Philis.dq
    W32/HLLP.Philis.ev
    W32/HLLP.Philis.fb
    W32/HLLP.Philis.fh
    W32/HLLP.Philis.ff
    W32/HLLP.Philis.dl
    W32/HLLP.Philis.dj
    W32/HLLP.Philis.dh
    W32/HLLP.Philis.dp
    W32/HLLP.Philis.fi
    W32/HLLP.Philis.fr
    W32/HLLP.Philis.gw
    W32/HLLP.Philis.fg
    W32/HLLP.Philis.fe
    W32/HLLP.Philis.fk
    W32/HLLP.Philis.ht
    W32/HLLP.Philis.hm
    W32/HLLP.Philis.ds
    W32/HLLP.Philis.cc
    W32/HLLP.Philis.bz
    W32/HLLP.Philis.eg
    W32/HLLP.Philis.eo
    W32/HLLP.Philis.cx
    W32/HLLP.Philis.df
    W32/HLLP.Philis.fp
    W32/HLLP.Philis.fx
    W32/HLLP.Philis.gc
    W32/HLLP.Philis.gt
    W32/HLLP.Philis.hg
    W32/HLLP.Philis.cn
    W32/HLLP.Philis.gs
    W32/HLLP.Philis.gy
    W32/HLLP.Philis.hl
    W32/HLLP.Philis.ii
    W32/HLLP.Philis.ft
    W32/HLLP.Philis.gp
    W32/HLLP.Philis.fm
    W32/HLLP.Philis.fu
    W32/HLLP.Philis.gj
    W32/HLLP.Philis.fw
    W32/HLLP.Philis.fv
    W32/HLLP.Philis.fs
    W32/HLLP.Philis.hw
    W32/HLLP.Philis.hu
    W32/HLLP.Philis.hs
    W32/HLLP.Philis.ew
    W32/HLLP.Philis.go
    W32/HLLP.Philis.cv
    W32/HLLP.Philis.ct
    W32/HLLP.Philis.de
    W32/HLLP.Philis.dc
    W32/HLLP.Philis.gb
    W32/HLLP.Philis.cw
    W32/HLLP.Philis.cu
    W32/HLLP.Philis.dd
    W32/HLLP.Philis.co
    W32/HLLP.Philis.cg
    W32/HLLP.Philis.cf
  Script (2)
    VBS/Generic
    VBS/IE-Title
  Win32 (8)
    W32/Bagle.cp
    W32/Bagle.cq
    W32/Bagle.co
    W32/Bagle.cm
    W32/Bagle.dd
    W32/Bagle.ey
    W32/Virut.d
    W32/Bagle.dc
  Worm (3)
    W32/Generic.worm.h
    W32/HLLP.Philis.gg
    W32/CWT.worm