Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

Latest Update
DAT Version 5025
DAT Release Date 05/07/2007
Threats Detected 254384
New Detections 11
Enhanced Detections 322

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Heuristics (1)
  Rootkit (1)
    MadCodeHook!mem
Trojan (9)
   (5)
    Generic.aca
    Generic Downloader.bz
    Generic.acb
    Generic PWS.ab
    Generic Rootkit.d!rootkit
  Downloader (1)
    Downloader-ZQ!rootkit
  Generic (1)
    PWS-Mmorpg.gen
  Win32 (2)
    W32/Generic.abq!worm
    W32/Generic.abr!worm
Virus (1)
  Parasitic (1)
    W32/HLLP.Philis.kb

Enhanced Detections:

Internet Worm (2)
  Internet Relay Chat (2)
    W32/Sdbot.worm!811a7027
    W32/Nirbot.worm
Program (7)
   (1)
    Generic PUP.a
  Downloader (1)
    Downloader-ABJ
  Dropper (1)
    Adware-Boran.dr
  Generic (1)
    Adware-BHO.gen.d
  Spyware (1)
    Spyware-GoldenEye
  Tool (1)
    FireDaemon
  Win32 (1)
    Winfixer
Trojan (62)
   (5)
    Generic.dx
    ObfuscatedHtml
    Generic.f
    Generic Spy.e
    Spy-Agent.bh
  - (1)
    IRC/Flood.mirc
  Application extension (4)
    PWS-QQPass.dll
    Spy-Agent.br.dll
    BackDoor-CVM.dll
    PWS-WoW.dll
  Downloader (9)
    W32/Bagle.ew
    W32/Bagle.cj
    Downloader-AAP
    PWS-Banker.dldr!0206BCE1
    Downloader-BAY
    PWS-Banker.dldr
    Downloader-BAI!M711
    PWS-Banker.dldr.c
    Downloader-BCB
  Downloader Generic (1)
    W32/Bagle.dldr
  Dropper (5)
    Generic Dropper
    DNSChanger.f.dr
    PWS-Lineage.dr
    BackDoor-CVM.dr
    Matcash.dr
  Exploit (2)
    VBS/Psyme
    Exploit-CVE2006-4534
  Generic (3)
    PWS-LegMir.gen.b
    Downloader-ASH.gen
    BackDoor-CMQ.gen
  Heuristic (5)
    New Malware.bx
    New Malware.bo
    New Malware.bl
    New Malware.aq
    New Malware.x
  Password (4)
    PWS-LegMir
    PWS-QQPass
    PWS-LDPinch
    Generic PWS
  Password Stealer (6)
    PWS-LegMir.dll
    PWS-Banker
    PWS-Maran
    PWS-WoW
    PWS-Lineage
    PWS-Goldun
  Remote Access (5)
    Generic BackDoor
    BackDoor-BAC
    BackDoor-AWQ
    BackDoor-DKA
    BackDoor-CVM
  Win32 (12)
    Generic Downloader.c
    Generic Downloader
    Generic Downloader.d
    Puper
    Generic Downloader.s
    Generic Dropper.ad
    Generic PWS.o
    Generic BackDoor.u
    Generic Downloader.ab
    Generic VB.c
    Generic AdClicker.p
    Generic AdClicker.d
Virus (251)
  Configuration settings (1)
    W32/Fujacks.ini
  Damaged Worm (1)
    W32/Sdbot.worm.dam
  Downloader (4)
    W32/Bagle.ci
    W32/Bagle.ck
    W32/Bagle.cl
    W32/Bagle.cn
  Dropper (1)
    W32/HLLP.Philis.dr
  E-mail (1)
    W32/Bagle.fd@MM
  E-mail worm (2)
    W32/Bagle.fc@MM
    W32/Bagle.fb@MM
  Email (3)
    W32/Bagle.cd@MM
    W32/Avon@MM
    W32/Bagle.ff@MM
  Generic (3)
    W32/Zhelatin.gen
    W32/HLLP.Philis.gr
    W32/Bagle.gen
  Generic Worm (5)
    W32/Sdbot.worm.gen.l
    W32/Sdbot.worm.gen.ca
    W32/Sdbot.worm.gen.ai
    W32/Sdbot.worm.gen.ax
    W32/Sdbot.worm.gen.q
  Heuristic (1)
    New Floppy Worm
  HTML document (1)
    W32/Nimda.htm
  Internet Relay Chat Worm (1)
    W32/Sdbot.worm.gen.cc
  Internet Worm (2)
    W32/Sdbot.worm
    W32/Sdbot.worm!MS06-040
  Overwriting (1)
    W32/RAHack
  P2P Worm (1)
    W32/Jhon.worm.p2p
  Parasitic (208)
    W32/HLLP.Philis.cj
    W32/HLLP.Philis.jf
    W32/HLLP.Philis.bs
    W32/HLLP.Philis.fq
    W32/HLLP.Philis.ga
    W32/HLLP.Philis.gd
    W32/HLLP.Philis.gz
    W32/HLLP.Philis.hk
    W32/HLLP.Philis.hr
    W32/HLLP.Philis.jc
    W32/HLLP.Philis.jq
    W32/HLLP.Philis.hx
    W32/HLLP.Philis.hv
    W32/HLLP.Philis.ea
    W32/HLLP.Philis.if
    W32/HLLP.Philis.je
    W32/HLLP.Philis.cs
    W32/HLLP.Philis.cq
    W32/HLLP.Philis.em
    W32/HLLP.Philis.dg
    W32/HLLP.Philis.ih
    W32/HLLP.Philis.bw
    W32/HLLP.Philis.bu
    W32/HLLP.Philis.fz
    W32/HLLP.Philis.ef
    W32/HLLP.Philis.hh
    W32/HLLP.Philis.hf
    W32/HLLP.Philis.dy
    W32/HLLP.Philis.iz
    W32/HLLP.Philis.iy
    W32/HLLP.Philis.hz
    W32/HLLP.Philis.fa
    W32/HLLP.Philis.jz
    W32/HLLP.Philis.ji
    W32/HLLP.Philis.hc
    W32/HLLP.Philis.gh
    W32/HLLP.Philis.jb
    W32/HLLP.Philis.hd
    W32/HLLP.Philis.hq
    W32/HLLP.Philis.bv
    W32/HLLP.Philis.gx
    W32/HLLP.Philis.ex
    W32/HLLP.Philis.ez
    W32/HLLP.Philis.cl
    W32/HLLP.Philis.ha
    W32/HLLP.Philis.dx
    W32/HLLP.Philis.bq
    W32/HLLP.Philis.cm
    W32/HLLP.Philis.db
    W32/HLLP.Philis.dw
    W32/HLLP.Philis.da
    W32/HLLP.Philis.dv
    W32/HLLP.Philis.gq
    W32/HLLP.Philis.ho
    W32/HLLP.Philis.fj
    W32/HLLP.Philis.bm
    W32/HLLP.Philis.ca
    W32/HLLP.Philis.ic
    W32/HLLP.Philis.ib
    W32/HLLP.Philis.ia
    W32/HLLP.Philis.iv
    W32/HLLP.Philis.iu
    W32/HLLP.Philis.cz
    W32/HLLP.Philis.gi
    W32/HLLP.Philis.gf
    W32/HLLP.Philis.jj
    W32/HLLP.Philis.it
    W32/HLLP.Philis.cr
    W32/HLLP.Philis.cp
    W32/HLLP.Philis.do
    W32/HLLP.Philis.dn
    W32/HLLP.Philis.jp
    W32/HLLP.Philis.ce
    W32/HLLP.Philis.cd
    W32/HLLP.Philis.by
    W32/HLLP.Philis.gv
    W32/HLLP.Philis.hj
    W32/HLLP.Philis.he
    W32/HLLP.Philis.fd
    W32/HLLP.Philis.fc
    W32/HLLP.Philis.gu
    W32/HLLP.Philis.hp
    W32/HLLP.Philis.ee
    W32/HLLP.Philis.ec
    W32/HLLP.Philis.eb
    W32/HLLP.Philis.dm
    W32/HLLP.Philis.hi
    W32/HLLP.Philis.ed
    W32/HLLP.Philis.ck
    W32/HLLP.Philis.bx
    W32/HLLP.Philis.ju
    W32/HLLP.Philis.jv
    W32/HLLP.Philis.gk
    W32/HLLP.Philis.gl
    W32/HLLP.Philis.ge
    W32/HLLP.Philis.en
    W32/HLLP.Philis.el
    W32/HLLP.Philis.jr
    W32/HLLP.Philis.fn
    W32/HLLP.Philis.hn
    W32/HLLP.Philis.eu
    W32/HLLP.Philis.et
    W32/HLLP.Philis.eq
    W32/HLLP.Philis.jk
    W32/HLLP.Philis.es
    W32/HLLP.Philis.er
    W32/HLLP.Philis.ep
    W32/HLLP.Philis.fl
    W32/HLLP.Philis.du
    W32/HLLP.Philis.dk
    W32/HLLP.Philis.di
    W32/HLLP.Philis.bp
    W32/HLLP.Philis.eh
    W32/HLLP.Philis.dt
    W32/HLLP.Philis.cy
    W32/HLLP.Philis.ej
    W32/HLLP.Philis.ei
    W32/HLLP.Philis.bt
    W32/HLLP.Philis.ch
    W32/HLLP.Philis.ci
    W32/HLLP.Philis.id
    W32/HLLP.Philis.il
    W32/HLLP.Philis.ja
    W32/HLLP.Philis.ix
    W32/HLLP.Philis.jg
    W32/HLLP.Philis.iw
    W32/HLLP.Philis.jh
    W32/HLLP.Philis.jl
    W32/HLLP.Philis.ie
    W32/HLLP.Philis.ij
    W32/HLLP.Philis.jn
    W32/HLLP.Philis.js
    W32/HLLP.Philis.jw
    W32/HLLP.Philis.gn
    W32/HLLP.Philis.is
    W32/HLLP.Philis.iq
    W32/HLLP.philis.hb
    W32/HLLP.Philis.hy
    W32/HLLP.Philis.ik
    W32/HLLP.Philis.ig
    W32/HLLP.Philis.gm
    W32/HLLP.Philis.dq
    W32/HLLP.Philis.ev
    W32/HLLP.Philis.fb
    W32/HLLP.Philis.fh
    W32/HLLP.Philis.ff
    W32/HLLP.Philis.jm
    W32/HLLP.Philis.dl
    W32/HLLP.Philis.dj
    W32/HLLP.Philis.dh
    W32/HLLP.Philis.dp
    W32/HLLP.Philis.fi
    W32/HLLP.Philis.fr
    W32/HLLP.Philis.gw
    W32/HLLP.Philis.ir
    W32/HLLP.Philis.ip
    W32/HLLP.Philis.fg
    W32/HLLP.Philis.fe
    W32/HLLP.Philis.fk
    W32/HLLP.Philis.ht
    W32/HLLP.Philis.hm
    W32/HLLP.Philis.ds
    W32/HLLP.Philis.cc
    W32/HLLP.Philis.bz
    W32/HLLP.Philis.eg
    W32/HLLP.Philis.eo
    W32/HLLP.Philis.cx
    W32/HLLP.Philis.df
    W32/HLLP.Philis.fp
    W32/HLLP.Philis.fx
    W32/HLLP.Philis.gc
    W32/HLLP.Philis.gt
    W32/HLLP.Philis.io
    W32/HLLP.Philis.jt
    W32/HLLP.Philis.ka
    W32/HLLP.Philis.hg
    W32/HLLP.Philis.cn
    W32/HLLP.Philis.jd
    W32/HLLP.Philis.gs
    W32/HLLP.Philis.gy
    W32/HLLP.Philis.hl
    W32/HLLP.Philis.ii
    W32/HLLP.Philis.im
    W32/HLLP.Philis.ft
    W32/HLLP.Philis.gp
    W32/HLLP.Philis.fm
    W32/HLLP.Philis.fu
    W32/HLLP.Philis.gj
    W32/HLLP.Philis.fw
    W32/HLLP.Philis.fv
    W32/HLLP.Philis.fs
    W32/HLLP.Philis.hw
    W32/HLLP.Philis.hu
    W32/HLLP.Philis.hs
    W32/HLLP.Philis.ew
    W32/HLLP.Philis.go
    W32/HLLP.Philis.cv
    W32/HLLP.Philis.ct
    W32/HLLP.Philis.de
    W32/HLLP.Philis.dc
    W32/HLLP.Philis.gb
    W32/HLLP.Philis.cw
    W32/HLLP.Philis.cu
    W32/HLLP.Philis.dd
    W32/HLLP.Philis.co
    W32/HLLP.Philis.in
    W32/HLLP.Philis.cg
    W32/HLLP.Philis.cf
  Script (1)
    VBS/IE-Title
  VbScript (1)
    New Script
  Win32 (7)
    W32/Bagle.cp
    W32/Bagle.cq
    W32/Bagle.co
    W32/Bagle.cm
    W32/Bagle.dd
    W32/Bagle.ey
    W32/Bagle.dc
  Worm (6)
    W32/Generic.worm.b
    W32/Pate.b
    W32/HLLP.Philis.gg
    W32/Emerleox.worm
    W32/Generic.worm.i
    W32/Sdbot.worm!678b37ba