Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

Latest Update
DAT Version 5182
DAT Release Date 12/10/2007
Threats Detected 353841
New Detections 16
Enhanced Detections 355

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
There are no noteworthy threats in this release

New Detections:

Program (3)
  Application extension (1)
    WStudio.dll
  Dropper (1)
    WStudio.dr
  Win32 (1)
    SysCare
Trojan (8)
   (1)
    QHosts-94!hosts
  Downloader (2)
    BraveSentry.dldr
    BackDoor-DLY.dldr
  Heuristic (4)
    New Malware.hp
    New Malware.hn
    New Malware.hq
    New Malware.ho
  Win32 (1)
    QHosts-94
Virus (5)
  Application extension (1)
    W32/Trats.dll
  Generic (1)
    W32/IRCBot.gen.s
  Parasitic (1)
    W32/HLLP.Philis.lb
  Win32 (1)
    W32/Trats
  Worm (1)
    W32/Autorun.worm.be

Enhanced Detections:

Program (7)
   (1)
    DeepDive
  - (1)
    Proxy-OSS
  Adware (2)
    Adware-PigSearch
    Adware-Cinmus
  Dropper (1)
    Adware-Boran.dr
  Registry (1)
    Generic AdClicker.h
  Win32 (1)
    WStudio
Trojan (51)
   (1)
    Generic Spy.e
  Application extension (1)
    Spy-Agent.br.dll
  Application extension Generi (1)
    Puper.dll.gen
  Configurator (1)
    BackDoor-DKG.cfg
  Damaged (2)
    Generic.dam
    BackDoor-AWQ.b.dam
  Downloader (9)
    Downloader-AFH
    Downloader-BCF
    Spy-Agent.bv.dldr
    Downloader-AZN
    Downloader-AWE
    Downloader-AWX
    StartPage-JU.dldr
    PWS-Banker.dldr
    Downloader-BDH
  Dropper (3)
    AdClicker-BJ.dr
    Generic Dropper.p
    Downloader-AZN.dr
  Exploit (1)
    JS/Exploit-DDay
  Generic (1)
    JS/Exploit-BO.gen
  Heuristic (6)
    New Malware.gr
    New Malware.ca
    New Malware.n
    New Malware.cj
    New Malware.j
    New Malware.aj
  Password (3)
    PWS-LegMir
    PWS-QQPass
    PWS-LDPinch
  Password Stealer (2)
    PWS-Banker.gen.i
    PWS-OnlineGames.a
  Remote Access (6)
    BackDoor-AWQ.b
    BackDoor-CSS
    BackDoor-DLY
    BackDoor-CWA
    Generic BackDoor.m
    BackDoor-DMO
  StartPage (1)
    StartPage-JU
  Win32 (13)
    Generic Downloader.a
    Generic Downloader.c
    QHosts-66
    Puper
    AdClicker-ET
    Generic Delphi.c
    Spy-Agent.bw
    Generic BackDoor.u
    Generic Downloader.ab
    Vundo
    DNSChanger.d
    BraveSentry
    Generic Downloader.e
Virus (297)
  Dropper (2)
    W32/Checkout.dr
    W32/HLLP.Philis.dr
  Generic (3)
    W32/IRCbot.gen!F3E69DA4
    W32/IRCbot.gen
    W32/HLLP.Philis.gr
  Generic Worm (2)
    W32/Sdbot.worm.gen.ax
    W32/Autorun.worm.i.gen
  Heuristic (1)
    New Malware.b
  Internet Worm (1)
    W32/Checkout
  Parasitic (225)
    W32/HLLP.Philis.cj
    W32/HLLP.Philis.jf
    W32/HLLP.Philis.bs
    W32/HLLP.Philis.fq
    W32/HLLP.Philis.ga
    W32/HLLP.Philis.gd
    W32/HLLP.Philis.gz
    W32/HLLP.Philis.hk
    W32/HLLP.Philis.hr
    W32/HLLP.Philis.jc
    W32/HLLP.Philis.jq
    W32/HLLP.Philis.kr
    W32/HLLP.Philis.hx
    W32/HLLP.Philis.hv
    W32/HLLP.Philis.ea
    W32/HLLP.Philis.if
    W32/HLLP.Philis.je
    W32/HLLP.Philis.cs
    W32/HLLP.Philis.cq
    W32/HLLP.Philis.kn
    W32/HLLP.Philis.em
    W32/HLLP.Philis.dg
    W32/HLLP.Philis.ih
    W32/HLLP.Philis.bw
    W32/HLLP.Philis.bu
    W32/HLLP.Philis.fz
    W32/HLLP.Philis.ef
    W32/HLLP.Philis.hh
    W32/HLLP.Philis.hf
    W32/HLLP.Philis.dy
    W32/HLLP.Philis.kq
    W32/HLLP.Philis.iz
    W32/HLLP.Philis.iy
    W32/HLLP.Philis.hz
    W32/HLLP.Philis.fa
    W32/HLLP.Philis.jz
    W32/HLLP.Philis.kf
    W32/HLLP.Philis.kd
    W32/HLLP.Philis.kg
    W32/HLLP.Philis.ke
    W32/HLLP.Philis.ji
    W32/HLLP.Philis.hc
    W32/HLLP.Philis.gh
    W32/HLLP.Philis.jb
    W32/HLLP.Philis.hd
    W32/HLLP.Philis.hq
    W32/HLLP.Philis.bv
    W32/HLLP.Philis.gx
    W32/HLLP.Philis.ex
    W32/HLLP.Philis.ez
    W32/HLLP.Philis.cl
    W32/HLLP.Philis.ha
    W32/HLLP.Philis.dx
    W32/HLLP.Philis.bq
    W32/HLLP.Philis.cm
    W32/HLLP.Philis.db
    W32/HLLP.Philis.dw
    W32/HLLP.Philis.kl
    W32/HLLP.Philis.kw
    W32/HLLP.Philis.da
    W32/HLLP.Philis.dv
    W32/HLLP.Philis.gq
    W32/HLLP.Philis.ho
    W32/HLLP.Philis.fj
    W32/HLLP.Philis.bm
    W32/HLLP.Philis.ca
    W32/HLLP.Philis.ic
    W32/HLLP.Philis.ib
    W32/HLLP.Philis.ia
    W32/HLLP.Philis.iv
    W32/HLLP.Philis.iu
    W32/HLLP.Philis.cz
    W32/HLLP.Philis.km
    W32/HLLP.Philis.gi
    W32/HLLP.Philis.gf
    W32/HLLP.Philis.jj
    W32/HLLP.Philis.it
    W32/HLLP.Philis.cr
    W32/HLLP.Philis.cp
    W32/HLLP.Philis.do
    W32/HLLP.Philis.dn
    W32/HLLP.Philis.jp
    W32/HLLP.Philis.ce
    W32/HLLP.Philis.cd
    W32/HLLP.Philis.by
    W32/HLLP.Philis.gv
    W32/HLLP.Philis.hj
    W32/HLLP.Philis.he
    W32/HLLP.Philis.fd
    W32/HLLP.Philis.fc
    W32/HLLP.Philis.gu
    W32/HLLP.Philis.hp
    W32/HLLP.Philis.ee
    W32/HLLP.Philis.ec
    W32/HLLP.Philis.eb
    W32/HLLP.Philis.dm
    W32/HLLP.Philis.la
    W32/HLLP.Philis.hi
    W32/HLLP.Philis.ed
    W32/HLLP.Philis.ck
    W32/HLLP.Philis.bx
    W32/HLLP.Philis.kb
    W32/HLLP.Philis.ju
    W32/HLLP.Philis.jv
    W32/HLLP.Philis.gk
    W32/HLLP.Philis.gl
    W32/HLLP.Philis.ge
    W32/HLLP.Philis.en
    W32/HLLP.Philis.el
    W32/HLLP.Philis.jr
    W32/HLLP.Philis.fn
    W32/HLLP.Philis.hn
    W32/HLLP.Philis.eu
    W32/HLLP.Philis.et
    W32/HLLP.Philis.eq
    W32/HLLP.Philis.jk
    W32/HLLP.Philis.es
    W32/HLLP.Philis.er
    W32/HLLP.Philis.ep
    W32/HLLP.Philis.fl
    W32/HLLP.Philis.du
    W32/HLLP.Philis.dk
    W32/HLLP.Philis.di
    W32/HLLP.Philis.bp
    W32/HLLP.Philis.eh
    W32/HLLP.Philis.dt
    W32/HLLP.Philis.cy
    W32/HLLP.Philis.ej
    W32/HLLP.Philis.ei
    W32/HLLP.Philis.bt
    W32/HLLP.Philis.ch
    W32/HLLP.Philis.ci
    W32/HLLP.Philis.ki
    W32/HLLP.Philis.id
    W32/HLLP.Philis.il
    W32/HLLP.Philis.ja
    W32/HLLP.Philis.ix
    W32/HLLP.Philis.jg
    W32/HLLP.Philis.iw
    W32/HLLP.Philis.jh
    W32/HLLP.Philis.jl
    W32/HLLP.Philis.ie
    W32/HLLP.Philis.ij
    W32/HLLP.Philis.jn
    W32/HLLP.Philis.js
    W32/HLLP.Philis.jw
    W32/HLLP.Philis.gn
    W32/HLLP.Philis.is
    W32/HLLP.Philis.iq
    W32/HLLP.philis.hb
    W32/HLLP.Philis.hy
    W32/HLLP.Philis.ik
    W32/HLLP.Philis.ig
    W32/HLLP.Philis.gm
    W32/HLLP.Philis.dq
    W32/HLLP.Philis.ev
    W32/HLLP.Philis.fb
    W32/HLLP.Philis.fh
    W32/HLLP.Philis.ff
    W32/HLLP.Philis.jm
    W32/HLLP.Philis.dl
    W32/HLLP.Philis.dj
    W32/HLLP.Philis.dh
    W32/HLLP.Philis.dp
    W32/HLLP.Philis.fi
    W32/HLLP.Philis.fr
    W32/HLLP.Philis.gw
    W32/HLLP.Philis.ir
    W32/HLLP.Philis.ip
    W32/HLLP.Philis.fg
    W32/HLLP.Philis.fe
    W32/HLLP.Philis.fk
    W32/HLLP.Philis.ht
    W32/HLLP.Philis.hm
    W32/HLLP.Philis.ds
    W32/HLLP.Philis.cc
    W32/HLLP.Philis.bz
    W32/HLLP.Philis.eg
    W32/HLLP.Philis.eo
    W32/HLLP.Philis.cx
    W32/HLLP.Philis.df
    W32/HLLP.Philis.fp
    W32/HLLP.Philis.fx
    W32/HLLP.Philis.gc
    W32/HLLP.Philis.gt
    W32/HLLP.Philis.io
    W32/HLLP.Philis.jt
    W32/HLLP.Philis.ka
    W32/HLLP.Philis.hg
    W32/HLLP.Philis.kh
    W32/HLLP.Philis.ko
    W32/HLLP.Philis.kp
    W32/HLLP.Philis.kc
    W32/HLLP.Philis.cn
    W32/HLLP.Philis.jd
    W32/HLLP.Philis.gs
    W32/HLLP.Philis.gy
    W32/HLLP.Philis.hl
    W32/HLLP.Philis.ii
    W32/HLLP.Philis.im
    W32/HLLP.Philis.ft
    W32/HLLP.Philis.gp
    W32/HLLP.Philis.fm
    W32/HLLP.Philis.fu
    W32/HLLP.Philis.gj
    W32/HLLP.Philis.fw
    W32/HLLP.Philis.fv
    W32/HLLP.Philis.fs
    W32/HLLP.Philis.hw
    W32/HLLP.Philis.hu
    W32/HLLP.Philis.hs
    W32/HLLP.Philis.ew
    W32/HLLP.Philis.go
    W32/HLLP.Philis.cv
    W32/HLLP.Philis.ct
    W32/HLLP.Philis.de
    W32/HLLP.Philis.dc
    W32/HLLP.Philis.gb
    W32/HLLP.Philis.cw
    W32/HLLP.Philis.cu
    W32/HLLP.Philis.dd
    W32/HLLP.Philis.co
    W32/HLLP.Philis.in
    W32/HLLP.Philis.cg
    W32/HLLP.Philis.cf
  Win32 (59)
    W32/NGVCK.a.7397
    W32/NGVCK.a.8809
    W32/NGVCK.a.4768
    W32/NGVCK.a.2404
    W32/NGVCK.a.2280
    W32/NGVCK.a.1365
    W32/NGVCK.a.2389
    W32/NGVCK.a.4907
    W32/NGVCK.a.3072a
    W32/NGVCK.a.1934
    W32/NGVCK.a.3560
    W32/NGVCK.a.2522/2537
    W32/NGVCK.a.2342
    W32/NGVCK.a.2218
    W32/NGVCK.a.2754
    W32/NGVCK.a.9412
    W32/NGVCK.a.1947
    W32/NGVCK.a.1416
    W32/NGVCK.a.3072b
    W32/NGVCK.a.1988
    W32/NGVCK.a.2092
    W32/NGVCK.a.2651
    W32/NGVCK.a.1056
    W32/NGVCK.a.2751
    W32/NGVCK.a.9632
    W32/NGVCK.a.1107
    W32/NGVCK.a.1700
    W32/NGVCK.a.3146
    W32/NGVCK.a.3250
    W32/NGVCK.a.1455
    W32/NGVCK.a.3427
    W32/NGVCK.a.5216
    W32/NGVCK.a.1364
    W32/NGVCK.a.2522
    W32/NGVCK.a.926
    W32/NGVCK.a.1352
    W32/NGVCK.a.2266
    W32/NGVCK.a.919
    W32/NGVCK.a.1840
    W32/NGVCK.a.968
    W32/NGVCK.a.5675
    W32/NGVCK.a.7168
    W32/MumaWow.b!inf
    W32/NGVCK.a.3989
    W32/NGVCK.a.3818
    W32/NGVCK.a.1613
    W32/NGVCK.a.3888
    W32/NGVCK.a.3746
    W32/NGVCK.a.1095
    W32/NGVCK.a.3106
    W32/NGVCK.a.1792
    W32/NGVCK.a.1537
    W32/Gexin.a
    W32/NGVCK.a.4347
    W32/NGVCK.a.853
    W32/NGVCK.a.1222
    W32/NGVCK.a.2712
    W32/NGVCK.a.2134
    W32/MumaWow.b
  Worm (4)
    W32/HLLP.Philis.gg
    VBS/Autorun.worm.k
    W32/Autorun.worm.g
    W32/Autorun.worm.h