McAfee DAT v4585 dat files have been released due to mutliple new variants of Bagle

McAfee DAT v4585 dat files have been released due to mutliple new variants of Bagle

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
McAfee DAT v4585 dat files have been released due to mutliple new variants of Bagle David H. Lipman 09-19-2005
Posted by David H. Lipman on September 19, 2005, 6:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
McAfee had detected them under Heuristics as "New Poly Win32" but with v4585 the
new variants are now called; "W32/Bagle.ci", "W32/Bagle.cj" and "W32/Bagle.cl"
{ I couldn't find information on "W32/Bagle.ck" variant but based upon mcAfe's
naming convention, they wouldn't name the W32/Bagle.cl variant without first
having a W32/Bagle.ck variant }

I don't know if Stinger will be updated but no Bagle variants have been added to
Stinger since 5/02/2005 when; W32/Bagle.bo - W32/Bagle.bt were added. That
leaves; W32/Bagle.bt - W32/Bagle.cl needing to be added.


-------
The 4585 dat files have been released due to the mutliple variants of Bagle that
have been spammed out today.

The various 4585 dat file packages can be found at
http://www.mcafeesecurity.com/us/downloads/default.asp.

IS YOUR ENGINE UP-TO-DATE? - Anti-virus is only as good as its last update!

Current Engine Information by platform:
- Microsoft: 4400
- Netware: 4400
- UNIX: 4400
- Macintosh OS X: 4400

Engine Security Tips from AVERT and the McAfee Security Engine Development
Team
- Updating your DAT files regularly is essential and a MUST!
- Updating your scan engine is just as important and a MUST
- An old Engine WON'T catch some of today's threats
- Sometimes architectural changes to the way DAT files and scan
- engine work together make it critical for you to update your scan
engine
- AVERT says it makes sense to have as part of your Security Policy
- Program an Engine Update process to take advantage of the latest
technology and stay protected!

The Problem
Between 250 and 400 new detections are added to the DATs monthly by AVERT.
If you're not up-to-date, you are vulnerable to any one of them that gets a
foothold in the field (a.k.a. 'in the wild'). McAfee AVERT releases
regular DAT files, ensuring that full protection is added to all McAfee
products.

The DAT files contain the information required to detect and remove threats
- what to look for and where to look for it. However, today's threats are
evolving almost on a daily basis. Software providers continue to have
operating systems and applications changes that can change the way a
program acts or works and a virus-scanning program may not understand the
changes.

The Solution
Taking this into account McAfee Security regularly updates its scan engine
used by ALL McAfee Security virus detection and removal products. The
engine understands all the different structures in which a virus could lurk
- EXE files, MS Office files, Linux files, etc. Occasionally these changes
require us to make significant architectural changes to the engine as well
as the DAT files. AVERT strongly recommends users of ALL McAfee Security
virus scanning products update the scan engines in the products they have
deployed as part of a sound Security best practices program.

Here's how to check your engine version. Right-click on the McAfee shield
in the system tray, select 'About' and look at the 'Scan engine' version
number. If you need to update, you should update your scan engine
immediately.

McAfee Security Engine End-Of-Life (EOL) Program
Because of the evolving malicious code threat, users should update their
engines as soon as possible upon the release of McAfee Security's latest
scanning technology. When a new engine is released the existing engine
will begin its countdown to its EOL, and will therefore no longer be
supported by McAfee Security. Information on the McAfee Security Engine
End of Life policy and a full list of supported scan engines and products
can be found at:
http://www.mcafeesecurity.com/us/products/mcafee/end_of_life.htm

Best Regards,

McAfee AVERT - Anti Virus and Vulnerability Research, Analysis, and
Solutions visit us at www.avertlabs.com


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by What's in a Name? on September 19, 2005, 9:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> McAfee had detected them under Heuristics as "New Poly Win32" but
> with v4585 the new variants are now called; "W32/Bagle.ci",
> "W32/Bagle.cj" and "W32/Bagle.cl" { I couldn't find information on
> "W32/Bagle.ck" variant but based upon mcAfe's naming convention,
> they wouldn't name the W32/Bagle.cl variant without first having a
> W32/Bagle.ck variant }
>
> I don't know if Stinger will be updated but no Bagle variants have
> been added to Stinger since 5/02/2005 when; W32/Bagle.bo -
> W32/Bagle.bt were added. That leaves; W32/Bagle.bt - W32/Bagle.cl
> needing to be added.
>
>
> -------
> The 4585 dat files have been released due to the mutliple variants
> of Bagle that have been spammed out today.
>
> The various 4585 dat file packages can be found at
> http://www.mcafeesecurity.com/us/downloads/default.asp.
>
> IS YOUR ENGINE UP-TO-DATE? - Anti-virus is only as good as its
> last update!
>
> Current Engine Information by platform:
> - Microsoft: 4400
> - Netware: 4400
> - UNIX: 4400
> - Macintosh OS X: 4400
>
> Engine Security Tips from AVERT and the McAfee Security Engine
> Development Team
> - Updating your DAT files regularly is essential and a MUST!
> - Updating your scan engine is just as important and a MUST
> - An old Engine WON'T catch some of today's threats
> - Sometimes architectural changes to the way DAT files and
> scan - engine work together make it critical for you to
> update your scan engine
> - AVERT says it makes sense to have as part of your Security
> Policy - Program an Engine Update process to take advantage
> of the latest
> technology and stay protected!
>
> The Problem
> Between 250 and 400 new detections are added to the DATs monthly
> by AVERT. If you're not up-to-date, you are vulnerable to any one
> of them that gets a foothold in the field (a.k.a. 'in the wild').
> McAfee AVERT releases regular DAT files, ensuring that full
> protection is added to all McAfee products.
>
> The DAT files contain the information required to detect and
> remove threats - what to look for and where to look for it.
> However, today's threats are evolving almost on a daily basis.
> Software providers continue to have operating systems and
> applications changes that can change the way a program acts or
> works and a virus-scanning program may not understand the changes.
>
> The Solution
> Taking this into account McAfee Security regularly updates its
> scan engine used by ALL McAfee Security virus detection and
> removal products. The engine understands all the different
> structures in which a virus could lurk - EXE files, MS Office
> files, Linux files, etc. Occasionally these changes require us to
> make significant architectural changes to the engine as well as
> the DAT files. AVERT strongly recommends users of ALL McAfee
> Security virus scanning products update the scan engines in the
> products they have deployed as part of a sound Security best
> practices program.
>
> Here's how to check your engine version. Right-click on the
> McAfee shield in the system tray, select 'About' and look at the
> 'Scan engine' version number. If you need to update, you should
> update your scan engine immediately.
>
> McAfee Security Engine End-Of-Life (EOL) Program
> Because of the evolving malicious code threat, users should update
> their engines as soon as possible upon the release of McAfee
> Security's latest scanning technology. When a new engine is
> released the existing engine will begin its countdown to its EOL,
> and will therefore no longer be supported by McAfee Security.
> Information on the McAfee Security Engine End of Life policy and a
> full list of supported scan engines and products can be found at:
> http://www.mcafeesecurity.com/us/products/mcafee/end_of_life.htm
>
> Best Regards,
>
> McAfee AVERT - Anti Virus and Vulnerability Research, Analysis,
> and Solutions visit us at www.avertlabs.com
>
>

Hey David-seems that Bagle.ck is the one that virusguy was talking
about the other day(price.zip)
http://vil.mcafeesecurity.com/vil/content/v_136039.htm
-max
--
Playing Nice on Usenet:
http://oakroadsystems.com/genl/unice.htm#xpost
My Pages: http://home.neo.rr.com/manna4u/
http://home.neo.rr.com/manna4u/keepingclean.html
http://home.neo.rr.com/manna4u/virusprevention.html
http://home.neo.rr.com/manna4u/tools.html
Change nomail.afraid.org to yahoo.com to reply.
Registered Linux User #393236

Posted by David H. Lipman on September 19, 2005, 10:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


| Hey David-seems that Bagle.ck is the one that virusguy was talking
| about the other day(price.zip)
| http://vil.mcafeesecurity.com/vil/content/v_136039.htm
| -max

Why did I miss that ? Oh well, Go figure....

Thanx Max !

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
McAfee DAT v4664 dat files have been released early due to new variants of Exploit-WMF January 1, 2006, 10:34 am
Is this a false positive or bug with IE 6, McAfee 8/9/10 or both IE 6 and McAfee? June 26, 2006, 6:57 am
New Sun Java Released April 11, 2007, 5:07 pm
Re: Internet Explorer 7 Released December 19, 2006, 5:56 pm
RE: Internet Explorer 7 Released December 19, 2006, 11:29 pm
Microsoft released the WMF patch today. January 5, 2006, 5:38 pm
Java Runtime Environment (JRE) 5.0 Update 10 Released December 8, 2006, 6:21 pm
Microsoft released update for Windows Defender in Vista April 10, 2007, 2:14 pm
Flash Player security update is available; Security Bulletins released by Adobe July 10, 2007, 7:29 pm
mcafee August 5, 2007, 11:56 am

The site map in XML format XML site map

Contact Us | Privacy Policy