Threat Search: 

ThreatExpert's Statistics for Mal/Behav-105 [Sophos]:

Mal/Behav-105 [Sophos] is also known as:
Threat AliasNumber of Incidents
AdClicker-GB [McAfee]50
TROJ_CLICKER.BNF [Trend Micro]24
W32.Hitapop [Symantec]24
Trojan-Clicker.Win32.Small.aal [Kaspersky Lab]16
Trojan Horse [Symantec]15
Trojan-Clicker.Win32.Small.ww [Kaspersky Lab]12
Trojan-Downloader.Win32.Small [Ikarus]11
Downloader [Symantec]10
Trojan-Clicker.Small!sd6 [PC Tools]8
Generic MultiDropper.f [McAfee]4
Generic.dx [McAfee]4
TROJ_CLICKER.ADN [Trend Micro]4
Trojan-Clicker.Win32.Small.ug [Kaspersky Lab]4
Win-Trojan/Xema.variant [AhnLab]4
Generic Downloader.x [McAfee]3
Trojan.Crypt [Ikarus]3
Trojan.Dropper [Symantec]3
TrojanDownloader:Win32/Troxen!rts [Microsoft]3
Trojan-Dropper.Win32.Agent.awb [Kaspersky Lab]3
Win-Trojan/Downloader.66277 [AhnLab]3
Rootkit.Win32.Agent.gkf [Kaspersky Lab]2
TROJ_ZEROML.JX [Trend Micro]2
Trojan.Generic [Ikarus]2
Trojan-Downloader.Win32.Small.dts [Kaspersky Lab]2
Win32.SuspectCrc [Ikarus]2
Adware.BetterInternet [Symantec]1
Adware.MSView [Symantec]1
Backdoor.Agent [PC Tools]1
Backdoor.Trojan [Symantec]1
BackDoor-CEP.gen.aq [McAfee]1
Generic Downloader.u [McAfee]1
Generic Dropper [McAfee]1
Generic.dh [McAfee]1
Generic.dn [McAfee]1
Hacktool.Patch&Keygen [Ikarus]1
HackTool:Win32/Vidc [Microsoft]1
New Win32.g2 [McAfee]1
not-a-virus.Patch.QuickBooks [Ikarus]1
not-a-virus:AdWare.Win32.Sahat.g [Ikarus]1
not-a-virus:AdWare.Win32.Sahat.g [Kaspersky Lab]1
not-a-virus:Server-Proxy.Win32.RCService.j [Kaspersky Lab]1
P2P-Worm.Win32.VB.DF [Ikarus]1
Rootkit.Win32.Agent [Ikarus]1
Rootkit.Win32.Agent.goc [Kaspersky Lab]1
Trackware.SAHAgent [Symantec]1
TROJ_SMALL.GV [Trend Micro]1
Trojan.DL.Agent.BJIJ [PC Tools]1
Trojan.PWS.Agent.BOQJ [PC Tools]1
Trojan.Win32.VB.uyk [Kaspersky Lab]1
Trojan:Win32/Agent [Microsoft]1
Trojan-Downloader.Win32.Banload [Ikarus]1
Trojan-Downloader.Win32.Banload.prc [Kaspersky Lab]1
Trojan-Downloader.Win32.VB [Ikarus]1
Trojan-Downloader.Win32.VB.hfx [Kaspersky Lab]1
TrojanDownloader:Win32/Small [Microsoft]1
Trojan-Dropper.Agent!sd5 [PC Tools]1
Trojan-Dropper.Agent.AWB [PC Tools]1
Trojan-Dropper.Win32.Agent.bdo [Kaspersky Lab]1
Trojan-Dropper.Win32.Agent.of [Kaspersky Lab]1
Trojan-Dropper.Win32.Agent.og [Kaspersky Lab]1
Trojan-Dropper.Win32.Small.abd [Kaspersky Lab]1
TrojanDropper:Win32/Agent [Microsoft]1
TrojanDropper:Win32/Multi.A [Microsoft]1
Trojan-PSW.Win32.VB.gi [Kaspersky Lab]1
Trojan-PWS.VB.Gen.1 [Ikarus]1
Trojan-PWS.Win32.VB [Ikarus]1
Trojan-Spy.Win32.Yazoka.a [Kaspersky Lab]1
VirTool.Win32.Vbinder [Ikarus]1
Virus.Win32.Rootkit [Ikarus]1
Win-Trojan/LdPinch.131072.E [AhnLab]1

Mal/Behav-105 [Sophos] has the following possible countries of origin:
OriginNumber of Incidents
China11
Russian Federation3
Spain3
France1
Iran1
Poland1
Saudi Arabia1

Mal/Behav-105 [Sophos] is known to be created as:
%System%\cinmon.exe
%System%\msonline.exe
%System%\regsvr.exe
%System%\sovlost.exe
%System%\system\.setupq\avps.exe
%Temp%\19.exe
%Temp%\5.exe
%Temp%\activator\xp32.exe
%Temp%\antiprorat.exe
%Temp%\rarsfx0\antiprorat.exe
%Temp%\windows200_3\5012kala.exe
%UserProfile%\vetrac.exe
%Windir%\crack.exe
%Windir%\svch0st.exe
%Windir%\system\msiexec.exe
%Windir%\system\vetrac.exe
%Windir%\winampa.exe
%Windir%\windowslogs.exe
c:\dwnsetup\1037live.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.