Threat Search: 

ThreatExpert's Statistics for Mal/Behav-112 [Sophos]:

Mal/Behav-112 [Sophos] is also known as:
Threat AliasNumber of Incidents
Win-Trojan/Xema.variant [AhnLab]104
Trojan-Dropper.Win32.Agent.awwv [Kaspersky Lab]96
Generic Dropper!gd [McAfee]88
W32.Fujacks.CB [Symantec]88
Infostealer.Gampass [Symantec]74
Trojan-Downloader [Ikarus]73
Trojan-PSW.Gampass [PC Tools]72
Trojan-Downloader.Agent.NZW [PC Tools]64
Trojan.ATRAPS [Ikarus]42
Mal/Generic-A [Sophos]32
Trojan.Dropper [Symantec]31
BehavesLike [Ikarus]30
Trojan-GameThief.Win32.WOW [Ikarus]28
Trojan-GameThief.Win32.OnLineGames.bnbw [Kaspersky Lab]24
Trojan Horse [Symantec]20
Generic Dropper.kb [McAfee]19
Trojan.Dropper [PC Tools]18
Downloader [Symantec]12
Generic.dx [McAfee]12
Trojan-GameThief.Win32.WOW.uuh [Kaspersky Lab]12
Win-Trojan/Malware.21016 [AhnLab]12
TrojanDropper:Win32/OnLineGames.FK [Microsoft]11
Backdoor.Prorat [Symantec]10
Backdoor.Win32.Prorat.jz [Kaspersky Lab]9
Backdoor:Win32/Prorat.AZ [Microsoft]9
Trojan-Dropper.Agent [Ikarus]9
Trojan-Dropper.Win32.Rooter.e [Kaspersky Lab]9
Backdoor.Prorat.AX [PC Tools]8
Mal/Generic-A, Mal/Behav-112 [Sophos]8
New Malware.aj [McAfee]8
Trojan-Dropper.Win32.Rooter [Ikarus]8
Hoax.Win32.Renos [Ikarus]7
Hoax.Win32.Renos.vavf [Kaspersky Lab]7
Trojan.Virantix.C [Symantec]7
Trojan-Dropper.Win32.Agent.blbg [Kaspersky Lab]7
Generic Dropper [McAfee]6
PWS.Win32 [Ikarus]6
PWS:Win32/Wowsteal.AP [Microsoft]6
TROJ_ROOTER.B [Trend Micro]6
Trojan-GameThief.Win32.OnLineGames.bnem [Kaspersky Lab]6
Win-Trojan/Prorat.358275 [AhnLab]6
Backdoor.Trojan [Symantec]5
Dropper/Agent.15360.I [AhnLab]5
MultiDropper-NF [McAfee]5
Rootkit.Win32.Agent [Ikarus]5
Troj/Agent-LVF [Sophos]5
Trojan-Downloader.Agent.cuau [PC Tools]5
Trojan-Downloader.Win32.Agent.cuau [Kaspersky Lab]5
Trojan-Dropper.Win32.Agent.zje [Kaspersky Lab]5
Trojan-GameThief.Win32.OnLineGames.vxfm [Kaspersky Lab]5
Trojan-Spy.Win32.Banker [Ikarus]5
Win-Trojan/Malware.35852 [AhnLab]5
Backdoor.Sdbot.dr [Symantec]4
Downloader.MisleadApp [Symantec]4
Downloader-BIS [McAfee]4
Generic PUP.x [McAfee]4
Hacktool [Symantec]4
Infostealer [Symantec]4
MultiDropper-NM [McAfee]4
not-a-virus:NetTool.Win32.ZXProxy.h [Kaspersky Lab]4
PWS-OnlineGames.ei [McAfee]4
Rootkit.Win32.Agent.fxi [Kaspersky Lab]4
Trojan.Win32.Agent [Ikarus]4
Trojan.Win32.Agent2 [Ikarus]4
Trojan.Win32.StartPage [Ikarus]4
Trojan-GameThief.Win32.WOW.ilp [Kaspersky Lab]4
Trojan-GameThief.Win32.WOW.veb [Kaspersky Lab]4
Trojan-PWS.OnlineGames.ADRD [PC Tools]4
TrojanSpy:Win32/Ambler.A [Microsoft]4
TSPY_BANKER.LJU [Trend Micro]4
Win32.SuspectCrc [Ikarus]4
Win-Trojan/Malware.21016.B [AhnLab]4
Backdoor:WinNT/Festi.A [Microsoft]3
Generic PWS.y [McAfee]3
Infostealer.Bancos [Symantec]3
PWS-Banker [McAfee]3
PWS-Mmorpg!le [McAfee]3
PWS-WOW.gen.j [McAfee]3
TROJ_STARTPG.C [Trend Micro]3
Trojan.Generic [PC Tools]3
Trojan.Startpage [Symantec]3
Trojan.Win32.KillAV [Ikarus]3
Trojan:Win32/Meredrop [Microsoft]3
Trojan-Downloader.Win32.Agent.jz [Kaspersky Lab]3
Trojan-Downloader.Win32.Small [Ikarus]3
TrojanDownloader:Win32/Bakted.A [Microsoft]3
Trojan-Dropper [Ikarus]3
Trojan-Dropper.Agent!sd6 [PC Tools]3
Trojan-Dropper.Win32.VB.FI [Ikarus]3
Trojan-GameThief.Win32.OnLineGames [Ikarus]3
Trojan-GameThief.Win32.OnLineGames.skmj [Kaspersky Lab]3
Trojan-Spy.Banker!sd5 [PC Tools]3
Virus.Neshta [PC Tools]3
Virus.Win32.Delf.DQP [Ikarus]3
Backdoor:Win32/Agent [Microsoft]2
BackDoor-DKI.dldr [McAfee]2
Dropper/Rooter.34304 [AhnLab]2
New Malware.x [McAfee]2
PWS:Win32/Yahoopass.H [Microsoft]2
PWS-Banker.gen.e [McAfee]2

Mal/Behav-112 [Sophos] has the following possible countries of origin:
OriginNumber of Incidents
China214
Russian Federation12
Turkey4
Israel2
Estonia1

Mal/Behav-112 [Sophos] is known to be created as:
%ProgramFiles%\smss\smss.exe
%System%\090514-a-9.exe
%System%\explorer.exe
%System%\mdb1.exe
%System%\update.exe
%System%\windowsupdate.exe
%Temp%\090610-6-9.exe
%Temp%\090614-a-28.exe
%Temp%\10317116.exe
%Temp%\1081256.exe
%Temp%\24600012.exe
%Temp%\24920314.exe
%Temp%\27373445.exe
%Temp%\34776555.exe
%Temp%\35504643.exe
%Temp%\guatian.exe
%Temp%\kafan virlist 2009.03.08\090308-8-7.exe
%Temp%\kafan virlist 20090713\090713-a-13.exe
%Temp%\smart04.exe
%Temp%\smart05.exe
%Temp%\tddownload\url.exe
%Temp%\tddownload\url_sexbox.exe
%Temp%\tem81.exe
%Temp%\to8_2222.exe
%Windir%\myserver.exe
%Windir%\temp\25210940.exe
%Windir%\temp\25321841.exe
%Windir%\temp\27531247.exe
%Windir%\temp\29512541.exe
%Windir%\temp\29848458.exe
%Windir%\temp\32260948.exe
%Windir%\temp\32589011.exe
c:\shb.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.