Threat Search: 

ThreatExpert's Statistics for Mal/Behav-117 [Sophos]:

Mal/Behav-117 [Sophos] is also known as:
Threat AliasNumber of Incidents
not-a-virus.Risktool.RemoveWGA [Ikarus]8
Application.RemoveWGA [PC Tools]6
Infostealer.Gampass [Symantec]3
Generic.fs [McAfee]1
New Malware.aj [McAfee]1
not-a-virus.Hacktool.RemoveWGA [Ikarus]1
Trojan.Popuper [PC Tools]1
Trojan-GameThief.Win32.OnLineGames.dnr [Kaspersky Lab]1
Trojan-PSW.Win32.OnLineGames.gwt [Kaspersky Lab]1
Trojan-Spy.Gampass!sd6 [PC Tools]1
Win-Trojan/Gampass.12800 [AhnLab]1

Mal/Behav-117 [Sophos] has the following possible country of origin:
OriginNumber of Incidents
China2

Mal/Behav-117 [Sophos] is known to be created as:
%System%\lyloader.exe
%System%\lyloadmr.exe
%System%\pirated.fixed - new\removewga.exe
%Temp%\removewga.exe
%Windir%\msg.exe
c:\readmsg.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.