Threat Search: 

ThreatExpert's Statistics for Mal/Behav-321 [Sophos]:

Mal/Behav-321 [Sophos] is also known as:
Threat AliasNumber of Incidents
Trojan-Downloader.Win32.Delf [Ikarus]7
PWS:Win32/OnLineGames.BX [Microsoft]4
PWS.Win32 [Ikarus]3
PWS:Win32/OnLineGames.BX.dr [Microsoft]3
Trojan Horse [Symantec]3
Trojan:Win32/Redosdru.E [Microsoft]3
Virus.Win32.Dialer.1313 [Ikarus]3
Backdoor.Win32.PcClient [Ikarus]2
Backdoor.Win32.ZZSlash.bto [Kaspersky Lab]2
Backdoor:Win32/PcClient.gen!G [Microsoft]2
Infostealer.Gampass [Symantec]2
Trojan.Generic [PC Tools]2
Trojan.Win32.Redosdru [Ikarus]2
Trojan:Win32/Tibs.gen!lds [Microsoft]2
Trojan-Downloader.Win32.FraudLoad [Ikarus]2
Trojan-Spy.Win32.Zbot.aaqa [Kaspersky Lab]2
Backdoor.Trojan [Symantec]1
Backdoor.Win32.ZZSlash.xl [Kaspersky Lab]1
Backdoor:Win32/Blackhole.Z [Microsoft]1
BackDoor-EBT [McAfee]1
Downloader [Symantec]1
FakeAlert-CM [McAfee]1
Generic Downloader.x!cdk [McAfee]1
Generic Dropper!cip [McAfee]1
Generic.dx!fcw [McAfee]1
Mal/Redos-B, Mal/Behav-321 [Sophos]1
Packed.Win32.Krap [Ikarus]1
PWS:Win32/Lineage.gen!A [Microsoft]1
PWS:Win32/Zbot.PG [Microsoft]1
Trojan.Fakeavalert [Symantec]1
Trojan.Win32.Agent [Ikarus]1
Trojan.Win32.Agent.cvff [Kaspersky Lab]1
Trojan.Win32.Bredolab [Ikarus]1
Trojan.Win32.Vilsel [Ikarus]1
Trojan.Win32.Vilsel.plq [Kaspersky Lab]1
Trojan:Win32/Bumat!rts [Microsoft]1
Trojan:Win32/Insebro.C [Microsoft]1
Trojan:Win32/Meredrop [Microsoft]1
Trojan-Downloader.Win32.FraudLoad.fkt [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.wbru [Kaspersky Lab]1
TrojanDownloader:Win32/Ufraie.A [Microsoft]1
TrojanDownloader:Win32/Waledac.C [Microsoft]1
Trojan-Dropper.Delf [Ikarus]1
Trojan-Dropper.Win32.Agent.blcx [Kaspersky Lab]1
Trojan-Dropper.Win32.Dogkild [Ikarus]1
TrojanDropper:Win32/Dogkild.A [Microsoft]1
Trojan-GameThief.Win32.OnLineGames [Ikarus]1
Trojan-GameThief.Win32.OnLineGames.vhay [Kaspersky Lab]1
Trojan-GameThief.Win32.OnLineGames.vkmn [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot [Ikarus]1
Trojan-Spy.Win32.Zbot.zcd [Kaspersky Lab]1
Win-Trojan/Agent.94208.NQ [AhnLab]1
Win-Trojan/Fraudload.29184.I [AhnLab]1
Win-Trojan/Malware.25600.L [AhnLab]1
Win-Trojan/OnlineGameHack.135680.AC [AhnLab]1
Win-Trojan/PcClient.72192.I [AhnLab]1
Win-Trojan/Xema.variant [AhnLab]1

Mal/Behav-321 [Sophos] has the following possible countries of origin:
OriginNumber of Incidents
China9
Russian Federation5
Ukraine1

Mal/Behav-321 [Sophos] is known to be created as:
%System%\19f87.dll
%System%\1a052.dll
%System%\1a1e8.dll
%System%\1ba71.dll
%System%\1f4ea.dll
%System%\emmsg32.dll
%System%\nwcworkstation.dll
%System%\ro.dll
%System%\sdra64.exe
%Temp%\iehostcx32.dll
%Windir%\help\eb6c4499b05f.dll
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.