| Threat Alias | Number of Incidents |
| Infostealer [Symantec] | 78 |
| Generic PWS.y [McAfee] | 72 |
| HackTool.Win32.Patcher.A [Ikarus] | 64 |
| HideWindow [McAfee] | 63 |
| not-a-virus:RiskTool.Win32.HideWindows [Kaspersky Lab] | 63 |
| Backdoor.Win32.Agent.afub [Kaspersky Lab] | 60 |
| Mal/Generic-A [Sophos] | 43 |
| Hacktool.HideWindow [Symantec] | 42 |
| HackTool.HideWindows [PC Tools] | 35 |
| Hacktool.HideWindows [PC Tools] | 28 |
| Downloader-BPA [McAfee] | 24 |
| Trojan-Clicker.Win32.Cycler.nop [Kaspersky Lab] | 24 |
| TrojanDownloader:Win32/Unruy.C [Microsoft] | 24 |
| Trojan Horse [Symantec] | 17 |
| Tool:Win32/HideWindows [Microsoft] | 14 |
| Backdoor.Agent!sd6 [PC Tools] | 12 |
| Trojan:Win32/Bumat!rts [Microsoft] | 12 |
| Trojan-Downloader.Win32.Agent.cwya [Kaspersky Lab] | 9 |
| Infostealer.Lineage [Symantec] | 8 |
| Trojan.Dropper [Symantec] | 8 |
| Trojan.PWS.QQPass [Symantec] | 8 |
| Trojan-Clicker.Cycler.nop [PC Tools] | 8 |
| Generic StartPage [McAfee] | 7 |
| Trojan-PSW.Nilage!sd5 [PC Tools] | 7 |
| PWS-Lineage [McAfee] | 6 |
| W32.Spybot.Worm [Symantec] | 6 |
| Generic.dx [McAfee] | 5 |
| StartPage-KG [McAfee] | 5 |
| TROJ_STARTPA.OQ [Trend Micro] | 5 |
| Trojan.DR.IRCBot.Gen.2 [PC Tools] | 5 |
| Generic Downloader.x [McAfee] | 4 |
| Trojan.PWS!sd6 [PC Tools] | 4 |
| Trojan.StartPage [Symantec] | 4 |
| Trojan-PSW.Agent!sd5 [PC Tools] | 4 |
| Trojan-PSW.Win32.Agent.aq [Kaspersky Lab] | 4 |
| Downloader [Symantec] | 3 |
| Generic Downloader.x!cdw [McAfee] | 3 |
| Infostealer.Refest [Symantec] | 3 |
| Mal/VB-G [Sophos] | 3 |
| Trojan-Dropper.Agent [Ikarus] | 3 |
| Virus.Win32.Sality.aa [Kaspersky Lab] | 3 |
| Virus:Win32/Sality.AM [Microsoft] | 3 |
| W32.Antiman.F@mm [Symantec] | 3 |
| W32.IRCBot [Symantec] | 3 |
| W32.Sality.AE [Symantec] | 3 |
| W32/Sality.aq [McAfee] | 3 |
| W32/Sality-AM [Sophos] | 3 |
| W32/Sdbot.worm [McAfee] | 3 |
| Adware.Purityscan [Symantec] | 2 |
| Backdoor.Agent [PC Tools] | 2 |
| Backdoor.IRC.Bot [Symantec] | 2 |
| Backdoor.Poison [Ikarus] | 2 |
| Backdoor.Trojan [Symantec] | 2 |
| Backdoor.Win32.IRCBot.aus [Kaspersky Lab] | 2 |
| Backdoor.Win32.Poison [Ikarus] | 2 |
| Backdoor.Win32.Poison.riy [Kaspersky Lab] | 2 |
| BackDoor-CEP [McAfee] | 2 |
| Downloader.gen.a [McAfee] | 2 |
| Email-Worm.Win32.Brontok.N [Ikarus] | 2 |
| Generic Dropper.ax [McAfee] | 2 |
| Hacktool [Symantec] | 2 |
| Mal/FakeAV-AA [Sophos] | 2 |
| not-a-Virus.Hacktool.Patch.winrarsetup [Ikarus] | 2 |
| not-a-virus:FraudTool.Win32.AntivirusPlus.fg [Kaspersky Lab] | 2 |
| Rootkit.Win32.Agent.X [Ikarus] | 2 |
| Rootkit.Win32.Agent.x [Kaspersky Lab] | 2 |
| Troj/Poison-VB [Sophos] | 2 |
| Troj/RKFu-B [Sophos] | 2 |
| Trojan.Crypt [Ikarus] | 2 |
| Trojan-Downloader.Win32.Agent.kwg [Kaspersky Lab] | 2 |
| Trojan-PSW.Win32.Nilage.abk [Kaspersky Lab] | 2 |
| Trojan-PSW.Win32.Nilage.afr [Kaspersky Lab] | 2 |
| Trojan-PSW.Win32.Prostor.a [Kaspersky Lab] | 2 |
| Trojan-PWS.Lineage [PC Tools] | 2 |
| TSPY_FOLIN.GEN [Trend Micro] | 2 |
| VirTool:Win32/Agent.X [Microsoft] | 2 |
| Win-Trojan/Siggen.372884 [AhnLab] | 2 |
| Win-Trojan/Xema.variant [AhnLab] | 2 |
| Backdoor.Bifrose [Symantec] | 1 |
| Backdoor.Dvldr [Symantec] | 1 |
| Backdoor.IRCBot.XFY [PC Tools] | 1 |
| Backdoor.IRCBot.YED [PC Tools] | 1 |
| Backdoor.Tsunami [PC Tools] | 1 |
| Backdoor.Win32.Assasin.20.p [Kaspersky Lab] | 1 |
| Backdoor.Win32.IRCBot.axr [Kaspersky Lab] | 1 |
| Backdoor.Win32.Rbot.gen [Kaspersky Lab] | 1 |
| Backdoor.Win32.Tsunami [Ikarus] | 1 |
| Backdoor.Win32.Tsunami.c [Kaspersky Lab] | 1 |
| Backdoor:Win32/Coolvidoor.D [Microsoft] | 1 |
| Backdoor:Win32/Pitchfork.A [Microsoft] | 1 |
| Backdoor:Win32/Rbot.gen [Microsoft] | 1 |
| BackDoor-AGS.gen [McAfee] | 1 |
| BKDR_AGENT.MFP [Trend Micro] | 1 |
| BKDR_CHANGEMEM.F [Trend Micro] | 1 |
| BKDR_CHANGEMEM.Q [Trend Micro] | 1 |
| BKDR_IRCBOT.AXI [Trend Micro] | 1 |
| BKDR_IRCBOT.AZB [Trend Micro] | 1 |
| BKDR_IRCBOT.AZF [Trend Micro] | 1 |
| BKDR_IRCBOT.BCY [Trend Micro] | 1 |
| BKDR_IRCBOT.ZP [Trend Micro] | 1 |