| Threat Alias | Number of Incidents |
| W32.Mandaph [Symantec] | 94 |
| Downloader.gen.a [McAfee] | 61 |
| Virus.Win32.AutoRun.aiu [Ikarus] | 50 |
| Troj/DwnLdc-Gen, Troj/Scrub-Gen [Sophos] | 46 |
| Worm.Win32.Socks.ex [Kaspersky Lab] | 44 |
| Downloader [Symantec] | 41 |
| Worm.Socks.O [PC Tools] | 41 |
| Generic.dx [McAfee] | 39 |
| Trojan Horse [Symantec] | 39 |
| WORM_SOCKS.BL [Trend Micro] | 31 |
| Mal/Heuri-D, Mal/Koceg-A [Sophos] | 30 |
| Trojan-Downloader.Win32.Agent.lab [Kaspersky Lab] | 30 |
| Trojan-Downloader.Small [Ikarus] | 26 |
| Backdoor.Koceg.E [PC Tools] | 25 |
| Mal/EncPk-DB [Sophos] | 20 |
| Trojan.Sockrypt.Gen [PC Tools] | 16 |
| BackDoor-DOQ [McAfee] | 14 |
| Worm.Socks.F [PC Tools] | 13 |
| Mal/Koceg-A [Sophos] | 11 |
| Trojan.Dropper [Symantec] | 11 |
| Backdoor.Trojan [Symantec] | 10 |
| WORM_SOCKS.BK [Trend Micro] | 10 |
| WORM_SOCKS.I [Trend Micro] | 10 |
| Downloader-BIM [McAfee] | 9 |
| W32.SillyFDC [Symantec] | 9 |
| TROJ_DLOADE.ADK [Trend Micro] | 8 |
| Trojan-Downloader.Win32.Small [Ikarus] | 8 |
| Trojan-Dropper.Agent [Ikarus] | 8 |
| Worm.Socks.Gen [PC Tools] | 8 |
| Worm.Socks.Gen.3 [PC Tools] | 8 |
| Backdoor:Win32/Koceg.gen!A [Microsoft] | 7 |
| Virus.Win32.Agent.OLI [Ikarus] | 7 |
| BackDoor-DRW [McAfee] | 6 |
| Generic BackDoor [McAfee] | 6 |
| Generic Dropper.av [McAfee] | 6 |
| Mal/Generic-A [Sophos] | 6 |
| Trojan.PWS.Agent.EEPQ [PC Tools] | 6 |
| Trojan-Downloader.Small.AAKR [Ikarus] | 6 |
| Backdoor.Win32.Agent.eks [Kaspersky Lab] | 5 |
| BackDoor-DNR [McAfee] | 5 |
| TROJ_DLOADER.WRI [Trend Micro] | 5 |
| Trojan-Downloader.Win32.Agent.jjt [Kaspersky Lab] | 5 |
| Trojan-PSW.Win32.Agent.ze [Kaspersky Lab] | 5 |
| Virus.Win32.Lineage.351 [Ikarus] | 5 |
| Win-Trojan/Agent.71680.BR [AhnLab] | 5 |
| Worm.Win32.AutoRun.eav [Kaspersky Lab] | 5 |
| Worm.Win32.Socks.fa [Kaspersky Lab] | 5 |
| Worm:Win32/SillyShareCopy.gen [Microsoft] | 5 |
| Backdoor.Graybird [Symantec] | 4 |
| Infostealer [Symantec] | 4 |
| Mal/Behav-238 [Sophos] | 4 |
| Mal/EncPk-AF [Sophos] | 4 |
| Packed/FSG [PC Tools] | 4 |
| Trojan.FakeAlert.EW [PC Tools] | 4 |
| Trojan-Downloader.Small!sd6 [PC Tools] | 4 |
| Trojan-Downloader.Small.uso [Ikarus] | 4 |
| Trojan-Downloader.Small.uuy [Ikarus] | 4 |
| Trojan-Downloader.Win32.Small.uni [Kaspersky Lab] | 4 |
| Trojan-Downloader.Win32.Small.uug [Kaspersky Lab] | 4 |
| W32.HLLW.Gaobot.gen [Symantec] | 4 |
| Worm.Win32.AutoRun [Ikarus] | 4 |
| WORM_SOCKS.BP [Trend Micro] | 4 |
| Backdoor.Win32.Koceg [Ikarus] | 3 |
| Backdoor:Win32/Koceg.gen!B [Microsoft] | 3 |
| Mal/EncPk-EI, Mal/Spyzee-A [Sophos] | 3 |
| Troj/Scrub-Gen [Sophos] | 3 |
| Trojan.Kibik!inf [Symantec] | 3 |
| Trojan-Downloader.Win32.Small.uum [Kaspersky Lab] | 3 |
| TSPY_LDPINCH.BFA [Trend Micro] | 3 |
| VirTool:Win32/Obfuscator.BC [Microsoft] | 3 |
| Worm.Socks.K [PC Tools] | 3 |
| Worm.Win32.Socks.bk [Kaspersky Lab] | 3 |
| Worm:Win32/Autorun.gen!BS [Microsoft] | 3 |
| Backdoor.Agent!sd5 [PC Tools] | 2 |
| Backdoor.Koceg.I [PC Tools] | 2 |
| Backdoor.Win32.Bifrose [Ikarus] | 2 |
| Backdoor.Win32.Bifrose.ceez [Kaspersky Lab] | 2 |
| Backdoor.Win32.Socks.b [Kaspersky Lab] | 2 |
| Backdoor:Win32/Koceg [Microsoft] | 2 |
| BKDR_KOCEG.Y [Trend Micro] | 2 |
| BKDR_SMALL.JAN [Trend Micro] | 2 |
| Generic Downloader.x [McAfee] | 2 |
| Generic PWS.y [McAfee] | 2 |
| Generic Spy.i [McAfee] | 2 |
| Mal/EncPk-FC [Sophos] | 2 |
| Mal/Heuri-D, Troj/Scrub-Gen [Sophos] | 2 |
| Mal/Koceg-A, Mal/Heuri-D [Sophos] | 2 |
| New Malware.bl [McAfee] | 2 |
| Packed.Generic.80 [Symantec] | 2 |
| Suspicious.MH690 [Symantec] | 2 |
| TROJ_AGENT.AHG [Trend Micro] | 2 |
| TROJ_DLOADER.AVV [Trend Micro] | 2 |
| TROJ_DROPPER.EKD [Trend Micro] | 2 |
| Trojan.DL.Agent.ECTH [PC Tools] | 2 |
| Trojan.DL.Small.ADJN [PC Tools] | 2 |
| Trojan.Win32.Scar [Ikarus] | 2 |
| Trojan.Win32.Scar.apon [Kaspersky Lab] | 2 |
| Trojan-Clicker.Win32.Delf.ug [Kaspersky Lab] | 2 |
| Trojan-Downloader.Small.GEN [PC Tools] | 2 |
| Trojan-Downloader.Small.uto [Ikarus] | 2 |