| Threat Alias | Number of Incidents |
| TrojanSpy:Win32/Zbot.gen!C [Microsoft] | 130 |
| PWS-Zbot.gen.c [McAfee] | 111 |
| Packed.Generic.196 [Symantec] | 89 |
| Infostealer.Banker.C [Symantec] | 87 |
| Virus.Win32.VB.FEW [Ikarus] | 84 |
| Mal/VB-Z, Mal/Behav-211 [Sophos] | 69 |
| Virus.Win32.Dropper.BEJ [Ikarus] | 54 |
| Mal/EncPk-CZ [Sophos] | 45 |
| Mal/EncPk-GS, Mal/TibsPk-D [Sophos] | 43 |
| Win32/IRCBot.worm.variant [AhnLab] | 36 |
| Trojan:Win32/Zbot.BW [Microsoft] | 35 |
| Trojan Horse [Symantec] | 29 |
| Trojan.Win32.Zbot [Ikarus] | 25 |
| Trojan-Spy.Win32.Zbot.roh [Kaspersky Lab] | 24 |
| Mal/Zbot-H [Sophos] | 23 |
| Infostealer [Symantec] | 21 |
| Trojan:Win32/Zbot.BY [Microsoft] | 18 |
| Mal/EncPk-GS [Sophos] | 17 |
| Spy-Agent.bw [McAfee] | 14 |
| Mal/TibsPk-D [Sophos] | 12 |
| PWS:Win32/Zbot.GA [Microsoft] | 12 |
| Infostealer.Bancos [Symantec] | 11 |
| Mal/VB-Z, Mal/Behav-211, Mal/Behav-009 [Sophos] | 11 |
| Mal/Zbot-I [Sophos] | 11 |
| Suspicious.MH690 [Symantec] | 10 |
| Mal/EncPk-FW [Sophos] | 9 |
| Mal/EncPk-HJ [Sophos] | 9 |
| Trojan.Banker.LER [Ikarus] | 9 |
| Backdoor.Paproxy [Symantec] | 7 |
| Downloader [Symantec] | 7 |
| VirTool:Win32/CeeInject.gen!J [Microsoft] | 7 |
| Mal/EncPk-GS, Mal/EncPk-FW [Sophos] | 6 |
| Mal/Zbot-G, Mal/EncPk-CZ [Sophos] | 6 |
| New Malware.ix [McAfee] | 6 |
| PWS:Win32/Zbot.BY [Microsoft] | 6 |
| PWS:Win32/Zbot.gen!Q [Microsoft] | 6 |
| PWS:Win32/Zbot.VA [Microsoft] | 6 |
| Troj/FakeAle-LE [Sophos] | 6 |
| Trojan-Dropper.Delf [Ikarus] | 6 |
| Downloader.MisleadApp [Symantec] | 5 |
| Mal/FakeVirPk-A [Sophos] | 5 |
| Spy-Agent.dp.gen [McAfee] | 5 |
| Trojan.Dropper [Symantec] | 5 |
| Win32.Outbreak [Ikarus] | 5 |
| Mal/EncPk-FS [Sophos] | 4 |
| Mal/EncPk-HJ, Mal/EncPk-HJ [Sophos] | 4 |
| Mal/EncPk-HZ [Sophos] | 4 |
| Mal/Zbot-H, Mal/EncPk-CZ [Sophos] | 4 |
| Trojan-Spy.Win32.Zbot.gar [Kaspersky Lab] | 4 |
| Trojan-Spy.Win32.Zbot.gen [Kaspersky Lab] | 4 |
| Trojan-Spy.Win32.Zbot.gxn [Kaspersky Lab] | 4 |
| VirTool.Win32.CeeInject [Ikarus] | 4 |
| Generic Dropper.cc [McAfee] | 3 |
| Mal/EncPk-IF [Sophos] | 3 |
| PWS:Win32/Zbot.C [Microsoft] | 3 |
| PWS:Win32/Zbot.FAK [Microsoft] | 3 |
| PWS:Win32/Zbot.VM [Microsoft] | 3 |
| Troj/Agent-ILE [Sophos] | 3 |
| Troj/Agent-JCY [Sophos] | 3 |
| Troj/Musor-Gen [Sophos] | 3 |
| Trojan.Win32.Buzus.angb [Kaspersky Lab] | 3 |
| Trojan.Win32.VB.ktq [Kaspersky Lab] | 3 |
| Trojan-PSW.Banker [PC Tools] | 3 |
| Trojan-Spy.Win32.Zbot.hkp [Kaspersky Lab] | 3 |
| VirTool:Win32/DelfInject.gen!AC [Microsoft] | 3 |
| VirTool:Win32/VBInject.C [Microsoft] | 3 |
| Virus.Win32.Enteos [Ikarus] | 3 |
| Virus.Win32.Zbot.APE [Ikarus] | 3 |
| Win-Trojan/Xema.variant [AhnLab] | 3 |
| Win-Trojan/Zbot.88064 [AhnLab] | 3 |
| Worm.Win32.Pinit.gen [Kaspersky Lab] | 3 |
| Backdoor.Bifrose [Symantec] | 2 |
| Backdoor.Trojan [Symantec] | 2 |
| Backdoor.Win32.IRCBot.grs [Kaspersky Lab] | 2 |
| BackDoor-DVL [McAfee] | 2 |
| Generic Dropper.bw [McAfee] | 2 |
| Generic Dropper.kj [McAfee] | 2 |
| Generic PWS.cq [McAfee] | 2 |
| Mal/Dropper-T [Sophos] | 2 |
| Mal/EncPk-FZ, Mal/EncPk-CZ [Sophos] | 2 |
| Mal/EncPk-HZ, Mal/Zbot-J [Sophos] | 2 |
| Mal/EncPk-JI [Sophos] | 2 |
| PWS:Win32/Zbot.NW [Microsoft] | 2 |
| PWS:Win32/Zbot.VL [Microsoft] | 2 |
| PWS-Zbot [McAfee] | 2 |
| Troj/VB-EBX [Sophos] | 2 |
| Trojan.Delf.Inject [Ikarus] | 2 |
| Trojan.Dropper [PC Tools] | 2 |
| Trojan.Win32.Obfuscater [Ikarus] | 2 |
| Trojan.Win32.Pakes.lge [Kaspersky Lab] | 2 |
| Trojan.Win32.VB.nmr [Kaspersky Lab] | 2 |
| Trojan:Win32/Zbot.BT [Microsoft] | 2 |
| Trojan-Dropper.Win32.Pincher.tl [Kaspersky Lab] | 2 |
| Trojan-Spy.Win32.Zbot.ffd [Kaspersky Lab] | 2 |
| Trojan-Spy.Win32.Zbot.fnv [Kaspersky Lab] | 2 |
| Trojan-Spy.Win32.Zbot.gal [Kaspersky Lab] | 2 |
| Trojan-Spy.Win32.Zbot.gaq [Kaspersky Lab] | 2 |
| Trojan-Spy.Win32.Zbot.gga [Kaspersky Lab] | 2 |
| Trojan-Spy.Win32.Zbot.ghq [Kaspersky Lab] | 2 |
| Trojan-Spy.Win32.Zbot.giv [Kaspersky Lab] | 2 |