| Threat Alias | Number of Incidents |
| Trojan:Win32/Alureon.gen!J [Microsoft] | 6,196 |
| Trojan.Win32.Agent.akwc [Kaspersky Lab] | 5,256 |
| Trojan Horse [Symantec] | 5,174 |
| Mal/AdvPatch-A, Mal/Broute-A [Sophos] | 5,042 |
| Worm.AutoRun.GEN [PC Tools] | 2,737 |
| Trojan.Win32.Agent [Ikarus] | 2,670 |
| Trojan.Win32.Alureon.J [Ikarus] | 2,570 |
| Trojan:Win32/Alureon.BB [Microsoft] | 1,406 |
| Trojan.Alureon.J [PC Tools] | 1,224 |
| Troj/VcRtHack-A [Sophos] | 830 |
| Trojan.Win32.Alureon [Ikarus] | 785 |
| Backdoor.Tidserv!inf [Symantec] | 753 |
| Backdoor.Tidserv!sd6 [PC Tools] | 534 |
| Mal/Generic-A [Sophos] | 103 |
| Trojan:Win32/Alureon.gen [Microsoft] | 99 |
| Trojan:Win32/Alureon.gen!N [Microsoft] | 67 |
| Rootkit.Win32.Agent.dqy [Kaspersky Lab] | 64 |
| Backdoor.Tidserv [Symantec] | 53 |
| Trojan.TDss.1 [Ikarus] | 36 |
| Trojan.Zlob [Symantec] | 35 |
| Packed.Generic.200 [Symantec] | 32 |
| Trojan:WinNT/Alureon.C [Microsoft] | 32 |
| Mal/EncPk-EQ [Sophos] | 26 |
| Trojan-Downloader.Win32.Renos.AQ [Ikarus] | 26 |
| Mal/EncPk-GB [Sophos] | 25 |
| Mal/TDSS-A [Sophos] | 25 |
| Rootkit.Win32.Agent [Ikarus] | 25 |
| Rootkit.Win32.TDSS [Ikarus] | 25 |
| Trojan.Win32.Patched [Ikarus] | 25 |
| Trojan.Win32.Patched.fl [Kaspersky Lab] | 25 |
| Trojan:Win32/Alureon.BI [Microsoft] | 25 |
| Win-Trojan/Dnschanger.4278 [AhnLab] | 24 |
| Win-Trojan/Xema.variant [AhnLab] | 24 |
| Troj/MsvcrtHk-C [Sophos] | 23 |
| Backdoor.Win32.UltimateDefender.gen [Kaspersky Lab] | 21 |
| Trojan.TDSServ [PC Tools] | 20 |
| Trojan.Vundo [Symantec] | 20 |
| Trojan-Downloader.Win32.Small.aczp [Kaspersky Lab] | 20 |
| Mal/EncPk-CZ [Sophos] | 19 |
| Trojan.Fakeavalert [Symantec] | 17 |
| Backdoor.Trojan [Symantec] | 16 |
| Mal/Generic-A, Mal/TDSSPack-B [Sophos] | 16 |
| Packed.Generic.188 [Symantec] | 15 |
| PE_PATCHED.HT [Trend Micro] | 15 |
| Trojan.Patched!sd6 [PC Tools] | 15 |
| Mal/TDSS-A, Mal/EncPk-CZ [Sophos] | 14 |
| Trojan.Flush.A [Symantec] | 13 |
| Trojan-Downloader.Small!sd6 [PC Tools] | 12 |
| Trojan.Win32.DNSChanger [Ikarus] | 11 |
| Virus.Win32.Fabot [Ikarus] | 10 |
| Trojan.DNSChanger.PW [PC Tools] | 9 |
| Rootkit.Win32.TDSS.eyj [Kaspersky Lab] | 8 |
| Troj/Meredrop-A [Sophos] | 8 |
| Mal/TDSSPack-A [Sophos] | 7 |
| Trojan.WinNT [Ikarus] | 7 |
| Packed.Win32.Tdss.c [Kaspersky Lab] | 6 |
| TROJ_ZLOB.CJG [Trend Micro] | 6 |
| Trojan.Adclicker [Symantec] | 6 |
| Trojan.DNSChanger!sd5 [PC Tools] | 6 |
| Trojan.Flush.L [Symantec] | 6 |
| Trojan.Win32.DNSChanger.io [Kaspersky Lab] | 6 |
| Trojan.Win32.Pakes [Ikarus] | 6 |
| Backdoor:Win32/Refpron.D [Microsoft] | 5 |
| Hoax.Win32.Renos.ebd [Kaspersky Lab] | 5 |
| Mal/Alureon-D [Sophos] | 5 |
| Mal/BadNSIS [Sophos] | 5 |
| Mal/EncPk-GU [Sophos] | 5 |
| Trojan:Win32/Alureon.BJ [Microsoft] | 5 |
| W32.SillyDC [Symantec] | 5 |
| Bloodhound.Packed.7 [Symantec] | 4 |
| Mal/Behav-321, Mal/TDSS-A [Sophos] | 4 |
| Mal/RootKit-Fam [Sophos] | 4 |
| Troj/Rootkit-DP [Sophos] | 4 |
| TROJ_DNSCHANG.BM [Trend Micro] | 4 |
| TROJ_IRCBOT.AUR [Trend Micro] | 4 |
| TROJ_ZLOB.ALQ [Trend Micro] | 4 |
| Trojan.DNSChanger [Ikarus] | 4 |
| Trojan.Win32.DNSChanger.abk [Kaspersky Lab] | 4 |
| Trojan.Win32.DNSChanger.vt [Kaspersky Lab] | 4 |
| Trojan.Win32.Pakes.mzs [Kaspersky Lab] | 4 |
| Trojan.Win32.Tdss [Ikarus] | 4 |
| Trojan.Win32.TDSS.abiu [Kaspersky Lab] | 4 |
| Trojan.Win32.TDSS.tzc [Kaspersky Lab] | 4 |
| Trojan-Downloader.Win32.Small [Ikarus] | 4 |
| W32.SillyIM [Symantec] | 4 |
| W32.Stration@mm [Symantec] | 4 |
| W32.Tidserv [Symantec] | 4 |
| Hacktool.Rootkit [Symantec] | 3 |
| Mal/Behav-196 [Sophos] | 3 |
| Mal/EncPk-CO [Sophos] | 3 |
| Mal/TDSS-B [Sophos] | 3 |
| Troj/AdvHack-A [Sophos] | 3 |
| Troj/FkAvDl-Fam [Sophos] | 3 |
| Trojan.Packed.7 [Symantec] | 3 |
| Trojan.Win32.Agent2 [Ikarus] | 3 |
| Trojan:Win32/Alureon.AS [Microsoft] | 3 |
| Trojan:Win32/Alureon.BL [Microsoft] | 3 |
| Trojan:Win32/Alureon.gen!H [Microsoft] | 3 |
| W32.SillyFDC [Symantec] | 3 |
| Backdoor.Win32.TDSS [Ikarus] | 2 |