| Threat Alias | Number of Incidents |
| Trojan.Crypt [Ikarus] | 363 |
| Trojan Horse [Symantec] | 353 |
| Win-Trojan/Xema.variant [AhnLab] | 275 |
| Mal/EncPk-IV [Sophos] | 261 |
| Trojan.Crypt.GEN [PC Tools] | 165 |
| Trojan-Downloader.Win32.Agent.ckkp [Kaspersky Lab] | 99 |
| Mal/Generic-A [Sophos] | 47 |
| Trojan:Win32/Ertfor.A [Microsoft] | 33 |
| Trojan:Win32/Ertfor.B [Microsoft] | 22 |
| Trojan.FakeAlert [PC Tools] | 11 |
| Packed.Generic.233 [Symantec] | 10 |
| Mal/EncPk-IF [Sophos] | 4 |
| PWS:Win32/Zbot.J [Microsoft] | 4 |
| Trojan-Downloader.Win32.FakeRean [Ikarus] | 3 |
| Packed.Win32.Krap.t [Kaspersky Lab] | 2 |
| Trojan.Win32.FraudPack.pjv [Kaspersky Lab] | 2 |
| Trojan-Clicker.Win32.Hatigh [Ikarus] | 2 |
| TrojanDownloader:Win32/FakeRean.gen!C [Microsoft] | 2 |
| Trojan-Spy.Win32.Zbot [Ikarus] | 2 |
| Trojan-Spy.Win32.Zbot.zom [Kaspersky Lab] | 2 |
| Trojan-Spy.Win32.Zbot.zpx [Kaspersky Lab] | 2 |
| Trojan-Spy.Win32.Zbot.zup [Kaspersky Lab] | 2 |
| Win-Trojan/Krap.23553.N [AhnLab] | 2 |
| Backdoor:Win32/Hostil.F [Microsoft] | 1 |
| Downloader [Symantec] | 1 |
| Downloader.MisleadApp [Symantec] | 1 |
| Dropper/Microjoin.1835008.B [AhnLab] | 1 |
| not-a-virus:FraudTool.Win32.Agent.tm [Kaspersky Lab] | 1 |
| Troj/FakeAV-VR [Sophos] | 1 |
| Trojan.Virantix [Symantec] | 1 |
| Trojan.Win32.Inject.agco [Kaspersky Lab] | 1 |
| Trojan.Win32.Small [Ikarus] | 1 |
| Trojan:Win32/FakeRean [Microsoft] | 1 |
| Trojan-Downloader.Win32.FraudLoad [Ikarus] | 1 |
| Trojan-Downloader.Win32.FraudLoad.wfyq [Kaspersky Lab] | 1 |
| Trojan-Dropper.Win32.Microjoin [Ikarus] | 1 |
| Trojan-Dropper.Win32.Microjoin.gwo [Kaspersky Lab] | 1 |
| VirTool.Win32.Injector [Ikarus] | 1 |
| Win-Trojan/Fraudload.43008.K [AhnLab] | 1 |
| Win-Trojan/Inject.12288.DM [AhnLab] | 1 |