| Threat Alias | Number of Incidents |
| Mal/EncPk-CZ [Sophos] | 110 |
| TrojanDownloader:Win32/Renos.gen!AQ [Microsoft] | 85 |
| Virus.Win32.Fasec [Ikarus] | 82 |
| Packed.Generic.200 [Symantec] | 77 |
| TROJ_FAKEAV.MQ [Trend Micro] | 75 |
| Trojan.Blusod [Symantec] | 70 |
| DNSChanger.r [McAfee] | 56 |
| Trojan.Blusod!sd6 [PC Tools] | 50 |
| Trojan.Fakealert.AFB [Ikarus] | 50 |
| Joke-Bluescreen.c [McAfee] | 45 |
| Generic Downloader.x [McAfee] | 31 |
| Win-Trojan/Xema.variant [AhnLab] | 28 |
| Mal/EncPk-GR, Mal/EncPk-GR [Sophos] | 24 |
| Trojan:Win32/Alureon.gen!J [Microsoft] | 23 |
| Trojan:Win32/Vundo.JC.dll [Microsoft] | 20 |
| VirTool:Win32/CeeInject.gen!J [Microsoft] | 19 |
| Trojan Horse [Symantec] | 16 |
| Mal/Alureon-C, Mal/FakeVirPk-A [Sophos] | 14 |
| Trojan-Downloader.Win32.Renos.AQ [Ikarus] | 14 |
| VirTool.Win32.CeeInject [Ikarus] | 11 |
| DNSChanger.f.gen.a [McAfee] | 10 |
| Packed.Win32.Tdss [Ikarus] | 10 |
| Rootkit.Win32.TDSS [Ikarus] | 10 |
| Win-Trojan/Fakeav.118784.B [AhnLab] | 10 |
| Mal/FakeVirPk-A, Mal/EncPk-CZ [Sophos] | 8 |
| SpywareGuard2008 [Symantec] | 8 |
| W32/Xirtem@MM [McAfee] | 8 |
| Backdoor.Trojan [Symantec] | 7 |
| Mal/FakeVirPk-A [Sophos] | 7 |
| Packed.Win32.Tdss.f [Kaspersky Lab] | 7 |
| Rootkit.TDSS!sd6 [PC Tools] | 7 |
| DNSChanger.gen [McAfee] | 6 |
| Generic FakeAlert.c [McAfee] | 6 |
| Mal/TDSS-A [Sophos] | 6 |
| Trojan.TDss.1 [Ikarus] | 6 |
| Trojan.Win32.FakeSpyguard [Ikarus] | 6 |
| Trojan:Win32/Alureon.gen [Microsoft] | 6 |
| Trojan:Win32/FakeSpyguard [Microsoft] | 6 |
| Trojan:Win32/Sudiet.B [Microsoft] | 6 |
| W32/Autorun-XI [Sophos] | 6 |
| W32/AutoVrt-Gen, Mal/CryptBox-A [Sophos] | 6 |
| Worm.Win32.AutoTDSS [Ikarus] | 6 |
| Trojan.FakeAlert [PC Tools] | 5 |
| Trojan.Win32.Alureon [Ikarus] | 5 |
| Trojan:Win32/InternetAntivirus [Microsoft] | 5 |
| TrojanDownloader:Win32/Rugzip.A [Microsoft] | 5 |
| BackDoor-DVT [McAfee] | 4 |
| Generic.dx [McAfee] | 4 |
| Mal/EncPk-GR, Mal/EncPk-GR, Mal/TDSSPack-E [Sophos] | 4 |
| Mal/FakeVirPk-A, Mal/TDSS-A [Sophos] | 4 |
| Troj/Mdrop-BZI [Sophos] | 4 |
| Virus.Win32.Rootkit [Ikarus] | 4 |
| Generic FakeAlert.h [McAfee] | 3 |
| Mal/Alureon-C, Mal/Alureon-B, Mal/FakeAV-S [Sophos] | 3 |
| Mal/CryptBox-A [Sophos] | 3 |
| Trojan:WinNT/Alureon.C [Microsoft] | 3 |
| Win-Trojan/Fraudpack.37245 [AhnLab] | 3 |
| Generic FakeAlert.k [McAfee] | 2 |
| Mal/Alureon-C, Mal/Alureon-B [Sophos] | 2 |
| Mal/Alureon-C, Mal/Alureon-B, Mal/FakeAV-S, Mal/FakeVirPk-A [Sophos] | 2 |
| Mal/EncPk-HT [Sophos] | 2 |
| Mal/Generic-A [Sophos] | 2 |
| Mal/TDSS-A, Mal/EncPk-CZ [Sophos] | 2 |
| Mal/TDSSPack-A, Mal/EncPk-CZ [Sophos] | 2 |
| Mal/TDSSPack-E, Mal/Alureon-C, Mal/FakeVirPk-A [Sophos] | 2 |
| Rootkit.Win32.TDSS.eyj [Kaspersky Lab] | 2 |
| Troj/FakeVir-KG [Sophos] | 2 |
| Trojan.TDss [Ikarus] | 2 |
| Trojan:Win32/Witer.B [Microsoft] | 2 |
| VirTool:Win32/DelfInject.gen!L [Microsoft] | 2 |
| Win32/Autotdss.worm.30720 [AhnLab] | 2 |
| Backdoor.Bifrose [Symantec] | 1 |
| Backdoor.Tidserv [Symantec] | 1 |
| Backdoor.Win32.TDSS [Ikarus] | 1 |
| Constructor.Win32.Bifrose.j [Kaspersky Lab] | 1 |
| Downloader.MisleadApp [Symantec] | 1 |
| Dropper/DnsChanger.65536 [AhnLab] | 1 |
| FakeAlert-AB.gen.e [McAfee] | 1 |
| FakeAlert-SpywareGuard.gen.b [McAfee] | 1 |
| Generic BackDoor [McAfee] | 1 |
| Generic BackDoor.u [McAfee] | 1 |
| Generic Dropper [McAfee] | 1 |
| Generic Dropper.dp [McAfee] | 1 |
| Generic PUP.z [McAfee] | 1 |
| InternetAntivirus [Symantec] | 1 |
| Mal/Alureon-A [Sophos] | 1 |
| Mal/Alureon-B, Mal/FakeAV-S [Sophos] | 1 |
| Mal/Alureon-C, Mal/FakeVirPk-A, Troj/Virtum-Gen [Sophos] | 1 |
| Mal/EncPk-IT [Sophos] | 1 |
| Mal/FakeAV-AD, Mal/Alureon-C, Mal/FakeVirPk-A, Troj/Virtum-Gen [Sophos] | 1 |
| Mal/FakeAV-AD, Mal/TDSSPack-A, Mal/TDSSPack-E, Mal/EncPk-CZ, Troj/Virtum-Gen [Sophos] | 1 |
| Mal/FakeAV-M [Sophos] | 1 |
| Mal/FakeVirPk-A, Mal/TDSS-A, Mal/TDSS-C [Sophos] | 1 |
| Mal/RootKit-Fam, Mal/Alureon-A [Sophos] | 1 |
| Mal/TDSSPack-E, Mal/Alureon-C [Sophos] | 1 |
| Mal/TDSSPack-E, Mal/TDSSPack-A, Mal/FakeVirPk-A, Mal/EncPk-CZ, Troj/Virtum-Gen [Sophos] | 1 |
| Mal/TDSSPack-Q, Mal/EncPk-HT, Mal/TDSS-A [Sophos] | 1 |
| not-a-virus:FraudTool.Win32.InternetAntivirusPro.m [Kaspersky Lab] | 1 |
| Packed.Generic.188 [Symantec] | 1 |
| Program:Win32/FakeWG.A [Microsoft] | 1 |