| Threat Alias | Number of Incidents |
| Trojan.Win32.Alureon [Ikarus] | 349 |
| Mal/EncPk-IF [Sophos] | 122 |
| Backdoor.Tidserv [Symantec] | 112 |
| Packed.Generic.233 [Symantec] | 96 |
| Suspicious.Vundo.2 [Symantec] | 85 |
| Packed.Win32.Tdss.w [Kaspersky Lab] | 60 |
| Generic FakeAlert!bd [McAfee] | 47 |
| Mal/Generic-A [Sophos] | 45 |
| Win-Trojan/Xema.variant [AhnLab] | 39 |
| Packed.Win32.Tdss [Ikarus] | 24 |
| DNSChanger.r [McAfee] | 18 |
| Packed.Generic.200 [Symantec] | 18 |
| Backdoor.Trojan [Symantec] | 12 |
| Trojan.Alureon.Gen [PC Tools] | 12 |
| W32.Tidserv.G [Symantec] | 12 |
| DNSChanger.s [McAfee] | 11 |
| Worm.Win32.AutoRun [Ikarus] | 11 |
| Packed.Generic.218 [Symantec] | 10 |
| Rootkit.Win32.TDSS.eyj [Kaspersky Lab] | 10 |
| Trojan.Win32.Tdss [Ikarus] | 10 |
| Vundo!a [McAfee] | 10 |
| Worm.Win32.AutoRun.fph [Kaspersky Lab] | 10 |
| DNSChanger!bd [McAfee] | 9 |
| Packed.Generic.228 [Symantec] | 9 |
| Trojan Horse [Symantec] | 8 |
| W32/Autorun.worm!bn [McAfee] | 7 |
| W32/Autorun.worm.gen [McAfee] | 7 |
| Packed.Win32.TDSS.w [Kaspersky Lab] | 6 |
| Trojan.Win32.InternetAntivirus [Ikarus] | 6 |
| Vundo!m [McAfee] | 6 |
| DNSChanger!bb [McAfee] | 5 |
| Packed.Win32.Krap.t [Kaspersky Lab] | 5 |
| Win-Trojan/Alureon.14336.D [AhnLab] | 5 |
| Backdoor.Win32.Rustock [Ikarus] | 4 |
| DNSChanger!o [McAfee] | 4 |
| Generic FakeAlert!s [McAfee] | 4 |
| Mal/Alureon-D [Sophos] | 4 |
| Troj/TDSS-Z [Sophos] | 4 |
| Trojan.Win32.Patcher.ex [Kaspersky Lab] | 4 |
| Trojan.Win32.Tdss.acxc [Kaspersky Lab] | 4 |
| Trojan.Win32.Tdss.afne [Kaspersky Lab] | 4 |
| Trojan.Win32.Tdss.xxz [Kaspersky Lab] | 4 |
| Worm.Win32.AutoRun.gah [Kaspersky Lab] | 4 |
| Backdoor.Tidserv [PC Tools] | 3 |
| Mal/EncPk-HG [Sophos] | 3 |
| Packed.Win32.Tdss.f [Kaspersky Lab] | 3 |
| W32.SillyFDC [Symantec] | 3 |
| HeurEngine.MaliciousPacker [PC Tools] | 2 |
| Mal/EncPk-ND, Mal/Krap-A, Mal/Krap-D, Mal/FakeVirPk-A, Mal/TDSSPack-E [Sophos] | 2 |
| Mal/FakeVirPk-A, Mal/EncPk-CZ [Sophos] | 2 |
| Trojan.Crypt [Ikarus] | 2 |
| Trojan.Generic [PC Tools] | 2 |
| Trojan.Win32.Agent [Ikarus] | 2 |
| Trojan.Win32.Agent.cnob [Kaspersky Lab] | 2 |
| Trojan.Win32.Obfuscated.absa [Kaspersky Lab] | 2 |
| Trojan.Win32.Tdss.uyx [Kaspersky Lab] | 2 |
| Vundo!j [McAfee] | 2 |
| Vundo!l [McAfee] | 2 |
| W32/Autorun-AFM [Sophos] | 2 |
| W32/AutoRun-AKI [Sophos] | 2 |
| Worm.Win32.AutoRun.gbc [Kaspersky Lab] | 2 |
| Backdoor.Win32.TDSS [Ikarus] | 1 |
| Backdoor.Win32.TDSS.kh [Kaspersky Lab] | 1 |
| DNSChanger!bj [McAfee] | 1 |
| DNSChanger!j [McAfee] | 1 |
| DNSChanger!k [McAfee] | 1 |
| DNSChanger!n [McAfee] | 1 |
| DNSChanger.gen [McAfee] | 1 |
| Generic.dx [McAfee] | 1 |
| Mal/Alureon-C [Sophos] | 1 |
| Mal/Alureon-C, Mal/FakeVirPk-A [Sophos] | 1 |
| Mal/EncPk-HH [Sophos] | 1 |
| Mal/EncPk-IF, Mal/EncPk-HH [Sophos] | 1 |
| Mal/FakeVirPk-A [Sophos] | 1 |
| Mal/TDSSPack-E, Mal/TDSSPack-A, Mal/FakeVirPk-A, Mal/EncPk-CZ [Sophos] | 1 |
| Mal/UnkPack-Fam [Sophos] | 1 |
| Rootkit.Win32.TDSS [Ikarus] | 1 |
| Rootkit.Win32.TDSS.hho [Kaspersky Lab] | 1 |
| Trojan.Win32.Agent2 [Ikarus] | 1 |
| Trojan.Win32.Agent2.eqf [Kaspersky Lab] | 1 |
| Virus.Win32.Fasec [Ikarus] | 1 |
| W32.SillyDC [Symantec] | 1 |
| Win-Trojan/Agent2.49152.B [AhnLab] | 1 |
| Win-Trojan/Zpack.10752.B [AhnLab] | 1 |
| Worm.AutoRun!sd6 [PC Tools] | 1 |
| Worm.Win32.AutoRun.avzj [Kaspersky Lab] | 1 |
| Worm.Win32.AutoRun.fbp [Kaspersky Lab] | 1 |