| Threat Alias | Number of Incidents |
| Mal/Behav-024 [Sophos] | 20 |
| Trojan.Win32.Scar.amna [Kaspersky Lab] | 18 |
| RogueAntiSpyware.AntiVirusPro [PC Tools] | 12 |
| FakeAlert-FQ [McAfee] | 11 |
| Mal/FakeAV-BP [Sophos] | 11 |
| Trojan.FakeAV [Symantec] | 7 |
| RogueAntiSpyware.WindowsAntivirusPro [PC Tools] | 6 |
| Trojan.FakeAV [PC Tools] | 6 |
| Trojan.Win32.Alureon [Ikarus] | 6 |
| WindowsAntivirusPro [Symantec] | 6 |
| AntiVirus2008 [Symantec] | 5 |
| Mal/EncPk-ND, Troj/Virtum-Gen [Sophos] | 4 |
| Packed.Win32.TDSS.aa [Kaspersky Lab] | 4 |
| RogueAntiSpyware.AntiVirus2008 [PC Tools] | 4 |
| Trojan.Win32.FraudPack.acif [Kaspersky Lab] | 4 |
| Trojan.Win32.Tdss.avhc [Kaspersky Lab] | 4 |
| Trojan-Dropper.Win32.Agent.bihg [Kaspersky Lab] | 4 |
| Win-Trojan/Malware.712704.C [AhnLab] | 4 |
| DNSChanger.p [McAfee] | 3 |
| Packed.Win32.Tdss [Ikarus] | 3 |
| Mal/EncPk-ND [Sophos] | 2 |
| Mal/EncPk-ND, Mal/FakeAV-BP [Sophos] | 2 |
| Mal/TDSSPack-Q, Mal/FakeAV-BP [Sophos] | 2 |
| Packed.Win32.TDSS.y [Kaspersky Lab] | 2 |
| SecurityRisk.Downldr [Symantec] | 2 |
| Win-Trojan/Malware.1040384.B [AhnLab] | 2 |
| FakeAlert-IR [McAfee] | 1 |
| Gen.Trojan [Ikarus] | 1 |
| HeurEngine.MaliciousPacker [PC Tools] | 1 |
| Mal/Generic-A [Sophos] | 1 |
| Packed.Generic.277 [Symantec] | 1 |
| Trojan.Fakeavalert [Symantec] | 1 |
| Trojan.Win32.FraudPack.abrj [Kaspersky Lab] | 1 |
| Trojan.Win32.Scar.axhi [Kaspersky Lab] | 1 |
| Trojan.Win32.Tdss.avsa [Kaspersky Lab] | 1 |
| Trojan-Downloader.Win32.FraudLoad.gdq [Kaspersky Lab] | 1 |
| Virus.Packed.Win32.Tdss [Ikarus] | 1 |
| Win-Trojan/Malware.1187840.F [AhnLab] | 1 |
| Win-Trojan/Malware.675840 [AhnLab] | 1 |