| Threat Alias | Number of Incidents |
| W32/YahLover.worm [McAfee] | 339 |
| W32.Imaut.A [Symantec] | 299 |
| WORM_SOHANAD.EJ [Trend Micro] | 283 |
| IM-Worm.Win32.Sohanad [Ikarus] | 245 |
| W32/SillyFDC-AE [Sophos] | 245 |
| Worm:Win32/Sohanad.I [Microsoft] | 245 |
| IM-Worm.Win32.AutoIt.g [Kaspersky Lab] | 239 |
| Win-Trojan/Downloader.290419 [AhnLab] | 119 |
| W32/AutoRun-PU [Sophos] | 70 |
| Worm.Autoit [Ikarus] | 57 |
| IM-Worm.Win32.Sohanad.as [Kaspersky Lab] | 55 |
| Trojan Horse [Symantec] | 42 |
| Virus.Win32.AutoIt.a [Kaspersky Lab] | 42 |
| WORM_YAHLOVER.AL [Trend Micro] | 42 |
| TrojanDownloader:Win32/Agent.B [Microsoft] | 36 |
| W32/Sohana-AH [Sophos] | 36 |
| Worm:AutoIt/YahLover.F!inf [Microsoft] | 31 |
| Virus.Win32.AutoRun.jq [Ikarus] | 24 |
| WORM_SOHANAD.AS [Trend Micro] | 17 |
| Trojan.Win32.KillAV.ayh [Kaspersky Lab] | 6 |
| Win32/YahLover.worm.226217 [AhnLab] | 6 |
| Worm.Win32.AutoRun.k [Kaspersky Lab] | 3 |
| WORM_AUTORUN.K [Trend Micro] | 2 |
| Email-Worm.Win32.Brontok.ab [Ikarus] | 1 |
| Generic.dx [McAfee] | 1 |
| IM-Worm.Win32.Sohanad.ae [Kaspersky Lab] | 1 |
| IM-Worm.Win32.Sohanad.gen [Kaspersky Lab] | 1 |
| IM-Worm.Win32.Sohanad.t [Kaspersky Lab] | 1 |
| Mal/Generic-A [Sophos] | 1 |
| Trojan:Win32/Meredrop [Microsoft] | 1 |
| W32.Imaut.AA [Symantec] | 1 |
| W32.SillyFDC [Symantec] | 1 |
| W32/Autorun.worm.cs [McAfee] | 1 |
| W32/Autorun.worm.g [McAfee] | 1 |
| W32/SillyFDC-AU [Sophos] | 1 |
| Win32/Autorun.worm.225604 [AhnLab] | 1 |
| Worm.Autorun.K [PC Tools] | 1 |
| Worm.Sohanad.U [PC Tools] | 1 |
| Worm.Win32.AutoRun [Ikarus] | 1 |
| Worm.Win32.VB.ck [Kaspersky Lab] | 1 |
| Worm:Win32/Autorun [Microsoft] | 1 |
| WORM_SOHANAD.BN [Trend Micro] | 1 |
| WORM_SOHANAD.FG [Trend Micro] | 1 |
| WORM_SOHANAD.IM [Trend Micro] | 1 |
| WORM_VB.ESA [Trend Micro] | 1 |