Lavasoft Security Bulletin - April 2014: Top Threats
Top 20 Blocked Malware
Position | Ad-Aware detection | % of all threats | Change in ranking |
1 | Win32.Trojan.Agent | 74.59% | -6.72% |
2 | Trojan.Win32.Generic!BT | 14.68% | +5.79% |
3 | Jeefo | 0.76% | +0.54% |
4 | Trojan.Win32.Generic.pak!cobra | 0.70% | +0.19% |
5 | Virus.Win32.Ramnit.a | 0.67% | new |
6 | Malware.JS.Generic | 0.66% | +0.13% |
7 | HackTool.Win32.Keygen | 0.60% | +0.32% |
8 | Worm.LNK.Jenxcus.aha | 0.57% | -0.26% |
9 | Win32.TrojanDropper.Agent/A | 0.45% | new |
10 | Virus.Win32.Sality.at | 0.41% | +0.07% |
11 | Trojan.Win32.Jpgiframe | 0.32% | +0.11% |
12 | Trojan.Win32.Generic!SB.0 | 0.31% | +0.15% |
13 | Virus.Win32.Sality.ah | 0.23% | new |
14 | Trojan-Clicker.HTML.RemoteScript | 0.23% | new |
15 | Trojan-Dropper.Win32.Agent.aeu | 0.15% | new |
16 | Virus.Win32.Expiro.i | 0.13% | new |
17 | Trojan.Win32.Ramnit.c | 0.12% | -0.22% |
18 | Trojan.Win32.AutoIT.gen | 0.11% | new |
19 | Trojan.Win32.Packer.PESpinv1.32 | 0.10% | new |
20 | Backdoor.Win32.Bifrose.fsi | 0.09% | new |
The Top 20 malicious programs blocked on PCs
Malware Prevalence Table - April 2014
The table below ranks the most prevalent families seen in April.
Position | Ad-Aware detection | % of all threats | Change in ranking |
1 | Trojan.Win32.Generic!BT | 33.87% | +0.41% |
2 | Virus.Win32.Expiro.gen | 7.52% | +0.17% |
3 | Virus.Win32.Virut.ce | 6.71% | +3.41% |
4 | Trojan-Downloader.Win32.LoadMoney.u | 5.16% | -0.85% |
5 | Trojan.Win32.Generic.pak!cobra | 3.01% | -0.10% |
6 | Trojan.Win32.Ircbot!cobra | 0.86% | -0.18% |
7 | InstallCore | 0.82% | new |
8 | Trojan.Win32.Generic!SB.0 | 0.77% | +0.41% |
9 | Adware.Bettersurf | 0.77% | new |
10 | Adware.OutBrowse | 0.58% | -0.06% |
11 | Optimum Installer | 0.53% | new |
12 | Click run software | 0.47% | new |
13 | Trojan.Win32.DelfInject.m | 0.36% | -0.07% |
14 | Trojan.Win32.LoadMoney.f | 0.34% | +0.02% |
15 | Trojan.StartPage | 0.22% | new |
16 | FraudTool.Win32.InternetProtection.ek!a | 0.21% | -0.05% |
17 | Worm.Win32.Gamarue.z | 0.21% | +0.02% |
18 | Trojan.HTML.Ransomware.b | 0.20% | -0.05% |
19 | Backdoor.MSIL.Bladabindi.a | 0.20% | +0.02% |
20 | Malware.JS.Generic | 0.20% | new |
New malicious programs entered the Top 20
In April Lavasoft Malware Analysis System detected the following fake antiviruses. This polymorphic Fake AV family was previously described in February 2014
Fake AV (MD5: 9e42968882b42a4f4418df8bb5301f65, 36f0e8ae4f8e14b35757136cc2200952, 78912dc0c6406105343ead0656b74f8a, aa1c742eafac0c819c3fb32f325c3be3, c3e6595842fd0366d87790c814b28af2, d6cb2f4d4f2b1db9087ed0f081cca1c5, d12bc79b2d8714fe80600730bc200138, df7721c0e49fdd1f14b43b1d3c6d3424)
Top20 Potentially Unwanted Programs
Below are the Top20 Potentially Unwanted Programs blocked by Ad-Aware on user’s PCs. These are advertising software, browser toolbars, search engines and other programs which change browser start pages and other system settings.
Position | Ad-Aware detection | % of all threats | Change in ranking |
1 | MyWebSearch | 17.07% | +1.19% |
2 | Conduit | 16.82% | -6.21% |
3 | Win32.PUP.Bandoo | 14.34% | +6.93% |
4 | Adware.Linkury | 9.21% | +2.32% |
5 | Adware.JS.Conduit | 9.19% | -0.99% |
6 | Adware.SaveSense | 2.52% | -1.33% |
7 | Crossrider | 1.96% | -0.23% |
8 | Win32.Toolbar.Iminent | 1.72% | -0.17% |
9 | Adware.Win32.Multiplug.c | 1.38% | new |
10 | DomaIQ | 1.23% | +0.09% |
11 | Adware.Agent | 1.12% | -0.24% |
12 | Iminent | 1.08% | -0.81% |
13 | Adware.DealPly | 1.01% | -0.14% |
14 | SweetIM | 0.95% | -0.11% |
15 | InstallCore | 0.82% | -0.08% |
16 | Opencandy | 0.80% | -0.20% |
17 | Win32.Adware.Agent | 0.75% | -0.61% |
18 | Yontoo | 0.70% | new |
19 | InstallCore.b | 0.69% | +0.10% |
20 | Montiera | 0.64% | -0.03% |
Top20 PUPs detected on user’s PC
Operating Systems
Infections by OS
Geographic Location
Infections by country of origin
We will keep investigating the epidemiological situation in the world and informing our readers about new malicious code samples in the next Lavasoft Security Bulletin.
Read also:
Lavasoft Security Bulletin - April 2014: Bot Review.
Share this post:

