Skip to main content

Monthly Malware Statistics: March 2009

1 April 2009

Two Top Twenties have been compiled from data generated by the Kaspersky Security Network (KSN) throughout March 2009.

Two Top Twenties have been compiled from data generated by the Kaspersky Security Network (KSN) throughout March 2009.

The first Top Twenty is based on data collected by Kaspersky Lab’s version 2009 antivirus product. The ranking is made up of the malicious programs, adware and potentially unwanted programs most frequently detected on users’ computers.


PositionChange in positionName
1   1Net-Worm.Win32.Kido.ih  
2   -1Virus.Win32.Sality.aa  
3   2Trojan.Win32.Autoit.ci  
4   4Trojan-Downloader.Win32.VB.eql  
5   2Packed.Win32.Krap.g  
6   0Worm.Win32.AutoRun.dui  
7   -4Packed.Win32.Krap.b  
8   -4Packed.Win32.Black.a  
9   NewTrojan-Dropper.Win32.Flystud.ko  
10   5Virus.Win32.Sality.z  
11   1Worm.Win32.Mabezat.b  
12   -2Virus.Win32.Alman.b  
13   1Worm.Win32.AutoIt.ar  
14   NewTrojan.JS.Agent.ty  
15   2Email-Worm.Win32.Brontok.q  
16   3Worm.Win32.AutoIt.i  
17   ReturnVirus.Win32.VB.bu  
18   NewPacked.Win32.Katusha.a  
19   NewTrojan.Win32.RaMag.a  
20   NewTrojan.Win32.Autoit.xp  

There were no significant changes to this ranking in March.

The network worm Net-Worm.Win32.Kido.ih, also known as Conficker and Downadup, topped the list. However, we don’t expect to see the latest version of this now infamous malicious program among the leaders in the following months: it’s now detected by Kaspersky Lab as Trojan-Downloader.Win32.Kido.a and unlike previous variants, this one is unable to spread independently across networks.

The highest new entry Trojan-Dropper.Win32.Flystud.ko is the highest ranking new entry; it came straight in at number nine and is a typical Trojan designed to stealthily install other Trojans. It is written in the FlyStudio script language that, along with AutoIt, is one of the most popular languages among malware writers. Both FlyStudio and the programs written in it originate in China.

Speaking of AutoIt, March’s ranking sees the Autoit.ci Trojan joined by a similar program called Autoit.xp.

At the lower end of the ranking there are two other new entries: Packed.Win32.Katusha.a and Trojan.Win32.Ramag.a. The former detects a compression utility used to pack both certain modifications of the fraudware program FraudTool and the malware which downloads these modifications. The Ramag.a Trojan is a modified WinRAR archive which has no malicious payload apart from carrying other malware.

There were fewer script downloader programs; only Trojan.JS.Agent.ty, with its traditional iframe, is present in the first Top Twenty.



All malicious, advertising and potentially unwanted programs in the first Top Twenty can be grouped according to the main classes of threats which we detect. There has been no significant change in the balance between these classes for the last three months. The number of self-replicating programs also remains relatively high.

In total, 45857 unique malicious, advertising, and potentially unwanted programs were detected on users’ computers in March. This figure is almost exactly the same as last month’s.

The second Top Twenty presents data on which malicious programs most commonly infected objects detected on users’ computers. Malicious programs capable of infecting files make up the majority of this ranking.


PositionChange in positionName
1   0Virus.Win32.Sality.aa  
2   0Worm.Win32.Mabezat.b  
3   1Virus.Win32.Virut.ce  
4   -1Net-Worm.Win32.Nimda  
5   0Virus.Win32.Xorer.du  
6   0Virus.Win32.Sality.z  
7   0Virus.Win32.Alman.b  
8   0Virus.Win32.Parite.b  
9   3Virus.Win32.Virut.q  
10   0Trojan-Downloader.HTML.Agent.ml  
11   8Virus.Win32.Small.l  
12   2Email-Worm.Win32.Runouce.b  
13   NewNet-Worm.Win32.Kido.ih  
14   -3Virus.Win32.Virut.n  
15   -2Virus.Win32.Parite.a  
16   0Virus.Win32.Hidrag.a  
17   -8Trojan-Clicker.HTML.IFrame.acy  
18   -3P2P-Worm.Win32.Bacteraloh.h  
19   ReturnWorm.Win32.Otwycal.g  
20   ReturnWorm.Win32.Fujack.k  

Net-Worm.Win32.Kido.ih also made its mark in the second of our rankings and held its own among the more common types of self-replicating programs. This is most probably due to the fact that not all users installed the necessary security updates to their operating system in February.

Monthly Malware Statistics: March 2009

Two Top Twenties have been compiled from data generated by the Kaspersky Security Network (KSN) throughout March 2009.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection, specialized security products and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help over 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Related Articles Press Releases