| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 77569 |
| N/A | |
| cd867d424388518b0a614144a0a0183a | |
| b6ea061aefeb79ef750ba3530b87d243f0c69262 | |
| 39766d5e7dc0c6cc0ec03f52d9a589a56f494673b3baad149f249dae5667e1b1 | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| application/octet-stream | |
| 6.0 | |
| N/A | |
| 163840 | |
| 0.0 | |
| Win32 EXE | |
| 76 kB | |
| Intel 386 or later, and compatibles | |
| Error processing PE data dictionary | |
| 4.0 | |
| Windows GUI | |
| 20480 | |
| 4.0 | |
| 0x5040 | |
| Source: |

| AVG | Generic25.BPOB |
| AhnLab-V3 | Trojan/Win32.Buzus |
| Antiy-AVL | Worm/Win32.Ngrbot.gen |
| Avast | Win32:MalOb-IE [Cryp] |
| BitDefender | Trojan.Generic.6829498 |
| CAT-QuickHeal | Worm.IRCBot.Gen |
| ClamAV | Worm.Dorkbot-3 |
| Commtouch | W32/Agent.MS.gen!Eldorado |
| Comodo | UnclassifiedMalware |
| DrWeb | BackDoor.IRC.NgrBot.42 |
| Emsisoft | Worm.Win32.Dorkbot!IK |
| F-Prot | W32/Agent.MS.gen!Eldorado |
| F-Secure | Trojan.Generic.6829498 |
| Fortinet | W32/Kryptik.AL!tr |
| GData | Trojan.Generic.6829498 |
| Ikarus | Worm.Win32.Dorkbot |
| Jiangmin | Worm/Ngrbot.il |
| K7AntiVirus | EmailWorm |
| Kaspersky | Worm.Win32.Ngrbot.hel |
| McAfee | PWS-Zbot.gen.ke |
| McAfee-GW-Edition | PWS-Zbot.gen.ke |
| Panda | Generic Trojan |
| Rising | Trojan.Win32.Generic.12A37686 |
| SUPERAntiSpyware | Trojan.Agent/Gen-Restlet |
| Sophos | W32/Dorkbot-AG |
| Symantec | W32.IRCBot |
| TheHacker | Trojan/Injector.ksw |
| TotalDefense | Win32/Dorkbot.FZ |
| TrendMicro | TROJ_KRYPTK.SMU3 |
| TrendMicro-HouseCall | TROJ_KRYPTK.SMU3 |
| VBA32 | BScope.Backdoor.Ruskill.1421 |
| ViRobot | Worm.Win32.A.Ngrbot.147456 |
| eSafe | Win32.Trojan |
| nProtect | Trojan.Generic.6829498 |