| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 208896 |
| N/A | |
| 21b717e607b7141b848f140e1975944a | |
| 11a109e376b8c71ccf2d8bbaac0d0b67883d1915 | |
| 505b521326a96b37fa5c8025c9e281ba18a2f34966696f80e19036b44809533d | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| 204 kB | |
| Intel 386 or later, and compatibles | |
| Win32 | |
| 94208 | |
| 4.0 | |
| 0x1e58 | |
| 0x003f | |
| 6.0 | |
| N/A | |
| N/A | |
| 8, 2, 1, 0 | |
| 106496 | |
| DeskSave | |
| 8.2.1.0 | |
| application/octet-stream | |
| Windows, Latin1 | |
| Greek | |
| 8.2.1.0 | |
| Win32 EXE | |
| DeskSave.exe | |
| Copyright © 1998-2008 by Thorsten Blauhut | |
| Windows GUI | |
| Executable application | |
| 1.0 | |
| (none) | |
| 4.0 | |
| 8.2.1 | |
| Source: |

| AVG | Worm/Generic2.BCLB |
| AhnLab-V3 | Trojan/Win32.Chifrax |
| AntiVir | Worm/Dorkbot.A.859 |
| Antiy-AVL | Worm/Win32.Ngrbot.gen |
| Avast | Win32:VBCrypter-A [Cryp] |
| BitDefender | Backdoor.Bot.145861 |
| CAT-QuickHeal | Trojan.Dorkbot.a |
| Comodo | Heur.Suspicious |
| DrWeb | BackDoor.IRC.NgrBot.42 |
| Emsisoft | Worm.Win32.Dorkbot!IK |
| F-Secure | Backdoor.Bot.145861 |
| Fortinet | W32/DORKBOT.DB!worm |
| GData | Backdoor.Bot.145861 |
| Ikarus | Worm.Win32.Dorkbot |
| Jiangmin | DangerousObject.Multi.dzi |
| K7AntiVirus | EmailWorm |
| Kaspersky | Worm.Win32.Ngrbot.hcd |
| McAfee | W32/IRCbot.gen.bj |
| McAfee-GW-Edition | W32/IRCbot.gen.bj |
| Microsoft | Worm:Win32/Dorkbot.A |
| NOD32 | a variant of Win32/Injector.KYJ |
| Norman | W32/Suspicious_Gen2.SNMCS |
| PCTools | Trojan.IRCBot |
| Panda | Generic Malware |
| SUPERAntiSpyware | Trojan.Agent/Gen-VBInject |
| Sophos | Mal/VB-ABD |
| Symantec | W32.IRCBot.NG |
| TrendMicro | WORM_DORKBOT.DB |
| TrendMicro-HouseCall | WORM_DORKBOT.DB |
| VBA32 | Worm.Ngrbot.hcd |
| VIPRE | Trojan.Win32.Generic!BT |
| VirusBuster | Trojan.Injector!tanZ185qJI8 |
| eTrust-Vet | Win32/Rbot.C!generic |
| nProtect | Backdoor.Bot.145861 |