| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 36922 |
| N/A | |
| 15e98b2ee1385f4c24fad8907884c3a6 | |
| 881002deabadc352fcab94bc308615a25952e169 | |
| 8fa8cf415aaee66a200b766613b01f75686be8bff559850168b4df12ce8622be | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| application/octet-stream | |
| 6.0 | |
| N/A | |
| 192512 | |
| 0.0 | |
| Win32 EXE | |
| 36 kB | |
| Intel 386 or later, and compatibles | |
| Error processing PE data dictionary | |
| 4.0 | |
| Windows GUI | |
| 20480 | |
| 4.0 | |
| 0x50bc | |
| Source: |

| AVG | Dropper.Generic4.CAPF |
| AhnLab-V3 | Trojan/Win32.HDC |
| Antiy-AVL | Worm/Win32.Ngrbot.gen |
| Avast | Win32:MalOb-IE [Cryp] |
| BitDefender | Trojan.Generic.6849537 |
| CAT-QuickHeal | Worm.IRCBot.Gen |
| ClamAV | Trojan.Kazy-428 |
| Commtouch | W32/Agent.MS.gen!Eldorado |
| Comodo | UnclassifiedMalware |
| DrWeb | BackDoor.IRC.NgrBot.42 |
| Emsisoft | Worm.Win32.Ngrbot!IK |
| F-Prot | W32/Agent.MS.gen!Eldorado |
| F-Secure | Trojan.Generic.6849537 |
| Fortinet | W32/Kryptik.AL!tr |
| GData | Trojan.Generic.6849537 |
| Ikarus | Worm.Win32.Ngrbot |
| Jiangmin | TrojanDropper.Injector.ceq |
| K7AntiVirus | Riskware |
| Kaspersky | Worm.Win32.Ngrbot.hdy |
| McAfee | PWS-Zbot.gen.ke |
| McAfee-GW-Edition | PWS-Zbot.gen.ke |
| Microsoft | VirTool:Win32/Injector.AR |
| NOD32 | a variant of Win32/Injector.KSW |
| Norman | W32/Ngrbot.M |
| Panda | Suspicious file |
| SUPERAntiSpyware | Trojan.Agent/Gen-Kryptik |
| Sophos | Mal/EncPk-AAQ |
| TheHacker | Trojan/Injector.ksw |
| VBA32 | BScope.Backdoor.Ruskill.1421 |
| eSafe | Win32.Trojan |
| eTrust-Vet | Win32/FraudPack.F!generic |
| nProtect | Trojan.Generic.6849537 |