| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 133197 |
| N/A | |
| 07d59aefd161ad1cc9b3700114cd3b3a | |
| c20bbbf382314489b77366ef017bfca174c2e637 | |
| 9bbcef68d9221c934cdc9de8211c0eec86215a6cf0ae03569998e9e75bdb55cb | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| application/octet-stream | |
| 6.0 | |
| N/A | |
| 8192 | |
| 1.0 | |
| Win32 EXE | |
| 130 kB | |
| Intel 386 or later, and compatibles | |
| 4.0 | |
| Windows GUI | |
| N/A | |
| 4.0 | |
| 0x14b0 | |
| Source: |

| AVG | IRC/BackDoor.SdBot4.VNC |
| AhnLab-V3 | Backdoor/Win32.Ruskill |
| AntiVir | TR/Crypt.XPACK.Gen |
| Avast | Win32:VB-AABH [Trj] |
| CAT-QuickHeal | Worm.Ngrbot.hcm |
| Comodo | UnclassifiedMalware |
| DrWeb | Worm.Siggen.5430 |
| Emsisoft | Worm.Win32.Ngrbot!IK |
| Fortinet | W32/Refroso.DZP!tr |
| GData | Win32:VB-AABH |
| Ikarus | Worm.Win32.Ngrbot |
| Jiangmin | Worm/Ngrbot.hr |
| K7AntiVirus | Riskware |
| Kaspersky | Worm.Win32.Ngrbot.hcm |
| McAfee | W32/IRCbot.gen.bg |
| McAfee-GW-Edition | W32/IRCbot.gen.bg |
| Microsoft | VirTool:Win32/VBInject.gen!IG |
| NOD32 | a variant of Win32/Injector.KUO |
| Norman | W32/Suspicious_Gen2.dam |
| PCTools | Trojan.ADH |
| Sophos | Mal/Generic-L |
| Symantec | Trojan.ADH.2 |
| TheHacker | Trojan/Injector.kuo |
| VBA32 | Worm.Ngrbot.hcm |
| VIPRE | Trojan.Win32.Generic!BT |
| eSafe | Win32.WormNgrbot.Hcm |