| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 264648 |
| N/A | |
| 6777b6c2ec8ffc8fbe062e7e4420e899 | |
| bb1fc1f06a08c4352f2c748d14a4e9e41091ac56 | |
| b38894a4b1b39f5c7108fe705928c80c9ef293eb9334bcce202d85524046d515 | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| application/octet-stream | |
| 6.0 | |
| N/A | |
| 241664 | |
| 0.0 | |
| Win32 EXE | |
| 258 kB | |
| Intel 386 or later, and compatibles | |
| Error processing PE data dictionary | |
| 4.0 | |
| Windows GUI | |
| 20480 | |
| 4.0 | |
| 0x5040 | |
| Source: |

| AVG | Generic25.BPOB |
| AhnLab-V3 | Trojan/Win32.Buzus |
| Antiy-AVL | Worm/Win32.Ngrbot.gen |
| Avast | Win32:MalOb-IE [Cryp] |
| BitDefender | Trojan.Generic.6829498 |
| ClamAV | Worm.Dorkbot-3 |
| Commtouch | W32/Agent.MS.gen!Eldorado |
| Comodo | UnclassifiedMalware |
| DrWeb | BackDoor.IRC.NgrBot.42 |
| Emsisoft | Worm.Win32.Dorkbot!IK |
| F-Prot | W32/Agent.MS.gen!Eldorado |
| F-Secure | Trojan.Generic.6829498 |
| Fortinet | W32/Kryptik.AL!tr |
| GData | Trojan.Generic.6829498 |
| Ikarus | Worm.Win32.Dorkbot |
| Jiangmin | Worm/Ngrbot.il |
| K7AntiVirus | EmailWorm |
| Kaspersky | Worm.Win32.Ngrbot.hel |
| McAfee | PWS-Zbot.gen.ke |
| McAfee-GW-Edition | PWS-Zbot.gen.ke |
| Microsoft | Worm:Win32/Dorkbot.A |
| NOD32 | a variant of Win32/Injector.KSW |
| Norman | W32/Ngrbot.M |
| PCTools | Trojan.IRCBot!rem |
| Panda | Suspicious file |
| SUPERAntiSpyware | Trojan.Agent/Gen-Restlet |
| Sophos | W32/Dorkbot-AG |
| Symantec | W32.IRCBot |
| TheHacker | Trojan/Injector.ksw |
| TrendMicro | TROJ_KRYPTK.SMU3 |
| TrendMicro-HouseCall | TROJ_KRYPTK.SMU3 |
| VBA32 | BScope.Backdoor.Ruskill.1421 |
| eTrust-Vet | Win32/Dorkbot.FZ |
| nProtect | Trojan.Generic.6829498 |