| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 123909 |
| N/A | |
| 7357ba4aac1170a0e7dfc922a1d1b526 | |
| 30a8de59739222c8e1e88455d20a8d014a97eb0d | |
| c7bfdf14d574083e3b3eea15ef494a7f4b842ae8c82840786fd58686b3874171 | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| application/octet-stream | |
| 6.0 | |
| N/A | |
| 24576 | |
| 10.42 | |
| Win32 EXE | |
| 121 kB | |
| Intel 386 or later, and compatibles | |
| Error processing PE data dictionary | |
| 4.0 | |
| Windows GUI | |
| 24576 | |
| 4.0 | |
| 0x69e0 | |
| Source: |

| AVG | BackDoor.Generic14.BGFY |
| AhnLab-V3 | Trojan/Win32.Xema |
| AntiVir | TR/Crypt.XPACK.Gen |
| Antiy-AVL | Worm/Win32.Ngrbot.gen |
| Avast | Win32:Dorkbot-AF [Trj] |
| BitDefender | Trojan.Generic.6794002 |
| Comodo | UnclassifiedMalware |
| DrWeb | Trojan.VbCrypt.53 |
| Emsisoft | Worm.Win32.Dorkbot!IK |
| F-Secure | Trojan.Generic.6794002 |
| Fortinet | W32/Injector.KJS!tr |
| GData | Trojan.Generic.6794002 |
| Ikarus | Worm.Win32.Dorkbot |
| Jiangmin | Worm/Ngrbot.if |
| K7AntiVirus | EmailWorm |
| Kaspersky | Worm.Win32.Ngrbot.gqv |
| McAfee | W32/Sdbot.worm!lr |
| McAfee-GW-Edition | Heuristic.LooksLike.Win32.SuspiciousPE.J!87 |
| Microsoft | Worm:Win32/Dorkbot.A |
| NOD32 | a variant of Win32/Injector.KJR |
| Norman | W32/Ruskill.H |
| PCTools | Trojan.IRCBot!rem |
| Sophos | Mal/Generic-L |
| Symantec | W32.IRCBot |
| TheHacker | W32/Behav-Heuristic-CorruptFile-EP |
| VBA32 | Backdoor.VB.Ruskill.gen |
| VIPRE | Trojan.Win32.Generic!BT |
| nProtect | Worm/W32.Ngrbot.123909 |