Win32/Bundpil [Threat Name] go to Threat

Win32/Bundpil.DF [Threat Variant Name]

Category trojan,worm
Size 98304 B
Detection created Oct 11, 2015
Detection database version 12389
Aliases Worm:Win32/Gamarue!rfn (Microsoft)
  Trojan.Encoder.2823 (Dr.Web)
Short description

The trojan has a simple payload. The trojan is usually a part of other malware.

Installation

The trojan does not create any copies of itself.


The trojan creates the following file:

  • %malwarefolder%\­mz_87.dll (47616 B)
Other information

The trojan tries to read following files:

  • %malwarefolder%\­IndexerVolumeGuid

The files contain encrypted executables.


After decryption, the trojan runs these files.

Please enable Javascript to ensure correct displaying of this content and refresh this page.