Malware

What is “Win32/Bundpil.BD”?

Malware Removal

The Win32/Bundpil.BD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Bundpil.BD virus can do?

  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Bundpil.BD?


File Info:

name: A530E4436C68F6F094A0.mlw
path: /opt/CAPEv2/storage/binaries/7647ff5856f12374976cf906b521c0db8e54cb27251afe527ed98328f5f60a84
crc32: B84E38B1
md5: a530e4436c68f6f094a066c69193130f
sha1: 2b2607c20f7f4f6001e6b9d118e1d407e98d57c3
sha256: 7647ff5856f12374976cf906b521c0db8e54cb27251afe527ed98328f5f60a84
sha512: 64225874debb25b52b359f9618ea3bcf2f00d4b1d9d5870364671c39f105186e31f024838ae577401ad207ae99d89f21f3d885bde4804dbd18803c30f3c91790
ssdeep: 48:qfAr1C9XDvrXkxLVvrhWR0Ui5X4nBvystYVzwGGQx8sUMflt:FrA1rrXk3vrY0x8duVzwGGQx8Elt
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D9716336B695FE77D098213216E72BDC205ACF25432301CB4E89863A586D3D27FF6B10
sha3_384: 0004cd47d082425ec97844c47f064400332e4d53a4d98aa0523089fcedc619974294ef55faed11703e1549a88a604c28
ep_bytes: 558bec518b450c8945fc837dfc017402
timestamp: 2013-07-02 21:12:18

Version Info:

0: [No Data]

Win32/Bundpil.BD also known as:

BkavW32.FamVT.DebrisA.Worm
DrWebTrojan.MulDrop4.25343
MicroWorld-eScanGen:Variant.Zusy.325289
CAT-QuickHealTrojan.Agent.WL
SkyhighDownloader-FOB!A530E4436C68
McAfeeDownloader-FOB!A530E4436C68
MalwarebytesWorm.Agent.SM
ZillyaWorm.DebrisGen.Win32.3
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f52e1 )
K7GWTrojan ( 0040f52e1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36802.aq4@aubLRpe
VirITWorm.Win32.Generic.BRR
SymantecW32.Dromedan
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bundpil.BD
APEXMalicious
TrendMicro-HouseCallWORM_GAMARUE.SMF
ClamAVWin.Worm.Debris-4
KasperskyWorm.Win32.Debris.al
BitDefenderGen:Variant.Zusy.325289
NANO-AntivirusTrojan.Win32.Debris.cfjcok
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Sg-C [Trj]
RisingWorm.Gamarue!1.9CC6 (CLASSIC)
EmsisoftGen:Variant.Zusy.325289 (B)
F-SecureWorm.WORM/Gamarue.358494
BaiduWin32.Worm.Bundpil.al
VIPREGen:Variant.Zusy.325289
TrendMicroWORM_GAMARUE.SMF
FireEyeGeneric.mg.a530e4436c68f6f0
SophosW32/Gamarue-BJ
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
JiangminWorm/Debris.k
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Gamarue.358494
VaristW32/Csyr.C.gen!Eldorado
Antiy-AVLWorm/Win32.Debris.al
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Andromeda.SIB!MTB
XcitiumWorm.Win32.Bundpil.BL@4zjaeb
ArcabitTrojan.Zusy.D4F6A9
ViRobotTrojan.Win32.Agent.3584.AX
ZoneAlarmWorm.Win32.Debris.al
GDataWin32.Trojan.PSE1.RMRK9G
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R73096
Acronissuspicious
VBA32Worm.Debris
ALYacGen:Variant.Zusy.325289
TACHYONWorm/W32.Debris.3584.C
Cylanceunsafe
PandaTrj/Vilsel.AF
TencentWorm.Win32.Debris.b
IkarusWorm.Win32.Debris
FortinetW32/Bundpil.AA!tr
AVGWin32:Sg-C [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Gamarue.efadea61

How to remove Win32/Bundpil.BD?

Win32/Bundpil.BD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment