Hidden inside the decoy is a second-stage payload called . Once executed, this DLL does not break your computer immediately. Instead, it uses a technique called "process hollowing" to inject code into svchost.exe .
Users searching for "1337x Bugonia" are likely not looking for ancient Roman beekeeping. They are looking for a file. Here is what is actually happening: 1337x bugonia