Malware

Win32:Eggnog [Wrm] information

Malware Removal

The Win32:Eggnog [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Eggnog [Wrm] virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Win32:Eggnog [Wrm]?


File Info:

name: 76401751BB7F3E1DD98B.mlw
path: /opt/CAPEv2/storage/binaries/850cc7f0d53d9698d3b750bacd73242a9957840bdbdc2e73ca559f37d297842a
crc32: F0D43142
md5: 76401751bb7f3e1dd98b7025110c787b
sha1: 404bd0e1946f922809364f2e93b12de4e4782a1b
sha256: 850cc7f0d53d9698d3b750bacd73242a9957840bdbdc2e73ca559f37d297842a
sha512: a7b42b9b99e20bdea730444c86c05859dba3f06cbd985038825eacc5c21d7ced42f34b16aaf05c7870cd637d335f1b3e8c66904bf2e09835cd8964f19cd03428
ssdeep: 768:2CmgvL73+kEJ63H8Uu+3KoNMCRQ7wQcOHcF4o6Qf9iGIooeomi9sfaPP4o:2CXvtOyymQRiZ6qXIjj9zQo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A23BF53F5C08973C9A286FCDD07D229BEAE7B105E01189B2FF90F8DD969507493E1A1
sha3_384: 518d7907aca173f0d201f9273d8a56b1de7629c296b93841c61938daf511b929f7a18a3db3035f6fe2bd48adcf4d3f5c
ep_bytes: 558bec83c4f0b81c584000e84cd1ffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32:Eggnog [Wrm] also known as:

BkavW32.FamVT.EggogKA.Worm
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Google.24576
MicroWorld-eScanGen:Trojan.P2P-Worm.dGY@aGDgc0g
CAT-QuickHealWorm.Eggnog.B8
ALYacGen:Trojan.P2P-Worm.dGY@aGDgc0g
CylanceUnsafe
ZillyaWorm.Eggnog.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 00556f041 )
K7GWEmailWorm ( 005327141 )
Cybereasonmalicious.1bb7f3
BitDefenderThetaAI:Packer.67EA300321
CyrenW32/Eggnog.VVTN-2043
SymantecW32.HLLW.Eggnog
ESET-NOD32Win32/Eggnog.A
TrendMicro-HouseCallWORM_EGGNOG.SMI
ClamAVWin.Worm.Fearso-7358009-0
KasperskyP2P-Worm.Win32.Eggnog.a
BitDefenderGen:Trojan.P2P-Worm.dGY@aGDgc0g
NANO-AntivirusTrojan.Win32.Eggnog.emlu
SUPERAntiSpywareTrojan.Agent/Gen-Eggnog
AvastWin32:Eggnog [Wrm]
RisingWorm.P2p.Eggnog.a (CLASSIC)
Ad-AwareGen:Trojan.P2P-Worm.dGY@aGDgc0g
EmsisoftGen:Trojan.P2P-Worm.dGY@aGDgc0g (B)
ComodoWorm.Win32.Eggnog.A@2e2v
BaiduWin32.Worm.Eggnog.a
VIPREBehavesLike.Win32.Malware.tsc (mx-v)
TrendMicroWORM_EGGNOG.SMI
McAfee-GW-EditionBehavesLike.Win32.Eggnog.pc
FireEyeGeneric.mg.76401751bb7f3e1d
SophosML/PE-A + W32/Eggnog-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Fearso.A
JiangminWorm/Eggnog.edc
eGambitUnsafe.AI_Score_100%
AviraWORM/Eggnog.A
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASBOL.BAC
ArcabitTrojan.P2P-Worm.E6BA10
ViRobotWorm.Win32.Eggnog.25017
MicrosoftWorm:Win32/Eggnog.A
CynetMalicious (score: 100)
AhnLab-V3Win32/Eggnog.worm.25017
Acronissuspicious
McAfeeW32/Eggnog.worm.gen
VBA32Worm.Eggnog
MalwarebytesMalware.AI.2878212836
APEXMalicious
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!EU7uvRL87VA
IkarusEmail-Worm.Win32.Fearso
MaxSecureWorm.Eggnog.a
FortinetW32/Eggnog.E!worm
AVGWin32:Eggnog [Wrm]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:Eggnog [Wrm]?

Win32:Eggnog [Wrm] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment