Worm

What is “Worm.Eggnog”?

Malware Removal

The Worm.Eggnog is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Eggnog virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Worm.Eggnog?


File Info:

name: 6C9B3BCD0F9A39F8CF04.mlw
path: /opt/CAPEv2/storage/binaries/de307efdc75f1b0992e9c9aaed1bbca1ad11b30e1a7da82777e32c5aff6f46cc
crc32: 1F4B8698
md5: 6c9b3bcd0f9a39f8cf0438f33084d144
sha1: c61c433b76123fd4c42d641a31a3b2da1c75b288
sha256: de307efdc75f1b0992e9c9aaed1bbca1ad11b30e1a7da82777e32c5aff6f46cc
sha512: 6d3fbefe10d100a00641a11f3356a2cd4c2d6c7d09db7f00e058c028c96bfc208198ed33d75156a40efc7a8bd3bcbda7c9a4a23a322b5603a0675c606ba22d2b
ssdeep: 768:LoixwqZOoQs1oRAqvQi+AFN2T6rH8E9+3KEa8Brvq:LvKqZZQs1ShQi7+q0bVrvq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128838D43F6E1D972C050C5FD9D07B628AA3F7A602D1414D3AAF51FCE6D2A24C5D2C2AB
sha3_384: 797bf6cd490e9b858281f2c94cfd80add338946a134e954334a659430f6f9ff4b6ddaef4894b0239175361bdbde0d735
ep_bytes: 00000000000000000000000000000000
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm.Eggnog also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
ClamAVWin.Worm.Eggnog-1
FireEyeGeneric.mg.6c9b3bcd0f9a39f8
McAfeeArtemis!6C9B3BCD0F9A
MalwarebytesWorm.Eggnog
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005a38561 )
K7AntiVirusTrojan ( 005a38561 )
BaiduWin32.Worm.Eggnog.a
VirITWorm.Win32.Eggnog.B
CyrenW32/Eggnog.K.gen!Eldorado
SymantecW32.Nofer.A@mm
ESET-NOD32a variant of Win32/Delf_AGen.P
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
TACHYONTrojan/W32.Agent.81920.DSK
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.mz
Trapminemalicious.moderate.ml.score
IkarusTrojan-Dropper.Agent
GDataWin32.Trojan.Agent.1LDNVP
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Evo-gen.R574932
Cylanceunsafe
RisingTrojan.Kryptik!1.BB30 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Delf.AGEN!worm
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.b76123
DeepInstinctMALICIOUS

How to remove Worm.Eggnog?

Worm.Eggnog removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment