Worm

Worm:Win32/Eggnog.A information

Malware Removal

The Worm:Win32/Eggnog.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog.A virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Worm:Win32/Eggnog.A?


File Info:

name: 1741C5AA8237286BA38B.mlw
path: /opt/CAPEv2/storage/binaries/7f1e0b9f406a4df549c9df262f0e083ab63725da59feed48d764d6d235dce7e9
crc32: FEA472F2
md5: 1741c5aa8237286ba38bf82d561aa44c
sha1: 66395a5126f1c4df3dc16211fb3d881ca754a152
sha256: 7f1e0b9f406a4df549c9df262f0e083ab63725da59feed48d764d6d235dce7e9
sha512: 074add03b2f0e3d659ead80424b8aab476b5f902934a8a891a06eafd84bb33cc9712e5e526b49d7950f38f1a5d4b2e7bad879b434785c620a2fd438c741b61ce
ssdeep: 768:2CmgvL73+kEJ63H8Uu+3KoNMCRQ7wQcOHcF4o6Qf9iGIooeomi9sff6O:2CXvtOyymQRiZ6qXIjj96H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D333CF42F5C08973C9A186FCDD07E229BE6EBB111E11189B3FF90F8DD969507483E2A1
sha3_384: 128442181338f1193e554837be24e333f0182809d478455273c9281a598897c242cab6c6855a1a90797c986c563ee6be
ep_bytes: 558bec83c4f0b81c584000e84cd1ffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog.A also known as:

BkavW32.FamVT.EggogKA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.P2P-Worm.dGY@aGDgc0g
FireEyeGeneric.mg.1741c5aa8237286b
CAT-QuickHealWorm.Eggnog.B8
ALYacGen:Trojan.P2P-Worm.dGY@aGDgc0g
CylanceUnsafe
ZillyaWorm.Eggnog.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 00556f041 )
K7GWEmailWorm ( 005327141 )
Cybereasonmalicious.a82372
BitDefenderThetaAI:Packer.67EA300321
CyrenW32/Eggnog.VVTN-2043
SymantecW32.HLLW.Eggnog
ESET-NOD32Win32/Eggnog.A
BaiduWin32.Worm.Eggnog.a
TrendMicro-HouseCallWORM_EGGNOG.SMI
ClamAVWin.Worm.Fearso-7358009-0
KasperskyP2P-Worm.Win32.Eggnog.a
BitDefenderGen:Trojan.P2P-Worm.dGY@aGDgc0g
NANO-AntivirusTrojan.Win32.Eggnog.emlu
AvastWin32:Eggnog [Wrm]
RisingWorm.P2p.Eggnog.a (CLASSIC)
Ad-AwareGen:Trojan.P2P-Worm.dGY@aGDgc0g
SophosML/PE-A + W32/Eggnog-A
ComodoWorm.Win32.Eggnog.A@2e2v
DrWebWin32.HLLW.Google.24576
VIPREBehavesLike.Win32.Malware.tsc (mx-v)
TrendMicroWORM_EGGNOG.SMI
McAfee-GW-EditionBehavesLike.Win32.Eggnog.pc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Trojan.P2P-Worm.dGY@aGDgc0g (B)
APEXMalicious
GDataWin32.Worm.Fearso.A
JiangminWorm/Eggnog.edc
MaxSecureWorm.Eggnog.a
AviraWORM/Eggnog.A
Antiy-AVLTrojan/Generic.ASBOL.BAC
ArcabitTrojan.P2P-Worm.E6BA10
ViRobotWorm.Win32.Eggnog.25017
MicrosoftWorm:Win32/Eggnog.A
CynetMalicious (score: 100)
AhnLab-V3Win32/Eggnog.worm.25017
Acronissuspicious
McAfeeW32/Eggnog.worm.gen
MAXmalware (ai score=84)
VBA32Worm.Eggnog
MalwarebytesMalware.AI.2878212836
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!EU7uvRL87VA
IkarusEmail-Worm.Win32.Fearso
eGambitUnsafe.AI_Score_100%
FortinetW32/Eggnog.E!worm
AVGWin32:Eggnog [Wrm]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Eggnog.A?

Worm:Win32/Eggnog.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment