Worm

Worm:Win32/Eggnog!pz removal guide

Malware Removal

The Worm:Win32/Eggnog!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself

How to determine Worm:Win32/Eggnog!pz?


File Info:

name: 737E1A1C93EE1957FBF9.mlw
path: /opt/CAPEv2/storage/binaries/5416a8009da1311db9f054329423763f29b2c970fadf51e3d40528a0c93593aa
crc32: C7D297CA
md5: 737e1a1c93ee1957fbf998b5bd709533
sha1: 9cd6bbc40a46ff3550273cf4b7f7288e1119dec6
sha256: 5416a8009da1311db9f054329423763f29b2c970fadf51e3d40528a0c93593aa
sha512: 4a8cd4d11bc7cff5356f1c846e669f4ab2e674f7d80fd460582a42a528ecf4e6b71696b8d7a915b6bdf2d3aac6b858438c9bc9cee5b33b304f630bceb826cdda
ssdeep: 1536:ovKqZZQs1ShQi7+q0birvqVO9ylgVZ9cmwFHQlkQ15se4:ovZx1UGpiWVO9yl6cwl1sH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A863E103F1D0DA77C180C9FE6D07B968A6367F702E4988E299F62F8E2D1D1405D1D29B
sha3_384: e8c2f6748fc3d5a2d6c8d76a175762b47c273ee0f09c05c00ce4d2cf0bd6ac2633c4fefce2b24e55ed9483e6f9f8da66
ep_bytes: 558bec83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog!pz also known as:

BkavW32.FamVT.EggogK.Worm
MicroWorld-eScanGen:Trojan.P2P-Worm.eGZ@aa4wiCi
ClamAVWin.Worm.Eggnog-1
CAT-QuickHealWorm.Eggnog.S28830318
SkyhighBehavesLike.Win32.Eggnog.kc
McAfeeW32/Eggnog.worm.gen
MalwarebytesGeneric.Trojan.Delf.DDS
ZillyaTrojan.Cospet.Win32.221
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005a7b871 )
K7GWTrojan ( 000a4e6a1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.P2P-Worm.EA20BD
BitDefenderThetaAI:Packer.CA9D0C3F21
VirITTrojan.Win32.Generic.BBBU
SymantecW32.Nofer.A@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Eggnog.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Eggnog.f
BitDefenderGen:Trojan.P2P-Worm.eGZ@aa4wiCi
NANO-AntivirusTrojan.Win32.Eggnog.qxemv
AvastWin32:WormX-gen [Wrm]
TencentWorm.Win32.Eggnog.a
SophosW32/Eggnog-Fam
BaiduWin32.Worm.Eggnog.a
F-SecureDropper.DR/Delphi.Gen
DrWebWin32.HLLW.Google.24577
VIPREGen:Trojan.P2P-Worm.eGZ@aa4wiCi
TrendMicroWORM_EGGNOG.SMI
EmsisoftGen:Trojan.P2P-Worm.eGZ@aa4wiCi (B)
IkarusWorm.Win32.Eggnog
JiangminTrojan/Cospet.gv
WebrootW32.Worm.Eggnog.Gen
GoogleDetected
AviraDR/Delphi.Gen
Antiy-AVLWorm[P2P]/Win32.Eggnog
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Cospet.X0@1mafpo
MicrosoftWorm:Win32/Eggnog!pz
ViRobotWorm.Win32.A.P2P-Eggnog.36850
ZoneAlarmP2P-Worm.Win32.Eggnog.f
GDataWin32.Worm.Fearso.A
VaristW32/Eggnog.A.gen!Eldorado
AhnLab-V3Worm/Win32.Eggnog.R66977
Acronissuspicious
VBA32BScope.Worm.Pluto
MAXmalware (ai score=81)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_EGGNOG.SMI
RisingWorm.Eggnog!1.E840 (CLASSIC)
YandexTrojan.GenAsa!9WQyNROzKr8
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.W32.Eggnog.F
FortinetW32/Eggnog.E!worm
AVGWin32:WormX-gen [Wrm]
Cybereasonmalicious.40a46f
DeepInstinctMALICIOUS

How to remove Worm:Win32/Eggnog!pz?

Worm:Win32/Eggnog!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment