Worm

What is “Worm:Win32/Eggnog!pz”?

Malware Removal

The Worm:Win32/Eggnog!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory

How to determine Worm:Win32/Eggnog!pz?


File Info:

name: 3698090669B2F4F703DE.mlw
path: /opt/CAPEv2/storage/binaries/8c37af48f8559cc179622fcc94e6f2a7126abe483b8692196cf11f211f0aca4f
crc32: D6FB7062
md5: 3698090669b2f4f703deaa1f5666a9d2
sha1: 17ec44ea7e9260e466dd9ff9539c85a440e079df
sha256: 8c37af48f8559cc179622fcc94e6f2a7126abe483b8692196cf11f211f0aca4f
sha512: cfceaac0fa6728cec344fdaa3668d74a671145d8a0ebf2557206632d3ec7a247adb86a758576d959f5aa96f991aa9fd826475207fbf8b5f49c28812095bb4d45
ssdeep: 1536:4MvKqZZQs1ShQi7+q0birvqqO9yBIXclqeEyz46:ZvZx1UGpiWqO9yqNh6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13463DF43F2C1CD37C14088FEAD47E528967F7A312E8958D268F13FCE691A690AD2D15B
sha3_384: 3bea0f36246a090a55cd2f34fad4d2075a42e9bd06efe7c806b1b6e7d807a73dd152e4b6adb8b0eace43d39e499cc4b0
ep_bytes: 558bec83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Trojan.P2P-Worm.eKZ@au9m8eo
ClamAVWin.Worm.Eggnog-1
CAT-QuickHealTrojan.GenericPMF.S30437502
SkyhighBehavesLike.Win32.Eggnog.kc
McAfeeW32/Eggnog.worm.gen
MalwarebytesGeneric.Trojan.Delf.DDS
VIPREGen:Trojan.P2P-Worm.eKZ@au9m8eo
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 00556f041 )
K7GWTrojan ( 000a4e6a1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.P2P-Worm.E921FE
BaiduWin32.Worm.Eggnog.a
VirITTrojan.Win32.Generic.BBBU
SymantecW32.Nofer.A@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Eggnog.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Eggnog.f
BitDefenderGen:Trojan.P2P-Worm.eKZ@au9m8eo
NANO-AntivirusTrojan.Win32.Eggnog.qxemv
AvastWin32:Evo-gen [Trj]
RisingWorm.Eggnog!1.E840 (CLASSIC)
EmsisoftGen:Trojan.P2P-Worm.eKZ@au9m8eo (B)
F-SecureDropper.DR/Delphi.Gen
DrWebWin32.HLLW.Google.24577
ZillyaWorm.Eggnog.Win32.52
TrendMicroWORM_EGGNOG.SMI
FireEyeGeneric.mg.3698090669b2f4f7
SophosW32/Eggnog-Fam
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Cospet.gv
WebrootW32.Worm.Eggnog.Gen
GoogleDetected
AviraDR/Delphi.Gen
Antiy-AVLWorm[P2P]/Win32.Eggnog
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Cospet.X0@1mafpo
MicrosoftWorm:Win32/Eggnog!pz
ViRobotWorm.Win32.A.P2P-Eggnog.36850
ZoneAlarmP2P-Worm.Win32.Eggnog.f
GDataWin32.Worm.Fearso.A
VaristW32/Eggnog.A2.gen!Eldorado
AhnLab-V3Worm/Win32.Eggnog.C3534480
Acronissuspicious
BitDefenderThetaAI:Packer.705B547921
ALYacGen:Trojan.P2P-Worm.eKZ@au9m8eo
VBA32BScope.Worm.Pluto
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_EGGNOG.SMI
TencentWorm.Win32.Eggnog.a
IkarusWorm.Win32.Eggnog
MaxSecureWorm.W32.Eggnog.F
FortinetW32/Eggnog.E!worm
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.a7e926
DeepInstinctMALICIOUS

How to remove Worm:Win32/Eggnog!pz?

Worm:Win32/Eggnog!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment