Worm

Worm:Win32/Eggnog!pz malicious file

Malware Removal

The Worm:Win32/Eggnog!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Worm:Win32/Eggnog!pz?


File Info:

name: 528DA2F0F45169ABE3FC.mlw
path: /opt/CAPEv2/storage/binaries/35fa1779d776afd7737915f6049320ed67dc27753222744e1499e0032a1546c2
crc32: FDF5DFE7
md5: 528da2f0f45169abe3fc73a9035ddda3
sha1: 043ae5abcc89d13159e9b7a6988f45742cb2ebc4
sha256: 35fa1779d776afd7737915f6049320ed67dc27753222744e1499e0032a1546c2
sha512: b884fbb2cf439b86c0810a0bc190eb5be671382f8349989e03ff08a4185a56d986c4019d7ae3497c8c7e2be1e8dbe153f1fb394b183392e40082c825d5ad960f
ssdeep: 1536:4MvKqZZQs1ShQi7+q0birvqqO9yBIRjQWV3e+Hx83+G8HbAGvgklsdgJMpPb:ZvZx1UGpiWqO9yqK63ey83+RsslsgKPb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14DA3E003F1C1E872C51488FFED63F669917E36613EA548D358B03FCE691F1A06A2D15A
sha3_384: 7cb5d506c140b00a080a7f6b721bea75937d20eddb2c58f9b966372535c12ed49686f1b138ecda03d5cf8b511b646542
ep_bytes: 558bec83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog!pz also known as:

BkavW32.AIDetectMalware
DrWebWin32.HLLW.Google.24577
MicroWorld-eScanGen:Trojan.P2P-Worm.gKZ@au9m8eo
ClamAVWin.Worm.Eggnog-1
CAT-QuickHealTrojan.GenericPMF.S31712645
SkyhighBehavesLike.Win32.Eggnog.cc
McAfeeW32/Eggnog.worm.gen
MalwarebytesGeneric.Trojan.Delf.DDS
VIPREGen:Trojan.P2P-Worm.gKZ@au9m8eo
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005a7b871 )
K7GWEmailWorm ( 005a7b871 )
Cybereasonmalicious.bcc89d
ArcabitTrojan.P2P-Worm.E9E249
BitDefenderThetaAI:Packer.1007E13221
VirITTrojan.Win32.Generic.BBBU
SymantecW32.Nofer.A@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Eggnog.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Eggnog.f
BitDefenderGen:Trojan.P2P-Worm.gKZ@au9m8eo
NANO-AntivirusTrojan.Win32.Eggnog.qxemv
AvastWin32:Evo-gen [Trj]
TencentWorm.Win32.Eggnog.a
EmsisoftGen:Trojan.P2P-Worm.gKZ@au9m8eo (B)
F-SecureDropper.DR/Delphi.Gen
BaiduWin32.Worm.Eggnog.a
ZillyaWorm.Eggnog.Win32.52
TrendMicroWORM_EGGNOG.SMI
FireEyeGeneric.mg.528da2f0f45169ab
SophosW32/Eggnog-Fam
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Cospet.gv
WebrootW32.Worm.Eggnog.Gen
GoogleDetected
AviraDR/Delphi.Gen
MAXmalware (ai score=86)
Antiy-AVLWorm[P2P]/Win32.Eggnog
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Cospet.X0@1mafpo
MicrosoftWorm:Win32/Eggnog!pz
ViRobotWorm.Win32.A.P2P-Eggnog.36850
ZoneAlarmP2P-Worm.Win32.Eggnog.f
GDataWin32.Worm.Fearso.A
VaristW32/Eggnog.A2.gen!Eldorado
AhnLab-V3Worm/Win32.Eggnog.C3534480
Acronissuspicious
VBA32BScope.Worm.Pluto
ALYacGen:Trojan.P2P-Worm.gKZ@au9m8eo
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_EGGNOG.SMI
RisingWorm.Eggnog!1.E840 (CLASSIC)
YandexTrojan.GenAsa!9WQyNROzKr8
IkarusWorm.Win32.Eggnog
MaxSecureWorm.W32.Eggnog.F
FortinetW32/Eggnog.E!worm
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Eggnog!pz?

Worm:Win32/Eggnog!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment