Worm

Worm:Win32/Eggnog!pz malicious file

Malware Removal

The Worm:Win32/Eggnog!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Worm:Win32/Eggnog!pz?


File Info:

name: E67F42223EEFFB9623C4.mlw
path: /opt/CAPEv2/storage/binaries/48bf70e4bedb87396e5d9f5e1b6aaacc3c899b1972113a90d0a2b460b3fdfed2
crc32: 4490AEDF
md5: e67f42223eeffb9623c4efef6a191de6
sha1: 21f7794de0f86afa03388f4f20051e990fd1902a
sha256: 48bf70e4bedb87396e5d9f5e1b6aaacc3c899b1972113a90d0a2b460b3fdfed2
sha512: cf22f682e94192b597aa2d5724f59ee6b155c2d7b2a2a49d427c6ca3432aa6e0a165fe8d21677dbd8dac8b15b959e32cb19c3716e0efb2bb02d8a49289d6f087
ssdeep: 1536:4MvKqZZQs1ShQi7+q0birvqqO9yBIXclqeEyz4N3e/:ZvZx1UGpiWqO9yqNhFe/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16363CF43F1C1CD77C28089FEAD47E528967F7A202E8554D228F13FCE5E1A690AE2D15B
sha3_384: 187305819bf68eb644ece97f50333b0c8f8f519c82b47d22579ab1d220585258b8c4dd13e42a2db87700f4a8096eb39f
ep_bytes: 558bec83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.P2P-Worm.eKZ@au9m8eo
ClamAVWin.Worm.Eggnog-1
FireEyeGeneric.mg.e67f42223eeffb96
CAT-QuickHealTrojan.GenericPMF.S30437502
SkyhighBehavesLike.Win32.Eggnog.lc
McAfeeW32/Eggnog.worm.gen
MalwarebytesGeneric.Trojan.Delf.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005a7b871 )
K7GWTrojan ( 000a4e6a1 )
Cybereasonmalicious.de0f86
BaiduWin32.Worm.Eggnog.a
VirITTrojan.Win32.Generic.BBBU
SymantecW32.Nofer.A@mm
ESET-NOD32Win32/Eggnog.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Eggnog.f
BitDefenderGen:Trojan.P2P-Worm.eKZ@au9m8eo
NANO-AntivirusTrojan.Win32.Eggnog.qxemv
AvastWin32:Evo-gen [Trj]
TencentWorm.Win32.Eggnog.a
SophosW32/Eggnog-Fam
F-SecureDropper.DR/Delphi.Gen
DrWebWin32.HLLW.Google.24577
ZillyaWorm.Eggnog.Win32.52
TrendMicroWORM_EGGNOG.SMI
EmsisoftGen:Trojan.P2P-Worm.eKZ@au9m8eo (B)
IkarusWorm.Win32.Eggnog
GDataWin32.Worm.Fearso.A
JiangminTrojan/Cospet.gv
WebrootW32.Worm.Eggnog.Gen
GoogleDetected
AviraDR/Delphi.Gen
MAXmalware (ai score=82)
Antiy-AVLWorm[P2P]/Win32.Eggnog
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Cospet.X0@1mafpo
ArcabitTrojan.P2P-Worm.E921FE
ViRobotWorm.Win32.A.P2P-Eggnog.36850
ZoneAlarmP2P-Worm.Win32.Eggnog.f
MicrosoftWorm:Win32/Eggnog!pz
VaristW32/Eggnog.A2.gen!Eldorado
AhnLab-V3Worm/Win32.Eggnog.C3534480
Acronissuspicious
BitDefenderThetaAI:Packer.705B547921
ALYacGen:Trojan.P2P-Worm.eKZ@au9m8eo
VBA32BScope.Worm.Pluto
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_EGGNOG.SMI
RisingWorm.Eggnog!1.E840 (CLASSIC)
YandexTrojan.GenAsa!9WQyNROzKr8
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.W32.Eggnog.F
FortinetW32/Eggnog.E!worm
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Eggnog!pz?

Worm:Win32/Eggnog!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment