Worm

Worm:Win32/Eggnog!pz malicious file

Malware Removal

The Worm:Win32/Eggnog!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Worm:Win32/Eggnog!pz?


File Info:

name: 468ACDADE60D3A03A6F2.mlw
path: /opt/CAPEv2/storage/binaries/b7496399d8ab9221ccdd5302261caa6eefc8d8dd318911e075657a92d98ab9df
crc32: 9604DA34
md5: 468acdade60d3a03a6f229b3ca88b932
sha1: edfd14844813ac05856013bf5d7b0a393cacc4fb
sha256: b7496399d8ab9221ccdd5302261caa6eefc8d8dd318911e075657a92d98ab9df
sha512: af2601eab0f93ed7f27a58c2d6d8972c1ca3937388317ef7859eb0dd871cf230d86fbb0bcacfcb2dd816ada0cd291c7badcc64ffba337b0d8260287aa94d68df
ssdeep: 1536:Vsqqf8w1Z5hw8D7lirvqVO9JtOXHb859KIB526Vj1qXU969YJu3+Qryx7:V6J1ZZDJiWVO9JQXHAWIiwjqU969YJRx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17DA3F153F692D9B2D05098FEEE076818DBB73A702E0450C2EFF91FDE6D1E590092C15A
sha3_384: 63b41088bf1732c47a04ba2e21a2fad8b7179562192618261c25b9273d05292c77b47722f9747746d5a28bc2c109950b
ep_bytes: 558bec83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog!pz also known as:

BkavW32.FamVT.EggogK.Worm
CynetMalicious (score: 100)
CAT-QuickHealWorm.GenericPMF.S23529727
SkyhighBehavesLike.Win32.Eggnog.nc
McAfeeW32/Eggnog.worm.gen
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Cospet.Win32.221
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005a7b871 )
K7GWEmailWorm ( 005a7b871 )
Cybereasonmalicious.44813a
ArcabitTrojan.P2P-Worm.E01429
BitDefenderThetaAI:Packer.7AD7063921
VirITTrojan.Win32.Generic.BBBU
SymantecW32.Nofer.A@mm!g1
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Eggnog.E
APEXMalicious
ClamAVWin.Worm.Fearso-7358009-0
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Trojan.P2P-Worm.gGZ@aCrxLBb
NANO-AntivirusTrojan.Win32.Kazaa.iaroor
MicroWorld-eScanGen:Trojan.P2P-Worm.gGZ@aCrxLBb
AvastWin32:WormX-gen [Wrm]
TencentWorm.Win32.Eggnog.a
EmsisoftGen:Trojan.P2P-Worm.gGZ@aCrxLBb (B)
BaiduWin32.Worm.Eggnog.a
F-SecureDropper.DR/Delphi.Gen
DrWebWin32.HLLW.Google.24577
VIPREGen:Trojan.P2P-Worm.gGZ@aCrxLBb
TrendMicroWORM_EGGNOG.SMI
SophosW32/Eggnog-Fam
IkarusTrojan-Dropper.Delf
JiangminTrojan/Cospet.gv
WebrootW32.Worm.Eggnog.Gen
VaristW32/Eggnog.A.gen!Eldorado
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Win32.Dorv
MicrosoftWorm:Win32/Eggnog!pz
ZoneAlarmUDS:Trojan.Win32.Generic
GDataWin32.Worm.Fearso.A
GoogleDetected
AhnLab-V3Worm/Win32.Eggnog.R66977
Acronissuspicious
VBA32BScope.Worm.Pluto
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallWORM_EGGNOG.SMI
RisingWorm.Eggnog!1.E840 (CLASSIC)
YandexWorm.Eggnog!gbIvyzPXjQg
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.W32.Eggnog.F
FortinetW32/Eggnog.E!worm
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Eggnog!pz?

Worm:Win32/Eggnog!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment