Worm

Worm:Win32/Eggnog!pz removal tips

Malware Removal

The Worm:Win32/Eggnog!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Worm:Win32/Eggnog!pz?


File Info:

name: 9F3B02A47D134B7F9482.mlw
path: /opt/CAPEv2/storage/binaries/d409216ce4135db85a10579e5b38be13cf808cac76060dc4ec86ab93fe424b85
crc32: CB46CE11
md5: 9f3b02a47d134b7f9482923a8fec4be1
sha1: 8e4bafbe53aa617e47c6e40141b8cc044af0f491
sha256: d409216ce4135db85a10579e5b38be13cf808cac76060dc4ec86ab93fe424b85
sha512: 4bb325fcb0f32a7c96bfb6b73a54f7c3694ffd440faf7d01ae422f5e9a398cc6e526e0c6eb4e6b8c9f913d7ab3a2e6549c1e2bca15c639005872ff4b871c1f2a
ssdeep: 768:ooixwqZOoQs1oRAqvQi+AFN2T6rH8E9+3KYR8BrvqVWn3Nyuk2fd7Mmt:ovKqZZQs1ShQi7+q0birvqVO9yuz1g2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A123BF03F2D1D972C150D5FE9D03B528EB7B3A203E5844A36AF12FCEAD1A2405D2D29B
sha3_384: 3e9ac19af47dcdd83f6a7251390796cec68c6c054876ed34432e91317feb63d9b3b7fc2e938f9c2e45e3f1244c1fef93
ep_bytes: 558bec83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog!pz also known as:

BkavW32.FamVT.EggogK.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.P2P-Worm.cGY@aa4wiCi
ClamAVWin.Worm.Eggnog-1
CAT-QuickHealTrojan.GenericPMF.S28915931
SkyhighBehavesLike.Win32.Eggnog.ph
McAfeeW32/Eggnog.worm.gen
Cylanceunsafe
ZillyaTrojan.Cospet.Win32.221
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005a7b871 )
K7GWTrojan ( 000a4e6a1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Eggnog.a
VirITTrojan.Win32.Generic.BBBU
SymantecW32.Nofer.A@mm
ESET-NOD32Win32/Eggnog.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Eggnog.f
BitDefenderGen:Trojan.P2P-Worm.cGY@aa4wiCi
NANO-AntivirusTrojan.Win32.Eggnog.qxemv
AvastWin32:WormX-gen [Wrm]
TencentWorm.Win32.Eggnog.a
EmsisoftGen:Trojan.P2P-Worm.cGY@aa4wiCi (B)
F-SecureDropper.DR/Delphi.Gen
DrWebWin32.HLLW.Google.24577
VIPREGen:Trojan.P2P-Worm.cGY@aa4wiCi
TrendMicroWORM_EGGNOG.SMI
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9f3b02a47d134b7f
SophosW32/Eggnog-Fam
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Cospet.gv
WebrootW32.Worm.Eggnog.Gen
GoogleDetected
AviraDR/Delphi.Gen
MAXmalware (ai score=88)
Antiy-AVLWorm[P2P]/Win32.Eggnog
MicrosoftWorm:Win32/Eggnog!pz
XcitiumTrojWare.Win32.Cospet.X0@1mafpo
ArcabitTrojan.P2P-Worm.E48FE6
ViRobotWorm.Win32.A.P2P-Eggnog.36850
ZoneAlarmP2P-Worm.Win32.Eggnog.f
GDataWin32.Worm.Fearso.A
VaristW32/Eggnog.A.gen!Eldorado
AhnLab-V3Worm/Win32.Eggnog.R66977
Acronissuspicious
VBA32BScope.Worm.Pluto
ALYacGen:Trojan.P2P-Worm.cGY@aa4wiCi
MalwarebytesGeneric.Trojan.Delf.DDS
PandaGeneric Malware
TrendMicro-HouseCallWORM_EGGNOG.SMI
RisingWorm.Eggnog!1.E840 (CLASSIC)
YandexTrojan.GenAsa!9WQyNROzKr8
IkarusWorm.Win32.Eggnog
MaxSecureWorm.W32.Eggnog.F
FortinetW32/Eggnog.E!worm
BitDefenderThetaAI:Packer.F39AB5E321
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Eggnog!pz?

Worm:Win32/Eggnog!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment