Worm

Worm:Win32/Eggnog!pz removal instruction

Malware Removal

The Worm:Win32/Eggnog!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory

How to determine Worm:Win32/Eggnog!pz?


File Info:

name: 60E4B57802794D304303.mlw
path: /opt/CAPEv2/storage/binaries/a63348262ddd86cc4de9859d9bf51152969d649a19d2697e2ea07532088ead23
crc32: 4D6A72C6
md5: 60e4b57802794d304303a72cd98e5c82
sha1: 0a4d7d3a512af12a8f4115815ea82f2461e40221
sha256: a63348262ddd86cc4de9859d9bf51152969d649a19d2697e2ea07532088ead23
sha512: 978f073de0b71c724867d003cb4ad0a9d0dd773ef7fc5663f2f19d8f9eba48454f9620b0c5743116bc224874fc2944f528a6fd214c69e0bb4caf04f940de1ea9
ssdeep: 3072:V6J1ZZDJiWVO9JQXHAWIiwjqU969YJR2Nt:wJHniWVO9KQHXN969YaNt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EEA3F163F793E9B2C05094BEDE077808DBB63A702E4461C2EEF91FDE6D1E550091D19A
sha3_384: 592f014a442187306ba82bb1555a3833ec1ad87ff9b9d092cb8dbc679758e90fb76f0b83118c33b321a49fcd7e04222f
ep_bytes: 558bec83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog!pz also known as:

BkavW32.FamVT.EggogK.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.P2P-Worm.gGZ@aCrxLBb
CAT-QuickHealWorm.Eggnog.S28830318
SkyhighBehavesLike.Win32.Eggnog.cc
McAfeeW32/Eggnog.worm.gen
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.P2P-Worm.gGZ@aCrxLBb
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005a7b871 )
K7GWEmailWorm ( 005a7b871 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.P2P-Worm.E01429
BaiduWin32.Worm.Eggnog.a
VirITTrojan.Win32.Generic.BBBU
SymantecW32.Nofer.A@mm!g1
ESET-NOD32a variant of Win32/Eggnog.E
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Fearso-7358009-0
KasperskyVHO:Trojan.Win32.Cospet.gen
BitDefenderGen:Trojan.P2P-Worm.gGZ@aCrxLBb
NANO-AntivirusTrojan.Win32.Kazaa.iaroor
AvastWin32:WormX-gen [Wrm]
RisingWorm.Eggnog!1.E840 (CLASSIC)
EmsisoftGen:Trojan.P2P-Worm.gGZ@aCrxLBb (B)
F-SecureDropper.DR/Delphi.Gen
DrWebWin32.HLLW.Google.24577
ZillyaTrojan.Cospet.Win32.221
TrendMicroWORM_EGGNOG.SMI
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.60e4b57802794d30
SophosW32/Eggnog-Fam
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Cospet.gv
WebrootW32.Worm.Eggnog.Gen
VaristW32/Eggnog.A.gen!Eldorado
AviraDR/Delphi.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Dorv
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Eggnog!pz
ZoneAlarmVHO:Trojan.Win32.Cospet.gen
GDataWin32.Worm.Fearso.A
GoogleDetected
AhnLab-V3Worm/Win32.Eggnog.R66977
Acronissuspicious
BitDefenderThetaAI:Packer.7AD7063921
ALYacGen:Trojan.P2P-Worm.gGZ@aCrxLBb
VBA32BScope.Worm.Pluto
Cylanceunsafe
TrendMicro-HouseCallWORM_EGGNOG.SMI
TencentWorm.Win32.Eggnog.a
YandexWorm.Eggnog!gbIvyzPXjQg
IkarusTrojan-Dropper.Delf
MaxSecureWorm.W32.Eggnog.F
FortinetW32/Eggnog.E!worm
AVGWin32:WormX-gen [Wrm]
Cybereasonmalicious.a512af
DeepInstinctMALICIOUS

How to remove Worm:Win32/Eggnog!pz?

Worm:Win32/Eggnog!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment