Worm

About “Worm:Win32/Eggnog!pz” infection

Malware Removal

The Worm:Win32/Eggnog!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Worm:Win32/Eggnog!pz?


File Info:

name: 4A8B434195A451BA951D.mlw
path: /opt/CAPEv2/storage/binaries/b371ab4041987cca840cc70db2f4a3123c039c3a5cf473f50cf244f9174df9be
crc32: 5124FF43
md5: 4a8b434195a451ba951d097004c9d55f
sha1: 3a6097f733e6ffeb6add356091a465adfc857ce2
sha256: b371ab4041987cca840cc70db2f4a3123c039c3a5cf473f50cf244f9174df9be
sha512: d3a74007678d3c2299eb8d3efab3c4585dd28958c1240f92d67c4e3a87361a9277f003d5fae0fdef16237bacde60faa6e164d7c73b96be18928fd1e48f22e2e0
ssdeep: 768:ooixwqZOoQs1oRAqvQi+AFN2T6rH8E9+3KYR8BrvqVWn3NoEQ:ovKqZZQs1ShQi7+q0birvqVO9oEQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A139D03F2D1C9B2C05089FE9D03B929EB7B3B602E5954936DF52FCE6D1A280592D19F
sha3_384: ba0f80accb76c4b11373d052baba02e0d1598ab95b82807727ee5fa5b5b91a54ed798f454dd8a89103b8b144bb635e09
ep_bytes: 558bec83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog!pz also known as:

BkavW32.FamVT.EggogK.Worm
LionicWorm.Win32.Eggnog.tr6O
CynetMalicious (score: 100)
FireEyeGeneric.mg.4a8b434195a451ba
CAT-QuickHealWorm.Eggnog.S28830318
SkyhighBehavesLike.Win32.Eggnog.ph
ALYacGen:Trojan.P2P-Worm.cGY@aa4wiCi
Cylanceunsafe
ZillyaTrojan.Cospet.Win32.221
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005a7b871 )
AlibabaWorm:Win32/Eggnog.f2b3
K7GWTrojan ( 000a4e6a1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.P2P-Worm.E48FE6
BitDefenderThetaAI:Packer.F39AB5E321
VirITTrojan.Win32.Generic.BBBU
SymantecW32.Nofer.A@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Eggnog.E
APEXMalicious
ClamAVWin.Worm.Eggnog-1
KasperskyP2P-Worm.Win32.Eggnog.f
BitDefenderGen:Trojan.P2P-Worm.cGY@aa4wiCi
NANO-AntivirusTrojan.Win32.Eggnog.qxemv
MicroWorld-eScanGen:Trojan.P2P-Worm.cGY@aa4wiCi
AvastWin32:WormX-gen [Wrm]
TencentWorm.Win32.Eggnog.a
SophosW32/Eggnog-Fam
BaiduWin32.Worm.Eggnog.a
F-SecureDropper.DR/Delphi.Gen
DrWebWin32.HLLW.Google.24577
VIPREGen:Trojan.P2P-Worm.cGY@aa4wiCi
TrendMicroWORM_EGGNOG.SMI
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.P2P-Worm.cGY@aa4wiCi (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Cospet.gv
WebrootW32.Worm.Eggnog.Gen
GoogleDetected
AviraDR/Delphi.Gen
Antiy-AVLWorm[P2P]/Win32.Eggnog
KingsoftWin32.Troj.Undef.a
XcitiumTrojWare.Win32.Cospet.X0@1mafpo
MicrosoftWorm:Win32/Eggnog!pz
ViRobotWorm.Win32.A.P2P-Eggnog.36850
ZoneAlarmP2P-Worm.Win32.Eggnog.f
GDataWin32.Worm.Fearso.A
VaristW32/Eggnog.A.gen!Eldorado
AhnLab-V3Worm/Win32.Eggnog.R66977
Acronissuspicious
McAfeeW32/Eggnog.worm.gen
MAXmalware (ai score=80)
VBA32BScope.Worm.Pluto
MalwarebytesGeneric.Trojan.Delf.DDS
PandaGeneric Malware
TrendMicro-HouseCallWORM_EGGNOG.SMI
RisingWorm.Eggnog!1.E840 (CLASSIC)
YandexTrojan.GenAsa!9WQyNROzKr8
IkarusWorm.Win32.Eggnog
MaxSecureWorm.W32.Eggnog.F
FortinetW32/Eggnog.E!worm
AVGWin32:WormX-gen [Wrm]
Cybereasonmalicious.733e6f
DeepInstinctMALICIOUS

How to remove Worm:Win32/Eggnog!pz?

Worm:Win32/Eggnog!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment