Worm

Worm:Win32/Eggnog!pz (file analysis)

Malware Removal

The Worm:Win32/Eggnog!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Worm:Win32/Eggnog!pz?


File Info:

name: BB0BCD13FB428F1B999A.mlw
path: /opt/CAPEv2/storage/binaries/f0620b8951436d9494b8a31ec28ac23308c75d939dcf80c87d2e7bd9c0eb05ee
crc32: 40C2EDAD
md5: bb0bcd13fb428f1b999af8a16fe4b74d
sha1: 137a83bbc6c9840b165ee2d6e310d4ab43f61687
sha256: f0620b8951436d9494b8a31ec28ac23308c75d939dcf80c87d2e7bd9c0eb05ee
sha512: 32f088d58a27cb12494b4ff34a3b39ba576455791c1a4f6a68a981a9ecb6a0da558c466dfca81de3c1b7fd14b9fe3c577037d95b0aea727ed270efb57f61c2ab
ssdeep: 1536:Vsqqf8w1Z5hw8D7lirvqVO9JtOXHb859K4Ql6T6:V6J1ZZDJiWVO9JQXHAW1l6T6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14153D003F2D1ED72C090C8BE9D06B819AFBA3B202E415492FEF91F8F6D1A150492D19F
sha3_384: 59ea403082bd59b35f30afa3cf3618f2679b1b247f4cacbe64b7a85af0501a8052b8f59112cd16de2a15afd3f7c38101
ep_bytes: 558bec83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog!pz also known as:

BkavW32.FamVT.EggogK.Worm
MicroWorld-eScanGen:Trojan.P2P-Worm.eGZ@aCrxLBb
CAT-QuickHealWorm.Eggnog.S28830318
SkyhighBehavesLike.Win32.Eggnog.kc
McAfeeW32/Eggnog.worm.gen
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.P2P-Worm.eGZ@aCrxLBb
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005a7b871 )
K7GWTrojan ( 000a4e6a1 )
Cybereasonmalicious.3fb428
BaiduWin32.Worm.Eggnog.a
VirITTrojan.Win32.Generic.BBBU
SymantecW32.Nofer.A@mm!g1
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Eggnog.E
APEXMalicious
TrendMicro-HouseCallWORM_EGGNOG.SMI
ClamAVWin.Worm.Fearso-7358009-0
KasperskyVHO:Trojan.Win32.Cospet.gen
BitDefenderGen:Trojan.P2P-Worm.eGZ@aCrxLBb
NANO-AntivirusTrojan.Win32.Kazaa.iaroor
AvastWin32:WormX-gen [Wrm]
EmsisoftGen:Trojan.P2P-Worm.eGZ@aCrxLBb (B)
F-SecureDropper.DR/Delphi.Gen
DrWebWin32.HLLW.Google.24577
ZillyaTrojan.Cospet.Win32.221
TrendMicroWORM_EGGNOG.SMI
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bb0bcd13fb428f1b
SophosW32/Eggnog-Fam
IkarusTrojan-Dropper.Delf
JiangminTrojan/Cospet.gv
WebrootW32.Worm.Eggnog.Gen
GoogleDetected
AviraDR/Delphi.Gen
VaristW32/Eggnog.A.gen!Eldorado
Antiy-AVLTrojan/Win32.Dorv
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Eggnog!pz
ArcabitTrojan.P2P-Worm.E357D5
ZoneAlarmVHO:Trojan.Win32.Cospet.gen
GDataWin32.Worm.Fearso.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Eggnog.R66977
Acronissuspicious
BitDefenderThetaAI:Packer.1A8BB37221
ALYacGen:Trojan.P2P-Worm.eGZ@aCrxLBb
MAXmalware (ai score=84)
VBA32BScope.Worm.Pluto
Cylanceunsafe
RisingWorm.Eggnog!1.E840 (CLASSIC)
YandexWorm.Eggnog!gbIvyzPXjQg
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.W32.Eggnog.F
FortinetW32/Eggnog.E!worm
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Eggnog!pz?

Worm:Win32/Eggnog!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment