Worm

Worm:Win32/Eggnog!pz removal guide

Malware Removal

The Worm:Win32/Eggnog!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Eggnog!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Worm:Win32/Eggnog!pz?


File Info:

name: EBE3D75A2FCCBBDEDDAC.mlw
path: /opt/CAPEv2/storage/binaries/ebcad5cafa70928693e6c923d5fb3f55917777ee6944c39bb55fc3ad447f184b
crc32: 0557BB31
md5: ebe3d75a2fccbbdeddac6227b78fa3e1
sha1: c2a96c03581307211476b218797cd313a829f88a
sha256: ebcad5cafa70928693e6c923d5fb3f55917777ee6944c39bb55fc3ad447f184b
sha512: 3595749d08990f21ad4cd8ed6e7eaed4b18c8bf3d20650de339bbc825a0211cc7494cd813e2d1e98ab54d485ffa6678394267cee82da534702bc3684557fa234
ssdeep: 768:ooixwqZOoQs1oRAqvQi+AFN2T6rH8E9+3KYR8BrvqVWn3NoErhlxJCtDt8JQ:ovKqZZQs1ShQi7+q0birvqVO9oEq0Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17733BE13E2D2C972C05089FE5D02B928FB7F3A612E585493AEF51FCE6D2A250592C1DF
sha3_384: 016cf7c385204b3dff7dd1718b743142f7cf013fe481121fcb743347c35e08fbe6320f828a0cd9c51da0bce33bffee06
ep_bytes: 558bec83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Eggnog!pz also known as:

BkavW32.FamVT.EggogK.Worm
LionicWorm.Win32.Eggnog.tr6O
DrWebWin32.HLLW.Google.24577
MicroWorld-eScanGen:Trojan.P2P-Worm.dGY@aa4wiCi
FireEyeGeneric.mg.ebe3d75a2fccbbde
CAT-QuickHealTrojan.GenericPMF.S28915931
SkyhighBehavesLike.Win32.Eggnog.ph
McAfeeW32/Eggnog.worm.gen
MalwarebytesGeneric.Trojan.Delf.DDS
ZillyaTrojan.Cospet.Win32.221
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005a7b871 )
AlibabaWorm:Win32/Eggnog.f2b3
K7GWTrojan ( 000a4e6a1 )
Cybereasonmalicious.a2fccb
BitDefenderThetaAI:Packer.8EE9B3BB21
VirITTrojan.Win32.Generic.BBBU
SymantecW32.Nofer.A@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Eggnog.E
APEXMalicious
TrendMicro-HouseCallWORM_EGGNOG.SMI
ClamAVWin.Worm.Eggnog-1
KasperskyP2P-Worm.Win32.Eggnog.f
BitDefenderGen:Trojan.P2P-Worm.dGY@aa4wiCi
NANO-AntivirusTrojan.Win32.Eggnog.qxemv
AvastWin32:WormX-gen [Wrm]
TencentWorm.Win32.Eggnog.a
EmsisoftGen:Trojan.P2P-Worm.dGY@aa4wiCi (B)
GoogleDetected
F-SecureDropper.DR/Delphi.Gen
BaiduWin32.Worm.Eggnog.a
VIPREGen:Trojan.P2P-Worm.dGY@aa4wiCi
TrendMicroWORM_EGGNOG.SMI
Trapminemalicious.high.ml.score
SophosW32/Eggnog-Fam
IkarusWorm.Win32.Eggnog
JiangminTrojan/Cospet.gv
VaristW32/Eggnog.A.gen!Eldorado
AviraDR/Delphi.Gen
Antiy-AVLWorm[P2P]/Win32.Eggnog
KingsoftWin32.Troj.Undef.a
MicrosoftWorm:Win32/Eggnog!pz
GridinsoftWorm.Win32.Generic.sa
XcitiumTrojWare.Win32.Cospet.X0@1mafpo
ArcabitTrojan.P2P-Worm.EE63C4
ViRobotWorm.Win32.A.P2P-Eggnog.36850
ZoneAlarmP2P-Worm.Win32.Eggnog.f
GDataWin32.Worm.Fearso.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Eggnog.R66977
Acronissuspicious
VBA32BScope.Worm.Pluto
ALYacGen:Trojan.P2P-Worm.dGY@aa4wiCi
MAXmalware (ai score=89)
Cylanceunsafe
PandaGeneric Malware
RisingWorm.Eggnog!1.E840 (CLASSIC)
YandexTrojan.GenAsa!9WQyNROzKr8
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.W32.Eggnog.F
FortinetW32/Eggnog.E!worm
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Eggnog.b492a0f2

How to remove Worm:Win32/Eggnog!pz?

Worm:Win32/Eggnog!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment