Threat Search: 

ThreatExpert's Statistics for PWS:Win32/Fignotok.A [Microsoft]:

PWS:Win32/Fignotok.A [Microsoft] is also known as:
Threat AliasNumber of Incidents
Infostealer [Symantec]147
Troj/Dloadr-CTC [Sophos]143
Trojan-PSW.Generic [PC Tools]120
Win-Trojan/Dybalom.32768.B [AhnLab]100
Trojan-PSW.Win32.Dybalom.afm [Kaspersky Lab]74
Generic Dropper.ny [McAfee]71
Generic Downloader!hv.x [McAfee]63
Trojan-PWS.Win32.Dybalom [Ikarus]21
Trojan-PSW.Win32.Dybalom.bcx [Kaspersky Lab]10
Generic Dropper.pm.gen [McAfee]7
Mal/Generic-A [Sophos]7
Trojan Horse [Symantec]6
Trojan-PSW.Win32.Dybalom.bnw [Kaspersky Lab]6
BackDoor-DKI.gen.bn [McAfee]5
Suspicious.MH690 [Symantec]5
Troj/Refroso-D [Sophos]5
Trojan.Generic [PC Tools]5
Trojan-PSW.Win32.Dybalom.aoj [Kaspersky Lab]4
Trojan-PSW.Win32.Dybalom.bns [Kaspersky Lab]3
Trojan-PSW.Win32.Dybalom.bqi [Kaspersky Lab]3
Backdoor.Trojan [PC Tools]2
Backdoor.Trojan [Symantec]2
BackDoor-CEP.gen.av [McAfee]2
Mal/HckPk-A [Sophos]2
New Win32 [McAfee]2
Trojan.Win32.Refroso.akhx [Kaspersky Lab]2
Trojan-Downloader.Win32.Small.almj [Kaspersky Lab]2
Trojan-PSW.Win32.Dybalom.aek [Kaspersky Lab]2
Trojan-PSW.Win32.Dybalom.afx [Kaspersky Lab]2
Trojan-PSW.Win32.Dybalom.bdc [Kaspersky Lab]2
Trojan-PSW.Win32.Dybalom.bdw [Kaspersky Lab]2
Trojan-PSW.Win32.Dybalom.bna [Kaspersky Lab]2
Win32/MalPackedB.suspicious [AhnLab]2
BackDoor-DVB.gen.i [McAfee]1
Downloader [Symantec]1
Dropper/Malware.223744 [AhnLab]1
Dropper/Malware.53248.BF [AhnLab]1
Dropper/Malware.59130 [AhnLab]1
Generic Downloader.x!lt [McAfee]1
Mal/Bifrose-S [Sophos]1
Mal/Generic-A, Mal/Krap-K, Mal/Krap-K [Sophos]1
Mal/Krap-K, Mal/Krap-K [Sophos]1
Packed.Win32.VBCrypt [Ikarus]1
PWS.Win32 [Ikarus]1
PWS-Dybalom [McAfee]1
Trojan-Downloader.Win32.Small.alif [Kaspersky Lab]1
Trojan-PSW.Win32.Dybalom.aho [Kaspersky Lab]1
Trojan-PSW.Win32.Dybalom.bcw [Kaspersky Lab]1
Trojan-PSW.Win32.Dybalom.bdb [Kaspersky Lab]1
Trojan-PSW.Win32.Dybalom.bgh [Kaspersky Lab]1
Trojan-PSW.Win32.Dybalom.bhh [Kaspersky Lab]1
Trojan-PSW.Win32.Dybalom.bhi [Kaspersky Lab]1
Trojan-PSW.Win32.Dybalom.bii [Kaspersky Lab]1
Trojan-PSW.Win32.Dybalom.bkn [Kaspersky Lab]1
Trojan-PSW.Win32.Dybalom.bnl [Kaspersky Lab]1
VirTool.Win32.Injector [Ikarus]1
Win-Trojan/AntiSb.74490 [AhnLab]1
Win-Trojan/Dybalom.32768.I [AhnLab]1
Win-Trojan/Xema.variant [AhnLab]1

PWS:Win32/Fignotok.A [Microsoft] has the following possible countries of origin:
OriginNumber of Incidents
Spain64
Germany2
Russian Federation1
Sweden1

PWS:Win32/Fignotok.A [Microsoft] is known to be created as:
%ProgramFiles%\bifrost\server.exe
%Temp%\decrypted.exe
%Temp%\f.exe
%Temp%\filetmp.exe
%Temp%\ixp000.tmp\aa.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).