Malware

About “PWS:Win32/Fignotok!pz” infection

Malware Removal

The PWS:Win32/Fignotok!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Fignotok!pz virus can do?

  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Harvests information related to installed instant messenger clients
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/Fignotok!pz?


File Info:

name: FADC7DA97023307A07AC.mlw
path: /opt/CAPEv2/storage/binaries/89074950d042491051910baa679064c841a95f03c50c93c5439988ac579a98e8
crc32: 07FAEADB
md5: fadc7da97023307a07ac188d09a7f2f0
sha1: aa5dc9c34dbeb06f53bdcd0d0f623a105591019f
sha256: 89074950d042491051910baa679064c841a95f03c50c93c5439988ac579a98e8
sha512: 07e228c68b368d0e0b9978e879c8fc7e87f3c81e06db6ddd4ad55a3f545c4cad7869e51c87f6c00799b327861e373f4a920d8afbd0ea94929de6beb0eeb4b35b
ssdeep: 49152:oGggui4ljAvjwwj2F+OWhUfOCX/wpBTzRrydkEbrBl6cp47s:2r9jQjwwqvSCXIpFNOdFr76cK7s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124E5231373D29073E88751B15299AB30DFFAB9201935999B9FE40E846E30761EF3274B
sha3_384: d6ffa263d5e2592cf8249d80347b2ff2bd6a0a6432aaa914d6ee254ada0e7ec8a33306ba671f8e6505043921eb754824
ep_bytes: 558bec6aff68d0d8440068d459440064
timestamp: 2009-12-18 19:48:31

Version Info:

0: [No Data]

PWS:Win32/Fignotok!pz also known as:

BkavW32.AIDetectMalware
AVGWin32:Fignotok-M [Trj]
tehtrisGeneric.Malware
DrWebTrojan.PWS.Dybalom
MicroWorld-eScanGen:Variant.Graftor.1203
FireEyeGeneric.mg.fadc7da97023307a
CAT-QuickHealTrojanpws.Fignotok.27946
SkyhighPWS-Dybalom.gen.a
McAfeePWS-Dybalom.gen.a
Cylanceunsafe
ZillyaTrojan.Dybalom.Win32.2848
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojanPSW:Win32/Fignotok.86bc2c4b
K7GWPassword-Stealer ( 00134e5f1 )
K7AntiVirusPassword-Stealer ( 00134e5f1 )
BitDefenderThetaAI:Packer.BBA47CF31E
VirITTrojan.Win32.Dybalom.BKN
SymantecInfostealer
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Fignotok.A
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.Dybalom-894
KasperskyTrojan-PSW.Win32.Dybalom.bkn
BitDefenderGen:Variant.Graftor.1203
NANO-AntivirusTrojan.Win32.TrjGen.cvbopr
AvastWin32:Fignotok-M [Trj]
TencentWin32.Trojan-QQPass.QQRob.Najl
TACHYONTrojan-PWS/W32.Dybalom.3194880
EmsisoftGen:Variant.Graftor.1203 (B)
F-SecureTrojan.TR/PSW.Dybalom.bkh.1
BaiduWin32.Trojan-PSW.Agent.c
VIPREGen:Variant.Graftor.1203
TrendMicroTROJ_FIGNOTO.SMA
Trapminemalicious.high.ml.score
SophosMal/PWS-FB
IkarusVirus.Win32.Vundo
JiangminTrojan/PSW.Dybalom.mc
GoogleDetected
AviraTR/PSW.Dybalom.bkh.1
Antiy-AVLTrojan[PSW]/Win32.Fignotok
KingsoftWin32.PSWTroj.Undef.a
MicrosoftPWS:Win32/Fignotok!pz
XcitiumTrojWare.Win32.PSW.Dybalom.~FAT@1v5v1y
ArcabitTrojan.Graftor.D4B3
ViRobotTrojan.Win32.PSWDybalom.679936
ZoneAlarmTrojan-PSW.Win32.Dybalom.bkn
GDataGen:Variant.Graftor.1203
AhnLab-V3Win-Trojan/Keylogger.217600.C
ALYacGen:Variant.Graftor.1203
MAXmalware (ai score=100)
VBA32Trojan-Spy.VK.0383
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallTROJ_FIGNOTO.SMA
RisingDropper.Win32.Undef.cad (CLASSIC)
YandexTrojan.GenAsa!m373mwwYlfs
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.12582!tr
ZonerTrojan.Win32.33868
Cybereasonmalicious.970233
DeepInstinctMALICIOUS
alibabacloudRiskWare:Win/Fignotok.A

How to remove PWS:Win32/Fignotok!pz?

PWS:Win32/Fignotok!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment