Threat Database Worms W32.Pixipos


By GoldSparrow in Worms

Threat Scorecard

Ranking: 16,674
Threat Level: 10 % (Normal)
Infected Computers: 97
First Seen: April 3, 2014
Last Seen: August 15, 2023
OS(es) Affected: Windows

W32.Pixipos is a worm that steals private details from point of sales systems and proliferates through removable drives using the potentially infected files. Once executed, W32.Pixipos creates the potentially infected file. W32.Pixipos creates the registry entry so that it can load automatically whenever the PC user boots up Windows. W32.Pixipos collects data from point of sales (PoS) systems and uploads the data to the distant location.

File System Details

W32.Pixipos may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\win.sxs
2. %DriveLetter%\autorun.inf

Registry Details

W32.Pixipos may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Taskbar" = "%UserProfile%\Application Data\win.sxs"


W32.Pixipos may call the following URLs:


Most Viewed
