Home Malware Programs Worms W32.Pixipos

W32.Pixipos

Posted: April 3, 2014

Threat Metric

Ranking: 14,783
Threat Level: 1/10
Infected PCs: 230
First Seen: April 3, 2014
Last Seen: September 26, 2023
OS(es) Affected: Windows


W32.Pixipos is a worm that steals personal information from point of sales systems and circulates through removable drives using the potentially malicious files. When W32.Pixipos is executed, it creates the potentially malicious file. W32.Pixipos creates the registry entry so that it can run automatically every time Windows is started. W32.Pixipos gathers data from point of sales (PoS) systems and uploads the data to a remote location.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Application Data\win.sxs File name: %UserProfile%\Application Data\win.sxs
Mime Type: unknown/sxs
Group: Malware file
%DriveLetter%\autorun.inf File name: %DriveLetter%\autorun.inf
Mime Type: unknown/inf
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Taskbar" = "%UserProfile%\Application Data\win.sxs"

Additional Information

The following URL's were detected:
Yo.u-know-who.com/ss/gate.php
Loading...