Solved! Use W9XPOPEN.EXE (Worm (Suspicious File)) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

W9XPOPEN.EXE – Worm (Suspicious File) removal

File MD5 Virus Alias
W9XPOPEN.EXE 8506776d3b857847a7ecd599968fb55e Worm (Suspicious File)

W9XPOPEN.EXE size: 3584 bytes
W9XPOPEN.EXE hash: 8506776D3B857847A7ECD599968FB55E

Created files:

C:\MSP\Tools\BleachBit\atk.pyd
C:\MSP\Tools\BleachBit\bleachbit.exe
C:\MSP\Tools\BleachBit\bleachbit_console.exe
C:\MSP\Tools\BleachBit\bz2.pyd
C:\MSP\Tools\BleachBit\cairo._cairo.pyd
C:\MSP\Tools\BleachBit\etc\gtk-2.0\gdk-pixbuf.loaders
C:\MSP\Tools\BleachBit\etc\gtk-2.0\gtkrc
C:\MSP\Tools\BleachBit\etc\gtk-2.0\im-multipress.conf
C:\MSP\Tools\BleachBit\gobject._gobject.pyd
C:\MSP\Tools\BleachBit\gtk._gtk.pyd
C:\MSP\Tools\BleachBit\intl.dll
C:\MSP\Tools\BleachBit\lib\gtk-2.0\2.10.0\engines\libwimp.dll
C:\MSP\Tools\BleachBit\lib\gtk-2.0\modules\libgail.dll
C:\MSP\Tools\BleachBit\libatk-1.0-0.dll
C:\MSP\Tools\BleachBit\libcairo-2.dll
C:\MSP\Tools\BleachBit\libgdk-win32-2.0-0.dll
C:\MSP\Tools\BleachBit\libgdk_pixbuf-2.0-0.dll
C:\MSP\Tools\BleachBit\libgio-2.0-0.dll
C:\MSP\Tools\BleachBit\libglib-2.0-0.dll
C:\MSP\Tools\BleachBit\libgmodule-2.0-0.dll
C:\MSP\Tools\BleachBit\libgobject-2.0-0.dll
C:\MSP\Tools\BleachBit\libgthread-2.0-0.dll
C:\MSP\Tools\BleachBit\libgtk-win32-2.0-0.dll
C:\MSP\Tools\BleachBit\libpango-1.0-0.dll
C:\MSP\Tools\BleachBit\libpangocairo-1.0-0.dll
C:\MSP\Tools\BleachBit\libpangowin32-1.0-0.dll
C:\MSP\Tools\BleachBit\libpng12-0.dll
C:\MSP\Tools\BleachBit\libpng14-14.dll
C:\MSP\Tools\BleachBit\msvcr71 (Corey-PC’s conflicted copy 2015-07-03).dll
C:\MSP\Tools\BleachBit\msvcr71.dll
C:\MSP\Tools\BleachBit\pango.pyd
C:\MSP\Tools\BleachBit\pangocairo.pyd
C:\MSP\Tools\BleachBit\perfmon.pyd
C:\MSP\Tools\BleachBit\pyexpat.pyd
C:\MSP\Tools\BleachBit\python25 (Corey-PC’s conflicted copy 2015-07-03).dll
C:\MSP\Tools\BleachBit\python25.dll
C:\MSP\Tools\BleachBit\pythoncom25 (Corey-PC’s conflicted copy 2015-07-03).dll
C:\MSP\Tools\BleachBit\pythoncom25.dll
C:\MSP\Tools\BleachBit\pywintypes25.dll
C:\MSP\Tools\BleachBit\select.pyd
C:\MSP\Tools\BleachBit\servicemanager.pyd
C:\MSP\Tools\BleachBit\share\themes\MS-Windows\gtk-2.0\gtkrc
C:\MSP\Tools\BleachBit\sqlite3 (Corey-PC’s conflicted copy 2015-07-03).dll
C:\MSP\Tools\BleachBit\unicodedata.pyd
C:\MSP\Tools\BleachBit\w9xpopen.exe
C:\MSP\Tools\BleachBit\win32api.pyd
C:\MSP\Tools\BleachBit\win32com.shell.shell.pyd
C:\MSP\Tools\BleachBit\win32evtlog.pyd
C:\MSP\Tools\BleachBit\win32file.pyd
C:\MSP\Tools\BleachBit\win32gui.pyd
C:\MSP\Tools\BleachBit\win32pipe.pyd
C:\MSP\Tools\BleachBit\win32process.pyd
C:\MSP\Tools\BleachBit\win32service.pyd
C:\MSP\Tools\BleachBit\win32ui.pyd
C:\MSP\Tools\BleachBit\zlib1.dll
C:\MSP\Tools\BleachBit\_ctypes.pyd
C:\MSP\Tools\BleachBit\_hashlib.pyd
C:\MSP\Tools\BleachBit\_socket.pyd
C:\MSP\Tools\BleachBit\_sqlite3.pyd
C:\MSP\Tools\BleachBit\_win32sysloader.pyd

Detected by UnHackMe:

W9XPOPEN.EXE
Default location: C:\MSP\TOOLS\BLEACHBIT\W9XPOPEN.EXE

Dropper information:
MD5: 7105887d23d2fab997070c3a4c4fb5dd
File size: 8911094 bytes

Leave a Reply