SETUP32.LJP – Unclassified Malware

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SETUP32.LJP – Unclassified Malware removal

SETUP32.LJP size: 51712 bytes
SETUP32.LJP hash: 153C02E07B24B2D8CC34B508E07D4C45

Created files:

%TEMP%\WZSE0.TMP\decryp32.ex_
%TEMP%\WZSE0.TMP\fcrypt32.ex_
%TEMP%\WZSE0.TMP\oleaut32.dl_
%TEMP%\WZSE0.TMP\olepro32.dl_
%TEMP%\WZSE0.TMP\Setup32.exe
%TEMP%\WZSE0.TMP\Setup32.lbr
%TEMP%\WZSE0.TMP\Setup32.lcn
%TEMP%\WZSE0.TMP\Setup32.lde
%TEMP%\WZSE0.TMP\Setup32.les
%TEMP%\WZSE0.TMP\Setup32.lfr
%TEMP%\WZSE0.TMP\Setup32.lhu
%TEMP%\WZSE0.TMP\Setup32.lit
%TEMP%\WZSE0.TMP\Setup32.ljp
%TEMP%\WZSE0.TMP\Setup64.exe
%TEMP%\WZSE0.TMP\Setup64.lbr
%TEMP%\WZSE0.TMP\Setup64.lcn
%TEMP%\WZSE0.TMP\Setup64.lde
%TEMP%\WZSE0.TMP\Setup64.les
%TEMP%\WZSE0.TMP\Setup64.lfr
%TEMP%\WZSE0.TMP\Setup64.lhu
%TEMP%\WZSE0.TMP\Setup64.lit
%TEMP%\WZSE0.TMP\Setup64.ljp
%TEMP%\WZSE0.TMP\wibuke32.cp_
%TEMP%\WZSE0.TMP\wibuke32._br
%TEMP%\WZSE0.TMP\wibuke32._cn
%TEMP%\WZSE0.TMP\wibuke32._de
%TEMP%\WZSE0.TMP\wibuke32._es
%TEMP%\WZSE0.TMP\wibuke32._fr
%TEMP%\WZSE0.TMP\wibuke32._hu
%TEMP%\WZSE0.TMP\wibuke32._it
%TEMP%\WZSE0.TMP\wibuke32._jp
%TEMP%\WZSE0.TMP\wibuke64.cp_
%TEMP%\WZSE0.TMP\wibuke64._br
%TEMP%\WZSE0.TMP\wibuke64._cn
%TEMP%\WZSE0.TMP\wibuke64._de
%TEMP%\WZSE0.TMP\wibuke64._es
%TEMP%\WZSE0.TMP\wibuke64._fr
%TEMP%\WZSE0.TMP\wibuke64._hu
%TEMP%\WZSE0.TMP\wibuke64._it
%TEMP%\WZSE0.TMP\wibuke64._jp
%TEMP%\WZSE0.TMP\wibukey.dl_
%TEMP%\WZSE0.TMP\wibukey.sy_
%TEMP%\WZSE0.TMP\wibukey.vx_
%TEMP%\WZSE0.TMP\wibukey2.sy_
%TEMP%\WZSE0.TMP\wibukey2_64.sy_
%TEMP%\WZSE0.TMP\wibukey64.dl_
%TEMP%\WZSE0.TMP\wibukey64.sy_
%TEMP%\WZSE0.TMP\wibukjni.dl_
%TEMP%\WZSE0.TMP\wibukjni64.dl_
%TEMP%\WZSE0.TMP\wibushellext.dl_
%TEMP%\WZSE0.TMP\wibushellext64.dl_
%TEMP%\WZSE0.TMP\wibuxpm4j32.dl_
%TEMP%\WZSE0.TMP\wibuxpm4j64.dl_
%TEMP%\WZSE0.TMP\wkdos.ex_
%TEMP%\WZSE0.TMP\wkext32.dl_
%TEMP%\WZSE0.TMP\wkext64.dl_
%TEMP%\WZSE0.TMP\wkstartcpl32.ex_
%TEMP%\WZSE0.TMP\wkstartcpl64.ex_
%TEMP%\WZSE0.TMP\wksvctrl.dl_
%TEMP%\WZSE0.TMP\wksvmgr.ex_
%TEMP%\WZSE0.TMP\wksvmgr_de.q_
%TEMP%\WZSE0.TMP\wksvmgr_es.q_
%TEMP%\WZSE0.TMP\wksvmgr_fr.q_
%TEMP%\WZSE0.TMP\wksvmgr_hu.q_
%TEMP%\WZSE0.TMP\wksvmgr_it.q_
%TEMP%\WZSE0.TMP\wksvmgr_ja.q_
%TEMP%\WZSE0.TMP\wksvmgr_pt.q_
%TEMP%\WZSE0.TMP\wksvmgr_zh.q_
%TEMP%\WZSE0.TMP\wksvmon.ex_
%TEMP%\WZSE0.TMP\wksvmon._br
%TEMP%\WZSE0.TMP\wksvmon._cn
%TEMP%\WZSE0.TMP\wksvmon._de
%TEMP%\WZSE0.TMP\wksvmon._es
%TEMP%\WZSE0.TMP\wksvmon._fr
%TEMP%\WZSE0.TMP\wksvmon._hu
%TEMP%\WZSE0.TMP\wksvmon._it
%TEMP%\WZSE0.TMP\wksvmon._jp
%TEMP%\WZSE0.TMP\wksvnw.nl_
%TEMP%\WZSE0.TMP\wksvw32.ex_
%TEMP%\WZSE0.TMP\wksvw32._br
%TEMP%\WZSE0.TMP\wksvw32._cn
%TEMP%\WZSE0.TMP\wksvw32._de
%TEMP%\WZSE0.TMP\wksvw32._es
%TEMP%\WZSE0.TMP\wksvw32._fr
%TEMP%\WZSE0.TMP\wksvw32._hu
%TEMP%\WZSE0.TMP\wksvw32._it
%TEMP%\WZSE0.TMP\wksvw32._jp
%TEMP%\WZSE0.TMP\wku.ex_
%TEMP%\WZSE0.TMP\wku32.ex_
%TEMP%\WZSE0.TMP\wkwin.dl_
%TEMP%\WZSE0.TMP\wkwin16._br
%TEMP%\WZSE0.TMP\wkwin16._cn
%TEMP%\WZSE0.TMP\wkwin16._de
%TEMP%\WZSE0.TMP\wkwin16._es
%TEMP%\WZSE0.TMP\wkwin16._fr
%TEMP%\WZSE0.TMP\wkwin16._hu
%TEMP%\WZSE0.TMP\wkwin16._it
%TEMP%\WZSE0.TMP\wkwin16._jp
%TEMP%\WZSE0.TMP\wkwin32.dl_
%TEMP%\WZSE0.TMP\wkwin32._br
%TEMP%\WZSE0.TMP\wkwin32._cn
%TEMP%\WZSE0.TMP\wkwin32._de
%TEMP%\WZSE0.TMP\wkwin32._es
%TEMP%\WZSE0.TMP\wkwin32._fr
%TEMP%\WZSE0.TMP\wkwin32._hu
%TEMP%\WZSE0.TMP\wkwin32._it
%TEMP%\WZSE0.TMP\wkwin32._jp
%TEMP%\WZSE0.TMP\wkwin64.dl_
%TEMP%\WZSE0.TMP\wkwin64._br
%TEMP%\WZSE0.TMP\wkwin64._cn
%TEMP%\WZSE0.TMP\wkwin64._de
%TEMP%\WZSE0.TMP\wkwin64._es
%TEMP%\WZSE0.TMP\wkwin64._fr
%TEMP%\WZSE0.TMP\wkwin64._hu
%TEMP%\WZSE0.TMP\wkwin64._it
%TEMP%\WZSE0.TMP\wkwin64._jp

Detected by UnHackMe:

SETUP32.LJP
Default location: %TEMP%\WZSE0.TMP\SETUP32.LJP

Dropper information:
MD5: a0fcbf347531bad73f1434ff6ac50541
File size: 19510592 bytes

Leave a Reply