Spy

What is “Win32/Spy.Zumanek.CX”?

Malware Removal

The Win32/Spy.Zumanek.CX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Zumanek.CX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Attempts to modify proxy settings

How to determine Win32/Spy.Zumanek.CX?


File Info:

name: A403D55E681DDAB99AC3.mlw
path: /opt/CAPEv2/storage/binaries/b2acdfb2c24c3ef7787974b58932a79fe396f7b34e9b625bbbc239a71c2fbac2
crc32: F70A080D
md5: a403d55e681ddab99ac389347e9b701f
sha1: 981d6b253d441ca4e1e9d97c7d58c50c3626832e
sha256: b2acdfb2c24c3ef7787974b58932a79fe396f7b34e9b625bbbc239a71c2fbac2
sha512: 20d990feab4d48d99b23c1517da414604d04679a006311fae86721f4585dcc4e2cda880e7a7686694a31361fe852aece2bc9e455887ae966f688690f08338d13
ssdeep: 12288:Vrijdqwffy3COzyeA4C6c3SkZCj0VhuGRGx+hNY2rhvxT:2cCapC6O40Vhu8Gx+/Y2rhpT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195E412D14D235C07D7970DB70B62336C77FE9BDE1347AD26EB30A668A932D8A1B05A10
sha3_384: 4e8dd44bd69b230bd20597d4c50f3c28029b18517b5e24fcb58b26f2d5d3455a9ab1fd6109434d58d6235965d2fbbb4f
ep_bytes: b8b84d69005064ff3500000000648925
timestamp: 2018-05-08 17:05:19

Version Info:

Comments: DGhPgVC
CompanyName: wpMCnUk
FileDescription: DGhPgVC wpMCnUk
FileVersion: 7, 12, 7, 362
InternalName: AVgVIKEenK
LegalCopyright: Copyrigth (C) AVgVIKEenK
OriginalFilename: AVgVIKEenK.exe
PrivateBuild: SgYbecKbdZ_362
ProductName: AVgVIKEenK Application
ProductVersion: 7, 0, 0, 7
Translation: 0x0409 0x04b0

Win32/Spy.Zumanek.CX also known as:

LionicTrojan.Win32.BestaFera.7!c
MicroWorld-eScanGen:Heur.Ranpax.1
FireEyeGeneric.mg.a403d55e681ddab9
ALYacGen:Heur.Ranpax.1
CylanceUnsafe
SangforTrojan.Win32.Zumanek.CX
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanBanker:Win32/BestaFera.781fe716
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e681dd
CyrenW32/Banload.DD.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Zumanek.CX
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.BestaFera.ashg
BitDefenderGen:Heur.Ranpax.1
NANO-AntivirusTrojan.Win32.Zumanek.fbvzll
AvastWin32:Malware-gen
TencentWin32.Trojan.Spy.Lizr
Ad-AwareGen:Heur.Ranpax.1
EmsisoftGen:Heur.Ranpax.1 (B)
ComodoMalware@#196ocuh9lj36b
ZillyaTrojan.Zumanek.Win32.501
McAfee-GW-EditionGenericRXEM-NT!CEE11DDDD77A
Trapminemalicious.high.ml.score
SophosMal/Generic-S
GDataGen:Heur.Ranpax.1
AviraTR/Spy.Zumanek.sfpjv
ArcabitTrojan.Ranpax.1
MicrosoftTrojan:Win32/Skeeyah.A!bit
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2493140
McAfeeArtemis!A403D55E681D
MAXmalware (ai score=99)
VBA32TrojanDownloader.Delf
MalwarebytesMalware.Heuristic.1001
RisingSpyware.Zumanek!8.EC44 (CLOUD)
YandexTrojan.GenAsa!rAd9QZCn3cU
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banload.WLW!tr.dldr
BitDefenderThetaAI:Packer.499F983A21
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Win32/Spy.Zumanek.CX?

Win32/Spy.Zumanek.CX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment