Trojan

About “TrojanDownloader:Win32/Cbeplay.P” infection

Malware Removal

The TrojanDownloader:Win32/Cbeplay.P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Cbeplay.P virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
www.ip-address.org
a.tomx.xyz
ocsp.digicert.com

How to determine TrojanDownloader:Win32/Cbeplay.P?


File Info:

crc32: A2192E68
md5: c153f8b73cd2d51dc1e2bfcf2a67626c
name: C153F8B73CD2D51DC1E2BFCF2A67626C.mlw
sha1: 9bccdc13ab6c9e6110d02061a0ec194aaa706cb0
sha256: 5eddeb8532747083614fdc37f34d1459c4e046916588566851fde912e9140513
sha512: fec50945fe120f2a627b58b2e494d1f592de0807eb5dd3c9b4f6ed56c5f934ae86ad2efef90d5567f808732a96677ed05e64f4730edfb6964c002d0e2b84cdae
ssdeep: 3072:Uf81AnyhZ6FPYhtMB070pElPNqhr4v//1KsGUAGbbrFjZPzUNZtC3A2o+OndzOh:Uf81nZhCaQ6c4v//1TAqrzP47UAAOe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9G.Skill
InternalName: Whole Polices
FileVersion: 2.2.0
CompanyName: G.Skill
ProductName: Whole Polices
ProductVersion: 2.2.0
FileDescription: Whole Polices
OriginalFilename: wholepolices.exe
Translation: 0x0809 0x04b0

TrojanDownloader:Win32/Cbeplay.P also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad2.47162
CynetMalicious (score: 100)
ALYacGen:Variant.Kazy.77274
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_70% (D)
Cybereasonmalicious.73cd2d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AHBD
APEXMalicious
AvastWin32:Crypt-NDU [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.77274
NANO-AntivirusTrojan.Win32.Inject.devkwz
MicroWorld-eScanGen:Variant.Kazy.77274
TencentWin32.Trojan-Dropper.Injector.cvfn
Ad-AwareGen:Variant.Kazy.77274
SophosML/PE-A + Mal/NecursDrp-A
ComodoMalware@#ctuniu1luqg8
BitDefenderThetaGen:NN.ZexaF.34236.pu0@aKNA78bi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-Zbot.gen.anc
FireEyeGeneric.mg.c153f8b73cd2d51d
EmsisoftGen:Variant.Kazy.77274 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Injector.ackr
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.23D9405
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanDownloader:Win32/Cbeplay.P
GDataGen:Variant.Kazy.77274
AhnLab-V3Dropper/Win32.Injector.C2321637
McAfeePWS-Zbot.gen.anc
MAXmalware (ai score=81)
VBA32BScope.Trojan.AET.281105
MalwarebytesTrojan.Agent.PHEX.Generic
PandaGeneric Malware
RisingTrojan.Generic@ML.89 (RDML:UdbzovJhFxlHx3MM0c4OOA)
YandexTrojan.DR.Injector!W39cp+OfRX4
IkarusTrojan-Dropper.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Crypt-NDU [Trj]
Paloaltogeneric.ml

How to remove TrojanDownloader:Win32/Cbeplay.P?

TrojanDownloader:Win32/Cbeplay.P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment