Trojan

How to remove “TrojanDownloader:Win32/Cbeplay.R”?

Malware Removal

The TrojanDownloader:Win32/Cbeplay.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Cbeplay.R virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Compression (or decompression)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • A process attempted to delay the analysis task by a long amount of time.
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine TrojanDownloader:Win32/Cbeplay.R?


File Info:

crc32: 2C6EE00A
md5: ce10ad414f06bda06e5fd7957696bf8c
name: CE10AD414F06BDA06E5FD7957696BF8C.mlw
sha1: 99951334cd0b3c97e928502e20251d676aa818f2
sha256: 09643290db1e01de0f3a726d15b1ea4a3014f3496c065a0eb011d10fefc53d87
sha512: 936743edeecec8b46bd5403a5cf6285e11d5a47517ac510d0b29cd1d17774f7f67c94e5aa377cd7d59d816e16d135736a05ef349212dcd47baa511c7794cf275
ssdeep: 1536:qK+NYElIuSv0oqxetmxrgT40ghk8dLc14KQYZcxJCXOvEwyQn1kj:qKgduuxo66QI40T14KQYZiQXGWue
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1992-1999 Microsoft Corp.
InternalName: MPlayer2.exe
FileVersion: 6.4.09.1125
CompanyName: Microsoft Corporation
DirectShow: Windows Media Player
ProductName: Microsoft Windows Media Player
ProductVersion: 6.4.09.1125
FileDescription: Windows Media Player
OriginalFilename: MPlayer2.exe
Translation: 0x0409 0x04e4

TrojanDownloader:Win32/Cbeplay.R also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.614309
FireEyeGeneric.mg.ce10ad414f06bda0
ALYacGen:Variant.Razy.614309
CylanceUnsafe
VIPRETrojan-PWS.Win32.Zbot.aql (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00530d5f1 )
K7GWTrojan ( 00530d5f1 )
Cybereasonmalicious.14f06b
BitDefenderThetaGen:NN.ZexaF.34590.gq0@aK4TzMbi
SymantecPacked.Generic.459
APEXMalicious
AvastWin32:Cbeplay-D [Trj]
ClamAVWin.Virus.Blocker-884
KasperskyTrojan-Ransom.Win32.Blocker.auqe
BitDefenderGen:Variant.Razy.614309
NANO-AntivirusTrojan.Win32.Blocker.cugbdf
AegisLabHacktool.Win32.Krap.lKMc
RisingRansom.Blocker!8.12A (CLOUD)
Ad-AwareGen:Variant.Razy.614309
EmsisoftGen:Variant.Razy.614309 (B)
ComodoTrojWare.Win32.MalPack.PKB@1rava1
F-SecureHeuristic.HEUR/AGEN.1115120
DrWebTrojan.DownLoader24.22624
ZillyaTrojan.Blocker.Win32.5748
TrendMicroTSPY_ZBOT.SML3
McAfee-GW-EditionPWS-Zbot-FANV!CE10AD414F06
SophosMal/Generic-R + Troj/Ransom-OQ
IkarusTrojan-Downloader.Win32.Cbeplay
JiangminTrojan.Blocker.shs
AviraHEUR/AGEN.1115120
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojanDownloader:Win32/Cbeplay.R
ArcabitTrojan.Razy.D95FA5
ZoneAlarmTrojan-Ransom.Win32.Blocker.auqe
GDataGen:Variant.Razy.614309
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R51060
Acronissuspicious
McAfeePWS-Zbot-FANV
MAXmalware (ai score=87)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesRansom.FileCryptor
PandaTrj/Hexas.HEU
ESET-NOD32Win32/LockScreen.AQR
TrendMicro-HouseCallTSPY_ZBOT.SML3
TencentWin32.Trojan.Blocker.Szbc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/Zbot.APRF!tr
WebrootTrojan.Dropper.Gen
AVGWin32:Cbeplay-D [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.8dc

How to remove TrojanDownloader:Win32/Cbeplay.R?

TrojanDownloader:Win32/Cbeplay.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment