What is Play.exe?
Play.exe is a legitimate process file popularly known as Easy CD Creater API. It belongs to Easy CD Creator API, developed by Roxio. It is located in C:\Windows\System32 by default. Malware programmers write virus files with malicious scripts and save them as Play.exe with an intention to spread virus on the internet.
Affected Platforms: Windows OS
How to determine if your computer is infected with Play.exe malware?
Look out for these symptoms to check if your PC is infected with Play.exe malware:
- Unstable internet connection
- Play.exe occupies extra CPU space
- PC processing speed slows down
- Browser often redirects to irrelevant websites
- Browser is bombarded with hordes of popup ads
- Computer screen freezes repeatedly
Take the following steps to diagnose your PC for possible Play.exe malware attack:
Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.
Step 2: If you notice the file located outside C:\Windows\System32, perform an antivirus scan to get rid of the malware.
How to remove Play.exe malware from system using Comodo Antivirus?
Step 1: Download our award-winning Free Antivirus.
Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.
Step 3: Select Customize Configuration option and arrange installers, configuration, and file location.
Step 4: Restart your PC after the installation gets over
Step 5: Wait for Comodo Internet Security to update the antivirus.
Step 6: Proceed with the quick scan that automatically begins after the update.
Step 7: If threats are found during the scanning, you will be notified through an alert screen.
Step 8: Comodo Antivirus will remove Play.exe malware from your computer including all other malwares!
Related Resources
No. | Company | File Type | SHA1 | MD5 | Malware Name |
Digitally Signed |
File Version |
Product Version |
Submitted From |
Malware Behavior |
---|---|---|---|---|---|---|---|---|---|---|
1 | N/A | Executable | e02eec0801755bc3 1544447743740cef d9f61afa |
19c5514f9ce93c0f 69874519c722ffa2 |
Win32.Neshta .A |
No | N/A | N/A | 191.102.120.15/32 | N/A |
2 | N/A | Executable | 71b43d53b183ffce dd4f54ddbd50bfee f86307d5 |
ba5931f5005bc532 1d398986c182785e |
Virus.Win32. Sality.gen |
No | 1.0.0.0 | 1.0.0.0 | Russian Federation | N/A |
3 | TQ Digital Entertainment | Executable | d1b82123cdd8d265 6e0bbf510bad9a7e ddb8b17b |
d297ce843fc9e99a ec184bce95a6517a |
Worm.Win32.D ropper.RA |
No | 2011.829.0 .1 |
2011.829.0 .1 |
Internal Submission | N/A |
4 | N/A | Executable | 2ef6211a96bc0205 f3f09bdd53585cd1 20ed47a3 |
a334a6c9a511329d 95acf159c1e5d028 |
Unclassified Malware |
No | N/A | N/A | Internal Submission | N/A |
No. | Company | File Type | SHA1 | MD5 | Digitally Signed |
File Version |
Product Version |
Submitted From |
---|---|---|---|---|---|---|---|---|
1 | N/A | Executable | 3dfcc6449e689361 d68275b6777a9773 17134445 |
c9e9e580bfa3cd09 39cb08fa77e5a194 |
No | N/A | N/A | Internal Submission |
2 | PopCap.com | Executable | 57b3bc0b6e97ac6a 2da3742d46c2ca50 32bd99be |
1a4be377cb728d86 36035fc3c0929147 |
No | 1, 2, 1, 0 | 1.21 | South Africa |
3 | N/A | Executable | 84fc530104df8d09 701dd8c64b57498d 4e38f351 |
8bcd24796232779d 33c664ae88c9a4b5 |
No | 2, 0, 0, 5 | 2, 0, 0, 5 | Internal Submission |
4 | N/A | Executable | 389d8f9c28967ffe d7804bb8008c6d55 09ac3ec7 |
25ef8472a6d35e20 9584d2ef9361b351 |
No | N/A | N/A | Bulgaria |