Spy Trojan

Should I remove “TrojanSpy:Win32/Ambler!pz”?

Malware Removal

The TrojanSpy:Win32/Ambler!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Ambler!pz virus can do?

  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanSpy:Win32/Ambler!pz?


File Info:

name: 13B58EF3A9C6FACFEE62.mlw
path: /opt/CAPEv2/storage/binaries/3b22308741efb5436c5173405743475e6fc76aa202dbf4cc5199895ec9cae4f0
crc32: 8DC4112A
md5: 13b58ef3a9c6facfee62f97018482a07
sha1: de7a642b1f0d03a937c2064c349c98585a2c3f42
sha256: 3b22308741efb5436c5173405743475e6fc76aa202dbf4cc5199895ec9cae4f0
sha512: 0408b6e50f821143b223de3fe4b46775fa2e4b39ee5b50b8db9ce55cdac2000fbdeee9a0c16402927eecc8b56a5c945653e2fde9df478a78016de328e9dce7f6
ssdeep: 384:wDG1dKdCipAm86wzWjtAtePDAuR5QwZH9HOT06ETRSQ1uiX+jOyWFQG8sH9Wil:wDbd4NtzWj2tIUauW762vD+jOnSM9WA
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T12EE2DF86B3D0CA81C5552B780DB198D41798FF9D9E1ECB8F325A337F2FB21903A96614
sha3_384: 7b3006420e35201dfa38a6f28a516c9572a7f03485e86ea8e6a0617394a27a6c950c3467671ce0efce702829789a8abf
ep_bytes: 807c2408010f85c201000060be004001
timestamp: 2008-08-10 21:03:01

Version Info:

Comments:
CompanyName: Gutman
FileDescription: Explorer
FileVersion: 1, 0, 0, 1
InternalName: Sonar
LegalCopyright: Copyright © 2008
LegalTrademarks:
OriginalFilename: gr
PrivateBuild:
ProductName: Sok
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0419 0x04b0

TrojanSpy:Win32/Ambler!pz also known as:

LionicTrojan.Win32.Amber.l4ij
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Adware.Heur.bmSfN4RSZzak
FireEyeGeneric.mg.13b58ef3a9c6facf
CAT-QuickHealTrojan.Generic.8386
SkyhighBehavesLike.Win32.Trojan.nc
McAfeeArtemis!13B58EF3A9C6
VIPREGen:Adware.Heur.bmSfN4RSZzak
SangforSpyware.Win32.Banker.PKY
AlibabaTrojanSpy:Win32/Ambler.7fe986cb
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitAdware.Heur.bmSfN4RSZzak
VirITBackdoor.Win32.Agent.VIP
SymantecDownloader
ESET-NOD32Win32/Spy.Banker.PKY
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Amber.gen
BitDefenderGen:Adware.Heur.bmSfN4RSZzak
NANO-AntivirusTrojan.Win32.Agent.rbat
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.13b8805f
SophosMal/Ambler-B
F-SecureTrojan-Spy:W32/Ambler.gen!A
DrWebTrojan.DownLoad.3454
ZillyaBackdoor.Agent.Win32.4657
TrendMicroWORM_AMBLER.SMI
EmsisoftGen:Adware.Heur.bmSfN4RSZzak (B)
IkarusTrojan-Downloader.Win32.BHO
JiangminBackdoor/Agent.bghi
WebrootWorm:Win32/Ambler.A
GoogleDetected
AviraTR/BHO.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Agent
KingsoftWin32.Trojan.Generic.a
XcitiumBackdoor@#2upukvulexrgo
MicrosoftTrojanSpy:Win32/Ambler!pz
ZoneAlarmHEUR:Trojan-Spy.Win32.Amber.gen
GDataGen:Adware.Heur.bmSfN4RSZzak
VaristW32/Ambler.C.gen!Eldorado
AhnLab-V3Spyware/Win32.Amber.R145085
BitDefenderThetaGen:NN.ZedlaF.36744.bmSfa4RSZzak
ALYacGen:Adware.Heur.bmSfN4RSZzak
MAXmalware (ai score=100)
VBA32BScope.TrojanSpy.Amber
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallWORM_AMBLER.SMI
RisingSpyware.Ambler!8.852 (TFE:5:OKZlAxBpiVF)
YandexTrojan.GenAsa!peawcZvPiSc
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.829849.susgen
FortinetW32/Ambler.A!tr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove TrojanSpy:Win32/Ambler!pz?

TrojanSpy:Win32/Ambler!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment