Malware

How to remove “Downloader.Win32.InnoBundle.amco”?

Malware Removal

The Downloader.Win32.InnoBundle.amco is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.InnoBundle.amco virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Enumerates physical drives
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Downloader.Win32.InnoBundle.amco?


File Info:

name: 221715072BAF37393782.mlw
path: /opt/CAPEv2/storage/binaries/d5afcacd97e9c9951644d14c3ca04244c275df7f0e59117c45b5ed3d92652e03
crc32: C3E84B9E
md5: 221715072baf37393782b314d87f920d
sha1: a0a77b7c7fd321db8620f726ca9d5552505c7cc9
sha256: d5afcacd97e9c9951644d14c3ca04244c275df7f0e59117c45b5ed3d92652e03
sha512: 58bdf2211bb56bf8d84be0f66693c071b2e63e5442cd05ea2af571e58a729da61560dc1bbce6f814705b74b97ec71a4ac6a408c1da48fadcf626a6e7eaa1afe2
ssdeep: 196608:N1DdgrdVc+3R/JBUMCFnFbNK+XEn7w+ofmF6WE0I/FeGjKu6AOjx00ShVXpI:N1KrdfR/JBuFFbSo+F1AYjrpi0SHC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T156D6237FB268A13FC45B4B3189B393508877BB54681B8C2F57F00A6DCF629711E3A616
sha3_384: afc9f68a814ac5ce287e412d46c33cae529d282d982e746f55487e06757a44d7aac057a7f6e0f8d2e3048b07055670a8
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-11-15 09:48:30

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: memtest86-usb Setup (r2312141200)
FileVersion: 1.5.1001.0
LegalCopyright:
OriginalFileName:
ProductName: memtest86-usb
ProductVersion: 1.5.1001.0
Translation: 0x0000 0x04b0

Downloader.Win32.InnoBundle.amco also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.InnoBundle.1!c
SkyhighBehavesLike.Win32.PUP.rc
McAfeeArtemis!221715072BAF
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Agent.Velk
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/grayware_confidence_70% (D)
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:Downloader.Win32.InnoBundle.amco
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13fa22b5
F-SecureHeuristic.HEUR/AGEN.1368613
AviraHEUR/AGEN.1368613
ZoneAlarmnot-a-virus:Downloader.Win32.InnoBundle.amco
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H07LL23
MaxSecureTrojan.Malware.221504733.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.c7fd32
DeepInstinctMALICIOUS

How to remove Downloader.Win32.InnoBundle.amco?

Downloader.Win32.InnoBundle.amco removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment