Malware

Application.Bundler.FileTour.T malicious file

Malware Removal

The Application.Bundler.FileTour.T is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.FileTour.T virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

How to determine Application.Bundler.FileTour.T?


File Info:

crc32: 8206ABDF
md5: 71cfb279d0eafab7fbd900557ee1eb4e
name: 71CFB279D0EAFAB7FBD900557EE1EB4E.mlw
sha1: ccb241f5b7f4ab2c06b2630508d8030974c600bc
sha256: 158ca51581831fc797d2014f55ec57c732f02541f475c47d0938b26d6b56370f
sha512: d38ea06c967526725190751b2a4b1294eb88b11e6bfdc60fc13666d98178cf8c6714ec3e6ab50539b565a7f06d1976c44bcf134e53dc3d6f913059045ae367ff
ssdeep: 24576:B7blb6Q65pOlZN42pUR0AjRyn+FeVGmxxFVMu5U3elS67aRq8Imj4Y:B75mQKpOlMV0ayn+FeVGmhyu5UuB+sm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: x423cx442ax43dox432x43aa __
ProductVersion: 0.3
FileDescription: x423cx442ax43dox432x43aa __ Setup
Translation: 0x0000 0x04b0

Application.Bundler.FileTour.T also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Moneyinst.937
ClamAVWin.Malware.Ursu-7346057-0
ALYacApplication.Bundler.FileTour.T
CylanceUnsafe
ZillyaAdware.DealPly.Win32.212134
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.cad884c1
K7GWAdware ( 0053f8811 )
K7AntiVirusTrojan ( 0054654a1 )
SymantecPUA.Gen.2
ESET-NOD32Win32/Adware.FileTour.FHO
APEXMalicious
AvastOther:Malware-gen [Trj]
CynetMalicious (score: 99)
Kasperskynot-a-virus:AdWare.Win32.DealPly.dytoi
BitDefenderApplication.Bundler.FileTour.T
NANO-AntivirusTrojan.InnoSetup.DealPly.fhowxj
MicroWorld-eScanApplication.Bundler.FileTour.T
TencentWin32.Adware.Dealply.Ahox
SophosFileTour (PUA)
Comodofls.noname@0
BitDefenderThetaAI:Packer.9C81F4BB17
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionFileTour
FireEyeApplication.Bundler.FileTour.T
EmsisoftApplication.Bundler.FileTour.T (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.FileTour.ljy
AviraHEUR/AGEN.1112384
Antiy-AVLTrojan/Generic.ASBOL.C562
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitApplication.Bundler.FileTour.T
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.dytoi
GDataApplication.Bundler.FileTour.T
AhnLab-V3PUP/Win32.InstallCore.R240806
McAfeeFileTour
MAXmalware (ai score=71)
MalwarebytesAdware.Csdimonetize
PandaTrj/CI.A
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/FileTour
AVGOther:Malware-gen [Trj]
Paloaltogeneric.ml

How to remove Application.Bundler.FileTour.T?

Application.Bundler.FileTour.T removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment