Adware

BScope.Adware.FileTour removal guide

Malware Removal

The BScope.Adware.FileTour is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Adware.FileTour virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects VirtualBox through the presence of a library
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a file
  • Attempts to detect VMware using known mutexes
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine BScope.Adware.FileTour?


File Info:

name: E84F75542E9285BEAB3F.mlw
path: /opt/CAPEv2/storage/binaries/f2de238cb8d0a6d1d8cf76341b10609b4b510f3ba3492a9e93d6ad06adeb26ce
crc32: 7A831CC2
md5: e84f75542e9285beab3f0c5817c0a74e
sha1: 29bc4cf265ec1b3c0a13d583cb9f7076e1858ffb
sha256: f2de238cb8d0a6d1d8cf76341b10609b4b510f3ba3492a9e93d6ad06adeb26ce
sha512: 40c27b2c5a84ae2f2f6a6931013142b8720934e0bc59b20d6f6f7d17fd10866e0224865e62e1b9bf32475fecdbe49b0045836ed44451d6228bc73492335204b2
ssdeep: 24576:NXKHwJ2soBpxuZ5w2q7iTus5PXGuCNT3b2+KTUrovqIUlj25nCU/tivCWn:4CcvA5jjpPlCoLTSovqINX/oPn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E35533761A5E4C86CA20FC744FA8BD056B756C476FBCE31250C62C86D23798BCAE3674
sha3_384: 649b7905051d3d691cca4598224637185693bd78a8e03b217e4fa44d947801d09e27e7e2a51fb27eb418b172b80c6d43
ep_bytes: 6a606838756000e810020000bf940000
timestamp: 2022-04-25 23:08:18

Version Info:

0: [No Data]

BScope.Adware.FileTour also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforARMADILLO17
Cybereasonmalicious.265ec1
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
KasperskyVHO:Trojan-Ransom.Win32.Blocker.gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Generic@AI.100 (RDMK:cmRtazqLTyDuUK/iWuRpBhR46av9)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Crypt.XPACK.Gen
FireEyeGeneric.mg.e84f75542e9285be
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.okha
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
BitDefenderThetaGen:NN.ZexaF.34606.svW@aWxVkDki
VBA32BScope.Adware.FileTour
MalwarebytesMachineLearning/Anomalous.100%
MaxSecureTrojan.Malware.300983.susgen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove BScope.Adware.FileTour?

BScope.Adware.FileTour removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment