Adware

What is “Win32/Adware.FileTour.BL”?

Malware Removal

The Win32/Adware.FileTour.BL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.FileTour.BL virus can do?

  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Ukrainian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Adware.FileTour.BL?


File Info:

name: 8263EE39F7931EBCA8E5.mlw
path: /opt/CAPEv2/storage/binaries/5c7b568fd39125a41270284b6fd1989a4c913003999514773cfca1a1bb9e1166
crc32: 10429C4B
md5: 8263ee39f7931ebca8e5a426291b5ed8
sha1: 4b088c798e62134c4349f28e9d8e9d7399bb2fc0
sha256: 5c7b568fd39125a41270284b6fd1989a4c913003999514773cfca1a1bb9e1166
sha512: 6614399083cae241d6a83343108d9e276ea3b3f17ecdd0cbf535241077c305adb1e2f3642e85a838c8fa6a59d36692894a28d38970e2ed3820b42199c98bf7aa
ssdeep: 24576:uNEEJgFTKdXomETlNF5YBaS0QHvJyrsEZVLQBKX1oR7H1/HkO6T2uiuRkSHM4:s1dXQTDYMSjUsEZFABH8T5R/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D755B1272A5503ED0721B364C6BC5E4EC7F7D206E568C4B3EB49E4C0E3AA415CF6A9E
sha3_384: f930662de478c8d303cd53803b9deb92a2199725ca7e6342c2ff88392b289e931d892458b674824586ea93945866a3e8
ep_bytes: 558bec83c4f0b838f35200e8f02cedff
timestamp: 2014-09-13 17:52:57

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.1189
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0419 0x04e3

Win32/Adware.FileTour.BL also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.ArchSMS.lppn
MicroWorld-eScanGen:Variant.Application.Bundler.FileTour.3
FireEyeGeneric.mg.8263ee39f7931ebc
CAT-QuickHealHoax.FakeInstaller.A9
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaAdWare:Win32/FileTour.1e1ccfeb
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.9f7931
CyrenW32/A-006c1943!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.FileTour.BL
TrendMicro-HouseCallTROJ_GEN.R002C0GGT23
AvastWin32:FileTour-DG [Adw]
ClamAVWin.Keylogger.Banbra-9936388-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Application.Bundler.FileTour.3
NANO-AntivirusRiskware.Win32.ArchSMS.dezwsf
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
TencentMalware.Win32.Gencirc.11551095
TACHYONJoke/W32.DP-ArchSMS.1650688
SophosFileTour (PUA)
F-SecureTrojan.TR/Fraud.Gen7
DrWebTrojan.SMSSend.5457
ZillyaTrojan.ArchSMS.Win32.25830
TrendMicroTROJ_GEN.R002C0GGT23
McAfee-GW-EditionBehavesLike.Win32.Infected.th
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Application.Bundler.FileTour.3 (B)
GDataGen:Variant.Application.Bundler.FileTour.3
WebrootW32.Adware.Gen
GoogleDetected
AviraTR/Fraud.Gen7
Antiy-AVLHackTool[Hoax]/Win32.ArchSMS
XcitiumMalware@#241ns60hvephd
ArcabitTrojan.Application.Bundler.FileTour.3
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPUADlManager:Win32/Vintaller
CynetMalicious (score: 99)
AhnLab-V3Adware/Win32.SMSHoax.R121246
BitDefenderThetaGen:NN.ZelphiF.36350.KL0@a4LSi0dk
MAXmalware (ai score=71)
VBA32TScope.Trojan.Delf
MalwarebytesFileTour.Adware.Bundler.DDS
PandaTrj/Genetic.gen
APEXMalicious
RisingAdware.Vintaller!8.13407 (TFE:5:gFwRABEzUMG)
MaxSecureTrojan.Malware.7164915.susgen
FortinetRiskware/ArchSMS
AVGWin32:FileTour-DG [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Win32/Adware.FileTour.BL?

Win32/Adware.FileTour.BL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment