Adware

Win32/Adware.FileTour.FHO removal instruction

Malware Removal

The Win32/Adware.FileTour.FHO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.FileTour.FHO virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Adware.FileTour.FHO?


File Info:

crc32: 6EE821EB
md5: c77eed0ea2d112e5454c11f6fab70b6e
name: C77EED0EA2D112E5454C11F6FAB70B6E.mlw
sha1: e7fff991151b93c94ece8d5b769dfbd5bc8b82dc
sha256: 5fe8a2228bfcd7aa67d00731c656592acae8b721744ef115b38b7a8817693d84
sha512: 19814332b635f20ed1cd627691780e9a6ceca3eaaea6e663b75a5ca1a230a91ead8895f17ecffc3bb7b96ce99e06fe38af3e77afb9cf7029b2d44b0b227ea649
ssdeep: 24576:z7blPCcxdrkW32RNGM9+l7WZWB3c4N41UyyGau0TKa375mV/E7A1Xc67aRq8Imjj:z75KmBj4Zw3HNxyyG50jr5mVcU1b+smH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: x423cx442ax43dox432x43aa ____
ProductVersion: 0.1
FileDescription: x423cx442ax43dox432x43aa ____ Setup
Translation: 0x0000 0x04b0

Win32/Adware.FileTour.FHO also known as:

K7AntiVirusTrojan ( 0054654a1 )
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Moneyinst.975
CynetMalicious (score: 99)
ALYacApplication.Bundler.FileTour.T
CylanceUnsafe
ZillyaAdware.DealPly.Win32.214976
SangforTrojan.Win32.Malware.gen
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.64a2e499
K7GWTrojan ( 0054654a1 )
Cybereasonmalicious.ea2d11
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/Adware.FileTour.FHO
APEXMalicious
AvastOther:Malware-gen [Trj]
ClamAVWin.Malware.Ursu-7346057-0
Kasperskynot-a-virus:AdWare.Win32.DealPly.eandu
BitDefenderApplication.Bundler.FileTour.T
NANO-AntivirusTrojan.InnoSetup.DealPly.fhowxj
MicroWorld-eScanApplication.Bundler.FileTour.T
TencentWin32.Adware.Dealply.Syru
SophosGeneric PUA OH (PUA)
ComodoApplicUnwnt@#2fmga1b9limtu
F-SecureHeuristic.HEUR/AGEN.1112384
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.tc
FireEyeApplication.Bundler.FileTour.T
EmsisoftApplication.Bundler.FileTour.T (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1112384
MicrosoftTrojan:Win32/Occamy.C
ArcabitApplication.Bundler.FileTour.T
SUPERAntiSpywarePUP.DealPly/Variant
GDataApplication.Bundler.FileTour.T
AhnLab-V3PUP/Win32.InstallCore.R241363
McAfeeFileTour
MAXmalware (ai score=73)
VBA32Adware.DealPly
MalwarebytesAdware.FileTour
PandaTrj/CI.A
YandexPUA.DealPly!QYVTqkapgf4
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/FileTour
AVGOther:Malware-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Adware.FileTour.FHO?

Win32/Adware.FileTour.FHO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment