FileTour

By GoldSparrow in Adware

Threat Scorecard

Popularity Rank: 11,811
Threat Level: 20 % (Normal)
Infected Computers: 720
First Seen: January 23, 2015
Last Seen: December 23, 2025
OS(es) Affected: Windows

FileTour is a detection name that refers to a family of adware-powered programs, which were discovered in the last week of September 2017. A wave of FileTour variants were detected when computer users submitted complaints that their browser started showing many ads that feature slogans like 'Results powered by FileTour,' 'Powered by FileTour,' 'Ads powered by FileTour,' 'Brought to you by FileTour,' 'Generated by FileTour' and 'Ads by FileTour.' The FileTour detection name is not used by all cybersecurity vendors and compromised users may find that their scanners may use the following names to refer to the objects utilized by the FileTour adware:

  • Adware/FileTour.A.2269
  • HEUR/QVM19.1.0000.Malware.Gen
  • Malware.Generic!ln1LE00ectG@2 (thunder)
  • RiskWare[Downloader]/Win32.LMN
  • Trojan.LoadMoney.1154
  • Win32/Adware.FileTour.BUD
  • Win32/Adware.FileTour.DSY
  • not-a-virus:Downloader.Win32.LMN.akw

The FileTour program is identical in behavior to adware we covered the same month such as CounterFlix and Setli. Observations show that FileTour may make modifications to how pages are loaded in the browser and add sponsored content from ad servers. The pages you spent the most time on may appear to include pop-up windows, floating ad boxes and open new tabs with promotional content. The FileTour adware may suggest users try out recommended software like System Optimizer Pro that has a trial version that doesn't boast a favorable reputation. Computer experts advise users to refrain from following links powered by FileTour and avoid installing apps that are promoted by the adware. Removing the FileTour adware and related data is possible with the help of a trusted anti-malware utility.

Registry Details

FileTour may create the following registry entry or registry entries:
Regexp file mask
%ALLUSERSPROFILE%\Synaptics\Synaptics.exe
%PROGRAMFILES(x86)%\Internet Explorer\InternetExp.exe

Analysis Report

General information

Family Name: Adware.Filetour
Signature status: Self Signed

Known Samples

MD5: c2d843855dc96957a2a3b2eb8b5cd6e5
SHA1: 0e7bafaf927d68a5b132654d867cadb9f6974f3b
SHA256: 3CA1D9D2C2489026F739C68DAC2DB72E16D844CBC2235F2C24A947053B3A9BF5
File Size: 13.26 KB, 13256 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 64-bit executable
  • File is driver (IMAGE_SUBSYSTEM_NATIVE)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name G.Georgiev
File Description AC97 NT kernel mode driver
File Version 5, 1, 0, 2600
Internal Name acdrv
Legal Copyright Copyright © 2004 G.Georgiev
Original Filename acdrv.sys
Product Name acdrv
Product Version 5, 1, 0, 2600

Digital Signatures

Signer Root Status
GG GG Self Signed

Block Information

Total Blocks: 1
Potentially Malicious Blocks: 0
Whitelisted Blocks: 0
Unknown Blocks: 1

Visual Map

?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...