FileTour

By GoldSparrow in Adware

Threat Scorecard

Ranking: 16,770
Threat Level: 20 % (Normal)
Infected Computers: 668
First Seen: January 23, 2015
Last Seen: June 25, 2023
OS(es) Affected: Windows

FileTour is a detection name that refers to a family of adware-powered programs, which were discovered in the last week of September 2017. A wave of FileTour variants were detected when computer users submitted complaints that their browser started showing many ads that feature slogans like 'Results powered by FileTour,' 'Powered by FileTour,' 'Ads powered by FileTour,' 'Brought to you by FileTour,' 'Generated by FileTour' and 'Ads by FileTour.' The FileTour detection name is not used by all cybersecurity vendors and compromised users may find that their scanners may use the following names to refer to the objects utilized by the FileTour adware:

  • Adware/FileTour.A.2269
  • HEUR/QVM19.1.0000.Malware.Gen
  • Malware.Generic!ln1LE00ectG@2 (thunder)
  • RiskWare[Downloader]/Win32.LMN
  • Trojan.LoadMoney.1154
  • Win32/Adware.FileTour.BUD
  • Win32/Adware.FileTour.DSY
  • not-a-virus:Downloader.Win32.LMN.akw

The FileTour program is identical in behavior to adware we covered the same month such as CounterFlix and Setli. Observations show that FileTour may make modifications to how pages are loaded in the browser and add sponsored content from ad servers. The pages you spent the most time on may appear to include pop-up windows, floating ad boxes and open new tabs with promotional content. The FileTour adware may suggest users try out recommended software like System Optimizer Pro that has a trial version that doesn't boast a favorable reputation. Computer experts advise users to refrain from following links powered by FileTour and avoid installing apps that are promoted by the adware. Removing the FileTour adware and related data is possible with the help of a trusted anti-malware utility.

Registry Details

FileTour may create the following registry entry or registry entries:
Regexp file mask
%ALLUSERSPROFILE%\Synaptics\Synaptics.exe
%PROGRAMFILES(x86)%\Internet Explorer\InternetExp.exe

Trending

Most Viewed

Loading...