PUA

PUAAdvertising:Win32/FlashHelper removal guide

Malware Removal

The PUAAdvertising:Win32/FlashHelper is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUAAdvertising:Win32/FlashHelper virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PUAAdvertising:Win32/FlashHelper?


File Info:

crc32: 477168E0
md5: 742c8314dc5d70e32a667d8ea1c21427
name: 742C8314DC5D70E32A667D8EA1C21427.mlw
sha1: d275271139ba0aab5496fe632ec4372e2078d220
sha256: 56e3f1e8e046801ba42898fac0958064063801883b7b54f692c087e7f59f0a98
sha512: 3d73e136ddce6f6aa78b268b00db83faba3bcb69bcb44e799415816db0d9e8177b01da9151a4fe29b6cb8554f30eb2328d4e054a04f77134d379bef00f95ab87
ssdeep: 24576:dNmY+fSycE7sh2vPEJqmAq7tDsvOrSH8tnrzw0DHS/:7mY+6dh2v8kmh7UO2HqffDK
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright(C) 2019 x91cdx5e86x91cdx6a59x7f51x7edcx79d1x6280x6709x9650x516cx53f8.All Rights Reserved
InternalName: FlashHelperServices.exe
FileVersion: 2.3.0.38
CompanyName: x91cdx5e86x91cdx6a59x7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: Flash Helper Service
ProductVersion: 2.3.0.38
FileDescription: Flash Helper Service rc
OriginalFilename: FlashHelperService.exe
Translation: 0x0804 0x04b0

PUAAdvertising:Win32/FlashHelper also known as:

K7AntiVirusAdware ( 0055b8191 )
LionicAdware.Win32.FlashServ.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Application.Bulz.134121
CylanceUnsafe
ZillyaAdware.FlashServ.Win32.78
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaAdWare:Win32/2144FlashPlayer.cfb315c6
K7GWAdware ( 0055b8191 )
Cybereasonmalicious.4dc5d7
ESET-NOD32a variant of Win32/2144FlashPlayer.A potentially unwanted
AvastWin32:MiscX-gen [PUP]
Kasperskynot-a-virus:HEUR:AdWare.Win32.FlashServ.gen
BitDefenderGen:Variant.Application.Bulz.134121
MicroWorld-eScanGen:Variant.Application.Bulz.134121
Ad-AwareGen:Variant.Application.Bulz.134121
SophosGeneric ML PUA (PUA)
ComodoApplicUnwnt@#1ophp5gc9wy2q
TrendMicroPUA.Win32.FlashPlay2144.A
McAfee-GW-EditionArtemis!PUP
FireEyeGen:Variant.Application.Bulz.134121
EmsisoftGen:Variant.Application.Bulz.134121 (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.FlashServ.af
WebrootW32.Adware.Gen
MicrosoftPUAAdvertising:Win32/FlashHelper
GridinsoftPUP.FlashServ.ka!c
ArcabitTrojan.Application.Bulz.D20BE9
GDataGen:Variant.Application.Bulz.134121
McAfeeArtemis!742C8314DC5D
MAXmalware (ai score=77)
VBA32Adware.FlashServ
MalwarebytesPUP.Optional.ChinAd
PandaTrj/CI.A
TrendMicro-HouseCallPUA.Win32.FlashPlay2144.A
RisingAdware.FlashNews!1.CEA9 (CLASSIC)
MaxSecureTrojan.Malware.74521221.susgen
FortinetRiskware/2144FlashPlayer
AVGWin32:MiscX-gen [PUP]

How to remove PUAAdvertising:Win32/FlashHelper?

PUAAdvertising:Win32/FlashHelper removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment