PUA

PUA:Win32/FlashHelper removal tips

Malware Removal

The PUA:Win32/FlashHelper is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/FlashHelper virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PUA:Win32/FlashHelper?


File Info:

name: 2AEF90446EF84BB7F4A2.mlw
path: /opt/CAPEv2/storage/binaries/d82e75634000932887d9aadd64c4875698e8c495fb6dc7deada106e00d27bf48
crc32: 1CFCC761
md5: 2aef90446ef84bb7f4a2be1110ffbd9d
sha1: d20f3e0d12bb99ec63435514e40df5e5d232cf76
sha256: d82e75634000932887d9aadd64c4875698e8c495fb6dc7deada106e00d27bf48
sha512: 5e76386eedcc78c232885dba41465ae557fdc9408ef438d1cc9b1a670d377d21e85a87309904556da38ec59cac03ffdb455155976ab4043f2600a5c5db89771c
ssdeep: 24576:4+nxeLO5cA/TnPT7nsbPLf/RoLL9C4jqxcYI:1nxn3c/YY4jpl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1733522D1A75BEC71F0143133B916D11C73465C9980C1EABBA76DF88EB43A0A64CF9B29
sha3_384: 0fb864fcc73934de95d22c8519a8c3e7e84940639d26d8f16833620a8f1316fcda6599947b12ec72c1137098e69b321b
ep_bytes: 60be00f05c008dbe0020e3ff57eb0b90
timestamp: 2022-01-20 07:02:19

Version Info:

0: [No Data]

PUA:Win32/FlashHelper also known as:

LionicAdware.Win32.FlashServ.2!c
MicroWorld-eScanTrojan.GenericKD.48676851
FireEyeTrojan.GenericKD.48676851
ALYacTrojan.GenericKD.48676851
CylanceUnsafe
ZillyaAdware.FlashServ.Win32.90
SangforAdware.Win32.Flashserv.V51m
AlibabaAdWare:Win32/FlashServ.80946c4a
Cybereasonmalicious.d12bb9
CyrenW32/Trojan.JWRW-6844
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.FlashServ.gen
BitDefenderTrojan.GenericKD.48676851
NANO-AntivirusRiskware.Win32.FlashServ.jrmupc
RisingAdware.FlashServ!8.13AEF (CLOUD)
Ad-AwareTrojan.GenericKD.48676851
SophosGeneric PUA NC (PUA)
VIPRETrojan.GenericKD.48676851
McAfee-GW-EditionBehavesLike.Win32.VirRansom.tc
EmsisoftTrojan.GenericKD.48676851 (B)
GDataTrojan.GenericKD.48676851
GoogleDetected
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.6F00
ArcabitTrojan.Generic.D2E6BFF3
MicrosoftPUA:Win32/FlashHelper
CynetMalicious (score: 100)
AhnLab-V3PUP/Win.AdLoad.R471470
McAfeeGenericRXAA-AA!2AEF90446EF8
MalwarebytesMalware.AI.2902881398
TrendMicro-HouseCallTROJ_GEN.R002H07BM22
YandexPUA.FlashServ!oyzGgCl1S94
MaxSecureTrojan.Malware.74521221.susgen
PandaTrj/CI.A

How to remove PUA:Win32/FlashHelper?

PUA:Win32/FlashHelper removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment