Home Malware Programs Potentially Unwanted Programs (PUPs) FlowSurf

FlowSurf

Posted: April 23, 2014

Threat Metric

Ranking: 4,983
Threat Level: 2/10
Infected PCs: 66,745
First Seen: April 22, 2014
Last Seen: October 14, 2023
OS(es) Affected: Windows

FlowSurf Screenshot 1FlowSurf is a potentially unwanted program (PUP)/adware that may enter a computer system, or it may be installed on a PC as an extra program packaged with free software. FlowSurf may interfere with a PC user's browsing activity by displaying unwanted ads containing various discount coupon offers and deals or affiliate links for online purchases, among search results in any popular search engine. FlowSurf may continuously divert a computer user to questionable websites that may be designed for advertising purposes. FlowSurf may be produced with the goal to generate advertising revenue from increased web traffic and clicks on ads. If a computer user clicks on the FlowSurf's ads, he may unknowingly install more adware or PUPs on a PC.

FlowSurf Screenshot 2FlowSurf Screenshot 3

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\Flowsurf\flowsurf.dll File name: flowsurf.dll
Size: 69.12 KB (69120 bytes)
MD5: 39a567e0c38542483c50c0bda30b71a3
Detection count: 14,095
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Flowsurf\flowsurf.dll
Group: Malware file
Last Updated: April 19, 2023
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files\Flwsrf\ijs.exe.vir File name: ijs.exe.vir
Size: 164.35 KB (164352 bytes)
MD5: 20cf0b2a87d2cfc94d53911d268f7414
Detection count: 8,624
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files\Flwsrf\ijs.exe.vir
Group: Malware file
Last Updated: November 4, 2020
C:\Program Files (x86)\Flowsurf\flowsurf.dll File name: flowsurf.dll
Size: 61.44 KB (61440 bytes)
MD5: 281838d65b1d5735cf71668d96a37a68
Detection count: 5,668
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Flowsurf\flowsurf.dll
Group: Malware file
Last Updated: March 5, 2023
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files\Flwsrf\uninstall.exe.vir File name: uninstall.exe.vir
Size: 62.01 KB (62011 bytes)
MD5: db1df7bb1ffb860852a7fe27ae8cd2c0
Detection count: 1,576
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files\Flwsrf\uninstall.exe.vir
Group: Malware file
Last Updated: February 23, 2022
%PROGRAMFILES%\Flwsrf\upfs7214.exe File name: upfs7214.exe
Size: 58.98 KB (58988 bytes)
MD5: 3953c60db38eafb23f71055914caa2ce
Detection count: 845
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Flwsrf
Group: Malware file
Last Updated: August 27, 2016
C:\Program Files (x86)\Flowsurf\fsupd.exe File name: fsupd.exe
Size: 57.39 KB (57392 bytes)
MD5: 2b140f9d8cd365bf8522a5118d0b06ef
Detection count: 548
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Flowsurf\fsupd.exe
Group: Malware file
Last Updated: April 27, 2023
%PROGRAMFILES%\Flowsurf\fsupd.exe File name: fsupd.exe
Size: 57.29 KB (57295 bytes)
MD5: 6784919e1b1c7a5a01de2f31847b7280
Detection count: 504
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Flowsurf
Group: Malware file
Last Updated: January 16, 2023
%PROGRAMFILES(x86)%\Flwsrf\ijs.exe File name: ijs.exe
Size: 247.29 KB (247296 bytes)
MD5: d250c2436964cafac44eb7acce1b9392
Detection count: 159
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Flwsrf
Group: Malware file
Last Updated: August 27, 2016
%PROGRAMFILES%\Flowsurf\FlowSurf.dll File name: FlowSurf.dll
Size: 435.58 KB (435585 bytes)
MD5: 0d1133d5b2cc62f8e0091a4e49390dfb
Detection count: 74
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Flowsurf
Group: Malware file
Last Updated: April 9, 2016
%PROGRAMFILES%\Flowsurf\FlowSurf.dll File name: FlowSurf.dll
Size: 69.12 KB (69120 bytes)
MD5: 00176e372b59b9664a93f5cc43d68e48
Detection count: 35
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Flowsurf
Group: Malware file
Last Updated: December 13, 2019

Registry Modifications

The following newly produced Registry Values are:

CLSID{6CA2A4DE-483E-456B-8634-6445460D7097}{A8018C54-B702-4D52-9ACC-8CA78911E633}{C321541F-B22D-4593-AC1A-9634812A4E40}{C6A846C5-D67F-48B4-8552-C22354E56966}{E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0}File name without pathBundle_FlowsurfCB[1].exeHKEY..\..\..\..{RegistryKeys}Software\FlowsurfSoftware\InstallPath\Status\FlowsurfCBSOFTWARE\Microsoft\Internet Explorer\Extensions\{6CA2A4DE-483E-456B-8634-6445460D7097}Software\Microsoft\Internet Explorer\LowRegistry\Extensions\CmdMapping\{6CA2A4DE-483E-456B-8634-6445460D7097}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6CA2A4DE-483E-456B-8634-6445460D7097}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6CA2A4DE-483E-456B-8634-6445460D7097}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0}SOFTWARE\Mozilla\Firefox\Extensions\jid1-tofUlNEIFlkUIA@jetpackSOFTWARE\Wow6432Node\FlowsurfSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{6CA2A4DE-483E-456B-8634-6445460D7097}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\jid1-tofUlNEIFlkUIA@jetpackSOFTWARE\Wow6432Node\Wow6432Node\Microsoft\Internet Explorer\Extensions\{6CA2A4DE-483E-456B-8634-6445460D7097}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}FlowsurfFlwsrf

Additional Information

The following directories were created:
%PROGRAMFILES%\Flowsurf%PROGRAMFILES%\Flwsrf%PROGRAMFILES(x86)%\Flowsurf%PROGRAMFILES(x86)%\Flwsrf
Loading...