Home Malware Programs Potentially Unwanted Programs (PUPs) FlowSpirit

FlowSpirit

Posted: April 27, 2017

Threat Metric

Ranking: 4,860
Threat Level: 1/10
Infected PCs: 16,868
First Seen: April 27, 2017
Last Seen: October 12, 2023
OS(es) Affected: Windows

FlowSpirit (distributed as TrafficSpirit to English speakers) is a program that belongs to a Chinese software publisher that specializes in webmaster tools. Many anti-virus vendors categorize FlowSpirit as a Potentially Unwanted Program (PUP) because this software carries out some suspicious activities and its overall behavior might be rather weird. In addition to this, FlowSpirit's true purpose is also very shady since the software is meant to be used as a traffic bot that can increase the amount of traffic that a Web page receives significantly.

This PUP operates by asking users to enter the website that they want to generate traffic to. Once this is done, other clients who run the FlowSpirit software may start visiting the user's website automatically via hidden Web browser instances that may consume a significant amount of hardware and network resources. In the meantime, the user who has decided to use FlowSpirit to boost their website's traffic also may experience the same thing – their installation of FlowSpirit may launch hidden Web browser instances and browse the pages of other users silently. In short, FlowSpirit's purpose is meant to help webmasters exchange traffic between their websites, therefore making their pages seem more popular artificially.

Although FlowSpirit is promoted as a reliable application, users might want to think twice whether they'd like to run a program that connects to various websites silently without revealing their content. It is not known whether FlowSpirit's security measures are enough to keep corrupted links out of the system, and a seemingly friendly traffic exchange operation may end up being more unsafe than it looks. It is recommended to remove FlowSpirit with the assistance of a credible cyber security software suite.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\System32\drivers\flowflt64.sys File name: flowflt64.sys
Size: 985.12 KB (985128 bytes)
MD5: 061cf22b54d38fd1a9e305786550dd13
Detection count: 64
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: May 5, 2017
\??\C:\Windows\system32\drivers\flowsys64.sys File name: flowsys64.sys
Size: 37.41 KB (37416 bytes)
MD5: 5ede982af8b75c305d280ad6448b0c41
Detection count: 23
File type: System file
Mime Type: unknown/sys
Path: \??\C:\Windows\system32\drivers
Group: Malware file
Last Updated: May 5, 2017
C:\WINDOWS\System32\drivers\flowflt64.sys File name: flowflt64.sys
Size: 962.1 KB (962104 bytes)
MD5: 1011439990005fd334cc4aae015a459c
Detection count: 19
File type: System file
Mime Type: unknown/sys
Path: C:\WINDOWS\System32\drivers\flowflt64.sys
Group: Malware file
Last Updated: January 27, 2022
%WINDIR%\System32\drivers\flowflt64.sys File name: flowflt64.sys
Size: 36.39 KB (36392 bytes)
MD5: 0d1818b0e2a188bbae6dc9d51b525b51
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: May 5, 2017

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%TEMP%\ipts_[NUMBERS].7z%USERPROFILE%\Desktop\ipts_[NUMBERS].7z%USERPROFILE%\Documents\ipts_[NUMBERS].7zHKEY..\..\..\..{RegistryKeys}SOFTWARE\JinglingSYSTEM\ControlSet001\services\flowfltSYSTEM\CurrentControlSet\services\flowflt
Loading...