PUP.2144FlashPlayer.B

The detection of PUP.2144FlashPlayer.B on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to address this detection promptly to prevent any potential harm to your system and data.

What Is PUP.2144FlashPlayer.B?

PUP.2144FlashPlayer.B is a type of malware that is categorized as a potentially unwanted program. This means that while it may not be as malicious as other types of malware, such as viruses or Trojans, it can still cause problems with your system and compromise your privacy. PUPs are often installed unintentionally by users, usually through software bundles or deceptive downloads.

How PUP.2144FlashPlayer.B Operates

PUP.2144FlashPlayer.B, like other PUPs, operates by installing itself on your system and then performing various unwanted actions. These actions can include displaying advertisements, collecting user data, and modifying system settings. PUPs can also install additional malware or unwanted programs on your system, which can lead to further problems. In some cases, PUPs can also compromise your system's security by creating vulnerabilities that can be exploited by other malware.

Symptoms of Infection

The symptoms of a PUP.2144FlashPlayer.B infection can vary, but common signs include unwanted advertisements, slow system performance, and unexpected changes to system settings. You may also notice that your browser homepage or search engine has been changed, or that new toolbars or extensions have been installed. In some cases, you may also experience pop-ups, redirects, or other unwanted browser behavior.

  • Unwanted advertisements or pop-ups
  • Slow system performance or crashes
  • Changes to system settings or browser configuration
  • Unexplained data usage or network activity
  • Appearance of new, unfamiliar programs or icons

How to Remove PUP.2144FlashPlayer.B

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or unwanted programs.
  3. Uninstall any suspicious programs or applications that were installed without your knowledge or consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.2144FlashPlayer.B from your system is essential to prevent any potential harm and to restore your system's performance and security. By following the steps outlined above, you can effectively remove this unwanted program and protect your system from future infections. It is also important to practice safe computing habits, such as avoiding suspicious downloads and being cautious when installing software, to prevent similar infections in the future.

Analysis Report

General information

Family Name: PUP.2144FlashPlayer.B
Signature status: Root Not Trusted

Known Samples

MD5: 431e876536732ef7b8ec9161dd033ad3
SHA1: f88d33f0dc18e1509068c04bff6ffaab4a032c84
File Size: 2.97 MB, 2971224 bytes
MD5: 118fe64142bee931d0aee2e98fb8d929
SHA1: 700f930f52aafbe213186683c2a4d3877dd6d146
SHA256: 2739C35DA3783B8A55D69BCE039162B2FF771B05DF28968C8A556821B4CC027C
File Size: 2.19 MB, 2188392 bytes
MD5: 239f9d4a19f46fa3b65b61d50ae62a2c
SHA1: 5a4657bcdd3387883fac701295fe261e68ea4bee
SHA256: 316E0937EFEB79341BBAAE1039013F6F04BEF3616302967EA7C06AF21EE5E875
File Size: 2.10 MB, 2103200 bytes
MD5: 7cc9813956507a89399fa6840f5d7e10
SHA1: 803d47196231e376024002fcd4764dd7788b701c
SHA256: 86D6176BB7BAA986B101A818599F1D7F4C82F00EFEE87ACE6557B05A4FC59702
File Size: 2.98 MB, 2980384 bytes
MD5: 0ba0bc4e44eacacb7d7e11ec6a9fafdc
SHA1: faa72c820dd9fc034eaff5979aee84463f41c588
SHA256: A8D36D59C8D6CB41130537FA27BD7F52D43DFBBDC4AC92E28853EBC3A9C81091
File Size: 2.50 MB, 2500696 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Chongqing Zhongcheng Network Technology Co., Ltd
File Description
  • FCPlay
  • Flash Center
  • FlashCenterSvc
File Version
  • 3.0.1.62
  • 3.0.1.53
  • 3.0.0.196
  • 2.6.1.43
  • 2.4.0.24
Internal Name
  • FCBrowse.exe
  • FCPlay.exe
  • FlashCenterSvc.exe
Legal Copyright
  • Copyright (C) 2021 Chongqing Zhongcheng Network Technology Co., Ltd
  • Copyright (C) 2022 Chongqing Zhongcheng Network Technology Co., Ltd
Original Filename
  • FCBrowse.exe
  • FCPlay.exe
  • FlashCenterSvc.exe
Product Name
  • FCPlay
  • Flash Center
  • FlashCenterSvc
Product Version
  • 3.0.1.62
  • 3.0.1.53
  • 3.0.0.196
  • 2.6.1.43
  • 2.4.0.24

Digital Signatures

Signer Root Status
Chongqing Zhongcheng Network Technology Co. Ltd. DigiCert Trusted Root G4 Root Not Trusted
Chongqing Zhongcheng Network Technology Co. Ltd. VeriSign Class 3 Public Primary Certification Authority - G5 Root Not Trusted

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 6,262
Potentially Malicious Blocks: 436
Whitelisted Blocks: 5,699
Unknown Blocks: 127

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 x x x 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 x 0 0 0 0 x 0 x x 0 0 x 0 0 x x 0 x x 0 0 0 0 0 2 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x x 1 x 0 0 0 0 0 0 0 x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 x x x 0 0 0 x x 0 x x 0 x x x 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 x x x x x 0 x 0 x 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 0 x 0 0 0 0 x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x ? x x ? 0 0 0 ? x ? x x x x 0 ? x ? x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 x ? 0 x x x x x 0 0 x ? x 0 x ? ? ? ? x 0 x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? x 0 x x x x x 0 ? x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 x x x x x x x x 0 0 0 0 0 0 x 0 0 0 0 0 x x ? x x x x ? ? ? ? x x x ? ? 0 0 0 0 ? 0 ? 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • 2144FlashPlayer.B
  • BMMedia.B
  • Conduit.A
  • Elex.R
  • GetNow.A
Show More
  • HeavensGate.A
  • InsAssist.A
  • Machaer.A
  • Machaer.B
  • Machaer.C
  • Ypack.B

Windows API Usage

Category API
Network Winsock2
  • WSAStartup

Related Posts

Trending

Most Viewed

Loading...