have you tried to block it via MIME-Type blocking?
Webprotection->Filteractions->Downloads->Block MIME-types
and than type in: application/x-shockwave-flash
Just for curiosity...have you ever resolved this, I have exactly the same request from a client, and the first lab results are the same like in your description.
There is an option to block flash completely. Flash by nature is a streaming protocol. under the content filter actions then anti-virus put a check into remove embedded objects./..that's a large hammer but something worth testing..[:)]