Adware

Adware.BetterSurf.15 removal tips

Malware Removal

The Adware.BetterSurf.15 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.BetterSurf.15 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Enumerates running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Steals private information from local Internet browsers
  • Attempts to create or modify a Browser Helper Object

How to determine Adware.BetterSurf.15?


File Info:

name: 9DFE3624E67053A378DD.mlw
path: /opt/CAPEv2/storage/binaries/073e11b7c0c1c066467211dbfe793abe2d3cae3ce9e4e6a0c1556626938e1dac
crc32: 0DC9AF00
md5: 9dfe3624e67053a378dd46ea4ac39e47
sha1: 0aa215ee6e7ed0c19744011396a3a2c8e7a54539
sha256: 073e11b7c0c1c066467211dbfe793abe2d3cae3ce9e4e6a0c1556626938e1dac
sha512: 9bb4eb22bbea337ba808da76da218c56cd68ded0c8b1c4211b6276ef35f7519d03ec4777e13c752741c1326345532adfc68d9cb055ee0526e0d2084151fb3fa1
ssdeep: 12288:FQM8cqG4GjeZHkwuPikQ7lKH5p5H9x15eZHkwuziDQBlKR5psxjlfk:FX8rG4GjeZEXi37l6Br15eZEriMBlm0Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9D423DA1FD39273E9CAB4771734EF9ED6F1B85840E361924F5A2EB93AE22C76150100
sha3_384: 3455e6a7aac296ff79ca16a4d5f94a8718ce79c533265fbce55c4c1e68740b9e488717f2568d6da0b796b22611c977a5
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

CompanyName: Media Watch
CompanyWebsite:
FileDescription:
FileVersion: 1.1
LegalCopyright:
ProductName: Media Watch home 11
ProductVersion: 1.1
Translation: 0x0000 0x04e4

Adware.BetterSurf.15 also known as:

LionicAdware.Win32.BetterSurf.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Amonetize.10
CynetMalicious (score: 100)
CAT-QuickHealAdware.BetterSurf.B5
ALYacGen:Variant.Mikey.74011
CylanceUnsafe
VIPREAdware.Bettersurf (fs)
SangforMalware.Generic-JS.Save.7cc5649c
CrowdStrikewin/grayware_confidence_100% (D)
AlibabaAdWare:Win32/Amonetize.7ea683a8
K7GWUnwanted-Program ( 0040f7f51 )
K7AntiVirusUnwanted-Program ( 0040f7f51 )
VirITAdware.Win32.BetterSurf.CGO
CyrenW32/Medfos.AE.gen!Eldorado
SymantecAdware.WebexpEnhanced
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_SPNR.0BCU14
Paloaltogeneric.ml
ClamAVWin.Adware.Bettersurf-9
Kasperskynot-a-virus:AdWare.Win32.BetterSurf.b
BitDefenderGen:Variant.Adware.BetterSurf.15
NANO-AntivirusRiskware.Win32.BetterSurf.cvrzvc
SUPERAntiSpywareAdware.BetterSurf/Variant
MicroWorld-eScanGen:Variant.Adware.BetterSurf.15
AvastNSIS:Amonetize-H [PUP]
TencentWin32.Adware.Bettersurf.Hzdu
EmsisoftApplication.InstallMon (A)
ComodoApplication.JS.BetterSurf.B@5c6sol
ZillyaAdware.BetterSurf.Win32.12712
TrendMicroTROJ_SPNR.0BCU14
McAfee-GW-EditionBehavesLike.Win32.AdwareBSurf.jc
FireEyeGen:Variant.Adware.BetterSurf.15
SophosBetterSurf (PUA)
GDataWin32.Adware.Amonetize.M
JiangminAdWare.BetterSurf.e
WebrootW32.Adware.Gen
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Generic.ASMalwNS.2781
KingsoftWin32.Troj.BetterSurf.b.(kcloud)
ArcabitTrojan.Adware.BetterSurf.15
ViRobotAdware.Bettersurf.649710.R
ZoneAlarmnot-a-virus:AdWare.Win32.BetterSurf.b
MicrosoftTrojan:Win32/Occamy.C
SentinelOneStatic AI – Malicious PE
AhnLab-V3Adware/Win32.BetterSurf.C233448
Acronissuspicious
McAfeeArtemis!9DFE3624E670
TACHYONTrojan-Clicker/W32.BetterSurf.649710
VBA32Adware.Amonetize
MalwarebytesAdware.BetterSurf
APEXMalicious
RisingTrojan.Win32.Generic.17BE35A0 (C64:YzY0Og1COjyeFRbr)
YandexPUA.BetterSurf!tAKTBBDgBWU
MAXmalware (ai score=100)
FortinetAdware/BetterSurf
AVGNSIS:Amonetize-H [PUP]
Cybereasonmalicious.4e6705
PandaTrj/NsisDownloader.A

How to remove Adware.BetterSurf.15?

Adware.BetterSurf.15 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment