Adware

Adware.BetterSurf.B5 (file analysis)

Malware Removal

The Adware.BetterSurf.B5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.BetterSurf.B5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering

How to determine Adware.BetterSurf.B5?


File Info:

name: F7903D0E773935656F31.mlw
path: /opt/CAPEv2/storage/binaries/60f282420c012c5a10958fde141d1ffb34038ff0b081be27bc3b144361a73546
crc32: 0388A076
md5: f7903d0e773935656f3141111f973a8d
sha1: 64c8345ec2aaa300c072386d3003d1a3899da8a1
sha256: 60f282420c012c5a10958fde141d1ffb34038ff0b081be27bc3b144361a73546
sha512: 58361c50a152f8ff1f523a1ebcb384b55e94b5b6beb6a5c4731e7ccb9cc763af1cf630a8c9641254c16337c20f05e43028b6fa60bdbb1942608ad7f21771c9ab
ssdeep: 12288:kpmStZTf00WG4GjeZHkwuPikQ7lKH5p5H9x1KeZHkwuli3QblKL5pFx3iR0:kpmsTfhWG4GjeZEXi37l6Br1KeZE9iAG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100D423EB1FA64173E9E7F17E1B30EA6DE7B1B88C40E365874BA61E693BD53871600140
sha3_384: ec5108390a4098c7c92ebc706a0c9c2d82ab4269ac8f8ab7253a1a160dc62131c36a96f8f9eb351601afdb401d3ee842
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

CompanyName: Media Watch
CompanyWebsite:
FileDescription:
FileVersion: 1.1
LegalCopyright:
ProductName: Media Watch home 7714
ProductVersion: 1.1
Translation: 0x0000 0x04e4

Adware.BetterSurf.B5 also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.BetterSurf.lXl2
Elasticmalicious (high confidence)
DrWebTrojan.Amonetize.10
MicroWorld-eScanGen:Variant.Adware.BetterSurf.15
ClamAVWin.Dropper.LokiBot-9938750-0
FireEyeGen:Variant.Adware.BetterSurf.15
CAT-QuickHealAdware.BetterSurf.B5
SkyhighRDN/Generic PUP.z
ALYacGen:Variant.Adware.BetterSurf.15
Cylanceunsafe
ZillyaAdware.Convagent.Win32.3671
SangforAdware.Win32.Bettersurf.Vcg6
K7AntiVirusUnwanted-Program ( 0040f7f51 )
AlibabaAdWare:Win32/Amonetize.dfa629c1
K7GWUnwanted-Program ( 0040f7f51 )
CrowdStrikewin/grayware_confidence_100% (W)
VirITTrojan.Win32.Amonetize.K
SymantecAdware.WebexpEnhanced
tehtrisGeneric.Malware
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.BetterSurf.b
BitDefenderGen:Variant.Adware.BetterSurf.15
NANO-AntivirusRiskware.Win32.BetterSurf.cvthxc
SUPERAntiSpywareAdware.BetterSurf/Variant
AvastNSIS:Amonetize-G [PUP]
TencentWin32.Adware.Bettersurf.Mgil
SophosBetterSurf (PUA)
F-SecureAdware.ADWARE/Adware.Gen
VIPREGen:Variant.Adware.BetterSurf.15
TrendMicroTROJ_SPNR.0BCP14
Trapminemalicious.high.ml.score
EmsisoftApplication.InstallMon (A)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Adware.Bettersurf.E
JiangminAdWare.Amonetize.arbm
WebrootW32.Adware.Gen
GoogleDetected
AviraADWARE/Adware.Gen7
Kingsoftmalware.kb.a.747
XcitiumApplication.Win32.AdWare.BetterSurf.C@58yosa
ArcabitTrojan.Adware.BetterSurf.15 [many]
ViRobotAdware.Bettersurf.649729.BN
ZoneAlarmnot-a-virus:AdWare.Win32.BetterSurf.b
MicrosoftAdware:Win32/BetterSurf
VaristW32/Medfos.AE.gen!Eldorado
AhnLab-V3Adware/Win32.BetterSurf.C233448
McAfeeArtemis!F7903D0E7739
MAXmalware (ai score=99)
VBA32Adware.Amonetize
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/NsisDownloader.A
TrendMicro-HouseCallTROJ_SPNR.0BCP14
RisingPUF.Amonetize!8.C5 (TFE:5:cqV4nwXZiWC)
YandexPUA.BetterSurf!ye39biwxyto
Ikarusnot-a-virus:AdWare.Win32.BetterSurf
FortinetW32/Amonetize.F!tr
AVGNSIS:Amonetize-G [PUP]
DeepInstinctMALICIOUS

How to remove Adware.BetterSurf.B5?

Adware.BetterSurf.B5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment