Adware

Adware.BetterSurf.H removal tips

Malware Removal

The Adware.BetterSurf.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.BetterSurf.H virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware.BetterSurf.H?


File Info:

name: 84D8E90E6751CC492337.mlw
path: /opt/CAPEv2/storage/binaries/096c1dfc165c728dff9608e783d22ebe717cc649ee07ed5e486a8f920d482157
crc32: D22811CC
md5: 84d8e90e6751cc4923376282d6f8880d
sha1: 1a0a9527cfd14bf49dc212e35884e4f0d2856cc2
sha256: 096c1dfc165c728dff9608e783d22ebe717cc649ee07ed5e486a8f920d482157
sha512: 11d5cd4a5c6ffa76aed756df7e1097b2d48c4a4ee86a3bff7be66c1c35f74bd2b82fc39028918ef8ad7dc22155d7eccec05041bde3c2cef7716124e4a97e79ca
ssdeep: 12288:7uwrNOsG4GjeZHkwuPikQ7lKH5p5H9x1teZHkwuPivQjlKT5pRxqlfY:7tgsG4GjeZEXi37l6Br1teZEHiojl4ZB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15BD423FA0FE29273EAD7B07A5734EE9DDAF1F88940D351974B651AE93AE63C72100140
sha3_384: 806dfe376e8c8897f66924e145c7d379e10109159fdb7cb50277c3ff81e8029f89d83750b0b17608cdef716c88a66c22
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

CompanyName: Media Watch
CompanyWebsite:
FileDescription:
FileVersion: 1.1
LegalCopyright:
ProductName: Media Watch home 4181
ProductVersion: 1.1
Translation: 0x0000 0x04e4

Adware.BetterSurf.H also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.BetterSurf.2!c
tehtrisGeneric.Malware
CynetMalicious (score: 100)
CAT-QuickHealAdware.BetterSurf.B5
SkyhighRDN/Generic PUP.z
McAfeeArtemis!84D8E90E6751
Cylanceunsafe
SangforAdware.Win32.Bettersurf.Vjw2
CrowdStrikewin/grayware_confidence_100% (W)
BitDefenderAdware.BetterSurf.H
K7GWUnwanted-Program ( 0040f7f51 )
K7AntiVirusUnwanted-Program ( 0040f7f51 )
SymantecAdware.WebexpEnhanced
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Dropper.LokiBot-9938750-0
Kasperskynot-a-virus:AdWare.Win32.BetterSurf.b
AlibabaAdWare:Win32/Amonetize.e9973764
NANO-AntivirusRiskware.Win32.BetterSurf.cvthxc
ViRobotAdware.Bettersurf.649736.BG
MicroWorld-eScanAdware.BetterSurf.H
AvastNSIS:Amonetize-G [PUP]
TencentWin32.Adware.Bettersurf.Tzfl
TACHYONTrojan-Clicker/W32.BetterSurf.649736
EmsisoftApplication.InstallMon (A)
F-SecureAdware.ADWARE/Adware.Gen
DrWebTrojan.Amonetize.10
ZillyaAdware.BetterSurf.Win32.917
TrendMicroTROJ_SPNR.0BCP14
Trapminemalicious.high.ml.score
FireEyeAdware.BetterSurf.H
SophosBetterSurf (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.BetterSurf.e
WebrootW32.Adware.Gen
GoogleDetected
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Win32.Detplock
MicrosoftAdware:Win32/BetterSurf
XcitiumApplication.Win32.AdWare.BetterSurf.C@58yosa
ArcabitAdware.BetterSurf.H [many]
SUPERAntiSpywareAdware.BetterSurf/Variant
ZoneAlarmnot-a-virus:AdWare.Win32.BetterSurf.b
GDataWin32.Adware.Bettersurf.E
VaristW32/Medfos.AE.gen!Eldorado
AhnLab-V3Adware/Win32.BetterSurf.C233448
ALYacAdware.BetterSurf.H
MAXmalware (ai score=99)
VBA32Adware.Amonetize
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/NsisDownloader.A
TrendMicro-HouseCallTROJ_SPNR.0BCP14
RisingPUF.Amonetize!8.C5 (TFE:5:cqV4nwXZiWC)
YandexPUA.BetterSurf!s+8aANBGufg
Ikarusnot-a-virus:AdWare.BetterSurf
FortinetW32/Amonetize.F!tr
AVGNSIS:Amonetize-G [PUP]
DeepInstinctMALICIOUS

How to remove Adware.BetterSurf.H?

Adware.BetterSurf.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment