Adware

Adware.BetterSurf.H malicious file

Malware Removal

The Adware.BetterSurf.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.BetterSurf.H virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to create or modify a Browser Helper Object
  • Touches a file containing cookies, possibly for information gathering

How to determine Adware.BetterSurf.H?


File Info:

name: 4B6B4487D817A3393433.mlw
path: /opt/CAPEv2/storage/binaries/608d7ee8f1387ae5098ea7db1c922c5a55b175cfe807b33967d829dcbd832a95
crc32: 83DE68AC
md5: 4b6b4487d817a3393433a1f41ffa741a
sha1: f416cda66d512eefb26c833c9b89c5165cf677a2
sha256: 608d7ee8f1387ae5098ea7db1c922c5a55b175cfe807b33967d829dcbd832a95
sha512: 0182e2c1d2ccadc74d55a682dccc1fb8feedcb57db787eb5877bf460f84b096221f1f2436928788aef3437015b22cf55d25a3cc169966b1e7491a7a5ba5e460d
ssdeep: 12288:r/hyISOBwwG4GjeZHkwuPikQ7lKH5p5H9x1QeZHkwu1iTQ1lKD5pjxloTd8zbB:r/kHOBwwG4GjeZEXi37l6Br1QeZENi84
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124D423EA1FE16533D5CE603A4B30EF5ED6F0754884E3AA978FA61DAE3EE22D71510500
sha3_384: b3ef45e2823459f809ab1e13250d85823b16869268c71eb28785f3b4eb986826a432a252f3bf084fe32f01650abb65af
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

CompanyName: Media Watch
CompanyWebsite:
FileDescription:
FileVersion: 1.1
LegalCopyright:
ProductName: Media Watch home 2677
ProductVersion: 1.1
Translation: 0x0000 0x04e4

Adware.BetterSurf.H also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.BetterSurf.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.BetterSurf.H
ClamAVWin.Dropper.LokiBot-9938750-0
FireEyeAdware.BetterSurf.H
CAT-QuickHealAdware.BetterSurf.B5
SkyhighRDN/Generic PUP.z
McAfeeArtemis!4B6B4487D817
MalwarebytesGeneric.Malware.AI.DDS
SangforPUP.Win32.BetterSurf.J
K7AntiVirusUnwanted-Program ( 0040f7f51 )
BitDefenderAdware.BetterSurf.H
K7GWUnwanted-Program ( 0040f7f51 )
CrowdStrikewin/grayware_confidence_100% (D)
VirITTrojan.Win32.Amonetize.K
SymantecAdware.WebexpEnhanced
tehtrisGeneric.Malware
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.BetterSurf.b
AlibabaAdWare:Win32/Amonetize.e9973764
NANO-AntivirusRiskware.Win32.BetterSurf.cvthxc
TencentWin32.Adware.Bettersurf.Mgil
SophosBetterSurf (PUA)
F-SecureAdware.ADWARE/Adware.Gen
DrWebTrojan.Amonetize.10
VIPREAdware.BetterSurf.H
TrendMicroTROJ_SPNR.0BCP14
Trapminemalicious.high.ml.score
EmsisoftApplication.InstallMon (A)
Ikarusnot-a-virus:AdWare.BetterSurf
GDataWin32.Adware.Bettersurf.E
JiangminAdWare.Amonetize.arbm
WebrootW32.Adware.Gen
GoogleDetected
AviraADWARE/Adware.Gen7
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Detplock
Kingsoftmalware.kb.a.747
XcitiumApplication.JS.BetterSurf.B@5c6sol
ArcabitAdware.BetterSurf.H [many]
SUPERAntiSpywareAdware.BetterSurf/Variant
ZoneAlarmnot-a-virus:AdWare.Win32.BetterSurf.b
MicrosoftAdware:Win32/BetterSurf
VaristW32/Medfos.AE.gen!Eldorado
AhnLab-V3Adware/Win32.BetterSurf.C233448
ALYacAdware.BetterSurf.H
DeepInstinctMALICIOUS
VBA32Adware.Amonetize
Cylanceunsafe
PandaTrj/NsisDownloader.A
TrendMicro-HouseCallTROJ_SPNR.0BCP14
RisingPUF.Amonetize!8.C5 (TFE:5:cqV4nwXZiWC)
YandexPUA.BetterSurf!VUxbyZ6p5lQ
SentinelOneStatic AI – Suspicious PE
FortinetAdware/BetterSurf
AVGNSIS:Amonetize-G [PUP]
AvastNSIS:Amonetize-G [PUP]

How to remove Adware.BetterSurf.H?

Adware.BetterSurf.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment