Adware

What is “Adware:Win32/BetterSurf!pz”?

Malware Removal

The Adware:Win32/BetterSurf!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/BetterSurf!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering

How to determine Adware:Win32/BetterSurf!pz?


File Info:

name: DE6ED73F21681824E40A.mlw
path: /opt/CAPEv2/storage/binaries/6abcb7119b0a444491baa79078f0c70b998ecc4cd2d8839b0f9e8dfd790808f8
crc32: 57DF58AF
md5: de6ed73f21681824e40a377c23eaa435
sha1: beff5d4a93e63b2b19e0621792c8ef5e433c9273
sha256: 6abcb7119b0a444491baa79078f0c70b998ecc4cd2d8839b0f9e8dfd790808f8
sha512: fa2eb9e4f44ef28265bbebb720799509668c7216c522c2cd321e67279ad6e5a62f3f45d2616077f4bd5742e7e44ef3814aaad187d259a89e1af58ea4f3833f62
ssdeep: 12288:U5HhvG4GCo7AhzNFQDXZXZxoIuLRwd7AhYNFtDXZuizivNfKU8k0:UZhvG4GCocHUZ/oIuLsci1ZeNf+k0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195D42343BA80C4EBCA8A48F256F2376BFF3455E9206A5506FB080E0C7968D7CF52F556
sha3_384: 33530ab9a975de9348bd78b7a37479977850bc32148691537beea47ed04f92695e47001a429ac744a15939b8810fcd28
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

CompanyName: Media View
CompanyWebsite:
FileDescription:
FileVersion: 1.1
LegalCopyright:
ProductName: Media View alpha 5763
ProductVersion: 1.1
Translation: 0x0000 0x04e4

Adware:Win32/BetterSurf!pz also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.BetterSurf.lXl2
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Adware.BetterSurf.2
ClamAVWin.Adware.Bettersurf-24
FireEyeGen:Variant.Adware.BetterSurf.2
CAT-QuickHealAdware.BetterSurf.B5
SkyhighRDN/Generic PUP.x
ALYacGen:Variant.Adware.BetterSurf.2
Cylanceunsafe
SangforPUP.Win32.BetterSurf.G
K7AntiVirusUnwanted-Program ( 00575d101 )
AlibabaAdWare:Win32/Amonetize.ce648e1e
K7GWUnwanted-Program ( 00575d101 )
CrowdStrikewin/grayware_confidence_100% (D)
VirITAdware.Win32.MediaView.A
SymantecAdware.WebexpEnhanced
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.BetterSurf.b
BitDefenderGen:Variant.Adware.BetterSurf.2
NANO-AntivirusRiskware.Win32.BetterSurf.cslwri
AvastWin32:Adware-BLV [PUP]
TACHYONTrojan-Clicker/W32.BetterSurf.647900
EmsisoftGen:Variant.Adware.BetterSurf.2 (B)
BaiduMulti.Threats.InArchive
F-SecureAdware.ADWARE/Adware.Gen
DrWebTrojan.Amonetize.347
VIPREGen:Variant.Adware.BetterSurf.2
TrendMicroTROJ_SPNR.0BC314
Trapminemalicious.high.ml.score
SophosBetterSurf (PUA)
Ikarusnot-a-virus:AdWare.Win32.BetterSurf
GDataWin32.Adware.Bettersurf.E
JiangminAdWare.Amonetize.arrb
WebrootW32.Adware.Gen
VaristW32/Medfos.AE.gen!Eldorado
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.716
XcitiumApplication.Win32.Amonetize.B@581td2
ArcabitTrojan.Adware.BetterSurf.2 [many]
SUPERAntiSpywarePUP.MediaView/Variant
ZoneAlarmnot-a-virus:AdWare.Win32.BetterSurf.b
MicrosoftAdware:Win32/BetterSurf!pz
GoogleDetected
AhnLab-V3Adware/Win32.BetterSurf.C233448
McAfeeArtemis!DE6ED73F2168
MAXmalware (ai score=99)
VBA32Adware.Amonetize
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/NsisDownloader.A
TrendMicro-HouseCallTROJ_SPNR.0BC314
RisingPUF.Amonetize!8.C5 (TFE:5:cqV4nwXZiWC)
YandexPUA.BetterSurf!EYs19P2AMl0
SentinelOneStatic AI – Suspicious PE
FortinetW32/MEDFOS.AE!tr
AVGWin32:Adware-BLV [PUP]
DeepInstinctMALICIOUS

How to remove Adware:Win32/BetterSurf!pz?

Adware:Win32/BetterSurf!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment