Adware

Adware:Win32/BetterSurf!pz removal

Malware Removal

The Adware:Win32/BetterSurf!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/BetterSurf!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware:Win32/BetterSurf!pz?


File Info:

name: E91110849458FE8FE9DA.mlw
path: /opt/CAPEv2/storage/binaries/500b5d20c58d943f3163277fc231aa54f04ab18843ce5d599e7ee0af90693bad
crc32: 735AA6AD
md5: e91110849458fe8fe9da740ae6cddaf5
sha1: e7710a6a4073778394646549779093c6d0ab2e52
sha256: 500b5d20c58d943f3163277fc231aa54f04ab18843ce5d599e7ee0af90693bad
sha512: f41c1dc73b3002abbfaccc70108e1b817965b970871730048792b52b8285f75411999e113b475cbfb235d183bf198ce8d3c6c29a7b7f76c472aa0088eed63b7b
ssdeep: 12288:wFlsiTG4GCo7AhzNFQDXZXZxoIuLRwl7AhCNHhDXZ+YEivNfKL8kT:wFlsiTG4GCocHUZ/oIuLgci5ZVNfHkT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17AD42203BA80C4EFD6CA48B15BB2366BEF7165EA24694446EF480E0C7678D3CF52F452
sha3_384: b55cff9efa72d2e6b8c6cfa7b320e9ac8ab1e4b08d470f0c8828f2c52afc486ab87e5b2ed981d96535d4f160dc22be63
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

CompanyName: Media View
CompanyWebsite:
FileDescription:
FileVersion: 1.1
LegalCopyright:
ProductName: Media View alpha 9471
ProductVersion: 1.1
Translation: 0x0000 0x04e4

Adware:Win32/BetterSurf!pz also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.BetterSurf.lWWV
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.BetterSurf.2
CAT-QuickHealAdware.BetterSurf.B5
SkyhighRDN/Generic PUP.x
McAfeeArtemis!E91110849458
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Adware.BetterSurf.2
SangforAdware.Win32.Bettersurf.Vs8h
CrowdStrikewin/grayware_confidence_100% (W)
AlibabaAdWare:Win32/Amonetize.ff38e4a0
K7GWUnwanted-Program ( 00575d101 )
K7AntiVirusUnwanted-Program ( 00575d101 )
BaiduMulti.Threats.InArchive
VirITAdware.Win32.MediaView.A
SymantecAdware.WebexpEnhanced
tehtrisGeneric.Malware
ESET-NOD32multiple detections
APEXMalicious
TrendMicro-HouseCallADW_BETTERSURF.UNP
ClamAVWin.Adware.Bettersurf-24
Kasperskynot-a-virus:AdWare.Win32.BetterSurf.b
BitDefenderGen:Variant.Adware.BetterSurf.2
NANO-AntivirusRiskware.Win32.BetterSurf.cslwri
SUPERAntiSpywarePUP.MediaView/Variant
AvastWin32:Adware-BLV [PUP]
TencentWin32.Adware.Bettersurf.Qwhl
TACHYONTrojan-Clicker/W32.BetterSurf.647901
EmsisoftGen:Variant.Adware.BetterSurf.2 (B)
F-SecureAdware.ADWARE/Adware.Gen
DrWebTrojan.Amonetize.347
ZillyaAdware.Amonetize.Win32.65365
TrendMicroADW_BETTERSURF.UNP
Trapminemalicious.high.ml.score
FireEyeGen:Variant.Adware.BetterSurf.2
SophosBetterSurf (PUA)
Ikarusnot-a-virus:AdWare.Win32.BetterSurf
JiangminAdWare.Amonetize.arrb
GoogleDetected
AviraADWARE/Adware.Gen7
VaristW32/Medfos.AE.gen!Eldorado
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.711
MicrosoftAdware:Win32/BetterSurf!pz
XcitiumApplication.Win32.Amonetize.B@581td2
ArcabitTrojan.Adware.BetterSurf.2 [many]
ViRobotAdware.Bettersurf.647901.P
ZoneAlarmnot-a-virus:AdWare.Win32.BetterSurf.b
GDataWin32.Adware.Bettersurf.E
CynetMalicious (score: 100)
AhnLab-V3Adware/Win32.BetterSurf.C233448
ALYacGen:Variant.Ulise.199507
MAXmalware (ai score=99)
VBA32Adware.Amonetize
Cylanceunsafe
PandaTrj/NsisDownloader.A
RisingPUF.Amonetize!8.C5 (TFE:5:cqV4nwXZiWC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/MEDFOS.AE!tr
AVGWin32:Adware-BLV [PUP]
DeepInstinctMALICIOUS
alibabacloudTrojan

How to remove Adware:Win32/BetterSurf!pz?

Adware:Win32/BetterSurf!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment