PUA

What is “BetterSurf (PUA)”?

Malware Removal

The BetterSurf (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BetterSurf (PUA) virus can do?

  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers

How to determine BetterSurf (PUA)?


File Info:

name: 19847634C086FCAD75C2.mlw
path: /opt/CAPEv2/storage/binaries/7e3ac5de2d70989b727c255fbbe3758c9c26fde5c0b79bbba995b2ac7c774053
crc32: 36E4B001
md5: 19847634c086fcad75c21bfd2960f338
sha1: 950a51230a5bb503d9b70ec91f06598c15a2e2d8
sha256: 7e3ac5de2d70989b727c255fbbe3758c9c26fde5c0b79bbba995b2ac7c774053
sha512: 1efd990c8596061dcc721d0d540d8622af3e2b77398fce9398d2be2d3cb92cea8bf05a5c0403202296adb25b4285884432066d588d226640c611489464533ae1
ssdeep: 6144:Ee34HwpeZH+zpyuuz6GZkDOJ/7OafSH5KmrWym09x18:eMeZHkwuPikQ7lKH5p5H9x18
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D654229F2FD155B3D9CB713A0630FBADDBF2E49940D356874F5A2EAA3EE12876600140
sha3_384: e35401c7e736394c9f8a583618f11075a9739bb2adfba7667e739783d7c82476ffcfeb3df297b952ae117f6b3ad33250
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

CompanyName: Media Watch
CompanyWebsite:
FileDescription:
FileVersion: 1.1
LegalCopyright:
ProductName: Media Watch home 242
ProductVersion: 1.1
Translation: 0x0000 0x04e4

BetterSurf (PUA) also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Amonetize.10
MicroWorld-eScanGen:Variant.Mikey.74011
FireEyeGen:Variant.Mikey.74011
CAT-QuickHealAdware.Bettersurf.PR5
McAfeeArtemis!19847634C086
CylanceUnsafe
SangforTrojan.Win32.Occamy.C
K7AntiVirusTrojan ( 0049026a1 )
AlibabaAdWare:Win32/Amonetize.5474451a
K7GWTrojan ( 0049026a1 )
Cybereasonmalicious.4c086f
CyrenW32/Amonetize.CN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Amonetize.X potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0DKN21
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.Amonetize.fqpg
BitDefenderGen:Variant.Mikey.74011
NANO-AntivirusTrojan.Win32.Amonetize.deipam
SUPERAntiSpywareAdware.BetterSurf/Variant
AvastWin32:Adware-gen [Adw]
TencentWin32.Adware.Amonetize.Dzke
EmsisoftApplication.InstallMon (A)
VIPREAdware.Bettersurf (fs)
TrendMicroTROJ_GEN.R002C0DKN21
McAfee-GW-EditionBehavesLike.Win32.AdwareBSurf.dc
SophosBetterSurf (PUA)
GDataWin32.Adware.Amonetize.M
JiangminAdWare.Amonetize.arbm
WebrootW32.Adware.Gen
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Generic.ASMalwNS.28D0
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Amonetize.R96015
VBA32AdWare.Amonetize
ALYacGen:Variant.Mikey.74011
MAXmalware (ai score=99)
MalwarebytesPUP.Optional.MediaWatch
APEXMalicious
RisingTrojan.Win32.Generic.17BE35A0 (C64:YzY0Og1COjyeFRbr)
YandexPUA.Amonetize!x4hpwO88bPY
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Adware
FortinetNSIS/Amonetize.F!tr
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/grayware_confidence_100% (D)

How to remove BetterSurf (PUA)?

BetterSurf (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment