PUA

How to remove “PUP.Optional.BetterSurf”?

Malware Removal

The PUP.Optional.BetterSurf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.BetterSurf virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Steals private information from local Internet browsers
  • Attempts to create or modify a Browser Helper Object

How to determine PUP.Optional.BetterSurf?


File Info:

name: 02C1DCFB1E0933CF7759.mlw
path: /opt/CAPEv2/storage/binaries/7365d31533e9fee9dbd60f07cda84ba69f97f4f2a4442eab65587a57906f232c
crc32: 30F4B09D
md5: 02c1dcfb1e0933cf7759f2ae5faba411
sha1: 8668403eadefdc815b066ae215c0a6e9de05373c
sha256: 7365d31533e9fee9dbd60f07cda84ba69f97f4f2a4442eab65587a57906f232c
sha512: c67c2661e1fb8e0d7de3ae1335c79ea90082318f1aaed671cba95f6161facc857d8e27e014bbe6509f26c793f095dc59e88b9188bed1b068194d92a5a3752976
ssdeep: 24576:/WxywYUG4Gdg7P+IoLCbawZ2eAArOf7UFxouObtw+EPV:ysqr+NW+wxFOfYFm15wf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F0252394E6C4D868C3904634A7AFFB74E1A8DECB1EF1155B83C61EE356423178EE3906
sha3_384: 42841d107856096fcda6c41f3bad4eae78a5f09a75b99ca45679f4bc03224efedb48a0e23eda162a4dc3c1d190d6c6d6
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

CompanyName: Video Player
CompanyWebsite:
FileDescription:
FileVersion: 1.1
LegalCopyright:
ProductName: Video Player beta 897
ProductVersion: 1.1
Translation: 0x0000 0x04e4

PUP.Optional.BetterSurf also known as:

LionicAdware.Win32.BetterSurf.lVJl
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGen:Variant.Adware.BetterSurf.1
CAT-QuickHealAdware.BetterSurf.B5
ALYacAdware.SwiftBrowse.DA
CylanceUnsafe
SangforTrojan.Generic-JS.Save.8ce68aae
K7AntiVirusUnwanted-Program ( 0040f7911 )
AlibabaAdWare:Win32/Amonetize.bc36d1f5
K7GWUnwanted-Program ( 0040f7911 )
CrowdStrikewin/grayware_confidence_100% (D)
BaiduMulti.Threats.InArchive
CyrenW32/Medfos.AE.gen!Eldorado
SymantecAdware.WebexpEnhanced
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Adware.Bettersurf-24
Kasperskynot-a-virus:AdWare.Win32.BetterSurf.b
BitDefenderGen:Variant.Adware.BetterSurf.1
NANO-AntivirusRiskware.Win32.BetterSurf.cslwri
SUPERAntiSpywareAdware.BetterSurf/Variant
MicroWorld-eScanGen:Variant.Adware.BetterSurf.1
AvastNSIS:Adware-MO [PUP]
TencentWin32.Risk.Adware.Fhx
SophosBetterSurf (PUA)
ComodoApplication.Win32.Amonetize.KL@56ab04
DrWebAdware.BetterSurf.1521
VIPREAdware.Bettersurf (fs)
TrendMicroADW_BETTERSURF.UNP
McAfee-GW-EditionBehavesLike.Win32.AdwareBSurf.fc
EmsisoftApplication.InstallMon (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare/BetterSurf.b
WebrootPua.Adware.Bettersurf
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Generic.ASMalwNS.28D7
KingsoftWin32.Troj.BetterSurf.b.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
GDataWin32.Adware.Amonetize.M
AhnLab-V3Adware/Win32.BetterSurf.C233448
McAfeeArtemis!02C1DCFB1E09
MAXmalware (ai score=99)
VBA32BScope.Adware.Downware
MalwarebytesPUP.Optional.BetterSurf
TrendMicro-HouseCallADW_BETTERSURF.UNP
RisingTrojan.Detplock!8.4A0D (CLOUD)
YandexAdware.BetterSurf!lhTB4ypqqYs
MaxSecurenot-a-virus:.Adware.BetterSurf.b
FortinetW32/MEDFOS.AE!tr
AVGNSIS:Adware-MO [PUP]
Cybereasonmalicious.b1e093
PandaPUP/BetterSurf

How to remove PUP.Optional.BetterSurf?

PUP.Optional.BetterSurf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment