Home Malware Programs Adware Adware.BetterSurf

Adware.BetterSurf

Posted: November 18, 2013

Threat Metric

Ranking: 6,077
Threat Level: 2/10
Infected PCs: 15,561
First Seen: November 18, 2013
Last Seen: October 11, 2023
OS(es) Affected: Windows

BetterSurf is adware that modifies Web pages as they're loaded to display additional advertising content. Since BetterSurf's advertisements don't provide any tangible benefit, malware researchers would recommend deleting BetterSurf to better the safety and performance of whatever Web browser is being affected at the time. Most casual PC users have experienced difficulties in deleting BetterSurf, which attempts to ignore normal software uninstallation methods, and using anti-malware tools for BetterSurf's removal is likely to save you significant time and trouble.

When 'Better' Means More Advertisements

BetterSurf is a browser add-on that has been confirmed to affect Chrome, Internet Explorer and Firefox (although not necessarily at the same time) by displaying additional advertisements. These advertisements are loaded into Web pages that are modified for their display, which may cause performance issues, security problems (related to exposure to unwanted third party advertisements) and, in some cases, problems with accessing the interface or content of the original site. BetterSurf may refuse to uninstall itself or disable its advertisements on request, making BetterSurf a non-consensual program that could be considered a threat, although most types of adware more usually are classified as PUPs.

BetterSurf's stubbornness in the face of prospective deletion isn't the only thing BetterSurf has in common with unsafe software; BetterSurf also has been seen being distributed through compromised software updates. Recent modified updates for the Firefox browser have been seeded with BetterSurf and distributed through third party advertisement networks. As malware experts always would recommend, taking the simple route of avoiding update links that aren't from the original company will provide the most obvious protection against this means of installing BetterSurf, which save you the trouble of needing to figure out how to be rid of BetterSurf.

The Best Way to Surf the Web: without BetterSurf

Even though BetterSurf includes more than enough negative traits, all by itself, malware researchers also have been unhappy to confirm that BetterSurf sometimes is related to the presence of high-level PC threats. Tesch.B is one of the recent PC threats to be seen included in the latest BetterSurf-related attacks, which are compatible with modern versions of Windows. Other operating systems are awaiting confirmation, but, nonetheless, are just as vulnerable to attacks by similar adware programs, even if they are lucky enough to be unaffected by BetterSurf.

One minor point in the victim's favor is that BetterSurf's advertising modifications are persistent and easy to detect, with clear labeling that will let you notice BetterSurf's presence immediately. Once you do see these symptoms, the use of anti-malware products to restore your browser and get rid of BetterSurf simply is a common sense reaction that all PC users should have whenever their online security is at stake.

Aliases

Riskware/BetterSurf [Fortinet]AdWare.Win32.BetterSurf [Ikarus]Adware/Win32.BetterSurf [AhnLab-V3]GrayWare[AdWare:not-a-virus]/Win32.BetterSurf [Antiy-AVL]BetterSurf [Sophos]BehavesLike.Win32.AdwareBetterSurf.mh [McAfee-GW-Edition]Adware.BetterSurf.1 [DrWeb]Application.Win32.AdWare.BetterSurf.C [Comodo]Win32:Adware-gen [Adw] [Avast]Adware.Adpopup [Symantec]Adware-BetterSurf [McAfee]AdWare.BetterSurf.r5 (Not a Virus) [CAT-QuickHeal]Generic5.AKJO [AVG]Adware/BetterSurf [Fortinet]JS.BetterSurf [Ikarus]
More aliases (46)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ProgramFiles(x86)%\BetterSurf\file-6220826_crx File name: file-6220826_crx
Size: 2.71 KB (2716 bytes)
MD5: 8cf09f72515a2aabf208546f6768fdba
Detection count: 190
Path: %ProgramFiles(x86)%\BetterSurf
Group: Malware file
Last Updated: September 10, 2023
%PROGRAMFILES%\Better-Surf\ie\BetterSrf.dll File name: BetterSrf.dll
Size: 179.18 KB (179181 bytes)
MD5: 999d5a8f6e5d31bace1fab96c58b4268
Detection count: 85
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Better-Surf\ie
Group: Malware file
Last Updated: January 13, 2014
%PROGRAMFILES%\Better-Surf\ie\BetterSrf.dll File name: BetterSrf.dll
Size: 197.51 KB (197511 bytes)
MD5: 7682b6217f31e9207b741c0778d7f8fc
Detection count: 80
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Better-Surf\ie
Group: Malware file
Last Updated: January 13, 2014
C:\Backup_23-Sep-14\Karata\AppData\Local\Temp\Better-Surf.exe File name: Better-Surf.exe
Size: 490.38 KB (490385 bytes)
MD5: 8ea615058f2fd5b7781e2da47d1e7978
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: C:\Backup_23-Sep-14\Karata\AppData\Local\Temp\Better-Surf.exe
Group: Malware file
Last Updated: August 8, 2023
%PROGRAMFILES%\Better-Surf\ie\BetterSrf.dll File name: BetterSrf.dll
Size: 188.92 KB (188925 bytes)
MD5: 80a488237f0b451fbd631ba106d021d4
Detection count: 41
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Better-Surf\ie
Group: Malware file
Last Updated: January 13, 2014
C:\Users\<username>\AppData\Local\Temp\Better-Surf.exe File name: Better-Surf.exe
Size: 490.39 KB (490391 bytes)
MD5: 9d4daf4db9f3b1398bb6b9c4d183af63
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\Better-Surf.exe
Group: Malware file
Last Updated: October 11, 2022
%PROGRAMFILES%\Better-Surf\ie\BetterSrf.dll File name: BetterSrf.dll
Size: 338.94 KB (338941 bytes)
MD5: 6f9b34cdc51c04bec390ec06526bedd4
Detection count: 23
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Better-Surf\ie
Group: Malware file
Last Updated: August 30, 2016
%PROGRAMFILES%\Better-Surf\ie\BetterSrf.dll File name: BetterSrf.dll
Size: 198.05 KB (198053 bytes)
MD5: 593cce274fa0bbffa69bf8e2fcef6c2a
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Better-Surf\ie
Group: Malware file
Last Updated: January 13, 2014
%PROGRAMFILES%\Better-Surf\ie\BetterSrf.dll File name: BetterSrf.dll
Size: 86.01 KB (86016 bytes)
MD5: eb505e6275b4e3723b4e568b7227c6d0
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Better-Surf\ie
Group: Malware file
Last Updated: January 13, 2014
%PROGRAMFILES%\Better-Surf\ie\BetterSrf.dll File name: BetterSrf.dll
Size: 174.94 KB (174949 bytes)
MD5: 6504d88bb3b08c4bb070c5ee9c7aab60
Detection count: 0
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Better-Surf\ie
Group: Malware file
Last Updated: January 13, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{0113A098-06EA-4776-A011-D75590778F1E}{1824FF90-C98E-48A6-838F-E3B6572B0C77}{462862BE-9A5C-49A5-9CBD-A649EAC63645}{6E3C6B04-08FE-43BC-8E50-F90285024DEA}{881E49A1-8325-4B19-AE6F-B889A40D073A}{DD3A66B9-8A7C-4C3C-8D60-DB225A60D69C}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Better Surf PlusSOFTWARE\BetterSurfSoftware\Microsoft\Internet Explorer\Approved Extensions\{1824FF90-C98E-48A6-838F-E3B6572B0C77}Software\Microsoft\Internet Explorer\Approved Extensions\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}Software\Microsoft\Internet Explorer\DOMStorage\rvzrjs.infoSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1824FF90-C98E-48A6-838F-E3B6572B0C77}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1824FF90-C98E-48A6-838F-E3B6572B0C77}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1824FF90-C98E-48A6-838F-E3B6572B0C77}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}SOFTWARE\Mozilla\Firefox\Extensions\ext@bettersurfplus.comSOFTWARE\Mozilla\Firefox\Extensions\xz123@ya456.comSOFTWARE\Wow6432Node\Better Surf PlusSOFTWARE\Wow6432Node\BetterSurfSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1824FF90-C98E-48A6-838F-E3B6572B0C77}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\ext@bettersurfplus.comSOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\xz123@ya456.comHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Better Surf Plus

Additional Information

The following directories were created:
%ProgramFiles%\Better-Surf%ProgramFiles%\BetterSurf%ProgramFiles(x86)%\Better-Surf%ProgramFiles(x86)%\BetterSurf
The following cookies were detected:
rvzr2-a.akamaihd
The following URL's were detected:
Better Surf PlusBetterSurf
Loading...