Virus BrowserModifier : Win 32 / Prifou

Solved
praline8330 Posted messages 24 Status Member -  
Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   -
Hello Malekal_morte,

I'm reaching out to you again because I have another BrowserModifier virus: Win 32 / Prifou on my backup drive D: /, impossible to remove with my antivirus, nor with Adwcleaner.
I ran a scan with FRST, here are the reports:

https://pjjoint.malekal.com/files.php?id=20160922_i6u6j14t15e13
https://pjjoint.malekal.com/files.php?id=FRST_20160922_c11k8l12s11g14
https://pjjoint.malekal.com/files.php?id=20160922_w12z8h7e15t12

I hope we can finally get rid of it.
Thank you in advance, Domi

Configuration: Windows 7 / Mozilla 11.0

5 answers

Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711
 
Hi

Give the file detected in the history and then Windows Defender details

--
2
praline8330 Posted messages 24 Status Member
 
Hello,

Thank you for your response.
Windows Defender is disabled and cannot be activated. Maybe because of MSE? I read somewhere that MSE disables it. Is there another solution?
0
praline8330 Posted messages 24 Status Member
 
Hello Malekal_morte,

I don’t quite understand what you are asking me.....
Here is the history of my antivirus:

Modified: Win32/Prifou high Active

This program modifies certain browser settings without the user's consent

Recommended: Remove this software immediately
Elements

Container file: D:\DOMI PC\Backup Set 2014-01-04 0106622\Backup Files 2014-02-02 190000\Backup files 1.zip
Container file: D:\DOMI PC\Backup Set 2015-10-22 013732\Backup Set 2015-10-22 013732\Backup files 9.zip files C:\Adwcleaner\Quarantine\C\Users\Domi\AppData\Roaming\Mysearchdial\UpdatzeProcTask.exe.vir
files D:\Domi PC\Backup Set 2014-01-04 0106622\Backup Files 2014-02-02 190000\Backup files 1.zip->\Users\Domi\Appdata\Roaming\Mysearchdial\UpdatzeProcTask.exe
files D:\Domi PC\Backup Set 2015-10-22 013732\Backup files 9.zip->\Users\Domi\Appdata\Roaming\Mysearchdial\UpdatzeProcTask.exe

There you go, I hope this is what you are asking me.
Thank you for your response.
Best regards
0
Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711
 
Once again, these are detections in your backups.
You can completely empty the folder c:\AdwCleaner\Quarantine.

No active infection.

You should add your backups to the scan exceptions, that would prevent you from getting these kinds of alerts.
0
praline8330 Posted messages 24 Status Member
 
Thank you Malekal-morte,

So if I understand correctly, there’s nothing to worry about, right??
Every time I get anxious when I see this kind of alert, especially when I read about the damage this virus can cause....
In any case, thank you very much.
0
Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711
 
No, these are isolated files in your backups
and in AdwCleaner’s quarantine.

They are not active threats in the system; these files must be old, anyway.

Also, it's not necessarily a virus as you understand...
The detection corresponds to programs that aim to modify the web browser configuration to impose a search engine (here MySearchDial, which AdWCleaner has shot down since it is in its quarantine).
It's just "annoying" because you end up with a search engine you don't want.

Nothing to do with trojans that steal passwords or stuff like that.

So be reassured :)
0
praline8330 Posted messages 24 Status Member
 
Thank you so much, you really reassure me, phew, thank you thank you.....
0
Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711
 
No worries :)
0