Virus BrowserModifier : Win 32 / Prifou

Solved
Hello Malekal_morte,

I'm reaching out to you again because I have another BrowserModifier virus: Win 32 / Prifou on my backup drive D: /, impossible to remove with my antivirus, nor with Adwcleaner.
I ran a scan with FRST, here are the reports:

https://pjjoint.malekal.com/files.php?id=20160922_i6u6j14t15e13
https://pjjoint.malekal.com/files.php?id=FRST_20160922_c11k8l12s11g14
https://pjjoint.malekal.com/files.php?id=20160922_w12z8h7e15t12

I hope we can finally get rid of it.
Thank you in advance, Domi

Configuration: Windows 7 / Mozilla 11.0

5 answers

  1. Moderator
    Hi

    Give the file detected in the history and then Windows Defender details

    --
    2
    1. Thank you so much, you really reassure me, phew, thank you thank you.....
      0
      1. Moderator
        No worries :)
        0
    2. Thank you Malekal-morte,

      So if I understand correctly, there’s nothing to worry about, right??
      Every time I get anxious when I see this kind of alert, especially when I read about the damage this virus can cause....
      In any case, thank you very much.
      0
      1. Moderator
        No, these are isolated files in your backups
        and in AdwCleaner’s quarantine.

        They are not active threats in the system; these files must be old, anyway.

        Also, it's not necessarily a virus as you understand...
        The detection corresponds to programs that aim to modify the web browser configuration to impose a search engine (here MySearchDial, which AdWCleaner has shot down since it is in its quarantine).
        It's just "annoying" because you end up with a search engine you don't want.

        Nothing to do with trojans that steal passwords or stuff like that.

        So be reassured :)
        0
    3. Hello Malekal_morte,

      I don’t quite understand what you are asking me.....
      Here is the history of my antivirus:

      Modified: Win32/Prifou high Active

      This program modifies certain browser settings without the user's consent

      Recommended: Remove this software immediately
      Elements

      Container file: D:\DOMI PC\Backup Set 2014-01-04 0106622\Backup Files 2014-02-02 190000\Backup files 1.zip
      Container file: D:\DOMI PC\Backup Set 2015-10-22 013732\Backup Set 2015-10-22 013732\Backup files 9.zip files C:\Adwcleaner\Quarantine\C\Users\Domi\AppData\Roaming\Mysearchdial\UpdatzeProcTask.exe.vir
      files D:\Domi PC\Backup Set 2014-01-04 0106622\Backup Files 2014-02-02 190000\Backup files 1.zip->\Users\Domi\Appdata\Roaming\Mysearchdial\UpdatzeProcTask.exe
      files D:\Domi PC\Backup Set 2015-10-22 013732\Backup files 9.zip->\Users\Domi\Appdata\Roaming\Mysearchdial\UpdatzeProcTask.exe

      There you go, I hope this is what you are asking me.
      Thank you for your response.
      Best regards
      0
      1. Moderator
        Once again, these are detections in your backups.
        You can completely empty the folder c:\AdwCleaner\Quarantine.

        No active infection.

        You should add your backups to the scan exceptions, that would prevent you from getting these kinds of alerts.
        0
    4. Hello,

      Thank you for your response.
      Windows Defender is disabled and cannot be activated. Maybe because of MSE? I read somewhere that MSE disables it. Is there another solution?
      0