Virus BrowserModifier : Win 32 / Prifou

Solved
Hello Malekal_morte,

I'm reaching out to you again because I have another BrowserModifier virus: Win 32 / Prifou on my backup drive D: /, impossible to remove with my antivirus, nor with Adwcleaner.
I ran a scan with FRST, here are the reports:

https://pjjoint.malekal.com/files.php?id=20160922_i6u6j14t15e13
https://pjjoint.malekal.com/files.php?id=FRST_20160922_c11k8l12s11g14
https://pjjoint.malekal.com/files.php?id=20160922_w12z8h7e15t12

I hope we can finally get rid of it.
Thank you in advance, Domi

Configuration: Windows 7 / Mozilla 11.0

5 answers

  1. Moderator
    Hi

    Give the file detected in the history and then Windows Defender details

    --
    2
    1. Hello,

      Thank you for your response.
      Windows Defender is disabled and cannot be activated. Maybe because of MSE? I read somewhere that MSE disables it. Is there another solution?
      0
      1. Hello Malekal_morte,

        I don’t quite understand what you are asking me.....
        Here is the history of my antivirus:

        Modified: Win32/Prifou high Active

        This program modifies certain browser settings without the user's consent

        Recommended: Remove this software immediately
        Elements

        Container file: D:\DOMI PC\Backup Set 2014-01-04 0106622\Backup Files 2014-02-02 190000\Backup files 1.zip
        Container file: D:\DOMI PC\Backup Set 2015-10-22 013732\Backup Set 2015-10-22 013732\Backup files 9.zip files C:\Adwcleaner\Quarantine\C\Users\Domi\AppData\Roaming\Mysearchdial\UpdatzeProcTask.exe.vir
        files D:\Domi PC\Backup Set 2014-01-04 0106622\Backup Files 2014-02-02 190000\Backup files 1.zip->\Users\Domi\Appdata\Roaming\Mysearchdial\UpdatzeProcTask.exe
        files D:\Domi PC\Backup Set 2015-10-22 013732\Backup files 9.zip->\Users\Domi\Appdata\Roaming\Mysearchdial\UpdatzeProcTask.exe

        There you go, I hope this is what you are asking me.
        Thank you for your response.
        Best regards
        0
        1. Moderator
          Once again, these are detections in your backups.
          You can completely empty the folder c:\AdwCleaner\Quarantine.

          No active infection.

          You should add your backups to the scan exceptions, that would prevent you from getting these kinds of alerts.
          0
      2. Thank you Malekal-morte,

        So if I understand correctly, there’s nothing to worry about, right??
        Every time I get anxious when I see this kind of alert, especially when I read about the damage this virus can cause....
        In any case, thank you very much.
        0
        1. Moderator
          No, these are isolated files in your backups
          and in AdwCleaner’s quarantine.

          They are not active threats in the system; these files must be old, anyway.

          Also, it's not necessarily a virus as you understand...
          The detection corresponds to programs that aim to modify the web browser configuration to impose a search engine (here MySearchDial, which AdWCleaner has shot down since it is in its quarantine).
          It's just "annoying" because you end up with a search engine you don't want.

          Nothing to do with trojans that steal passwords or stuff like that.

          So be reassured :)
          0
      3. Thank you so much, you really reassure me, phew, thank you thank you.....
        0
        1. Moderator
          No worries :)
          0