BrowserModifier: what the Defender alert means and how to remove it

BrowserModifier is the word Microsoft Defender puts in front of the name of a program that changes your browser, and it covers many different programs, not one virus. Find which family the alert names and where the file is, then follow the check, scan and removal steps.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If a BrowserModifier alert in Windows Security keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove BrowserModifier yourself 2 steps, about 6 minutes, no software needed.

Google ChromeMicrosoft EdgeMozilla FirefoxSafari (Mac)

A Windows Defender Alert window titled Review harmful or potentially unwanted software, listing three detections named BrowserModifier:Win32/SupTab!blnk with alert level High and action Disinfect, category Browser Modifier, and the resource file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk, on a red background with the word BrowserModifier
The alert from our 2020 guide: three detections of BrowserModifier:Win32/SupTab!blnk, alert level High, category Browser Modifier, on the Google Chrome shortcut in the Start Menu folder. It is the older Windows Defender window. The red background and the word BrowserModifier are ours, and the alert is for SupTab, not for the Foniad, Zwangi or Prifou entries described below.

BrowserModifier: summary

TypeA Microsoft Defender detection category for programs that change browser settings; not one virus. The families range from search toolbars to the payload of a trojan downloader
RiskMedium for the adware families (Zwangi, Prifou): ads, redirects, changed search results and shortcuts. High if the report also names a trojan downloader, as with Foniad
SymptomsThe alert itself, often the only sign; ads on every site, searches opening on another page, a changed home page, redirects, notifications, a shortcut that opens another address
How to get rid of itQuarantine and remove the item in Protection history, run a full scan, uninstall programs you did not add, check scheduled tasks and browser shortcuts, remove extensions, reset each browser, run Defender Offline
Our check (6 October 2026)No site or PC test: we read Microsoft's entries for Foniad, Zwangi, Prifou and Pokki and the reader threads; no sample was run
First seenZwangi entry 16 September 2009; Prifou 19 November 2015; Foniad 9 April 2018; our first guide 10 January 2020
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
DetectionMicrosoft: BrowserModifier:Win32/<Family>, for example Foniad, Zwangi, Prifou or SupTab!blnk. Pokki has not been detected since November 2015
Not to be confused withDofoil, the coin-miner campaign Microsoft compared Foniad with, and with the browser hijackers of Mac and Android, which use other names
DistributionSoftware bundles, third-party download sites, ads and fake updates; for Foniad a trojan downloader with a compromised media app
DamageNo encrypted files. Documented: ads, redirects, changed search results, allowed notifications and changed shortcuts. Passwords and money are not documented for the modifiers themselves, only for a trojan that came with one
EvidenceMicrosoft's entries for four families, Microsoft's posts on Foniad and three reader threads; no sample was run
BrowsersInternet Explorer, Firefox and Chrome in Microsoft's old entries; Chrome for Foniad. Edge and Safari steps are kept from our 2020 guide
NameBrowserModifier
ProgramA BrowserModifier alert in Windows Security
Facts checked6 October 2026

Facts checked on 6 October 2026 against Microsoft's encyclopedia entries for Foniad, Zwangi, Prifou and Pokki, Microsoft's posts on Foniad of 10 and 13 April 2018, Microsoft Learn and Microsoft Support pages, and a Stack Exchange thread from 2016.

We ran no sample and tested no PC; the removal steps follow Microsoft's pages and were not tried on a live infection. A quiet result from any check does not clear a PC.

What BrowserModifier is, and what it is not

BrowserModifier is the category word at the start of many Microsoft Defender detection names, not the name of one virus. A name such as BrowserModifier:Win32/Zwangi says what Microsoft thinks the program does, which is change the browser, and what it runs on, which is a Windows program. Our 2020 guide called it a malicious program that diverts traffic; that fits some entries and not others.

  1. 1

    What the name is

    Microsoft names a detection as Type:Platform/Family. BrowserModifier is the type, Win32 is the platform and the last part is the family, such as Zwangi or Prifou. Microsoft's entry for Prifou describes the type as a program that can change your web browser settings without adequate consent. Our 2020 guide called it a heuristic name for programs that hijack browsers; the word heuristic is ours, and the Microsoft entries we read do not use it.

  2. 2

    How wide the name is

    Our 2020 guide said it covers everything from harmless adware extensions to a trojan, and it spoke of thousands of programs. We cannot confirm that count. What we can confirm is the spread: the Microsoft entries we read range from an unwanted search toolbar (Zwangi) and an ad injector (Prifou) to a polymorphic program that a trojan downloader installed (Foniad).

  3. 3

    Why it shows on a PC

    Most of these programs arrive in a bundle with software you chose, after an ad, or with a fake update prompt, and a few come from a trojan downloader that is already on the PC. The alert is what your security software says when it finds one. It does not tell you which of those routes you were on.

Shown by
Microsoft Defender Antivirus and the other Microsoft antimalware products, in Windows Security and in the older Windows Defender window
Usual form
BrowserModifier:Win32/Family, sometimes followed by a suffix such as !blnk or !rfn
Platform
Windows programs. Win32 does not mean your Windows is 32-bit. The entries we read are all for Windows, so a Mac would show other names
Is it one program?
No. Each family is a different program with its own files, behaviour and alert level
Still in use
Microsoft's encyclopedia still carries the type: we found current entries such as Xeelyak, Linkhortry and Neobar in search results. We did not check when each was written

So the useful questions are which family the alert names, which file or shortcut it points to, and whether you installed something around the time it began. The next chapters help you answer them before you delete anything or allow anything.

Is BrowserModifier dangerous? What it collects

What we checked on 6 October 2026, and what we could not

There is no website behind this name, so our usual site test (notification request, pop-ups, redirects, service worker) had nothing to load. We ran no sample and tested no PC. We read the Microsoft entries and the threads where readers asked about the alert.

BrowserModifier detections · sources read on 6 October 2026

  • The name is a real Microsoft labelWe opened Microsoft's encyclopedia entries for BrowserModifier:Win32/Foniad, Zwangi, Prifou and Pokki on 6 October 2026. An alert with this name is a security product's finding, not a scam message that only imitates one.
  • A site to testNone. The name belongs to programs and shortcuts on a PC, not to a domain, so we cannot say anything from our side about notifications, pop-ups or redirects.
  • A sample of any familyNot run. What the families do comes from Microsoft's entries and tweets of 2015 to 2018. A copy that reaches a PC today may differ.
  • Whether the old families still circulateNot known. The newest entry we read, Foniad, is from April 2018; Zwangi and Prifou were last updated in September 2017. We did not look for newer copies.
  • Whether a quiet PC is cleanNot something we can say. Adware is built to hide, and a scan that finds nothing today is one scan on one day.

Medium risk The alert is real, and what is behind it ranges from an ad-injecting program to the payload of a trojan downloader. A quiet result on this one reading of the sources clears nothing; the steps below are written for the worst case and stop early if the first scan is clean and the alert does not return.

How to read the alert, part by part

Microsoft explains the type and the platform but not every suffix, so the table separates what the alert shows from what it does not.

Read from Microsoft's entries (6 October 2026) and from the alert in our 2020 picture. Not a test of your PC.
PartWhat it showsWhat it does not show
BrowserModifier:Microsoft's category: a program that changes browser settingsWhether it is a harmless-looking toolbar or part of a trojan's payload. Zwangi is the first, Foniad was installed by the second
Win32/A Windows program, file or shortcutThat your Windows is 32-bit
Zwangi, Prifou, Foniad, SupTabThe family name Microsoft gaveThe name you see in your list of programs. Zwangi alone appears under 57 different names
!blnk, !rfnA suffix after the family nameWhat it means. We found no Microsoft page that explains it. Microsoft's !rfn pages carry only a general text about a threat that can perform actions of a malicious actor's choice, and our 2020 picture shows !blnk on a shortcut file
Alert level HighMicrosoft's alert level for the family. Zwangi and Prifou are listed as a high threatThat anything bad has happened on your PC
Resources: fileThe file Defender flagged. In our 2020 picture it is the Google Chrome shortcut in the Start Menu folderThat Chrome itself is damaged. A shortcut can be changed so that it opens another address

The families named most often

Our 2020 guide said it would look over the most prolific versions. These are the ones it named, with what Microsoft's own entry says today, plus two more that readers meet.

Microsoft Security Intelligence entries read on 6 October 2026. The last two rows come from the summary text in search results; we did not open those entries.
FamilyWhat Microsoft saysWhat our 2020 guide saidStatus
BrowserModifier:Win32/FoniadA prevalent browser modifier that opens the browser and visits several sites in a series of redirects, and configures Chrome to allow desktop notifications. Highly polymorphic: thousands of distinct files in the first hours. Published 9 April 2018Acts as a trojan and installs a cryptominerCorrected: the miner and the DNS change came from the trojan downloader that installed it
BrowserModifier:Win32/ZwangiChanges your search results and shows pop-up ads. Published 16 September 2009, updated 15 September 2017. High threatAlso known as Zwangi 1.0 build 127; renamed several times; drops hundreds of files; takes screenshotsMostly confirmed; the file count and the screenshots are corrected below
BrowserModifier:Win32/PrifouCan change browser settings without adequate consent; installed with software from third-party sites. Published 19 November 2015, updated 15 September 2017. High threatA standalone PriceFountain application plus an add-on; ads marked PriceFountainConfirmed in part; the infection count could not be re-checked
BrowserModifier:Win32/PokkiNo longer detected after definition 1.209.1398.0 in November 2015, because it does not violate Microsoft's criteria for unwanted softwareNo longer recognized by most anti-malware engines and considered safe to use since November 2015Corrected: Microsoft says it stopped detecting it. Other products may differ
BrowserModifier:Win32/SupTab!blnkWe found no entry with this exact name; the alert appears in the picture of our 2020 guide and in 2016 reader threads, on browser shortcut filesNot discussed; it is the alert in the guide's first pictureAdded: see the reader cases
BrowserModifier:Win32/LinkhortryModifies browser shortcut files, so that the browser opens certain websites when started from them (Microsoft's summary, seen in search results)Not mentionedAdded: it explains why a shortcut is flagged
BrowserModifier:Win32/XeelyakUnwanted software that alters the Windows experience without your consent or control (Microsoft's summary, seen in search results)Not mentionedAdded: a newer entry of the same type

Foniad, April 2018: one family and the trojan that carried it

Our 2020 guide said Foniad acts as a trojan, changes DNS settings and installs a cryptominer. Microsoft's own posts split that between two programs: Foniad is the browser modifier, and a trojan downloader installed it, the miner and the DNS change.

From Microsoft's encyclopedia entry (9 to 10 April 2018) and Microsoft's posts of 10 and 13 April 2018. Not our own analysis.
PieceMicrosoft detection nameWhat Microsoft says it does
The downloaderTrojanDownloader:Win32/Esendi.AInstalls the other pieces. It modifies the DNS server settings, which lets attackers control answers to DNS queries and manipulate where most network connections go
The compromised media appTrojanDropper:Win32/AdpernokOne of the downloader's payloads. Microsoft traced infections to a compromised media app
The browser modifierBrowserModifier:Win32/FoniadRuns as xsetup.exe, opens Chrome and visits several sites in a series of redirects, and sets Chrome to allow notifications from those sites
The coin minerTrojan:Win32/CoinMiner.CZA trojanized version of an XMR miner that mines Monero. Installed in some cases
The adware componentAdware:Win32/AdposhelA .dll adware component the downloader also installs
File name
xsetup.exe, used by every copy Microsoft saw although the files differ
How many copies
Several millions of versions, Microsoft said on 10 April 2018, trying to infect and re-infect hundreds of thousands of machines. Versions are not victims, so the old figure of hits is not a count of infected PCs
Re-infection
One component tries to infect again with a scheduled task, per Microsoft on 13 April 2018. That is why a manual removal can seem to come undone
Chrome registry keys
It sets DefaultNotificationsSetting under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome, and adds addresses to NotificationsAllowedForUrls under the same key
Site addresses in Microsoft's entry
acinster[.]info, aclassigned[.]info, efishedo[.]info, enclosely[.]info, insupposity[.]info, maraukog[.]info, suggedin[.]info
Money
Microsoft says the sites it visits might be generating revenue through ad impressions

If your alert names Foniad, treat the PC as one that a trojan downloader may have visited, not only as one with a browser add-on. The check and removal chapters below include the DNS, notification and scheduled-task steps for that case. We did not test them against a live Foniad copy.

Zwangi: one program under 57 names

Zwangi is the oldest family in our 2020 guide and the best documented. Microsoft lists the folders, files, registry entries and the service it creates, which is the easiest route to checking whether a PC has it.

Read from Microsoft's entry for BrowserModifier:Win32/Zwangi on 6 October 2026. Not tested on a PC.
WhatWhat Microsoft's entry saysNote
Entry datesPublished 16 September 2009, updated 15 September 2017. Aliases Mal/BHO-S (Sophos) and Spyware.Screenspy (Symantec)Our 2020 guide said first detected in 2009: correct
Uninstall entryMay be called Zwangi 1.0 build 127. The entry says the program may create an uninstaller in the Control PanelOur 2020 picture shows the uninstall wizard of build 123, so the build number varies
Screen names57 names, among them QueryExplorer, SeekService, Findbasic, QuestBrwSearch, Weemi, Wyyo and Zwangi itself. Each copy uses oneOur 2020 guide named QueryExplorer, SeekService and Findbasic: correct
Folders%ProgramFiles%\<Screen name> and %APPDATA%\<Screen name>Our 2020 guide said hundreds of .dll and .exe files; the entry lists three files per name: <Screen name>.dll, <Screen name>.exe and Uninstall.exe, plus one dropped installer such as zwangi127.exe
Registry and serviceValues under HKLM\Software\<Screen name> and an Uninstall key. It installs a service, for example ZwangiSearch Service, that starts automatically under LocalSystemOur 2020 guide said a scheduled task. Microsoft's entry lists a service, not a task, so we corrected it
BrowsersSeen in the wild on Internet Explorer 6, 7 and 8, Firefox 3.6 and Chrome BetaOur 2020 list of browsers was cut off; this is Microsoft's list. The browsers are old, which tells you the age of the family
Search resultsTurns what you type in the address bar into a search on its own pages: questbrowse.com, weemi.com or zwangi.comMatches our 2020 guide
404 pageMay replace the error page the browser shows for an address that cannot be resolvedMatches our 2020 guide
Pop-upsShows pop-up messages tied to about a hundred keywords, among them auction, book, free, game, shop, travel and weather in several languagesMatches our 2020 guide, which said keywords
ScreenshotsNot in the entry. The only hint is Symantec's alias name Spyware.ScreenspyOur 2020 guide said it takes screenshots without permission. We could not confirm it, so treat it as not confirmed
A Windows Defender history list showing two High alert detections of BrowserModifier:Win32/Zwangi dated 2018-05-11, with the item path C:\Program Files (x86)\Nexon\Nexon Launcher\nexon_launcher.exe, and in front of it the Zwangi 1.0 build 123 Uninstall Wizard welcome window
From our 2020 guide: the Windows Defender history with two High detections of BrowserModifier:Win32/Zwangi dated 11 May 2018, the selected one on C:\Program Files (x86)\Nexon\Nexon Launcher\nexon_launcher.exe, and the Zwangi 1.0 build 123 uninstall wizard. The path is a game launcher file, not a folder named like Zwangi, and we do not know why it was flagged.

Prifou and PriceFountain

Prifou is the family behind ads marked PriceFountain. Microsoft lists it as a high threat and says it can install when you download other software from third-party websites.

Read from Microsoft's entry for Win32/Prifou on 6 October 2026. Not tested on a PC.
WhatWhat Microsoft's entry saysNote
Entry datesPublished 19 November 2015, updated 15 September 2017. Microsoft links its post about the September 2016 release of the Malicious Software Removal ToolWe could not open that post, so we could not re-check the number our 2020 guide gave
How it arrivesWith other software downloaded from third-party websitesMatches our 2020 guide
Program nameThe entry in the program list may be called PriceFountainOur 2020 guide called it a standalone application: correct
AdsAds carry the attribution name Price Fountain. It uses two ways: a browser add-on that it enables by itself, and rundll32.exe running a DLL that injects ads into the browserOur 2020 guide listed phrases such as Ads by PriceFountain. We could confirm only the name Price Fountain and the words brought by PriceFountain in our picture
Scheduled tasksAdds scheduled tasks that run it and check for and download updatesNot in our 2020 guide. A task you did not create is one of Microsoft's listed signs
UninstallerAdds an uninstall option. Microsoft says to remove the program from the list of programs and the add-on from the browserMatches the normal removal below
Infection countNot given in the entryOur 2020 guide said around 6.8 million infections in two months, mostly in the USA and Europe. We could not re-check it, so it is not repeated as a fact
Slowdowns and crashesNot stated for PrifouOur 2020 guide said slowdowns and crashes. Plausible for an ad injector, but not something Microsoft's entry says
Three windows under the words BrowserModifier:Win32/Prifou: an Internet Explorer Manage Add-ons list with an entry named PriceFountain, a shopping ad strip with laptop bags marked brought by PriceFountain, and the PriceFountain download page
From our 2020 guide: the Internet Explorer add-on list with an entry named PriceFountain, a banner of luggage prices marked "brought by PriceFountain", and the PriceFountain download page. The ad strip carries the attribution name Microsoft's entry describes.

The families over time, 1994 to 2026

The dates come from Microsoft's own entries and posts, the reader threads we found and our 2020 guide. The 1994 line is the old guide's starting point and not a Microsoft date.

  1. 27 October 1994

    The first banner ad

    Our 2020 guide began with online advertising as a gold mine from 1994. The first banner ad is usually dated 27 October 1994, an AT&T banner on HotWired (thefirstbannerad.com). We did not check the date further. The next step it described is the one that matters here: people building programs that put ads on thousands of PCs, paid per click and per install.

  2. 16 September 2009

    Zwangi enters Microsoft's list

    The entry for BrowserModifier:Win32/Zwangi is published and is last updated on 15 September 2017.

  3. 29 October 2015

    Pokki entry published

    Microsoft stops detecting Pokki after definition 1.209.1398.0 in November 2015, because it does not violate the criteria for unwanted software.

  4. 19 November 2015

    Prifou entry published

    The entry for Win32/Prifou, last updated 15 September 2017. In September 2016 Microsoft wrote about Prifou in its Malicious Software Removal Tool post.

  5. December 2016

    Readers ask why SupTab!blnk keeps coming back

    A reader on Information Security Stack Exchange (12 December 2016) and one on Reddit describe the alert returning after Clean system. See the reader cases below.

  6. 7 to 13 April 2018

    Foniad

    Microsoft says on 10 April that since Saturday (7 April) a highly polymorphic browser modifier has been trying to infect and re-infect hundreds of thousands of machines. On 13 April it names the downloader and the other pieces.

    A world map titled Dofoil outbreak geographic impact, with Russia in the darkest blue and most other countries pale blue, under the words BrowserModifier:Win32/Foniad
    From our 2020 guide, captioned there as Foniad: a Microsoft map titled Dofoil outbreak geographic impact, darkest on Russia. It shows Dofoil, the coin-miner campaign Microsoft compared Foniad with, and not Foniad. We found no country map for Foniad itself.
  7. 11 May 2018

    A game launcher flagged as Zwangi

    Our 2020 picture of the Windows Defender history shows two High detections of Zwangi on a file of the Nexon Launcher game client, dated 11 May 2018. We do not know whether it was a false alarm.

  8. 10 January 2020

    Our first guide

    The guide that this page replaces. It was 1,572 words, written as if BrowserModifier were one infection.

  9. 6 October 2026

    This rewrite

    Read against Microsoft's entries, with the Foniad and Zwangi claims corrected.

Reader cases: when the alert keeps coming back

These are the cases we could read. They are second-hand, from forums, and they show what readers tried. They are not proof of what your alert is.

Read from the Stack Exchange page on 6 October 2026. The Reddit and Microsoft Answers parts are quoted there, and we did not open those pages.
CaseWhat the source saysHow it ended
BrowserModifier:Win32/SupTab!blnk, Information Security Stack Exchange (12 December 2016)The reader's Defender kept detecting it, and it came back a few seconds after Clean system or Apply actions. BitDefender 2017, AdwCleaner, Malwarebytes and HitmanPro found nothing. The browsers looked healthy, with no extensions or changed search engine and no CPU loadAn answerer pointed to Microsoft Answers threads where a program called VulcanRT appeared in common, and suggested checking add-ons, resetting browsers and cleaning temp files. The page shows no reply from the asker
The same alert, quoted in that answer from Microsoft AnswersA reader reset Internet Explorer and ran several tools. Only RogueKiller found anything. Defender's alert then pointed to VulcanRT, which they uninstalled, with Chrome, two redistributables and a Steam gameThe warning did not return. The reader did not know which step helped
The same alert, quoted from Reddit r/techsupportA reader deleted the shortcut files listed in the alert, for Chrome and Internet Explorer, and said it looked like a false positive. A System Restore to an earlier point did not helpFixed for that reader, who lost the Start Menu shortcuts and said they could live without them

The pattern fits what Microsoft says about Linkhortry, a family that modifies browser shortcut files. A shortcut that is flagged and keeps coming back is a different problem from an extension you can remove in the browser, so the removal chapter checks the shortcut first.

How the money is made

A browser modifier is paid for what it sends you to. That is the reason for the ads, the changed search results and the redirects, and it is also why removing one thing does not always stop it.

The sites linked by these ads are not the program's makers, so a link in an ad can lead to a shop or a game and still pay the program's makers.
RouteHow it earnsSource
Ads shown on the sites you visitPay-per-click and pay-per-install: ads carry links to third-party websites, such as shops, services and gaming portals. Prifou injects them and marks them with its attribution nameOur 2020 guide; Microsoft's Prifou entry
Search results on its own pagesThe address bar becomes a search box on pages run by the program's makers, as Zwangi does with questbrowse.com, weemi.com and zwangi.comMicrosoft's Zwangi entry
Redirects to sites that earn from impressionsFoniad opens sites in a series of redirects. Microsoft says they might be generating revenue through ad impressionsMicrosoft's Foniad entry
Traffic generated in the backgroundOur 2020 guide said malware can also be installed on a PC to make background traffic to preset sites. We found no Microsoft entry for a browser modifier that does only thisOur 2020 guide; not confirmed

What can actually go wrong

Our 2020 guide said these programs can steal personal information, cost you money and even lead to identity theft. The Microsoft entries we read for the browser modifiers say nothing like that. The higher risks belong to a trojan that installed one.

  • Medium

    Ads and search results you did not choose

    Intrusive ads on every site, sponsored links in search results and a changed start page or new tab. This is what Zwangi and Prifou are documented to do, and it can lead you to a page that sells you something.

  • Medium

    Redirects to pages you did not ask for

    Foniad opens websites in a series of redirects. Zwangi sends your searches to its own pages and can replace the 404 page. A redirect can end on a shop, a scam page or a download.

  • Medium

    Notifications allowed without asking

    Foniad sets Chrome to allow desktop notifications for the sites it visits, through registry keys under the Chrome policy key. Those notifications can show ads after the sites are closed.

  • Medium

    Shortcuts that open another address

    A shortcut file can be modified so that the browser opens certain websites when started from it. That is what Microsoft says Linkhortry does, and our 2020 picture shows the shortcut as the flagged resource.

  • High

    Other malware, if a trojan installed it

    Foniad was installed together with a DNS changer, a Monero coin miner and an adware DLL. Our 2020 guide put the miner and the DNS change on Foniad itself. Microsoft puts them on the downloader. Either way, when Foniad is on a PC the rest may be too.

  • Low

    Registry changes, crashes and slowdowns

    Our 2020 guide said registry changes can corrupt Windows and cause persistent crashes. The Microsoft entries we read list registry changes, services and scheduled tasks but do not say the PC crashes. An ad injector can slow a browser, so slowness is a reason to scan, not a symptom of one family.

  • Low

    Passwords, money and identity

    Nothing in Microsoft's entries for Zwangi, Prifou or Foniad says they take passwords or card numbers. A trojan that came with them, such as a downloader, could. That is why the after-clicked chapter is written for the trojan case, and we do not claim it happened to you.

What you may notice

Our 2020 guide said the symptoms vary by version and that some background activity cannot be seen without advanced knowledge. Both are true. The signs below are the ones we can tie to a source.

Not a test. A single sign does not prove a family.
SignWhat we found
The alert itselfOften the only sign. It came from Windows Defender or Windows Security in every case we read
Intrusive ads on every siteDocumented for Prifou: ads marked Price Fountain. Our 2020 guide listed ads on all sites as the first symptom
Search results full of extra links, or your searches opening on another pageDocumented for Zwangi: address-bar searches open on questbrowse.com, weemi.com or zwangi.com
Random redirects to suspicious websitesDocumented for Foniad: the browser opens sites in a series of redirects
Home page and new tab changed, extensions you did not addOur 2020 guide listed them. Prifou adds an add-on that it enables by itself. We found no Microsoft entry that gives a name for one extension to look for
New registry keys, scheduled tasks, services, processes or filesDocumented: Zwangi adds a service and folders in %ProgramFiles% and %APPDATA%, Prifou adds scheduled tasks, Foniad adds Chrome policy keys and a re-infection task
Nothing visibleOur 2020 guide said some variants run activities that users cannot see. Nothing here lets us rule out a quiet copy

How BrowserModifier got into your browser

Our 2020 guide listed bundles, ads and fake updates, and a trojan downloader for some. Microsoft's entries agree. None of them says one route for the whole category.

  1. 1

    Bundled with software you wanted

    Most of these programs ride with another installer, and the optional parts are often hidden in it on purpose. Microsoft's entry for Prifou says it can install when you download other software from third-party websites. Our 2020 guide said many people do not read the installer, which is why bundling worked so well.

  2. 2

    Third-party download sites

    The bundled installers sit on download portals. Our 2020 guide said some of the sites might be trusted and others shady. Pirated software and cracks are the worst place to look, and one reader case below lists a Steam game and two redistributables among the suspects.

  3. 3

    Tricks inside the installer

    Our 2020 guide listed pre-ticked boxes, fine print, misleading offers and misplaced buttons. Microsoft's own criteria say software must not install other software without a clear indication of its relationship to the main program, and must not circumvent the browser's consent dialogs.

  4. 4

    An attractive ad or a fake update prompt

    Our 2020 guide said some copies arrive after an ad or a fake update message. We have no case of our own to show for it, but it is the same route used by many other adware families.

  5. 5

    A trojan downloader already on the PC

    Foniad was installed by TrojanDownloader:Win32/Esendi.A with a compromised media app. Our 2020 guide said some variants were injected by a trojan downloader that was already present. Microsoft's post is the source for that.

The same few habits cover all of them: take software from its maker, choose the Custom or Advanced setup when it is offered, and read the screen before you click Next.

How to remove BrowserModifier

How to remove BrowserModifier and get your search engine back

Remove the extension first.

The search settings only stay fixed once nothing on the PC can change them again.

Which browser shows the ads?

Do not click Allow on device and do not delete a file yet. Our 2020 guide said an alert must not be ignored, and Microsoft says that choosing Allow lets the file run. First write down what Windows says.

  1. Set your search engine and start page

    Open Settings > Search engine, choose Change next to the address-bar engine and pick yours, then delete unknown entries under Manage search engines and site search. Under On startup, remove any address you did not set.

  2. Remove extensions you do not recognise

    Paste chrome://extensions into the address bar and click Remove on anything you did not install.

    Full procedure with screenshots: Remove a browser extension

  3. Check the Chrome shortcut and notifications

    Right-click the Chrome shortcut, choose Properties and check that Target ends with chrome.exe. Open Settings > Privacy and security > Site settings > Notifications and remove sites you did not allow. If chrome://policy lists notification settings you did not set, see the Foniad chapter.

    Full procedure with screenshots: Stop website notifications and pop-ups

  4. Reset Chrome

    Open Settings > Reset settings > Restore settings to their original defaults and confirm. Start page, search engine and pinned tabs reset and extensions turn off; bookmarks and saved passwords stay.

    Full procedure with screenshots: Reset a browser and fix a hijacked search engine

Then, whichever browser you use

  1. Step 1: Uninstall a BrowserModifier alert in Windows Security

    A BrowserModifier alert in Windows Security is removed like any other program, from the list of installed apps.

    In Windows 11 that is Settings > Apps > Installed apps, in Windows 10 Settings > Apps > Apps & features, and in both you can also use Control Panel > Programs and Features.

    Select a BrowserModifier alert in Windows Security, click Uninstall and follow the uninstaller to the end. Then look at the entries just above and below it when the list is sorted by date: bundled programs install at the same minute.

    Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix

  2. Step 2: Scan the PC, then run the offline scan

    A scan finds the parts of BrowserModifier that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Remove it from Windows 11 and Windows 10

Do the steps in order and stop when a scan from outside normal Windows is clean and the alert has not returned. We did not run these steps on a live infection; they follow Microsoft's pages. Keep Microsoft Defender or your own security product on while you do them.

  1. 1

    Remove the quarantined item

    In Protection history open the quarantined item and choose Remove. Microsoft says Remove deletes the threat from your device. Our 2020 guide said an unwanted program can usually be taken out in the Control Panel and that a malware infection needs a scan; both are right, which is why the next steps follow.

  2. 2

    Update and run a full scan

    Open Windows Security > Virus & threat protection > Scan options, choose Full scan and click Scan now. Microsoft says a full scan might find hidden threats. Windows Update brings the newest definitions. A scan cannot promise to find every trace.

  3. 3

    Uninstall what came with it

    In Settings > Apps > Installed apps uninstall anything you did not install, starting with PriceFountain, a Zwangi screen name or whatever was installed the day the alert began. The program names and uninstall steps are in Uninstall a program or app in Windows On uGetFix. Our 2020 guide said some versions have no uninstaller, are not in the list or install themselves again, so keep the next steps even if the list is clean.

  4. 4

    Check scheduled tasks and services

    Press Windows logo + R, type taskschd.msc and open Task Scheduler Library. Prifou adds scheduled tasks and Foniad re-infects with one, so write down tasks you did not create, with the file each one runs. For a Zwangi service, press Windows logo + R, type services.msc and look for a service with a name such as ZwangiSearch Service. We could not confirm the exact name of tasks for any family.

  5. 5

    Fix the shortcuts

    For each browser shortcut, right-click it, choose Properties and remove any web address after the browser file name in Target. If you are unsure, delete the shortcut and make a new one from the program in Start.

  6. 6

    Remove extensions and reset the browsers

    Use the browser tabs above. Our 2020 guide said security experts recommend resetting every installed browser, and that unwanted ads can remain if you skip it. That is right for a modifier of browser settings, so reset each browser after the program is gone, not before.

  7. 7

    Run Microsoft Defender Offline as a second opinion

    The steps are in Run a Microsoft Defender Offline scan. It restarts the PC and scans from outside normal Windows, where a program that hides from a running system cannot. Then open Protection history to read the result.

  8. 8

    If Foniad was named: check DNS and notifications

    Open Settings > Network & internet, open your Wi-Fi or Ethernet connection and look at DNS server assignment. If you never set a DNS server, it should be automatic. Our 2020 guide said Foniad changes DNS; Microsoft says its downloader does. In Chrome open Settings > Privacy and security > Site settings > Notifications and remove sites you did not allow (Stop website notifications and pop-ups). Our menu names follow Microsoft and Google pages and were not tried on a live copy.

  9. 9

    Update Windows and scan again

    Install every update under Settings > Windows Update, then run a quick scan. If the same alert returns after a restart, something still recreates it. Go back to the scheduled tasks and the shortcuts, or restore the PC to a point before the alert with System Restore.

Never download a removal program because a pop-up, a stranger or a phone number tells you to. A real threat does not need a payment page to fix. We name no product as a remover; Windows Security and its Offline scan are already on your PC.

Could it be a false alarm? How to tell and what to do last

Sometimes. Microsoft says potentially unwanted applications are not malware, and it stopped detecting Pokki because it does not violate the criteria. Only Microsoft can confirm that your file is a false positive.

Not a test. These are signs to weigh, not a way to clear a file.
Points to a real program or infectionPoints to a false alarm
The file came from a bundle, a download portal, a crack or an emailThe file came from the maker's own site and you were expecting it
You see ads, a changed home page or redirects as wellThe browser works normally and the alert came once
Other detections sit beside it, including trojan or miner namesOnly one detection, and no other scanner agrees
A folder, service or scheduled task with a Zwangi screen name or PriceFountainA game launcher or program you know, as in our 2020 picture of the Nexon Launcher file
The alert returns after Remove and a restartIt stays quarantined after Remove
  1. 1

    Do not allow it first

    Allowing a file lets it run. If you allowed one by mistake, open Virus & threat protection > Protection history, then Allowed threats, and use Don't allow; Microsoft says Windows Security will act on it again the next time it sees it.

  2. 2

    Send it to Microsoft

    Microsoft takes files for analysis at microsoft.com/wdsi/filesubmission and says submissions help it decide whether software is malware or unwanted. We did not use the form, so check its wording.

  3. 3

    Turn on blocking for unwanted apps

    Microsoft says blocking of potentially unwanted applications is off by default. In Windows Security open App & browser control > Reputation-based protection settings and turn it on, with both Block apps and Block downloads. Block downloads works in Microsoft Edge only.

After removal: keep your search engine and start page

If a trojan came with it: what to do about accounts and files

The scans deal with the PC. These steps deal with what a trojan downloader could have seen or done. Do them if the report named TrojanDownloader, Foniad, a coin miner or DNS changes.

  1. 1

    Change passwords from another device

    Email first, then banking, then everything else. Turn on two-step sign-in. Do this before you use banking on the PC.

  2. 2

    Sign out everywhere

    Use the sign out of all sessions option in your Google, Microsoft and social accounts so stolen cookies stop working.

  3. 3

    Check your money

    Look at card statements and any wallets for payments you did not make. We found no source that says the browser modifiers take card numbers; a trojan could.

  4. 4

    Look for a miner

    A coin miner such as Trojan:Win32/CoinMiner.CZ makes the PC slow and hot. Open Task Manager with Ctrl + Shift + Esc and sort by CPU. A process you do not know that uses a lot of it for no reason is a reason to scan again.

  5. 5

    Check browser settings

    If the home page, new tab or search engine changed, remove the extension and reset the browser settings. See the browser tabs above.

  6. 6

    Scan again in a week

    Run another full scan and a Defender Offline scan a week later, and keep a screenshot of the first alert.

Keep browser modifiers off your PC

The advice of 2020 still holds. These are the habits, with current menu names.

Do

  • Download programs from their makers' sites or the Microsoft Store, and take the Custom or Advanced setup when it is offered, so bundled extras can be declined.
  • Read each installer screen. Pre-ticked boxes, fine print and a button in an unusual place are the tricks our 2020 guide listed, and Microsoft's criteria say installing other software without a clear indication is not allowed.
  • Turn on potentially unwanted app blocking in Windows Security > App & browser control > Reputation-based protection settings. Microsoft says it is off by default.
  • Keep Windows Security with Real-time protection on and update it with Windows Update.
  • Open each browser's home page and search settings once after installing free software.
  • Keep a backup of your documents on a disk you unplug (File History or OneDrive), so a clean-up never costs you files.
  • On a public network a VPN hides your IP address from the sites you visit. It does not block a modifier that is already installed.

Don't

  • Do not use cracks, keygens or pirated software, or installers from sites that bundle them.
  • Do not click an ad or a pop-up that says your browser or player is out of date.
  • Do not use Allow on device to stop an alert you have not checked.
  • Do not click Next without reading, even if the program is one you wanted.

Questions about BrowserModifier

What is BrowserModifier?

BrowserModifier is the category word that Microsoft Defender puts at the start of a detection name, as in BrowserModifier:Win32/Zwangi, and it is not one virus. It tells you that Microsoft judged a Windows program to change browser settings, such as the home page, the search engine or the shortcuts, without adequate consent. What sits behind the name differs by family:

  • an unwanted search toolbar
  • an ad injector or
  • in Foniad's case
  • the payload of a trojan downloader

Read the family name and the file path in the alert, because they decide what to do, not the category word.

Is BrowserModifier a virus?

Usually not in the strict sense, but it can come with one. Microsoft classes Zwangi and Prifou as unwanted software that changes your browser and shows ads, and Microsoft's own criteria say potentially unwanted applications are not malware.

Foniad was different: Microsoft says a trojan downloader installed it together with a coin miner and a DNS changer. So the word on its own does not tell you whether the PC is infected. Check which other detections sit beside it, and remove the program rather than ignore the alert.

How do I remove BrowserModifier from Windows 11 or 10?

Open Windows Security, go to Virus & threat protection and Protection history, and choose Remove on the quarantined item. Then run a Full scan, uninstall any program you did not install, check scheduled tasks and browser shortcuts, remove unknown extensions and reset each browser.

A Microsoft Defender Offline scan is a good second opinion. If the report names Foniad or a trojan, also check DNS and notifications and change your passwords from another device. We did not test these steps on a live copy, so stop only when a scan is clean and the alert stays away.

Why does Windows Defender keep finding BrowserModifier after I clean it?

Something still recreates it, or the alert points to a shortcut that stays modified. Readers in 2016 saw BrowserModifier:Win32/SupTab!blnk return within seconds of Clean system, and other scanners found nothing. One later uninstalled a program called VulcanRT and the alert stopped, though they did not know which step helped.

Foniad is documented to re-infect with a scheduled task. Check Task Scheduler, the browser shortcuts and recently installed programs, and run the Defender Offline scan. If nothing else helps, a restore point from before the alert is an option.

What is BrowserModifier:Win32/Foniad?

It is a polymorphic browser modifier that Microsoft described in April 2018. It runs as xsetup.exe, opens Chrome and visits listed sites in a series of redirects, and sets Chrome to allow notifications from them.

Microsoft says a trojan downloader, TrojanDownloader:Win32/Esendi.A, installed it along with a compromised media app, a Monero coin miner and an adware DLL, and that the downloader changes the DNS settings. Our 2020 guide put the miner and the DNS change on Foniad itself, which Microsoft's posts do not. Treat a Foniad alert as a possible trojan case.

What is BrowserModifier:Win32/Zwangi?

It is a browser modifier that Microsoft first listed on 16 September 2009 and last updated in September 2017. It changes your search results and shows pop-up ads, turns address-bar searches into searches on questbrowse.com, weemi.com or zwangi.com, and can replace the 404 page.

It installs under one of 57 screen names, such as QueryExplorer or Findbasic, with a folder in Program Files and AppData and a service that starts automatically. The program list may show Zwangi 1.0 build 127. Microsoft rates it a high threat, and it was built for old browsers.

Could the BrowserModifier alert be a false positive?

Yes, in some cases, though only Microsoft can confirm one. Microsoft stopped detecting Pokki in November 2015 because it does not violate its criteria, and our 2020 picture shows Zwangi flagged on a game launcher file, which looks odd.

A single detection on a program from its maker's own site, with no ads or changed settings, points that way. A detection on a shortcut after a bundled download, or beside a trojan name, does not. Do not choose Allow on device; send the file to Microsoft through its submission page and keep it quarantined meanwhile.

How does BrowserModifier get on my PC?

Mostly in a bundle with software you chose. Microsoft says Prifou can install when you download other software from third-party websites, and our 2020 guide added pre-ticked boxes, fine print, misleading offers and fake update prompts. A few came from a trojan downloader that was already on the PC, as with Foniad.

Cracks and pirated software are the worst source. Choose the Custom or Advanced setup, read each screen and download only from the maker's site or the Microsoft Store. Microsoft also lets you turn on blocking for unwanted apps, which is off by default.

Can BrowserModifier steal my passwords or money?

Nothing in Microsoft's entries for Zwangi, Prifou or Foniad says they take passwords or card numbers. Our 2020 guide said these programs can lead to scams and identity theft, and we could not confirm it for the modifiers themselves.

Their documented harm is ads, redirects, changed search results, notifications and changed shortcuts. The risk rises if a trojan downloader came with them, so check the other names in the report. If one did, change passwords from another device, sign out everywhere and watch your statements.

Will Fortect remove BrowserModifier?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For BrowserModifier, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

  1. Microsoft Security Intelligence: BrowserModifier:Win32/Foniad (published 9 April 2018) (read October 6, 2026)
  2. Microsoft Threat Intelligence (@MsftSecIntel) on Foniad, Esendi and CoinMiner.CZ, 10 and 13 April 2018 (read October 6, 2026)
  3. Microsoft Security Intelligence: BrowserModifier:Win32/Zwangi (published 16 September 2009, updated 15 September 2017) (read October 6, 2026)
  4. Microsoft Security Intelligence: Win32/Prifou (published 19 November 2015, updated 15 September 2017) (read October 6, 2026)
  5. Microsoft Security Intelligence: BrowserModifier:Win32/Pokki (published 29 October 2015, updated 13 July 2017) (read October 6, 2026)
  6. Microsoft Security Intelligence: BrowserModifier:Win32/Linkhortry (summary read in search results) (read October 6, 2026)
  7. Microsoft Security Intelligence: BrowserModifier:Win32/Xeelyak (summary read in search results) (read October 6, 2026)
  8. Microsoft Learn: How Microsoft identifies malware and potentially unwanted applications (updated 10 September 2026) (read October 6, 2026)
  9. Microsoft Support: Protect your PC from potentially unwanted applications (read October 6, 2026)
  10. Microsoft Support: Protection History in the Windows Security App (search excerpt) (read October 6, 2026)
  11. Microsoft Support: Virus and Threat Protection in the Windows Security App (search excerpt) (read October 6, 2026)
  12. Information Security Stack Exchange: Microsoft Windows Defender keeps detecting BrowserModifier:Win32/SupTab!blnk (12 December 2016) (read October 6, 2026)
  13. The First Banner Ad: AT&T "You Will", 27 October 1994 (search excerpt) (no longer online) (read October 6, 2026)
  14. 2-spyware.com: Remove BrowserModifier (our own guide of 10 January 2020, replaced by this one) (read October 6, 2026)

More removal guides

Remove Immediate Action Required

Immediate Action Required is a fake notification that might pop-up out of nowhere and prompt users to download useless bogus software Immediate Action Required is a scam that users mightAdwareMedium riskUgnius Kiguolis ·

Remove ReceiverHelper Mac virus

ReceiverHelper virus is a high threat to your personal safety and Mac security ReceiverHelper is a harmful application targeting Mac devices, classified under the Adload malware family. It is notoriousAdwareMedium riskJake Doevan ·

Remove Casalemedia

Casalemedia is a legal advertising service but is sometimes abused by crooks to gain personal income Casalemedia is a legitimate advertising service that provides assistance in monetizing on online contentAdwareMedium riskJake Doevan ·

Remove D1ue3yi0hkdsdl.cloudfront.net ads

D1ue3yi0hkdsdl.cloudfront.net ads is the content related to scam campaigns and fake errors or warnings D1ue3yi0hkdsdl.cloudfront.net is the program that causes notifications and advertisements that may appear unexpectedly, preventing you fromAdwareMedium riskJulie Splinters ·

Questions and experiences: BrowserModifier

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year