Adware.Social2Search
Short bio
Adware.Social2Search is Malwarebytes’ detection for a family of adwaretargeting Windows systems.
Symptoms
Protection
Remediation
Malwarebytes can detect and remove Adware.Social2Search without further user interaction.
- Please download Malwarebytesto your desktop.
- Double-click MBSetup.exeand follow the prompts to install the program.
- When your Malwarebytes for Windowsinstallation completes, the program opens to the Welcome to Malwarebytes screen.
- Click on the Get started button.
- Click Scan to start a Threat Scan.
- Click Quarantineto remove the found threats.
- Reboot the system if prompted to complete the removal process.
Malwarebytes removal log
Malwarebytes log of removal for a variant of Adware.Social2Search will look similar to this:
Malwarebyteswww.malwarebytes.com-Log Details-Scan Date: 3/29/17Scan Time: 11:49 AMLogfile: mbamSocial2Search.txtAdministrator: Yes-Software Information-Version: 3.0.5.1299Components Version: 1.0.43Update Package Version: 1.0.1620License: Premium-System Information-OS: Windows 7 Service Pack 1CPU: x64File System: NTFSUser:{computername}\{username}-Scan Summary-Scan Type: Threat ScanResult: CompletedObjects Scanned: 367332Time Elapsed: 5 min, 32 sec-Scan Options-Memory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: EnabledHeuristics: EnabledPUP: EnabledPUM: Enabled-Scan Details-Process: 1PUP.Optional.Wajam.Gen, C:\Program Files\85890b9283acfd8343df56cd6bb80a70\04146af46813e501bb7ca87370e1aaeb.exe, Quarantined, [18446], [259462],1.0.1620Module: 1PUP.Optional.Wajam.Gen, C:\Program Files\85890b9283acfd8343df56cd6bb80a70\04146af46813e501bb7ca87370e1aaeb.exe, Quarantined, [18446], [259462],1.0.1620Registry Key: 10PUP.Optional.Wajam, HKLM\SOFTWARE\CLASSES\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, Delete-on-Reboot, [131], [170024],1.0.1620PUP.Optional.Wajam, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, Delete-on-Reboot, [131], [-1],0.0.0PUP.Optional.Wajam, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, Delete-on-Reboot, [131], [170024],1.0.1620PUP.Optional.Wajam, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, Delete-on-Reboot, [131], [170024],1.0.1620PUP.Optional.Social2Search.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\85890b9283acfd8343df56cd6bb80a70, Delete-on-Reboot, [18492], [261569],1.0.1620PUP.Optional.Wajam, HKCU\SOFTWARE\WajIEnhance, Delete-on-Reboot, [131], [244670],1.0.1620PUP.Optional.Wajam.Gen, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\85890b9283acfd8343df56cd6bb80a70, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Social2Search, HKLM\SOFTWARE\Socia2Se Browser Enhancer, Delete-on-Reboot, [444], [345866],1.0.1620PUP.Optional.Wajam, HKCU\SOFTWARE\WajIEnhance, Delete-on-Reboot, [131], [244670],1.0.1620PUP.Optional.Social2Search, HKLM\SOFTWARE\WOW6432NODE\Socia2Se Browser Enhancer, Delete-on-Reboot, [444], [345866],1.0.1620Registry Value: 5PUP.Optional.Wajam, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [131], [-1],0.0.0PUP.Optional.Wajam, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [131], [-1],0.0.0PUP.Optional.Wajam, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [131], [-1],0.0.0PUP.Optional.Wajam, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [131], [-1],0.0.0PUP.Optional.Social2Search.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\85890b9283acfd8343df56cd6bb80a70|DISPLAYNAME, Delete-on-Reboot, [18492], [261569],1.0.1620Data Stream: 0(No malicious items detected)Folder: 3PUP.Optional.Wajam.Gen, C:\Program Files\85890b9283acfd8343df56cd6bb80a70\129f0fa04ac4d51af24977e119821088, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Wajam.Gen, C:\PROGRAM FILES\85890b9283acfd8343df56cd6bb80a70, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Social2Search.Generic, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Socia2Se Browser Enhancer, Delete-on-Reboot, [1484], [326625],1.0.1620File: 12PUP.Optional.Wajam.Gen, C:\PROGRAM FILES\85890b9283acfd8343df56cd6bb80a70\129f0fa04ac4d51af24977e119821088\cf52f145a89b363b48b0ccf0bc6cc06b.ico, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Wajam.Gen, C:\Program Files\85890b9283acfd8343df56cd6bb80a70\129f0fa04ac4d51af24977e119821088\d35531312b2e80d720898ab80ff109bc.ico, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Wajam.Gen, C:\Program Files\85890b9283acfd8343df56cd6bb80a70\129f0fa04ac4d51af24977e119821088\f7c22fa637448a035506da9e427461e4.ico, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Wajam.Gen, C:\Program Files\85890b9283acfd8343df56cd6bb80a70\04146af46813e501bb7ca87370e1aaeb.exe, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Wajam.Gen, C:\Program Files\85890b9283acfd8343df56cd6bb80a70\c6182f9cb662a9e333002e06810f826d.exe, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Wajam.Gen, C:\Program Files\85890b9283acfd8343df56cd6bb80a70\c92b3103a49ebb99abf869e8dd17de8f.exe, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Wajam.Gen, C:\Program Files\85890b9283acfd8343df56cd6bb80a70\cf52f145a89b363b48b0ccf0bc6cc06b.ico, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Wajam.Gen, C:\Program Files\85890b9283acfd8343df56cd6bb80a70\df1a166bec69178b887ca05ac8cb37de, Delete-on-Reboot, [18446], [259462],1.0.1620PUP.Optional.Social2Search.Generic, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Socia2Se Browser Enhancer\Social2Search Website.lnk, Delete-on-Reboot, [1484], [326625],1.0.1620PUP.Optional.Social2Search.Generic, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Socia2Se Browser Enhancer\Settings.lnk, Delete-on-Reboot, [1484], [326625],1.0.1620PUP.Optional.Social2Search.Generic, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Socia2Se Browser Enhancer\SignIn with Twitter.lnk, Delete-on-Reboot, [1484], [326625],1.0.1620PUP.Optional.Social2Search.Generic, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Socia2Se Browser Enhancer\uninstall.lnk, Delete-on-Reboot, [1484], [326625],1.0.1620Physical Sector: 0(No malicious items detected)(end)