PUP.Optional.Wajam

detection icon

Short bio

PUP.Optional.Wajam i Malwarebytes’ detection name for a type of potentially unwanted program (PUP)in the form of a browser add-on marketed as a “social search.” It injects new adverts into the websites you visit, making it possible to redirect traffic to potentially malicious sites, as well as collect personal information.

Type and source of infection

PUP.Optional.Wajam is often found detecting one or more parts of another PUP.

Protection

block PUP.Optional.Wajam

Malwarebytes blocks PUP.Optional.Wajam

Remediation

Malwarebytes can detect and remove PUP.Optional.Wajam without further user interaction.

  1. Please download Malwarebytesto your desktop.
  2. Double-click MBSetup.exeand follow the prompts to install the program.
  3. When your Malwarebytes for Windowsinstallation completes, the program opens to the Welcome to Malwarebytes screen.
  4. Click on the Get started button.
  5. Click Scan to start a Threat Scan.
  6. Click Quarantineto remove the found threats.
  7. Reboot the system if prompted to complete the removal process.

Add an exclusion

Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.

  • Open Malwarebytes for Windows.
  • Click the Detection History
  • Click the Allow List
  • To add an item to the Allow List, click Add.
  • Select the exclusion type Allow a file or folderand use the Select a folderbutton to select the main folder for the software that you wish to keep.
  • Repeat this for any secondary files or folder(s) that belong to the software.

Traces/IOCs

Associated files:

  • priam_bho.DLL
  • wajam_*.exe
  • wajam.ico
  • SHA256 c4a0e9d6684b1bcae6f1554e25cabbe1775307e8adfb3160b75f8a3c53dbc14c
  • SHA256 e9e3974e589c8f9757928c1cfe8954fc388a41c7a142ba30a2d685a6197cd2b0
  • SHA256 653c41fa8a501546a2382c7da15de2acb400885231a01ae3f10100cfa77d08ec
  • SHA256 727b5ca30c0a0baa35b5ca84ed2431ce7ce776208db638ab2f399e0d30722b97
  • SHA256 f30b08aa4be33a7eb225924a4490af9e2d24b4a558675add5af7c6e3d7d5180d
  • SHA256 7a97f99fc3876308a3315b38a8c61128e9b056a5b72fef55aadd838eef52f9fc
  • SHA256 ac9c1d06a1ad7a77a35d86fb72c484e0831b3a33d019e7165651e4f31d22a7d7
  • SHA256 4d1ff09f71d901f65da0f989761e8f333eb70a703e9461b57e400d5500714144
  • SHA256 b667ca825870cc60c0ecc2f930c1d307de6116753ef32ecdf2bfc8c96c82f2bc
  • SHA256 17aaf8918908a990690fb9181a7e8c8eb7033a818ceffed273bb904919a72fe0

Domains:

  • telecharger-Installer[DOT]com
  • technologiesaintdenis[DOT]com
  • technologierachel[DOT]com
  • technologielaurier[DOT]com
  • technologiecoloniale[DOT]com
  • technologiebernard[DOT]com
  • saintdominiquetechnology[DOT]com
  • InstallationRapideEtGratuite[DOT]com
  • installation-sur-iphone[DOT]com
  • InstallateurdAppsCool[DOT]com

Associated threats

  • PUP.Optional.Wajam.A
  • PUP.Optional.Wajam.PrxySvrRST