Recommended Free Tools
Special Search Option—also called SSOption or SpecialSearchOffer—is a historical potentially unwanted program (PUP) associated with adware and browser-hijacking behavior. Run a current Malwarebytes scan, use AdwCleaner if redirects remain, remove unknown extensions and installed programs, then verify your browser settings after a restart. Do not treat every Yahoo result or unfamiliar file as proof of this specific infection.
What Special Search Option is
Malwarebytes’ historical sample classified Special Search Option as a PUP, adware and browser hijacker. It could display advertisements unrelated to the websites being viewed, change the homepage, new-tab page and search provider, install browser extensions, and redirect searches through Yahoo-powered or related infrastructure. The documented sample arrived as a bundled installer component rather than as a normal browser feature.
Names that may refer to the same campaign or related detections include Special Search Option, SSOption, SpecialSearchOffer, Adware.SpecialSearchOffer.Generic, PUP.Optional.WinYahoo and SearchProvide. Detection names vary by security product and definition database; they should not automatically be interpreted as separate infections. The historical guide associated the sample with both Adware.SpecialSearchOffer.Generic and PUP.Optional.WinYahoo. Historical removal evidence
The original report dates from January 2019 and used Windows 7 and Malwarebytes 3.6.1.2711. Its file names and screenshots are useful identification clues, but its interface labels are not current Malwarebytes instructions.
#1 Best Overall
Signs your computer may be affected
- The homepage, new-tab page or default search engine changed without permission.
- Searches redirect through unfamiliar domains or unexpected Yahoo-powered URLs.
- Pop-ups or injected advertisements appear on sites that normally do not show them.
- An extension named SpecialSearchOffer or a similar unfamiliar name appears.
- An installed program named SSOption, Special Search Option or ThetaSoft is present.
- A service or executable associated with ThetaSoftQZO appears.
- Malwarebytes reports Adware.SpecialSearchOffer.Generic or PUP.Optional.WinYahoo.
A Yahoo result by itself is not evidence of infection: Yahoo can be a legitimate chosen provider. Unauthorized changes combined with an unknown extension, program, service or matching detection are more meaningful.
Before you remove it
- Stop entering passwords or financial information into redirected or unfamiliar pages. If you entered credentials, change them from a known-clean device and enable multifactor authentication where possible.
- Close suspicious tabs and save open work. Cleanup tools may restart Windows.
- Download Malwarebytes and AdwCleaner only from their official pages.
- Do not manually delete registry keys, services or program folders as a first step. Preserve logs and make a backup before advanced changes.
The historical sample was reported as arriving through a bundler. That means it was packaged with another installer and could be accepted accidentally when a user used default options instead of reviewing Custom or Advanced setup screens. This explains the documented sample; it does not prove that every later case used the same distributor.
Removal method 1: run current Malwarebytes
Use the current Malwarebytes for Windows application rather than copying labels from the 2019 guide.
- Download Malwarebytes from the official Malwarebytes page and install it.
- Allow the application and detection database to update.
- Start the available malware or threat scan in the current interface.
- Review the results and quarantine detected PUPs, adware and associated artifacts.
- Accept the restart prompt, then sign in again and review the scan report.
The historical scan quarantined a ThetaSoftQZO.exe process, its Windows service, Chrome extension data, a Firefox extension and search-plugin data, Internet Explorer SearchScopes and preference entries, and an installer named SPECIALSEARCHOPTION.EXE. Current detection names and interface controls may differ.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Removal method 2: use AdwCleaner for browser hijacking
Malwarebytes AdwCleaner is a free utility designed for adware, PUPs, browser hijackers and unwanted preinstalled software.
- Download and install AdwCleaner using Malwarebytes’ official instructions.
- Open AdwCleaner and click Scan Now.
- Review detected items and select the PUPs or adware you want quarantined.
- Click Next, then choose Quarantine where offered.
- Save and close documents when prompted; a restart may be required.
- After signing in, review the cleanup log and run another scan if symptoms remain.
Do not use Run Basic Repair unless a qualified support agent directs you. AdwCleaner’s repair controls and quarantine behavior are documented in its application overview and quarantine guidance.
Current requirements list Windows 10, Windows 11 and Windows 8.1. Windows XP, Vista, 7 and 8 are no longer supported: AdwCleaner system requirements. On an unsupported system, upgrade where possible or use security software that explicitly supports that Windows version.
Clean each browser
Chrome and Chromium browsers
- Open the browser’s Extensions page and remove extensions you do not recognize or no longer need.
- Check the homepage, startup and new-tab settings.
- Set the default search engine to the provider you chose.
- If an extension or search setting is locked, inspect browser policies instead of deleting profile files manually.
The historical guide recorded Chrome extension ID mpicjgpamgcnpiacdciefbgahmkhhogc. Treat it as a historical indicator, not a universal identifier for current variants.
Free tools Windows power users keep installed
One-click scans. No signup required.
Firefox
- Open Add-ons and Themes and remove unknown extensions.
- Check homepage, new-tab and search settings.
- Restart Firefox and confirm the settings stay unchanged.
- If they return, inspect the affected profile and synchronization settings.
Historical artifacts included specialsearchoffer-1.1.1-an+fx.xpi and a search-plugin file named Yahoo power search.xml. These names alone do not prove an active infection today.
Rank #4
Internet Explorer and legacy settings
The original Windows 7 evidence showed altered Internet Explorer start-page and SearchScopes registry values. Treat those instructions as legacy evidence; do not edit the registry blindly on a modern system.
Remove the associated installed program
- Open Installed apps (or Apps & features).
- Search for SSOption, Special Search Option, ThetaSoft or a program installed at the same time as the browser changes.
- Uninstall only an entry that clearly matches the unwanted software, then restart.
The historical uninstall entry was HKLMSOFTWAREWow6432NodeMicrosoftWindowsCurrentVersionUninstallThetaSoft, with C:Program Files (x86)ThetaSoftuninstall.exe. An unfamiliar publisher or folder without corroborating evidence is not automatically malicious.
Check persistence only when symptoms remain
The historical FRST log contained C:Program Files (x86)Common FilesThetaSoftQZOThetaSoftQZO.exe and a service named ThetaSoftQZO. Filename matching is not conclusive: confirm the path, publisher and digital signature, installed-program entry, browser changes, scan detections and file dates.
If a service, executable or setting survives automated cleanup, save the scan logs and seek a reputable malware-removal forum or qualified technician. Do not run random registry cleaners, “take ownership” scripts or FRST fixes you do not understand.
If the hijack keeps returning
- Check every installed browser, not just the one you normally use.
- Review extensions, installed programs, browser policies, scheduled tasks and startup items.
- Check security-software logs for a second infection.
- Review synchronization. Chrome Sync can restore a removed extension or setting; Malwarebytes documents resetting Chrome Sync for recurring browser detections: Chrome synchronization guidance.
- AdwCleaner includes a Reset Chrome Policies option, but do not use Basic Repair without qualified guidance.
If the scanner finds nothing, the original PUP may already be gone, only browser settings may remain, the setting may be legitimate, the browser may be organization-managed, or another hijacker may be responsible. A wrong homepage alone is not a reason to delete registry keys.
Verify that cleanup worked
- No SSOption, Special Search Option or matching ThetaSoft entry remains in Installed apps.
- No suspicious extension remains in any installed browser.
- The homepage, new-tab page and default search engine are expected.
- Searches no longer redirect and injected advertising has stopped.
- A follow-up scan is clean or no longer detects the same items.
- The ThetaSoftQZO service or executable does not reappear.
- Settings remain unchanged after a reboot and ordinary browsing.
- Synchronization is not restoring the removed extension or setting.
When to get professional help
Escalate beyond a routine PUP cleanup if the infection repeatedly returns, security tools are blocked, unknown user accounts or suspicious logins appear, ransomware or credential theft is suspected, multiple malware families are detected, or the computer contains sensitive business or financial data. A paid Malwarebytes plan can provide ongoing real-time protection, but purchasing it is not required to remove the historical PUP. AdwCleaner is the free first-line option for adware and browser hijacking; it is not a substitute for incident response in a broader compromise.
The Bottom Line
Use current Malwarebytes first, follow with AdwCleaner when browser hijacking remains, then remove unknown extensions and programs and verify settings after a restart. Historical names such as SSOption, ThetaSoftQZO and the recorded extension IDs help investigation, but none proves infection without supporting scan, path and behavior evidence.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




