WhiteSmoke Inc

Publisher Information

WhiteSmoke Inc is a software publisher located in Wilmington, Delaware in the United States*. The company is a primary distributor of unwanted software. WhiteSmoke based in Israel is a toolbar company that provides translation and grammar checking services within its toolbar products. Typically WhiteSmoke developes a customized Conduit toolbar in which it gets payments for each toolbar installed. Thre are 4 additional code signing certificates issued to this publisher.
Remove WhiteSmoke Inc Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
7/6/2013 8:00:00 PM

Valid to:
8/5/2015 7:59:59 PM

Subject:
CN=WhiteSmoke Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=Wilmington, S=Delaware, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
55439b87cb55e81147c072f06f4f77ef

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.WhiteSmoke, PUP.Installer.WhiteSmoke, PUP.WhiteSmoke.Installer, PUP.WhiteSmoke.Installer (M), PUP.WhiteSmoke.Amonetize.Installer (M), PUP.WhiteSmoke (M)
100.00%

Dr.Web
Adware.Conduit.6, Trojan.MulDrop5.10078, infected with Trojan.Packed.24524, Adware.Downware.1457, Adware.WhiteSmoke.1374
30.00%

VIPRE Antivirus
Conduit, Threat.4788237, Trojan.Win32.Generic!SB.0, Threat.4150696
24.00%

Bkav FE
W32.Clod13e.Trojan, W32.HfsAdware
22.00%

Avira AntiVirus
ADWARE/InstallCore.Gen9, ADWARE/Adware.Gen2
22.00%

ESET NOD32
Win32/OpenCandy, Win32/WhiteSmoke (variant), Win32/Toolbar.Montiera, Win32/Injected (variant), Win32/Amonetize (variant)
20.00%

G Data
Win32.Application.InstallCore.CZ, Gen:Variant.Adware.Graftor.154589, Trojan.GenericKD.1935474, Gen:Variant.Application.Bundler.Amonetize.14
20.00%

IKARUS anti.virus
Trojan.Win32.Injected, Trojan.SuspectCRC, Backdoor.Backdoor.Win32.Hupigon, PUA.ClientConnect
18.00%

ESET NOD32
Win32/Injected.F trojan, Win32/InstallCore.PD potentially unwanted application, Win32/InstallCore.PO potentially unwanted application
16.00%

NANO AntiVirus
Riskware.Win32.InstallCore.dfgoth, Trojan.Win32.Toolbar.dgukom, Riskware.Win32.InstallCore.dmiynb, Riskware.Win32.Amonetize.cxmucj
16.00%

1 / 68      (Adware)

1 / 68      (Adware)
whitesmoke_tsv44eds.exe  (f32830313a2edd0377a1520fc5cb2fde)

1 / 68      (Adware)
liveistream_installer.exe  (023cce98ce82d1a98db589329c471542)

1 / 68      (Adware)

1 / 68      (Adware)
whitesmokesetup-v1.3.exe  (d576f1d3f534781d5fef65117b9cb201)

1 / 68      (Adware)
setup-1.2.exe  (0becfd810217f3fb815dc49385e97c15)

1 / 68      (Adware)
shield.exe  (00c65f5848ad5c3f7966e4addb45ea8a)

1 / 68      (Adware)
whitesmokesetup-v1.3.exe  (0f77cd7e2343e7f58ef9a239e8f74917)

1 / 68      (Adware)
setup-1.2.exe  (db354e45bbec8a621fc608b28da9661a)

1 / 68      (Adware)
setup-1.2.exe  (904db380c56924c0bdb6bf154370d86a)

1 / 68      (Adware)
setup-1.2.exe  (14d610065903cd9f9aa9a81911b2a30b)

1 / 68      (Adware)
setup-1.2.exe  (cd6c58b095bb3d6b667c655b9237c0de)

1 / 68      (Adware)
whitesmoke4_1.3.12.2_cn.exe  (2814eab9c9492e2e561c7cfd13e39d86)

1 / 68      (Adware)
setup-1.2.exe  (eefd6d226be30bf575760d5ae5b032d7)

1 / 68      (Adware)
setup-1.2.exe  (50d6e5ab1714e5465410da146977ed78)

1 / 68      (Adware)
setup-1.2.exe  (f97a171320d18349cce3d0a651e1cb39)

1 / 68      (Adware)
dynamicsetup__155.exe (Installer by Amonetizé)  (b38a3e19bd2c286ffc93f5da70cae879)

1 / 68      (Adware)
whitesmoke_tsv3gj7xb.exe (WhiteSmoke)  (15b392c4b9e097ebcbf4986a9a2034a7)

1 / 68      (Adware)
whitesmoke_cid6667.exe  (95ea8a478bf7c6eab1110b4f5cb6afaa)

1 / 68      (Adware)
setup-1.2.exe  (62b4241f74f0d9d8a1595288dc2063cc)

12 / 68    (Adware)
whitesmoke_brch_cid6667.exe  (a1d1ae57b6b05bb9cf8228237a31b5cc)

7 / 68      (Adware)
whitesmoke_tsv24wgfw.exe  (28f0420819725505b77aa24e98d57b4a)

3 / 68      (Adware)
whitesmoke_tsv3h5zi2.exe (WhiteSmoke)  (f9021d71af1bf09836d0d44ecf933f0f)

5 / 68      (Adware)
whitesmoke_setup_ask.exe  (32e616ff9b846b8edee191471293e1c1)

1 / 68      (Adware)
setup-1.2.exe  (b70d4ea9ff321d638ede30357da5edc8)

1 / 68      (Adware)
whitesmokesetup-v1.3.exe  (3c32b5793787e299e983c7bbf2f3a628)

1 / 68      (Adware)

1 / 68      (Adware)
setup-1.2.exe  (c8a89b79f7d762dfe1f66d757cc09878)

4 / 68      (Adware)
whitesmoke_tsv4gq9rx.exe (WhiteSmoke)  (627439f3f2532ad1aba04cb2b280b57a)

8 / 68      (Adware)
liveistream_installer.exe  (6a13270bf2436174935cdb6a90aaf31b)

 
Latest 30 of 112 files

Downloads URLs for files signed by WhiteSmoke Inc.

3 / 68      (Adware)
http://get.whitesmoke.com/WhiteSmokeWriterPro.exe  (83360ea3da66866a7c681953b585e53d)

The following websites host and distribute files published by WhiteSmoke Inc.

The certificates below are also signed by WhiteSmoke Inc.

1464EFB2CC87AF9A3F855E683C12294D  (Aug 04, 2015 to Sep 03, 2017)

64048D72F9FFEF12A43FC4F4CEA580E3  (Jun 28, 2011 to Jul 07, 2013)

4261300AF5254B751250B0CDBDA6CE61  (Jun 09, 2008 to Jul 08, 2011)

6909B96020B7E23C83DA2D03280AA61E  (May 17, 2007 to Jun 17, 2008)

The following publishers (by Authenticode signature organization name) are related.

Remove WhiteSmoke Inc Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to WhiteSmoke Inc by VeriSign, Inc. on July 06, 2013 with the serial number '55439b87cb55e81147c072f06f4f77ef'.