WhiteSmoke Inc

Publisher Information

WhiteSmoke Inc is a software publisher located in New York, United States*. The company is a primary distributor of unwanted software. WhiteSmoke based in Israel is a toolbar company that provides translation and grammar checking services within its toolbar products. Typically WhiteSmoke developes a customized Conduit toolbar in which it gets payments for each toolbar installed. Thre are 4 additional code signing certificates issued to this publisher.
Remove WhiteSmoke Inc Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
5/17/2007 6:00:00 PM

Valid to:
6/17/2008 5:59:59 PM

Subject:
CN=WhiteSmoke Inc, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6909b96020b7e23c83da2d03280aa61e

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.WhiteSmoke.V, PUP.WhiteSmoke.H, PUP.WhiteSmoke.W, PUP.WhiteSmoke.M, PUP.WhiteSmoke.I, PUP.WhiteSmoke.G, Common.PUP.WhiteSmoke.H, PUP.WhiteSmoke.J, PUP.WhiteSmoke.F, PUP.WhiteSmoke.K, PUP.WhiteSmoke.Installer (M), PUP.WhiteSmoke (M), PUP.WhiteSmoke.PocketSoft (M), PUP.WhiteSmoke.WintertreeSoftware (M), PUP.WhiteSmoke.MacrovisionCorporation.Installer (M), Common.PartOf.PUP.WhiteSmoke (M), PUP.WhiteSmoke.Deskperience (M), PUP.WhiteSmoke.TODOCompanyname (M)
100.00%

avast!
Win32:WhiteSmoke-B [PUP]
25.53%

Panda Antivirus
Suspicious file
2.13%

1 / 68      (Adware)
WSEnrichment.exe (WSEnrichment Application by WhiteSmoke)  (0b0d9b54e71c13bc7a7e6f2fa6826232)

1 / 68      (Adware)
WSDirector.dll (WSDirector dll by WhiteSmoke)  (b75c5ec0556d11e71da9a63836f450ac)

1 / 68      (Adware)
WMonitorX.dll (WMonitorX by Deskperience)  (815e370ee722e2feadda6fde1aa9545a)

1 / 68      (Adware)
whook.dll (WWHook by Deskperience)  (2b8801a61cdfce225cfd14f31b17f3d9)

1 / 68      (Adware)

1 / 68      (Adware)
wcustom.dll (TCCustom by Deskperience)  (d95c6345ab5819159886dd3905272bb9)

1 / 68      (Adware)
WCaptureX.dll (WCaptureX by Deskperience)  (e3664c2531d6bbd8b2032b927466eb23)

1 / 68      (Adware)
wcapture.dll (DTCapt by Deskperience)  (8b7116baa09de78ab2a351469e576162)

1 / 68      (Adware)
TCCons.dll (TCCons Dynamic Link Library by Deskperience)  (02ebb436cd8431a9bd757c9f57d15730)

1 / 68      (Adware)
HookDllOE.dll (HookDll dll by WhiteSmoke)  (4aa26339aaa0fd209adbd4db8b3aad0f)

1 / 68      (Adware)
Director.dll (Director Module by WhiteSmoke)  (973fb5bc2b22e8df408ca18dcc5e07e0)

1 / 68      (Adware)
Setup.exe (InstallShield by Macrovision)  (41cc08639dab85f311b71e7b6fe94cbb)

1 / 68      (Adware)
issetup.dll (InstallShield by Macrovision)  (40c035b0d36613c6c00c4d019dbff153)

1 / 68      (Adware)

1 / 68      (Adware)
WMonitorX.dll (WMonitorX by Deskperience)  (b47bda000dd8a705f18ff05871a19616)

1 / 68      (Adware)
whook.dll (WWHook by Deskperience)  (3fcdc4e8f5f492be7ea15c4c33ccb38f)

1 / 68      (Adware)

1 / 68      (Adware)
wcustom.dll (TCCustom by Deskperience)  (78338d3ba90ee001e823ed862d7b0ad8)

1 / 68      (Adware)
WCaptureX.dll (WCaptureX by Deskperience)  (5a749ff055a0755801b74cc13c43d60f)

1 / 68      (Adware)
wcapture.dll (DTCapt by Deskperience)  (bb5e4a11866e47e11a76a9eff6c96f14)

1 / 68      (Adware)
TCCons.dll (TCCons Dynamic Link Library by Deskperience)  (ffa052029d1c3b1fe9795623a50c0f7f)

1 / 68      (Adware)

1 / 68      (inconclusive)
sqlite3.dll  (2be70722b0f8676be3e7ebbb48fa26ab)

1 / 68      (Adware)
mswordaddin.dll (wordaddin Module)  (0d9e913983379dc668d3ca9c67aa66d7)

1 / 68      (Adware)
hookdlloe.dll (HookDllOE_Atl Module)  (0a1980c763372bb2b621086dfecccf23)

1 / 68      (Adware)
Director.DLL (Director Module by WhiteSmoke)  (bca8be104040f63f9463b99058572fc1)

1 / 68      (Adware)
Setup.exe (InstallShield by Macrovision)  (e8500b017f4e2472241d8287612d8d7b)

1 / 68      (Adware)
issetup.dll (InstallShield by Macrovision)  (cdd20651386ad10505b3b89ca0c31cca)

1 / 68      (Adware)

1 / 68      (Adware)
patchw32.dll (RTPatch by Pocket Soft)  (c6066581d8183f362234c1b7381fe285)

 
Latest 30 of 47 files

The certificates below are also signed by WhiteSmoke Inc.

1464EFB2CC87AF9A3F855E683C12294D  (Aug 04, 2015 to Sep 03, 2017)

55439B87CB55E81147C072F06F4F77EF  (Jul 06, 2013 to Aug 05, 2015)

64048D72F9FFEF12A43FC4F4CEA580E3  (Jun 28, 2011 to Jul 07, 2013)

4261300AF5254B751250B0CDBDA6CE61  (Jun 09, 2008 to Jul 08, 2011)

The following publishers (by Authenticode signature organization name) are related.

Remove WhiteSmoke Inc Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to WhiteSmoke Inc by VeriSign, Inc. on May 17, 2007 with the serial number '6909b96020b7e23c83da2d03280aa61e'.