whitesmoke.dll

WhiteSmoke Toolbar

Montera Technologeis LTDD

This is part of the Montera web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The module whitesmoke.dll by Montera TechnologeisD has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘WhiteSmoke toolbar helper’.
Publisher:
WhiteSmoke.com  (signed by Montera Technologeis LTDD)

Product:
WhiteSmoke Toolbar

Version:
1.5.3.0

MD5:
9ccfa3d528574b263c52600a6085c767

SHA-1:
1b357285bab3f7d73787f782117094bdf4be87de

SHA-256:
90c80354f093ee84a0697bb35b4a54f721d10b6c5d1ad0b74eee712bd37c89fc

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/27/2024 3:10:55 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Montiera (M)
16.12.23.3

File size:
243.2 KB (249,040 bytes)

Product version:
1.5.3.0

Copyright:
(c) WhiteSmoke.com. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
Hebrew (Israel)

Common path:
C:\Program Files\whitesmoketoolbar\whitesmoke\1.5.3.6\bh\whitesmoke.dll

Digital Signature
Authority:
The USERTRUST Network

Valid from:
5/15/2011 8:00:00 PM

Valid to:
5/15/2012 7:59:59 PM

Subject:
CN=Montera Technologeis LTDD, O=Montera Technologeis LTDD, STREET="18, Amammi st", L=Even Yehuda, S=Hasharon, PostalCode=40500, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
0095D386F202E0248D39723608F340A6E5

File PE Metadata
Compilation timestamp:
11/8/2011 3:01:53 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x1767D

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, AF, 75, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, 60, 8F, 03, 10, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, D2, 77, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 29, F3, A5, FF, 24, 95, 10...
 
[+]

Code size:
159.5 KB (163,328 bytes)

Internet Explorer BHO
Display name:
WhiteSmoke toolbar helper

CLSID:
{F6389EFB-EA0B-40D4-AD5C-5F67AEBBB6AF}


Remove whitesmoke.dll - Powered by Reason Core Security