Welcome!I moved this to the
Am I Infected from the Win8 forum.
The WhiteSmoke web site indicates it makes English grammar correction software, translation software, and other specialized English writing tools. However, many users have reported they did not know how WhiteSmoke was downloaded or installed. From our investigation and dealings with this software we are also finding many cases of it with a
TDSS rootkit infection. So depending on the severity of system infection will determine how the disinfection process goes.
The web site says the software can be removed through
Add/Remove Programs or
Programs and Features if using
Vista/
Windows 7 so check there first, highlight anything with the name "
Whitesmoke", select Remove and restart the computer normally. This appears to work in most cases with the Whitesmoke Toolbar but not with the Translator.
Please download the
TDSS Rootkit Removing Tool (
TDSSKiller.exe) and
save it to your Desktop. <-Important!!!Be sure to download TDSSKiller.exe (2.6.11.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.- Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
Vista/Windows 7 users right-click and select Run As Administrator. - If TDSSKiller does not run, try renaming it.
- To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
- Click the Start Scan button.
- Do not use the computer during the scan
- If the scan completes with nothing found, click Close to exit.
- If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
- Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
- A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
- Copy and paste the contents of that file in your next reply.
If TDSSKiller does not run, try renaming it. To do this, right-click on
TDSSKiller.exe, select
Rename and give it a random name with the
.com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to these[/color]
instructions. [color=green]In some cases it may be necessary to redownload TDSSKiller and randomly rename it
before downloading and saving to the computer.
ADW CleanerPlease download
AdwCleaner by Xplode onto your desktop.
- Close all open programs and internet browsers.
- Double click on adwcleaner.exe to run the tool.
- Click on Delete.
- Confirm each time with Ok.
- You will be prompted to restart your computer. A text file will open after the restart.
- Please post the contents of that logfile with your next reply.
- You can find the logfile at C:\AdwCleaner[S1].txt as well.