{"id":2328,"date":"2012-02-24T10:12:41","date_gmt":"2012-02-24T10:12:41","guid":{"rendered":"http:\/\/malwaretips.com\/blogs\/?p=2328"},"modified":"2012-02-24T11:34:56","modified_gmt":"2012-02-24T11:34:56","slug":"remove-whitesmoke-translator","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/remove-whitesmoke-translator\/","title":{"rendered":"Remove WhiteSmoke Translator"},"content":{"rendered":"<h1>Remove WhiteSmoke Translator (Uninstall Guide)<\/h1>\n<p>WhiteSmoke Translator is &#8220;an all-new application that enables you to take any text from any text-based application, and automatically translate it into a destination language&#8221;<\/p><div id=\"mwtad1434948292\" class=\"gas_fallback-ad_309684--placement_360520\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p><img decoding=\"async\" src=\"\/\/i.min.us\/icbB50.jpg\" alt=\"[Image: icbB50.jpg]\" border=\"0\" title=\"\"><\/p>\n<p>However, when WhiteSmoke Translator is installed on the computer,\u00a0trojan\u00a0(MD5: c5a4a504e73fda80390b630643d580b9) is also secretly installed. Besides, WhiteSmoke Translator also installs\u00a0other adware\/malware\u00a0on the system without confirmation of the user.<br \/>\nBecause WhiteSmoke Translator is a malicious software which can severely damage your computer, compromise your credit card security and lead to identity theft,you are strongly advised to follow our WhiteSmoke Translator removal instructions below.<\/p>\n<div id=\"mwtad1331171664\" class=\"gas_fallback-ad_309746-ad_309691-placement_360521\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Am I infected with WhiteSmoke Translator ?<\/h2>\n<p>This is how the main screen of\u00a0<strong>WhiteSmoke Translator\u00a0<\/strong>looks:<br \/>\n<img decoding=\"async\" src=\"\/\/i.min.us\/icbDD8.jpg\" alt=\"[Image: icbDD8.jpg]\" border=\"0\" title=\"\"><\/p><div id=\"mwtad3120204909\" class=\"gas_fallback-ad_381396-ad_309691-placement_360566\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h1>WhiteSmoke Translator Removal Instructions<\/h1>\n<h3>STEP 1:\u00a0Perform a full system scan with\u00a0<a href=\"https:\/\/store.malwarebytes.org\/342\/cookie?affiliate=17877&amp;redirectto=http%3a%2f%2fwww.malwarebytes.org%2fproducts%2fmalwarebytes_free\" rel=\"nofollow noopener\" target=\"_blank\">Malwarebytes Anti-Malware Free<\/a><\/h3>\n<p>&nbsp;<\/p>\n<ol type=\"1\">\n<li>Please\u00a0<strong>download the latest official version of\u00a0<a href=\"https:\/\/store.malwarebytes.org\/342\/cookie?affiliate=17877&amp;redirectto=http%3a%2f%2fwww.malwarebytes.org%2fproducts%2fmalwarebytes_free\" rel=\"nofollow noopener\" target=\"_blank\">Malwarebytes Anti-Malware Free<\/a><\/strong>.<br \/>\n<a href=\"https:\/\/store.malwarebytes.org\/342\/cookie?affiliate=17877&amp;redirectto=http%3a%2f%2fwww.malwarebytes.org%2fproducts%2fmalwarebytes_free\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/downloadnow.gif\" alt=\"\" title=\"\"><\/a><\/li>\n<li>Install Malwarebytes&#8217; Anti-Malware by\u00a0<strong>double clicking on\u00a0mbam-setup<\/strong>.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam1.png\" alt=\"[Image: mbam1.png]\" border=\"0\" title=\"\"><\/li>\n<li>When the installation begins,\u00a0<strong>keep following the prompts<\/strong>\u00a0in order to continue with the installation process.\u00a0<strong>Do not make any changes to default settings<\/strong>\u00a0and when the program has finished installing, make sure you leave both the\u00a0<strong>Update Malwarebytes&#8217; Anti-Malware<\/strong>\u00a0and\u00a0<strong>Launch Malwarebytes&#8217; Anti-Malware\u00a0<\/strong>checked. Then click on the\u00a0<strong>Finish<\/strong>\u00a0button. If Malwarebytes&#8217; prompts you to reboot, please do not do so.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam2.png\" alt=\"[Image: mbam2.png]\" border=\"0\" title=\"\"><\/li>\n<li>Malwarebytes Anti-Malware will now start and you&#8217;ll be prompted to start a trial period , please select &#8216;<strong>Decline<\/strong>&#8216; as we just want to use the on-demand scanner.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam3.PNG\" alt=\"[Image: mbam3.PNG]\" border=\"0\" title=\"\"><\/li>\n<li>On the\u00a0<strong>Scanner<\/strong>\u00a0tab,please select\u00a0<strong>Perform full scan<\/strong>\u00a0and then click on the\u00a0<strong>Scan<\/strong>\u00a0button to start scanning your computer for any possible infections.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam4.png\" alt=\"[Image: mbam4.png]\" border=\"0\" title=\"\"><\/li>\n<li>Malwarebytes&#8217; Anti-Malware will now start scanning your computer for WhiteSmoke Translator malicious files as shown below.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam5.png\" alt=\"[Image: mbam5.png]\" border=\"0\" title=\"\"><\/li>\n<li>When the scan is finished a message box will appear, click\u00a0<strong>OK<\/strong>\u00a0to continue.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam9.png\" alt=\"[Image: mbam9.png]\" border=\"0\" title=\"\"><\/li>\n<li>You will now be presented with a screen showing you the malware infections that Malwarebytes&#8217; Anti-Malware has detected.Please note that the infections found may be different than what is shown in the image.<br \/>\nMake sure that everything is\u00a0<strong>Checked\u00a0(ticked)<\/strong>\u00a0and click on\u00a0<strong>Remove Selected<\/strong>\u00a0button.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam6.png\" alt=\"[Image: mbam6.png]\" border=\"0\" title=\"\"><\/li>\n<li>Malwarebytes&#8217; Anti-Malware will now start removing the malicious files.<br \/>\nIf during the removal process Malwarebytes will display a message stating that it needs to reboot, please\u00a0<strong>allow<\/strong>\u00a0this request.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam10.png\" alt=\"[Image: mbam10.png]\" border=\"0\" title=\"\"><\/li>\n<\/ol>\n<hr \/>\n<h3>STEP 6:\u00a0Perform a system scan with\u00a0<a href=\"https:\/\/www.cleverbridge.com\/747\/cookie?affiliate=17877&amp;redirectto=http:\/\/www.surfright.com\/downloads\" rel=\"nofollow noopener\" target=\"_blank\">HitmanPro<\/a><\/h3>\n<p>&nbsp;<\/p>\n<ol type=\"1\">\n<li>This step can be performed in Normal Mode ,so please\u00a0<strong>download the latest official version of HitmanPro<\/strong>.<br \/>\n<a href=\"https:\/\/www.cleverbridge.com\/747\/cookie?affiliate=17877&amp;redirectto=http:\/\/www.surfright.com\/downloads\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/downloadnow.gif\" alt=\"\" title=\"\"><\/a><\/li>\n<li>Start HitmanPro\u00a0 by\u00a0<strong>double clicking on the previously downloaded file.<\/strong><br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/hpro1.png\" alt=\"[Image: hitmanproscan1.png]\" border=\"0\" title=\"\"><br \/>\nNOTE\u00a0: If you have problems starting HitmanPro, use the \u201c<em>Force Breach<\/em>\u201d mode. Hold down the left\u00a0CTRL-key\u00a0when you start HitmanPro and all non-essential processes are terminated, including the malware process. (<a href=\"http:\/\/www.youtube.com\/watch?feature=player_embedded&amp;v=m6eRWTv2STk\" rel=\"nofollow noopener\" target=\"_blank\">How to start HitmanPro in Force Breach mode &#8211; video<\/a>)<\/li>\n<li>Click\u00a0on\u00a0<strong>Next<\/strong>\u00a0to start a scan for malicious software.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/hpro2.png\" alt=\"[Image: hitmanproscan2.png]\" border=\"0\" title=\"\"><\/li>\n<li>The setup screen is displayed, from which you can decide whether \u00a0you wish to install HitmanPro on your machine or just perform a one-time scan, select a option \u00a0then click\u00a0on\u00a0<strong>Next<\/strong>\u00a0to start a system scan<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/hpro3.png\" alt=\"[Image: hitmanproscan3.png]\" border=\"0\" title=\"\"><\/li>\n<li>HitmanPro will start scanning your system for malicious files. Depending on the size of your hard drive, and the performance of your computer, this step will take several minutes.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/hpro4.png\" alt=\"[Image: hitmanproscan4.png]\" border=\"0\" title=\"\"><\/li>\n<li>Once the scan is complete, a screen displaying all the malicious files that the program found will be shown as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br \/>\nAfter reviewing each malicious object click\u00a0<strong>Next<\/strong>\u00a0.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/02\/rsz_hpro5.png\" alt=\"[Image: hitmanproscan5.png]\" border=\"0\" title=\"\"><\/li>\n<li>Click\u00a0<strong>Activate free license<\/strong>\u00a0to start the free 30 days trial and remove the malicious files.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/hpro6.png\" alt=\"[Image: hitmanproscan6.png]\" border=\"0\" title=\"\"><\/li>\n<li>HitmanPro will now start removing the infected objects, and in some instances, may suggest a reboot in order to completely remove the malware from your system. In this scenario, always confirm the reboot action to be on the safe side.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/hpro7.png\" alt=\"[Image: hitmanproscan7.png]\" border=\"0\" title=\"\"><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h3>STEP 3\u00a0: Reset your browser to its default settings (homepage,add-ons and search engine)<\/h3>\n<h4>For Internet Explorer users<\/h4>\n<ol type=\"1\">\n<li>Open Internet Explorer &#8216;<strong>Internet Options<\/strong><br \/>\n<strong>For Internet Explorer 9<\/strong> : Click on the <strong>gear icon\u00a0<\/strong><img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/icongear.jpg\" alt=\"[Image: icongear.jpg]\" border=\"0\" title=\"\">\u00a0at the top (far right) and click again on\u00a0<strong>Internet Options<\/strong>.<\/li>\n<li><strong>For Internet Explorer 8<\/strong> : Click on\u00a0<strong>Tools<\/strong>, select <strong>Internet Options<\/strong>.<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/ie9.png\" alt=\"[Image: restoreie.png]\" border=\"0\" title=\"\"><\/li>\n<li>Now in the Internet Options dialog box, click on the\u00a0<strong>Advanced<\/strong>\u00a0tab, click\u00a0<strong>Reset<\/strong><br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/ine1.png\" alt=\"[Image: restoreie2.png]\" border=\"0\" title=\"\"><\/li>\n<li>In the Reset Internet Explorer settings section. Click\u00a0<strong>Reset<\/strong>\u00a0again in the information dialog box.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/ine2.png\" alt=\"[Image: restoreie1.png]\" border=\"0\" title=\"\"><\/li>\n<li>When Internet Explorer finishes resetting, click<strong>\u00a0Close<\/strong>\u00a0in the confirmation dialogue box and then click\u00a0<strong>OK<\/strong>.<\/li>\n<li><strong>Close and open Internet Explorer<\/strong> again.<\/li>\n<\/ol>\n<h4>For Mozilla Firefox users<\/h4>\n<ol type=\"1\">\n<li><strong>Start Firefox<\/strong> and at the top of the\u00a0Firefox\u00a0window, click the\u00a0<strong>Firefox\u00a0button<\/strong>, go over to the\u00a0<strong>Help<\/strong>\u00a0menu.Select\u00a0<strong>Restart with Add-ons Disabled<\/strong>,Firefox will start up with the\u00a0Firefox Safe Mode dialog.<br \/>\nNote:\u00a0You can also start Firefox in Safe Mode by holding down the\u00a0shift key\u00a0while starting Firefox.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/firefox1.png\" alt=\"[Image: restorefirefox.png]\" border=\"0\" title=\"\"><\/li>\n<li>Click to put a check mark by <strong>Reset all user preferences to Firefox defaults<\/strong>.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/firefox2.png\" alt=\"[Image: restorefirefox.png]\" border=\"0\" title=\"\"><\/li>\n<li>To apply your changes, click\u00a0<strong>Make Changes and Restart.<\/strong><\/li>\n<li>Firefox will restart with your preference settings changed back to the defaults.<\/li>\n<\/ol>\n<div><\/div>\n<h4><strong>For Google Chrome users<\/strong><\/h4>\n<ol type=\"1\">\n<li><strong>Close Google Chrome\u00a0<\/strong>and then\u00a0go to <strong>Start \u2192 Run<\/strong>\u00a0to open Run box,if you do not see Run option, press\u00a0<strong>Win + R<\/strong>\u00a0keys to get Run box on the screen.<\/li>\n<li>In the\u00a0<strong>Run<\/strong> <strong>box<\/strong>\u00a0copy the below path according to what system are you using;<br \/>\n<strong>Windows XP users:<\/strong><\/p>\n<div>\n<div>Code:<\/div>\n<div dir=\"ltr\"><code>%USERPROFILE%\\Local Settings\\Application Data\\GoogleChrome\\User Data<\/code><\/div>\n<\/div>\n<p><strong>Windows Vista and 7 users:<\/strong><\/p>\n<div>\n<div>Code:<\/div>\n<div dir=\"ltr\"><code>%LOCALAPPDATA%\\Google\\Chrome\\User Data<\/code><\/div>\n<\/div>\n<p><img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/Chrome1.png\" alt=\"[Image: restorechrome.png]\" border=\"0\" title=\"\"><\/li>\n<li>This will open a new folder that will contain more files and folders.<strong> Search for<\/strong>\u00a0<strong>Default<\/strong>\u00a0folder in the list and\u00a0<strong>Rename it<\/strong>\u00a0to something random like\u00a0<em>Old Default<\/em>.<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/Chrome2.png\" alt=\"[Image: restorechrome2.png]\" border=\"0\" title=\"\"><\/li>\n<li><strong>Start Google Chrome<\/strong>\u00a0and that&#8217;s it , a new Default folder will be created with the default settings.<\/li>\n<\/ol>\n<h3>STEP 4\u00a0: Remove the residual damage from WhiteSmoke Translator<\/h3>\n<p>WhiteSmoke Translator may also modify your HOSTS file default settings, which can cause browser redirects or errors while trying to access antivirus and security websites.<br \/>\nTo protect itself, WhiteSmoke Translator has changed the permissions of the HOSTS file so you can&#8217;t edit or delete it.<\/p>\n<ol type=\"1\">\n<li>Please\u00a0<strong>download the following batch file<\/strong>\u00a0to revert your HOSTS file permissions:<br \/>\n<img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/attachtypes\/html.gif\" alt=\".bat\" border=\"0\" title=\"\">\u00a0\u00a0<a href=\"http:\/\/malwaretips.com\/images\/removalguide\/hostfix.bat\" target=\"_blank\">hostfix.bat<\/a>\u00a0(Size: 134 bytes)<\/li>\n<li><strong>Click on\u00a0hostfix.bat<\/strong>\u00a0and allow this file to run.Once it starts you will see a small black window that opens and then quickly goes away, then you should be able access your HOSTS file.<\/li>\n<li>Please\u00a0<strong>download and run the below file from\u00a0Microsoft\u00a0<\/strong>to revert your host file to its original settings.Please note that if you have added custom entries to your HOSTS file then you will need to add them again after restoring the default HOSTS file.<br \/>\n<a href=\"http:\/\/go.microsoft.com\/?linkid=9668866\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"\/\/malwaretips.com\/images\/removalguide\/downloadnow.gif\" alt=\"\" title=\"\"><\/a><\/li>\n<\/ol>\n<div id=\"mwtad965690292\" class=\"gas_fallback-ad_309747-ad_309691-placement_360587\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>If you are still experiencing problems on your machine, please start a new thread in our\u00a0<a href=\"http:\/\/malwaretips.com\/Forum-Malware-Removal-Assistance-and-Help\" rel=\"nofollow\" target=\"_blank\">Malware Removal Assistance<\/a>\u00a0forum.<\/h2>\n","protected":false},"excerpt":{"rendered":"<p>WhiteSmoke Translator is a malicious software which can severely damage your computer, compromise your credit card security and lead to identity theft,you are strongly advised to follow our WhiteSmoke Translator removal instructions below.<\/p>\n","protected":false},"author":1,"featured_media":2329,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ai_generated_summary":"","footnotes":""},"categories":[49],"tags":[],"class_list":["post-2328","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/2328","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=2328"}],"version-history":[{"count":0,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/2328\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/2329"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=2328"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=2328"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=2328"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}