clickpotatolitesa.exe

ClickPotato Search assistant

Pinball Corporation.

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application clickpotatolitesa.exe by Pinball has been detected as adware by 40 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ClickPotatoLiteSA’.
Publisher:
Pinball Corporation.  (signed and verified)

Product:
ClickPotato Search assistant

Version:
10.0.636.0

MD5:
e7f93f7f99f8c9154b1fb6fee108d234

SHA-1:
5b6e8c88893da022f1922879ca0105811e30eaaf

SHA-256:
cf34bc212496f4daf1c834a138bd561a96179304a145e2c11f99b1bfc7b6f13f

Scanner detections:
40 / 68

Status:
Adware

Analysis date:
4/19/2024 9:18:46 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Adware.Heur.Tm1@RKSr@lp
359

Agnitum Outpost
Adware.Hotbar
7.1.1

AhnLab V3 Security
Win-Adware/ClickPotato.739632
2014.07.16

Avira AntiVirus
Adware/Frozen.A
7.11.160.254

avast!
Win32:Adware-PR [Adw]
2014.9-160210

AVG
Skodna.Generic_r.Q
2017.0.2837

Baidu Antivirus
Adware.Win32.HotBar
4.0.3.16210

Bitdefender
Gen:Adware.Heur.Tm1@RKSr@lp
1.0.20.205

Bkav FE
W32.Clod583.Trojan
1.3.0.4959

Clam AntiVirus
Suspect.W32.AdInstall
0.98/21411

Comodo Security
ApplicUnwnt.Win32.AdWare.HotBar.DE
18866

Dr.Web
Adware.Zango.15
9.0.1.041

Emsisoft Anti-Malware
Gen:Adware.Heur.Tm1@RKSr@lp
8.16.02.10.06

ESET NOD32
Win32/Adware.180Solutions (variant)
10.10103

Fortinet FortiGate
Adware/PlatriumSA
2/10/2016

F-Prot
W32/180Solutions.D.gen
v6.4.7.1.166

F-Secure
Gen:Adware.Heur.Tm1@RKSr@lp
11.2016-10-02_4

G Data
Gen:Adware.Heur.Tm1@RKSr@lp
16.2.24

IKARUS anti.virus
not-a-virus:AdWare.Win32.HotBar
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.180.12733

Kaspersky
not-a-virus:AdWare.Win32.HotBar
14.0.0.681

Malwarebytes
Adware.ClickPotato
v2016.02.10.06

McAfee
Adware-ClickPotato
5600.6493

Microsoft Security Essentials
Adware:Win32/Hotbar
1.10802

MicroWorld eScan
Gen:Adware.Heur.Tm1@RKSr@lp
17.0.0.123

NANO AntiVirus
Trojan.Win32.Zango.bsqzik
0.28.2.60881

nProtect
Trojan-Clicker/W32.HotBar.768816
14.11.24.01

Qihoo 360 Security
Win32/Virus.Adware.577
1.0.0.1015

Quick Heal
AdWare.Hotbar.r3 (Not a Virus)
2.16.14.00

Reason Heuristics
PUP.Pinball.PinballCorporation (M)
16.2.10.18

Rising Antivirus
PE:Trojan.Win32.Generic.12541FE8!307503080
23.00.65.16208

Sophos
ClickPotato Installer
4.98

SUPERAntiSpyware
Adware.Zango-Heur
9331

Total Defense
Win32/Zango.Pinball[HOTBAR]
37.0.11061

Trend Micro House Call
TROJ_SPNR.1EJT11
7.2.41

Trend Micro
TROJ_SPNR.1EJT11
10.465.10

Vba32 AntiVirus
Signed-Adware.Hotbar
3.12.26.3

VIPRE Antivirus
Pinball Corporation.
31316

ViRobot
Adware.HotBar.783664
2011.4.7.4223

Zillya! Antivirus
Adware.HotBar.Win32.142
2.0.0.1859

File size:
724.3 KB (741,680 bytes)

Product version:
10.0.636.0

Copyright:
Copyright © 2001-2009 Pinball Corporation. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\clickpotatolite\bin\10.0.636.0\clickpotatolitesa.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/19/2009 1:00:00 AM

Valid to:
5/20/2011 12:59:59 AM

Subject:
CN=Pinball Corporation., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Pinball Corporation., L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4FEAB55730A755A456FE6C18A4791C1A

File PE Metadata
Compilation timestamp:
1/7/2011 9:00:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:qNcccstSr9frQ6YELMBSpM/caFPrvO0hvXMcziuF4:AcccBr9frQ2MBSicaFPrvO0vXNzin

Entry address:
0x6494D

Entry point:
E8, 94, 7E, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, 55, 8B, EC, 83, EC, 14, 53, 56, FF, 75, 10, 33, DB, 8D, 4D, EC, 89, 5D, FC, E8, 6E, C2, FF, FF, 8B, 75, F0, 39, 5E, 08, 75, 1F, FF, 75, 0C, FF, 75, 08, E8, C1, 7E, 00, 00, 38, 5D, F8, 59, 59, 0F, 84, 86, 00, 00, 00, 8B, 4D, F4...
 
[+]

Entropy:
6.7309

Code size:
573.5 KB (587,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ClickPotatoLiteSA

Command:
"C:\Program Files\clickpotatolite\bin\10.0.636.0\clickpotatolitesa.exe"


Remove clickpotatolitesa.exe - Powered by Reason Core Security