clickpotatolitesa.exe

ClickPotato Search Assistant

Pinball Corporation.

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application clickpotatolitesa.exe by Pinball has been detected as adware by 40 anti-malware scanners.
Publisher:
Pinball Corporation.  (signed and verified)

Product:
ClickPotato Search Assistant

Version:
10.0.529.0

MD5:
d6b6d955e36ab63092ebd4478a22d89f

SHA-1:
7a66db52361bc6153eb0e2d8d84e2cc870a7bb1c

SHA-256:
65b5abb39290e8ddc8b4d37bd47d6dd97f10fbc7751ee0f0a4c853f4d9b74a0c

Scanner detections:
40 / 68

Status:
Adware

Analysis date:
4/26/2024 4:53:05 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Adware.Heur.Tm1@RKSr@lp
360

Agnitum Outpost
Adware.Hotbar
7.1.1

AhnLab V3 Security
Win-Adware/ClickPotato.739632
2014.07.16

Avira AntiVirus
Adware/Frozen.A
7.11.160.254

avast!
Win32:Adware-PR [Adw]
2014.9-160210

AVG
Skodna.Generic_r.Q
2017.0.2838

Baidu Antivirus
Adware.Win32.HotBar
4.0.3.16210

Bitdefender
Gen:Adware.Heur.Tm1@RKSr@lp
1.0.20.205

Bkav FE
W32.Clod583.Trojan
1.3.0.4959

Clam AntiVirus
Suspect.W32.AdInstall
0.98/21411

Comodo Security
ApplicUnwnt.Win32.AdWare.HotBar.DE
18866

Dr.Web
Adware.Zango.15
9.0.1.041

Emsisoft Anti-Malware
Gen:Adware.Heur.Tm1@RKSr@lp
8.16.02.10.09

ESET NOD32
Win32/Adware.180Solutions (variant)
10.10103

Fortinet FortiGate
Adware/PlatriumSA
2/10/2016

F-Prot
W32/180Solutions.D.gen
v6.4.7.1.166

F-Secure
Gen:Adware.Heur.Tm1@RKSr@lp
11.2016-10-02_4

G Data
Gen:Adware.Heur.Tm1@RKSr@lp
16.2.24

IKARUS anti.virus
not-a-virus:AdWare.Win32.HotBar
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.180.12733

Kaspersky
not-a-virus:AdWare.Win32.HotBar
14.0.0.683

Malwarebytes
Adware.ClickPotato
v2016.02.10.09

McAfee
Adware-ClickPotato
5600.6494

Microsoft Security Essentials
Adware:Win32/Hotbar
1.10802

MicroWorld eScan
Gen:Adware.Heur.Tm1@RKSr@lp
17.0.0.123

NANO AntiVirus
Trojan.Win32.Zango.bsqzik
0.28.2.60881

nProtect
Trojan-Clicker/W32.HotBar.768816
14.11.24.01

Qihoo 360 Security
Win32/Virus.Adware.577
1.0.0.1015

Quick Heal
AdWare.Hotbar.r3 (Not a Virus)
2.16.14.00

Reason Heuristics
PUP.Pinball.PinballCorporation (M)
16.2.10.9

Rising Antivirus
PE:Trojan.Win32.Generic.12541FE8!307503080
23.00.65.16208

Sophos
ClickPotato Installer
4.98

SUPERAntiSpyware
Adware.Zango-Heur
9332

Total Defense
Win32/Zango.Pinball[HOTBAR]
37.0.11061

Trend Micro House Call
TROJ_SPNR.1EJT11
7.2.41

Trend Micro
TROJ_SPNR.1EJT11
10.465.10

Vba32 AntiVirus
Signed-Adware.Hotbar
3.12.26.3

VIPRE Antivirus
Pinball Corporation.
31316

ViRobot
Adware.HotBar.783664
2011.4.7.4223

Zillya! Antivirus
Adware.HotBar.Win32.142
2.0.0.1859

File size:
722.8 KB (740,144 bytes)

Product version:
10.0.529.0

Copyright:
Copyright © 2001-2009 Pinball Corporation. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\clickpotatolite\bin\10.0.529.0\clickpotatolitesa.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/18/2009 6:00:00 PM

Valid to:
5/19/2011 5:59:59 PM

Subject:
CN=Pinball Corporation., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Pinball Corporation., L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4FEAB55730A755A456FE6C18A4791C1A

File PE Metadata
Compilation timestamp:
9/8/2010 10:26:07 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:imcjZYA7KBbgEkB3vUyMoaGKVBRU6eVjiQFv:ihC6KBbgdvU8aGK3RU5Vji2

Entry address:
0x6440D

Entry point:
E8, 95, 7E, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, 55, 8B, EC, 83, EC, 14, 53, 56, FF, 75, 10, 33, DB, 8D, 4D, EC, 89, 5D, FC, E8, 6E, C2, FF, FF, 8B, 75, F0, 39, 5E, 08, 75, 1F, FF, 75, 0C, FF, 75, 08, E8, C1, 7E, 00, 00, 38, 5D, F8, 59, 59, 0F, 84, 86, 00, 00, 00, 8B, 4D, F4...
 
[+]

Entropy:
6.7263

Code size:
572 KB (585,728 bytes)

Remove clickpotatolitesa.exe - Powered by Reason Core Security