clickpotatolitesaax.dll

ClickPotato ActiveX Control

Pinball Corporation.

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The module clickpotatolitesaax.dll by Pinball has been detected as adware by 41 anti-malware scanners.
Publisher:
Pinball Corporation.  (signed and verified)

Product:
ClickPotato ActiveX Control

Version:
10.0.624.0

MD5:
b4c0287e999a4ca5ac7d5fa8f7f79b5a

SHA-1:
1178510845ffd9f9fe71f541f99f5431191e96d4

Scanner detections:
41 / 68

Status:
Adware

Analysis date:
4/26/2024 4:29:04 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Adware.Heur.ru9@RWPrYlii
363

Agnitum Outpost
Adware.Agent
7.1.1

AhnLab V3 Security
Adware/Win32.Hotbar
2014.06.15

Avira AntiVirus
ADSPY/AdSpy.Gen2
7.11.155.78

Emsisoft A-Squared
AdWare.AdSpy!IK
5.0.0.31

avast!
Win32:Adware-gen [Adw]
2014.9-160206

AVG
Skodna.Generic_r
2017.0.2841

Baidu Antivirus
Adware.Win32.HotBar
4.0.3.1626

Bitdefender
Gen:Adware.Heur.ru9@RWPrYlii
1.0.20.185

Bkav FE
W32.HotbarFamTBI.Adware
1.3.0.4959

Clam AntiVirus
Suspect.W32.AdInstall
0.98/21411

Comodo Security
ApplicUnwnt.Win32.AdWare.HotBar.DE
18585

Dr.Web
Adware.Hotbar.780
9.0.1.037

Emsisoft Anti-Malware
Gen:Adware.Heur.ru9@RWPrYlii
8.16.02.06.12

ESET NOD32
Win32/Adware.HotBar (variant)
10.9961

Fortinet FortiGate
Adware/PlatriumSA
2/6/2016

F-Prot
W32/MalwareF.TOAW
v6.4.7.1.166

F-Secure
Gen:Adware.Heur.ru9@RWPrYlii
11.2016-06-02_7

G Data
Gen:Adware.Heur.ru9@RWPrYlii
16.2.24

IKARUS anti.virus
AdWare.Win32.ClickPotato
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.1712436

Kaspersky
not-a-virus:AdWare.Win32.HotBar
14.0.0.702

Malwarebytes
Adware.ClickPotato
v2016.02.06.12

McAfee
Adware-HotBar.g
5600.6497

Microsoft Security Essentials
Adware:Win32/ClickPotato
1.10701

MicroWorld eScan
Gen:Adware.Heur.ru9@RWPrYlii
17.0.0.111

NANO AntiVirus
Riskware.Win32.HotBar.cxppec
0.28.0.60253

nProtect
Trojan-Clicker/W32.HotBar.283952
14.06.17.01

Qihoo 360 Security
Win32/Trojan.Adware.8fb
1.0.0.1015

Quick Heal
Adware.ClickPotato (Not a Virus)
2.16.14.00

Reason Heuristics
PUP.Pinball.PinballCorporation (M)
16.2.6.12

Rising Antivirus
PE:Trojan.Win32.Generic.12825033!310530099
23.00.65.16204

Sophos
Hotbar
4.98

SUPERAntiSpyware
Adware.Zango-Heur
9340

Total Defense
Win32/Zango.Pinball[HOTBAR]
37.0.11005

Trend Micro House Call
ADW_CLICKPOTATO
7.2.37

Trend Micro
ADW_CLICKPOTATO
10.465.06

Vba32 AntiVirus
AdWare.HotBar
3.12.26.0

VIPRE Antivirus
Pinball Corporation.
30402

ViRobot
Adware.HotBar.283952
2011.4.7.4223

Zillya! Antivirus
Adware.Hotbar.Win32.160
2.0.0.1829

File size:
309.3 KB (316,720 bytes)

Product version:
10.0.624.0

Copyright:
Copyright © 2001-2009 Pinball Corporation. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\clickpotatolite\bin\10.0.624.0\clickpotatolitesaax.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/19/2009 2:00:00 AM

Valid to:
5/20/2011 1:59:59 AM

Subject:
CN=Pinball Corporation., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Pinball Corporation., L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4FEAB55730A755A456FE6C18A4791C1A

Registration
CLSIDs:
{1602F07D-8BF3-4c08-BDD6-DDDB1C48AEDC}, {AC6D819E-AA8F-4418-A3BB-D165C1B18BB5}

ProgIDs:
ClickPotatoLiteAX.Info.1, ClickPotatoLiteAX.UserProfiles.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
11/23/2010 5:40:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:DCG6+al8wD9DPh8wfQCaiUqLNg8nPUtnecmpQOOCo/m7lJfOPP8FEGtpGxiRSC5u:DCs8N9nPMeZpQpCVUyGxiO7ua

Entry address:
0x1A964

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, DE, 75, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, 55, 8B, EC, 83, EC, 18, 53, FF, 75, 10, 8D, 4D, E8, E8, 65, C6, FF, FF, 8B, 45, EC, 33, DB, 39, 58, 08, 75, 22, FF, 75, 0C, FF, 75, 08, E8, F4, 0D, 00, 00, 38, 5D, F4, 59, 59, 0F, 84, FA, 00, 00, 00, 8B, 4D, F0, 83, 61, 70, FD, E9, EE, 00, 00, 00, 8B, 45, 0C, 3B, C3, 75, 2B, E8, 15, 2D, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 7B, 2E, 00, 00, 83, C4, 14, 38, 5D...
 
[+]

Code size:
196 KB (200,704 bytes)

Remove clickpotatolitesaax.dll - Powered by Reason Core Security