clickpotatolitesaax.dll

ClickPotato ActiveX Control

Pinball Corporation.

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The module clickpotatolitesaax.dll by Pinball has been detected as adware by 41 anti-malware scanners.
Publisher:
Pinball Corporation.  (signed and verified)

Product:
ClickPotato ActiveX Control

Version:
10.0.528.0

MD5:
97f088223bdfeebc232185ce88fbb752

SHA-1:
4b0ac1d909cf6302d3c43708fd6df79faf8e5c85

SHA-256:
a86226b4350b5152dcc9f62649422b3ab6b16f58a0794dd2312b7467502b6f14

Scanner detections:
41 / 68

Status:
Adware

Analysis date:
4/27/2024 4:09:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Adware.Heur.ru9@RWPrYlii
355

Agnitum Outpost
Adware.Agent
7.1.1

AhnLab V3 Security
Adware/Win32.Hotbar
2014.06.15

Avira AntiVirus
ADSPY/AdSpy.Gen2
7.11.155.78

Emsisoft A-Squared
AdWare.AdSpy!IK
5.0.0.31

avast!
Win32:Adware-gen [Adw]
2014.9-160215

AVG
Skodna.Generic_r
2017.0.2833

Baidu Antivirus
Adware.Win32.HotBar
4.0.3.16215

Bitdefender
Gen:Adware.Heur.ru9@RWPrYlii
1.0.20.230

Bkav FE
W32.HotbarFamTBI.Adware
1.3.0.4959

Clam AntiVirus
Suspect.W32.AdInstall
0.98/21411

Comodo Security
ApplicUnwnt.Win32.AdWare.HotBar.DE
18585

Dr.Web
Adware.Hotbar.780
9.0.1.046

Emsisoft Anti-Malware
Gen:Adware.Heur.ru9@RWPrYlii
8.16.02.15.10

ESET NOD32
Win32/Adware.HotBar (variant)
10.9961

Fortinet FortiGate
Adware/PlatriumSA
2/15/2016

F-Prot
W32/MalwareF.TOAW
v6.4.7.1.166

F-Secure
Gen:Adware.Heur.ru9@RWPrYlii
11.2016-15-02_2

G Data
Gen:Adware.Heur.ru9@RWPrYlii
16.2.24

IKARUS anti.virus
AdWare.Win32.ClickPotato
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.1712436

Kaspersky
not-a-virus:AdWare.Win32.HotBar
14.0.0.658

Malwarebytes
Adware.ClickPotato
v2016.02.15.10

McAfee
Adware-HotBar.g
5600.6489

Microsoft Security Essentials
Adware:Win32/ClickPotato
1.10701

MicroWorld eScan
Gen:Adware.Heur.ru9@RWPrYlii
17.0.0.138

NANO AntiVirus
Riskware.Win32.HotBar.cxppec
0.28.0.60253

nProtect
Trojan-Clicker/W32.HotBar.283952
14.06.17.01

Qihoo 360 Security
Win32/Trojan.Adware.8fb
1.0.0.1015

Quick Heal
Adware.ClickPotato (Not a Virus)
2.16.14.00

Reason Heuristics
PUP.Pinball.PinballCorporation (M)
16.2.15.10

Rising Antivirus
PE:Trojan.Win32.Generic.12825033!310530099
23.00.65.16213

Sophos
Hotbar
4.98

SUPERAntiSpyware
Adware.Zango-Heur
9322

Total Defense
Win32/Zango.Pinball[HOTBAR]
37.0.11005

Trend Micro House Call
ADW_CLICKPOTATO
7.2.46

Trend Micro
ADW_CLICKPOTATO
10.465.15

Vba32 AntiVirus
AdWare.HotBar
3.12.26.0

VIPRE Antivirus
Pinball Corporation.
30402

ViRobot
Adware.HotBar.283952
2011.4.7.4223

Zillya! Antivirus
Adware.Hotbar.Win32.160
2.0.0.1829

File size:
309.3 KB (316,720 bytes)

Product version:
10.0.528.0

Copyright:
Copyright © 2001-2009 Pinball Corporation. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\clickpotatolite\bin\10.0.528.0\clickpotatolitesaax.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/18/2009 8:00:00 PM

Valid to:
5/19/2011 7:59:59 PM

Subject:
CN=Pinball Corporation., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Pinball Corporation., L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4FEAB55730A755A456FE6C18A4791C1A

File PE Metadata
Compilation timestamp:
8/12/2010 3:35:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:ohwUll8wD9DPh8wfQCFFWQLNg8WqcrDXmmpQWxCoa6vlTizTjtyJ7GUCxiRSC5ll:olBN9Wq2XnpQCCDvDxipBuq

Entry address:
0x1A964

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, DD, 75, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, 55, 8B, EC, 83, EC, 18, 53, FF, 75, 10, 8D, 4D, E8, E8, 65, C6, FF, FF, 8B, 45, EC, 33, DB, 39, 58, 08, 75, 22, FF, 75, 0C, FF, 75, 08, E8, F4, 0D, 00, 00, 38, 5D, F4, 59, 59, 0F, 84, FA, 00, 00, 00, 8B, 4D, F0, 83, 61, 70, FD, E9, EE, 00, 00, 00, 8B, 45, 0C, 3B, C3, 75, 2B, E8, 15, 2D, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 7B, 2E, 00, 00, 83, C4, 14, 38, 5D...
 
[+]

Entropy:
6.4503

Code size:
196 KB (200,704 bytes)

Remove clickpotatolitesaax.dll - Powered by Reason Core Security