Home Malware Programs Adware ClickPotato

ClickPotato

Posted: August 4, 2010

Threat Metric

Threat Level: 2/10
Infected PCs: 2,745
First Seen: December 1, 2010
Last Seen: December 3, 2021
OS(es) Affected: Windows

ClickPotato (or Click Potato) is an annoying adware program which targets cinema lovers. Click Potato spreads via corrupt ads offering the latest movies online. ClickPotato uses fraudulent websites as a platform to urge the sale of pirated movies via a video codec download. The video codec is actually the ClickPotato malware which produces unwanted ads. ClickPotato may also install a screensaver and change your home page. Use updated antispyware software to remove ClickPotato from your system before it starts wreaking havoc.

Aliases

Adware/Win32.Zango [AhnLab-V3]ApplicUnwnt.Win32.AdWare.HotBar.DE [Comodo]not-a-virus:WebToolbar.Win32.Zango.amp [Kaspersky]Win32:HotBar-BL [Adw] [Avast]Adware/Agent.741376.2 [AntiVir]Gen:Adware.Heur.Tm1@RmksX4c [BitDefender]Artemis!4BDCE738A4EF [McAfee]Adware/ClickPotato.A.24 [AntiVir]not-a-virus:HEUR:AdWare.Win32.HotBar.heur [Kaspersky]Artemis!0B20E8FBB7EB [McAfee]Gen:Adware.Heur.Xq0@RGbV9Qh [BitDefender]W32/SPNR.0BBD12!tr [Fortinet]AdWare.Win32.HotBar [Ikarus]Adware/Adware.757760.2 [AntiVir]not-a-virus:AdWare.Win32.Shopper.ra [Kaspersky]
More aliases (297)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%LOCALAPPDATA%\RavenBleuSA\bin\1.0.13.0\RavenBleuSA.exe File name: RavenBleuSA.exe
Size: 782.84 KB (782848 bytes)
MD5: 995bf4913243264269bdbdf64b51f94b
Detection count: 321
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\RavenBleuSA\bin\1.0.13.0
Group: Malware file
Last Updated: June 20, 2020
%LOCALAPPDATA%\SeekmoSA\bin\16.0.21.0\SeekmoSA.exe File name: SeekmoSA.exe
Size: 808.96 KB (808960 bytes)
MD5: 4fce225569eec77c52e3b00906400884
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\SeekmoSA\bin\16.0.21.0
Group: Malware file
Last Updated: January 28, 2013
C:\GAJA PODACI\disk drugi\AdwCleaner\Quarantine\C\Documents and Settings\Milan\Local Settings\Application Data\ClickPotatoLiteSA\bin\12.0.17.0\ClickPotatoLiteSA.exe.vir File name: ClickPotatoLiteSA.exe.vir
Size: 766.97 KB (766976 bytes)
MD5: 62d1fba4a2a72dab5a5998bd5590b6d2
Detection count: 49
Mime Type: unknown/vir
Path: C:\GAJA PODACI\disk drugi\AdwCleaner\Quarantine\C\Documents and Settings\Milan\Local Settings\Application Data\ClickPotatoLiteSA\bin\12.0.17.0\ClickPotatoLiteSA.exe.vir
Group: Malware file
Last Updated: October 28, 2021
%LOCALAPPDATA%\FREEzeFlipSA\bin\3.0.8.0\FREEzeFlipSA.exe File name: FREEzeFlipSA.exe
Size: 690.17 KB (690176 bytes)
MD5: 173134e27e713cf47997eabe92818e76
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\FREEzeFlipSA\bin\3.0.8.0
Group: Malware file
Last Updated: August 27, 2012
%PROGRAMFILES(x86)%\FREEzeFrog\bin\2.0.21.0\FREEzeFrogSA.exe File name: FREEzeFrogSA.exe
Size: 819.2 KB (819200 bytes)
MD5: f196f57b66790bc0cbee1ca7f54465f4
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\FREEzeFrog\bin\2.0.21.0
Group: Malware file
Last Updated: December 3, 2012
%PROGRAMFILES%\ShoppingReport2\Bin\2.7.27\ShoppingReport.dll File name: ShoppingReport.dll
Size: 1.14 MB (1142576 bytes)
MD5: 8b31e31a69a7ae89817721b8042c8966
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\ShoppingReport2\Bin\2.7.27
Group: Malware file
Last Updated: March 9, 2020
%USERPROFILE%\Desktop\VLCSetup.exe File name: VLCSetup.exe
Size: 206.44 KB (206440 bytes)
MD5: 79c790cea1cd51ab1bab2757a80c1bb9
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop
Group: Malware file
Last Updated: April 8, 2013
%PROGRAMFILES%\BrightBreeze\bin\2.0.5.0\BrightBreezeSA.exe File name: BrightBreezeSA.exe
Size: 706.56 KB (706560 bytes)
MD5: dd699e4dfb569231ada720ec18e36fc2
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\BrightBreeze\bin\2.0.5.0
Group: Malware file
Last Updated: July 14, 2020
%PROGRAMFILES(x86)%\ClickPotatoLite\bin\10.0.622.0\ClickPotatoLiteSA.exe File name: ClickPotatoLiteSA.exe
Size: 740.14 KB (740144 bytes)
MD5: 4bdce738a4efdc2060a235682a24cf3d
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ClickPotatoLite\bin\10.0.622.0
Group: Malware file
Last Updated: March 1, 2013
%SystemDrive%\Users\<username>\AppData\Local\KangoBoxSA\bin\1.0.3.0\KangoBoxSA.exe File name: KangoBoxSA.exe
Size: 757.76 KB (757760 bytes)
MD5: fd21f14a266286dec3c254f92cbca7dc
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\KangoBoxSA\bin\1.0.3.0
Group: Malware file
Last Updated: December 17, 2012

More files

2 Comments

  • santis says:

    Clickpotato did not show or is not in \" HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \"ClickPotato\"
    my os is win7

  • daveq says:

    I didnt find ith there either. But did find it in half a dozen other places in the registry. Just searched for potato and carefully deleted each entry found. Also the ClickPotato direccory under ProgramFiles

Loading...