Home Malware Programs Adware Popcornew

Popcornew

Posted: November 4, 2014

Threat Metric

Ranking: 6,602
Threat Level: 2/10
Infected PCs: 8,429
First Seen: November 4, 2014
Last Seen: March 8, 2025
OS(es) Affected: Windows

Popcornew is adware that you may install on your computer unknowingly. Popcornew usually comes bundled with freeware you downloaded from Internet, or you may have chosen to install it because of the functions it offers. Whichever the case, Popcornew may appear as a toolbar, browser add-on, extension or Browser Helper Object, it depends on your browser of choice. Popcornew may change your search provider. Popcornew displays many annoying pop-ups, coupons and ads whenever you go. If you are not comfortable with Popcornew, you might want to reconsider keeping Popcornew on your PC.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{083ABACD-BAF3-4AB7-A52C-32BAF0A44E6B}{16BC6838-379D-47A7-BA04-6F94A8A6CD88}{2BB27047-C938-4EBC-9158-6C84F1CC09D1}{2C22389C-2E28-4770-B96C-01AC9FFF6A49}{2C9F2C34-8F06-442D-90BE-B23C0A31983F}{3B455781-2C9A-4A5F-97BD-18CD9FB621F1}{49D20DEA-D609-42BE-A9E1-0673382F530D}{6A700506-A641-475A-8538-44AEE2F45DD0}{6B8D4379-95D4-428D-8B3D-D5A655251CD0}{74DDBF4E-EC16-468A-A6F4-6C1D250A4EC9}{7711974F-6685-46CD-A62E-63C7B46F9705}{7FB88587-9AA6-459D-B4BF-E8094DC46C02}{909F2E0D-650B-46B9-A27D-5A893BDDF58D}{91231829-C94F-497E-85B7-4A9ED7C8A2E4}{92C7CBA5-8948-44D6-8A87-998ECCFE24F4}{94612B35-2B11-4D25-A19B-4DEB5FCFCEC7}{97F85554-4DE1-4D54-86F1-E1273E0680EE}{9E598662-1ABE-48BC-B522-EF13ED372D08}{AAC9CBD8-BAE8-40DB-966D-7BF61B82CB85}{AB2D8F9B-2E9A-4996-964D-AD5F41B940B0}{ADA3F4C6-F003-41AE-968D-6C2FFF09DA28}{D5BCB6C9-3ED8-460D-95F3-BCC309AD1D29}{D76A79FC-8290-4B79-BABB-C0A2D584BA6E}{DA6E3D04-1BE1-489C-94F4-1913F6130DA8}{DDAC3A24-5C61-4ED6-9161-3248A4A3E239}{DEDFF457-8AA4-48A4-8A37-DC4ACA6133D2}{DF8EBF99-BB5B-4A47-880A-F73B2AA99C61}{E5CE287D-C5C8-4DA3-A66F-5F78CD501BD5}{EFA7A511-B491-4312-BB35-4586B99E45ED}{F38C5B49-653A-4AC0-9822-761201228D1C}{F930C6AB-C4F4-4CBC-97CB-49ED410F99CF}{F98FA5CB-A5B7-4836-8FB1-7317FD7FBA1A}{FDDD22AC-8EEB-4615-9D22-E7BF00BBDF98}Regexp file mask%WINDIR%\System32\Tasks\PopcornewUpdateTaskMachineUA%WINDIR%\Tasks\PopcornewUpdateTaskMachineUA.jobHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\AdRotate.AdRotateSOFTWARE\Classes\AdRotate.AdRotate.1SOFTWARE\Classes\AppID\PopcornewUpdate.exeSOFTWARE\Classes\AppID\{2BB27047-C938-4EBC-9158-6C84F1CC09D1}SOFTWARE\Classes\AppID\{6A700506-A641-475A-8538-44AEE2F45DD0}SOFTWARE\Classes\Installer\Features\6355A26657D93B943BE614BFD65B3ACCSOFTWARE\Classes\Installer\Products\6355A26657D93B943BE614BFD65B3ACCSOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.Popcornew.oneclickctrl.9SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.Popcornew.update3webcontrol.3SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFA7A511-B491-4312-BB35-4586B99E45ED}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PopcornewUpdate.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PopcornewUpdateTaskMachineCoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PopcornewUpdateTaskMachineUASOFTWARE\Microsoft\Windows\CurrentVersion\Run\PopcornewSoftware\PopcornewSOFTWARE\Wow6432Node\Classes\AppID\PopcornewUpdate.exeSOFTWARE\Wow6432Node\Classes\AppID\{2BB27047-C938-4EBC-9158-6C84F1CC09D1}SOFTWARE\Wow6432Node\Classes\AppID\{6A700506-A641-475A-8538-44AEE2F45DD0}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7CD8A44F-6DEF-4D91-952D-4492AC5E4306}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909F2E0D-650B-46B9-A27D-5A893BDDF58D}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ADA3F4C6-F003-41AE-968D-6C2FFF09DA28}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFA7A511-B491-4312-BB35-4586B99E45ED}SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PopcornewUpdate.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\PopcornewSOFTWARE\Wow6432Node\PopcornewSYSTEM\ControlSet001\services\Popcornew_updateSYSTEM\ControlSet001\services\Popcornew_update_mSYSTEM\ControlSet002\services\Popcornew_updateSYSTEM\ControlSet002\services\Popcornew_update_mSYSTEM\CurrentControlSet\services\Popcornew_updateSYSTEM\CurrentControlSet\services\Popcornew_update_mHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{662A5536-9D75-49B3-B36E-41FB6DB5A3CC}

Additional Information

The following directories were created:
%LOCALAPPDATA%\Popcornew%PROGRAMFILES%\Popcornew%PROGRAMFILES(x86)%\Popcornew
Loading...