Home Malware Programs Potentially Unwanted Programs (PUPs) Cantataweb

Cantataweb

Posted: June 2, 2015

Threat Metric

Ranking: 10,441
Threat Level: 2/10
Infected PCs: 1,295
First Seen: July 28, 2014
Last Seen: September 26, 2023
OS(es) Affected: Windows

Cantataweb is another product created and developed by SuperWeb LLC. The company is known for producing enormous amounts of adware or adware-laced applications such as Cantataweb. Adware such as Cantataweb is known to inject commercial advertisements that are displayed in your web browser. Users might often fall prey to deceptive marketing methods such as bundling as adware creators often rely on user's lack of attention during the installation of freeware. Adware applications such as Cantataweb are also known to collect information to tailor its advertisements. Consequently, computer security experts advise users not to click or rely on them. It is possible that clicking on ads by Cantataweb lead to questionable websites or sometimes to ones that promote potentially malicious content.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\Cantataweb\Cantatawebbho.dll File name: C:\Program Files\Cantataweb\Cantatawebbho.dll
MD5: 782120c72fed39f739d6d0e396adde92
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\Cantataweb\Cantatawebuninstall.exe File name: C:\Program Files\Cantataweb\Cantatawebuninstall.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
7za.exe File name: 7za.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
updateCantataweb.exe File name: updateCantataweb.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
CantatawebUninstall.exe File name: CantatawebUninstall.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

CLSID{35D85AD1-904F-4E27-8C74-2C60713A985B}{AA99E11B-00D2-4BD2-8BA6-709DCCEDD9D1}HKEY..\..\..\..{RegistryKeys}SOFTWARE\CantatawebSoftware\Microsoft\Internet Explorer\Approved Extensions\{AAB803BD-F01B-423A-A89A-60AF476E9F12}SOFTWARE\Microsoft\Tracing\Cantataweb_RASAPI32SOFTWARE\Microsoft\Tracing\Cantataweb_RASMANCSSOFTWARE\Microsoft\Tracing\updateCantataweb_RASAPI32SOFTWARE\Microsoft\Tracing\updateCantataweb_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{AAB803BD-F01B-423A-A89A-60AF476E9F12}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AAB803BD-F01B-423A-A89A-60AF476E9F12}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AAB803BD-F01B-423A-A89A-60AF476E9F12}SOFTWARE\Wow6432Node\CantatawebSOFTWARE\Wow6432Node\Microsoft\Tracing\Cantataweb_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Cantataweb_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateCantataweb_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateCantataweb_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{AAB803BD-F01B-423A-A89A-60AF476E9F12}SYSTEM\ControlSet001\services\eventlog\Application\Update CantatawebSYSTEM\ControlSet001\services\Update CantatawebSYSTEM\ControlSet002\services\eventlog\Application\Update CantatawebSYSTEM\ControlSet002\services\Update CantatawebSYSTEM\CurrentControlSet\services\eventlog\Application\Update CantatawebSYSTEM\CurrentControlSet\services\Update CantatawebHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Cantataweb

Additional Information

The following directories were created:
%PROGRAMFILES%\Cantataweb%PROGRAMFILES(x86)%\Cantataweb%Temp%\Cantataweb
The following URL's were detected:
Cantatawebcantataweb.net
Loading...