3721 Chinese Keywords Spyware Profile

3721 Chinese Keywords is a spyware program created by Beijing 3721 Technologies.  This company and its products were acquired by the Chinese branch of Yahoo!.  Yahoo! China contested the assertion by Beijing Sanjiwuxian Internet Technology Co. Ltd in court, but apparently didn’t contest the same statement when made by Microsoft and Panda Antivirus.

3721 Chinese Keywords began as a normal program, but started using ActiveX controls to install itself on computers in drive-by installations.  Now it is considered to be a browser hijacker, as it takes control of the search feature in Internet Explorer’s search bar.  Ostensibly, it provides keywords in Chinese characters.  While this may be useful to Chinese users, other users may find it annoying and not useful.  It is also known to track browsing habits, which qualifies it as spyware.

3721 Chinese Keywords has been largely determined to be almost impossible to remove safely from a computer.  Early attempts at removal of 3721 Chinese Keywords resulted in computer system crashes.  SpyZooka has been shown to be consistently effective in removing 3721 Chinese Keywords.

Associated File Names:
asbar.dll,
asbar.dll,
asbar.dll,
assisres.dll,
autolive.dll,
cnsmin.dll,
cnsmin.dll,
cnsmin.dll,
cnsmin.dll,
cnsminck.dll,
cnsminkp2k.sys,
cnsminsv.dll,
eheflash.dll,
helper.dll,
helper.dll,
helper.dll,
icsetup.exe,
icsetup.exe,
ieangel.dll,
regkper.dll,
setup.exe

Registry Info:
HKEY_CURRENT_USERsoftware3721
,HKEY_LOCAL_MACHINEsoftwareclassesinterface{be08f6bc-c3e6-4149-beb1-cb449e1b372e}
HKEY_LOCAL_MACHINEsoftwareclassestypelib{4158db95-de71-41ff-bea1-2c3d1c679df1}
,HKEY_LOCAL_MACHINEsystemcurrentcontrolsetenumrootlegacy_cnsminkp000|classguid
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetenumrootlegacy_cnsminkp000|configflags
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetenumrootlegacy_cnsminkp000|devicedesc
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetenumrootlegacy_cnsminkp000|legacy
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetenumrootlegacy_cnsminkp000|service
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetenumrootlegacy_cnsminkp|nextinstance
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|dnsserveraddresscount
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|dnsserveraddresses
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|domainname
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|hostname
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|primarydomainname
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|registeredaddresscount
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|registeredaddresses
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|registeredflags
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|registeredsinceboot
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|registeredttl
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|sentpriupdatetoip
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicestcpipparameters
dnsregisteredadapters{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|sentupdatetoip
profilepath+favorites3721 chinese keywords.url,
c:winntsystem32c_is2022.dll
C:Program Files3721
C:Program Files37213721

Also known as: 
CNSMin,
Adware.CDN,
3721 Chinese Keywords (CNSMin).C (vf),
Adware.Win32.3721 Chinese Keywords

Leave a Reply

Yes Scan My PcFor FREE!
  • AlphaAV

    AlphaAV is a rogue antivirus application that is promoted through Trojan horse programs. They download it and install it secretly, then the user is bombarded with false security alerts and phony scans. The scans will inevitably generate bogus results and then pressure the user into paying to register the useless program.
    If purchased, the user will [...]

  • NetSpy

    Net Spy is known as a keylogger. This means that it records every keystroke made and sends it to a remote users. It is marketed as commercial surveillance software that tracks keystrokes, takes screen shots, and records addresses of various sites visited by the infected computer. Click the button below for a free scan to [...]

  • Acontix

    Acontix is an adware that places itself on your computer and may hack your browser, which causes it to redirect to questionable websites. Acontix displays pornographic and adult content as well as intrusive third-party advertisements. These malicious applications allow the hacker to take control of your PC, and gain access to personal information such as [...]

  • Afcore

    Afcore is a backdoor Trojan that poses a high threat to your computer, as it gives control of the system over to the hacker without your knowledge. Upon installation, Afcore can be instructed to send, receive, and delete files. It can also gather information that is confidential and transfer this information to remote locations. Afcore [...]

© 2010 SpyZooka Blog – Easy Spyware Removal All rights reserved. Powered by Wordpress. Designed by Woo Themes