3721 Chinese Keywords Spyware Profile

3721 Chinese Keywords is a spyware program created by Beijing 3721 Technologies.  This company and its products were acquired by the Chinese branch of Yahoo!.  Yahoo! China contested the assertion by Beijing Sanjiwuxian Internet Technology Co. Ltd in court, but apparently didn’t contest the same statement when made by Microsoft and Panda Antivirus.

3721 Chinese Keywords began as a normal program, but started using ActiveX controls to install itself on computers in drive-by installations.  Now it is considered to be a browser hijacker, as it takes control of the search feature in Internet Explorer’s search bar.  Ostensibly, it provides keywords in Chinese characters.  While this may be useful to Chinese users, other users may find it annoying and not useful.  It is also known to track browsing habits, which qualifies it as spyware.

3721 Chinese Keywords has been largely determined to be almost impossible to remove safely from a computer.  Early attempts at removal of 3721 Chinese Keywords resulted in computer system crashes.  ZookaWare PC Cleaner has been shown to be consistently effective in removing 3721 Chinese Keywords.

Associated File Names:
asbar.dll,
asbar.dll,
asbar.dll,
assisres.dll,
autolive.dll,
cnsmin.dll,
cnsmin.dll,
cnsmin.dll,
cnsmin.dll,
cnsminck.dll,
cnsminkp2k.sys,
cnsminsv.dll,
eheflash.dll,
helper.dll,
helper.dll,
helper.dll,
icsetup.exe,
icsetup.exe,
ieangel.dll,
regkper.dll,
setup.exe

Registry Info:
HKEY_CURRENT_USER\software\3721
,HKEY_LOCAL_MACHINE\software\classes\interface\{be08f6bc-c3e6-4149-beb1-cb449e1b372e}
HKEY_LOCAL_MACHINE\software\classes\typelib\{4158db95-de71-41ff-bea1-2c3d1c679df1}
,HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_cnsminkp\0000|classguid
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_cnsminkp\0000|configflags
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_cnsminkp\0000|devicedesc
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_cnsminkp\0000|legacy
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_cnsminkp\0000|service
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_cnsminkp|nextinstance
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|dnsserveraddresscount
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|dnsserveraddresses
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|domainname
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|hostname
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|primarydomainname
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|registeredaddresscount
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|registeredaddresses
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|registeredflags
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|registeredsinceboot
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|registeredttl
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|sentpriupdatetoip
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
\dnsregisteredadapters\{47d5bfd0-e6a1-47b3-973d-1e8074de2beb}|sentupdatetoip
profilepath+\favorites\3721 chinese keywords.url,
c:\winnt\system32\c_is2022.dll
C:\Program Files\3721
C:\Program Files\3721\3721

Also known as:
CNSMin,
Adware.CDN,
3721 Chinese Keywords (CNSMin).C (vf),
Adware.Win32.3721 Chinese Keywords

Download Free Scan
ZookaWare runs on Windows Vista, 7, 8 and 10. It has no ads, popups or bundled software and fully uninstalls by clicking Start > All Programs > select ZookaWare and click Uninstall.

Leave a Reply

Your email address will not be published. Required fields are marked *

css.php