spyware removal instructions

CnsMin removal

Spyware CnsMin Information
Name: CnsMin
Category: Hijacker
Date: 2004-10-24
Dangerous: Yes
CNSMIN hijacks the search ability in MS IE, by replacing your typed search keywords with chinese chars & redirects you to their website. This strongly suggests that this spyware originated from China. Side-effects of attempts to uninstall Cnsmin caused computer crash within 5 minutes of uptime. Thus usage of professional anti-spyware software is advised.
>> Delete CnsMin automatically - Download Spyware Doctor

CnsMin Removal Instructions
Kill the following processes
assist4.exe, ierepairer.exe, assistantwzd.exe, assistse.exe, setup.exe
Unregister the following DLLs and reboot
patch03.dll, patch05.dll, patch06.dll, regkper.dll.
autolive.dll, helper.dll, notifier.dll, scrblock.dll in Program Files\3721\
scrblock.dll in Program Files\3721\3721\
adfilter.dll, adwreg.dll, assisres.dll, assist.dll, assistex.dll, eheflash.dll, eheocx.dll, optimum.dll, repair.dll, xpstyle.dll in Program Files\3721\assist\
abmain.dll, cescache.dll, cesfox.dll, cesmain.dll, cesout.dll, cesout10.dll, cespack.dll, cesweb.dll, cmail.dll in Program Files\3721\ces\
asmenu.dll, ieangel.dll, menuinfo.dll in Program Files\3721\shell\
axfilter.dll, cnshook.dll, cnsio.dll, cnsmin.dll, cnsminck.dll, cnsmindt.dll, cnsminex.dll, cnsminio.dll, cnsminsv.dll in Windows\downloaded program files\
abmain.dll, autolive.dll, cescache.dll, cesfox.dll, cesmain.dll, cesout.dll, cesout10.dll, cesweb.dll, cmail.dll, cnsio.dll in Windows\downloaded program files\3721\
axfilter.dll, cnshook.dll, cnsio.dll, cnsmin.dll, cnsminck.dll, cnsmindt.dll, cnsminex.dll, cnsminio.dll, cnsminsv.dll in Windows\downlo~1\
cnsio.dll in Windows\downlo~1\3721\
assist.dll, bdhelper.dll, cesweb.dll, cnshook.dll, ehelper.dll in Windows\system32\
assist.dll, bdhelper.dll, cesweb.dll, cnshook.dll in Windows\system\
Delete these registry entries
HKEY_CLASSES_ROOT\clsid\{1b0e7716-898e-48cc-9690-4e338e8de1d3}
HKEY_CLASSES_ROOT\clsid\{6231d512-e4a4-4df2-be62-5b8f0ee348ef}
HKEY_CLASSES_ROOT\clsid\{6d8f256b-6ab8-4398-8f86-1e56207db77a}
HKEY_CLASSES_ROOT\clsid\{b83fc273-3522-4cc6-92ec-75cc86678da4}
HKEY_CLASSES_ROOT\clsid\{ca92b524-bc8a-4610-bd2c-6bd3e28155d0}
HKEY_CLASSES_ROOT\clsid\{d157330a-9ef3-49f8-9a67-4141ac41add4}
HKEY_CLASSES_ROOT\clsid\{e5e4e352-6947-44ee-a420-db84efd3fe93}
HKEY_CLASSES_ROOT\cnshelper.ch
HKEY_CLASSES_ROOT\cnsminhk.cnshook
HKEY_CLASSES_ROOT\interface\{1bb0abbe-2d95-4847-b9d8-6f90de3714c1}
HKEY_CLASSES_ROOT\interface\{df692509-d9ef-48a0-9cd0-3aa5b81f6f68}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{6231d512-e4a4-4df2-be62-5b8f0ee348ef}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{ca92b524-bc8a-4610-bd2c-6bd3e28155d0}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{d157330a-9ef3-49f8-9a67-4141ac41add4}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{e5e4e352-6947-44ee-a420-db84efd3fe93}
HKEY_CLASSES_ROOT\typelib\{a5adeae7-a8b4-4f94-9128-bf8d8db5e927}
HKEY_CURRENT_USER\software\3721
HKEY_LOCAL_MACHINE\software\3721
HKEY_LOCAL_MACHINE\software\3721\alhelper
HKEY_LOCAL_MACHINE\software\3721\alpath
HKEY_LOCAL_MACHINE\software\3721\assist\adfilter.dll
HKEY_LOCAL_MACHINE\software\3721\assist\adfilter.dll_new
HKEY_LOCAL_MACHINE\software\3721\assist\adfilter.dll_upd
HKEY_LOCAL_MACHINE\software\3721\assist\adwreg.dll
HKEY_LOCAL_MACHINE\software\3721\assist\adwreg.dll_new
HKEY_LOCAL_MACHINE\software\3721\assist\adwreg.dll_upd
HKEY_LOCAL_MACHINE\software\3721\assist\alini
HKEY_LOCAL_MACHINE\software\3721\assist\allasttime
HKEY_LOCAL_MACHINE\software\3721\assist\altimei
HKEY_LOCAL_MACHINE\software\3721\assist\assisres.dll
HKEY_LOCAL_MACHINE\software\3721\assist\assisres.dll_new
HKEY_LOCAL_MACHINE\software\3721\assist\assisres.dll_upd
HKEY_LOCAL_MACHINE\software\3721\assist\assist.dll
HKEY_LOCAL_MACHINE\software\3721\assist\assist.dll_new
HKEY_LOCAL_MACHINE\software\3721\assist\assistex.dll
HKEY_LOCAL_MACHINE\software\3721\assist\assistex.dll_new
HKEY_LOCAL_MACHINE\software\3721\assist\assistpath
HKEY_LOCAL_MACHINE\software\3721\assist\coop\partner
HKEY_LOCAL_MACHINE\software\3721\assist\coop\prepartner
HKEY_LOCAL_MACHINE\software\3721\assist\coop\urlfg
HKEY_LOCAL_MACHINE\software\3721\assist\eheocx.dll
HKEY_LOCAL_MACHINE\software\3721\assist\eheocx.dll_new
HKEY_LOCAL_MACHINE\software\3721\assist\eheocx.dll_upd
HKEY_LOCAL_MACHINE\software\3721\assist\ehessq.dat
HKEY_LOCAL_MACHINE\software\3721\assist\ehessq.dat_new
HKEY_LOCAL_MACHINE\software\3721\assist\ehessq.dat_upd
HKEY_LOCAL_MACHINE\software\3721\assist\ehetle.dat
HKEY_LOCAL_MACHINE\software\3721\assist\ehetle.dat_new
HKEY_LOCAL_MACHINE\software\3721\assist\ehetle.dat_upd
HKEY_LOCAL_MACHINE\software\3721\assist\ehetli.dat
HKEY_LOCAL_MACHINE\software\3721\assist\ehetli.dat_new
HKEY_LOCAL_MACHINE\software\3721\assist\ehetli.dat_upd
HKEY_LOCAL_MACHINE\software\3721\assist\eheule.dat
HKEY_LOCAL_MACHINE\software\3721\assist\eheule.dat_new
HKEY_LOCAL_MACHINE\software\3721\assist\eheule.dat_upd
HKEY_LOCAL_MACHINE\software\3721\assist\eheuli.dat
HKEY_LOCAL_MACHINE\software\3721\assist\eheuli.dat_new
HKEY_LOCAL_MACHINE\software\3721\assist\eheuli.dat_upd
HKEY_LOCAL_MACHINE\software\3721\assist\ierepair.dat
HKEY_LOCAL_MACHINE\software\3721\assist\ierepair.dat_new
HKEY_LOCAL_MACHINE\software\3721\assist\ierepair.dat_upd
HKEY_LOCAL_MACHINE\software\3721\assist\kpact
HKEY_LOCAL_MACHINE\software\3721\assist\modules\adfilter.dll
HKEY_LOCAL_MACHINE\software\3721\assist\modules\assistex.dll
HKEY_LOCAL_MACHINE\software\3721\assist\modules\optimum.dll
HKEY_LOCAL_MACHINE\software\3721\assist\modules\repair.dll
HKEY_LOCAL_MACHINE\software\3721\assist\modules\scrblock.dll
HKEY_LOCAL_MACHINE\software\3721\assist\modules\xpstyle.dll
HKEY_LOCAL_MACHINE\software\3721\assist\nonewuser
HKEY_LOCAL_MACHINE\software\3721\assist\optimum.dll
HKEY_LOCAL_MACHINE\software\3721\assist\optimum.dll_new
HKEY_LOCAL_MACHINE\software\3721\assist\optimum.dll_upd
HKEY_LOCAL_MACHINE\software\3721\assist\path
HKEY_LOCAL_MACHINE\software\3721\assist\regrundel.dat
HKEY_LOCAL_MACHINE\software\3721\assist\regrundel.dat_new
HKEY_LOCAL_MACHINE\software\3721\assist\regrundel.dat_upd
HKEY_LOCAL_MACHINE\software\3721\assist\repair.dll
HKEY_LOCAL_MACHINE\software\3721\assist\repair.dll_new
HKEY_LOCAL_MACHINE\software\3721\assist\repair.dll_upd
HKEY_LOCAL_MACHINE\software\3721\assist\xpstyle.dll
HKEY_LOCAL_MACHINE\software\3721\assist\xpstyle.dll_new
HKEY_LOCAL_MACHINE\software\3721\assist\xpstyle.dll_upd
HKEY_LOCAL_MACHINE\software\3721\autolive\alini
HKEY_LOCAL_MACHINE\software\3721\autolive\alinisw
HKEY_LOCAL_MACHINE\software\3721\autolive\allasttime
HKEY_LOCAL_MACHINE\software\3721\autolive\allasttimesw
HKEY_LOCAL_MACHINE\software\3721\autolive\altimei
HKEY_LOCAL_MACHINE\software\3721\autolive\altimeisw
HKEY_LOCAL_MACHINE\software\3721\autolive\autolive.dll
HKEY_LOCAL_MACHINE\software\3721\autolive\autolive.dll_new
HKEY_LOCAL_MACHINE\software\3721\autolive\cns01.dat
HKEY_LOCAL_MACHINE\software\3721\autolive\cns01.dat_new
HKEY_LOCAL_MACHINE\software\3721\autolive\helper.dll
HKEY_LOCAL_MACHINE\software\3721\autolive\helper.dll_new
HKEY_LOCAL_MACHINE\software\3721\autolive\nonewuser
HKEY_LOCAL_MACHINE\software\3721\autolive\notifier.dll
HKEY_LOCAL_MACHINE\software\3721\autolive\patch03.dll
HKEY_LOCAL_MACHINE\software\3721\autolive\patch03.dll_new
HKEY_LOCAL_MACHINE\software\3721\autolive\patch03.dll_upd
HKEY_LOCAL_MACHINE\software\3721\autolive\patch05.dll
HKEY_LOCAL_MACHINE\software\3721\autolive\patch05.dll_new
HKEY_LOCAL_MACHINE\software\3721\autolive\patch05.dll_upd
HKEY_LOCAL_MACHINE\software\3721\autolive\patch06.dll
HKEY_LOCAL_MACHINE\software\3721\autolive\patch06.dll_new
HKEY_LOCAL_MACHINE\software\3721\autolive\patch06.dll_upd
HKEY_LOCAL_MACHINE\software\3721\autolive\path
HKEY_LOCAL_MACHINE\software\3721\autolive\scrblock.dll
HKEY_LOCAL_MACHINE\software\3721\cfile
HKEY_LOCAL_MACHINE\software\3721\cnsmin\alini
HKEY_LOCAL_MACHINE\software\3721\cnsmin\clear
HKEY_LOCAL_MACHINE\software\3721\cnsmin\cnsminex\autolive.dll
HKEY_LOCAL_MACHINE\software\3721\cnsmin\cnsminex\autolive.dll_bup
HKEY_LOCAL_MACHINE\software\3721\cnsmin\cnsminex\cnshook.dll
HKEY_LOCAL_MACHINE\software\3721\cnsmin\cnsminex\cnshook.dll_bup
HKEY_LOCAL_MACHINE\software\3721\cnsmin\cnsminex\cnsmindt.dll
HKEY_LOCAL_MACHINE\software\3721\cnsmin\cnsminex\cnsmindt.dll_bup
HKEY_LOCAL_MACHINE\software\3721\cnsmin\cnsminex\cnsminio.dll
HKEY_LOCAL_MACHINE\software\3721\cnsmin\cnsminex\cnsminio.dll_bup
HKEY_LOCAL_MACHINE\software\3721\cnsmin\cnsminex\keepmain.dll
HKEY_LOCAL_MACHINE\software\3721\cnsmin\cnsminex\keepmain.dll_bup
HKEY_LOCAL_MACHINE\software\3721\cnsmin\kpm
HKEY_LOCAL_MACHINE\software\3721\cnsmin\kpver
HKEY_LOCAL_MACHINE\software\3721\cnsmin\partner
HKEY_LOCAL_MACHINE\software\3721\cnsmin\setaddparams
HKEY_LOCAL_MACHINE\software\3721\cnsmin\setdelparams
HKEY_LOCAL_MACHINE\software\3721\cnsmin\version
HKEY_LOCAL_MACHINE\software\3721\cnsmin\version_bup
HKEY_LOCAL_MACHINE\software\3721\cnsmin\versionex
HKEY_LOCAL_MACHINE\software\3721\cnsmin\versionex_bup
HKEY_LOCAL_MACHINE\software\3721\cnsmin\versionup
HKEY_LOCAL_MACHINE\software\3721\cnsmincg\lastupdate
HKEY_LOCAL_MACHINE\software\3721\shellsystray\path
HKEY_LOCAL_MACHINE\software\3721\shellsystray\windowname
HKEY_LOCAL_MACHINE\software\classes\assist.easyassist
HKEY_LOCAL_MACHINE\software\classes\assist.easyassist\clsid
HKEY_LOCAL_MACHINE\software\classes\assist.easyassist\curver
HKEY_LOCAL_MACHINE\software\classes\autolive.live
HKEY_LOCAL_MACHINE\software\classes\autolive.live\clsid
HKEY_LOCAL_MACHINE\software\classes\autolive.live\curver
HKEY_LOCAL_MACHINE\software\classes\clsid\{1b0e7716-898e-48cc-9690-4e338e8de1d3}
HKEY_LOCAL_MACHINE\software\classes\clsid\{6231d512-e4a4-4df2-be62-5b8f0ee348ef}
HKEY_LOCAL_MACHINE\software\classes\clsid\{7ca83cf1-3aea-42d0-a4e3-1594fc6e48b2}
HKEY_LOCAL_MACHINE\software\classes\clsid\{9eb2b422-c9ee-46c4-a471-1e79c7517b1d}
HKEY_LOCAL_MACHINE\software\classes\clsid\{abec6103-f6ac-43a3-834f-fb03fba339a2}
HKEY_LOCAL_MACHINE\software\classes\clsid\{b835c273-3522-4cc6-92ec-75cc86678da4}
HKEY_LOCAL_MACHINE\software\classes\clsid\{b83fc273-3522-4cc6-92ec-75cc86678da4}
HKEY_LOCAL_MACHINE\software\classes\clsid\{ca92b524-bc8a-4610-bd2c-6bd3e28155d0}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d157330a-9ef3-49f8-9a67-4141ac41add4}
HKEY_LOCAL_MACHINE\software\classes\clsid\{e5e4e352-6947-44ee-a420-db84efd3fe93}
HKEY_LOCAL_MACHINE\software\classes\cnshelper.ch
HKEY_LOCAL_MACHINE\software\classes\cnshelper.ch\clsid
HKEY_LOCAL_MACHINE\software\classes\cnshelper.ch\curver
HKEY_LOCAL_MACHINE\software\classes\cnsminhk.cnshook
HKEY_LOCAL_MACHINE\software\classes\cnsminhk.cnshook\clsid
HKEY_LOCAL_MACHINE\software\classes\cnsminhk.cnshook\curver
HKEY_LOCAL_MACHINE\software\classes\fflash.flashobjectinterface
HKEY_LOCAL_MACHINE\software\classes\fflash.flashobjectinterface\clsid
HKEY_LOCAL_MACHINE\software\classes\fflash.flashobjectinterface\curver
HKEY_LOCAL_MACHINE\software\classes\interface\{1bb0abbe-2d95-4847-b9d8-6f90de3714c1}
HKEY_LOCAL_MACHINE\software\classes\interface\{48e688c8-609f-4b08-944e-3c7fab99cd08}
HKEY_LOCAL_MACHINE\software\classes\interface\{924f5b3a-7a27-484a-b873-e855c9708667}
HKEY_LOCAL_MACHINE\software\classes\interface\{be08f6bc-c3e6-4149-beb1-cb449e1b372e}
HKEY_LOCAL_MACHINE\software\classes\interface\{c3a9f7f8-8862-496a-b8a4-25d4140b7dbc}
HKEY_LOCAL_MACHINE\software\classes\interface\{df692509-d9ef-48a0-9cd0-3aa5b81f6f68}
HKEY_LOCAL_MACHINE\software\classes\typelib\{19069804-2cf0-4357-b696-ba6e9aad99ef}
HKEY_LOCAL_MACHINE\software\classes\typelib\{4158db95-de71-41ff-bea1-2c3d1c679df1}
HKEY_LOCAL_MACHINE\software\classes\typelib\{7354662f-caa3-448b-bc01-04f55a2dca35}
HKEY_LOCAL_MACHINE\software\classes\typelib\{a5adeae7-a8b4-4f94-9128-bf8d8db5e927}
HKEY_LOCAL_MACHINE\software\classes\typelib\{aab6bce3-1df6-4930-9b14-9ca79dc8c267}
HKEY_LOCAL_MACHINE\software\classes\typelib\{f9ad9d67-efa8-480e-8291-0163f3960de7}
HKEY_LOCAL_MACHINE\software\interchina
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\autoupdate\checkedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\autoupdate\defaultvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\autoupdate\hkeyroot
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\autoupdate\pluguitext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\autoupdate\regpath
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\autoupdate\text
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\autoupdate\type
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\autoupdate\uncheckedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\autoupdate\valuename
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\bitmap
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\enable\checkedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\enable\defaultvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\enable\hkeyroot
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\enable\pluguitext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\enable\regpath
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\enable\text
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\enable\type
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\enable\uncheckedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\enable\valuename
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\hint\checkedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\hint\defaultvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\hint\hkeyroot
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\hint\pluguitext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\hint\regpath
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\hint\text
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\hint\type
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\hint\uncheckedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\hint\valuename
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\list\checkedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\list\defaultvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\list\hkeyroot
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\list\pluguitext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\list\regpath
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\list\text
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\list\type
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\list\uncheckedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\list\valuename
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\menu\checkedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\menu\defaultvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\menu\hkeyroot
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\menu\pluguitext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\menu\regpath
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\menu\text
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\menu\type
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\menu\uncheckedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\menu\valuename
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\pluguitext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\reset\checkedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\reset\defaultvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\reset\hkeyroot
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\reset\pluguitext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\reset\regpath
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\reset\text
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\reset\type
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\reset\uncheckedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\reset\valuename
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\resetcatch\checkedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\resetcatch\defaultvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\resetcatch\hkeyroot
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\resetcatch\pluguitext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\resetcatch\regpath
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\resetcatch\text
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\resetcatch\type
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\resetcatch\uncheckedvalue
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\resetcatch\valuename
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\text
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\advancedoptions\!cns\type
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{00000000-0000-0001-0001-596baedd1289}\buttontext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{00000000-0000-0001-0001-596baedd1289}\clsid
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{00000000-0000-0001-0001-596baedd1289}\default visible
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{00000000-0000-0001-0001-596baedd1289}\exec
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{00000000-0000-0001-0001-596baedd1289}\hoticon
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{00000000-0000-0001-0001-596baedd1289}\icon
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{0f7de07d-bd74-4991-9d5f-ecbb8391875d}\buttontext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{0f7de07d-bd74-4991-9d5f-ecbb8391875d}\clsid
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{0f7de07d-bd74-4991-9d5f-ecbb8391875d}\default visible
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{0f7de07d-bd74-4991-9d5f-ecbb8391875d}\exec
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{0f7de07d-bd74-4991-9d5f-ecbb8391875d}\hoticon
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{0f7de07d-bd74-4991-9d5f-ecbb8391875d}\icon
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{5d73ee86-05f1-49ed-b850-e423120ec338}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{5d73ee86-05f1-49ed-b850-e423120ec338}\buttontext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{5d73ee86-05f1-49ed-b850-e423120ec338}\clsid
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{5d73ee86-05f1-49ed-b850-e423120ec338}\default visible
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{5d73ee86-05f1-49ed-b850-e423120ec338}\exec
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{5d73ee86-05f1-49ed-b850-e423120ec338}\hoticon
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{5d73ee86-05f1-49ed-b850-e423120ec338}\icon
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{ecf2e268-f28c-48d2-9ab7-8f69c11ccb71}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{ecf2e268-f28c-48d2-9ab7-8f69c11ccb71}\clsid
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{ecf2e268-f28c-48d2-9ab7-8f69c11ccb71}\default visible
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{ecf2e268-f28c-48d2-9ab7-8f69c11ccb71}\exec
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{ecf2e268-f28c-48d2-9ab7-8f69c11ccb71}\menutext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{fd00d911-7529-4084-9946-a29f1bdf4fe5}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{fd00d911-7529-4084-9946-a29f1bdf4fe5}\clsid
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{fd00d911-7529-4084-9946-a29f1bdf4fe5}\default visible
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{fd00d911-7529-4084-9946-a29f1bdf4fe5}\exec
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{fd00d911-7529-4084-9946-a29f1bdf4fe5}\menutext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search\ocustomizesearch
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search\osearchassistant
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{1b0e7716-898e-48cc-9690-4e338e8de1d3}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\cnsmin
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{1b0e7716-898e-48cc-9690-4e338e8de1d3}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6231d512-e4a4-4df2-be62-5b8f0ee348ef}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ca92b524-bc8a-4610-bd2c-6bd3e28155d0}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d157330a-9ef3-49f8-9a67-4141ac41add4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{e5e4e352-6947-44ee-a420-db84efd3fe93}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks\{b83fc273-3522-4cc6-92ec-75cc86678da4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks\{d157330a-9ef3-49f8-9a67-4141ac41add4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/cns02.dat
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/cnshook.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/cnsmin.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/autolive.dll\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/autolive.dll\{7ca83cf1-3aea-42d0-a4e3-1594fc6e48b2}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/cns02.dat\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/cns02.dat\{b83fc273-3522-4cc6-92ec-75cc86678da4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/cnsmin.dll\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/cnsmin.dll\{b83fc273-3522-4cc6-92ec-75cc86678da4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\cesmain.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\cnsmin
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\helper.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\3721c:\progra~1\3721\autolive.dll253343
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\downloaded program files\cns02.dat
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\downloaded program files\cnshook.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\downloaded program files\cnsmin.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{1b0e7716-898e-48cc-9690-4e338e8de1d3}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\cnsmin
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\cnsmin\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\cnsmin\uninstallstring
Remove the following files
ÍeÍ░Í.lnk, ░▓eÀa╗ñ.lnk, 1.reg, 12.reg, 14.reg, 15.reg, 1a_a1o.lnk, 3.reg, 3721╔iioÍeÍ.lnk, 4.reg, adfilter.to_be_deleted, asdf.txt, assist.to_be_deleted_x, assist4.exe, bbb.txt, cns01.dat, cnsinfo.dat, cnsmin-install.htm, cnsmin.txt, ehessq.dat, iÁi3╝oeu.lnk, ied__'.lnk, ierepair.dat, ierepairer.exe, o_e▒ú╗ñ.lnk, patch03.dll, patch05.dll, patch06.dll, regkper.dll, regrundel.dat, repair.to_be_deleted, test.txt, xpstyle.to_be_deleted.
cnsminkp.sys in c:\winnt\system32\drivers\
‗■Ù▒ú╗ñ.lnk, ╣Ò╣.lnk, ░▓ÞÀ╗ñ.lnk, 3721ÚÝÛ.lnk, ie■┤.lnk, ÁÝ│╝Ù.lnk, Û░.lnk in Documents and Settings\UserName\administrator\start menu\programs\3721ÚÝÛ\
aneestdpea.lib in Documents and Settings\UserName\application data\
3721 chinese keywords.url in Favorites\
cnscfgf.dat, cnscfgr.dat, cnsmin.dat in Program Files\
assistse.exe, autolive.dll, autolive.ini, autolvsw.ini, helper.dll, notifier.dll, scrblock.dll, setup.exe in Program Files\3721\
scrblock.dll in Program Files\3721\3721\
adfilter.dll, adwreg.dll, assisres.dll, assist.dll, assist.ini, assistantwzd.exe, assistex.dll, cnsminkp.sys, eheflash.dll, eheocx.dll, optimum.dll, repair.dll, xpstyle.dll in Program Files\3721\assist\
abmain.dll, ces.ini, cescache.dll, cesfox.dll, cesmain.dll, cesout.dll, cesout10.dll, cespack.dll, cessw.ini, cesweb.dll, cmail.dll in Program Files\3721\ces\
asmenu.dll, ieangel.dll, menuinfo.dll in Program Files\3721\shell\
3721 assistant.url, about chinese keyword.url, clean internet access record.url, repair browser.url, uninstall.lnk in Program Files\Common Files\chinese keywords\
axfilter.dll, cns02.dat, cnshook.dll, cnsio.dll, cnsmin.dll, cnsmin.inf, cnsmin.ini, cnsminaf.cab, cnsmincg.ini, cnsminck.cab, cnsminck.dll, cnsmindt.cab, cnsmindt.dll, cnsminex.cab, cnsminex.dll, cnsminex.ini, cnsminio.cab, cnsminio.dll, cnsminsv.cab, cnsminsv.dll, cnsup.ini, keepmainm.cab in Windows\downloaded program files\
abmain.dll, autolive.dll, cescache.dll, cesfox.dll, cesmain.dll, cesout.dll, cesout10.dll, cesweb.dll, cmail.dll, cnsio.dll, cnsminkp.vxd, cnsminkp2k.sys, cnsminkpxp.sys in Windows\downloaded program files\3721\
axfilter.dll, cnshook.dll, cnsio.dll, cnsmin.dll, cnsmin.ini, cnsmincg.ini, cnsminck.dll, cnsmindt.dll, cnsminex.dll, cnsminex.ini, cnsminio.dll, cnsminsv.dll, cnsup.ini in Windows\downlo~1\
cnsio.dll in Windows\downlo~1\3721\
assist.dll, bdhelper.dll, cesweb.dll, cnshook.dll, ehelper.dll in Windows\system32\
cnsminkp.sys in Windows\system32\drivers\
assist.dll, bdhelper.dll, cesweb.dll, cnshook.dll in Windows\system\
Remove the following directories
c:\documents and settings\all users.windows\start menu\programs\chinese keywor
Program Files\Common Files\chinese keywords
Documents and Settings\UserName\start menu\programs\3721ÚÝÛ
Program Files\3721
Program Files\3721\assist
Windows\downloaded program files\3721

Bookmark CnsMin page

Visitor Comments on CnsMin
2006-05-13 01:05:13, Guest:
BTW it definitely is from China. The company that made it was bought by Yahoo, meaning Yahoo condones unremovable spyware.
2006-05-28 20:59:52, Guest:
Not only that but the chinese yahoo assistant toolbar is ofered as a means to remove cnsmin. It does no such thing, but rather hides it and leaves a whole new layer of garbage that can only be removed by visiting their site.
2006-07-02 12:23:35, Guest:
how to Unregister the following DLLs and reboot?
Does it mean that i have to type "msconfig" in Run? then unclick some of startup .exe program?
2006-07-02 12:25:42, Guest:
Plus, if I always go to the Chines Website, it make no sense to uninstall it? 'coz i am going to be attacked by the same spyware again?
2006-10-20 00:25:54, Guest:
Do i have the same virus even though it doesn't direct me to any site? My virus scans tell me cns.dll is in my computer. Anti-spywares also tell me that i have cns.
2006-12-18 20:22:18, Guest:
is there any easier way to remove it?
2006-12-26 06:39:29, Guest:
OMG I can't understand anything of that, where to find those processes?
2007-01-08 04:44:58, Guest:
1. press start->run and type regedit
2. press [enter]
3. find the registry entries and delete them
2007-01-25 04:17:29, Guest:
does anyone know any program that can remove the stupid file?
2007-02-19 02:42:48, Guest:
I heard that the guy who created this virus/spyware made tons of money out of it. I would wish he will be put into the jail some day, considering all the ordeals caused by him.
2007-02-23 07:53:30, Guest JL:
I stopped using IE. Does this effect other browsers?
2007-04-15 19:46:01, Guest:
is there a tool that can remove cnsmin??
2007-07-24 15:07:43, Guest MR:
I don't want to advertise, but Spy Sweeper did a fine job to me.
 Previous Spyware: Remove CNK 1.0 Next Spyware: Remove CnsMin variant