Home Articles Spyware Research Support Scan Now Purchase F.A.Q.

Hijacker/JWord Plugin

Alias: JWord Plugin

Description: Hijacker/JWord Plugin is hijacker. A Hijacker is a software application that takes control of your browser's settings. Usually it changes your home page and redirects it to some unknown site or modifies your search settings. It prevents you from changing back your browser's settings. An infected browser usually operates much slower.

Threat type:

Hijacker - A Hijacker is a software application that takes control of your browser's settings. Usually it changes your home page and redirects it to some unknown site or modifies your search settings. It prevents you from changing back your browser's settings. An infected browser usually operates much slower.


Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy.

Detection:
SpyNoMore detects Hijacker/JWord Plugin: Yes

Threat risk: High Risk
SpyNoMore AntiSpyware: Remove JWord Plugin, JWord Plugin Remover
Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans.

Symptoms:

Hijacker/JWord Plugin Signature Details: The following information includes some of the standard signatures associated with this spyware threat. Please do not attempt to manually remove these items from your computer; Removing these items incorrectly or partially can cause your computer to experience critical errors, prevent your computer from restarting or cause loss of Internet connectivity. Should you be infected with Hijacker/JWord Plugin, you can clean your computer by downloading SpyNoMore now.

Running Process Signatures:
N/A

File Signatures:
%WINDOWS%\downloaded program files\cnsminex.cab
%WINDOWS%\downloaded program files\cnsminsv.dll
%WINDOWS%\downloaded program files\jwordhot.ico
%COMMON_PROGRAMS%\japanese keywords\japanese keyword setting.url
%WINDOWS%\downloaded program files\cnsmincg.ini
%COMMON_PROGRAMS%\japanese keywords\about japanese keyword.url
%WINDOWS%\downloaded program files\jword.ico
%WINDOWS%\downloaded program files\cnsminex.ini
%WINDOWS%\downloaded program files\cnsmin.dll
%WINDOWS%\downloaded program files\cnsmin.inf
%COMMON_PROGRAMS%\japanese keywords\uninstall.lnk
%WINDOWS%\downloaded program files\cnsminsv.cab
%WINDOWS%\downloaded program files\cnsio.dll
%WINDOWS%\downloaded program files\cnsminex.dll
%PROFILE%\recent\jword plugin.lnk
%WINDOWS%\downloaded program files\cnsminidn.cab
%WINDOWS%\downloaded program files\cnsup.ini


Registered Dll (Dynamic Link Library) Signatures:
N/A

Folder Signatures:
N/A

Registry Signatures:
HKCR\clsid\{b83fc273-3522-4cc6-92ec-75cc86678da4}
HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/cnsmin.dll
HKCR\interface\{df692509-d9ef-48a0-9cd0-3aa5b81f6f68}
HKLM\software\microsoft\internet explorer\extensions\{5d73ee86-05f1-49ed-b850-e423120ec338}
HKCR\cnshelper.ch
HKLM\software\microsoft\internet explorer\advancedoptions\!cns
HKCR\cnshelper.ch.1
HKLM\software\microsoft\windows\currentversion\uninstall\cnsmin

SpyNoMore Collected Residual File Signatures:
N/A


See Also:
Spyware/Unclassified.103
Trojan/P2E.ai
Trojan/PSGuard
Backdoor/BackDoor-YQ
Toolbar/Snap UltraSearch
Trojan/BAT.FTPDownloader
Trojan/Bambo.BS
Trojan/PSW.Bancos.AKT
Trojan/Boxed.BB
Trojan/Centim.AU

Spyware Removal Home | Support | F.A.Q. | Contact Us | Spyware Removal Database | Privacy Policy | Site Map
Copyright © 2005-2008 Illysoft LLC