Job Recruitment Website - Job seeking and recruitment - From time to time, a camouflage advertisement prompt box similar to QQ information will pop up in the lower right corner of my computer. I don't have QQ installed. What poison is it?

From time to time, a camouflage advertisement prompt box similar to QQ information will pop up in the lower right corner of my computer. I don't have QQ installed. What poison is it?

this is very troublesome

It was published by a website called chaxun.com.

Particularly stubborn

At that time, as long as I opened IE, an advertisement would pop up in the lower right corner of the screen, like what QQ members greeted Zhaopin for recruitment. Right-click "Properties" to show that these advertisements are all "/img/* * *". Jpg "address style. I have tried various methods, such as modifying the registry and terminating the system process with a "willow brush", but all of them are useless. It's a mystery which website I got this poison from in the first place. You know, even the portal website can't lead an honest and clean life now, throwing advertisements at random, and other websites have everything.

Solution:

1 and F8 enter the safe mode;

Malicious files and folders related to C: \ Windows \ Downloaded program files.

Key actions:

There are many hidden files in this folder, which cannot be seen in the normal way. You can create a new WINRAR document in this directory and delete related items in the winrar management interface. (That is to say, it is very important to read the documents under the downloaded program files through a compressed file! Otherwise, I really can't see it)

2. directly modify the file name of the program file \ _ is _ 0518 \ _ is _ isc.dll downloaded by% Windows (just change it casually).

3. Restart the computer after the operation

4. After the restart, there will be an error prompt of "advapi32" startup item, saying that the dialog boxes such as files can't be found, just click "OK", which is actually those _ yes _ *. Dll file is not loaded, we can delete it directly! (If there is no pop-up prompt, it means that it has not been changed. Please repeat the previous step. )

Then enter the downloaded program file and delete everything.

Common names and ISC, adv, 05 18, {c85cbfbcf-a5de-1d9-9651-0003ff7e92ce} are all related to chaxun.com. Delete, delete, delete hard!

C:\ _ Yes _ *. *

%ProgramFiles%\ISC\

%Windows%\backup\

% Windows% \ downloaded program file \_IS_05 18\

%System%\msuuid_。 DLL

%System%\msvendr_。 DLL

(delete it when you touch it)

5. Delete c:\windows\backup\ (the virus code is generated by itself, so it cannot be deleted without the previous operation, and it will be automatically restored after deletion).

6. Delete malicious entries in the registry, find keywords "chaxun.com", "_ is _" and "Advapi32" and delete related key values and key entries.

The method is point start = > input = > to open the registry.

Under [HKEY _ local _ machine \ software \ Microsoft \ Windows \ current version \ running], "advAPI 32" = "rundll32c: \ Windows \ downlo ~1\ _ is _ 0518 \ _ is _.

(If you are not familiar with the registry, please go to the next software called Hijackthis, run HijackThis and fix the following items:

04 startup item hklm \ \ run: [advabi32] rundll32c: \ Windows \ downlo ~1\ _ is _ isc.dll.isc. It is also possible).

7. restart.

That thing is really harmful.

Don't download things indiscriminately in the future.

I have put a lot of effort into your reply! Hmm. How interesting