I don't know when, when I open IE to browse the Web page, I always pop up a MMS advertisement, which is a MMS advertisement for a8.com. CTRL + n. When I saw the website, the hacker did not respond at all, I made an advertisement fee for 138y.com, and checked the registry carefully.
\ HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
An additional system item is found to start c: \ windows \ iw.e. EXE, but this is not the real IE browserProgram!! Good guy, I don't have to hesitate to delete this pseudo System in the registry from the command window.
Rename c: \ windows \ i0000e. EXE c: \ windows \ i0000e. EXE. sb
Then del c: \ windows \ iw.e. EXE. sb
Restart the machine to check whether there are no damn 138y.com ads.
Finally\ HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
All users are read-only!
Source: http://blog.toohi.com/toohi/articles/469.html