官网下载费尔木马强力清除助手,勾选“抑制文件再生”删除。
http://dl.filseclab.com/down/powerrmv.zipC:\WINDOWS\system32\drivers\gd.sys
C:\WINDOWS\system32\lofsajbo.dll
C:\WINDOWS\system32\yxcsbhlp.dll
C:\WINDOWS\system32\ptjhchlp.dll
C:\WINDOWS\system32\mndscsrv.dll
C:\WINDOWS\system32\oohxbbyt.dll
C:\WINDOWS\system32\zptlbsys.dll
C:\WINDOWS\system32\ypcqchlp.dll
C:\WINDOWS\system32\yzztdmsn.dll
C:\WINDOWS\system32\zxmsawin.dll
清理后,用sreng删除下列驱动
[gd / gd][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\gd.sys><N/A>
用sreng删除下列浏览器加载
[]
{170165F1-9F65-569F-F895-F14F58F41071} <C:\WINDOWS\system32\lofsajbo.dll, N/A>
[]
{25671234-7890-ABCD-CDEF-567801237652} <C:\WINDOWS\system32\yxcsbhlp.dll, N/A>
[]
{328DF602-9541-A985-210A-984A698C6F23} <C:\WINDOWS\system32\ptjhchlp.dll, N/A>
[]
{37FD640A-158F-48AC-FD14-1597F14A9773} <C:\WINDOWS\system32\mndscsrv.dll, N/A>
[]
{3B1AEF69-DDAE-FDAD-DCAB-698F026ABDB3} <C:\WINDOWS\system32\oohxbbyt.dll, N/A>
[]
{40940F85-F015-14F1-A05F-F69858AC6D04} <C:\WINDOWS\system32\zptlbsys.dll, N/A>
[]
{40AF1289-F140-A140-D012-C1458759FC04} <C:\WINDOWS\system32\ypcqchlp.dll, N/A>
[]
{4490415F-65F8-B5C5-D8BA-9405FB120544} <C:\WINDOWS\system32\yzztdmsn.dll, N/A>
[]
{4A041F13-A111-12A3-B0CF-F99818AA68A4} <C:\WINDOWS\system32\zxmsawin.dll, N/A>
[]
{5A59145F-315D-BC23-AC1F-145DF81A34A5} <C:\WINDOWS\system32\zyzxeime.dll, N/A>