用xdelbox重启后删除
C:\WINDOWS\system32\Drivers\PauseDrv.sys
c:\windows\system32\drivers\aejihsh.sys
c:\windows\system32\drivers\ferdr.sys
在注册表[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
中删除
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><> [N/A]
用SReng删除服务-驱动程序
[PauseDrv / PauseDrv][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\PauseDrv.sys><N/A>
[aejihsh / aejihsh][Running/Boot Start]
<\SystemRoot\system32\drivers\aejihsh.sys><>
[ferdr / ferdr] <\??\C:\WINDOWS\system32\Drivers\Ferdr.sys>
用SReng删除浏览器加载项
浏览器加载项
[]
{00000055-9980-0010-8000-00AA00389B71} <, >
[]
{00000055-9980-0010-8000-00AA00389B71} <, >
[]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, >
[]
{1B2F92A1-CDAF-4511-9382-91E3F5CE0880} <, >
[]
{507F9113-CD77-4866-BA92-0E86DA3D0B97} <, >
{55302805-482E-470E-8A57-6795A1487F90} <, >
[]
{59BC54A2-56B3-44A0-93E5-432D58746E26} <, >
[]
{5D73EE86-05F1-49ED-B850-E423120EC338} <, >
[]
{6354ABE6-05F1-49ED-B850-E423120EC338} <, >
[]
{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <, >
[]
{BB936323-19FA-4521-BA29-ECA6A121BC78} <, >
{C95FE080-8F5D-11D2-A20B-00AA003C157B} <, >
[]
{D157330A-9EF3-49F8-9A67-4141AC41ADD4} <, >
[]
{DEDEB80D-FA35-45D9-9460-4983E5A8AFE6} <, >
[]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, >
[]
{E847C78C-C210-4195-8799-FBF3BF89797D} <, >
[]
{ECF2E268-F28C-48D2-9AB7-8F69C11CCB71} <, >
[]
{EF72500A-C234-46C4-BF0A-9AA6913DDF34} <, >
[]
{FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <, >
[]
{FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[]
{FD00D911-7529-4084-9946-A29F1BDF4FE5} <, >