O23 - NT 服务: Windows Management Protocol v.0 (experimental) - Unknown owner - Rundll32.exe (file missing)
O23 - NT 服务: _reg - Unknown owner - Rundll32.exe (file missing)
安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索experimental和 _reg 删除...
O4 - 启动项HKLM\\Run: [Realplayer.exe] C:\WINDOWS\system32\Realplayer.exe
参考顶置帖...
修复
F3 - REG:win.ini: run=RAVMOND.exe
O4 - 启动项HKLM\\Run: [Program In Windows] C:\WINDOWS\system32\IEXPLORE.EXE
O4 - 启动项HKLM\\RunServices: [SystemTra] C:\WINDOWS\SysTra.EXE
删除
RAVMOND.exe
C:\WINDOWS\system32\IEXPLORE.EXE
C:\WINDOWS\SysTra.EXE