运行SRENG 启动项 注册表
删除[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<9><C:\WINDOWS\system32\Ravdm.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<themeadp><C:\WINDOWS\system32\themeadp.dll> [N/A]
删除 C:\WINDOWS\system32\Ravdm.exe,
C:\WINDOWS\system32\themeadp.dll