F3 - REG:win.ini: run=C:\WINDOWS\services.exeO4 - HKLM\..\Run: [services] C:\WINDOWS\services.exeO4 - HKLM\..\RunServices: [services] C:\WINDOWS\services.exeO4 - HKCU\..\Run: [services] C:\WINDOWS\services.exeO4 - HKCU\..\RunServices: [services] C:\WINDOWS\services.exeservices.exe应该在system32目录下,这个一看就知道是个伪装的恶意文件。