有问题的进程
C:\WINNT\QWRtaW5pc3RyYXRvcg\command.exe
C:\Program Files\Network Monitor\netmon.exe
修复
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINNT\system32\khfgdda.dll
O2 - BHO: (no name) - {AB2BEE46-5677-4E8C-A1E9-A22B9D934358} - C:\WINNT\system32\sstro.dll
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [defender] C:\\dfndrfg_7.exe
O4 - 启动项HKLM\\Run: [keyboard] C:\\kybrdfg_7.exe
O4 - 启动项HKLM\\Run: [newname] C:\\nwnmfg_7.exe
O20 - Winlogon Notify: IntlRun - C:\WINNT\system32\UBERENV.DLL (file missing)
O20 - Winlogon Notify: AdminDebug - C:\WINNT\system32\p6n80g5ue6.dll
O20 - Winlogon Notify: IPConfTSP - C:\WINNT\system32\mvafd.dll (file missing)
O20 - Winlogon Notify: khfgdda - C:\WINNT\SYSTEM32\khfgdda.dll
O20 - Winlogon Notify: ljjihfd - C:\WINNT\SYSTEM32\ljjihfd.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINNT\system32\mvafd.dll (file missing
O20 - Winlogon Notify: rqrsrro - rqrsrro.dll (file missing)
O20 - Winlogon Notify: Shell Extensions - C:\WINNT\system32\rjsutils.dll (file missing)
O20 - Winlogon Notify: ShellScrap - C:\WINNT\system32\rjsutils.dll (file missing)
O20 - Winlogon Notify: sstro - C:\WINNT\system32\sstro.dll
O23 - NT 服务: Command Service (cmdService) - Unknown owner - C:\WINNT\QWRtaW5pc3RyYXRvcg\command.exe
O23 - NT 服务: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
删除文件
C:\WINNT\QWRtaW5pc3RyYXRvcg\command.exe
C:\Program Files\Network Monitor\netmon.exe
禁止服务