C:\WINDOWS\system32\setupsrv.exe是间谍程序
用于远程控制
修复
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [Winntsrv] C:\WINDOWS\system32\setupsrv.exe
O4 - 启动项HKLM\\RunOnce: [*Winntsrv] C:\WINDOWS\system32\setupsrv.exe
O4 - HKCU\..\Run: [Winntsrv] C:\WINDOWS\system32\setupsrv.exe
O4 - 启动项HKCU\\RunOnce: [*Winntsrv] C:\WINDOWS\system32\setupsrv.exe
删除
C:\WINDOWS\system32\setupsrv.exe