你的是笔记本电脑以下我不认得启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<pop><C:\WINDOWS\help\runauto.vbs> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{C3D16072-2E1B-450B-B843-50EADDC8EB63}><C:\WINDOWS\system32\bnmhggo0.dll> [File is missing]
<{189F087F-4378-405F-85FA-37D955AD7A8C}><C:\WINDOWS\system32\mtewdh.dll> [File is missing]
<{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}><C:\WINDOWS\system32\wklsdd.dll> [File is missing]
<{6C648541-1025-9650-9057-6541258720C6}><> [N/A]
<{DC3D30AE-0380-4151-8934-EE98A34B0370}><> [N/A]
<{50940F85-F015-14F1-A05F-F69858AC6D05}><> [N/A]
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><> [N/A]
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><> [N/A]
<{45AADFAA-DD36-42AB-83AD-0521BBF58C24}><> [N/A]
<{35671234-7890-ABCD-CDEF-567801237653}><> [N/A]
<{528DF602-9541-A985-210A-984A698C6F25}><> [N/A]
<{80AF1289-F140-A140-D012-C1458759FC08}><> [N/A]
<{CAED0F3B-DF8B-4DBF-BB20-8DFBC3199068}><C:\WINDOWS\system32\jggtsr.dll> [File is missing]
<{C490415F-65F8-B5C5-D8BA-9405FB12054C}><> [N/A]
<{B490415F-65F8-B5C5-D8BA-9405FB12054B}><> [N/A]
<{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}><C:\WINDOWS\system32\jfdses.dll> [File is missing]
<{5A069845-2036-6084-9054-6087502480A5}><> [N/A]
<{4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4}><C:\WINDOWS\system32\tdggrz.dll> [File is missing]
<{25FD6584-698F-BCD2-602C-698745210352}><> [N/A]
<{5D098345-6785-1098-5413-678067AE03D5}><> [N/A]
<{32596546-2036-9451-6058-658402589723}><> [N/A]
<{52023698-6984-8541-9654-698745012525}><> [N/A]
<{38093456-9012-4568-9076-908765467183}><> [N/A]
<{87FD640A-158F-48AC-FD14-1597F14A9778}><> [N/A]
<{470165F1-9F65-569F-F895-F14F58F41074}><> [N/A]
<{B29583D8-033A-4B9F-8553-7C5458F3FB8E}><C:\WINDOWS\system32\jdsaex.dll> [File is missing]
<{30618412-C528-C784-C056-C164D1F7C503}><C:\WINDOWS\system32\detxciua.dll> [File is missing]
<{2A698452-C5D8-C584-C256-C264C987C5A2}><> [N/A]
计划任务
[已启用] 4e5sc.job
rundll32
[已启用] 4e5dc.job
rundll32
[已启用] 4e5b.job
rundll32
[已启用] 4e5ac.job
rundll32
==================================
隐藏进程
[480] C:\WINDOWS\mtyvkdgw.exe
[Invoke Class]
{7ECF71AD-0663-4c49-BBDA-FAE8EF65E67D} <C:\WINDOWS\system32\1rge.dll, N/A>
[BHO Class]
{1307E689-5CA1-4A15-9583-F2350790290D} <C:\WINDOWS\system32\geu.dll, N/A>
C:\WINDOWS\system32\ESPI11.dll
d:\文档\暑假实习实践报告4297228.dll
d:\驱动\thunder5.7.11.486\thunder5.7.11.4864297228.dll