有问题的注册表项:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{A12BC423-3713-224D-3F55-32B35C62B11A}<c:\windows\system32\tlupri.dll>
{5562452F-FA36-BA4F-892A-FF5FBBAC5315}<c:\windows\system32\myepri.dll>
{90BC520C-9175-470E-94B8-10FD869D170B}<c:\program files\common files\microsoft shared\msinfo\sysinfo.yer>
{D1351752-5628-1547-FFAB-BADC13512AFD}<c:\windows\system32\ztmpri.dll>
{5182C1EB-375C-573D-1F5E-234552345215}<c:\windows\system32\wlhpri.dll>
{959AFD5B-159F-ACD8-954C-ACD545FA6589}<c:\windows\system32\jzipri.dll>
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
<ravmsmon>c:\program files\netmeeting\ravmsmon.exe
<ravdhmon>c:\program files\netmeeting\ravdhmon.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
<AppInit_DLLs>c:\windows\system32\tlupri.dll
有问题的文件:c:\windows\system32\drivers\npf.sys
d:\autorun.inf
d:\sysauto.exe
c:\program files\netmeeting\ravmsmon.exe
c:\program files\netmeeting\ravdhmon.exe
c:\windows\system32\jziins.exe
c:\windows\system32\tluins.exe
c:\windows\system32\wlhins.exe
c:\windows\system32\ztmins.exe
c:\windows\system32\wlhpri.dll
c:\windows\system32\jzipri.dll
c:\windows\system32\ztmpri.dll
c:\windows\system32\tlupri.dll
c:\windows\system32\myepri.dll
c:\windows\system32\mssql.dll
c:\program files\common files\microsoft shared\msinfo\sysinfo.yer
c:\documents and settings\administrator\local settings\temp\rsva.tmp
c:\documents and settings\administrator\local settings\temp\ravsons.exe
c:\documents and settings\administrator\local settings\temp\v7d.dll
c:\windows\system32\ravzxmon.dat
c:\program files\netmeeting\ravdhmon.dat
c:\program files\netmeeting\ravmsmon.dat