Solution:
1. Turn off the system restore before antivirus:
Right-click My computer, properties, system restore, turn off system restore on all drives and check it.
Clear IE's temporary files:
Open IE Click Tools --> Internet Options: Temporary Internet files, click the "Delete File" button, and delete all offline content, and click OK to delete.
Restart the computer and then enter safe mode to perform the following operations
--------------------------------------------------------------
All the following operations are required in safe mode.
[Enter safe mode: Press and hold F8 when restarting the computer and select to enter safe mode]
--------------------------------------------------------------
2 SREng Delete the following items:
Start the project --> The following items of the registry
[
Code:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ravtask><C:\Progra~1\Eset\> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{1A404685-7563-4d02-B0F6-58B308A406A9}><c:\docume~1\admini~1\locals~1\temp\> []
Start the project --> Services --> Win32 service application
Code:
[Windows DHCP Service / WinDHCPsvc]
<C:\WINDOWS\system32\ ,start><Microsoft Corporation>
Manually delete the virus files mentioned above
Code:
C:\Progra~1\Eset\
c:\docume~1\admini~1\locals~1\temp\
c:\windows\
1. Turn off the system restore before antivirus:
Right-click My computer, properties, system restore, turn off system restore on all drives and check it.
Clear IE's temporary files:
Open IE Click Tools --> Internet Options: Temporary Internet files, click the "Delete File" button, and delete all offline content, and click OK to delete.
Restart the computer and then enter safe mode to perform the following operations
--------------------------------------------------------------
All the following operations are required in safe mode.
[Enter safe mode: Press and hold F8 when restarting the computer and select to enter safe mode]
--------------------------------------------------------------
2 SREng Delete the following items:
Start the project --> The following items of the registry
[
Code:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ravtask><C:\Progra~1\Eset\> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{1A404685-7563-4d02-B0F6-58B308A406A9}><c:\docume~1\admini~1\locals~1\temp\> []
Start the project --> Services --> Win32 service application
Code:
[Windows DHCP Service / WinDHCPsvc]
<C:\WINDOWS\system32\ ,start><Microsoft Corporation>
Manually delete the virus files mentioned above
Code:
C:\Progra~1\Eset\
c:\docume~1\admini~1\locals~1\temp\
c:\windows\