Home » Post Item » Removing Ravmone.exe in your PC and Flash Drive
Removing Ravmone.exe in your PC and Flash Drive
August 17, 2007
Upon execution, it creates a copy of itself into the windows system directory:
%Windir%\RAVMON.EXE
Also create a non-malicious "RavMonLog" file that contains the
port number on which its backdoor component listens.
Adds the following values to the registry to auto start itself when Windows starts.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
"RavAV" = "%Windir%\RAVMON.EXE"
Indications of Infection
Removing Ravmone.exe in your flash drive
1. CTRL-ALT-DEL
2. click task manager. click on processes tab.
3. end all processes named Ravmone.exe except for one.
(magtira ka ng isa. usually more than one ang nakarun)
4. Open your flash drive in explorer and look for the file
ravmone.exe (be sure that hidden files are viewable) .
In the task manager, end the remaining ravmone.exe process.
Quickly switch back to your flash drive and delete
the file ravmone.exe.
5. Delete the file autorun.inf in the flash drive.
search the net for any backup autorun.inf for flashdrive
and replace your infected autorun.inf file.
To remove ravmone in your pc.
Follow 1-3
4. Goto c:/windows in explorer and look for the file ravmone.exe
(be sure that hidden files are viewable) . In the task manager,
end the remaining ravmone.exe process. Quickly switch back to
c:/windows and delete the file ravmone.exe.
credited by : Sir Billie










i want the some information windows vista and windows xp. pls help me
Posted by Muhammad Riaz Ahmed at April 2, 2008, 2:17 pm