Ravmon Logs

Bravestar

Senior Member
Joined
Feb 26, 2007
Messages
665
Reaction score
0
I've got this virus/whatever it is....

RAVMON, how can I rmove this fom my PC?

USB stuff can't open and PC is getting very slow...

Please help... :(
 
Kill it in task manager, then delete from Windows directory and the USB drive, (it's hidden, so you have to turn on, 'Show Hidden files' in Explorer

And, stop putting your stick into strange holes!! ;-)
 
ahhh the ravmon, ever so popular, most irritating virus/software

i got a file 2... called "q.com" does the same thing, how do i get rid of it...?

my anti-virus gets rid of ravmon but not this one...sofar its the only virus my anti-virus cant pick up.....

need help plz
 
got the q.com one as well, anti-virus doesn't pick it up either.

Look for amvo.exe and amvo0.dll files in \windows\system32 directory and delete them, both are hidden so it's best to open a command prompt and use dir /a:h to find them.
 
got the q.com one as well, anti-virus doesn't pick it up either.

Look for amvo.exe and amvo0.dll files in \windows\system32 directory and delete them, both are hidden so it's best to open a command prompt and use dir /a:h to find them.

i found then with command prompt but now when i use the del function it says cannot find file :confused:
 
need to change the file attributes first

attrib -r -a -s -h amvo.exe
attrib -r -a -s -h amvo0.dll

might need to kill it in task manager first
 
i got rid of the amvo.exe
but acces denied for the dll file....

and nothing in my task manager
 
ok now im angry, not both my hdd r doing it, i deleted the file and still doing it... i deleted both

HELP
 
ive even e-mailed my anti-virus ppl, informing them bout it so ja
lets wait and see
 
Last edited:
hey all my drives are now cured... yay now i dnt need to format... finally a solution..

but

just the one HDD is fixed my big baby that i dnt want to format

still got it on my small one, my primary hdd
this is what cmd says

not ressetting hudden file - C:\autorun.inf
not ressetting hudden file - C:\boot.ini
not ressetting hudden file - C:\IO.SYS
not ressetting hudden file - C:\MSDOS.SYS
not ressetting hudden file - C:\NTDETECT.COM
not ressetting hudden file - C:\ntldr
not ressetting hudden file - C:\pagefile.sys

after doin this attrib -s -a -r....any suggestions

the same files appear on my big baby but it ddnt give this msg... and i just deleted those files....

well my only problem is or so i think is i need 2 delete the autorun.inf to solve my problem.. can any1 plz say what the other files are 4? thanx

:(:(:confused::confused::(:( :eek:
 
not ressetting hudden file - C:\autorun.inf
not ressetting hudden file - C:\boot.ini
not ressetting hudden file - C:\IO.SYS
not ressetting hudden file - C:\MSDOS.SYS
not ressetting hudden file - C:\NTDETECT.COM
not ressetting hudden file - C:\ntldr
not ressetting hudden file - C:\pagefile.sys
after doin this attrib -s -a -r


#1. Autorun.inf.. open that in notepad, paste the contents here..
#2. Your Boot.ini is a super protected file, should be reading similar to this:
post the contents here and I will tell you if it is fine
Code:
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

#3. IO.sys.. no worries about that one aswell, but open it in notepad and paste contents here, just to be sure

#4. open it in notepad and paste contents here, just to be sure

#5. NTLDR and boot.ini are brothers, very difficult to infect this - it has to do wit your bootsectors, should be okay if it does not change attrib

#6. Pagefile.sys.. that is just your pagefile (temp memory -RAM- Alternative taken from Hard drive space
 
Autorun.inf--look at this... i cant delete it... help:mad:

;JAakKsS0l7AdelOD
[AutoRun]
;Lf7Fw2joaa3krAaq45
open=q.com
;afLkJwaiLL24DqdskAooil3sZSkwwDo1KK9wKLlkda4oj4mDZfrj72rikwrLwkCKS5c9D352r7d02siA3dSl2
shell\open\Command=q.com
;fq3f2Dfk0qKiw4L3sokK9oaK6aeXkdadLoOpJok230aqIqissHKjijSas7aA93
shell\open\Default=1
;DsJ0li5seoLalLwqdlasw1LwK2H2Ji3UKo
shell\explore\Command=q.com
;1FasAqa53iwe1Aa3JLDdks75aLrkk9CK2s1oie0wcal3SjjKais1l6L2fo49KiaAD4s75r5Sklwr8U824d3awZ27Jk4ossjeaw3lLJ5dlDKK

Boot.ini

[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

IO.SYS

Empty

MSDOS.SYS

Empty

netdetect.com

doesn't open

rest dnt open casue beung used by another process
 
Top
Sign up to the MyBroadband newsletter
X