Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Serious Ravmon.exe
   
BullGuard Antivirus Forum > Virus Removal > Removal Tools > Serious Ravmon.exe  
Forum Quick Jump
 
New Topic Post reply to : Serious Ravmon.exe Printable version of : Serious Ravmon.exe
[ << Previous Thread | Next Thread >> ]

Hot Male
New Member


Date Joined Apr 2007
Total Posts : 2
 
   Posted 4-22-2007 8:36 (GMT +1)    Quote: Serious Ravmon.exeAlert an admin about: Serious Ravmon.exe
hey I am getting a big problem with Ravmon.exe
I am attaching the scrnshot of my registry editor coz I dont knw the typical methods to transfer informations like registry.
The expandable keys in mountPoints2 belongs to the partitions in My Computer. As you can see there is some unknown language in the data and in "command key" there is written "RavMon.exe-e". If I delete the "shell" key everything becomes normal untill next reboot. All the 5 keys are automatically created on my next boot ( I have 5 drives in my computer) and I also delete "Ravmon.exe" but its present in every drive of My hard disk on next reboot. The other things is that I cant show hidden files and my computer becomes open for spywares and malwares if I uninstall norton (I have Norton Protection Centre - 2007 - Trial Version Installed). Please give me a permanent Solution for my problem. Also I scanned my pc with
 
spyware doctor
registry mechanics
Ad-aware SE Pro
 
but they didnt detect the Ravmon
 
here is the sample key of one drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{27497547-e68a-11db-9ae1-806d6172696f}\Shell\AutoRun\command
 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{27497547-e68a-11db-9ae1-806d6172696f}\Shell\explore\Command
 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{27497547-e68a-11db-9ae1-806d6172696f}\Shell\open\Command
 
these are the three sub keys in the key named "shell"
 
Sorry for bad English

Post Edited (Hot Male) : 4/22/2007 7:45:48 PM GMT



Image Attachment :
Image Preview
reg.JPG
  83KB (image/pjpeg)
This image has been viewed 639 time(s).
Back to Top
 

King Khan
New Member


Date Joined Apr 2007
Total Posts : 1
 
   Posted 4-30-2007 11:01 (GMT +1)    Quote: Serious Ravmon.exeAlert an admin about: Serious Ravmon.exe
HI HOT MALE ....

First U Have To Hit CTRL+ALT+DEL Key To Enter In Task Manager ... Go To Processes And End Process Ravmon.exe File ...

Second Step Go To C:\WINDOWS\RAVMON.EXE Delete It

Third Step Go To Start -> Search -> Files And Folder -> And Type Ravmon.exe And Search It Including System Hidden Files And Folders ...

If This Method Does Not Help U Then I Will Give U Another Method ...

Sorry For Bad English .... :)
Back to Top
 

asaygo
Junior Member


Date Joined Apr 2007
Total Posts : 60
 
   Posted 5-8-2007 12:48 (GMT +1)    Quote: Serious Ravmon.exeAlert an admin about: Serious Ravmon.exe
You may want to try the cleaning instructions that can be found in the BullGuard Techguides at How to remove the Ravmon.exe

Post Edited (asaygo) : 11-06-2007 05:27:03 GMT

Back to Top
 

Hot Male
New Member


Date Joined Apr 2007
Total Posts : 2
 
   Posted 5-22-2007 10:33 (GMT +1)    Quote: Serious Ravmon.exeAlert an admin about: Serious Ravmon.exe
I can delete it from a single PC but cant delete it from a network and when I attach a USB Flashdrive or anyother infective harddrive to my pc my pc again gone infected I use the following method
 
delete Autorun.inf
delete Ravmon.exe
delte copy.exe (if found)
 
.....from all the drives and
delete the "shell" key from HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
 
and turn off system restore
Back to Top
 

Antonio22
New Member


Date Joined May 2007
Total Posts : 3
 
   Posted 5-25-2007 2:08 (GMT +1)    Quote: Serious Ravmon.exeAlert an admin about: Serious Ravmon.exe
I had the same problem.
I ran a scan with symantec,
 
However, the virus has a hidden file "autorun.inf" in the root directory.
The file contains autorun= ...ravmon.exe
which also probably screwd your hidden file folder options from appearing.
 
Change its attrib -h in dos, delete, rename or fiddle around with it, then your done.
 
 
Back to Top
 

waller540
New Member


Date Joined May 2007
Total Posts : 4
 
   Posted 5-31-2007 5:18 (GMT +1)    Quote: Serious Ravmon.exeAlert an admin about: Serious Ravmon.exe
I was looking for the best antivirus software to buy the other day & came across this site: www.notgettingscammed.co.uk/antivirus
it has loads of great unbiased information. All Free, check it out
Back to Top
 

farihabest
New Member


Date Joined Oct 2007
Total Posts : 2
 
   Posted 10-26-2007 8:09 (GMT +1)    Quote: Serious Ravmon.exeAlert an admin about: Serious Ravmon.exe
Hi friends..
Assalam o Alikom
I am farimarwat from Lakki Marwat in pakistan. Do not worry about these fakes. These are two files that run in your pc. One is AutoRun.inf and the seconed is RavMon.exe. The work of AutoRun.inf is to run the RavMon.exe and add some unknown languages to your drive menu. And when RavMon.exe runs, it creat a file in windows directory MDM.exe. so I have made a tool to burn that fakes withour MDM.exe. Download the tool from here www.geocities.com/farimarwat/setup.zip
the tutorial is also in the tool. simply install the "Fari Auto Play Burner 2007" and scan drives for that fakes
farimarwat
lakkki marwat
pakistan
Back to Top
 

farihabest
New Member


Date Joined Oct 2007
Total Posts : 2
 
   Posted 10-26-2007 8:16 (GMT +1)    Quote: Serious Ravmon.exeAlert an admin about: Serious Ravmon.exe
I have tested the above link but does not existe please right click and then "Save target as " it will start

www.geocities.com/farimarwat/setup.zip
Back to Top
 

justinnn



Date Joined Oct 2008
Total Posts : 0
 
   Posted 10-13-2008 6:40 (GMT +1)    Quote: Serious Ravmon.exeAlert an admin about: Serious Ravmon.exe
Hi, I Do have a solution regarding your problem. All you have to do just go to your command Prompt. Go to any drive of your system and write dir /ah when you press enter key it will display the hidden files of that drive. now type the following command i.e. del /ah racmon.exe and press enter key. So in this way you can erase ravmon.exe from your system. By folllowing this command you can also erase autorun.inf,nmtumef.exe and copy.exe too. So go for it, its quiet simple and easy one.
Ba bye
Hot Male said...
hey I am getting a big problem with Ravmon.exe
I am attaching the scrnshot of my registry editor coz I dont knw the typical methods to transfer informations like registry.
The expandable keys in mountPoints2 belongs to the partitions in My Computer. As you can see there is some unknown language in the data and in "command key" there is written "RavMon.exe-e". If I delete the "shell" key everything becomes normal untill next reboot. All the 5 keys are automatically created on my next boot ( I have 5 drives in my computer) and I also delete "Ravmon.exe" but its present in every drive of My hard disk on next reboot. The other things is that I cant show hidden files and my computer becomes open for spywares and malwares if I uninstall norton (I have Norton Protection Centre - 2007 - Trial Version Installed). Please give me a permanent Solution for my problem. Also I scanned my pc with
 
spyware doctor
registry mechanics
Ad-aware SE Pro
 
but they didnt detect the Ravmon
 
here is the sample key of one drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{27497547-e68a-11db-9ae1-806d6172696f}\Shell\AutoRun\command
 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{27497547-e68a-11db-9ae1-806d6172696f}\Shell\explore\Command
 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{27497547-e68a-11db-9ae1-806d6172696f}\Shell\open\Command
 
these are the three sub keys in the key named "shell"
 
Sorry for bad English
Back to Top
 
New Topic Post reply to : Serious Ravmon.exe Printable version of : Serious Ravmon.exe
 
Forum Information
Currently it is Saturday, November 22, 2008 1:28 PM (GMT +1)
There are a total of 64.046 posts in 15.836 threads.
In the last 3 days there were 26 new threads and 154 reply posts. View Active Threads
Who's Online
This forum has 27196 registered members. Please welcome our newest member, Catlady UK.
46 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Generic.PWS.WoW.B7078E0 (16)22-11-2008 11:55:15 (Behram)
Redirecting virus? (5)22-11-2008 10:29:08 (r1ch1e)
Help please!!! (15)22-11-2008 10:05:45 (Touch)
HELP I AM GOING MAD (5)22-11-2008 06:51:49 (Touch)
Win 32-trojan-gen (17)22-11-2008 05:29:27 (Touch)