Ravmon.exe Virus
Ravmon.exe file is a backdoor.trojan, or called as W32/Rjump. Symptoms of infection:
- When open pen drive or external hard disk content, very slow.
- When open above devices, found there is a extra folder called RavMonLog, which content only string of number ( backdoor opened port number )
- When right click above devices, invalid character appears in the menu.

To get rid of it is not very hard, it can be manually done without using any anti-virus software.
1. G to Task Manager, click Processes tab and find the progam named “SVCHOST.EXE”, there will few more svchost in small case but you have to terminate the one which is written in CAPS, if you see more than one “SVCHOST.EXE” (all caps one) end the one with your username infront of it instead of LOCAL SERVICE, NETWORK SERVICE or SYSTEM.
2. You need to show system protected files in order to delete the infected files. Go to My Computer–>(Menu)Tools–>Folder Options>(Tab)Views–>Uncheck “Hide System protected files”–>Press OK
If you are unable to unhide the system files you can use 3rd party softwares to browse drive and delete files, try ACDsee or WinRAR.
Delete below two files from all of drives.
- Autorun.inf
- Ravmon.exe
3. Open Windows folder and delete SVCHOST.EXE, SVCHOST.dll and MDM.exe.
Now restart the explorer.exe process by killing it in taskmanager and run it again [(winkey + R), type “explorer” and hit enter].
4. Right-click on any drive and you will find valid characters appears on your menu
Chinese guide on manually remove the virus can be obtain here.















on
on
on
on 