How to remove RavMonE.Exe

January 18, 2009 by Ang Gu Gu · Leave a Comment
Filed under: Guides 

Lately alot of my friends, even my company’s computer got effected by this trojan called RavMonE. Its so annoying that it will slow your computer down .

So today i shall share how to remove this virus with you all =)

How to know that are you effected by the virus?
-Do a Ctrl + Alt then Del and it will show the Windows Task Manager and from the Processes it will show a program running that is called RavMonE.exe.

What is RavMonE.exe?
- RavMonE is actually a Trojan that opens a backdoor on computers running Microsoft Windows.It creates a copy of itself in the Windows system directory and creates a log file containing the port number on which its back door component listens.

How to remove the trojan RavMonE?
1. Go to your Task Manager and look for a process by the name RavMonE.Exe and end the process by clicking on the End Process button. Sometimes it might be more than one RavMonE.exe process running so you must end all the process by the name RavMonE.exe.

2. Go to your Local Disk : C and then locate the windows folder and click on it.

3. Look for the RavMonE.exe program using the find option or locate it amongs all the files inside windows folder and then delete the program off including the RavMonLog file.

4. Then in the windows folder, look for a folder name “Prefetch” and click on it and see whether inside it got any file with the name RavMonE and remove them as well.

5. RavMonE also leave a startup registry key to your computer so you have to go to the registry editor by going to start > run > then type in regedit and press enter.

6. Now, to go to where we want to delete off the registry key, go to hkey_local_machine > software > Microsoft > Windows > CurrentVersion > Run

7. Find the RavAV subkey and delete it.

That should remove off the RavMonE trojan completely. Alternatively, most of the antivirus will be able to detect this trojan and remove it as well.

But if your thumbdrive or external harddisk got effected by this trojan,

1. Go to tools > folder option > view then click on the Show Hidden Files and Folders

2. Go to your drive that is effected and remove the autorun.inf, msvcr71.dl and RavMonE.exe.

That’s All!

All the best on removing this trojan =)