Manual removal of Auto virus

Source: Internet
Author: User
Tags manual tmp file

This log only for the operating system is very skilled administrator, ordinary users please go to download antivirus software

Phenomenon: The move disk cannot be opened, and the traditional method of removing the INF file is not possible!

U Disk Solution:

1, open Task Manager (Ctrl+alt+del or taskbar right click also can), terminate all Ravmone.exe process
2, into the C:\Windows, delete the Ravmone.exe
3, into the C:\Windows, running Regedit.exe, in turn on the left to open hk_loacal_machine\software\microsoft\windows\currentversion\run\, On the right you can see that a value is c:\windows\ravmone.exe and remove it.
4, after the completion of the virus was cleared.

For mobile storage devices, if poisoned, then the folder options operation, all files and folders are displayed, click OK, and then in the mobile storage device will see the following several files, Autorun.inf,msvcr71.dl,ravmone.exe, all deleted, there is also a suffix of. tmp file, can also be deleted, when finished, the virus is cleared.

So far, the "Trojan" on your machine is completely lifted.

Now is your mobile facility, first you unplug your mobile facility, insert again (this step is not less). On my computer, hold down the right mouse button on the letter. Check if the first option is "Auto" and if it is, it is already in the middle of the horse, if not, you can safely double-click the use.

If it is "Auto", there are currently two solutions:

1, format the mobile facilities, the method to remove a more thorough, suitable for a small number of documents, space, mobile facilities, the format of the problem completely resolved

2, right click to select "Open" (Do not double-click to open, otherwise the Trojan will be replicated), find the RavmonE.exe file, autorun file, super text to fot the beginning of the file, all delete (autorun, super text to fot as hidden, Can be at the top of my Computer window-Tools-Folder Options-View-show all hidden files Let it display, in the determination of the above file, exit the U disk, and then insert check whether there is "Auto", if not, then delete success.

To sum up:

1, to avoid this kind of Trojan only in the open mobile facilities when the right key-open to enter, so copy or open the file will not be infected, Trojan transmission is "double click on the disk letter."

2, by observing whether there is "auto" to determine whether the disk has been such a trojan, and then through the "auto" solution to deal with.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.