...the logfile 'C:\windows\RavMonE.exe.log' for details"怎么回事...
发布网友
发布时间:2024-10-23 08:21
我来回答
共3个回答
热心网友
时间:2024-11-07 05:23
中了假冒瑞星的RAVMONE病毒,是通过U盘传播的
运行后生成
%windows%\RavMonE.exe(3,515,723 字节)——病毒本身
msvcr71.dll(348,160字节)——库文件,支持病毒运行
RavMoneE.exe.log(644字节)
RavMonlog(5字节)
Autorun.inf(103字节)
2. 添加注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RavAV" = "\%windows%\RavMonE.exe"
3. Autorun.inf内容:
[AutoRun]
open=RavMonE.exe e
shellexecute=RavMonE.exe e
shell\Auto\command=RavMonE.exe e
shell=Auto
用来启动RavMonE.exe
4. RavMoneE.exe.log内容:
Traceback (most recent call last):
File "RavMonE.py", line 1, in ?
File "zipextimporter.pyo", line 78, in load_module
File "twisted\internet\reactor.pyo", line 12, in ?
File "twisted\internet\selectreactor.pyo", line 182, in install
File "twisted\internet\posixbase.pyo", line 168, in __init__
File "twisted\internet\base.pyo", line 268, in __init__
File "twisted\internet\base.pyo", line 568, in _initThreads
File "twisted\internet\posixbase.pyo", line 265, in installWaker
File "twisted\internet\posixbase.pyo", line 77, in __init__
File "", line 1, in listen
socket.error: (10022, 'Invalid argument')
5. RavMonlog内容:
16704 17608 类似的数字
===
清除方法:
1. ctrl+alt+del,打开任务管理器,结束RavmonE.exe进程
2. 删除注册表
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
"RavAV" = "C:\WINNT\RavMonE.exe"
3. 打开“文件夹选项”,在“查看”选项卡中,去掉“隐藏受保护的操作系统文件”前的勾,同时选中“显示所以文件和文件夹”
4. 删除%windows%\RavMonE.exe、msvcr71.dll、RavMoneE.exe.log、RavMonlog
5. 用右键打开U盘,删除包括RavmonE.exe、msvcr71.dll、RavMoneE.exe.log、RavMonlog、autorun.inf
热心网友
时间:2024-11-07 05:22
瑞星出问题了
你那瑞星重装一下。。。
热心网友
时间:2024-11-07 05:25
在关闭电脑之前你是否利用瑞星查杀过病毒?如果查过病毒的话那么这个提示的意思是要你查看一下瑞星的查杀日志,了解详细的查杀情况。