I have been asked by a friend on what type of virus got them. There is a message that displays on the computer upon start up with the following text:
Window Title: Doomsday Has Come
Message: YOU ARE iNFECTED BY RAVO_5002
I cannot reply to them until McAfee released the definition for this type of infection which they called W32/Vora.worm!p2p.
For sure, the next question will be “How to remove W32/Vora.worm!p2p?”
27 Responses for "Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002"
DOOMSDAYS HAS COME: you have been infected by ravo_5002
How to Remove Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002:
I want to know what I have to do to remove this virus Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002. I have all ready scan my computer but my antivirus can not dettecte it.
I was also infected by the bravo, Mcafee couldn’t detect it. I did the following: (Please dont do this if you are not an advanced user.)
(You have to be administrator to do this)
Click start then run
on the box that appear type regedit then enter
click on edit then find
on the popup box type protector
It will find the entry for doomsday. Delete it.
close the regedit and your good to go.
If still having problems let me know.
i have been infected by RAVO_5002, how can i clear it or what anti-virus can i use to clear it on computer.
I followed the process of deleting “Dommsday Has Come” thus RAVO 5002 through the regeidt. Still the problem persits. Please kindly help to get rid of the virus.
Thank you
To do away with this infection, Go to run, Type cmd, At the command prompt, change to drive c: and type attrib ENTER. I am sure protector.exe and autorun.inf with attrib SHR will be among the files listed. Then type attrib -s -h -r ENTER.
After that type del protector.exe and del autorun.inf
They are now deleted from your machine.
Pendrives easily carry them. Insert it and change to it’s drive letter and start the process.
NB
DO NOT OPEN THE PENDRIVE
my system is infected with ravo 5002.but then paulin agdemelo gave a solution but l have tried and the command attrib in cmd acommand apears to be not recognise as internal or external command.
my system is infected with ravo 5002.but then paulin agdemelo gave a solution but l have tried and the command attrib in cmd acommand apears to be not recognise as internal or external command.please help me out urgent.
is there any anti-virus to remove this infection.
Narworld, can you please tell what to do after typing in ‘protector’? explain yourself more.
I have also tried the above recommendations but none of them seems to be able to remove the infection. Could you please help me out. Is it spreading in this area like gangrene.
i have ravo on my machine and i dont know how to get rid of it.please help me
i just got infected with this toublesome virus. have tried all of the above but the message i get is access denied. Had it 26-11-08
i have this on my screen always poping up and i dont what to do,if any one have idea pls do let me know
i have been infected by ravo_5002. i’ve used the registry edit but i’m still having the problem of dooms day as come
i have a problem i have this virus on my pc ”DOOMSDAY HAS-COME-YOU ARE INFECTD-BY-RAVO_5002” and macafee enterprise updated edition seems do not be able to remove it from my pc.Can you please help me out.thanks
Help!!!!! how do i get rid of doomsday
I had this virus, and the following procedure seemed to work in getting rid of it for me. Hopefully it works for you as well.
open command prompt my going Start > Run and typing cmd.
You should be in a directory called something like “C:\Documents and Settings\User”. if you are not, change to it by typing ‘cd’ and the directory above (replacing ‘user’ with your username), and then pressing enter.
type ‘attrib’ and press enter. There should be a file called svchost.exe, and will have the attributes SHR (which stands for System-file, hidden, and read-only).
type ‘attrib -s -h -r svchost.exe’. This removes the SHR properties and allows you to delete the file.
type ‘del svchost.exe’. This should delete the virus from your computer.
NOTE: svchost.exe is a critical system file if it is located in C:\WINDOWS\System32. If it is located elsewhere (as this one is), it is generally a virus.
Then, insert infected pen drives (memory sticks, iPods etc.) which carry the virus. Change the directory to the pen drive by typing ‘E:’(or whatever letter it is) ENTER. Then type ‘attrib’ as above.
there should be the files ‘protector.exe’ and ‘autorun.inf’ which also have the properties SHR. type ‘attrib -s -h -r’ ENTER, and then delete the files by typing ‘del autorun.inf’ ENTER then ‘del protector.inf’ ENTER. This should remove the virus. Autorun.inf might reappear, but this shouldn’t be a problem.
Do not open the pen drive after you insert it, and cancel any autorun windows that come up.
My Pc got infested by the doomsday ravo_5002.
Pls how can i delete it? thanx
1. Download Malwarebytes’ Anti-Malware (mbam-setup.exe) and save it on your Desktop.
2. After downloading, double-click on mbam-setup.exe to install the application.
3. Follow the prompts and install as “default” only
4. Before the installation completes, check on the following prompts:
- Update Malwarebytes’ Anti-Malware
- Launch Malwarebytes’ Anti-Malware
5. Click “Finish.” Program will run automatically and you will be prompt to update the program before doing a scan. Please update.
6. Scan your computer thoroughly.
7. When scanning is finished click on the “Show Results”
8. Make sure that all detected threats are marked, click on Remove Selected.
9. Restart your computer.
Note: Some malware may prevent mbam-setup.exe from downloading and running. You can download and rename this program from a different computer before running it on infected system.
I’VE BEING AFFECTED BY THIS VIRUS AND CAN SOME ONE TELL ME HOW TO DO ABOUT THIS PLEASE.MY MAIL IS NADIA2005LOVE@YAHOO.COM.I NEED YOUR HELP.
Yeah, the easiest way to do it is with DOS
We have this virus going around in my school and we(kids that get constantly asked to take it off) have gotten so annoyed were just distributing a simple batch file to take it off.
But yeah the basics of taking it off are
attrib -s -h -r
attrib
read it, if any of the following are there delete them,
del svchost.exe
del protector.exe
del autorun.inf
You may notice that some of the programs will be in the C drive and others may be in the flashdrive
just type in
E:
or F:
or whatever the flashdrive is
than do the same
If it tells you its not a recognized command, your typing it in wrong.
If it tells you access denied(a common thing at school due to so many freaking things being blocked),
you may have to restart your computer.
Note: Use the Task Manager to end the process of Doomsdayhascome before doing any of this.
Note: You may have to delete them in a certain order for granted access, such as
del protector.exe
del autorun.inf
del svchost.exe
This is extremely freaking basic.
If your downloading any programs for this your just wasting your time and your harddrive space.
Temporary Solution - can be used as Permanent.
Click Start
Click Run
Type msconfig then Press Enter
on Startup tab uncheck the Svchost in the list
Click Apply and Close and Restart your computer.
thanks Alexander Mc, I have removed it :)
My computer has infested by the doomsday ravo_5002.
Pls how can i delete/scan it? please i need your help thanx
my E.mail is ashitiok@yahoo.com
Infacted by RAVO
Any Response?
Can't Find a Solution?
Start a Discussion Here!