|
I hav been hit by the same thing this past few days, plus that cfsb.exe infostealer.
Had a busy week myself.
Symantec has a good fix on this and hav named it w32.Rajump.
How ever their fix does not delete the AutoRun.inf that hides itself with Ravmone.exe in the root directory of your drives.
Change their attrib in dos to delete them manually.
And if there ar funny symbols that appear in opening the drives under My Computer,
Enter the registry under Mountpoints2 and delete those shells that point to them.
These thing jump from USB to USB, and posseses the Floppy Drive to turn themselves on and infec any disk in them with a hidden Ravmone.exe.
I hope this is the same Ravmone variation we hav.
Reports hav it they originated from China, installd on a load of ipods Mcdonalds gave away. Which probably explains those funny symbols on opening those hardrives which also actually launches the virus.
. |