There has been some speculation that perhaps the infected iPods were shipped from a "contract manufacturer", using Apple's words, in China, but I've not seen any confirmation of that.

Security best practices dictate that administrators should restrict file formats commonly associated with malicious code from entering the corporate network. RavMonE was made famous in September 2006 when a number of iPod videos were shipped with the virus already installed.[1] Because the virus only infects Windows computers, it can be inferred n 2dae, another thumbdrive with ramone got into my usb port....

Configure antivirus products to scan three levels deep on compressed files.

Because of autoplay in thumbdrive devices.

norton said it was moderate difficulty 2 remove... sianz.... It is indeed hard to remove. it will be blocked.

These firewalls can be configured to prompt a user each time a new process or service is attempting to access the Internet or local network. I understand I will receive a complimentary subscription to TechRepublic's News and Special Offers newsletter, and the Daily Digest newsletter (you can opt out at any time). Although the IBM-Sun deal fell apart, expect more tech acquisitions in 2009. Moderator ndmmxiaomayi 54,017 posts since Aug '05 21 Oct `06, 12:45AM Discover a new variant again.

http://download.nai.com/products/mcafee-avert/QQPass-RjumpStinger.zip McAfee Stinger has a standalone tool for removal of this RavMone. Administrators are advised to restrict or block access to all ports not used for normal business operations.

Both types of firewalls may prevent malicious code from downloading updates or additional files. Edit: Note: Disabling autorun only prevents the virus from infecting your system. Apple came under some public criticism for releasing the virus with their product.

Because the trojan attempts to open a back door on a randomly chosen port, it may be difficult to detect.

but disabling norton makes my com fun a whole load faster...

Disable all unnecessary products, features, and sharing.

Moderator ndmmxiaomayi 54,017 posts since Aug '05 20 Oct `06, 7:43AM Originally posted by asdfzhao: well i m back! That old log won't tell me what has happened over the last few days.

And the files that the RavMonE is running, plus the backdoor.Rajump. For removal tools and/or anti-virus programs for Backdoor.Rajump then anti-virus programs and tools from Symantec can remove the virus/malware. Users may download this trojan over P2P networks, FTP servers, or as an e-mail attachment sent from a remote attacker.

Moderator ndmmxiaomayi 54,017 posts since Aug '05 13 Oct `06, 6:57PM Originally posted by asdfzhao: oops cant send .exe file... 4get it....