<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Iframe Virus jl.chura.pl Removal Todo List</title>
	<atom:link href="http://www.webmastersucks.com/iframe-virus-jl-chura-pl-removal-todo-list/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webmastersucks.com/iframe-virus-jl-chura-pl-removal-todo-list/</link>
	<description>Here I share stuff I used to suck at as a novice webmaster..</description>
	<lastBuildDate>Thu, 03 Jun 2010 17:08:38 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: astone9</title>
		<link>http://www.webmastersucks.com/iframe-virus-jl-chura-pl-removal-todo-list/comment-page-1/#comment-1082</link>
		<dc:creator>astone9</dc:creator>
		<pubDate>Mon, 18 Jan 2010 17:21:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.webmastersucks.com/?p=210#comment-1082</guid>
		<description>Well i have also written an article on my blog. There is a script in PHP which automaticly scans and cleans you hosts and all index files infected with a iframe code. It is easy to use, if you would like you can inlcude it in you site. My post URL is 
&lt;a href=&quot;http://hotfixes.edibra.com/webmasters/clean-iframe-virus&quot; target=&quot;_blank&quot;&gt;http://hotfixes.edibra.com/webmasters/clean-ifram...&lt;/a&gt; 
 </description>
		<content:encoded><![CDATA[<p>Well i have also written an article on my blog. There is a script in PHP which automaticly scans and cleans you hosts and all index files infected with a iframe code. It is easy to use, if you would like you can inlcude it in you site. My post URL is<br />
<a href="http://hotfixes.edibra.com/webmasters/clean-iframe-virus" target="_blank"></a><a href="http://hotfixes.edibra.com/webmasters/clean-ifram.." rel="nofollow">http://hotfixes.edibra.com/webmasters/clean-ifram..</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lisa</title>
		<link>http://www.webmastersucks.com/iframe-virus-jl-chura-pl-removal-todo-list/comment-page-1/#comment-446</link>
		<dc:creator>lisa</dc:creator>
		<pubDate>Fri, 18 Sep 2009 20:25:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.webmastersucks.com/?p=210#comment-446</guid>
		<description>This link can be helpfull. 
&lt;a href=&quot;http://kawablog.com/scarabox/product.php?id_produit=1&amp;id_rub=2&amp;lng=en&quot; target=&quot;_blank&quot;&gt;http://kawablog.com/scarabox/product.php?id_produ...&lt;/a&gt; 
This script remove all malicious iframe from your server, for me that worked fine. </description>
		<content:encoded><![CDATA[<p>This link can be helpfull.<br />
<a href="http://kawablog.com/scarabox/product.php?id_produit=1&amp;id_rub=2&amp;lng=en" target="_blank"></a><a href="http://kawablog.com/scarabox/product.php?id_produ.." rel="nofollow">http://kawablog.com/scarabox/product.php?id_produ..</a>.<br />
This script remove all malicious iframe from your server, for me that worked fine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: webmastersucks</title>
		<link>http://www.webmastersucks.com/iframe-virus-jl-chura-pl-removal-todo-list/comment-page-1/#comment-201</link>
		<dc:creator>webmastersucks</dc:creator>
		<pubDate>Wed, 05 Aug 2009 08:26:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.webmastersucks.com/?p=210#comment-201</guid>
		<description>Thank you for explanation  </description>
		<content:encoded><![CDATA[<p>Thank you for explanation</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dracconus</title>
		<link>http://www.webmastersucks.com/iframe-virus-jl-chura-pl-removal-todo-list/comment-page-1/#comment-189</link>
		<dc:creator>Dracconus</dc:creator>
		<pubDate>Mon, 03 Aug 2009 06:43:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.webmastersucks.com/?p=210#comment-189</guid>
		<description># Change all FTP passwords in your ftp programs used to uplaod files - Do this on another system. 
# Close ALL internet, and local computer browsers. 
# Open  EVERY PHP, HTML, HTM, and MHT , Javascript, and CSS file you have, and remove IFRAME code using an HTML editor (WYSIWYG style preferrably.) 
# Download “Avast Home Edition“, free and infected this virus. (Bit Defender is my personal choice actually) 
# Setup Avast Home Edition (Or Bit Defender.) 
#Download SpyBot Search and Destroy (Update it COMPLETELY) 
#Download WinPatrol (regular version is fine, you&#039;ll need this to make sure that it&#039;s not back when you resume normal mode.) 
# Restart your PC; When it reboots, automatically spam the F8 Button to choose to boot into SafeMode.  Choose SafeMode By itself, not one with networking, or command prompt. 
# Scan your ENTIRE computer.  (If asked to delete, then delete.  This is going to possibly eradicate some MUCH needed files, but trust me, going back, and getting these, or not deleting them now, this thing WILL come back.) 
#While in SafeMode - Make sure to DISABLE System Restore Service.  The virus itself DOES store itself in the boot sectors of your operating system, and your system restore files as well. 
# Upload clean pages to your web site 
# Install SpyBot Search and Destroy, and WinPatrol. 
#Scan your system with Spybot 
#Open your internet browser of your choice, and MAKE SURE TO DELETE ALL HISTORY, SETTINGS, and other information including passwords. 
#Restart and boot into the regular mode of your computer. 
BEFORE YOU DO ANYTHING ELSE!!!!! 
DO THE FOLLOWING: 
Run Winpatrol, and browse the startup, delayed startup, processes, and services tabs.  make ABSOLUTELY SURE that this is NO WHERE to be found. 
You&#039;ll be looking for ANYTHING that has a TMP extension (E.G. Thisfile.TMP 
IF you DO find any file like this - Do the following steps: 
Right click on the file (if available in that menu) and click INFO 
Gather the location of the file. 
Start up your internet connection, and browse to  
http://majorgeeks.com/Unlocker_d4660.html
Download and install this program.  This program lets you delete files, or folders that are currently in use by your operating system (EG the virus.) 
Locate the virus TMP file after the installation of Unlocker and Right click on it. 
Select Unlocker in the Right Click Menu, and then in the popup window, select DELETE, and then hit UNLOCK. 
You MAY have to reboot the computer to effectively remove this file, if that&#039;s the case, so be it, reboot, and AUTOMATICALLY go back into safemode.  Delete the folder C:Documents and settingsYOURUSERNAMETEMP 
Also delete the C:Documents and settingsYOURUSERNAMEApplication DataTEMP folder 
One last deletion 
C:Documents and settingsYOURUSERNAMEMy DocumentTemporary Internet Files 
Now restart the computer ONE last time, and re-run in Normal Mode. 
All the problems SHOULD be gone (as well as possibly some of your files, but, sorry, that&#039;s how it goes sometimes... 
 
**************A little more information******************* 
I have dealt with this virus for almost a month, studying it&#039;s habits, and attempting MANY different removal methods with GREAT failure upon restoring the files. 
  Although this virus only somewhat clings to your files, it&#039;s the ability it has to be stored in TMP iles that makes it so &quot;wonderous.&quot;  The virus can embed itself to ANY kind of document necessary.  This is a TRUE leech on your system, and it&#039;s best to follow these removal steps in the EXACT order that they&#039;re given. </description>
		<content:encoded><![CDATA[<p># Change all FTP passwords in your ftp programs used to uplaod files &#8211; Do this on another system.<br />
# Close ALL internet, and local computer browsers.<br />
# Open  EVERY PHP, HTML, HTM, and MHT , Javascript, and CSS file you have, and remove IFRAME code using an HTML editor (WYSIWYG style preferrably.)<br />
# Download “Avast Home Edition“, free and infected this virus. (Bit Defender is my personal choice actually)<br />
# Setup Avast Home Edition (Or Bit Defender.)<br />
#Download SpyBot Search and Destroy (Update it COMPLETELY)<br />
#Download WinPatrol (regular version is fine, you&#8217;ll need this to make sure that it&#8217;s not back when you resume normal mode.)<br />
# Restart your PC; When it reboots, automatically spam the F8 Button to choose to boot into SafeMode.  Choose SafeMode By itself, not one with networking, or command prompt.<br />
# Scan your ENTIRE computer.  (If asked to delete, then delete.  This is going to possibly eradicate some MUCH needed files, but trust me, going back, and getting these, or not deleting them now, this thing WILL come back.)<br />
#While in SafeMode &#8211; Make sure to DISABLE System Restore Service.  The virus itself DOES store itself in the boot sectors of your operating system, and your system restore files as well.<br />
# Upload clean pages to your web site<br />
# Install SpyBot Search and Destroy, and WinPatrol.<br />
#Scan your system with Spybot<br />
#Open your internet browser of your choice, and MAKE SURE TO DELETE ALL HISTORY, SETTINGS, and other information including passwords.<br />
#Restart and boot into the regular mode of your computer.<br />
BEFORE YOU DO ANYTHING ELSE!!!!!<br />
DO THE FOLLOWING:<br />
Run Winpatrol, and browse the startup, delayed startup, processes, and services tabs.  make ABSOLUTELY SURE that this is NO WHERE to be found.<br />
You&#8217;ll be looking for ANYTHING that has a TMP extension (E.G. Thisfile.TMP<br />
IF you DO find any file like this &#8211; Do the following steps:<br />
Right click on the file (if available in that menu) and click INFO<br />
Gather the location of the file.<br />
Start up your internet connection, and browse to<br />
<a href="http://majorgeeks.com/Unlocker_d4660.html" rel="nofollow">http://majorgeeks.com/Unlocker_d4660.html</a><br />
Download and install this program.  This program lets you delete files, or folders that are currently in use by your operating system (EG the virus.)<br />
Locate the virus TMP file after the installation of Unlocker and Right click on it.<br />
Select Unlocker in the Right Click Menu, and then in the popup window, select DELETE, and then hit UNLOCK.<br />
You MAY have to reboot the computer to effectively remove this file, if that&#8217;s the case, so be it, reboot, and AUTOMATICALLY go back into safemode.  Delete the folder C:Documents and settingsYOURUSERNAMETEMP<br />
Also delete the C:Documents and settingsYOURUSERNAMEApplication DataTEMP folder<br />
One last deletion<br />
C:Documents and settingsYOURUSERNAMEMy DocumentTemporary Internet Files<br />
Now restart the computer ONE last time, and re-run in Normal Mode.<br />
All the problems SHOULD be gone (as well as possibly some of your files, but, sorry, that&#8217;s how it goes sometimes&#8230; </p>
<p>**************A little more information*******************<br />
I have dealt with this virus for almost a month, studying it&#8217;s habits, and attempting MANY different removal methods with GREAT failure upon restoring the files.<br />
  Although this virus only somewhat clings to your files, it&#8217;s the ability it has to be stored in TMP iles that makes it so &#8220;wonderous.&#8221;  The virus can embed itself to ANY kind of document necessary.  This is a TRUE leech on your system, and it&#8217;s best to follow these removal steps in the EXACT order that they&#8217;re given.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: abrar</title>
		<link>http://www.webmastersucks.com/iframe-virus-jl-chura-pl-removal-todo-list/comment-page-1/#comment-183</link>
		<dc:creator>abrar</dc:creator>
		<pubDate>Fri, 31 Jul 2009 07:50:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.webmastersucks.com/?p=210#comment-183</guid>
		<description>i cant understand toooo long 
 </description>
		<content:encoded><![CDATA[<p>i cant understand toooo long</p>
]]></content:encoded>
	</item>
</channel>
</rss>
