Wednesday, April 7, 2010

how to remove jl.chura.pl virus

hey friends,here i have a cool fact for u.
actually what happened is that,from our colleges computer center i got a bunch of crap virus.
it came with my pendrive,which got destroyed after proper deletion of the virus.(may b coincident,but it was new.)
i had Norton Internet security 2010 at that time.It simply couldnt detect the virus while it entered.
My start icon at the bottom left disappeared & pressing win-key a blank start window was appearing at the top left corner of the screen.
later norton was able to clean it(but after a amount of loss in system files).
I dont know how many types of virus & viruts were there,but one crap remained in my system...virut!html.
Norton was deleting it again & again..in vain.it obviously must have a generator somewhere in my 40GB C drive.
Type of it as shown by Norton is virut!html.
Later i installed Kaspersky & it did nothing more than Norton.
they do great things in ur computer...
1.its size is 251 bytes.
2.they infect html,exe,scr & asp,php files.
3.they insert malicious Iframe into the normal & configuring .js(javascript) files to connect to various harmful sites..
            1.jl.chura.pl
            2.zief.pl
            3.ntkrnlpa.info
like “<iframe src=”http://jL.chura.pl/rc/” style=”display:none”></iframe>”
suppose whenever u r trying to open Mozilla Firefox..kaspersky showed that its trying to connect to jl.chura.pl
but your homepage is different.actually configuring javascript files of Mozilla Firefox is infected with that Iframe.
now if u r thinking that u will replace each iframe with null string by batch replace software then wait...
it uses html obfuscation..suppose rather than writing jl.chura.pl it will write
            jL.ch& # 117;ra.pl
now u got problem.
but the solution is very simple.
  1. install latest avast free home edition & update it.
  2. then uninstall ur old anti-virus program.
  3. cut & paste all ur necessary files from C to other drive.
  4. open full scan settings & apply take action automatically             
                      in this order
                      Virus : 1.repair,2.move to chest,3.delete
                      PUP   : same
                      suspicious : same
  5. open ur PC in safe mode.
  6. give a full computer scan.
  7. it will probably delete unrepairable infected system files.(if u r not lucky).
    actually in my case USB,sounddriver & lots of other things were not working.
  8. u can also try Malwarebytes & follow the same procedure.
So i needed to format C drive,(its safer than repair).now ur C,D,E,F all r clean wrt virut.
i have read in some forums that its produced by avast team itself.(dont blame me,I know nothing :P).
Viruts are comparatively new in market.I am using avast from that time...its new features are just made for this new kind of viruses.I will suggest u to use avast(Either free or paid).I am using free version.
My next blog will be on some good settings to increase the efficiency of avast against new viruses.
for any query contact me at krishanu.nitdgp@gmail.com or krishanu.spider@gmail.com