:: Your Computer Technical Resource Headquarters! :: Your Computer Technical Resource Headquarters!
Computer Support Forums arrow Internet & Network Support arrow Security & Viruses arrow Topic: jimbutt virus
May 31, 2020, 01:15:20 PM

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
May 31, 2020, 01:15:20 PM

Login with username, password and session length
 Featured Sites:
New  Check out our improved Download section for tons of software....
  0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: jimbutt virus  (Read 842 times)

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 3

Bookmark and Share

View Profile
« on: September 20, 2005, 05:47:57 PM »

Operating System Version:
Problem Application Name & Version:
Problem Hardware Make & Model:
Error Messages:

Huh????Help me remove jimbutt PLEASE!!
Windows me
Warning window pops up "ports 3128 and 8880" are infected
explorer automatically is
web site reads :
hjt's log attached


Download Attachment: hijackthislog2.txt 1.45 KB
Right click and select Save Target As... then rename the file as shown here and save.

Global Moderator
Hero Member

Karma: +78/-0
Offline Offline

Gender: Male
Posts: 3915

Bookmark and Share

View Profile
« Reply #1 on: September 21, 2005, 01:33:04 AM »


Print out these instructions as you should not start Internet Explorer until they are completed.

Please start by putting your computer in SAFE MODE.  During reboot, tap the F8 key. Select Safe Mode and then run HJT.

Download KillBox and extract it to c:\killbox

Navigate to the c:\killbox directory and double-click on Killbox.exe

When it is open enter  c:\windows\system\systr.dll into the field labeled Full path of file to delete. This infection has recently morphed, so if the previously mentioned file does not exist, killbox param32.dll instead. They will be in the same directories.

Select the Delete on reboot option.

Then press the button that looks like a red circle with a white X in it. When it asks if you would like to reboot, allow it to do so.

When your computer has rebooted and your back at your desktop, Run HijackThis and press the Scan button.

Put a checkmark next to the following entries:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:://

Once those entries are checked, press the Fix button.

Exit HijackThis.

Check that you have carried out all the above steps/fixes and then reboo and download Cleanup This will  clean out your tempory files.

When done please post a new (full) HJT log to this thread.(Do not attatch it)

An Australian Member of

Pages: [1] Go Up Print 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page December 11, 2018, 05:17:31 AM