MyTechSupport.ca :: Your Computer Technical Resource Headquarters! MyTechSupport.ca :: Your Computer Technical Resource Headquarters!
HOME FORUMS RESOURCES & TOOLS ARTICLES ONLINE STORE ABOUT US
Computer Support Forums arrow Internet & Network Support arrow Security & Viruses arrow Topic: jimbutt virus
May 31, 2020, 01:15:20 PM
 

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
May 31, 2020, 01:15:20 PM

Login with username, password and session length
 Featured Sites:
News
New  Check out our improved Download section for tons of software....
  0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: jimbutt virus  (Read 842 times)
DougD
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 3


Bookmark and Share

View Profile
« on: September 20, 2005, 05:47:57 PM »

PLEASE SUPPLY RELEVANT INFORMATION:
Operating System Version:
Problem Application Name & Version:
Problem Hardware Make & Model:
Error Messages:



Huh????Help me remove jimbutt PLEASE!!
Windows me
Warning window pops up "ports 3128 and 8880" are infected
explorer automatically is jimbutt.com
web site reads : terra.es/personable/dames5/nger.html
hjt's log attached

THANK YOU< THANK YOU < THANK YOU!!!!!

Download Attachment: hijackthislog2.txt 1.45 KB
Right click and select Save Target As... then rename the file as shown here and save.
Logged

 
Pancake
Global Moderator
Hero Member
*****

Karma: +78/-0
Offline Offline

Gender: Male
Posts: 3915


Bookmark and Share

View Profile
« Reply #1 on: September 21, 2005, 01:33:04 AM »

Hi..........

Print out these instructions as you should not start Internet Explorer until they are completed.

Please start by putting your computer in SAFE MODE.  During reboot, tap the F8 key. Select Safe Mode and then run HJT.

Download KillBox and extract it to c:\killbox


Navigate to the c:\killbox directory and double-click on Killbox.exe


When it is open enter  c:\windows\system\systr.dll into the field labeled Full path of file to delete. This infection has recently morphed, so if the previously mentioned file does not exist, killbox param32.dll instead. They will be in the same directories.


Select the Delete on reboot option.


Then press the button that looks like a red circle with a white X in it. When it asks if you would like to reboot, allow it to do so.


When your computer has rebooted and your back at your desktop, Run HijackThis and press the Scan button.


Put a checkmark next to the following entries:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:://www.jimbutt.com/stuffs/


Once those entries are checked, press the Fix button.


Exit HijackThis.


Check that you have carried out all the above steps/fixes and then reboo and download Cleanup This will  clean out your tempory files.

When done please post a new (full) HJT log to this thread.(Do not attatch it)
Logged

An Australian Member of

EDDY
Pages: [1] Go Up Print 
 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

Disclaimer
This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page December 11, 2018, 05:17:31 AM