BleepingComputer.com: How To Remove Www.jimbutt.com / Systr.dll / Param32.dll

Jump to content

How to use the self-help guides

This forum contains self-help guides on removing common malware and viruses. These guides can be advanced so please use them at your own risk.

If after following the self-help guide, or you can not find an appropriate guide, then you can receive step-by-step instructions directly from one of our experts by following the instructions in this topic:

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

How To Remove Www.jimbutt.com / Systr.dll / Param32.dll Self-Help Guide

#1 User is offline   Grinler 

  • Bleep Bleep!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Admin
  • Posts: 36,603
  • Joined: 24-January 04
  • Gender:Male
  • Location:USA

Posted 05 April 2005 - 12:13 PM


How to remove the www.jimbutt.com start page


What this infection does:
  • Changes your Internet Explorer start page to http:://www.jimbutt.com/stuffs/ or http:://www.hotoffers.info/179/
  • Delivers popups
Tools Needed for this fix: Related Tutorials: Symptoms in a HijackThis Log (Will be different file names):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = -http:://www.jimbutt.com/stuffs/



Removal Instructions:


Manual Removal:
  1. Print out these instructions as you should not start Internet Explorer until they are completed.

  2. Download Killbox from the above and link and extract it to c:\killbox

  3. Navigate to the c:\killbox directory and double-click on Killbox.exe

  4. When it is open enter c:\windows\system32\systr.dll, or c:\windows\system\systr.dll if you are using Windows 95/98/ME, into the field labeled Full path of file to delete. This infection has recently morphed, so if the previously mentioned file does not exist, killbox param32.dll instead. They will be in the same directories.

  5. Select the Delete on reboot option.

  6. Then press the button that looks like a red circle with a white X in it. When it asks if you would like to reboot, allow it to do so.

  7. When your computer has rebooted and your back at your desktop, download HijackThis from the above link and extract it to c:\hijackthis.

  8. Navigate to the c:\hijackthis directory and double-click on HijackThis

  9. Run HijackThis and press the Scan button.

  10. Put a checkmark next to the following entries:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:://www.jimbutt.com/stuffs/

  11. Once those entries are checked, press the Fix button.

  12. Exit HijackThis.

  13. In this step we are going to clean out your temp files. Click on Start and then run, and type %temp% and press the ok button.

    This should open up the temp directory that your machine uses. Please delete all files that are found there. If you get an error when deleting a file, skip that file and delete all the others. If you had trouble deleting a file, reboot into Safe Mode and follow this step again. You should now be able to delete all the files.

  14. Disable and reenable System restore using the instructions found here:

    Windows XP System Restore Guide

    Managing Windows Millenium System Restore

  15. Reboot your computer
Now your computer should no longer be infected with the Jimbutt or Hotoffers infection. You should read and follow the instructions found in the following tutorial: Simple and easy ways to keep your computer safe and secure on the Internet



This is a self-help guide. Use at your own risk.



BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum.

If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you.


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users