Korea (한국어) -
Global (English) -
Brazil (Português) -
Japan (日本語) -
Russia (русский) -
[Chinese(简体中文) 即将推出]
WindowexeAllkiller Download : Free Download
WindowexeAllkiller is a free software which can remove unwanted software from your computer at once. WindowexeAllkiller is able to easily remove all Startup, Browser Helper Object, Toolbar, Service, Task Scheduler, Chrome Extension, malware, trojan, ad-popup and so on.
Easy to use, Very simple, Very Powerful.
No Viruses, No Spyware, No Adware, It's free!
System Requirements : .Net framework 2.0 , Windows xp, vista, 7, 8, 10 32/64bit
How to remove [Trojan-GameThief. BFCO0GAT.exe monsthy.dll] using command prompt
You are supposed to start with all programs closed because an Explorer and Taskbar all terminate.
Run a command prompt. [Start] - [Program] - [Accessories] - [Command prompt]
* Important : In Windows Vista/7/8/10, you are advised to select [Run as Administrator] by clicking on [command prompt] using the right mouse button.
When the command prompt is run, there comes out a black screen as below and the cursor begins to flicker.
The letters or shape appearing on the screen might be slightly different, but don't bother. It'll be all right for you just to get a similar screen as below.
|
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corpation. All right reserved.
C:\Users\Administrator>
|
When you fast click the mouse button for three times in a row in the red line(command line) below, you can select all.
Then, mouseclick the selected zone and copy it. (Ctrl + c or Select a [copy] on Right-click contextmenu.)
In case all the zones are not automatically selected, you will have to copy it by dragging the whole of the red line using the mouse.
---------------------------------------------------------------------------------------------------------------
echo Start
echo #
echo ##################### Default System32 directory for x86 x64 #####################
echo #
echo 000 change to the default system directory & cd %WINDIR% & cd system32
echo Kill Process & taskkill /im explorer.exe /f & echo wait
echo Kill Process & tskill explorer & echo wait
echo Kill Process & taskkill /im IEXPLORE.EXE /f & echo wait
echo Kill Process & tskill IEXPLORE & echo wait
echo wait & ping 127.0.0.1 -n 1 > %WINDIR%\pingwait.txt
echo Created by http://windowdel.com/en.php?w=110618-trojan-gamethief-bfco0gat-exe-monsthy-dll
echo ################# Created by windowdel.com http://www.windowdel.com #################
echo do not modify any label echo 000 & taskkill /im "rundll32.exe" /f & echo wait echo 000 & tskill "rundll32" & echo wait echo 001 & attrib -r -h -s "%WINDIR%\system32\BFCO0GAT.exe
" & echo windowdel.com echo 001 & del /q "%WINDIR%\system32\BFCO0GAT.exe
" & echo windowdel.com echo 002 & attrib -r -h -s "%WINDIR%\system32\BFCO0GAT10.dll
" & echo windowdel.com echo 002 & del /q "%WINDIR%\system32\BFCO0GAT10.dll
" & echo windowdel.com echo 001 created by windowdel.com echo 003 & attrib -r -h -s "%WINDIR%\system32\BFCO0GAT11.dll
" & echo windowexeallkiller.com echo 003 & del /q "%WINDIR%\system32\BFCO0GAT11.dll
" & echo windowexeallkiller.com echo 004 & attrib -r -h -s "%WINDIR%\system32\BFCO0GAT20.dll
" & echo windowexeallkiller.com echo 004 & del /q "%WINDIR%\system32\BFCO0GAT20.dll
" & echo windowexeallkiller.com echo 005 & attrib -r -h -s "%USERPROFILE%\Microsoft\monsthy.dll" & echo windowexeallkiller.com echo 005 & del /q "%USERPROFILE%\Microsoft\monsthy.dll" & echo windowexeallkiller.com echo 006 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94AC7942-7BE1-4FB9-A7CA-67CD88362758}
" /f & echo windowdel.com echo 007 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94AC7941-7BE1-4FB9-A7CA-67CD88362758}
" /f & echo windowdel.com echo 008 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{94AC7948-7BE1-4FB9-A7CA-67CD88362758}
" /f & echo windowdel.com echo 009 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHlprObj.IEHlprObj
" /f & echo windowdel.com echo 010 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
" /f & echo windowdel.com echo 011 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{94AC7942-7BE1-4FB9-A7CA-67CD88362758}" /f & echo windowdel.com echo 012 & echo HKEY_CURRENT_USER Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "monsthy" /f & echo created by windowdel.com echo 012 & echo HKEY_LOCAL_MACHINE Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "monsthy" /f & echo created by windowexe.com echo 013 & echo HKEY_CURRENT_USER Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "BFCO0GAT" /f & echo created by windowdel.com echo 013 & echo HKEY_LOCAL_MACHINE Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "BFCO0GAT" /f & echo created by windowexe.com echo 014 your ip is 18.117.71.239 do not delete this label. echo http://windowdel.com/en.php?w=110618-trojan-gamethief-bfco0gat-exe-monsthy-dll echo do not modify any label echo do not stop here for x86, you have to start explorer process. echo # echo ##################### Change directory SysWOW64 for x64 OS ##################### echo # echo Remove x86 Application's registry for x64 OS & ping 127.0.0.1 -n 1 > %WINDIR%\pingwait.txt echo change to the syswow64 directory & cd %WINDIR% & cd syswow64 echo 000 & taskkill /im "rundll32.exe" /f & echo wait echo 000 & tskill "rundll32" & echo wait echo 015 & attrib -r -h -s "%WINDIR%\system32\BFCO0GAT.exe
" & echo windowexeallkiller.com echo 015 & del /q "%WINDIR%\system32\BFCO0GAT.exe
" & echo windowexeallkiller.com echo 016 & attrib -r -h -s "%WINDIR%\system32\BFCO0GAT10.dll
" & echo windowexeallkiller.com echo 016 & del /q "%WINDIR%\system32\BFCO0GAT10.dll
" & echo windowexeallkiller.com echo 001 created by windowdel.com echo 017 & attrib -r -h -s "%WINDIR%\system32\BFCO0GAT11.dll
" & echo windowdel.com echo 017 & del /q "%WINDIR%\system32\BFCO0GAT11.dll
" & echo windowdel.com echo 018 & attrib -r -h -s "%WINDIR%\system32\BFCO0GAT20.dll
" & echo windowexeallkiller.com echo 018 & del /q "%WINDIR%\system32\BFCO0GAT20.dll
" & echo windowexeallkiller.com echo 019 & attrib -r -h -s "%USERPROFILE%\Microsoft\monsthy.dll" & echo windowdel.com echo 019 & del /q "%USERPROFILE%\Microsoft\monsthy.dll" & echo windowdel.com echo 020 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94AC7942-7BE1-4FB9-A7CA-67CD88362758}
" /f & echo windowdel.com echo 021 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94AC7941-7BE1-4FB9-A7CA-67CD88362758}
" /f & echo windowdel.com echo 022 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{94AC7948-7BE1-4FB9-A7CA-67CD88362758}
" /f & echo windowdel.com echo 023 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHlprObj.IEHlprObj
" /f & echo windowdel.com echo 024 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
" /f & echo windowdel.com echo 025 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{94AC7942-7BE1-4FB9-A7CA-67CD88362758}" /f & echo windowdel.com echo 026 & echo HKEY_CURRENT_USER Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "monsthy" /f & echo created by windowdel.com echo 026 & echo HKEY_LOCAL_MACHINE Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "monsthy" /f & echo created by windowexe.com echo 027 & echo HKEY_CURRENT_USER Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "BFCO0GAT" /f & echo created by windowdel.com echo 027 & echo HKEY_LOCAL_MACHINE Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "BFCO0GAT" /f & echo created by windowexe.com echo 028 your ip is 18.117.71.239 do not delete this label. echo http://windowdel.com/en.php?w=110618-trojan-gamethief-bfco0gat-exe-monsthy-dll
echo 029 rechange dir to system32 & cd %WINDIR% & cd system32
echo ################# Created by windowdel.com http://www.windowdel.com ###############
echo do not modify any label
echo del pingwait.txt & del /q %WINDIR%\pingwait.txt
echo 030 & explorer.exe & echo explorer start
echo End
---------------------------------------------------------------------------------------------------------------
All files are deleted when [Paste] is selected by clicking the mouse on the right button in between the command prompt screen after copying.
|
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corpation. All right reserved.
C:\Users\Administrator>
Mark |
Copy |
Paste |
Select All |
Scroll |
Find.. |
|
There might happen a case where files are not deleted due to the next command line(deletion) starts too quickly while terminating the process.
so you are advised to do one more [paste]at the prompt window after all command lines are run.
Once the command lines are all run, you can close the command prompt window.
WindowexeAllkiller is a free software which can remove unwanted software from your computer at once. WindowexeAllkiller is able to easily remove all Startup, Browser Helper Object, Toolbar, Service, Task Scheduler, Chrome Extension, malware, trojan, ad-popup and so on.
WindowexeAllkiller
Easy to Use, Very Simple, Very Powerful, No Viruses, No Spyware, No Adware, It's free!
Removal Guide Similar Software
00493 - ADSTOP 00500 - bearshare 00494 - Funpop 00508 - greenvaccine 00495 - HappyCoin 00502 - ktprotect 00506 - MineFilter - midiasvc.exe mineeisvc.exe 00507 - MineFilter - minerun.exe mineejsvc.exe 00498 - minipopup 00501 - NanoLinkGuide 00497 - oneclickservice 00503 - ShoppingDum 00504 - Trojan-GameThief. RFCILHKT.exe serviceslass.dll 00490 - Trojan-GameThief. XFCILIKT.exe FV3smx4pnp.dll 00492 - Trojan-GameThief. XFCILIKT.exe spoolsver.dll 00491 - Trojan-GameThief. XFCILIKT.exe spoolver.dll 00505 - VaccineScan 00496 - zrclient
System Environment (X = System Drive)
Environment variable | Windows xp | Windows vista / 7 / 8 |
%ALLUSERSPROFILE% | X:\Documents and Settings\All Users | X:\ProgramData |
%APPDATA% | X:\Documents and Settings\{User}\Application Data | X:\Users\{User}\AppData\Roaming |
%USERPROFILE% | X:\Documents and Settings\{User} | X:\Users\{User} |
%PROGRAMFILES% | X:\Program Files | X:\Program Files |
%PROGRAMFILES(x86)% | X:\Program Files(x86) | X:\Program Files(x86) |
%COMMONPROGRAMFILES% | X:\Program Files\Common Files | X:\Program Files\Common Files |
%COMMONPROGRAMFILES(x86)% | X:\Program Files(x86)\Common Files | X:\Program Files(x86)\Common Files |
%WINDIR% | X:\Windows | X:\Windows |
%HOMEDRIVE% | X: | X: |
|