Korea (한국어) -
Global (English) -
Brazil (Português) -
Japan (日本語) -
Russia (русский) -
[Chinese(简体中文) 即将推出]
WindowexeAllkiller Download : Free Download
WindowexeAllkiller is a free software which can remove unwanted software from your computer at once. WindowexeAllkiller is able to easily remove all Startup, Browser Helper Object, Toolbar, Service, Task Scheduler, Chrome Extension, malware, trojan, ad-popup and so on.
Easy to use, Very simple, Very Powerful.
No Viruses, No Spyware, No Adware, It's free!
System Requirements : .Net framework 2.0 , Windows xp, vista, 7, 8, 10 32/64bit
How to remove [Trojan-GameThief. MTRVEHNT.exe sopphos.dll] using command prompt
You are supposed to start with all programs closed because an Explorer and Taskbar all terminate.
Run a command prompt. [Start] - [Program] - [Accessories] - [Command prompt]
* Important : In Windows Vista/7/8/10, you are advised to select [Run as Administrator] by clicking on [command prompt] using the right mouse button.
When the command prompt is run, there comes out a black screen as below and the cursor begins to flicker.
The letters or shape appearing on the screen might be slightly different, but don't bother. It'll be all right for you just to get a similar screen as below.
|
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corpation. All right reserved.
C:\Users\Administrator>
|
When you fast click the mouse button for three times in a row in the red line(command line) below, you can select all.
Then, mouseclick the selected zone and copy it. (Ctrl + c or Select a [copy] on Right-click contextmenu.)
In case all the zones are not automatically selected, you will have to copy it by dragging the whole of the red line using the mouse.
---------------------------------------------------------------------------------------------------------------
echo Start
echo #
echo ##################### Default System32 directory for x86 x64 #####################
echo #
echo 000 change to the default system directory & cd %WINDIR% & cd system32
echo Kill Process & taskkill /im explorer.exe /f & echo wait
echo Kill Process & tskill explorer & echo wait
echo Kill Process & taskkill /im IEXPLORE.EXE /f & echo wait
echo Kill Process & tskill IEXPLORE & echo wait
echo wait & ping 127.0.0.1 -n 1 > %WINDIR%\pingwait.txt
echo Created by http://windowdel.com/en.php?w=110618-trojan-gamethief-mtrvehnt-exe-sopphos-dll
echo ################# Created by windowdel.com http://www.windowdel.com #################
echo do not modify any label echo 000 & taskkill /im "rundll32.exe" /f & echo wait echo 000 & tskill "rundll32" & echo wait echo 001 & attrib -r -h -s "%WINDIR%\system32\MTRVEHNT.exe
" & echo windowexeallkiller.com echo 001 & del /q "%WINDIR%\system32\MTRVEHNT.exe
" & echo windowexeallkiller.com echo 002 & attrib -r -h -s "%WINDIR%\system32\MTRVEHNT10.dll
" & echo windowexeallkiller.com echo 002 & del /q "%WINDIR%\system32\MTRVEHNT10.dll
" & echo windowexeallkiller.com echo 001 created by windowdel.com echo 003 & attrib -r -h -s "%WINDIR%\system32\MTRVEHNT11.dll
" & echo windowdel.com echo 003 & del /q "%WINDIR%\system32\MTRVEHNT11.dll
" & echo windowdel.com echo 004 & attrib -r -h -s "%WINDIR%\system32\MTRVEHNT20.dll
" & echo windowexeallkiller.com echo 004 & del /q "%WINDIR%\system32\MTRVEHNT20.dll
" & echo windowexeallkiller.com echo 005 & attrib -r -h -s "%USERPROFILE%\Microsoft\sopphos.dll" & echo windowdel.com echo 005 & del /q "%USERPROFILE%\Microsoft\sopphos.dll" & echo windowdel.com echo 006 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3EAB4692-4178-4CA4-9568-9BCBE55D3096}
" /f & echo windowdel.com echo 007 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3EAB4691-4178-4CA4-9568-9BCBE55D3096}
" /f & echo windowdel.com echo 008 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3EAB4698-4178-4CA4-9568-9BCBE55D3096}
" /f & echo windowdel.com echo 009 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHlprObj.IEHlprObj
" /f & echo windowdel.com echo 010 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
" /f & echo windowdel.com echo 011 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EAB4692-4178-4CA4-9568-9BCBE55D3096}" /f & echo windowdel.com echo 012 & echo HKEY_CURRENT_USER Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "sopphos" /f & echo created by windowdel.com echo 012 & echo HKEY_LOCAL_MACHINE Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "sopphos" /f & echo created by windowexe.com echo 013 & echo HKEY_CURRENT_USER Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MTRVEHNT" /f & echo created by windowdel.com echo 013 & echo HKEY_LOCAL_MACHINE Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MTRVEHNT" /f & echo created by windowexe.com echo 014 your ip is 18.221.192.248 do not delete this label. echo http://windowdel.com/en.php?w=110618-trojan-gamethief-mtrvehnt-exe-sopphos-dll echo do not modify any label echo do not stop here for x86, you have to start explorer process. echo # echo ##################### Change directory SysWOW64 for x64 OS ##################### echo # echo Remove x86 Application's registry for x64 OS & ping 127.0.0.1 -n 1 > %WINDIR%\pingwait.txt echo change to the syswow64 directory & cd %WINDIR% & cd syswow64 echo 000 & taskkill /im "rundll32.exe" /f & echo wait echo 000 & tskill "rundll32" & echo wait echo 015 & attrib -r -h -s "%WINDIR%\system32\MTRVEHNT.exe
" & echo windowdel.com echo 015 & del /q "%WINDIR%\system32\MTRVEHNT.exe
" & echo windowdel.com echo 016 & attrib -r -h -s "%WINDIR%\system32\MTRVEHNT10.dll
" & echo windowexeallkiller.com echo 016 & del /q "%WINDIR%\system32\MTRVEHNT10.dll
" & echo windowexeallkiller.com echo 001 created by windowdel.com echo 017 & attrib -r -h -s "%WINDIR%\system32\MTRVEHNT11.dll
" & echo windowdel.com echo 017 & del /q "%WINDIR%\system32\MTRVEHNT11.dll
" & echo windowdel.com echo 018 & attrib -r -h -s "%WINDIR%\system32\MTRVEHNT20.dll
" & echo windowexeallkiller.com echo 018 & del /q "%WINDIR%\system32\MTRVEHNT20.dll
" & echo windowexeallkiller.com echo 019 & attrib -r -h -s "%USERPROFILE%\Microsoft\sopphos.dll" & echo windowexeallkiller.com echo 019 & del /q "%USERPROFILE%\Microsoft\sopphos.dll" & echo windowexeallkiller.com echo 020 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3EAB4692-4178-4CA4-9568-9BCBE55D3096}
" /f & echo windowdel.com echo 021 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3EAB4691-4178-4CA4-9568-9BCBE55D3096}
" /f & echo windowdel.com echo 022 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3EAB4698-4178-4CA4-9568-9BCBE55D3096}
" /f & echo windowdel.com echo 023 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHlprObj.IEHlprObj
" /f & echo windowdel.com echo 024 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
" /f & echo windowdel.com echo 025 & reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EAB4692-4178-4CA4-9568-9BCBE55D3096}" /f & echo windowdel.com echo 026 & echo HKEY_CURRENT_USER Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "sopphos" /f & echo created by windowdel.com echo 026 & echo HKEY_LOCAL_MACHINE Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "sopphos" /f & echo created by windowexe.com echo 027 & echo HKEY_CURRENT_USER Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MTRVEHNT" /f & echo created by windowdel.com echo 027 & echo HKEY_LOCAL_MACHINE Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MTRVEHNT" /f & echo created by windowexe.com echo 028 your ip is 18.221.192.248 do not delete this label. echo http://windowdel.com/en.php?w=110618-trojan-gamethief-mtrvehnt-exe-sopphos-dll
echo 029 rechange dir to system32 & cd %WINDIR% & cd system32
echo ################# Created by windowdel.com http://www.windowdel.com ###############
echo do not modify any label
echo del pingwait.txt & del /q %WINDIR%\pingwait.txt
echo 030 & explorer.exe & echo explorer start
echo End
---------------------------------------------------------------------------------------------------------------
All files are deleted when [Paste] is selected by clicking the mouse on the right button in between the command prompt screen after copying.
|
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corpation. All right reserved.
C:\Users\Administrator>
Mark |
Copy |
Paste |
Select All |
Scroll |
Find.. |
|
There might happen a case where files are not deleted due to the next command line(deletion) starts too quickly while terminating the process.
so you are advised to do one more [paste]at the prompt window after all command lines are run.
Once the command lines are all run, you can close the command prompt window.
WindowexeAllkiller is a free software which can remove unwanted software from your computer at once. WindowexeAllkiller is able to easily remove all Startup, Browser Helper Object, Toolbar, Service, Task Scheduler, Chrome Extension, malware, trojan, ad-popup and so on.
WindowexeAllkiller
Easy to Use, Very Simple, Very Powerful, No Viruses, No Spyware, No Adware, It's free!
Removal Guide Similar Software
00528 - BoanSupport 00520 - Cloud-Web - cloudihsvc.exe cloudwebih.dll 00517 - cyadicon 00524 - DaSearch 00512 - FilemaniaService 00522 - ggjjang 00521 - goodprivacy 00510 - MineFilter - minerun.exe mineeksvc.exe 00515 - MineFilter - minerun.exe mineelsvc.exe 00518 - MineFilter - minerun.exe mineemsvc.exe 00525 - mypopmall 00526 - OpenShopper - oplsvc 00516 - SmartKeyword CircusLink 00511 - Tubesong 00523 - VStopper 00527 - Windows Live Smart Update .NETAX 00513 - Windows Live Smart Update .NETAY 00514 - Windows Safe Search AY30
System Environment (X = System Drive)
Environment variable | Windows xp | Windows vista / 7 / 8 |
%ALLUSERSPROFILE% | X:\Documents and Settings\All Users | X:\ProgramData |
%APPDATA% | X:\Documents and Settings\{User}\Application Data | X:\Users\{User}\AppData\Roaming |
%USERPROFILE% | X:\Documents and Settings\{User} | X:\Users\{User} |
%PROGRAMFILES% | X:\Program Files | X:\Program Files |
%PROGRAMFILES(x86)% | X:\Program Files(x86) | X:\Program Files(x86) |
%COMMONPROGRAMFILES% | X:\Program Files\Common Files | X:\Program Files\Common Files |
%COMMONPROGRAMFILES(x86)% | X:\Program Files(x86)\Common Files | X:\Program Files(x86)\Common Files |
%WINDIR% | X:\Windows | X:\Windows |
%HOMEDRIVE% | X: | X: |
|