6 Must Have Replacement Tools when Fixing a Computer Infected by Virus

Posted By Raymond In Category: Computer

Sep
29
2008
Donate

When a good and powerful virus infects a computer, most likely it will disable you from running Task Manager (taskmgr.exe), Registry Editor (regedit.exe), Command Prompt (cmd.exe), System Configuration Utility (msconfig.exe), configuring Folder Options and hide the Run from Start Menu. Reason the virus does that is because most of the time it is “possible” for computer experts to remove the virus by using the built-in Windows programs without any third party tools.

Command Prompt replacement
But if you can’t run Task Manager, you cannot end the suspicious process. You could use the taskkill command in command prompt to kill the process but again you won’t be able to do that if CMD has been disabled. Perhaps you can run msconfig to stop the virus from auto startup but also cannot because of the virus. For advance computer users who has knowledge in registry and thought that they could manually remove the virus auto startup entries there, they too can’t do anything about it if regedit has been disabled. Disabling of Folder Options is to stop you from setting your computer to display hidden and system files. This way you can’t see the virus file and hence you won’t be able to delete them.

It is easy to re-enable all those tools back by modifying some values in your registry but if the is still virus active in your computer, the restrictions will be restored back. So for emergency cases, here are some replacement tools you can use to replace the disabled Windows tools.


1. Task Manager taskmgr.exe Replacement
taskmgr alternative
- Task Manager is very important because that is where you get to see all the running processes and also the amount of memory and CPU usage. If you find anything suspicious there, you can try terminating it. If you cannot run Task Manager and get the error message “Task Manager has been disabled by your administrator”, you can try using Process Explorer. It is portable and you can save it in your USB flash drive.

[ Download Process Explorer, a task manager alternative ]

2. Registry Editor regedit.exe Replacement
Regedit alternative
- Without the ability to access Windows registry, you cannot manually make any changes at all. You can however, import registry REG files. When a virus has disabled regedit, you should see the message “Registry editing has been disabled by your administrator” when you try to run it. A good regedit alternative is RegAlyzer, developed by the author of the famous SpyBot. RegAlyzer requires installation but you can copy the whole RegAlyzer folder to your USB flash drive and run it as portable application.

[ Download RegAlyzer, a regedit alternative ]

3. Command Prompt cmd.exe Replacement
CMD alternative
- Command Prompt is a very powerful command line tool which supports a lot of commands when you find it impossible to do it in Windows. If you try to run cmd and get the following message “The command prompt has been disabled by your administrator. Press any key to continue”, you can try using GS. GS is a cmd replacement but it is a little old, dated back in year 2005. We’re not looking for a permanent replacement, so it is good enough as long as it can support some important command lines. Do take note that “Console2″, is an EXTENSION for command prompt. If cmd is disabled, Console2 won’t work. GS is small, free and portable.

[ Download GS, a command prompt alternative ]

4. Run Dialog Box Replacement
Run alternative
- Some virus will also remove the run command from your Start Menu and it is not easy to restore it back. Although this is not really important, but it could easily allow you to run important commands. Run dialog replacement v1.0 is small, only 48KB in size and portable. If you have Process Explorer, you can also access the run command from File > Run, or just hit CTRL+R.

[ Download Run Dialog Replacement 1.0 ]

5. System Configuration Utility msconfig.exe Replacement
msconfig alternative
- MSCONFIG is the first place that I will go to check if a computer has a virus. If you run msconfig and go to the Startup tab, it will list all programs that will start when Windows is booted up using the common startup method. Virus makers are aware of this and usually they will either delete your original msconfig.exe file or change the reference location in registry. You should get this message “Windows cannot find ‘msconfig’. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.” when type msconfig at the run dialog box. One very good msconfig alternative is definitely Autoruns, which is from the same author as Process Explorer. Autoruns has the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login.

[ Download Autoruns, a msconfig alternative ]

6. Enable Show hidden files and protected operating system files
Folder Options alternative
- I’ve tried many File Managers and most of them inherits the Show Hidden Files and Folders or Hide protected operating system files from Folder Options settings in Windows. If a virus is still active in memory, it will keep on changing the settings to disable you from viewing hidden and system files. I found one free file manager called FreeCommander which is able to show you all hidden files and folders as well as protected operating system files no matter what is the settings in Folder Options. It actually ignores the permission in Folder Options! It is portable, so you can also copy the whole extracted folder to your USB flash drive.

[ Download FreeCommander, a file manager replacement ]

There you go, I’ve shared with you the 6 MUST have replacement or alternative tools when fixing a computer that has many restrictions caused by the virus.


Related posts:
  • Scan Your Computer with Multiple Anti Virus for FREE
  • Deltree Command Replacement in Windows 2000 or Windows XP
  • Upgrade your Windows User Account Control with Smart UAC Replacement
  • CaSIR – A Very Effective Stubborn Computer Virus Infection Remover
  • Stop Virus from Running Automatically When you Execute Files
    • Prashanth

      Some of my favorite tools – I guess you missed HJT.
      We can copy and rename cmd.exe and run it and virus will not end it or block it. Thanks for GS.

    • http://www.raymond.cc/ Raymond

      Prashanth, if you have DisableCMD value set to 1 or disable command prompt via Group Policy, changing the cmd.exe to another name wouldn’t work. That is where the virus usually modifies to disable cmd.

    • Prashanth

      In one PC, there was this usual msg that cmd has been disabled by admin. I had a copy of cmd renamed in my USB and I was able to run it. Maybe that virus did not modify the DisableCMD setting. Thanks for the info Raymond.
      I had written a vbs (like RegSwitch) for DisableCMD also but for some reason it didn’t work. I’ll be fixing it soon.

    • Sak

      Thx, Ray :-)
      I guess it is enough to have those utils in zip format – perhaps on another drive – and only install them in case of a virus infection, or am I missing smg?

    • Dk

      I think there is no replacement for your blog.Thanks a lot for useful articles.

    • http://www.budoshellhole Patrick Budowski

      Ray,
      Great tips! Thanks.

    • Basel

      Sweet

    • MR7

      If I remember well, some time ago you posted a tool that can enable all this functions back with a few clicks. Don’t remember the name, but I’m sure a search in the site would do it…

    • MR7
    • http://www.raymond.cc/ Raymond

      MR7, Remove Restrictions Tool (RRT) fixes the restrictions but when a virus is still present and active in memory, the restrictions will be reverted back.

      These replacement tools serve a different purpose which is to allow you to access what the virus has restricted ;)
      Trust me, it is useful and has helped me a lot.

    • vishal

      Thanks !

      it will be useful!

    • jeff parker

      Thanks Raymond! This is another useful tools!

    • http://www.rajib.com Rajib Ghosh

      Invaluable tips! Will save the rookie administrator tons of time. I am gonna take all these tools, put it in USB drives and make them standard issue for IT admins in my organization.

      Thanks.

    • proview

      process explorer and msconfig alternative download links are not working . Any help Thanks

    • MR7

      Love when you reply me Raymond S2
      What I mean to say is that if you reactivate the disabled tools, you can kill the virus before it disable them again. That way, you can use only RRT. Other than that, these replacement tools are really useful, it’s something to carry around for sure…

    • Tony

      Thanks for these replacement tools. It’s much faster now to fix or remove spywares and viruses from my customers’ computer.

      Even though you manage to reactivate the disabled tools you’ll be in situation when the computer might not even boot up probably and have to boot up in safe mode where the tools might be deactivated or out of function.

      Probably the worst kind of viruses or spywares in my case might be the ones who can infect other computers through the network…now that would take time to fix

      Thanks

    • http://go4contact.com robbie

      i’ve found a few reg files that usally fix things or VBS but i think i shall try using these for when im removing a stubbon virus.

    • syxxnyne69

      a valuable tool that i use when attempting to repair pc seriously infected by worms and virii is syspad portable
      the link is here
      http://www.softpedia.com/get/PORTABLE-SOFTWARE/System/Launchers/Windows-Portable-Applications-Portable-XP-SysPad.shtml

    • ahmad maher

      wow, this is so good and a real must to have

      thanks a lot

    • Amirz

      Great info Raymond! Thx alot!

    • Samir

      Ideal solution will be using latest Offline (DOS) Anti Virus.

      In most situations we cant do the following on infected PC:

      run any exe ..so how to run these?

      USB might not detect

      USB will get infected

      Thanks for update.

    • xinfu

      a great alternative for HJT and Autoruns would be Runscanner. it is a freeware which scans a windows system for all configured running programs and autostart locations. Runscanner connects to an online database to whitelist instead of blacklisting.

      http://www.runscanner.net/

    • Ed

      Nowadays, my first tool to clean virus is ComboFix. In 10 minutes and takes out the big problem areas. The team that work on this project is amazing and productive. My only complaint is that is always deletes autorun.inf from my USB drive :). It will also restore many of the restrictions.

      Also, for Windows XP you can use Dial-a-Fix and look at Policies. I wish this project is being developed again.

    • Tim

      Thanks so much for this very informative post among many others I have benefited from. I look forward to that newsletter always and save every one of them!

    • Razali Rambli

      CMD can be replace with this freeware, NIRCMD

      http://www.nirsoft.net/utils/nircmd.html

      The team that create Combofix use this tool too.

    • Bret

      Not a bad list. I prefer Icesword to find hidden processes, etc.

      MoveOnBoot is also good for getting rid of files associated with the virus that are running and thus can’t be deleted.

      Killbox can also help you kill processes so files can be deleted.

      All 3 are free also.

    • cho

      i cant seem to get it.it does work but how do you remove the virus?

    • simab

      great.but what to do with these tools if really infected?

    • Ranhiru

      Thanx a lot!!! Really useful! I like it! ;) (SU)

    • http://dots.webhop.org Macus

      open notepad

      type this in:

      :start
      set /p command=”%cd%>”
      %command%
      goto start

      save it as “cmd.bat” with the quotas

      run it

      thats how we get past our schools cmd block

    • rpgfan3233

      Regarding the cmd.exe bit, these tools are most likely invaluable for 32-bit/64-bit Windows servers and 64-bit client machines. However, 32-bit Windows XP still has command.com from the MS-DOS days. Because it is a DOS application, it has no knowledge of advanced security permissions – only file attributes such as read-only, system file, etc. As a result, secured files and directories using NT security permissions will be inaccessible, but you can still access things like you would using cmd.exe, bypassing the Group Policy/Registry issue. In this way, you could access things.

      regedt32 is also in Windows XP as a remnant of the Windows NT days. In Windows XP, it simply runs regedit, but using such a program to launch it rather than trying to run it directly might circumvent the issue.

    • guy smat

      Lovely work you’re doing here.
      Thanks for all your posts.
      I wonder where you get the energy to do all of this.
      Nice gift you have.
      Keep up the good work and thanks for sharing.

    • http://www.happybruno.com Bruno

      Thanks. You don’t know how helpful this post has been. Been a living hell trying to get rid of a virus from my computer.

    • jayaprakash

      Dear friend, I open this site by chance ,I am facing the problem narated by you regarding the folder option- view-advanced settings , i was really shocked to see a foreign laungage settings . i read your solution options. As am a civil engineer , i would like to clear my doubt, 1st should i had to download one of your tips and then what to do ? please guide me. My operating system is window xp professional. Hope you will guide me so that i can read folder advance settings in english. thank you.

    • RJ

      A great list of tools, but to be honest removing an active virus and removing group policy restrictions is much easier done when you dont have to use the infected OS. One of the most usefull tools in my arsenal is “BartPE” it allows you to creat a bootable “Live CD” version of XP.

      Boot from the CD, run regedit, mount the users/system registry hives, do your fixin, reboot and presto.

      not to mention it gives you access to NTFS acl’s to fix permission problems.

    • RJ

      forgot the URL for BartPE

      http://www.nu2.nu/pebuilder/

    • Chantrea

      Thank Raymond. Nothing can be replaced your blog.

    • Ears14U

      Nice…been looking for awhile for some decent tools to overcome some of these parasitic viruses…thanks…

    Copyright © 2005-2012 - Raymond.CC Blog