davidliverett2008 Posted January 12, 2008 Share Posted January 12, 2008 Computer RestrictionsScrewed up since:December 2007Alternative action required:Reformat harddrive, or harddrive wipeI have 2 computers. the one I am on now is my own, and the other one my grandma uses for her msn games. A few weeks ago, the computer got a virus and has disabled quite a few operations. I can't open control panel, access my network, hell, I can't even change my background picture. The error message that pops up says that "This operation has been cancelled due to restrictions in effect on your computer. Please see your system administrator." I am the system admin.Can anyone help me out? Link to comment Share on other sites More sharing options...
PC_LOAD_LETTER Posted January 12, 2008 Share Posted January 12, 2008 likely there have been some policies changed in the system registry that forbid access to certain parts of the OS. Usually these are set by malicious programs so they can hide on your system without being discovered (and removed) by the user. you will find most of these polices in the registry (Start->Run->regedit) under the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ branch. once you get into that section of the registry you should see several values like DisableTaskMgr, DisableCMD, etc you can safely delete most of these values but if you arent sure enough of what it does to delete it, just double click it and change its value to 0 there is a possiblity that you will get the same message when attempting to access Start->Run->regedit if that happens either download and run this file: disableregistrytoolsundo.regcontents of attached file:Windows Registry Editor Version 5.00[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]"DisableRegistryTools"=dword:00000000[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]"**.del.DisableRegistryTools"=-[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalUser\Software\Microsoft\Windows\CurrentVersion\Policies\System]"DisableRegistryTools"=dword:00000000[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalUser\Software\Microsoft\Windows\CurrentVersion\Policies\System]"**del.DisableRegistryTools"=-[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]"NoSaveSettings"=dword:00000000now as i mentioned earlier, this is likely a result of something malicious running on the system causing this problem so the malicious program might just change the values right back to what they were. even if it doesn't you will want to find something to scan and remove the malware you can try our Malware Prevention & Security forum for more information on what to use to clean the system.REF Link to comment Share on other sites More sharing options...
gosh Posted January 12, 2008 Share Posted January 12, 2008 Delete the following:HKLM\SOFTWARE\PoliciesHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policiesHKCU\SOFTWARE\PoliciesHKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies-gosh Link to comment Share on other sites More sharing options...
Idontwantspam Posted January 13, 2008 Share Posted January 13, 2008 (edited) Don't do what gosh said, since then system policies, that winlogon usually likes to have there to be happy, will be removed. Only delete the HKCU ones. Also, if you can access it, you may want to check out gpedit.msc. Lots can be set (or unset) there. Finally, check out the link in my sig for a bit more info on policies and using the registry to set them. Welcome to MSFN! edit: Your profile says xp home addition, but this is under the xp x64 forum. So which OS is it running? Edited January 13, 2008 by Idontwantspam Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now