PDA

View Full Version : "Registry editing has been disabled by your admin"


frayed
February 20th 04, 04:24 AM
I am running Windows XP Pro.

When trying to open regedit I receive the message: ""Registry editing has been disabled by your admin"

This I'm fairly sure is the result of having foolishly acquired a virus identified by Pc Cillin as TROJ_SAGIC.15.

I searched the virus database at pc cillin, and it doesn't have an explaination of how to remove Sagic.15, only information on other variants of the virus.
The same applies when searching symnatec.

I figure my best bet is to follow the procedures outlined in the other variants as best as possible.
All the information on the other variants requires that you delete a registry key at one point, which I am unable to do since I cannot open regedit.
It is acknowledged in in some of the virus database articles that a version of sagic can disable regedit, however it doesn't explain how to reenable this.

1. Does anyone know how I can enable registry editing again?

I tried system restore, but that didn't work.

There is only one user account set up on this pc, and that happens to be an admin account. So according to the error message the admin has disabled access to regedit on their own account.

Pc Cillin has quarantined the infected files. The infected files are
a) regsvr.exe
b)2 files in c:/ system volume info/_restore(LOTS OF RANDOM CHARACTERS HERE).

2. Is it ok to delete these files or are they important to operating Windows?

3. Anyone know how I can rid of this virus for good, short of a clean reinstallation?

All help would be greatly appreciated.

I realise it was due to my own stupidity that I acquired this virus. I've spent the last 3 hrs searching the web for a solution. Please spare me the lecture.

Doug Knox MS-MVP
February 20th 04, 05:21 AM
See www.dougknox.com, Win XP Utilities, Windows XP Security Console. =
This restriction and others can be controlled with this utility.

--=20
Doug Knox, MS-MVP Windows XP/ Windows Smart Display
Win 95/98/Me/XP Tweaks and Fixes
http://www.dougknox.com
--------------------------------
Per user Group Policy Restrictions for XP Home and XP Pro
http://www.dougknox.com/xp/utils/xp_securityconsole.htm
--------------------------------
Please reply only to the newsgroup so all may benefit.
Unsolicited e-mail is not answered.
=20
"frayed" > wrote in message =
s.com...
> I am running Windows XP Pro.
>=20
> When trying to open regedit I receive the message: ""Registry editing
> has been disabled by your admin"
>=20
> This I'm fairly sure is the result of having foolishly acquired a =
virus
> identified by Pc Cillin as TROJ_SAGIC.15.
>=20
> I searched the virus database at pc cillin, and it doesn't have an
> explaination of how to remove Sagic.15, only information on other
> variants of the virus.
> The same applies when searching symnatec.
>=20
> I figure my best bet is to follow the procedures outlined in the other
> variants as best as possible.
> All the information on the other variants requires that you delete a
> registry key at one point, which I am unable to do since I cannot open
> regedit.
> It is acknowledged in in some of the virus database articles that a
> version of sagic can disable regedit, however it doesn't explain how =
to
> reenable this.
>=20
> 1. Does anyone know how I can enable registry editing again?
>=20
> I tried system restore, but that didn't work.
>=20
> There is only one user account set up on this pc, and that happens to
> be an admin account. So according to the error message the admin has
> disabled access to regedit on their own account.
>=20
> Pc Cillin has quarantined the infected files. The infected files are=20
> a) regsvr.exe
> b)2 files in c:/ system volume info/_restore(LOTS OF RANDOM CHARACTERS
> HERE).
>=20
> 2. Is it ok to delete these files or are they important to operating
> Windows?
>=20
> 3. Anyone know how I can rid of this virus for good, short of a clean
> reinstallation?
>=20
> All help would be greatly appreciated.
>=20
> I realise it was due to my own stupidity that I acquired this virus.
> I've spent the last 3 hrs searching the web for a solution. Please
> spare me the lecture.
> --
> frayed
> =
------------------------------------------------------------------------
> posted via www.PCBanter.net=20
>

Google