Deleting XP System Restore points remotely

Posted on 2006-06-13
Last Modified: 2008-02-01
Due to virus issues, we are going to try and push out a disable and delete of all system restore points and functionality over our network.  We have found a registry key that should be easy enough to implement via GPOs (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR=1).  However, deleting the restore points themselves seems to be an issue, since just doing the regedit does not delete the prior points created.  The folder that the points reside in is restricted to SYSTEM access only (easy enough to implement in GPOs, since those authenticate as SYSTEM), however having an exact script to run is stumping us, as deleting the wrong thing could cause huge issues.

ANybody have experience with this problem?
Question by:Hyppy
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Expert Comment

by:Tony Gimenez
ID: 16900194
The folder that the system restore points are located are C:\System Volume Information and enabling access is as simple as a batch/script file.

Well anyway.. doing this over the network would take some sort of remote administration program, and if you dont have one already here are two good ones.

Oh and by the way, if I remember correctly once that registry value is changed the restore points are deleted upon next system reboot. So if you want to reboot all your computers on the LAN use this:
(this is free, but with less functionality)
(and this is the ultimate best)

Expert Comment

ID: 16900231

To delete all the restore points on your computer, disable and re-enable system restore on the system. Click Start, Control Panel, and then the System icon. Click on the System Restore tab in the dialog box, select the Turn off System Restore check box, and click Apply. Clear the check box again to re-enable System Restore and then click OK
You can use WMI scripts for remote restore, so you could use them to delete points as is a link for any WMI questions you may have:
I hope this helps...Booda2us

Accepted Solution

ADExpert earned 500 total points
ID: 16901165
strComputer = "."
Set objWMIService = GetObject("winmgmts:\\" & strComputer & "\root\default")
Set objItem = objWMIService.Get("SystemRestore")
errResults = objItem.Disable("")
errResults = objItem.Enable("")

Above mentioned is a vbscript which can be used to delete all local system restore points. You can change the "." in strComputer variable with the remote system name to perform the same operation on remote systems.


Featured Post

Want Experts Exchange at your fingertips?

With Experts Exchange’s latest app release, you can now experience our most recent features, updates, and the same community interface while on-the-go. Download our latest app release at the Android or Apple stores today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I don't know if many of you have made the great mistake of using the Cisco Thin Client model with the management software VXC. If you have then you are probably more then familiar with the incredibly clunky interface, the numerous work arounds, and …
In this article we will discuss all things related to StageFright bug, the most vulnerable bug of android devices.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.
Suggested Courses

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question