Can't Boot From Bootable CD -- Bios Set Correctly

Anonymous
2015-11-02T05:57:29+00:00

I am trying for the first time to boot my Windows 8.1 laptop from the internal CD-DVD drive. I have a bootable CD in there, and yes, I do have the bios set with CDROM drive as first in the list to boot from. But when I try to boot from the CD, it won't boot, instead the computer gives me this message:

"ATAPI CDROM has been blocked by the current security policy."

(Its actually a DVD drive.) All it lets me do at that message is hit the Enter key to OK the message, and then it boots from the hard drive.

I have no idea where "security policy" settings are or what they are set for. What do I have to do to get this to boot?

This is a Gateway laptop, 2.2 MHz Intel Pentium processor, 4 GB RAM, 64 bit OS, with Windows 8.1 fully updated, and Windows Defender running and fully updated.

I have already looked everywhere I can find, but nothing seems to address this message or issue, as follows:

*I went to Help menu to look up "Security Policy." While the computer is giving me the message about "security policy," the Help menu has no idea what "security policy" is, it just comes up blank!

*I went to Control Panels/System and Security/Action Center/Change Windows Settings/Smart Screen/... All I found in there that might be involved is a setting to block anything downloaded from the Internet until I give administrator access. Well, the booting issue didn't allow me to give administrator access (yes, I am the administrator) when I tried to boot, I only could hit the enter key to OK. Nonetheless, I changed to: notify me but proceed (not a quote).

With that, I tried again, but it still would not boot from the CD, got the same message, so that setting is not it. I changed the setting back.

I see no other setting there that could be related by even a stretch. And the control panels should be dealing with the OS anyway, and this is happening while trying to boot from the OS on the CD, not the hard drive. That is, this is something in the root.

*I then went into bios area (UEFI Firmware) by sweeping in from the right and into Settings/Change PC settings ..., and found a tab in bios for Security. Looking there, there is a list of things, but it lets me access only "Supervisor Password." It was currently set as "clear," meaning no password. I left it as that -- surely I can't need a password just to boot from a CD, and the message I got in trying to boot from the CD did not allow me to enter a password.

Other settings in the Security tab were not accessible. The only ones they included that might be remotely related were:

*Password on Boot, which was set as no password. But again, the message I get with this issue does not ask for nor allow me to enter a password.

*Secure Boot Mode: Standard (It does not let me access to change that.)

Some others also were in the list that are not worth listing, not even vaguely related.

I then went into some other things elsewhere in the main settings called Startup Settings. The only thing in there that sounded the least bit vaguely related was "Enable boot logging." I punched F2 to go into that, but the machine instead restarted, and did not start from the CDROM, same message again. I went back to it, and it is still listed as Enable boot logging, does not instead say Disable - so I don't know if anything even got changed. I did not touch it again, left it as-is.

So, that's it. I've checked all the settings I know about. Nothing about this bit about "ATAPI CDROM has been blocked by current security policy."

I tested with two DVDs that I have booted from in the past on other Windows machines -- they also would not boot, but they did not give me that message.

I note, all three CDs/DVDs are being read fine by the DVD drive once the machine is booted in Windows 8.1 from the hard drive - so the issue is not that the DVD drive can't read the disks.

Where is this "security policy" set?! What do I need to do to get this to boot from the CD?

Windows for home | Previous Windows versions | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2016-08-24T15:35:47+00:00

Hi,

So everything is back to normal... or at least working to your satisfaction ?

You seem to know more about manipulating your email than I do, but though I may be able to help by describing what my screen looks like !

I know how that kind of conversation goes... Not so much with Microsoft, but with my internet provider sometimes..

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

596 additional answers

Sort by: Oldest
  1. Anonymous
    2016-09-07T22:17:00+00:00

    I came across some free recovery software I thought you might appreciate. Norton Bootable Recovery Tool. This is something Norton gives out free.

    You can download it here:

    https://security.symantec.com/nbrt/nbrt.aspx?lcid=1033

    And some information about it is here:

    https://support.norton.com/sp/en/us/home/current/solutions/v72380755\_EndUserProfile\_en\_us

    When I just got it, it did indicate at the bottom of the page that the latest update was today. At first I thought  it would not   be able  to update virus and malware definitions,  but in booting from it, it says it does download the latest, and I do see that  it actually opens Opera browser  to  go onloine.

    It should be helpful. Before I booted from it, I thought it was saying it does more than malware. But after booting, the Help menu seems to say that malware is all it does, but all  kinds right  down to ransomware. So, if your booting issue is due to any kind of malware, this could help. In running it, I see it does seem to look for all malware, not solely malware that might interfere with booting -- so that makes this kind of like free Norton Antivirus/Malware. 

    In running, it clearly is doing a deep scan, not a quick one. I guess this scan is going is going to take a few more hours. (I'm on my other computer now.) It  has identified a few things that my Microsoft  antivirus has  not. 

    I'm a bit bothered by its explanation about how to boot from it and use it, as that is NOT how you do those steps it says. :)

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-09-07T23:59:30+00:00

    Hi,

    That is one of the problems with UEFI Bios... For the most part, it seems this was created without sufficient standards as to how it functions.... The instructions that work for one machine may not even make sense for another...

    I haven't used much Norton\Symantec stuff for a number of years, but for a period of maybe five years, I had their full suite on my machines..

    That Recovery Tool looks useful... I will check it out when I get my Desktop back up and running... I am currently on a 8" Tablet that is too slow to experiment with...

    I had to take down most of my computer setups due to getting new windows installed in the house...

    There are similar programs by Malware Bytes and Windows Defender, but without the boot repair feature... Windows Defender was able to remove Ransomware from my sister's machine from a bootable CD...

    I avoid needing stuff like that due to all of the backup images I have saved... I can completely overwrite a partition and load a fresh one a lot faster than a scan can be done...

    I was recently checking out Norton Utilities... I always liked the SpeedDisk Defragging program, among others, but decided I have too much similar stuff installed already...

    BTW... I was going to check on your email issue, but have been too busy... Did the Tier 3 people ever get back with you ?

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-09-08T02:20:51+00:00

    Re the Hotmail/Outlook issue, after two weeks of MS wasting my time, remotely accessing my computer four times -- something I am VERY sensitive about, I consider it an extreme privacy infringement -- and multiple phone calls from them, they finally agreed with what I PROVED to them from the very first contact, but they are not allowed to think: their software is broken. Nothing I or any other user can do to fix it. So, they referred the issue over to their products team, which might or might not some day do something to fix it, but even if they do, that day could be a long, long time down the road. In fact, in looking at the forums more, I found people complaining about this for more than a year!

    In the end, the issue is that they changed from using POP to instead using their own creation, something they call Exchange. And Exchange as some incompatibility issue with POP/IMAP, which of course the other side uses. They, of course, were starting to say the rest of the world needs to fix what they are doing to they can work with Exchange smoothly. I snapped his head off and told him no, MS should make the change, to be compatible with the standard everyone else on the planet uses, MS is the one who went out of whack. Well, the guy agreed, how could he argue with that logic.

    They told me for my circumstances, a work around would be to push from Hotmail/Outlook, rather than pull from Gmail as I had been doing. (I first set it up from Gmail because at that time, Hotmail did not offer any function to push it). But then I pointed out to them that I already had tested that, same problem. He was surprised, said it should work -and wanted to access my computer again and see it,- as if he thought I was lying. Well, he accessed, and he saw it.  He then speculated that it might be a delay behind the scenes. We had to disconnect Gmail to do it, and he was saying that while we see it disconnected, behind the scenes more has to happen and doesn't happen immediately, maybe will in a couple hours or certainly in a full 24 hours cycle it will. OK, so I waited and watched, and a few hours later, yes, pushing did work without creating the problem. So, I am operating as I want, but they still need to fix it for pulling - there can be plenty of reasons to prefer to pull rather than push.

    Re this Norton disk, the links  I sent does seem to suggest it does more than check malware, but after booting from it and running it, and going to the Help menu, in the Help menu it pretty much says it is only going after malware, and that is all I saw it do. (It does, though, offer the ability to use command lines, if you want to.) So, the only "recovery" is if your problem booting is due to malware.

    I am very surprised to hear Windows Defender can even get Ransomware. If these things get it, how can Ransomware be so terrible as they say? I thought Defender only went after viruses and maybe also trojans, but not any other malware, like spyware, and other.

    Ransomware gets down in the root, so using an image to reinstall all of the OS would not get it. This Norton is checking the root. Well, I suppose some spoof or low grade ransomware might not go to the root, might actually be a virus trying to appear as ransomware.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-09-08T13:47:18+00:00

    Hi,

    Windows Defender is getting more sophisticated as time goes by... It was only able to remove the ransomware using it's bootable version... It didn't stop it from infecting the machine...

    Another thing... some of the newer ransomware "Encrypts" the files of the OS, and possibly the entire HDD....  It then requires a "KEY" to Decrypt it...

    Windows Defender, Norton, Malwarebytes, etc., would not be able to fix this unless they could somehow come up with a "KEY"...

    There have been Decryption keys discovered for some of the ransomware, but most has not been cracked... The only option would then be to pay the ransom, or wipe the drive and reinstall everything...

    Even paying the ransom is no guarantee that the drive will actually be decrypted\unlocked...

    At least the Techs were able to find a workaround... That is better than nothing...

    You should get some satisfaction from the fact that the higher ups at Microsoft will be aware of the issue...

    The problem with the Forum is that it is mostly people like you and I... Sometimes an actual Microsoft person gets involved, but for the most part, an issue posted on the forum is not likely to be seen by the people that can actually fix it...

    Microsoft has introduced a "Feedback Hub" to address this type of issue, which supposedly IS seen by the appropriate people...

    Was this answer helpful?

    0 comments No comments