Registry tweaks – Administration and Security


  • 1. get complete access to a registry key and restore the changed settings.

    Modify permissions or owner to obtain full access to the registry key.

    1) click on Start and type regedit in the search string
    2) click on results, and then right-click Run as administrator.
    3) open the registry key whose rights you want to edit.
    4) in the list on the left, click on this registry key and select Permissions.
    5) click the Administrators group:
    6) select the allow Full control permissions, and then click OK.
    7) if the check box is unavailable or you see an error message, click Advanced, and then click the Owner tab.
    8) left click on your account, select the Replace owner on subcontainers and objects check box, and then click OK.
    9) select the Administrators group to select the Full control check box, and then click OK.

    Return of the original rights owner and recovery.
    To maintain system security, after you make changes to the registry and restore reset the right owner.

    1) right-click the registry key whose rights you want to restore, and then click Permissions.
    2) click the Administrators group:
    3) uncheck the allow Full control permissions, and then click apply.
    4) click Advanced, and then click the Owner tab.
    5) click on Other users or groups… and as the name of the object in the text box, type:
    NT SERVICE\TrustedInstaller owner was the TrustedInstaller account, if the owner of an account System (on an English Windows 7 you need to enter the System)
    6) in the Change owner to: choose the TrustedInstaller or System.
    7) select the Replace owner on subcontainers and objects check box, and then click OK.

  • 2. Remove information on used USB flash drive.

    1) start Registry Editor (Win + R-> regedit-> Ok)
    2) open branch:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USBSTOR

    Here you will see a list of topics for plug-ins ever Flash drives to your system.
    3) locate the Flash drive, mention of which you want to remove from the registry. (Example: Disk & Ven_Corsair & Prod_Flash_Voyager & Rev_1100)
    4) open the section.
    The path to the branch, in my example:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USBSTOR\Disk&Ven_Corsair&Prod_Flash_Voyager&Rev_1100
    

    5) in this thread you will see a subkey (for example: AB00000000005136&0)
    The path to the branch, in my example:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USBSTOR\Disk&Ven_Corsair&Prod_Flash_Voyager&Rev_1100\AB00000000005136&0

    6) open the registry branch:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB

    7) lifting off each of the sections of this line, locate the subkey contains the name of AB00000000005136
    The path to the branch, in my example:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_090C&PID_1000\AB00000000005136

    8) remove found a registry hive. In my example, you must remove the following line:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USBSTOR\Disk&Ven_Corsair&Prod_Flash_Voyager&Rev_1100
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_090C&PID_1000

    9) then restart your computer.

  • 3. Remove Programs in safe mode with Windows Installer.

    In most cases, when you try to remove the program in Safe Mode, if the program does not use native installer (e.g. Winamp) you will get a warning message:

    The Windows Installer Service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance.

    To enable you to uninstall programs in Safe Mode, do the following:
    1) start Registry Editor (Win + R-> regedit-> Ok)
    2) open the branch HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
    3) create here section MSIService
    4) set default parameter string value Service.
    5) reboot the computer.

  • 4. Cancel limiting the use of commands in context menu when you select more than 15 files.

    As is known, when more than 15 files shortcut menu commands such as “Open/Print/Edit” are no longer available.
    To remove this limitation, do the following:

    1) start Registry Editor (Win + R-> regedit-> OK)
    2) open the branch HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
    3) create a DWORD parameter MultipleInvokePromptMinimum.
    4) select a value for this parameter is set to 16.

    To reduce the number of files on which the restriction of the use of commands, enter a value between 1 and 15.
    When you select files above the chosen values command on the shortcut menu will not apply. When you specify a value of 0 will disable commands, including commands “open”.

  • 5. disable signing verification for downloaded programs.

    1) go to Control Panel->Internet Options->Advanced tab
    2) uncheck “Check for signatures for downloaded programs” and select “Allow software to run or install even if the signature is invalid .”
    3) create and apply the .reg file:

    Windows Registry Editor Version 5.00
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies]
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations]
    "DefaultFileTypeRisk"=dword:00006152
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments]
    "HideZoneInfoOnProperties"=dword:00000001
    "SaveZoneInformation"=dword:00000002
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations]
    "LowRiskFileTypes"=".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;"
    
  • 6. Remove stale icons from the taskbar notification area.

    After you install/run programs that are placed in the notification area, this list is growing all the time.
    Using the following registry tweek, can be left in the current dialogue display only those icons that are located in the notification area at the moment.

    Windows Registry Editor Version 5.00
    
    [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify]
    "PastIconsStream"=-
    "IconStreams"=-
    

    1) copy the code into any text editor (e.g. Notepad).
    2) press CTRL + S to save the file with any name and extension .reg
    3) If you choose the type of files: text files, the file name in quotation marks to be sure. (For example: “demo.reg”)
    4) If you choose the save as type: all files, the file name in quotation marks do not have to borrow.
    To apply changes, restart the Explorer.exe process, log off/log on or restart your computer.

    Download a .reg file, you can link: Clean_TrayNotify.zip

  • 7. clear history locations desktop backgrounds in Windows 7.

    In the settings window wallpaper (right-click on desktop->Personalise->Desktop Background) there is an item “Picture location” that contains a list of folders that store thumbnails that can be used as wallpaper. By default this list always has a reference to the four folders:

    1. Windows Desktop Backgrounds;
    2. Pictures Library;
    3. Top Rated Photos;
    4. Solid Colors.

    If you add a picture from a folder that is not in the list, the folder will automatically appear in this list. Over time, this list will grow, with new folders. If anything, in the list will contain folders, which are no longer physically on disk and write about them remains.

    To clear the list the Picture location from unnecessary entries and leave only the standard title, in section HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpapers\Images to remove all the parameters ID numbered from 0 to 9 that contain encrypted paths of images selected by the user.

    Now when you open the settings window wallpaper (right-click on desktop->Personalise->Desktop Background) in the Picture location you will see a list containing only the default entries.

  • 8. deleting folders and user profile Public.

    For quiet delete Public folders and user profile Public the following steps are recommended to clean the installed system. If your system is already installed, and it has already installed the program, before following the instructions below, copy all folders from C:\Users\Public\ in c: \Users\Your_Name\
    Option 1.
    1) at the command prompt (Start-> Run) type REGEDIT
    2) locate branch

    HKEY_CURRENT_USER\ Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
    

    3) then right-click in the right pane and select New->DWORD.
    4) give this parameter the name NoSharedDocuments and set it Value data to 1
    5) restart the computer
    Option 2.
    1) Go to the registry branch

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace

    2) remove the following line:

    {59031a47-3f72-44a7-89c5-5595fe6b30ee}

    3) Go to the registry branch

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\

    4) remove the following line (if any):

    {59031a47-3f72-44a7-89c5-5595fe6b30ee}

    Option 3.
    1) go to Control Panel\All Control Panel items\System (or Computer->Properties)
    2) open the Advanced system settings
    3) go to the Computer Name tab, and then Network ID…
    4) select This is a home computer…
    5) click Next, then Finish, then Ok
    6) reboot

    After use the solution to one of these options, perform the following actions:

    1) in the registry branch:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

    replace the values with C:\Users\Public\ on c: \Users\Your_Name\
    2) in the registry branch:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

    replace the values with %PUBLIC%\ the %USERPROFILE%\
    3) delete the folder (if they are):
    Drive C: C:\Users\Public\
    Libraries->Documents->Public

    Note: If you don’t want on your desktop appear duplicate icons files, do not set the value for Common Desktop that is identical to the desktop of your profile. For example, instead of c:\Users\Your_Name\Desktop type c:\Users\Your_Name\Public\Desktop and instead %USERPROFILE%\Desktop type %USERPROFILE%\Public\Desktop

  • 9. ban launch Windows Explorer context menu when you right-click.

    1) start Registry Editor.
    2) open the following registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    3) create a DWORD value
    4) rename it NoViewContextMenu
    5) change the value to 1.
    6) reboot the computer.

    You can also create and apply the .reg file to read as follows:
    Windows Registry Editor Version 5.00
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoViewContextMenu"=dword:00000001

  • 10. deleting the menu item File from Windows Explorer.

    1) start Registry Editor
    2) open the following registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    3) create a DWORD value
    4) rename it NoFileMenu
    5) change the value to 1.
    6) reboot the computer.
    You can also create and apply the .reg file to read as follows:
    Windows Registry Editor Version 5.00
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoFileMenu"=dword:00000001

    Note: This item is also removed from all locations that use the Windows shell
  • 11. Prohibition of startup programs.

    1) start Registry Editor
    2) open the following registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    3) create a DWORD value
    4) rename it RestrictRun
    5) change the value to 1.
    6) reboot the computer.
    7) create a subkey with the same name RestrictRun
    8) Create in section (HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun) list of allowed to launch programmes for the current user.
    8.1) create a String options
    8.2) specify a name for the generated string parameters, starting with 1 and further
    8.3) select option values path to your applications and their names. Files must be specified with the extension. For Example:
    1 REG_SZ Regedit.exe
    2 REG_SZ Calc.exe
    3 REG_SZ Iexplore.exe
    Don’t forget regedit.exe, so you can go into it and lift restrictions set by you!
    To reset the program limits must be set to key RestrictRun to 0 or delete it.

    If you forgot to enter regedit.exe in the list or have not created a subsection RestrictRun to disable startup programs. For lifting the ban, do the following:
    1) restart your computer.
    2) prior to starting Windows, press the F8 key, and then select Safe mode with command prompt
    3) at the command prompt type regedit and press Enter.
    4) go to branch HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    5) delete the RestrictRun key or set its value to 0.

  • 12. deleting entries from the history of dialog box “run”.

    If you are using the Run dialog box in the Start menu (Win + R), for deleting records from his stories, do the following.

    1) start Registry Editor: Win + R–> regedit
    2) open the following registry branch: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
    Commands entered by you previously stored as values of the parameters a, b, c, d and so on using the English alphabet.
    3) delete the unnecessary command, and it disappears from the history of dialogue “run”.

  • 13. Delete/restore warning window for changes in msconfig.

    If changes are made to the utility msconfig (System Configuration), system configuration window appears in which you are offered a choice: either a reboot or exit without restart.

    To disable this warning, select the don’t show this warning and the window will no longer appear.

    To restore the window:

    1) start Registry Editor (Win + R-> regedit-> Ok)
    2) open the branch HKCU\Software\Microsoft\Shared Tools\MsConfig
    3) remove NoRebootUI.

  • 14. remove extra entries from utility msconfig.

    If the utility msconfig (System Configuration) there are many records and you wish to delete. Do the following:

    1) start Registry Editor (Win + R-> regedit-> Ok)
    2) open the branch HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig
    3) browse all subkeys of the twigs and remove unnecessary you write.
    4) also records can be stored in the mscfgtlc.xml located in the folder C:\Windows\system32\. In 64-bit Windows this file is also located in the folder C:\Windows\SysWOW64\.
    5) Open this file with Notepad, delete the unnecessary records and save. If you want to remove all unnecessary entries, simply delete the file mscfgtlc.xml.

  • 15. disable reminders to reboot after installing the updates.

    1) start Registry Editor (Win + R-> regedit-> Ok)
    2) open the branch HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU.
    3) create a DWORD parameter NoAutoRebootWithLoggedOnUsers and give it a value of 1.
    or
    Open menu run (Win + R) and type:

    reg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /v NoAutoRebootWithLoggedOnUsers /t REG_DWORD /d 1

    For the changes to take effect log off/log on in the system or reboot your computer.
  • 16. starting multiple copies of the registry editor.

    Users who work with the Windows Registry Editor, you will have come across a situation where it is necessary to verify the contents of the branches of the registry. Very comfortable would open two registry editor, locate and compare them side by side. However, when you try to run a program, the system switches you to the open window of the program. Start by holding down Shift with too didn’t work.
    To run a second copy of the Registry Editor:
    1) open the menu “Run” (Win + R)
    2) Enter regedit using the -m option and press Enter.
    regedit -m

2 thoughts on “Registry tweaks – Administration and Security

    • Hi Mark

      If you do not reinstall Windows, then you will edit the registry using
      the computer boot from one of these CDs:
      1. LiveCD ( eg Hiren’s BootCD www.hirensbootcd.org/)
      2. WinPE
      3. Windows installation disk (select Repair your computer->command prompt)

Leave a Reply