Note: This tip only applies to Professional editions of Windows. That includes Windows XP Pro, Windows Vista Pro, and Windows 7 Pro. This will not work on Home editions.
The Registry is the heart of a Windows operating system. Almost all Windows configuration settings and options are stored there.
The Windows Registry is accessed through a system application called: the Registry Editor. It allows administrators to make crucial changes to the functionality of Windows (on that computer).
Still, the Registry is not to be taken lightly. Great care must be taken when digging around in it’s hierarchal structure.
Since it controls almost all Windows functions, even a small configuration error can render a computer useless (unless a complete operating system reinstall is performed).
Being so important, it’s no wonder that it’s often the first target when hackers or malicious software invade computers.
By restricting access to the Registry Editor, spyware and viruses can prevent their discovery and termination and can continue to corrupt the Registry with impunity.
To prevent this, the best security measure you can take, is to disable the Registry Editor yourself. This way you’ll keep your Registry safe from spyware and protect your computer from unintentional configuration mistakes.
Seeing how dangerous it is to make any changes to the Registry itself (especially if you’re not familiar with it), we are going to use the Local Group Policy Editor to disable and enable the Registry Editor.
Here’s how to open the Local Group Policy Editor on a local computer.
Note: To access the Local Group Policy Editor in Windows Vista and Windows 7 you must log in with an administrator account.
Go to the Start Menu and click on the Run command, situated above the Turn off Computer button. Then type the command gpedit.msc in the Open box (or the search field in Windows Vista or 7) and press the Enter key.
The Local Group Policy Editor will now open.
On the left side of the window, under User Configuration, double-click the Administrative Templates folder.
Then, under Administrative Templates, double-click the System folder.
On the right side of the window, under Setting, scroll down and double-click on the Prevent access to registry editing tools option.
In the Prevent access to registry editing tools window, check the box next to Enabled and click on the OK button to apply the changes and exit.
Then close the Local Group Policy Editor by clicking the red X (close) button on the top right.
To check if the Registry Editor has been disabled, go to the Start Menu and click on the Run command, situated above the Turn off Computer button. Then type the command regedit in the Open box (or the search field in Windows Vista or 7) and press the Enter key.
If everything went well, you should see the message: “Registry editing has been disabled by your administrator”.
In case no change was made and the editor still opens, just restart your computer.
Here’s how to enable the Registry Editor, if it’s already disabled by malicious software or if you want to make some changes.
Follow the same steps presented above until you reach the Prevent access to registry editing tools window. Here, check the box next to Disabled and click on the OK button to apply the changes and exit.
If the Registry Editor is still disabled, restart your computer to allow the changes to take effect.