Lock Down Run keys in HKEY_USERS

Townshend

New member
Local time
1:20 PM
Messages
6
I would like to lock down the Run keys in the HKEY_USERS hive to prevent malware. I know in Group Policy you can enable "Do Not Process The Legacy Run List" however that also restricts HKLM which is locked down to non-admins and I would still like programs to run from there. Any suggestions on how I can accomplish?

Thanks!
 

My Computer

OS
Windows 7, Vista, XP
Install an anti-virus suit of software. That is how you prevent malware. Any real nasty malware is not going to be affected by your restricted user startup programs.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Been using Norton Antivirus but finding it doesn't always disallow malicious software from inserting itself into HKCU. Norton does not always stop everything even with the latest defs.
 

My Computer

OS
Windows 7, Vista, XP
You could try WinPatrol. When it detects a new startup it asks if you wish to allow it. I've used it for years. Although BillP Studios is selling WinPatrol. I believe it's still in a transition state. But if that makes you paranoid you can always download the free version a few releases back.
 

My Computer

Computer Manufacturer/Model Number
HP Media Center
OS
Windows 7 32 bit
CPU
AMD 5200+ dual core
Memory
2 GB
Graphics Card(s)
NVidia GeForce 6150SE 128 MB
Monitor(s) Displays
CRT
Screen Resolution
1280x1024
Hard Drives
500 GB Sata internal :

SIIG USB 3.0 docking stations w/WD Caviar Black 6 Gb/s drives
Keyboard
PS/2
Mouse
PS/2 Wheel Mouse
Other Info
SIIG USB 3.0 PCIexpress card.
Ideally I wanted to avoid utilizing 3rd party software and either utilize Group Policy or a logon script of some sort but I'll certainly take a look. Thanks for the suggestion!
 

My Computer

OS
Windows 7, Vista, XP
The trouble with group policy is it runs as the user who set the policy. I tried using it to prevent IE from being run. During the install of a program IE popped up. Windows installer has a higher security rating than my normal admin account it seems.

Perhaps some system administrator who runs a domain knows the right way to do it.
 

My Computer

Computer Manufacturer/Model Number
HP Media Center
OS
Windows 7 32 bit
CPU
AMD 5200+ dual core
Memory
2 GB
Graphics Card(s)
NVidia GeForce 6150SE 128 MB
Monitor(s) Displays
CRT
Screen Resolution
1280x1024
Hard Drives
500 GB Sata internal :

SIIG USB 3.0 docking stations w/WD Caviar Black 6 Gb/s drives
Keyboard
PS/2
Mouse
PS/2 Wheel Mouse
Other Info
SIIG USB 3.0 PCIexpress card.
Back
Top