Hi malware fighters,
Regedit won't work and this could be because of you, an administrator or malware intervened.
Unless you or an administrator has applied this policy in your system for the users,
it is safe to have freefixer or HijackThis fix this entry (one of so-called 07 restrictions)
HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1
(there could also be one or more additional 04 entries involved with worms and trojans of this sort)
The malcreants without the victim noticing changed a registry key,
so one can no longer access regedit.
It is a component of malware or spyware,
you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the forum.
Name of trojan activity: DisableRegedit
HijackThis Category: O7
HijackThis Line:
O7 – HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
Description: Disabled Regedit tools is a signature of trojan activity
How to remove: Use HijackThis, freefixer or Use Malwarebytes Antimalware
A work-around is to download freefixer.
You find it here: (
http://www.freefixer.com/static/freefixersetup.exe).
Install, perform a scan and maybe you encounter this item:
HKCU Software Microsoft WindowsCurrent VersionPoliciesSystem, DisableRegedit=1
That is the cause of your predicament. Select this item and click"fix checked"
and then restart your computer.
How to use MBAM here:
Download MalwareBytes' Anti-Malware:
http://www.besttechie.net/mbam/mbam-setup.exethen download it onto your desktop.
Double click mbam-setup.exe to install the program.
See to it that after install there are tags next to:
Update MalwareBytes' Anti-Malware
Start MalwareBytes' Anti-Malware
Then click "Finish".
Whenever an update is available , that will be downloaded and installed.
As soon as the program is started, go to the tab window "General Settings".
Here you tag: "Close Internet Explorer during removal of malware".
Then go to tab window "Scanner", choose "Quick Scan".
Then click "Scan" to start the scan.
Scanning may take a while so be patient.
When the sacn has finished, you click OK, then view "View results" to see results.
See to it that everything is tagged there, and then click: "Remove selected".
After removal a log will open and you will be asked to restart the computer.
The log will be automatically be saved by MalwareBytes' Anti-Malware
and can be found by clicking the "Logs" tab inside the program.
Now a practical example description of a worm that disables regedit
in this fashion and how to remove it can be found here:
http://www.quickheal.co.in/alerts/archives/alerts-Worm-VB-jp.asppolonus