You'd have to hook the writes if you want to have it effective for local admins as well. Haven't seen a product that does that.
Thanks, Brian Desmond br...@briandesmond.com c - 312.731.3132 From: David Lum [mailto:david....@nwea.org] Sent: Monday, April 27, 2009 1:15 PM To: NT System Admin Issues Subject: Prevent mods to HKLM\Software\Microsoft\CurrentVersion\Run Is there a GPO way to prevent something from modifying this registry key? If I could prevent that and stuff from auto-populating the \Startup folder for "all users" I would be a happy camper. Tools like Spybot can do it, but that's not enterprise grade (read, centrally manageable). McAfee has a product that can do it - and we even have it and are licensed for it, but it's interface is so atrocious I'd probably nuke half my systems just attempting it. I'm looking for something other than "not local admin". David Lum // SYSTEMS ENGINEER NORTHWEST EVALUATION ASSOCIATION (Desk) 971.222.1025 // (Cell) 503.267.9764 ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~