Platinum Edition Using Windows 98

Previous chapterNext chapterContents


- 20 -

Advanced Registry Hacks


by Jerry Honeycutt

Editing a Remote Computer's Registry

Remote administration enables you to inspect and change settings on one computer from another computer on the network. Typically, you change settings on the target (remote) computer from an administrative computer.

The cornerstone of Windows 98's remote administration capabilities is, of course, remote Registry administration. In fact, many of the other remote administration tools you learn about in this book, such as System Monitor, rely on the remote Registry to provide the information the tool uses. Closer to home, you can browse a remote computer's Registry or define policies that specify what users can and can't do on the remote computer.

Both the target and administrative computers must meet the following requirements to support remote Registry administration:


Creating a Custom Setup Script

Did you deploy Windows 98 without enabling remote administration? If so, you'll have to manually enable remote administration on each workstation in order to take advantage of the tools this chapter describes. Alternatively, you can enable remote administration using the System Policy Editor, as described in Chapter 38, "Configuring Windows Network Components."

If you haven't yet deployed Windows 98, however, you can use a custom setup script to enable remote administration as Setup installs Windows 98. Here's how. Copy the Windows 98 source files to an installation on the server and share that folder. Create a setup script in the MSBATCH.INF format that enables remote administration. Provide a means by which the user can launch Setup with the setup script, using either push or pull installation methods. (The section "Advanced Installation Techniques" in Appendix A, "Installing Windows 98," describes how to use login scripts to push the Windows 98 installation and how to email a batch file to the user so that he can pull the installation when he's ready.)


Enabling the Remote Registry Service

As you learned in the preceding section, before you can use remote Registry administration, you have to enable the Remote Registry Service on the target and administrative computers. Follow these steps:

1. Open the Network dialog box by double-clicking the Network icon in the Control Panel.

2.
Click Add to display the list of network components.

3.
Select Service from the components list and click Add. Windows 98 might pause for a moment while it builds a driver information database. The Select Network Service dialog box appears, as shown in Figure 20.1.

4.
Click Have Disk to locate the Remote Registry Service on your Windows 98 CD-ROM. Then, in the dialog box that appears, type the path to the Remote Registry Service's installation files. (These files are located in \Tools\Reskit\Netadmin\Remotreg on the Windows 98 CD-ROM.) Click OK to continue, and you again see the Select Network Service dialog box.

FIG. 20.1 The services you see in this dialog box are described in the Remote Registry Service's INF file (REGSRV.INF).

5. Select Microsoft Remote Registry from the list and click OK.

6.
In the Network properties sheet, click OK. Windows 98 copies the appropriate files to your computer.

7.
Restart your computer when prompted.

Opening a Remote Computer's Registry

Connecting to a remote computer's Registry gives you full access to it. You must be as careful editing a remote computer's Registry as you would be editing your own, because the implications of making careless changes are just as bad. Note that even though the changes you make are immediately reflected in the remote computer's Registry, the user might have to reboot his computer in order to reflect those changes in the rest of the operating system or in the applications that depend on those settings. As a general rule of thumb, if the user would have to restart his computer after making a change in the Control Panel, he'll have to restart it after you make a similar change in the Registry.

Use the following steps to open a remote computer's Registry in the Registry Editor:

1. Open the Registry Editor by typing regedit in the Run dialog box and pressing Enter.

2.
From the main menu, choose Registry, Connect Network Registry. You see the Connect Network Registry dialog box.

3.
Type the name of the remote computer, or click Browse and select the computer in the dialog box that appears. Click OK, and you see the remote computer's Registry in the Registry Editor (see Figure 20.2).

FIG. 20.2 At any given time, the Registry Editor shows all the Registries to which you are connected.

After you connect to the remote computer's Registry, everything works the same as usual. For example, you can add and remove Registry keys, and you can add, remove, and change value entries. Just make sure that you're selecting keys and value entries in the computer that you intend. Otherwise, you might change a Registry key on your own computer when you really intended to change a key on the remote computer.

Using the System Policy Editor

The System Policy Editor enables you to define restrictions that control the user's configuration. You can enforce a certain network configuration, for instance, or remove certain icons from the user's desktop. Figure 20.3 shows the System Policy Editor.

You learn how to use the System Policy Editor in Chapter 38. This chapter shows you how to install the System Policy Editor, set up machine and user policies, and apply policies to individual users, groups, and machines.

The System Policy Editor provides access to a subset of the remote computer's Registry, whereas the Registry Editor gives you complete access to the Registry.

FIG. 20.3 Many of the forms in the System Policy Editor use drop-down list boxes to minimize the chance of error.


CAUTION: In many cases, the System Policy Editor is a better alternative than the Registry Editor because the risks are not as great when you use the System Policy Editor.

You have two options for using the System Policy Editor. The first is to create policy files that Windows 98 downloads from the network server and merges with the Registry. The second is to use the System Policy Editor in Registry mode, which allows you to change the remote Registry directly. Regardless of which method you use, you specify the values you want to change and their data by using forms and data-entry fields that make sense in their context. (In the Registry Editor, on the other hand, it's an editing free-for-all.)

To connect to a remote computer's Registry in the System Policy Editor, use the following steps:

1. Open the System Policy Editor.

2.
From the main menu, choose File, Connect.

3.
Type the name of the computer to which you want to connect, and then click OK.


TROUBLESHOOTING:

I can't connect to a remote computer, even though I've enabled remote administration on the remote computer. You must enable remote administration and the Remote Registry Service on both computers. Make sure the Remote Registry Service is enabled on the computer from which you're administering as well as on the computer you're administering.

I can't administer a remote computer now, even though I've been able to administer the same computer before. Remote administration works only if someone is logged on to the remote computer. Thus, make sure someone is logged on before you attempt to administer the computer.




TIP: To learn more about working with and administering the Windows 98 Registry, take a look at Using the Windows 98 Registry (Que, 1998). This book covers the Registry's organization in detail, discusses each of the tools that are available for managing the Registry, and shows you how to leverage the Registry in your organization.

Troubleshooting the Registry

The following sections contain information about specific tools and techniques you can use to diagnose and fix problems with the Registry. The following list contains answers to some of the most common questions and problems related to the Registry:

Fixing the Registry with the Registry Checker

As you learned in Chapter 19, "Working with the Windows Registry," Windows 98 runs the Windows Registry Checker each time you start your computer. The first time it runs each day, the Windows Registry Checker makes a backup of the Registry and stores the backup in a .CAB file that it stores in \Windows\Sysbckup.

You use the Registry Checker to scan the Registry for errors and fix them. Windows 98 includes two versions of the Registry Checker: one for MS-DOS and one for Windows. The MS-DOS version is a program called SCANREG.EXE, and the Windows version is a file called SCANREGW.EXE. Both versions can scan the Registry for errors, but only the MS-DOS version can restore backup copies of the Registry or actually repair a damaged Registry. Table 20.1 describes the command-line parameters you can use with both versions of the Registry Checker. Note that /restore and /fix work only with the MS-DOS version.

Table 20.1  Command-Line Parameters for Registry Checker

Parameter Description
/backup Backs up the Windows Registry
/restore Restores a backup copy of the Registry
"/comment" Associates a comment with a Registry backup
/fix Fixes any errors found in the Registry
/autoscan Scans for errors and backs up the Registry
/scanonly Scans for errors without backing up the Registry


NOTE: Chapter 19 contains more information about using and configuring the Registry Checker. You learn how to increase the number of backup copies the Registry Checker keeps, for instance. 

Manually Removing Program Settings from the Registry

The way most programs use the Registry is rather predictable. They all store the same types of information in the same types of places. You can use this fact to help you successfully remove a program from the Registry.


TIP: Before you begin, back up the Registry. You'll be making significant changes to the Registry, and it's comforting to know you have a way out if things get out of hand.

First, delete all the program's installation folders. Most Windows 98 programs are installed in the folder C:\Program Files.

After you've removed the program's files, open the Registry Editor. Search the Registry for any entry that belongs to that program, and then remove it. The following list suggests some types of things you should search for:


TIP: If you find a key whose default value entry contains the name or path of the program you're removing, it's probably safe to remove the entire key, even if it has subkeys.


TROUBLESHOOTING:

I can't start Windows 98 after I install a particular program. The program is loading shell extensions, drivers, or other files when Windows 98 starts, and those files are causing it to crash. Restart your computer and press F8 when Windows 98 displays the message Starting Windows 98. When the Startup menu appears, choose Command Prompt Only. Then completely delete the program's installation folder and subfolders (normally found under C:\Program Files). When you finish, restart Windows 98. You'll see a few messages about missing files, but Windows 98 will start successfully. Finally, remove the program's Registry entries using the steps in this section. After you remove the program's Registry entries, you won't see the messages about missing files.


Using Windows 98 to Repair the Registry

In most cases, you don't have to use the Registry Editor to repair the Registry. You can let Windows 98 do it for you. In fact, Windows will fix some errors before you even know they exist. The following list describes three techniques you can use to fix the most common problems associated with configuration data in the Registry:


NOTE: If the Add New Hardware Wizard doesn't fix the problem, you'll need to remove the device from the Device Manager and then try the wizard again. To remove the device, double-click the Control Panel's System icon and click the Device Manager tab. Delete the device from the list and click OK to save your changes. 


TIP: Many programs use .REG files to create their settings in the Registry. You might be able to use the .REG file again to restore the damaged settings without reinstalling the program. Look in the program's installation folders for a .REG file, and then inspect it by right-clicking the file and choosing Open. If it looks like it will fix your problem, double-click the file to merge its settings with the Registry.

FIG. 20.4 The bottom part of the File Types tab describes the extensions associated with the selected file type and the application that opens the file.

Configuring Windows 98 via the Registry

The following sections describe a variety of settings you can configure using the Windows 98 Registry. You won't find step-by-step instructions in these sections, however, because the instructions are very repetitive:

1. Open the Registry Editor.

2.
Locate the given Registry key.

3.
Add, change, or remove the given value entry.

4.
Close the Registry Editor and restart the computer if necessary.


ON THE WEB: The Windows 98 Annoyances web page contains a variety of customizations for Windows 98. You'll also find tips there that don't involve editing the Registry.

http://www.creativelement.com/win98ann


Adding Actions to the Context Menus

If you have more than one program that can access the same type of file, you'll want to add an action to the file extension's context menu that allows you to choose between the two programs. This gives you two options for opening a file: You can open with program A or open with program B, for example.

To better understand this, take a look at .DOC files. When you install Windows, it associates WordPad with .DOC files. WordPad is a fast editor that is file-compatible with Microsoft Word. The trouble begins when you install Microsoft Word. It associates .DOC files with itself--leaving you without a convenient way to open a .DOC file in WordPad if you so choose. To make it easy to open the file in WordPad, you can add a new action to the .DOC file's context menu that allows you to open .DOC files with WordPad, too. Here's how:

1. Add a subkey called \Open with Wordpad to the key HKEY_CLASSES_ROOT\ Word.Document.6\shell.

2.
Under the new subkey, add another subkey called \command and set its default value entry to c:\Program Files\Accessories\WordPad.exe "%1".


NOTE: The quotation marks around the %1 in the command line tell Windows 98 to put the file name inside quotation marks. The %1 is called a placeholder. If you don't put "%1" in the command line and you select a long filename with spaces in it, WordPad won't be able to open the file. 

Now you can open .DOC files with either Microsoft Word or WordPad. Double-click a .DOC file to open it in Word. Right-click a .DOC file and choose Open with WordPad to open it in WordPad.

Changing the Desktop Icons

You're not stuck with the icons or icon names that Windows 98 and NT use for the special desktop icons (My Computer, Recycle Bin, and so on). You can change them all by following these guidelines:

Table 20.2  Subkeys for Changing Desktop Icons

Name Subkey
Briefcase {85BBD920-42A0-1069-A2E4-08002B30309D}
Control Panel {21EC2020-3AEA-1069-A2DD-08002B30309D}
Dial-Up Networking {992CFFA0-F557-101A-88EC-00DD010CCC48}
Inbox {00020D75-0000-0000-C000-000000000046}
My Computer {20D04FE0-3AEA-1069-A2D8-08002B30309D}
Network {208D2C60-3AEA-1069-A2D7-08002B30309D}
Printers {2227A280-3AEA-1069-A2DE-08002B30309D}
Recycle Bin {645FF040-5081-101B-9F08-00AA002F954E}
The Internet {FBF23B42-E3F0-101B-8488-00AA003E56F8}
Microsoft Network {00028B00-0000-0000-C000-000000000046}


NOTE: Most .EXE and .DLL files have icons in them. You'll find that some DLLs--such as MORICONS.DLL, COOL.DLL, PIFMGR.DLL, PROGMAN.DLL, and SHELL32.DLL in your \Windows or \Windows\System folder--have a large number of useful icons. 

Changing the Location of System Folders

Have you ever tried to move the \ShellNew folder to a new location? How about the \My Documents folder? You can't unless you do so through the Registry. Delete any of these folders, if you can, and Windows creates the folder when you restart your computer. Windows keeps a list of shell folders in the Registry. This is how it knows where to find things such as your Start menu, desktop shortcuts, and recent documents.

You find these shell folders at HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\Shell Folders. Table 20.3 shows you the value entries you'll find in Windows 98.

Table 20.3  Default Shell Folders in Windows 98

Value Entry Default
Desktop C:\WINDOWS\Desktop
Favorites C:\WINDOWS\Favorites
Fonts C:\WINDOWS\Fonts
NetHood C:\WINDOWS\NetHood
Personal C:\My Documents
Programs C:\WINDOWS\Start Menu\Programs
Recent C:\WINDOWS\Recent
SendTo C:\WINDOWS\SendTo
Start Menu C:\WINDOWS\Start Menu
Startup C:\WINDOWS\Start Menu\Programs\Startup\
Templates C:\WINDOWS\ShellNew

Launching Explorer from My Computer

There are many different ways to get to Explorer. You can launch it from the Start menu. You can right-click My Computer and choose Explore. You can even double-click My Computer while you hold down the Shift key. So why can't you launch Explorer just by double-clicking My Computer? Well, you can. To do so, change the default value entry for HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\Shell to explore.

Viewing Unknown File Types

Have you ever right-clicked CONFIG.SYS, hoping to open it in Notepad, only to find the Open With menu option? .SYS files are registered as system files and have no commands associated with them. There are plenty of other files that would be useful to open in Notepad that have no commands associated with them. You can remedy this situation, however, by associating Notepad with all unknown file types. Then, the next time you right-click on Config.sys or any other unregistered file type, you'll see Notepad on the context menu. Here's how:

1. Add a subkey called \Notepad to the HKEY_CLASSES_ROOT\Unknown\Shell Registry key.

2.
Under the new key, add a subkey called command and set its default value entry to C:\Windows\Notepad.exe "%1".

Comparing Snapshots of the Registry

Before you begin, make sure you understand how the Registry is organized. That means take a closer look at Chapter 19. A full understanding of this information can lead you to some of the best customizations.

The easiest way to find changes in the Registry is to compare a version of it before and after Windows 98 (or another program) makes a change. To do that, however, you need a program to compare two text files and point out the changes. I haven't found such a program on the Internet, but you'll find one included with Norton Utilities for Windows 98, Norton Navigator, Microsoft Win32 SDK, and Premia's Codewright for Windows 95. Many other utilities also include a program that compares two text files. The following example uses WinDiff from the Win32 SDK. Microsoft Word also allows you to compare two text files.

With the comparison tool in hand, use the following process to pin down a change made to the Registry:

1. Export the Registry to a .REG file, as you learned how to do in Chapter 19. Name this file BEFORE.REG.

2.
Close the Registry Editor and run the program you believe will change the Registry. For instance, start Windows Explorer and change your settings in the Folder Options dialog box. Then close the program.

3.
Open the Registry Editor and export the Registry to another .REG file called AFTER.REG.

4.
Use the comparison utility to identify each change between the before and after versions of the .REG files.

You won't always be able to figure out which program on your computer will change a particular value entry. For that matter, you might not be able to figure out what actions on your part will cause a value entry to be changed. In these cases, you might have to resort to tinkering with the value entry until you see a noticeable change. Modifying the value entry is generally safe as long as you can re-create the previous value when things go awry. It's easy to give yourself some insurance. Create a temporary value entry and copy into it the contents of the entry that you're changing. If anything goes wrong, you can copy the contents that you saved back into the original entry.

Distributing Registry Hacks via .REG Files

.REG files are text files that you can easily import into the Registry. In fact, when you double-click a .REG file, Windows automatically imports it into the Registry by default. This fact makes it easy for you to distribute the .REG file. When the user opens it, Windows 95 automatically makes the changes that the .REG file contains.


CAUTION: Don't double-click a .REG file unless you know for sure what it contains. Double-clicking a .REG file merges its contents into the Registry without any confirmation.

.REG files resemble .INI files. Take a look at the following listing. The first line always contains REGEDIT4. This indicates that the file was created by REGEDIT. The remainder of the listing contains keys and value entries you'd normally find under HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\FS Templates:

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\FS Templates]
@="Server"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ ¬FS Templates\Desktop]
@="Desktop computer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ ¬FS Templates\Mobile]
@="Mobile or docking system"
"PathCache"=hex:10,00,00,00
"NameCache"=hex:51,01,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ ¬FS Templates\Server]
@="Network server"
"PathCache"=hex:40,00,00,00
"NameCache"=hex:a9,0a,00,00

The file is split into multiple sections, with each Registry key in its own section. The fully qualified name of the Registry file key is given--that is, you see the entire name of the path to that key, beginning with the name of the root key--between two brackets. Each value entry for a key is listed under that key's section. The value entry's name is quoted, except for default value entries, which REGEDIT represents with the at sign (@). The value entry's data looks different depending on its type, as shown in Table 20.4.

Table 20.4  Formats for String, DWORD, and HEX Data

Type Example
String "This is a string value"
DWORD DWORD:00000001
HEX HEX:FF,00,FF,00,FF,00,FF,00,FF,00,FF,00

Creating .REG Files by Hand

Creating a .REG file by hand is easy enough. Create a new file with the .REG extension. Then follow these steps:

1. Put REGEDIT4 at the very top of the file. This must be the very first line in the file. Also, make sure that you insert one blank line between REGEDIT4 and the first section of the .REG file, as just shown in the listing.

2.
Add a section for each key that you want to add to or change in the Registry. Put each key name in square brackets, like this: [Keyname]. Make sure that you use the fully qualified path to the key, beginning with the root key.

3.
Put an entry under each key for each value entry that you want to add or change. Each entry has the form "Name"=Value, where Name is the name of the value entry that you're adding or changing. If you're changing the default value entry, use the at sign (@) for Name, without the quotation marks. Value is the value to which you want to set the value entry. Make sure it follows one of the forms shown in Table 20.4.

4.
Save your changes to the .REG file.


NOTE: You can't use a .REG file to remove a key from the Registry. If you need to create a script to do this, consider building an .INF file. The Windows 95 Resource Kit contains complete information about building .INF files. 

Creating .REG Files Using REGEDIT

Creating .REG files by hand seems easy enough, but it's not recommended. There are entirely too many opportunities for error--especially if you're a bad typist. Thus, you should use REGEDIT if at all possible. Chapter 19 shows you how to export a branch of the Registry to a .REG file.

You should be aware of a couple issues when you use this technique:

Distributing .REG Files to Users

A good way to impress the users that you support is to distribute fixes to them without their asking. If you have an intranet in your organization, you can make .REG files available on a web page. Lacking an intranet, you can also distribute .REG files in mail messages or in the user's login script:


Previous chapterNext chapterContents


© Copyright, Macmillan Computer Publishing. All rights reserved.