Personally I think you will be fighting a losing battle trying to look at the registry to determine what people are using and trying to prevent it. If that is your goal then use policies to only allow AUTHORIZED applications to be run, then nothing can be run except those applications on your list.

Though on a side note I still don't really see the reasoning behind this. If an employee can not be trusted to do his/her work then let them go and hire someone else that will.