Over the past several months Emissoft is finding these registry keys as being bad and run the clean/delete process.
Malwarebytes , SuperantiSpyware, and Comodo do not find these keys as malware. Not sure what is creating these keys, they have appeared in scans 6-7 times.
Here are the latest scan results:
Emsisoft Anti-Malware - Version 9.0
Last update: 7/24/2014 5:08:18 PM
User account: Martha-PC\Martha
Scan settings:
Scan type: Smart Scan
Objects: Rootkits, Memory, Traces, C:\Windows, C:\Program Files\
Detect PUPs: Off
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off
Scan start: 7/24/2014 6:57:25 PM
Value: HKEY_USERS\S-1-5-21-1943577299-1749160357-1101987479-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM → DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-1943577299-1749160357-1101987479-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM → DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-1943577299-1749160357-1101987479-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM → DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-21-1943577299-1749160357-1101987479-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM → DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
Scanned 199477
Found 4
Scan end: 7/24/2014 9:40:51 PM
Scan time: 2:43:26
Value: HKEY_USERS\S-1-5-21-1943577299-1749160357-1101987479-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM → DISABLEREGISTRYTOOLS Deleted Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-21-1943577299-1749160357-1101987479-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM → DISABLETASKMGR Deleted Setting.DisableTaskMgr (A)
Deleted 2
Thanks
UncleDoug