What is Deleting this Registry Key?

Discussion in 'other software & services' started by Krusty, Mar 8, 2018.

  1. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
  2. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Do you run the Registry Cleaner Module in CCleaner? You are not using PrivaZer are you?
     
  3. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Krusty I have CCleaner > Cleaner > Applications > Windows > RegEdit ticked and the key is not removed here.

    It does sound like a cleaner issue though, you may have ticked some other non-default option.
     
    Last edited: Mar 8, 2018
  4. pegas

    pegas Registered Member

    Joined:
    May 22, 2008
    Posts:
    2,966
    Aren't you using CCenhancer?
     
  5. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    No.
    I do use PrivaZer but I have the Registry cleaning disabled. The problem is though that key is being deleted without running PrivaZer so I can rule that out.
    No.
     
  6. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Paul, which Windows Explorer options have you enabled?
     
  7. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
  8. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I would not rule PrivaZer completely out. Maybe there is something hidden in the settings you are not seeing, or maybe PrivaZer has something that runs you are not aware of. I would give it an extra look over. Also check to see if PrivaZer has some sort of maintenance process that runs when you are not using it manually.
     
  9. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Just the defaults (I think): MS Management Console, MS Search, RegEdit.

    CCEnhancer adds many options under Windows, but I have not selected any of them.
     
  10. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Paul, these?

    CCleaner.PNG

    But PrivaZer doesn't do anything until I run it. There is no background cleanup in the free version.
     
  11. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
  12. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Sorry I thought you meant Applications > Windows ...

    I don't have 'Recent Documents' ticked.
     
  13. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Does that key belong to Blackfog Privacy?
     
  14. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    No that is the key we need from M$ to receive updates.
     
  15. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,068
    Location:
    UK
    You can right-click on blue Windows Explorer in the CCleaner list and select restore default state.
     
  16. stackz

    stackz Registered Member

    Joined:
    Dec 27, 2007
    Posts:
    646
    Location:
    Sydney Australia
    You could capture the culprit with Process Monitor and a custom filter. Just capture registry events and set the filter:
    Code:
    Path contains HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat then Include
    
     
  17. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Thanks stapp. That's a neat trick I didn't know about.

    I just ran WD Update and received new definitions, then restarted and sure enough the key was recreated. I've run CCleaner in almost default state and the key is still there, so I'll have to see what happens from there.

    Thanks everyone! :thumb:
     
  18. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    That sounds like a plan. I'll have to look into that as I've never used Process Monitor. If CCleaner isn't the cause how would I reproduce though?
     
  19. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    You can set up registry key auditing under Local Security Policy settings to audit what is deleting the key, but it might be a little complicated. Here is a video on how to do it for folders, and files. The difference in enabling auditing for registry hives, or keys is you right click the registry folder (qualitycom), and select Permission to audit the registry key. He selects Properties on the file to enable auditing for the file, but you have to select Permissions and then select Advanced on the registry folder to enable logging for the registry key. Then you can go back, and look at the Security Log in Windows Event Viewer to see if it records what is deleting the key. It should work. https://www.youtube.com/watch?v=gAsXy6_X-L8
     

    Attached Files:

    Last edited: Mar 8, 2018
  20. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,010
    Location:
    Member state of European Union
    Maybe use Registry Guard?
     
  21. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    That would probably do the trick but creating custom rules is over my pay grade.
     
  22. guest

    guest Guest

  23. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
  24. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    The reg key value referenced is used by AV vendors to certify that their software is compatible with recent changes MS made for the Spectre motigation. If the key value does not exist, Win Update processing will not serve up OS and Microsoft app updates; either automatically or manually.

    This reg key value is normally set by AV software vendors but at least in the past could be manually created. My current understanding is if Windows Defender is the active realtime AV, this key is not necessary; Win Updating will be performed unimpeded. So if Windows Defender is your active AV solution and you are able to receive Win Updates, I would not be concerned about the key not being present.
     
    Last edited: Mar 8, 2018
  25. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    I'm on a machine running WD now. The key was present yesterday but it isn't today.
    That sounds good but WD (or maybe Malwarebytes?) appears to create it and something is removing it.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.