[*Global]
Revision=2012
NextIDValue=2145
;
; WARNING - DO NOT EDIT THIS FILE
; If you would like to create custom entries then create a new file
; called winapp2.ini which follows the same format as this one.
; CCleaner will automatically pick up the new file.
;
; Copyright ©2004-2009 Piriform Ltd, All Rights Reserved.
; This file and it's contents may not be copied or distributed
; without the express permission of the author.
;
; Notes
; ---------------------------------------
; LangSecRef
; 3021 = Applications
; 3022 = Internet
; 3023 = Multimedia
; 3024 = Utilities
; 3025 = Windows
; 3026 = Firefox/Mozilla
; 3027 = Opera
; 3028 = Safari
[*32bit Web Browser]
LangSecRef=3022
DetectFile=%ProgramFiles%\32BITWEB\32BW.exe
Default=False
FileKey1=%ProgramFiles%\32BITWEB\Data|LastURL.dat
FileKey2=%ProgramFiles%\32BITWEB\Data|LastURL.DA0
[*3GP Video Converter]
LangSecRef=3023
Detect=HKCU\Software\ImTOO\3GP Video Converter
Default=False
RegKey1=HKCU\Software\ImTOO\3GP Video Converter\Settings|last_openpath
RegKey2=HKCU\Software\ImTOO\3GP Video Converter\Settings|OuputDir
[*7-Zip]
LangSecRef=3024
Default=False
Detect=HKCU\SOFTWARE\7-ZIP\
RegKey1=HKCU\SOFTWARE\7-ZIP\Compression\ArcHistory
RegKey2=HKCU\SOFTWARE\7-ZIP\Extraction\PathHistory
RegKey3=HKCU\Software\7-Zip\FM|CopyHistory
RegKey4=HKCU\Software\7-Zip\FM|FolderHistory
RegKey5=HKCU\Software\7-Zip\FM|PanelPath0
[*A-squared Free]
LangSecRef=3024
Detect=HKLM\Software\Emsi Software GmbH\a-squared Free
Default=False
FileKey1=%userprofile%\My Documents\a-squared\Reports|*.*
FileKey2=%programfiles%\a-squared Free\Logs|*.*
[*AI Roboform Search]
LangSecRef=3022
Detect=HKCU\Software\Siber Systems
Default=False
RegKey1=HKCU\Software\Siber Systems\RoboForm\Query-MRU
[*AOL AIM Messenger]
Default=False
DetectFile=%userprofile%\Application Data\acccore\caches\bart
FileKey1=%userprofile%\Application Data\acccore\caches\bart|*.*|RECURSE
fileKey2=%userprofile%\Local Settings\Application Data\AIM\Settings\aolbartcache|*.*|RECURSE
LangSecRef=3022
[*AOL Instant Messenger]
LangSecRef=3022
Detect=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion
Default=False
RegKey1=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent IM ScreenNames
RegKey2=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent ScreenNames
RegKey3=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\Users
[*AVG Anti-Spyware]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\AVGAntiSpyware
Default=False
FileKey1=%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5|logfile.txt
[*AVG AntiVirus 8.0]
: Modified to handle AVG Temp folder
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|*.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|*.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|*.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|*.*
FileKey5=%allusersprofile%\Application Data\avg8\temp|*.tmp
[*AVG AntiVirus 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|*.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|*.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|*.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|*.*
[*AVG AntiVirus 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|*.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|*.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|*.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|*.*
FileKey5=%allusersprofile%\Application Data\avg8\Emc\Log|*.log
[*AVG AntiVirus 9.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg9
Default=False
FileKey1=%allusersprofile%\Application Data\avg9\Log|*.log
FileKey2=%allusersprofile%\Application Data\avg9\scanlogs|*.log
FileKey3=%allusersprofile%\Application Data\avg9\Log|*.xml
FileKey4=%allusersprofile%\Application Data\avg9\update\backup|*.*
FileKey5=%allusersprofile%\Application Data\avg9\Emc\Log|*.log
[*AVI Preview]
LangSecRef=3023
Detect=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit www.avipreview.com for more
Default=False
RegKey1=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit www.avipreview.com for more\Recent File List
[*AVS Disc Creator (Logs)]
LangSecRef=3021
Detect=HKLM\Software\AVS\DiscCreator
Default=False
FileKey1=%windir%|coredw.log
FileKey2=%windir%|datawriter.log
[*Ace Utilities]
LangSecRef=3024
Detect=HKCU\Software\Acelogix\Ace Utilities
Default=False
FileKey1=%userprofile%\My Documents\Ace Utilities Backups|*.reg
[*AceHTML 5]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Visicom Media\AceHTML 5 Freeware
RegKey1=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last URLs
RegKey2=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Projects
RegKey3=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Open
RegKey4=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Files
[*Acronis True Image Home]
LangSecRef=3024
Detect=HKCU\Software\Acronis\TrueImageHome
Default=False
FileKey1=%allusersprofile%\Application Data\Acronis\TrueImage\Logs|*.log
[*Acronis True Image]
LangSecRef=3024
Detect=HKCU\Software\Acronis\TrueImage
Default=False
FileKey1=%userprofile%\Application Data\Acronis\TrueImage\Logs|*.log
[*ActiveX and Class Issues]
LangSecRef=3501
LangRef=3603
Default=False
SpecialKey1=R_ACTIVEX
[*Ad-Aware SE Personal]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt
[*Ad-Aware SE Plus]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt
[*Ad-Aware SE Professional]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt
[*Adaptec's Audio CD]
LangSecRef=3024
Detect=HKCU\Software\Adaptec
Default=False
RegKey1=HKCU\Software\Adaptec\AUDIO_CD_INFO
[*Adobe Acrobat 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral\cRecentFiles
[*Adobe Acrobat 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE
[*Adobe Acrobat 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral\cRecentFiles
[*Adobe Acrobat 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE
[*Adobe Acrobat 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral\cRecentFiles
[*Adobe Acrobat 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE
[*Adobe Acrobat 8.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral\cRecentFiles
[*Adobe Acrobat Reader 4.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\4.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile1
RegKey2=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile2
RegKey3=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile3
RegKey4=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile4
[*Adobe Acrobat Reader 4.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\4.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile1
RegKey2=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile2
RegKey3=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile3
RegKey4=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile4
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE
[*Adobe Acrobat Reader 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles
[*Adobe Acrobat Reader 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral\cRecentFiles
[*Adobe Acrobat Reader 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\7.0\Cache\Search70|*.*
FileKey2=%ProgramFiles%\Adobe\Acrobat 7.0\Reader|*.bak
FileKey3=%ProgramFiles%\Adobe\Acrobat 7.0\ActiveX|*.bak
FileKey4=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\plug_ins|*.bak
FileKey5=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\Updater|*.bak
[*Adobe Flash Player]
LangSecRef=3023
Detect=HKCR\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
Default=False
SpecialKey1=N_FLASH_COOKIES
[*Adobe Illustrator CS4]
LangSecRef=3021
Detect=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator
Default=False
RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator\FileList
[*Adobe ImageReady 7.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\ImageReady 7.0
RegKey1=HKCU\Software\Adobe\ImageReady 7.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 7.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 7.0\Preferences\RecentFiles
[*Adobe ImageReady CS]
LangSecRef=3021
Detect=HKCU\Software\Adobe\ImageReady 8.0
Default=False
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles
[*Adobe ImageReady CS]
LangSecRef=3021
Detect=HKCU\Software\Adobe\ImageReady 8.0
Default=False
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE
[*Adobe Photoshop 5.5]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\5.5
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\5.5\VisitedDirs
[*Adobe Photoshop 5.5]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\5.5
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\5.5\VisitedDirs
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE
[*Adobe Photoshop 6.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\6.0
RegKey1=HKCU\Software\Adobe\Photoshop\6.0\VisitedDirs
[*Adobe Photoshop 7.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\7.0
RegKey1=HKCU\Software\Adobe\Photoshop\7.0\VisitedDirs
[*Adobe Photoshop CS2]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\9.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\9.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
FileKey1=%appdata%\Adobe\CameraRaw\Cache|*.*
[*Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
[*Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
[*Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE
[*Adobe Photoshop CS4]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\11.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\11.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
[*Adobe Photoshop CS]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\8.0
RegKey1=HKCU\Software\Adobe\Photoshop\8.0\VisitedDirs
[*Adobe Reader 8.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\8.0\Cache\Search80|*.*
[*Adobe Reader 8]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5|*.log
FileKey2=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE
[*Adobe Reader 9.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\9.0\Cache\Search90|*.*
[*Adobe Reader 9]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\9.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Updater6|*.log
FileKey2=%LocalAppData%\Adobe\Updater6\Install|*.*|RECURSE
[*Advanced Searchbar]
LangSecRef=3022
Detect= HKCU\Software\Advanced Searchbar\Toolbar
Default=False
RegKey1=HKCU\Software\Advanced Searchbar\Toolbar\Historysearchbox1
[*Ahead Nero Burning Rom 8]
LangSecRef=3021
Detect=HKCU\Software\Nero\Nero8
Default=False
RegKey1=HKCU\Software\Nero\Nero8\Cover Designer\Recent File List
RegKey2=HKCU\Software\Nero\Nero8\Nero - Burning Rom\Recent File List
FileKey1=%userprofile%\Application Data\Nero\Nero8\Nero Burning ROM|*.log
[*Ahead Nero PhotoSnap]
LangSecRef=3021
Detect=HKCU\Software\ahead\Nero PhotoSnap
Default=False
RegKey1=HKCU\Software\ahead\Nero PhotoSnap\Recent File List
[*Ahead NeroSearch]
LangSecRef=3021
Detect=HKCU\Software\Ahead\NeroSearch
Default=False
RegKey1=HKCU\Software\Ahead\NeroSearch\NeroSavedSearches\SavedSearches
[*Ahead NeroVision 2.0]
LangSecRef=3021
Detect=HKCU\Software\ahead\NeroVision\2.0
Default=False
RegKey1=HKCU\Software\ahead\NeroVision\2.0\RecentFiles
[*AkelPad]
LangSecRef=3024
Detect=HKCU\Software\Akelsoft\AkelPad
Default=False
RegKey1=HKCU\Software\Akelsoft\AkelPad\Recent
RegKey2=HKCU\Software\Akelsoft\AkelPad\Search
[*Alcohol 120%]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Alcohol Soft\Alcohol 120%
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 120%\MountedMRU
[*Alcohol 52%]
LangSecRef=3023
Detect=HKCU\Software\Alcohol Soft
Default=False
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 52%\Images
RegKey2=HKCU\Software\Alcohol Soft\Alcohol 52%\MountedMRU\0
RegKey3=HKCU\Software\Alcohol Soft\Alcohol 52%\Basic|Image File Path
RegKey4=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageFilePath
RegKey5=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageName
[*Always Right]
LangSecRef=3024
Detect=HKCU\Software\AlwaysRight
Default=False
FileKey1=%ProgramFiles%\Superhunter\Always Right\FileBackup|*.*
FileKey2=%ProgramFiles%\Superhunter\Always Right\RegBackup|*.*
[*America Online 9.1]
Default=False
DetectFile=%allusersprofile%\Application Data\AOL\C_AOL 9.1
FileKey1=%allusersprofile%\Application Data\AOL\C_AOL 9.1\bart|*.*|RECURSE
FileKey2=%allusersprofile%\Application Data\AOL\C_AOL 9.1\spool|*.*|RECURSE
LangSecRef=3021
[*Amsn - Display Pictures]
LangSecRef=3021
Default=False
Detect=HKCU\Software\aMSN
FileKey1=%userprofile%\amsn\displaypic\cache|*.*
[*Anim8or]
LangSecRef=3021
Detect=HKCU\Software\Silicon Valley Software\Anim8or
Default=False
RegKey1=HKCU\Software\Silicon Valley Software\Anim8or|File1
RegKey2=HKCU\Software\Silicon Valley Software\Anim8or|File2
RegKey3=HKCU\Software\Silicon Valley Software\Anim8or|File3
RegKey4=HKCU\Software\Silicon Valley Software\Anim8or|File4
[*AntiVir Desktop]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Avira\AntiVir Desktop
Default=False
FileKey1=%commonappdata%\Avira\AntiVir Desktop\FAILSAVE|*.*
FileKey2=%commonappdata%\Avira\AntiVir Desktop\INFECTED|*.*
FileKey3=%commonappdata%\Avira\AntiVir Desktop\LOGFILES|*.*
FileKey4=%commonappdata%\Avira\AntiVir Desktop\SYSSAVE|*.*
FileKey5=%commonappdata%\Avira\AntiVir Desktop\TEMP|*.*
FileKey6=%ProgramFiles%\Avira\AntiVir Desktop|*.old
FileKey7=%ProgramFiles%\Avira\AntiVir Desktop|*.tmp
FileKey8=%ProgramFiles%\Avira\AntiVir Desktop\FAILSAFE|*.tmp
[*AntiVir Personal 8]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Avira\AntiVir PersonalEdition Classic
Default=False
FileKey1=%commonappdata%\Avira\AntiVir PersonalEdition Classic\BACKUP\FAILSAFE|*.tmp
FileKey2=%commonappdata%\Avira\AntiVir PersonalEdition Classic\LOGFILES|*.log
FileKey3=%ProgramFiles%\Avira\AntiVir PersonalEdition Classic|*.tmp
FileKey4=%ProgramFiles%\Avira\AntiVir PersonalEdition Classic\FAILSAFE|*.tmp
[*Application Paths]
LangSecRef=3501
LangRef=3606
Default=False
SpecialKey1=R_APP_PATHS
[*Applications]
LangSecRef=3501
LangRef=3604
Default=False
SpecialKey1=R_APP_OPENWITH
[*Arasan Chess]
LangSecRef=3024
Detect=HKCU\Software\Arasan\Arasan
Default=False
RegKey1=HKCU\Software\Arasan\Arasan\Recent File List
[*Ashampoo Burning Studio 7]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Burn Image Project\AddDialog
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Dump Image Project\DumpImage
RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Unknown Project\AddDialog
FileKey1=%appdata%\Ashampoo\Ashampoo Burning Studio 2007\Logs|*.*
[*Ashampoo Burning Studio 9]
LangSecRef=3024
Detect=HKLM\Software\Ashampoo\Ashampoo Burning Studio 2009
Default=False
FileKey1=%appdata%\Ashampoo\Ashampoo Burning Studio 2009|backupmetainfo.xml
FileKey2=%appdata%\Ashampoo\Ashampoo Burning Studio 2009\Logs|*.xml
FileKey3=%appdata%\Ashampoo\Logs|*.txt
[*Ashampoo Burning Studio 5]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\DumpImage
RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Unknown Project\AddDialog
[*Ashampoo Burning Studio 6 Free (Logs)]
LangSecRef=3023
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6
Default=False
FileKey1=%userprofile%\Application Data\Ashampoo\Ashampoo Burning Studio 6 Free\Logs|*.*
[*Ashampoo Burning Studio 6]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Unknown Project\AddDialog
[*Ashampoo Burning Studio 7]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Unknown Project\AddDialog
[*Ashampoo Burning Studio 8]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8\Data Disc Project\AddDialog
[*Audacity]
LangSecRef=3023
Detect=HKCU\Software\Audacity
Default=False
RegKey1=HKCU\Software\Audacity\Audacity\RecentFiles
[*AusLogics Disk Defrag]
LangSecRef=3024
Detect=HKCU\Software\AusLogics\Disk Defrag\1.x
Default=False
FileKey1=%ProgramFiles%\AusLogics Disk Defrag\reports|*.*
[*AusLogics Registry Defrag]
LangSecRef=3024
Detect=HKCU\Software\AusLogics\Registry Defrag\4.x
Default=False
FileKey1=%ProgramFiles%\AusLogics Registry Defrag\Data\RegistryDefrag|*.*
FileKey2=%ProgramFiles%\AusLogics Registry Defrag\Reports\Registry Defrag|*.*
[*Auslogics Free Utilities]
LangSecRef=3024
Detect=HKCU\Software\Auslogics
Default=False
FileKey1=%appdata%\Auslogics\Disk Defrag\Reports|*.*
FileKey2=%appdata%\Auslogics\Registry Defrag\Logs|*.*
FileKey3=%appdata%\Auslogics\Registry Defrag\Reports|*.*
FileKey4=%appdata%\Auslogics\System Information\Reports|*.*
[*AutoIt3]
LangSecRef=3021
Detect=HKCU\Software\AutoIt v3
Default=False
RegKey1=HKCU\Software\AutoIt v3\Aut2Exe|LastExeDir
RegKey2=HKCU\Software\AutoIt v3\Aut2Exe|LastIcon
RegKey3=HKCU\Software\AutoIt v3\Aut2Exe|LastIconDir
RegKey4=HKCU\Software\AutoIt v3\Aut2Exe|LastScriptDir
FileKey1=%userprofile%|SciTE.*
[*Autocomplete Form History]
LangSecRef=3001
LangRef=3106
WarningRef=3202
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
SpecialKey1=N_INT_AUTOCOMPLETE
[*Avant Browser]
LangSecRef=3022
DetectFile=%ProgramFiles%\Avant Browser\avant.exe
Default=False
FileKey1=%appdata%\Avant Browser|keywords.dat
FileKey2=%appdata%\Avant Browser|pages.dat
FileKey3=%appdata%\Avant Browser|recents.dat
FileKey4=%appdata%\Avant Browser|reopen.dat
[*Avast Antivirus]
LangSecRef=3024
Detect=HKCU\Software\ALWIL Software\Avast
Default=False
FileKey1=%ProgramFiles%\Alwil Software\Avast4\DATA\report|avast.xsl
FileKey2=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Resident protection.txt
FileKey3=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Simple user interface.txt
FileKey4=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Simple user interface*.xml
FileKey5=%ProgramFiles%\Alwil Software\Avast4\DATA\log|*.*
[*Avi-Mux GUI]
LangSecRef=3023
DetectFile=%ProgramFiles%\AVIMuxGUI\AVIMux_GUI.exe
Default=False
FileKey1=%ProgramFiles%\AVIMuxGUI|AVI-Mux GUI - Logfile*
FileKey2=%ProgramFiles%\AVIMuxGUI|*.dmp
[*Avira RootKit Detection]
LangSecRef=3024
DetectFile=%ProgramFiles%\Avira GmbH\Avira RootKit Detection\avirarkd.exe
Default=False
FileKey1=%ProgramFiles%\Avira GmbH\Avira RootKit Detection|avirarkd.log
[*Axialis IconWorkshop]
LangSecRef=3023
Detect=HKCU\Software\Axialis\IconWorkshop
Default=False
RegKey1=HKCU\Software\Axialis\IconWorkshop\Recent File List
RegKey2=HKCU\Software\Axialis\IconWorkshop\CoolBarList
FileKey1=%appdata%\Axialis\Temporary Preview Files|*.*|RECURSE
[*Azureus]
LangSecRef=3022
DetectFile=%userprofile%\Application Data\Azureus\.lock
Default=False
FileKey1=%userprofile%\Application Data\Azureus\tmp|*.*
FileKey2=%userprofile%\Application Data\Azureus|*.bak
FileKey3=%userprofile%\Application Data\Azureus|*.log
FileKey4=%userprofile%\Application Data\Azureus\active|*.bak
FileKey5=%userprofile%\Application Data\Azureus\plugins\advancedstatistics|*.txt
FileKey6=%userprofile%\Application Data\Azureus\plugins\progressbar|*.txt
[*BSPlayer]
LangSecRef=3023
Detect=HKCU\Software\BST\bsplayer
Default=False
RegKey1=HKCU\Software\BST\bsplayer|File0
RegKey2=HKCU\Software\BST\bsplayer|File1
RegKey3=HKCU\Software\BST\bsplayer|File2
RegKey4=HKCU\Software\BST\bsplayer|File3
RegKey5=HKCU\Software\BST\bsplayer|File4
RegKey6=HKCU\Software\BST\bsplayer|File5
RegKey7=HKCU\Software\BST\bsplayer|File6
RegKey8=HKCU\Software\BST\bsplayer|File7
RegKey9=HKCU\Software\BST\bsplayer|File8
RegKey10=HKCU\Software\BST\bsplayer|File9
[*Babylon]
LangSecRef=3024
Detect=HKCU\Software\Babylon\Babylon Translator\UserInfo
Default=False
RegKey1=HKCU\Software\Babylon\Babylon Translator\UserInfo\History
[*BitDefender 9]
LangSecRef=3024
Detect=HKLM\Software\Softwin\BitDefender Antivirus
Default=False
FileKey1=%ProgramFiles%\Softwin\BitDefender9\Logs|*.*
[*BitTorrent]
LangSecRef=3022
DetectFile=%ProgramFiles%\BitTorrent\bittorrent.exe
Default=False
FileKey1=%userprofile%\Application Data\BitTorrent\incomplete|*.*
[*Boinc]
LangSecRef=3024
DetectFile=%ProgramFiles%\BOINC\boinc.exe
Default=False
FileKey1=%ProgramFiles%\BOINC|stdout*.*
FileKey2=%ProgramFiles%\BOINC|stderr*.*
[*Borland C++ Builder 5.0]
LangSecRef=3024
Detect=HKCU\Software\Borland\C++Builder\5.0
Default=False
RegKey1=HKCU\Software\Borland\C++Builder\5.0\Closed Files
RegKey2=HKCU\Software\Borland\C++Builder\5.0\Closed Projects
RegKey3=HKCU\Software\Borland\C++Builder\5.0\Session
[*Borland Developer Studio 2006]
LangSecRef=3024
Detect=HKCU\Software\Borland\BDS\4.0
Default=False
RegKey1=HKCU\Software\Borland\BDS\4.0\Closed Files
RegKey2=HKCU\Software\Borland\BDS\4.0\Closed Projects
KegKey3=HKCU\Software\Borland\BDS\4.0\Session
[*CA Anti-Virus]
LangSecRef=3024
Default=False
Detect=HKLM\SOFTWARE\ComputerAssociates\Anti-Virus
FileKey1=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|*.log
FileKey2=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|*log.txt
FileKey3=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ArcTemp|*.tmp
FileKey4=%commonappdata%\CA\Consumer\AV|*.tmp|RECURSE
FileKey5=%commonappdata%\CA\Consumer\AV|*.txt|RECURSE
FileKey6=%commonappdata%\CA\Consumer\CCube|*.tmp|RECURSE
FileKey7=%commonappdata%\CA\Consumer\CCube|*.txt|RECURSE
FileKey8=%commonappdata%\CA\Consumer\ISS\FeedStore|*.txt|RECURSE
FileKey9=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\ArcTemp|*.*
FileKey10=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\tmp|*.*
[*CDex]
LangSecRef=3024
Detect=HKLM\SOFTWARE\CDex
Default=False
FileKey1=%userprofile%\My Documents\My Music\CDDB|*.txt
[*Centarsia]
LangSecRef=3021
Detect=HKCU\Software\Centarsia
Default=False
RegKey1=HKCU\Software\Centarsia|RecentImage0
RegKey2=HKCU\Software\Centarsia|RecentImage1
RegKey3=HKCU\Software\Centarsia|RecentImage2
RegKey4=HKCU\Software\Centarsia|RecentImage3
RegKey5=HKCU\Software\Centarsia|RecentImage4
RegKey6=HKCU\Software\Centarsia|RecentImage5
RegKey7=HKCU\Software\Centarsia|RecentImage6
[*Chkdsk File Fragments]
LangSecRef=3003
LangRef=3144
Default=False
FileKey1=%SystemDrive%|File*.chk
[*ClamWin]
LangSecRef=3024
Detect=HKCU\Software\ClamWin
Default=False
FileKey1=%allusersprofile%\.clamwin\log|*.*
FileKey2=%userprofile%\.clamwin\log|*.*
FileKey3=%windir%\All Users\.clamwin\log|*.*
[*Clipboard]
LangSecRef=3003
LangRef=3148
Default=False
SpecialKey1=N_TEMP_CLIPBOARD
[*CloneCD]
LangSecRef=3021
Detect=HKLM\Software\SlySoft\CloneCD
Default=False
RegKey1=HKCU\Software\SlySoft\CloneCD\Settings|ImageFileName
[*CoffeeCup GIF Animator]
LangSecRef=3024
Detect=HKCU\Software\CoffeeCup Software\GIF Animator
Default=False
RegKey1=HKCU\Software\CoffeeCup Software\GIF Animator\Settings\MRU
[*Compare It!]
LangSecRef=3021
Detect=HKCU\Software\grigsoft.com\Compare It!
Default=False
RegKey1=HKCU\Software\grigsoft.com\Compare It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Compare It!\dirs
RegKey3=HKCU\Software\grigsoft.com\Compare It!\options|Recent0
RegKey4=HKCU\Software\grigsoft.com\Compare It!\options|Recent1
RegKey5=HKCU\Software\grigsoft.com\Compare It!\options|Recent2
RegKey6=HKCU\Software\grigsoft.com\Compare It!\options|Recent3
RegKey7=HKCU\Software\grigsoft.com\Compare It!\options|Recent4
RegKey8=HKCU\Software\grigsoft.com\Compare It!\options|Recent5
RegKey9=HKCU\Software\grigsoft.com\Compare It!\options|Recent6
RegKey10=HKCU\Software\grigsoft.com\Compare It!\options|Recent7
RegKey11=HKCU\Software\grigsoft.com\Compare It!\options|Recent8
RegKey12=HKCU\Software\grigsoft.com\Compare It!\options|Recent9
RegKey13=HKCU\Software\grigsoft.com\Compare It!\options|Recent10
[*ConTEXT]
LangSecRef=3021
Detect=HKCU\Software\Eden\ConTEXT
Default=False
Regkey1=HKCU\Software\Eden\ConTEXT\FileHistory
Regkey2=HKCU\Software\Eden\ConTEXT\FindHistory
[*Config.msi Folder]
LangSecRef=3025
Default=False
DetectFile=%windir%\system32\msiexec.exe
FileKey1=%systemdrive%\Config.msi|*.*|RECURSE
[*ConvertXToDVD]
LangSecRef=3023
Detect=HKCU\Software\VSO\ConvertXToDVD
Default=False
FileKey1=%userprofile%\Application Data\Vso|*.log
[*Cookies]
LangSecRef=3001
LangRef=3102
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_COOKIES
[*Copernic Desktop Search]
LangSecRef=3021
Detect=HKCU\Software\Copernic\DesktopSearch2
Default=False
RegKey1=HKCU\Software\Copernic\DesktopSearch2\Config\SearchHistory
[*CounterSpy]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Sunbelt Software\CounterSpy
Default=False
FileKey1=%allusersprofile%\Application Data\Sunbelt Software\CounterSpy\Logs|*.*
[*Creative Pro Proteus VX]
LangSecRef=3023
Detect=HKCU\Software\Creative Professional\Proteus VX
Default=False
RegKey1=HKCU\Software\Creative Professional\Proteus VX VSTi\Recent File List
[*Custom File Deletion]
LangSecRef=3024
FileKey1=%allusersprofile%\DRM\Cache|*.*|recurse
FileKey2=%userprofile%\Application Data\Microsoft\Outlook Express\News|cleanup.log
FileKey3=%userprofile%\Cookies|*.*|recurse
FileKey4=%userprofile%\Local Settings\History\History.IE5|*.*|recurse
FileKey5=%userprofile%\Local Settings\Temporary Internet Files\Content.IE5|*.*|recurse
FileKey6=%userprofile%\Local Settings\Temp|*.*|recurse
FileKey7=%userprofile%\UserData|*.*|recurse
FileKey8=%windir%\Prefetch|*.pf|recurse
FileKey9=%windir%\system32\config\systemprofile\Cookies|*.*|recurse
FileKey10=%windir%\system32\config\systemprofile\Local Settings\History\History.IE5|*.*|recurse
FileKey11=%windir%\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5|*.*|recurse
FileKey12=%windir%\Temp|*.*|recurse
FileKey13=C:\Documents and Settings\LocalService\Cookies|*.*|recurse
FileKey14=C:\Documents and Settings\LocalService\Local Settings\History\History.IE5|*.*|recurse
FileKey15=C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5|*.*|recurse
[*Custom Folders]
LangSecRef=3004
LangRef=3129
SpecialKey1=N_EX_CUSTOMFOLDERS
[*CuteFTP Home 7.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Home
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\7.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\7.0\CacheThumbs|*.*|RECURSE
[*CuteFTP Home 8.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Home
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\8.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\8.0\CacheThumbs|*.*|RECURSE
[*CuteFTP Pro 7.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Professional
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\CacheThumbs|*.*|RECURSE
[*CuteFTP Pro 8.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Professional
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\CacheThumbs|*.*|RECURSE
[*CuteHTML 2.3]
LangSecRef=3024
Detect=HKCU\Software\GlobalSCAPE\CuteHTML\2.3
Default=False
RegKey1=HKCU\Software\GlobalSCAPE\CuteHTML\2.3\Recent File List
[*DC++]
LangSecRef=3022
DetectFile=%ProgramFiles%\DC++\DCPlusPlus.exe
Default=False
FileKey1=%ProgramFiles%\DC++|files.xml.bz2
FileKey2=%ProgramFiles%\DC++\FileLists|*.*
FileKey3=%ProgramFiles%\DC++\Logs|*.*
[*DU meter]
LangSecRef=3022
Detect=HKCU\SOFTWARE\Hagel\DU Meter
Default=False
FileKey1=%allusersprofile%\Application Data\Hagel Technologies\DU Meter|*.csv
[*DVD Shrink (Analysis Results)]
LangSecRef=3023
Detect=HKCU\Software\DVD Shrink
Default=False
FileKey1=%allusersprofile%\Application Data\DVD Shrink|*.*
[*DVD Shrink]
LangSecRef=3023
Default=False
Detect=HKCU\Software\DVD Shrink\
RegKey1=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent Targets
RegKey2=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent File List
RegKey3=HKCU\Software\DVD Shrink\DVDSHRINK103\TargetFiles
RegKey4=HKCU\Software\DVD Shrink\DVDSHRINK103\SourceFolders
[*DVDx]
LangSecRef=3023
Detect=HKCU\Software\DVDx
Default=False
RegKey1=HKCU\Software\DVDx\LastDir
RegKey2=HKCU\Software\DVDx\LastOutput
FileKey1=%ProgramFiles%\DVDx|*.tmp
[*Delete Index.dat files]
LangSecRef=3001
LangRef=3105
WarningRef=3201
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_INDEXDAT
[*Dependency Walker]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Dependency Walker
Default=False
RegKey1=HKCU\Software\Microsoft\Dependency Walker\Recent File List
[*Desktop Shortcuts]
LangSecRef=3003
LangRef=3613
Default=False
SpecialKey1=F_DESKTOP
[*DivX Movies Cache]
LangSecRef=3023
Detect=HKLM\Software\DivXNetworks
Default=False
FileKey1=%userprofile%\My Documents\My Videos\DivX Movies|*.*|RECURSE
RegKey1=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry1
RegKey2=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry2
RegKey3=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry3
RegKey4=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry4
RegKey5=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry5
RegKey6=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry6
[*Dogpile Toolbar]
LangSecRef=3022
Detect=HCKU\Software\Infospace\DogpileToolbar
Default=False
RegKey1=HCKU\Software\Infospace\DogpileToolbar\History|1-terms
[*Download Accelerator Plus]
LangSecRef=3022
Detect=HKCU\Software\SpeedBit\Download Accelerator
Default=False
RegKey1=HKLM\SOFTWARE\SpeedBit\Download Accelerator\FileList
RegKey2=HKCU\Software\SpeedBit\Download Accelerator\HistoryCombo
RegKey3=HKCU\Software\SpeedBit\Download Accelerator\ADS\SecondMedia
FileKey1=%ProgramFiles%\DAP\Temp|*.*
FileKey2=%ProgramFiles%\DAP\Ads|*.*
FileKey3=%ProgramFiles%\DAP\Log|*.*
[*Driver Cleaner Pro]
LangSecRef=3024
DetectFile=%ProgramFiles%\Driver Cleaner Pro\DCleaner.exe
Default=False
FileKey1=%ProgramFiles%\Driver Cleaner Pro\Log|*.log
[*Dup Detector]
LangSecRef=3023
Detect=HKCU\Software\Prismatic Software\PhotoBatch
Default=False
RegKey1=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastBatFile
RegKey2=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastFold
RegKey3=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSecFold
RegKey4=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSingleFold
[*ESPN Motion Advertisements]
LangSecRef=3023
Detect=HKCU\SOFTWARE\Disney\DIGStream
Default=False
FileKey1=%allusersprofile%\Application Data\DIGStream\ESPNMotion|ad_*.wmv
FileKey2=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*promo*.wmv
FileKey3=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*commercial*.wmv
FileKey4=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*motionbumper*.wmv
[*ESPN Motion]
LangSecRef=3023
Detect=HKCU\SOFTWARE\Disney\DIGStream
Default=False
FileKey1=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*.wmv
FileKey2=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*.tmp
[*Easy CD-DA Extractor]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8
RegKey1=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k80
RegKey2=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k81
RegKey3=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k8c
RegKey4=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k91
RegKey5=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k92
RegKey5=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k92
[*Effective File Search]
LangSecRef=3021
DetectFile=%ProgramFiles%\efs\search.exe
Default=False
FileKey1=%ProgramFiles%\efs|cblist*.dat
[*EmEditor]
LangSecRef=3024
Detect=HKCU\Software\EmSoft\EmEditor v3
Default=False
RegKey1=HKCU\Software\EmSoft\EmEditor v3\Recent File List
RegKey2=HKCU\Software\EmSoft\EmEditor v3\Recent Folder List
RegKey3=HKCU\Software\EmSoft\EmEditor v3\Recent Font List
[*Empty Recycle Bin]
LangSecRef=3003
LangRef=3141
Default=False
SpecialKey1=N_TEMP_RECYCLEBIN
[*Eraser (Log)]
LangSecRef=3024
Detect=HKCU\Software\Heidi Computers Ltd\Eraser\5.5
Default=False
FileKey1=%ProgramFiles%\Eraser|schedlog.txt
[*Essential NetTools 3]
LangSecRef=3022
Detect=HKCU\Software\ENT3
Default=False
RegKey1=HKCU\Software\ENT3\Recent
[*Ewido Anti-Malware (Log)]
LangSecRef=3024
Detect=HKLM\Software\ewido
Default=False
FileKey1=%ProgramFiles%\Ewido\Security Suite|logfile.txt
FileKey2=%ProgramFiles%\Ewido Anti-Malware|logfile.txt
[*ExamDiff Pro]
LangSecRef=3024
Detect=HKCU\Software\PrestoSoft\ExamDiff Pro
Default=False
RegKey1=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Left Files
RegKey2=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Right Files
RegKey3=HCKU\Software\PrestoSoft\ExamDiff Pro\Settings|File 1
RegKey4=HCKU\Software\PrestoSoft\ExamDiff Pro\Settings|File 2
[*ExamDiff]
LangSecRef=3024
Detect=HKCU\Software\PrestoSoft\ExamDiff
Default=False
RegKey1=HKCU\Software\PrestoSoft\ExamDiff\Recent Left Files
RegKey2=HKCU\Software\PrestoSoft\ExamDiff\Recent Right Files
RegKey3=HCKU\Software\PrestoSoft\ExamDiff\Settings|File 1
RegKey4=HCKU\Software\PrestoSoft\ExamDiff\Settings|File 2
[*Excel Viewer]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files
[*ExifPro]
LangSecRef=3023
Detect=HKCU\Software\MKowalski\ExifPro
Default=False
RegKey1=HKCU\Software\MKowalski\ExifPro\1.0\RecentPaths
RegKey2=HKCU\Software\MKowalski\ExifPro\1.0\ResizeDlg\RecentDestPaths
RegKey3=HKCU\Software\MKowalski\ExifPro\1.0\HTMLAlbumGen\RecentDestPaths
RegKey4=HKCU\Software\MKowalski\ExifPro\1.0\Browser\View 0|LastPath
FileKey1=%allusersprofile%\Application Data\MiK\ExifPro|Cache*
[*Exifer]
LangSecRef=3021
Detect=HKCU\Software\Exifer
Default=False
RegKey1=HKCU\Software\Exifer\Browse\History
[*FARManager]
LangSecRef=3021
Detect=HKCU\Software\Far\
Default=False
RegKey1=HKCU\Software\Far\SavedDialogHistory
RegKey2=HKCU\Software\Far\SavedFolderHistory
RegKey3=HKCU\Software\Far\SavedHistory
RegKey4=HKCU\Software\Far\SavedViewHistory
[*FTP Accounts]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Ftp
Default=False
RegKey1=HKCU\Software\Microsoft\Ftp\Accounts
[*FeedDemon]
LangSecRef=3022
Detect=HKCU\Software\Bradbury\FeedDemon\1.0
Default=False
RegKey1=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TypedURLs
RegKey2=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TabbedBrowserUrls
[*FileLocator Pro]
LangSecRef=3024
Detect=HKCU\Software\Mythicsoft\FileLocatorPro
Default=False
RegKey1=HKCU\Software\Mythicsoft\FileLocatorPro\RecentContains
RegKey2=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFileName
RegKey3=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFolders
[*FlashFXP]
LangSecRef=3022
DetectFile=%ProgramFiles%\FlashFXP\flashfxp.exe
Default=False
FileKey1=%ProgramFiles%\FlashFXP|quick.dat
[*FlashGet]
LangSecRef=3022
Detect=HKCU\SOFTWARE\JetCar\JetCar
Default=False
RegKey1=HKCU\SOFTWARE\JetCar\JetCar\DownDir
RegKey2=HKCU\SOFTWARE\JetCar\JetCar\Recent File List
RegKey3=HKCU\SOFTWARE\JetCar\JetCar\SelFolder
FileKey1=%ProgramFiles%\FlashGet|Default.jcd.bak
FileKey2=%ProgramFiles%\FlashGet|Default.bk*
FileKey3=%ProgramFiles%\FlashGet\Torrent|*.*
[*FlashGet]
LangSecRef=3022
Detect=HKCU\Software\JetCar
Default=False
RegKey1=HKCU\Software\JetCar\JetCar|Recent File List
FileKey1=%programfiles%\FlashGet|Default.bk*
FileKey2=%programfiles%\FlashGet|Default.jcd
FileKey3=%programfiles%\FlashGet|Default.jcd.bak
[*Fonts]
LangSecRef=3501
LangRef=3605
Default=False
SpecialKey1=R_FONTS
[*Foobar2000 (Crash Log)]
LangSecRef=3023
Detect=HKLM\Software\foobar2000
Default=False
FileKey1=%programfiles%\foobar2000|failure.txt
[*Forward Observer]
LangSecRef=3021
DetectFile=%Program Files%\AAForwardObserver\AAForwardObserver.exe
Default=False
FileKey1=%Program Files%\AAForwardObserver|FO.log
[*Foxit PDF Editor]
LangSecRef=3021
DetectFile=%ProgramFiles%\Foxit Software\PDF Editor\PDFEdit.exe
Default=False
RegKey1=HKCU\Software\Foxit Software Company\Foxit PDF Editor|Recent File List
[*Foxit Reader]
LangSecRef=3021
Detect=HKCU\Software\Foxit Software\Foxit Reader
Default=False
RegKey1=HKCU\Software\Foxit Software\Foxit Reader\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit Reader\History
[*Free Download Manager]
LangSecRef=3022
DetectFile=%ProgramFiles%\Free Download Manager\fdm.exe
Default=False
RegKey1=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings\Find","What
RegKey2=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings\View","LastDldMoveToFolder
FileKey1=%userprofile%\Application Data\Free Download Manager|downloads.sav
FileKey2=%userprofile%\Application Data\Free Download Manager|uploads.1.sav
FileKey3=%userprofile%\Application Data\Free Download Manager|dlmgrsi.sav
FileKey4=%userprofile%\Application Data\Free Download Manager|downloads.his.sav
FileKey5=%userprofile%\Application Data\Free Download Manager|history.sav
FileKey6=%userprofile%\Application Data\Free Download Manager|sites.sav
FileKey7=%userprofile%\Application Data\Free Download Manager|spider.sav
FileKey8=%userprofile%\Application Data\Free Download Manager|schedules.sav
FileKey9=%userprofile%\Application Data\Free Download Manager|mctasks.sav
FileKey10=%userprofile%\Application Data\Free Download Manager|*.bak
[*Free Registry Defrag]
LangSecRef=3024
Detect=HKCU\Software\Local AppWizard-Generated Applications\RegDefrag
Default=False
FileKey1=%WinDir%\$regcmp$|*.*
[*FreshDownload]
LangSecRef=3022
Detect=HKCU\Software\FreshDevices\FreshDownload
Default=False
RegKey1=HKCU\Software\FreshDevices\FreshDownload\History
[*FrostWire]
LangSecRef=3022
DetectFile=%ProgramFiles%\FrostWire\FrostWire.exe
Default=False
FileKey1=%userprofile%\Application Data\FrostWire|fileurns.cache
FileKey2=%userprofile%\Application Data\FrostWire|createtimes.cache
FileKey3=%userprofile%\Application Data\FrostWire|responses.cache
FileKey4=%userprofile%\Application Data\FrostWire|ttree.cache
FileKey5=%userprofile%\Application Data\FrostWire|gnutella.net
FileKey6=%userprofile%\Application Data\FrostWire|ttroot.cache
FileKey7=%userprofile%\Application Data\FrostWire|fileurns.bak
FileKey8=%userprofile%\Application Data\FrostWire|checkandupdate.txt
[*GIANT AntiSpyware]
LangSecRef=3024
DetectFile=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware\GIANTAntiSpywareMain.exe
Default=False
FileKey1=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|errors.log
FileKey2=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|tracksEraser.log
FileKey3=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|cleaner.log
[*GIMP]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Classes\GIMP-2.0-gbr\shell
filekey1=%userprofile%\.thumbnails\normal|*.*
filekey2=%userprofile%\.gimp-2.4|documents
[*GSpot]
LangSecRef=3024
Detect=HKCU\Software\GSpot Appliance Corp
Default=False
RegKey1=HKCU\Software\GSpot Appliance Corp\GSpot\v2.6 Settings|LastMediaFile
[*Game Maker 4]
LangSecRef=3021
Detect=HKCU\Software\Game Maker 4
Default=False
RegKey1=HKCU\Software\Game Maker 4\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker 4\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker 4\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker 4\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker 4\Preferences|GameDir
[*Game Maker 5]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 5
Default=False
RegKey1=HKCU\Software\Game Maker\Version 5\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 5\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 5\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 5\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 5\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 5\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 5\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 5\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 5\Preferences|GameDir
[*Game Maker 6]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 6
Default=False
RegKey1=HKCU\Software\Game Maker\Version 6\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 6\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 6\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 6\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 6\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 6\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 6\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 6\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 6\Preferences|GameDir
[*Game Maker 7]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 7
Default=False
RegKey1=HKCU\Software\Game Maker\Version 7\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 7\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 7\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 7\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 7\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 7\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 7\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 7\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 7\Preferences|GameDir
[*Genie Backup Manager Pro 6.0]
LangSecRef=3024
DetectFile=%userprofile%\Application Data\Genie-soft\GBMPro6
Default=False
FileKey1=%userprofile%\Application Data\Genie-soft\GBMPro6\logs|*.*
[*GetRight]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Headlight\GetRight\
RegKey1=HKCU\Software\Headlight\GetRight\MRU
RegKey2=HKCU\Software\Headlight\GetRight\TypedURLS
RegKey3=HKCU\Software\Headlight\GetRight\Recent File List
FileKey1=%ProgramFiles%\GetRight|GetRight.hst
[*Go!Zilla]
LangSecRef=3022
Detect=%Program Files%\Go!Zilla
Default=False
FileKey1=%ProgramFiles%\Go!Zilla\golog.htm
FileKey2=%ProgramFiles%\Go!Zilla\leech.hst
FileKey3=%ProgramFiles%\Go!Zilla\download.log
[*Google Calendar Sync]
LangSecRef=3022
Detect=HKCU\Software\Google\Google Calendar Sync
Default=False
FileKey1=%userprofile%\Application Data\Google\Google Calendar Sync\logs|*.log
[*Google Chrome - Cookies]
Section=Google Chrome
LangRef=3102
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_COOKIES
[*Google Chrome - Download History]
Section=Google Chrome
LangRef=3163
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_DOWNLOAD
[*Google Chrome - Internet Cache]
Section=Google Chrome
LangRef=3161
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_CACHE
[*Google Chrome - Internet History]
Section=Google Chrome
LangRef=3162
Section = Chrome
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_HISTORY
[*Google Chrome - Saved Form Information]
Section=Google Chrome
LangRef=3164
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_FORM
[*Google Deskbar]
LangSecRef=3022
Detect=HKCU\Software\Google\Deskbar
Default=False
RegKey1=HKCU\Software\Google\Deskbar\termhistory
RegKey2=HKCU\Software\Google\Deskbar\urlhistory
[*Google Earth]
LangSecRef=3021
Detect=HKLM\SOFTWARE\Google\Google Earth Plus
; Detect2=HKLM\SOFTWARE\Google\Google Earth Pro
Default=False
FileKey1=%appdata%\Google\GoogleEarth|dbcache.dat
FileKey2=%appdata%\Google\GoogleEarth|dbcache.dat.index
RegKey1=HKCU\Software\Google\Google Earth Plus\Search
RegKey2=HKCU\Software\Google\Google Earth Pro\Search
[*Google Talk]
LangSecRef=3022
DetectFile=%ProgramFiles%\Google\Google Talk
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Google\Google Talk\status|*.txt
FileKey2=%userprofile%\Local Settings\Application Data\Google\Google Talk\chatlogs|*.log
[*Google Toolbar 4.0]
LangSecRef=3022
Detect=HKCU\Software\Google\Google Toolbar
Default=False
FileKey1=%appdata%\Google\Local Search History|*.*
[*Google Toolbar Firefox]
LangSecRef=3022
Default=False
SpecialDetect=DET_MOZILLA_GOOGLE_TOOLBAR
SpecialKey1=N_MOZ_GOOGLE_TOOLBAR
[*Google Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Google\NavClient\1.1
Default=False
RegKey1=HKCU\Software\Google\NavClient\1.1\History
RegKey2=HKCU\Software\Google\NavClient\1.1\Options|KillPopupCount
[*Google Video Player]
LangSecRef=3023
DetectFile=%ProgramFiles%\Google\Google Video Player\GoogleVideoPlayer.exe
Default=False
RegKey1=HKCU\Software\Google\Google Video Player\MRUList
[*GridinSoft Notepad]
LangSecRef=3021
Detect=HKCU\Software\GridinSoft\Notepad3
Default=False
RegKey1=HKCU\Software\GridinSoft\Notepad3\Files
RegKey2=HKCU\Software\GridinSoft\Notepad3\Search|ReplaceTextHistory
RegKey3=HKCU\Software\GridinSoft\Notepad3\Search|TextHistory
[*Grisoft AVG 7.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\Avg7
Default=False
FileKey1=%commonappdata%\Grisoft\Avg7Data|*.log
FileKey2=%commonappdata%\Grisoft\Avg7Data\upd7bin|*.*
FileKey3=%commonappdata%\Grisoft\Avg7Data\$history|*.*
FileKey4=%commonappdata%\Grisoft\Avg7Data\avg7upd|*.log
FileKey5=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|*.*
FileKey6=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey7=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|*.log
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|*.log
FileKey9=%windir%\Application Data\AVG7\Log|*.log
[*Grisoft AVG 7.5]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\Avg7
Default=False
FileKey1=%allusersprofile%\Application Data\Grisoft|*.AVG
FileKey2=%allusersprofile%\Application Data\Grisoft\Avg7Data|*.AVG
FileKey3=%allusersprofile%\Application Data\Grisoft\Avg7Data|*.log
FileKey4=%allusersprofile%\Application Data\Grisoft\Avg7Data\upd7bin|*.*
FileKey5=%allusersprofile%\Application Data\Grisoft\Avg7Data\$history|*.*
FileKey6=%allusersprofile%\Application Data\Grisoft\Avg7Data\avg7upd|*.log
FileKey7=%windir%\All Users\Application Data\Grisoft|*.AVG
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|*.AVG
FileKey9=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|*.*
FileKey10=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey11=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|*.log
FileKey12=%windir%\All Users\Application Data\Grisoft\Avg7Data|*.log
FileKey13=%windir%\Application Data\AVG7\Log|*.log
[*Grisoft AVG 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|*.log
FileKey2=%allusersprofile%\Application Data\avg8\Log|*.xml
FileKey3=%allusersprofile%\Application Data\avg8\scanlogs|*.log
FileKey4=%allusersprofile%\Application Data\avg8\emc\Log|*.log
FileKey5=%allusersprofile%\Application Data\avg8\update\backup|*.*
FileKey6=%allusersprofile%\Application Data\avg8\download|*.bin
[*GroupWise Messenger]
LangSecRef=3021
Detect=HKCU\Software\Novell\Messenger
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Novell\GroupWise Messenger\history\%user%|*.*
[*HDD Thermometer]
LangSecRef=3024
Detect=HKCU\SOFTWARE\RSD Software, Inc.\HDD Thermometer
Default=False
FileKey1=%allusersprofile%\Application Data\HDD Thermometer|*.log
FileKey2=%allusersprofile%\Application Data\HDD Thermometer\logs|*.log
[*HP Photosmart Premier]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\HP Photo & Imaging
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\HP\Digital Imaging\cache|*.*
[*Help Files]
LangSecRef=3501
LangRef=3607
Default=False
SpecialKey1=R_HELP
[*History]
LangSecRef=3001
LangRef=3103
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_HISTORY
[*HitManPro]
LangSecRef=3024
DetectFile=%ProgramFiles%\Hitman Pro\hitmanpro2.exe
Default=False
FileKey1=%ProgramFiles%\Hitman Pro\logs|*.htm
FileKey2=%ProgramFiles%\Hitman Pro\updates|*.*
FileKey3=%ProgramFiles%\Hitman Pro\downloads|*.*
[*HostsMan]
LangSecRef=3024
DetectFile=%ProgramFiles%\HostsMan\hm.exe
Default=False
FileKey1=%appdata%\abelhadigital.com\HostsServer|block2.log
FileKey2=%appdata%\abelhadigital.com\HostsServer|block1.log
[*Hotbar 3.0]
LangSecRef=3022
Detect=HKCU\Software\Hotbar\
Default=False
RegKey1=HKCU\Software\Hotbar\hotbar\ImagesHistory
FileKey1=%ProgramFiles%\Hotbar\v3.0\dynamic|*.*|RECURSE
FileKey2=%ProgramFiles%\Hotbar\v3.0\static|*.*
[*Hotfix Uninstallers]
LangSecRef=3004
LangRef=3130
DetectOS=|5.2
SpecialKey1=N_EX_HOTFIX
[*HxD Hexeditor]
LangSecRef=3021
Detect=HKCU\Software\Mael\HxD
Default=False
RegKey1=HKCU\Software\Mael\HxD\History Lists\Recent Files
[*IE Toy]
LangSecRef=3024
Detect=HKCU\Software\MySoftware\IEToy
Default=False
FileKey1=%ProgramFiles%\IE Toy\Data|history
FileKey2=%ProgramFiles%\IE Toy\Data|history_ad
RegKey1=HKCU\Software\MySoftware\IEToy|FRAGS_ad
RegKey2=HKCU\Software\MySoftware\IEToy|FRAGS_popup
[*IE7pro]
LangSecRef=3024
Detect=HKCU\Software\IE7pro
Default=False
RegKey1=HKCU\Software\IE7pro\ClosedTabs
[*IIS Log Files]
LangSecRef=3004
LangRef=3146
Detect=HKLM\System\CurrentControlSet\Services\w3svc
DetectOS=|6.0
FileKey1=%windir%\system32\LogFiles|*.*|RECURSE
FileKey2=%SystemDrive%\inetpub\logs\LogFiles|*.*|RECURSE
[*IZArc]
LangSecRef=3024
Detect=HKCU\Software\IZSoftware\IZArc
Default=False
RegKey1=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey2=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey3=HKCU\Software\IZSoftware\IZArc\Recent
[*Icon Cache]
LangSecRef=3002
Default=False
FileKey1=%userprofile%\Local Settings\Application Data|IconCache.db
FileKey2=%LocalAppData%|IconCache.db
[*IconCool Editor]
LangSecRef=3021
DetectFile=%ProgramFiles%\IconCoolEditor\IconCooleditor.exe
Default=False
FileKey1=%ProgramFiles%\IconCoolEditor|IconFileList.src
FileKey2=%ProgramFiles%\IconCoolEditor|Recentlyused.src
[*IdeaSoft Scrapbooks Plus 1.0]
LangSecRef=3021
Detect=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0
Default=False
RegKey1=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0\Recent File List
[*ImgBurn]
LangSecRef=3021
Detect=HKCU\Software\ImgBurn
Default=False
FileKey1=%AppData%\ImgBurn|ImgBurn.log
FileKey2=%AppData%\ImgBurn\Log Files|ImgBurn.log
[*ImgBurn]
LangSecRef=3021
Detect=HKCU\Software\ImgBurn
Default=False
FileKey1=%appdata%\ImgBurn\Log Files|*.*
FileKey2=%appdata%\ImgBurn\IBG Files|*.*
RegKey1=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Destination
RegKey2=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Source
RegKey3=HKCU\Software\ImgBurn|ISOWRITE_RecentFiles_Source
[*Inno Setup]
LangSecRef=3021
Detect=HKCU\Software\Jordan Russell\Inno Setup
Default=False
RegKey1=HKCU\Software\Jordan Russell\Inno Setup\ScriptFileHistoryNew
[*InstallShield Professional]
LangSecRef=3021
Detect=HKCU\Software\InstallShield\InstallShield Professional
Default=False
RegKey1=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU1
RegKey2=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU2
RegKey3=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU3
RegKey4=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU4
[*Installer]
LangSecRef=3501
LangRef=3608
Default=False
SpecialKey1=R_INSTALLER
[*Installshield Developer 7.0]
LangSecRef=3021
Detect=HKCU\Software\InstallShield\Developer\7.0
Default=False
RegKey1=HKCU\Software\InstallShield\Developer\7.0\Recent File List
[*Interface]
LangSecRef=3501
LangRef=3615
Default=False
SpecialKey1=R_INTERFACE
[*Internet Download Manager]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Internet Download Manager
Default=False
FileKey1=%Appdata%\IDM\UrlHistory.txt
FileKey2=%Appdata%\IDM\UrlHistory2.txt
[*Internet Logs]
LangSecRef=3025
DetectFile=%windir%\Internet Logs
Default=False
FileKey1=%windir%\Internet Logs|*.dmp
FileKey2=%windir%\Internet Logs|*.log
FileKey3=%windir%\Internet Logs|*.tmp
FileKey4=%windir%\Internet Logs|*.zip
[*Invalid File Extensions]
LangSecRef=3501
LangRef=3602
Default=False
SpecialKey1=R_FILE_EXTS
[*IsoBuster]
LangSecRef=3021
Detect=HKCU\Software\Smart Projects\IsoBuster
Default=False
RegKey1=HKCU\Software\Smart Projects\IsoBuster|ImageFilePath
[*IsoBuster]
LangSecRef=3023
Detect=HKCU\Software\Smart Projects\IsoBuster
Default=False
RegKey1=HKCU\Software\Smart Projects\IsoBuster\RecentImages
[*Jetico Personal Firewall (Logs)]
LangSecRef=3022
Detect=HKLM\Software\Jetico\Personal Firewall
Default=False
FileKey1=%ProgramFiles%\Jetico\Jetico Personal Firewall|firewall*.log
[*KMPlayer]
LangSecRef=3023
Detect=HKCU\Software\KMPlayer
Default=False
RegKey1=HKCU\Software\KMPlayer\KMP2.0|LastFileName
RegKey2=HKCU\Software\KMPlayer\WideAlbum\(Default Album)
[*Kazaa (Search History)]
LangSecRef=3022
Detect=HKCU\Software\Kazaa
Default=False
RegKey1=HKCU\Software\Kazaa\Search
[*Koffix Blocker]
LangSecRef=3024
DetectFile=%ProgramFiles%\Koffix Blocker\Koffix.exe
Default=False
FileKey1=%userprofile%\My Documents\My Koffix Blocker Logs|*.*
[*Last Download Location]
LangSecRef=3001
LangRef=3108
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
RegKey1=HKCU\Software\Microsoft\Internet Explorer|Download Directory
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Main|Save Directory
[*LeechGet]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Cronosoft\LeechGet
RegKey1=HKCU\Software\Cronosoft\LeechGet\History
[*LimeWire]
LangSecRef=3022
DetectFile=%ProgramFiles%\LimeWire\LimeWire.exe
Default=False
FileKey1=%userprofile%\Incomplete|*.*|RECURSE
FileKey2=%userprofile%\Application Data\LimeWire|fileurns.cache
FileKey3=%userprofile%\Application Data\LimeWire|createtimes.cache
FileKey4=%userprofile%\Application Data\LimeWire|responses.cache
FileKey5=%userprofile%\Application Data\LimeWire|ttree.cache
FileKey6=%userprofile%\Application Data\LimeWire|gnutella.net
[*LogMeIn]
LangSecRef=3022
DetectFile=%ProgramFiles%\Logmein\x86\LogMeIn.exe
Default=False
FileKey1=%ProgramFiles%\Logmein|LMI*.log
[*MP3Gain (Logs)]
LangSecRef=3023
Detect=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis
Default=False
FileKey1=%ProgramFiles%\MP3Gain|*.log
[*MPEG Audio Collection]
LangSecRef=3023
Detect=HKCU\Software\MPEG Audio Collection
Default=False
RegKey1=HKCU\Software\MPEG Audio Collection|LastNameText1
RegKey2=HKCU\Software\MPEG Audio Collection|LastNameText2
RegKey3=HKCU\Software\MPEG Audio Collection|LastNameText3
RegKey4=HKCU\Software\MPEG Audio Collection|LastNameText4
RegKey5=HKCU\Software\MPEG Audio Collection|LastNameText5
RegKey6=HKCU\Software\MPEG Audio Collection|LastNameText6
[*MS Backup (Logs)]
LangSecRef=3025
DetectFile=%SystemRoot%\System32\ntbackup.exe
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Microsoft\Windows NT\NTBackup\Data|*.log
[*MS Direct Draw]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\DirectDraw
Default=False
RegKey1=HKCU\Software\Microsoft\DirectDraw\MostRecentApplicationName
[*MS HTML Help Workshop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\HTML Help Workshop
Default=False
RegKey1=HKCU\Software\Microsoft\HTML Help Workshop\Compressed HTML
RegKey2=HKCU\Software\Microsoft\HTML Help Workshop\Html Titles
RegKey3=HKCU\Software\Microsoft\HTML Help Workshop\Project Files
RegKey4=HKCU\Software\Microsoft\HTML Help Workshop\Recent File List
RegKey5=HKCU\Software\Microsoft\HTML Help Workshop\Settings|LastProject
RegKey6=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Folders
RegKey7=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Recent File List
[*MS Help Workshop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Help Workshop
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft Help Workshop\Cnt Files
RegKey2=HKCU\Software\Microsoft\Microsoft Help Workshop\Forage Files
RegKey3=HKCU\Software\Microsoft\Microsoft Help Workshop\Hlp Files
RegKey4=HKCU\Software\Microsoft\Microsoft Help Workshop\Hpj Files
RegKey5=HKCU\Software\Microsoft\Microsoft Help Workshop\Map Files
RegKey6=HKCU\Software\Microsoft\Microsoft Help Workshop\Recent File List
[*MS Imaging]
LangSecRef=3024
Detect=HKCU\Software\Kodak\Imaging
Default=False
RegKey1=HKCU\Software\Kodak\Imaging\Recent File List
[*MS Management Console]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List
[*MS Office 2003 Script Editor]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\MSE
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\MSE|LastLoadedSolution
Regkey2=HKCU\Software\Microsoft\Office\11.0\MSE\FileMRUList
Regkey3=HKCU\Software\Microsoft\Office\11.0\MSE\ProjectMRUList
Regkey4=HKCU\Software\Microsoft\Office\11.0\MSE\SolutionMRUList
[*MS Office Picture Manager]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office
Default=False
FileKey1=%LocalAppData%\Microsoft\OIS|OIScatalog.cag
FileKey2=%LocalAppData%\Microsoft\OIS\thumbnails|*.*
[*MS Office Publisher 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Publisher
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List
[*MS Paint]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List
[*MS Photo Editor]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor
Default=False
RegKey1=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile1
RegKey2=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile2
RegKey3=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile3
RegKey4=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile4
RegKey5=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType1
RegKey6=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType2
RegKey7=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType3
RegKey8=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType4
[*MS PhotoDraw 2000]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\PhotoDraw\1.0
Default=False
RegKey1=HKCU\Software\Microsoft\PhotoDraw\1.0\Recent File List
[*MS SQL Server 2005]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\FileMRUList
RegKey2=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\ProjectMRUList
[*MS Snapshot Viewer]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Snapshot Viewer
Default=False
RegKey1=HKCU\Software\Microsoft\Snapshot Viewer\Recent File List
[*MS Visual Studio 2005]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\8.0
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\8.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\8.0\ProjectMRUList
[*MS Visual Studio.NET 03]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\7.1
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\7.1\FileMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\7.1|LastLoadedSolution
FileKey1=%userprofile%\Local Settings\Application Data\ApplicationHistory|*.*|REMOVESELF
[*MS Visual Studio.NET 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\7.1
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File1
RegKey2=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File2
RegKey3=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File3
RegKey4=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File4
RegKey5=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File5
[*MS Windows Wallpaper]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU
[*MS Wordpad]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List
[*MS Works 4.0]
LangSecRef=3021
Detect= HKCU\Software\Microsoft\Works\4.0
Default=False
RegKey1=HKCU\Software\Microsoft\Works\4.0\Recent File List
[*MS Works Suite 2006]
LangSecRef=3021
Detect= HKCU\Software\Microsoft\Works\8.0
Default=False
RegKey1=HKCU\Software\Microsoft\Works\8.0\Recent File List
[*MS XML Notepad]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\XML Notepad
Default=False
RegKey1=HKCU\Software\Microsoft\XML Notepad\Recent File List
[*MSConfig]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Shared Tools\MSConfig
Default=False
RegKey1=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandFrom
RegKey2=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandTo
RegKey3=HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSConfig
[*MUI Cache]
LangSecRef=3501
LangRef=3614
Default=False
SpecialKey1=R_MUICACHE
[*MUICache]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\
[*Macromedia Dreamweaver MX]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Macromedia\Dreamweaver MX 2004
RegKey1=HKCU\Software\Macromedia\Dreamweaver MX 2004\Recent File List
[*Macromedia Fireworks 6.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Macromedia\Firework 6
RegKey1=HKCU\Software\Macromedia\Firework 6\Recent File List
[*Macromedia Flash 4.0]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 4
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 4\Recent File List
[*Macromedia Flash 5.0]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 5
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 5\Recent File List
[*Macromedia Flash MX 2004]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 7
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 7\Recent File List
[*Macromedia Flash MX]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 6
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 6\Recent File List
[*Macromedia Homesite 5.0]
LangSecRef=3021
Detect=HKCU\Software\Macromedia\HomeSite5
Default=False
RegKey1=HKCU\Software\Macromedia\HomeSite5\RecentFiles
[*Macromedia Shockwave 10]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Shockwave 10
Default=False
RegKey1=Software\Macromedia\Shockwave 10\movies
[*Macromedia Shockwave 8]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Shockwave 8
Default=False
RegKey1=Software\Macromedia\Shockwave 8\movies
[*MagicISO]
LangSecRef=3021
Detect=HKCU\Software\MagicISO
Default=False
RegKey1=HKCU\Software\MagicISO\Reopen
[*Malwarebytes' Anti Malware]
LangSecRef=3024
DetectFile=%ProgramFiles%\Malwarebytes' Anti-Malware\mbam.exe
Default=False
FileKey1=%appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Logs|*.txt
FileKey2=%appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine|*.*
[*Maxthon Browser 2]
LangSecRef=3022
DetectFile=%ProgramFiles%\Maxthon2\Maxthon.exe
Default=False
FileKey1=%ProgramFiles%\Maxthon2\Temp|*.*
[*McAfee SiteAdvisor]
LangSecRef=3024
DetectFile=%appdata%\SiteAdvisor
Default=False
FileKey1=%appdata%\SiteAdvisor|asserts.txt
FileKey2=%allusersdata%\SiteAdvisor|*.log
FileKey3=%commonappdata%\McAfee\MCLOGS\MISP\SAService|SAService*.log
[*Media Player Classic]
LangSecRef=3023
Detect=HKCU\Software\Gabest\Media Player Classic
Default=False
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName
[*Media Player Classic]
LangSecRef=3023
Detect=HKLM\Software\Gabest\Media Player Classic
Default=False
FileKey1=%appdata%\Media Player Classic|default.mpcpl
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName
[*MediaMonkey]
LangSecRef=3023
DetectFile=%ProgramFiles%\MediaMonkey\MediaMonkey.exe
Default=False
FileKey1=%userprofile%\Local Settings\Temp|*.*|RECURSE
FileKey2=%userprofile%\My Documents\My Music\MediaMonkey|MediaMonkey.m3u
FileKey3=%userprofile%\My Documents\My Music\MediaMonkey\Previews|*.*|RECURSE
[*Memory Dumps]
LangSecRef=3003
LangRef=3143
Default=False
FileKey1=%windir%|memory.dmp
FileKey2=%windir%\MiniDump|*.dmp
[*Menu Order Cache]
LangSecRef=3004
LangRef=3125
WarningRef=3203
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder
[*Messenger Plus! Live (Logs)]
LangSecRef=3022
Detect=HKCU\Software\Patchou
Default=False
FileKey1=%userprofile%\My Documents\My Chat Logs|*.*|RECURSE
[*MiTeC DFM Editor]
LangSecRef=3021
Detect=HKCU\Software\MiTeC\DFM Editor
Default=False
RegKey1=HKCU\Software\MiTeC\DFM Editor\5.x\Main\MRUHistory
[*Microangelo 6]
LangSecRef=3021
Detect=HKCU\Software\Eclipsit\Microangelo\Toolset 6
Default=False
RegKey1=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Animator\MRU List
RegKey2=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Librarian\MRU List
RegKey3=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Studio\MRU List
[*Microangelo]
LangSecRef=3021
Detect=HKCU\Software\Impact\Microangelo
Default=False
RegKey1=HKCU\Software\Impact\Microangelo\Animator\MRU List
RegKey2=HKCU\Software\Impact\Microangelo\Librarian\MRU List
RegKey3=HKCU\Software\Impact\Microangelo\Studio\MRU List
[*Microsoft AntiSpyware]
LangSecRef=3024
DetectFile=%ProgramFiles%\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
Default=False
FileKey1=%ProgramFiles%\Microsoft AntiSpyware|errors.log
FileKey2=%ProgramFiles%\Microsoft AntiSpyware|tracksEraser.log
FileKey3=%ProgramFiles%\Microsoft AntiSpyware|cleaner.log
[*Microsoft Visual Studio 6.0]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\6.0
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\6.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\6.0\MenuMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\6.0\ProjectMRUList
RegKey4=HKCU\Software\Microsoft\Visual Basic\6.0\RecentFiles
[*Missing Shared DLLs]
LangSecRef=3501
LangRef=3601
Default=False
SpecialKey1=R_SHARED_DLLS
[*More Windows Explorer]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
[*Morpheus]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Morpheus
RegKey1=HKCU\Software\Morpheus\Morpheus\Recent File List
[*Mozilla - Cookies]
LangSecRef=3026
LangRef=3102
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_COOKIES
[*Mozilla - Download History]
LangSecRef=3026
LangRef=3163
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_DOWNLOAD
[*Mozilla - Internet Cache]
LangSecRef=3026
LangRef=3161
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_CACHE
[*Mozilla - Internet History]
LangSecRef=3026
LangRef=3162
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_HISTORY
[*Mozilla - Saved Form Information]
LangSecRef=3026
LangRef=3164
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_FORM
[*Mp3tag (Log)]
LangSecRef=3023
Detect=HKLM\Software\Florian Heidenreich\Mp3tag
Default=False
FileKey1=%appdata%\Mp3tag|Mp3tagError.log
[*Mp3tag]
LangSecRef=3021
Detect=HKCU\Software\Moebius\Mp3tag
Default=False
RegKey1=HKCU\Software\Moebius\Mp3tag\Settings|LastDirName
RegKey2=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|0
RegKey3=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|1
RegKey4=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|2
RegKey5=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|3
RegKey6=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|4
RegKey7=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|5
RegKey8=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|6
RegKey9=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|7
[*MusicMatch Jukebox]
LangSecRef=3023
Detect=HKLM\Software\MUSICMATCH\MUSICMATCH Jukebox
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox|*.log
FileKey2=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox|*log.txt
FileKey3=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox\Cache|*.*
FileKey4=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\TEMP|*.*
FileKey5=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\MMRadio\Cache|*.*
[*MyToolkit]
LangSecRef=3024
Detect=HKCU\Software\FutureFog\MyToolkit\Options
Default=False
RegKey1=HKCU\Software\FutureFog\MyToolkit\Options|LastUsedFolder
[*NA Framework Agent]
LangSecRef=3021
Detect=HKLM\Software\Network Associates\TVD\Shared Components\Framework
Default=False
FileKey1=%allusersprofile%\Application Data\Network Associates\Common Framework\AgentEvents|*.*
FileKey2=%allusersprofile%\Application Data\McAfee\Common Framework\AgentEvents|*.*
[*NSIS]
LangSecRef=3021
Detect=HKLM\Software\NSIS
Default=False
RegKey1=HKLM\Software\NSIS\MRU
[*Nero Burning ROM 9]
LangSecRef=3021
Detect=HKCU\Software\Nero\Nero 9
Default=False
RegKey1=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BrowserDir
RegKey2=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey3=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|WorkingDir
RegKey4=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey5=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BootImageDir
RegKey6=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Recent File List
FileKey1=%appdata%\Nero\Nero 9\Nero Burning ROM|*.log
[*Nero Burning ROM]
LangSecRef=3021
Detect=HKCU\Software\ahead\Nero - Burning Rom
Default=False
RegKey1=HKCU\Software\ahead\Nero - Burning Rom\Settings|BrowserDir
RegKey2=HKCU\Software\ahead\Nero - Burning Rom\Settings|ImageDir
RegKey3=HKCU\Software\ahead\Nero - Burning Rom\Settings|WorkingDir
RegKey4=HKLM\Software\Ahead\Nero - Burning Rom\Settings|ImageDir
RegKey5=HKLM\Software\Ahead\Nero - Burning Rom\Settings|BootImageDir
RegKey6=HKCU\Software\Ahead\Nero - Burning Rom\Recent File List
RegKey7=HKCU\Software\Ahead\Cover Designer\Recent File List
RegKey8=HKCU\Software\Ahead\Nero Wave Editor\Recent File List
FileKey1=%ProgramFiles%\Ahead\Nero|NeroHistory.log
[*Netscape Navigator 4.x]
LangSecRef=3022
Detect=HKCU\Software\Netscape\Netscape Navigator\Main
Default=False
FileKey1=%ProgramFiles%\Netscape\Users\default|netscape.hst
FileKey2=%ProgramFiles%\Netscape\Users\default|cookies.txt
FileKey3=%ProgramFiles%\Netscape\Users\default\cache|*.*
[*Norton AntiVirus]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Symantec\Norton AntiVirus NT\Install\7.50
Default=False
FileKey1=%commonappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey2=%localappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|*.*
[*NoteXpad]
LangSecRef=3021
Detect=HKLM\Software\NoteXpad
Default=False
RegKey1=HKLM\Software\NoteXpad\Recent
[*O&O Defrag]
LangSecRef=3024
Detect=HKCU\Software\O&O\O&O Defrag
Default=False
FileKey1=%userprofile%\My Documents\O&O\O&O Defrag\data\reports|*.*|RECURSE
[*Obsolete Software]
LangSecRef=3501
LangRef=3609
Default=False
SpecialKey1=R_OLDSOFTWARE
[*Office 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel\Recent Files
RegKey2=HKCU\Software\Microsoft\Office\11.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
Regkey3=HKCU\Software\Microsoft\Office\11.0\PowerPoint\Recent File List
Regkey4=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List
Regkey5=HKCU\Software\Microsoft\Office\11.0\InfoPath\Recent File List
RegKey6=HKCU\Software\Microsoft\Office\11.0\Common\Internet\Server Cache
RegKey7=HKCU\Software\Microsoft\Office\11.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\MSPaper 11.0\Persist File Name
RegKey9=HKCU\Software\Microsoft\MSPaper 11.0\Recent File List
RegKey10=HKCU\Software\Microsoft\Office\11.0\Word\Data|Settings
RegKey11=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile1
RegKey12=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile2
RegKey13=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile3
RegKey14=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile4
RegKey15=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile5
RegKey16=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile6
RegKey17=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile7
RegKey18=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile8
RegKey19=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey20=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey21=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
[*Office 2007]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\12.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey2=HKCU\Software\Microsoft\Office\12.0\Word\File MRU
RegKey3=HKCU\Software\Microsoft\Office\12.0\Excel\File MRU
RegKey4=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU1
RegKey5=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU2
RegKey6=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU3
RegKey7=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU4
RegKey8=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU5
RegKey9=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU6
RegKey10=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU7
RegKey11=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU8
RegKey12=HKCU\Software\Microsoft\Office\12.0\PowerPoint\File MRU
RegKey13=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Save As\File Name MRU
RegKey14=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open\File Name MRU
RegKey15=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Save As\File Name MRU
RegKey16=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Excel\Settings\Save As\File Name MRU
RegKey17=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Publisher\Settings\Save As\File Name MRU
RegKey18=HKCU\Software\Microsoft\Office\12.0\Publisher\Recent File List
RegKey19=HKCU\Software\Microsoft\Office\12.0\InfoPath\Recent File List
[*Office 97]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\8.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\8.0\Excel\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\8.0\Project\Recent File List
RegKey3=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent File List
RegKey4=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent Folder List
RegKey5=HKCU\Software\Microsoft\Office\8.0\Common\Internet\LocationOfComponents
RegKey6=HKCU\Software\Microsoft\Office\8.0\Access\Settings
[*Office XP]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\10.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\10.0\PowerPoint\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\10.0\Excel\Recent Files
RegKey3=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent File List
RegKey4=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List
RegKey5=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List
RegKey6=HKCU\Software\Microsoft\Office\10.0\Word\Recent Templates
RegKey7=HKCU\Software\Microsoft\Office\10.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\Office\10.0\Word\Data|Settings
RegKey9=HKCU\Software\Microsoft\Office\10.0\Access\Settings
[*Old Prefetch data]
LangSecRef=3004
LangRef=3147
Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OptimalLayout
SpecialKey1=N_INT_PREFETCH
[*OpenOffice 1.14]
LangSecRef=3021
DetectFile=%ProgramFiles%\OpenOffice.org1.1.4\program\soffice.exe
Default=False
FileKey1=%ProgramFiles%\OpenOffice.org1.1.4\user\registry\data\org\openoffice\Office|Common.xcu
[*OpenOffice 2.0]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.0
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu
[*OpenOffice 2.1]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.1
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu
[*OpenOffice 2.3]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.3
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu
[*OpenOffice 3.1]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.1
Default=False
FileKey1=%appdata%\OpenOffice.org\3\user\registry\data\org\openoffice\Office|Common.xcu
[*Opera - Cookies]
LangSecRef=3027
LangRef=3102
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_COOKIES
[*Opera - Internet Cache]
LangSecRef=3027
LangRef=3161
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_CACHE
[*Opera - Internet History]
LangSecRef=3027
LangRef=3162
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_HISTORY
[*Opera 9 (Classic)]
LangSecRef=3022
DetectFile=%ProgramFiles%\Opera 9\Opera.exe
Default=False
FileKey1=%ProgramFiles%\Opera 9\profile|cookies4.dat
FileKey2=%ProgramFiles%\Opera 9\profile|global.dat
FileKey3=%ProgramFiles%\Opera 9\profile|vlink4.dat
FileKey4=%ProgramFiles%\Opera 9\profile\cache4|*.*
FileKey5=%ProgramFiles%\Opera 9\profile\cacheOp|*.*
[*Orbit Downloader]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Orbit
Default=False
FileKey1=%appdata%\Orbit\|fileinfo.dat
FileKey2=%appdata%\Orbit\|history.dat
FileKey3=%appdata%\Orbit\|unfinish.dat
FileKey4=%appdata%\Orbit\flink|*.*
[*Other Explorer MRUs]
LangSecRef=3002
LangRef=3124
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\PrnPortsMRU
RegKey4=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU
RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComputerDescriptions
RegKey6=HKLM\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey7=HKCU\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey8=HKLM\Software\Microsoft\DirectDraw\MostRecentApplication|Name
RegKey9=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Id
RegKey10=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Name
[*Outlook 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Outlook
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey2=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey3=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
RegKey4=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 1
RegKey5=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 3
FileKey1=%appdata%\Microsoft\Outlook|Outlook.NK2
[*PDF-XChange Viewer]
LangSecRef=3021
Detect=HKCU\Software\Tracker Software\PDFViewer
Default=False
RegKey1=HKCU\Software\Tracker Software\PDFViewer\Documents\LastOpened
RegKey2=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Bars
RegKey3=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Panes
[*PDFCreator]
LangSecRef=3024
Detect=HKCU\Software\PDFCreator
Default=False
RegKey1=HKCU\Software\PDFCreator\Program|LastsaveDirectory
[*PE Module Explorer]
LangSecRef=3024
Detect=HKCU\Software\Woozle\PE Module Explorer
Default=False
RegKey1=HKCU\Software\Woozle\PE Module Explorer\Recent Files
[*Paint Shop Pro 7.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 7
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 7\Recent File List
RegKey2=HKCU\Software\Jasc\Animation Shop 3\Recent File List
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 7\General|FolderHistory
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveAsDirectory
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveCopyDirectory
[*Paint Shop Pro 8.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 8
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 8\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 8\WorkspaceMRU
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdPyScript\RunScript|FileName
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdFile\FileSaveAs|FileFolder
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdNonGraphic\SaveWorkspace|WorkspaceFilename
RegKey6=HKCU\Software\Jasc\Paint Shop Pro 8\ScriptMRU
[*Paint Shop Pro 9.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 9
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 9\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 9\WorkspaceMRU
Regkey3=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileOpen|Folder
[*Paint Shop Pro XI]
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\11
Default=False
RegKey1=HKCU\Software\Corel\Paint Shop Pro\11\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\11\WorkspaceMRU
Regkey3=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileOpen|Folder
[*Paint Shop Pro X]
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\10
Default=False
RegKey1=HKCU\Software\Corel\Paint Shop Pro\10\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\10\WorkspaceMRU
Regkey3=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileOpen|Folder
[*Paint.NET]
LangSecRef=3021
Detect=HKCU\Software\Paint.NET
Default=False
RegKey1=HKCU\Software\Paint.NET|MRU0
RegKey2=HKCU\Software\Paint.NET|MRU1
RegKey3=HKCU\Software\Paint.NET|MRU2
RegKey4=HKCU\Software\Paint.NET|MRU3
RegKey5=HKCU\Software\Paint.NET|MRU4
RegKey6=HKCU\Software\Paint.NET|MRU5
RegKey7=HKCU\Software\Paint.NET|MRU6
RegKey8=HKCU\Software\Paint.NET|MRU7
RegKey9=HKCU\Software\Paint.NET|MRU0Thumb
RegKey10=HKCU\Software\Paint.NET|MRU1Thumb
RegKey11=HKCU\Software\Paint.NET|MRU2Thumb
RegKey12=HKCU\Software\Paint.NET|MRU3Thumb
RegKey13=HKCU\Software\Paint.NET|MRU4Thumb
RegKey14=HKCU\Software\Paint.NET|MRU5Thumb
RegKey15=HKCU\Software\Paint.NET|MRU6Thumb
RegKey16=HKCU\Software\Paint.NET|MRU7Thumb
[*Pelles C]
LangSecRef=3021
Detect=HKCU\Software\Pelle Orinius\PellesC
Default=False
RegKey1=HKCU\Software\Pelle Orinius\PellesC\Recent File List
RegKey2=HKCU\Software\Pelle Orinius\PellesC\Recent Project List
RegKey3=HKCU\Software\Pelle Orinius\PellesC\Recent Search List
[*PerfectDisk 7.0]
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\7.0
Default=False
FileKey1=%commonappdata%\Raxco\PerfectDisk\7.0|PerfectDisk.log
[*PerfectDisk 8]
LAngSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\8.0
Default=False
FileKey1=%allusersprofile%\Application Data\Raxco\PerfectDisk\8.0|*.log
[*Phorest]
LangSecRef=3024
Detect=HKCU\Software\FutureFog\Phorest\Options
Default=False
RegKey1=HKCU\Software\FutureFog\Phorest\Options|LastUsedFolder
RegKey2=HKCU\Software\FutureFog\Phorest\Layout|SelectionLeft
RegKey3=HKCU\Software\FutureFog\Phorest\Layout|SelectionTop
RegKey4=HKCU\Software\FutureFog\Phorest\Layout|SelectionWidth
RegKey5=HKCU\Software\FutureFog\Phorest\Layout|SelectionHeight
[*Photo Print Calendar 3.00E Beta]
LangSecRef=3021
Detect=HKLM\SOFTWARE\Computer Institute of Japan, Ltd.\Photo Print Calendar from YOKOHAMA Ver.3.00E beta\3.00E beta
Default=False
FileKey1=%programfiles%\Photo Print Calendar|update.bmp
[*Photoshop CS Filebrowser]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Adobe\Photoshop
FileKey1=%userprofile%\application data\Adobe\FileBrowser\PhotoshopCS|*.*
[*Photoshop CS Filebrowser]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Adobe\Photoshop
FileKey1=%userprofile%\application data\Adobe\FileBrowser\PhotoshopCS|*.*
fileKey2=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE
[*PicoZip]
LangSecRef=3024
Detect=HKCU\Software\PicoZip
Default=False
RegKey1=HKCU\Software\PicoZip\MRU Items
RegKey2=HKCU\Software\PicoZip\MRUExtract
[*Pok3D]
LangSecRef=3021
DetectFile=%ProgramFiles%\Pok3d\Pok3d.ico
Default=False
FileKey1=%userprofile%\Application Data\Pok3d|*.log
FileKey2=%userprofile%\Application Data\Pok3d|*.dmp
[*PowerArchiver]
LangSecRef=3024
Detect=HKCU\Software\PowerArchiver
Default=False
RegKey1=HKCU\Software\PowerArchiver\Files|Active_File1
RegKey2=HKCU\Software\PowerArchiver\Files|Active_File2
RegKey3=HKCU\Software\PowerArchiver\Files|Active_File3
RegKey4=HKCU\Software\PowerArchiver\Files|Active_File4
RegKey5=HKCU\Software\PowerArchiver\Files|Active_File5
RegKey6=HKCU\Software\PowerArchiver\Files|Extract1
RegKey7=HKCU\Software\PowerArchiver\Files|Extract2
RegKey8=HKCU\Software\PowerArchiver\Files|Extract3
RegKey9=HKCU\Software\PowerArchiver\Files|Extract4
RegKey10=HKCU\Software\PowerArchiver\Files|Extract5
RegKey11=HKCU\Software\PowerArchiver\Files|Last open dir
RegKey12=HKCU\Software\PowerArchiver\Files|Last backup dir
RegKey13=HKCU\Software\PowerArchiver\Files|Last add dir
[*PowerDVD]
LangSecRef=3021
DetectFile=%ProgramFiles%\Cyberlink\PowerDVD\PowerDVD.exe
Default=False
FileKey1=%ProgramFiles%\CyberLink\PowerDVD|*.pls
FileKey2=%userprofile%\My Documents\CyberLink\PowerDVD|*.pls
[*PowerZip]
LangSecRef=3024
Detect=HKCU\Software\Trident Software\PowerZip
Default=False
RegKey1=HKCU\Software\Trident Software\PowerZip\Recent File List
[*QuickPAR]
LangSecRef=3024
Detect=HKCU\Software\QuickPar
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\QuickPar|*.*
[*Quicktime Player Cache]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=False
FileKey1=%localappdata%\Apple Computer\QuickTime\downloads|*.*|RECURSE
[*Quicktime Player]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=False
RegKey1=HKLM\Software\Apple Computer, Inc.\QuickTime\Recent Movies
FileKey1=%userprofile%|QTPlayerSession.xml
FileKey2=%appdata%\Apple Computer\QuickTime|QTPlayerSession.xml
[*Qwest QuickCare]
LangSecRef=3022
Detect=HKLM\Software\QuickCare
Default=False
FileKey1=%allusersprofile%\Application Data\Support.com|*.tmp|RECURSE
FileKey2=%userprofile%\Local Settings\Application Data\SupportSoft|*.tmp|RECURSE
[*ReGet Deluxe]
LangSecRef=3022
Detect=HKCU\Software\ReGet Software\ReGetDx
Default=False
FileKey1=%ProgramFiles%\ReGet Deluxe\history|*.*
RegKey1=HKCU\Software\ReGet Software\ReGetDx\FtpExplorer\Hist
RegKey2=HKCU\Software\ReGet Software\ReGetDx\History
RegKey3=HKCU\Software\ReGet Software\ReGetDx\Search\HistFind
[*Real Player SP]
LangSecRef=3023
Detect=HKCU\Software\RealNetworks\RealPlayer\12.0
Default=False
RegKey1=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins1
RegKey10=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins2
RegKey11=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins3
RegKey12=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins4
RegKey13=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins5
RegKey14=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins6
RegKey15=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins7
RegKey16=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins8
RegKey17=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\LastOpenFileDir
RegKey18=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips1
RegKey19=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips2
RegKey20=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips3
RegKey21=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips4
RegKey22=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips5
RegKey23=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips6
RegKey24=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips7
FileKey1=%appdata%\Real\RealPlayer|RealPlayer-log.txt
FileKey2=%appdata%\Real\RealPlayer\History|*.*
[*Recent Documents]
LangSecRef=3002
LangRef=3121
Default=False
SpecialKey1=N_EX_RECENTDOCS
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
[*Recently Typed URLs]
LangSecRef=3001
LangRef=3104
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
RegKey1=HKCU\Software\Microsoft\Internet Explorer\TypedURLs
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
RegKey3=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU
[*RegAlyzer]
LangSecRef=3024
Detect=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer
Default=False
RegKey1=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|LastKey
RegKey2=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|RemoteListHistory
RegKey3=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|SearchTerm
[*RegEdit]
LangSecRef=3025
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit|LastKey
[*Registry Mechanic]
LangSecRef=3024
Detect=HKLM\Software\PCTools\Registry Mechanic
Default=False
FileKey1=%userprofile%|*.rmbak|RECURSE
FileKey2=%userprofile%|*.rrr|RECURSE
FileKey3=%userprofile%|*.rrr.bak|RECURSE
FileKey4=%userprofile%\Local Settings\Application Data\Microsoft\Windows|*.rmbak
FileKey5=%userprofile%\Local Settings\Application Data\Microsoft\Windows|*.rrr
FileKey6=%userprofile%\Local Settings\Application Data\Microsoft\Windows|*.rrr.bak
FileKey7=%allusersprofile%|*.rmbak|RECURSE
FileKey8=%allusersprofile%|*.rrr|RECURSE
FileKey9=%allusersprofile%|*.rrr.bak|RECURSE
FileKey10=%systemdrive%\Documents and Settings\Guest|*.rmbak|RECURSE
FileKey11=%systemdrive%\Documents and Settings\Guest|*.rrr|RECURSE
FileKey12=%systemdrive%\Documents and Settings\Guest|*.rrr.bak|RECURSE
FileKey13=%systemdrive%\Documents and Settings\LocalService|*.rmbak|RECURSE
FileKey14=%systemdrive%\Documents and Settings\LocalService|*.rrr|RECURSE
FileKey15=%systemdrive%\Documents and Settings\LocalService|*.rrr.bak|RECURSE
FileKey16=%systemdrive%\Documents and Settings\NetworkService|*.rmbak|RECURSE
FileKey17=%systemdrive%\Documents and Settings\NetworkService|*.rrr|RECURSE
FileKey18=%systemdrive%\Documents and Settings\NetworkService|*.rrr.bak|RECURSE
FileKey19=%windir%\system32\config|*.rmbak
FileKey20=%windir%\system32\config|*.rrr
FileKey21=%windir%\system32\config|*.rrr.bak
FileKey22=%ProgramFiles%\Registry Mechanic\Log|compactlog.log
FileKey23=%ProgramFiles%\Registry Mechanic\Log|results.log
FileKey24=%ProgramFiles%\Registry Mechanic\Log|scan.log
[*RegistryFix]
LangSecRef=3024
DetectFile=%ProgramFiles%\RegistryFix\RegistryFix.exe
Default=False
FileKey1=%ProgramFiles%\RegistryFix\logs|*.*
[*Remote Desktop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Terminal Server Client
Default=False
FileKey1=%localappdata%\Microsoft\Terminal Server Client\Cache|*.*
RegKey1=HKCU\Software\Microsoft\Terminal Server Client\Default
[*Run (in Start Menu)]
LangSecRef=3002
LangRef=3122
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
[*Run At Startup]
LangSecRef=3501
LangRef=3610
Default=False
SpecialKey1=R_RUNSTARTUP
[*STOIK Smart Resizer]
LangSecRef=3023
Detect=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer\Recent File List
Default=False
RegKey1=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer\Recent File List
[*STOIK Video Converter 2]
LangSecRef=3023
Detect=HKCU\Software\STOIK
Default=False
FileKey1=%appdata%\STOIK\videopak2|*.ini
[*SUPERAntiSpyware (Logs)]
LangSecRef=3024
Detect=HKLM\Software\SUPERAntiSpyware.com\SUPERAntiSpyware
Default=False
FileKey1=%appdata%\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs|*.log
[*SWiSH]
LangSecRef=3023
Detect=HKCU\Software\DJJ Holdings\SWiSH
Default=False
RegKey1=HKCU\Software\DJJ Holdings\SWiSH\Recent File List
[*Safari - Cookies]
LangSecRef=3028
LangRef=3102
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari\Cookies|Cookies.plist
[*Safari - Internet Cache]
LangSecRef=3028
LangRef=3161
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%localappdata%\Apple Computer\Safari|Cache.db
[*Safari - Internet History]
LangSecRef=3028
LangRef=3162
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari|History.plist
FileKey2=%appdata%\Apple Computer\Safari|Downloads.plist
FileKey3=%localappdata%\Apple Computer\Safari\History|*.*
[*Safari - Saved Form Information]
LangSecRef=3028
LangRef=3164
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari|Form Values.plist
[*ScanDefrag (Logs)]
LangSecRef=3024
Detect=HKLM\Software\ScanDefrag
Default=False
FileKey1=%SystemDrive%\ScanDefrag|*.log
FileKey2=%SystemDrive%\ScanDefrag\logs|*.txt
[*Search Assistant Autocomplete]
LangSecRef=3002
LangRef=3123
Detect=HKCU\Software\Microsoft\Search Assistant
Default=False
RegKey1=HKCU\Software\Microsoft\Search Assistant\ACMru
[*Second Copy 2000]
LangSecRef=3021
Detect=HKCU\Software\Centered Systems\Second Copy 2000
Default=False
FileKey1=%ProgramFiles%\SecCopy|log.rtf
FileKey2=%ProgramFiles%\SecCopy|log-old.rtf
RegKey1=HKCU\Software\Centered Systems\Second Copy 2000\MRU
[*SecureCRT]
LangSecRef=3021
Detect=HKCU\Software\VanDyke\SecureCRT
Default=False
FileKey1=%appdata%\VanDyke\SecureCRT\Config|Recent File List.ini
FileKey2=%appdata%\VanDyke\SecureCRT\Config|Recent Script List.ini
[*Shareaza]
LangSecRef=3022
DetectFile=%ProgramFiles%\Shareaza\Shareaza.exe
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Shareaza\Incomplete|*.*
[*Smart Installer Maker]
LangSecRef=3024
Detect=HKCU\Software\InstallBuilders\Smart Install Maker
Default=False
RegKey1=HKCU\Software\InstallBuilders\Smart Install Maker\Reopen
[*SmartFTP]
LangSecRef=3022
Detect=HKCU\Software\SmartFTP
Default=False
FileKey1=%appdata%\SmartFTP\Cache|*.*|RECURSE
FileKey2=%appdata%\SmartFTP|History.dat
[*SoftThinks CD Creator]
LangSecRef=3021
Detect=HKLM\SOFTWARE\SoftThinks
Default=False
FileKey1=%windir%\CREATOR|*.log
[*Soulseek Beta]
LangSecRef=3022
DetectFile=%ProgramFiles%\Soulseek-Test\slsk.exe
Default=False
FileKey1=%ProgramFiles%\Soulseek-Test|search.cfg
[*Soulseek]
LangSecRef=3022
DetectFile=%ProgramFiles%\Soulseek\slsk.exe
Default=False
FileKey1=%ProgramFiles%\Soulseek|search.cfg
[*Sound Forge 6.0]
LangSecRef=3022
Detect=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics
Default=False
RegKey1=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30110
RegKey2=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30111
RegKey3=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30112
RegKey4=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30113
RegKey5=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30114
RegKey6=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30115
[*SpyBot Search and Destroy]
LangSecRef=3024
Detect=HKCU\Software\Safer Networking Limited\SpybotSnD
Default=False
FileKey1=%commonappdata%\Spybot - Search & Destroy\Logs|*.*
FileKey2=%ProgramFiles%\Spybot - Search & Destroy|advdebug.txt
FileKey3=%commonappdata%\Spybot - Search & Destroy|Statistics.ini
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|*.*
FileKey5=%windir%\All Users\Application Data\Spybot - Search & Destroy|Statistics.ini
FileKey6=%commonappdata%\Spybot - Search & Destroy\Backups|*.log
[*SpyDefense]
LangSecRef=3024
DetectFile=%ProgramFiles%\Everest Labs\Spydefense\sdc.exe
Default=False
FileKey1=%userprofile%\Application Data\Everest Labs\Spydefense\Backups|BF7.tmp
FileKey2=%userprofile%\Application Data\Everest Labs\Spydefense|SpyDefense.log
FileKey3=%userprofile%\Application Data\Everest Labs\Spydefense|History.ini
FileKey3=%userprofile%\Application Data\Everest Labs\Spydefense|Backups.ini
[*Spyware Doctor]
LangSecRef=3024
Detect=HKCU\Software\PCTools\Spyware Doctor
Default=False
FileKey1=%ProgramFiles%\Spyware Doctor\Log|*.*
[*Spyware Terminator]
LangSecRef=3024
Detect=HKCU\Software\Spyware Terminator
Default=False
FileKey1=%ProgramFiles%\Spyware Terminator\|*.err
FileKey2=%ProgramFiles%\Spyware Terminator\|*.old
FileKey3=%ProgramFiles%\Spyware Terminator\update|*.*
FileKey4=%appdata%\Spyware Terminator\Reports\|*.*
FileKey5=%ProgramFiles%\Spyware Terminator\Clamav\|*.old
[*StarOffice 8]
LangSecRef=3021
DetectFile=%ProgramFiles%\Sun\StarOffice 8\program\soffice.exe
Default=False
FileKey1=%appdata%\StarOffice8\user\registry\data\org\openoffice\Office|Common.xcu
[*Start Menu Ordering]
LangSecRef=3501
LangRef=3611
Default=False
SpecialKey1=R_STARTMENUORDER
[*Start Menu Shortcuts]
LangSecRef=3003
LangRef=3612
Default=False
SpecialKey1=F_STARTMENU
[*Sun Java]
LangSecRef=3022
Detect=HKLM\SOFTWARE\JavaSoft\Java Plug-in
Default=False
FileKey1=%appdata%\Sun\Java\Deployment\cache|*.*|RECURSE
FileKey2=%appdata%\Sun\Java\Deployment\javaws\cache|*.*|RECURSE
[*Symantec AntiVirus]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Symantec\Symantec AntiVirus\Install\7.50
Default=False
FileKey1=%commonappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey2=%localappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|*.*
[*Symantec Ghost]
LangSecRef=3024
Detect=HKCU\Software\Symantec\Symantec Ghost
Default=False
RegKey1=HKCU\Software\Symantec\Symantec Ghost\Explorer\Ghost Explorer\Recent File List
[*Synchronize It!]
LangSecRef=3021
Detect=HKCU\Software\grigsoft.com\Synchronize It!
Default=False
RegKey1=HKCU\Software\grigsoft.com\Synchronize It!\Synchronize It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Synchronize It!\Combos
[*TUGZip]
LangSecRef=3024
Detect=HKCU\Software\TUGZip
Default=False
RegKey1=HKCU\Software\TUGZip|mainRecent
RegKey2=HKCU\Software\TUGZip|extrRecent
RegKey3=HKCU\Software\TUGZip|cmpWorkingDir
[*Tag&Rename 3]
LangSecRef=3024
Detect=HKCU\Software\Softpointer\Tag&Rename3\Config
Default=False
RegKey1=HKCU\Software\Softpointer\Tag&Rename3\Config|FCurrentFolder
RegKey2=HKCU\Software\Softpointer\Tag&Rename3\Config|FHistoryList
[*Talkback (Crash Reports)]
LangSecRef=3026
Detect=HKLM\SOFTWARE\FullCircle\TalkBack
Default=False
RegKey1=HKLM\SOFTWARE\FullCircle\TalkBack
FileKey1=%userprofile%\Application Data\Talkback\MozillaOrg\Firefox15|*.*|RECURSE
FileKey2=%userprofile%\Application Data\Talkback\MozillaOrg\Firefox2|*.*|RECURSE
FileKey3=%userprofile%\Application Data\Talkback\MozillaOrg\Thunderbird2|*.*|RECURSE
[*TechSmith DubIt]
LangSecRef=3023
Detect=HKCU\Software\TechSmith\DubIt
Default=False
FileKey1=%ProgramFiles%\TechSmith\DubIt|*.gid
RegKey1=HKCU\Software\TechSmith\DubIt\Recent Audio Files
RegKey2=HKCU\Software\TechSmith\DubIt\Recent Video Files
[*Temporary Files]
LangSecRef=3003
LangRef=3142
Default=False
SpecialKey1=N_TEMP_DIRS
[*Temporary Internet Files]
LangSecRef=3001
LangRef=3101
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_TEMP
[*TeraCopy]
LangSecRef=3024
Detect=HKCU\Software\Code Sector\TeraCopy
Default=False
RegKey1=HKCU\Software\Code Sector\TeraCopy|LastTargetFolder
FileKey1=%appdata%\TeraCopy|FileList.dat
FileKey2=%appdata%\TeraCopy|Transfer.log
[*TextPad]
LangSecRef=3021
Detect=HKCU\Software\Helios\TextPad 4
Default=False
RegKey1=HKCU\Software\Helios\TextPad 4\Recent File List
RegKey2=HKCU\Software\Helios\TextPad 4\Recent Strings
[*The Bat]
LangSecRef=3022
Detect=HKCU\Software\RIT\The Bat!
Default=False
FileKey1=%appdata%\The Bat!\cache|*.*
[*The Cleaner]
LangSecRef=3024
DetectFile=%ProgramFiles%\The Cleaner\cleaner.exe
Default=False
FileKey1=%ProgramFiles%\The Cleaner|logfile.txt
FileKey2=%ProgramFiles%\The Cleaner|moolive.log
FileKey3=%ProgramFiles%\The Cleaner|tca.log
[*The GIMP 2.2]
LangSecRef=3021
DetectFile=%userprofile%\.gimp-2.2\gimprc
Default=False
FileKey1=%userprofile%\.gimp-2.2|documents
[*Thumbnail Cache]
LangSecRef=3002
LangRef=3131
DetectOS=6.0
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\Explorer|thumbcache_*.db
[*Tivo Desktop]
LangSecRef=3023
Default=False
Detect=HKCU\SOFTWARE\TiVo\Desktop
FileKey1=%localappdata%\TiVo Desktop\Cache|*.*
[*Tomahawk PDF+]
LangSecRef=3021
Detect=HKCU\Software\NativeWinds\Tomahawk
Default=False
RegKey1=HKCU\Software\NativeWinds\Tomahawk\MRU
[*Total Recorder]
LangSecRef=3023
Detect=HKCU\Software\HighCriteria\TotalRecorder\Recent File List
Default=False
RegKey1=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File1
RegKey2=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File2
RegKey3=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File3
RegKey4=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File4
RegKey5=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File5
RegKey6=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File6
RegKey7=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File7
RegKey8=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File8
RegKey9=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File9
[*Total Uninstall]
LangSecRef=3024
Detect=HKCU\Software\MartS\Total Uninstall
Default=False
FileKey1=%ProgramFiles%\Total Uninstall|Log.txt
FileKey2=%ProgramFiles%\Total Uninstall|*.GID
[*Tray Notifications Cache]
LangSecRef=3004
LangRef=3126
WarningRef=3204
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|IconStreams
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|PastIconsStream
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|IconStreams
RegKey4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|PastIconsStream
[*Trillian]
LangSecRef=3024
Detect=HKLM\Software\Clients\IM\Trillian
Default=False
FileKey1=%ProgramFiles%\Trillian\users\default\instantlookup|*.*
FileKey2=%ProgramFiles%\Trillian\users\default\logs|*.*|RECURSE
FileKey3=%ProgramFiles%\Trillian\users\default\buddyicons|*.*|RECURSE
FileKey4=%ProgramFiles%\Trillian\Crash Files|*.*|RECURSE
[*TuneUp Utilities]
LangSecRef=3024
Detect=HKCU\Software\TuneUp
Default=False
FileKey1=%appdata%\TuneUp Software\TuneUp Utilities\Backups|*.rcb
[*TweakNow PowerPack 2005]
LangSecRef=3024
Detect=HKCU\Software\TweakNow PowerPack
Default=False
FileKey1=%ProgramFiles%\TweakNow PowerPack\Backup|*.*
[*UPX Shell]
LangSecRef=3024
Detect=HKCU\Software\ION Tek\UPX Shell
Default=False
RegKey1=HKCU\Software\ION Tek\UPX Shell\3.x|History
[*Ulead GIF Animator 5.05]
LangSecRef=3024
Detect=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05
Default=False
RegKey1=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05\Recent File List
[*Ulead Smart Saver Pro 3.0]
LangSecRef=3023
Detect=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0
Default=False
RegKey1=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0\Recent File List
[*UltraISO]
LangSecRef=3024
Detect=HKCU\Software\EasyBoot Systems\UltraISO
Default=False
RegKey1=HKCU\Software\EasyBoot Systems\UltraISO\5.0|Reopen
RegKey2=HKCU\Software\EasyBoot Systems\UltraISO\5.0|a
RegKey3=HKCU\Software\EasyBoot Systems\UltraISO\5.0|b
RegKey4=HKCU\Software\EasyBoot Systems\UltraISO\5.0|c
RegKey5=HKCU\Software\EasyBoot Systems\UltraISO\5.0|d
RegKey6=HKCU\Software\EasyBoot Systems\UltraISO\5.0|e
RegKey7=HKCU\Software\EasyBoot Systems\UltraISO\5.0|f
RegKey8=HKCU\Software\EasyBoot Systems\UltraISO\5.0|g
RegKey9=HKCU\Software\EasyBoot Systems\UltraISO\5.0|h
RegKey10=HKCU\Software\EasyBoot Systems\UltraISO\5.0|i
[*Universal Share Downloader]
LangSecRef=3022
DetectFile=%ProgramFiles%\USDownloader\USDownloader.exe
Default=False
FileKey1=%ProgramFiles%\USDownloader|USDownloader.log
FileKey2=%ProgramFiles%\USDownloader|*.bak
FileKey3=%ProgramFiles%\USDownloader|*.bmp
FileKey4=%ProgramFiles%\USDownloader|*.jpg
FileKey5=%ProgramFiles%\USDownloader|*.png
[*User Assist History]
LangSecRef=3004
LangRef=3128
WarningRef=3206
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
[*VNCViewer 3]
LangSecRef=3024
Default=False
Detect=HKCU\Software\ORL\VNCviewer
RegKey1=HKCU\Software\ORL\VNCviewer\MRU
[*VNCViewer 4]
LangSecRef=3024
Default=False
Detect=HKCU\Software\RealVNC\VNCviewer4
RegKey1=HKCU\Software\RealVNC\VNCviewer4\MRU
[*Valve - Steam (Logs)]
LangSecRef=3023
Detect=HKCU\Software\Valve\Steam
Default=False
FileKey1=%ProgramFiles%\Valve\Steam\SteamLogs|*.log
FileKey2=%ProgramFiles%\Valve\Steam|Steam.log
[*Venis IX]
LangSecRef=3021
Detect=HKCU\Software\Spaceblue\Venis IX
Default=False
RegKey1=HKCU\Software\Spaceblue\Venis IX\FileHistory
[*Ventrilo Client]
LangSecRef=3021
Detect=HKCU\Software\Ventrilo
Default=False
FileKey1=%userprofile%\Application Data\Ventrilo|ventrilo.log
FileKey2=%userprofile%\Application Data\Ventrilo\temp|*.*
FileKey3=%userprofile%\Application Data\Ventrilo\recordings|*.*
[*Ventrilo Server]
LangSecRef=3022
DetectFile=%ProgramFiles%\VentSrv\ventrilo_srv.exe
Default=False
FileKey1=%ProgramFiles%\VentSrv|ventrilo_srv.log
[*VideoGet]
LangSecRef=3022
DetectFile=%ProgramFiles%\VideoGet\VideoGet.exe
Default=False
FileKey1=%ProgramFiles%\VideoGet\Temp|*.*
[*VirtualCloneDrive]
LangSecRef=3021
Detect=HKLM\Software\Elaborate Bytes\VirtualCloneDrive
Default=False
RegKey1=HKLM\Software\Elaborate Bytes\VirtualCloneDrive\0
RegKey2=HKCU\Software\Elaborate Bytes\VirtualCloneDrive\LRU
[*VirtualDub]
LangSecRef=3023
Default=False
Detect=HKCU\Software\Freeware\VirtualDub
RegKey1=HKCU\Software\Freeware\VirtualDub\MRU List
[*VirtualFDD]
LangSecRef=3024
Detect=HKCU\Software\Korbos\VirtualFDD
Default=False
RegKey1=HKCU\Software\Korbos\VirtualFDD\Recent File List
[*Vuze]
LangSecRef=3022
Detect=HKCU\Software\Azureus
Default=False
FileKey1=%appdata%\Azureus\logs|*.log
FileKey2=%appdata%\Azureus\logs\save|*.log
FileKey3=%userprofile%\Application Data\Azureus\tmp|*.*
FileKey4=%userprofile%\Application Data\Azureus|*.bak
FileKey5=%userprofile%\Application Data\Azureus|*.log
FileKey6=%userprofile%\Application Data\Azureus\active|*.bak
[*WM Recorder 10]
LangSecRef=3023
DetectFile=%ProgramFiles%\WM Recorder 10\WMR.exe
Default=False
FileKey1=%ProgramFiles%\WM Recorder 10|log.txt
FileKey2=%ProgramFiles%\WM Recorder 10|urls.txt
[*WMP (TFC)]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MediaPlayer\Player
Default=False
FileKey1=%UserProfile%\Local Settings\Application Data\Microsoft\Media Player\Transcoded Files Cache|*.*
[*WS FTP (Pro)]
LangSecRef=3022
Detect=HKCU\Software\Ipswitch\WS_FTP
Default=False
FileKey1=%userprofile%\Application Data\Ipswitch\WS_FTP\Logs|*.*
[*Wavosaur (Logs)]
LangSecRef=3023
DetectFile=%ProgramFiles%\Wavosaur\wavosaur.exe
Default=False
FileKey1=%ProgramFiles%\Wavosaur|wavosaur.log
[*Webroot SpySweeper]
LangSecRef=3024
Detect=HKCU\Software\Webroot\SpySweeper
FileKey1=%ProgramFiles%\Webroot\Spy Sweeper\Temp|*.*
FileKey2=%appdata%\Webroot\Spy Sweeper\Logs|*Log.txt
[*WinAVI Video Converter (Log)]
LangSecRef=3023
Detect=HKCU\Software\ZjSoft\WinAVI
Default=False
FileKey1=%LocalAppData%\WinAVI|debug.log
[*WinAce 2.0]
LangSecRef=3024
Detect=HKCU\Software\e-merge\WinAce\2.0
Default=False
RegKey1=HKCU\Software\e-merge\WinAce\2.0\Favorites
RegKey2=HKCU\Software\e-merge\WinAce\2.0\MRU Items
[*WinCHM]
LangSecRef=3021
Detect=HKCU\Software\Softany\WinCHM
Default=False
RegKey1=HKCU\Software\Softany\WinCHM|RecentFile1
RegKey2=HKCU\Software\Softany\WinCHM|RecentFile2
RegKey3=HKCU\Software\Softany\WinCHM|RecentFile3
RegKey4=HKCU\Software\Softany\WinCHM|RecentFile4
RegKey5=HKCU\Software\Softany\WinCHM|RecentFile5
RegKey6=HKCU\Software\Softany\WinCHM|RecentFile6
[*WinDiff]
LangSecRef=3024
Detect=HKCU\Software\Microsoft\Windiff
Default=False
RegKey1=HKCU\Software\Microsoft\Windiff|NameLeft
RegKey2=HKCU\Software\Microsoft\Windiff|NameRight
[*WinISO]
LangSecRef=3024
Detect=HKLM\Software\WinISO
Default=False
RegKey1=HKLM\Software\WinISO\Reopen
[*WinImage]
LangSecRef=3024
Detect=HKCU\Software\WinImage
Default=False
RegKey1=HKCU\Software\WinImage|File1
RegKey2=HKCU\Software\WinImage|File2
RegKey3=HKCU\Software\WinImage|File3
RegKey4=HKCU\Software\WinImage|File4
RegKey5=HKCU\Software\WinImage|File5
RegKey6=HKCU\Software\WinImage|File6
RegKey7=HKCU\Software\WinImage|File7
RegKey8=HKCU\Software\WinImage|File8
RegKey9=HKCU\Software\WinImage|File9
RegKey10=HKCU\Software\WinImage|PathExtract
[*WinMerge]
LangSecRef=3024
Detect=HKCU\Software\Thingamahoochie\WinMerge\Files
Default=False
RegKey1=HKCU\Software\Thingamahoochie\WinMerge\Files\Ext
RegKey2=HKCU\Software\Thingamahoochie\WinMerge\Files\Left
RegKey3=HKCU\Software\Thingamahoochie\WinMerge\Files\Right
[*WinPatrol]
LangSecRef=3024
Detect=HKCU\Software\BillP Studios\WinPatrol
Default=False
FileKey1=%ProgramFiles%\BillP Studios\WinPatrol|history.txt
[*WinRAR Comment]
LangSecRef=3024
Detect=HKCU\Software\WinRAR
Default=False
RegKey1=HKCU\Software\WinRAR\General\Info|CommentFile
[*WinRAR SFX]
LangSecRef=3024
Detect=HKCU\Software\WinRAR SFX
Default=False
RegKey1=HKCU\Software\WinRAR SFX
[*WinRAR]
LangSecRef=3024
Detect=HKCU\Software\WinRAR
Default=False
RegKey1=HKCU\Software\WinRAR\ArcHistory
RegKey2=HKCU\Software\WinRAR\General|LastFolder
RegKey3=HKCU\Software\WinRAR\DialogEditHistory\Arcname
RegKey4=HKCU\Software\WinRAR\DialogEditHistory\ExtrPath
[*WinWAP]
LangSecRef=3022
Detect=HKCU\Software\Winwap Technologies
Default=False
FileKey1=%userprofile%\WinWAP Temporary Files|*.*
[*WinZip]
LangSecRef=3024
Detect=HKCU\Software\Nico Mak Computing\WinZip
Default=False
RegKey1=HKCU\Software\Nico Mak Computing\WinZip\filemenu
RegKey2=HKCU\Software\Nico Mak Computing\WinZip\extract
RegKey3=HKCU\Software\Nico Mak Computing\WinZip\directories|DefDir
RegKey4=HKCU\Software\Nico Mak Computing\WinZip\directories|ExtractTo
RegKey5=HKCU\Software\Nico Mak Computing\WinZip\directories|gzAddDir
RegKey6=HKCU\Software\Nico Mak Computing\WinZip\directories|zDefDir
RegKey7=HKCU\Software\Nico Mak Computing\WinZip\directories|AddDir
RegKey8=HKCU\Software\Nico Mak Computing\WinZip\directories|gzExtractTo
RegKey9=HKCU\Software\Nico Mak Computing\WinZip\rrs\Opened
[*Winamp]
LangSecRef=3023
Detect=HKCU\Software\Winamp
Default=False
FileKey1=%ProgramFiles%\Winamp|winamp.m3u
FileKey2=%ProgramFiles%\Winamp|winamp.m3u8
FileKey3=%ProgramFiles%\Winamp\Plugins\ml|recent.dat
FileKey4=%ProgramFiles%\Winamp\Plugins\ml\cache|*.*|RECURSE
FileKey5=%userprofile%\Application Data\Winamp|winamp.m3u
FileKey6=%userprofile%\Application Data\Winamp|winamp.m3u8
FileKey7=%userprofile%\Application Data\Winamp\Plugins\ml|recent.dat
FileKey8=%userprofile%\Application Data\Winamp\Plugins\ml\Cache|*.*|RECURSE
[*Window Size/Location Cache]
LangSecRef=3004
LangRef=3127
WarningRef=3205
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams
[*Windows Defender]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Microsoft\Windows Defender
Default=False
FileKey1=%commonappdata%\Microsoft\Windows Defender\Scans\History\Results\Quick|*.*
FileKey2=%commonappdata%\Microsoft\Windows Defender\Scans\History\Results\Resource|*.*
[*Windows Error Reporting]
LangSecRef=3003
LangRef=3149
Default=False
DetectOS=6.0
FileKey1=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportArchive|*.*|RECURSE
FileKey2=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportQueue|*.*|RECURSE
FileKey3=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportArchive|*.*|RECURSE
FileKey4=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportQueue|*.*|RECURSE
[*Windows Live Mail]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Windows Live Mail
Default=False
RegKey1=HKEY_CURRENT_USER\Software\Microsoft\Windows Live Mail|SearchFolderVersion
[*Windows Live Messenger]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\MSNMessenger\PerPassportSettings
Default=False
RegKey1=HKCU\Software\Microsoft\MessengerService\ListCache\.NET Messenger Service
FileKey1=%appdata%\Microsoft\MSN Messenger|*.sqm|RECURSE
[*Windows Live Messenger]
LangSecRef=3022
DetectFile=%ProgramFiles%\Windows Live\Messenger\msnmsgr.exe
Default=False
FileKey1=%USERPROFILE%\Application Data\Microsoft\MSN Messenger|*.*|RECURSE
[*Windows Live Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\MSN Apps\SearchBox
Default=False
RegKey1=HKCU\Software\Microsoft\MSN Apps\SearchBox|History
RegKey2=HKCU\Software\Microsoft\MSN Apps\MSN Toolbar|SearchStrings
[*Windows Log Files]
LangSecRef=3003
LangRef=3145
Default=False
FileKey1=%windir%\system32\wbem\Logs|*.log
FileKey2=%windir%\system32\wbem\Logs|*.lo_
FileKey3=%windir%|*.log
FileKey4=%windir%|*.bak
FileKey5=%windir%|*log.txt
FileKey6=%commonappdata%\Microsoft\Dr Watson|*.log
FileKey7=%commonappdata%\Microsoft\Dr Watson|*.dmp
FileKey8=%windir%\Debug|*.log
FileKey9=%windir%\Debug\UserMode|*.log
FileKey10=%windir%\Debug\UserMode|*.bak
FileKey11=%windir%|SchedLgU.txt
FileKey12=%windir%\security\logs|*.log
FileKey13=%windir%\security\logs|*.old
[*Windows ME]
LangSecRef=3025
DetectFile=%windir%\WINFILE.EXE
Default=False
FileKey1=%rootdir%|SCANDISK.LOG
FileKey2=%windir%|*.tmp
FileKey3=%windir%\Application Data|dw.log
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|*.*
FileKey5=%windir%\APPLOG|*.LGC
FileKey6=%windir%\Windows Update Setup Files|*.*
[*Windows Media Player]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MediaPlayer\Player
Default=False
RegKey1=HKCU\Software\Microsoft\MediaPlayer\Player\RecentFileList
RegKey2=HKCU\Software\Microsoft\MediaPlayer\Player\RecentURLList
RegKey3=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayList
RegKey4=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayListIndex
RegKey5=HKCU\Software\Microsoft\MediaPlayer\Player\Settings|SaveAsDir
RegKey6=HKCU\Software\Microsoft\MediaPlayer\AutoComplete\MediaEdit
RegKey7=HKCU\Software\Microsoft\MediaPlayer\Radio\MRUList
[*Windows Movie Maker]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MovieMaker
Default=False
FileKey1=%localappdata%\Microsoft\Movie Maker|MEDIATAB0.DAT
[*Windows Update Logs]
LangSecRef=3025
DetectFile=%windir%\SoftwareDistribution\DataStore\Logs
Default=False
FileKey1=%windir%\SoftwareDistribution\DataStore\Logs|*.*
[*Wipe Free Space]
LangSecRef=3004
LangRef=3132
WarningRef=3207
Default=False
DetectOS=5.0
SpecialKey1=N_EX_WIPEFREESPACE
[*Wordweb]
LangSecRef=3021
DetectFile=%ProgramFiles%\WordWeb\wweb32.exe
Default=False
FileKey1=%userprofile%\Application Data\WordWeb|History.txt
[*X-Cleaner (free)]
LangSecRef=3024
DetectFile=%ProgramFiles%\X-Cleaner\XCleaner_free.exe
Default=False
FileKey1=%ProgramFiles%\X-Cleaner|XCL_LOG.txt
[*X-Cleaner (full)]
LangSecRef=3024
DetectFile=%ProgramFiles%\X-Cleaner\XCleaner_full.exe
Default=False
FileKey1=%ProgramFiles%\X-Cleaner|XCL_LOG.txt
[*XFire (Logs)]
LangSecRef=3022
Detect=HKLM\Software\Xfire
Default=False
FileKey1=%userprofile%\Application Data\Xfire\chatlog|*.*|RECURSE
[*XML Spy]
LangSecRef=3021
Detect=HKCU\Software\Altova\XML Spy
Default=False
RegKey1=HKCU\Software\Altova\XML Spy\Recent File List
RegKey2=HKCU\Software\Altova\XML Spy\Recent Project List
[*XN Resource Editor]
LangSecRef=3024
Detect=HKCU\Software\Woozle\XN Resource Editor
Default=False
RegKey1=HKCU\Software\Woozle\XN Resource Editor\Recent Files
[*XviD Stats]
LangSecRef=3023
Detect=HKCU\Software\GNU\Xvid
Default=False
RegKey1=HKCU\Software\GNU\Xvid|stats
[*YPOPs]
LangSecRef=3021
DetectFile=%ProgramFiles%\YPOPs\ypops.exe
Default=False
FileKey1=%ProgramFiles%\YPOPs|ypops.log
[*Yahoo Messenger (Logs/Cache)]
LangSecRef=3022
Detect=%ProgramFiles%\Yahoo!\Messenger|ypager.log
Default=False
FileKey1=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey2=%ProgramFiles%\Yahoo!\Messenger\Profiles|*.*|RECURSE
FileKey3=%ProgramFiles%\Yahoo!\Messenger\Cache|*.*|RECURSE
FileKey4=%ProgramFiles%\Yahoo!\Messenger\IMVCache|*.*|RECURSE
[*Yahoo Messenger (Logs/Cache)]
LangSecRef=3022
Detect=HKCU\Software\Yahoo\pager
Default=False
FileKey1=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey2=%ProgramFiles%\Yahoo!\Messenger\Profiles|*.*|RECURSE
FileKey3=%ProgramFiles%\Yahoo!\Messenger\Cache|*.*|RECURSE
FileKey4=%ProgramFiles%\Yahoo!\Messenger\IMVCache|*.*|RECURSE
[*Yahoo! Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Yahoo\Companion
Default=False
RegKey1=HKCU\Software\Yahoo\Companion\SearchHistory
[*ZX32 ZX Spectrum Emulator v1.03]
LangSecRef=3021
Detect=HKCU\Software\VK\zx32\1.03
Default=False
RegKey1=HKCU\Software\VK\zx32\1.03\FileMRU
[*ZipGenius]
LangSecRef=3024
Detect=HKCU\Software\M.Dev Software\ZG5
Default=False
RegKey1=HKCU\Software\M.Dev Software\ZG5\MRU Items
FileKey1=%appdata%\ZipGenius|mru.dat
[*ZipMagic]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Mijenix\ZipMagic
RegKey1=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Recent
RegKey2=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Archive Manager\UnZip To
RegKey3=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\UnZip To
RegKey4=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Zip To
[*ZoneAlarm (Logs)]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Zone Labs\ZoneAlarm
Default=False
FileKey1=%windir%\Internet Logs|ZALog*.*
[*eBay Toolbar]
LangSecRef=3022
DetectFile=%ProgramFiles%\eBay\eBay Toolbar2\eBayTBDaemon.exe
Default=False
RegKey1=HKCU\Software\eBay\eBayToolbar\History
RegKey2=HKCU\Software\eBay\eBayToolbar\RecentSearches
FileKey1=%ProgramFiles%\eBay\eBay Toolbar2|toolbar.log
FileKey2=%ProgramFiles%\eBay\eBay Toolbar2|eBayDaemon.log
[*eMule (File Hashes)]
LangSecRef=3022
Detect=HKCU\Software\eMule
Default=False
FileKey1=%ProgramFiles%\eMule\config|known.met
FileKey2=%ProgramFiles%\eMule\config|known2.met
[*eMule (Search History)]
LangSecRef=3022
Detect=HKCU\Software\eMule
Default=False
FileKey1=%ProgramFiles%\eMule\config|AC_SearchStrings.dat
[*iSysCleaner]
LangSecRef=3024
DetectFile=%ProgramFiles%\Utils\iSysCleaner\iSysCleaner.exe
Default=False
FileKey1=%ProgramFiles%\Utils\iSysCleaner\traces|*.*
[*mIRC]
LangSecRef=3022
Detect=HKCU\Software\mIRC\
Default=False
DectectFile=%ProgramFiles%\mirc\mIRC.exe
Filekey1=%ProgramFiles%\mirc\logs\|*.*
[*neXBC]
LangSecRef=3022
DetectFile=%ProgramFiles%\neXBC\neXBC.exe
Default=False
FileKey1=%ProgramFiles%\neXBC|messages.txt
FileKey2=%ProgramFiles%\neXBC\Logs\Hosted|*.*
FileKey3=%ProgramFiles%\neXBC\Logs\Joined|*.*
[*uTorrent]
LangSecRef=3022
DetectFile=%ProgramFiles%\uTorrent\uTorrent.exe
Default=False
FileKey1=%ProgramFiles%\uTorrent|*.dmp












