SMalik Posted October 11, 2018 Share Posted October 11, 2018 @Winapp2.ini I think we should add this HKEY_CURRENT_USER\Software\Classes\VirtualStore https://docs.microsoft.com/en-us/windows/desktop/sysinfo/registry-virtualization Link to comment Share on other sites More sharing options...
siliconman01 Posted October 12, 2018 Share Posted October 12, 2018 My virtual store has what looks like settings for some programs such as Belarc, AtomTime, and others. Windows 10 x64 Pro on ASUS Maximus VIII Extreme motherboard, i7-6700k CPU,H220 X2 Liquid Cooler, 64 gbyte RipJaws DDR4 3200 RAM, Samsung 970 Pro NVMe M.2 500 gbyte SSD + Samsung 850 Pro 512 gbyte SSD, EVGA RTX 3060 Titan graphics card (Home Built System); Windows 11x64 Pro on 512 gigabyte Dell XPS 15 2-in-1 Laptop/tablet and Dell XPS 8940 PC. ASUS RT-AC88U router, 14 tbyte WD My Cloud PR2100 NAS Server, 200 Mbps cable Internet, MS Edge Chromium, MS Office 2021 (Local), Casper 11, DisplayFusion (3 Flat Panel Displays per system): Latest Bitdefender Internet Security, Quicken, Weather Watcher Live, ThumbsPlus 10, Sticky Password 8, WD Smartware, CyberLink PowerDVD23, MSI AfterBurner, Rainmeter, 8GadgetPack, and many more. Link to comment Share on other sites More sharing options...
Winapp2.ini Posted October 12, 2018 Author Share Posted October 12, 2018 I think items associated with VirtualStore locations are related to how Windows handles sandboxing / security when the UAC is enabled. winapp2.ini additions thread winapp2.ini github Link to comment Share on other sites More sharing options...
SMalik Posted October 12, 2018 Share Posted October 12, 2018 Revised Entry Added FileKey12 [Apple iTunes *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AppleInc.iTunes_nzyj5cx40ttqa DetectFile=%LocalAppData%\Packages\AppleInc.iTunes_nzyj5cx40ttqa Default=False FileKey1=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Local\Apple Computer\iTunes|Cache.db;*.xml FileKey5=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Local\Microsoft\Windows\Caches|*.*|RECURSE FileKey6=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey7=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\iTunes\Cookies|Cookies.binarycookies FileKey8=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\iTunes\Device Support|*.*|RECURSE FileKey9=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\Logs|*.*|RECURSE FileKey10=%LocalAppData%\Packages\AppleInc.iTunes_*\SystemAppData\Helium\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\AppleInc.iTunes_*\TempState|*.*|RECURSE FileKey12=%WinDir%\System32\config\systemprofile\AppData\Roaming\Apple Computer\Logs|*.*|RECURSE Link to comment Share on other sites More sharing options...
SMalik Posted October 12, 2018 Share Posted October 12, 2018 Revised Entry Added FileKey11 & FileKey12 [Plex Media Server *] LangSecRef=3023 Detect=HKCU\Software\Plex, Inc.\Plex Media Server Default=False FileKey1=%LocalAppData%\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE FileKey2=%LocalAppData%\Plex Media Server\Crash Reports|*.*|RECURSE FileKey3=%LocalAppData%\Plex Media Server\Logs|*.*|RECURSE FileKey4=%LocalAppData%\Plex Media Server\Updates|*.*|RECURSE FileKey5=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE FileKey6=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Crash Reports|*.*|RECURSE FileKey7=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Logs|*.*|RECURSE FileKey8=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Updates|*.*|RECURSE FileKey9=%LocalAppData%\VirtualStore\Program Files*\Plex\Plex Media Server|*.txt;*.log|RECURSE FileKey10=%ProgramFiles%\Plex\Plex Media Server|*.txt;*.log|RECURSE FileKey11=%WinDir%\System32\config\systemprofile\AppData\Local\Plex Media Server\Logs|*.*|RECURSE FileKey12=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Plex Media Server\Logs|*.*|RECURSE Link to comment Share on other sites More sharing options...
SMalik Posted October 13, 2018 Share Posted October 13, 2018 Revised Entry Added FileKey4 & FileKey16 [Adobe CC *] LangSecRef=3023 Detect=HKCU\Software\Adobe\CreativeCloud Default=False FileKey1=%AppData%\Adobe\Adobe Media Encoder\*\logs|*.*|RECURSE FileKey2=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings\CrashLogs|*.*|RECURSE FileKey3=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings\web-cache-temp|*.*|RECURSE FileKey4=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings|PSErrorLog.txt;sniffer-*.txt FileKey5=%AppData%\Adobe\Adobe Photoshop CC *\Logs|*.*|RECURSE FileKey6=%AppData%\Adobe\CRLogs|*.*|RECURSE FileKey7=%AppData%\Adobe\dynamiclinkmanager\*\logs|*.*|RECURSE FileKey8=%AppData%\Adobe\Extension Manager CC\Log|*.*|RECURSE FileKey9=%AppData%\Adobe\Extension Manager CC\Temp|*.*|RECURSE FileKey10=%AppData%\Adobe\LogTransport2CC\Logs|*.*|RECURSE FileKey11=%AppData%\Adobe\Lumetri\*\logs|*.*|RECURSE FileKey12=%AppData%\Adobe\Premiere Pro\*|Plugin Loading.log FileKey13=%AppData%\Adobe\Premiere Pro\*\logs|*.*|RECURSE FileKey14=%CommonProgramFiles%\Adobe\Installers|CoreSyncInstall.log;Install.log FileKey15=%Documents%\Adobe|*.log FileKey16=%Documents%\Adobe\Adobe Media Encoder\*|AMEEncodingErrorLog.txt;AMEEncodingLog.txt; FileKey17=%Documents%\Adobe\Adobe Media Encoder\*\logs|*.*|RECURSE FileKey18=%Documents%\Adobe\Premiere Pro\*|Plugin Loading.log RegKey1=KCU\Software\Adobe\MediaBrowser\MRU Link to comment Share on other sites More sharing options...
SMalik Posted October 13, 2018 Share Posted October 13, 2018 10 hours ago, Winapp2.ini said: I think items associated with VirtualStore locations are related to how Windows handles sandboxing / security when the UAC is enabled. https://docs.microsoft.com/en-us/windows/desktop/sysinfo/registry-virtualization Link to comment Share on other sites More sharing options...
APMichael Posted October 13, 2018 Share Posted October 13, 2018 On 11.10.2018 at 23:42, SMalik said: I think we should add this HKEY_CURRENT_USER\Software\Classes\VirtualStore If you remove the key "VirtualStore" you will remove settings of old legacy applications (coded for Windows XP and older) or wrong coded applications. You can see it on siliconman01s screenshot. And the Microsoft documentation explains it also: Quote Virtualization Overview Prior to Windows Vista, applications were typically run by administrators. As a result, applications could freely access system files and registry keys. If these applications were run by a standard user, they would fail due to insufficient access rights. Windows Vista and later versions of Windows improve application compatibility for these applications by automatically redirecting these operations. For example, registry operations to the global store (HKEY_LOCAL_MACHINE\Software) are redirected to a per-user location within the user's profile known as the virtual store (HKEY_USERS\_Classes\VirtualStore\Machine\Software). Here you can find a more detailed explanation: https://technet.microsoft.com/en-us/library/2007.06.uac.aspx (Piriform could improve CCleaner, so that it checks the HKLM RegKeys also under HKCU\Software\Classes\VirtualStore\MACHINE. Unfortunately, they never react on those feature requests.) Link to comment Share on other sites More sharing options...
APMichael Posted October 13, 2018 Share Posted October 13, 2018 Thanks for the revised entries. Winapp2.ini update:https://github.com/MoscaDotTo/Winapp2/commit/d67fd8de127430428ec028c98ec916731315f3bc Link to comment Share on other sites More sharing options...
SMalik Posted October 14, 2018 Share Posted October 14, 2018 New Entry I have made this entry from a Windows 8.1 system, not just making it up. I think Store entries for Windows 8 and Windows 10 should be separate. [Windows Store *] DetectOS=6.2|6.3 LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\winstore_cw5n1h2txyewy DetectFile=%LocalAppData%\Packages\winstore_cw5n1h2txyewy Default=False FileKey1=%LocalAppData%\Packages\winstore_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\winstore_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\winstore_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\winstore_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\winstore_*\LocalCache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\winstore_*\LocalState\Cache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\winstore_*\LocalState\LiveTile|*.*|RECURSE ExcludeKey1=FILE|%LocalAppData%\Packages\winstore_*\AC\INetCache\|container.dat Link to comment Share on other sites More sharing options...
SMalik Posted October 14, 2018 Share Posted October 14, 2018 Revised Entry Added FileKey10, FileKey11 & FileKey12 Removed FileKey9 [Groove Music *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\PRICache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalCache\PlayReady\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\Database\*|*.log FileKey10=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageCache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageRetrievalFailure|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageStore|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\navigationHistory|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\PlayReady|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\SearchHistory ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCache\|container.dat Link to comment Share on other sites More sharing options...
SMalik Posted October 14, 2018 Share Posted October 14, 2018 Revised Entry Added FileKey10, FileKey11 & FileKey12 Removed FileKey9 [Movies & TV *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe* Default=False FileKey1=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\PRICache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalCache\PlayReady\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Database\anonymous|*.log FileKey10=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageCache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageRetrievalFailure|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageStore|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\navigationHistory|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\PlayReady|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe\SearchHistory\SearchHistory ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCache\|container.dat Link to comment Share on other sites More sharing options...
SMalik Posted October 14, 2018 Share Posted October 14, 2018 New Entries [OneConnect *] DetectOS=10.0 LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.OneConnect_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalCache\Cache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalState\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalState\DiagOutputDir|*.txt FileKey7=%LocalAppData%\Packages\Microsoft.OneConnect_*\TempState|*.*|RECURSE [XboxGameOverlay *] DetectOS=10.0 LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxGameOverlay_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalCache\Cache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalState\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalState\DiagOutputDir|*.txt FileKey7=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\TempState|*.*|RECURSE Link to comment Share on other sites More sharing options...
SMalik Posted October 14, 2018 Share Posted October 14, 2018 Revised Entry Added FileKey5 [Feedback Hub *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalCache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalState\DiagOutputDir|*.txt FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\TempState|*.*|RECURSE ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INetCache\|container.dat Link to comment Share on other sites More sharing options...
SMalik Posted October 14, 2018 Share Posted October 14, 2018 Revised Entry Added FileKey7 [Xbox *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxApp_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalCache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\*Cache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\DiagOutputDir|*.txt FileKey8=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log FileKey9=%LocalAppData%\Packages\Microsoft.XboxApp_*\TempState|*.*|RECURSE ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCache\|container.dat Link to comment Share on other sites More sharing options...
SMalik Posted October 14, 2018 Share Posted October 14, 2018 On 10/12/2018 at 09:00, Winapp2.ini said: I think items associated with VirtualStore locations are related to how Windows handles sandboxing / security when the UAC is enabled. I have been watching that path in the registry. Portable apps leave traces there, but no settings. In the screenshot above, I used a portable app, Windows ISO Downloader, and I deleted it from the drive. I tried some other portable apps and they also left traces at the same path, even though the program was removed from the drive. The link posted above with the screenshot has good information about these traces. Link to comment Share on other sites More sharing options...
APMichael Posted October 15, 2018 Share Posted October 15, 2018 Winapp2.ini updates:https://github.com/MoscaDotTo/Winapp2/commit/3e63e7e7b52912519422df4bbc113343e85af0fehttps://github.com/MoscaDotTo/Winapp2/commit/777627bd0551a0ae30bf63c253dd15b042b59b11 Link to comment Share on other sites More sharing options...
tankist_ua Posted October 17, 2018 Share Posted October 17, 2018 New app - Sonata (Accounting software) [Sonata *] LangSecRef=3024 DetectFile=%ProgramFiles%\Sonata Default=False Warning=This will remove all backups FileKey1=%ProgramFiles%\Sonata\update|*.*|RECURSE FileKey2=%LocalAppData%\sonata\temp|*.*|RECURSE FileKey3=D:\Sonata\backups|*.*|RECURSE Link to comment Share on other sites More sharing options...
APMichael Posted October 17, 2018 Share Posted October 17, 2018 1 hour ago, tankist_ua said: New app - Sonata (Accounting software) Thanks for the new entry. The location of the backups (FileKey3) seems to be user-defined (not everybody has a second partition D). Therefore, we can add FileKey1 and 2 only. Link to comment Share on other sites More sharing options...
APMichael Posted October 18, 2018 Share Posted October 18, 2018 Winapp2.ini update:https://github.com/MoscaDotTo/Winapp2/commit/306ba37546b11e5e426734a42bcb4773c04e4881 Winapp3.ini update:https://github.com/MoscaDotTo/Winapp2/commit/295f285dbccb3872bcde9e7d32658446bec9a1e6 Link to comment Share on other sites More sharing options...
SMalik Posted October 19, 2018 Share Posted October 19, 2018 Revised Entry Added FileKey12 [MS Office *] LangSecRef=3021 Detect1=HKCU\Software\Microsoft\Office\12.0\Common Detect2=HKCU\Software\Microsoft\Office\14.0\Common Detect3=HKCU\Software\Microsoft\Office\15.0\Common Detect4=HKCU\Software\Microsoft\Office\16.0\Common Default=False FileKey1=%AppData%\Microsoft\Document Building Blocks|*.*|RECURSE FileKey2=%AppData%\Microsoft\Office|*.tmp|RECURSE FileKey3=%AppData%\Microsoft\OIS|Toolbars.dat FileKey4=%AppData%\Microsoft\UProof|*.bin;*.XML FileKey5=%CommonAppData%\Microsoft\ClickToRun\ProductReleases|*.*|RECURSE FileKey6=%Documents%|~*.ppt;~*.pptx;~*.doc;~*.docx|RECURSE FileKey7=%LocalAppData%\Microsoft Help|*.* FileKey8=%LocalAppData%\Microsoft\Office\*|OneNoteOfflineCache.onecache FileKey9=%LocalAppData%\Microsoft\Office\*\OfficeFileCache|*.*|RECURSE FileKey10=%LocalAppData%\Microsoft\OneNote\*|OneNoteOfflineCache.onecache FileKey11=%LocalAppData%\Microsoft\OneNote\*\OneNoteOfflineCache_Files|*.*|RECURSE FileKey12=%LocalAppData%\Microsoft\OneNote\*\cache|*.*|RECURSE FileKey13=%SystemDrive%|propfix.log RegKey1=HKCU\Software\Microsoft\Office\11.0\MSE|LastLoadedSolution RegKey2=HKCU\Software\Microsoft\Office\11.0\MSE\FileMRUList RegKey3=HKCU\Software\Microsoft\Office\11.0\MSE\ProjectMRUList RegKey4=HKCU\Software\Microsoft\Office\11.0\MSE\SolutionMRUList RegKey5=HKCU\Software\Microsoft\Office\12.0\Common\Internet|UseRWHlinkNavigation RegKey6=HKCU\Software\Microsoft\Office\12.0\Word\Reading Locations RegKey7=HKCU\Software\Microsoft\Office\14.0\Common\Internet|UseRWHlinkNavigation RegKey8=HKCU\Software\Microsoft\Office\14.0\Word\Reading Locations RegKey9=HKCU\Software\Microsoft\Office\15.0\Common\Internet|UseRWHlinkNavigation RegKey10=HKCU\Software\Microsoft\Office\15.0\Word\Reading Locations RegKey11=HKCU\Software\Microsoft\Office\16.0\Common\Internet|UseRWHlinkNavigation RegKey12=HKCU\Software\Microsoft\Office\16.0\Word\Reading Locations RegKey13=HKCU\Software\Microsoft\Office\Common|FontBmpCache RegKey14=HKCU\Software\Microsoft\OfficeCustomizeWizard\12.0\RecentFileList RegKey15=HKCU\Software\Microsoft\OfficeCustomizeWizard\14.0\RecentFileList RegKey16=HKCU\Software\Microsoft\OfficeCustomizeWizard\15.0\RecentFileList RegKey17=HKCU\Software\Microsoft\OfficeCustomizeWizard\16.0\RecentFileList Link to comment Share on other sites More sharing options...
SMalik Posted October 20, 2018 Share Posted October 20, 2018 Revised Entry Added FileKey5 [Adobe Acrobat DC *] LangSecRef=3021 Detect=HKLM\Software\Adobe\Adobe Acrobat\DC Default=False FileKey1=%LocalAppData%\Adobe\Acrobat\DC|*.lst;UserCache.bin FileKey2=%LocalAppData%\Adobe\Acrobat\DC\Cache|*.lst FileKey3=%LocalAppData%\Adobe\Acrobat\DC\ToolsSearchCacheAcro|*.*|RECURSE FileKey4=%LocalLowAppData%\Adobe\Acrobat\DC\Search|*.*|RECURSE FileKey5=%LocalLowAppData%\Adobe\AcroCef\DC\Acrobat\Cache|*.*|RECURSE RegKey1=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionFromPDF\cSettings RegKey2=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionToPDF\cSettings RegKey3=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cDockables RegKey4=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles RegKey5=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFolders RegKey6=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentToolsList RegKey7=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars RegKey8=HKCU\Software\Adobe\Adobe Acrobat\DC\RememberedViews\cNoCategoryFiles RegKey9=HKCU\Software\Adobe\Adobe Acrobat\DC\ShareIdentity RegKey10=HKCU\Software\Adobe\Adobe Synchronizer\DC Link to comment Share on other sites More sharing options...
SMalik Posted October 20, 2018 Share Posted October 20, 2018 Revised Entry Added FileKey1 [Windows Communications Apps *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Comms\Unistore\data|AggregateCache.uca FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\AppCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INet*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\PRICache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*|RECURSE FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\LiveComm\*\*\DBStore\LogFiles|edbtmp.log FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory ExcludeKey1=FILE|%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCache\|container.dat Link to comment Share on other sites More sharing options...
APMichael Posted October 21, 2018 Share Posted October 21, 2018 Winapp2.ini update:https://github.com/MoscaDotTo/Winapp2/commit/5ed5a4ef1661016048b105b0a63373d21a9a2140 Link to comment Share on other sites More sharing options...
SMalik Posted October 21, 2018 Share Posted October 21, 2018 New Entry http://forums.mozillazine.org/viewtopic.php?f=23&t=2919581 [HSTS supercookies*] LangSecRef=3026 SpecialDetect=DET_MOZILLA Default=False FileKey1=%AppData%\Mozilla\Firefox\Profiles\*|SiteSecurityServiceState.txt Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now