Jump to content

Winapp2.ini additions


Winapp2.ini

Recommended Posts

My virtual store has what looks like settings for some programs such as Belarc, AtomTime, and others.

 

VirtualStore.png

Windows 10 x64 Pro on ASUS Maximus VIII Extreme motherboard, i7-6700k CPU,H220 X2 Liquid Cooler, 64 gbyte RipJaws DDR4 3200 RAM, Samsung 970 Pro NVMe M.2 500 gbyte SSD + Samsung 850 Pro 512 gbyte SSD, EVGA RTX 3060 Titan graphics card (Home Built System);  Windows 11x64 Pro on 512 gigabyte Dell XPS 15 2-in-1 Laptop/tablet and Dell XPS 8940 PC.  ASUS RT-AC88U router, 14 tbyte WD My Cloud PR2100 NAS Server, 200 Mbps cable Internet, MS Edge Chromium, MS Office 2021 (Local), Casper 11, DisplayFusion (3 Flat Panel Displays per system):   Latest Bitdefender Internet Security, Quicken, Weather Watcher Live, ThumbsPlus 10, Sticky Password 8, WD Smartware, CyberLink PowerDVD23, MSI AfterBurner, Rainmeter, 8GadgetPack, and many more.

Link to comment
Share on other sites

Revised Entry

Added FileKey12

[Apple iTunes *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AppleInc.iTunes_nzyj5cx40ttqa
DetectFile=%LocalAppData%\Packages\AppleInc.iTunes_nzyj5cx40ttqa
Default=False
FileKey1=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Local\Apple Computer\iTunes|Cache.db;*.xml
FileKey5=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Local\Microsoft\Windows\Caches|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\iTunes\Cookies|Cookies.binarycookies
FileKey8=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\iTunes\Device Support|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\Logs|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\AppleInc.iTunes_*\SystemAppData\Helium\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\AppleInc.iTunes_*\TempState|*.*|RECURSE
FileKey12=%WinDir%\System32\config\systemprofile\AppData\Roaming\Apple Computer\Logs|*.*|RECURSE

Link to comment
Share on other sites

Revised Entry

Added FileKey11 & FileKey12

[Plex Media Server *]
LangSecRef=3023
Detect=HKCU\Software\Plex, Inc.\Plex Media Server
Default=False
FileKey1=%LocalAppData%\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey2=%LocalAppData%\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey3=%LocalAppData%\Plex Media Server\Logs|*.*|RECURSE
FileKey4=%LocalAppData%\Plex Media Server\Updates|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Logs|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Updates|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey10=%ProgramFiles%\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey11=%WinDir%\System32\config\systemprofile\AppData\Local\Plex Media Server\Logs|*.*|RECURSE
FileKey12=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Plex Media Server\Logs|*.*|RECURSE

Link to comment
Share on other sites

Revised Entry

Added FileKey4 & FileKey16

[Adobe CC *]
LangSecRef=3023
Detect=HKCU\Software\Adobe\CreativeCloud
Default=False
FileKey1=%AppData%\Adobe\Adobe Media Encoder\*\logs|*.*|RECURSE
FileKey2=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings\CrashLogs|*.*|RECURSE
FileKey3=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings\web-cache-temp|*.*|RECURSE
FileKey4=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings|PSErrorLog.txt;sniffer-*.txt
FileKey5=%AppData%\Adobe\Adobe Photoshop CC *\Logs|*.*|RECURSE
FileKey6=%AppData%\Adobe\CRLogs|*.*|RECURSE
FileKey7=%AppData%\Adobe\dynamiclinkmanager\*\logs|*.*|RECURSE
FileKey8=%AppData%\Adobe\Extension Manager CC\Log|*.*|RECURSE
FileKey9=%AppData%\Adobe\Extension Manager CC\Temp|*.*|RECURSE
FileKey10=%AppData%\Adobe\LogTransport2CC\Logs|*.*|RECURSE
FileKey11=%AppData%\Adobe\Lumetri\*\logs|*.*|RECURSE
FileKey12=%AppData%\Adobe\Premiere Pro\*|Plugin Loading.log
FileKey13=%AppData%\Adobe\Premiere Pro\*\logs|*.*|RECURSE
FileKey14=%CommonProgramFiles%\Adobe\Installers|CoreSyncInstall.log;Install.log
FileKey15=%Documents%\Adobe|*.log
FileKey16=%Documents%\Adobe\Adobe Media Encoder\*|AMEEncodingErrorLog.txt;AMEEncodingLog.txt;
FileKey17=%Documents%\Adobe\Adobe Media Encoder\*\logs|*.*|RECURSE
FileKey18=%Documents%\Adobe\Premiere Pro\*|Plugin Loading.log
RegKey1=KCU\Software\Adobe\MediaBrowser\MRU

Link to comment
Share on other sites

On 11.10.2018 at 23:42, SMalik said:

I think we should add this HKEY_CURRENT_USER\Software\Classes\VirtualStore

If you remove the key "VirtualStore" you will remove settings of old legacy applications (coded for Windows XP and older) or wrong coded applications.

You can see it on siliconman01s screenshot. And the Microsoft documentation explains it also:

Quote

Virtualization Overview

Prior to Windows Vista, applications were typically run by administrators. As a result, applications could freely access system files and registry keys. If these applications were run by a standard user, they would fail due to insufficient access rights. Windows Vista and later versions of Windows improve application compatibility for these applications by automatically redirecting these operations. For example, registry operations to the global store (HKEY_LOCAL_MACHINE\Software) are redirected to a per-user location within the user's profile known as the virtual store (HKEY_USERS\_Classes\VirtualStore\Machine\Software).

Here you can find a more detailed explanation: https://technet.microsoft.com/en-us/library/2007.06.uac.aspx

(Piriform could improve CCleaner, so that it checks the HKLM RegKeys also under HKCU\Software\Classes\VirtualStore\MACHINE. Unfortunately, they never react on those feature requests.)

Link to comment
Share on other sites

New Entry

I have made this entry from a Windows 8.1 system, not just making it up. I think Store entries for Windows 8 and Windows 10 should be separate.

[Windows Store *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\winstore_cw5n1h2txyewy
DetectFile=%LocalAppData%\Packages\winstore_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\winstore_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\winstore_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\winstore_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\winstore_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\winstore_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\winstore_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\winstore_*\LocalState\LiveTile|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Packages\winstore_*\AC\INetCache\|container.dat

Link to comment
Share on other sites

Revised Entry
Added FileKey10, FileKey11 & FileKey12
Removed FileKey9

[Groove Music *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\PRICache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalCache\PlayReady\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\Database\*|*.log
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageRetrievalFailure|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageStore|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\navigationHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\PlayReady|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\SearchHistory
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCache\|container.dat

Link to comment
Share on other sites

Revised Entry
Added FileKey10, FileKey11 & FileKey12
Removed FileKey9

[Movies & TV *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe*
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\PRICache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalCache\PlayReady\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Database\anonymous|*.log
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageRetrievalFailure|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageStore|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\navigationHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\PlayReady|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe\SearchHistory\SearchHistory
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCache\|container.dat

Link to comment
Share on other sites

New Entries

[OneConnect *]
DetectOS=10.0
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.OneConnect_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalCache\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalState\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalState\DiagOutputDir|*.txt
FileKey7=%LocalAppData%\Packages\Microsoft.OneConnect_*\TempState|*.*|RECURSE

[XboxGameOverlay *]
DetectOS=10.0
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxGameOverlay_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalCache\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalState\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalState\DiagOutputDir|*.txt
FileKey7=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\TempState|*.*|RECURSE

Link to comment
Share on other sites

Revised Entry
Added FileKey5

[Feedback Hub *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalState\DiagOutputDir|*.txt
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\TempState|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INetCache\|container.dat

Link to comment
Share on other sites

Revised Entry
Added FileKey7

[Xbox *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxApp_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\*Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\DiagOutputDir|*.txt
FileKey8=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log
FileKey9=%LocalAppData%\Packages\Microsoft.XboxApp_*\TempState|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCache\|container.dat

Link to comment
Share on other sites

On 10/12/2018 at 09:00, Winapp2.ini said:

I think items associated with VirtualStore locations are related to how Windows handles sandboxing / security when the UAC is enabled.

I have been watching that path in the registry. Portable apps leave traces there, but no settings. In the screenshot above, I used a portable app, Windows ISO Downloader, and I deleted it from the drive. I tried some other portable apps and they also left traces at the same path, even though the program was removed from the drive. The link posted above with the screenshot has good information about these traces.

Link to comment
Share on other sites

New app - Sonata (Accounting software)

 

[Sonata *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Sonata
Default=False
Warning=This will remove all backups
FileKey1=%ProgramFiles%\Sonata\update|*.*|RECURSE
FileKey2=%LocalAppData%\sonata\temp|*.*|RECURSE
FileKey3=D:\Sonata\backups|*.*|RECURSE

 

Link to comment
Share on other sites

1 hour ago, tankist_ua said:

New app - Sonata (Accounting software)

Thanks for the new entry.

The location of the backups (FileKey3) seems to be user-defined (not everybody has a second partition D). Therefore, we can add FileKey1 and 2 only.

Link to comment
Share on other sites

Revised Entry
Added
FileKey12

[MS Office *]
LangSecRef=3021
Detect1=HKCU\Software\Microsoft\Office\12.0\Common
Detect2=HKCU\Software\Microsoft\Office\14.0\Common
Detect3=HKCU\Software\Microsoft\Office\15.0\Common
Detect4=HKCU\Software\Microsoft\Office\16.0\Common
Default=False
FileKey1=%AppData%\Microsoft\Document Building Blocks|*.*|RECURSE
FileKey2=%AppData%\Microsoft\Office|*.tmp|RECURSE
FileKey3=%AppData%\Microsoft\OIS|Toolbars.dat
FileKey4=%AppData%\Microsoft\UProof|*.bin;*.XML
FileKey5=%CommonAppData%\Microsoft\ClickToRun\ProductReleases|*.*|RECURSE
FileKey6=%Documents%|~*.ppt;~*.pptx;~*.doc;~*.docx|RECURSE
FileKey7=%LocalAppData%\Microsoft Help|*.*
FileKey8=%LocalAppData%\Microsoft\Office\*|OneNoteOfflineCache.onecache
FileKey9=%LocalAppData%\Microsoft\Office\*\OfficeFileCache|*.*|RECURSE
FileKey10=%LocalAppData%\Microsoft\OneNote\*|OneNoteOfflineCache.onecache
FileKey11=%LocalAppData%\Microsoft\OneNote\*\OneNoteOfflineCache_Files|*.*|RECURSE
FileKey12=%LocalAppData%\Microsoft\OneNote\*\cache|*.*|RECURSE
FileKey13=%SystemDrive%|propfix.log
RegKey1=HKCU\Software\Microsoft\Office\11.0\MSE|LastLoadedSolution
RegKey2=HKCU\Software\Microsoft\Office\11.0\MSE\FileMRUList
RegKey3=HKCU\Software\Microsoft\Office\11.0\MSE\ProjectMRUList
RegKey4=HKCU\Software\Microsoft\Office\11.0\MSE\SolutionMRUList
RegKey5=HKCU\Software\Microsoft\Office\12.0\Common\Internet|UseRWHlinkNavigation
RegKey6=HKCU\Software\Microsoft\Office\12.0\Word\Reading Locations
RegKey7=HKCU\Software\Microsoft\Office\14.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\Office\14.0\Word\Reading Locations
RegKey9=HKCU\Software\Microsoft\Office\15.0\Common\Internet|UseRWHlinkNavigation
RegKey10=HKCU\Software\Microsoft\Office\15.0\Word\Reading Locations
RegKey11=HKCU\Software\Microsoft\Office\16.0\Common\Internet|UseRWHlinkNavigation
RegKey12=HKCU\Software\Microsoft\Office\16.0\Word\Reading Locations
RegKey13=HKCU\Software\Microsoft\Office\Common|FontBmpCache
RegKey14=HKCU\Software\Microsoft\OfficeCustomizeWizard\12.0\RecentFileList
RegKey15=HKCU\Software\Microsoft\OfficeCustomizeWizard\14.0\RecentFileList
RegKey16=HKCU\Software\Microsoft\OfficeCustomizeWizard\15.0\RecentFileList
RegKey17=HKCU\Software\Microsoft\OfficeCustomizeWizard\16.0\RecentFileList

Link to comment
Share on other sites

Revised Entry

Added FileKey5

[Adobe Acrobat DC *]
LangSecRef=3021
Detect=HKLM\Software\Adobe\Adobe Acrobat\DC
Default=False
FileKey1=%LocalAppData%\Adobe\Acrobat\DC|*.lst;UserCache.bin
FileKey2=%LocalAppData%\Adobe\Acrobat\DC\Cache|*.lst
FileKey3=%LocalAppData%\Adobe\Acrobat\DC\ToolsSearchCacheAcro|*.*|RECURSE
FileKey4=%LocalLowAppData%\Adobe\Acrobat\DC\Search|*.*|RECURSE
FileKey5=%LocalLowAppData%\Adobe\AcroCef\DC\Acrobat\Cache|*.*|RECURSE
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionFromPDF\cSettings
RegKey2=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionToPDF\cSettings
RegKey3=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cDockables
RegKey4=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles
RegKey5=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFolders
RegKey6=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentToolsList
RegKey7=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars
RegKey8=HKCU\Software\Adobe\Adobe Acrobat\DC\RememberedViews\cNoCategoryFiles
RegKey9=HKCU\Software\Adobe\Adobe Acrobat\DC\ShareIdentity
RegKey10=HKCU\Software\Adobe\Adobe Synchronizer\DC

Link to comment
Share on other sites

Revised Entry

Added FileKey1

[Windows Communications Apps *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Comms\Unistore\data|AggregateCache.uca
FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\AppCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INet*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\PRICache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\LiveComm\*\*\DBStore\LogFiles|edbtmp.log
FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory
ExcludeKey1=FILE|%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCache\|container.dat

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.