Jump to content

SMalik

Experienced Members
  • Posts

    1,747
  • Joined

  • Last visited

Everything posted by SMalik

  1. Is there a code to delete only the registry values?
  2. Revised entry Added: RegKey4 - RegKey12 [Internet Explorer *] LangSecRef=3001 Detect=HKCU\Software\Microsoft\Internet Explorer FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE FileKey2=%LocalAppData%\Microsoft\Internet Explorer|*.log;*.txt|RECURSE FileKey3=%LocalAppData%\Microsoft\Internet Explorer\CacheStorage|*.*|RECURSE FileKey4=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE FileKey5=%LocalAppData%\Microsoft\Windows\IECompat*Cache|*.*|RECURSE FileKey6=%LocalAppData%\Microsoft\Windows\INetCache|*.*|RECURSE FileKey7=%LocalAppData%\Microsoft\Windows\INetCookies|*.*|RECURSE FileKey8=%LocalAppData%\Microsoft\Windows\WebCache|*.*|RECURSE FileKey9=%LocalAppData%\Microsoft\Windows\WebCache.old|*.*|REMOVESELF FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\IECompat*Cache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\AC\IEDownloadHistory|*.*|RECURSE FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey15=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.* FileKey16=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey17=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\Emie*List|*.*|RECURSE FileKey18=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*|RECURSE FileKey19=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*|RECURSE FileKey20=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE FileKey21=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE FileKey22=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE FileKey23=%SystemDrive%\Documents and Settings\LocalService*\Cookies|*.*|RECURSE FileKey24=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\History|*.*|RECURSE FileKey25=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\Temporary Internet Files|*.*|RECURSE FileKey26=%SystemDrive%\Documents and Settings\NetworkService*\Cookies|*.*|RECURSE FileKey27=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\History|*.*|RECURSE FileKey28=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\Temporary Internet Files|*.*|RECURSE FileKey29=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\History|*.*|RECURSE FileKey30=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE FileKey31=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE FileKey32=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE FileKey33=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE FileKey34=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE FileKey35=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE FileKey36=%WinDir%\System32\config\systemprofile\Cookies|*.*|RECURSE FileKey37=%WinDir%\System32\config\systemprofile\History|*.*|RECURSE FileKey38=%WinDir%\System32\config\systemprofile\Local Settings\Temporary Internet Files|*.*|RECURSE FileKey39=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE FileKey40=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE FileKey41=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE FileKey42=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE RegKey1=HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage RegKey2=HKCU\SOFTWARE\Microsoft\Internet Explorer\DOMStorage RegKey3=HKCU\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage RegKey4=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION RegKey5=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_Cross_Domain_Redirect_Mitigation RegKey6=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CrossDomain_Fix_KB867801 RegKey7=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_CLIPCHILDREN_OPTIMIZATION RegKey8=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING RegKey9=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN RegKey10=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER RegKey11=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER RegKey12=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION RegKey13=HKCU\SOFTWARE\Microsoft\Internet Explorer\Recovery\PendingDelete RegKey14=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats RegKey15=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU RegKey16=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU RegKey17=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\TypedURLs
  3. Revised entry Added *.jpg into FileKey9 [Mail and Calendar *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe FileKey1=%LocalAppData%\Comms\Unistore\data|AggregateCache.uca FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*|RECURSE FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalCache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState|*.etl;*.jpg;*.log FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\AppData\Local\Office\*\WebServiceCache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\Livecomm\*\dbStore\LogFiles|*.* FileKey12=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory
  4. Revised entry Added: HKCU\Software\Microsoft\Internet Explorer\DOMStorage [Internet Explorer *] LangSecRef=3001 Detect=HKCU\Software\Microsoft\Internet Explorer FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE FileKey2=%LocalAppData%\Microsoft\Internet Explorer|*.log;*.txt|RECURSE FileKey3=%LocalAppData%\Microsoft\Internet Explorer\CacheStorage|*.*|RECURSE FileKey4=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE FileKey5=%LocalAppData%\Microsoft\Windows\IECompat*Cache|*.*|RECURSE FileKey6=%LocalAppData%\Microsoft\Windows\INetCache|*.*|RECURSE FileKey7=%LocalAppData%\Microsoft\Windows\INetCookies|*.*|RECURSE FileKey8=%LocalAppData%\Microsoft\Windows\WebCache|*.*|RECURSE FileKey9=%LocalAppData%\Microsoft\Windows\WebCache.old|*.*|REMOVESELF FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\IECompat*Cache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\AC\IEDownloadHistory|*.*|RECURSE FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey15=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.* FileKey16=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey17=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\Emie*List|*.*|RECURSE FileKey18=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*|RECURSE FileKey19=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*|RECURSE FileKey20=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE FileKey21=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE FileKey22=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE FileKey23=%SystemDrive%\Documents and Settings\LocalService*\Cookies|*.*|RECURSE FileKey24=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\History|*.*|RECURSE FileKey25=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\Temporary Internet Files|*.*|RECURSE FileKey26=%SystemDrive%\Documents and Settings\NetworkService*\Cookies|*.*|RECURSE FileKey27=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\History|*.*|RECURSE FileKey28=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\Temporary Internet Files|*.*|RECURSE FileKey29=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\History|*.*|RECURSE FileKey30=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE FileKey31=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE FileKey32=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE FileKey33=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE FileKey34=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE FileKey35=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE FileKey36=%WinDir%\System32\config\systemprofile\Cookies|*.*|RECURSE FileKey37=%WinDir%\System32\config\systemprofile\History|*.*|RECURSE FileKey38=%WinDir%\System32\config\systemprofile\Local Settings\Temporary Internet Files|*.*|RECURSE FileKey39=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE FileKey40=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE FileKey41=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE FileKey42=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage RegKey2=HKCU\Software\Microsoft\Internet Explorer\DOMStorage RegKey3=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage RegKey4=HKCU\Software\Microsoft\Internet Explorer\Recovery\PendingDelete RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats RegKey6=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU RegKey7=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU RegKey8=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\TypedURLs
  5. Revised entry Added .tmp in FileKey23 [Windows Logs *] LangSecRef=3025 Detect=HKLM\Software\Microsoft\Windows FileKey1=%CommonAppData%\Microsoft\Diagnosis\DownloadedSettings|*.json.bk FileKey2=%CommonAppData%\Microsoft\Diagnosis\ETLLogs|*.*|RECURSE FileKey3=%CommonAppData%\Microsoft\DiagnosticLogCSP|*.*|RECURSE FileKey4=%CommonAppData%\Microsoft\Network\Downloader|*.*|RECURSE FileKey5=%CommonAppData%\Microsoft\WDF|*.*|RECURSE FileKey6=%CommonAppData%\Microsoft\Windows Security Health\Logs|*.*|RECURSE FileKey7=%CommonAppData%\Microsoft\Windows\wfp|*.etl FileKey8=%CommonAppData%\USOShared\Logs|*.*|RECURSE FileKey9=%LocalAppData%\ConnectedDevicesPlatform|*.log FileKey10=%LocalAppData%\Diagnostics|*.*|RECURSE FileKey11=%LocalAppData%\Microsoft\Dialer|*.log.txt FileKey12=%LocalAppData%\Microsoft\msipc\Logs|*.* FileKey13=%LocalAppData%\Microsoft\Windows\Explorer|*.etl FileKey14=%ProgramFiles%\UNP\*Logs|*.* FileKey15=%SystemDrive%|DumpStack.log FileKey16=%SystemDrive%\PerfLogs\System\Diagnostics|*.*|RECURSE FileKey17=%SystemDrive%\PerfLogs\System\Performance|*.*|RECURSE FileKey18=%WinDir%\AppCompat\Programs|*.txt;*.xml FileKey19=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml FileKey20=%WinDir%\debug\WIA|*.log FileKey21=%WinDir%\INF|*.etl;*.log* FileKey22=%WinDir%\Logs\CBS|*.cab FileKey23=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log;*.tmp FileKey24=%WinDir%\Panther\FastCleanup|*.log FileKey25=%WinDir%\Panther\Rollback|*.txt FileKey26=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml FileKey27=%WinDir%\repair|setup.log FileKey28=%WinDir%\security\logs|*.*|RECURSE FileKey29=%WinDir%\ServiceProfiles\NetworkService\debug|*.log FileKey30=%WinDir%\System32\CatRoot|*.tmp FileKey31=%WinDir%\System32\CatRoot_bak|*.*|REMOVESELF FileKey32=%WinDir%\System32\catroot2|*.chk;*.log;*.jrs;*.txt FileKey33=%WinDir%\System32\LogFiles\HTTPERR|*.log FileKey34=%WinDir%\System32\LogFiles\Scm|*.*|RECURSE FileKey35=%WinDir%\System32\LogFiles\setupcln|*.*|RECURSE FileKey36=%WinDir%\System32\LogFiles\Srt|*.*|RECURSE FileKey37=%WinDir%\System32\LogFiles\WMI|*.*|RECURSE FileKey38=%WinDir%\System32\LogFiles\WUDF|*.* FileKey39=%WinDir%\System32\SleepStudy|*.etl FileKey40=%WinDir%\System32\SleepStudy\ScreenOn|*.etl FileKey41=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml;*.log FileKey42=%WinDir%\System32\WDI\*|snapshot.etl|REMOVESELF FileKey43=%WinDir%\System32\WDI\LogFiles\StartupInfo|*.*|RECURSE RegKey1=HKLM\Software\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications RegKey2=HKLM\Software\Microsoft\Tracing RegKey3=HKLM\Software\Wow6432Node\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications RegKey4=HKLM\Software\Wow6432Node\Microsoft\Tracing
  6. Revised entry Added .cache files FileKey13=%Public%\TechSmith\Snagit\License|*.cache;*.log [Snagit *] LangSecRef=3021 Detect=HKCU\Software\TechSmith\Snagit FileKey1=%CommonAppData%\TechSmith\Uploader|*.log FileKey2=%Documents%|SnagitDebug.log FileKey3=%Documents%\Snagit|*.snagx FileKey4=%Documents%\Snagit\.metadata|*.*|RECURSE FileKey5=%LocalAppData%\TechSmith\Logs|*.log FileKey6=%LocalAppData%\TechSmith\Snagit|Tray.bin FileKey7=%LocalAppData%\TechSmith\Snagit\*\NativeCrashReporting\Reports|*.dmp|RECURSE FileKey8=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE FileKey9=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico FileKey10=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico FileKey11=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE FileKey12=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log;*.logtmp FileKey13=%Public%\TechSmith\Snagit\License|*.cache;*.log RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount RegKey5=HKCU\Software\TechSmith\Snagit\11|OutputDirLastUsed RegKey6=HKCU\Software\TechSmith\Snagit\11|VidOutputDirLastUsed RegKey7=HKCU\Software\TechSmith\Snagit\11\SnagItEditor\Tray|Thumbnailsize RegKey8=HKCU\Software\TechSmith\Snagit\12|CaptureCount RegKey9=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount RegKey10=HKCU\Software\TechSmith\Snagit\12|OutputDirLastUsed RegKey11=HKCU\Software\TechSmith\Snagit\12|VidOutputDirLastUsed RegKey12=HKCU\Software\TechSmith\Snagit\12\SnagItEditor\Tray|Thumbnailsize RegKey13=HKCU\Software\TechSmith\Snagit\13|CaptureCount RegKey14=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount RegKey15=HKCU\Software\TechSmith\Snagit\13|OutputDirLastUsed RegKey16=HKCU\Software\TechSmith\Snagit\13|VidOutputDirLastUsed RegKey17=HKCU\Software\TechSmith\Snagit\13\Recent Captures RegKey18=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List RegKey19=HKCU\Software\TechSmith\Snagit\13\SnagItEditor\Tray|Thumbnailsize RegKey20=HKCU\Software\TechSmith\Snagit\18|CaptureCount RegKey21=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount RegKey22=HKCU\Software\TechSmith\Snagit\18|OutputDirLastUsed RegKey23=HKCU\Software\TechSmith\Snagit\18|VidOutputDirLastUsed RegKey24=HKCU\Software\TechSmith\Snagit\18\Recent Captures RegKey25=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List RegKey26=HKCU\Software\TechSmith\Snagit\18\SnagItEditor\Tray|Thumbnailsize RegKey27=HKCU\Software\TechSmith\Snagit\19|CaptureCount RegKey28=HKCU\Software\TechSmith\Snagit\19|CaptureOpenCount RegKey29=HKCU\Software\TechSmith\Snagit\19|OutputDirLastUsed RegKey30=HKCU\Software\TechSmith\Snagit\19|VidOutputDirLastUsed RegKey31=HKCU\Software\TechSmith\Snagit\19\Recent Captures RegKey32=HKCU\Software\TechSmith\Snagit\19\SnagitEditor\Recent File List RegKey33=HKCU\Software\TechSmith\Snagit\19\SnagItEditor\Tray|Thumbnailsize RegKey34=HKCU\Software\TechSmith\Snagit\20|CaptureCount RegKey35=HKCU\Software\TechSmith\Snagit\20|CaptureOpenCount RegKey36=HKCU\Software\TechSmith\Snagit\20|OutputDirLastUsed RegKey37=HKCU\Software\TechSmith\Snagit\20|VidOutputDirLastUsed RegKey38=HKCU\Software\TechSmith\Snagit\20\Recent Captures RegKey39=HKCU\Software\TechSmith\Snagit\20\SnagitEditor\Recent File List RegKey40=HKCU\Software\TechSmith\Snagit\20\SnagItEditor\Tray|Thumbnailsize RegKey41=HKCU\Software\TechSmith\Snagit\21|CaptureCount RegKey42=HKCU\Software\TechSmith\Snagit\21|CaptureOpenCount RegKey43=HKCU\Software\TechSmith\Snagit\21|OutputDirLastUsed RegKey44=HKCU\Software\TechSmith\Snagit\21|VidOutputDirLastUsed RegKey45=HKCU\Software\TechSmith\Snagit\21\Recent Captures RegKey46=HKCU\Software\TechSmith\Snagit\21\SnagitEditor\Recent File List RegKey47=HKCU\Software\TechSmith\Snagit\21\SnagItEditor\Tray|Thumbnailsize RegKey48=HKCU\Software\TechSmith\Snagit\22|CaptureCount RegKey49=HKCU\Software\TechSmith\Snagit\22|CaptureOpenCount RegKey50=HKCU\Software\TechSmith\Snagit\22|OutputDirLastUsed RegKey51=HKCU\Software\TechSmith\Snagit\22|VidOutputDirLastUsed RegKey52=HKCU\Software\TechSmith\Snagit\22\Recent Captures RegKey53=HKCU\Software\TechSmith\Snagit\22\SnagitEditor\Recent File List RegKey54=HKCU\Software\TechSmith\Snagit\22\SnagItEditor\Tray|Thumbnailsize
  7. Snagit creates the MSI*.tmp- folders. [Windows Installer *] LangSecRef=3025 Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Installer FileKey1=%SystemDrive%\Config.msi|*.*|REMOVESELF FileKey2=%WinDir%\Installer|*.tmp|RECURSE FileKey3=%WinDir%\Installer|SourceHash{*};wix{*}.SchedServiceConfig.rmi FileKey4=%WinDir%\Installer\Config.Msi|*.*|REMOVESELF FileKey5=%WinDir%\Installer\MSI*.tmp-|*.*|REMOVESELF
  8. Revised entry [GIMP *] LangSecRef=3021 DetectFile=%LocalAppData%\GIMP DetectFile1=%UserProfile%\.gimp-* FileKey1=%LocalAppData%|recently-used.xbel FileKey2=%LocalAppData%\webkit|*.*|REMOVESELF FileKey3=%LocalAppData%\GIMP\*\CrashLog|*.*|RECURSE FileKey4=%LocalAppData%\GIMP\*\tmp|*.*|RECURSE FileKey5=%UserProfile%\.gegl-*|documents FileKey6=%UserProfile%\.gimp-*|documents FileKey7=%UserProfile%\.gimp-*\tmp|*.*|RECURSE FileKey8=%UserProfile%\.thumbnails\normal|*.*|RECURSE
  9. This entry is present on Windows 10. I deleted approx 8MB of junk using my custom entry for Store apps.
  10. This entry is not working on Windows 10. Detect should be changed to DetectFile=%LocalAppData%\Packages\microsoft.windows.authhost.sso_8wekyb3d8bbwe and DetectOS=6.2|6.3 should be changed to DetectOS=10.0|. [AuthHost *] DetectOS=6.2|6.3 LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windows.authhost.sso_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey4=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\CryptnetUrlCache\*|*.* FileKey5=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\PRICache|*.* FileKey7=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Temp|*.* FileKey8=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\LocalState\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\LocalState\navigationHistory|*.*|RECURSE FileKey10=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\TempState|*.*|RECURSE
  11. New entry [Explorer Diagnostic Logs *] LangSecRef=3025 Detect=HKCU\SOFTWARE\Microsoft\Windows FileKey1=%LocalAppData%\Microsoft\Windows\Explorer|*.etl
  12. New Entry [Microsoft Teams *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MicrosoftTeams_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\MicrosoftTeams_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\MicrosoftTeams_*\AC\Temp|*.*|RECURSE FileKey3=%LocalAppData%\Packages\MicrosoftTeams_*\LocalCache|*.*|RECURSE FileKey4=%LocalAppData%\Packages\MicrosoftTeams_*\TempState|*.*|RECURSE
  13. Revised Entries Moved from [HP Support Assistant *] and added into [HP Logs *]: %SystemDrive%\system.sav\logs|*.*|RECURSE [HP Logs *] LangSecRef=3021 Detect=HKCU\Software\HP DetectFile1=%AppData%\hpqlog DetectFile2=%CommonAppData%\Hewlett-Packard DetectFile3=%CommonAppData%\HP DetectFile4=%LocalAppData%\Hewlett-Packard DetectFile5=%LocalAppData%\TouchSmartData DetectFile6=%ProgramFiles%\HPQ\Shared\Sierra Wireless FileKey1=%AppData%\hp active health\app analytics\*logs|*.*|RECURSE FileKey2=%AppData%\HP\*Logs|*Log.txt FileKey3=%AppData%\hpqlog|*.log FileKey4=%CommonAppData%|hpzinstall.log FileKey5=%CommonAppData%\Hewlett-Packard|*.log*.*;*Log.txt|RECURSE FileKey6=%CommonAppData%\Hewlett-Packard\HP*\Log*|*.*|RECURSE FileKey7=%CommonAppData%\hp audio switch|*.log* FileKey8=%CommonAppData%\HP\HP Touchpoint Analytics Client\Logs|*.* FileKey9=%CommonAppData%\HP\HP Touchpoint Analytics Client\Monitor-History|*.* FileKey10=%CommonAppData%\HP\HP Touchpoint Analytics Client\MRU|*.* FileKey11=%CommonAppData%\HP\logs|*.*|RECURSE FileKey12=%CommonAppData%\HP\StreamLog|*.*|RECURSE FileKey13=%LocalAppData%\Hewlett-Packard\HP Support Framework\Profile\Upload|*.log FileKey14=%LocalAppData%\TouchSmartData\Log|*.* FileKey15=%ProgramFiles%\HPQ\Shared\Sierra Wireless|*.log|RECURSE FileKey16=%SystemDrive%|dism.log FileKey17=%SystemDrive%\hp\bin\logs|*.log FileKey18=%SystemDrive%\system.sav\logs|*.*|RECURSE FileKey19=%WinDir%\HP|Installer.log Added: %LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE [HP Smart *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AD2F1837.HPPrinterControl_v10z8vjag6ke6 FileKey1=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE FileKey4=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Temp|*.*|RECURSE FileKey7=%LocalAppData%\Packages\*.HPPrinterControl_*\LocalCache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\*.HPPrinterControl_*\TempState|*.*|RECURSE [HP Support Assistant *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AD2F1837.HPSupportAssistant_v10z8vjag6ke6 FileKey1=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey4=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\LocalCache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\TempState|*.*|RECURSE I think [Intel Graphics Command Center *] entry name should be changed to [Intel Graphics Experience *] [Intel Graphics Command Center *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AppUp.IntelGraphicsExperience_8j3eq9eme6ctt FileKey1=%LocalAppData%\Intel\GCC|gcc*_log_*.txt FileKey2=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\BackgroundTransferApi|*.*|RECURSE FileKey3=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\INet*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\Temp|*.*|RECURSE FileKey6=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalCache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState|gcc*_log_*.txt FileKey8=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\Games2\cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\Intel\GCC|gcc*_log_*.txt FileKey10=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\MetroLogs|*.*|RECURSE FileKey11=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\Promotions|*.*|RECURSE FileKey12=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\TempState|*.*|RECURSE [Windows Client WebExperience *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\LocalCache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\LocalState\EBWebview\*|LOG;LOG.old FileKey6=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\TempState|*.*|RECURSE
  14. [Foxit PDF Editor *] LangSecRef=3021 Detect=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0 FileKey1=%AppData%\Foxit Software\Addon\Foxit PDF Editor\Install|*.*|RECURSE FileKey2=%AppData%\Foxit Software\Foxit PDF Editor\Cache|*.*|RECURSE FileKey3=%AppData%\Foxit Software\Foxit PDF Editor\FormFiller|AutoComplete.ds FileKey4=%AppData%\Foxit Software\Foxit PDF Editor\StartPage\*\Start\en-US|index.html FileKey5=%AppData%\Foxit Software\RMS|FXRMS_Log.txt FileKey6=%CommonAppData%\Foxit Software\Foxit PDF Editor\Foxit Service\Log|*.*|RECURSE FileKey7=%CommonAppData%\Foxit Software\Foxit PDF Editor\FoxitSensor\Log|*.*|RECURSE FileKey8=%LocalLowAppData%\Foxit\Search|*.*|RECURSE RegKey1=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0\CommentPanel\Filter RegKey2=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\File MRU RegKey3=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\Place MRU RegKey4=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\plugins\JSPlugins RegKey5=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\Preferences\History
  15. Revised Entry Added: Detect1 and related FileKeys [Wondershare UniConverter *] LangSecRef=3023 Detect=HKLM\SOFTWARE\Wondershare\Wondershare UniConverter Detect1=HKLM\SOFTWARE\Wondershare\Wondershare UniConverter 13 FileKey1=%CommonAppData%\Wondershare\ProductFeatures\*Logs|*.*|RECURSE FileKey2=%CommonAppData%\Wondershare\UniConverter\DataTrack|tmp;*.bak;*.log FileKey3=%CommonAppData%\Wondershare\UniConverter\TempThumbDir|*.*|RECURSE FileKey4=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE FileKey5=%CommonAppData%\Wondershare\UniConverter 13\DataTrack|tmp;*.bak;*.log FileKey6=%CommonAppData%\Wondershare\UniConverter 13\TempThumbDir|*.*|RECURSE FileKey7=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE FileKey8=%ProgramFiles%\Wondershare\UniConverter\Log|*.*|RECURSE FileKey9=%ProgramFiles%\Wondershare\Wondershare UniConverter 13 for Windows\Log|*.*|RECURSE FileKey10=%Public%\Documents\Wondershare|*.*|REMOVESELF FileKey11=%SystemDrive%|logWSVCUUpdateHelper.log FileKey12=%SystemDrive%\Wondershare UniConverter\Downloaded\temp|*.*|REMOVESELF FileKey13=%UserProfile%\.cache|*.*|REMOVESELF
  16. New Entry [Foxit PDF Editor *] LangSecRef=3021 Detect=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0 FileKey1=%LocalLowAppData%\Foxit\Search|*.*|RECURSE FileKey2=%AppData%\Foxit Software\Addon\Foxit PDF Editor\Install|*.*|RECURSE FileKey3=%AppData%\Foxit Software\Foxit PDF Editor\Cache|*.*|RECURSE FileKey4=%AppData%\Foxit Software\Foxit PDF Editor\FormFiller|AutoComplete.ds FileKey5=%AppData%\Foxit Software\Foxit PDF Editor\StartPage\*\Start\en-US|index.html FileKey6=%AppData%\Foxit Software\RMS|FXRMS_Log.txt RegKey1=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0\CommentPanel\Filter RegKey2=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\Foxit PhantomPDF Advanced Editor\Recent File List RegKey3=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\File MRU RegKey4=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\Place MRU RegKey5=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\plugins\JSPlugins RegKey6=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\Preferences\History
  17. New Entry [Stored Notification Settings *] LangSecRef=3025 Detect=HKCU\SOFTWARE\Microsoft\Windows RegKey1=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings
  18. New Entry [HP Support Assistant *] LangSecRef=3021 Detect=HKCU\SOFTWARE\HP FileKey1=%SystemDrive%\system.sav\logs|*.*|RECURSE
  19. Please do no change this entry. system.sav is part of HP Support Assistant program and it keeps logs there.
  20. I think [HP Install Temps *] and [HP Installation Files *] entries should be merged.
  21. Revised Entry Added: DetectFile3 %SystemDrive%\system.sav|*.*|REMOVESELF [HP Installation Files *] LangSecRef=3024 DetectFile1=%SystemDrive%\HP Universal Print Driver DetectFile2=%SystemDrive%\swsetup DetectFile3=%SystemDrive%\system.sav FileKey1=%SystemDrive%\HP Universal Print Driver|*.*|REMOVESELF FileKey2=%SystemDrive%\swsetup|*.*|REMOVESELF FileKey3=%SystemDrive%\system.sav|*.*|REMOVESELF
  22. New Entry [Edge Website Redirecting Statistics *] LangSecRef=3006 DetectFile=%LocalAppData%\Microsoft\Edge* FileKey1=%LocalAppData%\Microsoft\Edge*\User Data\*|load_statistics.db;load_statistics.db-shm;load_statistics.db-wal
  23. Revised Entry Subscriptions Activity History Added: RegKey1 [Content Delivery Manager *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalCache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Favicons|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\MobilityExperience\ImageCache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\OneSettingsResponseCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\TargetedContentCache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\TempState|*.*|RECURSE RegKey1=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions
  24. Revised Entry Added: UserActivity.json into FileKey9 [Weather *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp;UserActivity.json FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory
  25. As soon as I posted about these empty folders, I realized there is already an entry for this. I requested one of the admins to delete the post. They deleted that post to which afterwards, I noticed your response. My apologies.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.