Jump to content
CCleaner Community Forums

APMichael

Members
  • Content count

    592
  • Joined

  • Last visited

Everything posted by APMichael

  1. New forum look.

    Is it possible to make the old links to other posts working again? Old link: ...//forum.piriform.com/index.php?showtopic=12345&page=1&do=findComment&comment=123456 New link: ...//forum.piriform.com/topic/12345-abcdefgh/?do=findComment&comment=123456
  2. Winapp2.ini additions

    We discussed that just a month ago. That's why I revised all the ExcludeKeys and added the \|. (Post, Post)
  3. Support for Waterfox's new data location

    You can use following methods to change the profile location: http://www.piriform.com/docs/ccleaner/advanced-usage/ccleaner-ini-files/how-to-clean-user-data-from-non-standard-mozilla-browsers
  4. Latest Update Avast on Desktop

    Or you could try the uninstall utility: https://www.avast.com/en-us/uninstall-utility
  5. Latest Update Avast on Desktop

    Yes, you are right. It should be unticked by default.
  6. Latest Update Avast on Desktop

    Stealth tactics?! I think you just click to fast. Something like that can happen.
  7. Yes, no favicon disappears anymore. Many thanks for fixing!
  8. Winapp2.ini additions

    Thank you for the notification. Ok, you can close my last 3 PRs (#127-129). I will compare the changes later again. Robert revised many of the affected entries also.
  9. Winapp2.ini additions

    I installed the latest version using the Battle.net Launcher. This version also didn't write any StarCraft II entries in HKCU. Yes, I switched the StarCraft II Client between 32- and 64-bit.
  10. Winapp2.ini additions

    I installed StarCraft II today and replaced Detect1 and Detect2 with following lines: Detect=HKLM\SOFTWARE\Blizzard Entertainment\StarCraft II Editor ...respectively... Detect=HKLM\SOFTWARE\Blizzard Entertainment\StarCraft II CCleaner detects all 4 entries flawless, the detection works as expected. Are you sure that there wasn't a typo in the Detect line when you tested it?
  11. Winapp2.ini additions

    Revised entry: Merged FileKeys. [DxO Photo Suite*] LangSecRef=3021 Detect1=HKCU\Software\DxO Detect2=HKCU\Software\DxO Labs Detect3=HKCU\Software\DxOLabs Detect4=HKLM\Software\DxO Detect5=HKLM\Software\DxO Labs Detect6=HKLM\Software\DxOLabs Default=False FileKey1=%Documents%\DxO FilmPack *\log|*.* FileKey2=%Documents%\DxO Optics*Pro * crash*s|*.* FileKey3=%Documents%\DxO Optics*Pro * logs|*.* FileKey4=%Documents%\DxO PhotoLab logs|*.* FileKey5=%Documents%\DxO ViewPoint*\log|*.* FileKey6=%LocalAppData%\DxO\DxO PhotoLab *\Cache|*.*|RECURSE FileKey7=%LocalAppData%\DxO_Labs\DataCache|*.*|RECURSE FileKey8=%LocalAppData%\DxO_Labs\DxO FilmPack *\CrashReports|*.* FileKey9=%LocalAppData%\DxO_Labs\DxO FilmPack *\DiskCache|*.* FileKey10=%LocalAppData%\DxO_Labs\DxO FilmPack *\Logs|*.* FileKey11=%LocalAppData%\DxO_Labs\DxO Optics*Pro *\Cache|*.*|RECURSE FileKey12=%LocalAppData%\DxO_Labs\DxO ViewPoint *\DiskCache|*.* FileKey13=%LocalAppData%\DxO_Labs\DxO ViewPoint *\Logs|*.* FileKey14=%LocalAppData%\DxO_Labs\Logs|*.*
  12. Winapp2.ini additions

    Thanks! And yes, I suppose there are some more "uncompressed" entries in the winapp2.ini. Revised entries (to make it easier for ROCKNROLL): [CyberLink AudioDirector*] LangSecRef=3023 Detect1=HKCU\Software\CyberLink\AudioDirector4 Detect2=HKCU\Software\CyberLink\AudioDirector5 Detect3=HKCU\Software\CyberLink\AudioDirector6 Detect4=HKCU\Software\CyberLink\AudioDirector7 Detect5=HKCU\Software\CyberLink\AudioDirector8 Default=False FileKey1=%AppData%\CyberLink\MediaCache|*.*|RECURSE FileKey2=%Documents%\Cyberlink\AudioDirector\*.0\SplitterIndex|*.*|RECURSE FileKey3=%LocalAppData%\Cyberlink\AudioDirector\*.0|*.*|RECURSE RegKey1=HKCU\Software\CyberLink\AudioDirector4\MediaObj\MediaCache5\Data5 RegKey2=HKCU\Software\CyberLink\AudioDirector4\MediaObj\MediaCache5\Thumbnail5 RegKey3=HKCU\Software\CyberLink\AudioDirector5\MediaObj\MediaCache5\Data5 RegKey4=HKCU\Software\CyberLink\AudioDirector5\MediaObj\MediaCache5\Thumbnail5 RegKey5=HKCU\Software\CyberLink\AudioDirector6\MediaObj\MediaCache5\Data5 RegKey6=HKCU\Software\CyberLink\AudioDirector6\MediaObj\MediaCache5\Thumbnail5 RegKey7=HKCU\Software\CyberLink\AudioDirector7\MediaObj\MediaCache5\Data5 RegKey8=HKCU\Software\CyberLink\AudioDirector7\MediaObj\MediaCache5\Thumbnail5 RegKey9=HKCU\Software\CyberLink\AudioDirector8\MediaObj\MediaCache5\Data5 RegKey10=HKCU\Software\CyberLink\AudioDirector8\MediaObj\MediaCache5\Thumbnail5 [CyberLink ColorDirector*] LangSecRef=3023 Detect1=HKCU\Software\CyberLink\ColorDirector3 Detect2=HKCU\Software\CyberLink\ColorDirector4 Detect3=HKCU\Software\CyberLink\ColorDirector5 Detect4=HKCU\Software\CyberLink\ColorDirector6 Default=False FileKey1=%AppData%\CyberLink\MediaCache|*.*|RECURSE FileKey2=%LocalAppData%\Cyberlink\ColorDirector\*.0|*.*|RECURSE RegKey1=HKCU\Software\CyberLink\ColorDirector3\MediaObj\MediaCache5\Data5 RegKey2=HKCU\Software\CyberLink\ColorDirector3\MediaObj\MediaCache5\Thumbnail5 RegKey3=HKCU\Software\CyberLink\ColorDirector4\MediaObj\MediaCache5\Data5 RegKey4=HKCU\Software\CyberLink\ColorDirector4\MediaObj\MediaCache5\Thumbnail5 RegKey5=HKCU\Software\CyberLink\ColorDirector5\MediaObj\MediaCache5\Data5 RegKey6=HKCU\Software\CyberLink\ColorDirector5\MediaObj\MediaCache5\Thumbnail5 RegKey7=HKCU\Software\CyberLink\ColorDirector6\MediaObj\MediaCache5\Data5 RegKey8=HKCU\Software\CyberLink\ColorDirector6\MediaObj\MediaCache5\Thumbnail5 [CyberLink PhotoDirector*] LangSecRef=3023 Detect1=HKCU\Software\CyberLink\PhotoDirector3 Detect2=HKLM\Software\CyberLink\PhotoDirector4 Detect3=HKLM\Software\CyberLink\PhotoDirector5 Detect4=HKLM\Software\CyberLink\PhotoDirector6 Detect5=HKLM\Software\CyberLink\PhotoDirector7 Detect6=HKLM\Software\CyberLink\PhotoDirector8 Detect7=HKLM\Software\CyberLink\PhotoDirector9 Default=False FileKey1=%Pictures%\PhotoDirector\*.0\*|*.*|RECURSE ExcludeKey1=PATH|%Pictures%\PhotoDirector\*.0\*\|*.phd [CyberLink PowerDirector*] LangSecRef=3023 Detect1=HKCU\Software\CyberLink\PowerDirector10 Detect2=HKCU\Software\CyberLink\PowerDirector11 Detect3=HKCU\Software\CyberLink\PowerDirector12 Detect4=HKCU\Software\CyberLink\PowerDirector13 Detect5=HKCU\Software\CyberLink\PowerDirector14 Detect6=HKCU\Software\CyberLink\PowerDirector15 Detect7=HKCU\Software\CyberLink\PowerDirector16 Default=False FileKey1=%AppData%\CyberLink\MediaCache|*.*|RECURSE FileKey2=%AppData%\Cyberlink\PowerDirector\*.0|Recentfiles.ini FileKey3=%AppData%\CyberLink\PowerDirector\*.0\AutoSave|*.*|RECURSE FileKey4=%AppData%\CyberLink\PowerDirector\*.0\photoTmp|*.*|RECURSE FileKey5=%AppData%\Cyberlink\PowerDirector\*.0\WaveForms|*.*|RECURSE FileKey6=%Documents%\CyberLink\PowerDirector\*.0|Snapshot(*).jpg FileKey7=%Documents%\CyberLink\PowerDirector\*.0\MyTitles|*.*|RECURSE FileKey8=%Documents%\Cyberlink\PowerDirector\*.0\PDRMUSIC.TMP|*.*|REMOVESELF FileKey9=%Documents%\Cyberlink\PowerDirector\*.0\PP.TWOPASS|*.*|REMOVESELF FileKey10=%Documents%\CyberLink\PowerDirector\*.0\Preview Cache Files|*.* FileKey11=%Documents%\CyberLink\PowerDirector\*.0\ShadowEditFiles|*.MPG FileKey12=%Documents%\CyberLink\PowerDirector\*.0\SplitterIndex|*.maidx RegKey1=HKCU\Software\CyberLink\Hanuman RegKey2=HKCU\Software\CyberLink\PowerDirector10\MediaObj\MediaCache5\Data5 RegKey3=HKCU\Software\CyberLink\PowerDirector10\MediaObj\MediaCache5\Thumbnail5 RegKey4=HKCU\Software\CyberLink\PowerDirector11\MediaObj\MediaCache5\Data5 RegKey5=HKCU\Software\CyberLink\PowerDirector11\MediaObj\MediaCache5\Thumbnail5 RegKey6=HKCU\Software\CyberLink\PowerDirector12\MediaObj\MediaCache5\Data5 RegKey7=HKCU\Software\CyberLink\PowerDirector12\MediaObj\MediaCache5\Thumbnail5 RegKey8=HKCU\Software\CyberLink\PowerDirector13\MediaObj\MediaCache5\Data5 RegKey9=HKCU\Software\CyberLink\PowerDirector13\MediaObj\MediaCache5\Thumbnail5 RegKey10=HKCU\Software\CyberLink\PowerDirector14\MediaObj\MediaCache5\Data5 RegKey11=HKCU\Software\CyberLink\PowerDirector14\MediaObj\MediaCache5\Thumbnail5 RegKey12=HKCU\Software\CyberLink\PowerDirector15\MediaObj\MediaCache5\Data5 RegKey13=HKCU\Software\CyberLink\PowerDirector15\MediaObj\MediaCache5\Thumbnail5 RegKey14=HKCU\Software\CyberLink\PowerDirector16\MediaObj\MediaCache5\Data5 RegKey15=HKCU\Software\CyberLink\PowerDirector16\MediaObj\MediaCache5\Thumbnail5 [CyberLink Power2Go*] LangSecRef=3023 Detect1=HKCU\Software\CyberLink\Power2Go9\9.0 Detect2=HKCU\Software\CyberLink\Power2Go10\10.0 Detect3=HKCU\Software\CyberLink\Power2Go11\11.0 Default=False FileKey1=%AppData%\CyberLink\MediaCache|*.*|RECURSE FileKey2=%Documents%\PDRMUSIC.TMP|*.*|REMOVESELF FileKey3=%LocalAppData%\Cyberlink\Power2Go*|DLDB.db FileKey4=%Music%|*.tmp FileKey5=%Pictures%|*.tmp FileKey6=%ProgramFiles%\Cyberlink\Power2Go*|*.tmp FileKey7=%ProgramFiles%\Cyberlink\Power2Go*|Thumbs.db|RECURSE FileKey8=%SystemDrive%\Users\Public\Documents\Cyberlink\Power2Go11|MP3Cache.log RegKey1=HKCU\Software\CyberLink\LabelPrint\Recent File List RegKey2=HKCU\Software\CyberLink\MediaCache\Data4 RegKey3=HKCU\Software\CyberLink\MediaCache5\Data5 RegKey4=HKCU\Software\CyberLink\MediaCache5\Thumbnail5 RegKey5=HKCU\Software\CyberLink\Power2Go9\9.0|CDRippingPath RegKey6=HKCU\Software\CyberLink\Power2Go9\9.0|CUEName RegKey7=HKCU\Software\CyberLink\Power2Go9\9.0|CUEPath RegKey8=HKCU\Software\CyberLink\Power2Go9\9.0|DestFolder RegKey9=HKCU\Software\CyberLink\Power2Go9\9.0|DVDFolderPath RegKey10=HKCU\Software\CyberLink\Power2Go9\9.0|ImagePath RegKey11=HKCU\Software\CyberLink\Power2Go9\9.0|LastBrowsePath RegKey12=HKCU\Software\CyberLink\Power2Go9\9.0|LastSaveProjPath RegKey13=HKCU\Software\CyberLink\Power2Go9\9.0|MonitorPaths RegKey14=HKCU\Software\CyberLink\Power2Go9\9.0|OpenPrjFilePath RegKey15=HKCU\Software\CyberLink\Power2Go9\9.0|SelectedFolderPath RegKey16=HKCU\Software\CyberLink\Power2Go9\9.0\MediaObj\MediaCache5\Data5 RegKey17=HKCU\Software\CyberLink\Power2Go9\9.0\MediaObj\MediaCache5\Thumbnail5 RegKey18=HKCU\Software\CyberLink\Power2Go10\10.0|CDRippingPath RegKey19=HKCU\Software\CyberLink\Power2Go10\10.0|CUEName RegKey20=HKCU\Software\CyberLink\Power2Go10\10.0|CUEPath RegKey21=HKCU\Software\CyberLink\Power2Go10\10.0|DestFolder RegKey22=HKCU\Software\CyberLink\Power2Go10\10.0|DVDFolderPath RegKey23=HKCU\Software\CyberLink\Power2Go10\10.0|ImagePath RegKey24=HKCU\Software\CyberLink\Power2Go10\10.0|LastBrowsePath RegKey25=HKCU\Software\CyberLink\Power2Go10\10.0|LastSaveProjPath RegKey26=HKCU\Software\CyberLink\Power2Go10\10.0|MonitorPaths RegKey27=HKCU\Software\CyberLink\Power2Go10\10.0|OpenPrjFilePath RegKey28=HKCU\Software\CyberLink\Power2Go10\10.0|SelectedFolderPath RegKey29=HKCU\Software\CyberLink\Power2Go10\10.0\MediaObj\MediaCache5\Data5 RegKey30=HKCU\Software\CyberLink\Power2Go10\10.0\MediaObj\MediaCache5\Thumbnail5 RegKey31=HKCU\Software\CyberLink\Power2Go11\11.0|CDRippingPath RegKey32=HKCU\Software\CyberLink\Power2Go11\11.0|CUEName RegKey33=HKCU\Software\CyberLink\Power2Go11\11.0|CUEPath RegKey34=HKCU\Software\CyberLink\Power2Go11\11.0|DestFolder RegKey35=HKCU\Software\CyberLink\Power2Go11\11.0|DVDFolderPath RegKey36=HKCU\Software\CyberLink\Power2Go11\11.0|ImagePath RegKey37=HKCU\Software\CyberLink\Power2Go11\11.0|LastBrowsePath RegKey38=HKCU\Software\CyberLink\Power2Go11\11.0|LastSaveProjPath RegKey39=HKCU\Software\CyberLink\Power2Go11\11.0|MonitorPaths RegKey40=HKCU\Software\CyberLink\Power2Go11\11.0|OpenPrjFilePath RegKey41=HKCU\Software\CyberLink\Power2Go11\11.0|SelectedFolderPath RegKey42=HKCU\Software\CyberLink\Power2Go11\11.0\MediaObj\MediaCache5\Data5 RegKey43=HKCU\Software\CyberLink\Power2Go11\11.0\MediaObj\MediaCache5\Thumbnail5 RegKey44=HKCU\Software\CyberLink\WaveEditor\2.0|ImportDir RegKey45=HKCU\Software\CyberLink\WaveEditor\2.0|TempFileDir RegKey46=HKCU\Software\CyberLink\WaveEditor\2.0|WorkDir
  13. Winapp2.ini additions

    Just a suggestion: merging the FileKeys. What do you think about it? [CyberLink AudioDirector*] ... FileKey1=%Documents%\Cyberlink\AudioDirector\*.0\SplitterIndex|*.*|RECURSE FileKey2=%LocalAppData%\Cyberlink\AudioDirector\*.0|*.*|RECURSE ... [CyberLink ColorDirector*] ... FileKey2=%LocalAppData%\Cyberlink\ColorDirector\*.0|*.*|RECURSE ... [CyberLink PhotoDirector*] ... FileKey1=%Pictures%\PhotoDirector\*.0\*|*.*|RECURSE ... [CyberLink PowerDirector*] ... FileKey2=%AppData%\Cyberlink\PowerDirector\*.0|Recentfiles.ini FileKey3=%AppData%\CyberLink\PowerDirector\*.0\AutoSave|*.*|RECURSE FileKey4=%AppData%\CyberLink\PowerDirector\*.0\photoTmp|*.*|RECURSE FileKey5=%AppData%\Cyberlink\PowerDirector\*.0\WaveForms|*.*|RECURSE FileKey6=%Documents%\CyberLink\PowerDirector\*.0|Snapshot(*).jpg FileKey7=%Documents%\CyberLink\PowerDirector\*.0\MyTitles|*.*|RECURSE FileKey8=%Documents%\Cyberlink\PowerDirector\*.0\PDRMUSIC.TMP|*.*|REMOVESELF FileKey9=%Documents%\Cyberlink\PowerDirector\*.0\PP.TWOPASS|*.*|REMOVESELF FileKey10=%Documents%\CyberLink\PowerDirector\*.0\Preview Cache Files|*.* FileKey11=%Documents%\CyberLink\PowerDirector\*.0\ShadowEditFiles|*.MPG FileKey12=%Documents%\CyberLink\PowerDirector\*.0\SplitterIndex|*.maidx [CyberLink Power2Go*] ... FileKey1=%LocalAppData%\Cyberlink\Power2Go*|DLDB.db ... FileKey6=%ProgramFiles%\Cyberlink\Power2Go*|*.tmp FileKey7=%ProgramFiles%\Cyberlink\Power2Go*|Thumbs.db|RECURSE ...
  14. old issues still remain

    You should untick following options: Cleaner > Applications > Internet > Internet Explorer 10/11* Internet Explorer Icon Cache* Internet Explorer More*
  15. Winapp2.ini additions

    That's very strange! All 32-bit applications write their data to the HKLM\SOFTWARE\Wow6432Node (on Windows 64-bit). But they all get detected by CCleaner. Good examples for that behavior: Acrobat Reader = HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Adobe\Acrobat Reader\DC ...works with Detect=HKLM\Software\Adobe\Acrobat Reader\DC Notepad++ = HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Notepad++ ...works with Detect=HKLM\SOFTWARE\Notepad++ If that wouldn't work, all entries would need an additional Detect with the Wow6432Node, because most of the applications are still 32-bit. But only 46 of 2,495 entries had it. BTW I didn't touch the StarCraft II entries, because they get detected by Detect=HKCU\Software\Blizzard Entertainment\StarCraft II.
  16. Winapp2.ini additions

    Yes, a ExcludeKey for "single" files would always work without it. Because CC accept that syntax. If a syntax works or not only relies on the syntax itself respectively how CC interpret it. It's absolutely not related to the excluded file or the application the entry is written for. But if a future CC version will check the syntax stricter, we should use the syntax from the official documentation. I don't understand your concern. The syntax from the official documentation works always, is more accurate and future proof. CC uses the same syntax in the ccleaner.ini (and the "settings" registry). And some of the current ExcludeKeys are definitely wrong and won't work. The overhaul and a common syntax for all entries is important.
  17. Winapp2.ini additions

    My final words about the ExcludeKey syntax. I discovered the official documentation: http://www.piriform.com/docs/ccleaner/advanced-usage/ccleaner-ini-files/how-to-exclude-items-from-ccleaners-cleaning. I don't know since when this documentation exists, but somehow I missed it. The official documentation should always be the reference for the syntax. Therefore, I revised all the ExcludeKeys again and posted them on GitHub. @siliconman01: The "unnecessary" pipe symbol is back again! Even if the entries usually would work without it. (CCleaner seems to allow much tolerance in the syntax.)
  18. Winapp2.ini additions

    Modified entries: Sorted, and fixed (not working) ExcludeKeys. [360 Browser - Cache*] LangSecRef=3029 Detect=HKCU\Software\360Browser\Browser Default=False FileKey1=%LocalAppData%\360Browser\Browser\User Data\Default|*-journal* FileKey2=%LocalAppData%\360Browser\Browser\User Data\Default\Cache|*.* FileKey3=%LocalAppData%\360Browser\Browser\User Data\Default\Local Storage|*.* ExcludeKey1=FILE|%LocalAppData%\360Browser\Browser\User Data\Default\Login data-journal ExcludeKey2=FILE|%LocalAppData%\360Browser\Browser\User Data\Default\switcher-journal ExcludeKey3=FILE|%LocalAppData%\360Browser\Browser\User Data\Default\Web data-journal [HuluPlus*] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\HuluLLC.HuluPlus_fphbd361v8tya Default=False FileKey1=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\INetCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\INetCookies|*.*|RECURSE FileKey3=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\INetHistory|*.*|RECURSE FileKey4=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\Temp|*.* FileKey5=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\Microsoft\CryptnetUrlCache\Content|*.* FileKey6=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.* FileKey7=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\TempState|*.*|RECURSE FileKey8=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\LocalState|*.tmp|RECURSE ExcludeKey1=FILE|%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\INetCache\container.dat [Internet Explorer More*] LangSecRef=3022 Detect=HKCU\Software\Microsoft\Internet Explorer Default=False FileKey1=%AppData%\Microsoft\Internet Explorer|brndlog.bak;brndlog.txt FileKey2=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE FileKey3=%LocalAppData%\Microsoft\Internet Explorer|frameiconcache.dat;tabiconcache.dat;brndlog.txt;brndlog.bak FileKey4=%LocalAppData%\Microsoft\Internet Explorer\Recovery\Last Active|*.*|RECURSE FileKey5=%LocalAppData%\Microsoft\SmartScreen|*.tmp FileKey6=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE FileKey7=%LocalAppData%\Microsoft\Windows\IECompatCache|*.*|RECURSE FileKey8=%LocalAppData%\Microsoft\Windows\IECompatUACache|*.*|RECURSE FileKey9=%LocalAppData%\Microsoft\Windows\INetCache|*.*|RECURSE FileKey10=%LocalAppData%\Microsoft\Windows\INetCache\Content.Word|*.* FileKey11=%LocalAppData%\Microsoft\Windows\INetCache\IE|*.*|RECURSE FileKey12=%LocalAppData%\Microsoft\Windows\WebCache|*.*|RECURSE FileKey13=%LocalAppData%\Microsoft\Windows\WebCache.old|*.*|REMOVESELF FileKey14=%LocalLowAppData%\Microsoft\Internet Explorer\iconcache|*.*|RECURSE FileKey15=%LocalLowAppData%\Microsoft\Windows\AppCache|*.*|RECURSE FileKey16=%SystemDrive%\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer|brndlog.bak;brndlog.txt FileKey17=%SystemDrive%\Documents and Settings\LocalService\IETldCache|*.*|RECURSE FileKey18=%SystemDrive%\Documents and Settings\NetworkService\IETldCache|*.*|RECURSE FileKey19=%WinDir%\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\IETldCache|*.*|RECURSE FileKey20=%WinDir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache|*.*|RECURSE FileKey21=%WinDir%\System32\config\Systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE FileKey22=%WinDir%\System32\config\SystemProfile\AppData\LocalLow\Microsoft\Internet Explorer|brndlog.bak;brndlog.txt FileKey23=%WinDir%\System32\config\SystemProfile\Application Data\Microsoft\Internet Explorer|brndlog.bak;brndlog.txt RegKey1=HKCU\Software\Microsoft\Internet Explorer\International|CNum_CpCache RegKey2=HKCU\Software\Microsoft\Internet Explorer\International|CpCache RegKey3=HKCU\Software\Microsoft\Internet Explorer\International\CpMRU RegKey4=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore RegKey5=HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl RegKey6=HKCU\Software\Microsoft\Internet Explorer\PageSetup RegKey7=HKCU\Software\Microsoft\Internet Explorer\Recovery\PendingDelete RegKey8=HKCU\Software\Microsoft\Internet Explorer\TypedURLSTime RegKey9=HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats ExcludeKey1=FILE|%LocalAppData%\Microsoft\Windows\INetCache\IE\container.datI think all syntax mismatches should be fixed now.
  19. Winapp2.ini additions

    Please don't take it personally! It wasn't my intention. Bugs in applications are something different. We are just talking about the syntax of the ExcludeKeys! And that syntax gets interpreted by CCleaner only and not by the application the entry is written for. I know the posts you mentioned about the ExcludeKeys. If you search them you will see that the syntax was wrong always, like "folder|file.txt" which doesn't work. You can correct that to "folder\file.txt" or "folder\|file.txt". The second one is correct and working, but simply not necessary. I just want to help to clean up winapp2.ini and to make sure that the syntax is common for all entries. (That's essential if e.g. somebody wants to code a tool for error checking the winapp2.ini file.) (BTW: We are talking about only 2 of 2,495 entries.) Edit: Please ignore it! More information: #6536
  20. Winapp2.ini additions

    There are .cab files if you wait long enough, until the .log file reaches his file size limit! It's not necessary to leave them as is, because it's 100% clear how the ExcludeKey works: #4274. The revised [Jump Lists*] entry works flawless. All other entries don't have that unnecessary pipe symbol also. And we should use a common syntax for all the winapp2.ini entries! If we "just leave developed and tested code as is" then we have to stop overhauling of winapp2.ini completely.
  21. Winapp2.ini additions

    Modified entry: Removed unnecessary pipe symbols from ExcludeKeys. [FlashPlayer SharedObjects*] LangSecRef=3029 SpecialDetect=DET_CHROME Detect1=HKCU\Software\Chromium Detect2=HKCU\Software\SuperBird Detect3=HKCU\Software\Torch Detect4=HKCU\Software\Vivaldi Default=False FileKey1=%LocalAppData%\Amigo\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE FileKey2=%LocalAppData%\Chrome Plus\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE FileKey3=%LocalAppData%\Chromium\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE FileKey4=%LocalAppData%\Flock\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE FileKey5=%LocalAppData%\Google\Chrome*\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE FileKey6=%LocalAppData%\Rockmelt\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE FileKey7=%LocalAppData%\SRWare Iron\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE FileKey8=%LocalAppData%\SuperBird\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE FileKey9=%LocalAppData%\Torch\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE FileKey10=%LocalAppData%\Vivaldi\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE ExcludeKey1=FILE|%LocalAppData%\Amigo\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol ExcludeKey2=FILE|%LocalAppData%\Chrome Plus\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol ExcludeKey3=FILE|%LocalAppData%\Chromium\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol ExcludeKey4=FILE|%LocalAppData%\Flock\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol ExcludeKey5=FILE|%LocalAppData%\Google\Chrome*\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol ExcludeKey6=FILE|%LocalAppData%\Rockmelt\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol ExcludeKey7=FILE|%LocalAppData%\SRWare Iron\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol ExcludeKey8=FILE|%LocalAppData%\SuperBird\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol ExcludeKey9=FILE|%LocalAppData%\Torch\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol ExcludeKey10=FILE|%LocalAppData%\Vivaldi\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol Modified entry: Removed unnecessary pipe symbol from ExcludeKey. [Jump Lists*] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%AppData%\Microsoft\windows\recent\Automaticdestinations|*.*|RECURSE FileKey2=%AppData%\Microsoft\windows\recent\CustomDestinations|*.*|RECURSE ExcludeKey1=FILE|%AppData%\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms
  22. Winapp2.ini additions

    Modified entry: Changed Detect and removed unnecessary pipe symbols from ExcludeKeys. [Multi-Edit 2008 Logs*] LangSecRef=3024 Detect=HKCU\Software\Multi Edit Software\Multi-Edit\11.0 Default=False FileKey1=%AppData%\Multi Edit Software|*.log|RECURSE ExcludeKey1=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\EVOLVE.LOG ExcludeKey2=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\FILEPANE.LOG ExcludeKey3=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\INSTALL.LOG ExcludeKey4=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\POLYSTYLE.LOG ExcludeKey5=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\TMPLPANE.LOG ExcludeKey6=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\WINLIST.LOG Modified entry: Changed name from [Multi-Edit 2008 11.04*] to [Multi-Edit 2008 Temps*] and corrected LangSecRef. [Multi-Edit 2008 Temps*] LangSecRef=3024 Detect=HKCU\Software\Multi Edit Software\Multi-Edit\11.0 Default=False FileKey1=%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\Tmp|*.TMP Edit: Fixed entry.
  23. Winapp2.ini additions

    Modified entries: Revised those Detect lines. [Active Setup Temp Folder*] LangSecRef=3025 Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Active Setup Temp Folders [Age of Empires*] Section=Games Detect1=HKLM\Software\Microsoft\Games\Age of Empires Detect2=HKLM\Software\Microsoft\Microsoft Games\Age of Empires Detect3=HKLM\Software\Microsoft\microsoft games\age of empires 3 [Auslogics Registry Cleaner*] LangSecRef=3024 Detect1=HKCU\Software\Auslogics\Registry Cleaner Detect2=HKLM\Software\Auslogics\Registry Cleaner\3.x Detect3=HKLM\Software\Auslogics\Registry Cleaner\4.x Detect4=HKLM\Software\Auslogics\Registry Cleaner\5.X [Bitcoin*] LangSecRef=3022 Detect1=HKCU\Software\Bitcoin Detect2=HKCU\Software\Bitcoin Core Detect3=HKLM\SOFTWARE\Bitcoin Core [Copernic DesktopSearch4 Logs*] LangSecRef=3024 Detect=HKLM\SOFTWARE\Copernic\DesktopSearch4 [Crysis 3*] Section=Games Detect=HKLM\Software\Crytek\Crysis 3 [CyberLink PhotoDirector*] LangSecRef=3023 Detect1=HKCU\Software\CyberLink\PhotoDirector3 Detect2=HKLM\Software\CyberLink\PhotoDirector4 Detect3=HKLM\SOFTWARE\CyberLink\PhotoDirector6 Detect4=HKCU\Software\Cyberlink\PowerDirector7 Detect5=HKCU\Software\CyberLink\PowerDirector10 Detect6=HKCU\Software\CyberLink\PowerDirector11 Detect7=HKCU\Software\CyberLink\PowerDirector12 Detect8=HKCU\Software\CyberLink\PowerDirector13 [Dragon Age: Origins*] Section=Games Detect1=HKCU\Software\BioWare\Dragon Age Detect2=HKLM\Software\BioWare\Dragon Age [DVBDream*] LangSecRef=3024 Detect=HKLM\SOFTWARE\DVBDream [Forte Agent*] LangSecRef=3025 Detect=HKLM\SOFTWARE\Forte [FossaMail Corrupt SQLites*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [FossaMail Crash Reports*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [FossaMail Extensions Log*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [FossaMail Log*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [FossaMail Maintenance Service*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [FossaMail Minidumps*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [FossaMail Net Predictions*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [FossaMail Startup Cache*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [FossaMail TestPilot Error Logs*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [FossaMail Update Logs*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [FossaMail webappsstore.sqlite*] LangSecRef=3030 Detect=HKLM\SOFTWARE\Mozilla\FossaMail [Hedgewars VideoTemp*] Section=Games Detect=HKLM\SOFTWARE\Hedgewars [HitmanPro*] LangSecRef=3024 Detect1=HKCU\Software\HitMan Pro Detect2=HKCU\Software\HitMan Pro 2 Detect3=HKCU\Software\HitMan Pro 3 Detect4=HKLM\SOFTWARE\HitmanPro [League of Legends*] Section=Games Detect1=HKCU\Software\Bugsplat\lol_beta_riotgames_com Detect2=HKCU\Software\Riot Games Detect3=HKLM\Software\Riot Games [Logitech Desktop Messenger*] LangSecRef=3024 Detect1=HKCU\Software\Logitech\DesktopMessenger Detect2=HKLM\SOFTWARE\Logitech\DesktopMessenger Detect3=HKLM\SOFTWARE\Logitech\Logitech Desktop Messenger [Microsoft XNA Game Studio*] Section=Games Detect=HKLM\Software\Microsoft\XNA [Midori - Cache*] LangSecRef=3022 Detect=HKLM\Software\Midori [Midori - Cookies*] LangSecRef=3022 Detect=HKLM\Software\Midori [Midori - History*] LangSecRef=3022 Detect=HKLM\Software\Midori [Midori - Session*] LangSecRef=3022 Detect=HKLM\Software\Midori [Neostar CMS Station Client Logs*] LangSecRef=3024 Detect=HKLM\SOFTWARE\company\Neostar CMS [Nero*] LangSecRef=3021 Detect1=HKLM\Software\Nero\Nero 11\Nero11Suite Detect2=HKLM\Software\Nero\Nero 12\Nero12Suite [OpenOffice.org Setup Files*] LangSecRef=3021 Detect1=HKLM\Software\OpenOffice Detect2=HKLM\Software\OpenOffice.org [OpenOffice.org*] LangSecRef=3021 Detect1=HKLM\Software\OpenOffice Detect2=HKLM\Software\OpenOffice.org [Samsung Magician Logs*] LangSecRef=3021 Detect=HKLM\Software\Samsung Magician [Seagate SeaTools for Windows Logs*] LangSecRef=3024 Detect=HKLM\SOFTWARE\SeaToolsforWindows [TrendMicro RUBotted Logs*] LangSecRef=3024 Detect=HKLM\SOFTWARE\TrendMicro\RUBotted [UltraDefrag Logs*] LangSecRef=3024 Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UltraDefrag DetectFile=%WinDir%\UltraDefrag\ultradefrag.exe [Windows Live Writer Logs*] LangSecRef=3024 Detect=HKLM\SOFTWARE\Microsoft\Windows Live Writer [Wistron Corp Launch Manager Logs*] LangSecRef=3024 Detect=HKLM\SOFTWARE\Wistron Corp\Launch Manager [Wondershare PDF Editor*] LangSecRef=3021 Detect=HKLM\Software\Wondershare\Wondershare PDF Editor [Wondershare Video Converter Ultimate More*] LangSecRef=3023 Detect=HKLM\SOFTWARE\Wondershare\Wondershare Video Converter Ultimate [XnView More*] LangSecRef=3023 Detect1=HKCU\Software\XnView Detect2=HKLM\Software\XnView
  24. Winapp2.ini additions

    No, CC doesn't remove the .cab files! (winsys.ini: FileKey15=%windir%\Logs|*.log|RECURSE) Modified entry: [CBS Logs*] LangSecRef=3025 Detect=HKLM\Software\Microsoft\Windows Default=False FileKey1=%WinDir%\Logs\CBS|*.cab
  25. Yes, the key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WbemPerf" is a Windows default key. Only the mentioned subkeys (\001 to \004) are created by the malware.
×