Jump to content

Winapp2.ini additions


Winapp2.ini

Recommended Posts

Welcome back and glad to hear that you are okay.  :)

Windows 10 x64 Pro on ASUS Maximus VIII Extreme motherboard, i7-6700k CPU,H220 X2 Liquid Cooler, 64 gbyte RipJaws DDR4 3200 RAM, Samsung 970 Pro NVMe M.2 500 gbyte SSD + Samsung 850 Pro 512 gbyte SSD, EVGA RTX 3060 Titan graphics card (Home Built System);  Windows 11x64 Pro on 512 gigabyte Dell XPS 15 2-in-1 Laptop/tablet and Dell XPS 8940 PC.  ASUS RT-AC88U router, 14 tbyte WD My Cloud PR2100 NAS Server, 200 Mbps cable Internet, MS Edge Chromium, MS Office 2021 (Local), Casper 11, DisplayFusion (3 Flat Panel Displays per system):   Latest Bitdefender Internet Security, Quicken, Weather Watcher Live, ThumbsPlus 10, Sticky Password 8, WD Smartware, CyberLink PowerDVD23, MSI AfterBurner, Rainmeter, 8GadgetPack, and many more.

Link to comment
Share on other sites

  • Moderators
Missing Kaspersky Network Agent dumps (part of Security Center suite) stored in :

C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\~dumps

 

huh? For what entry. Please provide the edited or new entry.

 

ADVICE FOR USING CCleaner'S REGISTRY INTEGRITY SECTION

DON'T JUST CLEAN EVERYTHING THAT'S CHECKED OFF.

Do your Registry Cleaning in small bits (at the very least Check-mark by Check-mark)

ALWAYS BACKUP THE ENTRY, YOU NEVER KNOW WHAT YOU'LL BREAK IF YOU DON'T.

Support at https://support.ccleaner.com/s/?language=en_US

Pro users file a PRIORITY SUPPORT via email support@ccleaner.com

Link to comment
Share on other sites

Missing Kaspersky Network Agent dumps (part of Security Center suite) stored in :

C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\~dumps

 

Modified entry:

added filekey7

 

[Kaspersky*]

LangSecRef=3024

Detect=HKCU\Software\KasperskyLab

Default=False

Warning=Make sure to disable “Self Defense” before cleaning.

FileKey1=%CommonAppData%\Kaspersky Lab\*\Bases\Cache|*.*|RECURSE

FileKey2=%CommonAppData%\Kaspersky Lab\*\Data\Updater\Temporary Files|*.*|RECURSE

FileKey3=%CommonAppData%\Kaspersky Lab\*\Temp|*.*

FileKey4=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Bases\Cache|*.*|RECURSE

FileKey5=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Data\Updater\Temporary Files|*.*|RECURSE

FileKey6=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Temp|*.*

FileKey7=%ProgramFiles%\Kaspersky Lab\NetworkAgent\~dumps|*.*

Link to comment
Share on other sites

  • Moderators
Modified entry:added filekey7

 

 

Thanks

 

 

ADVICE FOR USING CCleaner'S REGISTRY INTEGRITY SECTION

DON'T JUST CLEAN EVERYTHING THAT'S CHECKED OFF.

Do your Registry Cleaning in small bits (at the very least Check-mark by Check-mark)

ALWAYS BACKUP THE ENTRY, YOU NEVER KNOW WHAT YOU'LL BREAK IF YOU DON'T.

Support at https://support.ccleaner.com/s/?language=en_US

Pro users file a PRIORITY SUPPORT via email support@ccleaner.com

Link to comment
Share on other sites

new entry

 

[NVIDIA Install Files More*]
LangSecRef=3024
Detect=HKLM\Software\NVIDIA Corporation
Default=False
FileKey1=%ProgramFiles%\NVIDIA Corporation\Installer2\*.*

Link to comment
Share on other sites

new entry

 

[NVIDIA Install Files More*]

LangSecRef=3024

Detect=HKLM\Software\NVIDIA Corporation

Default=False

FileKey1=%ProgramFiles%\NVIDIA Corporation\Installer2\*.*

Already included in:

 

[**Nvidia Graphics Driver Installation Files]

LangSecRef=3024

Warning=You will not be able to do an uninstall of your drivers without first reinstalling them.

Detect=HKCU\Software\NVIDIA Corporation

Default=False

FileKey1=%SystemDrive%\Nvidia|*.*|REMOVESELF

FileKey2=%ProgramFiles%\NVIDIA Corporation\Installer2|*.*|RECURSE

 

Actually, scrap that, seems that entry was removed at some point and only exists still in my winapp2 file. Presumably for good reason, though it clears a good 350Mb every Nvidia update and never caused me a problem, hence it still exists in mine.

 

Link to comment
Share on other sites

If you remove the Nvidia Installer2 folder, you can no longer "uninstall" the Nvidia software via Control Panel>Programs and Features.  You can do an over-the-top upgrade to a newer version of the Nvidia software.  

 

Personally, I prefer to remove the Installer2 folder and have been doing so for years.  If I ever need to uninstall the Nvidia software, I can just re-install the same version number and the Installer2 folder is added back so that I can then uninstall the Nvidia software via Control Panel>Programs and Features.  

Windows 10 x64 Pro on ASUS Maximus VIII Extreme motherboard, i7-6700k CPU,H220 X2 Liquid Cooler, 64 gbyte RipJaws DDR4 3200 RAM, Samsung 970 Pro NVMe M.2 500 gbyte SSD + Samsung 850 Pro 512 gbyte SSD, EVGA RTX 3060 Titan graphics card (Home Built System);  Windows 11x64 Pro on 512 gigabyte Dell XPS 15 2-in-1 Laptop/tablet and Dell XPS 8940 PC.  ASUS RT-AC88U router, 14 tbyte WD My Cloud PR2100 NAS Server, 200 Mbps cable Internet, MS Edge Chromium, MS Office 2021 (Local), Casper 11, DisplayFusion (3 Flat Panel Displays per system):   Latest Bitdefender Internet Security, Quicken, Weather Watcher Live, ThumbsPlus 10, Sticky Password 8, WD Smartware, CyberLink PowerDVD23, MSI AfterBurner, Rainmeter, 8GadgetPack, and many more.

Link to comment
Share on other sites

 

If you remove the Nvidia Installer2 folder, you can no longer "uninstall" the Nvidia software via Control Panel>Programs and Features.  You can do an over-the-top upgrade to a newer version of the Nvidia software.  

 

Personally, I prefer to remove the Installer2 folder and have been doing so for years.  If I ever need to uninstall the Nvidia software, I can just re-install the same version number and the Installer2 folder is added back so that I can then uninstall the Nvidia software via Control Panel>Programs and Features.  

Ah yeah, now you mention it, rings a bell ;)

Link to comment
Share on other sites

  • Moderators

IIf I ever need to uninstall the Nvidia software, I can just re-install the same version number and the Installer2 folder is added back so that I can then uninstall the Nvidia software via Control Panel>Programs and Features.  

 

Wonder what would happen if the graphics card went kaput, install a brand new one, and that old installer won't install due to incompatibilities with the new card.

Link to comment
Share on other sites

Wonder what would happen if the graphics card went kaput, install a brand new one, and that old installer won't install due to incompatibilities with the new card.

 

I don't know about Nvidia, but I do know that AMD drivers are universal. The drivers should be able to run on any card. I assume the same should be for Nvidia.

I am a maintainer for Winapp2. I also have a open-source group on Steam.

http://steamcommunity.com/groups/opencommunity

Link to comment
Share on other sites

Also, I think it would be best if we waited on suggesting entries until he has it up and running on GitHub. That way we can make them as pull requests without having to have him go through all these pages and re-add them himself.

I am a maintainer for Winapp2. I also have a open-source group on Steam.

http://steamcommunity.com/groups/opencommunity

Link to comment
Share on other sites

New entry for SageThumbs (DDS/Thumbnail viewer)

 

[sageThumbs Thumbnail Cache*]
LangSecRef=3021
DetectFile=%ProgramFiles%\SageThumbs\64\SageThumbs.dll
Default=False
FileKey1=%LocalAppData%\|SageThumbs.*

 

Tested and works. there is also a 32bit dir, \SageThumbs\32\SageThumbs.dll that could be added as well for 32bit only users.

Link to comment
Share on other sites

Hi.

I found an error in Beyond Compare section:

 

Current:

[Beyond Compare*]
LangSecRef=3021
Detect=HKCU\Software\Scooter Software\Beyond Compare
Default=False
FileKey1=%AppData%\Scooter Software\Beyond Compare*|*.bak;*.xml

It only should be:

[Beyond Compare*]
LangSecRef=3021
Detect=HKCU\Software\Scooter Software\Beyond Compare
Default=False
FileKey1=%AppData%\Scooter Software\Beyond Compare*|*.bak

Because the .xml files are its actual options and must be preserved.

 

Thanks!

 

Sorry for my terrible English!

Link to comment
Share on other sites

  • Moderators

Updated:
* Added Detect3
* Added FileKey4

[Auslogics Disk Defrag Portable*]
LangSecRef=3024
Detect1=HKCU\Software\Auslogics\Disk Defrag Portable
Detect2=HKLM\Software\Auslogics\DiskDefrag Portable
Detect3=HKLM\Software\Auslogics\Disk Defrag Portable
Default=False
FileKey1=%AppData%\Auslogics\Disk Defrag\Reports|*.*
FileKey2=%AppData%\Auslogics\Disk Defrag\Logs|*.*
FileKey3=%CommonAppData%\Auslogics\DiskDefrag Portable\*\Reports|*.*
FileKey4=%CommonAppData%\Auslogics\Disk Defrag Portable\*\Reports|*.*

Edited by Andavari
Had to remove the "[code]" boxes since the forum software created a mess using it.
Link to comment
Share on other sites

  • Moderators

Woot thanks

 

ADVICE FOR USING CCleaner'S REGISTRY INTEGRITY SECTION

DON'T JUST CLEAN EVERYTHING THAT'S CHECKED OFF.

Do your Registry Cleaning in small bits (at the very least Check-mark by Check-mark)

ALWAYS BACKUP THE ENTRY, YOU NEVER KNOW WHAT YOU'LL BREAK IF YOU DON'T.

Support at https://support.ccleaner.com/s/?language=en_US

Pro users file a PRIORITY SUPPORT via email support@ccleaner.com

Link to comment
Share on other sites

Updated

 

 

 

What's new in winapp2.ini 5.19.160702

General:
43 New Entries
25 Modified Entries
07 Removed Entries

Note:

Change log excludes minor changes (mild pathing changes, key reordering, non-major key tweaks, etc)

Verbose:

------------------------------------------------------------------------------

New Entries:

[3D Builder*]
DetectOS=10.0
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.3DBuilder_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.3DBuilder_*\TempState|*.*|RECURSE

[Accounts Control*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.AccountsControl_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.AccountsControl_*\TempState|*.*|RECURSE

[Adobe Acrobat DC*]
LangSecRef=3021
Detect=HKLM\Software\Adobe\Adobe Acrobat\DC
Default=False
FileKey1=%ProgramFiles%\Adobe\Acrobat DC\Setup Files|*.*|REMOVESELF
FileKey2=%LocalAppData%\Adobe\Acrobat\DC\Cache|*.lst
FileKey3=%LocalAppData%\Adobe\Acrobat\DC\ToolsSearchCacheAcro|*.*|RECURSE
FileKey4=%LocalAppData%\Adobe\Acrobat\DC|*.lst
FileKey5=%LocalAppData%\Adobe\Acrobat\DC|UserCache.bin
FileKey6=%LocalLowAppData%\Adobe\Acrobat\DC\Search|*.*
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionFromPDF\cSettings
RegKey2=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionToPDF\cSettings
RegKey3=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cDockables
RegKey4=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles
RegKey5=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFolders
RegKey6=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentToolsList
RegKey7=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars
RegKey8=HKCU\Software\Adobe\Adobe Acrobat\DC\RememberedViews\cNoCategoryFiles
RegKey9=HKCU\Software\Adobe\Adobe Acrobat\DC\ShareIdentity
RegKey10=HKCU\Software\Adobe\Adobe Synchronizer\DC

[AIMP 4*]
LangSecRef=3023
DetectFile=%ProgramFiles%\AIMP\AIMP.exe
Default=False
FileKey1=%AppData%\AIMP|*.bak

[Ashampoo Snap 9 (AutoSave)*]
LangSecRef=3024
Detect=HKCU\Software\Ashampoo\Ashampoo Snap 9
Default=False
FileKey1=%Pictures%\Ashampoo Snap 9\_SNAPDOC|*.*

[Ashampoo Snap 9*]
LangSecRef=3024
Detect=HKCU\Software\Ashampoo\Ashampoo Snap 9
Default=False
FileKey1=%LocalAppData%\CrashRpt\UnsentCrashReports|*.*|RECURSE
FileKey2=%AppData%\Ashampoo\Ashampoo Snap 9|*.*|RECURSE
FileKey3=%ProgramFiles%\Ashampoo\Ashampoo Snap 9|_NLogMsg.txt

[bITS Logs*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\Network\Downloader|*.*|RECURSE

[CamStudio Temps*]
LangSecRef=3023
Detect=HKCU\Software\CamStudioOpenSource for Nick
Default=False
FileKey1=%Documents%\My CamStudio Temp Files|*.*

[Comms Phone*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.CommsPhone_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.CommsPhone_*\TempState|*.*|RECURSE

[Connectivity Store*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ConnectivityStore_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\TempState|*.*|RECURSE

[Contact Support*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Windows.ContactSupport_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0|*.log
FileKey6=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32|*.log
FileKey9=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Temp|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalCache|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalState\Cache|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\Windows.ContactSupport_*\TempState|*.*|RECURSE

[CyberLink Power2Go 9*]
LangSecRef=3023
Detect=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0
Default=False
FileKey1=%ProgramFiles%\Cyberlink\Power2Go9|*.tmp
FileKey2=%ProgramFiles%\Cyberlink\Power2Go9|Thumbs.db|RECURSE
FileKey3=%LocalAppData%\Cyberlink\Power2Go9|DLDB.db
FileKey4=%Documents%\PDRMUSIC.TMP|*.*|REMOVESELF
FileKey5=%Music%|*.tmp
FileKey6=%Pictures%|*.tmp
RegKey1=HKCU\SOFTWARE\CyberLink\LabelPrint\Recent File List
RegKey2=HKCU\SOFTWARE\CyberLink\MediaCache\Data4
RegKey3=HKCU\SOFTWARE\CyberLink\MediaCache5\Data5
RegKey4=HKCU\SOFTWARE\CyberLink\MediaCache5\Thumbnail5
RegKey5=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|CDRippingPath
RegKey6=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|CUEName
RegKey7=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|CUEPath
RegKey8=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|DestFolder
RegKey9=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|DVDFolderPath
RegKey9=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|ImagePath
RegKey11=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|LastBrowsePath
RegKey12=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|LastSaveProjPath
RegKey13=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|MonitorPaths
RegKey14=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|OpenPrjFilePath
RegKey15=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0|SelectedFolderPath
RegKey16=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0\MediaObj\MediaCache5\Data5
RegKey17=HKCU\SOFTWARE\CyberLink\Power2Go9\9.0\MediaObj\MediaCache5\Thumbnail5
RegKey18=HKCU\SOFTWARE\CyberLink\WaveEditor\2.0|ImportDir
RegKey19=HKCU\SOFTWARE\CyberLink\WaveEditor\2.0|TempFileDir
RegKey20=HKCU\SOFTWARE\CyberLink\WaveEditor\2.0|WorkDir

[CyberLink Power2Go 10*]
LangSecRef=3023
Detect=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0
Default=False
FileKey1=%ProgramFiles%\Cyberlink\Power2Go10|*.tmp
FileKey2=%ProgramFiles%\Cyberlink\Power2Go10|Thumbs.db|RECURSE
FileKey3=%LocalAppData%\Cyberlink\Power2Go10|DLDB.db
FileKey4=%Documents%\PDRMUSIC.TMP|*.*|REMOVESELF
FileKey5=%Music%|*.tmp
FileKey6=%Pictures%|*.tmp
RegKey1=HKCU\SOFTWARE\CyberLink\LabelPrint\Recent File List
RegKey2=HKCU\SOFTWARE\CyberLink\MediaCache\Data4
RegKey3=HKCU\SOFTWARE\CyberLink\MediaCache5\Data5
RegKey4=HKCU\SOFTWARE\CyberLink\MediaCache5\Thumbnail5
RegKey5=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|CDRippingPath
RegKey6=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|CUEName
RegKey7=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|CUEPath
RegKey8=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|DestFolder
RegKey9=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|DVDFolderPath
RegKey10=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|ImagePath
RegKey11=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|LastBrowsePath
RegKey12=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|LastSaveProjPath
RegKey13=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|MonitorPaths
RegKey14=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|OpenPrjFilePath
RegKey15=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0|SelectedFolderPath
RegKey16=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0\MediaObj\MediaCache5\Data5
RegKey17=HKCU\SOFTWARE\CyberLink\Power2Go10\10.0\MediaObj\MediaCache5\Thumbnail5
RegKey18=HKCU\SOFTWARE\CyberLink\WaveEditor\2.0|ImportDir
RegKey19=HKCU\SOFTWARE\CyberLink\WaveEditor\2.0|TempFileDir
RegKey20=HKCU\SOFTWARE\CyberLink\WaveEditor\2.0|WorkDir

[Delivery Optimization Files*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
RegKey1=HKLM\Software\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Jobs
FileKey1=%WinDir%\Logs\dosvc|*.*|RECURSE
FileKey2=%WinDir%\SoftwareDistribution\DeliveryOptimization|*.*|RECURSE

[DRM Traces*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\DRM
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey2=%CommonAppData%\Microsoft\Windows\DRM\PreUpgrade|*.log
FileKey3=%CommonAppData%\Microsoft\Windows\DRM|*.log
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\PreUpgrade|*.log
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM|*.log

[Get Started*]
DetectOS=10.0
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Getstarted_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Getstarted_*\TempState|*.*|RECURSE

[imTOO Video Converter Ultimate*]
LangSecRef=3023
Detect=HKCU\Software\ImTOO\Video Converter Ultimate
Default=False
FileKey1=%CommonAppData%\ImTOO\Video Converter Ultimate\customdata|settings.old
RegKey1=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_openfile_dir
RegKey2=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_output_dir
RegKey3=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_profile_group
RegKey4=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_profile_url
RegKey5=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|recent_profiles
RegKey6=HKCU\Software\ImTOO\Video Converter Ultimate\Settings\output

[Leawo Prof. Media*]
LangSecRef=3023
Detect=HKCU\Software\Leawo Software\SoftwarePassport\Leawo Prof. Media
Default=False
FileKey1=%LocalAppData%\Leawo Prof\cache|*.*|RECURSE
FileKey2=%AppData%\Leawo\Prof. Media\Burn\MenuTemplate\Cache|*.*|RECURSE
FileKey3=%AppData%\Leawo\Prof. Media\Burn|*.log
FileKey4=%AppData%\Leawo\Prof. Media\CrashReport|*.*|RECURSE
FileKey5=%AppData%\Leawo\Prof. Media\Download\Thumbnails|*.*|RECURSE
FileKey6=%AppData%\Leawo\Prof. Media\Download\WebCache|*.*|RECURSE
FileKey7=%AppData%\Leawo\Prof. Media\Download\WebFiles|*.*|RECURSE
FileKey8=%AppData%\Leawo\Prof. Media\Download|*.dat;*.db;*log;*.xml
FileKey9=%AppData%\Leawo\Prof. Media\Log|*.*|RECURSE

[Leawo Video Converter Pro*]
LangSecRef=3023
DetectFile=%AppData%\Leawo\Video Converter Pro
Default=False
FileKey1=%LocalAppData%\Video Converter Pro\cache|*.*|RECURSE
FileKey2=%AppData%\Leawo\Video Converter Pro\CrashReport|*.*|RECURSE
FileKey3=%AppData%\Leawo\Video Converter Pro|*.log

[Lock App*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.LockApp_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.LockApp_*\TempState|*.*|RECURSE

[Maps*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsMaps_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\TempState|*.*|RECURSE

[Movavi Video Converter (Logs)*]
LangSecRef=3023
Detect=HKCU\Software\MOVAVI
Default=False
FileKey1=%LocalAppData%\Movavi\Logs\VideoConverter16\|*.*

[Office 2007 More*]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\12.0\Common
FileKey1=%Documents%|~*.ppt;~*.pptx|RECURSE
FileKey2=%Documents%|~*.doc;~*.docx|RECURSE
RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Internet|UseRWHlinkNavigation
RegKey2=HKCU\Software\Microsoft\Office\12.0\Word\Reading Locations

[Office 2016 More*]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\16.0\Common
Default=False
FileKey1=%Documents%|~*.ppt;~*.pptx|RECURSE
FileKey2=%Documents%|~*.doc;~*.docx|RECURSE
RegKey1=HKCU\Software\Microsoft\Office\16.0\Common\Internet|UseRWHlinkNavigation
RegKey2=HKCU\Software\Microsoft\Office\16.0\Word\Reading Locations

[Orcs Must Die! Unchained Logs*]
LangSecRef=Games
Detect=HKCU\SOFTWARE\Robot Entertainment\Orcs Must Die! Unchained
Default=False
FileKey1=%Documents%\My Games\Orcs Must Die Unchained\SpitfireGame\Logs|*.log;*.dmg;*.dmp|RECURSE

[Panther*]
LangSecRef=3025
DetectFile=%Windir%\Panther
Default=False
FileKey1=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log
FileKey2=%WinDir%\Panther\FastCleanup|*.log
FileKey3=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml
FileKey4=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml

[People*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.People_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.People_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.People_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.People_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.People_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.People_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.People_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.People_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.People_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.People_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.People_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.People_*\TempState|*.*|RECURSE

[Phone*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsPhone_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\TempState|*.*|RECURSE

[QuizUp*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\QuizUp.QuizUp_n36z36qeaxk8a
FileKey1=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey6=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0_32|*.log|RECURSE
FileKey8=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Temp|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalCache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalState\Cache|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\QuizUp.QuizUp_*\TempState|*.*|RECURSE

[sageThumbs Thumbnail Cache*]
LangSecRef=3021
DetectFile=%ProgramFiles%\SageThumbs\64\SageThumbs.dll
Default=False
FileKey1=%LocalAppData%\|SageThumbs.*

[scan*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsScan_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsScan_*\TempState|*.*|RECURSE

[shell Experience Host*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\TempState|*.*|RECURSE

[signature Verification Logs*]
DetectOS=|5.1
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%|SIGVERIF.TXT

[snagit 13*]
LangSecRef=3024
Detect=HKCU\Software\TechSmith\SnagIt\13
Default=False
RegKey1=HKCU\Software\TechSmith\SnagIt\13\Recent Captures
RegKey2=HKCU\Software\TechSmith\SnagIt\13\SnagItEditor\Recent File List
FileKey1=%LocalAppData%\TechSmith\SnagIt|Tray.bin
FileKey2=%LocalAppData%\TechSmith\SnagIt\DataStore\AppIcons|*.ico
FileKey3=%LocalAppData%\TechSmith\SnagIt\DataStore\WebSiteIcons|*.ico
FileKey4=%LocalAppData%\TechSmith\SnagIt\Thumbnails|*.*

[snagit 12/13 Local Dumps*]
LangSecRef=3024
Detect1=HKCU\Software\TechSmith\SnagIt\12
Detect2=HKCU\Software\TechSmith\SnagIt\13
Default=False
FileKey1=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*

[snagit 12/13 More*]
LangSecRef=3024
Detect1=HKCU\Software\TechSmith\SnagIt\12
Detect2=HKCU\Software\TechSmith\SnagIt\13
Default=False
Warning=This will delete the backups of the captures that you have performed with SnagIt 12/13.
FileKey1=%LocalAppData%\TechSmith\Snagit\DataStore|*.SNAG;*.SNAGundo;*.MP4
FileKey2=%Documents%\|SnagItDebug.log
FileKey3=%LocalAppData%\TechSmith\Logs\|*.log
RegKey1=HKCU\Software\TechSmith\Snagit\12|CaptureCount
RegKey2=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder

[sound Recorder*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\TempState|*.*|RECURSE

[startup Repair Logs*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\System32\LogFiles\Srt|*.*|RECURSE

[sway*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.Sway_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Office.Sway_*\TempState|*.*|RECURSE

[WDI Logs*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\System32\WDI\{*}|*.*|REMOVESELF
FileKey2=%WinDir%\System32\WDI\LogFiles\StartupInfo|*.*|RECURSE

[Wondershare AllMyTube*]
LangSecRef=3022
Detect1=HKLM\SOFTWARE\Wondershare\Wondershare AllMyTube
Detect2=HKLM\SOFTWARE\WOW6432Node\Wondershare\Wondershare AllMyTube
Default=False
FileKey1=%ProgramFiles%\Wondershare\AllMyTube\Log|*.*|RECURSE
FileKey2=%CommonAppData%\Wondershare\AllMyTube|*.bak
FileKey3=%CommonAppData%\Wondershare AllMyTube\ConvertedLibPic|*.*|RECURSE
FileKey4=%CommonAppData%\Wondershare AllMyTube|*.xml
FileKey5=%CommonAppData%\Wondershare Application Common Data\Download\MediaLibPic|*.*|RECURSE
FileKey6=%CommonAppData%\Wondershare Application Common Data\Download\SiteLogo|*.*|RECURSE
FileKey7=%CommonAppData%\Wondershare Application Common Data\Download\TempThumbDir|*.*|RECURSE
FileKey8=%CommonAppData%\Wondershare Application Common Data\Download|*.bak;*.xml
FileKey9=%AppData%\Wondershare AllMyTube|*.*|RECURSE

[Wondershare MobileGo*]
LangSecRef=3021
Detect=HKCU\SOFTWARE\Wondershare\MobileGo
Default=False
FileKey1=%ProgramFiles%\Wondershare\MobileGo|*.log
FileKey2=%CommonAppData%\Wondershare\Dr.FoneTool\Log|*.txt
FileKey3=%CommonAppData%\Wondershare\WAF\ProductFeatures\LocalLogs|*.*|RECURSE
FileKey4=%CommonAppData%\Wondershare\WAF\ProductFeatures\RemoteLogs|*.*|RECURSE
FileKey5=%AppData%\se_tmp|*.*|REMOVESELF
FileKey6=%AppData%\Wondershare\DataEraser|*.log
FileKey7=%AppData%\Wondershare\Dr.FoneTool\log|*.log
FileKey8=%AppData%\Wondershare\DrFoneAndroidTool\log|*.log
FileKey9=%AppData%\Wondershare\MirrorGo\ImageCache\ADImage|*.*|RECURSE
FileKey10=%AppData%\Wondershare\MirrorGo|*.log
FileKey11=%AppData%\Wondershare\MobileGo|*.log
FileKey12=%AppData%\Wondershare\MobileGo\DeviceImageCache|*.*|RECURSE
FileKey13=%AppData%\Wondershare\MobileGo\iOSTemp|*.*|REMOVESELF
FileKey14=%AppData%\Wondershare\MobileGo\Logs\DeviceConnection|*.*|RECURSE
FileKey15=%AppData%\Wondershare\MobileTransTool|*.log
FileKey16=%AppData%\Wondershare\WsRoot\Logs|*.*|RECURSE

[Xilisoft Video Converter Ultimate*]
LangSecRef=3023
Detect=HKCU\Software\Xilisoft\Video Converter Ultimate
Default=False
RegKey1=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings|last_openfile_dir
RegKey2=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings|last_output_dir
RegKey3=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings|last_profile_group
RegKey4=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings|last_profile_url
RegKey5=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings|recent_profiles
RegKey6=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings\output
FileKey1=%CommonAppData%\Xilisoft\Video Converter Ultimate\customdata|settings.old

------------------------------------------------------------------------------

Modified Entries:

[Action Center*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Notifications\Current

- Added FileKey1, RegKey3

[Auslogics Disk Defrag Portable*]
LangSecRef=3024
Detect1=HKCU\Software\Auslogics\Disk Defrag Portable
Detect2=HKLM\Software\Auslogics\DiskDefrag Portable
Detect3=HKLM\Software\Auslogics\Disk Defrag Portable
Default=False
FileKey1=%AppData%\Auslogics\Disk Defrag\Reports|*.*
FileKey2=%AppData%\Auslogics\Disk Defrag\Logs|*.*
FileKey3=%CommonAppData%\Auslogics\DiskDefrag Portable\*\Reports|*.*
FileKey4=%CommonAppData%\Auslogics\Disk Defrag Portable\*\Reports|*.*

- Added Detect3, FileKey4

[bing Finance More*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingFinance_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingFinance_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingFinance_*\TempState|*.*|RECURSE

-Added FileKeys 4 and 5

[bing News More*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingNews_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\PRICache|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingNews_*\LocalState\navigationHistory|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe\SearchHistory

- Added FileKeys3 and 4

[bing Sports More*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingSports_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingSports_*\LocalState\navigationHistory|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingSports_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe\SearchHistory

- Added FileKeys4 and 5

[bing Weather*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingWeather_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log
FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp
FileKey13=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory

- Added FileKey11

[Camera*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsCamera_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Camera_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.Camera_*\AC\PRICache|*.*
FileKey9=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Temp|*.*
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\AppCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetCache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetCookies|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Temp|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalCache|*.*|RECURSE
FileKey19=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\AppData|*.*|RECURSE
FileKey20=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\Cache|*.*|RECURSE
FileKey21=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe\SearchHistory

- Added Detect2, FileKeys10 through 21

[Cloud Experience Host*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\TempState|*.*|RECURSE

- Added FileKey1

[Cortana*]
Section=3031
Default=False
Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Cortana_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Cortana_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Cortana_*\TempState|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\AppCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetCache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetCookies|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Temp|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey19=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalCache|*.*|RECURSE
FileKey20=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\Cache|*.*|RECURSE
FileKey21=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\AppIconCache|*.*|RECURSE
FileKey22=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache|*.*|RECURSE
FileKey23=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\TempState|*.*|RECURSE

- Added FileKeys 10,21,22

[CyberLink PowerDirector 13*]
LangSecRef=3023
Detect=HKCU\Software\CyberLink\PowerDirector13
Default=False
FileKey1=%AppData%\CyberLink\PowerDirector\13.0\AutoSave|*.*|RECURSE
FileKey2=%AppData%\CyberLink\PowerDirector\13.0\photoTmp|*.*|RECURSE
FileKey3=%AppData%\Cyberlink\PowerDirector\13.0\WaveForms|*.*|RECURSE
FileKey4=%AppData%\Cyberlink\PowerDirector\13.0|Recentfiles.ini
FileKey5=%Documents%\CyberLink\PowerDirector\13.0|Snapshot(*).jpg
FileKey6=%Documents%\CyberLink\PowerDirector\13.0\MyTitles|*.*|RECURSE
FileKey7=%Documents%\Cyberlink\PowerDirector\13.0\PDRMUSIC.TMP|*.*|REMOVESELF
FileKey8=%Documents%\Cyberlink\PowerDirector\13.0\PP.TWOPASS|*.*|REMOVESELF
FileKey9=%Documents%\CyberLink\PowerDirector\13.0\Preview Cache Files|*.*
FileKey10=%Documents%\CyberLink\PowerDirector\13.0\ShadowEditFiles|*.MPG
FileKey11=%Documents%\CyberLink\PowerDirector\13.0\SplitterIndex|*.maidx
RegKey1=HKCU\Software\CyberLink\Hanuman
RegKey2=HKCU\Software\CyberLink\PowerDirector13\MediaObj\MediaCache5\Data5
RegKey3=HKCU\Software\CyberLink\PowerDirector13\MediaObj\MediaCache5\Thumbnail5

- Added FileKey7,8

[Diagnostics Logs*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\debug\WIA|*.log

- Switched to Wildcard cleaning

[Kaspersky*]
LangSecRef=3024
Detect=HKCU\Software\KasperskyLab
Default=False
Warning=Make sure to disable “Self Defense” before cleaning.
FileKey1=%CommonAppData%\Kaspersky Lab\*\Bases\Cache|*.*|RECURSE
FileKey2=%CommonAppData%\Kaspersky Lab\*\Data\Updater\Temporary Files|*.*|RECURSE
FileKey3=%CommonAppData%\Kaspersky Lab\*\Temp|*.*
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Bases\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Data\Updater\Temporary Files|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Temp|*.*
FileKey7=%ProgramFiles%\Kaspersky Lab\NetworkAgent\~dumps|*.*

- Added FileKey7

[Leawo Video Converter*]
LangSecRef=3023
DetectFile=%AppData%\Leawo\Video Converter
Default=False
FileKey1=%LocalAppData%\Video Converter\cache|*.*|RECURSE
FileKey2=%AppData%\Leawo\Video Converter\CrashReport|*.*|RECURSE
FileKey3=%AppData%\Leawo\Video Converter|*.log

- Added FileKey1,2

[Office 2010 More*]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\14.0\Common
Default=False
FileKey1=%LocalAppData%\Microsoft\Office\14.0\OfficeFileCache|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Office\14.0|OneNoteOfflineCache.onecache
FileKey3=%LocalAppData%\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files|*.*|RECURSE
FileKey4=%Documents%|~*.ppt;~*.pptx|RECURSE
FileKey5=%Documents%|~*.doc;~*.docx|RECURSE
RegKey1=HKCU\Software\Microsoft\Office\14.0\Common\Internet|UseRWHlinkNavigation
RegKey2=HKCU\Software\Microsoft\Office\14.0\Word\Reading Locations

- Added FileKeys1,4,5, RegKeys1,2

[Office 2013 More*]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\15.0\Common
Default=False
FileKey1=%LocalAppData%\Microsoft\Office\15.0\OfficeFileCache|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Office\15.0|OneNoteOfflineCache.onecache
FileKey3=%LocalAppData%\Microsoft\OneNote\15.0\OneNoteOfflineCache_Files|*.*|RECURSE
FileKey4=%Documents%|~*.ppt;~*.pptx|RECURSE
FileKey5=%Documents%|~*.doc;~*.docx|RECURSE
RegKey1=HKCU\Software\Microsoft\Office\15.0\Common\Internet|UseRWHlinkNavigation
RegKey2=HKCU\Software\Microsoft\Office\15.0\Word\Reading Locations

- Added FileKeys 1,4,5, regKeys1,2

[OneNote*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local|msodata*.dat
FileKey9=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\OTele|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\office15client.microsoft.com|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0\OneNoteOfflineCache_Files|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0\OneNotePagePreviewCache_Files|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0|*.onecache
FileKey15=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe\SearchHistory

- Added FileKeys7, 10

[Plex Media Server*]
LangSecRef=3023
Detect=HKCU\Software\Plex, Inc.\Plex Media Server
Default=False
FileKey1=%ProgramFiles%\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey2=%LocalAppData%\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey3=%LocalAppData%\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey4=%LocalAppData%\Plex Media Server\Logs|*.*|RECURSE
FileKey5=%LocalAppData%\Plex Media Server\Updates|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Logs|*.*|RECURSE
FileKey10=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Updates|*.*|RECURSE

- Added FileKeys2,5,7,10

[VoidTools Search Everything*]
LangSecRef=3024
DetectFile1=%ProgramFiles%\Everything
DetectFile2=%AppData%\Everything
Default=False
FileKey1=%AppData%\Everything|*.csv;*.txt;*.tmp
FileKey2=%ProgramFiles%\Everything|*.csv;*.txt;*.tmp
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Everything|*.txt;*.csv;*.tmp
ExcludeKey1=FILE|%AppData%\Everything\Filters.csv
ExcludeKey2=FILE|%ProgramFiles%\Everything\Filters.csv
ExcludeKey3=FILE|%LocalAppData%\VirtualStore\Program Files*\Everything\Filters.csv

- Added tmp file cleaning

[WebSite-Watcher*]
LangSecRef=3021
Detect=HKCU\Software\aignes\wswatch
Default=False
FileKey1=%AppData%\aignes\WebSite-Watcher\config\favicons|*.*
FileKey2=%AppData%\aignes\WebSite-Watcher\config\settings|*.cfg_bak*

- Removed lines included in other entries

[Windows Communications Apps*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Comms\Temp|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\AppCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\PRICache|*.*
FileKey11=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*
FileKey12=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\LiveComm\*\*\DBStore\LogFiles|edbtmp.log
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory

- Added FileKey1

[Windows Defender More*]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows Defender
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows Defender\Definition Updates\Backup|*.*|RECURSE
FileKey2=%CommonAppData%\Microsoft\Windows Defender\LocalCopy|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\Windows Defender\Network Inspection System\Support|*.txt
FileKey4=%CommonAppData%\Microsoft\Windows Defender\Scans|*.bin;*.bin*
FileKey5=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Service|*.log
FileKey6=%CommonAppData%\Microsoft\Windows Defender\Scans\Scans\History\CacheManager|*.*|RECURSE
FileKey7=%CommonAppData%\Microsoft\Windows Defender\Support|*.*|RECURSE

- Added FileKey2

[Xbox Identity Provider*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxIdentityProvider_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0|*.log
FileKey5=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32|*.log
FileKey8=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalCache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalState\Cache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\TempState|*.*|RECURSE

- Added FileKey6.9

[XboxApp*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxApp_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log;*.log*
FileKey10=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log
FileKey12=%LocalAppData%\Packages\Microsoft.XboxApp_*\TempState|*.*|RECURSE

- Added FileKeys9,11

[Zune Music*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\PRICache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageCache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\PlayReady|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\SearchHistory

- Added FileKey11

[Zune Video*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\PRICache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageCache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\PlayReady|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\TempState|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Database\anonymous|*.log
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe\SearchHistory

- Added FileKey11

------------------------------------------------------------------------------
Removed Entries:

[CyberLink PowerToGo9*]
LangSecRef=3024
Detect=HKCU\Software\CyberLink\Power2Go9
Default=False
FileKey1=%ProgramFiles%\Cyberlink\Power2Go9\Template\Cyberlink\frame|*.tmp

- Replaced by new entry

[CyberLink Youcam Installation Files*]
LangSecRef=3023
Detect=HKCU\Software\CyberLink\YouCam
Default=False
FileKey1=%CommonAppData%\install_clap|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\ProgramData\install_clap|*.*|REMOVESELF

- Duplicate

[DRM Cache*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\DRM
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\Cache|*.*|RECURSE

- Replaced by DRM Traces

[Log Files More*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\inf|*.log*
FileKey2=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log
FileKey3=%WinDir%\winsxs|poqexec.log
FileKey4=%WinDir%\debug\WIA|*.log
FileKey5=%WinDir%|SIGVERIF.TXT
FileKey6=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml
FileKey7=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml
FileKey8=%WinDir%\Panther\FastCleanup|*.log

- Broken into multiple more concise entries

[MS Office PowerPoint More*]
LangSecRef=3021
Detect1=HKCU\Software\Microsoft\Office\12.0
Detect2=HKCU\Software\Microsoft\Office\14.0
Detect3=HKCU\Software\Microsoft\Office\15.0
Detect4=HKCU\Software\Microsoft\Office\16.0
Default=False
RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Internet|UseRWHlinkNavigation
RegKey2=HKCU\Software\Microsoft\Office\14.0\Common\Internet|UseRWHlinkNavigation
RegKey3=HKCU\Software\Microsoft\Office\15.0\Common\Internet|UseRWHlinkNavigation
RegKey4=HKCU\Software\Microsoft\Office\16.0\Common\Internet|UseRWHlinkNavigation
FileKey1=%Documents%|~*.ppt;~*.pptx|RECURSE

- Merged into new office entries

[MS Office Word More*]
LangSecRef=3021
Detect1=HKCU\Software\Microsoft\Office\12.0
Detect2=HKCU\Software\Microsoft\Office\14.0
Detect3=HKCU\Software\Microsoft\Office\15.0
Detect4=HKCU\Software\Microsoft\Office\16.0
Default=False
RegKey1=HKCU\Software\Microsoft\Office\15.0\Word\Reading Locations
RegKey2=HKCU\Software\Microsoft\Office\16.0\Word\Reading Locations
FileKey1=%Documents%|~*.doc;~*.docx|RECURSE

- Merged into new Office entries

[Panther*]
LangSecRef=3025
DetectFile=%Windir%\Panther
Warning=The Windows\Panther directory is used during a Windows version upgrade. Following the upgrade, this directory can be safely removed.
Default=False
FileKey1=%Windir%\Panther\|*.*|REMOVESELF

- Replaced by new Panther entry

------------------------------------------------------------------------------

 

 

 

Link to comment
Share on other sites

New Entry:  [Core Temp Logs**]

[Core Temp Logs*]
LangSecRef=3024
DetectFile=%ProgramFiles%\Core Temp
Default=False
FileKey1=%ProgramFiles%\Core Temp\|*.csv

Windows 10 x64 Pro on ASUS Maximus VIII Extreme motherboard, i7-6700k CPU,H220 X2 Liquid Cooler, 64 gbyte RipJaws DDR4 3200 RAM, Samsung 970 Pro NVMe M.2 500 gbyte SSD + Samsung 850 Pro 512 gbyte SSD, EVGA RTX 3060 Titan graphics card (Home Built System);  Windows 11x64 Pro on 512 gigabyte Dell XPS 15 2-in-1 Laptop/tablet and Dell XPS 8940 PC.  ASUS RT-AC88U router, 14 tbyte WD My Cloud PR2100 NAS Server, 200 Mbps cable Internet, MS Edge Chromium, MS Office 2021 (Local), Casper 11, DisplayFusion (3 Flat Panel Displays per system):   Latest Bitdefender Internet Security, Quicken, Weather Watcher Live, ThumbsPlus 10, Sticky Password 8, WD Smartware, CyberLink PowerDVD23, MSI AfterBurner, Rainmeter, 8GadgetPack, and many more.

Link to comment
Share on other sites

New Entries:  [Avira System Speedup Logs*] and [Avira System Speedup Error Reports*]

[Avira System Speedup Logs*]
LangSecRef=3024
Detect=HKLM\Software\AviraSpeedup
Default=False
FileKey1=%CommonAppData%\Avira\SystemSpeedup\Logs\|*.*

[Avira System Speedup Error Reports*]
LangSecRef=3024
Detect=HKLM\Software\AviraSpeedup
Default=False
FileKey1=%CommonAppData%\Avira\SystemSpeedup\Errors\|*.*

Windows 10 x64 Pro on ASUS Maximus VIII Extreme motherboard, i7-6700k CPU,H220 X2 Liquid Cooler, 64 gbyte RipJaws DDR4 3200 RAM, Samsung 970 Pro NVMe M.2 500 gbyte SSD + Samsung 850 Pro 512 gbyte SSD, EVGA RTX 3060 Titan graphics card (Home Built System);  Windows 11x64 Pro on 512 gigabyte Dell XPS 15 2-in-1 Laptop/tablet and Dell XPS 8940 PC.  ASUS RT-AC88U router, 14 tbyte WD My Cloud PR2100 NAS Server, 200 Mbps cable Internet, MS Edge Chromium, MS Office 2021 (Local), Casper 11, DisplayFusion (3 Flat Panel Displays per system):   Latest Bitdefender Internet Security, Quicken, Weather Watcher Live, ThumbsPlus 10, Sticky Password 8, WD Smartware, CyberLink PowerDVD23, MSI AfterBurner, Rainmeter, 8GadgetPack, and many more.

Link to comment
Share on other sites



[NVIDIA GFExperience Updates*]
LangSecRef=3024
DetectFile=%CommonAppData%\NVIDIA Corporation\GeForce Experience
Default=False
FileKey1=%CommonAppData%\NVIDIA\Updatus\DownloadManager|*.*
FileKey2=%CommonAppData%\NVIDIA\NvBackend\Updatus\DownloadManager|*.*
FileKey3=%CommonAppData%\NVIDIA Corporation\NetService|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\NVIDIA\Updatus\DownloadManager|*.*
FileKey5=%LocalAppData%\VirtualStore\ProgramData\NVIDIA\NvBackend\Updatus\DownloadManager|*.*
FileKey6=%LocalAppData%\VirtualStore\ProgramData\NVIDIA Corporation\NetService|*.*|RECURSE
FileKey7=%CommonAppData%\NVIDIA Corporation\GeForce Experience\Update|*.*|RECURSE

add filekey 7 new place when you use GFEXP ...

[Syncthing*]
LangSecRef=3022
DetectFile=%LocalAppData%\Syncthing
Default=False
FileKey1=%LocalAppData%\Syncthing|*.log

new

 

 

Please rename to sort them in the right posistion:

 

[AntiVir Desktop IPM*]

to

[Avira AntiVir Desktop IPM*]

 

[AntiVir Desktop REPORTS*]

also

[Avira AntiVir Desktop REPORTS*]

 

 

new:


[Avira Phantom VPN Logs*]
LangSecRef=3024
DetectFile=%CommonAppData%\Avira\VPN
Default=False
FileKey1=%CommonAppData%\Avira\VPN|*.log
Link to comment
Share on other sites

  • 3 weeks later...

Righty-o. Update coming, I'm doing some styling cleanup on the definitions (alphabetization of keys) and will be through with it tonight (the 22nd). Just some tidying before moving to github :)

 

I know it has been discussed before, but what are thoughts on merging entries for different versions of softwares. Currently we don't have a convention. Some applications have both individual and shared versioning (eg. 12/13 local dumps, 12/13 More, but 11 More is its own entry)? Compatible paths that hold only a different version number could be easily dealt with using wildcards, and for most applications, users aren't running multiple versions side-by-side (while also wanting individual control over the clean-up for them)

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.