Jump to content
CCleaner Community Forums
Winapp2.ini

Winapp2.ini additions

Recommended Posts

Can you add support of Eraser 6 ?

 

[Eraser 6*]
LangSecRef=3024
Detect=HKCU\Software\Eraser\Eraser 6
Default=False
FileKey1=%ProgramFiles%\Eraser|schedlog.txt
FileKey2=%LocalAppData%\Eraser 6\Logs|*.log

Share this post


Link to post
Share on other sites

Would "Store Extras*" be acceptable?

 

Anyways, what I meant by what I was saying was that, since I am not usually logged in, it isn't a problem for my system. That's why I recommended moving to a different entry and add a warning. I mean this is kind of the samething with removing passwords in FireFox/Chrome/Edge/IE/etc (yes I know you said unlike websites).

Your point is valid. I think we should keep that entry as it.

Share this post


Link to post
Share on other sites

Can you add support of Eraser 6 ?

 

[Eraser 6*]

LangSecRef=3024

Detect=HKCU\Software\Eraser\Eraser 6

Default=False

FileKey1=%ProgramFiles%\Eraser|schedlog.txt

FileKey2=%LocalAppData%\Eraser 6\Logs|*.log

 

I think we can just combine this with this entry:

 

[Eraser*]

LangSecRef=3024

Detect=HKCU\Software\Heidi Computers Ltd\Eraser\5.5

Default=False

FileKey1=%ProgramFiles%\Eraser|schedlog.txt

FileKey2=%LocalAppData%\VirtualStore\Program Files*\Eraser|schedlog.txt

Share this post


Link to post
Share on other sites

[Xilisoft Video Converter Ultimate*] should be removed as it is included in the latest version (5.21) of CCleaner. By the way, there are two [Xilisoft Video Converter Ultimate*] entries in Winapp2.ini.

 

 

 

 

Share this post


Link to post
Share on other sites

Speaking of duplicates, these entries are all duplicated:

[Polarity Cache*]LangSecRef=3022DetectFile=%ProgramFiles%\PolarityDefault=FalseFileKey1=%AppData%\Stanley Lim\Polarity\Cache|*.*|RECURSE[Polarity Cache*]Section=BrowsersDetectFile=%ProgramFiles%\PolarityDefault=FalseFileKey1=%AppData%\Stanley Lim\Polarity\Cache|*.*|RECURSE[Polarity Favicon*]Section=BrowsersDetectFile=%ProgramFiles%\PolarityDefault=False[Polarity Favicon*]LangSecRef=3022DetectFile=%ProgramFiles%\PolarityDefault=False[Polarity History*]LangSecRef=3022DetectFile=%ProgramFiles%\PolarityDefault=FalseFileKey1=%UserProfile%\Polarity_Config|history_times.ini;savedTabs.ini;history.ini;history_names.ini;history_times.ini;downloads_urls.ini;downloads_times.ini;downloads_names.ini;[Polarity History*]Section=BrowsersDetectFile=%ProgramFiles%\PolarityDefault=FalseFileKey1=%UserProfile%\Polarity_Config|history_times.ini;savedTabs.ini;history.ini;history_names.ini;history_times.ini;downloads_urls.ini;downloads_times.ini;downloads_names.ini;

I just don't know which section is the proper one to use.

 

EDIT: I just realised the "Polarity Favicon*" don't even have FileKeys to them. Weird...

Share this post


Link to post
Share on other sites
[Malwarebytes Anti-Exploit*]LangSecRef=3024DetectFile=%CommonAppData%\Malwarebytes\Malwarebytes Anti-ExploitDefault=FalseFileKey1=%CommonAppData%\Malwarebytes\Malwarebytes Anti-Exploit|*.logFileKey2=%LocalAppData%\VirtualStore\ProgramData\Malwarebytes\Malwarebytes Anti-Exploit|*.log

FileKey1 doesn't exist on my system. Also, I think we can just combine this entry with this one:

[Malwarebytes Anti-Exploit Logs*]LangSecRef=3024Detect=HKLM\SYSTEM\CurrentControlSet\Services\MbaeSvcDefault=FalseFileKey1=%CommonAppData%\Malwarebytes Anti-Exploit\|*.LogFileKey2=%ProgramFiles%\Malwarebytes Anti-Exploit\|mbae-uninstall.log;changelog.txt

Share this post


Link to post
Share on other sites

https://github.com/MoscaDotTo/Winapp2/

 

The "ccleaner-less version is in the works, I haven't updated this against the newest version of CCleaner (5.21) just yet but that's the beauty of github, eh? :)

 

Everything in the above link is current as far as this thread is concerned though.

 

I haven't updated winapp2.com to reflect the move to GitHub just yet either, but I will soon

Share this post


Link to post
Share on other sites

 

[Polarity Favicon*]

LangSecRef=3022DetectFile=%ProgramFiles%\PolarityDefault=False

EDIT: I just realised the "Polarity Favicon*" don't even have FileKeys to them. Weird...

Well isn't that a useful entry :lol:

Share this post


Link to post
Share on other sites

It appears this forums isn't plain text friendly. I tried spacing these out, but it shows them like that.

Using code tags is the best way to post winapp2 entries like that.

Share this post


Link to post
Share on other sites

Modified entry:  [LastGood.Tmp Folder*]


Removed: DetectFile=%SystemDrive%\LastGood.tmp so that this entry shows up when using a Trim.bat even if a LastGood.tmp folder is NOT present at the time the Trim.bat is executed.  The reason is that a very large LastGood.Tmp folder could be "store on %Windir%" at any time when updating Windows after the Trim.bat is utilized.



[LastGood.tmp Folder*]
LangSecRef=3025
Default=False
FileKey1=%WinDir%\LastGood.tmp|*.*|REMOVESELF

Share this post


Link to post
Share on other sites

https://github.com/MoscaDotTo/Winapp2/

 

The "ccleaner-less version is in the works, I haven't updated this against the newest version of CCleaner (5.21) just yet but that's the beauty of github, eh? :)

 

Everything in the above link is current as far as this thread is concerned though.

 

I haven't updated winapp2.com to reflect the move to GitHub just yet either, but I will soon

 

Nice. Starred and have it set to watch.

Share this post


Link to post
Share on other sites

Share this post


Link to post
Share on other sites

Modified Entry

Added for newer version of office and updated Detect to only show when Outlook is install as not all office installs contain Outlook. Updated to actually remove keys as there was typo in previous version 

 

 

[Outlook Appointment Location MRU*]
LangSecRef=3021
Detect1=HKCU\Software\Microsoft\Office\9.0\Outlook
Detect2=HKCU\Software\Microsoft\Office\11.0\Outlook
Detect3=HKCU\Software\Microsoft\Office\12.0\Outlook
Detect4=HKCU\Software\Microsoft\Office\14.0\Outlook
Detect5=HKCU\Software\Microsoft\Office\15.0\Outlook
Detect6=HKCU\Software\Microsoft\Office\16.0\Outlook
Warning=This Will Remove the Most Frequent Appointment Locations from all Outlook Versions.
Default=False
RegKey1=HKCU\Software\Microsoft\Office\9.0\Outlook\Preferences|LocationMRU
RegKey2=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
RegKey3=HKCU\Software\Microsoft\Office\12.0\Outlook\Preferences|LocationMRU
RegKey4=HKCU\Software\Microsoft\Office\14.0\Outlook\Preferences|LocationMRU
RegKey5=HKCU\Software\Microsoft\Office\15.0\Outlook\Preferences|LocationMRU
RegKey6=HKCU\Software\Microsoft\Office\16.0\Outlook\Preferences|LocationMRU

Share this post


Link to post
Share on other sites

Thanks for the update!

 

Typo: [360 Browser - Cache*] - FileKey3 has no equality sign (=).

 

The new file has UNIX + UTF-8 format which causes some problems: Windows Notepad does not recognize the UNIX line breaks. And CCleaner does not like UTF-8 because special chars are displayed wrong (for example: "Dr. Despicable’s Dastardly Deeds*" is shown as "Dr. Despicable’s Dastardly Deeds*"). I think this will affect Detect/FileKey/RegKey also, therefore the file should be DOS/Win + ANSI format.

Share this post


Link to post
Share on other sites

Is th

 

Thanks for the update!

 

Typo: [360 Browser - Cache*] - FileKey3 has no equality sign (=).

 

The new file has UNIX + UTF-8 format which causes some problems: Windows Notepad does not recognize the UNIX line breaks. And CCleaner does not like UTF-8 because special chars are displayed wrong (for example: "Dr. Despicable’s Dastardly Deeds*" is shown as "Dr. Despicable’s Dastardly Deeds*"). I think this will affect Detect/FileKey/RegKey also, therefore the file should be DOS/Win + ANSI format.

Try using the direct link: https://raw.githubusercontent.com/MoscaDotTo/Winapp2/master/Winapp2.ini

 

You may find it easier to copy/paste the page content over an existing instance of winapp2.ini. I will try to keep the one on Winapp2.com updated as a fallback if there's no reasonable fix through GitHub for this issue

Share this post


Link to post
Share on other sites

Try using the direct link: https://raw.githubusercontent.com/MoscaDotTo/Winapp2/master/Winapp2.ini

 

You may find it easier to copy/paste the page content over an existing instance of winapp2.ini. I will try to keep the one on Winapp2.com updated as a fallback if there's no reasonable fix through GitHub for this issue

Unfortunately downloading using the direct link does not help. But Copy & Paste works flawless.

 

I prefer using "Notepad++" to convert the downloaded file (Encoding > Convert to ANSI, Edit > EOL Conversion > Convert to Windows Format).

Share this post


Link to post
Share on other sites

Revised Entries

 

[MUICache*]
DetectOS=6.1|
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache

Changed the Detect from HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell to HKCU\Software\Microsoft\Windows
Corrected RegKey1

[Stored Explorer View Settings*]
DetectOS=6.1|
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This will delete window size, window position and view setting of all folders.
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags

Changed entry name from [shellBags*] to [stored Explorer View Settings*]
Changed the Detect from HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell to HKCU\Software\Microsoft\Windows
Corrected RegKey1 and RegKey

Share this post


Link to post
Share on other sites

Revised Entry

 

[MS Search More*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Warning=It could stop Indexing for IE
Default=False
FileKey1=%CommonAppData%\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey2=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey4=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
RegKey1=HKLM\SOFTWARE\Microsoft\Windows Search\VolumeInfoCache

Removed DetectOS=

Changed the Warning from "Can cause major issues with IE on Windows 10" to "It could stop Indexing for IE".

Share this post


Link to post
Share on other sites

 

Modified Entry

Added for newer version of office and updated Detect to only show when Outlook is install as not all office installs contain Outlook. Updated to actually remove keys as there was typo in previous version 

 

 

[Outlook Appointment Location MRU*]
LangSecRef=3021
Detect1=HKCU\Software\Microsoft\Office\9.0\Outlook
Detect2=HKCU\Software\Microsoft\Office\11.0\Outlook
Detect3=HKCU\Software\Microsoft\Office\12.0\Outlook
Detect4=HKCU\Software\Microsoft\Office\14.0\Outlook
Detect5=HKCU\Software\Microsoft\Office\15.0\Outlook
Detect6=HKCU\Software\Microsoft\Office\16.0\Outlook
Warning=This Will Remove the Most Frequent Appointment Locations from all Outlook Versions.
Default=False
RegKey1=HKCU\Software\Microsoft\Office\9.0\Outlook\Preferences|LocationMRU
RegKey2=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
RegKey3=HKCU\Software\Microsoft\Office\12.0\Outlook\Preferences|LocationMRU
RegKey4=HKCU\Software\Microsoft\Office\14.0\Outlook\Preferences|LocationMRU
RegKey5=HKCU\Software\Microsoft\Office\15.0\Outlook\Preferences|LocationMRU
RegKey6=HKCU\Software\Microsoft\Office\16.0\Outlook\Preferences|LocationMRU

 

 

How about if we change the name to [Outlook Appointment Location*]?

Share this post


Link to post
Share on other sites

Having an issue with something in [Coranta*] on Windows 10 Anniversary Update..

 

After cleaning Cortana* the start menu search will only find programs if I type in the full program name: firefox.exe, powershell.exe, notepad.exe etc.
If I type just the first couple letters I only get results for Documents and Settings.

I can duplicate it by: Cleaning [Cortana*], restart explorer.exe in task manager (or reboot), then searching.
 

To fix broken search I use this powershell script:

Get-AppXPackage -AllUsers | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register "$($_.InstallLocation)\AppXManifest.xml"}

I do have Cortana turned off in Group Policy. Having it on seems to temporary break it but it automatically fixes itself.

Share this post


Link to post
Share on other sites

Can you post a change log up for the last update so we can see what got added and removed, etc?

this should be approximately accurate but it may be missing a few items

 

 

 

New Entries:

[Avira Phantom VPN Logs*]

LangSecRef=3024

DetectFile=%CommonAppData%\Avira\VPN

Default=False

FileKey1=%CommonAppData%\Avira\VPN|*.log

[Avira System Speedup Logs*]

LangSecRef=3024

Detect=HKLM\Software\AviraSpeedup

Default=False

FileKey1=%CommonAppData%\Avira\SystemSpeedup\Logs\|*.*

FileKey2=%LocalAppData%\AviraSpeedup\logs\|*.*

[Core Temp Logs*]

LangSecRef=3024

DetectFile=%ProgramFiles%\Core Temp

Default=False

FileKey1=%ProgramFiles%\Core Temp\|*.csv

[CorelDRAW Graphics Suite X7*]

LangSecRef=3021

Detect=HKCU\SOFTWARE\Corel\CorelDRAW\17.0

Default=False

FileKey1=%ProgramFiles%\Corel\CorelDRAW Graphics Suite X7\Setup|*.*|REMOVESELF

FileKey2=%CommonAppData%\Bitstream\Font Navigator\6.0\Cache|*.*|RECURSE

FileKey3=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw\Export|dialog.export.web.xml

FileKey4=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw\Presets\HTML Export|default.pst

FileKey5=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Config|corelpdf.ini

FileKey6=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw|FindAndReplaceMRU.xml

FileKey7=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw\PreviewCache|*.*|RECURSE

FileKey8=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Connect|Connect.config

FileKey9=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Config|corelpdf.ini

FileKey10=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\PHOTO-PAINT\PreviewCache|*.*|RECURSE

FileKey11=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Config|capture.ini

RegKey1=HKCU\Software\Bitstream\Font Navigator\6.0\Copy|Folders

RegKey2=HKCU\Software\Bitstream\Font Navigator\6.0\Move|Folders

RegKey3=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\Directories|DrawDocsDir

RegKey4=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\Framework|RecentFiles

RegKey5=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\HTML Export|DestPath

RegKey6=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\NewFromTemplate|BrowseTemplateDir

RegKey7=HKCU\Software\Corel\CorelDRAW\17.0\PHOTO-PAINT\Application Preferences\Framework|RecentFiles

[Foxit PhantomPDF 8*]

LangSecRef=3021

Detect=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0

Default=False

FileKey1=%LocalAppData%\Foxit PhantomPDF\msilog|*.log

FileKey2=%AppData%\Foxit Software\Foxit PhantomPDF\FormFiller|AutoComplete.ds

FileKey3=%AppData%\Foxit Software\RMS|FXRMS_Log.txt

RegKey1=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\MRU\File MRU

RegKey2=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\MRU\Place MRU

RegKey3=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Preferences\History

RegKey4=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Recent File List

RegKey5=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Foxit PhantomPDF Advanced Editor\Recent File List

[Kodi Crash Logs*]

LangSecRef=3023

DetectFile=%AppData%\kodi

Default=False

FileKey1=%AppData%\kodi|*.dmp

[Kodi Logs*]

LangSecRef=3023

DetectFile=%AppData%\kodi

Default=False

FileKey1=%AppData%\kodi|*.log

[syncthing*]

LangSecRef=3022

DetectFile=%LocalAppData%\Syncthing

Default=False

FileKey1=%LocalAppData%\Syncthing|*.log

[Temporary ASP.NET Files*]

LangSecRef=3025

Detect=HKLM\Software\Microsoft\.NETFramework

Default=False

FileKey1=%WinDir%\Microsoft.NET\Framework\*\Temporary ASP.NET Files|*.*|REMOVESELF

FileKey2=%WinDir%\Microsoft.NET\Framework64\*\Temporary ASP.NET Files|*.*|REMOVESELF

------------------------------------------------------------------------------

Modified Entries:

[Adobe Patch Files*]

LangSecRef=3021

Detect=HKCU\Software\Adobe

Default=False

FileKey1=%CommonAppData%\Adobe\CameraRaw\Adobe\AdobePatchFiles|*.*|RECURSE

FileKey2=%ProgramFiles%\Adobe\Adobe\AdobePatchFiles|*.*|REMOVESELF

- Added FileKey1

 

[Adobe Premiere Elements 11*]

LangSecRef=3023

Detect=HKCU\Software\Adobe\Premiere Elements\11.0

Default=False

RegKey1=HKCU\Software\Adobe\Premiere Elements\11.0\MRUDocuments

FileKey1=%AppData%\Adobe\Common\Thumbnail Cache|*.*|RECURSE

FileKey2=%CommonAppData%|StreamingMediaTechnologyLog.txt

FileKey3=%Documents%\Adobe\Premiere Elements\11.0|*.log

FileKey4=%Documents%\NewBlueFX\Logs|*.log;*.txt

- Added FileKey2

 

[Adobe Premiere Elements 12 More*]

LangSecRef=3023

Detect=HKCU\Software\Adobe\Premiere Elements\12.0

Default=False

FileKey1=%AppData%\Adobe\Common\Thumbnail Cache|*.*|RECURSE

FileKey2=%CommonAppData%|StreamingMediaTechnologyLog.txt

FileKey3=%Documents%\Adobe\Premiere Elements\12.0|*.log

FileKey4=%Documents%\NewBlueFX\Logs|*.log;*.txt

RegKey1=HKCU\Software\Adobe\Premiere Elements\12.0\MRUDocuments

- Added FileKey2

[Adobe Premiere Elements 13*]

LangSecRef=3023

Detect=HKCU\Software\Adobe\Premiere Elements\13.0

Default=False

FileKey1=%AppData%\Adobe\Common\Thumbnail Cache|*.*|RECURSE

FileKey2=%CommonAppData%|StreamingMediaTechnologyLog.txt

FileKey3=%Documents%\Adobe\Premiere Elements\13.0|*.log

FileKey4=%Documents%\NewBlueFX\Logs|*.txt

RegKey1=HKCU\Software\Adobe\Premiere Elements\13.0\MRUDocuments

- Added FileKey2

 

[Ashampoo Burning Studio 16*]

LangSecRef=3024

Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16

Default=False

FileKey1=%AppData%\Ashampoo\Ashampoo Burning Studio 16\log|*.xml;*.txt

RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory

RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Backup Project\BackupOptions|CustomLocation

RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\BDMV Disc Project\SelectBDMVFolder|BdmvPath

RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Browse Image Project\BrowseImageFile|ImagePath

RegKey5=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory

RegKey6=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory

RegKey7=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Burn Image Project\SelectImage|ImagePath

RegKey8=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory

RegKey9=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Data Disc Project\DumpImage|ImagePath

RegKey10=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\DVD-Video Disc Project\MoviesPage|Path

RegKey11=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\DVD-Video Disc Project\SaveDialog_authed.CMoviesPage.Movies|InitialDirectory

RegKey12=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Logs

RegKey13=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\tempFiles

RegKey14=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Unknown Project

RegKey15=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VCD Project\SaveDialog_OnAddMovies|InitialDirectory

RegKey16=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VIDEO_TS Disc Project\DumpImage|ImagePath

RegKey17=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath

- Added FileKey9

 

[Ashampoo Burning Studio 2016*]

LangSecRef=3024

Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016

Default=False

FileKey1=%AppData%\Ashampoo\Ashampoo Burning Studio 2016|backupmetainfo.xml

FileKey2=%AppData%\Ashampoo\Ashampoo Burning Studio 2016\log|*.xml;*.txt

RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory

RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Backup Project\BackupOptions|CustomLocation

RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Browse Image Project\BrowseImageFile|ImagePath

RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory

RegKey5=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory

RegKey6=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Burn Image Project\SelectImage|ImagePath

RegKey7=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory

RegKey8=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Data Disc Project\DumpImage|ImagePath

RegKey9=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Logs

RegKey10=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\tempFiles

RegKey11=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Unknown Project

RegKey12=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\VCD Project\SaveDialog_OnAddMovies|InitialDirectory

RegKey13=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\VIDEO_TS Disc Project\DumpImage|ImagePath

RegKey14=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath

- Added 12 new RegKeys

[Avira AntiVir Desktop IPM*]

LangSecRef=3024

Detect=HKLM\Software\Avira\AntiVir Desktop

Default=False

FileKey1=%CommonAppData%\Avira\AntiVir Desktop\IPM|*.*|RECURSE

FileKey2=%LocalAppData%\VirtualStore\ProgramData\Avira\AntiVir Desktop\IPM|*.*|RECURSE

- Added Avira to entry name

[Avira AntiVir Desktop Reports*]

LangSecRef=3024

Detect=HKLM\Software\Avira\AntiVir Desktop

Default=False

FileKey1=%CommonAppData%\Avira\AntiVir Desktop\REPORTS|*.*

FileKey2=%LocalAppData%\VirtualStore\ProgramData\Avira\AntiVir Desktop\REPORTS|*.*

- Added Avira to entry name

 

[Hauppauge WinTV*]

LangSecRef=3024

Detect=HKLM\SOFTWARE\Hauppauge

Default=False

FileKey1=%SystemDrive%\|hcwDriverInstall.txt

FileKey2=%Public%\Videos\Pause Buffer|*.*|RECURSE

FileKey3=%Public%\WinTV|Settings-old.xml

FileKey4=%Public%\WinTV\Channel Database|hcwChanDB_5-lastgood.mdb

FileKey5=%Public%\WinTV\Logs\minidump|*.*|RECURSE

- Added FileKeys3 and 4

 

[Microsoft Edge More*]

LangSecRef=3022

Detect=HKCU\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe

DetectFile=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe

Default=False

FileKey1=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\#!001\Microsoft\CryptnetUrlCache|*.*|RECURSE

FileKey2=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\#!002\Microsoft\CryptnetUrlCache|*.*|RECURSE

FileKey3=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\Microsoft\CryptnetUrlCache|*.*|RECURSE

FileKey4=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\DataStore\Data|*.*|RECURSE

FileKey5=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\DataStore\Indexed\Data|*.*|RECURSE

FileKey6=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AppData\User\Default\Indexed DB|*.*|RECURSE

- Added FileKey6

[NVIDIA GFExperience Updates*]

LangSecRef=3024

DetectFile=%CommonAppData%\NVIDIA Corporation\GeForce Experience

Default=False

FileKey1=%CommonAppData%\NVIDIA\Updatus\DownloadManager|*.*

FileKey2=%CommonAppData%\NVIDIA\NvBackend\Updatus\DownloadManager|*.*

FileKey3=%CommonAppData%\NVIDIA Corporation\NetService|*.*|RECURSE

FileKey4=%LocalAppData%\VirtualStore\ProgramData\NVIDIA\Updatus\DownloadManager|*.*

FileKey5=%LocalAppData%\VirtualStore\ProgramData\NVIDIA\NvBackend\Updatus\DownloadManager|*.*

FileKey6=%LocalAppData%\VirtualStore\ProgramData\NVIDIA Corporation\NetService|*.*|RECURSE

FileKey7=%CommonAppData%\NVIDIA Corporation\GeForce Experience\Update|*.*|RECURSE

- Added FileKey7

------------------------------------------------------------------------------

Removed Entries:

[Aiseesoft Studio Logs*]

LangSecRef=3023

Detect=HKCU\Software\Aiseesoft Studio

Default=False

FileKey1=%AppData%\Aiseesoft Studio|fileinfolog.txt;*.log|RECURSE

FileKey2=%AppData%\log|*.*|REMOVESELF

FileKey3=%SystemDrive%\log|*.*|REMOVESELF

- No such software

[Avira Speedup Logs*]

LangSecRef=3024

Detect=HKLM\Software\AviraSpeedup

Default=False

FileKey1=%LocalAppData%\AviraSpeedup\logs\|*.*

- Merged into Avira SystemSpeedup Logs

 

[Cached File Extensions*]

LangSecRef=3025

Detect=HKCU\Software\Microsoft\Windows

Default=False

Warning=Can cause issues on Windows 8.1!

RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts

RegKey2=HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts

RegKey3=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts

- Removed upon request of contributor

 

[Video Converter Pro*]

LangSecRef=3023

DetectFile=%AppData%\Leawo\Video Converter Pro

Default=False

FileKey1=%AppData%\Leawo\Video Converter Pro|*.log

- Duplicated Entry

 

[Wondershare MobileGo for iOS*]

LangSecRef=3021

DetectFile=%AppData%\Wondershare\MobileGo for iOS

Default=False

FileKey1=%AppData%\Wondershare\MobileGo for iOS|*.log

- Merged into MobileGo entry

------------------------------------------------------------------------------

 

 

Share this post


Link to post
Share on other sites

Modified entries:

 

[starCraft II Logs*]
Section=Games
Detect1=HKCU\Software\Blizzard Entertainment\StarCraft II
Detect2=HKLM\Software\Wow6432Node\Blizzard Entertainment\StarCraft II
Default=False
FileKey1=%Documents%\StarCraft II\EditorLogs|*.*|RECURSE
FileKey2=%Documents%\StarCraft II\GameLogs|*.*|RECURSE
FileKey3=%Documents%\StarCraft II\UserLogs|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Starcraft II\Logs|*.*
FileKey5=%ProgramFiles%\Starcraft II\Logs|*.*
FileKey6=%Public%\games\Starcraft II\Logs|*.*

 

Added FileKey1 and removed entry %SystemDrive%\Starcraft II\Logs|*.*

 

 

[battle.net*]
Section=Games
Detect=HKCU\Software\Blizzard Entertainment\Battle.net
Default=False
FileKey1=%CommonAppData%\Battle.net|*.log|RECURSE
FileKey2=%CommonAppData%\Battle.net\Agent\Agent.*\Logs|*.*|RECURSE
FileKey3=%CommonAppData%\Battle.net\Agent\Logs|*.*|RECURSE
FileKey4=%CommonAppData%\Battle.net\Setup\*\Logs|*.*
FileKey5=%CommonAppData%\Battle.net\Telemetry|*.*
FileKey6=%CommonAppData%\Blizzard Entertainment\Battle.net\Cache|*.*|REMOVESELF
FileKey7=%LocalAppData%\Blizzard Entertainment\Battle.Net\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Blizzard Entertainment\System Survey|log.txt
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Battle.net|*.log|RECURSE
FileKey10=%LocalAppData%\VirtualStore\ProgramData\Battle.net\Agent\Agent.*\Logs|*.*|RECURSE
FileKey11=%LocalAppData%\VirtualStore\ProgramData\Battle.net\Agent\Logs|*.*|RECURSE
FileKey12=%LocalAppData%\VirtualStore\ProgramData\Blizzard Entertainment\Battle.net\Cache|*.*|REMOVESELF
RegKey1=HKCU\Software\Blizzard Entertainment\Battle.net\Authenticator

 

Added FileKey5

 

 

[steam Logs*]
Section=Games
Detect=HKCU\Software\Valve\Steam
Default=False
FileKey1=%AppData%\SteamVR\Logs|*.*|REMOVESELF
FileKey2=%ProgramFiles%\Steam|*.log;*log.last;connection_log_*.txt;*_log.txt;remote_connections.txt;vr*_*.txt|RECURSE
FileKey3=%ProgramFiles%\Steam\logs|*.*
FileKey4=%ProgramFiles%\Steam\vr\runtime\logs|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Steam|*.log;*log.last;connection_log_*.txt;*_log.txt;remote_connections.txt;vr*_*.txt|RECURSE

 

Added FileKey3.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×