Jump to content
CCleaner Community Forums
Winapp2.ini

Winapp2.ini additions

Recommended Posts

previous name for this entry were using "Windows" but based on suggestion, the "Windows" were removed so that the result page will show [Windows - Error Reporting More*] instead of [Windows - Windows Error Reporting More*]

and usually entries that complement default cc's cleaning rule will have "more" so i think we don't need to change the name

 

I agree, but there are some entries that have "Windows" in it. There is no CCleaner default rule for this. They have an entry with the name "Memory Dump".

 

EDIT

You're right, there is a built-in rule for this. I'm sorry. I think we should keep the same name.

 

 

Share this post


Link to post
Share on other sites

New:

[Zemana AntiMalware (Reports)*]
LangSecRef=3024
Detect1=HKCU\Software\Zemana\AntiMalware
Detect2=HKLM\Software\Zemana\AntiMalware
Default=False
FileKey1=%LocalAppData%\Zemana\Zemana AntiMalware\reports|*.txt

Share this post


Link to post
Share on other sites

I agree, but there are some entries that have "Windows" in it. There is no CCleaner default rule for this. They have an entry with the name "Memory Dump".

under system, Windows Error Reporting

the dump location are used by WER

 

as for entries that have "Windows" in it, some entries should have "Windows" to avoid confusion and it's up to the @ROCKNROLL whether to follow that naming scheme or not

Share this post


Link to post
Share on other sites

under system, Windows Error Reporting

the dump location are used by WER

 

as for entries that have "Windows" in it, some entries should have "Windows" to avoid confusion and it's up to the @ROCKNROLL whether to follow that naming scheme or not

 

I agree. I think "Windows" can be removed from [Windows Error Reporting More*], [Windows Installer Temps*], [Windows Memory Leak Detection*], [Windows System Profile*] and [Windows Tracing*].

Share this post


Link to post
Share on other sites

Updated: https://github.com/MoscaDotTo/Winapp2/commit/b0a91971be469b26030d37c375e5bdeeb6a81066

 

I will keep the current version scheme then.

 

As for the Memory Dumps rule, that is only for the non-CCleaner version of Winapp2. Years ago, there was a cleaner for Winapp2 for cleaning memory dumps, until it was added to CCleaner. That is why it is in the Removed entries file.

Share this post


Link to post
Share on other sites

Revised Entry

Changed name from [Windows Backup*] to [Windows Backup Logs*] and corrected the Detect.
 

[Windows Backup Logs*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\Logs\WindowsBackup|*.etl
 

Share this post


Link to post
Share on other sites

 [AIMP 4*]
LangSecRef=3023
DetectFile=%ProgramFiles%\AIMP\AIMP.exe
Default=False
Warning=This will delete AIMP's auto profile and program backup. Make sure your AIMP running properly before using this entry
FileKey1=%AppData%\AIMP|*.bak
Filekey2=%ProgramFiles%\AIMP\!Backup|*.*|REMOVESELF
- add FK2 - delete auto backup of profile and program

[PnaclTranslation Cache*]
LangSecRef=3029
SpecialDetect=DET_CHROME
Default=False
FileKey1=%LocalAppData%\Google\Chrome\User Data\PnaclTranslationCache|*.*

[Auslogics Disk Defrag Professional*]
LangSecRef=3024
Detect1=HKLM\SOFTWARE\Auslogics\Disk Defrag Professional
Detect2=HKLM\SOFTWARE\WOW6432Node\Auslogics\Disk Defrag Professional
Default=False
FileKey1=%CommonAppData%\Auslogics\Disk Defrag Professional\*\Logs|*.*|RECURSE
FileKey2=%CommonAppData%\Auslogics\Disk Defrag Professional\*\Reports|*.*|RECURSE
FileKey3=%ProgramFiles%\Auslogics\Disk Defrag Professional|ndefrg.log
- fix filekey3



is there any reason why we should delete PendingFileRenameOperations@RK1? https://technet.microsoft.com/en-us/library/cc960241.aspx
i noticed the problem with this entry using WhyReboot software after updating 7-zip where older context menu dll file doesn't get replaced with the newer dll
i think we need to remove RK1 and rename to [AppCompactCache*]

[session Manager*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\AppCompat\Programs|*.txt;*.xml
FileKey2=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml
RegKey1=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager|PendingFileRenameOperations
RegKey2=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|AppCompatCache
RegKey3=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|CacheMainSdb
RegKey4=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|SdbTime

Share this post


Link to post
Share on other sites

is there any reason why we should delete PendingFileRenameOperations@RK1? https://technet.microsoft.com/en-us/library/cc960241.aspx

i noticed the problem with this entry using WhyReboot software after updating 7-zip where older context menu dll file doesn't get replaced with the newer dll

i think we need to remove RK1 and rename to [AppCompactCache*]

 

[session Manager*]

LangSecRef=3025

Detect=HKLM\Software\Microsoft\Windows

Default=False

FileKey1=%WinDir%\AppCompat\Programs|*.txt;*.xml

FileKey2=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml

RegKey1=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager|PendingFileRenameOperations

RegKey2=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|AppCompatCache

RegKey3=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|CacheMainSdb

RegKey4=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|SdbTime

 

This could contain information about programs that were once on the system and now are not. There are two other known privacy eraser programs that have included this into their programs. My suggestion is, open some portable apps then remove it from the system completely, and purge from the Recycle bin. Then, uninstall a few programs from the system and then view the "AppCompatCache" value and you will see for yourself.

Share this post


Link to post
Share on other sites

This could contain information about programs that were once on the system and now are not. There are two other known privacy eraser programs that have included this into their programs. My suggestion is, open some portable apps then remove it from the system completely, and purge from the Recycle bin. Then, uninstall a few programs from the system and then view the "AppCompatCache" value and you will see for yourself.

AppCompatCache work like Perfetch, i know that after i google-d it but what about RegKeg1?

deleting PendingFileRenameOperations will create problem like i've mentioned above

Share this post


Link to post
Share on other sites

AppCompatCache work like Perfetch, i know that after i google-d it but what about RegKeg1?

deleting PendingFileRenameOperations will create problem like i've mentioned above

I agree with you. RegKey1 should be excluded.

Share this post


Link to post
Share on other sites

Distributed [Windows System Profile*] into separate entries. So please add these and remove [Windows System Profile*].

[systemprofile Cookies*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\System32\config\SystemProfile\Cookies|*.*|RECURSE
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE
FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE

[systemprofile History*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\System32\config\SystemProfile\History|*.*|RECURSE
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\History|*.*|RECURSE

[systemprofile Temporary Files*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\System32\config\SystemProfile\Local Settings\Temp|*.*|RECURSE
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Temp|*.*|RECURSE
FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Temp|*.*|RECURSE

[systemprofile Temporary Internet Files*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\System32\config\SystemProfile\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE
FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

Share this post


Link to post
Share on other sites

Revised Entry

Changed |REMOVESELF with |RECURSE

 

[NetworkService Cookies*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\NetworkService\Cookies|*.*|RECURSE
FileKey2=%SystemDrive%\Documents and Settings\NetworkService.NT*\Cookies|*.*|RECURSE
FileKey3=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies|*.*|RECURSE
FileKey4=%WinDir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE

Share this post


Link to post
Share on other sites

Revised Entry

Removed: HKLM\SYSTEM\CurrentControlSet\Control\Session Manager|PendingFileRenameOperations

 

[session Manager*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\AppCompat\Programs|*.txt;*.xml
FileKey2=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml
RegKey1=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|AppCompatCache
RegKey2=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|CacheMainSdb
RegKey3=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|SdbTime

Share this post


Link to post
Share on other sites

Revised Entry

Removed: HKLM\SYSTEM\CurrentControlSet\Control\Session Manager|PendingFileRenameOperations

 

[session Manager*]

LangSecRef=3025

Detect=HKLM\Software\Microsoft\Windows

Default=False

FileKey1=%WinDir%\AppCompat\Programs|*.txt;*.xml

FileKey2=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml

RegKey1=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|AppCompatCache

RegKey2=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|CacheMainSdb

RegKey3=HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache|SdbTime

why not change the name to AppCompactCache* ?

i think it is better to use that name rather than Session Manager

Share this post


Link to post
Share on other sites

What is this entry about and why is it in the Windows Store Apps section?

I think it should be removed.

 

[Windows Retail Demo*]
DetectOS=10.0|
Section=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows\RetailDemo|*.*|REMOVESELF

Share this post


Link to post
Share on other sites

What is this entry about and why is it in the Windows Store Apps section?

I think it should be removed.

 

[Windows Retail Demo*]

DetectOS=10.0|

Section=3031

Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft

Default=False

FileKey1=%CommonAppData%\Microsoft\Windows\RetailDemo|*.*|REMOVESELF

 

https://github.com/MoscaDotTo/Winapp2/issues/20

 

https://github.com/MoscaDotTo/Winapp2/pull/21

Share this post


Link to post
Share on other sites

What is this entry about and why is it in the Windows Store Apps section?

I think it should be removed.

 

[Windows Retail Demo*]

DetectOS=10.0|

Section=3031

Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft

Default=False

FileKey1=%CommonAppData%\Microsoft\Windows\RetailDemo|*.*|REMOVESELF

 

This is from Windows 10 Insider Builds.  I would not remove it.

 

https://www.neowin.net/news/windows-10-has-a-secret-retail-demo-mode-with-a-new-app-and-video-loop

Share this post


Link to post
Share on other sites

If someone want to remove the Retail Demo, I think this is the better way:

 

Settings > System > Apps & features > Manage optional features

Uninstall all "xxx Retail Demo Content" entries.

Share this post


Link to post
Share on other sites

Revised Entry

Changed name from [NetworkService Temps*] to [NetworkService Temporary Files*] same like [LocalService Temporary Files*] and [systemprofile Temporary Files*].

 

[NetworkService Temporary Files*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\NetworkService\Local Settings\Temp|*.*|RECURSE
FileKey2=%SystemDrive%\Documents and Settings\NetworkService.NT*\Local Settings\Temp|*.*|RECURSE
FileKey3=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Temp|*.*|RECURSE

Share this post


Link to post
Share on other sites

Do we really need the entries listed below. I cannot find those locations on Window 7, 8, 8.1 and 10. I checked a few other known privacy eraser programs and they don't have cleaning rules for the locations listed below.

 

[LocalService Cookies*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\LocalService\Cookies|*.*|RECURSE
FileKey2=%SystemDrive%\Documents and Settings\LocalService.NT*\Cookies|*.*|RECURSE
FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies|*.*|REMOVESELF
FileKey4=%WinDir%\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|REMOVESELF

[LocalService History*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\LocalService\Local Settings\History|*.*|RECURSE
FileKey2=%SystemDrive%\Documents and Settings\LocalService.NT*\Local Settings\History|*.*|RECURSE
FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History|*.*|RECURSE

[LocalService Temporary Internet Files*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\LocalService\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey2=%SystemDrive%\Documents and Settings\LocalService.NT*\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

[NetworkService Cookies*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\NetworkService\Cookies|*.*|RECURSE
FileKey2=%SystemDrive%\Documents and Settings\NetworkService.NT*\Cookies|*.*|RECURSE
FileKey3=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies|*.*|RECURSE
FileKey4=%WinDir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE

[NetworkService History*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\NetworkService\Local Settings\History|*.*|RECURSE
FileKey2=%SystemDrive%\Documents and Settings\NetworkService.NT*\Local Settings\History|*.*|RECURSE
FileKey3=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History|*.*|RECURSE

[NetworkService Temporary Internet Files*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\NetworkService\Local Settings\Content.IE5|*.*|RECURSE
FileKey2=%SystemDrive%\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey3=%SystemDrive%\Documents and Settings\NetworkService.NT*\Local Settings\Content.IE5|*.*|RECURSE
FileKey4=%SystemDrive%\Documents and Settings\NetworkService.NT*\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey5=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE
FileKey6=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Content.IE5|*.*|RECURSE

[systemprofile Cookies*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\System32\config\SystemProfile\Cookies|*.*|RECURSE
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE
FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE

[systemprofile History*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\System32\config\SystemProfile\History|*.*|RECURSE
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\History|*.*|RECURSE

[systemprofile Temporary Internet Files*]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\System32\config\SystemProfile\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE
FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

Share this post


Link to post
Share on other sites

Do we really need the entries listed below. I cannot find those locations on Window 7, 8, 8.1 and 10. I checked a few other known privacy eraser programs and they don't have cleaning rules for the locations listed below.

 

[LocalService Cookies*]

LangSecRef=3022

Detect=HKCU\Software\Microsoft\Windows

Default=False

FileKey1=%SystemDrive%\Documents and Settings\LocalService\Cookies|*.*|RECURSE

FileKey2=%SystemDrive%\Documents and Settings\LocalService.NT*\Cookies|*.*|RECURSE

FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies|*.*|REMOVESELF

FileKey4=%WinDir%\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|REMOVESELF

 

[LocalService History*]

LangSecRef=3022

Detect=HKCU\Software\Microsoft\Windows

Default=False

FileKey1=%SystemDrive%\Documents and Settings\LocalService\Local Settings\History|*.*|RECURSE

FileKey2=%SystemDrive%\Documents and Settings\LocalService.NT*\Local Settings\History|*.*|RECURSE

FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History|*.*|RECURSE

 

[LocalService Temporary Internet Files*]

LangSecRef=3022

Detect=HKCU\Software\Microsoft\Windows

Default=False

FileKey1=%SystemDrive%\Documents and Settings\LocalService\Local Settings\Temporary Internet Files|*.*|RECURSE

FileKey2=%SystemDrive%\Documents and Settings\LocalService.NT*\Local Settings\Temporary Internet Files|*.*|RECURSE

FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

 

[NetworkService Cookies*]

LangSecRef=3022

Detect=HKCU\Software\Microsoft\Windows

Default=False

FileKey1=%SystemDrive%\Documents and Settings\NetworkService\Cookies|*.*|RECURSE

FileKey2=%SystemDrive%\Documents and Settings\NetworkService.NT*\Cookies|*.*|RECURSE

FileKey3=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies|*.*|RECURSE

FileKey4=%WinDir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE

 

[NetworkService History*]

LangSecRef=3022

Detect=HKCU\Software\Microsoft\Windows

Default=False

FileKey1=%SystemDrive%\Documents and Settings\NetworkService\Local Settings\History|*.*|RECURSE

FileKey2=%SystemDrive%\Documents and Settings\NetworkService.NT*\Local Settings\History|*.*|RECURSE

FileKey3=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History|*.*|RECURSE

 

[NetworkService Temporary Internet Files*]

LangSecRef=3022

Detect=HKCU\Software\Microsoft\Windows

Default=False

FileKey1=%SystemDrive%\Documents and Settings\NetworkService\Local Settings\Content.IE5|*.*|RECURSE

FileKey2=%SystemDrive%\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files|*.*|RECURSE

FileKey3=%SystemDrive%\Documents and Settings\NetworkService.NT*\Local Settings\Content.IE5|*.*|RECURSE

FileKey4=%SystemDrive%\Documents and Settings\NetworkService.NT*\Local Settings\Temporary Internet Files|*.*|RECURSE

FileKey5=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

FileKey6=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Content.IE5|*.*|RECURSE

 

[systemprofile Cookies*]

LangSecRef=3022

Detect=HKCU\Software\Microsoft\Windows

Default=False

FileKey1=%WinDir%\System32\config\SystemProfile\Cookies|*.*|RECURSE

FileKey2=%WinDir%\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE

FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE

 

[systemprofile History*]

LangSecRef=3022

Detect=HKCU\Software\Microsoft\Windows

Default=False

FileKey1=%WinDir%\System32\config\SystemProfile\History|*.*|RECURSE

FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE

FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\History|*.*|RECURSE

 

[systemprofile Temporary Internet Files*]

LangSecRef=3022

Detect=HKCU\Software\Microsoft\Windows

Default=False

FileKey1=%WinDir%\System32\config\SystemProfile\Local Settings\Temporary Internet Files|*.*|RECURSE

FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

 

I have some of the locations on my Win10 system. My guess could be these are some old entries during 2000/XP times, as I see Content.IE5, which makes me think of Internet Explorer 5.

Share this post


Link to post
Share on other sites

I think we should change Detect to DetectFile=CommonAppData%\Microsoft\Windows\RetailDemo and DetectOS=10.0| can be removed.

 

[Windows Retail Demo*]
DetectOS=10.0|
Section=3025
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows\RetailDemo|*.*|REMOVESELF

Share this post


Link to post
Share on other sites

I have some of the locations on my Win10 system. My guess could be these are some old entries during 2000/XP times, as I see Content.IE5, which makes me think of Internet Explorer 5.

Same here, all of these exist on my Win7 laptop:

 

[LocalService Cookies*]

FileKey4=%WinDir%\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|REMOVESELF

 

[LocalService Temporary Internet Files*]

FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

 

[NetworkService Cookies*]

FileKey4=%WinDir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE

 

[NetworkService History*]

FileKey3=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History|*.*|RECURSE

 

[NetworkService Temporary Internet Files*]

FileKey5=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

 

[systemprofile Cookies*]

FileKey2=%WinDir%\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE

FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE

 

[systemprofile History*]

FileKey1=%WinDir%\System32\config\SystemProfile\History|*.*|RECURSE

FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE

 

[systemprofile Temporary Internet Files*]

FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE

 

Becoming a regular occurrence in this thread - "This doesn't exist on MY system so should be removed from winapp2". Not that it bothers me as I hardly bother with the main file since the GitHub move, makes it a PITA to copy new entries.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×