Jump to content
Piriform Community Forums
Winapp2.ini

Winapp2.ini additions

Recommended Posts

Revised Entry

Added: %AppData%\Adobe\Photoshop Elements\*\Editor|*.txt

[Adobe Photoshop Elements *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop Elements
Default=False
FileKey1=%CommonAppData%\Adobe\Photoshop Elements\File Agent|WatchFolder.3.cache
FileKey2=%AppData%\Adobe\Photoshop Elements\*\Editor|*.txt
RegKey1=HKCU\Software\Adobe\Photoshop Elements\11.0\common\settings\Elements MRU
RegKey2=HKCU\Software\Adobe\Photoshop Elements\11.0\CurrentMediaFilePath
RegKey3=HKCU\Software\Adobe\Photoshop Elements\11.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey4=HKCU\Software\Adobe\Photoshop Elements\12.0\common\settings\Elements MRU
RegKey5=HKCU\Software\Adobe\Photoshop Elements\12.0\CurrentMediaFilePath
RegKey6=HKCU\Software\Adobe\Photoshop Elements\12.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey7=HKCU\Software\Adobe\Photoshop Elements\13.0\common\settings\Elements MRU
RegKey8=HKCU\Software\Adobe\Photoshop Elements\13.0\CurrentMediaFilePath
RegKey9=HKCU\Software\Adobe\Photoshop Elements\13.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey10=HKCU\Software\Adobe\Photoshop Elements\14.0\common\settings\Elements MRU
RegKey11=HKCU\Software\Adobe\Photoshop Elements\14.0\CurrentMediaFilePath
RegKey12=HKCU\Software\Adobe\Photoshop Elements\14.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey13=HKCU\Software\Adobe\Photoshop Elements\15.0\common\settings\Elements MRU
RegKey14=HKCU\Software\Adobe\Photoshop Elements\15.0\CurrentMediaFilePath
RegKey15=HKCU\Software\Adobe\Photoshop Elements\15.0\VisitedDirs|STARTUPIMAGEDIRECTORY

Share this post


Link to post
Share on other sites
On 10/1/2018 at 13:22, Andavari said:

Unfortunately deleting lang files can break some programs, i.e.; in some they may show a pop-up error dialog about missing files, and some others they won't run at all.

It's one of those things that if I'm about to delete a bunch of lang files in a program I ZIP them first, then delete them manually and see what happens. If all goes well I add them into my winapp2.ini file, but I never submit them on here because someone using a non-English lang version of a program may need those lang files.

you didn't understand, I'm keeping only English based files (even though it's not my mother language for me either),
but I get sick when I get an app (a portable one for example) that is only available in "international" version and
I don't have a choice than to install thousands of junk files from languages all over the world,
and later, when there's an update and I need to sync that app, I would have to wait for it to sync
all these completely useless thousands of files relying in random folders and difficult to find,
well, this sucks, obviously..

other than that, I've had only one or two problems with chrome,
where there was one or two files that were needed for an extension to run,
even though that seemed like language files to me,
other than that, no problems..

Share this post


Link to post
Share on other sites
On 1/11/2018 at 07:26, SMalik said:

Does it make sense to remove "Application Cache" directories from this entry?

[Chrome Application Cache *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect1=HKCU\Software\Chromium
Detect2=HKCU\Software\SuperBird
Detect3=HKCU\Software\Torch
Detect4=HKCU\Software\Vivaldi
Default=False
FileKey1=%AppData%\Brave\*\Application Cache|*.*|REMOVESELF
FileKey2=%LocalAppData%\Amigo\User Data\*\Application Cache|*.*|REMOVESELF
FileKey3=%LocalAppData%\Chrome Plus\User Data\*\Application Cache|*.*|REMOVESELF
FileKey4=%LocalAppData%\Chromium\User Data\*\Application Cache|*.*|REMOVESELF
FileKey5=%LocalAppData%\Flock\User Data\*\Application Cache|*.*|REMOVESELF
FileKey6=%LocalAppData%\Google\Chrome*\User Data\*\Application Cache|*.*|REMOVESELF
FileKey7=%LocalAppData%\Rockmelt\User Data\*\Application Cache|*.*|REMOVESELF
FileKey8=%LocalAppData%\SRWare Iron\User Data\*\Application Cache|*.*|REMOVESELF
FileKey9=%LocalAppData%\SuperBird\User Data\*\Application Cache|*.*|REMOVESELF
FileKey10=%LocalAppData%\Torch\User Data\*\Application Cache|*.*|REMOVESELF
FileKey11=%LocalAppData%\Vivaldi\User Data\*\Application Cache|*.*|REMOVESELF

With my own personal Chrome/Chrome-based browser cleaners on my system I only use RECURSE with Application Cache folders.

Share this post


Link to post
Share on other sites
22 hours ago, JDPower said:

That may be true, but my point was you can't easily copy and paste the entries from Git update page. Unless I'm missing something, you copy and paste, then have to delete a load of plus signs, minus signs, removed lines, leading spaces. Then hope you've not accidentally screwed up the entry in the process lol

I've completed the basic work for this now actually. It's not ready for public release just yet, but it is functional. Here is an example of the output:

NOTE TO READERS: THE BELOW IS NOT AN OFFICIAL CHANGELOG OF ANY SORT AND SHOULD NOT BE INTERPRETED AS ONE. IT IS SIMPLY THE OUTPUT OF A CLASS I AM TESTING THAT WILL EVENTUALLY REPLACE THE BACKBONE OF THE CURRENT SET OF TOOLS SUCH AS WINAPPDEBUG. I have provided it for feedback purposes only
 

 

 

Installer * has been modified.

[Installer *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect=HKCU\Software\Vivaldi
Default=False
FileKey1=%LocalAppData%\SuperBird\Application\*\Installer|*.7z
FileKey2=%LocalAppData%\Torch\Application\*\Installer|*.7z
FileKey3=%LocalAppData%\Vivaldi\Application\*\Installer|*.7z
FileKey4=%LocalAppData%\Yandex\YandexBrowser\Application\*\Installer|*.7z
FileKey5=%ProgramFiles%\Google\Chrome\Application\*\Installer|*.7z
----------------------------------------------------------------------------------------------------------------------
Web Data * has been modified.

[Web Data *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect1=HKCU\Software\Chromium
Detect2=HKCU\Software\SuperBird
Detect3=HKCU\Software\Torch
Detect4=HKCU\Software\Vivaldi
Default=False
Warning=This will remove Autofill, Autocomplete, Search Engines keyword, Sign-in and Credit Card info.
FileKey1=%LocalAppData%\Amigo\User Data\*\*|Web Data
FileKey2=%LocalAppData%\Chrome Plus\User Data\*|Web Data
FileKey3=%LocalAppData%\Chromium\User Data\*|Web Data
FileKey4=%LocalAppData%\Flock\User Data\*|Web Data
FileKey5=%LocalAppData%\Google\Chrome*\User Data\*|Web Data
FileKey6=%LocalAppData%\Rockmelt\User Data\*|Web Data
FileKey7=%LocalAppData%\SRWare Iron\User Data\*|Web Data
FileKey8=%LocalAppData%\SuperBird\User Data\*|Web Data
FileKey9=%LocalAppData%\Torch\User Data\*|Web Data
FileKey10=%LocalAppData%\Vivaldi\User Data\*|Web Data
----------------------------------------------------------------------------------------------------------------------
Active@ Disk Image * has been modified.

[Active@ Disk Image *]
LangSecRef=3024
Detect=HKLM\Software\LSoft Technologies\Active Disk Image
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
FileKey3=%ProgramFiles%\LSoft Technologies\Active@ Disk Image|*.txt
FileKey4=%ProgramFiles%\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Images * was removed.

[Active@ UNDELETE Images *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all saved disk images.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*\disk_images|*.*|REMOVESELF
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*\disk_images|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Recovered Files * was removed.

[Active@ UNDELETE Recovered Files *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all recovered data.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*\recovered|*.*|REMOVESELF
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*\recovered|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Sessions * was removed.

[Active@ UNDELETE Sessions *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all saved sessions.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*|*.usf|RECURSE
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*|*.usf|RECURSE
----------------------------------------------------------------------------------------------------------------------
Adobe Photoshop * has been modified.

[Adobe Photoshop *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\5.5\VisitedDirs
FileKey1=%AppData%\Adobe\Adobe Photoshop*\Generator\logs|*.*
FileKey2=%AppData%\Adobe\Bridge*\Cache\Thumbnails|*.*|RECURSE
FileKey3=%AppData%\Adobe\CameraRaw\Cache|*.*|RECURSE
FileKey4=%AppData%\Adobe\FileBrowser\PhotoshopCS|*.*
FileKey5=%AppData%\Adobe\Photoshop Album\*.*|Logse*.txt
FileKey6=%Pictures%|.BridgeSort|RECURSE
----------------------------------------------------------------------------------------------------------------------
Cameyo * has been modified.

[Cameyo *]
LangSecRef=3021
Detect=HKCU\Software\VOS
Default=False
RegKey1=HKCU\Software\VOS
FileKey1=%AppData%\VOS|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
CCDump * has been modified.

[CCDump *]
LangSecRef=3024
DetectFile=%ProgramFiles%\CCleaner\CCDump.exe
Default=False
Warning=This removes files winapp.ini, winsys.ini, winreg.ini and regkeys.output.txt from the CCleaner folder.
FileKey1=%ProgramFiles%\CCleaner|winapp.ini;winreg.ini;winsys.ini;regkeys.output.txt
----------------------------------------------------------------------------------------------------------------------
CD/DVD Burn Cache * has been modified.

[CD/DVD Burn Cache *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning
Default=False
Warning=This will wipe all files that are waiting to be burned to a CD/DVD/BD drive.
FileKey1=%LocalAppData%\Microsoft\CD Burning|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\Burn|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo
----------------------------------------------------------------------------------------------------------------------
DriverPack Solution * has been modified.

[DriverPack Solution *]
LangSecRef=3024
Detect=HKCU\Software\drpsu
Default=False
Warning=This will delete your bug report.
FileKey1=%AppData%\DRPSu\Logs|*.*
FileKey2=%AppData%\DRPSu\snapshots|*.*
FileKey3=%AppData%\DRPSu\temp|*.*
FileKey4=%Documents%\DRP-Log|*.*
FileKey5=%WinDir%\Logs\DRPLog|*.png;*.txt
FileKey6=%WinDir%\Logs\SysInfo|*.*
----------------------------------------------------------------------------------------------------------------------
DUC * was removed.

[DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%LocalAppData%\Vitalwerks\DUC|DUC.log
----------------------------------------------------------------------------------------------------------------------
ElsterFormular * has been modified.

[ElsterFormular *]
LangSecRef=3021
DetectFile=%AppData%\elsterformular
Default=False
FileKey1=%AppData%\elsterformular\*\log|*.log;*.log.*
FileKey2=%AppData%\elsterformular\*\tmp|*.*|RECURSE
FileKey3=%AppData%\elsterformular\pluginmanager\data|*_cpy.zip
FileKey4=%CommonAppData%\elsterformular\log|*.log
FileKey5=%LocalAppData%\.elfohilfe|*.*|REMOVESELF
FileKey6=%LocalAppData%\elfopatch|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
HyperSnap 7 * has been modified.

[HyperSnap 7 *]
LangSecRef=3021
Detect=HKCU\Software\Hyperionics\HyperSnap 7
Default=False
FileKey1=%ProgramFiles%\HyperSnap 7|*.url
RegKey1=HKCU\Software\Hyperionics\HyperSnap 7\Recent File List
----------------------------------------------------------------------------------------------------------------------
Intuit TurboTax * has been modified.

[Intuit TurboTax *]
LangSecRef=3021
DetectFile=%ProgramFiles%\TurboTax*
Default=False
FileKey1=%AppData%\Intuit*|*.log|RECURSE
FileKey2=%CommonAppData%|*.bc
FileKey3=%CommonAppData%\Intuit*|*.log|RECURSE
FileKey4=%CommonAppData%\Intuit\Common\Metrix\*\Logs|*.*
FileKey5=%CommonAppData%\Intuit\Common\QuickBaseClient\*\Logs|*.*
FileKey6=%CommonAppData%\Intuit\Common\Update Service\*\Logs|*.*
FileKey7=%CommonAppData%\Intuit\TurboTax\MSI\*\Logs|*.*
FileKey8=%CommonProgramFiles%\Intuit\Internet Client|Msdun13.exe
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Common Files\Intuit\Internet Client|Msdun13.exe
FileKey10=%LocalAppData%\VirtualStore\Program Files*\TurboTax*|*.txt
FileKey11=%LocalAppData%\VirtualStore\ProgramData|*.bc
FileKey12=%LocalAppData%\VirtualStore\ProgramData\Intuit*|*.log|RECURSE
FileKey13=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\Metrix\*\Logs|*.*
FileKey14=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\QuickBaseClient\*\Logs|*.*
FileKey15=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\Update Service\*\Logs|*.*
FileKey16=%LocalAppData%\VirtualStore\ProgramData\Intuit\TurboTax\MSI\*\Logs|*.*
FileKey17=%ProgramFiles%\TurboTax*|*.txt
----------------------------------------------------------------------------------------------------------------------
Macrium Reflect * has been modified.

[Macrium Reflect *]
LangSecRef=3024
Detect=HKCU\Software\Macrium\Reflect
Default=False
FileKey1=%CommonAppData%\Macrium|*.log|RECURSE
FileKey2=%CommonAppData%\Macrium\Reflect|*.html;*.vsslog
FileKey3=%CommonAppData%\Macrium\waik|waiklog.txt
FileKey4=%SystemDrive%|ref~tmp~.txt;Reflect_Install.log;rescuepe.log
----------------------------------------------------------------------------------------------------------------------
MS Search * has been modified.

[MS Search *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey2=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey4=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
FileKey9=%UserProfile%\Searches|*.search-ms
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
RegKey2=HKLM\Software\Microsoft\Windows Search\VolumeInfoCache
----------------------------------------------------------------------------------------------------------------------
Nitro PDF Reader * has been modified.

[Nitro PDF Reader *]
LangSecRef=3024
Detect=HKCU\Software\Nitro PDF\Reader
Default=False
RegKey1=HKCU\Software\Nitro PDF\Reader\1.0\Recent File List
RegKey2=HKCU\Software\Nitro PDF\Reader\2.0\Recent File List
FileKey1=%AppData%\Nitro|*.log*;*Log.txt*|RECURSE
----------------------------------------------------------------------------------------------------------------------
Notepad++ * has been modified.

[Notepad++ *]
LangSecRef=3021
Detect=HKLM\Software\Notepad++
Default=False
FileKey1=%AppData%\Notepad++\plugins\config|PluginManagerGpup.xml;PluginManagerPlugins.xml;PluginManagerPlugins.zip
FileKey2=%AppData%\Notepad++\plugins\config\plugin_install_temp|*.*|REMOVESELF
FileKey3=%ProgramFiles%\Notepad++\plugins\disabled|*.*
----------------------------------------------------------------------------------------------------------------------
OpenDNS Updater * has been modified.

[OpenDNS Updater *]
LangSecRef=3021
Detect=HKCU\Software\OpenDNS Updater
Default=False
Warning=You must exit OpenDNS Updater in the System Tray to clear log files.
FileKey1=%AppData%\OpenDNS Updater|*.txt
----------------------------------------------------------------------------------------------------------------------
OpenOffice.org Setup Files * has been modified.

[OpenOffice.org Setup Files *]
LangSecRef=3021
Detect1=HKLM\Software\OpenOffice
Detect2=HKLM\Software\OpenOffice.org
Default=False
FileKey1=%UserProfile%\Desktop\OpenOffice.org * Installation Files|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Pando * has been modified.

[Pando *]
Detect=HKCU\Software\Pando Networks\Pando
LangSecRef=3024
Default=False
Warning=Make sure Pando is totally shut down before using this.
FileKey1=%LocalAppData%\Pando\Pando Files|*.*|RECURSE
ExcludeKey1=PATH|%LocalAppData%\Pando\Pando Files\|*pando.prev.log;*pando.log;*pando.sav;*pando.save;*pando.txt
ExcludeKey2=PATH|%LocalAppData%\Pando\Pando Files\Cert\|*.*
----------------------------------------------------------------------------------------------------------------------
Photos * has been modified.

[Photos *]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState|*.sqlite;*.sqlite-shm;*.sqlite-wal;*.xml
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState\PhotosAppTile|*.*|RECURSE
FileKey10=%LocalAppData%\PackagesMicrosoft.Windows.Photos_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedPickerData\Microsoft.Windows.Photos_8wekyb3d8bbwe!App\DefaultSaveFileSingle
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\MostRecentlyUsed
----------------------------------------------------------------------------------------------------------------------
QTTabBar * has been modified.

[QTTabBar *]
LangSecRef=3024
Detect=HKCU\Software\Quizo\QTTabBar
Default=False
FileKey1=%AppData%\QTTabBar|*.log
RegKey1=HKCU\Software\Quizo\QTTabBar|TabsOnLastClosedWindow
RegKey2=HKCU\Software\Quizo\QTTabBar\Cache
RegKey3=HKCU\Software\Quizo\QTTabBar\RecentlyClosed
----------------------------------------------------------------------------------------------------------------------
Saved Search Folders * was removed.

[Saved Search Folders *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=Can cause issues on Windows 8 or newer
FileKey1=%UserProfile%\Searches|*.search-ms
----------------------------------------------------------------------------------------------------------------------
SoftEther VPN * has been modified.

[SoftEther VPN *]
LangSecRef=3024
Detect=HKCU\Software\SoftEther Project\SoftEther VPN
Default=False
Warning=Exclude installer.cache if you're using SoftEther VPN Client Web Installer.
FileKey1=%ProgramFiles%\SoftEther VPN Client|installer.cache
FileKey2=%ProgramFiles%\SoftEther VPN Client\backup.vpn_client.config|*.config
FileKey3=%ProgramFiles%\SoftEther VPN Client\client_log|*.*
FileKey4=%ProgramFiles%\SoftEther VPN Client\vpn_debug|*.*
----------------------------------------------------------------------------------------------------------------------
TortoiseSVN History * has been modified.

[TortoiseSVN History *]
LangSecRef=3024
Detect=HKCU\Software\TortoiseSVN
Default=False
Warning=This will remove your repo paths and last checkout location.
RegKey1=HKCU\Software\TortoiseSVN\History
----------------------------------------------------------------------------------------------------------------------
UsbFix * has been modified.

[UsbFix *]
LangSecRef=3023
Detect=HKCU\Software\UsbFix
Default=False
FileKey1=%SystemDrive%\UsbFix\Log|*.*|REMOVESELF
FileKey2=%SystemDrive%\UsbFix\Quarantine|*.*|REMOVESELF
FileKey3=%UserProfile%\Desktop|UsbFix_Report.txt
RegKey1=HKCU\Software\UsbFix\LastReport
----------------------------------------------------------------------------------------------------------------------
VSO Media Player 1 * has been modified.

[VSO Media Player 1 *]
LangSecRef=3023
Detect=HKCU\Software\VSO\VSO Media Player\1
Default=False
RegKey1=HKCU\Software\VSO\VSO Media Player\1\RecentlyOpenedFiles
FileKey1=%AppData%\VSO\VSO Media Player\1|autoresume.xml
FileKey2=%CommonAppData%\VSO|font.cache
FileKey3=%CommonAppData%\VSO\VSO Media Player\1\log|*.log;*.crashlist
FileKey4=%CommonAppData%\VSO\vsothumbs|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\VSO|font.cache
FileKey6=%LocalAppData%\VirtualStore\ProgramData\VSO\VSO Media Player\1\log|*.log;*.crashlist
FileKey7=%LocalAppData%\VirtualStore\ProgramData\VSO\vsothumbs|*.*|RECURSE
----------------------------------------------------------------------------------------------------------------------
Windows Media Center * has been modified.

[Windows Media Center *]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\MRU\SettingsMRU
FileKey1=%CommonAppData%\Microsoft\eHome\thmb|TVThumb.db
FileKey2=%LocalAppData%\Microsoft\Ehome|Image.db;Video.db;musicThumbs.db
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Microsoft\eHome\thmb|TVThumb.db
----------------------------------------------------------------------------------------------------------------------
Windows ShellBags * has been modified.

[Windows ShellBags *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This will reset folders size, view, icon or position settings to default and remove traces of the folders that do not exist anymore.
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags
RegKey3=HKCU\Software\Microsoft\Windows\Shell\BagMRU
RegKey4=HKCU\Software\Microsoft\Windows\Shell\Bags
RegKey5=HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU
RegKey6=HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
ExcludeKey1=REG|HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey2=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop
ExcludeKey3=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey4=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Desktop
ExcludeKey5=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\AllFolders
----------------------------------------------------------------------------------------------------------------------
X-Chat 2 * has been modified.

[X-Chat 2 *]
LangSecRef=3022
DetectFile=%AppData%\X-Chat 2
Default=False
Warning=This removes Chat Scrollback and Logs.
FileKey1=%AppData%\X-Chat 2\scrollback|*.*|REMOVESELF
FileKey2=%AppData%\X-Chat 2\xchatlogs|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
No-IP DUC * was added.

[No-IP DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%CommonAppData%\Vitalwerks\DUC|*.log
FileKey2=%LocalAppData%\Vitalwerks\DUC|*.log
----------------------------------------------------------------------------------------------------------------------

Note: the above output doesn't reflect any particular current set of changes and should not be interpreted as a changelog. It is only an example of the output of the compareTo method for a new class I wrote that will eventually be used replace the backbone of the current set of tools

Share this post


Link to post
Share on other sites
7 minutes ago, Winapp2.ini said:

I've completed the basic work for this now actually. It's not ready for public release just yet, but it is functional. Here is an example of the output:

NOTE TO READERS: THE BELOW IS NOT AN OFFICIAL CHANGELOG OF ANY SORT AND SHOULD NOT BE INTERPRETED AS ONE. IT IS SIMPLY THE OUTPUT OF A CLASS I AM TESTING THAT WILL EVENTUALLY REPLACE THE BACKBONE OF THE CURRENT SET OF TOOLS SUCH AS WINAPPDEBUG. I have provided it for feedback purposes only
 

  Reveal hidden contents

 

Installer * has been modified.

[Installer *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect=HKCU\Software\Vivaldi
Default=False
FileKey1=%LocalAppData%\SuperBird\Application\*\Installer|*.7z
FileKey2=%LocalAppData%\Torch\Application\*\Installer|*.7z
FileKey3=%LocalAppData%\Vivaldi\Application\*\Installer|*.7z
FileKey4=%LocalAppData%\Yandex\YandexBrowser\Application\*\Installer|*.7z
FileKey5=%ProgramFiles%\Google\Chrome\Application\*\Installer|*.7z
----------------------------------------------------------------------------------------------------------------------
Web Data * has been modified.

[Web Data *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect1=HKCU\Software\Chromium
Detect2=HKCU\Software\SuperBird
Detect3=HKCU\Software\Torch
Detect4=HKCU\Software\Vivaldi
Default=False
Warning=This will remove Autofill, Autocomplete, Search Engines keyword, Sign-in and Credit Card info.
FileKey1=%LocalAppData%\Amigo\User Data\*\*|Web Data
FileKey2=%LocalAppData%\Chrome Plus\User Data\*|Web Data
FileKey3=%LocalAppData%\Chromium\User Data\*|Web Data
FileKey4=%LocalAppData%\Flock\User Data\*|Web Data
FileKey5=%LocalAppData%\Google\Chrome*\User Data\*|Web Data
FileKey6=%LocalAppData%\Rockmelt\User Data\*|Web Data
FileKey7=%LocalAppData%\SRWare Iron\User Data\*|Web Data
FileKey8=%LocalAppData%\SuperBird\User Data\*|Web Data
FileKey9=%LocalAppData%\Torch\User Data\*|Web Data
FileKey10=%LocalAppData%\Vivaldi\User Data\*|Web Data
----------------------------------------------------------------------------------------------------------------------
Active@ Disk Image * has been modified.

[Active@ Disk Image *]
LangSecRef=3024
Detect=HKLM\Software\LSoft Technologies\Active Disk Image
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
FileKey3=%ProgramFiles%\LSoft Technologies\Active@ Disk Image|*.txt
FileKey4=%ProgramFiles%\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Images * was removed.

[Active@ UNDELETE Images *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all saved disk images.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*\disk_images|*.*|REMOVESELF
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*\disk_images|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Recovered Files * was removed.

[Active@ UNDELETE Recovered Files *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all recovered data.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*\recovered|*.*|REMOVESELF
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*\recovered|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Sessions * was removed.

[Active@ UNDELETE Sessions *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all saved sessions.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*|*.usf|RECURSE
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*|*.usf|RECURSE
----------------------------------------------------------------------------------------------------------------------
Adobe Photoshop * has been modified.

[Adobe Photoshop *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\5.5\VisitedDirs
FileKey1=%AppData%\Adobe\Adobe Photoshop*\Generator\logs|*.*
FileKey2=%AppData%\Adobe\Bridge*\Cache\Thumbnails|*.*|RECURSE
FileKey3=%AppData%\Adobe\CameraRaw\Cache|*.*|RECURSE
FileKey4=%AppData%\Adobe\FileBrowser\PhotoshopCS|*.*
FileKey5=%AppData%\Adobe\Photoshop Album\*.*|Logse*.txt
FileKey6=%Pictures%|.BridgeSort|RECURSE
----------------------------------------------------------------------------------------------------------------------
Cameyo * has been modified.

[Cameyo *]
LangSecRef=3021
Detect=HKCU\Software\VOS
Default=False
RegKey1=HKCU\Software\VOS
FileKey1=%AppData%\VOS|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
CCDump * has been modified.

[CCDump *]
LangSecRef=3024
DetectFile=%ProgramFiles%\CCleaner\CCDump.exe
Default=False
Warning=This removes files winapp.ini, winsys.ini, winreg.ini and regkeys.output.txt from the CCleaner folder.
FileKey1=%ProgramFiles%\CCleaner|winapp.ini;winreg.ini;winsys.ini;regkeys.output.txt
----------------------------------------------------------------------------------------------------------------------
CD/DVD Burn Cache * has been modified.

[CD/DVD Burn Cache *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning
Default=False
Warning=This will wipe all files that are waiting to be burned to a CD/DVD/BD drive.
FileKey1=%LocalAppData%\Microsoft\CD Burning|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\Burn|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo
----------------------------------------------------------------------------------------------------------------------
DriverPack Solution * has been modified.

[DriverPack Solution *]
LangSecRef=3024
Detect=HKCU\Software\drpsu
Default=False
Warning=This will delete your bug report.
FileKey1=%AppData%\DRPSu\Logs|*.*
FileKey2=%AppData%\DRPSu\snapshots|*.*
FileKey3=%AppData%\DRPSu\temp|*.*
FileKey4=%Documents%\DRP-Log|*.*
FileKey5=%WinDir%\Logs\DRPLog|*.png;*.txt
FileKey6=%WinDir%\Logs\SysInfo|*.*
----------------------------------------------------------------------------------------------------------------------
DUC * was removed.

[DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%LocalAppData%\Vitalwerks\DUC|DUC.log
----------------------------------------------------------------------------------------------------------------------
ElsterFormular * has been modified.

[ElsterFormular *]
LangSecRef=3021
DetectFile=%AppData%\elsterformular
Default=False
FileKey1=%AppData%\elsterformular\*\log|*.log;*.log.*
FileKey2=%AppData%\elsterformular\*\tmp|*.*|RECURSE
FileKey3=%AppData%\elsterformular\pluginmanager\data|*_cpy.zip
FileKey4=%CommonAppData%\elsterformular\log|*.log
FileKey5=%LocalAppData%\.elfohilfe|*.*|REMOVESELF
FileKey6=%LocalAppData%\elfopatch|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
HyperSnap 7 * has been modified.

[HyperSnap 7 *]
LangSecRef=3021
Detect=HKCU\Software\Hyperionics\HyperSnap 7
Default=False
FileKey1=%ProgramFiles%\HyperSnap 7|*.url
RegKey1=HKCU\Software\Hyperionics\HyperSnap 7\Recent File List
----------------------------------------------------------------------------------------------------------------------
Intuit TurboTax * has been modified.

[Intuit TurboTax *]
LangSecRef=3021
DetectFile=%ProgramFiles%\TurboTax*
Default=False
FileKey1=%AppData%\Intuit*|*.log|RECURSE
FileKey2=%CommonAppData%|*.bc
FileKey3=%CommonAppData%\Intuit*|*.log|RECURSE
FileKey4=%CommonAppData%\Intuit\Common\Metrix\*\Logs|*.*
FileKey5=%CommonAppData%\Intuit\Common\QuickBaseClient\*\Logs|*.*
FileKey6=%CommonAppData%\Intuit\Common\Update Service\*\Logs|*.*
FileKey7=%CommonAppData%\Intuit\TurboTax\MSI\*\Logs|*.*
FileKey8=%CommonProgramFiles%\Intuit\Internet Client|Msdun13.exe
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Common Files\Intuit\Internet Client|Msdun13.exe
FileKey10=%LocalAppData%\VirtualStore\Program Files*\TurboTax*|*.txt
FileKey11=%LocalAppData%\VirtualStore\ProgramData|*.bc
FileKey12=%LocalAppData%\VirtualStore\ProgramData\Intuit*|*.log|RECURSE
FileKey13=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\Metrix\*\Logs|*.*
FileKey14=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\QuickBaseClient\*\Logs|*.*
FileKey15=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\Update Service\*\Logs|*.*
FileKey16=%LocalAppData%\VirtualStore\ProgramData\Intuit\TurboTax\MSI\*\Logs|*.*
FileKey17=%ProgramFiles%\TurboTax*|*.txt
----------------------------------------------------------------------------------------------------------------------
Macrium Reflect * has been modified.

[Macrium Reflect *]
LangSecRef=3024
Detect=HKCU\Software\Macrium\Reflect
Default=False
FileKey1=%CommonAppData%\Macrium|*.log|RECURSE
FileKey2=%CommonAppData%\Macrium\Reflect|*.html;*.vsslog
FileKey3=%CommonAppData%\Macrium\waik|waiklog.txt
FileKey4=%SystemDrive%|ref~tmp~.txt;Reflect_Install.log;rescuepe.log
----------------------------------------------------------------------------------------------------------------------
MS Search * has been modified.

[MS Search *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey2=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey4=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
FileKey9=%UserProfile%\Searches|*.search-ms
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
RegKey2=HKLM\Software\Microsoft\Windows Search\VolumeInfoCache
----------------------------------------------------------------------------------------------------------------------
Nitro PDF Reader * has been modified.

[Nitro PDF Reader *]
LangSecRef=3024
Detect=HKCU\Software\Nitro PDF\Reader
Default=False
RegKey1=HKCU\Software\Nitro PDF\Reader\1.0\Recent File List
RegKey2=HKCU\Software\Nitro PDF\Reader\2.0\Recent File List
FileKey1=%AppData%\Nitro|*.log*;*Log.txt*|RECURSE
----------------------------------------------------------------------------------------------------------------------
Notepad++ * has been modified.

[Notepad++ *]
LangSecRef=3021
Detect=HKLM\Software\Notepad++
Default=False
FileKey1=%AppData%\Notepad++\plugins\config|PluginManagerGpup.xml;PluginManagerPlugins.xml;PluginManagerPlugins.zip
FileKey2=%AppData%\Notepad++\plugins\config\plugin_install_temp|*.*|REMOVESELF
FileKey3=%ProgramFiles%\Notepad++\plugins\disabled|*.*
----------------------------------------------------------------------------------------------------------------------
OpenDNS Updater * has been modified.

[OpenDNS Updater *]
LangSecRef=3021
Detect=HKCU\Software\OpenDNS Updater
Default=False
Warning=You must exit OpenDNS Updater in the System Tray to clear log files.
FileKey1=%AppData%\OpenDNS Updater|*.txt
----------------------------------------------------------------------------------------------------------------------
OpenOffice.org Setup Files * has been modified.

[OpenOffice.org Setup Files *]
LangSecRef=3021
Detect1=HKLM\Software\OpenOffice
Detect2=HKLM\Software\OpenOffice.org
Default=False
FileKey1=%UserProfile%\Desktop\OpenOffice.org * Installation Files|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Pando * has been modified.

[Pando *]
Detect=HKCU\Software\Pando Networks\Pando
LangSecRef=3024
Default=False
Warning=Make sure Pando is totally shut down before using this.
FileKey1=%LocalAppData%\Pando\Pando Files|*.*|RECURSE
ExcludeKey1=PATH|%LocalAppData%\Pando\Pando Files\|*pando.prev.log;*pando.log;*pando.sav;*pando.save;*pando.txt
ExcludeKey2=PATH|%LocalAppData%\Pando\Pando Files\Cert\|*.*
----------------------------------------------------------------------------------------------------------------------
Photos * has been modified.

[Photos *]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState|*.sqlite;*.sqlite-shm;*.sqlite-wal;*.xml
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState\PhotosAppTile|*.*|RECURSE
FileKey10=%LocalAppData%\PackagesMicrosoft.Windows.Photos_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedPickerData\Microsoft.Windows.Photos_8wekyb3d8bbwe!App\DefaultSaveFileSingle
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\MostRecentlyUsed
----------------------------------------------------------------------------------------------------------------------
QTTabBar * has been modified.

[QTTabBar *]
LangSecRef=3024
Detect=HKCU\Software\Quizo\QTTabBar
Default=False
FileKey1=%AppData%\QTTabBar|*.log
RegKey1=HKCU\Software\Quizo\QTTabBar|TabsOnLastClosedWindow
RegKey2=HKCU\Software\Quizo\QTTabBar\Cache
RegKey3=HKCU\Software\Quizo\QTTabBar\RecentlyClosed
----------------------------------------------------------------------------------------------------------------------
Saved Search Folders * was removed.

[Saved Search Folders *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=Can cause issues on Windows 8 or newer
FileKey1=%UserProfile%\Searches|*.search-ms
----------------------------------------------------------------------------------------------------------------------
SoftEther VPN * has been modified.

[SoftEther VPN *]
LangSecRef=3024
Detect=HKCU\Software\SoftEther Project\SoftEther VPN
Default=False
Warning=Exclude installer.cache if you're using SoftEther VPN Client Web Installer.
FileKey1=%ProgramFiles%\SoftEther VPN Client|installer.cache
FileKey2=%ProgramFiles%\SoftEther VPN Client\backup.vpn_client.config|*.config
FileKey3=%ProgramFiles%\SoftEther VPN Client\client_log|*.*
FileKey4=%ProgramFiles%\SoftEther VPN Client\vpn_debug|*.*
----------------------------------------------------------------------------------------------------------------------
TortoiseSVN History * has been modified.

[TortoiseSVN History *]
LangSecRef=3024
Detect=HKCU\Software\TortoiseSVN
Default=False
Warning=This will remove your repo paths and last checkout location.
RegKey1=HKCU\Software\TortoiseSVN\History
----------------------------------------------------------------------------------------------------------------------
UsbFix * has been modified.

[UsbFix *]
LangSecRef=3023
Detect=HKCU\Software\UsbFix
Default=False
FileKey1=%SystemDrive%\UsbFix\Log|*.*|REMOVESELF
FileKey2=%SystemDrive%\UsbFix\Quarantine|*.*|REMOVESELF
FileKey3=%UserProfile%\Desktop|UsbFix_Report.txt
RegKey1=HKCU\Software\UsbFix\LastReport
----------------------------------------------------------------------------------------------------------------------
VSO Media Player 1 * has been modified.

[VSO Media Player 1 *]
LangSecRef=3023
Detect=HKCU\Software\VSO\VSO Media Player\1
Default=False
RegKey1=HKCU\Software\VSO\VSO Media Player\1\RecentlyOpenedFiles
FileKey1=%AppData%\VSO\VSO Media Player\1|autoresume.xml
FileKey2=%CommonAppData%\VSO|font.cache
FileKey3=%CommonAppData%\VSO\VSO Media Player\1\log|*.log;*.crashlist
FileKey4=%CommonAppData%\VSO\vsothumbs|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\VSO|font.cache
FileKey6=%LocalAppData%\VirtualStore\ProgramData\VSO\VSO Media Player\1\log|*.log;*.crashlist
FileKey7=%LocalAppData%\VirtualStore\ProgramData\VSO\vsothumbs|*.*|RECURSE
----------------------------------------------------------------------------------------------------------------------
Windows Media Center * has been modified.

[Windows Media Center *]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\MRU\SettingsMRU
FileKey1=%CommonAppData%\Microsoft\eHome\thmb|TVThumb.db
FileKey2=%LocalAppData%\Microsoft\Ehome|Image.db;Video.db;musicThumbs.db
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Microsoft\eHome\thmb|TVThumb.db
----------------------------------------------------------------------------------------------------------------------
Windows ShellBags * has been modified.

[Windows ShellBags *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This will reset folders size, view, icon or position settings to default and remove traces of the folders that do not exist anymore.
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags
RegKey3=HKCU\Software\Microsoft\Windows\Shell\BagMRU
RegKey4=HKCU\Software\Microsoft\Windows\Shell\Bags
RegKey5=HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU
RegKey6=HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
ExcludeKey1=REG|HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey2=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop
ExcludeKey3=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey4=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Desktop
ExcludeKey5=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\AllFolders
----------------------------------------------------------------------------------------------------------------------
X-Chat 2 * has been modified.

[X-Chat 2 *]
LangSecRef=3022
DetectFile=%AppData%\X-Chat 2
Default=False
Warning=This removes Chat Scrollback and Logs.
FileKey1=%AppData%\X-Chat 2\scrollback|*.*|REMOVESELF
FileKey2=%AppData%\X-Chat 2\xchatlogs|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
No-IP DUC * was added.

[No-IP DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%CommonAppData%\Vitalwerks\DUC|*.log
FileKey2=%LocalAppData%\Vitalwerks\DUC|*.log
----------------------------------------------------------------------------------------------------------------------

Note: the above output doesn't reflect any particular current set of changes and should not be interpreted as a changelog. It is only an example of the output of the compareTo method for a new class I wrote that will eventually be used replace the backbone of the current set of tools

Now we're talking. Thanks for putting the work into that, looking forward to keeping an up to date winapp2.ini again :D

Share this post


Link to post
Share on other sites
On 1/8/2018 at 06:54, APMichael said:

Sorry, but you overlooked it.

We can remove the entry [Explorer MRUs *], because it is in winsys.ini already:

[Window Size/Location Cache] ...
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams

 

On 1/8/2018 at 10:38, SMalik said:

I’m sorry. I think they should move these into the 'Other Explorer MRUs' entry.

Like [Windows ShellBags *], [Window Size/Location Cache] may be an entry users may NOT wish to enable. I know this is true for me. So, keeping [Window Size/Location Cache] as a separate entry from [Other Explorer MRUs] entry, as is the case currently in winsys.ini, would be preferable for these users.

Share this post


Link to post
Share on other sites

This one IS a changelog.

Changes made between  Version: 180107 and  Version: 180111
Installer * has been modified.

[Installer *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect=HKCU\Software\Vivaldi
Default=False
FileKey1=%LocalAppData%\SuperBird\Application\*\Installer|*.7z
FileKey2=%LocalAppData%\Torch\Application\*\Installer|*.7z
FileKey3=%LocalAppData%\Vivaldi\Application\*\Installer|*.7z
FileKey4=%LocalAppData%\Yandex\YandexBrowser\Application\*\Installer|*.7z
FileKey5=%ProgramFiles%\Google\Chrome\Application\*\Installer|*.7z
----------------------------------------------------------------------------------------------------------------------
Web Data * has been modified.

[Web Data *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect1=HKCU\Software\Chromium
Detect2=HKCU\Software\SuperBird
Detect3=HKCU\Software\Torch
Detect4=HKCU\Software\Vivaldi
Default=False
Warning=This will remove Autofill, Autocomplete, Search Engines keyword, Sign-in and Credit Card info.
FileKey1=%LocalAppData%\Amigo\User Data\*\*|Web Data
FileKey2=%LocalAppData%\Chrome Plus\User Data\*|Web Data
FileKey3=%LocalAppData%\Chromium\User Data\*|Web Data
FileKey4=%LocalAppData%\Flock\User Data\*|Web Data
FileKey5=%LocalAppData%\Google\Chrome*\User Data\*|Web Data
FileKey6=%LocalAppData%\Rockmelt\User Data\*|Web Data
FileKey7=%LocalAppData%\SRWare Iron\User Data\*|Web Data
FileKey8=%LocalAppData%\SuperBird\User Data\*|Web Data
FileKey9=%LocalAppData%\Torch\User Data\*|Web Data
FileKey10=%LocalAppData%\Vivaldi\User Data\*|Web Data
----------------------------------------------------------------------------------------------------------------------
Active@ Disk Image * has been modified.

[Active@ Disk Image *]
LangSecRef=3024
Detect=HKLM\Software\LSoft Technologies\Active Disk Image
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
FileKey3=%ProgramFiles%\LSoft Technologies\Active@ Disk Image|*.txt
FileKey4=%ProgramFiles%\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Images * was removed.

[Active@ UNDELETE Images *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all saved disk images.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*\disk_images|*.*|REMOVESELF
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*\disk_images|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Recovered Files * was removed.

[Active@ UNDELETE Recovered Files *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all recovered data.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*\recovered|*.*|REMOVESELF
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*\recovered|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Sessions * was removed.

[Active@ UNDELETE Sessions *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all saved sessions.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*|*.usf|RECURSE
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*|*.usf|RECURSE
----------------------------------------------------------------------------------------------------------------------
Apple MobileSync Backups * has been modified.

[Apple MobileSync Backups *]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.
Default=False
FileKey1=%AppData%\Apple Computer\MobileSync\Backup|*.*|RECURSE
----------------------------------------------------------------------------------------------------------------------
CCDump * has been modified.

[CCDump *]
LangSecRef=3024
DetectFile=%ProgramFiles%\CCleaner\CCDump.exe
Default=False
Warning=This removes files winapp.ini, winsys.ini, winreg.ini and regkeys.output.txt from the CCleaner folder.
FileKey1=%ProgramFiles%\CCleaner|winapp.ini;winreg.ini;winsys.ini;regkeys.output.txt
----------------------------------------------------------------------------------------------------------------------
CD/DVD Burn Cache * has been modified.

[CD/DVD Burn Cache *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning
Default=False
Warning=This will wipe all files that are waiting to be burned to a CD/DVD/BD drive.
FileKey1=%LocalAppData%\Microsoft\CD Burning|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\Burn|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo
----------------------------------------------------------------------------------------------------------------------
DriverPack Solution * has been modified.

[DriverPack Solution *]
LangSecRef=3024
Detect=HKCU\Software\drpsu
Default=False
Warning=This will delete your bug report.
FileKey1=%AppData%\DRPSu\Logs|*.*
FileKey2=%AppData%\DRPSu\snapshots|*.*
FileKey3=%AppData%\DRPSu\temp|*.*
FileKey4=%Documents%\DRP-Log|*.*
FileKey5=%WinDir%\Logs\DRPLog|*.png;*.txt
FileKey6=%WinDir%\Logs\SysInfo|*.*
----------------------------------------------------------------------------------------------------------------------
DUC * was removed.

[DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%LocalAppData%\Vitalwerks\DUC|DUC.log
----------------------------------------------------------------------------------------------------------------------
ElsterFormular * has been modified.

[ElsterFormular *]
LangSecRef=3021
DetectFile=%AppData%\elsterformular
Default=False
FileKey1=%AppData%\elsterformular\*\log|*.log;*.log.*
FileKey2=%AppData%\elsterformular\*\tmp|*.*|RECURSE
FileKey3=%AppData%\elsterformular\pluginmanager\data|*_cpy.zip
FileKey4=%CommonAppData%\elsterformular\log|*.log
FileKey5=%LocalAppData%\.elfohilfe|*.*|REMOVESELF
FileKey6=%LocalAppData%\elfopatch|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Explorer MRUs * has been modified.

[Explorer MRUs *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams
----------------------------------------------------------------------------------------------------------------------
Hauppauge WinTV * has been modified.

[Hauppauge WinTV *]
LangSecRef=3024
Detect=HKLM\Software\Hauppauge
Default=False
FileKey1=%Public%\WinTV|Settings-old.xml
FileKey2=%Public%\WinTV\Channel Database|hcwChanDB_5-lastgood.mdb
FileKey3=%Public%\WinTV\Installation Log|*.*|RECURSE
FileKey4=%Public%\WinTV\Logs|*.log;*.txt
FileKey5=%Public%\WinTV\Logs\minidump|*.*|RECURSE
FileKey6=%SystemDrive%|hcwDriverInstall.txt
----------------------------------------------------------------------------------------------------------------------
HyperSnap 7 * has been modified.

[HyperSnap 7 *]
LangSecRef=3021
Detect=HKCU\Software\Hyperionics\HyperSnap 7
Default=False
FileKey1=%ProgramFiles%\HyperSnap 7|*.url
RegKey1=HKCU\Software\Hyperionics\HyperSnap 7\Recent File List
----------------------------------------------------------------------------------------------------------------------
Internet Explorer * has been modified.

[Internet Explorer *]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Internet Explorer
Default=False
FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE
FileKey3=%LocalAppData%\Microsoft\Windows\IECompatCache|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Windows\IECompatUaCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey9=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*
FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*
FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE
FileKey15=%WinDir%\System32\config\Systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
RegKey1=HKCR\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage
RegKey2=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore
RegKey3=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage
RegKey4=HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl
RegKey5=HKCU\Software\Microsoft\Internet Explorer\Recovery\PendingDelete
RegKey6=HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
----------------------------------------------------------------------------------------------------------------------
IObit Advanced SystemCare * has been modified.

[IObit Advanced SystemCare *]
LangSecRef=3024
DetectFile1=%AppData%\IObit\Advanced SystemCare V*
DetectFile2=%CommonAppData%\IObit\Advanced SystemCare V*
Default=False
FileKey1=%AppData%\IObit\Advanced SystemCare *|*.log
FileKey2=%AppData%\IObit\Advanced SystemCare *\Boottime|*.log
FileKey3=%AppData%\IObit\Advanced SystemCare *\EmptyFolder|*.*|RECURSE
FileKey4=%AppData%\IObit\Advanced SystemCare *\Log|*.*|RECURSE
FileKey5=%CommonAppData%\IObit\Advanced SystemCare *\Log|*.*|REMOVESELF
FileKey6=%CommonAppData%\IObit\ASCDownloader|*.log
FileKey7=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *|*.log;*.txt|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *\*.cab_Temp|*.*|REMOVESELF
FileKey9=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *\ASCServiceLog|*.*|RECURSE
FileKey10=%LocalAppData%\VirtualStore\ProgramData\IObit\Advanced SystemCare *\Log|*.*|RECURSE
FileKey11=%LocalAppData%\VirtualStore\ProgramData\IObit\ASCDownloader|*.log
FileKey12=%ProgramFiles%\IObit\Advanced SystemCare *|*.log;*.txt|RECURSE
FileKey13=%ProgramFiles%\IObit\Advanced SystemCare *\*.cab_Temp|*.*|REMOVESELF
FileKey14=%ProgramFiles%\IObit\Advanced SystemCare *\ASCServiceLog|*.*|RECURSE
FileKey15=%SystemDrive%\Users\Default\AppData\Roaming\IObit\Advanced SystemCare *|*.log
FileKey16=%WinDir%\System32\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare *|*.log
FileKey17=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare *|*.log
----------------------------------------------------------------------------------------------------------------------
K-Lite Codec Pack * has been modified.

[K-Lite Codec Pack *]
LangSecRef=3023
Detect=HKLM\Software\KLCodecPack
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\K-Lite*|*.log;*.txt|RECURSE
FileKey2=%ProgramFiles%\K-Lite*|*.log;*.txt|RECURSE
FileKey3=%SystemDrive%|*klcp_itp_*.tmp;*klcp_iph_*.tmp
FileKey4=%UserProfile%\Desktop|klcp_codec_log.txt
RegKey1=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path0
RegKey2=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path1
RegKey3=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path2
----------------------------------------------------------------------------------------------------------------------
Macrium Reflect * has been modified.

[Macrium Reflect *]
LangSecRef=3024
Detect=HKCU\Software\Macrium\Reflect
Default=False
FileKey1=%CommonAppData%\Macrium|*.log|RECURSE
FileKey2=%CommonAppData%\Macrium\Reflect|*.html;*.vsslog
FileKey3=%CommonAppData%\Macrium\waik|waiklog.txt
FileKey4=%SystemDrive%|ref~tmp~.txt;Reflect_Install.log;rescuepe.log
----------------------------------------------------------------------------------------------------------------------
MS Search * has been modified.

[MS Search *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey2=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey4=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
FileKey5=%UserProfile%\Searches|*.search-ms
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
RegKey2=HKLM\Software\Microsoft\Windows Search\VolumeInfoCache
----------------------------------------------------------------------------------------------------------------------
Notepad++ * has been modified.

[Notepad++ *]
LangSecRef=3021
Detect=HKLM\Software\Notepad++
Default=False
FileKey1=%AppData%\Notepad++\plugins\config|PluginManagerGpup.xml;PluginManagerPlugins.xml;PluginManagerPlugins.zip
FileKey2=%AppData%\Notepad++\plugins\config\plugin_install_temp|*.*|REMOVESELF
FileKey3=%ProgramFiles%\Notepad++\plugins\disabled|*.*
----------------------------------------------------------------------------------------------------------------------
OpenDNS Updater * has been modified.

[OpenDNS Updater *]
LangSecRef=3021
Detect=HKCU\Software\OpenDNS Updater
Default=False
Warning=You must exit OpenDNS Updater in the System Tray to clear log files.
FileKey1=%AppData%\OpenDNS Updater|*.txt
----------------------------------------------------------------------------------------------------------------------
OpenOffice.org Setup Files * has been modified.

[OpenOffice.org Setup Files *]
LangSecRef=3021
Detect1=HKLM\Software\OpenOffice
Detect2=HKLM\Software\OpenOffice.org
Default=False
FileKey1=%UserProfile%\Desktop\OpenOffice.org * Installation Files|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Pando * has been modified.

[Pando *]
Detect=HKCU\Software\Pando Networks\Pando
LangSecRef=3024
Default=False
Warning=Make sure Pando is totally shut down before using this.
FileKey1=%LocalAppData%\Pando\Pando Files|*.*|RECURSE
ExcludeKey1=PATH|%LocalAppData%\Pando\Pando Files\|*pando.prev.log;*pando.log;*pando.sav;*pando.save;*pando.txt
ExcludeKey2=PATH|%LocalAppData%\Pando\Pando Files\Cert\|*.*
----------------------------------------------------------------------------------------------------------------------
Photos * has been modified.

[Photos *]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState|*.sqlite;*.sqlite-shm;*.sqlite-wal;*.xml
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState\PhotosAppTile|*.*|RECURSE
FileKey10=%LocalAppData%\PackagesMicrosoft.Windows.Photos_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedPickerData\Microsoft.Windows.Photos_8wekyb3d8bbwe!App\DefaultSaveFileSingle
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\MostRecentlyUsed
----------------------------------------------------------------------------------------------------------------------
QTTabBar * has been modified.

[QTTabBar *]
LangSecRef=3024
Detect=HKCU\Software\Quizo\QTTabBar
Default=False
FileKey1=%AppData%\QTTabBar|*.log
RegKey1=HKCU\Software\Quizo\QTTabBar|TabsOnLastClosedWindow
RegKey2=HKCU\Software\Quizo\QTTabBar\Cache
RegKey3=HKCU\Software\Quizo\QTTabBar\RecentlyClosed
----------------------------------------------------------------------------------------------------------------------
Saved Search Folders * was removed.

[Saved Search Folders *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=Can cause issues on Windows 8 or newer
FileKey1=%UserProfile%\Searches|*.search-ms
----------------------------------------------------------------------------------------------------------------------
Snagit * has been modified.

[Snagit *]
LangSecRef=3021
Detect=HKCU\Software\TechSmith\Snagit
Default=False
Warning=This will delete the backups of the captures.
FileKey1=%CommonAppData%\TechSmith\Uploader|*.log
FileKey2=%Documents%|SnagitDebug.log
FileKey3=%LocalAppData%\TechSmith\Logs|*.log
FileKey4=%LocalAppData%\TechSmith\Snagit|Tray.bin
FileKey5=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE
FileKey6=%LocalAppData%\TechSmith\Snagit\DataStore|*.SNAG;*.SNAGundo;*.MP4
FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico
FileKey8=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico
FileKey9=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE
FileKey10=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log
RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder
RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder
RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount
RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount
RegKey5=HKCU\Software\TechSmith\Snagit\12|CaptureCount
RegKey6=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount
RegKey7=HKCU\Software\TechSmith\Snagit\13|CaptureCount
RegKey8=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount
RegKey9=HKCU\Software\TechSmith\Snagit\13\Recent Captures
RegKey10=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List
RegKey11=HKCU\Software\TechSmith\Snagit\18|CaptureCount
RegKey12=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount
RegKey13=HKCU\Software\TechSmith\Snagit\18\Recent Captures
RegKey14=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List
RegKey15=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder
----------------------------------------------------------------------------------------------------------------------
SoftEther VPN * has been modified.

[SoftEther VPN *]
LangSecRef=3024
Detect=HKCU\Software\SoftEther Project\SoftEther VPN
Default=False
Warning=Exclude installer.cache if you're using SoftEther VPN Client Web Installer.
FileKey1=%ProgramFiles%\SoftEther VPN Client|installer.cache
FileKey2=%ProgramFiles%\SoftEther VPN Client\backup.vpn_client.config|*.config
FileKey3=%ProgramFiles%\SoftEther VPN Client\client_log|*.*
FileKey4=%ProgramFiles%\SoftEther VPN Client\vpn_debug|*.*
----------------------------------------------------------------------------------------------------------------------
TortoiseSVN History * has been modified.

[TortoiseSVN History *]
LangSecRef=3024
Detect=HKCU\Software\TortoiseSVN
Default=False
Warning=This will remove your repo paths and last checkout location.
RegKey1=HKCU\Software\TortoiseSVN\History
----------------------------------------------------------------------------------------------------------------------
UsbFix * has been modified.

[UsbFix *]
LangSecRef=3023
Detect=HKCU\Software\UsbFix
Default=False
FileKey1=%SystemDrive%\UsbFix\Log|*.*|REMOVESELF
FileKey2=%SystemDrive%\UsbFix\Quarantine|*.*|REMOVESELF
FileKey3=%UserProfile%\Desktop|UsbFix_Report.txt
RegKey1=HKCU\Software\UsbFix\LastReport
----------------------------------------------------------------------------------------------------------------------
Windows ShellBags * has been modified.

[Windows ShellBags *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This will reset folders size, view, icon or position settings to default and remove traces of the folders that do not exist anymore.
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags
RegKey3=HKCU\Software\Microsoft\Windows\Shell\BagMRU
RegKey4=HKCU\Software\Microsoft\Windows\Shell\Bags
RegKey5=HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU
RegKey6=HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
ExcludeKey1=REG|HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey2=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop
ExcludeKey3=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey4=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Desktop
ExcludeKey5=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\AllFolders
----------------------------------------------------------------------------------------------------------------------
X-Chat 2 * has been modified.

[X-Chat 2 *]
LangSecRef=3022
DetectFile=%AppData%\X-Chat 2
Default=False
Warning=This removes Chat Scrollback and Logs.
FileKey1=%AppData%\X-Chat 2\scrollback|*.*|REMOVESELF
FileKey2=%AppData%\X-Chat 2\xchatlogs|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
No-IP DUC * was added.

[No-IP DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%CommonAppData%\Vitalwerks\DUC|*.log
FileKey2=%LocalAppData%\Vitalwerks\DUC|*.log
----------------------------------------------------------------------------------------------------------------------

Share this post


Link to post
Share on other sites

Here is a demo of the new multitool (winapp2ool): https://github.com/MoscaDotTo/Winapp2/tree/master/Tools/beta

 

Please give it a try, it includes a slightly improved WinappDebug, ccinidebug, a new module called "diff" that compares two winapp2.ini versions and outputs the changes, and a trimming module with an option to both overwrite the existing winapp2.ini file or to output to a new file called winapp2-trimmed.ini

Recommended that you run it as an administrator, many of the functions don't work will without elevation. Trim especially, as it can't access certain registry keys without elevation and will as a result, erroneously trim entries from your file.

Share this post


Link to post
Share on other sites
9 hours ago, Winapp2.ini said:

This one IS a changelog.

 

  Hide contents

 

Changes made between  Version: 180107 and  Version: 180111
Installer * has been modified.

[Installer *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect=HKCU\Software\Vivaldi
Default=False
FileKey1=%LocalAppData%\SuperBird\Application\*\Installer|*.7z
FileKey2=%LocalAppData%\Torch\Application\*\Installer|*.7z
FileKey3=%LocalAppData%\Vivaldi\Application\*\Installer|*.7z
FileKey4=%LocalAppData%\Yandex\YandexBrowser\Application\*\Installer|*.7z
FileKey5=%ProgramFiles%\Google\Chrome\Application\*\Installer|*.7z
----------------------------------------------------------------------------------------------------------------------
Web Data * has been modified.

[Web Data *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect1=HKCU\Software\Chromium
Detect2=HKCU\Software\SuperBird
Detect3=HKCU\Software\Torch
Detect4=HKCU\Software\Vivaldi
Default=False
Warning=This will remove Autofill, Autocomplete, Search Engines keyword, Sign-in and Credit Card info.
FileKey1=%LocalAppData%\Amigo\User Data\*\*|Web Data
FileKey2=%LocalAppData%\Chrome Plus\User Data\*|Web Data
FileKey3=%LocalAppData%\Chromium\User Data\*|Web Data
FileKey4=%LocalAppData%\Flock\User Data\*|Web Data
FileKey5=%LocalAppData%\Google\Chrome*\User Data\*|Web Data
FileKey6=%LocalAppData%\Rockmelt\User Data\*|Web Data
FileKey7=%LocalAppData%\SRWare Iron\User Data\*|Web Data
FileKey8=%LocalAppData%\SuperBird\User Data\*|Web Data
FileKey9=%LocalAppData%\Torch\User Data\*|Web Data
FileKey10=%LocalAppData%\Vivaldi\User Data\*|Web Data
----------------------------------------------------------------------------------------------------------------------
Active@ Disk Image * has been modified.

[Active@ Disk Image *]
LangSecRef=3024
Detect=HKLM\Software\LSoft Technologies\Active Disk Image
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
FileKey3=%ProgramFiles%\LSoft Technologies\Active@ Disk Image|*.txt
FileKey4=%ProgramFiles%\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Images * was removed.

[Active@ UNDELETE Images *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all saved disk images.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*\disk_images|*.*|REMOVESELF
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*\disk_images|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Recovered Files * was removed.

[Active@ UNDELETE Recovered Files *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all recovered data.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*\recovered|*.*|REMOVESELF
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*\recovered|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Sessions * was removed.

[Active@ UNDELETE Sessions *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all saved sessions.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*|*.usf|RECURSE
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*|*.usf|RECURSE
----------------------------------------------------------------------------------------------------------------------
Apple MobileSync Backups * has been modified.

[Apple MobileSync Backups *]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.
Default=False
FileKey1=%AppData%\Apple Computer\MobileSync\Backup|*.*|RECURSE
----------------------------------------------------------------------------------------------------------------------
CCDump * has been modified.

[CCDump *]
LangSecRef=3024
DetectFile=%ProgramFiles%\CCleaner\CCDump.exe
Default=False
Warning=This removes files winapp.ini, winsys.ini, winreg.ini and regkeys.output.txt from the CCleaner folder.
FileKey1=%ProgramFiles%\CCleaner|winapp.ini;winreg.ini;winsys.ini;regkeys.output.txt
----------------------------------------------------------------------------------------------------------------------
CD/DVD Burn Cache * has been modified.

[CD/DVD Burn Cache *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning
Default=False
Warning=This will wipe all files that are waiting to be burned to a CD/DVD/BD drive.
FileKey1=%LocalAppData%\Microsoft\CD Burning|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\Burn|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo
----------------------------------------------------------------------------------------------------------------------
DriverPack Solution * has been modified.

[DriverPack Solution *]
LangSecRef=3024
Detect=HKCU\Software\drpsu
Default=False
Warning=This will delete your bug report.
FileKey1=%AppData%\DRPSu\Logs|*.*
FileKey2=%AppData%\DRPSu\snapshots|*.*
FileKey3=%AppData%\DRPSu\temp|*.*
FileKey4=%Documents%\DRP-Log|*.*
FileKey5=%WinDir%\Logs\DRPLog|*.png;*.txt
FileKey6=%WinDir%\Logs\SysInfo|*.*
----------------------------------------------------------------------------------------------------------------------
DUC * was removed.

[DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%LocalAppData%\Vitalwerks\DUC|DUC.log
----------------------------------------------------------------------------------------------------------------------
ElsterFormular * has been modified.

[ElsterFormular *]
LangSecRef=3021
DetectFile=%AppData%\elsterformular
Default=False
FileKey1=%AppData%\elsterformular\*\log|*.log;*.log.*
FileKey2=%AppData%\elsterformular\*\tmp|*.*|RECURSE
FileKey3=%AppData%\elsterformular\pluginmanager\data|*_cpy.zip
FileKey4=%CommonAppData%\elsterformular\log|*.log
FileKey5=%LocalAppData%\.elfohilfe|*.*|REMOVESELF
FileKey6=%LocalAppData%\elfopatch|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Explorer MRUs * has been modified.

[Explorer MRUs *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams
----------------------------------------------------------------------------------------------------------------------
Hauppauge WinTV * has been modified.

[Hauppauge WinTV *]
LangSecRef=3024
Detect=HKLM\Software\Hauppauge
Default=False
FileKey1=%Public%\WinTV|Settings-old.xml
FileKey2=%Public%\WinTV\Channel Database|hcwChanDB_5-lastgood.mdb
FileKey3=%Public%\WinTV\Installation Log|*.*|RECURSE
FileKey4=%Public%\WinTV\Logs|*.log;*.txt
FileKey5=%Public%\WinTV\Logs\minidump|*.*|RECURSE
FileKey6=%SystemDrive%|hcwDriverInstall.txt
----------------------------------------------------------------------------------------------------------------------
HyperSnap 7 * has been modified.

[HyperSnap 7 *]
LangSecRef=3021
Detect=HKCU\Software\Hyperionics\HyperSnap 7
Default=False
FileKey1=%ProgramFiles%\HyperSnap 7|*.url
RegKey1=HKCU\Software\Hyperionics\HyperSnap 7\Recent File List
----------------------------------------------------------------------------------------------------------------------
Internet Explorer * has been modified.

[Internet Explorer *]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Internet Explorer
Default=False
FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE
FileKey3=%LocalAppData%\Microsoft\Windows\IECompatCache|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Windows\IECompatUaCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey9=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*
FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*
FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE
FileKey15=%WinDir%\System32\config\Systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
RegKey1=HKCR\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage
RegKey2=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore
RegKey3=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage
RegKey4=HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl
RegKey5=HKCU\Software\Microsoft\Internet Explorer\Recovery\PendingDelete
RegKey6=HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
----------------------------------------------------------------------------------------------------------------------
IObit Advanced SystemCare * has been modified.

[IObit Advanced SystemCare *]
LangSecRef=3024
DetectFile1=%AppData%\IObit\Advanced SystemCare V*
DetectFile2=%CommonAppData%\IObit\Advanced SystemCare V*
Default=False
FileKey1=%AppData%\IObit\Advanced SystemCare *|*.log
FileKey2=%AppData%\IObit\Advanced SystemCare *\Boottime|*.log
FileKey3=%AppData%\IObit\Advanced SystemCare *\EmptyFolder|*.*|RECURSE
FileKey4=%AppData%\IObit\Advanced SystemCare *\Log|*.*|RECURSE
FileKey5=%CommonAppData%\IObit\Advanced SystemCare *\Log|*.*|REMOVESELF
FileKey6=%CommonAppData%\IObit\ASCDownloader|*.log
FileKey7=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *|*.log;*.txt|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *\*.cab_Temp|*.*|REMOVESELF
FileKey9=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *\ASCServiceLog|*.*|RECURSE
FileKey10=%LocalAppData%\VirtualStore\ProgramData\IObit\Advanced SystemCare *\Log|*.*|RECURSE
FileKey11=%LocalAppData%\VirtualStore\ProgramData\IObit\ASCDownloader|*.log
FileKey12=%ProgramFiles%\IObit\Advanced SystemCare *|*.log;*.txt|RECURSE
FileKey13=%ProgramFiles%\IObit\Advanced SystemCare *\*.cab_Temp|*.*|REMOVESELF
FileKey14=%ProgramFiles%\IObit\Advanced SystemCare *\ASCServiceLog|*.*|RECURSE
FileKey15=%SystemDrive%\Users\Default\AppData\Roaming\IObit\Advanced SystemCare *|*.log
FileKey16=%WinDir%\System32\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare *|*.log
FileKey17=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare *|*.log
----------------------------------------------------------------------------------------------------------------------
K-Lite Codec Pack * has been modified.

[K-Lite Codec Pack *]
LangSecRef=3023
Detect=HKLM\Software\KLCodecPack
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\K-Lite*|*.log;*.txt|RECURSE
FileKey2=%ProgramFiles%\K-Lite*|*.log;*.txt|RECURSE
FileKey3=%SystemDrive%|*klcp_itp_*.tmp;*klcp_iph_*.tmp
FileKey4=%UserProfile%\Desktop|klcp_codec_log.txt
RegKey1=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path0
RegKey2=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path1
RegKey3=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path2
----------------------------------------------------------------------------------------------------------------------
Macrium Reflect * has been modified.

[Macrium Reflect *]
LangSecRef=3024
Detect=HKCU\Software\Macrium\Reflect
Default=False
FileKey1=%CommonAppData%\Macrium|*.log|RECURSE
FileKey2=%CommonAppData%\Macrium\Reflect|*.html;*.vsslog
FileKey3=%CommonAppData%\Macrium\waik|waiklog.txt
FileKey4=%SystemDrive%|ref~tmp~.txt;Reflect_Install.log;rescuepe.log
----------------------------------------------------------------------------------------------------------------------
MS Search * has been modified.

[MS Search *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey2=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey4=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
FileKey5=%UserProfile%\Searches|*.search-ms
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
RegKey2=HKLM\Software\Microsoft\Windows Search\VolumeInfoCache
----------------------------------------------------------------------------------------------------------------------
Notepad++ * has been modified.

[Notepad++ *]
LangSecRef=3021
Detect=HKLM\Software\Notepad++
Default=False
FileKey1=%AppData%\Notepad++\plugins\config|PluginManagerGpup.xml;PluginManagerPlugins.xml;PluginManagerPlugins.zip
FileKey2=%AppData%\Notepad++\plugins\config\plugin_install_temp|*.*|REMOVESELF
FileKey3=%ProgramFiles%\Notepad++\plugins\disabled|*.*
----------------------------------------------------------------------------------------------------------------------
OpenDNS Updater * has been modified.

[OpenDNS Updater *]
LangSecRef=3021
Detect=HKCU\Software\OpenDNS Updater
Default=False
Warning=You must exit OpenDNS Updater in the System Tray to clear log files.
FileKey1=%AppData%\OpenDNS Updater|*.txt
----------------------------------------------------------------------------------------------------------------------
OpenOffice.org Setup Files * has been modified.

[OpenOffice.org Setup Files *]
LangSecRef=3021
Detect1=HKLM\Software\OpenOffice
Detect2=HKLM\Software\OpenOffice.org
Default=False
FileKey1=%UserProfile%\Desktop\OpenOffice.org * Installation Files|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Pando * has been modified.

[Pando *]
Detect=HKCU\Software\Pando Networks\Pando
LangSecRef=3024
Default=False
Warning=Make sure Pando is totally shut down before using this.
FileKey1=%LocalAppData%\Pando\Pando Files|*.*|RECURSE
ExcludeKey1=PATH|%LocalAppData%\Pando\Pando Files\|*pando.prev.log;*pando.log;*pando.sav;*pando.save;*pando.txt
ExcludeKey2=PATH|%LocalAppData%\Pando\Pando Files\Cert\|*.*
----------------------------------------------------------------------------------------------------------------------
Photos * has been modified.

[Photos *]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState|*.sqlite;*.sqlite-shm;*.sqlite-wal;*.xml
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState\PhotosAppTile|*.*|RECURSE
FileKey10=%LocalAppData%\PackagesMicrosoft.Windows.Photos_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedPickerData\Microsoft.Windows.Photos_8wekyb3d8bbwe!App\DefaultSaveFileSingle
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\MostRecentlyUsed
----------------------------------------------------------------------------------------------------------------------
QTTabBar * has been modified.

[QTTabBar *]
LangSecRef=3024
Detect=HKCU\Software\Quizo\QTTabBar
Default=False
FileKey1=%AppData%\QTTabBar|*.log
RegKey1=HKCU\Software\Quizo\QTTabBar|TabsOnLastClosedWindow
RegKey2=HKCU\Software\Quizo\QTTabBar\Cache
RegKey3=HKCU\Software\Quizo\QTTabBar\RecentlyClosed
----------------------------------------------------------------------------------------------------------------------
Saved Search Folders * was removed.

[Saved Search Folders *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=Can cause issues on Windows 8 or newer
FileKey1=%UserProfile%\Searches|*.search-ms
----------------------------------------------------------------------------------------------------------------------
Snagit * has been modified.

[Snagit *]
LangSecRef=3021
Detect=HKCU\Software\TechSmith\Snagit
Default=False
Warning=This will delete the backups of the captures.
FileKey1=%CommonAppData%\TechSmith\Uploader|*.log
FileKey2=%Documents%|SnagitDebug.log
FileKey3=%LocalAppData%\TechSmith\Logs|*.log
FileKey4=%LocalAppData%\TechSmith\Snagit|Tray.bin
FileKey5=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE
FileKey6=%LocalAppData%\TechSmith\Snagit\DataStore|*.SNAG;*.SNAGundo;*.MP4
FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico
FileKey8=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico
FileKey9=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE
FileKey10=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log
RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder
RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder
RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount
RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount
RegKey5=HKCU\Software\TechSmith\Snagit\12|CaptureCount
RegKey6=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount
RegKey7=HKCU\Software\TechSmith\Snagit\13|CaptureCount
RegKey8=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount
RegKey9=HKCU\Software\TechSmith\Snagit\13\Recent Captures
RegKey10=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List
RegKey11=HKCU\Software\TechSmith\Snagit\18|CaptureCount
RegKey12=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount
RegKey13=HKCU\Software\TechSmith\Snagit\18\Recent Captures
RegKey14=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List
RegKey15=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder
----------------------------------------------------------------------------------------------------------------------
SoftEther VPN * has been modified.

[SoftEther VPN *]
LangSecRef=3024
Detect=HKCU\Software\SoftEther Project\SoftEther VPN
Default=False
Warning=Exclude installer.cache if you're using SoftEther VPN Client Web Installer.
FileKey1=%ProgramFiles%\SoftEther VPN Client|installer.cache
FileKey2=%ProgramFiles%\SoftEther VPN Client\backup.vpn_client.config|*.config
FileKey3=%ProgramFiles%\SoftEther VPN Client\client_log|*.*
FileKey4=%ProgramFiles%\SoftEther VPN Client\vpn_debug|*.*
----------------------------------------------------------------------------------------------------------------------
TortoiseSVN History * has been modified.

[TortoiseSVN History *]
LangSecRef=3024
Detect=HKCU\Software\TortoiseSVN
Default=False
Warning=This will remove your repo paths and last checkout location.
RegKey1=HKCU\Software\TortoiseSVN\History
----------------------------------------------------------------------------------------------------------------------
UsbFix * has been modified.

[UsbFix *]
LangSecRef=3023
Detect=HKCU\Software\UsbFix
Default=False
FileKey1=%SystemDrive%\UsbFix\Log|*.*|REMOVESELF
FileKey2=%SystemDrive%\UsbFix\Quarantine|*.*|REMOVESELF
FileKey3=%UserProfile%\Desktop|UsbFix_Report.txt
RegKey1=HKCU\Software\UsbFix\LastReport
----------------------------------------------------------------------------------------------------------------------
Windows ShellBags * has been modified.

[Windows ShellBags *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This will reset folders size, view, icon or position settings to default and remove traces of the folders that do not exist anymore.
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags
RegKey3=HKCU\Software\Microsoft\Windows\Shell\BagMRU
RegKey4=HKCU\Software\Microsoft\Windows\Shell\Bags
RegKey5=HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU
RegKey6=HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
ExcludeKey1=REG|HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey2=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop
ExcludeKey3=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey4=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Desktop
ExcludeKey5=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\AllFolders
----------------------------------------------------------------------------------------------------------------------
X-Chat 2 * has been modified.

[X-Chat 2 *]
LangSecRef=3022
DetectFile=%AppData%\X-Chat 2
Default=False
Warning=This removes Chat Scrollback and Logs.
FileKey1=%AppData%\X-Chat 2\scrollback|*.*|REMOVESELF
FileKey2=%AppData%\X-Chat 2\xchatlogs|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
No-IP DUC * was added.

[No-IP DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%CommonAppData%\Vitalwerks\DUC|*.log
FileKey2=%LocalAppData%\Vitalwerks\DUC|*.log
----------------------------------------------------------------------------------------------------------------------

 

 

Brilliant. Thanks :)

Share this post


Link to post
Share on other sites
9 hours ago, Winapp2.ini said:

This one IS a changelog.

 

  Reveal hidden contents

 

Changes made between  Version: 180107 and  Version: 180111
Installer * has been modified.

[Installer *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect=HKCU\Software\Vivaldi
Default=False
FileKey1=%LocalAppData%\SuperBird\Application\*\Installer|*.7z
FileKey2=%LocalAppData%\Torch\Application\*\Installer|*.7z
FileKey3=%LocalAppData%\Vivaldi\Application\*\Installer|*.7z
FileKey4=%LocalAppData%\Yandex\YandexBrowser\Application\*\Installer|*.7z
FileKey5=%ProgramFiles%\Google\Chrome\Application\*\Installer|*.7z
----------------------------------------------------------------------------------------------------------------------
Web Data * has been modified.

[Web Data *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect1=HKCU\Software\Chromium
Detect2=HKCU\Software\SuperBird
Detect3=HKCU\Software\Torch
Detect4=HKCU\Software\Vivaldi
Default=False
Warning=This will remove Autofill, Autocomplete, Search Engines keyword, Sign-in and Credit Card info.
FileKey1=%LocalAppData%\Amigo\User Data\*\*|Web Data
FileKey2=%LocalAppData%\Chrome Plus\User Data\*|Web Data
FileKey3=%LocalAppData%\Chromium\User Data\*|Web Data
FileKey4=%LocalAppData%\Flock\User Data\*|Web Data
FileKey5=%LocalAppData%\Google\Chrome*\User Data\*|Web Data
FileKey6=%LocalAppData%\Rockmelt\User Data\*|Web Data
FileKey7=%LocalAppData%\SRWare Iron\User Data\*|Web Data
FileKey8=%LocalAppData%\SuperBird\User Data\*|Web Data
FileKey9=%LocalAppData%\Torch\User Data\*|Web Data
FileKey10=%LocalAppData%\Vivaldi\User Data\*|Web Data
----------------------------------------------------------------------------------------------------------------------
Active@ Disk Image * has been modified.

[Active@ Disk Image *]
LangSecRef=3024
Detect=HKLM\Software\LSoft Technologies\Active Disk Image
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
FileKey3=%ProgramFiles%\LSoft Technologies\Active@ Disk Image|*.txt
FileKey4=%ProgramFiles%\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Images * was removed.

[Active@ UNDELETE Images *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all saved disk images.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*\disk_images|*.*|REMOVESELF
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*\disk_images|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Recovered Files * was removed.

[Active@ UNDELETE Recovered Files *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all recovered data.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*\recovered|*.*|REMOVESELF
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*\recovered|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Active@ UNDELETE Sessions * was removed.

[Active@ UNDELETE Sessions *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9F0B916A-F7DD-4335-923E-397979C6AE1B}_is1
Default=False
Warning=This will delete all saved sessions.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ UNDELETE*|*.usf|RECURSE
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ UNDELETE*|*.usf|RECURSE
----------------------------------------------------------------------------------------------------------------------
Apple MobileSync Backups * has been modified.

[Apple MobileSync Backups *]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.
Default=False
FileKey1=%AppData%\Apple Computer\MobileSync\Backup|*.*|RECURSE
----------------------------------------------------------------------------------------------------------------------
CCDump * has been modified.

[CCDump *]
LangSecRef=3024
DetectFile=%ProgramFiles%\CCleaner\CCDump.exe
Default=False
Warning=This removes files winapp.ini, winsys.ini, winreg.ini and regkeys.output.txt from the CCleaner folder.
FileKey1=%ProgramFiles%\CCleaner|winapp.ini;winreg.ini;winsys.ini;regkeys.output.txt
----------------------------------------------------------------------------------------------------------------------
CD/DVD Burn Cache * has been modified.

[CD/DVD Burn Cache *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning
Default=False
Warning=This will wipe all files that are waiting to be burned to a CD/DVD/BD drive.
FileKey1=%LocalAppData%\Microsoft\CD Burning|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\Burn|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo
----------------------------------------------------------------------------------------------------------------------
DriverPack Solution * has been modified.

[DriverPack Solution *]
LangSecRef=3024
Detect=HKCU\Software\drpsu
Default=False
Warning=This will delete your bug report.
FileKey1=%AppData%\DRPSu\Logs|*.*
FileKey2=%AppData%\DRPSu\snapshots|*.*
FileKey3=%AppData%\DRPSu\temp|*.*
FileKey4=%Documents%\DRP-Log|*.*
FileKey5=%WinDir%\Logs\DRPLog|*.png;*.txt
FileKey6=%WinDir%\Logs\SysInfo|*.*
----------------------------------------------------------------------------------------------------------------------
DUC * was removed.

[DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%LocalAppData%\Vitalwerks\DUC|DUC.log
----------------------------------------------------------------------------------------------------------------------
ElsterFormular * has been modified.

[ElsterFormular *]
LangSecRef=3021
DetectFile=%AppData%\elsterformular
Default=False
FileKey1=%AppData%\elsterformular\*\log|*.log;*.log.*
FileKey2=%AppData%\elsterformular\*\tmp|*.*|RECURSE
FileKey3=%AppData%\elsterformular\pluginmanager\data|*_cpy.zip
FileKey4=%CommonAppData%\elsterformular\log|*.log
FileKey5=%LocalAppData%\.elfohilfe|*.*|REMOVESELF
FileKey6=%LocalAppData%\elfopatch|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Explorer MRUs * has been modified.

[Explorer MRUs *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams
----------------------------------------------------------------------------------------------------------------------
Hauppauge WinTV * has been modified.

[Hauppauge WinTV *]
LangSecRef=3024
Detect=HKLM\Software\Hauppauge
Default=False
FileKey1=%Public%\WinTV|Settings-old.xml
FileKey2=%Public%\WinTV\Channel Database|hcwChanDB_5-lastgood.mdb
FileKey3=%Public%\WinTV\Installation Log|*.*|RECURSE
FileKey4=%Public%\WinTV\Logs|*.log;*.txt
FileKey5=%Public%\WinTV\Logs\minidump|*.*|RECURSE
FileKey6=%SystemDrive%|hcwDriverInstall.txt
----------------------------------------------------------------------------------------------------------------------
HyperSnap 7 * has been modified.

[HyperSnap 7 *]
LangSecRef=3021
Detect=HKCU\Software\Hyperionics\HyperSnap 7
Default=False
FileKey1=%ProgramFiles%\HyperSnap 7|*.url
RegKey1=HKCU\Software\Hyperionics\HyperSnap 7\Recent File List
----------------------------------------------------------------------------------------------------------------------
Internet Explorer * has been modified.

[Internet Explorer *]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Internet Explorer
Default=False
FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE
FileKey3=%LocalAppData%\Microsoft\Windows\IECompatCache|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Windows\IECompatUaCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey9=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*
FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*
FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE
FileKey15=%WinDir%\System32\config\Systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
RegKey1=HKCR\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage
RegKey2=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore
RegKey3=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage
RegKey4=HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl
RegKey5=HKCU\Software\Microsoft\Internet Explorer\Recovery\PendingDelete
RegKey6=HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
----------------------------------------------------------------------------------------------------------------------
IObit Advanced SystemCare * has been modified.

[IObit Advanced SystemCare *]
LangSecRef=3024
DetectFile1=%AppData%\IObit\Advanced SystemCare V*
DetectFile2=%CommonAppData%\IObit\Advanced SystemCare V*
Default=False
FileKey1=%AppData%\IObit\Advanced SystemCare *|*.log
FileKey2=%AppData%\IObit\Advanced SystemCare *\Boottime|*.log
FileKey3=%AppData%\IObit\Advanced SystemCare *\EmptyFolder|*.*|RECURSE
FileKey4=%AppData%\IObit\Advanced SystemCare *\Log|*.*|RECURSE
FileKey5=%CommonAppData%\IObit\Advanced SystemCare *\Log|*.*|REMOVESELF
FileKey6=%CommonAppData%\IObit\ASCDownloader|*.log
FileKey7=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *|*.log;*.txt|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *\*.cab_Temp|*.*|REMOVESELF
FileKey9=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *\ASCServiceLog|*.*|RECURSE
FileKey10=%LocalAppData%\VirtualStore\ProgramData\IObit\Advanced SystemCare *\Log|*.*|RECURSE
FileKey11=%LocalAppData%\VirtualStore\ProgramData\IObit\ASCDownloader|*.log
FileKey12=%ProgramFiles%\IObit\Advanced SystemCare *|*.log;*.txt|RECURSE
FileKey13=%ProgramFiles%\IObit\Advanced SystemCare *\*.cab_Temp|*.*|REMOVESELF
FileKey14=%ProgramFiles%\IObit\Advanced SystemCare *\ASCServiceLog|*.*|RECURSE
FileKey15=%SystemDrive%\Users\Default\AppData\Roaming\IObit\Advanced SystemCare *|*.log
FileKey16=%WinDir%\System32\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare *|*.log
FileKey17=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare *|*.log
----------------------------------------------------------------------------------------------------------------------
K-Lite Codec Pack * has been modified.

[K-Lite Codec Pack *]
LangSecRef=3023
Detect=HKLM\Software\KLCodecPack
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\K-Lite*|*.log;*.txt|RECURSE
FileKey2=%ProgramFiles%\K-Lite*|*.log;*.txt|RECURSE
FileKey3=%SystemDrive%|*klcp_itp_*.tmp;*klcp_iph_*.tmp
FileKey4=%UserProfile%\Desktop|klcp_codec_log.txt
RegKey1=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path0
RegKey2=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path1
RegKey3=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path2
----------------------------------------------------------------------------------------------------------------------
Macrium Reflect * has been modified.

[Macrium Reflect *]
LangSecRef=3024
Detect=HKCU\Software\Macrium\Reflect
Default=False
FileKey1=%CommonAppData%\Macrium|*.log|RECURSE
FileKey2=%CommonAppData%\Macrium\Reflect|*.html;*.vsslog
FileKey3=%CommonAppData%\Macrium\waik|waiklog.txt
FileKey4=%SystemDrive%|ref~tmp~.txt;Reflect_Install.log;rescuepe.log
----------------------------------------------------------------------------------------------------------------------
MS Search * has been modified.

[MS Search *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey2=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey4=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
FileKey5=%UserProfile%\Searches|*.search-ms
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
RegKey2=HKLM\Software\Microsoft\Windows Search\VolumeInfoCache
----------------------------------------------------------------------------------------------------------------------
Notepad++ * has been modified.

[Notepad++ *]
LangSecRef=3021
Detect=HKLM\Software\Notepad++
Default=False
FileKey1=%AppData%\Notepad++\plugins\config|PluginManagerGpup.xml;PluginManagerPlugins.xml;PluginManagerPlugins.zip
FileKey2=%AppData%\Notepad++\plugins\config\plugin_install_temp|*.*|REMOVESELF
FileKey3=%ProgramFiles%\Notepad++\plugins\disabled|*.*
----------------------------------------------------------------------------------------------------------------------
OpenDNS Updater * has been modified.

[OpenDNS Updater *]
LangSecRef=3021
Detect=HKCU\Software\OpenDNS Updater
Default=False
Warning=You must exit OpenDNS Updater in the System Tray to clear log files.
FileKey1=%AppData%\OpenDNS Updater|*.txt
----------------------------------------------------------------------------------------------------------------------
OpenOffice.org Setup Files * has been modified.

[OpenOffice.org Setup Files *]
LangSecRef=3021
Detect1=HKLM\Software\OpenOffice
Detect2=HKLM\Software\OpenOffice.org
Default=False
FileKey1=%UserProfile%\Desktop\OpenOffice.org * Installation Files|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
Pando * has been modified.

[Pando *]
Detect=HKCU\Software\Pando Networks\Pando
LangSecRef=3024
Default=False
Warning=Make sure Pando is totally shut down before using this.
FileKey1=%LocalAppData%\Pando\Pando Files|*.*|RECURSE
ExcludeKey1=PATH|%LocalAppData%\Pando\Pando Files\|*pando.prev.log;*pando.log;*pando.sav;*pando.save;*pando.txt
ExcludeKey2=PATH|%LocalAppData%\Pando\Pando Files\Cert\|*.*
----------------------------------------------------------------------------------------------------------------------
Photos * has been modified.

[Photos *]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState|*.sqlite;*.sqlite-shm;*.sqlite-wal;*.xml
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState\PhotosAppTile|*.*|RECURSE
FileKey10=%LocalAppData%\PackagesMicrosoft.Windows.Photos_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedPickerData\Microsoft.Windows.Photos_8wekyb3d8bbwe!App\DefaultSaveFileSingle
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\MostRecentlyUsed
----------------------------------------------------------------------------------------------------------------------
QTTabBar * has been modified.

[QTTabBar *]
LangSecRef=3024
Detect=HKCU\Software\Quizo\QTTabBar
Default=False
FileKey1=%AppData%\QTTabBar|*.log
RegKey1=HKCU\Software\Quizo\QTTabBar|TabsOnLastClosedWindow
RegKey2=HKCU\Software\Quizo\QTTabBar\Cache
RegKey3=HKCU\Software\Quizo\QTTabBar\RecentlyClosed
----------------------------------------------------------------------------------------------------------------------
Saved Search Folders * was removed.

[Saved Search Folders *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=Can cause issues on Windows 8 or newer
FileKey1=%UserProfile%\Searches|*.search-ms
----------------------------------------------------------------------------------------------------------------------
Snagit * has been modified.

[Snagit *]
LangSecRef=3021
Detect=HKCU\Software\TechSmith\Snagit
Default=False
Warning=This will delete the backups of the captures.
FileKey1=%CommonAppData%\TechSmith\Uploader|*.log
FileKey2=%Documents%|SnagitDebug.log
FileKey3=%LocalAppData%\TechSmith\Logs|*.log
FileKey4=%LocalAppData%\TechSmith\Snagit|Tray.bin
FileKey5=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE
FileKey6=%LocalAppData%\TechSmith\Snagit\DataStore|*.SNAG;*.SNAGundo;*.MP4
FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico
FileKey8=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico
FileKey9=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE
FileKey10=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log
RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder
RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder
RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount
RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount
RegKey5=HKCU\Software\TechSmith\Snagit\12|CaptureCount
RegKey6=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount
RegKey7=HKCU\Software\TechSmith\Snagit\13|CaptureCount
RegKey8=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount
RegKey9=HKCU\Software\TechSmith\Snagit\13\Recent Captures
RegKey10=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List
RegKey11=HKCU\Software\TechSmith\Snagit\18|CaptureCount
RegKey12=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount
RegKey13=HKCU\Software\TechSmith\Snagit\18\Recent Captures
RegKey14=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List
RegKey15=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder
----------------------------------------------------------------------------------------------------------------------
SoftEther VPN * has been modified.

[SoftEther VPN *]
LangSecRef=3024
Detect=HKCU\Software\SoftEther Project\SoftEther VPN
Default=False
Warning=Exclude installer.cache if you're using SoftEther VPN Client Web Installer.
FileKey1=%ProgramFiles%\SoftEther VPN Client|installer.cache
FileKey2=%ProgramFiles%\SoftEther VPN Client\backup.vpn_client.config|*.config
FileKey3=%ProgramFiles%\SoftEther VPN Client\client_log|*.*
FileKey4=%ProgramFiles%\SoftEther VPN Client\vpn_debug|*.*
----------------------------------------------------------------------------------------------------------------------
TortoiseSVN History * has been modified.

[TortoiseSVN History *]
LangSecRef=3024
Detect=HKCU\Software\TortoiseSVN
Default=False
Warning=This will remove your repo paths and last checkout location.
RegKey1=HKCU\Software\TortoiseSVN\History
----------------------------------------------------------------------------------------------------------------------
UsbFix * has been modified.

[UsbFix *]
LangSecRef=3023
Detect=HKCU\Software\UsbFix
Default=False
FileKey1=%SystemDrive%\UsbFix\Log|*.*|REMOVESELF
FileKey2=%SystemDrive%\UsbFix\Quarantine|*.*|REMOVESELF
FileKey3=%UserProfile%\Desktop|UsbFix_Report.txt
RegKey1=HKCU\Software\UsbFix\LastReport
----------------------------------------------------------------------------------------------------------------------
Windows ShellBags * has been modified.

[Windows ShellBags *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This will reset folders size, view, icon or position settings to default and remove traces of the folders that do not exist anymore.
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags
RegKey3=HKCU\Software\Microsoft\Windows\Shell\BagMRU
RegKey4=HKCU\Software\Microsoft\Windows\Shell\Bags
RegKey5=HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU
RegKey6=HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
ExcludeKey1=REG|HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey2=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop
ExcludeKey3=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey4=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Desktop
ExcludeKey5=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\AllFolders
----------------------------------------------------------------------------------------------------------------------
X-Chat 2 * has been modified.

[X-Chat 2 *]
LangSecRef=3022
DetectFile=%AppData%\X-Chat 2
Default=False
Warning=This removes Chat Scrollback and Logs.
FileKey1=%AppData%\X-Chat 2\scrollback|*.*|REMOVESELF
FileKey2=%AppData%\X-Chat 2\xchatlogs|*.*|REMOVESELF
----------------------------------------------------------------------------------------------------------------------
No-IP DUC * was added.

[No-IP DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%CommonAppData%\Vitalwerks\DUC|*.log
FileKey2=%LocalAppData%\Vitalwerks\DUC|*.log
----------------------------------------------------------------------------------------------------------------------

 

 

Great job on the changelog. Thanks! :)

One correction though:

"Explorer MRUs * has been modified." should be changed to "Explorer MRUs * was removed."

See APMichael's pull request, https://github.com/MoscaDotTo/Winapp2/pull/166

Share this post


Link to post
Share on other sites
Just now, cbaumer0628 said:

Great job on the changelog. Thanks! :)

One correction though:

"Explorer MRUs * has been modified." should be changed to "Explorer MRUs * was removed."

See APMichael's pull request, https://github.com/MoscaDotTo/Winapp2/pull/166

The output is generated based on the file contents, so I must have used a version from before that PR was merged to produce it, or else it's absence in the later file would have triggered the "was removed" line. The next time I post a change log, this change will most likely make itself apparent.

Share this post


Link to post
Share on other sites
4 hours ago, Winapp2.ini said:

Here is a demo of the new multitool (winapp2ool): https://github.com/MoscaDotTo/Winapp2/tree/master/Tools/beta

 

Please give it a try, it includes a slightly improved WinappDebug, ccinidebug, a new module called "diff" that compares two winapp2.ini versions and outputs the changes, and a trimming module with an option to both overwrite the existing winapp2.ini file or to output to a new file called winapp2-trimmed.ini

Recommended that you run it as an administrator, many of the functions don't work will without elevation. Trim especially, as it can't access certain registry keys without elevation and will as a result, erroneously trim entries from your file.

My system is Windows 10x64 Professional Build 16299.192 V1709.  I am running Winapp2ool.exe as "Run as Administrator"

ISSUE 1: 

When I run the DIFF tool, it crashes after I have entered the 2 names of the Winapp2.ini files I want to compare.  Below are the two errors via the Event Viewer

Quote

Application: winapp2ool.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.ArgumentOutOfRangeException
   at System.ThrowHelper.ThrowArgumentOutOfRangeException(System.ExceptionArgument, System.ExceptionResource)
   at System.Collections.Generic.List`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Item(Int32)
   at winapp2ool.diff.main()
   at winapp2ool.Module1.Main()

  System
   
- Provider
      [ Name] .NET Runtime
   
- EventID 1026
      [ Qualifiers] 0
   
  Level 2
   
  Task 0
   
  Keywords 0x80000000000000
   
- TimeCreated
      [ SystemTime] 2018-01-15T06:35:15.961132000Z
   
  EventRecordID 61619
   
  Channel Application
   
  Computer ASUSHomeBuilt
   
  Security
- EventData
      Application: winapp2ool.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.ArgumentOutOfRangeException at System.ThrowHelper.ThrowArgumentOutOfRangeException(System.ExceptionArgument, System.ExceptionResource) at System.Collections.Generic.List`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Item(Int32) at winapp2ool.diff.main() at winapp2ool.Module1.Main()
Quote

Faulting application name: winapp2ool.exe, version: 1.0.0.0, time stamp: 0x5a5c06fd
Faulting module name: KERNELBASE.dll, version: 10.0.16299.15, time stamp: 0x4736733c
Exception code: 0xe0434352
Fault offset: 0x0000000000013fb8
Faulting process id: 0xe1c
Faulting application start time: 0x01d38dca44861e56
Faulting application path: C:\Program Files\CCleaner\winapp2ool.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: e5237595-e02c-4acb-9d7f-fde2ec73574f
Faulting package full name: 
Faulting package-relative application ID: 

- System
   
- Provider
      [ Name] Application Error
   
- EventID 1000
      [ Qualifiers] 0
   
  Level 2
   
  Task 100
   
  Keywords 0x80000000000000
   
- TimeCreated
      [ SystemTime] 2018-01-15T06:30:50.868131000Z
   
  EventRecordID 61613
   
  Channel Application
   
  Computer ASUSHomeBuilt
   
  Security
- EventData
      winapp2ool.exe
      1.0.0.0
      5a5c06fd
      KERNELBASE.dll
      10.0.16299.15
      4736733c
      e0434352
      0000000000013fb8
      e1c
      01d38dca44861e56
      C:\Program Files\CCleaner\winapp2ool.exe
      C:\WINDOWS\System32\KERNELBASE.dll
      e5237595-e02c-4acb-9d7f-fde2ec73574f
       
       

ISSUE 2:

Even though I run the tool as "Run as Administrator", it trims 5 more items than the original Trim.bat tool.  I can't tell which ones are being trimmed because the DIFF tool is crashing. :(

Share this post


Link to post
Share on other sites
8 minutes ago, siliconman01 said:

My system is Windows 10x64 Professional Build 16299.192 V1709.  I am running Winapp2ool.exe as "Run as Administrator"

ISSUE 1: 

When I run the DIFF tool, it crashes after I have entered the 2 names of the Winapp2.ini files I want to compare.  Below are the two errors via the Event Viewer

ISSUE 2:

Even though I run the tool as "Run as Administrator", it trims 5 more items than the original Trim.bat tool.  I can't tell which ones are being trimmed because the DIFF tool is crashing. :(

You may want to try running the .NET Repair Tool

are you including the .ini extension when entering the file name? (you should be!) '

Have you tried running just the trim module? It doesn't call any code from diff so it should not trigger a crash in that module as far as I'm aware.

Does the error still occur if you move to tool to a less privileged folder?(ie. downloads)

Thanks for trying it out! :)

Share this post


Link to post
Share on other sites

ISSUE 3:

Winappdebug failed to detect the missing backslash in the following ExcludeKey

ExcludeKey1=FILE|%SystemDrive%\TomsCommonData\Rainmeter\Skins\Gadgets\@Resources\Language|Weather_EN-US.inc

Quote

You may want to try running the .NET Repair Tool

I ran this tool and it did not resolve the crash issue.

Quote

are you including the .ini extension when entering the file name? (you should be!) '

Yes, I am including the .ini extension

Quote

Have you tried running just the trim module? It doesn't call any code from diff so it should not trigger a crash in that module as far as I'm aware.

Yes, I have run the TRIM module.  It is trimming 5 more cleaning items than the original TRIM.BAT.  That is why I am wanting to get the DIFF module working.

Quote

Does the error still occur if you move to tool to a less privileged folder?(ie. downloads)

Yes, it still crashes...with and without "Run as Administrator"

Share this post


Link to post
Share on other sites
2 minutes ago, siliconman01 said:

ISSUE 3:

Winappdebug failed to detect the missing backslash in the following ExcludeKey

ExcludeKey1=FILE|%SystemDrive%\TomsCommonData\Rainmeter\Skins\Gadgets\@Resources\Language|Weather_EN-US.inc

I ran this tool and it did not resolve the crash issue.

Yes, I am including the .ini extension

Yes, I have run the TRIM module.  It is trimming 5 more cleaning items than the original TRIM.BAT.  That is why I am wanting to get the DIFF module working.

Yes, it still crashes...with and without "Run as Administrator"

I've just uploaded a new version of winapp2ool, give it a try. The trim module has been tweaked a bit to prevent it from outputting a bad ini file.

FWIW I think there may be some bug in trim.bat because it also generated more entries for me, but some of them should not have been detected as being on my system.

Share this post


Link to post
Share on other sites

The new winapp2ool.exe no longer crashes when using DIFF. :D

Quote

FWIW I think there may be some bug in trim.bat because it also generated more entries for me, but some of them should not have been detected as being on my system.

Yes, it does appear to be improperly trimming.  In addition it does not alphabetize its final selection.  The new version of Trim is still showing 5 less than the original TRIM.BAT.  However, the DIFF run shows a lot of adds and removes that do not look correct.

TRIM does not seem to like it if the cleaning module has no DETECT or DETECTFILE in the code.  It removes these modules

Edited by siliconman01
Added DETECT/DETECTFILE comment

Share this post


Link to post
Share on other sites
13 hours ago, siliconman01 said:

The new winapp2ool.exe no longer crashes when using DIFF. :D

Yes, it does appear to be improperly trimming.  In addition it does not alphabetize its final selection.  The new version of Trim is still showing 5 less than the original TRIM.BAT.  However, the DIFF run shows a lot of adds and removes that do not look correct.

TRIM does not seem to like it if the cleaning module has no DETECT or DETECTFILE in the code.  It removes these modules

I've uploaded a new version of winapp2ool that should address both the ExcludeKey error checking in WinappDebug and the detectless entries being ignored in the trim module.

Share this post


Link to post
Share on other sites

I have updated winapp2ool considerably and made available the source code.

https://github.com/MoscaDotTo/Winapp2/commit/b69b08c54e70929c2ca8c33ec0a5fdec5f11b8cb

Notably, I made a fix to trim such that it will actually respect the hive provided by Detect= entries, it previously ignored any markers such as HKCU, HKLM.. etc and checked all hives simultaneously, which can (strangely enough!) lead to "false" positives (eg. a key exists in HKLM but not HKCU, while the detect is for HKCU. Thus trim would count is as valid but CCleaner would never present this entry, presumably.)

Share this post


Link to post
Share on other sites

I installed the new winapp2ool.exe and performed a TRIM.  The new TRIM removed 7 cleaning modules that should not have been removed.  In examining the ones falsely trimmed (see attached file), the "Detect" checks are all located in the HKLM\Software\WOW6432Node hive area of the registry.  So it looks like the new TRIM is not testing this area or is testing it incorrectly.

TrimmedIncorrectly.txt

Share this post


Link to post
Share on other sites

ISSUE 1 with ccinidebug:

In running the new ccinidebug, it falsely displays that every entry in the ccleaner.ini is a stale entry and will be pruned.  If I continue to the second step to let it prune and organize ccleaner.ini, it does not actually prune these entries.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×