Jump to content
CCleaner Community Forums
Winapp2.ini

Winapp2.ini additions

Recommended Posts

Modified:

[VoidTools Search Everything*]
LangSecRef=3024
DetectFile1=%ProgramFiles%\Everything
DetectFile2=%AppData%\Everything
Default=False
FileKey1=%AppData%\Everything|*.csv;*.txt;*.tmp
FileKey2=%ProgramFiles%\Everything|*.csv;*.txt;*.tmp
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Everything|*.txt;*.csv;*.tmp
ExcludeKey1=FILE|%AppData%\Everything\Filters.csv
ExcludeKey2=FILE|%ProgramFiles%\Everything\Filters.csv
ExcludeKey3=FILE|%LocalAppData%\VirtualStore\Program Files*\Everything\Filters.csv

added *.tmp to end of 3 FileKey's listed....

Share this post


Link to post
Share on other sites

@Winapp2.ini Looks like the new Winapp2.ini file is uploaded, but you forgot to fix the entries mentioned in the links below.

 

http://forum.piriform.com/index.php?showtopic=32310&p=271094

 

http://forum.piriform.com/index.php?showtopic=32310&p=271093

 

I guess his new year wish didn't come true. Well, there is always next year.

Share this post


Link to post
Share on other sites

I guess his new year wish didn't come true. Well, there is always next year.

Probably should have doubled it up with a birthday wish or something :lol:

Share this post


Link to post
Share on other sites

New:



[CamStudio Temps*]
LangSecRef=3023
Detect=HKCU\Software\CamStudioOpenSource for Nick
Default=False
FileKey1=%Documents%\My CamStudio Temp Files|*.*

[AIMP 4*]
LangSecRef=3023
DetectFile=%ProgramFiles%\AIMP\AIMP.exe
Default=False
FileKey1=%AppData%\AIMP|*.bak


Share this post


Link to post
Share on other sites

New Entry

 

[Wondershare MobileGo*]
LangSecRef=3021
Detect=HKCU\SOFTWARE\Wondershare\MobileGo
Default=False
FileKey1=%ProgramFiles%\Wondershare\MobileGo|*.log
FileKey2=%CommonAppData%\Wondershare\Dr.FoneTool\Log|*.txt
FileKey3=%CommonAppData%\Wondershare\WAF\ProductFeatures\LocalLogs|*.*|RECURSE
FileKey4=%CommonAppData%\Wondershare\WAF\ProductFeatures\RemoteLogs|*.*|RECURSE
FileKey5=%AppData%\se_tmp|*.*|REMOVESELF
FileKey6=%AppData%\Wondershare\DataEraser|*.log
FileKey7=%AppData%\Wondershare\Dr.FoneTool\log|*.log
FileKey8=%AppData%\Wondershare\DrFoneAndroidTool\log|*.log
FileKey9=%AppData%\Wondershare\MirrorGo\ImageCache\ADImage|*.*|RECURSE
FileKey10=%AppData%\Wondershare\MirrorGo|*.log
FileKey11=%AppData%\Wondershare\MobileGo|*.log
FileKey12=%AppData%\Wondershare\MobileGo\DeviceImageCache|*.*|RECURSE
FileKey13=%AppData%\Wondershare\MobileGo\iOSTemp|*.*|REMOVESELF
FileKey14=%AppData%\Wondershare\MobileGo\Logs\DeviceConnection|*.*|RECURSE
FileKey15=%AppData%\Wondershare\MobileTransTool|*.log
FileKey16=%AppData%\Wondershare\WsRoot\Logs|*.*|RECURSE

 

Please remove [Wondershare MobileGo for iOS*] entry.

Share this post


Link to post
Share on other sites

New Entries

 

[3D Builder*]
DetectOS=10.0
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.3DBuilder_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.3DBuilder_*\TempState|*.*|RECURSE

[Get Started*]
DetectOS=10.0
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Getstarted_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Getstarted_*\TempState|*.*|RECURSE

Share this post


Link to post
Share on other sites

Revised Entries

 

[Cortana*]
Section=3031
Default=False
Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Cortana_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Cortana_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Cortana_*\TempState|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\AppCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetCache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetCookies|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Temp|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey19=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalCache|*.*|RECURSE
FileKey20=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\Cache|*.*|RECURSE
FileKey21=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\AppIconCache|*.*|RECURSE
FileKey22=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache|*.*|RECURSE
FileKey23=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\TempState|*.*|RECURSE

Added:
%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\AppCache|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\AppIconCache|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache|*.*|RECURSE


[DRM Traces*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\DRM
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey2=%CommonAppData%\Microsoft\Windows\DRM\PreUpgrade|*.log
FileKey3=%CommonAppData%\Microsoft\Windows\DRM|*.log
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\PreUpgrade|*.log
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM|*.log

Changed entry name from [DRM Cache*] to [DRM Traces*].

Added:
%CommonAppData%\Microsoft\Windows\DRM\PreUpgrade|*.log
%CommonAppData%\Microsoft\Windows\DRM|*.log

[Windows Communications Apps*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Comms\Temp|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\AppCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\PRICache|*.*
FileKey11=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*
FileKey12=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\LiveComm\*\*\DBStore\LogFiles|edbtmp.log
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory

Added: %LocalAppData%\Comms\Temp|*.*|RECURSE

Share this post


Link to post
Share on other sites

Revised Entry

 

[Action Center*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Notifications\Current

Changed the Detect.

 

Added:
%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE
HKCU\Software\Microsoft\Windows\CurrentVersion\Notifications\Current

Share this post


Link to post
Share on other sites

Revised Entries

 

Moved some paths from [Log Files More*] into the entries listed below. Two paths, %WinDir%\winsxs|poqexec.log & %WinDir%\inf|*.log*, are still in this entry and they should not be removed. [Log Files More*] can be removed.

 

[Diagnostics Logs*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\debug\WIA|*.log

[Panther*]
LangSecRef=3025
DetectFile=%Windir%\Panther
Default=False
FileKey1=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log
FileKey2=%WinDir%\Panther\FastCleanup|*.log
FileKey3=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml
FileKey4=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml
 

Share this post


Link to post
Share on other sites

Revised Entries

 

Moved some paths from [Log Files More*] into the entries listed below. Two paths, %WinDir%\winsxs|poqexec.log & %WinDir%\inf|*.log*, are still in this entry and they should not be removed. [Log Files More*] can be removed.

 is this a mistake?

Share this post


Link to post
Share on other sites

Revised Entries

 

Moved some paths from [Log Files More*] into the entries listed below. Two paths, %WinDir%\winsxs|poqexec.log & %WinDir%\inf|*.log*, are still in this entry and they should not be removed. [Log Files More*] can be removed.

 

What about FileKey5=%WinDir%|SIGVERIF.TXT?

Share this post


Link to post
Share on other sites
R.I.P domain.

huh?

Share this post


Link to post
Share on other sites
Perhaps he means the Winapp2.ini website.

Works for me

Share this post


Link to post
Share on other sites

I am on the email list for a few groups on Piriform - there has been a lot of S.P.A.M. the last few days.  Maybe he means he blocked the senders today.....??

Share this post


Link to post
Share on other sites

I am on the email list for a few groups on Piriform - there has been a lot of S.P.A.M. the last few days.  Maybe he means he blocked the senders today.....??

There's been a lot of spam around everywhere the last week or so.

 

I'll ask Piriform to check things.

Share this post


Link to post
Share on other sites

New Entries

[Accounts Control*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.AccountsControl_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.AccountsControl_*\TempState|*.*|RECURSE

[Comms Phone*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.CommsPhone_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.CommsPhone_*\TempState|*.*|RECURSE

[Connectivity Store*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ConnectivityStore_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\TempState|*.*|RECURSE

[Contact Support*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Windows.ContactSupport_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0|*.log
FileKey6=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32|*.log
FileKey9=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Temp|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalCache|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalState\Cache|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\Windows.ContactSupport_*\TempState|*.*|RECURSE

[Lock App*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.LockApp_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.LockApp_*\TempState|*.*|RECURSE

[Maps*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsMaps_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\TempState|*.*|RECURSE

[People*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.People_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.People_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.People_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.People_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.People_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.People_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.People_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.People_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.People_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.People_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.People_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.People_*\TempState|*.*|RECURSE

[Phone*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsPhone_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\TempState|*.*|RECURSE

[QuizUp*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\QuizUp.QuizUp_n36z36qeaxk8a
FileKey1=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey6=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0_32|*.log|RECURSE
FileKey8=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Temp|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalCache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalState\Cache|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\QuizUp.QuizUp_*\TempState|*.*|RECURSE

[scan*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsScan_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsScan_*\TempState|*.*|RECURSE

[shell Experience Host*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\TempState|*.*|RECURSE

[sound Recorder*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\TempState|*.*|RECURSE

[sway*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.Sway_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Office.Sway_*\TempState|*.*|RECURSE

[Windows Feedback*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedback_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0|*.log
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0_32|*.log
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Temp|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\LocalCache|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\LocalState\Cache|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\TempState|*.*|RECURSE

Share this post


Link to post
Share on other sites

Revised Entries

 

[bing Finance More*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingFinance_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingFinance_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingFinance_*\TempState|*.*|RECURSE

Added:
%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\TokenBroker\Cache|*.*|RECURSE

[bing News More*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingNews_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\PRICache|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingNews_*\LocalState\navigationHistory|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe\SearchHistory

Added:
%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.BingNews_*\AC\TokenBroker\Cache|*.*|RECURSE

[bing Sports More*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingSports_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingSports_*\LocalState\navigationHistory|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingSports_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe\SearchHistory

Added:
%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.BingSports_*\AC\TokenBroker\Cache|*.*|RECURSE

[bing Weather*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingWeather_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log
FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp
FileKey13=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory

Added |RECURSE to some lines.

[Camera*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsCamera_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Camera_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.Camera_*\AC\PRICache|*.*
FileKey9=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Temp|*.*
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\AppCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetCache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetCookies|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Temp|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalCache|*.*|RECURSE
FileKey19=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\AppData|*.*|RECURSE
FileKey20=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\Cache|*.*|RECURSE
FileKey21=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe\SearchHistory

Added: Detect2
Added: FileKey 10 thru FileKey21 for Windows 10

[Cloud Experience Host*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\TempState|*.*|RECURSE

Added:
%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\AppCache|*.*|RECURSE

[OneNote*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local|msodata*.dat
FileKey9=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\OTele|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\office15client.microsoft.com|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0\OneNoteOfflineCache_Files|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0\OneNotePagePreviewCache_Files|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0|*.onecache
FileKey15=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe\SearchHistory

Added:
%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\TokenBroker\Cache|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com|*.*|RECURSE

[Xbox Identity Provider*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxIdentityProvider_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0|*.log
FileKey5=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32|*.log
FileKey8=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalCache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalState\Cache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\TempState|*.*|RECURSE

Removed |RECURSE from some lines.

 

[XboxApp*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxApp_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log;*.log*
FileKey10=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log
FileKey12=%LocalAppData%\Packages\Microsoft.XboxApp_*\TempState|*.*|RECURSE

Added:
%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log;*.log.
%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log

[Zune Music*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\PRICache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageCache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\PlayReady|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\SearchHistory

Added:
%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\TokenBroker\Cache|*.*|RECURSE

[Zune Video*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\PRICache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageCache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\PlayReady|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\TempState|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Database\anonymous|*.log
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe\SearchHistory

Added:
%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\TokenBroker\Cache|*.*|RECURSE

Share this post


Link to post
Share on other sites

Revised Entry

 

[Plex Media Server*]
LangSecRef=3023
Detect=HKCU\Software\Plex, Inc.\Plex Media Server
Default=False
FileKey1=%ProgramFiles%\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey2=%LocalAppData%\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey3=%LocalAppData%\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey4=%LocalAppData%\Plex Media Server\Logs|*.*|RECURSE
FileKey5=%LocalAppData%\Plex Media Server\Updates|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Logs|*.*|RECURSE
FileKey10=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Updates|*.*|RECURSE

Added:
%LocalAppData%\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
%LocalAppData%\Plex Media Server\Updates|*.*|RECURSE
%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Updates|*.*|RECURSE

Share this post


Link to post
Share on other sites

New Entry

Windows Disk Cleanup removes these files.

 

[Delivery Optimization Files*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
RegKey1=HKLM\Software\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Jobs
FileKey1=%WinDir%\Logs\dosvc|*.*|RECURSE
FileKey2=%WinDir%\SoftwareDistribution\DeliveryOptimization|*.*|RECURSE

Share this post


Link to post
Share on other sites

Revised Entry

 

[Windows Defender More*]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows Defender
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows Defender\Definition Updates\Backup|*.*|RECURSE
FileKey2=%CommonAppData%\Microsoft\Windows Defender\LocalCopy|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\Windows Defender\Network Inspection System\Support|*.txt
FileKey4=%CommonAppData%\Microsoft\Windows Defender\Scans|*.bin;*.bin*
FileKey5=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Service|*.log
FileKey6=%CommonAppData%\Microsoft\Windows Defender\Scans\Scans\History\CacheManager|*.*|RECURSE
FileKey7=%CommonAppData%\Microsoft\Windows Defender\Support|*.*|RECURSE

Added:
%CommonAppData%\Microsoft\Windows Defender\LocalCopy|*.*|RECURSE

Windows Disk Cleanup removes files from this location.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...

×
×
  • Create New...