Jump to content
CCleaner Community Forums
Winapp2.ini

Winapp2.ini additions

Recommended Posts

Modified Entries:  

[Chrome Application Cache *]

Changed Filekeys 1-11 from REMOVESELF to RECURSE

[Chrome Application Cache *]
LangSecRef=3029
SpecialDetect=DET_CHROME
Detect1=HKCU\Software\Chromium
Detect2=HKCU\Software\SuperBird
Detect3=HKCU\Software\Torch
Detect4=HKCU\Software\Vivaldi
Default=False
FileKey1=%AppData%\Brave\*\Application Cache|*.*|RECURSE
FileKey2=%LocalAppData%\Amigo\User Data\*\Application Cache|*.*|RECURSE
FileKey3=%LocalAppData%\Chrome Plus\User Data\*\Application Cache|*.*|RECURSE
FileKey4=%LocalAppData%\Chromium\User Data\*\Application Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Flock\User Data\*\Application Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Google\Chrome*\User Data\*\Application Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Rockmelt\User Data\*\Application Cache|*.*|RECURSE
FileKey8=%LocalAppData%\SRWare Iron\User Data\*\Application Cache|*.*|RECURSE
FileKey9=%LocalAppData%\SuperBird\User Data\*\Application Cache|*.*|RECURSE
FileKey10=%LocalAppData%\Torch\User Data\*\Application Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Vivaldi\User Data\*\Application Cache|*.*|RECURSE

[Creative Sound Blaster *]

Changed FileKey1/3 from REMOVESELF to  RECURSE

[Creative Sound Blaster *]
LangSecRef=3024
Detect1=HKLM\Software\CREATIVE TECH\Software Installed\Software Update
Detect2=HKLM\Software\CREATIVE TECH\Sound Blaster X-Fi MB
Detect3=HKLM\Software\CREATIVE TECH\Sound Blaster Z-Series Control Panel
Default=False
FileKey1=%CommonAppData%\Creative\Software Update\Cache|*.*|RECURSE
FileKey2=%CommonAppData%\Creative\Software Update\Log|*.*
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Creative\Software Update\Cache|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Creative\Software Update\Log|*.*

 

Share this post


Link to post
Share on other sites

Modified entry:  [Malwarebytes Anti-Malware *]

Modified FileKey4 to include ;*.regtrans-ms;*.TM.blf;*-ntuser.dat;*.LOG1;*.LOG2;*-UsrClass.dat

[Malwarebytes Anti-Malware *]
LangSecRef=3024
Detect=HKCU\Software\Malwarebytes
DetectFile=%ProgramFiles%\Malwarebytes Anti-Malware\mbam.exe
Default=False
Warning=You must manually and temporarily turn off Malwarebytes "self-protection" to remove the logs.
FileKey1=%AppData%\Malwarebytes\Malwarebytes' Anti-Malware\Logs|*.*
FileKey2=%CommonAppData%\Malwarebytes\Malwarebytes' Anti-Malware|mbam-setup.exe
FileKey3=%CommonAppData%\Malwarebytes\Malwarebytes*Anti-Malware\Logs|*.*
FileKey4=%CommonAppData%\Malwarebytes\MBAMService|*.log;*.bak;*.regtrans-ms;*.TM.blf;*-ntuser.dat;*.LOG1;*.LOG2;*-UsrClass.dat
FileKey5=%CommonAppData%\Malwarebytes\MBAMService\logs|*.*
FileKey6=%CommonAppData%\Malwarebytes\MBAMService\ScanResults|*.*
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Malwarebytes\Malwarebytes*Anti-Malware|mbam-setup.exe
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Malwarebytes\Malwarebytes*Anti-Malware\Logs|*.*

 

Share this post


Link to post
Share on other sites
On 19.1.2018 at 02:59, CSGalloway said:

[Utilities - TeamViewer] and [Utilities - Teamviewer *] find the same files.

But the entry [TeamViewer *] could remove more files. Maybe this is related to older versions or to special features of the paid versions.

 

Revised entry:

Removed "Connections_incoming.txt" from FileKey2/3 (covered by CCleaner already).

[TeamViewer *]
LangSecRef=3024
Detect=HKCU\Software\TeamViewer
Default=False
FileKey1=%AppData%\TeamViewer|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\TeamViewer|*.log|RECURSE
FileKey3=%ProgramFiles%\TeamViewer|*.log|RECURSE
FileKey4=%WinDir%\System32|TeamViewer*_Hooks.log
RegKey1=HKCU\Software\TeamViewer\Version5|Last_Machine_Connections
RegKey2=HKCU\Software\TeamViewer\Version5.1|Last_Machine_Connections
RegKey3=HKCU\Software\TeamViewer\Version6|Last_Machine_Connections
RegKey4=HKCU\Software\TeamViewer\Version7|Last_Machine_Connections

Share this post


Link to post
Share on other sites
5 hours ago, APMichael said:

But the entry [TeamViewer *] could remove more files. Maybe this is related to older versions or to special features of the paid versions.

 

Revised entry:

Removed "Connections_incoming.txt" from FileKey2/3 (covered by CCleaner already).


[TeamViewer *]
LangSecRef=3024
Detect=HKCU\Software\TeamViewer
Default=False
FileKey1=%AppData%\TeamViewer|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\TeamViewer|*.log|RECURSE
FileKey3=%ProgramFiles%\TeamViewer|*.log|RECURSE
FileKey4=%WinDir%\System32|TeamViewer*_Hooks.log
RegKey1=HKCU\Software\TeamViewer\Version5|Last_Machine_Connections
RegKey2=HKCU\Software\TeamViewer\Version5.1|Last_Machine_Connections
RegKey3=HKCU\Software\TeamViewer\Version6|Last_Machine_Connections
RegKey4=HKCU\Software\TeamViewer\Version7|Last_Machine_Connections

------------------------------------------------------------------------------------------
Utilities - TeamViewer    1 KB    2 files    
Utilities - TeamViewer *    1 KB    2 files    
------------------------------------------------------------------------------------------
C:\Users\Galloway\AppData\Roaming\TeamViewer\Connections.txt    1 KB
C:\Users\Galloway\AppData\Roaming\TeamViewer\MRU\RemoteSupport\524987459.tvc    1 KB
C:\Users\Galloway\AppData\Roaming\TeamViewer\Connections.txt    1 KB
C:\Users\Galloway\AppData\Roaming\TeamViewer\MRU\RemoteSupport\524987459.tvc    1 KB

winapp.ini has:

[TeamViewer]
ID=2395
LangSecRef=3024
Detect=HKCU\Software\TeamViewer
Default=True
RegKey1=HKCU\Software\TeamViewer\Version9|MRU
RegKey2=HKCU\Software\TeamViewer\Version10|MRU
RegKey3=HKCU\Software\TeamViewer\Version11|MRU
FileKey1=%ProgramFiles%\TeamViewer\*|*.tmp|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\TeamViewer\*|*.tmp|RECURSE
FileKey3=%ProgramFiles%\TeamViewer*|Connections_incoming.txt
FileKey4=%AppData%\TeamViewer|Connections.txt
FileKey5=%AppData%\TeamViewer\MRU\RemoteSupport|*.tvc

Current Winapp2.ini has

[TeamViewer *]
LangSecRef=3024
Detect=HKCU\Software\TeamViewer
Default=False
FileKey1=%AppData%\TeamViewer|*.*|RECURSE  <== already in [Teamviewer]
FileKey2=%LocalAppData%\VirtualStore\Program Files*\TeamViewer|Connections_incoming.txt;*.log|RECURSE
FileKey3=%ProgramFiles%\TeamViewer|Connections_incoming.txt;*.log|RECURSE
FileKey4=%WinDir%\System32|TeamViewer*_Hooks.log
RegKey1=HKCU\Software\TeamViewer\Version5|Last_Machine_Connections
RegKey2=HKCU\Software\TeamViewer\Version5.1|Last_Machine_Connections
RegKey3=HKCU\Software\TeamViewer\Version6|Last_Machine_Connections
RegKey4=HKCU\Software\TeamViewer\Version7|Last_Machine_Connections

 

Share this post


Link to post
Share on other sites
1 hour ago, CSGalloway said:

Since Piriform places RegKeys before FileKeys, why does the forum members not do that as well?

When we did both overhauls, most entries had RegKey under FileKey, so we just moved the remaining ones to match that as it was easier. Anyways, it looks better with RegKey under FileKey and that is proper ABC order, too, and also it makes us look like we are not directly copying Winapp.

Share this post


Link to post
Share on other sites

Here are the entries for Adobe Reader 2017 and Adobe Acrobat 2017:

[Adobe Reader 2017 *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\2017
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\2017\AVGeneral\cRecentFiles
RegKey2=HKCU\Software\Adobe\Acrobat Reader\2017\AVGeneral\cRecentFolders
[Adobe Acrobat 2017 *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\2017
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\2017\AVGeneral\cRecentFiles
RegKey2=HKCU\Software\Adobe\Adobe Acrobat\2017\AVGeneral\cRecentFolders

 

Share this post


Link to post
Share on other sites

Instead of one entry for [.NET Framework *] please delete this and separate the entries as in former versions, because some software like Futuremarks 3DMark and PCMark are storing important information like registration details e.g. in .NET Framework Isolated Storage. Here is how it looks seperated:

[.NET Framework Isolated Storage *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\.NETFramework
Default=False
FileKey1=%LocalAppData%\IsolatedStorage|*.*|REMOVESELF

[.NET Framework Temps *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\.NETFramework
Default=False
FileKey1=%WinDir%\assembly\NativeImages_*\Temp|*.*|RECURSE
FileKey2=%WinDir%\assembly\temp|*.*|RECURSE
FileKey3=%WinDir%\assembly\tmp|*.*|RECURSE
FileKey4=%WinDir%\Microsoft.net\Framework\*\Temporary ASP.NET Files|*.*|RECURSE
FileKey5=%WinDir%\Microsoft.net\Framework64\*\Temporary ASP.NET Files|*.*|RECURSE
FileKey6=%WinDir%\System32\URTTemp|*.*|RECURSE

 

 

Share this post


Link to post
Share on other sites
5 hours ago, hand_polished said:

Instead of one entry for [.NET Framework *] please delete this and separate the entries as in former versions, because some software like Futuremarks 3DMark and PCMark are storing important information like registration details e.g. in .NET Framework Isolated Storage. Here is how it looks seperated:


[.NET Framework Isolated Storage*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\.NETFramework
Default=False
FileKey1=%LocalAppData%\IsolatedStorage|*.*|REMOVESELF

[.NET Framework Temps*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\.NETFramework
Default=False
FileKey1=%WinDir%\assembly\NativeImages_*\Temp|*.*|RECURSE
FileKey2=%WinDir%\assembly\temp|*.*|RECURSE
FileKey3=%WinDir%\assembly\tmp|*.*|RECURSE
FileKey4=%WinDir%\Microsoft.net\Framework\*\Temporary ASP.NET Files|*.*|RECURSE
FileKey5=%WinDir%\Microsoft.net\Framework64\*\Temporary ASP.NET Files|*.*|RECURSE
FileKey6=%WinDir%\System32\URTTemp|*.*|RECURSE

 

 

If that is deleting a program’s registration, why do you still want to keep that, even in a seperste entry? In that case, that FileKey should be removed from [.NET Framework *].

Share this post


Link to post
Share on other sites
5 hours ago, hand_polished said:

Here are the entries for Adobe Reader 2017 and Adobe Acrobat 2017:


[Adobe Reader 2017*]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\2017
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\2017\AVGeneral\cRecentFiles
RegKey2=HKCU\Software\Adobe\Acrobat Reader\2017\AVGeneral\cRecentFolders

[Adobe Acrobat 2017*]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\2017
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\2017\AVGeneral\cRecentFiles
RegKey2=HKCU\Software\Adobe\Adobe Acrobat\2017\AVGeneral\cRecentFolders

 

I just checked adobe.com and they don’t have Adobe Reader 2017 or Adobe Acrobat 2017.

Share this post


Link to post
Share on other sites

Share this post


Link to post
Share on other sites
5 hours ago, hand_polished said:

Here are the entries for Adobe Reader 2017 and Adobe Acrobat 2017:


[Adobe Reader 2017*]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\2017
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\2017\AVGeneral\cRecentFiles
RegKey2=HKCU\Software\Adobe\Acrobat Reader\2017\AVGeneral\cRecentFolders

[Adobe Acrobat 2017*]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\2017
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\2017\AVGeneral\cRecentFiles
RegKey2=HKCU\Software\Adobe\Adobe Acrobat\2017\AVGeneral\cRecentFolders

 

Be sure to leave a space before the *  [Adobe Reader 2017 *]  [Adobe Acrobat 2017 *]

Share this post


Link to post
Share on other sites
8 hours ago, SMalik said:

If that is deleting a program’s registration, why do you still want to keep that, even in a seperste entry? In that case, that FileKey should be removed from [.NET Framework *].

For those who want to keep that Isolated Storage and because I only want to delete the temps. Of course you can delete the Isolated Storage completely if you want.

8 hours ago, SMalik said:

I just checked adobe.com and they don’t have Adobe Reader 2017 or Adobe Acrobat 2017.

https://www.adobe.com/devnet-docs/acrobatetk/tools/ReleaseNotesDC/classic/dcclassic2017base.html

Share this post


Link to post
Share on other sites
4 hours ago, hand_polished said:

For those who want to keep that Isolated Storage and because I only want to delete the temps. Of course you can delete the Isolated Storage completely if you want.

https://www.adobe.com/devnet-docs/acrobatetk/tools/ReleaseNotesDC/classic/dcclassic2017base.html

Acrobat DC is the latest subscription version of Acrobat. Acrobat 2017 is the latest perpetual desktop version of Acrobat.

https://helpx.adobe.com/acrobat/using/whats-new-acrobat-2017.html

By the way, there is no Adobe Reader 2017.

Share this post


Link to post
Share on other sites

Share this post


Link to post
Share on other sites

Revised Entry

Removed:
%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Assets|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\ContentManagementSDK\Creatives|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Features|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\StagedAssets|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\Settings|*.dat*

Added:
%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\BackgroundTransferApi|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Favicons|*.*|RECURSE

[Content Delivery Manager *]
DetectOS=10.0|
Section=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\BackgroundTransferApi|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\INet*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Favicons|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\MobilityExperience\ImageCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\OneSettingsResponseCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\TargetedContentCache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\TempState|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\INetCache\|container.dat

Share this post


Link to post
Share on other sites

Revised Entry

Added:
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetCache\|container.dat;*.css;*.js

[Cloud Experience Host *]
DetectOS=10.0|
Section=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\TempState|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetCache\|container.dat;*.css;*.js

Share this post


Link to post
Share on other sites

Revised Entry

Merged [Push Notifications *] into the [Notifications *] entry.
Added FileKey2

[Notifications *]
DetectOS=10.0|
LangSecRef=3025
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\Notifications\wpnidm|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\Notifications|*.db;*.db-shm;*.db-wal
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications\wpnidm
RegKey2=HKLM\Software\Microsoft\Windows NT\CurrentVersion\Notifications\Data

Share this post


Link to post
Share on other sites

I apologize it is not FileKey3 in the [Windows Logs *] that removes login info for Windows Insider Program account, it is FileKey11 in the [Windows Subsystems *] that is causing this issue.

I have removed FileKey 11 from [Windows Subsystems *].

https://forum.piriform.com/topic/32310-winapp2ini-additions/?do=findComment&comment=292388

insider_account.png

Edited by SMalik

Share this post


Link to post
Share on other sites

Revised Entry

Removed:
This is removing the Windows Insider Program account.
%LocalAppData%\Microsoft\TokenBroker\Cache|*.*|RECURSE

RegKey1=HKCR\VirtualStore\MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
RegKey2=HKCR\VirtualStore\MACHINE\Software\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication

Just these are enough.
RegKey3=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
RegKey4=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication

[Windows Subsystems *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\PlayReady|*.hds
FileKey2=%CommonAppData%\Microsoft\PlayReady\Cache|*.*
FileKey3=%CommonAppData%\Microsoft\RAC\PublishedData|*.log;*.jrs
FileKey4=%CommonAppData%\Microsoft\RAC\StateData|*.log;*.jrs
FileKey5=%CommonAppData%\Microsoft\RAC\Temp|*.*
FileKey6=%CommonAppData%\Microsoft\Windows\DRM|*.log
FileKey7=%CommonAppData%\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey8=%CommonAppData%\Microsoft\Windows\DRM\PreUpgrade|*.log
FileKey9=%CommonAppData%\Microsoft\Windows\Sqm\Manifest|*.bin
FileKey10=%CommonAppData%\Microsoft\Windows\Sqm\Sessions|*.psqm;*.sqm
FileKey11=%LocalAppData%\Microsoft\Windows\PRICache|*.*|RECURSE
FileKey12=%LocalAppData%\Microsoft\Windows\SettingSync\metastore|*.jrs
FileKey13=%LocalAppData%\Microsoft\Windows\SettingSync\remotemetastore\*|*.jrs
FileKey14=%LocalAppData%\VirtualStore\ProgramData\Microsoft\PlayReady|*.hds
FileKey15=%LocalAppData%\VirtualStore\ProgramData\Microsoft\PlayReady\Cache|*.*
FileKey16=%LocalAppData%\VirtualStore\ProgramData\Microsoft\RAC\PublishedData|*.log;*.jrs
FileKey17=%LocalAppData%\VirtualStore\ProgramData\Microsoft\RAC\StateData|*.log;*.jrs
FileKey18=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM|*.log
FileKey19=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey20=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\PreUpgrade|*.log
FileKey21=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\Sqm\Manifest|*.bin
FileKey22=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\Sqm\Sessions|*.psqm;*.sqm
FileKey23=%SystemDrive%\spoolerlogs|spooler.xml
FileKey24=%WinDir%\ehome|PRDMOWrapper.log
FileKey25=%WinDir%\System32|PRDMOWrapper.log
FileKey26=%WinDir%\system32\spool|spooler.xml
FileKey27=%WinDir%\System32\sru|*.*|RECURSE
RegKey1=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
RegKey2=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication
RegKey3=HKCU\Software\Microsoft\Direct3D\MostRecentApplication
RegKey4=HKLM\Software\Microsoft\Direct3D\MostRecentApplication
RegKey5=HKLM\Software\Microsoft\DirectDraw\MostRecentApplication
RegKey6=HKLM\Software\Microsoft\Windows\CurrentVersion\Setup|Installation Sources
RegKey7=HKLM\Software\Wow6432Node\Microsoft\Direct3D\MostRecentApplication
RegKey8=HKLM\Software\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication

Share this post


Link to post
Share on other sites

New Entry

[Feedback Hub *]
DetectOS=10.0
Section=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\TempState|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INetCache\|container.dat

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...

×
×
  • Create New...