Jump to content
CCleaner Community Forums
Winapp2.ini

Winapp2.ini additions

Recommended Posts

I think items associated with VirtualStore locations are related to how Windows handles sandboxing / security when the UAC is enabled.

Share this post


Link to post
Share on other sites

Revised Entry

Added FileKey12

[Apple iTunes *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AppleInc.iTunes_nzyj5cx40ttqa
DetectFile=%LocalAppData%\Packages\AppleInc.iTunes_nzyj5cx40ttqa
Default=False
FileKey1=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Local\Apple Computer\iTunes|Cache.db;*.xml
FileKey5=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Local\Microsoft\Windows\Caches|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\iTunes\Cookies|Cookies.binarycookies
FileKey8=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\iTunes\Device Support|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\Logs|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\AppleInc.iTunes_*\SystemAppData\Helium\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\AppleInc.iTunes_*\TempState|*.*|RECURSE
FileKey12=%WinDir%\System32\config\systemprofile\AppData\Roaming\Apple Computer\Logs|*.*|RECURSE

Share this post


Link to post
Share on other sites

Revised Entry

Added FileKey11 & FileKey12

[Plex Media Server *]
LangSecRef=3023
Detect=HKCU\Software\Plex, Inc.\Plex Media Server
Default=False
FileKey1=%LocalAppData%\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey2=%LocalAppData%\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey3=%LocalAppData%\Plex Media Server\Logs|*.*|RECURSE
FileKey4=%LocalAppData%\Plex Media Server\Updates|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Logs|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Updates|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey10=%ProgramFiles%\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey11=%WinDir%\System32\config\systemprofile\AppData\Local\Plex Media Server\Logs|*.*|RECURSE
FileKey12=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Plex Media Server\Logs|*.*|RECURSE

Share this post


Link to post
Share on other sites

Revised Entry

Added FileKey4 & FileKey16

[Adobe CC *]
LangSecRef=3023
Detect=HKCU\Software\Adobe\CreativeCloud
Default=False
FileKey1=%AppData%\Adobe\Adobe Media Encoder\*\logs|*.*|RECURSE
FileKey2=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings\CrashLogs|*.*|RECURSE
FileKey3=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings\web-cache-temp|*.*|RECURSE
FileKey4=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings|PSErrorLog.txt;sniffer-*.txt
FileKey5=%AppData%\Adobe\Adobe Photoshop CC *\Logs|*.*|RECURSE
FileKey6=%AppData%\Adobe\CRLogs|*.*|RECURSE
FileKey7=%AppData%\Adobe\dynamiclinkmanager\*\logs|*.*|RECURSE
FileKey8=%AppData%\Adobe\Extension Manager CC\Log|*.*|RECURSE
FileKey9=%AppData%\Adobe\Extension Manager CC\Temp|*.*|RECURSE
FileKey10=%AppData%\Adobe\LogTransport2CC\Logs|*.*|RECURSE
FileKey11=%AppData%\Adobe\Lumetri\*\logs|*.*|RECURSE
FileKey12=%AppData%\Adobe\Premiere Pro\*|Plugin Loading.log
FileKey13=%AppData%\Adobe\Premiere Pro\*\logs|*.*|RECURSE
FileKey14=%CommonProgramFiles%\Adobe\Installers|CoreSyncInstall.log;Install.log
FileKey15=%Documents%\Adobe|*.log
FileKey16=%Documents%\Adobe\Adobe Media Encoder\*|AMEEncodingErrorLog.txt;AMEEncodingLog.txt;
FileKey17=%Documents%\Adobe\Adobe Media Encoder\*\logs|*.*|RECURSE
FileKey18=%Documents%\Adobe\Premiere Pro\*|Plugin Loading.log
RegKey1=KCU\Software\Adobe\MediaBrowser\MRU

Share this post


Link to post
Share on other sites
On 11.10.2018 at 23:42, SMalik said:

I think we should add this HKEY_CURRENT_USER\Software\Classes\VirtualStore

If you remove the key "VirtualStore" you will remove settings of old legacy applications (coded for Windows XP and older) or wrong coded applications.

You can see it on siliconman01s screenshot. And the Microsoft documentation explains it also:

Quote

Virtualization Overview

Prior to Windows Vista, applications were typically run by administrators. As a result, applications could freely access system files and registry keys. If these applications were run by a standard user, they would fail due to insufficient access rights. Windows Vista and later versions of Windows improve application compatibility for these applications by automatically redirecting these operations. For example, registry operations to the global store (HKEY_LOCAL_MACHINE\Software) are redirected to a per-user location within the user's profile known as the virtual store (HKEY_USERS\_Classes\VirtualStore\Machine\Software).

Here you can find a more detailed explanation: https://technet.microsoft.com/en-us/library/2007.06.uac.aspx

(Piriform could improve CCleaner, so that it checks the HKLM RegKeys also under HKCU\Software\Classes\VirtualStore\MACHINE. Unfortunately, they never react on those feature requests.)

Share this post


Link to post
Share on other sites

New Entry

I have made this entry from a Windows 8.1 system, not just making it up. I think Store entries for Windows 8 and Windows 10 should be separate.

[Windows Store *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\winstore_cw5n1h2txyewy
DetectFile=%LocalAppData%\Packages\winstore_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\winstore_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\winstore_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\winstore_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\winstore_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\winstore_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\winstore_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\winstore_*\LocalState\LiveTile|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Packages\winstore_*\AC\INetCache\|container.dat

Share this post


Link to post
Share on other sites

Revised Entry
Added FileKey10, FileKey11 & FileKey12
Removed FileKey9

[Groove Music *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\PRICache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalCache\PlayReady\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\Database\*|*.log
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageRetrievalFailure|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageStore|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\navigationHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\PlayReady|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\SearchHistory
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCache\|container.dat

Share this post


Link to post
Share on other sites

Revised Entry
Added FileKey10, FileKey11 & FileKey12
Removed FileKey9

[Movies & TV *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe*
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\PRICache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalCache\PlayReady\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Database\anonymous|*.log
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageRetrievalFailure|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageStore|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\navigationHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\PlayReady|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe\SearchHistory\SearchHistory
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCache\|container.dat

Share this post


Link to post
Share on other sites

New Entries

[OneConnect *]
DetectOS=10.0
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.OneConnect_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalCache\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalState\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalState\DiagOutputDir|*.txt
FileKey7=%LocalAppData%\Packages\Microsoft.OneConnect_*\TempState|*.*|RECURSE

[XboxGameOverlay *]
DetectOS=10.0
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxGameOverlay_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalCache\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalState\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalState\DiagOutputDir|*.txt
FileKey7=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\TempState|*.*|RECURSE

Share this post


Link to post
Share on other sites

Revised Entry
Added FileKey5

[Feedback Hub *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalState\DiagOutputDir|*.txt
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\TempState|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INetCache\|container.dat

Share this post


Link to post
Share on other sites

Revised Entry
Added FileKey7

[Xbox *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxApp_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\*Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\DiagOutputDir|*.txt
FileKey8=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log
FileKey9=%LocalAppData%\Packages\Microsoft.XboxApp_*\TempState|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCache\|container.dat

Share this post


Link to post
Share on other sites
On 10/12/2018 at 09:00, Winapp2.ini said:

I think items associated with VirtualStore locations are related to how Windows handles sandboxing / security when the UAC is enabled.

I have been watching that path in the registry. Portable apps leave traces there, but no settings. In the screenshot above, I used a portable app, Windows ISO Downloader, and I deleted it from the drive. I tried some other portable apps and they also left traces at the same path, even though the program was removed from the drive. The link posted above with the screenshot has good information about these traces.

Share this post


Link to post
Share on other sites

New app - Sonata (Accounting software)

 

[Sonata *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Sonata
Default=False
Warning=This will remove all backups
FileKey1=%ProgramFiles%\Sonata\update|*.*|RECURSE
FileKey2=%LocalAppData%\sonata\temp|*.*|RECURSE
FileKey3=D:\Sonata\backups|*.*|RECURSE

 

Share this post


Link to post
Share on other sites
1 hour ago, tankist_ua said:

New app - Sonata (Accounting software)

Thanks for the new entry.

The location of the backups (FileKey3) seems to be user-defined (not everybody has a second partition D). Therefore, we can add FileKey1 and 2 only.

Share this post


Link to post
Share on other sites

Revised Entry
Added
FileKey12

[MS Office *]
LangSecRef=3021
Detect1=HKCU\Software\Microsoft\Office\12.0\Common
Detect2=HKCU\Software\Microsoft\Office\14.0\Common
Detect3=HKCU\Software\Microsoft\Office\15.0\Common
Detect4=HKCU\Software\Microsoft\Office\16.0\Common
Default=False
FileKey1=%AppData%\Microsoft\Document Building Blocks|*.*|RECURSE
FileKey2=%AppData%\Microsoft\Office|*.tmp|RECURSE
FileKey3=%AppData%\Microsoft\OIS|Toolbars.dat
FileKey4=%AppData%\Microsoft\UProof|*.bin;*.XML
FileKey5=%CommonAppData%\Microsoft\ClickToRun\ProductReleases|*.*|RECURSE
FileKey6=%Documents%|~*.ppt;~*.pptx;~*.doc;~*.docx|RECURSE
FileKey7=%LocalAppData%\Microsoft Help|*.*
FileKey8=%LocalAppData%\Microsoft\Office\*|OneNoteOfflineCache.onecache
FileKey9=%LocalAppData%\Microsoft\Office\*\OfficeFileCache|*.*|RECURSE
FileKey10=%LocalAppData%\Microsoft\OneNote\*|OneNoteOfflineCache.onecache
FileKey11=%LocalAppData%\Microsoft\OneNote\*\OneNoteOfflineCache_Files|*.*|RECURSE
FileKey12=%LocalAppData%\Microsoft\OneNote\*\cache|*.*|RECURSE
FileKey13=%SystemDrive%|propfix.log
RegKey1=HKCU\Software\Microsoft\Office\11.0\MSE|LastLoadedSolution
RegKey2=HKCU\Software\Microsoft\Office\11.0\MSE\FileMRUList
RegKey3=HKCU\Software\Microsoft\Office\11.0\MSE\ProjectMRUList
RegKey4=HKCU\Software\Microsoft\Office\11.0\MSE\SolutionMRUList
RegKey5=HKCU\Software\Microsoft\Office\12.0\Common\Internet|UseRWHlinkNavigation
RegKey6=HKCU\Software\Microsoft\Office\12.0\Word\Reading Locations
RegKey7=HKCU\Software\Microsoft\Office\14.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\Office\14.0\Word\Reading Locations
RegKey9=HKCU\Software\Microsoft\Office\15.0\Common\Internet|UseRWHlinkNavigation
RegKey10=HKCU\Software\Microsoft\Office\15.0\Word\Reading Locations
RegKey11=HKCU\Software\Microsoft\Office\16.0\Common\Internet|UseRWHlinkNavigation
RegKey12=HKCU\Software\Microsoft\Office\16.0\Word\Reading Locations
RegKey13=HKCU\Software\Microsoft\Office\Common|FontBmpCache
RegKey14=HKCU\Software\Microsoft\OfficeCustomizeWizard\12.0\RecentFileList
RegKey15=HKCU\Software\Microsoft\OfficeCustomizeWizard\14.0\RecentFileList
RegKey16=HKCU\Software\Microsoft\OfficeCustomizeWizard\15.0\RecentFileList
RegKey17=HKCU\Software\Microsoft\OfficeCustomizeWizard\16.0\RecentFileList

Share this post


Link to post
Share on other sites

Revised Entry

Added FileKey5

[Adobe Acrobat DC *]
LangSecRef=3021
Detect=HKLM\Software\Adobe\Adobe Acrobat\DC
Default=False
FileKey1=%LocalAppData%\Adobe\Acrobat\DC|*.lst;UserCache.bin
FileKey2=%LocalAppData%\Adobe\Acrobat\DC\Cache|*.lst
FileKey3=%LocalAppData%\Adobe\Acrobat\DC\ToolsSearchCacheAcro|*.*|RECURSE
FileKey4=%LocalLowAppData%\Adobe\Acrobat\DC\Search|*.*|RECURSE
FileKey5=%LocalLowAppData%\Adobe\AcroCef\DC\Acrobat\Cache|*.*|RECURSE
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionFromPDF\cSettings
RegKey2=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionToPDF\cSettings
RegKey3=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cDockables
RegKey4=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles
RegKey5=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFolders
RegKey6=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentToolsList
RegKey7=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars
RegKey8=HKCU\Software\Adobe\Adobe Acrobat\DC\RememberedViews\cNoCategoryFiles
RegKey9=HKCU\Software\Adobe\Adobe Acrobat\DC\ShareIdentity
RegKey10=HKCU\Software\Adobe\Adobe Synchronizer\DC

Share this post


Link to post
Share on other sites

Revised Entry

Added FileKey1

[Windows Communications Apps *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Comms\Unistore\data|AggregateCache.uca
FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\AppCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INet*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\PRICache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\LiveComm\*\*\DBStore\LogFiles|edbtmp.log
FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory
ExcludeKey1=FILE|%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCache\|container.dat

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...

×
×
  • Create New...