Jump to content

siliconman01

Experienced Members
  • Posts

    1,117
  • Joined

  • Last visited

Posts posted by siliconman01

  1. New Entries

    LSys (Local System)

     

    [LSys Cached File Extensions*]
    LangSecRef=3025
    Detect=HKU\.DEFAULT\Software\Microsoft\Windows
    Default=False
    RegKey1=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    
    [LSys Cached Shell Extensions*]
    LangSecRef=3025
    Detect=HKU\.DEFAULT\Software\Microsoft\Windows
    Default=False
    RegKey1=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached

     

    If these are added to Winapp2.ini, I suggest the name be "Local System" instead of the abbreviated "LSys" so that users are better able to identify what these are related to.

     

    Does Windows have to rebuild these after they are cleared?

  2. I strongly recommend that the entry Windows SCM Logs* be removed from WinApp2.ini because it causes the Event ID 114 failure in the system Task Scheduler as described above.

     

    [Windows SCM Logs*]
    LangSecRef=3025
    Detect=HKCU\Software\Microsoft\Windows
    Default=False
    FileKey1=%WinDir%\System32\LogFiles\Scm|*.*
    

  3. I am attempting to track down what WinApp2.ini entry is causing the system Task Scheduler to experience Event ID 114 on scheduled tasks that run via the Task Scheduler. If anyone has any clues or feedback on what entry might be causing this, please "point me in the right direction". Below is a more detailed description of the issue. I use my "Casper" system backup program as the example; however, the problem affects all programs in the Task Scheduler. My systems are Windows 7 and Windows 8.

     

    - I have Casper set up in the Task Scheduler to run every Tuesday and Saturday at 3:00 a.m. to copy my primary operating system to a separate bootable backup drive.

    - In the Task Scheduler on the Settings tab, I have "Run task as soon as possible after a scheduled start is missed" selected.

    - The Task Scheduler works correctly and runs Casper on Tuesday and Saturday at the prescribed times.

    - The time/date of the Casper run is properly displayed via the Task Scheduler under "Last Run Time".

    - The time/date of the next scheduled Casper execution is properly displayed via the Task Scheduler under "Next Run Time"

     

    - When I run CCleaner after the above Casper execution, the "Last Run Time" is cleared out and "Never" now shows as the "Last Run Time".

    - On system reboot, this causes the Task Scheduler to think that Casper did not run when scheduled (Event ID 114). And it then runs Casper as directed via the option "Run task as soon as possible after a scheduled start is missed".

     

    I am going through the process of elimination under the Applications tab of CCleaner; however, in the interest of time I am posting this "request for assistance". :unsure:

  4. New Windows 8 Apps: GasBuddy and Team Crossword

     

    [GasBuddy*]

    Section=Windows 8 Apps

    DetectFile=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_932xwky9axss4

    Default=False

    FileKey1=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\INetCache|*.*|RECURSE

    FileKey2=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\INetCookies|*.*|RECURSE

    FileKey3=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\INetHistory|*.*|RECURSE

    FileKey4=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\Temp|*.*

    FileKey5=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\PRICache|*.*

    FileKey6=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE

    FileKey7=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\TempState|*.*|RECURSE

     

     

    [Team Crossword*]

    Section=Windows 8 Apps

    DetectFile=%LocalAppData%\Packages\Microsoft.TeamCrossword_8wekyb3d8bbwe

    Default=False

    FileKey1=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\Microsoft\CryptnetUrlCache\Content|*.*

    FileKey2=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*

    FileKey3=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\INetCache|*.*|RECURSE

    FileKey4=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\INetCookies|*.*|RECURSE

    FileKey5=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\INetHistory|*.*|RECURSE

    FileKey6=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\Temp|*.*

    FileKey7=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\PRICache|*.*

    FileKey8=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE

    FileKey9=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\TempState|*.*|RECURSE

  5. Changing [Nvidia Graphics Driver Installation Files*] from:

     

    [Nvidia Graphics Driver Installation Files*]
    LangSecRef=3023
    Detect=HKCU\Software\NVIDIA Corporation
    Default=False
    Warning=You will not be able to do an uninstall of your drivers without first reinstalling them.
    FileKey1=%SystemDrive%\Nvidia|*.*|REMOVESELF
    FileKey2=%ProgramFiles%\NVIDIA Corporation\Installer2|*.*|RECURSE
    

     

    to

     

    [Nvidia Graphics Driver Installation Files*]
    LangSecRef=3023
    Detect=HKCU\Software\NVIDIA Corporation
    Default=False
    FileKey1=%SystemDrive%\Nvidia|*.*|REMOVESELF
    

     

    is a solution to the problem that Saad2011 aptly points out. I recommend this change be made. :) %SystemDrive%\Nvidia is an extraction folder that is used by the Nvidia installer when performing an update. After the update is completed, this folder is no longer needed or used.

  6. The [Nvidia Graphics Driver Installation Files*] does contain the warning

     

    Warning=You will not be able to do an uninstall of your drivers without first reinstalling them.

     

    I've always been able to download and successfully install new updates (either released or beta versions) right over the top of an old version of NVidia.

  7. Please do NOT remove the [Nvidia Graphics Driver Installation Files*] unless someone can point to a problem that it is causing. I've been removing this for months on Windows 7 and Windows 8 with no issues uncovered...at least on my systems. ^_^

  8. jv16 PowerTools 2013 is in the release candidate stages and most likely will be released in the next few weeks. You can add the following cleaning items for it.

     

    New:

     

    [jv16 PowerTools 2013 Backup Files*]

    LangSecRef=3024

    DetectFile=%ProgramFiles%\jv16 PowerTools 2013\jv16PT.exe

    Default=False

    FileKey1=%ProgramFiles%\jv16 PowerTools 2013\Backups|*.*|RECURSE

    FileKey2=%ProgramFiles%\jv16 PowerTools 2013\Settings|UserActionLog.txt

    ExcludeKey1=FILE|%ProgramFiles%\jv16 PowerTools 2013\Backups|License.xbin_backup

     

    Modified:

    [jv16 PowerTools Registry Compact Backups*]

    LangSecRef=3024

    DetectFile1=%ProgramFiles%\jv16 PowerTools 2009\jv16PT.exe

    DetectFile2=%ProgramFiles%\jv16 PowerTools 2010\jv16PT.exe

    DetectFile3=%ProgramFiles%\jv16 PowerTools 2011\jv16PT.exe

    DetectFile4=%ProgramFiles%\jv16 PowerTools 2012\jv16PT.exe

    DetectFile5=%ProgramFiles%\jv16 PowerTools 2013\jv16PT.exe

    Default=False

    Warning=This removes the registry hive backup files generated by jv16 PowerTools during a registry compaction. These files are not needed once the compaction is successfully completed. They can be safely deleted. NOTE that the system must be rebooted following a registry compaction completion in order for jv16 to release these files for deletion.

    FileKey1=%UserProfile%|NTUSER.DAT.jv16pt*

    FileKey2=%LocalAppData%\Microsoft\Windows|UsrClass.dat.jv16pt*

    FileKey3=%WinDir%\system32\config|Default.jv16pt*;software.jv16pt*;system.jv16pt*;SAM.jv16pt*;COMPONENTS.jv16pt*

    FileKey4=%WinDir%\ServiceProfiles\NetworkService|NTUSER.DAT.jv16pt*

    FileKey5=%WinDir%\ServiceProfiles\LocalService|NTUSER.DAT.jv16pt*

    FileKey6=%SystemDrive%\Documents and Settings\NetworkService|NTUSER.DAT.jv16pt*

    FileKey7=%SystemDrive%\Documents and Settings\LocalService|NTUSER.DAT.jv16pt*

    FileKey8=%SystemDrive%\Documents and Settings\NetworkService.NT*|NTUSER.DAT.jv16pt*

    FileKey9=%SystemDrive%\Documents and Settings\LocalService.NT*|NTUSER.DAT.jv16pt*

  9. New Entry:

     

    [NBC News*]

    DetectOS=6.2|

    Section=Windows 8 Apps

    DetectFile=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_amdjbdaxqsje6

    Default=False

    FileKey1=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\INetCache|*.*|RECURSE

    FileKey2=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\INetCookies|*.*|RECURSE

    FileKey3=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\INetHistory|*.*|RECURSE

    FileKey4=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\Temp|*.*

    FileKey5=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\PRICache|*.*

    FileKey6=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE

    FileKey7=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\TempState|*.*|RECURSE

  10. New Entry:

     

    [Norton Power Eraser*]

    LangSecRef=3024

    DetectFile=%CommonAppData%\Norton\NPE\NPEsettings.dat

    Warning=This removes ALL files and traces of Norton's diagnostic and scan tool known as Norton Power Eraser. This tool should be downloaded fresh from Symantec each time it is run.

    Default=False

    FileKey1=%CommonAppData%\Norton\NPE\|*.*|REMOVESELF

    FileKey2=%LocalAppData%\NPE\|*.*|REMOVESELF

    FileKey3=%UserProfile%\Desktop|NPE.exe

  11. New Entries for Windows 8 Apps:

     

     

    [uSA Today*]

    DetectOS=6.2|

    Section=Windows 8 Apps

    DetectFile=%LocalAppData%\Packages\USATODAY.USATODAY_wy7mw3214mat8

    Default=False

    FileKey1=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\INetCache|*.*|RECURSE

    FileKey2=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\INetCookies|*.*|RECURSE

    FileKey3=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\INetHistory|*.*|RECURSE

    FileKey4=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\Temp|*.*

    FileKey5=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\PRICache|*.*

    FileKey6=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE

    FileKey7=%LocalAppData%\Packages\USATODAY.USATODAY_*\TempState|*.*|RECURSE

     

    [Netflix*]

    DetectOS=6.2|

    Section=Windows 8 Apps

    DetectFile=%LocalAppData%\Packages\4DF9E0F8.Netflix_mcm4njqhnhss8

    Default=False

    FileKey1=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\INetCache|*.*|RECURSE

    FileKey2=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\INetCookies|*.*|RECURSE

    FileKey3=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\INetHistory|*.*|RECURSE

    FileKey4=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\Temp|*.*

    FileKey5=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\PRICache|*.*

    FileKey6=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE

    FileKey7=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\TempState|*.*|RECURSE

     

    [CNN*]

    DetectOS=6.2|

    Section=Windows 8 Apps

    DetectFile=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_cs8eyncph15zy

    Default=False

    FileKey1=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\INetCache|*.*|RECURSE

    FileKey2=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\INetCookies|*.*|RECURSE

    FileKey3=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\INetHistory|*.*|RECURSE

    FileKey4=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\Temp|*.*

    FileKey5=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\PRICache|*.*

    FileKey6=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE

    FileKey7=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE

    FileKey8=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\TempState|*.*|RECURSE

  12. The [Camera*] and [store*] Windows 8 Apps code has a bug in them that cause the Camera app to fail when recording videos. If you use that app and make a video, then go do something else, and then run CCleaner with Camera* and/or Store* checkmarked, you cannot record another video via the Camera* app until you reboot the computer. An error message occurs and the video will not record. I have commented out the line in these two codes that stops this error in the Camera app.

     

    [Camera*]

    DetectOS=6.2|

    Section=Windows 8 Apps

    DetectFile=%LocalAppData%\Packages\Microsoft.Camera_8wekyb3d8bbwe

    Default=False

    FileKey1=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CryptnetUrlCache\Content|*.*

    FileKey2=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*

    FileKey3=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetCache|*.*|RECURSE

    FileKey4=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetCookies|*.*|RECURSE

    FileKey5=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetHistory|*.*|RECURSE

    FileKey6=%LocalAppData%\Packages\Microsoft.Camera_*\AC\AppCache|*.*|RECURSE

    FileKey7=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Temp|*.*

    FileKey8=%LocalAppData%\Packages\Microsoft.Camera_*\AC\PRICache|*.*

    ; FileKey9=%LocalAppData%\Packages\Microsoft.Camera_*\TempState|*.*|RECURSE

    RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe\SearchHistory

     

    FileKey9 has been commented out.

     

     

    [store*]

    DetectOS=6.2|

    Section=Windows 8 Apps

    DetectFile=%LocalAppData%\Packages\WinStore_cw5n1h2txyewy

    Default=False

    FileKey1=%LocalAppData%\Packages\WinStore_*\AC\Microsoft\CryptnetUrlCache\Content|*.*

    FileKey2=%LocalAppData%\Packages\WinStore_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*

    FileKey3=%LocalAppData%\Packages\WinStore_*\AC\INetCache|*.*|RECURSE

    FileKey4=%LocalAppData%\Packages\WinStore_*\AC\INetCookies|*.*|RECURSE

    FileKey5=%LocalAppData%\Packages\WinStore_*\AC\INetHistory|*.*|RECURSE

    FileKey6=%LocalAppData%\Packages\WinStore_*\AC\AppCache|*.*|RECURSE

    FileKey7=%LocalAppData%\Packages\WinStore_*\AC\Temp|*.*

    FileKey8=%LocalAppData%\Packages\WinStore_*\AC\PRICache|*.*

    FileKey9=%LocalAppData%\Packages\WinStore_*\LocalState\Cache|*.*|RECURSE

    FileKey10=%LocalAppData%\Packages\WinStore_*\LocalState\navigationHistory|*.*|RECURSE

    FileKey11=%LocalAppData%\Packages\WinStore_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE

    ; FileKey12=%LocalAppData%\Packages\*\TempState|*.*|RECURSE

    FileKey13=%LocalAppData%\Packages\WinStore*\AC\Microsoft\Windows Store\Cache|*.*|RECURSE

    FileKey14=%LocalAppData%\Microsoft\Windows Store\Cache Medium IL|*.*|RECURSE

    FileKey15=%LocalAppData%\Packages\WinStore_*\AC\Microsoft\Windows Store\Data|history.dat

    RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\WinStore_cw5n1h2txyewy\SearchHistory

     

    FileKey12 has been commented out.

  13. Modified Entry: Changed DetectOS=|6.1 to DetectOS=6.1|

     

    [Windows 7/8 Transcoded Wallpaper Cache*]

    LangSecRef=3025

    Detect=HKCU\Software\Microsoft\Windows

    DetectOS=6.1|

    Default=False

    Warning=You have to refresh your background!

    FileKey1=%AppData%\Microsoft\Windows\Themes|TranscodedWallpaper.jpg

  14. Looks like you overlooked the one below:

     

    [MS Office 2013 SkyDrive (setup logs)*]

    LangSecRef=3021

    Detect=HKCU\Software\Microsoft\SkyDrive

    Default=False

    FileKey1=%LocalAppData%\Microsoft\SkyDrive\Setup\Logs\|*.*

  15. Yes, it can be added to Indexing Traces. I tested it with Windows Search enabled on Windows 7 and Windows 8. When CCleaner tries to remove Windows.edb, it cannot because the service has it in use. No error messages are emitted either. So I agree that the Warning message is not needed either. Again, I have no way of testing it on XP or Vista.

  16. [indexing Traces*] entry removes .db files. There is no need to add a duplicate entry.

     

    It is safe to remove .db files from that location. There is no need to add a warning.

     

    Windows.edb is in a different folder than addressed by Indexing Traces*. It is in the Windows folder and not in the three folders of Indexing Traces*

     

    [indexing Traces*]
    LangSecRef=3025
    Detect=HKCU\Software\Microsoft\Windows
    Default=False
    FileKey1=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
    FileKey2=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
    FileKey3=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
    

  17. If the user does checkmark the entry whilst the service is enabled,

    OR IF the service is subsequently enabled,

    WHAT is the consequence ?

     

    It may be acceptable if the consequence is that a search instantly results in zero results,

    but not acceptable if the system locks up.

     

    If Search is re-enabled, Windows.edb is rebuilt automatically. Google Windows.edb delete shows several results such as:

     

    http://windows7themes.net/what-is-windows-edb-can-i-delete-it-or-change-its-location.html

  18. New Entry:

     

    [Windows 7/8 Search (Windows.edb)*]

    LangSecRef=3025

    DetectOS=6.1|

    Warning=Checkmark this entry to remove file Windows.edb ONLY if you have Windows Search service disabled. Windows.edb can be several hundred megabytes in size and is not needed if Search is disabled.

    Default=False

    FileKey1=%ProgramData%\Microsoft\Search\Data\Applications\Windows\|Windows.edb

     

    NOTE: This entry MAY be applicable to Windows Vista and XP; however, I have no way of testing it on these systems. I suspect that if search/Indexing is disabled on Windows Vista and XP, then Windows.edb can be removed.

  19. Please note that I made an error in this one. There were 2 RegKey2 entries. It is corrected below.

     

    [MS Office PowerPoint More*]

    LangSecRef=3021

    Detect1=HKCU\Software\Microsoft\Office\12.0

    Detect2=HKCU\Software\Microsoft\Office\14.0

    Detect3=HKCU\Software\Microsoft\Office\15.0

    Default=False

    RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Internet|UseRWHlinkNavigation

    RegKey2=HKCU\Software\Microsoft\Office\14.0\Common\Internet|UseRWHlinkNavigation

    RegKey3=HKCU\Software\Microsoft\Office\15.0\Common\Internet|UseRWHlinkNavigation

  20. Modified Entries to Include MS Office 2013:

     

     

    [MS Office Help Cache*]

    LangSecRef=3021

    Detect1=HKCU\Software\Microsoft\Office\12.0

    Detect2=HKCU\Software\Microsoft\Office\14.0

    Detect3=HKCU\Software\Microsoft\Office\15.0

    Default=False

    FileKey1=%LocalAppData%\Microsoft Help|*.*

     

    [MS Office PowerPoint More*]

    LangSecRef=3021

    Detect1=HKCU\Software\Microsoft\Office\12.0

    Detect2=HKCU\Software\Microsoft\Office\14.0

    Detect3=HKCU\Software\Microsoft\Office\15.0

    Default=False

    RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Internet|UseRWHlinkNavigation

    RegKey2=HKCU\Software\Microsoft\Office\14.0\Common\Internet|UseRWHlinkNavigation

    RegKey3=HKCU\Software\Microsoft\Office\15.0\Common\Internet|UseRWHlinkNavigation

     

    [MS Office Saved CEIP Data*]

    LangSecRef=3021

    Detect1=HKCU\Software\Microsoft\Office\12.0

    Detect2=HKCU\Software\Microsoft\Office\14.0

    Detect3=HKCU\Software\Microsoft\Office\15.0

    Default=False

    FileKey1=%AppData%\Microsoft\UProof|*.bin;*.XML

     

    [MS Office UnsavedFiles*]

    LangSecRef=3021

    Detect1=HKCU\Software\Microsoft\Office\12.0

    Detect2=HKCU\Software\Microsoft\Office\14.0

    Detect3=HKCU\Software\Microsoft\Office\15.0

    Default=False

    FileKey1=%LocalAppData%\Microsoft\Office\UnsavedFiles|*.*

     

    [MS Office Word More*]

    LangSecRef=3021

    Detect1=HKCU\Software\Microsoft\Office\12.0

    Detect2=HKCU\Software\Microsoft\Office\14.0

    Detect3=HKCU\Software\Microsoft\Office\15.0

    Default=False

    FileKey1=%AppData%\Microsoft\Word|*.*|RECURSE

    FileKey2=%Documents%|~*.doc|RECURSE

    ExcludeKey1=PATH|%AppData%\Microsoft\Word\STARTUP

    ExcludeKey2=FILE|%AppData%\Microsoft\Word|listgal.dat

  21. Gotcha and thanks on the Detect1 being enough....was not sure.

     

    ALSO, please change the ** to a single *. I use the ** to signal my private customizations and sometimes forget to change to * when I post here. Sorry! :wacko:

  22. New Entry for NETGEAR Router:

     

     

    [NETGEAR Genie (logs)**]

    LangSecRef=3024

    Detect1=HKLM\Software\NETGEAR Genie

    Detect2=HKLM\Software\Wow6432Node\NETGEAR Genie

    Default=False

    FileKey1=%LocalAppData%\NETGEARGenie\log\|*.log

  23. Modified Entry:

     

    Removed ExcludeKey1 and modified FileKey3.

     

    [Quicken Logs*]

    LangSecRef=3021

    Detect=HKLM\SOFTWARE\Intuit\Quicken

    Default=False

    FileKey1=%AppData%\Intuit\Quicken\Log|*.txt;*.log

    FileKey2=%CommonAppData%\Intuit\Quicken\Log|*.log

    FileKey3=%CommonAppData%\Intuit\Quicken\Log\installer|*.*|REMOVESELF

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.