Jump to content

SMalik

Experienced Members
  • Posts

    1,705
  • Joined

  • Last visited

Reputation

0 Neutral

Profile Information

  • Gender
    Male
  • Location
    United States

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. New Entry [Stored Notification Settings *] LangSecRef=3025 Detect=HKCU\SOFTWARE\Microsoft\Windows RegKey1=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings
  2. New Entry [HP Support Assistant *] LangSecRef=3021 Detect=HKCU\SOFTWARE\HP FileKey1=%SystemDrive%\system.sav\logs|*.*|RECURSE
  3. Please do no change this entry. system.sav is part of HP Support Assistant program and it keeps logs there.
  4. I think [HP Install Temps *] and [HP Installation Files *] entries should be merged.
  5. Revised Entry Added: DetectFile3 %SystemDrive%\system.sav|*.*|REMOVESELF [HP Installation Files *] LangSecRef=3024 DetectFile1=%SystemDrive%\HP Universal Print Driver DetectFile2=%SystemDrive%\swsetup DetectFile3=%SystemDrive%\system.sav FileKey1=%SystemDrive%\HP Universal Print Driver|*.*|REMOVESELF FileKey2=%SystemDrive%\swsetup|*.*|REMOVESELF FileKey3=%SystemDrive%\system.sav|*.*|REMOVESELF
  6. New Entry [Edge Website Redirecting Statistics *] LangSecRef=3006 DetectFile=%LocalAppData%\Microsoft\Edge* FileKey1=%LocalAppData%\Microsoft\Edge*\User Data\*|load_statistics.db;load_statistics.db-shm;load_statistics.db-wal
  7. Revised Entry Subscriptions Activity History Added: RegKey1 [Content Delivery Manager *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalCache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Favicons|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\MobilityExperience\ImageCache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\OneSettingsResponseCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\TargetedContentCache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\TempState|*.*|RECURSE RegKey1=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions
  8. Revised Entry Added: UserActivity.json into FileKey9 [Weather *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp;UserActivity.json FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory
  9. As soon as I posted about these empty folders, I realized there is already an entry for this. I requested one of the admins to delete the post. They deleted that post to which afterwards, I noticed your response. My apologies.
  10. New Entries [Taskbar Favorites Statistics *] DetectOS=10.0| LangSecRef=3025 Detect=HKCU\SOFTWARE\Microsoft\Windows RegKey1=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Taskband|FavoritesChanges [Windows Media Player *] LangSecRef=3025 Detect=HKCU\SOFTWARE\Microsoft\MediaPlayer RegKey1=HKCU\SOFTWARE\Microsoft\MediaPlayer\Preferences|MostRecentFileAddOrRemove
  11. Revised Entry Removed FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Caches|*.*|RECURSE because this location does not exist. This is the correct location %WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Caches|*.*|RECURSE, but I think this should be excluded. [Windows Start Cache *] DetectOS=10.0| Section=Dangerous Windows Detect=HKCU\Software\Microsoft\Windows Warning=Use only in Windows Safe Mode. FileKey1=%CommonAppData%\Microsoft\Windows\Caches|*.*|RECURSE FileKey2=%LocalAppData%\Microsoft\Windows\Caches|*.*|RECURSE
  12. New Entry [Edge Stored Favicons *] LangSecRef=3006 DetectFile=%LocalAppData%\Microsoft\Edge* FileKey1=%LocalAppData%\Microsoft\Edge*\User Data\*\|Favicons
  13. I think we should go through all of the entries and see if any LangSecRef need to be corrected.
  14. Revised Entry Changed: LangSecRef from 3023 to 3021 [Mp3tag *] LangSecRef=3021 Detect=HKLM\Software\Florian Heidenreich\Mp3tag FileKey1=%AppData%\Mp3tag|Mp3tagError.log
  15. We can add the rest of the files.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.