Jump to content

SMalik

Experienced Members
  • Posts

    1,704
  • Joined

  • Last visited

Reputation

0 Neutral

Profile Information

  • Gender
    Male
  • Location
    United States

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. New Entry [HP Support Assistant *] LangSecRef=3021 Detect=HKCU\SOFTWARE\HP FileKey1=%SystemDrive%\system.sav\logs|*.*|RECURSE
  2. Please do no change this entry. system.sav is part of HP Support Assistant program and it keeps logs there.
  3. I think [HP Install Temps *] and [HP Installation Files *] entries should be merged.
  4. Revised Entry Added: DetectFile3 %SystemDrive%\system.sav|*.*|REMOVESELF [HP Installation Files *] LangSecRef=3024 DetectFile1=%SystemDrive%\HP Universal Print Driver DetectFile2=%SystemDrive%\swsetup DetectFile3=%SystemDrive%\system.sav FileKey1=%SystemDrive%\HP Universal Print Driver|*.*|REMOVESELF FileKey2=%SystemDrive%\swsetup|*.*|REMOVESELF FileKey3=%SystemDrive%\system.sav|*.*|REMOVESELF
  5. New Entry [Edge Website Redirecting Statistics *] LangSecRef=3006 DetectFile=%LocalAppData%\Microsoft\Edge* FileKey1=%LocalAppData%\Microsoft\Edge*\User Data\*|load_statistics.db;load_statistics.db-shm;load_statistics.db-wal
  6. Revised Entry Subscriptions Activity History Added: RegKey1 [Content Delivery Manager *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalCache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Favicons|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\MobilityExperience\ImageCache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\OneSettingsResponseCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\TargetedContentCache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\TempState|*.*|RECURSE RegKey1=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions
  7. Revised Entry Added: UserActivity.json into FileKey9 [Weather *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp;UserActivity.json FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory
  8. As soon as I posted about these empty folders, I realized there is already an entry for this. I requested one of the admins to delete the post. They deleted that post to which afterwards, I noticed your response. My apologies.
  9. New Entries [Taskbar Favorites Statistics *] DetectOS=10.0| LangSecRef=3025 Detect=HKCU\SOFTWARE\Microsoft\Windows RegKey1=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Taskband|FavoritesChanges [Windows Media Player *] LangSecRef=3025 Detect=HKCU\SOFTWARE\Microsoft\MediaPlayer RegKey1=HKCU\SOFTWARE\Microsoft\MediaPlayer\Preferences|MostRecentFileAddOrRemove
  10. Revised Entry Removed FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Caches|*.*|RECURSE because this location does not exist. This is the correct location %WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Caches|*.*|RECURSE, but I think this should be excluded. [Windows Start Cache *] DetectOS=10.0| Section=Dangerous Windows Detect=HKCU\Software\Microsoft\Windows Warning=Use only in Windows Safe Mode. FileKey1=%CommonAppData%\Microsoft\Windows\Caches|*.*|RECURSE FileKey2=%LocalAppData%\Microsoft\Windows\Caches|*.*|RECURSE
  11. New Entry [Edge Stored Favicons *] LangSecRef=3006 DetectFile=%LocalAppData%\Microsoft\Edge* FileKey1=%LocalAppData%\Microsoft\Edge*\User Data\*\|Favicons
  12. I think we should go through all of the entries and see if any LangSecRef need to be corrected.
  13. Revised Entry Changed: LangSecRef from 3023 to 3021 [Mp3tag *] LangSecRef=3021 Detect=HKLM\Software\Florian Heidenreich\Mp3tag FileKey1=%AppData%\Mp3tag|Mp3tagError.log
  14. We can add the rest of the files.
  15. Revised Entry Removed: Detect2, Detect3, Detect4, Detect5 Added: Detect2=HKCU\Software\Nero %AppData%\Nero\Nero Start\cefcache.1\Cache|*.*|RECURSE %AppData%\Nero\Nero Start\cefcache.1\Code Cache|*.*|RECURSE %AppData%\Nero\Nero Start\cefcache.1\GPUCache|*.*|RECURSE %AppData%\Nero\Nero Start\cefcache.1\IndexedDB|*.*|RECURSE %AppData%\Nero\Nero Start\cefcache.1\Local Storage\leveldb|*.log;*.old;MANIFEST-000001 %AppData%\Nero\Nero Start\cefcache.1\Session Storage|*.log;*.old;MANIFEST-000001 %AppData%\Nero\Nero Start\cefcache.1|*.log;*.old;Cookies;Cookies-journal;MANIFEST-000001;QuotaManager;QuotaManager-journal;Visited Links %AppData%\Nero\Nero Start\logs|*.*|RECURSE %AppData%\Nero\Nero Start\temp|*.*|RECURSE %LocalAppData%\Nero\NeroKnowHowPLUS\*|*.cache %LocalAppData%\Nero\NeroKnowHowPLUS|*.log [Nero *] LangSecRef=3021 Detect1=HKCU\Software\Ahead Detect2=HKCU\Software\Nero FileKey1=%AppData%\Nero|NeroHistory.log FileKey2=%AppData%\Nero\Nero Burning ROM|*.log FileKey3=%AppData%\Nero\Nero*\Nero BackItUp\Cache|*.* FileKey4=%AppData%\Nero\Nero*\Nero Burning ROM|*.log FileKey5=%AppData%\Nero\Nero*\Nero Recode\AnalysisData|*.dat FileKey6=%AppData%\Nero\Nero*\Nero Recode\Thumbs|*.* FileKey7=%AppData%\Nero\Nero*\Nero Vision|*.txt;*.bin FileKey8=%AppData%\Nero\Nero*\Nero Vision\NVFACache|*.* FileKey9=%AppData%\Nero\Nero*\Nero3D|*.log FileKey10=%AppData%\Nero\Nero Start\cefcache.1\Cache|*.*|RECURSE FileKey11=%AppData%\Nero\Nero Start\cefcache.1\Code Cache|*.*|RECURSE FileKey12=%AppData%\Nero\Nero Start\cefcache.1\GPUCache|*.*|RECURSE FileKey13=%AppData%\Nero\Nero Start\cefcache.1\IndexedDB|*.*|RECURSE FileKey14=%AppData%\Nero\Nero Start\cefcache.1\Local Storage\leveldb|*.log;*.old;MANIFEST-000001 FileKey15=%AppData%\Nero\Nero Start\cefcache.1\Session Storage|*.log;*.old;MANIFEST-000001 FileKey16=%AppData%\Nero\Nero Start\cefcache.1|*.log;*.old;Cookies;Cookies-journal;MANIFEST-000001;QuotaManager;QuotaManager-journal;Visited Links FileKey17=%AppData%\Nero\Nero Start\logs|*.*|RECURSE FileKey18=%AppData%\Nero\Nero Start\temp|*.*|RECURSE FileKey19=%CommonAppData%\Nero\Nero BackItUp*\Cache|*.* FileKey20=%CommonAppData%\Nero\PeakFiles|*.tmp FileKey21=%LocalAppData%\Nero\Nero *\Nero Vision\Cache|*.* FileKey22=%LocalAppData%\Nero\Nero *\Nero Vision\Cache\GraphicObjectCache|*.* FileKey23=%LocalAppData%\Nero\NeroKnowHowPLUS\*|*.cache FileKey24=%LocalAppData%\Nero\NeroKnowHowPLUS|*.log RegKey1=HKCU\Software\ahead\Nero PhotoSnap\Recent File List RegKey2=HKCU\Software\Ahead\NeroSearch\NeroSavedSearches\SavedSearches RegKey3=HKCU\Software\ahead\NeroVision\2.0\RecentFiles RegKey4=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumeLabelAutoTemplate RegKey5=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumeLabelISOTemplate RegKey6=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumelabelJolietTemplate RegKey7=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumeLabelUDFTemplate RegKey8=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Recent File List RegKey9=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|EncodingLastDir RegKey10=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|NeroCompilation RegKey11=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|TrackSaveDir RegKey12=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|WorkingDir RegKey13=HKCU\Software\Nero\Nero 11\Nero CoverDesigner\Recent File List RegKey14=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumeLabelAutoTemplate RegKey15=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumeLabelISOTemplate RegKey16=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumelabelJolietTemplate RegKey17=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumeLabelUDFTemplate RegKey18=HKCU\Software\Nero\Nero 11\Nero Express\General|OFDLastAudioDir RegKey19=HKCU\Software\Nero\Nero 11\Nero Express\General|OFDLastISODir RegKey20=HKCU\Software\Nero\Nero 11\Nero Express\General|OFDLastVideoDVDKey RegKey21=HKCU\Software\Nero\Nero 11\Nero Express\Recent File List RegKey22=HKCU\Software\Nero\Nero 11\Nero Express\Settings|BootImageDir RegKey23=HKCU\Software\Nero\Nero 11\Nero Express\Settings|BrowserDir RegKey24=HKCU\Software\Nero\Nero 11\Nero Express\Settings|ImageDir RegKey25=HKCU\Software\Nero\Nero 11\Nero Express\Settings|NeroCompilation RegKey26=HKCU\Software\Nero\Nero 11\Nero Express\Settings|TrackSaveDir RegKey27=HKCU\Software\Nero\Nero 11\Nero Express\Settings|WorkingDir RegKey28=HKCU\Software\Nero\Nero 11\Nero Toolkit\DiscSpeed\Capture|Folder RegKey29=HKCU\Software\Nero\Nero 11\Nero Toolkit\DiscSpeed\Save|Folder RegKey30=HKCU\Software\Nero\Nero 11\Nero Vision\Application|AudioDir RegKey31=HKCU\Software\Nero\Nero 11\Nero Vision\Application|CaptureDir RegKey32=HKCU\Software\Nero\Nero 11\Nero Vision\Application|DocDir RegKey33=HKCU\Software\Nero\Nero 11\Nero Vision\Application|ExportAudioDir RegKey34=HKCU\Software\Nero\Nero 11\Nero Vision\Application|ExportVideoDir RegKey35=HKCU\Software\Nero\Nero 11\Nero Vision\Application|ImportVideoDir RegKey36=HKCU\Software\Nero\Nero 11\Nero Vision\Application|MediaDir RegKey37=HKCU\Software\Nero\Nero 11\Nero Vision\Application|PicDir RegKey38=HKCU\Software\Nero\Nero 11\Nero Vision\Application|PicSaveDir RegKey39=HKCU\Software\Nero\Nero 11\Nero Vision\Application|TmpDir RegKey40=HKCU\Software\Nero\Nero 11\Nero Vision\Application|VideoDir RegKey41=HKCU\Software\Nero\Nero 11\Nero WaveEditor\Directories|Last RegKey42=HKCU\Software\Nero\Nero 11\Nero WaveEditor\Recent File List RegKey43=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumeLabelAutoTemplate RegKey44=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumeLabelISOTemplate RegKey45=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumelabelJolietTemplate RegKey46=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumeLabelUDFTemplate RegKey47=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|EncodingLastDir RegKey48=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|TrackSaveDir RegKey49=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|WorkingDir RegKey50=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumeLabelAutoTemplate RegKey51=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumeLabelISOTemplate RegKey52=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumelabelJolietTemplate RegKey53=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumeLabelUDFTemplate RegKey54=HKCU\Software\Nero\Nero 12\Nero Express\Settings|BootImageDir RegKey55=HKCU\Software\Nero\Nero 12\Nero Express\Settings|ImageDir RegKey56=HKCU\Software\Nero\Nero 12\Nero Express\Settings|NeroCompilation RegKey57=HKCU\Software\Nero\Nero 12\Nero Express\Settings|TrackSaveDir RegKey58=HKCU\Software\Nero\Nero 12\Nero Toolkit\DiscSpeed\Capture|Folder RegKey59=HKCU\Software\Nero\Nero 12\Nero Toolkit\DiscSpeed\Save|Folder RegKey60=HKCU\Software\Nero\Nero 12\Nero Vision\Application|AudioDir RegKey61=HKCU\Software\Nero\Nero 12\Nero Vision\Application|CaptureDir RegKey62=HKCU\Software\Nero\Nero 12\Nero Vision\Application|DocDir RegKey63=HKCU\Software\Nero\Nero 12\Nero Vision\Application|ExportAudioDir RegKey64=HKCU\Software\Nero\Nero 12\Nero Vision\Application|ExportVideoDir RegKey65=HKCU\Software\Nero\Nero 12\Nero Vision\Application|ImportVideoDir RegKey66=HKCU\Software\Nero\Nero 12\Nero Vision\Application|MediaDir RegKey67=HKCU\Software\Nero\Nero 12\Nero Vision\Application|PicDir RegKey68=HKCU\Software\Nero\Nero 12\Nero Vision\Application|PicSaveDir RegKey69=HKCU\Software\Nero\Nero 12\Nero Vision\Application|TmpDir RegKey70=HKCU\Software\Nero\Nero 12\Nero Vision\Application|VideoDir RegKey71=HKCU\Software\Nero\Nero 12\Nero WaveEditor\Directories|Last RegKey72=HKCU\Software\Nero\Nero Blu-ray Player\Settings|DefFolder RegKey73=HKCU\Software\Nero\Nero8\Cover Designer\Recent File List RegKey74=HKCU\Software\Nero\Nero8\Nero - Burning Rom\Recent File List
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.