Jump to content

SMalik

Experienced Members
  • Posts

    1,747
  • Joined

  • Last visited

Everything posted by SMalik

  1. Just updated to v5.52 and this issue still exists. It shuts down when Analyzing or Running Cleaner.
  2. New Entry System should be restarted after wiping these caches. Works well in Windows Safe Mode. [Windows Start Cache *] DetectOS=10.0| LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%LocalAppData%\Microsoft\Windows\Caches|*.*|RECURSE FileKey2=%CommonAppData%\Microsoft\Windows\Caches|*.*|RECURSE FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Caches|*.*|RECURSE
  3. Let's bring this entry back. The Security Token Service provides brokered authentication for web services. Previously there was an issue when removing Token Broker Cache files on a Windows Insider Preview build. It was removing Windows Insider account login info. The issue was fixed in the later insider preview build. [Security Service Token Cache *] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%LocalAppData%\Microsoft\TokenBroker\Cache|*.*|RECURSE
  4. Revised Entry I think we should change the Detect from HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\WindowsUpdate to HKCU\Software\Microsoft\Windows [Windows Update *] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%WinDir%\Logs\waasmedic|*.*|RECURSE FileKey2=%WinDir%\Logs\WindowsUpdate|*.*|RECURSE FileKey3=%WinDir%\SoftwareDistribution\DataStore\Logs|*.*|RECURSE
  5. User names and passwords that you log on to websites or other computers on a network. It is completely safe.
  6. Here is an entry that I use. It wipes locally stored user names and passwords. I think we should add it, maybe with a warning. [Credentials *] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%LocalAppData%\Microsoft\Credentials|*.*|RECURSE FileKey2=%AppData%\Microsoft\Credentials|*.*|RECURSE FileKey3=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Credentials|*.*|RECURSE FileKey4=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Credentials|*.*|RECURSE
  7. Revised Entry Added: %AppData%\Foxit Software\Foxit PhantomPDF\StartPage\*\Start\en-US|index.html [Foxit PhantomPDF *] LangSecRef=3021 Detect1=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0 Detect2=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0 Detect3=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0 Detect4=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0 Default=False FileKey1=%AppData%\Foxit Software\Foxit PDF Creator\Creator-Log|*.*|RECURSE FileKey2=%AppData%\Foxit Software\Foxit PhantomPDF\FormFiller|AutoComplete.ds FileKey3=%AppData%\Foxit Software\Foxit PhantomPDF\StartPage\*\Start\en-US|index.html FileKey4=%AppData%\Foxit Software\RMS|FXRMS_Log.txt FileKey5=%LocalAppData%\Foxit PhantomPDF\msilog|*.log FileKey6=%WinDir%\System32\config\systemprofile\AppData\Roaming\Foxit Software\Foxit PDF Creator|*__foxittemp.xml|RECURSE RegKey1=HKCU\Software\Foxit Software Company\Foxit PDF Editor|Recent File List RegKey2=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0\Preferences\History RegKey3=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0\RecentFiles RegKey4=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\MRU\File MRU RegKey5=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\MRU\Place MRU RegKey6=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\plugins\JSPlugins RegKey7=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\Preferences\History RegKey8=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\Recent File List RegKey9=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\CommentPanel\Filter RegKey10=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Foxit PhantomPDF Advanced Editor\Recent File List RegKey11=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\MRU\File MRU RegKey12=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\MRU\Place MRU RegKey13=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\plugins\JSPlugins RegKey14=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Preferences\History RegKey15=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Recent File List RegKey16=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\CommentPanel\Filter RegKey17=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\Foxit PhantomPDF Advanced Editor\Recent File List RegKey18=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\MRU\File MRU RegKey19=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\MRU\Place MRU RegKey20=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\plugins\JSPlugins RegKey21=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\Preferences\History RegKey22=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\Recent File List
  8. Revised Entry Added: RegKey1 & RegKey2 [Snip & Sketch *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ScreenSketch_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\AC\Temp|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\LocalCache|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\LocalState\Cache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ScreenSketch_8wekyb3d8bbwe\PersistedPickerData\Microsoft.ScreenSketch_8wekyb3d8bbwe!App\AppSnipAndSketchFileSaveSettings|LastLocation RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ScreenSketch_8wekyb3d8bbwe\PersistedPickerData\Microsoft.ScreenSketch_8wekyb3d8bbwe!App\DefaultOpenFileSingle|LastLocation
  9. New Entry [Delivery Optimization Service *] DetectOS=10.0| LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache|*.*|RECURSE FileKey2=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs|*.*|RECURSE
  10. [Notifications *] entry works on all OS. [Push Notifications *] is for Windows 10 only, other OS don’t need it.
  11. Here are my suggestions. [Notifications *] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Security and Maintenance\Providers\EventLog [Push Notifications *] DetectOS=10.0| LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%LocalAppData%\Microsoft\Windows\Notifications|*.db;*.db-shm;*.db-wal;*.tmp FileKey2=%LocalAppData%\Microsoft\Windows\Notifications\wpnidm|*.*|RECURSE RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications\wpnidm RegKey3=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup RegKey4=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\PushNotifications\wpnidm
  12. You're wrong on this one. "%LocalAppData%\Microsoft\Windows\ActionCenterCache" has nothing to do with Push Notifications. This should go with [Action Center *] and [Security and Maintenance *] entries. Open Event Viewer Go to Applications and Services Logs> Microsoft> Windows> PushNotifications-Platform> Operational, and check the logs.
  13. Push Notifications belong to Microsoft Store apps. Action Center Notifications are different. We should have this "%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE" in [Action Center *] and [Security and Maintenance *] entries. It should not be in the [Push Notifications *] entry.
  14. New Entries [3DViewer *] DetectOS=10.0 LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\LocalCache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\LocalState\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\TempState|*.*|RECURSE [Alarms *] DetectOS=10.0 LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsAlarms_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.WindowsAlarms_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.WindowsAlarms_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.WindowsAlarms_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.WindowsAlarms_*\LocalCache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.WindowsAlarms_*\LocalState\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.WindowsAlarms_*\TempState|*.*|RECURSE [Calculator *] DetectOS=10.0 LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsCalculator_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.WindowsCalculator_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.WindowsCalculator_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.WindowsCalculator_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.WindowsCalculator_*\LocalCache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.WindowsCalculator_*\LocalState\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.WindowsCalculator_*\TempState|*.*|RECURSE [Get Help *] DetectOS=10.0 LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.GetHelp_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.GetHelp_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.GetHelp_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.GetHelp_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.GetHelp_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.GetHelp_*\AC\Temp|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.GetHelp_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.GetHelp_*\LocalCache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.GetHelp_*\LocalState\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.GetHelp_*\TempState|*.*|RECURSE [Mixed Reality Portal *] DetectOS=10.0 LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MixedReality.Portal_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.MixedReality.Portal_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.MixedReality.Portal_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.MixedReality.Portal_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.MixedReality.Portal_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.MixedReality.Portal_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.MixedReality.Portal_*\LocalCache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.MixedReality.Portal_*\LocalState\Cache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.MixedReality.Portal_*\TempState|*.*|RECURSE
  15. Revised Entries Changed the name from [Sound Recorder *] to [Voice Recorder *] [Voice Recorder *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalCache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalState\Cache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\TempState|*.*|RECURSE Changed FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalCache\PlayReady\Cache|*.*|RECURSE with FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalCache\PlayReady|*.*|RECURSE [Groove Music *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\PRICache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalCache\PlayReady|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\Database\*|*.log FileKey11=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageCache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageRetrievalFailure|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageStore|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\navigationHistory|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\PlayReady|*.*|RECURSE FileKey16=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\SearchHistory Changed FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalCache\PlayReady\Cache|*.*|RECURSE with FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalCache\PlayReady|*.*|RECURSE [Movies & TV *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe* Default=False FileKey1=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\PRICache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalCache\PlayReady|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Database\anonymous|*.log FileKey11=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageCache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageRetrievalFailure|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageStore|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\navigationHistory|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\PlayReady|*.*|RECURSE FileKey16=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe\SearchHistory\SearchHistory
  16. Revised Entry Changed name from [Notifications *] to [Push Notifications *] Added *.db, *.db-shm and *.db-wal file extensions in FileKey1 [Push Notifications *] DetectOS=10.0| LangSecRef=3025 Default=False FileKey1=%LocalAppData%\Microsoft\Windows\Notifications|*.db; *.db-shm;*.db-wal;*.tmp FileKey2=%LocalAppData%\Microsoft\Windows\Notifications\wpnidm|*.*|RECURSE RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications\wpnidm RegKey3=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup RegKey4=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\PushNotifications\wpnidm
  17. @APMichael Have you seen my two posts above with images? I want to delete the images.
  18. Then I think we should change its name to Push Notifications. By the way, whenever I delete wpndatabase.db file, LiveTile stop working on Microsoft Store apps, but I think we should add this back in the entry since it holds sensitive stuff.
  19. You're right. The [Notifications *] entry has nothing to do with notifications. This entry should be removed completely. I just opened %LocalAppData%\Microsoft\Windows\Notifications\wpnidm, and it has .jpg files that belongs to Microsoft Store apps. Then, I opened wpndatabase.db from %LocalAppData%\Microsoft\Windows\Notifications\wpnidm, and it has information about Microsoft Store apps. I then opened HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications\wpnidm, and it has information about the Microsoft Store apps that are listed in wpndatabase.db
  20. Revised Entry It is safe to delete all files from the Backup folder. These are just cached files. ShareX uses original .json files from "%Documents%\ShareX". Changed DetectFile from "%Documents%\ShareX" to "%ProgramFiles%\ShareX" because ShareX Microsoft Store app also uses "%Documents%\ShareX" location to store files. [ShareX *] LangSecRef=3021 DetectFile=%ProgramFiles%\ShareX Default=False FileKey1=%Documents%\ShareX\Backup|*.*|RECURSE FileKey2=%Documents%\ShareX|History.xml FileKey3=%Documents%\ShareX\Logs|*.*|RECURSE New Entry [ShareX App *] DetectOS=10.0 LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\19568ShareX.ShareX_egrzcvs15399j Default=False FileKey1=%Documents%\ShareX\Backup|*.*|RECURSE FileKey2=%Documents%\ShareX|History.xml FileKey3=%Documents%\ShareX\Logs|*.*|RECURSE FileKey4=%LocalAppData%\Packages\19568ShareX.ShareX_*\AC\INet*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\19568ShareX.ShareX_*\AC\Temp|*.*|RECURSE FileKey6=%LocalAppData%\Packages\19568ShareX.ShareX_*\LocalCache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\19568ShareX.ShareX_*\LocalState\Cache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\19568ShareX.ShareX_*\TempState|*.*|RECURSE
  21. Revised Entry Added: %LocalAppData%\Packages\Microsoft.MSPaint_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE [Paint 3D *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MSPaint_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.MSPaint_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\Temp|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.MSPaint_*\LocalCache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.MSPaint_*\LocalState|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.MSPaint_*\TempState|*.*|RECURSE
  22. @APMichael Regarding the [Sharing MFU *] entry, I have checked a few Windows 10 systems and "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SharingMFU" is not present in the registry.
  23. @APMichael Lets restrict [Action Center *] to Windows 7 and make another entry with the proper name, which is Security and Maintenance. Move "%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE" and "HKCU\Software\Microsoft\Windows\CurrentVersion\Security and Maintenance\Providers\EventLog" to this entry from the [Action Center *].
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.