SMalik
-
Posts
1,747 -
Joined
-
Last visited
Posts posted by SMalik
-
-
Revised entry
Added: RegKey4 - RegKey12
[Internet Explorer *]
LangSecRef=3001
Detect=HKCU\Software\Microsoft\Internet Explorer
FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Internet Explorer|*.log;*.txt|RECURSE
FileKey3=%LocalAppData%\Microsoft\Internet Explorer\CacheStorage|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE
FileKey5=%LocalAppData%\Microsoft\Windows\IECompat*Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Microsoft\Windows\INetCache|*.*|RECURSE
FileKey7=%LocalAppData%\Microsoft\Windows\INetCookies|*.*|RECURSE
FileKey8=%LocalAppData%\Microsoft\Windows\WebCache|*.*|RECURSE
FileKey9=%LocalAppData%\Microsoft\Windows\WebCache.old|*.*|REMOVESELF
FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\IECompat*Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\AC\IEDownloadHistory|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey16=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\Emie*List|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*|RECURSE
FileKey19=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*|RECURSE
FileKey20=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE
FileKey21=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE
FileKey22=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE
FileKey23=%SystemDrive%\Documents and Settings\LocalService*\Cookies|*.*|RECURSE
FileKey24=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\History|*.*|RECURSE
FileKey25=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey26=%SystemDrive%\Documents and Settings\NetworkService*\Cookies|*.*|RECURSE
FileKey27=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\History|*.*|RECURSE
FileKey28=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey29=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey30=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
FileKey31=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
FileKey32=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey33=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
FileKey34=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
FileKey35=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE
FileKey36=%WinDir%\System32\config\systemprofile\Cookies|*.*|RECURSE
FileKey37=%WinDir%\System32\config\systemprofile\History|*.*|RECURSE
FileKey38=%WinDir%\System32\config\systemprofile\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey39=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey40=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
FileKey41=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
FileKey42=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE
RegKey1=HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage
RegKey2=HKCU\SOFTWARE\Microsoft\Internet Explorer\DOMStorage
RegKey3=HKCU\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage
RegKey4=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
RegKey5=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_Cross_Domain_Redirect_Mitigation
RegKey6=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CrossDomain_Fix_KB867801
RegKey7=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_CLIPCHILDREN_OPTIMIZATION
RegKey8=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING
RegKey9=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
RegKey10=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER
RegKey11=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER
RegKey12=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION
RegKey13=HKCU\SOFTWARE\Microsoft\Internet Explorer\Recovery\PendingDelete
RegKey14=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
RegKey15=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU
RegKey16=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
RegKey17=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\TypedURLs -
Revised entry
Added *.jpg into FileKey9
[Mail and Calendar *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Comms\Unistore\data|AggregateCache.uca
FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState|*.etl;*.jpg;*.log
FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\AppData\Local\Office\*\WebServiceCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\Livecomm\*\dbStore\LogFiles|*.*
FileKey12=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory -
Revised entry
Added: HKCU\Software\Microsoft\Internet Explorer\DOMStorage
[Internet Explorer *]
LangSecRef=3001
Detect=HKCU\Software\Microsoft\Internet Explorer
FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Internet Explorer|*.log;*.txt|RECURSE
FileKey3=%LocalAppData%\Microsoft\Internet Explorer\CacheStorage|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE
FileKey5=%LocalAppData%\Microsoft\Windows\IECompat*Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Microsoft\Windows\INetCache|*.*|RECURSE
FileKey7=%LocalAppData%\Microsoft\Windows\INetCookies|*.*|RECURSE
FileKey8=%LocalAppData%\Microsoft\Windows\WebCache|*.*|RECURSE
FileKey9=%LocalAppData%\Microsoft\Windows\WebCache.old|*.*|REMOVESELF
FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\IECompat*Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\AC\IEDownloadHistory|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey16=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\Emie*List|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*|RECURSE
FileKey19=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*|RECURSE
FileKey20=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE
FileKey21=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE
FileKey22=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE
FileKey23=%SystemDrive%\Documents and Settings\LocalService*\Cookies|*.*|RECURSE
FileKey24=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\History|*.*|RECURSE
FileKey25=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey26=%SystemDrive%\Documents and Settings\NetworkService*\Cookies|*.*|RECURSE
FileKey27=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\History|*.*|RECURSE
FileKey28=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey29=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey30=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
FileKey31=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
FileKey32=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey33=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
FileKey34=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
FileKey35=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE
FileKey36=%WinDir%\System32\config\systemprofile\Cookies|*.*|RECURSE
FileKey37=%WinDir%\System32\config\systemprofile\History|*.*|RECURSE
FileKey38=%WinDir%\System32\config\systemprofile\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey39=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey40=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
FileKey41=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
FileKey42=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage
RegKey2=HKCU\Software\Microsoft\Internet Explorer\DOMStorage
RegKey3=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage
RegKey4=HKCU\Software\Microsoft\Internet Explorer\Recovery\PendingDelete
RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
RegKey6=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU
RegKey7=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
RegKey8=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\TypedURLs -
Revised entry
Added .tmp in FileKey23
[Windows Logs *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
FileKey1=%CommonAppData%\Microsoft\Diagnosis\DownloadedSettings|*.json.bk
FileKey2=%CommonAppData%\Microsoft\Diagnosis\ETLLogs|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\DiagnosticLogCSP|*.*|RECURSE
FileKey4=%CommonAppData%\Microsoft\Network\Downloader|*.*|RECURSE
FileKey5=%CommonAppData%\Microsoft\WDF|*.*|RECURSE
FileKey6=%CommonAppData%\Microsoft\Windows Security Health\Logs|*.*|RECURSE
FileKey7=%CommonAppData%\Microsoft\Windows\wfp|*.etl
FileKey8=%CommonAppData%\USOShared\Logs|*.*|RECURSE
FileKey9=%LocalAppData%\ConnectedDevicesPlatform|*.log
FileKey10=%LocalAppData%\Diagnostics|*.*|RECURSE
FileKey11=%LocalAppData%\Microsoft\Dialer|*.log.txt
FileKey12=%LocalAppData%\Microsoft\msipc\Logs|*.*
FileKey13=%LocalAppData%\Microsoft\Windows\Explorer|*.etl
FileKey14=%ProgramFiles%\UNP\*Logs|*.*
FileKey15=%SystemDrive%|DumpStack.log
FileKey16=%SystemDrive%\PerfLogs\System\Diagnostics|*.*|RECURSE
FileKey17=%SystemDrive%\PerfLogs\System\Performance|*.*|RECURSE
FileKey18=%WinDir%\AppCompat\Programs|*.txt;*.xml
FileKey19=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml
FileKey20=%WinDir%\debug\WIA|*.log
FileKey21=%WinDir%\INF|*.etl;*.log*
FileKey22=%WinDir%\Logs\CBS|*.cab
FileKey23=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log;*.tmp
FileKey24=%WinDir%\Panther\FastCleanup|*.log
FileKey25=%WinDir%\Panther\Rollback|*.txt
FileKey26=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml
FileKey27=%WinDir%\repair|setup.log
FileKey28=%WinDir%\security\logs|*.*|RECURSE
FileKey29=%WinDir%\ServiceProfiles\NetworkService\debug|*.log
FileKey30=%WinDir%\System32\CatRoot|*.tmp
FileKey31=%WinDir%\System32\CatRoot_bak|*.*|REMOVESELF
FileKey32=%WinDir%\System32\catroot2|*.chk;*.log;*.jrs;*.txt
FileKey33=%WinDir%\System32\LogFiles\HTTPERR|*.log
FileKey34=%WinDir%\System32\LogFiles\Scm|*.*|RECURSE
FileKey35=%WinDir%\System32\LogFiles\setupcln|*.*|RECURSE
FileKey36=%WinDir%\System32\LogFiles\Srt|*.*|RECURSE
FileKey37=%WinDir%\System32\LogFiles\WMI|*.*|RECURSE
FileKey38=%WinDir%\System32\LogFiles\WUDF|*.*
FileKey39=%WinDir%\System32\SleepStudy|*.etl
FileKey40=%WinDir%\System32\SleepStudy\ScreenOn|*.etl
FileKey41=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml;*.log
FileKey42=%WinDir%\System32\WDI\*|snapshot.etl|REMOVESELF
FileKey43=%WinDir%\System32\WDI\LogFiles\StartupInfo|*.*|RECURSE
RegKey1=HKLM\Software\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications
RegKey2=HKLM\Software\Microsoft\Tracing
RegKey3=HKLM\Software\Wow6432Node\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications
RegKey4=HKLM\Software\Wow6432Node\Microsoft\Tracing -
Revised entry
Added .cache files
FileKey13=%Public%\TechSmith\Snagit\License|*.cache;*.log[Snagit *]
LangSecRef=3021
Detect=HKCU\Software\TechSmith\Snagit
FileKey1=%CommonAppData%\TechSmith\Uploader|*.log
FileKey2=%Documents%|SnagitDebug.log
FileKey3=%Documents%\Snagit|*.snagx
FileKey4=%Documents%\Snagit\.metadata|*.*|RECURSE
FileKey5=%LocalAppData%\TechSmith\Logs|*.log
FileKey6=%LocalAppData%\TechSmith\Snagit|Tray.bin
FileKey7=%LocalAppData%\TechSmith\Snagit\*\NativeCrashReporting\Reports|*.dmp|RECURSE
FileKey8=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE
FileKey9=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico
FileKey10=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico
FileKey11=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE
FileKey12=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log;*.logtmp
FileKey13=%Public%\TechSmith\Snagit\License|*.cache;*.log
RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder
RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder
RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount
RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount
RegKey5=HKCU\Software\TechSmith\Snagit\11|OutputDirLastUsed
RegKey6=HKCU\Software\TechSmith\Snagit\11|VidOutputDirLastUsed
RegKey7=HKCU\Software\TechSmith\Snagit\11\SnagItEditor\Tray|Thumbnailsize
RegKey8=HKCU\Software\TechSmith\Snagit\12|CaptureCount
RegKey9=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount
RegKey10=HKCU\Software\TechSmith\Snagit\12|OutputDirLastUsed
RegKey11=HKCU\Software\TechSmith\Snagit\12|VidOutputDirLastUsed
RegKey12=HKCU\Software\TechSmith\Snagit\12\SnagItEditor\Tray|Thumbnailsize
RegKey13=HKCU\Software\TechSmith\Snagit\13|CaptureCount
RegKey14=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount
RegKey15=HKCU\Software\TechSmith\Snagit\13|OutputDirLastUsed
RegKey16=HKCU\Software\TechSmith\Snagit\13|VidOutputDirLastUsed
RegKey17=HKCU\Software\TechSmith\Snagit\13\Recent Captures
RegKey18=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List
RegKey19=HKCU\Software\TechSmith\Snagit\13\SnagItEditor\Tray|Thumbnailsize
RegKey20=HKCU\Software\TechSmith\Snagit\18|CaptureCount
RegKey21=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount
RegKey22=HKCU\Software\TechSmith\Snagit\18|OutputDirLastUsed
RegKey23=HKCU\Software\TechSmith\Snagit\18|VidOutputDirLastUsed
RegKey24=HKCU\Software\TechSmith\Snagit\18\Recent Captures
RegKey25=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List
RegKey26=HKCU\Software\TechSmith\Snagit\18\SnagItEditor\Tray|Thumbnailsize
RegKey27=HKCU\Software\TechSmith\Snagit\19|CaptureCount
RegKey28=HKCU\Software\TechSmith\Snagit\19|CaptureOpenCount
RegKey29=HKCU\Software\TechSmith\Snagit\19|OutputDirLastUsed
RegKey30=HKCU\Software\TechSmith\Snagit\19|VidOutputDirLastUsed
RegKey31=HKCU\Software\TechSmith\Snagit\19\Recent Captures
RegKey32=HKCU\Software\TechSmith\Snagit\19\SnagitEditor\Recent File List
RegKey33=HKCU\Software\TechSmith\Snagit\19\SnagItEditor\Tray|Thumbnailsize
RegKey34=HKCU\Software\TechSmith\Snagit\20|CaptureCount
RegKey35=HKCU\Software\TechSmith\Snagit\20|CaptureOpenCount
RegKey36=HKCU\Software\TechSmith\Snagit\20|OutputDirLastUsed
RegKey37=HKCU\Software\TechSmith\Snagit\20|VidOutputDirLastUsed
RegKey38=HKCU\Software\TechSmith\Snagit\20\Recent Captures
RegKey39=HKCU\Software\TechSmith\Snagit\20\SnagitEditor\Recent File List
RegKey40=HKCU\Software\TechSmith\Snagit\20\SnagItEditor\Tray|Thumbnailsize
RegKey41=HKCU\Software\TechSmith\Snagit\21|CaptureCount
RegKey42=HKCU\Software\TechSmith\Snagit\21|CaptureOpenCount
RegKey43=HKCU\Software\TechSmith\Snagit\21|OutputDirLastUsed
RegKey44=HKCU\Software\TechSmith\Snagit\21|VidOutputDirLastUsed
RegKey45=HKCU\Software\TechSmith\Snagit\21\Recent Captures
RegKey46=HKCU\Software\TechSmith\Snagit\21\SnagitEditor\Recent File List
RegKey47=HKCU\Software\TechSmith\Snagit\21\SnagItEditor\Tray|Thumbnailsize
RegKey48=HKCU\Software\TechSmith\Snagit\22|CaptureCount
RegKey49=HKCU\Software\TechSmith\Snagit\22|CaptureOpenCount
RegKey50=HKCU\Software\TechSmith\Snagit\22|OutputDirLastUsed
RegKey51=HKCU\Software\TechSmith\Snagit\22|VidOutputDirLastUsed
RegKey52=HKCU\Software\TechSmith\Snagit\22\Recent Captures
RegKey53=HKCU\Software\TechSmith\Snagit\22\SnagitEditor\Recent File List
RegKey54=HKCU\Software\TechSmith\Snagit\22\SnagItEditor\Tray|Thumbnailsize -
Snagit creates the MSI*.tmp- folders.
[Windows Installer *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Installer
FileKey1=%SystemDrive%\Config.msi|*.*|REMOVESELF
FileKey2=%WinDir%\Installer|*.tmp|RECURSE
FileKey3=%WinDir%\Installer|SourceHash{*};wix{*}.SchedServiceConfig.rmi
FileKey4=%WinDir%\Installer\Config.Msi|*.*|REMOVESELF
FileKey5=%WinDir%\Installer\MSI*.tmp-|*.*|REMOVESELF -
Revised entry
[GIMP *]
LangSecRef=3021
DetectFile=%LocalAppData%\GIMP
DetectFile1=%UserProfile%\.gimp-*
FileKey1=%LocalAppData%|recently-used.xbel
FileKey2=%LocalAppData%\webkit|*.*|REMOVESELF
FileKey3=%LocalAppData%\GIMP\*\CrashLog|*.*|RECURSE
FileKey4=%LocalAppData%\GIMP\*\tmp|*.*|RECURSE
FileKey5=%UserProfile%\.gegl-*|documents
FileKey6=%UserProfile%\.gimp-*|documents
FileKey7=%UserProfile%\.gimp-*\tmp|*.*|RECURSE
FileKey8=%UserProfile%\.thumbnails\normal|*.*|RECURSE -
18 hours ago, APMichael said:
???
This entry was never for Windows 10, it has always used "DetectOS=6.2|6.3", thus it will only show up on Windows 8 and Windows 8.1. A change should therefore not be necessary. By the way "DetectOS=10.0|" means Windows 10 and newer.
This entry is present on Windows 10. I deleted approx 8MB of junk using my custom entry for Store apps.
-
This entry is not working on Windows 10. Detect should be changed to DetectFile=%LocalAppData%\Packages\microsoft.windows.authhost.sso_8wekyb3d8bbwe and DetectOS=6.2|6.3 should be changed to DetectOS=10.0|.
[AuthHost *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windows.authhost.sso_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\PRICache|*.*
FileKey7=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\LocalState\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\LocalState\navigationHistory|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\TempState|*.*|RECURSE -
New entry
[Explorer Diagnostic Logs *]
LangSecRef=3025
Detect=HKCU\SOFTWARE\Microsoft\Windows
FileKey1=%LocalAppData%\Microsoft\Windows\Explorer|*.etl -
New Entry
[Microsoft Teams *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MicrosoftTeams_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\MicrosoftTeams_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\MicrosoftTeams_*\AC\Temp|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\MicrosoftTeams_*\LocalCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\MicrosoftTeams_*\TempState|*.*|RECURSE -
Revised Entries
Moved from [HP Support Assistant *] and added into [HP Logs *]: %SystemDrive%\system.sav\logs|*.*|RECURSE
[HP Logs *]
LangSecRef=3021
Detect=HKCU\Software\HP
DetectFile1=%AppData%\hpqlog
DetectFile2=%CommonAppData%\Hewlett-Packard
DetectFile3=%CommonAppData%\HP
DetectFile4=%LocalAppData%\Hewlett-Packard
DetectFile5=%LocalAppData%\TouchSmartData
DetectFile6=%ProgramFiles%\HPQ\Shared\Sierra Wireless
FileKey1=%AppData%\hp active health\app analytics\*logs|*.*|RECURSE
FileKey2=%AppData%\HP\*Logs|*Log.txt
FileKey3=%AppData%\hpqlog|*.log
FileKey4=%CommonAppData%|hpzinstall.log
FileKey5=%CommonAppData%\Hewlett-Packard|*.log*.*;*Log.txt|RECURSE
FileKey6=%CommonAppData%\Hewlett-Packard\HP*\Log*|*.*|RECURSE
FileKey7=%CommonAppData%\hp audio switch|*.log*
FileKey8=%CommonAppData%\HP\HP Touchpoint Analytics Client\Logs|*.*
FileKey9=%CommonAppData%\HP\HP Touchpoint Analytics Client\Monitor-History|*.*
FileKey10=%CommonAppData%\HP\HP Touchpoint Analytics Client\MRU|*.*
FileKey11=%CommonAppData%\HP\logs|*.*|RECURSE
FileKey12=%CommonAppData%\HP\StreamLog|*.*|RECURSE
FileKey13=%LocalAppData%\Hewlett-Packard\HP Support Framework\Profile\Upload|*.log
FileKey14=%LocalAppData%\TouchSmartData\Log|*.*
FileKey15=%ProgramFiles%\HPQ\Shared\Sierra Wireless|*.log|RECURSE
FileKey16=%SystemDrive%|dism.log
FileKey17=%SystemDrive%\hp\bin\logs|*.log
FileKey18=%SystemDrive%\system.sav\logs|*.*|RECURSE
FileKey19=%WinDir%\HP|Installer.log
Added: %LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE[HP Smart *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AD2F1837.HPPrinterControl_v10z8vjag6ke6
FileKey1=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE
FileKey4=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\*.HPPrinterControl_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\*.HPPrinterControl_*\TempState|*.*|RECURSE
[HP Support Assistant *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AD2F1837.HPSupportAssistant_v10z8vjag6ke6
FileKey1=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\TempState|*.*|RECURSE
I think [Intel Graphics Command Center *] entry name should be changed to [Intel Graphics Experience *][Intel Graphics Command Center *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AppUp.IntelGraphicsExperience_8j3eq9eme6ctt
FileKey1=%LocalAppData%\Intel\GCC|gcc*_log_*.txt
FileKey2=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\BackgroundTransferApi|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\INet*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState|gcc*_log_*.txt
FileKey8=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\Games2\cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\Intel\GCC|gcc*_log_*.txt
FileKey10=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\MetroLogs|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\Promotions|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\TempState|*.*|RECURSE
[Windows Client WebExperience *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\LocalCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\LocalState\EBWebview\*|LOG;LOG.old
FileKey6=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\TempState|*.*|RECURSE -
3 hours ago, SMalik said:
New Entry
[Foxit PDF Editor *]
[Foxit PDF Editor *]
LangSecRef=3021
Detect=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0
FileKey1=%AppData%\Foxit Software\Addon\Foxit PDF Editor\Install|*.*|RECURSE
FileKey2=%AppData%\Foxit Software\Foxit PDF Editor\Cache|*.*|RECURSE
FileKey3=%AppData%\Foxit Software\Foxit PDF Editor\FormFiller|AutoComplete.ds
FileKey4=%AppData%\Foxit Software\Foxit PDF Editor\StartPage\*\Start\en-US|index.html
FileKey5=%AppData%\Foxit Software\RMS|FXRMS_Log.txt
FileKey6=%CommonAppData%\Foxit Software\Foxit PDF Editor\Foxit Service\Log|*.*|RECURSE
FileKey7=%CommonAppData%\Foxit Software\Foxit PDF Editor\FoxitSensor\Log|*.*|RECURSE
FileKey8=%LocalLowAppData%\Foxit\Search|*.*|RECURSE
RegKey1=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0\CommentPanel\Filter
RegKey2=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\File MRU
RegKey3=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\Place MRU
RegKey4=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\plugins\JSPlugins
RegKey5=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\Preferences\History -
Revised Entry
Added: Detect1 and related FileKeys
[Wondershare UniConverter *]
LangSecRef=3023
Detect=HKLM\SOFTWARE\Wondershare\Wondershare UniConverter
Detect1=HKLM\SOFTWARE\Wondershare\Wondershare UniConverter 13
FileKey1=%CommonAppData%\Wondershare\ProductFeatures\*Logs|*.*|RECURSE
FileKey2=%CommonAppData%\Wondershare\UniConverter\DataTrack|tmp;*.bak;*.log
FileKey3=%CommonAppData%\Wondershare\UniConverter\TempThumbDir|*.*|RECURSE
FileKey4=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE
FileKey5=%CommonAppData%\Wondershare\UniConverter 13\DataTrack|tmp;*.bak;*.log
FileKey6=%CommonAppData%\Wondershare\UniConverter 13\TempThumbDir|*.*|RECURSE
FileKey7=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE
FileKey8=%ProgramFiles%\Wondershare\UniConverter\Log|*.*|RECURSE
FileKey9=%ProgramFiles%\Wondershare\Wondershare UniConverter 13 for Windows\Log|*.*|RECURSE
FileKey10=%Public%\Documents\Wondershare|*.*|REMOVESELF
FileKey11=%SystemDrive%|logWSVCUUpdateHelper.log
FileKey12=%SystemDrive%\Wondershare UniConverter\Downloaded\temp|*.*|REMOVESELF
FileKey13=%UserProfile%\.cache|*.*|REMOVESELF -
New Entry
[Foxit PDF Editor *]
LangSecRef=3021
Detect=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0
FileKey1=%LocalLowAppData%\Foxit\Search|*.*|RECURSE
FileKey2=%AppData%\Foxit Software\Addon\Foxit PDF Editor\Install|*.*|RECURSE
FileKey3=%AppData%\Foxit Software\Foxit PDF Editor\Cache|*.*|RECURSE
FileKey4=%AppData%\Foxit Software\Foxit PDF Editor\FormFiller|AutoComplete.ds
FileKey5=%AppData%\Foxit Software\Foxit PDF Editor\StartPage\*\Start\en-US|index.html
FileKey6=%AppData%\Foxit Software\RMS|FXRMS_Log.txt
RegKey1=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0\CommentPanel\Filter
RegKey2=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\Foxit PhantomPDF Advanced Editor\Recent File List
RegKey3=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\File MRU
RegKey4=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\Place MRU
RegKey5=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\plugins\JSPlugins
RegKey6=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\Preferences\History -
New Entry
[Stored Notification Settings *]
LangSecRef=3025
Detect=HKCU\SOFTWARE\Microsoft\Windows
RegKey1=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings -
New Entry
[HP Support Assistant *]
LangSecRef=3021
Detect=HKCU\SOFTWARE\HP
FileKey1=%SystemDrive%\system.sav\logs|*.*|RECURSE -
On 25/06/2021 at 17:04, SMalik said:
Revised Entry
Added:
DetectFile3
%SystemDrive%\system.sav|*.*|REMOVESELF[HP Installation Files *]
LangSecRef=3024
DetectFile1=%SystemDrive%\HP Universal Print Driver
DetectFile2=%SystemDrive%\swsetup
DetectFile3=%SystemDrive%\system.sav
FileKey1=%SystemDrive%\HP Universal Print Driver|*.*|REMOVESELF
FileKey2=%SystemDrive%\swsetup|*.*|REMOVESELF
FileKey3=%SystemDrive%\system.sav|*.*|REMOVESELFPlease do no change this entry. system.sav is part of HP Support Assistant program and it keeps logs there.
-
I think [HP Install Temps *] and [HP Installation Files *] entries should be merged.
-
Revised Entry
Added:
DetectFile3
%SystemDrive%\system.sav|*.*|REMOVESELF[HP Installation Files *]
LangSecRef=3024
DetectFile1=%SystemDrive%\HP Universal Print Driver
DetectFile2=%SystemDrive%\swsetup
DetectFile3=%SystemDrive%\system.sav
FileKey1=%SystemDrive%\HP Universal Print Driver|*.*|REMOVESELF
FileKey2=%SystemDrive%\swsetup|*.*|REMOVESELF
FileKey3=%SystemDrive%\system.sav|*.*|REMOVESELF -
New Entry
[Edge Website Redirecting Statistics *]
LangSecRef=3006
DetectFile=%LocalAppData%\Microsoft\Edge*
FileKey1=%LocalAppData%\Microsoft\Edge*\User Data\*|load_statistics.db;load_statistics.db-shm;load_statistics.db-wal -
Revised Entry
Subscriptions Activity History
Added: RegKey1[Content Delivery Manager *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Favicons|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\MobilityExperience\ImageCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\OneSettingsResponseCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\TargetedContentCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\TempState|*.*|RECURSE
RegKey1=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions -
Revised Entry
Added: UserActivity.json into FileKey9
[Weather *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log
FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp;UserActivity.json
FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory -
On 03/03/2021 at 03:34, APMichael said:
An entry for removing these empty "tw-*.tmp" folders has existed for quite some time: [System Profile Temp Folders *]
As soon as I posted about these empty folders, I realized there is already an entry for this. I requested one of the admins to delete the post. They deleted that post to which afterwards, I noticed your response. My apologies.
Winapp2.ini additions
in CCleaner
Posted
Is there a code to delete only the registry values?