Jump to content

SMalik

Experienced Members
  • Posts

    1,747
  • Joined

  • Last visited

Posts posted by SMalik

  1. Revised entry

    Added: RegKey4 - RegKey12

    [Internet Explorer *]
    LangSecRef=3001
    Detect=HKCU\Software\Microsoft\Internet Explorer
    FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE
    FileKey2=%LocalAppData%\Microsoft\Internet Explorer|*.log;*.txt|RECURSE
    FileKey3=%LocalAppData%\Microsoft\Internet Explorer\CacheStorage|*.*|RECURSE
    FileKey4=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE
    FileKey5=%LocalAppData%\Microsoft\Windows\IECompat*Cache|*.*|RECURSE
    FileKey6=%LocalAppData%\Microsoft\Windows\INetCache|*.*|RECURSE
    FileKey7=%LocalAppData%\Microsoft\Windows\INetCookies|*.*|RECURSE
    FileKey8=%LocalAppData%\Microsoft\Windows\WebCache|*.*|RECURSE
    FileKey9=%LocalAppData%\Microsoft\Windows\WebCache.old|*.*|REMOVESELF
    FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE
    FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\IECompat*Cache|*.*|RECURSE
    FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\AC\IEDownloadHistory|*.*|RECURSE
    FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE
    FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
    FileKey15=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.*
    FileKey16=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey17=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\Emie*List|*.*|RECURSE
    FileKey18=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*|RECURSE
    FileKey19=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*|RECURSE
    FileKey20=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE
    FileKey21=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE
    FileKey22=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE
    FileKey23=%SystemDrive%\Documents and Settings\LocalService*\Cookies|*.*|RECURSE
    FileKey24=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\History|*.*|RECURSE
    FileKey25=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\Temporary Internet Files|*.*|RECURSE
    FileKey26=%SystemDrive%\Documents and Settings\NetworkService*\Cookies|*.*|RECURSE
    FileKey27=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\History|*.*|RECURSE
    FileKey28=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\Temporary Internet Files|*.*|RECURSE
    FileKey29=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
    FileKey30=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
    FileKey31=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
    FileKey32=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
    FileKey33=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
    FileKey34=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
    FileKey35=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE
    FileKey36=%WinDir%\System32\config\systemprofile\Cookies|*.*|RECURSE
    FileKey37=%WinDir%\System32\config\systemprofile\History|*.*|RECURSE
    FileKey38=%WinDir%\System32\config\systemprofile\Local Settings\Temporary Internet Files|*.*|RECURSE
    FileKey39=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
    FileKey40=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
    FileKey41=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
    FileKey42=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE
    RegKey1=HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage
    RegKey2=HKCU\SOFTWARE\Microsoft\Internet Explorer\DOMStorage
    RegKey3=HKCU\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage
    RegKey4=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
    RegKey5=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_Cross_Domain_Redirect_Mitigation
    RegKey6=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CrossDomain_Fix_KB867801
    RegKey7=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_CLIPCHILDREN_OPTIMIZATION
    RegKey8=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING
    RegKey9=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
    RegKey10=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER
    RegKey11=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER
    RegKey12=HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION
    RegKey13=HKCU\SOFTWARE\Microsoft\Internet Explorer\Recovery\PendingDelete
    RegKey14=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
    RegKey15=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU
    RegKey16=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
    RegKey17=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\TypedURLs

  2. Revised entry

    Added *.jpg into FileKey9

    [Mail and Calendar *]
    DetectOS=10.0|
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
    FileKey1=%LocalAppData%\Comms\Unistore\data|AggregateCache.uca
    FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INet*|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*|RECURSE
    FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\TokenBroker\Cache|*.*|RECURSE
    FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalCache|*.*|RECURSE
    FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState|*.etl;*.jpg;*.log
    FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\AppData\Local\Office\*\WebServiceCache|*.*|RECURSE
    FileKey11=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\Livecomm\*\dbStore\LogFiles|*.*
    FileKey12=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE
    RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory

  3. Revised entry

    Added: HKCU\Software\Microsoft\Internet Explorer\DOMStorage

    [Internet Explorer *]
    LangSecRef=3001
    Detect=HKCU\Software\Microsoft\Internet Explorer
    FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE
    FileKey2=%LocalAppData%\Microsoft\Internet Explorer|*.log;*.txt|RECURSE
    FileKey3=%LocalAppData%\Microsoft\Internet Explorer\CacheStorage|*.*|RECURSE
    FileKey4=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE
    FileKey5=%LocalAppData%\Microsoft\Windows\IECompat*Cache|*.*|RECURSE
    FileKey6=%LocalAppData%\Microsoft\Windows\INetCache|*.*|RECURSE
    FileKey7=%LocalAppData%\Microsoft\Windows\INetCookies|*.*|RECURSE
    FileKey8=%LocalAppData%\Microsoft\Windows\WebCache|*.*|RECURSE
    FileKey9=%LocalAppData%\Microsoft\Windows\WebCache.old|*.*|REMOVESELF
    FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE
    FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\IECompat*Cache|*.*|RECURSE
    FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\AC\IEDownloadHistory|*.*|RECURSE
    FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE
    FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
    FileKey15=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.*
    FileKey16=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey17=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\Emie*List|*.*|RECURSE
    FileKey18=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*|RECURSE
    FileKey19=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*|RECURSE
    FileKey20=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE
    FileKey21=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE
    FileKey22=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE
    FileKey23=%SystemDrive%\Documents and Settings\LocalService*\Cookies|*.*|RECURSE
    FileKey24=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\History|*.*|RECURSE
    FileKey25=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\Temporary Internet Files|*.*|RECURSE
    FileKey26=%SystemDrive%\Documents and Settings\NetworkService*\Cookies|*.*|RECURSE
    FileKey27=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\History|*.*|RECURSE
    FileKey28=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\Temporary Internet Files|*.*|RECURSE
    FileKey29=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
    FileKey30=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
    FileKey31=%WinDir%\ServiceProfiles\*\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
    FileKey32=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
    FileKey33=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
    FileKey34=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
    FileKey35=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE
    FileKey36=%WinDir%\System32\config\systemprofile\Cookies|*.*|RECURSE
    FileKey37=%WinDir%\System32\config\systemprofile\History|*.*|RECURSE
    FileKey38=%WinDir%\System32\config\systemprofile\Local Settings\Temporary Internet Files|*.*|RECURSE
    FileKey39=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
    FileKey40=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
    FileKey41=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies|*.*|RECURSE
    FileKey42=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache|*.*|RECURSE
    RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage
    RegKey2=HKCU\Software\Microsoft\Internet Explorer\DOMStorage
    RegKey3=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage
    RegKey4=HKCU\Software\Microsoft\Internet Explorer\Recovery\PendingDelete
    RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
    RegKey6=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU
    RegKey7=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
    RegKey8=HKU\.DEFAULT\Software\Microsoft\Internet Explorer\TypedURLs

  4. Revised entry

    Added .tmp in FileKey23

    [Windows Logs *]
    LangSecRef=3025
    Detect=HKLM\Software\Microsoft\Windows
    FileKey1=%CommonAppData%\Microsoft\Diagnosis\DownloadedSettings|*.json.bk
    FileKey2=%CommonAppData%\Microsoft\Diagnosis\ETLLogs|*.*|RECURSE
    FileKey3=%CommonAppData%\Microsoft\DiagnosticLogCSP|*.*|RECURSE
    FileKey4=%CommonAppData%\Microsoft\Network\Downloader|*.*|RECURSE
    FileKey5=%CommonAppData%\Microsoft\WDF|*.*|RECURSE
    FileKey6=%CommonAppData%\Microsoft\Windows Security Health\Logs|*.*|RECURSE
    FileKey7=%CommonAppData%\Microsoft\Windows\wfp|*.etl
    FileKey8=%CommonAppData%\USOShared\Logs|*.*|RECURSE
    FileKey9=%LocalAppData%\ConnectedDevicesPlatform|*.log
    FileKey10=%LocalAppData%\Diagnostics|*.*|RECURSE
    FileKey11=%LocalAppData%\Microsoft\Dialer|*.log.txt
    FileKey12=%LocalAppData%\Microsoft\msipc\Logs|*.*
    FileKey13=%LocalAppData%\Microsoft\Windows\Explorer|*.etl
    FileKey14=%ProgramFiles%\UNP\*Logs|*.*
    FileKey15=%SystemDrive%|DumpStack.log
    FileKey16=%SystemDrive%\PerfLogs\System\Diagnostics|*.*|RECURSE
    FileKey17=%SystemDrive%\PerfLogs\System\Performance|*.*|RECURSE
    FileKey18=%WinDir%\AppCompat\Programs|*.txt;*.xml
    FileKey19=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml
    FileKey20=%WinDir%\debug\WIA|*.log
    FileKey21=%WinDir%\INF|*.etl;*.log*
    FileKey22=%WinDir%\Logs\CBS|*.cab
    FileKey23=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log;*.tmp
    FileKey24=%WinDir%\Panther\FastCleanup|*.log
    FileKey25=%WinDir%\Panther\Rollback|*.txt
    FileKey26=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml
    FileKey27=%WinDir%\repair|setup.log
    FileKey28=%WinDir%\security\logs|*.*|RECURSE
    FileKey29=%WinDir%\ServiceProfiles\NetworkService\debug|*.log
    FileKey30=%WinDir%\System32\CatRoot|*.tmp
    FileKey31=%WinDir%\System32\CatRoot_bak|*.*|REMOVESELF
    FileKey32=%WinDir%\System32\catroot2|*.chk;*.log;*.jrs;*.txt
    FileKey33=%WinDir%\System32\LogFiles\HTTPERR|*.log
    FileKey34=%WinDir%\System32\LogFiles\Scm|*.*|RECURSE
    FileKey35=%WinDir%\System32\LogFiles\setupcln|*.*|RECURSE
    FileKey36=%WinDir%\System32\LogFiles\Srt|*.*|RECURSE
    FileKey37=%WinDir%\System32\LogFiles\WMI|*.*|RECURSE
    FileKey38=%WinDir%\System32\LogFiles\WUDF|*.*
    FileKey39=%WinDir%\System32\SleepStudy|*.etl
    FileKey40=%WinDir%\System32\SleepStudy\ScreenOn|*.etl
    FileKey41=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml;*.log
    FileKey42=%WinDir%\System32\WDI\*|snapshot.etl|REMOVESELF
    FileKey43=%WinDir%\System32\WDI\LogFiles\StartupInfo|*.*|RECURSE
    RegKey1=HKLM\Software\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications
    RegKey2=HKLM\Software\Microsoft\Tracing
    RegKey3=HKLM\Software\Wow6432Node\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications
    RegKey4=HKLM\Software\Wow6432Node\Microsoft\Tracing

  5. Revised entry

    Added .cache files
    FileKey13=%Public%\TechSmith\Snagit\License|*.cache;*.log

    [Snagit *]
    LangSecRef=3021
    Detect=HKCU\Software\TechSmith\Snagit
    FileKey1=%CommonAppData%\TechSmith\Uploader|*.log
    FileKey2=%Documents%|SnagitDebug.log
    FileKey3=%Documents%\Snagit|*.snagx
    FileKey4=%Documents%\Snagit\.metadata|*.*|RECURSE
    FileKey5=%LocalAppData%\TechSmith\Logs|*.log
    FileKey6=%LocalAppData%\TechSmith\Snagit|Tray.bin
    FileKey7=%LocalAppData%\TechSmith\Snagit\*\NativeCrashReporting\Reports|*.dmp|RECURSE
    FileKey8=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE
    FileKey9=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico
    FileKey10=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico
    FileKey11=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE
    FileKey12=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log;*.logtmp
    FileKey13=%Public%\TechSmith\Snagit\License|*.cache;*.log
    RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder
    RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder
    RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount
    RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount
    RegKey5=HKCU\Software\TechSmith\Snagit\11|OutputDirLastUsed
    RegKey6=HKCU\Software\TechSmith\Snagit\11|VidOutputDirLastUsed
    RegKey7=HKCU\Software\TechSmith\Snagit\11\SnagItEditor\Tray|Thumbnailsize
    RegKey8=HKCU\Software\TechSmith\Snagit\12|CaptureCount
    RegKey9=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount
    RegKey10=HKCU\Software\TechSmith\Snagit\12|OutputDirLastUsed
    RegKey11=HKCU\Software\TechSmith\Snagit\12|VidOutputDirLastUsed
    RegKey12=HKCU\Software\TechSmith\Snagit\12\SnagItEditor\Tray|Thumbnailsize
    RegKey13=HKCU\Software\TechSmith\Snagit\13|CaptureCount
    RegKey14=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount
    RegKey15=HKCU\Software\TechSmith\Snagit\13|OutputDirLastUsed
    RegKey16=HKCU\Software\TechSmith\Snagit\13|VidOutputDirLastUsed
    RegKey17=HKCU\Software\TechSmith\Snagit\13\Recent Captures
    RegKey18=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List
    RegKey19=HKCU\Software\TechSmith\Snagit\13\SnagItEditor\Tray|Thumbnailsize
    RegKey20=HKCU\Software\TechSmith\Snagit\18|CaptureCount
    RegKey21=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount
    RegKey22=HKCU\Software\TechSmith\Snagit\18|OutputDirLastUsed
    RegKey23=HKCU\Software\TechSmith\Snagit\18|VidOutputDirLastUsed
    RegKey24=HKCU\Software\TechSmith\Snagit\18\Recent Captures
    RegKey25=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List
    RegKey26=HKCU\Software\TechSmith\Snagit\18\SnagItEditor\Tray|Thumbnailsize
    RegKey27=HKCU\Software\TechSmith\Snagit\19|CaptureCount
    RegKey28=HKCU\Software\TechSmith\Snagit\19|CaptureOpenCount
    RegKey29=HKCU\Software\TechSmith\Snagit\19|OutputDirLastUsed
    RegKey30=HKCU\Software\TechSmith\Snagit\19|VidOutputDirLastUsed
    RegKey31=HKCU\Software\TechSmith\Snagit\19\Recent Captures
    RegKey32=HKCU\Software\TechSmith\Snagit\19\SnagitEditor\Recent File List
    RegKey33=HKCU\Software\TechSmith\Snagit\19\SnagItEditor\Tray|Thumbnailsize
    RegKey34=HKCU\Software\TechSmith\Snagit\20|CaptureCount
    RegKey35=HKCU\Software\TechSmith\Snagit\20|CaptureOpenCount
    RegKey36=HKCU\Software\TechSmith\Snagit\20|OutputDirLastUsed
    RegKey37=HKCU\Software\TechSmith\Snagit\20|VidOutputDirLastUsed
    RegKey38=HKCU\Software\TechSmith\Snagit\20\Recent Captures
    RegKey39=HKCU\Software\TechSmith\Snagit\20\SnagitEditor\Recent File List
    RegKey40=HKCU\Software\TechSmith\Snagit\20\SnagItEditor\Tray|Thumbnailsize
    RegKey41=HKCU\Software\TechSmith\Snagit\21|CaptureCount
    RegKey42=HKCU\Software\TechSmith\Snagit\21|CaptureOpenCount
    RegKey43=HKCU\Software\TechSmith\Snagit\21|OutputDirLastUsed
    RegKey44=HKCU\Software\TechSmith\Snagit\21|VidOutputDirLastUsed
    RegKey45=HKCU\Software\TechSmith\Snagit\21\Recent Captures
    RegKey46=HKCU\Software\TechSmith\Snagit\21\SnagitEditor\Recent File List
    RegKey47=HKCU\Software\TechSmith\Snagit\21\SnagItEditor\Tray|Thumbnailsize
    RegKey48=HKCU\Software\TechSmith\Snagit\22|CaptureCount
    RegKey49=HKCU\Software\TechSmith\Snagit\22|CaptureOpenCount
    RegKey50=HKCU\Software\TechSmith\Snagit\22|OutputDirLastUsed
    RegKey51=HKCU\Software\TechSmith\Snagit\22|VidOutputDirLastUsed
    RegKey52=HKCU\Software\TechSmith\Snagit\22\Recent Captures
    RegKey53=HKCU\Software\TechSmith\Snagit\22\SnagitEditor\Recent File List
    RegKey54=HKCU\Software\TechSmith\Snagit\22\SnagItEditor\Tray|Thumbnailsize

  6. Snagit creates the MSI*.tmp- folders.

    [Windows Installer *]
    LangSecRef=3025
    Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Installer
    FileKey1=%SystemDrive%\Config.msi|*.*|REMOVESELF
    FileKey2=%WinDir%\Installer|*.tmp|RECURSE
    FileKey3=%WinDir%\Installer|SourceHash{*};wix{*}.SchedServiceConfig.rmi
    FileKey4=%WinDir%\Installer\Config.Msi|*.*|REMOVESELF
    FileKey5=%WinDir%\Installer\MSI*.tmp-|*.*|REMOVESELF

  7. Revised entry

    [GIMP *]
    LangSecRef=3021
    DetectFile=%LocalAppData%\GIMP
    DetectFile1=%UserProfile%\.gimp-*
    FileKey1=%LocalAppData%|recently-used.xbel
    FileKey2=%LocalAppData%\webkit|*.*|REMOVESELF
    FileKey3=%LocalAppData%\GIMP\*\CrashLog|*.*|RECURSE
    FileKey4=%LocalAppData%\GIMP\*\tmp|*.*|RECURSE
    FileKey5=%UserProfile%\.gegl-*|documents
    FileKey6=%UserProfile%\.gimp-*|documents
    FileKey7=%UserProfile%\.gimp-*\tmp|*.*|RECURSE
    FileKey8=%UserProfile%\.thumbnails\normal|*.*|RECURSE

  8. 18 hours ago, APMichael said:

    ???

    This entry was never for Windows 10, it has always used "DetectOS=6.2|6.3", thus it will only show up on Windows 8 and Windows 8.1. A change should therefore not be necessary. By the way "DetectOS=10.0|" means Windows 10 and newer.  

    This entry is present on Windows 10. I deleted approx 8MB of junk using my custom entry for Store apps.

  9. This entry is not working on Windows 10. Detect should be changed to DetectFile=%LocalAppData%\Packages\microsoft.windows.authhost.sso_8wekyb3d8bbwe and DetectOS=6.2|6.3 should be changed to DetectOS=10.0|.

    [AuthHost *]
    DetectOS=6.2|6.3
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windows.authhost.sso_8wekyb3d8bbwe
    FileKey1=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\AppCache|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\INet*|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\CryptnetUrlCache\*|*.*
    FileKey5=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\PRICache|*.*
    FileKey7=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Temp|*.*
    FileKey8=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\LocalState\Cache|*.*|RECURSE
    FileKey9=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\LocalState\navigationHistory|*.*|RECURSE
    FileKey10=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\TempState|*.*|RECURSE

  10. New Entry

    [Microsoft Teams *]
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MicrosoftTeams_8wekyb3d8bbwe
    FileKey1=%LocalAppData%\Packages\MicrosoftTeams_*\AC\INet*|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\MicrosoftTeams_*\AC\Temp|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\MicrosoftTeams_*\LocalCache|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\MicrosoftTeams_*\TempState|*.*|RECURSE

  11. Revised Entries

    Moved from [HP Support Assistant *] and added into [HP Logs *]: %SystemDrive%\system.sav\logs|*.*|RECURSE

    [HP Logs *]
    LangSecRef=3021
    Detect=HKCU\Software\HP
    DetectFile1=%AppData%\hpqlog
    DetectFile2=%CommonAppData%\Hewlett-Packard
    DetectFile3=%CommonAppData%\HP
    DetectFile4=%LocalAppData%\Hewlett-Packard
    DetectFile5=%LocalAppData%\TouchSmartData
    DetectFile6=%ProgramFiles%\HPQ\Shared\Sierra Wireless
    FileKey1=%AppData%\hp active health\app analytics\*logs|*.*|RECURSE
    FileKey2=%AppData%\HP\*Logs|*Log.txt
    FileKey3=%AppData%\hpqlog|*.log
    FileKey4=%CommonAppData%|hpzinstall.log
    FileKey5=%CommonAppData%\Hewlett-Packard|*.log*.*;*Log.txt|RECURSE
    FileKey6=%CommonAppData%\Hewlett-Packard\HP*\Log*|*.*|RECURSE
    FileKey7=%CommonAppData%\hp audio switch|*.log*
    FileKey8=%CommonAppData%\HP\HP Touchpoint Analytics Client\Logs|*.*
    FileKey9=%CommonAppData%\HP\HP Touchpoint Analytics Client\Monitor-History|*.*
    FileKey10=%CommonAppData%\HP\HP Touchpoint Analytics Client\MRU|*.*
    FileKey11=%CommonAppData%\HP\logs|*.*|RECURSE
    FileKey12=%CommonAppData%\HP\StreamLog|*.*|RECURSE
    FileKey13=%LocalAppData%\Hewlett-Packard\HP Support Framework\Profile\Upload|*.log
    FileKey14=%LocalAppData%\TouchSmartData\Log|*.*
    FileKey15=%ProgramFiles%\HPQ\Shared\Sierra Wireless|*.log|RECURSE
    FileKey16=%SystemDrive%|dism.log
    FileKey17=%SystemDrive%\hp\bin\logs|*.log
    FileKey18=%SystemDrive%\system.sav\logs|*.*|RECURSE
    FileKey19=%WinDir%\HP|Installer.log


    Added: %LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE

    [HP Smart *]
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AD2F1837.HPPrinterControl_v10z8vjag6ke6
    FileKey1=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\AppCache|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\INet*|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE
    FileKey4=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\*.HPPrinterControl_*\AC\Temp|*.*|RECURSE
    FileKey7=%LocalAppData%\Packages\*.HPPrinterControl_*\LocalCache|*.*|RECURSE
    FileKey8=%LocalAppData%\Packages\*.HPPrinterControl_*\TempState|*.*|RECURSE


    [HP Support Assistant *]
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AD2F1837.HPSupportAssistant_v10z8vjag6ke6
    FileKey1=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\INet*|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\AC\Temp|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\LocalCache|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\AD2F1837.HPSupportAssistant_*\TempState|*.*|RECURSE


    I think [Intel Graphics Command Center *] entry name should be changed to [Intel Graphics Experience *]

    [Intel Graphics Command Center *]
    DetectOS=10.0|
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AppUp.IntelGraphicsExperience_8j3eq9eme6ctt
    FileKey1=%LocalAppData%\Intel\GCC|gcc*_log_*.txt
    FileKey2=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\BackgroundTransferApi|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\INet*|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\AC\Temp|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalCache|*.*|RECURSE
    FileKey7=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState|gcc*_log_*.txt
    FileKey8=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\Games2\cache|*.*|RECURSE
    FileKey9=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\Intel\GCC|gcc*_log_*.txt
    FileKey10=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\MetroLogs|*.*|RECURSE
    FileKey11=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\LocalState\Promotions|*.*|RECURSE
    FileKey12=%LocalAppData%\Packages\AppUp.IntelGraphicsExperience_*\TempState|*.*|RECURSE


    [Windows Client WebExperience *]
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy
    FileKey1=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\AC\INet*|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\AC\Temp|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\LocalCache|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\LocalState\EBWebview\*|LOG;LOG.old
    FileKey6=%LocalAppData%\Packages\MicrosoftWindows.Client.WebExperience_*\TempState|*.*|RECURSE

  12. 3 hours ago, SMalik said:

    New Entry

    [Foxit PDF Editor *]
     

    [Foxit PDF Editor *]
    LangSecRef=3021
    Detect=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0
    FileKey1=%AppData%\Foxit Software\Addon\Foxit PDF Editor\Install|*.*|RECURSE
    FileKey2=%AppData%\Foxit Software\Foxit PDF Editor\Cache|*.*|RECURSE
    FileKey3=%AppData%\Foxit Software\Foxit PDF Editor\FormFiller|AutoComplete.ds
    FileKey4=%AppData%\Foxit Software\Foxit PDF Editor\StartPage\*\Start\en-US|index.html
    FileKey5=%AppData%\Foxit Software\RMS|FXRMS_Log.txt
    FileKey6=%CommonAppData%\Foxit Software\Foxit PDF Editor\Foxit Service\Log|*.*|RECURSE
    FileKey7=%CommonAppData%\Foxit Software\Foxit PDF Editor\FoxitSensor\Log|*.*|RECURSE
    FileKey8=%LocalLowAppData%\Foxit\Search|*.*|RECURSE
    RegKey1=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0\CommentPanel\Filter
    RegKey2=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\File MRU
    RegKey3=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\Place MRU
    RegKey4=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\plugins\JSPlugins
    RegKey5=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\Preferences\History

  13. Revised Entry

    Added: Detect1 and related FileKeys

    [Wondershare UniConverter *]
    LangSecRef=3023
    Detect=HKLM\SOFTWARE\Wondershare\Wondershare UniConverter
    Detect1=HKLM\SOFTWARE\Wondershare\Wondershare UniConverter 13
    FileKey1=%CommonAppData%\Wondershare\ProductFeatures\*Logs|*.*|RECURSE
    FileKey2=%CommonAppData%\Wondershare\UniConverter\DataTrack|tmp;*.bak;*.log
    FileKey3=%CommonAppData%\Wondershare\UniConverter\TempThumbDir|*.*|RECURSE
    FileKey4=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE
    FileKey5=%CommonAppData%\Wondershare\UniConverter 13\DataTrack|tmp;*.bak;*.log
    FileKey6=%CommonAppData%\Wondershare\UniConverter 13\TempThumbDir|*.*|RECURSE
    FileKey7=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE
    FileKey8=%ProgramFiles%\Wondershare\UniConverter\Log|*.*|RECURSE
    FileKey9=%ProgramFiles%\Wondershare\Wondershare UniConverter 13 for Windows\Log|*.*|RECURSE
    FileKey10=%Public%\Documents\Wondershare|*.*|REMOVESELF
    FileKey11=%SystemDrive%|logWSVCUUpdateHelper.log
    FileKey12=%SystemDrive%\Wondershare UniConverter\Downloaded\temp|*.*|REMOVESELF
    FileKey13=%UserProfile%\.cache|*.*|REMOVESELF

  14. New Entry

    [Foxit PDF Editor *]
    LangSecRef=3021
    Detect=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0
    FileKey1=%LocalLowAppData%\Foxit\Search|*.*|RECURSE
    FileKey2=%AppData%\Foxit Software\Addon\Foxit PDF Editor\Install|*.*|RECURSE
    FileKey3=%AppData%\Foxit Software\Foxit PDF Editor\Cache|*.*|RECURSE
    FileKey4=%AppData%\Foxit Software\Foxit PDF Editor\FormFiller|AutoComplete.ds
    FileKey5=%AppData%\Foxit Software\Foxit PDF Editor\StartPage\*\Start\en-US|index.html
    FileKey6=%AppData%\Foxit Software\RMS|FXRMS_Log.txt
    RegKey1=HKCU\SOFTWARE\Foxit Software\Foxit PDF Editor 11.0\CommentPanel\Filter
    RegKey2=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\Foxit PhantomPDF Advanced Editor\Recent File List
    RegKey3=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\File MRU
    RegKey4=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\MRU\Place MRU
    RegKey5=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\plugins\JSPlugins
    RegKey6=HKCU\Software\Foxit Software\Foxit PDF Editor 11.0\Preferences\History

  15. On 25/06/2021 at 17:04, SMalik said:

    Revised Entry

    Added:
    DetectFile3
    %SystemDrive%\system.sav|*.*|REMOVESELF

    [HP Installation Files *]
    LangSecRef=3024
    DetectFile1=%SystemDrive%\HP Universal Print Driver
    DetectFile2=%SystemDrive%\swsetup
    DetectFile3=%SystemDrive%\system.sav
    FileKey1=%SystemDrive%\HP Universal Print Driver|*.*|REMOVESELF
    FileKey2=%SystemDrive%\swsetup|*.*|REMOVESELF
    FileKey3=%SystemDrive%\system.sav|*.*|REMOVESELF

    Please do no change this entry. system.sav is part of HP Support Assistant program and it keeps logs there.

  16. Revised Entry

    Added:
    DetectFile3
    %SystemDrive%\system.sav|*.*|REMOVESELF

    [HP Installation Files *]
    LangSecRef=3024
    DetectFile1=%SystemDrive%\HP Universal Print Driver
    DetectFile2=%SystemDrive%\swsetup
    DetectFile3=%SystemDrive%\system.sav
    FileKey1=%SystemDrive%\HP Universal Print Driver|*.*|REMOVESELF
    FileKey2=%SystemDrive%\swsetup|*.*|REMOVESELF
    FileKey3=%SystemDrive%\system.sav|*.*|REMOVESELF

  17. New Entry

    [Edge Website Redirecting Statistics *]
    LangSecRef=3006
    DetectFile=%LocalAppData%\Microsoft\Edge*
    FileKey1=%LocalAppData%\Microsoft\Edge*\User Data\*|load_statistics.db;load_statistics.db-shm;load_statistics.db-wal

  18. Revised Entry

    Subscriptions Activity History
    Added: RegKey1

    [Content Delivery Manager *]
    DetectOS=10.0|
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy
    FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\AppCache|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\INet*|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Temp|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\TokenBroker\Cache|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalCache|*.*|RECURSE
    FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Favicons|*.*|RECURSE
    FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\MobilityExperience\ImageCache|*.*|RECURSE
    FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\OneSettingsResponseCache|*.*|RECURSE
    FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\TargetedContentCache|*.*|RECURSE
    FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\TempState|*.*|RECURSE
    RegKey1=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions

  19. Revised Entry

    Added: UserActivity.json into FileKey9

    [Weather *]
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe
    FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INet*|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log
    FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE
    FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE
    FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE
    FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp;UserActivity.json
    FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE
    FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE
    FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE
    RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory

  20. On 03/03/2021 at 03:34, APMichael said:

    An entry for removing these empty "tw-*.tmp" folders has existed for quite some time: [System Profile Temp Folders *]

    As soon as I posted about these empty folders, I realized there is already an entry for this. I requested one of the admins to delete the post. They deleted that post to which afterwards, I noticed your response. My apologies.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.