Jump to content

SMalik

Experienced Members
  • Posts

    1,757
  • Joined

  • Last visited

Everything posted by SMalik

  1. Revised Entries [bing Finance More*] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingFinance_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.BingFinance_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\PRICache|*.* FileKey4=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.BingFinance_*\TempState|*.*|RECURSE Added: %LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*|RECURSE %LocalAppData%\Packages\Microsoft.BingFinance_*\AC\TokenBroker\Cache|*.*|RECURSE [bing News More*] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.BingNews_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\PRICache|*.* FileKey3=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.BingNews_*\LocalState\navigationHistory|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe\SearchHistory Added: %LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*|RECURSE %LocalAppData%\Packages\Microsoft.BingNews_*\AC\TokenBroker\Cache|*.*|RECURSE [bing Sports More*] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.BingSports_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\PRICache|*.* FileKey4=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.BingSports_*\LocalState\navigationHistory|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.BingSports_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe\SearchHistory Added: %LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*|RECURSE %LocalAppData%\Packages\Microsoft.BingSports_*\AC\TokenBroker\Cache|*.*|RECURSE [bing Weather*] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.BingWeather_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp FileKey13=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory Added |RECURSE to some lines. [Camera*] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsCamera_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.Camera_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CryptnetUrlCache\Content|*.* FileKey7=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.* FileKey8=%LocalAppData%\Packages\Microsoft.Camera_*\AC\PRICache|*.* FileKey9=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Temp|*.* FileKey10=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\AppCache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetCache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetCookies|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetHistory|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey16=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Temp|*.*|RECURSE FileKey17=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey18=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalCache|*.*|RECURSE FileKey19=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\AppData|*.*|RECURSE FileKey20=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\Cache|*.*|RECURSE FileKey21=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe\SearchHistory Added: Detect2 Added: FileKey 10 thru FileKey21 for Windows 10 [Cloud Experience Host*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\TempState|*.*|RECURSE Added: %LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\AppCache|*.*|RECURSE [OneNote*] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetCache|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetCookies|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetHistory|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Temp|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local|msodata*.dat FileKey9=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\OTele|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\office15client.microsoft.com|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0\OneNoteOfflineCache_Files|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0\OneNotePagePreviewCache_Files|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0|*.onecache FileKey15=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe\SearchHistory Added: %LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\TokenBroker\Cache|*.*|RECURSE %LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com|*.*|RECURSE [Xbox Identity Provider*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxIdentityProvider_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetCookies|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetHistory|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0|*.log FileKey5=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32|*.log FileKey8=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Temp|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalCache|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalState\Cache|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\TempState|*.*|RECURSE Removed |RECURSE from some lines. [XboxApp*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxApp_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCookies|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetHistory|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Temp|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalCache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log;*.log* FileKey10=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log FileKey12=%LocalAppData%\Packages\Microsoft.XboxApp_*\TempState|*.*|RECURSE Added: %LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log;*.log. %LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log [Zune Music*] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\PRICache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Temp|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\Cache|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageCache|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\navigationHistory|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\PlayReady|*.*|RECURSE FileKey16=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\SearchHistory Added: %LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\TokenBroker\Cache|*.*|RECURSE [Zune Video*] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\PRICache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Temp|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Cache|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageCache|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\navigationHistory|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\PlayReady|*.*|RECURSE FileKey16=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\TempState|*.*|RECURSE FileKey17=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Database\anonymous|*.log RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe\SearchHistory Added: %LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\TokenBroker\Cache|*.*|RECURSE
  2. New Entries [Accounts Control*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.AccountsControl_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.AccountsControl_*\TempState|*.*|RECURSE [Comms Phone*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.CommsPhone_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.CommsPhone_*\TempState|*.*|RECURSE [Connectivity Store*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ConnectivityStore_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\TempState|*.*|RECURSE [Contact Support*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Windows.ContactSupport_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0|*.log FileKey6=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32|*.log FileKey9=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Temp|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey16=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalCache|*.*|RECURSE FileKey17=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalState\Cache|*.*|RECURSE FileKey18=%LocalAppData%\Packages\Windows.ContactSupport_*\TempState|*.*|RECURSE [Lock App*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.LockApp_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.LockApp_*\TempState|*.*|RECURSE [Maps*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsMaps_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\TempState|*.*|RECURSE [People*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.People_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.People_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.People_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.People_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.People_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.People_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.People_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.People_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.People_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.People_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.People_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.People_*\TempState|*.*|RECURSE [Phone*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsPhone_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\TempState|*.*|RECURSE [QuizUp*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\QuizUp.QuizUp_n36z36qeaxk8a FileKey1=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE FileKey6=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE FileKey7=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0_32|*.log|RECURSE FileKey8=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE FileKey9=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey10=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey11=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Temp|*.*|RECURSE FileKey12=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey13=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalCache|*.*|RECURSE FileKey14=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalState\Cache|*.*|RECURSE FileKey15=%LocalAppData%\Packages\QuizUp.QuizUp_*\TempState|*.*|RECURSE [scan*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsScan_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.WindowsScan_*\TempState|*.*|RECURSE [shell Experience Host*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\TempState|*.*|RECURSE [sound Recorder*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\TempState|*.*|RECURSE [sway*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.Sway_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Temp|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalState\Cache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.Office.Sway_*\TempState|*.*|RECURSE [Windows Feedback*] DetectOS=10.0| Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedback_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0|*.log FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0_32|*.log FileKey9=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Temp|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\LocalCache|*.*|RECURSE FileKey16=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\LocalState\Cache|*.*|RECURSE FileKey17=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\TempState|*.*|RECURSE
  3. CCleaner's built-in entry for Xilisoft Video Converter is not compatible with the Standard and Ultimate versions of the program. [Xilisoft Video Converter] ID=2381 LangSecRef=3023 Detect=HKLM\Software\Xilisoft\Video Converter Platinum Detect2=HKLM\Software\Xilisoft\Video Converter Ultimate Detect3=HKLM\Software\Xilisoft\Video Converter Standard Default=True RegKey1=Software\Xilisoft\Video Converter Platinum\Settings|last_output_dir RegKey2=Software\Xilisoft\Video Converter Platinum\Settings|last_profile_group RegKey3=Software\Xilisoft\Video Converter Platinum\Settings|last_profile_url RegKey4=Software\Xilisoft\Video Converter Platinum\Settings|recent_profiles RegKey5=Software\Xilisoft\Video Converter Platinum\Settings\output Filekey1=%CommonAppData%\Xilisoft\Video Converter Platinum\customdata|settings.old
  4. New Entry [signature Verification Logs*] DetectOS=|5.1 LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%WinDir%|SIGVERIF.TXT https://support.microsoft.com/en-us/kb/934019
  5. Revised Entries Moved some paths from [Log Files More*] into the entries listed below. Two paths, %WinDir%\winsxs|poqexec.log & %WinDir%\inf|*.log*, are still in this entry and they should not be removed. [Log Files More*] can be removed. [Diagnostics Logs*] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%WinDir%\debug\WIA|*.log [Panther*] LangSecRef=3025 DetectFile=%Windir%\Panther Default=False FileKey1=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log FileKey2=%WinDir%\Panther\FastCleanup|*.log FileKey3=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml FileKey4=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml
  6. Revised Entry [Action Center*] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Notifications\Current Changed the Detect. Added: %LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE HKCU\Software\Microsoft\Windows\CurrentVersion\Notifications\Current
  7. Revised Entries [Cortana*] Section=3031 Default=False Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Cortana_8wekyb3d8bbwe Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Cortana_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetCookies|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetHistory|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Temp|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.Cortana_*\TempState|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\AppCache|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetCache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetCookies|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetHistory|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE FileKey16=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey17=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Temp|*.*|RECURSE FileKey18=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey19=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalCache|*.*|RECURSE FileKey20=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\Cache|*.*|RECURSE FileKey21=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\AppIconCache|*.*|RECURSE FileKey22=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache|*.*|RECURSE FileKey23=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\TempState|*.*|RECURSE Added: %LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\AppCache|*.*|RECURSE %LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\AppIconCache|*.*|RECURSE %LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache|*.*|RECURSE [DRM Traces*] LangSecRef=3025 Detect=HKLM\Software\Microsoft\DRM Default=False FileKey1=%CommonAppData%\Microsoft\Windows\DRM\Cache|*.*|RECURSE FileKey2=%CommonAppData%\Microsoft\Windows\DRM\PreUpgrade|*.log FileKey3=%CommonAppData%\Microsoft\Windows\DRM|*.log FileKey4=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\Cache|*.*|RECURSE FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\PreUpgrade|*.log FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM|*.log Changed entry name from [DRM Cache*] to [DRM Traces*]. Added: %CommonAppData%\Microsoft\Windows\DRM\PreUpgrade|*.log %CommonAppData%\Microsoft\Windows\DRM|*.log [Windows Communications Apps*] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe DetectFile=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe Default=False FileKey1=%LocalAppData%\Comms\Temp|*.*|RECURSE FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\AppCache|*.*|RECURSE FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCache|*.*|RECURSE FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCookies|*.*|RECURSE FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetHistory|*.*|RECURSE FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\Content|*.* FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.* FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\PRICache|*.* FileKey11=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.* FileKey12=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE FileKey13=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\LiveComm\*\*\DBStore\LogFiles|edbtmp.log RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory Added: %LocalAppData%\Comms\Temp|*.*|RECURSE
  8. New Entries [3D Builder*] DetectOS=10.0 Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.3DBuilder_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetCookies|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetHistory|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalCache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalState\Cache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.3DBuilder_*\TempState|*.*|RECURSE [Get Started*] DetectOS=10.0 Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Getstarted_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetCookies|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetHistory|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalCache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalState\Cache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Getstarted_*\TempState|*.*|RECURSE
  9. New Entry [Wondershare MobileGo*] LangSecRef=3021 Detect=HKCU\SOFTWARE\Wondershare\MobileGo Default=False FileKey1=%ProgramFiles%\Wondershare\MobileGo|*.log FileKey2=%CommonAppData%\Wondershare\Dr.FoneTool\Log|*.txt FileKey3=%CommonAppData%\Wondershare\WAF\ProductFeatures\LocalLogs|*.*|RECURSE FileKey4=%CommonAppData%\Wondershare\WAF\ProductFeatures\RemoteLogs|*.*|RECURSE FileKey5=%AppData%\se_tmp|*.*|REMOVESELF FileKey6=%AppData%\Wondershare\DataEraser|*.log FileKey7=%AppData%\Wondershare\Dr.FoneTool\log|*.log FileKey8=%AppData%\Wondershare\DrFoneAndroidTool\log|*.log FileKey9=%AppData%\Wondershare\MirrorGo\ImageCache\ADImage|*.*|RECURSE FileKey10=%AppData%\Wondershare\MirrorGo|*.log FileKey11=%AppData%\Wondershare\MobileGo|*.log FileKey12=%AppData%\Wondershare\MobileGo\DeviceImageCache|*.*|RECURSE FileKey13=%AppData%\Wondershare\MobileGo\iOSTemp|*.*|REMOVESELF FileKey14=%AppData%\Wondershare\MobileGo\Logs\DeviceConnection|*.*|RECURSE FileKey15=%AppData%\Wondershare\MobileTransTool|*.log FileKey16=%AppData%\Wondershare\WsRoot\Logs|*.*|RECURSE Please remove [Wondershare MobileGo for iOS*] entry.
  10. @Winapp2.ini Looks like the new Winapp2.ini file is uploaded, but you forgot to fix the entries mentioned in the links below. http://forum.piriform.com/index.php?showtopic=32310&p=271094 http://forum.piriform.com/index.php?showtopic=32310&p=271093
  11. Revised Entry [Foxit PhantomPDF 7 More*] LangSecRef=3021 Detect=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0 Default=False FileKey1=%LocalAppData%\Foxit PhantomPDF\msilog|*.log FileKey2=%AppData%\Foxit Software\Foxit PhantomPDF\FormFiller|AutoComplete.ds FileKey3=%AppData%\Foxit Software\RMS|FXRMS_Log.txt RegKey1=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\MRU\File MRU RegKey2=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\MRU\Place MRU RegKey3=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\Preferences\History RegKey4=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\Recent File List Added: HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\MRU\File MRU HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\MRU\Place MRU
  12. Revised Entry Changed DetectFile to Detect [Plex Media Server*] LangSecRef=3023 Detect=HKCU\Software\Plex, Inc.\Plex Media Server Default=False FileKey1=%ProgramFiles%\Plex\Plex Media Server|log*.txt;*.log|RECURSE FileKey2=%LocalAppData%\VirtualStore\Program Files*\Plex\Plex Media Server|log*.txt;*.log|RECURSE FileKey3=%LocalAppData%\Plex Media Server\Logs|*.*|RECURSE FileKey4=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Logs|*.*|RECURSE FileKey5=%LocalAppData%\Plex Media Server\Crash Reports|*.*|RECURSE FileKey6=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Crash Reports|*.*|RECURSE
  13. Revised Entry [Ashampoo Burning Studio 16*] LangSecRef=3024 Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16 Default=False FileKey1=%AppData%\Ashampoo\Ashampoo Burning Studio 16\log|*.xml;*.txt RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Backup Project\BackupOptions|CustomLocation RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\BDMV Disc Project\SelectBDMVFolder|BdmvPath RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Browse Image Project\BrowseImageFile|ImagePath RegKey5=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory RegKey6=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory RegKey7=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Burn Image Project\SelectImage|ImagePath RegKey8=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory RegKey9=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\DVD-Video Disc Project\MoviesPage|Path RegKey10=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\DVD-Video Disc Project\SaveDialog_authed.CMoviesPage.Movies|InitialDirectory RegKey11=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Logs RegKey12=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\tempFiles RegKey13=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Unknown Project RegKey14=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VCD Project\SaveDialog_OnAddMovies|InitialDirectory RegKey15=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VIDEO_TS Disc Project\DumpImage|ImagePath RegKey16=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath
  14. Revised Entry [Compatibility Assistant*] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant Default=False RegKey1=HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted RegKey2=HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store RegKey3=HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted RegKey4=HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store Removed: Warning=The will clear compatibility settings for some applcations. HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers There is no need of the Warning anymore.
  15. The RegKeys listed below in the [Compatibility Assistant*] entry are causing this issue. HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
  16. This is not true. I use one of their programs. This entry must have been added mistakenly into Winapp2.ini.
  17. Aiseesoft Studio as a company does exist, but they didn't make a software called "Aiseesoft Studio". http://www.aiseesoft.com/
  18. Revised Entry [Greenshot*] LangSecRef=3024 DetectFile=%AppData%\Greenshot Default=False FileKey1=%LocalAppData%\Greenshot|*.log Removed: %AppData%\Greenshot|*.log Detect=HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Greenshot_is1 I think the DetectFile is enough and there is no .log file in %AppData%\Greenshot\. There is only an .ini file there.
  19. Please remove the [Aiseesoft Studio Logs*] entry. "Aiseesoft Studio" program does not exist. [Aiseesoft Studio Logs*] LangSecRef=3023 Detect=HKCU\Software\Aiseesoft Studio Default=False FileKey1=%AppData%\log|*.*|REMOVESELF FileKey2=%AppData%\Aiseesoft Studio|fileinfolog.txt;*.log|RECURSE FileKey3=%SystemDrive%\log|*.*|REMOVESELF
  20. New Entry [Xilisoft Video Converter Ultimate*] LangSecRef=3023 Detect=HKCU\Software\Xilisoft\Video Converter Ultimate Default=False RegKey1=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings|last_openfile_dir RegKey2=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings|last_output_dir RegKey3=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings|last_profile_group RegKey4=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings|last_profile_url RegKey5=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings|recent_profiles RegKey6=HKCU\Software\Xilisoft\Video Converter Ultimate\Settings\output FileKey1=%CommonAppData%\Xilisoft\Video Converter Ultimate\customdata|settings.old
  21. New Entry [Photos*] DetectOS=10.0 Section=3031 Default=False Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\AC\INetCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\AC\INetCookies|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\AC\INetHistory|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\AC\Temp|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalCache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppTile|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\MostRecentlyUsed
  22. Are you going to release the new file this weekend or next month?
  23. I think the entry listed below should be removed as it is causing issues on Windows 10, and corrupting UsrClass.dat. This link provides more info on these files: http://forum.piriform.com/?showtopic=34468 To me, after defragmentation and compacting the registry hives, new .regtrans-ms files are created and the old ones can be removed. All of the .regtrans-ms files should not be removed. [Registry Transaction Logs*] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Default=False FileKey1=%LocalAppData%\Microsoft\Windows|*.regtrans-ms FileKey2=%SystemDrive%\Users\Default|*.regtrans-ms
  24. New Entry Merged [Garmin Express*] and [GARMIN MapSource*] into [Garmin*] and added some more locations. Please remove the [Garmin Express*] and [GARMIN MapSource*] entries. [Garmin*] LangSecRef=3024 Detect=HKCU\Software\Garmin Default=False FileKey1=%CommonAppData%\Garmin\Logs|*.log;*.txt|RECURSE FileKey2=%LocalAppData%\Garmin\BaseCamp\CardProductCache|*.*|RECURSE FileKey3=%LocalAppData%\Garmin\BaseCamp\DeviceCache|*.*|RECURSE FileKey4=%LocalAppData%\Garmin\BaseCamp\ProductDataCache|*.*|RECURSE FileKey5=%LocalAppData%\Garmin\BaseCamp\TileCache|*.*|RECURSE FileKey6=%LocalAppData%\Garmin\MapInstall\TileCache|*.*|RECURSE FileKey7=%AppData%\Garmin\BaseCamp\Database\*\GeocacheLogs|*.*|RECURSE FileKey8=%AppData%\Garmin\BaseCamp\Database\*\Thumbnails|*.*|RECURSE FileKey9=%AppData%\Garmin\MapSource\TileCache|*.*|RECURSE
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.