Jump to content

FreeRyde

Experienced Members
  • Posts

    187
  • Joined

  • Last visited

Posts posted by FreeRyde

  1. New Entries:

    [AOMEI Backupper *]
    LangSecRef=3024
    DetectFile=%ProgramFiles%\AOMEI Backupper
    FileKey1=%CommonAppData%\AomeiBR|brlog.xml
    FileKey2=%ProgramFiles%\AOMEI Backupper\log|*.*
    FileKey3=%ProgramFiles%\AOMEI Backupper\AOMEI Image Deploy\log|*.*
    
    [CoinManage *]
    LangSecRef=3021
    Detect=HKCU\Software\Liberty Street Software\CoinManage
    Detect2=HKCU\Software\Liberty Street Software\CoinManage Canada
    Default=False
    FileKey1=%ProgramFiles%\CoinManage*|*.txt
    
    [CoinManage Crash Reports *]
    LangSecRef=3021
    Detect=HKCU\Software\Liberty Street Software\CoinManage
    Detect2=HKCU\Software\Liberty Street Software\CoinManage Canada
    Default=False
    FileKey1=%Documents%|CoinManage.zip;CRASH.DMP;ERRORLOG.TXT;XCrashReport.ini;XCRASHREPORT_Mon1.bmp
    
    [CurrencyManage *]
    LangSecRef=3021
    Detect=HKCU\Software\Liberty Street Software\CurrencyManage
    Default=False
    FileKey1=%ProgramFiles%\CurrencyManage|*.txt
    
    [PrivaZer *]
    LangSecRef=3024
    Detect=HKCU\Software\PrivaZer
    Default=False
    FileKey1=%LocalAppData%\PrivaZer|*.txt
    
    [PrivaZer Backups *]
    LangSecRef=3024
    Detect=HKCU\Software\PrivaZer
    DetectFile=%ProgramFiles%\PrivaZer
    Default=False
    Warning=This deletes PrivaZer Registry backups.
    FileKey1=%LocalAppData%\PrivaZer\Registry backups|*.*|RECURSE
    FileKey2=%ProgramFiles%\PrivaZer\PrivaZer registry backups|*.*|RECURSE
    
    [R-Wipe & Clean *]
    LangSecRef=3024
    Detect=HKLM\Software\R-TT\RWC
    Default=False
    FileKey1=%ProgramFiles%\R-Wipe & Clean|*.txt
    FileKey2=%AppData%\R-TT|*.*|REMOVESELF

     

  2. [Marionette Log*]
    LangSecRef=3026
    SpecialDetect=DET_MOZILLA
    Default=False
    FileKey1=%AppData%\Mozilla\Firefox\Profiles\*|marionette.log
    

    Marionette Log above was a new entry in winapp2.ini 4.08.131125

     

    In winapp2.ini 4.12.140408, FileKey2 was added to the entry below; causing the redundancy.

    [Firefox Logs*]
    LangSecRef=3026
    SpecialDetect=DET_MOZILLA
    Default=False
    FileKey1=%ProgramFiles%\Mozilla Firefox|*.log
    
    FileKey2=%AppData%\Mozilla|*.log|RECURSE
  3. I don’t see FileKey1 & 2 on Win 7 and 8. Can someone check Win XP? If these lines are not there, then we can remove these from this entry.

    http://forum.piriform.com/index.php?showtopic=32310&p=247616

     

    FileKey1=%WinDir%\System32\config\SystemProfile\Application Data\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE

    FileKey2=%WinDir%\System32\config\SystemProfile\Application Data\Microsoft\CryptnetUrlCache\MetaData|*.*RECURSE

    Present on my XP. and empty.

     

    [useless File Extension*]
    LangSecRef=3025
    Detect=HKLM\SOFTWARE\Microsoft\
    Default=False
    FileKey1=%SystemDrive%|*.diz;*.tmp;*.temp;*.chk;*.old;*.gid;*.nch;*.wbk;*.fts;*.ftg;*.$$$;*log.txt;*.err;*.---;*.~*;*.??$;*.___;*.log;*.~mp;*._mp;*.dmp;*.prv;*.sik;*.bak;thumbs.db;CHKLIST.MS;*Desktop.ini;*.ilk;*.aps;*.ncb;*.pch;*.$db;*.?$?;*.??~;*.?~?;*.db$;*.^;*._dd;*._detmp;chklist.*;mscreate.dir;log*.txt;*.log?|RECURSE

     

    IMO a bit harsh with regard to .bak and Desktop.ini files.

    The entry found 88.6 MB on my XP system.

     

    XP scan details:

    http://pastebin.com/i4HYWKWv

  4. Really to make a HOSTS file understand all of what's floating about these should be the first entries:

    0.0.0.0  localhost
    127.0.0.1  localhost
    ::1  localhost #[IPv6]
    

    Thank-you!

    I have both... the thought never occurred to simply add '0.0.0.0 localhost'

  5. Modified:

    [Disk Space Fan History*]
    LangSecRef=3024
    Warning=You will need to rescan your disks.
    Detect=HKCU\Software\Cookapp\DSF4
    Default=False
    FileKey1=%AppData%\DiskSpaceFan|history_C.sqlite
    
    - Added missing LangSecRef=3024
     
    [DiskBoss Logs*]
    LangSecRef=3024
    Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DiskBoss Ultimate
    Default=False
    FileKey1=%LocalAppData%\DiskBoss Ultimate\data\reports|*.*|REMOVESELF
     
    - Fixed typo in entry title
  6. EDIT:

     

    [Windows Log Files More*]

    LangSecRef=3025

    Detect=HKCU\Software\Microsoft\Windows

    Default=False

    FileKey1=%WinDir%\inf|setupapi.offline.log

    FileKey2=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html

    FileKey3=%WinDir%\winsxs|poqexec.log

    FileKey4=%WinDir%\debug\WIA|*.log

    FileKey5=%WinDir%|SIGVERIF.TXT

    FileKey6=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml

    FileKey7=%WinDir%\Panther|PostGatherPnPList.log;PreGatherPnPList.log

    FileKey8=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml

    FileKey9=%WinDir%\Logs\CBS|*.log

    FileKey10=%WinDir%\Logs\DISM|*.log

    FileKey11=%WinDir%\Logs\DPX|*.log

    FileKey12=%WinDir%\Logs|*.log

     

    Added FileKey 9 - 12.

     

    FileKey 9 is already present in:

     

    [Windows CBS Logs*]

    LangSecRef=3025

    Detect=HKLM\SOFTWARE\Microsoft\Windows

    Default=False

    FileKey1=%WinDir%\Logs\CBS|cbs.log;*.cab

     

    Regardless, couldn't you just use:

    FileKey9=%WinDir%\Logs|*.log|RECURSE

    ... and eliminate FileKey10 through 12

     

  7.  

    Updated the Mozilla Firefox 'Adblock Backups' cleaner since Adblock Plus has started creating a new naming structure for some backups which I noticed within the last week such as: patterns-1.ini
     
    I've tested it and it will cover all of the backups it creates; patterns-#.ini, patterns-backup.ini, etc.
     
    Before update:
    FileKey1=%AppData%\Mozilla\Firefox\Profiles\*\adblock*|patterns-backup*.ini
     
    After update:
    FileKey1=%AppData%\Mozilla\Firefox\Profiles\*\adblock*|patterns-*.ini
     
    [Adblock Backups*]
    LangSecRef=3026
    SpecialDetect=DET_MOZILLA
    Default=False
    FileKey1=%AppData%\Mozilla\Firefox\Profiles\*\adblock*|patterns-*.ini
    

    I'm hoping that patterns-1.ini was indeed a true backup because it hadn't updated in a long time on my system which had me thinking it was just another backup copy.

     

    I have patterns-1, patterns-2, patterns-3 at %AppData%\Mozilla\Firefox\Profiles\*\adblockedge.

    The modification works and removed the 3 files above, and patterns-backup1 that was also present.

     

    Possibly patterns-1, patterns-2, and patterns-3 are a previously used file system.

    patterns-3 was the latest; dated  February 18, 2014. patterns-1, the oldest, being November 12, 2013.

     

    February 18, 2014 was the date I updated to the new release of Adblock Edge (a fork of Adblock Plus), and coincidentally the same date as patterns-3.

    patterns-*.ini file system appears not utililized with the most recent update; possibly with Adblock Plus also.

     

    I updated my filter subscriptions last night and again just now..

    At this time, the patterns.ini is the only file being repeatedly updated.

    patterns-backup1.ini will update with a browser restart.

  8. may be an xp only folder, thanks for the input

    Not on XP either.

    Perhaps an iPhone needs to be connected to generate the folder.

    My Android can't help there.

     

    Wondershare Video Converter Pro is replaced by Ultimate. I think this entry should be removed. If you still like to keep it, then replace it with the one listed here.

     

    Wondershare Video Converter Ultimate still exists.

     

    I use the entry below to clean both Pro and Ultimate entries not covered by winapp.ini

    The folders in REMOVESELF lines regenerate.

    [Wondershare Video Converter*]
    LangSecRef=3023
    Detect=HKLM\SOFTWARE\Wondershare\Wondershare Video Converter Pro
    Default=False
    FileKey1=%AllUsersProfile%\Documents\Wondershare|*.*|REMOVESELF
    FileKey2=%CommonAppData%\Wondershare Video Converter*|*.dat.bak
    FileKey3=%CommonAppData%\Wondershare Video Converter*\TempSiteIconDir
    FileKey4=%CommonAppData%\Wondershare Video Converter*\TempThumbDir
    FileKey5=%ProgramFiles%\Wondershare\Video Converter*\Log|*.*|REMOVESELF
  9. On Windows 8.1, the FileKey1 entry for [Windows Burn Cache*] is different.  Here is the change.  I suspect the original post is in error. 

     

    [Windows Burn Cache*]

    LangSecRef=3025

    Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning

    Default=False

    Warning=This option will wipe all files that are waiting to be burned to a CD/DVD/BRD

    FileKey1=%LocalAppData%\Microsoft\Windows\Burn\Temporary Burn Folder|*.*

     

    siliconman01's correction of FileKey1 now works for Win 7 also.

     

    Modified:

    [Windows Burn Cache*]
    LangSecRef=3025
    Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning
    Default=False
    Warning=This option will wipe all files that are waiting to be burned to a CD/DVD/BRD
    FileKey1=%LocalAppData%\Microsoft\CD Burning|*.*
    FileKey2=%LocalAppData%\Microsoft\Windows\Burn\Burn|*.*
    FileKey3=%LocalAppData%\Microsoft\Windows\Burn\Temporary Burn Folder|*.*

    Now works for XP and Vista also.

    - Added FileKey1 and 2

    - FileKey3 address corrected

  10. Edit:

    [Call of Juarez Logs*]

    Section=Games

    Detect=HKLM\SOFTWARE\Techland\CallofJuarez2

    Default=False

    FileKey1=%Documents%\call of juarez\Out\logs|*.log|RECURSE

    FileKey2=%Documents%\Call of Juarez - Bound in Blood\Out\logs|*.log|RECURSE

     

    Remove Detect 1 as it is causing to detect Call of Juarez if any techland game is installed.

     

    Did you test before posting?

    Detect1 only requires improved detection, not removal.

     

    Detect2 only detects expansion pack: Call of Juarez - Bound in Blood

    Detect1 detects original base game: Call of Juarez

     

    Modified:

    [Call of Juarez Logs*]
    Section=Games
    Detect1=HKLM\SOFTWARE\Techland\CallOfJuarez
    Detect2=HKLM\SOFTWARE\Techland\CallofJuarez2
    Default=False
    FileKey1=%Documents%\call of juarez\Out\logs|*.log|RECURSE
    FileKey2=%Documents%\Call of Juarez - Bound in Blood\Out\logs|*.log|RECURSE

    - Improved Detect1

  11. IP Filter and Blocklist updates available at TBG Blocklists

    To see when the Lists were last updated and for the filesize of each List, take a look in the Lists folder

    Available IP Filters for use in µTorrent/Azureus/eMule:
        ipfilter.dat.gz
        safepeer.zip

    Available Blocklists (PeerBlock/PeerGuardian2/Protowall):
        PrimaryThreats.zip
        GeneralCorporateRanges.zip
        BusinessISPs.zip
        SearchEngines.zip
        Educational-Institutions.zip
        Bogon.zip
        Hijacked.zip

  12.  

    [Total Uninstall 6*]
    LangSecRef=3024
    Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall 6_is1
    Default=False
    FileKey1=%CommonAppData%\Martau\Total Uninstall 6\*|*.*|REMOVESELF

     

    Total Uninstall 5 & 6 are already covered in Winapp2.ini as 'Total Uninstall' entry.

  13. New entry:

    [Rock of Ages*]
    Section=Games
    Detect=HKCU\Software\Valve\Steam\Apps\22230
    Detect2=HKLM\Software\ACE Team\Rock of Ages
    Default=False
    FileKey1=%ProgramFiles%\ATLUS\Rock of Ages\Prerequisites|*.*|REMOVESELF
    FileKey2=%ProgramFiles%\Steam\steamapps\common\Rock of Ages\Prerequisites|*.*|REMOVESELF
  14. New entries:

    [Chicken Hunter*]
    Section=Games
    Detect=HKLM\Software\Chicken Hunter
    Default=False
    FileKey1=%ProgramFiles%\Chicken Hunter|debug.txt
    
    [HP Drive Key Boot Utility*]
    LangSecRef=3024
    Detect=HKLM\Software\microsoft\windows\currentversion\uninstall\HP Drive Key Boot Utility
    Default=False
    FileKey1=%SystemDrive%\CPQSYSTEM|*.*|REMOVESELF
    

    Modified:

    [AI Roboform*]
    LangSecRef=3022
    Detect=HKCU\Software\Siber Systems
    Default=False
    FileKey1=%AppData%\RoboForm\_gsdata_mirrors_|*.*|RECURSE
    FileKey2=%AppData%\RoboForm\_mirrors_|*.*|RECURSE
    FileKey3=%Documents%\My RoboForm Data\_gsdata_|*.log;*.gss;*.gsl
    FileKey4=%Documents%\My RoboForm Data|mru.rfo;cache.rfo
    FileKey5=%Documents%\My RoboForm Data\*|mru.rfo;cache.rfo
    RegKey1=HKCU\Software\Siber Systems|_InstallerDir
    RegKey2=HKCU\Software\Siber Systems\RoboForm\Query-MRU
    ExcludeKey1=FILE|%ProgramFiles%\Siber Systems\AI RoboForm\affid.txt
    

    - Added FileKey2
    - Added RegKey1

  15. New entry:

    [Ableton Live Suite*]
    LangSecRef=3023
    Detect=HKLM\Software\Propellerhead Software\ReWire\Ableton Live Engine
    Default=False
    FileKey1=%AppData%\Ableton\Live Reports\Temp|*.*|REMOVESELF
    FileKey2=%AppData%\Ableton\Live Reports\Usage|*.*|REMOVESELF
    FileKey3=%AppData%\Ableton\*\Preferences|AsioLog.txt;Indexer.txt;Log.txt|RECURSE
    FileKey4=%CommonAppData%\Ableton\*\Redist|vcredist*.exe
    FileKey5=%ProgramFiles%\Ableton\*\Redist|vcredist*.exe

    Modified:

    [Ableton Live Decoding Cache*]
    LangSecRef=3023
    Detect=HKLM\SOFTWARE\Propellerhead Software\ReWire\Ableton Live Engine
    Default=False
    FileKey1=%AppData%\Ableton\Cache|*.*|RECURSE
    

    - Changed LangSecRef to 3023 = Multimedia

     

    Modified 'CI3demo':

    [Chicken Invaders*]
    Section=Games
    DetectFile1=%AppData%\InterAction studios\CI3demo
    DetectFile2=%ProgramFiles%\ChickenInvaders*
    DetectFile3=%ProgramFiles%\Chicken Invaders*
    Default=False
    FileKey1=%AppData%\InterAction studios|*.log|RECURSE
    FileKey2=%CommonAppData%\InterAction studios|*.log|RECURSE
    FileKey3=%ProgramFiles%\ChickenInvaders*|*.log|RECURSE
    FileKey4=%ProgramFiles%\Chicken Invaders*|*.log|RECURSE
    FileKey5=%ProgramFiles%\*\Chicken Invaders*|*.log;*.html;*.png|RECURSE

    - Renamed to Chicken Invaders

    - Changed LangSecRef=3025 to Section=Games

    - Added DetectFile2 and 3

    - Edited FileKey1

    - Added FileKey2 through 5

    - All Chicken Invaders versions

  16. @FreeRyde:

     

    I assumed if you installed it for all users, which I just installed it for myself, then the logs would be located in all users. I have the AppData ones because that is where mine is installed because I just installed it for myself. If you run through the installer of ClamWin, you will see what I mean. They are correct as it is.

    Good point... I did indeed install to All Users.

  17. On my XP PC...

    %AllUsersProfile% is:

    C:\Documents and Settings\All Users

     

    %CommonAppData% is:

    C:\Documents and Settings\All Users\Application Data

     

    Maybe it's time I did an upgrade or time to go to bed. Probably both.

  18. [ClamWin*]
    LangSecRef=3021
    Detect=HKLM\SOFTWARE\ClamWin
    Default=False
    FileKey1=%AllUsersProfile%\.clamwin\log|*.*|REMOVESELF
    FileKey2=%AppData%\.clamwin\log|*.*|REMOVESELF
    FileKey3=%ProgramFiles%\ClamWin\bin|*.txt

    Looks good. Win 7 and XP must use differnet locations.

     

    But I don't understand your FileKey1 and 2 below. Do you have .txt files in either of those locations?

     

    [Clam Sentinel**]

    LangSecRef=3021

    Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{060FE577-1BDF-4330-ACCA-B6760AB07191}_is1

    Default=False

    FileKey1=%AllUsersProfile%\ClamSentinel|*.txt

    FileKey2=%AppData%\ClamSentinel|*.txt

    FileKey3=%ProgramFiles%\ClamSentinel|*.txt

     

    Ignore the 2 stars... don't remember who, but another member uses two instead of one to denote their own entries.

    I liked the idea and use it now also.

    It slipped through.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.