Jump to content

Coffee4Joe

Experienced Members
  • Posts

    247
  • Joined

  • Last visited

Posts posted by Coffee4Joe

  1. New

    the warning might need tweaking/rewording.

     

     

    [Windows 8 Sharing MFU*]
    DetectOS=6.2|
    LangSecRef=3025
    Detect=HKCU\Software\Microsoft\Windows
    Default=False
    Warning=This will remove the frequently shared list. e.g. email addresses that have been used to share. This does not remove the Apps listed under sharing.
    RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SharingMFU
  2. Edited FileKey12 (again)

    changed from nouser0000000000000001\120712-0049\DBStore\LogFiles\|*.Log"
    to nouser*\*-*\DBStore\LogFiles\|*.Log"

     

    Having it \*\*-*\DBStore\LogFiles\|*.Log makes the mail app forget mail passwords


    [Windows Communications Apps*]
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
    DetectFile=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
    Default=False
    FileKey1=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\AppCache|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCache|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCookies|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetHistory|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
    FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
    FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\PRICache|*.*
    FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*
    FileKey11=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE
    FileKey12=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\LiveComm\nouser*\*-*\DBStore\LogFiles\|*.Log
    RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory
    
  3. New

    [Reddit To Go!*]
    LangSecRef=3031
    DetectFile=%LocalAppData%\Packages\*.RedditToGo_*
    Default=False
    FileKey1=%LocalAppData%\Packages\*.RedditToGo_*\RoamingState|history.txt
    FileKey2=%LocalAppData%\Packages\*.RedditToGo_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
    FileKey3=%LocalAppData%\Packages\*.RedditToGo_*\AC\Microsoft\CryptnetUrlCache\MetaData*.*
    
  4. Also looks like in 8.1 what used to be in [Windows Photos*] are now in %AppData%Local\Packages\FileManager_cw5n1h2txyewy

     

     

    Added Detect2 & DetectFile2

    
    [WinJS*]
    LangSecRef=3031
    Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WinJS.1.0_8wekyb3d8bbwe
    Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WinJS.2.0_8wekyb3d8bbwe
    DetectFile1=%LocalAppData%\Packages\Microsoft.WinJS.1.0_8wekyb3d8bbwe
    DetectFile2=%LocalAppData%\Packages\Microsoft.WinJS.2.0_8wekyb3d8bbwe
    Default=False
    FileKey1=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\AppCache|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\INetCache|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\INetCookies|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\INetHistory|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
    FileKey7=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
    FileKey8=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey9=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\PRICache|*.*
    FileKey10=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Temp|*.*
    FileKey11=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\LocalState\Cache|*.*|RECURSE
    FileKey12=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\LocalState\navigationHistory|*.*|RECURSE
    FileKey13=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\TempState|*.*|RECURSE
    
    

    Added Detect2 & DetectFile2

    [Microsoft.VCLibs*]
    LangSecRef=3031
    Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.VCLibs.110.00_8wekyb3d8bbwe
    Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.VCLibs.120.00_8wekyb3d8bbwe
    DetectFile1=%LocalAppData%\Packages\Microsoft.VCLibs.110.00_8wekyb3d8bbwe
    DetectFile2=%LocalAppData%\Packages\Microsoft.VCLibs.120.00_8wekyb3d8bbwe
    Default=False
    FileKey1=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\AppCache|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\INetCache|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\INetCookies|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\INetHistory|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
    FileKey7=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
    FileKey8=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey9=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\PRICache|*.*
    FileKey10=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Temp|*.*
    FileKey11=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\LocalState\Cache|*.*|RECURSE
    FileKey12=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\LocalState\navigationHistory|*.*|RECURSE
    FileKey13=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\TempState|*.*|RECURSE
    
    
  5. un-checking [saved Search Folders*] [MS Search] & [MS Search More*] definitely solves it. I agree that 8/8.1 doesn't need [MS Search] & [MS Search More*] They spit event viewer errors before they regenerate. The files it removes don't seem to increase in size anyways. For me they stay at 64kb and 1024kb

  6. Applies on Windows 8.1 32-bit & 64-bit systems with a Microsoft Account (Skydrive enabled account).

    Is this what it's breaking?  With a local account it doesn't break anything right away but after a reboot Event viewers shows

    "The Windows Search Service is starting up and attempting to remove the old search index {Reason: Index Corruption}."

  7. they are sadly located in %AppData%\Roaming\Notepad++\config.xml so it'd remove settings if deleted.
    But if you open config.xml in windows notepad you can change it so it doesn't store recently opened and search phrases.

     

    near the bottom of config.xml look for these.

    nbMaxFindHistoryPath="0" 
    nbMaxFindHistoryFilter="0" 
    nbMaxFindHistoryFind="0" 
    nbMaxFindHistoryReplace="0"
    History nbMaxFile="0" 
    
  8. In Win 8.1 FileKey1 sometimes resets default open with apps (Music, Photo Viewer, Video, etc)

     

    Edit #1: I see it's been mentioned before, maybe adding a warning as this is useful for removing cached extentions

    Edit #2: is there a way to ExcludeKey for registry entries? Like "ExcludeKey1=Key1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi;.mp3;http; etc etc"

    [Cached File Extensions*]
    LangSecRef=3025
    Detect=HKCU\Software\Microsoft\Windows
    Default=False
    RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    RegKey2=HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts
    RegKey3=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    
    
  9. Thanks for the update

    New Entry

    [SkyDrive App Logs*]
    LangSecRef=3031
    DetectFile=%LocalAppData%\Microsoft\Windows\SkyDrive
    Default=False
    FileKey1=%LocalAppData%\Microsoft\Windows\SkyDrive\logs|*.*
    

    Edit: Had it with [skyDrive App*] made it it's own entry instead. 8.1 + Local account doesn't seem to have the "microsoft.microsoftskydrive_8wekyb3d8bbwe" locations

  10. Added FileKey11

    [bing Weather*]
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe
    DetectFile=%LocalAppData%\Packages\Microsoft.BingWeather_8wekyb3d8bbwe
    Default=False
    FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetCache|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetCookies|*.*|RECURSE
    FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetHistory|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
    FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
    FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
    FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*
    FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*
    FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp
    FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE
    FileKey13=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE
    FileKey14=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE
    RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory
    

     

    Added FileKey9

    [bing Maps More*]
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingMaps_8wekyb3d8bbwe
    DetectFile=%LocalAppData%\Packages\Microsoft.BingMaps_8wekyb3d8bbwe
    Default=False
    FileKey1=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\AppCache|*.*|RECURSE
    FileKey2=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
    FileKey3=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
    FileKey4=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
    FileKey5=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
    FileKey6=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\PRICache|*.*
    FileKey7=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\Temp|*.*
    FileKey8=%LocalAppData%\Packages\Microsoft.BingMaps*\LocalState\Bing.Maps|*.*|RECURSE
    FileKey9=%LocalAppData%/Packages\Microsoft.BingMaps_8wekyb3d8bbwe\LocalState\MapInstrumentation|*.*
    RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingMaps_8wekyb3d8bbwe\SearchHistory
    

     

     

    Added FileKey1

    [Windows 8 Search History*]
    DetectOS=6.2|
    LangSecRef=3025
    Detect=HKCU\Software\Microsoft\Windows
    Default=False
    RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SearchHistory
    FileKey1=%LocalAppData%\Microsoft\Windows\ConnectedSearch\History|*.*
    

     

    filekey1 Cleans the recent searches from the start screen

  11. place of interest %LocalAppData%\Microsoft\Windows\SkyDrive\logs

    I'm on a local account in 8.1 and never use skydrive. Could someone that uses an MS account & skydrive make sure removing those *.etl's doesn't break anything for them.

     

    edit: If the above is added to SkyDrive App*, DetectFile2=%LocalAppData%\Microsoft\Windows\SkyDrive will be needed

  12. Fixed missing backslash in Detect

     

    [bing Health and Fitness*]
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingHealthAndFitness_8wekyb3d8bbwe
    Default=False
    FileKey1=%LocalAppData%\Packages\Microsoft.BingHealthAndFitness_*\LocalState\Cache|*.*|RECURSE
    

  13. Modified

    Added FileKey5

     

    [Minecraft*]
    Section=Games
    DetectFile=%AppData%\.minecraft
    Default=False
    FileKey1=%AppData%\.minecraft|*.log;*.log.*
    FileKey2=%AppData%\.minecraft\crash-reports|*.*
    FileKey3=%AppData%\.minecraft\server|server.log
    FileKey4=%AppData%\.minecraft\stats|*.old
    FileKey5=%AppData%\.minecraft\logs|*.*

     

     

     

    Also two WIP that need more testing and/or if there's any more filekeys for them

    [bing Food and Drink*]
    LangSecRef=3031
    Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingFoodAndDrink_8wekyb3d8bbwe
    Default=False
    FileKey1=%LocalAppData%\Packages\Microsoft.BingFoodAndDrink_*\LocalState\Cache|*.*|RECURSE
    
    [bing Health and Fitness*]
    LangSecRef=3031
    Detect=HKCUSoftware\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingHealthAndFitness_8wekyb3d8bbwe
    Default=False
    FileKey1=%LocalAppData%\Packages\Microsoft.BingHealthAndFitness_*\LocalState\Cache|*.*|RECURSE
    

  14. That's what I did, start/stop trick. I actually downloaded it twice, once thru the store, had some driver issues once it installed. I decided to just go the the pc settings and full reset but was met with a "Install media to continue message". Then the second time with the iso from key trick.

  15. Did we decide not to include entries that deleted reg backups, only I notice there's an entry in the update that deletes all erunt reg backups (which on a side point seems completely pointless anyway - why install a program to make backups, then have a cleaner delete them all? :huh: )

    NERGAL presses the virtual like button

     

     

    This can either be removed entirely or just the .bak entry

    [NirSoft RegScanner Backups*]
    LangSecRef=3024
    Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NirSoft RegScanner
    Default=False
    Warning=This will remove all backups and reports made by RegScanner. If you backed up elsewhere these are safe to remove.
    FileKey1=%ProgramFiles%\NirSoft\RegScanner|report.html;*.bak
    

  16. Didn't know weather to post here or in the firefox addon thread.

    I tried blocking those IP ranges and it was hit or miss, after using the below addon & disabling dash youtube videos are finally loading right for me.

     

    YouTube's default option has Dash enabled, because it's buffering faster for people with a good internet connection.

    http://github.com/Ye...s#dash-playback

     

    and for the addon itself https://github.com/Y...TubeCenter/wiki

     

    (sorry if this has already been posted, couldn't find it doing a quick browse) :ph34r:

  17. New Entry

     

    [sketchUp Make 2013*]
    LangSecRef=3021
    Warning=This will clear your most recent list
    Detect=HKCU\Software\SketchUp
    Default=False
    RegKey1=HKCU\Software\SketchUp\SketchUp 2013\Recent File List
    

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.