; CCleaner - Application Cleaning file
[*Global]
Revision=2012
NextIDValue=2145
;
; WARNING - DO NOT EDIT THIS FILE ; If you would like to create custom entries then create a new file ; called winapp2.ini which follows the same format as this one. ; CCleaner will automatically pick up the new file. ; ; Copyright ?2004-2009 Piriform Ltd, All Rights Reserved. ; This file and it's contents may not be copied or distributed ; without the express permission of the author. ; ; Notes ; --------------------------------------- ; LangSecRef ; 3021 = Applications ; 3022 = Internet ; 3023 = Multimedia ; 3024 = Utilities ; 3025 = Windows ; 3026 = Firefox/Mozilla ; 3027 = Opera ; 3028 = Safari[*32bit Web Browser]
LangSecRef=3022
DetectFile=%ProgramFiles%\32BITWEB\32BW.exe
Default=False
FileKey1=%ProgramFiles%\32BITWEB\Data|LastURL.dat
FileKey2=%ProgramFiles%\32BITWEB\Data|LastURL.DA0[*3GP Video Converter]
LangSecRef=3023
Detect=HKCU\Software\ImTOO\3GP Video Converter
Default=False
RegKey1=HKCU\Software\ImTOO\3GP Video Converter\Settings|last_openpath
RegKey2=HKCU\Software\ImTOO\3GP Video Converter\Settings|OuputDir[*7-Zip]
LangSecRef=3024
Default=False
Detect=HKCU\SOFTWARE\7-ZIP
RegKey1=HKCU\SOFTWARE\7-ZIP\Compression\ArcHistory
RegKey2=HKCU\SOFTWARE\7-ZIP\Extraction\PathHistory
RegKey3=HKCU\Software\7-Zip\FM|CopyHistory
RegKey4=HKCU\Software\7-Zip\FM|FolderHistory
RegKey5=HKCU\Software\7-Zip\FM|PanelPath0[A-squared Free]
LangSecRef=3024
Detect=HKLM\Software\Emsi Software GmbH\a-squared Free
Default=False
FileKey1=%userprofile%\My Documents\a-squared\Reports|.*
FileKey2=%programfiles%\a-squared Free\Logs|.[*AI Roboform Search]
LangSecRef=3022
Detect=HKCU\Software\Siber Systems
Default=False
RegKey1=HKCU\Software\Siber Systems\RoboForm\Query-MRU[AOL AIM Messenger]
Default=False
DetectFile=%userprofile%\Application Data\acccore\caches\bart
FileKey1=%userprofile%\Application Data\acccore\caches\bart|.|RECURSE
fileKey2=%userprofile%\Local Settings\Application Data\AIM\Settings\aolbartcache|.*|RECURSE
LangSecRef=3022[*AOL Instant Messenger]
LangSecRef=3022
Detect=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion
Default=False
RegKey1=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent IM ScreenNames
RegKey2=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent ScreenNames
RegKey3=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\Users[*AVG Anti-Spyware]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\AVGAntiSpyware
Default=False
FileKey1=%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5|logfile.txt[AVG AntiVirus 8.0]
: Modified to handle AVG Temp folder
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|.
FileKey5=%allusersprofile%\Application Data\avg8\temp|*.tmp[AVG AntiVirus 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|.[AVG AntiVirus 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|.
FileKey5=%allusersprofile%\Application Data\avg8\Emc\Log|*.log[AVG AntiVirus 9.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg9
Default=False
FileKey1=%allusersprofile%\Application Data\avg9\Log|.log
FileKey2=%allusersprofile%\Application Data\avg9\scanlogs|.log
FileKey3=%allusersprofile%\Application Data\avg9\Log|.xml
FileKey4=%allusersprofile%\Application Data\avg9\update\backup|.
FileKey5=%allusersprofile%\Application Data\avg9\Emc\Log|*.log[*AVI Preview]
LangSecRef=3023
Detect=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit www.avipreview.com for more
Default=False
RegKey1=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit www.avipreview.com for more\Recent File List[*AVS Disc Creator (Logs)]
LangSecRef=3021
Detect=HKLM\Software\AVS\DiscCreator
Default=False
FileKey1=%windir%|coredw.log
FileKey2=%windir%|datawriter.log[Ace Utilities]
LangSecRef=3024
Detect=HKCU\Software\Acelogix\Ace Utilities
Default=False
FileKey1=%userprofile%\My Documents\Ace Utilities Backups|.reg[*AceHTML 5]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Visicom Media\AceHTML 5 Freeware
RegKey1=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last URLs
RegKey2=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Projects
RegKey3=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Open
RegKey4=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Files[Acronis True Image Home]
LangSecRef=3024
Detect=HKCU\Software\Acronis\TrueImageHome
Default=False
FileKey1=%allusersprofile%\Application Data\Acronis\TrueImage\Logs|.log[Acronis True Image]
LangSecRef=3024
Detect=HKCU\Software\Acronis\TrueImage
Default=False
FileKey1=%userprofile%\Application Data\Acronis\TrueImage\Logs|.log[*ActiveX and Class Issues]
LangSecRef=3501
LangRef=3603
Default=False
SpecialKey1=R_ACTIVEX[Ad-Aware SE Personal]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|.txt[Ad-Aware SE Plus]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|.txt[Ad-Aware SE Professional]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|.txt[*Adaptec’s Audio CD]
LangSecRef=3024
Detect=HKCU\Software\Adaptec
Default=False
RegKey1=HKCU\Software\Adaptec\AUDIO_CD_INFO[*Adobe Acrobat 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral\cRecentFiles[Adobe Acrobat 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.*|RECURSE[*Adobe Acrobat 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral\cRecentFiles[Adobe Acrobat 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.*|RECURSE[*Adobe Acrobat 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral\cRecentFiles[Adobe Acrobat 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.*|RECURSE[*Adobe Acrobat 8.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral\cRecentFiles[*Adobe Acrobat Reader 4.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\4.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile1
RegKey2=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile2
RegKey3=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile3
RegKey4=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile4[Adobe Acrobat Reader 4.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\4.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile1
RegKey2=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile2
RegKey3=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile3
RegKey4=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile4
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.*|RECURSE[*Adobe Acrobat Reader 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles[*Adobe Acrobat Reader 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral\cRecentFiles[Adobe Acrobat Reader 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\7.0\Cache\Search70|.*
FileKey2=%ProgramFiles%\Adobe\Acrobat 7.0\Reader|.bak
FileKey3=%ProgramFiles%\Adobe\Acrobat 7.0\ActiveX|.bak
FileKey4=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\plug_ins|.bak
FileKey5=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\Updater|.bak[*Adobe Flash Player]
LangSecRef=3023
Detect=HKCR\CLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}
Default=False
SpecialKey1=N_FLASH_COOKIES[*Adobe Illustrator CS4]
LangSecRef=3021
Detect=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator
Default=False
RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator\FileList[*Adobe ImageReady 7.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\ImageReady 7.0
RegKey1=HKCU\Software\Adobe\ImageReady 7.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 7.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 7.0\Preferences\RecentFiles[*Adobe ImageReady CS]
LangSecRef=3021
Detect=HKCU\Software\Adobe\ImageReady 8.0
Default=False
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles[Adobe ImageReady CS]
LangSecRef=3021
Detect=HKCU\Software\Adobe\ImageReady 8.0
Default=False
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.*|RECURSE[*Adobe Photoshop 5.5]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\5.5
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\5.5\VisitedDirs[Adobe Photoshop 5.5]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\5.5
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\5.5\VisitedDirs
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.*|RECURSE[*Adobe Photoshop 6.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\6.0
RegKey1=HKCU\Software\Adobe\Photoshop\6.0\VisitedDirs[*Adobe Photoshop 7.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\7.0
RegKey1=HKCU\Software\Adobe\Photoshop\7.0\VisitedDirs[Adobe Photoshop CS2]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\9.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\9.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
FileKey1=%appdata%\Adobe\CameraRaw\Cache|.*[*Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs[*Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList[Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.*|RECURSE[*Adobe Photoshop CS4]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\11.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\11.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList[*Adobe Photoshop CS]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\8.0
RegKey1=HKCU\Software\Adobe\Photoshop\8.0\VisitedDirs[Adobe Reader 8.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\8.0\Cache\Search80|.*[Adobe Reader 8]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5|.log
FileKey2=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.|RECURSE[Adobe Reader 9.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\9.0\Cache\Search90|.*[Adobe Reader 9]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\9.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Updater6|.log
FileKey2=%LocalAppData%\Adobe\Updater6\Install|.|RECURSE[*Advanced Searchbar]
LangSecRef=3022
Detect= HKCU\Software\Advanced Searchbar\Toolbar
Default=False
RegKey1=HKCU\Software\Advanced Searchbar\Toolbar\Historysearchbox1[Ahead Nero Burning Rom 8]
LangSecRef=3021
Detect=HKCU\Software\Nero\Nero8
Default=False
RegKey1=HKCU\Software\Nero\Nero8\Cover Designer\Recent File List
RegKey2=HKCU\Software\Nero\Nero8\Nero - Burning Rom\Recent File List
FileKey1=%userprofile%\Application Data\Nero\Nero8\Nero Burning ROM|.log[*Ahead Nero PhotoSnap]
LangSecRef=3021
Detect=HKCU\Software\ahead\Nero PhotoSnap
Default=False
RegKey1=HKCU\Software\ahead\Nero PhotoSnap\Recent File List[*Ahead NeroSearch]
LangSecRef=3021
Detect=HKCU\Software\Ahead\NeroSearch
Default=False
RegKey1=HKCU\Software\Ahead\NeroSearch\NeroSavedSearches\SavedSearches[*Ahead NeroVision 2.0]
LangSecRef=3021
Detect=HKCU\Software\ahead\NeroVision\2.0
Default=False
RegKey1=HKCU\Software\ahead\NeroVision\2.0\RecentFiles[*AkelPad]
LangSecRef=3024
Detect=HKCU\Software\Akelsoft\AkelPad
Default=False
RegKey1=HKCU\Software\Akelsoft\AkelPad\Recent
RegKey2=HKCU\Software\Akelsoft\AkelPad\Search[*Alcohol 120%]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Alcohol Soft\Alcohol 120%
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 120%\MountedMRU[*Alcohol 52%]
LangSecRef=3023
Detect=HKCU\Software\Alcohol Soft
Default=False
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 52%\Images
RegKey2=HKCU\Software\Alcohol Soft\Alcohol 52%\MountedMRU\0
RegKey3=HKCU\Software\Alcohol Soft\Alcohol 52%\Basic|Image File Path
RegKey4=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageFilePath
RegKey5=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageName[Always Right]
LangSecRef=3024
Detect=HKCU\Software\AlwaysRight
Default=False
FileKey1=%ProgramFiles%\Superhunter\Always Right\FileBackup|.*
FileKey2=%ProgramFiles%\Superhunter\Always Right\RegBackup|.[America Online 9.1]
Default=False
DetectFile=%allusersprofile%\Application Data\AOL\C_AOL 9.1
FileKey1=%allusersprofile%\Application Data\AOL\C_AOL 9.1\bart|.|RECURSE
FileKey2=%allusersprofile%\Application Data\AOL\C_AOL 9.1\spool|.*|RECURSE
LangSecRef=3021[Amsn - Display Pictures]
LangSecRef=3021
Default=False
Detect=HKCU\Software\aMSN
FileKey1=%userprofile%\amsn\displaypic\cache|.*[*Anim8or]
LangSecRef=3021
Detect=HKCU\Software\Silicon Valley Software\Anim8or
Default=False
RegKey1=HKCU\Software\Silicon Valley Software\Anim8or|File1
RegKey2=HKCU\Software\Silicon Valley Software\Anim8or|File2
RegKey3=HKCU\Software\Silicon Valley Software\Anim8or|File3
RegKey4=HKCU\Software\Silicon Valley Software\Anim8or|File4[AntiVir Desktop]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Avira\AntiVir Desktop
Default=False
FileKey1=%commonappdata%\Avira\AntiVir Desktop\FAILSAVE|.*
FileKey2=%commonappdata%\Avira\AntiVir Desktop\INFECTED|.
FileKey3=%commonappdata%\Avira\AntiVir Desktop\LOGFILES|.
FileKey4=%commonappdata%\Avira\AntiVir Desktop\SYSSAVE|.
FileKey5=%commonappdata%\Avira\AntiVir Desktop\TEMP|.
FileKey6=%ProgramFiles%\Avira\AntiVir Desktop|.old
FileKey7=%ProgramFiles%\Avira\AntiVir Desktop|.tmp
FileKey8=%ProgramFiles%\Avira\AntiVir Desktop\FAILSAFE|*.tmp[AntiVir Personal 8]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Avira\AntiVir PersonalEdition Classic
Default=False
FileKey1=%commonappdata%\Avira\AntiVir PersonalEdition Classic\BACKUP\FAILSAFE|.tmp
FileKey2=%commonappdata%\Avira\AntiVir PersonalEdition Classic\LOGFILES|.log
FileKey3=%ProgramFiles%\Avira\AntiVir PersonalEdition Classic|.tmp
FileKey4=%ProgramFiles%\Avira\AntiVir PersonalEdition Classic\FAILSAFE|*.tmp[*Application Paths]
LangSecRef=3501
LangRef=3606
Default=False
SpecialKey1=R_APP_PATHS[*Applications]
LangSecRef=3501
LangRef=3604
Default=False
SpecialKey1=R_APP_OPENWITH[*Arasan Chess]
LangSecRef=3024
Detect=HKCU\Software\Arasan\Arasan
Default=False
RegKey1=HKCU\Software\Arasan\Arasan\Recent File List[Ashampoo Burning Studio 7]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Burn Image Project\AddDialog
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Dump Image Project\DumpImage
RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Unknown Project\AddDialog
FileKey1=%appdata%\Ashampoo\Ashampoo Burning Studio 2007\Logs|.*[Ashampoo Burning Studio 9]
LangSecRef=3024
Detect=HKLM\Software\Ashampoo\Ashampoo Burning Studio 2009
Default=False
FileKey1=%appdata%\Ashampoo\Ashampoo Burning Studio 2009|backupmetainfo.xml
FileKey2=%appdata%\Ashampoo\Ashampoo Burning Studio 2009\Logs|.xml
FileKey3=%appdata%\Ashampoo\Logs|*.txt[*Ashampoo Burning Studio 5]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\DumpImage
RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Unknown Project\AddDialog[Ashampoo Burning Studio 6 Free (Logs)]
LangSecRef=3023
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6
Default=False
FileKey1=%userprofile%\Application Data\Ashampoo\Ashampoo Burning Studio 6 Free\Logs|.*[*Ashampoo Burning Studio 6]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Unknown Project\AddDialog[*Ashampoo Burning Studio 7]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Unknown Project\AddDialog[*Ashampoo Burning Studio 8]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8\Data Disc Project\AddDialog[*Audacity]
LangSecRef=3023
Detect=HKCU\Software\Audacity
Default=False
RegKey1=HKCU\Software\Audacity\Audacity\RecentFiles[AusLogics Disk Defrag]
LangSecRef=3024
Detect=HKCU\Software\AusLogics\Disk Defrag\1.x
Default=False
FileKey1=%ProgramFiles%\AusLogics Disk Defrag\reports|.*[AusLogics Registry Defrag]
LangSecRef=3024
Detect=HKCU\Software\AusLogics\Registry Defrag\4.x
Default=False
FileKey1=%ProgramFiles%\AusLogics Registry Defrag\Data\RegistryDefrag|.*
FileKey2=%ProgramFiles%\AusLogics Registry Defrag\Reports\Registry Defrag|.[Auslogics Free Utilities]
LangSecRef=3024
Detect=HKCU\Software\Auslogics
Default=False
FileKey1=%appdata%\Auslogics\Disk Defrag\Reports|.*
FileKey2=%appdata%\Auslogics\Registry Defrag\Logs|.
FileKey3=%appdata%\Auslogics\Registry Defrag\Reports|.
FileKey4=%appdata%\Auslogics\System Information\Reports|.[AutoIt3]
LangSecRef=3021
Detect=HKCU\Software\AutoIt v3
Default=False
RegKey1=HKCU\Software\AutoIt v3\Aut2Exe|LastExeDir
RegKey2=HKCU\Software\AutoIt v3\Aut2Exe|LastIcon
RegKey3=HKCU\Software\AutoIt v3\Aut2Exe|LastIconDir
RegKey4=HKCU\Software\AutoIt v3\Aut2Exe|LastScriptDir
FileKey1=%userprofile%|SciTE.[*Autocomplete Form History]
LangSecRef=3001
LangRef=3106
WarningRef=3202
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
SpecialKey1=N_INT_AUTOCOMPLETE[*Avant Browser]
LangSecRef=3022
DetectFile=%ProgramFiles%\Avant Browser\avant.exe
Default=False
FileKey1=%appdata%\Avant Browser|keywords.dat
FileKey2=%appdata%\Avant Browser|pages.dat
FileKey3=%appdata%\Avant Browser|recents.dat
FileKey4=%appdata%\Avant Browser|reopen.dat[Avast Antivirus]
LangSecRef=3024
Detect=HKCU\Software\ALWIL Software\Avast
Default=False
FileKey1=%ProgramFiles%\Alwil Software\Avast4\DATA\report|avast.xsl
FileKey2=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Resident protection.txt
FileKey3=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Simple user interface.txt
FileKey4=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Simple user interface.xml
FileKey5=%ProgramFiles%\Alwil Software\Avast4\DATA\log|.[Avi-Mux GUI]
LangSecRef=3023
DetectFile=%ProgramFiles%\AVIMuxGUI\AVIMux_GUI.exe
Default=False
FileKey1=%ProgramFiles%\AVIMuxGUI|AVI-Mux GUI - Logfile
FileKey2=%ProgramFiles%\AVIMuxGUI|*.dmp[*Avira RootKit Detection]
LangSecRef=3024
DetectFile=%ProgramFiles%\Avira GmbH\Avira RootKit Detection\avirarkd.exe
Default=False
FileKey1=%ProgramFiles%\Avira GmbH\Avira RootKit Detection|avirarkd.log[Axialis IconWorkshop]
LangSecRef=3023
Detect=HKCU\Software\Axialis\IconWorkshop
Default=False
RegKey1=HKCU\Software\Axialis\IconWorkshop\Recent File List
RegKey2=HKCU\Software\Axialis\IconWorkshop\CoolBarList
FileKey1=%appdata%\Axialis\Temporary Preview Files|.*|RECURSE[Azureus]
LangSecRef=3022
DetectFile=%userprofile%\Application Data\Azureus.lock
Default=False
FileKey1=%userprofile%\Application Data\Azureus\tmp|.*
FileKey2=%userprofile%\Application Data\Azureus|.bak
FileKey3=%userprofile%\Application Data\Azureus|.log
FileKey4=%userprofile%\Application Data\Azureus\active|.bak
FileKey5=%userprofile%\Application Data\Azureus\plugins\advancedstatistics|.txt
FileKey6=%userprofile%\Application Data\Azureus\plugins\progressbar|*.txt[*BSPlayer]
LangSecRef=3023
Detect=HKCU\Software\BST\bsplayer
Default=False
RegKey1=HKCU\Software\BST\bsplayer|File0
RegKey2=HKCU\Software\BST\bsplayer|File1
RegKey3=HKCU\Software\BST\bsplayer|File2
RegKey4=HKCU\Software\BST\bsplayer|File3
RegKey5=HKCU\Software\BST\bsplayer|File4
RegKey6=HKCU\Software\BST\bsplayer|File5
RegKey7=HKCU\Software\BST\bsplayer|File6
RegKey8=HKCU\Software\BST\bsplayer|File7
RegKey9=HKCU\Software\BST\bsplayer|File8
RegKey10=HKCU\Software\BST\bsplayer|File9[*Babylon]
LangSecRef=3024
Detect=HKCU\Software\Babylon\Babylon Translator\UserInfo
Default=False
RegKey1=HKCU\Software\Babylon\Babylon Translator\UserInfo\History[BitDefender 9]
LangSecRef=3024
Detect=HKLM\Software\Softwin\BitDefender Antivirus
Default=False
FileKey1=%ProgramFiles%\Softwin\BitDefender9\Logs|.*[BitTorrent]
LangSecRef=3022
DetectFile=%ProgramFiles%\BitTorrent\bittorrent.exe
Default=False
FileKey1=%userprofile%\Application Data\BitTorrent\incomplete|.*[Boinc]
LangSecRef=3024
DetectFile=%ProgramFiles%\BOINC\boinc.exe
Default=False
FileKey1=%ProgramFiles%\BOINC|stdout.*
FileKey2=%ProgramFiles%\BOINC|stderr*.*[*Borland C++ Builder 5.0]
LangSecRef=3024
Detect=HKCU\Software\Borland\C++Builder\5.0
Default=False
RegKey1=HKCU\Software\Borland\C++Builder\5.0\Closed Files
RegKey2=HKCU\Software\Borland\C++Builder\5.0\Closed Projects
RegKey3=HKCU\Software\Borland\C++Builder\5.0\Session[*Borland Developer Studio 2006]
LangSecRef=3024
Detect=HKCU\Software\Borland\BDS\4.0
Default=False
RegKey1=HKCU\Software\Borland\BDS\4.0\Closed Files
RegKey2=HKCU\Software\Borland\BDS\4.0\Closed Projects
KegKey3=HKCU\Software\Borland\BDS\4.0\Session[CA Anti-Virus]
LangSecRef=3024
Default=False
Detect=HKLM\SOFTWARE\ComputerAssociates\Anti-Virus
FileKey1=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|.log
FileKey2=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|log.txt
FileKey3=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ArcTemp|.tmp
FileKey4=%commonappdata%\CA\Consumer\AV|.tmp|RECURSE
FileKey5=%commonappdata%\CA\Consumer\AV|.txt|RECURSE
FileKey6=%commonappdata%\CA\Consumer\CCube|.tmp|RECURSE
FileKey7=%commonappdata%\CA\Consumer\CCube|.txt|RECURSE
FileKey8=%commonappdata%\CA\Consumer\ISS\FeedStore|.txt|RECURSE
FileKey9=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\ArcTemp|.*
FileKey10=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\tmp|.[CDex]
LangSecRef=3024
Detect=HKLM\SOFTWARE\CDex
Default=False
FileKey1=%userprofile%\My Documents\My Music\CDDB|.txt[*Centarsia]
LangSecRef=3021
Detect=HKCU\Software\Centarsia
Default=False
RegKey1=HKCU\Software\Centarsia|RecentImage0
RegKey2=HKCU\Software\Centarsia|RecentImage1
RegKey3=HKCU\Software\Centarsia|RecentImage2
RegKey4=HKCU\Software\Centarsia|RecentImage3
RegKey5=HKCU\Software\Centarsia|RecentImage4
RegKey6=HKCU\Software\Centarsia|RecentImage5
RegKey7=HKCU\Software\Centarsia|RecentImage6[Chkdsk File Fragments]
LangSecRef=3003
LangRef=3144
Default=False
FileKey1=%SystemDrive%|File.chk[ClamWin]
LangSecRef=3024
Detect=HKCU\Software\ClamWin
Default=False
FileKey1=%allusersprofile%.clamwin\log|.*
FileKey2=%userprofile%.clamwin\log|.
FileKey3=%windir%\All Users.clamwin\log|.[*Clipboard]
LangSecRef=3003
LangRef=3148
Default=False
SpecialKey1=N_TEMP_CLIPBOARD[*CloneCD]
LangSecRef=3021
Detect=HKLM\Software\SlySoft\CloneCD
Default=False
RegKey1=HKCU\Software\SlySoft\CloneCD\Settings|ImageFileName[*CoffeeCup GIF Animator]
LangSecRef=3024
Detect=HKCU\Software\CoffeeCup Software\GIF Animator
Default=False
RegKey1=HKCU\Software\CoffeeCup Software\GIF Animator\Settings\MRU[*Compare It!]
LangSecRef=3021
Detect=HKCU\Software\grigsoft.com\Compare It!
Default=False
RegKey1=HKCU\Software\grigsoft.com\Compare It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Compare It!\dirs
RegKey3=HKCU\Software\grigsoft.com\Compare It!\options|Recent0
RegKey4=HKCU\Software\grigsoft.com\Compare It!\options|Recent1
RegKey5=HKCU\Software\grigsoft.com\Compare It!\options|Recent2
RegKey6=HKCU\Software\grigsoft.com\Compare It!\options|Recent3
RegKey7=HKCU\Software\grigsoft.com\Compare It!\options|Recent4
RegKey8=HKCU\Software\grigsoft.com\Compare It!\options|Recent5
RegKey9=HKCU\Software\grigsoft.com\Compare It!\options|Recent6
RegKey10=HKCU\Software\grigsoft.com\Compare It!\options|Recent7
RegKey11=HKCU\Software\grigsoft.com\Compare It!\options|Recent8
RegKey12=HKCU\Software\grigsoft.com\Compare It!\options|Recent9
RegKey13=HKCU\Software\grigsoft.com\Compare It!\options|Recent10[*ConTEXT]
LangSecRef=3021
Detect=HKCU\Software\Eden\ConTEXT
Default=False
Regkey1=HKCU\Software\Eden\ConTEXT\FileHistory
Regkey2=HKCU\Software\Eden\ConTEXT\FindHistory[Config.msi Folder]
LangSecRef=3025
Default=False
DetectFile=%windir%\system32\msiexec.exe
FileKey1=%systemdrive%\Config.msi|.*|RECURSE[ConvertXToDVD]
LangSecRef=3023
Detect=HKCU\Software\VSO\ConvertXToDVD
Default=False
FileKey1=%userprofile%\Application Data\Vso|.log[*Cookies]
LangSecRef=3001
LangRef=3102
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_COOKIES[*Copernic Desktop Search]
LangSecRef=3021
Detect=HKCU\Software\Copernic\DesktopSearch2
Default=False
RegKey1=HKCU\Software\Copernic\DesktopSearch2\Config\SearchHistory[CounterSpy]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Sunbelt Software\CounterSpy
Default=False
FileKey1=%allusersprofile%\Application Data\Sunbelt Software\CounterSpy\Logs|.*[*Creative Pro Proteus VX]
LangSecRef=3023
Detect=HKCU\Software\Creative Professional\Proteus VX
Default=False
RegKey1=HKCU\Software\Creative Professional\Proteus VX VSTi\Recent File List[Custom File Deletion]
LangSecRef=3024
FileKey1=%allusersprofile%\DRM\Cache|.|recurse
FileKey2=%userprofile%\Application Data\Microsoft\Outlook Express\News|cleanup.log
FileKey3=%userprofile%\Cookies|.|recurse
FileKey4=%userprofile%\Local Settings\History\History.IE5|.|recurse
FileKey5=%userprofile%\Local Settings\Temporary Internet Files\Content.IE5|.|recurse
FileKey6=%userprofile%\Local Settings\Temp|.|recurse
FileKey7=%userprofile%\UserData|.|recurse
FileKey8=%windir%\Prefetch|.pf|recurse
FileKey9=%windir%\system32\config\systemprofile\Cookies|.|recurse
FileKey10=%windir%\system32\config\systemprofile\Local Settings\History\History.IE5|.|recurse
FileKey11=%windir%\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5|.|recurse
FileKey12=%windir%\Temp|.|recurse
FileKey13=C:\Documents and Settings\LocalService\Cookies|.|recurse
FileKey14=C:\Documents and Settings\LocalService\Local Settings\History\History.IE5|.|recurse
FileKey15=C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5|.|recurse[*Custom Folders]
LangSecRef=3004
LangRef=3129
SpecialKey1=N_EX_CUSTOMFOLDERS[CuteFTP Home 7.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Home
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\7.0\Cache|.|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\7.0\CacheThumbs|.*|RECURSE[CuteFTP Home 8.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Home
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\8.0\Cache|.|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\8.0\CacheThumbs|.*|RECURSE[CuteFTP Pro 7.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Professional
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\Cache|.|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\CacheThumbs|.*|RECURSE[CuteFTP Pro 8.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Professional
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\Cache|.|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\CacheThumbs|.*|RECURSE[*CuteHTML 2.3]
LangSecRef=3024
Detect=HKCU\Software\GlobalSCAPE\CuteHTML\2.3
Default=False
RegKey1=HKCU\Software\GlobalSCAPE\CuteHTML\2.3\Recent File List[DC++]
LangSecRef=3022
DetectFile=%ProgramFiles%\DC++\DCPlusPlus.exe
Default=False
FileKey1=%ProgramFiles%\DC++|files.xml.bz2
FileKey2=%ProgramFiles%\DC++\FileLists|.*
FileKey3=%ProgramFiles%\DC++\Logs|.[DU meter]
LangSecRef=3022
Detect=HKCU\SOFTWARE\Hagel\DU Meter
Default=False
FileKey1=%allusersprofile%\Application Data\Hagel Technologies\DU Meter|.csv[DVD Shrink (Analysis Results)]
LangSecRef=3023
Detect=HKCU\Software\DVD Shrink
Default=False
FileKey1=%allusersprofile%\Application Data\DVD Shrink|.*[*DVD Shrink]
LangSecRef=3023
Default=False
Detect=HKCU\Software\DVD Shrink
RegKey1=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent Targets
RegKey2=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent File List
RegKey3=HKCU\Software\DVD Shrink\DVDSHRINK103\TargetFiles
RegKey4=HKCU\Software\DVD Shrink\DVDSHRINK103\SourceFolders[DVDx]
LangSecRef=3023
Detect=HKCU\Software\DVDx
Default=False
RegKey1=HKCU\Software\DVDx\LastDir
RegKey2=HKCU\Software\DVDx\LastOutput
FileKey1=%ProgramFiles%\DVDx|.tmp[*Delete Index.dat files]
LangSecRef=3001
LangRef=3105
WarningRef=3201
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_INDEXDAT[*Dependency Walker]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Dependency Walker
Default=False
RegKey1=HKCU\Software\Microsoft\Dependency Walker\Recent File List[*Desktop Shortcuts]
LangSecRef=3003
LangRef=3613
Default=False
SpecialKey1=F_DESKTOP[DivX Movies Cache]
LangSecRef=3023
Detect=HKLM\Software\DivXNetworks
Default=False
FileKey1=%userprofile%\My Documents\My Videos\DivX Movies|.*|RECURSE
RegKey1=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry1
RegKey2=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry2
RegKey3=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry3
RegKey4=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry4
RegKey5=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry5
RegKey6=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry6[*Dogpile Toolbar]
LangSecRef=3022
Detect=HCKU\Software\Infospace\DogpileToolbar
Default=False
RegKey1=HCKU\Software\Infospace\DogpileToolbar\History|1-terms[Download Accelerator Plus]
LangSecRef=3022
Detect=HKCU\Software\SpeedBit\Download Accelerator
Default=False
RegKey1=HKLM\SOFTWARE\SpeedBit\Download Accelerator\FileList
RegKey2=HKCU\Software\SpeedBit\Download Accelerator\HistoryCombo
RegKey3=HKCU\Software\SpeedBit\Download Accelerator\ADS\SecondMedia
FileKey1=%ProgramFiles%\DAP\Temp|.*
FileKey2=%ProgramFiles%\DAP\Ads|.
FileKey3=%ProgramFiles%\DAP\Log|.[Driver Cleaner Pro]
LangSecRef=3024
DetectFile=%ProgramFiles%\Driver Cleaner Pro\DCleaner.exe
Default=False
FileKey1=%ProgramFiles%\Driver Cleaner Pro\Log|.log[*Dup Detector]
LangSecRef=3023
Detect=HKCU\Software\Prismatic Software\PhotoBatch
Default=False
RegKey1=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastBatFile
RegKey2=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastFold
RegKey3=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSecFold
RegKey4=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSingleFold[ESPN Motion Advertisements]
LangSecRef=3023
Detect=HKCU\SOFTWARE\Disney\DIGStream
Default=False
FileKey1=%allusersprofile%\Application Data\DIGStream\ESPNMotion|ad_.wmv
FileKey2=%allusersprofile%\Application Data\DIGStream\ESPNMotion|promo.wmv
FileKey3=%allusersprofile%\Application Data\DIGStream\ESPNMotion|commercial.wmv
FileKey4=%allusersprofile%\Application Data\DIGStream\ESPNMotion|motionbumper.wmv[ESPN Motion]
LangSecRef=3023
Detect=HKCU\SOFTWARE\Disney\DIGStream
Default=False
FileKey1=%allusersprofile%\Application Data\DIGStream\ESPNMotion|.wmv
FileKey2=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*.tmp[*Easy CD-DA Extractor]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8
RegKey1=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k80
RegKey2=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k81
RegKey3=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k8c
RegKey4=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k91
RegKey5=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k92
RegKey5=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k92[Effective File Search]
LangSecRef=3021
DetectFile=%ProgramFiles%\efs\search.exe
Default=False
FileKey1=%ProgramFiles%\efs|cblist.dat[*EmEditor]
LangSecRef=3024
Detect=HKCU\Software\EmSoft\EmEditor v3
Default=False
RegKey1=HKCU\Software\EmSoft\EmEditor v3\Recent File List
RegKey2=HKCU\Software\EmSoft\EmEditor v3\Recent Folder List
RegKey3=HKCU\Software\EmSoft\EmEditor v3\Recent Font List[*Empty Recycle Bin]
LangSecRef=3003
LangRef=3141
Default=False
SpecialKey1=N_TEMP_RECYCLEBIN[*Eraser (Log)]
LangSecRef=3024
Detect=HKCU\Software\Heidi Computers Ltd\Eraser\5.5
Default=False
FileKey1=%ProgramFiles%\Eraser|schedlog.txt[*Essential NetTools 3]
LangSecRef=3022
Detect=HKCU\Software\ENT3
Default=False
RegKey1=HKCU\Software\ENT3\Recent[*Ewido Anti-Malware (Log)]
LangSecRef=3024
Detect=HKLM\Software\ewido
Default=False
FileKey1=%ProgramFiles%\Ewido\Security Suite|logfile.txt
FileKey2=%ProgramFiles%\Ewido Anti-Malware|logfile.txt[*ExamDiff Pro]
LangSecRef=3024
Detect=HKCU\Software\PrestoSoft\ExamDiff Pro
Default=False
RegKey1=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Left Files
RegKey2=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Right Files
RegKey3=HCKU\Software\PrestoSoft\ExamDiff Pro\Settings|File 1
RegKey4=HCKU\Software\PrestoSoft\ExamDiff Pro\Settings|File 2[*ExamDiff]
LangSecRef=3024
Detect=HKCU\Software\PrestoSoft\ExamDiff
Default=False
RegKey1=HKCU\Software\PrestoSoft\ExamDiff\Recent Left Files
RegKey2=HKCU\Software\PrestoSoft\ExamDiff\Recent Right Files
RegKey3=HCKU\Software\PrestoSoft\ExamDiff\Settings|File 1
RegKey4=HCKU\Software\PrestoSoft\ExamDiff\Settings|File 2[*Excel Viewer]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files[ExifPro]
LangSecRef=3023
Detect=HKCU\Software\MKowalski\ExifPro
Default=False
RegKey1=HKCU\Software\MKowalski\ExifPro\1.0\RecentPaths
RegKey2=HKCU\Software\MKowalski\ExifPro\1.0\ResizeDlg\RecentDestPaths
RegKey3=HKCU\Software\MKowalski\ExifPro\1.0\HTMLAlbumGen\RecentDestPaths
RegKey4=HKCU\Software\MKowalski\ExifPro\1.0\Browser\View 0|LastPath
FileKey1=%allusersprofile%\Application Data\MiK\ExifPro|Cache[*Exifer]
LangSecRef=3021
Detect=HKCU\Software\Exifer
Default=False
RegKey1=HKCU\Software\Exifer\Browse\History[*FARManager]
LangSecRef=3021
Detect=HKCU\Software\Far
Default=False
RegKey1=HKCU\Software\Far\SavedDialogHistory
RegKey2=HKCU\Software\Far\SavedFolderHistory
RegKey3=HKCU\Software\Far\SavedHistory
RegKey4=HKCU\Software\Far\SavedViewHistory[*FTP Accounts]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Ftp
Default=False
RegKey1=HKCU\Software\Microsoft\Ftp\Accounts[*FeedDemon]
LangSecRef=3022
Detect=HKCU\Software\Bradbury\FeedDemon\1.0
Default=False
RegKey1=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TypedURLs
RegKey2=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TabbedBrowserUrls[*FileLocator Pro]
LangSecRef=3024
Detect=HKCU\Software\Mythicsoft\FileLocatorPro
Default=False
RegKey1=HKCU\Software\Mythicsoft\FileLocatorPro\RecentContains
RegKey2=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFileName
RegKey3=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFolders[*FlashFXP]
LangSecRef=3022
DetectFile=%ProgramFiles%\FlashFXP\flashfxp.exe
Default=False
FileKey1=%ProgramFiles%\FlashFXP|quick.dat[FlashGet]
LangSecRef=3022
Detect=HKCU\SOFTWARE\JetCar\JetCar
Default=False
RegKey1=HKCU\SOFTWARE\JetCar\JetCar\DownDir
RegKey2=HKCU\SOFTWARE\JetCar\JetCar\Recent File List
RegKey3=HKCU\SOFTWARE\JetCar\JetCar\SelFolder
FileKey1=%ProgramFiles%\FlashGet|Default.jcd.bak
FileKey2=%ProgramFiles%\FlashGet|Default.bk
FileKey3=%ProgramFiles%\FlashGet\Torrent|.[FlashGet]
LangSecRef=3022
Detect=HKCU\Software\JetCar
Default=False
RegKey1=HKCU\Software\JetCar\JetCar|Recent File List
FileKey1=%programfiles%\FlashGet|Default.bk
FileKey2=%programfiles%\FlashGet|Default.jcd
FileKey3=%programfiles%\FlashGet|Default.jcd.bak[*Fonts]
LangSecRef=3501
LangRef=3605
Default=False
SpecialKey1=R_FONTS[*Foobar2000 (Crash Log)]
LangSecRef=3023
Detect=HKLM\Software\foobar2000
Default=False
FileKey1=%programfiles%\foobar2000|failure.txt[*Forward Observer]
LangSecRef=3021
DetectFile=%Program Files%\AAForwardObserver\AAForwardObserver.exe
Default=False
FileKey1=%Program Files%\AAForwardObserver|FO.log[*Foxit PDF Editor]
LangSecRef=3021
DetectFile=%ProgramFiles%\Foxit Software\PDF Editor\PDFEdit.exe
Default=False
RegKey1=HKCU\Software\Foxit Software Company\Foxit PDF Editor|Recent File List[*Foxit Reader]
LangSecRef=3021
Detect=HKCU\Software\Foxit Software\Foxit Reader
Default=False
RegKey1=HKCU\Software\Foxit Software\Foxit Reader\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit Reader\History[Free Download Manager]
LangSecRef=3022
DetectFile=%ProgramFiles%\Free Download Manager\fdm.exe
Default=False
RegKey1=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings\Find",“What
RegKey2=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings\View”,"LastDldMoveToFolder
FileKey1=%userprofile%\Application Data\Free Download Manager|downloads.sav
FileKey2=%userprofile%\Application Data\Free Download Manager|uploads.1.sav
FileKey3=%userprofile%\Application Data\Free Download Manager|dlmgrsi.sav
FileKey4=%userprofile%\Application Data\Free Download Manager|downloads.his.sav
FileKey5=%userprofile%\Application Data\Free Download Manager|history.sav
FileKey6=%userprofile%\Application Data\Free Download Manager|sites.sav
FileKey7=%userprofile%\Application Data\Free Download Manager|spider.sav
FileKey8=%userprofile%\Application Data\Free Download Manager|schedules.sav
FileKey9=%userprofile%\Application Data\Free Download Manager|mctasks.sav
FileKey10=%userprofile%\Application Data\Free Download Manager|.bak[Free Registry Defrag]
LangSecRef=3024
Detect=HKCU\Software\Local AppWizard-Generated Applications\RegDefrag
Default=False
FileKey1=%WinDir%$regcmp$|.*[*FreshDownload]
LangSecRef=3022
Detect=HKCU\Software\FreshDevices\FreshDownload
Default=False
RegKey1=HKCU\Software\FreshDevices\FreshDownload\History[*FrostWire]
LangSecRef=3022
DetectFile=%ProgramFiles%\FrostWire\FrostWire.exe
Default=False
FileKey1=%userprofile%\Application Data\FrostWire|fileurns.cache
FileKey2=%userprofile%\Application Data\FrostWire|createtimes.cache
FileKey3=%userprofile%\Application Data\FrostWire|responses.cache
FileKey4=%userprofile%\Application Data\FrostWire|ttree.cache
FileKey5=%userprofile%\Application Data\FrostWire|gnutella.net
FileKey6=%userprofile%\Application Data\FrostWire|ttroot.cache
FileKey7=%userprofile%\Application Data\FrostWire|fileurns.bak
FileKey8=%userprofile%\Application Data\FrostWire|checkandupdate.txt[*GIANT AntiSpyware]
LangSecRef=3024
DetectFile=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware\GIANTAntiSpywareMain.exe
Default=False
FileKey1=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|errors.log
FileKey2=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|tracksEraser.log
FileKey3=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|cleaner.log[GIMP]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Classes\GIMP-2.0-gbr\shell
filekey1=%userprofile%.thumbnails\normal|.*
filekey2=%userprofile%.gimp-2.4|documents[*GSpot]
LangSecRef=3024
Detect=HKCU\Software\GSpot Appliance Corp
Default=False
RegKey1=HKCU\Software\GSpot Appliance Corp\GSpot\v2.6 Settings|LastMediaFile[*Game Maker 4]
LangSecRef=3021
Detect=HKCU\Software\Game Maker 4
Default=False
RegKey1=HKCU\Software\Game Maker 4\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker 4\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker 4\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker 4\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker 4\Preferences|GameDir[*Game Maker 5]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 5
Default=False
RegKey1=HKCU\Software\Game Maker\Version 5\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 5\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 5\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 5\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 5\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 5\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 5\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 5\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 5\Preferences|GameDir[*Game Maker 6]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 6
Default=False
RegKey1=HKCU\Software\Game Maker\Version 6\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 6\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 6\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 6\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 6\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 6\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 6\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 6\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 6\Preferences|GameDir[*Game Maker 7]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 7
Default=False
RegKey1=HKCU\Software\Game Maker\Version 7\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 7\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 7\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 7\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 7\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 7\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 7\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 7\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 7\Preferences|GameDir[Genie Backup Manager Pro 6.0]
LangSecRef=3024
DetectFile=%userprofile%\Application Data\Genie-soft\GBMPro6
Default=False
FileKey1=%userprofile%\Application Data\Genie-soft\GBMPro6\logs|.*[*GetRight]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Headlight\GetRight
RegKey1=HKCU\Software\Headlight\GetRight\MRU
RegKey2=HKCU\Software\Headlight\GetRight\TypedURLS
RegKey3=HKCU\Software\Headlight\GetRight\Recent File List
FileKey1=%ProgramFiles%\GetRight|GetRight.hst[*Go!Zilla]
LangSecRef=3022
Detect=%Program Files%\Go!Zilla
Default=False
FileKey1=%ProgramFiles%\Go!Zilla\golog.htm
FileKey2=%ProgramFiles%\Go!Zilla\leech.hst
FileKey3=%ProgramFiles%\Go!Zilla\download.log[Google Calendar Sync]
LangSecRef=3022
Detect=HKCU\Software\Google\Google Calendar Sync
Default=False
FileKey1=%userprofile%\Application Data\Google\Google Calendar Sync\logs|.log[*Google Chrome - Cookies]
Section=Google Chrome
LangRef=3102
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_COOKIES[*Google Chrome - Download History]
Section=Google Chrome
LangRef=3163
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_DOWNLOAD[*Google Chrome - Internet Cache]
Section=Google Chrome
LangRef=3161
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_CACHE[*Google Chrome - Internet History]
Section=Google Chrome
LangRef=3162
Section = Chrome
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_HISTORY[*Google Chrome - Saved Form Information]
Section=Google Chrome
LangRef=3164
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_FORM[*Google Deskbar]
LangSecRef=3022
Detect=HKCU\Software\Google\Deskbar
Default=False
RegKey1=HKCU\Software\Google\Deskbar\termhistory
RegKey2=HKCU\Software\Google\Deskbar\urlhistory[*Google Earth]
LangSecRef=3021
Detect=HKLM\SOFTWARE\Google\Google Earth Plus
; Detect2=HKLM\SOFTWARE\Google\Google Earth Pro
Default=False
FileKey1=%appdata%\Google\GoogleEarth|dbcache.dat
FileKey2=%appdata%\Google\GoogleEarth|dbcache.dat.index
RegKey1=HKCU\Software\Google\Google Earth Plus\Search
RegKey2=HKCU\Software\Google\Google Earth Pro\Search[Google Talk]
LangSecRef=3022
DetectFile=%ProgramFiles%\Google\Google Talk
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Google\Google Talk\status|.txt
FileKey2=%userprofile%\Local Settings\Application Data\Google\Google Talk\chatlogs|*.log[Google Toolbar 4.0]
LangSecRef=3022
Detect=HKCU\Software\Google\Google Toolbar
Default=False
FileKey1=%appdata%\Google\Local Search History|.*[*Google Toolbar Firefox]
LangSecRef=3022
Default=False
SpecialDetect=DET_MOZILLA_GOOGLE_TOOLBAR
SpecialKey1=N_MOZ_GOOGLE_TOOLBAR[*Google Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Google\NavClient\1.1
Default=False
RegKey1=HKCU\Software\Google\NavClient\1.1\History
RegKey2=HKCU\Software\Google\NavClient\1.1\Options|KillPopupCount[*Google Video Player]
LangSecRef=3023
DetectFile=%ProgramFiles%\Google\Google Video Player\GoogleVideoPlayer.exe
Default=False
RegKey1=HKCU\Software\Google\Google Video Player\MRUList[*GridinSoft Notepad]
LangSecRef=3021
Detect=HKCU\Software\GridinSoft\Notepad3
Default=False
RegKey1=HKCU\Software\GridinSoft\Notepad3\Files
RegKey2=HKCU\Software\GridinSoft\Notepad3\Search|ReplaceTextHistory
RegKey3=HKCU\Software\GridinSoft\Notepad3\Search|TextHistory[Grisoft AVG 7.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\Avg7
Default=False
FileKey1=%commonappdata%\Grisoft\Avg7Data|.log
FileKey2=%commonappdata%\Grisoft\Avg7Data\upd7bin|.
FileKey3=%commonappdata%\Grisoft\Avg7Data$history|.
FileKey4=%commonappdata%\Grisoft\Avg7Data\avg7upd|.log
FileKey5=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|.*
FileKey6=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey7=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|.log
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|.log
FileKey9=%windir%\Application Data\AVG7\Log|*.log[Grisoft AVG 7.5]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\Avg7
Default=False
FileKey1=%allusersprofile%\Application Data\Grisoft|.AVG
FileKey2=%allusersprofile%\Application Data\Grisoft\Avg7Data|.AVG
FileKey3=%allusersprofile%\Application Data\Grisoft\Avg7Data|.log
FileKey4=%allusersprofile%\Application Data\Grisoft\Avg7Data\upd7bin|.
FileKey5=%allusersprofile%\Application Data\Grisoft\Avg7Data$history|.
FileKey6=%allusersprofile%\Application Data\Grisoft\Avg7Data\avg7upd|.log
FileKey7=%windir%\All Users\Application Data\Grisoft|.AVG
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|.AVG
FileKey9=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|.*
FileKey10=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey11=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|.log
FileKey12=%windir%\All Users\Application Data\Grisoft\Avg7Data|.log
FileKey13=%windir%\Application Data\AVG7\Log|*.log[Grisoft AVG 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|.log
FileKey2=%allusersprofile%\Application Data\avg8\Log|.xml
FileKey3=%allusersprofile%\Application Data\avg8\scanlogs|.log
FileKey4=%allusersprofile%\Application Data\avg8\emc\Log|.log
FileKey5=%allusersprofile%\Application Data\avg8\update\backup|.*
FileKey6=%allusersprofile%\Application Data\avg8\download|*.bin[GroupWise Messenger]
LangSecRef=3021
Detect=HKCU\Software\Novell\Messenger
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Novell\GroupWise Messenger\history%user%|.*[HDD Thermometer]
LangSecRef=3024
Detect=HKCU\SOFTWARE\RSD Software, Inc.\HDD Thermometer
Default=False
FileKey1=%allusersprofile%\Application Data\HDD Thermometer|.log
FileKey2=%allusersprofile%\Application Data\HDD Thermometer\logs|*.log[HP Photosmart Premier]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\HP Photo & Imaging
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\HP\Digital Imaging\cache|.*[*Help Files]
LangSecRef=3501
LangRef=3607
Default=False
SpecialKey1=R_HELP[*History]
LangSecRef=3001
LangRef=3103
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_HISTORY[HitManPro]
LangSecRef=3024
DetectFile=%ProgramFiles%\Hitman Pro\hitmanpro2.exe
Default=False
FileKey1=%ProgramFiles%\Hitman Pro\logs|.htm
FileKey2=%ProgramFiles%\Hitman Pro\updates|.
FileKey3=%ProgramFiles%\Hitman Pro\downloads|.[*HostsMan]
LangSecRef=3024
DetectFile=%ProgramFiles%\HostsMan\hm.exe
Default=False
FileKey1=%appdata%\abelhadigital.com\HostsServer|block2.log
FileKey2=%appdata%\abelhadigital.com\HostsServer|block1.log[Hotbar 3.0]
LangSecRef=3022
Detect=HKCU\Software\Hotbar
Default=False
RegKey1=HKCU\Software\Hotbar\hotbar\ImagesHistory
FileKey1=%ProgramFiles%\Hotbar\v3.0\dynamic|.|RECURSE
FileKey2=%ProgramFiles%\Hotbar\v3.0\static|.*[*Hotfix Uninstallers]
LangSecRef=3004
LangRef=3130
DetectOS=|5.2
SpecialKey1=N_EX_HOTFIX[*HxD Hexeditor]
LangSecRef=3021
Detect=HKCU\Software\Mael\HxD
Default=False
RegKey1=HKCU\Software\Mael\HxD\History Lists\Recent Files[*IE Toy]
LangSecRef=3024
Detect=HKCU\Software\MySoftware\IEToy
Default=False
FileKey1=%ProgramFiles%\IE Toy\Data|history
FileKey2=%ProgramFiles%\IE Toy\Data|history_ad
RegKey1=HKCU\Software\MySoftware\IEToy|FRAGS_ad
RegKey2=HKCU\Software\MySoftware\IEToy|FRAGS_popup[*IE7pro]
LangSecRef=3024
Detect=HKCU\Software\IE7pro
Default=False
RegKey1=HKCU\Software\IE7pro\ClosedTabs[IIS Log Files]
LangSecRef=3004
LangRef=3146
Detect=HKLM\System\CurrentControlSet\Services\w3svc
DetectOS=|6.0
FileKey1=%windir%\system32\LogFiles|.|RECURSE
FileKey2=%SystemDrive%\inetpub\logs\LogFiles|.*|RECURSE[*IZArc]
LangSecRef=3024
Detect=HKCU\Software\IZSoftware\IZArc
Default=False
RegKey1=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey2=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey3=HKCU\Software\IZSoftware\IZArc\Recent[*Icon Cache]
LangSecRef=3002
Default=False
FileKey1=%userprofile%\Local Settings\Application Data|IconCache.db
FileKey2=%LocalAppData%|IconCache.db[*IconCool Editor]
LangSecRef=3021
DetectFile=%ProgramFiles%\IconCoolEditor\IconCooleditor.exe
Default=False
FileKey1=%ProgramFiles%\IconCoolEditor|IconFileList.src
FileKey2=%ProgramFiles%\IconCoolEditor|Recentlyused.src[*IdeaSoft Scrapbooks Plus 1.0]
LangSecRef=3021
Detect=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0
Default=False
RegKey1=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0\Recent File List[*ImgBurn]
LangSecRef=3021
Detect=HKCU\Software\ImgBurn
Default=False
FileKey1=%AppData%\ImgBurn|ImgBurn.log
FileKey2=%AppData%\ImgBurn\Log Files|ImgBurn.log[ImgBurn]
LangSecRef=3021
Detect=HKCU\Software\ImgBurn
Default=False
FileKey1=%appdata%\ImgBurn\Log Files|.*
FileKey2=%appdata%\ImgBurn\IBG Files|.
RegKey1=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Destination
RegKey2=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Source
RegKey3=HKCU\Software\ImgBurn|ISOWRITE_RecentFiles_Source[*Inno Setup]
LangSecRef=3021
Detect=HKCU\Software\Jordan Russell\Inno Setup
Default=False
RegKey1=HKCU\Software\Jordan Russell\Inno Setup\ScriptFileHistoryNew[*InstallShield Professional]
LangSecRef=3021
Detect=HKCU\Software\InstallShield\InstallShield Professional
Default=False
RegKey1=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU1
RegKey2=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU2
RegKey3=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU3
RegKey4=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU4[*Installer]
LangSecRef=3501
LangRef=3608
Default=False
SpecialKey1=R_INSTALLER[*Installshield Developer 7.0]
LangSecRef=3021
Detect=HKCU\Software\InstallShield\Developer\7.0
Default=False
RegKey1=HKCU\Software\InstallShield\Developer\7.0\Recent File List[*Interface]
LangSecRef=3501
LangRef=3615
Default=False
SpecialKey1=R_INTERFACE[*Internet Download Manager]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Internet Download Manager
Default=False
FileKey1=%Appdata%\IDM\UrlHistory.txt
FileKey2=%Appdata%\IDM\UrlHistory2.txt[Internet Logs]
LangSecRef=3025
DetectFile=%windir%\Internet Logs
Default=False
FileKey1=%windir%\Internet Logs|.dmp
FileKey2=%windir%\Internet Logs|.log
FileKey3=%windir%\Internet Logs|.tmp
FileKey4=%windir%\Internet Logs|*.zip[*Invalid File Extensions]
LangSecRef=3501
LangRef=3602
Default=False
SpecialKey1=R_FILE_EXTS[*IsoBuster]
LangSecRef=3021
Detect=HKCU\Software\Smart Projects\IsoBuster
Default=False
RegKey1=HKCU\Software\Smart Projects\IsoBuster|ImageFilePath[*IsoBuster]
LangSecRef=3023
Detect=HKCU\Software\Smart Projects\IsoBuster
Default=False
RegKey1=HKCU\Software\Smart Projects\IsoBuster\RecentImages[Jetico Personal Firewall (Logs)]
LangSecRef=3022
Detect=HKLM\Software\Jetico\Personal Firewall
Default=False
FileKey1=%ProgramFiles%\Jetico\Jetico Personal Firewall|firewall.log[*KMPlayer]
LangSecRef=3023
Detect=HKCU\Software\KMPlayer
Default=False
RegKey1=HKCU\Software\KMPlayer\KMP2.0|LastFileName
RegKey2=HKCU\Software\KMPlayer\WideAlbum(Default Album)[*Kazaa (Search History)]
LangSecRef=3022
Detect=HKCU\Software\Kazaa
Default=False
RegKey1=HKCU\Software\Kazaa\Search[Koffix Blocker]
LangSecRef=3024
DetectFile=%ProgramFiles%\Koffix Blocker\Koffix.exe
Default=False
FileKey1=%userprofile%\My Documents\My Koffix Blocker Logs|.*[*Last Download Location]
LangSecRef=3001
LangRef=3108
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
RegKey1=HKCU\Software\Microsoft\Internet Explorer|Download Directory
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Main|Save Directory[*LeechGet]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Cronosoft\LeechGet
RegKey1=HKCU\Software\Cronosoft\LeechGet\History[LimeWire]
LangSecRef=3022
DetectFile=%ProgramFiles%\LimeWire\LimeWire.exe
Default=False
FileKey1=%userprofile%\Incomplete|.*|RECURSE
FileKey2=%userprofile%\Application Data\LimeWire|fileurns.cache
FileKey3=%userprofile%\Application Data\LimeWire|createtimes.cache
FileKey4=%userprofile%\Application Data\LimeWire|responses.cache
FileKey5=%userprofile%\Application Data\LimeWire|ttree.cache
FileKey6=%userprofile%\Application Data\LimeWire|gnutella.net[LogMeIn]
LangSecRef=3022
DetectFile=%ProgramFiles%\Logmein\x86\LogMeIn.exe
Default=False
FileKey1=%ProgramFiles%\Logmein|LMI.log[MP3Gain (Logs)]
LangSecRef=3023
Detect=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis
Default=False
FileKey1=%ProgramFiles%\MP3Gain|.log[*MPEG Audio Collection]
LangSecRef=3023
Detect=HKCU\Software\MPEG Audio Collection
Default=False
RegKey1=HKCU\Software\MPEG Audio Collection|LastNameText1
RegKey2=HKCU\Software\MPEG Audio Collection|LastNameText2
RegKey3=HKCU\Software\MPEG Audio Collection|LastNameText3
RegKey4=HKCU\Software\MPEG Audio Collection|LastNameText4
RegKey5=HKCU\Software\MPEG Audio Collection|LastNameText5
RegKey6=HKCU\Software\MPEG Audio Collection|LastNameText6[MS Backup (Logs)]
LangSecRef=3025
DetectFile=%SystemRoot%\System32\ntbackup.exe
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Microsoft\Windows NT\NTBackup\Data|.log[*MS Direct Draw]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\DirectDraw
Default=False
RegKey1=HKCU\Software\Microsoft\DirectDraw\MostRecentApplicationName[*MS HTML Help Workshop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\HTML Help Workshop
Default=False
RegKey1=HKCU\Software\Microsoft\HTML Help Workshop\Compressed HTML
RegKey2=HKCU\Software\Microsoft\HTML Help Workshop\Html Titles
RegKey3=HKCU\Software\Microsoft\HTML Help Workshop\Project Files
RegKey4=HKCU\Software\Microsoft\HTML Help Workshop\Recent File List
RegKey5=HKCU\Software\Microsoft\HTML Help Workshop\Settings|LastProject
RegKey6=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Folders
RegKey7=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Recent File List[*MS Help Workshop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Help Workshop
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft Help Workshop\Cnt Files
RegKey2=HKCU\Software\Microsoft\Microsoft Help Workshop\Forage Files
RegKey3=HKCU\Software\Microsoft\Microsoft Help Workshop\Hlp Files
RegKey4=HKCU\Software\Microsoft\Microsoft Help Workshop\Hpj Files
RegKey5=HKCU\Software\Microsoft\Microsoft Help Workshop\Map Files
RegKey6=HKCU\Software\Microsoft\Microsoft Help Workshop\Recent File List[*MS Imaging]
LangSecRef=3024
Detect=HKCU\Software\Kodak\Imaging
Default=False
RegKey1=HKCU\Software\Kodak\Imaging\Recent File List[*MS Management Console]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List[*MS Office 2003 Script Editor]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\MSE
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\MSE|LastLoadedSolution
Regkey2=HKCU\Software\Microsoft\Office\11.0\MSE\FileMRUList
Regkey3=HKCU\Software\Microsoft\Office\11.0\MSE\ProjectMRUList
Regkey4=HKCU\Software\Microsoft\Office\11.0\MSE\SolutionMRUList[MS Office Picture Manager]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office
Default=False
FileKey1=%LocalAppData%\Microsoft\OIS|OIScatalog.cag
FileKey2=%LocalAppData%\Microsoft\OIS\thumbnails|.*[*MS Office Publisher 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Publisher
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List[*MS Paint]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List[*MS Photo Editor]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor
Default=False
RegKey1=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile1
RegKey2=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile2
RegKey3=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile3
RegKey4=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile4
RegKey5=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType1
RegKey6=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType2
RegKey7=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType3
RegKey8=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType4[*MS PhotoDraw 2000]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\PhotoDraw\1.0
Default=False
RegKey1=HKCU\Software\Microsoft\PhotoDraw\1.0\Recent File List[*MS SQL Server 2005]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\FileMRUList
RegKey2=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\ProjectMRUList[*MS Snapshot Viewer]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Snapshot Viewer
Default=False
RegKey1=HKCU\Software\Microsoft\Snapshot Viewer\Recent File List[*MS Visual Studio 2005]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\8.0
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\8.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\8.0\ProjectMRUList[MS Visual Studio.NET 03]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\7.1
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\7.1\FileMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\7.1|LastLoadedSolution
FileKey1=%userprofile%\Local Settings\Application Data\ApplicationHistory|.*|REMOVESELF[*MS Visual Studio.NET 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\7.1
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File1
RegKey2=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File2
RegKey3=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File3
RegKey4=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File4
RegKey5=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File5[*MS Windows Wallpaper]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU[*MS Wordpad]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List[*MS Works 4.0]
LangSecRef=3021
Detect= HKCU\Software\Microsoft\Works\4.0
Default=False
RegKey1=HKCU\Software\Microsoft\Works\4.0\Recent File List[*MS Works Suite 2006]
LangSecRef=3021
Detect= HKCU\Software\Microsoft\Works\8.0
Default=False
RegKey1=HKCU\Software\Microsoft\Works\8.0\Recent File List[*MS XML Notepad]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\XML Notepad
Default=False
RegKey1=HKCU\Software\Microsoft\XML Notepad\Recent File List[*MSConfig]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Shared Tools\MSConfig
Default=False
RegKey1=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandFrom
RegKey2=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandTo
RegKey3=HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSConfig[*MUI Cache]
LangSecRef=3501
LangRef=3614
Default=False
SpecialKey1=R_MUICACHE[*MUICache]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\[*Macromedia Dreamweaver MX]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Macromedia\Dreamweaver MX 2004
RegKey1=HKCU\Software\Macromedia\Dreamweaver MX 2004\Recent File List[*Macromedia Fireworks 6.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Macromedia\Firework 6
RegKey1=HKCU\Software\Macromedia\Firework 6\Recent File List[*Macromedia Flash 4.0]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 4
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 4\Recent File List[*Macromedia Flash 5.0]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 5
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 5\Recent File List[*Macromedia Flash MX 2004]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 7
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 7\Recent File List[*Macromedia Flash MX]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 6
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 6\Recent File List[*Macromedia Homesite 5.0]
LangSecRef=3021
Detect=HKCU\Software\Macromedia\HomeSite5
Default=False
RegKey1=HKCU\Software\Macromedia\HomeSite5\RecentFiles[*Macromedia Shockwave 10]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Shockwave 10
Default=False
RegKey1=Software\Macromedia\Shockwave 10\movies[*Macromedia Shockwave 8]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Shockwave 8
Default=False
RegKey1=Software\Macromedia\Shockwave 8\movies[*MagicISO]
LangSecRef=3021
Detect=HKCU\Software\MagicISO
Default=False
RegKey1=HKCU\Software\MagicISO\Reopen[Malwarebytes’ Anti Malware]
LangSecRef=3024
DetectFile=%ProgramFiles%\Malwarebytes’ Anti-Malware\mbam.exe
Default=False
FileKey1=%appdata%\Malwarebytes\Malwarebytes’ Anti-Malware\Logs|.txt
FileKey2=%appdata%\Malwarebytes\Malwarebytes’ Anti-Malware\Quarantine|.[Maxthon Browser 2]
LangSecRef=3022
DetectFile=%ProgramFiles%\Maxthon2\Maxthon.exe
Default=False
FileKey1=%ProgramFiles%\Maxthon2\Temp|.*[McAfee SiteAdvisor]
LangSecRef=3024
DetectFile=%appdata%\SiteAdvisor
Default=False
FileKey1=%appdata%\SiteAdvisor|asserts.txt
FileKey2=%allusersdata%\SiteAdvisor|.log
FileKey3=%commonappdata%\McAfee\MCLOGS\MISP\SAService|SAService*.log[*Media Player Classic]
LangSecRef=3023
Detect=HKCU\Software\Gabest\Media Player Classic
Default=False
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName[*Media Player Classic]
LangSecRef=3023
Detect=HKLM\Software\Gabest\Media Player Classic
Default=False
FileKey1=%appdata%\Media Player Classic|default.mpcpl
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName[MediaMonkey]
LangSecRef=3023
DetectFile=%ProgramFiles%\MediaMonkey\MediaMonkey.exe
Default=False
FileKey1=%userprofile%\Local Settings\Temp|.|RECURSE
FileKey2=%userprofile%\My Documents\My Music\MediaMonkey|MediaMonkey.m3u
FileKey3=%userprofile%\My Documents\My Music\MediaMonkey\Previews|.*|RECURSE[Memory Dumps]
LangSecRef=3003
LangRef=3143
Default=False
FileKey1=%windir%|memory.dmp
FileKey2=%windir%\MiniDump|.dmp[*Menu Order Cache]
LangSecRef=3004
LangRef=3125
WarningRef=3203
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder[Messenger Plus! Live (Logs)]
LangSecRef=3022
Detect=HKCU\Software\Patchou
Default=False
FileKey1=%userprofile%\My Documents\My Chat Logs|.*|RECURSE[*MiTeC DFM Editor]
LangSecRef=3021
Detect=HKCU\Software\MiTeC\DFM Editor
Default=False
RegKey1=HKCU\Software\MiTeC\DFM Editor\5.x\Main\MRUHistory[*Microangelo 6]
LangSecRef=3021
Detect=HKCU\Software\Eclipsit\Microangelo\Toolset 6
Default=False
RegKey1=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Animator\MRU List
RegKey2=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Librarian\MRU List
RegKey3=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Studio\MRU List[*Microangelo]
LangSecRef=3021
Detect=HKCU\Software\Impact\Microangelo
Default=False
RegKey1=HKCU\Software\Impact\Microangelo\Animator\MRU List
RegKey2=HKCU\Software\Impact\Microangelo\Librarian\MRU List
RegKey3=HKCU\Software\Impact\Microangelo\Studio\MRU List[*Microsoft AntiSpyware]
LangSecRef=3024
DetectFile=%ProgramFiles%\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
Default=False
FileKey1=%ProgramFiles%\Microsoft AntiSpyware|errors.log
FileKey2=%ProgramFiles%\Microsoft AntiSpyware|tracksEraser.log
FileKey3=%ProgramFiles%\Microsoft AntiSpyware|cleaner.log[*Microsoft Visual Studio 6.0]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\6.0
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\6.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\6.0\MenuMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\6.0\ProjectMRUList
RegKey4=HKCU\Software\Microsoft\Visual Basic\6.0\RecentFiles[*Missing Shared DLLs]
LangSecRef=3501
LangRef=3601
Default=False
SpecialKey1=R_SHARED_DLLS[*More Windows Explorer]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU[*Morpheus]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Morpheus
RegKey1=HKCU\Software\Morpheus\Morpheus\Recent File List[*Mozilla - Cookies]
LangSecRef=3026
LangRef=3102
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_COOKIES[*Mozilla - Download History]
LangSecRef=3026
LangRef=3163
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_DOWNLOAD[*Mozilla - Internet Cache]
LangSecRef=3026
LangRef=3161
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_CACHE[*Mozilla - Internet History]
LangSecRef=3026
LangRef=3162
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_HISTORY[*Mozilla - Saved Form Information]
LangSecRef=3026
LangRef=3164
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_FORM[*Mp3tag (Log)]
LangSecRef=3023
Detect=HKLM\Software\Florian Heidenreich\Mp3tag
Default=False
FileKey1=%appdata%\Mp3tag|Mp3tagError.log[*Mp3tag]
LangSecRef=3021
Detect=HKCU\Software\Moebius\Mp3tag
Default=False
RegKey1=HKCU\Software\Moebius\Mp3tag\Settings|LastDirName
RegKey2=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|0
RegKey3=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|1
RegKey4=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|2
RegKey5=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|3
RegKey6=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|4
RegKey7=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|5
RegKey8=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|6
RegKey9=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|7[MusicMatch Jukebox]
LangSecRef=3023
Detect=HKLM\Software\MUSICMATCH\MUSICMATCH Jukebox
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox|.log
FileKey2=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox|log.txt
FileKey3=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox\Cache|.*
FileKey4=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\TEMP|.
FileKey5=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\MMRadio\Cache|.[*MyToolkit]
LangSecRef=3024
Detect=HKCU\Software\FutureFog\MyToolkit\Options
Default=False
RegKey1=HKCU\Software\FutureFog\MyToolkit\Options|LastUsedFolder[NA Framework Agent]
LangSecRef=3021
Detect=HKLM\Software\Network Associates\TVD\Shared Components\Framework
Default=False
FileKey1=%allusersprofile%\Application Data\Network Associates\Common Framework\AgentEvents|.*
FileKey2=%allusersprofile%\Application Data\McAfee\Common Framework\AgentEvents|.[*NSIS]
LangSecRef=3021
Detect=HKLM\Software\NSIS
Default=False
RegKey1=HKLM\Software\NSIS\MRU[Nero Burning ROM 9]
LangSecRef=3021
Detect=HKCU\Software\Nero\Nero 9
Default=False
RegKey1=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BrowserDir
RegKey2=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey3=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|WorkingDir
RegKey4=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey5=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BootImageDir
RegKey6=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Recent File List
FileKey1=%appdata%\Nero\Nero 9\Nero Burning ROM|.log[*Nero Burning ROM]
LangSecRef=3021
Detect=HKCU\Software\ahead\Nero - Burning Rom
Default=False
RegKey1=HKCU\Software\ahead\Nero - Burning Rom\Settings|BrowserDir
RegKey2=HKCU\Software\ahead\Nero - Burning Rom\Settings|ImageDir
RegKey3=HKCU\Software\ahead\Nero - Burning Rom\Settings|WorkingDir
RegKey4=HKLM\Software\Ahead\Nero - Burning Rom\Settings|ImageDir
RegKey5=HKLM\Software\Ahead\Nero - Burning Rom\Settings|BootImageDir
RegKey6=HKCU\Software\Ahead\Nero - Burning Rom\Recent File List
RegKey7=HKCU\Software\Ahead\Cover Designer\Recent File List
RegKey8=HKCU\Software\Ahead\Nero Wave Editor\Recent File List
FileKey1=%ProgramFiles%\Ahead\Nero|NeroHistory.log[Netscape Navigator 4.x]
LangSecRef=3022
Detect=HKCU\Software\Netscape\Netscape Navigator\Main
Default=False
FileKey1=%ProgramFiles%\Netscape\Users\default|netscape.hst
FileKey2=%ProgramFiles%\Netscape\Users\default|cookies.txt
FileKey3=%ProgramFiles%\Netscape\Users\default\cache|.*[Norton AntiVirus]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Symantec\Norton AntiVirus NT\Install\7.50
Default=False
FileKey1=%commonappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|.log
FileKey2=%localappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|.*[*NoteXpad]
LangSecRef=3021
Detect=HKLM\Software\NoteXpad
Default=False
RegKey1=HKLM\Software\NoteXpad\Recent[O&O Defrag]
LangSecRef=3024
Detect=HKCU\Software\O&O\O&O Defrag
Default=False
FileKey1=%userprofile%\My Documents\O&O\O&O Defrag\data\reports|.*|RECURSE[*Obsolete Software]
LangSecRef=3501
LangRef=3609
Default=False
SpecialKey1=R_OLDSOFTWARE[Office 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|.*
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel\Recent Files
RegKey2=HKCU\Software\Microsoft\Office\11.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
Regkey3=HKCU\Software\Microsoft\Office\11.0\PowerPoint\Recent File List
Regkey4=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List
Regkey5=HKCU\Software\Microsoft\Office\11.0\InfoPath\Recent File List
RegKey6=HKCU\Software\Microsoft\Office\11.0\Common\Internet\Server Cache
RegKey7=HKCU\Software\Microsoft\Office\11.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\MSPaper 11.0\Persist File Name
RegKey9=HKCU\Software\Microsoft\MSPaper 11.0\Recent File List
RegKey10=HKCU\Software\Microsoft\Office\11.0\Word\Data|Settings
RegKey11=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile1
RegKey12=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile2
RegKey13=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile3
RegKey14=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile4
RegKey15=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile5
RegKey16=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile6
RegKey17=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile7
RegKey18=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile8
RegKey19=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey20=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey21=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU[Office 2007]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\12.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|.*
RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey2=HKCU\Software\Microsoft\Office\12.0\Word\File MRU
RegKey3=HKCU\Software\Microsoft\Office\12.0\Excel\File MRU
RegKey4=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU1
RegKey5=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU2
RegKey6=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU3
RegKey7=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU4
RegKey8=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU5
RegKey9=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU6
RegKey10=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU7
RegKey11=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU8
RegKey12=HKCU\Software\Microsoft\Office\12.0\PowerPoint\File MRU
RegKey13=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Save As\File Name MRU
RegKey14=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open\File Name MRU
RegKey15=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Save As\File Name MRU
RegKey16=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Excel\Settings\Save As\File Name MRU
RegKey17=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Publisher\Settings\Save As\File Name MRU
RegKey18=HKCU\Software\Microsoft\Office\12.0\Publisher\Recent File List
RegKey19=HKCU\Software\Microsoft\Office\12.0\InfoPath\Recent File List[Office 97]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\8.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|.*
RegKey1=HKCU\Software\Microsoft\Office\8.0\Excel\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\8.0\Project\Recent File List
RegKey3=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent File List
RegKey4=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent Folder List
RegKey5=HKCU\Software\Microsoft\Office\8.0\Common\Internet\LocationOfComponents
RegKey6=HKCU\Software\Microsoft\Office\8.0\Access\Settings[Office XP]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\10.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|.*
RegKey1=HKCU\Software\Microsoft\Office\10.0\PowerPoint\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\10.0\Excel\Recent Files
RegKey3=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent File List
RegKey4=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List
RegKey5=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List
RegKey6=HKCU\Software\Microsoft\Office\10.0\Word\Recent Templates
RegKey7=HKCU\Software\Microsoft\Office\10.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\Office\10.0\Word\Data|Settings
RegKey9=HKCU\Software\Microsoft\Office\10.0\Access\Settings[*Old Prefetch data]
LangSecRef=3004
LangRef=3147
Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OptimalLayout
SpecialKey1=N_INT_PREFETCH[*OpenOffice 1.14]
LangSecRef=3021
DetectFile=%ProgramFiles%\OpenOffice.org1.1.4\program\soffice.exe
Default=False
FileKey1=%ProgramFiles%\OpenOffice.org1.1.4\user\registry\data\org\openoffice\Office|Common.xcu[*OpenOffice 2.0]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.0
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu[*OpenOffice 2.1]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.1
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu[*OpenOffice 2.3]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.3
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu[*OpenOffice 3.1]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.1
Default=False
FileKey1=%appdata%\OpenOffice.org\3\user\registry\data\org\openoffice\Office|Common.xcu[*Opera - Cookies]
LangSecRef=3027
LangRef=3102
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_COOKIES[*Opera - Internet Cache]
LangSecRef=3027
LangRef=3161
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_CACHE[*Opera - Internet History]
LangSecRef=3027
LangRef=3162
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_HISTORY[Opera 9 (Classic)]
LangSecRef=3022
DetectFile=%ProgramFiles%\Opera 9\Opera.exe
Default=False
FileKey1=%ProgramFiles%\Opera 9\profile|cookies4.dat
FileKey2=%ProgramFiles%\Opera 9\profile|global.dat
FileKey3=%ProgramFiles%\Opera 9\profile|vlink4.dat
FileKey4=%ProgramFiles%\Opera 9\profile\cache4|.*
FileKey5=%ProgramFiles%\Opera 9\profile\cacheOp|.[Orbit Downloader]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Orbit
Default=False
FileKey1=%appdata%\Orbit|fileinfo.dat
FileKey2=%appdata%\Orbit|history.dat
FileKey3=%appdata%\Orbit|unfinish.dat
FileKey4=%appdata%\Orbit\flink|.*[*Other Explorer MRUs]
LangSecRef=3002
LangRef=3124
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\PrnPortsMRU
RegKey4=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU
RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComputerDescriptions
RegKey6=HKLM\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey7=HKCU\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey8=HKLM\Software\Microsoft\DirectDraw\MostRecentApplication|Name
RegKey9=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Id
RegKey10=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Name[*Outlook 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Outlook
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey2=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey3=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
RegKey4=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 1
RegKey5=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 3
FileKey1=%appdata%\Microsoft\Outlook|Outlook.NK2[*PDF-XChange Viewer]
LangSecRef=3021
Detect=HKCU\Software\Tracker Software\PDFViewer
Default=False
RegKey1=HKCU\Software\Tracker Software\PDFViewer\Documents\LastOpened
RegKey2=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Bars
RegKey3=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Panes[*PDFCreator]
LangSecRef=3024
Detect=HKCU\Software\PDFCreator
Default=False
RegKey1=HKCU\Software\PDFCreator\Program|LastsaveDirectory[*PE Module Explorer]
LangSecRef=3024
Detect=HKCU\Software\Woozle\PE Module Explorer
Default=False
RegKey1=HKCU\Software\Woozle\PE Module Explorer\Recent Files[*Paint Shop Pro 7.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 7
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 7\Recent File List
RegKey2=HKCU\Software\Jasc\Animation Shop 3\Recent File List
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 7\General|FolderHistory
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveAsDirectory
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveCopyDirectory[*Paint Shop Pro 8.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 8
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 8\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 8\WorkspaceMRU
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdPyScript\RunScript|FileName
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdFile\FileSaveAs|FileFolder
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdNonGraphic\SaveWorkspace|WorkspaceFilename
RegKey6=HKCU\Software\Jasc\Paint Shop Pro 8\ScriptMRU[*Paint Shop Pro 9.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 9
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 9\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 9\WorkspaceMRU
Regkey3=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileOpen|Folder[*Paint Shop Pro XI]
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\11
Default=False
RegKey1=HKCU\Software\Corel\Paint Shop Pro\11\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\11\WorkspaceMRU
Regkey3=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileOpen|Folder[*Paint Shop Pro X]
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\10
Default=False
RegKey1=HKCU\Software\Corel\Paint Shop Pro\10\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\10\WorkspaceMRU
Regkey3=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileOpen|Folder[*Paint.NET]
LangSecRef=3021
Detect=HKCU\Software\Paint.NET
Default=False
RegKey1=HKCU\Software\Paint.NET|MRU0
RegKey2=HKCU\Software\Paint.NET|MRU1
RegKey3=HKCU\Software\Paint.NET|MRU2
RegKey4=HKCU\Software\Paint.NET|MRU3
RegKey5=HKCU\Software\Paint.NET|MRU4
RegKey6=HKCU\Software\Paint.NET|MRU5
RegKey7=HKCU\Software\Paint.NET|MRU6
RegKey8=HKCU\Software\Paint.NET|MRU7
RegKey9=HKCU\Software\Paint.NET|MRU0Thumb
RegKey10=HKCU\Software\Paint.NET|MRU1Thumb
RegKey11=HKCU\Software\Paint.NET|MRU2Thumb
RegKey12=HKCU\Software\Paint.NET|MRU3Thumb
RegKey13=HKCU\Software\Paint.NET|MRU4Thumb
RegKey14=HKCU\Software\Paint.NET|MRU5Thumb
RegKey15=HKCU\Software\Paint.NET|MRU6Thumb
RegKey16=HKCU\Software\Paint.NET|MRU7Thumb[*Pelles C]
LangSecRef=3021
Detect=HKCU\Software\Pelle Orinius\PellesC
Default=False
RegKey1=HKCU\Software\Pelle Orinius\PellesC\Recent File List
RegKey2=HKCU\Software\Pelle Orinius\PellesC\Recent Project List
RegKey3=HKCU\Software\Pelle Orinius\PellesC\Recent Search List[*PerfectDisk 7.0]
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\7.0
Default=False
FileKey1=%commonappdata%\Raxco\PerfectDisk\7.0|PerfectDisk.log[PerfectDisk 8]
LAngSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\8.0
Default=False
FileKey1=%allusersprofile%\Application Data\Raxco\PerfectDisk\8.0|.log[*Phorest]
LangSecRef=3024
Detect=HKCU\Software\FutureFog\Phorest\Options
Default=False
RegKey1=HKCU\Software\FutureFog\Phorest\Options|LastUsedFolder
RegKey2=HKCU\Software\FutureFog\Phorest\Layout|SelectionLeft
RegKey3=HKCU\Software\FutureFog\Phorest\Layout|SelectionTop
RegKey4=HKCU\Software\FutureFog\Phorest\Layout|SelectionWidth
RegKey5=HKCU\Software\FutureFog\Phorest\Layout|SelectionHeight[*Photo Print Calendar 3.00E Beta]
LangSecRef=3021
Detect=HKLM\SOFTWARE\Computer Institute of Japan, Ltd.\Photo Print Calendar from YOKOHAMA Ver.3.00E beta\3.00E beta
Default=False
FileKey1=%programfiles%\Photo Print Calendar|update.bmp[Photoshop CS Filebrowser]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Adobe\Photoshop
FileKey1=%userprofile%\application data\Adobe\FileBrowser\PhotoshopCS|.*[Photoshop CS Filebrowser]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Adobe\Photoshop
FileKey1=%userprofile%\application data\Adobe\FileBrowser\PhotoshopCS|.*
fileKey2=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.|RECURSE[*PicoZip]
LangSecRef=3024
Detect=HKCU\Software\PicoZip
Default=False
RegKey1=HKCU\Software\PicoZip\MRU Items
RegKey2=HKCU\Software\PicoZip\MRUExtract[Pok3D]
LangSecRef=3021
DetectFile=%ProgramFiles%\Pok3d\Pok3d.ico
Default=False
FileKey1=%userprofile%\Application Data\Pok3d|.log
FileKey2=%userprofile%\Application Data\Pok3d|*.dmp[*PowerArchiver]
LangSecRef=3024
Detect=HKCU\Software\PowerArchiver
Default=False
RegKey1=HKCU\Software\PowerArchiver\Files|Active_File1
RegKey2=HKCU\Software\PowerArchiver\Files|Active_File2
RegKey3=HKCU\Software\PowerArchiver\Files|Active_File3
RegKey4=HKCU\Software\PowerArchiver\Files|Active_File4
RegKey5=HKCU\Software\PowerArchiver\Files|Active_File5
RegKey6=HKCU\Software\PowerArchiver\Files|Extract1
RegKey7=HKCU\Software\PowerArchiver\Files|Extract2
RegKey8=HKCU\Software\PowerArchiver\Files|Extract3
RegKey9=HKCU\Software\PowerArchiver\Files|Extract4
RegKey10=HKCU\Software\PowerArchiver\Files|Extract5
RegKey11=HKCU\Software\PowerArchiver\Files|Last open dir
RegKey12=HKCU\Software\PowerArchiver\Files|Last backup dir
RegKey13=HKCU\Software\PowerArchiver\Files|Last add dir[PowerDVD]
LangSecRef=3021
DetectFile=%ProgramFiles%\Cyberlink\PowerDVD\PowerDVD.exe
Default=False
FileKey1=%ProgramFiles%\CyberLink\PowerDVD|.pls
FileKey2=%userprofile%\My Documents\CyberLink\PowerDVD|*.pls[*PowerZip]
LangSecRef=3024
Detect=HKCU\Software\Trident Software\PowerZip
Default=False
RegKey1=HKCU\Software\Trident Software\PowerZip\Recent File List[QuickPAR]
LangSecRef=3024
Detect=HKCU\Software\QuickPar
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\QuickPar|.*[Quicktime Player Cache]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=False
FileKey1=%localappdata%\Apple Computer\QuickTime\downloads|.*|RECURSE[*Quicktime Player]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=False
RegKey1=HKLM\Software\Apple Computer, Inc.\QuickTime\Recent Movies
FileKey1=%userprofile%|QTPlayerSession.xml
FileKey2=%appdata%\Apple Computer\QuickTime|QTPlayerSession.xml[Qwest QuickCare]
LangSecRef=3022
Detect=HKLM\Software\QuickCare
Default=False
FileKey1=%allusersprofile%\Application Data\Support.com|.tmp|RECURSE
FileKey2=%userprofile%\Local Settings\Application Data\SupportSoft|*.tmp|RECURSE[ReGet Deluxe]
LangSecRef=3022
Detect=HKCU\Software\ReGet Software\ReGetDx
Default=False
FileKey1=%ProgramFiles%\ReGet Deluxe\history|.*
RegKey1=HKCU\Software\ReGet Software\ReGetDx\FtpExplorer\Hist
RegKey2=HKCU\Software\ReGet Software\ReGetDx\History
RegKey3=HKCU\Software\ReGet Software\ReGetDx\Search\HistFind[Real Player SP]
LangSecRef=3023
Detect=HKCU\Software\RealNetworks\RealPlayer\12.0
Default=False
RegKey1=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins1
RegKey10=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins2
RegKey11=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins3
RegKey12=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins4
RegKey13=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins5
RegKey14=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins6
RegKey15=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins7
RegKey16=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins8
RegKey17=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\LastOpenFileDir
RegKey18=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips1
RegKey19=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips2
RegKey20=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips3
RegKey21=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips4
RegKey22=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips5
RegKey23=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips6
RegKey24=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips7
FileKey1=%appdata%\Real\RealPlayer|RealPlayer-log.txt
FileKey2=%appdata%\Real\RealPlayer\History|.*[*Recent Documents]
LangSecRef=3002
LangRef=3121
Default=False
SpecialKey1=N_EX_RECENTDOCS
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs[*Recently Typed URLs]
LangSecRef=3001
LangRef=3104
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
RegKey1=HKCU\Software\Microsoft\Internet Explorer\TypedURLs
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
RegKey3=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU[*RegAlyzer]
LangSecRef=3024
Detect=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer
Default=False
RegKey1=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|LastKey
RegKey2=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|RemoteListHistory
RegKey3=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|SearchTerm[*RegEdit]
LangSecRef=3025
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit|LastKey[Registry Mechanic]
LangSecRef=3024
Detect=HKLM\Software\PCTools\Registry Mechanic
Default=False
FileKey1=%userprofile%|.rmbak|RECURSE
FileKey2=%userprofile%|.rrr|RECURSE
FileKey3=%userprofile%|.rrr.bak|RECURSE
FileKey4=%userprofile%\Local Settings\Application Data\Microsoft\Windows|.rmbak
FileKey5=%userprofile%\Local Settings\Application Data\Microsoft\Windows|.rrr
FileKey6=%userprofile%\Local Settings\Application Data\Microsoft\Windows|.rrr.bak
FileKey7=%allusersprofile%|.rmbak|RECURSE
FileKey8=%allusersprofile%|.rrr|RECURSE
FileKey9=%allusersprofile%|.rrr.bak|RECURSE
FileKey10=%systemdrive%\Documents and Settings\Guest|.rmbak|RECURSE
FileKey11=%systemdrive%\Documents and Settings\Guest|.rrr|RECURSE
FileKey12=%systemdrive%\Documents and Settings\Guest|.rrr.bak|RECURSE
FileKey13=%systemdrive%\Documents and Settings\LocalService|.rmbak|RECURSE
FileKey14=%systemdrive%\Documents and Settings\LocalService|.rrr|RECURSE
FileKey15=%systemdrive%\Documents and Settings\LocalService|.rrr.bak|RECURSE
FileKey16=%systemdrive%\Documents and Settings\NetworkService|.rmbak|RECURSE
FileKey17=%systemdrive%\Documents and Settings\NetworkService|.rrr|RECURSE
FileKey18=%systemdrive%\Documents and Settings\NetworkService|.rrr.bak|RECURSE
FileKey19=%windir%\system32\config|.rmbak
FileKey20=%windir%\system32\config|.rrr
FileKey21=%windir%\system32\config|.rrr.bak
FileKey22=%ProgramFiles%\Registry Mechanic\Log|compactlog.log
FileKey23=%ProgramFiles%\Registry Mechanic\Log|results.log
FileKey24=%ProgramFiles%\Registry Mechanic\Log|scan.log[RegistryFix]
LangSecRef=3024
DetectFile=%ProgramFiles%\RegistryFix\RegistryFix.exe
Default=False
FileKey1=%ProgramFiles%\RegistryFix\logs|.*[Remote Desktop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Terminal Server Client
Default=False
FileKey1=%localappdata%\Microsoft\Terminal Server Client\Cache|.*
RegKey1=HKCU\Software\Microsoft\Terminal Server Client\Default[*Run (in Start Menu)]
LangSecRef=3002
LangRef=3122
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU[*Run At Startup]
LangSecRef=3501
LangRef=3610
Default=False
SpecialKey1=R_RUNSTARTUP[*STOIK Smart Resizer]
LangSecRef=3023
Detect=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer\Recent File List
Default=False
RegKey1=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer\Recent File List[STOIK Video Converter 2]
LangSecRef=3023
Detect=HKCU\Software\STOIK
Default=False
FileKey1=%appdata%\STOIK\videopak2|.ini[SUPERAntiSpyware (Logs)]
LangSecRef=3024
Detect=HKLM\Software\SUPERAntiSpyware.com\SUPERAntiSpyware
Default=False
FileKey1=%appdata%\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs|.log[*SWiSH]
LangSecRef=3023
Detect=HKCU\Software\DJJ Holdings\SWiSH
Default=False
RegKey1=HKCU\Software\DJJ Holdings\SWiSH\Recent File List[*Safari - Cookies]
LangSecRef=3028
LangRef=3102
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari\Cookies|Cookies.plist[*Safari - Internet Cache]
LangSecRef=3028
LangRef=3161
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%localappdata%\Apple Computer\Safari|Cache.db[Safari - Internet History]
LangSecRef=3028
LangRef=3162
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari|History.plist
FileKey2=%appdata%\Apple Computer\Safari|Downloads.plist
FileKey3=%localappdata%\Apple Computer\Safari\History|.*[*Safari - Saved Form Information]
LangSecRef=3028
LangRef=3164
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari|Form Values.plist[ScanDefrag (Logs)]
LangSecRef=3024
Detect=HKLM\Software\ScanDefrag
Default=False
FileKey1=%SystemDrive%\ScanDefrag|.log
FileKey2=%SystemDrive%\ScanDefrag\logs|*.txt[*Search Assistant Autocomplete]
LangSecRef=3002
LangRef=3123
Detect=HKCU\Software\Microsoft\Search Assistant
Default=False
RegKey1=HKCU\Software\Microsoft\Search Assistant\ACMru[*Second Copy 2000]
LangSecRef=3021
Detect=HKCU\Software\Centered Systems\Second Copy 2000
Default=False
FileKey1=%ProgramFiles%\SecCopy|log.rtf
FileKey2=%ProgramFiles%\SecCopy|log-old.rtf
RegKey1=HKCU\Software\Centered Systems\Second Copy 2000\MRU[*SecureCRT]
LangSecRef=3021
Detect=HKCU\Software\VanDyke\SecureCRT
Default=False
FileKey1=%appdata%\VanDyke\SecureCRT\Config|Recent File List.ini
FileKey2=%appdata%\VanDyke\SecureCRT\Config|Recent Script List.ini[Shareaza]
LangSecRef=3022
DetectFile=%ProgramFiles%\Shareaza\Shareaza.exe
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Shareaza\Incomplete|.*[*Smart Installer Maker]
LangSecRef=3024
Detect=HKCU\Software\InstallBuilders\Smart Install Maker
Default=False
RegKey1=HKCU\Software\InstallBuilders\Smart Install Maker\Reopen[SmartFTP]
LangSecRef=3022
Detect=HKCU\Software\SmartFTP
Default=False
FileKey1=%appdata%\SmartFTP\Cache|.*|RECURSE
FileKey2=%appdata%\SmartFTP|History.dat[SoftThinks CD Creator]
LangSecRef=3021
Detect=HKLM\SOFTWARE\SoftThinks
Default=False
FileKey1=%windir%\CREATOR|.log[*Soulseek Beta]
LangSecRef=3022
DetectFile=%ProgramFiles%\Soulseek-Test\slsk.exe
Default=False
FileKey1=%ProgramFiles%\Soulseek-Test|search.cfg[*Soulseek]
LangSecRef=3022
DetectFile=%ProgramFiles%\Soulseek\slsk.exe
Default=False
FileKey1=%ProgramFiles%\Soulseek|search.cfg[*Sound Forge 6.0]
LangSecRef=3022
Detect=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics
Default=False
RegKey1=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30110
RegKey2=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30111
RegKey3=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30112
RegKey4=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30113
RegKey5=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30114
RegKey6=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30115[SpyBot Search and Destroy]
LangSecRef=3024
Detect=HKCU\Software\Safer Networking Limited\SpybotSnD
Default=False
FileKey1=%commonappdata%\Spybot - Search & Destroy\Logs|.*
FileKey2=%ProgramFiles%\Spybot - Search & Destroy|advdebug.txt
FileKey3=%commonappdata%\Spybot - Search & Destroy|Statistics.ini
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|.
FileKey5=%windir%\All Users\Application Data\Spybot - Search & Destroy|Statistics.ini
FileKey6=%commonappdata%\Spybot - Search & Destroy\Backups|*.log[*SpyDefense]
LangSecRef=3024
DetectFile=%ProgramFiles%\Everest Labs\Spydefense\sdc.exe
Default=False
FileKey1=%userprofile%\Application Data\Everest Labs\Spydefense\Backups|BF7.tmp
FileKey2=%userprofile%\Application Data\Everest Labs\Spydefense|SpyDefense.log
FileKey3=%userprofile%\Application Data\Everest Labs\Spydefense|History.ini
FileKey3=%userprofile%\Application Data\Everest Labs\Spydefense|Backups.ini[Spyware Doctor]
LangSecRef=3024
Detect=HKCU\Software\PCTools\Spyware Doctor
Default=False
FileKey1=%ProgramFiles%\Spyware Doctor\Log|.*[Spyware Terminator]
LangSecRef=3024
Detect=HKCU\Software\Spyware Terminator
Default=False
FileKey1=%ProgramFiles%\Spyware Terminator|.err
FileKey2=%ProgramFiles%\Spyware Terminator|.old
FileKey3=%ProgramFiles%\Spyware Terminator\update|.*
FileKey4=%appdata%\Spyware Terminator\Reports|.
FileKey5=%ProgramFiles%\Spyware Terminator\Clamav|*.old[*StarOffice 8]
LangSecRef=3021
DetectFile=%ProgramFiles%\Sun\StarOffice 8\program\soffice.exe
Default=False
FileKey1=%appdata%\StarOffice8\user\registry\data\org\openoffice\Office|Common.xcu[*Start Menu Ordering]
LangSecRef=3501
LangRef=3611
Default=False
SpecialKey1=R_STARTMENUORDER[*Start Menu Shortcuts]
LangSecRef=3003
LangRef=3612
Default=False
SpecialKey1=F_STARTMENU[Sun Java]
LangSecRef=3022
Detect=HKLM\SOFTWARE\JavaSoft\Java Plug-in
Default=False
FileKey1=%appdata%\Sun\Java\Deployment\cache|.|RECURSE
FileKey2=%appdata%\Sun\Java\Deployment\javaws\cache|.*|RECURSE[Symantec AntiVirus]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Symantec\Symantec AntiVirus\Install\7.50
Default=False
FileKey1=%commonappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|.log
FileKey2=%localappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|.*[*Symantec Ghost]
LangSecRef=3024
Detect=HKCU\Software\Symantec\Symantec Ghost
Default=False
RegKey1=HKCU\Software\Symantec\Symantec Ghost\Explorer\Ghost Explorer\Recent File List[*Synchronize It!]
LangSecRef=3021
Detect=HKCU\Software\grigsoft.com\Synchronize It!
Default=False
RegKey1=HKCU\Software\grigsoft.com\Synchronize It!\Synchronize It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Synchronize It!\Combos[*TUGZip]
LangSecRef=3024
Detect=HKCU\Software\TUGZip
Default=False
RegKey1=HKCU\Software\TUGZip|mainRecent
RegKey2=HKCU\Software\TUGZip|extrRecent
RegKey3=HKCU\Software\TUGZip|cmpWorkingDir[*Tag&Rename 3]
LangSecRef=3024
Detect=HKCU\Software\Softpointer\Tag&Rename3\Config
Default=False
RegKey1=HKCU\Software\Softpointer\Tag&Rename3\Config|FCurrentFolder
RegKey2=HKCU\Software\Softpointer\Tag&Rename3\Config|FHistoryList[Talkback (Crash Reports)]
LangSecRef=3026
Detect=HKLM\SOFTWARE\FullCircle\TalkBack
Default=False
RegKey1=HKLM\SOFTWARE\FullCircle\TalkBack
FileKey1=%userprofile%\Application Data\Talkback\MozillaOrg\Firefox15|.|RECURSE
FileKey2=%userprofile%\Application Data\Talkback\MozillaOrg\Firefox2|.|RECURSE
FileKey3=%userprofile%\Application Data\Talkback\MozillaOrg\Thunderbird2|.*|RECURSE[TechSmith DubIt]
LangSecRef=3023
Detect=HKCU\Software\TechSmith\DubIt
Default=False
FileKey1=%ProgramFiles%\TechSmith\DubIt|.gid
RegKey1=HKCU\Software\TechSmith\DubIt\Recent Audio Files
RegKey2=HKCU\Software\TechSmith\DubIt\Recent Video Files[*Temporary Files]
LangSecRef=3003
LangRef=3142
Default=False
SpecialKey1=N_TEMP_DIRS[*Temporary Internet Files]
LangSecRef=3001
LangRef=3101
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_TEMP[*TeraCopy]
LangSecRef=3024
Detect=HKCU\Software\Code Sector\TeraCopy
Default=False
RegKey1=HKCU\Software\Code Sector\TeraCopy|LastTargetFolder
FileKey1=%appdata%\TeraCopy|FileList.dat
FileKey2=%appdata%\TeraCopy|Transfer.log[*TextPad]
LangSecRef=3021
Detect=HKCU\Software\Helios\TextPad 4
Default=False
RegKey1=HKCU\Software\Helios\TextPad 4\Recent File List
RegKey2=HKCU\Software\Helios\TextPad 4\Recent Strings[The Bat]
LangSecRef=3022
Detect=HKCU\Software\RIT\The Bat!
Default=False
FileKey1=%appdata%\The Bat!\cache|.*[*The Cleaner]
LangSecRef=3024
DetectFile=%ProgramFiles%\The Cleaner\cleaner.exe
Default=False
FileKey1=%ProgramFiles%\The Cleaner|logfile.txt
FileKey2=%ProgramFiles%\The Cleaner|moolive.log
FileKey3=%ProgramFiles%\The Cleaner|tca.log[*The GIMP 2.2]
LangSecRef=3021
DetectFile=%userprofile%.gimp-2.2\gimprc
Default=False
FileKey1=%userprofile%.gimp-2.2|documents[Thumbnail Cache]
LangSecRef=3002
LangRef=3131
DetectOS=6.0
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\Explorer|thumbcache_.db[Tivo Desktop]
LangSecRef=3023
Default=False
Detect=HKCU\SOFTWARE\TiVo\Desktop
FileKey1=%localappdata%\TiVo Desktop\Cache|.*[*Tomahawk PDF+]
LangSecRef=3021
Detect=HKCU\Software\NativeWinds\Tomahawk
Default=False
RegKey1=HKCU\Software\NativeWinds\Tomahawk\MRU[*Total Recorder]
LangSecRef=3023
Detect=HKCU\Software\HighCriteria\TotalRecorder\Recent File List
Default=False
RegKey1=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File1
RegKey2=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File2
RegKey3=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File3
RegKey4=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File4
RegKey5=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File5
RegKey6=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File6
RegKey7=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File7
RegKey8=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File8
RegKey9=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File9[Total Uninstall]
LangSecRef=3024
Detect=HKCU\Software\MartS\Total Uninstall
Default=False
FileKey1=%ProgramFiles%\Total Uninstall|Log.txt
FileKey2=%ProgramFiles%\Total Uninstall|.GID[*Tray Notifications Cache]
LangSecRef=3004
LangRef=3126
WarningRef=3204
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|IconStreams
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|PastIconsStream
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|IconStreams
RegKey4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|PastIconsStream[Trillian]
LangSecRef=3024
Detect=HKLM\Software\Clients\IM\Trillian
Default=False
FileKey1=%ProgramFiles%\Trillian\users\default\instantlookup|.*
FileKey2=%ProgramFiles%\Trillian\users\default\logs|.|RECURSE
FileKey3=%ProgramFiles%\Trillian\users\default\buddyicons|.|RECURSE
FileKey4=%ProgramFiles%\Trillian\Crash Files|.|RECURSE[TuneUp Utilities]
LangSecRef=3024
Detect=HKCU\Software\TuneUp
Default=False
FileKey1=%appdata%\TuneUp Software\TuneUp Utilities\Backups|.rcb[TweakNow PowerPack 2005]
LangSecRef=3024
Detect=HKCU\Software\TweakNow PowerPack
Default=False
FileKey1=%ProgramFiles%\TweakNow PowerPack\Backup|.*[*UPX Shell]
LangSecRef=3024
Detect=HKCU\Software\ION Tek\UPX Shell
Default=False
RegKey1=HKCU\Software\ION Tek\UPX Shell\3.x|History[*Ulead GIF Animator 5.05]
LangSecRef=3024
Detect=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05
Default=False
RegKey1=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05\Recent File List[*Ulead Smart Saver Pro 3.0]
LangSecRef=3023
Detect=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0
Default=False
RegKey1=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0\Recent File List[*UltraISO]
LangSecRef=3024
Detect=HKCU\Software\EasyBoot Systems\UltraISO
Default=False
RegKey1=HKCU\Software\EasyBoot Systems\UltraISO\5.0|Reopen
RegKey2=HKCU\Software\EasyBoot Systems\UltraISO\5.0|a
RegKey3=HKCU\Software\EasyBoot Systems\UltraISO\5.0|b
RegKey4=HKCU\Software\EasyBoot Systems\UltraISO\5.0|c
RegKey5=HKCU\Software\EasyBoot Systems\UltraISO\5.0|d
RegKey6=HKCU\Software\EasyBoot Systems\UltraISO\5.0|e
RegKey7=HKCU\Software\EasyBoot Systems\UltraISO\5.0|f
RegKey8=HKCU\Software\EasyBoot Systems\UltraISO\5.0|g
RegKey9=HKCU\Software\EasyBoot Systems\UltraISO\5.0|h
RegKey10=HKCU\Software\EasyBoot Systems\UltraISO\5.0|i[Universal Share Downloader]
LangSecRef=3022
DetectFile=%ProgramFiles%\USDownloader\USDownloader.exe
Default=False
FileKey1=%ProgramFiles%\USDownloader|USDownloader.log
FileKey2=%ProgramFiles%\USDownloader|.bak
FileKey3=%ProgramFiles%\USDownloader|.bmp
FileKey4=%ProgramFiles%\USDownloader|.jpg
FileKey5=%ProgramFiles%\USDownloader|*.png[*User Assist History]
LangSecRef=3004
LangRef=3128
WarningRef=3206
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist{75048700-EF1F-11D0-9888-006097DEACF9}\Count[*VNCViewer 3]
LangSecRef=3024
Default=False
Detect=HKCU\Software\ORL\VNCviewer
RegKey1=HKCU\Software\ORL\VNCviewer\MRU[*VNCViewer 4]
LangSecRef=3024
Default=False
Detect=HKCU\Software\RealVNC\VNCviewer4
RegKey1=HKCU\Software\RealVNC\VNCviewer4\MRU[Valve - Steam (Logs)]
LangSecRef=3023
Detect=HKCU\Software\Valve\Steam
Default=False
FileKey1=%ProgramFiles%\Valve\Steam\SteamLogs|.log
FileKey2=%ProgramFiles%\Valve\Steam|Steam.log[*Venis IX]
LangSecRef=3021
Detect=HKCU\Software\Spaceblue\Venis IX
Default=False
RegKey1=HKCU\Software\Spaceblue\Venis IX\FileHistory[Ventrilo Client]
LangSecRef=3021
Detect=HKCU\Software\Ventrilo
Default=False
FileKey1=%userprofile%\Application Data\Ventrilo|ventrilo.log
FileKey2=%userprofile%\Application Data\Ventrilo\temp|.*
FileKey3=%userprofile%\Application Data\Ventrilo\recordings|.[*Ventrilo Server]
LangSecRef=3022
DetectFile=%ProgramFiles%\VentSrv\ventrilo_srv.exe
Default=False
FileKey1=%ProgramFiles%\VentSrv|ventrilo_srv.log[VideoGet]
LangSecRef=3022
DetectFile=%ProgramFiles%\VideoGet\VideoGet.exe
Default=False
FileKey1=%ProgramFiles%\VideoGet\Temp|.*[*VirtualCloneDrive]
LangSecRef=3021
Detect=HKLM\Software\Elaborate Bytes\VirtualCloneDrive
Default=False
RegKey1=HKLM\Software\Elaborate Bytes\VirtualCloneDrive\0
RegKey2=HKCU\Software\Elaborate Bytes\VirtualCloneDrive\LRU[*VirtualDub]
LangSecRef=3023
Default=False
Detect=HKCU\Software\Freeware\VirtualDub
RegKey1=HKCU\Software\Freeware\VirtualDub\MRU List[*VirtualFDD]
LangSecRef=3024
Detect=HKCU\Software\Korbos\VirtualFDD
Default=False
RegKey1=HKCU\Software\Korbos\VirtualFDD\Recent File List[Vuze]
LangSecRef=3022
Detect=HKCU\Software\Azureus
Default=False
FileKey1=%appdata%\Azureus\logs|.log
FileKey2=%appdata%\Azureus\logs\save|.log
FileKey3=%userprofile%\Application Data\Azureus\tmp|.*
FileKey4=%userprofile%\Application Data\Azureus|.bak
FileKey5=%userprofile%\Application Data\Azureus|.log
FileKey6=%userprofile%\Application Data\Azureus\active|*.bak[*WM Recorder 10]
LangSecRef=3023
DetectFile=%ProgramFiles%\WM Recorder 10\WMR.exe
Default=False
FileKey1=%ProgramFiles%\WM Recorder 10|log.txt
FileKey2=%ProgramFiles%\WM Recorder 10|urls.txt[WMP (TFC)]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MediaPlayer\Player
Default=False
FileKey1=%UserProfile%\Local Settings\Application Data\Microsoft\Media Player\Transcoded Files Cache|.*[WS FTP (Pro)]
LangSecRef=3022
Detect=HKCU\Software\Ipswitch\WS_FTP
Default=False
FileKey1=%userprofile%\Application Data\Ipswitch\WS_FTP\Logs|.*[*Wavosaur (Logs)]
LangSecRef=3023
DetectFile=%ProgramFiles%\Wavosaur\wavosaur.exe
Default=False
FileKey1=%ProgramFiles%\Wavosaur|wavosaur.log[Webroot SpySweeper]
LangSecRef=3024
Detect=HKCU\Software\Webroot\SpySweeper
FileKey1=%ProgramFiles%\Webroot\Spy Sweeper\Temp|.*
FileKey2=%appdata%\Webroot\Spy Sweeper\Logs|*Log.txt[*WinAVI Video Converter (Log)]
LangSecRef=3023
Detect=HKCU\Software\ZjSoft\WinAVI
Default=False
FileKey1=%LocalAppData%\WinAVI|debug.log[*WinAce 2.0]
LangSecRef=3024
Detect=HKCU\Software\e-merge\WinAce\2.0
Default=False
RegKey1=HKCU\Software\e-merge\WinAce\2.0\Favorites
RegKey2=HKCU\Software\e-merge\WinAce\2.0\MRU Items[*WinCHM]
LangSecRef=3021
Detect=HKCU\Software\Softany\WinCHM
Default=False
RegKey1=HKCU\Software\Softany\WinCHM|RecentFile1
RegKey2=HKCU\Software\Softany\WinCHM|RecentFile2
RegKey3=HKCU\Software\Softany\WinCHM|RecentFile3
RegKey4=HKCU\Software\Softany\WinCHM|RecentFile4
RegKey5=HKCU\Software\Softany\WinCHM|RecentFile5
RegKey6=HKCU\Software\Softany\WinCHM|RecentFile6[*WinDiff]
LangSecRef=3024
Detect=HKCU\Software\Microsoft\Windiff
Default=False
RegKey1=HKCU\Software\Microsoft\Windiff|NameLeft
RegKey2=HKCU\Software\Microsoft\Windiff|NameRight[*WinISO]
LangSecRef=3024
Detect=HKLM\Software\WinISO
Default=False
RegKey1=HKLM\Software\WinISO\Reopen[*WinImage]
LangSecRef=3024
Detect=HKCU\Software\WinImage
Default=False
RegKey1=HKCU\Software\WinImage|File1
RegKey2=HKCU\Software\WinImage|File2
RegKey3=HKCU\Software\WinImage|File3
RegKey4=HKCU\Software\WinImage|File4
RegKey5=HKCU\Software\WinImage|File5
RegKey6=HKCU\Software\WinImage|File6
RegKey7=HKCU\Software\WinImage|File7
RegKey8=HKCU\Software\WinImage|File8
RegKey9=HKCU\Software\WinImage|File9
RegKey10=HKCU\Software\WinImage|PathExtract[*WinMerge]
LangSecRef=3024
Detect=HKCU\Software\Thingamahoochie\WinMerge\Files
Default=False
RegKey1=HKCU\Software\Thingamahoochie\WinMerge\Files\Ext
RegKey2=HKCU\Software\Thingamahoochie\WinMerge\Files\Left
RegKey3=HKCU\Software\Thingamahoochie\WinMerge\Files\Right[*WinPatrol]
LangSecRef=3024
Detect=HKCU\Software\BillP Studios\WinPatrol
Default=False
FileKey1=%ProgramFiles%\BillP Studios\WinPatrol|history.txt[*WinRAR Comment]
LangSecRef=3024
Detect=HKCU\Software\WinRAR
Default=False
RegKey1=HKCU\Software\WinRAR\General\Info|CommentFile[*WinRAR SFX]
LangSecRef=3024
Detect=HKCU\Software\WinRAR SFX
Default=False
RegKey1=HKCU\Software\WinRAR SFX[*WinRAR]
LangSecRef=3024
Detect=HKCU\Software\WinRAR
Default=False
RegKey1=HKCU\Software\WinRAR\ArcHistory
RegKey2=HKCU\Software\WinRAR\General|LastFolder
RegKey3=HKCU\Software\WinRAR\DialogEditHistory\Arcname
RegKey4=HKCU\Software\WinRAR\DialogEditHistory\ExtrPath[WinWAP]
LangSecRef=3022
Detect=HKCU\Software\Winwap Technologies
Default=False
FileKey1=%userprofile%\WinWAP Temporary Files|.*[*WinZip]
LangSecRef=3024
Detect=HKCU\Software\Nico Mak Computing\WinZip
Default=False
RegKey1=HKCU\Software\Nico Mak Computing\WinZip\filemenu
RegKey2=HKCU\Software\Nico Mak Computing\WinZip\extract
RegKey3=HKCU\Software\Nico Mak Computing\WinZip\directories|DefDir
RegKey4=HKCU\Software\Nico Mak Computing\WinZip\directories|ExtractTo
RegKey5=HKCU\Software\Nico Mak Computing\WinZip\directories|gzAddDir
RegKey6=HKCU\Software\Nico Mak Computing\WinZip\directories|zDefDir
RegKey7=HKCU\Software\Nico Mak Computing\WinZip\directories|AddDir
RegKey8=HKCU\Software\Nico Mak Computing\WinZip\directories|gzExtractTo
RegKey9=HKCU\Software\Nico Mak Computing\WinZip\rrs\Opened[Winamp]
LangSecRef=3023
Detect=HKCU\Software\Winamp
Default=False
FileKey1=%ProgramFiles%\Winamp|winamp.m3u
FileKey2=%ProgramFiles%\Winamp|winamp.m3u8
FileKey3=%ProgramFiles%\Winamp\Plugins\ml|recent.dat
FileKey4=%ProgramFiles%\Winamp\Plugins\ml\cache|.|RECURSE
FileKey5=%userprofile%\Application Data\Winamp|winamp.m3u
FileKey6=%userprofile%\Application Data\Winamp|winamp.m3u8
FileKey7=%userprofile%\Application Data\Winamp\Plugins\ml|recent.dat
FileKey8=%userprofile%\Application Data\Winamp\Plugins\ml\Cache|.*|RECURSE[*Window Size/Location Cache]
LangSecRef=3004
LangRef=3127
WarningRef=3205
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams[Windows Defender]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Microsoft\Windows Defender
Default=False
FileKey1=%commonappdata%\Microsoft\Windows Defender\Scans\History\Results\Quick|.*
FileKey2=%commonappdata%\Microsoft\Windows Defender\Scans\History\Results\Resource|.[Windows Error Reporting]
LangSecRef=3003
LangRef=3149
Default=False
DetectOS=6.0
FileKey1=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportArchive|.|RECURSE
FileKey2=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportQueue|.|RECURSE
FileKey3=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportArchive|.|RECURSE
FileKey4=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportQueue|.*|RECURSE[*Windows Live Mail]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Windows Live Mail
Default=False
RegKey1=HKEY_CURRENT_USER\Software\Microsoft\Windows Live Mail|SearchFolderVersion[Windows Live Messenger]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\MSNMessenger\PerPassportSettings
Default=False
RegKey1=HKCU\Software\Microsoft\MessengerService\ListCache.NET Messenger Service
FileKey1=%appdata%\Microsoft\MSN Messenger|.sqm|RECURSE[Windows Live Messenger]
LangSecRef=3022
DetectFile=%ProgramFiles%\Windows Live\Messenger\msnmsgr.exe
Default=False
FileKey1=%USERPROFILE%\Application Data\Microsoft\MSN Messenger|.*|RECURSE[*Windows Live Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\MSN Apps\SearchBox
Default=False
RegKey1=HKCU\Software\Microsoft\MSN Apps\SearchBox|History
RegKey2=HKCU\Software\Microsoft\MSN Apps\MSN Toolbar|SearchStrings[Windows Log Files]
LangSecRef=3003
LangRef=3145
Default=False
FileKey1=%windir%\system32\wbem\Logs|.log
FileKey2=%windir%\system32\wbem\Logs|.lo_
FileKey3=%windir%|.log
FileKey4=%windir%|.bak
FileKey5=%windir%|log.txt
FileKey6=%commonappdata%\Microsoft\Dr Watson|.log
FileKey7=%commonappdata%\Microsoft\Dr Watson|.dmp
FileKey8=%windir%\Debug|.log
FileKey9=%windir%\Debug\UserMode|.log
FileKey10=%windir%\Debug\UserMode|.bak
FileKey11=%windir%|SchedLgU.txt
FileKey12=%windir%\security\logs|.log
FileKey13=%windir%\security\logs|*.old[Windows ME]
LangSecRef=3025
DetectFile=%windir%\WINFILE.EXE
Default=False
FileKey1=%rootdir%|SCANDISK.LOG
FileKey2=%windir%|.tmp
FileKey3=%windir%\Application Data|dw.log
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|.
FileKey5=%windir%\APPLOG|.LGC
FileKey6=%windir%\Windows Update Setup Files|.*[*Windows Media Player]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MediaPlayer\Player
Default=False
RegKey1=HKCU\Software\Microsoft\MediaPlayer\Player\RecentFileList
RegKey2=HKCU\Software\Microsoft\MediaPlayer\Player\RecentURLList
RegKey3=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayList
RegKey4=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayListIndex
RegKey5=HKCU\Software\Microsoft\MediaPlayer\Player\Settings|SaveAsDir
RegKey6=HKCU\Software\Microsoft\MediaPlayer\AutoComplete\MediaEdit
RegKey7=HKCU\Software\Microsoft\MediaPlayer\Radio\MRUList[*Windows Movie Maker]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MovieMaker
Default=False
FileKey1=%localappdata%\Microsoft\Movie Maker|MEDIATAB0.DAT[Windows Update Logs]
LangSecRef=3025
DetectFile=%windir%\SoftwareDistribution\DataStore\Logs
Default=False
FileKey1=%windir%\SoftwareDistribution\DataStore\Logs|.*[*Wipe Free Space]
LangSecRef=3004
LangRef=3132
WarningRef=3207
Default=False
DetectOS=5.0
SpecialKey1=N_EX_WIPEFREESPACE[*Wordweb]
LangSecRef=3021
DetectFile=%ProgramFiles%\WordWeb\wweb32.exe
Default=False
FileKey1=%userprofile%\Application Data\WordWeb|History.txt[*X-Cleaner (free)]
LangSecRef=3024
DetectFile=%ProgramFiles%\X-Cleaner\XCleaner_free.exe
Default=False
FileKey1=%ProgramFiles%\X-Cleaner|XCL_LOG.txt[*X-Cleaner (full)]
LangSecRef=3024
DetectFile=%ProgramFiles%\X-Cleaner\XCleaner_full.exe
Default=False
FileKey1=%ProgramFiles%\X-Cleaner|XCL_LOG.txt[XFire (Logs)]
LangSecRef=3022
Detect=HKLM\Software\Xfire
Default=False
FileKey1=%userprofile%\Application Data\Xfire\chatlog|.*|RECURSE[*XML Spy]
LangSecRef=3021
Detect=HKCU\Software\Altova\XML Spy
Default=False
RegKey1=HKCU\Software\Altova\XML Spy\Recent File List
RegKey2=HKCU\Software\Altova\XML Spy\Recent Project List[*XN Resource Editor]
LangSecRef=3024
Detect=HKCU\Software\Woozle\XN Resource Editor
Default=False
RegKey1=HKCU\Software\Woozle\XN Resource Editor\Recent Files[*XviD Stats]
LangSecRef=3023
Detect=HKCU\Software\GNU\Xvid
Default=False
RegKey1=HKCU\Software\GNU\Xvid|stats[*YPOPs]
LangSecRef=3021
DetectFile=%ProgramFiles%\YPOPs\ypops.exe
Default=False
FileKey1=%ProgramFiles%\YPOPs|ypops.log[Yahoo Messenger (Logs/Cache)]
LangSecRef=3022
Detect=%ProgramFiles%\Yahoo!\Messenger|ypager.log
Default=False
FileKey1=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey2=%ProgramFiles%\Yahoo!\Messenger\Profiles|.|RECURSE
FileKey3=%ProgramFiles%\Yahoo!\Messenger\Cache|.|RECURSE
FileKey4=%ProgramFiles%\Yahoo!\Messenger\IMVCache|.*|RECURSE[Yahoo Messenger (Logs/Cache)]
LangSecRef=3022
Detect=HKCU\Software\Yahoo\pager
Default=False
FileKey1=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey2=%ProgramFiles%\Yahoo!\Messenger\Profiles|.|RECURSE
FileKey3=%ProgramFiles%\Yahoo!\Messenger\Cache|.|RECURSE
FileKey4=%ProgramFiles%\Yahoo!\Messenger\IMVCache|.*|RECURSE[*Yahoo! Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Yahoo\Companion
Default=False
RegKey1=HKCU\Software\Yahoo\Companion\SearchHistory[*ZX32 ZX Spectrum Emulator v1.03]
LangSecRef=3021
Detect=HKCU\Software\VK\zx32\1.03
Default=False
RegKey1=HKCU\Software\VK\zx32\1.03\FileMRU[*ZipGenius]
LangSecRef=3024
Detect=HKCU\Software\M.Dev Software\ZG5
Default=False
RegKey1=HKCU\Software\M.Dev Software\ZG5\MRU Items
FileKey1=%appdata%\ZipGenius|mru.dat[*ZipMagic]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Mijenix\ZipMagic
RegKey1=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Recent
RegKey2=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Archive Manager\UnZip To
RegKey3=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\UnZip To
RegKey4=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Zip To[ZoneAlarm (Logs)]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Zone Labs\ZoneAlarm
Default=False
FileKey1=%windir%\Internet Logs|ZALog.*[*eBay Toolbar]
LangSecRef=3022
DetectFile=%ProgramFiles%\eBay\eBay Toolbar2\eBayTBDaemon.exe
Default=False
RegKey1=HKCU\Software\eBay\eBayToolbar\History
RegKey2=HKCU\Software\eBay\eBayToolbar\RecentSearches
FileKey1=%ProgramFiles%\eBay\eBay Toolbar2|toolbar.log
FileKey2=%ProgramFiles%\eBay\eBay Toolbar2|eBayDaemon.log[*eMule (File Hashes)]
LangSecRef=3022
Detect=HKCU\Software\eMule
Default=False
FileKey1=%ProgramFiles%\eMule\config|known.met
FileKey2=%ProgramFiles%\eMule\config|known2.met[*eMule (Search History)]
LangSecRef=3022
Detect=HKCU\Software\eMule
Default=False
FileKey1=%ProgramFiles%\eMule\config|AC_SearchStrings.dat[iSysCleaner]
LangSecRef=3024
DetectFile=%ProgramFiles%\Utils\iSysCleaner\iSysCleaner.exe
Default=False
FileKey1=%ProgramFiles%\Utils\iSysCleaner\traces|.*[mIRC]
LangSecRef=3022
Detect=HKCU\Software\mIRC
Default=False
DectectFile=%ProgramFiles%\mirc\mIRC.exe
Filekey1=%ProgramFiles%\mirc\logs|.*[neXBC]
LangSecRef=3022
DetectFile=%ProgramFiles%\neXBC\neXBC.exe
Default=False
FileKey1=%ProgramFiles%\neXBC|messages.txt
FileKey2=%ProgramFiles%\neXBC\Logs\Hosted|.*
FileKey3=%ProgramFiles%\neXBC\Logs\Joined|.[uTorrent]
LangSecRef=3022
DetectFile=%ProgramFiles%\uTorrent\uTorrent.exe
Default=False
FileKey1=%ProgramFiles%\uTorrent|.dmp