winapp2.ini from CC site befroe deleting on site.

; CCleaner - Application Cleaning file

[*Global]

Revision=2012

NextIDValue=2145

;

; WARNING - DO NOT EDIT THIS FILE
; If you would like to create custom entries then create a new file
; called winapp2.ini which follows the same format as this one.
; CCleaner will automatically pick up the new file.
;
; Copyright ?2004-2009 Piriform Ltd, All Rights Reserved.
; This file and it's contents may not be copied or distributed
; without the express permission of the author.
;
; Notes
; ---------------------------------------
; LangSecRef
;  3021 = Applications
;  3022 = Internet
;  3023 = Multimedia
;  3024 = Utilities
;  3025 = Windows
;  3026 = Firefox/Mozilla
;  3027 = Opera
;  3028 = Safari

[*32bit Web Browser]
LangSecRef=3022
DetectFile=%ProgramFiles%\32BITWEB\32BW.exe
Default=False
FileKey1=%ProgramFiles%\32BITWEB\Data|LastURL.dat
FileKey2=%ProgramFiles%\32BITWEB\Data|LastURL.DA0

[*3GP Video Converter]
LangSecRef=3023
Detect=HKCU\Software\ImTOO\3GP Video Converter
Default=False
RegKey1=HKCU\Software\ImTOO\3GP Video Converter\Settings|last_openpath
RegKey2=HKCU\Software\ImTOO\3GP Video Converter\Settings|OuputDir

[*7-Zip]
LangSecRef=3024
Default=False
Detect=HKCU\SOFTWARE\7-ZIP
RegKey1=HKCU\SOFTWARE\7-ZIP\Compression\ArcHistory
RegKey2=HKCU\SOFTWARE\7-ZIP\Extraction\PathHistory
RegKey3=HKCU\Software\7-Zip\FM|CopyHistory
RegKey4=HKCU\Software\7-Zip\FM|FolderHistory
RegKey5=HKCU\Software\7-Zip\FM|PanelPath0

[A-squared Free]
LangSecRef=3024
Detect=HKLM\Software\Emsi Software GmbH\a-squared Free
Default=False
FileKey1=%userprofile%\My Documents\a-squared\Reports|
.*
FileKey2=%programfiles%\a-squared Free\Logs|.

[*AI Roboform Search]
LangSecRef=3022
Detect=HKCU\Software\Siber Systems
Default=False
RegKey1=HKCU\Software\Siber Systems\RoboForm\Query-MRU

[AOL AIM Messenger]
Default=False
DetectFile=%userprofile%\Application Data\acccore\caches\bart
FileKey1=%userprofile%\Application Data\acccore\caches\bart|
.|RECURSE
fileKey2=%userprofile%\Local Settings\Application Data\AIM\Settings\aolbartcache|
.*|RECURSE
LangSecRef=3022

[*AOL Instant Messenger]
LangSecRef=3022
Detect=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion
Default=False
RegKey1=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent IM ScreenNames
RegKey2=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent ScreenNames
RegKey3=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\Users

[*AVG Anti-Spyware]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\AVGAntiSpyware
Default=False
FileKey1=%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5|logfile.txt

[AVG AntiVirus 8.0]
: Modified to handle AVG Temp folder
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|
.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|
.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|.
FileKey5=%allusersprofile%\Application Data\avg8\temp|*.tmp

[AVG AntiVirus 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|
.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|
.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|.

[AVG AntiVirus 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|
.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|
.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|.
FileKey5=%allusersprofile%\Application Data\avg8\Emc\Log|*.log

[AVG AntiVirus 9.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg9
Default=False
FileKey1=%allusersprofile%\Application Data\avg9\Log|
.log
FileKey2=%allusersprofile%\Application Data\avg9\scanlogs|.log
FileKey3=%allusersprofile%\Application Data\avg9\Log|
.xml
FileKey4=%allusersprofile%\Application Data\avg9\update\backup|.
FileKey5=%allusersprofile%\Application Data\avg9\Emc\Log|*.log

[*AVI Preview]
LangSecRef=3023
Detect=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit www.avipreview.com for more
Default=False
RegKey1=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit www.avipreview.com for more\Recent File List

[*AVS Disc Creator (Logs)]
LangSecRef=3021
Detect=HKLM\Software\AVS\DiscCreator
Default=False
FileKey1=%windir%|coredw.log
FileKey2=%windir%|datawriter.log

[Ace Utilities]
LangSecRef=3024
Detect=HKCU\Software\Acelogix\Ace Utilities
Default=False
FileKey1=%userprofile%\My Documents\Ace Utilities Backups|
.reg

[*AceHTML 5]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Visicom Media\AceHTML 5 Freeware
RegKey1=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last URLs
RegKey2=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Projects
RegKey3=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Open
RegKey4=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Files

[Acronis True Image Home]
LangSecRef=3024
Detect=HKCU\Software\Acronis\TrueImageHome
Default=False
FileKey1=%allusersprofile%\Application Data\Acronis\TrueImage\Logs|
.log

[Acronis True Image]
LangSecRef=3024
Detect=HKCU\Software\Acronis\TrueImage
Default=False
FileKey1=%userprofile%\Application Data\Acronis\TrueImage\Logs|
.log

[*ActiveX and Class Issues]
LangSecRef=3501
LangRef=3603
Default=False
SpecialKey1=R_ACTIVEX

[Ad-Aware SE Personal]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|
.txt

[Ad-Aware SE Plus]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|
.txt

[Ad-Aware SE Professional]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|
.txt

[*Adaptec’s Audio CD]
LangSecRef=3024
Detect=HKCU\Software\Adaptec
Default=False
RegKey1=HKCU\Software\Adaptec\AUDIO_CD_INFO

[*Adobe Acrobat 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral\cRecentFiles

[Adobe Acrobat 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|
.*|RECURSE

[*Adobe Acrobat 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral\cRecentFiles

[Adobe Acrobat 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|
.*|RECURSE

[*Adobe Acrobat 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral\cRecentFiles

[Adobe Acrobat 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|
.*|RECURSE

[*Adobe Acrobat 8.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral\cRecentFiles

[*Adobe Acrobat Reader 4.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\4.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile1
RegKey2=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile2
RegKey3=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile3
RegKey4=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile4

[Adobe Acrobat Reader 4.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\4.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile1
RegKey2=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile2
RegKey3=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile3
RegKey4=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile4
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|
.*|RECURSE

[*Adobe Acrobat Reader 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles

[*Adobe Acrobat Reader 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral\cRecentFiles

[Adobe Acrobat Reader 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\7.0\Cache\Search70|
.*
FileKey2=%ProgramFiles%\Adobe\Acrobat 7.0\Reader|.bak
FileKey3=%ProgramFiles%\Adobe\Acrobat 7.0\ActiveX|
.bak
FileKey4=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\plug_ins|.bak
FileKey5=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\Updater|
.bak

[*Adobe Flash Player]
LangSecRef=3023
Detect=HKCR\CLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}
Default=False
SpecialKey1=N_FLASH_COOKIES

[*Adobe Illustrator CS4]
LangSecRef=3021
Detect=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator
Default=False
RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator\FileList

[*Adobe ImageReady 7.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\ImageReady 7.0
RegKey1=HKCU\Software\Adobe\ImageReady 7.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 7.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 7.0\Preferences\RecentFiles

[*Adobe ImageReady CS]
LangSecRef=3021
Detect=HKCU\Software\Adobe\ImageReady 8.0
Default=False
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles

[Adobe ImageReady CS]
LangSecRef=3021
Detect=HKCU\Software\Adobe\ImageReady 8.0
Default=False
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|
.*|RECURSE

[*Adobe Photoshop 5.5]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\5.5
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\5.5\VisitedDirs

[Adobe Photoshop 5.5]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\5.5
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\5.5\VisitedDirs
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|
.*|RECURSE

[*Adobe Photoshop 6.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\6.0
RegKey1=HKCU\Software\Adobe\Photoshop\6.0\VisitedDirs

[*Adobe Photoshop 7.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\7.0
RegKey1=HKCU\Software\Adobe\Photoshop\7.0\VisitedDirs

[Adobe Photoshop CS2]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\9.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\9.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
FileKey1=%appdata%\Adobe\CameraRaw\Cache|
.*

[*Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs

[*Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList

[Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|
.*|RECURSE

[*Adobe Photoshop CS4]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\11.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\11.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList

[*Adobe Photoshop CS]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\8.0
RegKey1=HKCU\Software\Adobe\Photoshop\8.0\VisitedDirs

[Adobe Reader 8.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\8.0\Cache\Search80|
.*

[Adobe Reader 8]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5|
.log
FileKey2=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.|RECURSE

[Adobe Reader 9.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\9.0\Cache\Search90|
.*

[Adobe Reader 9]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\9.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Updater6|
.log
FileKey2=%LocalAppData%\Adobe\Updater6\Install|.|RECURSE

[*Advanced Searchbar]
LangSecRef=3022
Detect= HKCU\Software\Advanced Searchbar\Toolbar
Default=False
RegKey1=HKCU\Software\Advanced Searchbar\Toolbar\Historysearchbox1

[Ahead Nero Burning Rom 8]
LangSecRef=3021
Detect=HKCU\Software\Nero\Nero8
Default=False
RegKey1=HKCU\Software\Nero\Nero8\Cover Designer\Recent File List
RegKey2=HKCU\Software\Nero\Nero8\Nero - Burning Rom\Recent File List
FileKey1=%userprofile%\Application Data\Nero\Nero8\Nero Burning ROM|
.log

[*Ahead Nero PhotoSnap]
LangSecRef=3021
Detect=HKCU\Software\ahead\Nero PhotoSnap
Default=False
RegKey1=HKCU\Software\ahead\Nero PhotoSnap\Recent File List

[*Ahead NeroSearch]
LangSecRef=3021
Detect=HKCU\Software\Ahead\NeroSearch
Default=False
RegKey1=HKCU\Software\Ahead\NeroSearch\NeroSavedSearches\SavedSearches

[*Ahead NeroVision 2.0]
LangSecRef=3021
Detect=HKCU\Software\ahead\NeroVision\2.0
Default=False
RegKey1=HKCU\Software\ahead\NeroVision\2.0\RecentFiles

[*AkelPad]
LangSecRef=3024
Detect=HKCU\Software\Akelsoft\AkelPad
Default=False
RegKey1=HKCU\Software\Akelsoft\AkelPad\Recent
RegKey2=HKCU\Software\Akelsoft\AkelPad\Search

[*Alcohol 120%]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Alcohol Soft\Alcohol 120%
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 120%\MountedMRU

[*Alcohol 52%]
LangSecRef=3023
Detect=HKCU\Software\Alcohol Soft
Default=False
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 52%\Images
RegKey2=HKCU\Software\Alcohol Soft\Alcohol 52%\MountedMRU\0
RegKey3=HKCU\Software\Alcohol Soft\Alcohol 52%\Basic|Image File Path
RegKey4=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageFilePath
RegKey5=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageName

[Always Right]
LangSecRef=3024
Detect=HKCU\Software\AlwaysRight
Default=False
FileKey1=%ProgramFiles%\Superhunter\Always Right\FileBackup|
.*
FileKey2=%ProgramFiles%\Superhunter\Always Right\RegBackup|.

[America Online 9.1]
Default=False
DetectFile=%allusersprofile%\Application Data\AOL\C_AOL 9.1
FileKey1=%allusersprofile%\Application Data\AOL\C_AOL 9.1\bart|
.|RECURSE
FileKey2=%allusersprofile%\Application Data\AOL\C_AOL 9.1\spool|
.*|RECURSE
LangSecRef=3021

[Amsn - Display Pictures]
LangSecRef=3021
Default=False
Detect=HKCU\Software\aMSN
FileKey1=%userprofile%\amsn\displaypic\cache|
.*

[*Anim8or]
LangSecRef=3021
Detect=HKCU\Software\Silicon Valley Software\Anim8or
Default=False
RegKey1=HKCU\Software\Silicon Valley Software\Anim8or|File1
RegKey2=HKCU\Software\Silicon Valley Software\Anim8or|File2
RegKey3=HKCU\Software\Silicon Valley Software\Anim8or|File3
RegKey4=HKCU\Software\Silicon Valley Software\Anim8or|File4

[AntiVir Desktop]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Avira\AntiVir Desktop
Default=False
FileKey1=%commonappdata%\Avira\AntiVir Desktop\FAILSAVE|
.*
FileKey2=%commonappdata%\Avira\AntiVir Desktop\INFECTED|.
FileKey3=%commonappdata%\Avira\AntiVir Desktop\LOGFILES|.
FileKey4=%commonappdata%\Avira\AntiVir Desktop\SYSSAVE|.
FileKey5=%commonappdata%\Avira\AntiVir Desktop\TEMP|.
FileKey6=%ProgramFiles%\Avira\AntiVir Desktop|.old
FileKey7=%ProgramFiles%\Avira\AntiVir Desktop|
.tmp
FileKey8=%ProgramFiles%\Avira\AntiVir Desktop\FAILSAFE|*.tmp

[AntiVir Personal 8]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Avira\AntiVir PersonalEdition Classic
Default=False
FileKey1=%commonappdata%\Avira\AntiVir PersonalEdition Classic\BACKUP\FAILSAFE|
.tmp
FileKey2=%commonappdata%\Avira\AntiVir PersonalEdition Classic\LOGFILES|.log
FileKey3=%ProgramFiles%\Avira\AntiVir PersonalEdition Classic|
.tmp
FileKey4=%ProgramFiles%\Avira\AntiVir PersonalEdition Classic\FAILSAFE|*.tmp

[*Application Paths]
LangSecRef=3501
LangRef=3606
Default=False
SpecialKey1=R_APP_PATHS

[*Applications]
LangSecRef=3501
LangRef=3604
Default=False
SpecialKey1=R_APP_OPENWITH

[*Arasan Chess]
LangSecRef=3024
Detect=HKCU\Software\Arasan\Arasan
Default=False
RegKey1=HKCU\Software\Arasan\Arasan\Recent File List

[Ashampoo Burning Studio 7]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Burn Image Project\AddDialog
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Dump Image Project\DumpImage
RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Unknown Project\AddDialog
FileKey1=%appdata%\Ashampoo\Ashampoo Burning Studio 2007\Logs|
.*

[Ashampoo Burning Studio 9]
LangSecRef=3024
Detect=HKLM\Software\Ashampoo\Ashampoo Burning Studio 2009
Default=False
FileKey1=%appdata%\Ashampoo\Ashampoo Burning Studio 2009|backupmetainfo.xml
FileKey2=%appdata%\Ashampoo\Ashampoo Burning Studio 2009\Logs|
.xml
FileKey3=%appdata%\Ashampoo\Logs|*.txt

[*Ashampoo Burning Studio 5]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\DumpImage
RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Unknown Project\AddDialog

[Ashampoo Burning Studio 6 Free (Logs)]
LangSecRef=3023
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6
Default=False
FileKey1=%userprofile%\Application Data\Ashampoo\Ashampoo Burning Studio 6 Free\Logs|
.*

[*Ashampoo Burning Studio 6]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Unknown Project\AddDialog

[*Ashampoo Burning Studio 7]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Unknown Project\AddDialog

[*Ashampoo Burning Studio 8]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8\Data Disc Project\AddDialog

[*Audacity]
LangSecRef=3023
Detect=HKCU\Software\Audacity
Default=False
RegKey1=HKCU\Software\Audacity\Audacity\RecentFiles

[AusLogics Disk Defrag]
LangSecRef=3024
Detect=HKCU\Software\AusLogics\Disk Defrag\1.x
Default=False
FileKey1=%ProgramFiles%\AusLogics Disk Defrag\reports|
.*

[AusLogics Registry Defrag]
LangSecRef=3024
Detect=HKCU\Software\AusLogics\Registry Defrag\4.x
Default=False
FileKey1=%ProgramFiles%\AusLogics Registry Defrag\Data\RegistryDefrag|
.*
FileKey2=%ProgramFiles%\AusLogics Registry Defrag\Reports\Registry Defrag|.

[Auslogics Free Utilities]
LangSecRef=3024
Detect=HKCU\Software\Auslogics
Default=False
FileKey1=%appdata%\Auslogics\Disk Defrag\Reports|
.*
FileKey2=%appdata%\Auslogics\Registry Defrag\Logs|.
FileKey3=%appdata%\Auslogics\Registry Defrag\Reports|.
FileKey4=%appdata%\Auslogics\System Information\Reports|.

[AutoIt3]
LangSecRef=3021
Detect=HKCU\Software\AutoIt v3
Default=False
RegKey1=HKCU\Software\AutoIt v3\Aut2Exe|LastExeDir
RegKey2=HKCU\Software\AutoIt v3\Aut2Exe|LastIcon
RegKey3=HKCU\Software\AutoIt v3\Aut2Exe|LastIconDir
RegKey4=HKCU\Software\AutoIt v3\Aut2Exe|LastScriptDir
FileKey1=%userprofile%|SciTE.

[*Autocomplete Form History]
LangSecRef=3001
LangRef=3106
WarningRef=3202
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
SpecialKey1=N_INT_AUTOCOMPLETE

[*Avant Browser]
LangSecRef=3022
DetectFile=%ProgramFiles%\Avant Browser\avant.exe
Default=False
FileKey1=%appdata%\Avant Browser|keywords.dat
FileKey2=%appdata%\Avant Browser|pages.dat
FileKey3=%appdata%\Avant Browser|recents.dat
FileKey4=%appdata%\Avant Browser|reopen.dat

[Avast Antivirus]
LangSecRef=3024
Detect=HKCU\Software\ALWIL Software\Avast
Default=False
FileKey1=%ProgramFiles%\Alwil Software\Avast4\DATA\report|avast.xsl
FileKey2=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Resident protection.txt
FileKey3=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Simple user interface.txt
FileKey4=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Simple user interface
.xml
FileKey5=%ProgramFiles%\Alwil Software\Avast4\DATA\log|.

[Avi-Mux GUI]
LangSecRef=3023
DetectFile=%ProgramFiles%\AVIMuxGUI\AVIMux_GUI.exe
Default=False
FileKey1=%ProgramFiles%\AVIMuxGUI|AVI-Mux GUI - Logfile

FileKey2=%ProgramFiles%\AVIMuxGUI|*.dmp

[*Avira RootKit Detection]
LangSecRef=3024
DetectFile=%ProgramFiles%\Avira GmbH\Avira RootKit Detection\avirarkd.exe
Default=False
FileKey1=%ProgramFiles%\Avira GmbH\Avira RootKit Detection|avirarkd.log

[Axialis IconWorkshop]
LangSecRef=3023
Detect=HKCU\Software\Axialis\IconWorkshop
Default=False
RegKey1=HKCU\Software\Axialis\IconWorkshop\Recent File List
RegKey2=HKCU\Software\Axialis\IconWorkshop\CoolBarList
FileKey1=%appdata%\Axialis\Temporary Preview Files|
.*|RECURSE

[Azureus]
LangSecRef=3022
DetectFile=%userprofile%\Application Data\Azureus.lock
Default=False
FileKey1=%userprofile%\Application Data\Azureus\tmp|
.*
FileKey2=%userprofile%\Application Data\Azureus|.bak
FileKey3=%userprofile%\Application Data\Azureus|
.log
FileKey4=%userprofile%\Application Data\Azureus\active|.bak
FileKey5=%userprofile%\Application Data\Azureus\plugins\advancedstatistics|
.txt
FileKey6=%userprofile%\Application Data\Azureus\plugins\progressbar|*.txt

[*BSPlayer]
LangSecRef=3023
Detect=HKCU\Software\BST\bsplayer
Default=False
RegKey1=HKCU\Software\BST\bsplayer|File0
RegKey2=HKCU\Software\BST\bsplayer|File1
RegKey3=HKCU\Software\BST\bsplayer|File2
RegKey4=HKCU\Software\BST\bsplayer|File3
RegKey5=HKCU\Software\BST\bsplayer|File4
RegKey6=HKCU\Software\BST\bsplayer|File5
RegKey7=HKCU\Software\BST\bsplayer|File6
RegKey8=HKCU\Software\BST\bsplayer|File7
RegKey9=HKCU\Software\BST\bsplayer|File8
RegKey10=HKCU\Software\BST\bsplayer|File9

[*Babylon]
LangSecRef=3024
Detect=HKCU\Software\Babylon\Babylon Translator\UserInfo
Default=False
RegKey1=HKCU\Software\Babylon\Babylon Translator\UserInfo\History

[BitDefender 9]
LangSecRef=3024
Detect=HKLM\Software\Softwin\BitDefender Antivirus
Default=False
FileKey1=%ProgramFiles%\Softwin\BitDefender9\Logs|
.*

[BitTorrent]
LangSecRef=3022
DetectFile=%ProgramFiles%\BitTorrent\bittorrent.exe
Default=False
FileKey1=%userprofile%\Application Data\BitTorrent\incomplete|
.*

[Boinc]
LangSecRef=3024
DetectFile=%ProgramFiles%\BOINC\boinc.exe
Default=False
FileKey1=%ProgramFiles%\BOINC|stdout
.*
FileKey2=%ProgramFiles%\BOINC|stderr*.*

[*Borland C++ Builder 5.0]
LangSecRef=3024
Detect=HKCU\Software\Borland\C++Builder\5.0
Default=False
RegKey1=HKCU\Software\Borland\C++Builder\5.0\Closed Files
RegKey2=HKCU\Software\Borland\C++Builder\5.0\Closed Projects
RegKey3=HKCU\Software\Borland\C++Builder\5.0\Session

[*Borland Developer Studio 2006]
LangSecRef=3024
Detect=HKCU\Software\Borland\BDS\4.0
Default=False
RegKey1=HKCU\Software\Borland\BDS\4.0\Closed Files
RegKey2=HKCU\Software\Borland\BDS\4.0\Closed Projects
KegKey3=HKCU\Software\Borland\BDS\4.0\Session

[CA Anti-Virus]
LangSecRef=3024
Default=False
Detect=HKLM\SOFTWARE\ComputerAssociates\Anti-Virus
FileKey1=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|
.log
FileKey2=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|log.txt
FileKey3=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ArcTemp|
.tmp
FileKey4=%commonappdata%\CA\Consumer\AV|.tmp|RECURSE
FileKey5=%commonappdata%\CA\Consumer\AV|
.txt|RECURSE
FileKey6=%commonappdata%\CA\Consumer\CCube|.tmp|RECURSE
FileKey7=%commonappdata%\CA\Consumer\CCube|
.txt|RECURSE
FileKey8=%commonappdata%\CA\Consumer\ISS\FeedStore|.txt|RECURSE
FileKey9=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\ArcTemp|
.*
FileKey10=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\tmp|.

[CDex]
LangSecRef=3024
Detect=HKLM\SOFTWARE\CDex
Default=False
FileKey1=%userprofile%\My Documents\My Music\CDDB|
.txt

[*Centarsia]
LangSecRef=3021
Detect=HKCU\Software\Centarsia
Default=False
RegKey1=HKCU\Software\Centarsia|RecentImage0
RegKey2=HKCU\Software\Centarsia|RecentImage1
RegKey3=HKCU\Software\Centarsia|RecentImage2
RegKey4=HKCU\Software\Centarsia|RecentImage3
RegKey5=HKCU\Software\Centarsia|RecentImage4
RegKey6=HKCU\Software\Centarsia|RecentImage5
RegKey7=HKCU\Software\Centarsia|RecentImage6

[Chkdsk File Fragments]
LangSecRef=3003
LangRef=3144
Default=False
FileKey1=%SystemDrive%|File
.chk

[ClamWin]
LangSecRef=3024
Detect=HKCU\Software\ClamWin
Default=False
FileKey1=%allusersprofile%.clamwin\log|
.*
FileKey2=%userprofile%.clamwin\log|.
FileKey3=%windir%\All Users.clamwin\log|.

[*Clipboard]
LangSecRef=3003
LangRef=3148
Default=False
SpecialKey1=N_TEMP_CLIPBOARD

[*CloneCD]
LangSecRef=3021
Detect=HKLM\Software\SlySoft\CloneCD
Default=False
RegKey1=HKCU\Software\SlySoft\CloneCD\Settings|ImageFileName

[*CoffeeCup GIF Animator]
LangSecRef=3024
Detect=HKCU\Software\CoffeeCup Software\GIF Animator
Default=False
RegKey1=HKCU\Software\CoffeeCup Software\GIF Animator\Settings\MRU

[*Compare It!]
LangSecRef=3021
Detect=HKCU\Software\grigsoft.com\Compare It!
Default=False
RegKey1=HKCU\Software\grigsoft.com\Compare It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Compare It!\dirs
RegKey3=HKCU\Software\grigsoft.com\Compare It!\options|Recent0
RegKey4=HKCU\Software\grigsoft.com\Compare It!\options|Recent1
RegKey5=HKCU\Software\grigsoft.com\Compare It!\options|Recent2
RegKey6=HKCU\Software\grigsoft.com\Compare It!\options|Recent3
RegKey7=HKCU\Software\grigsoft.com\Compare It!\options|Recent4
RegKey8=HKCU\Software\grigsoft.com\Compare It!\options|Recent5
RegKey9=HKCU\Software\grigsoft.com\Compare It!\options|Recent6
RegKey10=HKCU\Software\grigsoft.com\Compare It!\options|Recent7
RegKey11=HKCU\Software\grigsoft.com\Compare It!\options|Recent8
RegKey12=HKCU\Software\grigsoft.com\Compare It!\options|Recent9
RegKey13=HKCU\Software\grigsoft.com\Compare It!\options|Recent10

[*ConTEXT]
LangSecRef=3021
Detect=HKCU\Software\Eden\ConTEXT
Default=False
Regkey1=HKCU\Software\Eden\ConTEXT\FileHistory
Regkey2=HKCU\Software\Eden\ConTEXT\FindHistory

[Config.msi Folder]
LangSecRef=3025
Default=False
DetectFile=%windir%\system32\msiexec.exe
FileKey1=%systemdrive%\Config.msi|
.*|RECURSE

[ConvertXToDVD]
LangSecRef=3023
Detect=HKCU\Software\VSO\ConvertXToDVD
Default=False
FileKey1=%userprofile%\Application Data\Vso|
.log

[*Cookies]
LangSecRef=3001
LangRef=3102
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_COOKIES

[*Copernic Desktop Search]
LangSecRef=3021
Detect=HKCU\Software\Copernic\DesktopSearch2
Default=False
RegKey1=HKCU\Software\Copernic\DesktopSearch2\Config\SearchHistory

[CounterSpy]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Sunbelt Software\CounterSpy
Default=False
FileKey1=%allusersprofile%\Application Data\Sunbelt Software\CounterSpy\Logs|
.*

[*Creative Pro Proteus VX]
LangSecRef=3023
Detect=HKCU\Software\Creative Professional\Proteus VX
Default=False
RegKey1=HKCU\Software\Creative Professional\Proteus VX VSTi\Recent File List

[Custom File Deletion]
LangSecRef=3024
FileKey1=%allusersprofile%\DRM\Cache|
.|recurse
FileKey2=%userprofile%\Application Data\Microsoft\Outlook Express\News|cleanup.log
FileKey3=%userprofile%\Cookies|
.|recurse
FileKey4=%userprofile%\Local Settings\History\History.IE5|
.|recurse
FileKey5=%userprofile%\Local Settings\Temporary Internet Files\Content.IE5|
.|recurse
FileKey6=%userprofile%\Local Settings\Temp|
.|recurse
FileKey7=%userprofile%\UserData|
.|recurse
FileKey8=%windir%\Prefetch|
.pf|recurse
FileKey9=%windir%\system32\config\systemprofile\Cookies|.|recurse
FileKey10=%windir%\system32\config\systemprofile\Local Settings\History\History.IE5|.|recurse
FileKey11=%windir%\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5|.|recurse
FileKey12=%windir%\Temp|.|recurse
FileKey13=C:\Documents and Settings\LocalService\Cookies|.|recurse
FileKey14=C:\Documents and Settings\LocalService\Local Settings\History\History.IE5|.|recurse
FileKey15=C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5|.|recurse

[*Custom Folders]
LangSecRef=3004
LangRef=3129
SpecialKey1=N_EX_CUSTOMFOLDERS

[CuteFTP Home 7.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Home
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\7.0\Cache|
.|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\7.0\CacheThumbs|
.*|RECURSE

[CuteFTP Home 8.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Home
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\8.0\Cache|
.|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\8.0\CacheThumbs|
.*|RECURSE

[CuteFTP Pro 7.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Professional
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\Cache|
.|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\CacheThumbs|
.*|RECURSE

[CuteFTP Pro 8.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Professional
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\Cache|
.|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\CacheThumbs|
.*|RECURSE

[*CuteHTML 2.3]
LangSecRef=3024
Detect=HKCU\Software\GlobalSCAPE\CuteHTML\2.3
Default=False
RegKey1=HKCU\Software\GlobalSCAPE\CuteHTML\2.3\Recent File List

[DC++]
LangSecRef=3022
DetectFile=%ProgramFiles%\DC++\DCPlusPlus.exe
Default=False
FileKey1=%ProgramFiles%\DC++|files.xml.bz2
FileKey2=%ProgramFiles%\DC++\FileLists|
.*
FileKey3=%ProgramFiles%\DC++\Logs|.

[DU meter]
LangSecRef=3022
Detect=HKCU\SOFTWARE\Hagel\DU Meter
Default=False
FileKey1=%allusersprofile%\Application Data\Hagel Technologies\DU Meter|
.csv

[DVD Shrink (Analysis Results)]
LangSecRef=3023
Detect=HKCU\Software\DVD Shrink
Default=False
FileKey1=%allusersprofile%\Application Data\DVD Shrink|
.*

[*DVD Shrink]
LangSecRef=3023
Default=False
Detect=HKCU\Software\DVD Shrink
RegKey1=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent Targets
RegKey2=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent File List
RegKey3=HKCU\Software\DVD Shrink\DVDSHRINK103\TargetFiles
RegKey4=HKCU\Software\DVD Shrink\DVDSHRINK103\SourceFolders

[DVDx]
LangSecRef=3023
Detect=HKCU\Software\DVDx
Default=False
RegKey1=HKCU\Software\DVDx\LastDir
RegKey2=HKCU\Software\DVDx\LastOutput
FileKey1=%ProgramFiles%\DVDx|
.tmp

[*Delete Index.dat files]
LangSecRef=3001
LangRef=3105
WarningRef=3201
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_INDEXDAT

[*Dependency Walker]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Dependency Walker
Default=False
RegKey1=HKCU\Software\Microsoft\Dependency Walker\Recent File List

[*Desktop Shortcuts]
LangSecRef=3003
LangRef=3613
Default=False
SpecialKey1=F_DESKTOP

[DivX Movies Cache]
LangSecRef=3023
Detect=HKLM\Software\DivXNetworks
Default=False
FileKey1=%userprofile%\My Documents\My Videos\DivX Movies|
.*|RECURSE
RegKey1=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry1
RegKey2=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry2
RegKey3=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry3
RegKey4=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry4
RegKey5=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry5
RegKey6=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry6

[*Dogpile Toolbar]
LangSecRef=3022
Detect=HCKU\Software\Infospace\DogpileToolbar
Default=False
RegKey1=HCKU\Software\Infospace\DogpileToolbar\History|1-terms

[Download Accelerator Plus]
LangSecRef=3022
Detect=HKCU\Software\SpeedBit\Download Accelerator
Default=False
RegKey1=HKLM\SOFTWARE\SpeedBit\Download Accelerator\FileList
RegKey2=HKCU\Software\SpeedBit\Download Accelerator\HistoryCombo
RegKey3=HKCU\Software\SpeedBit\Download Accelerator\ADS\SecondMedia
FileKey1=%ProgramFiles%\DAP\Temp|
.*
FileKey2=%ProgramFiles%\DAP\Ads|.
FileKey3=%ProgramFiles%\DAP\Log|.

[Driver Cleaner Pro]
LangSecRef=3024
DetectFile=%ProgramFiles%\Driver Cleaner Pro\DCleaner.exe
Default=False
FileKey1=%ProgramFiles%\Driver Cleaner Pro\Log|
.log

[*Dup Detector]
LangSecRef=3023
Detect=HKCU\Software\Prismatic Software\PhotoBatch
Default=False
RegKey1=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastBatFile
RegKey2=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastFold
RegKey3=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSecFold
RegKey4=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSingleFold

[ESPN Motion Advertisements]
LangSecRef=3023
Detect=HKCU\SOFTWARE\Disney\DIGStream
Default=False
FileKey1=%allusersprofile%\Application Data\DIGStream\ESPNMotion|ad_
.wmv
FileKey2=%allusersprofile%\Application Data\DIGStream\ESPNMotion|promo.wmv
FileKey3=%allusersprofile%\Application Data\DIGStream\ESPNMotion|commercial.wmv
FileKey4=%allusersprofile%\Application Data\DIGStream\ESPNMotion|motionbumper.wmv

[ESPN Motion]
LangSecRef=3023
Detect=HKCU\SOFTWARE\Disney\DIGStream
Default=False
FileKey1=%allusersprofile%\Application Data\DIGStream\ESPNMotion|
.wmv
FileKey2=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*.tmp

[*Easy CD-DA Extractor]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8
RegKey1=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k80
RegKey2=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k81
RegKey3=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k8c
RegKey4=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k91
RegKey5=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k92
RegKey5=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k92

[Effective File Search]
LangSecRef=3021
DetectFile=%ProgramFiles%\efs\search.exe
Default=False
FileKey1=%ProgramFiles%\efs|cblist
.dat

[*EmEditor]
LangSecRef=3024
Detect=HKCU\Software\EmSoft\EmEditor v3
Default=False
RegKey1=HKCU\Software\EmSoft\EmEditor v3\Recent File List
RegKey2=HKCU\Software\EmSoft\EmEditor v3\Recent Folder List
RegKey3=HKCU\Software\EmSoft\EmEditor v3\Recent Font List

[*Empty Recycle Bin]
LangSecRef=3003
LangRef=3141
Default=False
SpecialKey1=N_TEMP_RECYCLEBIN

[*Eraser (Log)]
LangSecRef=3024
Detect=HKCU\Software\Heidi Computers Ltd\Eraser\5.5
Default=False
FileKey1=%ProgramFiles%\Eraser|schedlog.txt

[*Essential NetTools 3]
LangSecRef=3022
Detect=HKCU\Software\ENT3
Default=False
RegKey1=HKCU\Software\ENT3\Recent

[*Ewido Anti-Malware (Log)]
LangSecRef=3024
Detect=HKLM\Software\ewido
Default=False
FileKey1=%ProgramFiles%\Ewido\Security Suite|logfile.txt
FileKey2=%ProgramFiles%\Ewido Anti-Malware|logfile.txt

[*ExamDiff Pro]
LangSecRef=3024
Detect=HKCU\Software\PrestoSoft\ExamDiff Pro
Default=False
RegKey1=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Left Files
RegKey2=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Right Files
RegKey3=HCKU\Software\PrestoSoft\ExamDiff Pro\Settings|File 1
RegKey4=HCKU\Software\PrestoSoft\ExamDiff Pro\Settings|File 2

[*ExamDiff]
LangSecRef=3024
Detect=HKCU\Software\PrestoSoft\ExamDiff
Default=False
RegKey1=HKCU\Software\PrestoSoft\ExamDiff\Recent Left Files
RegKey2=HKCU\Software\PrestoSoft\ExamDiff\Recent Right Files
RegKey3=HCKU\Software\PrestoSoft\ExamDiff\Settings|File 1
RegKey4=HCKU\Software\PrestoSoft\ExamDiff\Settings|File 2

[*Excel Viewer]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files

[ExifPro]
LangSecRef=3023
Detect=HKCU\Software\MKowalski\ExifPro
Default=False
RegKey1=HKCU\Software\MKowalski\ExifPro\1.0\RecentPaths
RegKey2=HKCU\Software\MKowalski\ExifPro\1.0\ResizeDlg\RecentDestPaths
RegKey3=HKCU\Software\MKowalski\ExifPro\1.0\HTMLAlbumGen\RecentDestPaths
RegKey4=HKCU\Software\MKowalski\ExifPro\1.0\Browser\View 0|LastPath
FileKey1=%allusersprofile%\Application Data\MiK\ExifPro|Cache

[*Exifer]
LangSecRef=3021
Detect=HKCU\Software\Exifer
Default=False
RegKey1=HKCU\Software\Exifer\Browse\History

[*FARManager]
LangSecRef=3021
Detect=HKCU\Software\Far
Default=False
RegKey1=HKCU\Software\Far\SavedDialogHistory
RegKey2=HKCU\Software\Far\SavedFolderHistory
RegKey3=HKCU\Software\Far\SavedHistory
RegKey4=HKCU\Software\Far\SavedViewHistory

[*FTP Accounts]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Ftp
Default=False
RegKey1=HKCU\Software\Microsoft\Ftp\Accounts

[*FeedDemon]
LangSecRef=3022
Detect=HKCU\Software\Bradbury\FeedDemon\1.0
Default=False
RegKey1=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TypedURLs
RegKey2=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TabbedBrowserUrls

[*FileLocator Pro]
LangSecRef=3024
Detect=HKCU\Software\Mythicsoft\FileLocatorPro
Default=False
RegKey1=HKCU\Software\Mythicsoft\FileLocatorPro\RecentContains
RegKey2=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFileName
RegKey3=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFolders

[*FlashFXP]
LangSecRef=3022
DetectFile=%ProgramFiles%\FlashFXP\flashfxp.exe
Default=False
FileKey1=%ProgramFiles%\FlashFXP|quick.dat

[FlashGet]
LangSecRef=3022
Detect=HKCU\SOFTWARE\JetCar\JetCar
Default=False
RegKey1=HKCU\SOFTWARE\JetCar\JetCar\DownDir
RegKey2=HKCU\SOFTWARE\JetCar\JetCar\Recent File List
RegKey3=HKCU\SOFTWARE\JetCar\JetCar\SelFolder
FileKey1=%ProgramFiles%\FlashGet|Default.jcd.bak
FileKey2=%ProgramFiles%\FlashGet|Default.bk

FileKey3=%ProgramFiles%\FlashGet\Torrent|.

[FlashGet]
LangSecRef=3022
Detect=HKCU\Software\JetCar
Default=False
RegKey1=HKCU\Software\JetCar\JetCar|Recent File List
FileKey1=%programfiles%\FlashGet|Default.bk

FileKey2=%programfiles%\FlashGet|Default.jcd
FileKey3=%programfiles%\FlashGet|Default.jcd.bak

[*Fonts]
LangSecRef=3501
LangRef=3605
Default=False
SpecialKey1=R_FONTS

[*Foobar2000 (Crash Log)]
LangSecRef=3023
Detect=HKLM\Software\foobar2000
Default=False
FileKey1=%programfiles%\foobar2000|failure.txt

[*Forward Observer]
LangSecRef=3021
DetectFile=%Program Files%\AAForwardObserver\AAForwardObserver.exe
Default=False
FileKey1=%Program Files%\AAForwardObserver|FO.log

[*Foxit PDF Editor]
LangSecRef=3021
DetectFile=%ProgramFiles%\Foxit Software\PDF Editor\PDFEdit.exe
Default=False
RegKey1=HKCU\Software\Foxit Software Company\Foxit PDF Editor|Recent File List

[*Foxit Reader]
LangSecRef=3021
Detect=HKCU\Software\Foxit Software\Foxit Reader
Default=False
RegKey1=HKCU\Software\Foxit Software\Foxit Reader\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit Reader\History

[Free Download Manager]
LangSecRef=3022
DetectFile=%ProgramFiles%\Free Download Manager\fdm.exe
Default=False
RegKey1=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings\Find",“What
RegKey2=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings\View”,"LastDldMoveToFolder
FileKey1=%userprofile%\Application Data\Free Download Manager|downloads.sav
FileKey2=%userprofile%\Application Data\Free Download Manager|uploads.1.sav
FileKey3=%userprofile%\Application Data\Free Download Manager|dlmgrsi.sav
FileKey4=%userprofile%\Application Data\Free Download Manager|downloads.his.sav
FileKey5=%userprofile%\Application Data\Free Download Manager|history.sav
FileKey6=%userprofile%\Application Data\Free Download Manager|sites.sav
FileKey7=%userprofile%\Application Data\Free Download Manager|spider.sav
FileKey8=%userprofile%\Application Data\Free Download Manager|schedules.sav
FileKey9=%userprofile%\Application Data\Free Download Manager|mctasks.sav
FileKey10=%userprofile%\Application Data\Free Download Manager|
.bak

[Free Registry Defrag]
LangSecRef=3024
Detect=HKCU\Software\Local AppWizard-Generated Applications\RegDefrag
Default=False
FileKey1=%WinDir%$regcmp$|
.*

[*FreshDownload]
LangSecRef=3022
Detect=HKCU\Software\FreshDevices\FreshDownload
Default=False
RegKey1=HKCU\Software\FreshDevices\FreshDownload\History

[*FrostWire]
LangSecRef=3022
DetectFile=%ProgramFiles%\FrostWire\FrostWire.exe
Default=False
FileKey1=%userprofile%\Application Data\FrostWire|fileurns.cache
FileKey2=%userprofile%\Application Data\FrostWire|createtimes.cache
FileKey3=%userprofile%\Application Data\FrostWire|responses.cache
FileKey4=%userprofile%\Application Data\FrostWire|ttree.cache
FileKey5=%userprofile%\Application Data\FrostWire|gnutella.net
FileKey6=%userprofile%\Application Data\FrostWire|ttroot.cache
FileKey7=%userprofile%\Application Data\FrostWire|fileurns.bak
FileKey8=%userprofile%\Application Data\FrostWire|checkandupdate.txt

[*GIANT AntiSpyware]
LangSecRef=3024
DetectFile=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware\GIANTAntiSpywareMain.exe
Default=False
FileKey1=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|errors.log
FileKey2=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|tracksEraser.log
FileKey3=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|cleaner.log

[GIMP]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Classes\GIMP-2.0-gbr\shell
filekey1=%userprofile%.thumbnails\normal|
.*
filekey2=%userprofile%.gimp-2.4|documents

[*GSpot]
LangSecRef=3024
Detect=HKCU\Software\GSpot Appliance Corp
Default=False
RegKey1=HKCU\Software\GSpot Appliance Corp\GSpot\v2.6 Settings|LastMediaFile

[*Game Maker 4]
LangSecRef=3021
Detect=HKCU\Software\Game Maker 4
Default=False
RegKey1=HKCU\Software\Game Maker 4\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker 4\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker 4\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker 4\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker 4\Preferences|GameDir

[*Game Maker 5]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 5
Default=False
RegKey1=HKCU\Software\Game Maker\Version 5\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 5\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 5\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 5\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 5\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 5\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 5\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 5\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 5\Preferences|GameDir

[*Game Maker 6]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 6
Default=False
RegKey1=HKCU\Software\Game Maker\Version 6\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 6\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 6\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 6\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 6\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 6\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 6\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 6\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 6\Preferences|GameDir

[*Game Maker 7]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 7
Default=False
RegKey1=HKCU\Software\Game Maker\Version 7\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 7\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 7\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 7\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 7\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 7\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 7\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 7\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 7\Preferences|GameDir

[Genie Backup Manager Pro 6.0]
LangSecRef=3024
DetectFile=%userprofile%\Application Data\Genie-soft\GBMPro6
Default=False
FileKey1=%userprofile%\Application Data\Genie-soft\GBMPro6\logs|
.*

[*GetRight]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Headlight\GetRight
RegKey1=HKCU\Software\Headlight\GetRight\MRU
RegKey2=HKCU\Software\Headlight\GetRight\TypedURLS
RegKey3=HKCU\Software\Headlight\GetRight\Recent File List
FileKey1=%ProgramFiles%\GetRight|GetRight.hst

[*Go!Zilla]
LangSecRef=3022
Detect=%Program Files%\Go!Zilla
Default=False
FileKey1=%ProgramFiles%\Go!Zilla\golog.htm
FileKey2=%ProgramFiles%\Go!Zilla\leech.hst
FileKey3=%ProgramFiles%\Go!Zilla\download.log

[Google Calendar Sync]
LangSecRef=3022
Detect=HKCU\Software\Google\Google Calendar Sync
Default=False
FileKey1=%userprofile%\Application Data\Google\Google Calendar Sync\logs|
.log

[*Google Chrome - Cookies]
Section=Google Chrome
LangRef=3102
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_COOKIES

[*Google Chrome - Download History]
Section=Google Chrome
LangRef=3163
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_DOWNLOAD

[*Google Chrome - Internet Cache]
Section=Google Chrome
LangRef=3161
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_CACHE

[*Google Chrome - Internet History]
Section=Google Chrome
LangRef=3162
Section = Chrome
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_HISTORY

[*Google Chrome - Saved Form Information]
Section=Google Chrome
LangRef=3164
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_FORM

[*Google Deskbar]
LangSecRef=3022
Detect=HKCU\Software\Google\Deskbar
Default=False
RegKey1=HKCU\Software\Google\Deskbar\termhistory
RegKey2=HKCU\Software\Google\Deskbar\urlhistory

[*Google Earth]
LangSecRef=3021
Detect=HKLM\SOFTWARE\Google\Google Earth Plus
; Detect2=HKLM\SOFTWARE\Google\Google Earth Pro
Default=False
FileKey1=%appdata%\Google\GoogleEarth|dbcache.dat
FileKey2=%appdata%\Google\GoogleEarth|dbcache.dat.index
RegKey1=HKCU\Software\Google\Google Earth Plus\Search
RegKey2=HKCU\Software\Google\Google Earth Pro\Search

[Google Talk]
LangSecRef=3022
DetectFile=%ProgramFiles%\Google\Google Talk
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Google\Google Talk\status|
.txt
FileKey2=%userprofile%\Local Settings\Application Data\Google\Google Talk\chatlogs|*.log

[Google Toolbar 4.0]
LangSecRef=3022
Detect=HKCU\Software\Google\Google Toolbar
Default=False
FileKey1=%appdata%\Google\Local Search History|
.*

[*Google Toolbar Firefox]
LangSecRef=3022
Default=False
SpecialDetect=DET_MOZILLA_GOOGLE_TOOLBAR
SpecialKey1=N_MOZ_GOOGLE_TOOLBAR

[*Google Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Google\NavClient\1.1
Default=False
RegKey1=HKCU\Software\Google\NavClient\1.1\History
RegKey2=HKCU\Software\Google\NavClient\1.1\Options|KillPopupCount

[*Google Video Player]
LangSecRef=3023
DetectFile=%ProgramFiles%\Google\Google Video Player\GoogleVideoPlayer.exe
Default=False
RegKey1=HKCU\Software\Google\Google Video Player\MRUList

[*GridinSoft Notepad]
LangSecRef=3021
Detect=HKCU\Software\GridinSoft\Notepad3
Default=False
RegKey1=HKCU\Software\GridinSoft\Notepad3\Files
RegKey2=HKCU\Software\GridinSoft\Notepad3\Search|ReplaceTextHistory
RegKey3=HKCU\Software\GridinSoft\Notepad3\Search|TextHistory

[Grisoft AVG 7.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\Avg7
Default=False
FileKey1=%commonappdata%\Grisoft\Avg7Data|
.log
FileKey2=%commonappdata%\Grisoft\Avg7Data\upd7bin|.
FileKey3=%commonappdata%\Grisoft\Avg7Data$history|.
FileKey4=%commonappdata%\Grisoft\Avg7Data\avg7upd|.log
FileKey5=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|
.*
FileKey6=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey7=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|.log
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|
.log
FileKey9=%windir%\Application Data\AVG7\Log|*.log

[Grisoft AVG 7.5]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\Avg7
Default=False
FileKey1=%allusersprofile%\Application Data\Grisoft|
.AVG
FileKey2=%allusersprofile%\Application Data\Grisoft\Avg7Data|.AVG
FileKey3=%allusersprofile%\Application Data\Grisoft\Avg7Data|
.log
FileKey4=%allusersprofile%\Application Data\Grisoft\Avg7Data\upd7bin|.
FileKey5=%allusersprofile%\Application Data\Grisoft\Avg7Data$history|.
FileKey6=%allusersprofile%\Application Data\Grisoft\Avg7Data\avg7upd|.log
FileKey7=%windir%\All Users\Application Data\Grisoft|
.AVG
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|.AVG
FileKey9=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|
.*
FileKey10=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey11=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|.log
FileKey12=%windir%\All Users\Application Data\Grisoft\Avg7Data|
.log
FileKey13=%windir%\Application Data\AVG7\Log|*.log

[Grisoft AVG 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|
.log
FileKey2=%allusersprofile%\Application Data\avg8\Log|.xml
FileKey3=%allusersprofile%\Application Data\avg8\scanlogs|
.log
FileKey4=%allusersprofile%\Application Data\avg8\emc\Log|.log
FileKey5=%allusersprofile%\Application Data\avg8\update\backup|
.*
FileKey6=%allusersprofile%\Application Data\avg8\download|*.bin

[GroupWise Messenger]
LangSecRef=3021
Detect=HKCU\Software\Novell\Messenger
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Novell\GroupWise Messenger\history%user%|
.*

[HDD Thermometer]
LangSecRef=3024
Detect=HKCU\SOFTWARE\RSD Software, Inc.\HDD Thermometer
Default=False
FileKey1=%allusersprofile%\Application Data\HDD Thermometer|
.log
FileKey2=%allusersprofile%\Application Data\HDD Thermometer\logs|*.log

[HP Photosmart Premier]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\HP Photo & Imaging
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\HP\Digital Imaging\cache|
.*

[*Help Files]
LangSecRef=3501
LangRef=3607
Default=False
SpecialKey1=R_HELP

[*History]
LangSecRef=3001
LangRef=3103
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_HISTORY

[HitManPro]
LangSecRef=3024
DetectFile=%ProgramFiles%\Hitman Pro\hitmanpro2.exe
Default=False
FileKey1=%ProgramFiles%\Hitman Pro\logs|
.htm
FileKey2=%ProgramFiles%\Hitman Pro\updates|.
FileKey3=%ProgramFiles%\Hitman Pro\downloads|.

[*HostsMan]
LangSecRef=3024
DetectFile=%ProgramFiles%\HostsMan\hm.exe
Default=False
FileKey1=%appdata%\abelhadigital.com\HostsServer|block2.log
FileKey2=%appdata%\abelhadigital.com\HostsServer|block1.log

[Hotbar 3.0]
LangSecRef=3022
Detect=HKCU\Software\Hotbar
Default=False
RegKey1=HKCU\Software\Hotbar\hotbar\ImagesHistory
FileKey1=%ProgramFiles%\Hotbar\v3.0\dynamic|
.|RECURSE
FileKey2=%ProgramFiles%\Hotbar\v3.0\static|
.*

[*Hotfix Uninstallers]
LangSecRef=3004
LangRef=3130
DetectOS=|5.2
SpecialKey1=N_EX_HOTFIX

[*HxD Hexeditor]
LangSecRef=3021
Detect=HKCU\Software\Mael\HxD
Default=False
RegKey1=HKCU\Software\Mael\HxD\History Lists\Recent Files

[*IE Toy]
LangSecRef=3024
Detect=HKCU\Software\MySoftware\IEToy
Default=False
FileKey1=%ProgramFiles%\IE Toy\Data|history
FileKey2=%ProgramFiles%\IE Toy\Data|history_ad
RegKey1=HKCU\Software\MySoftware\IEToy|FRAGS_ad
RegKey2=HKCU\Software\MySoftware\IEToy|FRAGS_popup

[*IE7pro]
LangSecRef=3024
Detect=HKCU\Software\IE7pro
Default=False
RegKey1=HKCU\Software\IE7pro\ClosedTabs

[IIS Log Files]
LangSecRef=3004
LangRef=3146
Detect=HKLM\System\CurrentControlSet\Services\w3svc
DetectOS=|6.0
FileKey1=%windir%\system32\LogFiles|
.|RECURSE
FileKey2=%SystemDrive%\inetpub\logs\LogFiles|
.*|RECURSE

[*IZArc]
LangSecRef=3024
Detect=HKCU\Software\IZSoftware\IZArc
Default=False
RegKey1=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey2=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey3=HKCU\Software\IZSoftware\IZArc\Recent

[*Icon Cache]
LangSecRef=3002
Default=False
FileKey1=%userprofile%\Local Settings\Application Data|IconCache.db
FileKey2=%LocalAppData%|IconCache.db

[*IconCool Editor]
LangSecRef=3021
DetectFile=%ProgramFiles%\IconCoolEditor\IconCooleditor.exe
Default=False
FileKey1=%ProgramFiles%\IconCoolEditor|IconFileList.src
FileKey2=%ProgramFiles%\IconCoolEditor|Recentlyused.src

[*IdeaSoft Scrapbooks Plus 1.0]
LangSecRef=3021
Detect=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0
Default=False
RegKey1=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0\Recent File List

[*ImgBurn]
LangSecRef=3021
Detect=HKCU\Software\ImgBurn
Default=False
FileKey1=%AppData%\ImgBurn|ImgBurn.log
FileKey2=%AppData%\ImgBurn\Log Files|ImgBurn.log

[ImgBurn]
LangSecRef=3021
Detect=HKCU\Software\ImgBurn
Default=False
FileKey1=%appdata%\ImgBurn\Log Files|
.*
FileKey2=%appdata%\ImgBurn\IBG Files|.
RegKey1=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Destination
RegKey2=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Source
RegKey3=HKCU\Software\ImgBurn|ISOWRITE_RecentFiles_Source

[*Inno Setup]
LangSecRef=3021
Detect=HKCU\Software\Jordan Russell\Inno Setup
Default=False
RegKey1=HKCU\Software\Jordan Russell\Inno Setup\ScriptFileHistoryNew

[*InstallShield Professional]
LangSecRef=3021
Detect=HKCU\Software\InstallShield\InstallShield Professional
Default=False
RegKey1=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU1
RegKey2=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU2
RegKey3=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU3
RegKey4=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU4

[*Installer]
LangSecRef=3501
LangRef=3608
Default=False
SpecialKey1=R_INSTALLER

[*Installshield Developer 7.0]
LangSecRef=3021
Detect=HKCU\Software\InstallShield\Developer\7.0
Default=False
RegKey1=HKCU\Software\InstallShield\Developer\7.0\Recent File List

[*Interface]
LangSecRef=3501
LangRef=3615
Default=False
SpecialKey1=R_INTERFACE

[*Internet Download Manager]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Internet Download Manager
Default=False
FileKey1=%Appdata%\IDM\UrlHistory.txt
FileKey2=%Appdata%\IDM\UrlHistory2.txt

[Internet Logs]
LangSecRef=3025
DetectFile=%windir%\Internet Logs
Default=False
FileKey1=%windir%\Internet Logs|
.dmp
FileKey2=%windir%\Internet Logs|.log
FileKey3=%windir%\Internet Logs|
.tmp
FileKey4=%windir%\Internet Logs|*.zip

[*Invalid File Extensions]
LangSecRef=3501
LangRef=3602
Default=False
SpecialKey1=R_FILE_EXTS

[*IsoBuster]
LangSecRef=3021
Detect=HKCU\Software\Smart Projects\IsoBuster
Default=False
RegKey1=HKCU\Software\Smart Projects\IsoBuster|ImageFilePath

[*IsoBuster]
LangSecRef=3023
Detect=HKCU\Software\Smart Projects\IsoBuster
Default=False
RegKey1=HKCU\Software\Smart Projects\IsoBuster\RecentImages

[Jetico Personal Firewall (Logs)]
LangSecRef=3022
Detect=HKLM\Software\Jetico\Personal Firewall
Default=False
FileKey1=%ProgramFiles%\Jetico\Jetico Personal Firewall|firewall
.log

[*KMPlayer]
LangSecRef=3023
Detect=HKCU\Software\KMPlayer
Default=False
RegKey1=HKCU\Software\KMPlayer\KMP2.0|LastFileName
RegKey2=HKCU\Software\KMPlayer\WideAlbum(Default Album)

[*Kazaa (Search History)]
LangSecRef=3022
Detect=HKCU\Software\Kazaa
Default=False
RegKey1=HKCU\Software\Kazaa\Search

[Koffix Blocker]
LangSecRef=3024
DetectFile=%ProgramFiles%\Koffix Blocker\Koffix.exe
Default=False
FileKey1=%userprofile%\My Documents\My Koffix Blocker Logs|
.*

[*Last Download Location]
LangSecRef=3001
LangRef=3108
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
RegKey1=HKCU\Software\Microsoft\Internet Explorer|Download Directory
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Main|Save Directory

[*LeechGet]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Cronosoft\LeechGet
RegKey1=HKCU\Software\Cronosoft\LeechGet\History

[LimeWire]
LangSecRef=3022
DetectFile=%ProgramFiles%\LimeWire\LimeWire.exe
Default=False
FileKey1=%userprofile%\Incomplete|
.*|RECURSE
FileKey2=%userprofile%\Application Data\LimeWire|fileurns.cache
FileKey3=%userprofile%\Application Data\LimeWire|createtimes.cache
FileKey4=%userprofile%\Application Data\LimeWire|responses.cache
FileKey5=%userprofile%\Application Data\LimeWire|ttree.cache
FileKey6=%userprofile%\Application Data\LimeWire|gnutella.net

[LogMeIn]
LangSecRef=3022
DetectFile=%ProgramFiles%\Logmein\x86\LogMeIn.exe
Default=False
FileKey1=%ProgramFiles%\Logmein|LMI
.log

[MP3Gain (Logs)]
LangSecRef=3023
Detect=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis
Default=False
FileKey1=%ProgramFiles%\MP3Gain|
.log

[*MPEG Audio Collection]
LangSecRef=3023
Detect=HKCU\Software\MPEG Audio Collection
Default=False
RegKey1=HKCU\Software\MPEG Audio Collection|LastNameText1
RegKey2=HKCU\Software\MPEG Audio Collection|LastNameText2
RegKey3=HKCU\Software\MPEG Audio Collection|LastNameText3
RegKey4=HKCU\Software\MPEG Audio Collection|LastNameText4
RegKey5=HKCU\Software\MPEG Audio Collection|LastNameText5
RegKey6=HKCU\Software\MPEG Audio Collection|LastNameText6

[MS Backup (Logs)]
LangSecRef=3025
DetectFile=%SystemRoot%\System32\ntbackup.exe
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Microsoft\Windows NT\NTBackup\Data|
.log

[*MS Direct Draw]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\DirectDraw
Default=False
RegKey1=HKCU\Software\Microsoft\DirectDraw\MostRecentApplicationName

[*MS HTML Help Workshop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\HTML Help Workshop
Default=False
RegKey1=HKCU\Software\Microsoft\HTML Help Workshop\Compressed HTML
RegKey2=HKCU\Software\Microsoft\HTML Help Workshop\Html Titles
RegKey3=HKCU\Software\Microsoft\HTML Help Workshop\Project Files
RegKey4=HKCU\Software\Microsoft\HTML Help Workshop\Recent File List
RegKey5=HKCU\Software\Microsoft\HTML Help Workshop\Settings|LastProject
RegKey6=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Folders
RegKey7=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Recent File List

[*MS Help Workshop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Help Workshop
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft Help Workshop\Cnt Files
RegKey2=HKCU\Software\Microsoft\Microsoft Help Workshop\Forage Files
RegKey3=HKCU\Software\Microsoft\Microsoft Help Workshop\Hlp Files
RegKey4=HKCU\Software\Microsoft\Microsoft Help Workshop\Hpj Files
RegKey5=HKCU\Software\Microsoft\Microsoft Help Workshop\Map Files
RegKey6=HKCU\Software\Microsoft\Microsoft Help Workshop\Recent File List

[*MS Imaging]
LangSecRef=3024
Detect=HKCU\Software\Kodak\Imaging
Default=False
RegKey1=HKCU\Software\Kodak\Imaging\Recent File List

[*MS Management Console]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List

[*MS Office 2003 Script Editor]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\MSE
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\MSE|LastLoadedSolution
Regkey2=HKCU\Software\Microsoft\Office\11.0\MSE\FileMRUList
Regkey3=HKCU\Software\Microsoft\Office\11.0\MSE\ProjectMRUList
Regkey4=HKCU\Software\Microsoft\Office\11.0\MSE\SolutionMRUList

[MS Office Picture Manager]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office
Default=False
FileKey1=%LocalAppData%\Microsoft\OIS|OIScatalog.cag
FileKey2=%LocalAppData%\Microsoft\OIS\thumbnails|
.*

[*MS Office Publisher 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Publisher
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List

[*MS Paint]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List

[*MS Photo Editor]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor
Default=False
RegKey1=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile1
RegKey2=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile2
RegKey3=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile3
RegKey4=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile4
RegKey5=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType1
RegKey6=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType2
RegKey7=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType3
RegKey8=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType4

[*MS PhotoDraw 2000]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\PhotoDraw\1.0
Default=False
RegKey1=HKCU\Software\Microsoft\PhotoDraw\1.0\Recent File List

[*MS SQL Server 2005]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\FileMRUList
RegKey2=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\ProjectMRUList

[*MS Snapshot Viewer]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Snapshot Viewer
Default=False
RegKey1=HKCU\Software\Microsoft\Snapshot Viewer\Recent File List

[*MS Visual Studio 2005]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\8.0
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\8.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\8.0\ProjectMRUList

[MS Visual Studio.NET 03]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\7.1
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\7.1\FileMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\7.1|LastLoadedSolution
FileKey1=%userprofile%\Local Settings\Application Data\ApplicationHistory|
.*|REMOVESELF

[*MS Visual Studio.NET 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\7.1
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File1
RegKey2=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File2
RegKey3=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File3
RegKey4=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File4
RegKey5=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File5

[*MS Windows Wallpaper]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU

[*MS Wordpad]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List

[*MS Works 4.0]
LangSecRef=3021
Detect= HKCU\Software\Microsoft\Works\4.0
Default=False
RegKey1=HKCU\Software\Microsoft\Works\4.0\Recent File List

[*MS Works Suite 2006]
LangSecRef=3021
Detect= HKCU\Software\Microsoft\Works\8.0
Default=False
RegKey1=HKCU\Software\Microsoft\Works\8.0\Recent File List

[*MS XML Notepad]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\XML Notepad
Default=False
RegKey1=HKCU\Software\Microsoft\XML Notepad\Recent File List

[*MSConfig]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Shared Tools\MSConfig
Default=False
RegKey1=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandFrom
RegKey2=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandTo
RegKey3=HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSConfig

[*MUI Cache]
LangSecRef=3501
LangRef=3614
Default=False
SpecialKey1=R_MUICACHE

[*MUICache]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\

[*Macromedia Dreamweaver MX]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Macromedia\Dreamweaver MX 2004
RegKey1=HKCU\Software\Macromedia\Dreamweaver MX 2004\Recent File List

[*Macromedia Fireworks 6.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Macromedia\Firework 6
RegKey1=HKCU\Software\Macromedia\Firework 6\Recent File List

[*Macromedia Flash 4.0]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 4
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 4\Recent File List

[*Macromedia Flash 5.0]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 5
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 5\Recent File List

[*Macromedia Flash MX 2004]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 7
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 7\Recent File List

[*Macromedia Flash MX]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 6
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 6\Recent File List

[*Macromedia Homesite 5.0]
LangSecRef=3021
Detect=HKCU\Software\Macromedia\HomeSite5
Default=False
RegKey1=HKCU\Software\Macromedia\HomeSite5\RecentFiles

[*Macromedia Shockwave 10]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Shockwave 10
Default=False
RegKey1=Software\Macromedia\Shockwave 10\movies

[*Macromedia Shockwave 8]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Shockwave 8
Default=False
RegKey1=Software\Macromedia\Shockwave 8\movies

[*MagicISO]
LangSecRef=3021
Detect=HKCU\Software\MagicISO
Default=False
RegKey1=HKCU\Software\MagicISO\Reopen

[Malwarebytes’ Anti Malware]
LangSecRef=3024
DetectFile=%ProgramFiles%\Malwarebytes’ Anti-Malware\mbam.exe
Default=False
FileKey1=%appdata%\Malwarebytes\Malwarebytes’ Anti-Malware\Logs|
.txt
FileKey2=%appdata%\Malwarebytes\Malwarebytes’ Anti-Malware\Quarantine|.

[Maxthon Browser 2]
LangSecRef=3022
DetectFile=%ProgramFiles%\Maxthon2\Maxthon.exe
Default=False
FileKey1=%ProgramFiles%\Maxthon2\Temp|
.*

[McAfee SiteAdvisor]
LangSecRef=3024
DetectFile=%appdata%\SiteAdvisor
Default=False
FileKey1=%appdata%\SiteAdvisor|asserts.txt
FileKey2=%allusersdata%\SiteAdvisor|
.log
FileKey3=%commonappdata%\McAfee\MCLOGS\MISP\SAService|SAService*.log

[*Media Player Classic]
LangSecRef=3023
Detect=HKCU\Software\Gabest\Media Player Classic
Default=False
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName

[*Media Player Classic]
LangSecRef=3023
Detect=HKLM\Software\Gabest\Media Player Classic
Default=False
FileKey1=%appdata%\Media Player Classic|default.mpcpl
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName

[MediaMonkey]
LangSecRef=3023
DetectFile=%ProgramFiles%\MediaMonkey\MediaMonkey.exe
Default=False
FileKey1=%userprofile%\Local Settings\Temp|
.|RECURSE
FileKey2=%userprofile%\My Documents\My Music\MediaMonkey|MediaMonkey.m3u
FileKey3=%userprofile%\My Documents\My Music\MediaMonkey\Previews|
.*|RECURSE

[Memory Dumps]
LangSecRef=3003
LangRef=3143
Default=False
FileKey1=%windir%|memory.dmp
FileKey2=%windir%\MiniDump|
.dmp

[*Menu Order Cache]
LangSecRef=3004
LangRef=3125
WarningRef=3203
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder

[Messenger Plus! Live (Logs)]
LangSecRef=3022
Detect=HKCU\Software\Patchou
Default=False
FileKey1=%userprofile%\My Documents\My Chat Logs|
.*|RECURSE

[*MiTeC DFM Editor]
LangSecRef=3021
Detect=HKCU\Software\MiTeC\DFM Editor
Default=False
RegKey1=HKCU\Software\MiTeC\DFM Editor\5.x\Main\MRUHistory

[*Microangelo 6]
LangSecRef=3021
Detect=HKCU\Software\Eclipsit\Microangelo\Toolset 6
Default=False
RegKey1=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Animator\MRU List
RegKey2=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Librarian\MRU List
RegKey3=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Studio\MRU List

[*Microangelo]
LangSecRef=3021
Detect=HKCU\Software\Impact\Microangelo
Default=False
RegKey1=HKCU\Software\Impact\Microangelo\Animator\MRU List
RegKey2=HKCU\Software\Impact\Microangelo\Librarian\MRU List
RegKey3=HKCU\Software\Impact\Microangelo\Studio\MRU List

[*Microsoft AntiSpyware]
LangSecRef=3024
DetectFile=%ProgramFiles%\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
Default=False
FileKey1=%ProgramFiles%\Microsoft AntiSpyware|errors.log
FileKey2=%ProgramFiles%\Microsoft AntiSpyware|tracksEraser.log
FileKey3=%ProgramFiles%\Microsoft AntiSpyware|cleaner.log

[*Microsoft Visual Studio 6.0]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\6.0
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\6.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\6.0\MenuMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\6.0\ProjectMRUList
RegKey4=HKCU\Software\Microsoft\Visual Basic\6.0\RecentFiles

[*Missing Shared DLLs]
LangSecRef=3501
LangRef=3601
Default=False
SpecialKey1=R_SHARED_DLLS

[*More Windows Explorer]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU

[*Morpheus]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Morpheus
RegKey1=HKCU\Software\Morpheus\Morpheus\Recent File List

[*Mozilla - Cookies]
LangSecRef=3026
LangRef=3102
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_COOKIES

[*Mozilla - Download History]
LangSecRef=3026
LangRef=3163
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_DOWNLOAD

[*Mozilla - Internet Cache]
LangSecRef=3026
LangRef=3161
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_CACHE

[*Mozilla - Internet History]
LangSecRef=3026
LangRef=3162
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_HISTORY

[*Mozilla - Saved Form Information]
LangSecRef=3026
LangRef=3164
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_FORM

[*Mp3tag (Log)]
LangSecRef=3023
Detect=HKLM\Software\Florian Heidenreich\Mp3tag
Default=False
FileKey1=%appdata%\Mp3tag|Mp3tagError.log

[*Mp3tag]
LangSecRef=3021
Detect=HKCU\Software\Moebius\Mp3tag
Default=False
RegKey1=HKCU\Software\Moebius\Mp3tag\Settings|LastDirName
RegKey2=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|0
RegKey3=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|1
RegKey4=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|2
RegKey5=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|3
RegKey6=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|4
RegKey7=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|5
RegKey8=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|6
RegKey9=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|7

[MusicMatch Jukebox]
LangSecRef=3023
Detect=HKLM\Software\MUSICMATCH\MUSICMATCH Jukebox
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox|
.log
FileKey2=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox|log.txt
FileKey3=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox\Cache|
.*
FileKey4=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\TEMP|.
FileKey5=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\MMRadio\Cache|.

[*MyToolkit]
LangSecRef=3024
Detect=HKCU\Software\FutureFog\MyToolkit\Options
Default=False
RegKey1=HKCU\Software\FutureFog\MyToolkit\Options|LastUsedFolder

[NA Framework Agent]
LangSecRef=3021
Detect=HKLM\Software\Network Associates\TVD\Shared Components\Framework
Default=False
FileKey1=%allusersprofile%\Application Data\Network Associates\Common Framework\AgentEvents|
.*
FileKey2=%allusersprofile%\Application Data\McAfee\Common Framework\AgentEvents|.

[*NSIS]
LangSecRef=3021
Detect=HKLM\Software\NSIS
Default=False
RegKey1=HKLM\Software\NSIS\MRU

[Nero Burning ROM 9]
LangSecRef=3021
Detect=HKCU\Software\Nero\Nero 9
Default=False
RegKey1=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BrowserDir
RegKey2=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey3=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|WorkingDir
RegKey4=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey5=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BootImageDir
RegKey6=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Recent File List
FileKey1=%appdata%\Nero\Nero 9\Nero Burning ROM|
.log

[*Nero Burning ROM]
LangSecRef=3021
Detect=HKCU\Software\ahead\Nero - Burning Rom
Default=False
RegKey1=HKCU\Software\ahead\Nero - Burning Rom\Settings|BrowserDir
RegKey2=HKCU\Software\ahead\Nero - Burning Rom\Settings|ImageDir
RegKey3=HKCU\Software\ahead\Nero - Burning Rom\Settings|WorkingDir
RegKey4=HKLM\Software\Ahead\Nero - Burning Rom\Settings|ImageDir
RegKey5=HKLM\Software\Ahead\Nero - Burning Rom\Settings|BootImageDir
RegKey6=HKCU\Software\Ahead\Nero - Burning Rom\Recent File List
RegKey7=HKCU\Software\Ahead\Cover Designer\Recent File List
RegKey8=HKCU\Software\Ahead\Nero Wave Editor\Recent File List
FileKey1=%ProgramFiles%\Ahead\Nero|NeroHistory.log

[Netscape Navigator 4.x]
LangSecRef=3022
Detect=HKCU\Software\Netscape\Netscape Navigator\Main
Default=False
FileKey1=%ProgramFiles%\Netscape\Users\default|netscape.hst
FileKey2=%ProgramFiles%\Netscape\Users\default|cookies.txt
FileKey3=%ProgramFiles%\Netscape\Users\default\cache|
.*

[Norton AntiVirus]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Symantec\Norton AntiVirus NT\Install\7.50
Default=False
FileKey1=%commonappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|
.log
FileKey2=%localappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|
.*

[*NoteXpad]
LangSecRef=3021
Detect=HKLM\Software\NoteXpad
Default=False
RegKey1=HKLM\Software\NoteXpad\Recent

[O&O Defrag]
LangSecRef=3024
Detect=HKCU\Software\O&O\O&O Defrag
Default=False
FileKey1=%userprofile%\My Documents\O&O\O&O Defrag\data\reports|
.*|RECURSE

[*Obsolete Software]
LangSecRef=3501
LangRef=3609
Default=False
SpecialKey1=R_OLDSOFTWARE

[Office 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|
.*
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel\Recent Files
RegKey2=HKCU\Software\Microsoft\Office\11.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
Regkey3=HKCU\Software\Microsoft\Office\11.0\PowerPoint\Recent File List
Regkey4=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List
Regkey5=HKCU\Software\Microsoft\Office\11.0\InfoPath\Recent File List
RegKey6=HKCU\Software\Microsoft\Office\11.0\Common\Internet\Server Cache
RegKey7=HKCU\Software\Microsoft\Office\11.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\MSPaper 11.0\Persist File Name
RegKey9=HKCU\Software\Microsoft\MSPaper 11.0\Recent File List
RegKey10=HKCU\Software\Microsoft\Office\11.0\Word\Data|Settings
RegKey11=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile1
RegKey12=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile2
RegKey13=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile3
RegKey14=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile4
RegKey15=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile5
RegKey16=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile6
RegKey17=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile7
RegKey18=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile8
RegKey19=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey20=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey21=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU

[Office 2007]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\12.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|
.*
RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey2=HKCU\Software\Microsoft\Office\12.0\Word\File MRU
RegKey3=HKCU\Software\Microsoft\Office\12.0\Excel\File MRU
RegKey4=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU1
RegKey5=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU2
RegKey6=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU3
RegKey7=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU4
RegKey8=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU5
RegKey9=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU6
RegKey10=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU7
RegKey11=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU8
RegKey12=HKCU\Software\Microsoft\Office\12.0\PowerPoint\File MRU
RegKey13=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Save As\File Name MRU
RegKey14=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open\File Name MRU
RegKey15=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Save As\File Name MRU
RegKey16=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Excel\Settings\Save As\File Name MRU
RegKey17=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Publisher\Settings\Save As\File Name MRU
RegKey18=HKCU\Software\Microsoft\Office\12.0\Publisher\Recent File List
RegKey19=HKCU\Software\Microsoft\Office\12.0\InfoPath\Recent File List

[Office 97]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\8.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|
.*
RegKey1=HKCU\Software\Microsoft\Office\8.0\Excel\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\8.0\Project\Recent File List
RegKey3=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent File List
RegKey4=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent Folder List
RegKey5=HKCU\Software\Microsoft\Office\8.0\Common\Internet\LocationOfComponents
RegKey6=HKCU\Software\Microsoft\Office\8.0\Access\Settings

[Office XP]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\10.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|
.*
RegKey1=HKCU\Software\Microsoft\Office\10.0\PowerPoint\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\10.0\Excel\Recent Files
RegKey3=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent File List
RegKey4=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List
RegKey5=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List
RegKey6=HKCU\Software\Microsoft\Office\10.0\Word\Recent Templates
RegKey7=HKCU\Software\Microsoft\Office\10.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\Office\10.0\Word\Data|Settings
RegKey9=HKCU\Software\Microsoft\Office\10.0\Access\Settings

[*Old Prefetch data]
LangSecRef=3004
LangRef=3147
Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OptimalLayout
SpecialKey1=N_INT_PREFETCH

[*OpenOffice 1.14]
LangSecRef=3021
DetectFile=%ProgramFiles%\OpenOffice.org1.1.4\program\soffice.exe
Default=False
FileKey1=%ProgramFiles%\OpenOffice.org1.1.4\user\registry\data\org\openoffice\Office|Common.xcu

[*OpenOffice 2.0]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.0
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu

[*OpenOffice 2.1]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.1
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu

[*OpenOffice 2.3]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.3
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu

[*OpenOffice 3.1]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.1
Default=False
FileKey1=%appdata%\OpenOffice.org\3\user\registry\data\org\openoffice\Office|Common.xcu

[*Opera - Cookies]
LangSecRef=3027
LangRef=3102
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_COOKIES

[*Opera - Internet Cache]
LangSecRef=3027
LangRef=3161
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_CACHE

[*Opera - Internet History]
LangSecRef=3027
LangRef=3162
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_HISTORY

[Opera 9 (Classic)]
LangSecRef=3022
DetectFile=%ProgramFiles%\Opera 9\Opera.exe
Default=False
FileKey1=%ProgramFiles%\Opera 9\profile|cookies4.dat
FileKey2=%ProgramFiles%\Opera 9\profile|global.dat
FileKey3=%ProgramFiles%\Opera 9\profile|vlink4.dat
FileKey4=%ProgramFiles%\Opera 9\profile\cache4|
.*
FileKey5=%ProgramFiles%\Opera 9\profile\cacheOp|.

[Orbit Downloader]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Orbit
Default=False
FileKey1=%appdata%\Orbit|fileinfo.dat
FileKey2=%appdata%\Orbit|history.dat
FileKey3=%appdata%\Orbit|unfinish.dat
FileKey4=%appdata%\Orbit\flink|
.*

[*Other Explorer MRUs]
LangSecRef=3002
LangRef=3124
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\PrnPortsMRU
RegKey4=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU
RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComputerDescriptions
RegKey6=HKLM\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey7=HKCU\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey8=HKLM\Software\Microsoft\DirectDraw\MostRecentApplication|Name
RegKey9=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Id
RegKey10=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Name

[*Outlook 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Outlook
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey2=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey3=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
RegKey4=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 1
RegKey5=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 3
FileKey1=%appdata%\Microsoft\Outlook|Outlook.NK2

[*PDF-XChange Viewer]
LangSecRef=3021
Detect=HKCU\Software\Tracker Software\PDFViewer
Default=False
RegKey1=HKCU\Software\Tracker Software\PDFViewer\Documents\LastOpened
RegKey2=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Bars
RegKey3=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Panes

[*PDFCreator]
LangSecRef=3024
Detect=HKCU\Software\PDFCreator
Default=False
RegKey1=HKCU\Software\PDFCreator\Program|LastsaveDirectory

[*PE Module Explorer]
LangSecRef=3024
Detect=HKCU\Software\Woozle\PE Module Explorer
Default=False
RegKey1=HKCU\Software\Woozle\PE Module Explorer\Recent Files

[*Paint Shop Pro 7.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 7
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 7\Recent File List
RegKey2=HKCU\Software\Jasc\Animation Shop 3\Recent File List
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 7\General|FolderHistory
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveAsDirectory
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveCopyDirectory

[*Paint Shop Pro 8.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 8
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 8\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 8\WorkspaceMRU
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdPyScript\RunScript|FileName
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdFile\FileSaveAs|FileFolder
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdNonGraphic\SaveWorkspace|WorkspaceFilename
RegKey6=HKCU\Software\Jasc\Paint Shop Pro 8\ScriptMRU

[*Paint Shop Pro 9.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 9
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 9\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 9\WorkspaceMRU
Regkey3=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileOpen|Folder

[*Paint Shop Pro XI]
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\11
Default=False
RegKey1=HKCU\Software\Corel\Paint Shop Pro\11\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\11\WorkspaceMRU
Regkey3=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileOpen|Folder

[*Paint Shop Pro X]
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\10
Default=False
RegKey1=HKCU\Software\Corel\Paint Shop Pro\10\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\10\WorkspaceMRU
Regkey3=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileOpen|Folder

[*Paint.NET]
LangSecRef=3021
Detect=HKCU\Software\Paint.NET
Default=False
RegKey1=HKCU\Software\Paint.NET|MRU0
RegKey2=HKCU\Software\Paint.NET|MRU1
RegKey3=HKCU\Software\Paint.NET|MRU2
RegKey4=HKCU\Software\Paint.NET|MRU3
RegKey5=HKCU\Software\Paint.NET|MRU4
RegKey6=HKCU\Software\Paint.NET|MRU5
RegKey7=HKCU\Software\Paint.NET|MRU6
RegKey8=HKCU\Software\Paint.NET|MRU7
RegKey9=HKCU\Software\Paint.NET|MRU0Thumb
RegKey10=HKCU\Software\Paint.NET|MRU1Thumb
RegKey11=HKCU\Software\Paint.NET|MRU2Thumb
RegKey12=HKCU\Software\Paint.NET|MRU3Thumb
RegKey13=HKCU\Software\Paint.NET|MRU4Thumb
RegKey14=HKCU\Software\Paint.NET|MRU5Thumb
RegKey15=HKCU\Software\Paint.NET|MRU6Thumb
RegKey16=HKCU\Software\Paint.NET|MRU7Thumb

[*Pelles C]
LangSecRef=3021
Detect=HKCU\Software\Pelle Orinius\PellesC
Default=False
RegKey1=HKCU\Software\Pelle Orinius\PellesC\Recent File List
RegKey2=HKCU\Software\Pelle Orinius\PellesC\Recent Project List
RegKey3=HKCU\Software\Pelle Orinius\PellesC\Recent Search List

[*PerfectDisk 7.0]
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\7.0
Default=False
FileKey1=%commonappdata%\Raxco\PerfectDisk\7.0|PerfectDisk.log

[PerfectDisk 8]
LAngSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\8.0
Default=False
FileKey1=%allusersprofile%\Application Data\Raxco\PerfectDisk\8.0|
.log

[*Phorest]
LangSecRef=3024
Detect=HKCU\Software\FutureFog\Phorest\Options
Default=False
RegKey1=HKCU\Software\FutureFog\Phorest\Options|LastUsedFolder
RegKey2=HKCU\Software\FutureFog\Phorest\Layout|SelectionLeft
RegKey3=HKCU\Software\FutureFog\Phorest\Layout|SelectionTop
RegKey4=HKCU\Software\FutureFog\Phorest\Layout|SelectionWidth
RegKey5=HKCU\Software\FutureFog\Phorest\Layout|SelectionHeight

[*Photo Print Calendar 3.00E Beta]
LangSecRef=3021
Detect=HKLM\SOFTWARE\Computer Institute of Japan, Ltd.\Photo Print Calendar from YOKOHAMA Ver.3.00E beta\3.00E beta
Default=False
FileKey1=%programfiles%\Photo Print Calendar|update.bmp

[Photoshop CS Filebrowser]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Adobe\Photoshop
FileKey1=%userprofile%\application data\Adobe\FileBrowser\PhotoshopCS|
.*

[Photoshop CS Filebrowser]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Adobe\Photoshop
FileKey1=%userprofile%\application data\Adobe\FileBrowser\PhotoshopCS|
.*
fileKey2=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|.|RECURSE

[*PicoZip]
LangSecRef=3024
Detect=HKCU\Software\PicoZip
Default=False
RegKey1=HKCU\Software\PicoZip\MRU Items
RegKey2=HKCU\Software\PicoZip\MRUExtract

[Pok3D]
LangSecRef=3021
DetectFile=%ProgramFiles%\Pok3d\Pok3d.ico
Default=False
FileKey1=%userprofile%\Application Data\Pok3d|
.log
FileKey2=%userprofile%\Application Data\Pok3d|*.dmp

[*PowerArchiver]
LangSecRef=3024
Detect=HKCU\Software\PowerArchiver
Default=False
RegKey1=HKCU\Software\PowerArchiver\Files|Active_File1
RegKey2=HKCU\Software\PowerArchiver\Files|Active_File2
RegKey3=HKCU\Software\PowerArchiver\Files|Active_File3
RegKey4=HKCU\Software\PowerArchiver\Files|Active_File4
RegKey5=HKCU\Software\PowerArchiver\Files|Active_File5
RegKey6=HKCU\Software\PowerArchiver\Files|Extract1
RegKey7=HKCU\Software\PowerArchiver\Files|Extract2
RegKey8=HKCU\Software\PowerArchiver\Files|Extract3
RegKey9=HKCU\Software\PowerArchiver\Files|Extract4
RegKey10=HKCU\Software\PowerArchiver\Files|Extract5
RegKey11=HKCU\Software\PowerArchiver\Files|Last open dir
RegKey12=HKCU\Software\PowerArchiver\Files|Last backup dir
RegKey13=HKCU\Software\PowerArchiver\Files|Last add dir

[PowerDVD]
LangSecRef=3021
DetectFile=%ProgramFiles%\Cyberlink\PowerDVD\PowerDVD.exe
Default=False
FileKey1=%ProgramFiles%\CyberLink\PowerDVD|
.pls
FileKey2=%userprofile%\My Documents\CyberLink\PowerDVD|*.pls

[*PowerZip]
LangSecRef=3024
Detect=HKCU\Software\Trident Software\PowerZip
Default=False
RegKey1=HKCU\Software\Trident Software\PowerZip\Recent File List

[QuickPAR]
LangSecRef=3024
Detect=HKCU\Software\QuickPar
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\QuickPar|
.*

[Quicktime Player Cache]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=False
FileKey1=%localappdata%\Apple Computer\QuickTime\downloads|
.*|RECURSE

[*Quicktime Player]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=False
RegKey1=HKLM\Software\Apple Computer, Inc.\QuickTime\Recent Movies
FileKey1=%userprofile%|QTPlayerSession.xml
FileKey2=%appdata%\Apple Computer\QuickTime|QTPlayerSession.xml

[Qwest QuickCare]
LangSecRef=3022
Detect=HKLM\Software\QuickCare
Default=False
FileKey1=%allusersprofile%\Application Data\Support.com|
.tmp|RECURSE
FileKey2=%userprofile%\Local Settings\Application Data\SupportSoft|*.tmp|RECURSE

[ReGet Deluxe]
LangSecRef=3022
Detect=HKCU\Software\ReGet Software\ReGetDx
Default=False
FileKey1=%ProgramFiles%\ReGet Deluxe\history|
.*
RegKey1=HKCU\Software\ReGet Software\ReGetDx\FtpExplorer\Hist
RegKey2=HKCU\Software\ReGet Software\ReGetDx\History
RegKey3=HKCU\Software\ReGet Software\ReGetDx\Search\HistFind

[Real Player SP]
LangSecRef=3023
Detect=HKCU\Software\RealNetworks\RealPlayer\12.0
Default=False
RegKey1=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins1
RegKey10=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins2
RegKey11=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins3
RegKey12=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins4
RegKey13=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins5
RegKey14=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins6
RegKey15=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins7
RegKey16=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins8
RegKey17=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\LastOpenFileDir
RegKey18=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips1
RegKey19=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips2
RegKey20=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips3
RegKey21=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips4
RegKey22=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips5
RegKey23=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips6
RegKey24=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips7
FileKey1=%appdata%\Real\RealPlayer|RealPlayer-log.txt
FileKey2=%appdata%\Real\RealPlayer\History|
.*

[*Recent Documents]
LangSecRef=3002
LangRef=3121
Default=False
SpecialKey1=N_EX_RECENTDOCS
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

[*Recently Typed URLs]
LangSecRef=3001
LangRef=3104
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
RegKey1=HKCU\Software\Microsoft\Internet Explorer\TypedURLs
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
RegKey3=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU

[*RegAlyzer]
LangSecRef=3024
Detect=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer
Default=False
RegKey1=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|LastKey
RegKey2=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|RemoteListHistory
RegKey3=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|SearchTerm

[*RegEdit]
LangSecRef=3025
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit|LastKey

[Registry Mechanic]
LangSecRef=3024
Detect=HKLM\Software\PCTools\Registry Mechanic
Default=False
FileKey1=%userprofile%|
.rmbak|RECURSE
FileKey2=%userprofile%|.rrr|RECURSE
FileKey3=%userprofile%|
.rrr.bak|RECURSE
FileKey4=%userprofile%\Local Settings\Application Data\Microsoft\Windows|.rmbak
FileKey5=%userprofile%\Local Settings\Application Data\Microsoft\Windows|
.rrr
FileKey6=%userprofile%\Local Settings\Application Data\Microsoft\Windows|.rrr.bak
FileKey7=%allusersprofile%|
.rmbak|RECURSE
FileKey8=%allusersprofile%|.rrr|RECURSE
FileKey9=%allusersprofile%|
.rrr.bak|RECURSE
FileKey10=%systemdrive%\Documents and Settings\Guest|.rmbak|RECURSE
FileKey11=%systemdrive%\Documents and Settings\Guest|
.rrr|RECURSE
FileKey12=%systemdrive%\Documents and Settings\Guest|.rrr.bak|RECURSE
FileKey13=%systemdrive%\Documents and Settings\LocalService|
.rmbak|RECURSE
FileKey14=%systemdrive%\Documents and Settings\LocalService|.rrr|RECURSE
FileKey15=%systemdrive%\Documents and Settings\LocalService|
.rrr.bak|RECURSE
FileKey16=%systemdrive%\Documents and Settings\NetworkService|.rmbak|RECURSE
FileKey17=%systemdrive%\Documents and Settings\NetworkService|
.rrr|RECURSE
FileKey18=%systemdrive%\Documents and Settings\NetworkService|.rrr.bak|RECURSE
FileKey19=%windir%\system32\config|
.rmbak
FileKey20=%windir%\system32\config|.rrr
FileKey21=%windir%\system32\config|
.rrr.bak
FileKey22=%ProgramFiles%\Registry Mechanic\Log|compactlog.log
FileKey23=%ProgramFiles%\Registry Mechanic\Log|results.log
FileKey24=%ProgramFiles%\Registry Mechanic\Log|scan.log

[RegistryFix]
LangSecRef=3024
DetectFile=%ProgramFiles%\RegistryFix\RegistryFix.exe
Default=False
FileKey1=%ProgramFiles%\RegistryFix\logs|
.*

[Remote Desktop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Terminal Server Client
Default=False
FileKey1=%localappdata%\Microsoft\Terminal Server Client\Cache|
.*
RegKey1=HKCU\Software\Microsoft\Terminal Server Client\Default

[*Run (in Start Menu)]
LangSecRef=3002
LangRef=3122
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU

[*Run At Startup]
LangSecRef=3501
LangRef=3610
Default=False
SpecialKey1=R_RUNSTARTUP

[*STOIK Smart Resizer]
LangSecRef=3023
Detect=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer\Recent File List
Default=False
RegKey1=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer\Recent File List

[STOIK Video Converter 2]
LangSecRef=3023
Detect=HKCU\Software\STOIK
Default=False
FileKey1=%appdata%\STOIK\videopak2|
.ini

[SUPERAntiSpyware (Logs)]
LangSecRef=3024
Detect=HKLM\Software\SUPERAntiSpyware.com\SUPERAntiSpyware
Default=False
FileKey1=%appdata%\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs|
.log

[*SWiSH]
LangSecRef=3023
Detect=HKCU\Software\DJJ Holdings\SWiSH
Default=False
RegKey1=HKCU\Software\DJJ Holdings\SWiSH\Recent File List

[*Safari - Cookies]
LangSecRef=3028
LangRef=3102
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari\Cookies|Cookies.plist

[*Safari - Internet Cache]
LangSecRef=3028
LangRef=3161
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%localappdata%\Apple Computer\Safari|Cache.db

[Safari - Internet History]
LangSecRef=3028
LangRef=3162
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari|History.plist
FileKey2=%appdata%\Apple Computer\Safari|Downloads.plist
FileKey3=%localappdata%\Apple Computer\Safari\History|
.*

[*Safari - Saved Form Information]
LangSecRef=3028
LangRef=3164
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari|Form Values.plist

[ScanDefrag (Logs)]
LangSecRef=3024
Detect=HKLM\Software\ScanDefrag
Default=False
FileKey1=%SystemDrive%\ScanDefrag|
.log
FileKey2=%SystemDrive%\ScanDefrag\logs|*.txt

[*Search Assistant Autocomplete]
LangSecRef=3002
LangRef=3123
Detect=HKCU\Software\Microsoft\Search Assistant
Default=False
RegKey1=HKCU\Software\Microsoft\Search Assistant\ACMru

[*Second Copy 2000]
LangSecRef=3021
Detect=HKCU\Software\Centered Systems\Second Copy 2000
Default=False
FileKey1=%ProgramFiles%\SecCopy|log.rtf
FileKey2=%ProgramFiles%\SecCopy|log-old.rtf
RegKey1=HKCU\Software\Centered Systems\Second Copy 2000\MRU

[*SecureCRT]
LangSecRef=3021
Detect=HKCU\Software\VanDyke\SecureCRT
Default=False
FileKey1=%appdata%\VanDyke\SecureCRT\Config|Recent File List.ini
FileKey2=%appdata%\VanDyke\SecureCRT\Config|Recent Script List.ini

[Shareaza]
LangSecRef=3022
DetectFile=%ProgramFiles%\Shareaza\Shareaza.exe
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Shareaza\Incomplete|
.*

[*Smart Installer Maker]
LangSecRef=3024
Detect=HKCU\Software\InstallBuilders\Smart Install Maker
Default=False
RegKey1=HKCU\Software\InstallBuilders\Smart Install Maker\Reopen

[SmartFTP]
LangSecRef=3022
Detect=HKCU\Software\SmartFTP
Default=False
FileKey1=%appdata%\SmartFTP\Cache|
.*|RECURSE
FileKey2=%appdata%\SmartFTP|History.dat

[SoftThinks CD Creator]
LangSecRef=3021
Detect=HKLM\SOFTWARE\SoftThinks
Default=False
FileKey1=%windir%\CREATOR|
.log

[*Soulseek Beta]
LangSecRef=3022
DetectFile=%ProgramFiles%\Soulseek-Test\slsk.exe
Default=False
FileKey1=%ProgramFiles%\Soulseek-Test|search.cfg

[*Soulseek]
LangSecRef=3022
DetectFile=%ProgramFiles%\Soulseek\slsk.exe
Default=False
FileKey1=%ProgramFiles%\Soulseek|search.cfg

[*Sound Forge 6.0]
LangSecRef=3022
Detect=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics
Default=False
RegKey1=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30110
RegKey2=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30111
RegKey3=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30112
RegKey4=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30113
RegKey5=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30114
RegKey6=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30115

[SpyBot Search and Destroy]
LangSecRef=3024
Detect=HKCU\Software\Safer Networking Limited\SpybotSnD
Default=False
FileKey1=%commonappdata%\Spybot - Search & Destroy\Logs|
.*
FileKey2=%ProgramFiles%\Spybot - Search & Destroy|advdebug.txt
FileKey3=%commonappdata%\Spybot - Search & Destroy|Statistics.ini
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|.
FileKey5=%windir%\All Users\Application Data\Spybot - Search & Destroy|Statistics.ini
FileKey6=%commonappdata%\Spybot - Search & Destroy\Backups|*.log

[*SpyDefense]
LangSecRef=3024
DetectFile=%ProgramFiles%\Everest Labs\Spydefense\sdc.exe
Default=False
FileKey1=%userprofile%\Application Data\Everest Labs\Spydefense\Backups|BF7.tmp
FileKey2=%userprofile%\Application Data\Everest Labs\Spydefense|SpyDefense.log
FileKey3=%userprofile%\Application Data\Everest Labs\Spydefense|History.ini
FileKey3=%userprofile%\Application Data\Everest Labs\Spydefense|Backups.ini

[Spyware Doctor]
LangSecRef=3024
Detect=HKCU\Software\PCTools\Spyware Doctor
Default=False
FileKey1=%ProgramFiles%\Spyware Doctor\Log|
.*

[Spyware Terminator]
LangSecRef=3024
Detect=HKCU\Software\Spyware Terminator
Default=False
FileKey1=%ProgramFiles%\Spyware Terminator|
.err
FileKey2=%ProgramFiles%\Spyware Terminator|.old
FileKey3=%ProgramFiles%\Spyware Terminator\update|
.*
FileKey4=%appdata%\Spyware Terminator\Reports|.
FileKey5=%ProgramFiles%\Spyware Terminator\Clamav|*.old

[*StarOffice 8]
LangSecRef=3021
DetectFile=%ProgramFiles%\Sun\StarOffice 8\program\soffice.exe
Default=False
FileKey1=%appdata%\StarOffice8\user\registry\data\org\openoffice\Office|Common.xcu

[*Start Menu Ordering]
LangSecRef=3501
LangRef=3611
Default=False
SpecialKey1=R_STARTMENUORDER

[*Start Menu Shortcuts]
LangSecRef=3003
LangRef=3612
Default=False
SpecialKey1=F_STARTMENU

[Sun Java]
LangSecRef=3022
Detect=HKLM\SOFTWARE\JavaSoft\Java Plug-in
Default=False
FileKey1=%appdata%\Sun\Java\Deployment\cache|
.|RECURSE
FileKey2=%appdata%\Sun\Java\Deployment\javaws\cache|
.*|RECURSE

[Symantec AntiVirus]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Symantec\Symantec AntiVirus\Install\7.50
Default=False
FileKey1=%commonappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|
.log
FileKey2=%localappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|
.*

[*Symantec Ghost]
LangSecRef=3024
Detect=HKCU\Software\Symantec\Symantec Ghost
Default=False
RegKey1=HKCU\Software\Symantec\Symantec Ghost\Explorer\Ghost Explorer\Recent File List

[*Synchronize It!]
LangSecRef=3021
Detect=HKCU\Software\grigsoft.com\Synchronize It!
Default=False
RegKey1=HKCU\Software\grigsoft.com\Synchronize It!\Synchronize It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Synchronize It!\Combos

[*TUGZip]
LangSecRef=3024
Detect=HKCU\Software\TUGZip
Default=False
RegKey1=HKCU\Software\TUGZip|mainRecent
RegKey2=HKCU\Software\TUGZip|extrRecent
RegKey3=HKCU\Software\TUGZip|cmpWorkingDir

[*Tag&Rename 3]
LangSecRef=3024
Detect=HKCU\Software\Softpointer\Tag&Rename3\Config
Default=False
RegKey1=HKCU\Software\Softpointer\Tag&Rename3\Config|FCurrentFolder
RegKey2=HKCU\Software\Softpointer\Tag&Rename3\Config|FHistoryList

[Talkback (Crash Reports)]
LangSecRef=3026
Detect=HKLM\SOFTWARE\FullCircle\TalkBack
Default=False
RegKey1=HKLM\SOFTWARE\FullCircle\TalkBack
FileKey1=%userprofile%\Application Data\Talkback\MozillaOrg\Firefox15|
.|RECURSE
FileKey2=%userprofile%\Application Data\Talkback\MozillaOrg\Firefox2|
.|RECURSE
FileKey3=%userprofile%\Application Data\Talkback\MozillaOrg\Thunderbird2|
.*|RECURSE

[TechSmith DubIt]
LangSecRef=3023
Detect=HKCU\Software\TechSmith\DubIt
Default=False
FileKey1=%ProgramFiles%\TechSmith\DubIt|
.gid
RegKey1=HKCU\Software\TechSmith\DubIt\Recent Audio Files
RegKey2=HKCU\Software\TechSmith\DubIt\Recent Video Files

[*Temporary Files]
LangSecRef=3003
LangRef=3142
Default=False
SpecialKey1=N_TEMP_DIRS

[*Temporary Internet Files]
LangSecRef=3001
LangRef=3101
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_TEMP

[*TeraCopy]
LangSecRef=3024
Detect=HKCU\Software\Code Sector\TeraCopy
Default=False
RegKey1=HKCU\Software\Code Sector\TeraCopy|LastTargetFolder
FileKey1=%appdata%\TeraCopy|FileList.dat
FileKey2=%appdata%\TeraCopy|Transfer.log

[*TextPad]
LangSecRef=3021
Detect=HKCU\Software\Helios\TextPad 4
Default=False
RegKey1=HKCU\Software\Helios\TextPad 4\Recent File List
RegKey2=HKCU\Software\Helios\TextPad 4\Recent Strings

[The Bat]
LangSecRef=3022
Detect=HKCU\Software\RIT\The Bat!
Default=False
FileKey1=%appdata%\The Bat!\cache|
.*

[*The Cleaner]
LangSecRef=3024
DetectFile=%ProgramFiles%\The Cleaner\cleaner.exe
Default=False
FileKey1=%ProgramFiles%\The Cleaner|logfile.txt
FileKey2=%ProgramFiles%\The Cleaner|moolive.log
FileKey3=%ProgramFiles%\The Cleaner|tca.log

[*The GIMP 2.2]
LangSecRef=3021
DetectFile=%userprofile%.gimp-2.2\gimprc
Default=False
FileKey1=%userprofile%.gimp-2.2|documents

[Thumbnail Cache]
LangSecRef=3002
LangRef=3131
DetectOS=6.0
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\Explorer|thumbcache_
.db

[Tivo Desktop]
LangSecRef=3023
Default=False
Detect=HKCU\SOFTWARE\TiVo\Desktop
FileKey1=%localappdata%\TiVo Desktop\Cache|
.*

[*Tomahawk PDF+]
LangSecRef=3021
Detect=HKCU\Software\NativeWinds\Tomahawk
Default=False
RegKey1=HKCU\Software\NativeWinds\Tomahawk\MRU

[*Total Recorder]
LangSecRef=3023
Detect=HKCU\Software\HighCriteria\TotalRecorder\Recent File List
Default=False
RegKey1=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File1
RegKey2=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File2
RegKey3=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File3
RegKey4=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File4
RegKey5=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File5
RegKey6=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File6
RegKey7=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File7
RegKey8=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File8
RegKey9=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File9

[Total Uninstall]
LangSecRef=3024
Detect=HKCU\Software\MartS\Total Uninstall
Default=False
FileKey1=%ProgramFiles%\Total Uninstall|Log.txt
FileKey2=%ProgramFiles%\Total Uninstall|
.GID

[*Tray Notifications Cache]
LangSecRef=3004
LangRef=3126
WarningRef=3204
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|IconStreams
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|PastIconsStream
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|IconStreams
RegKey4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|PastIconsStream

[Trillian]
LangSecRef=3024
Detect=HKLM\Software\Clients\IM\Trillian
Default=False
FileKey1=%ProgramFiles%\Trillian\users\default\instantlookup|
.*
FileKey2=%ProgramFiles%\Trillian\users\default\logs|.|RECURSE
FileKey3=%ProgramFiles%\Trillian\users\default\buddyicons|.|RECURSE
FileKey4=%ProgramFiles%\Trillian\Crash Files|.|RECURSE

[TuneUp Utilities]
LangSecRef=3024
Detect=HKCU\Software\TuneUp
Default=False
FileKey1=%appdata%\TuneUp Software\TuneUp Utilities\Backups|
.rcb

[TweakNow PowerPack 2005]
LangSecRef=3024
Detect=HKCU\Software\TweakNow PowerPack
Default=False
FileKey1=%ProgramFiles%\TweakNow PowerPack\Backup|
.*

[*UPX Shell]
LangSecRef=3024
Detect=HKCU\Software\ION Tek\UPX Shell
Default=False
RegKey1=HKCU\Software\ION Tek\UPX Shell\3.x|History

[*Ulead GIF Animator 5.05]
LangSecRef=3024
Detect=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05
Default=False
RegKey1=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05\Recent File List

[*Ulead Smart Saver Pro 3.0]
LangSecRef=3023
Detect=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0
Default=False
RegKey1=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0\Recent File List

[*UltraISO]
LangSecRef=3024
Detect=HKCU\Software\EasyBoot Systems\UltraISO
Default=False
RegKey1=HKCU\Software\EasyBoot Systems\UltraISO\5.0|Reopen
RegKey2=HKCU\Software\EasyBoot Systems\UltraISO\5.0|a
RegKey3=HKCU\Software\EasyBoot Systems\UltraISO\5.0|b
RegKey4=HKCU\Software\EasyBoot Systems\UltraISO\5.0|c
RegKey5=HKCU\Software\EasyBoot Systems\UltraISO\5.0|d
RegKey6=HKCU\Software\EasyBoot Systems\UltraISO\5.0|e
RegKey7=HKCU\Software\EasyBoot Systems\UltraISO\5.0|f
RegKey8=HKCU\Software\EasyBoot Systems\UltraISO\5.0|g
RegKey9=HKCU\Software\EasyBoot Systems\UltraISO\5.0|h
RegKey10=HKCU\Software\EasyBoot Systems\UltraISO\5.0|i

[Universal Share Downloader]
LangSecRef=3022
DetectFile=%ProgramFiles%\USDownloader\USDownloader.exe
Default=False
FileKey1=%ProgramFiles%\USDownloader|USDownloader.log
FileKey2=%ProgramFiles%\USDownloader|
.bak
FileKey3=%ProgramFiles%\USDownloader|.bmp
FileKey4=%ProgramFiles%\USDownloader|
.jpg
FileKey5=%ProgramFiles%\USDownloader|*.png

[*User Assist History]
LangSecRef=3004
LangRef=3128
WarningRef=3206
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist{75048700-EF1F-11D0-9888-006097DEACF9}\Count

[*VNCViewer 3]
LangSecRef=3024
Default=False
Detect=HKCU\Software\ORL\VNCviewer
RegKey1=HKCU\Software\ORL\VNCviewer\MRU

[*VNCViewer 4]
LangSecRef=3024
Default=False
Detect=HKCU\Software\RealVNC\VNCviewer4
RegKey1=HKCU\Software\RealVNC\VNCviewer4\MRU

[Valve - Steam (Logs)]
LangSecRef=3023
Detect=HKCU\Software\Valve\Steam
Default=False
FileKey1=%ProgramFiles%\Valve\Steam\SteamLogs|
.log
FileKey2=%ProgramFiles%\Valve\Steam|Steam.log

[*Venis IX]
LangSecRef=3021
Detect=HKCU\Software\Spaceblue\Venis IX
Default=False
RegKey1=HKCU\Software\Spaceblue\Venis IX\FileHistory

[Ventrilo Client]
LangSecRef=3021
Detect=HKCU\Software\Ventrilo
Default=False
FileKey1=%userprofile%\Application Data\Ventrilo|ventrilo.log
FileKey2=%userprofile%\Application Data\Ventrilo\temp|
.*
FileKey3=%userprofile%\Application Data\Ventrilo\recordings|.

[*Ventrilo Server]
LangSecRef=3022
DetectFile=%ProgramFiles%\VentSrv\ventrilo_srv.exe
Default=False
FileKey1=%ProgramFiles%\VentSrv|ventrilo_srv.log

[VideoGet]
LangSecRef=3022
DetectFile=%ProgramFiles%\VideoGet\VideoGet.exe
Default=False
FileKey1=%ProgramFiles%\VideoGet\Temp|
.*

[*VirtualCloneDrive]
LangSecRef=3021
Detect=HKLM\Software\Elaborate Bytes\VirtualCloneDrive
Default=False
RegKey1=HKLM\Software\Elaborate Bytes\VirtualCloneDrive\0
RegKey2=HKCU\Software\Elaborate Bytes\VirtualCloneDrive\LRU

[*VirtualDub]
LangSecRef=3023
Default=False
Detect=HKCU\Software\Freeware\VirtualDub
RegKey1=HKCU\Software\Freeware\VirtualDub\MRU List

[*VirtualFDD]
LangSecRef=3024
Detect=HKCU\Software\Korbos\VirtualFDD
Default=False
RegKey1=HKCU\Software\Korbos\VirtualFDD\Recent File List

[Vuze]
LangSecRef=3022
Detect=HKCU\Software\Azureus
Default=False
FileKey1=%appdata%\Azureus\logs|
.log
FileKey2=%appdata%\Azureus\logs\save|.log
FileKey3=%userprofile%\Application Data\Azureus\tmp|
.*
FileKey4=%userprofile%\Application Data\Azureus|.bak
FileKey5=%userprofile%\Application Data\Azureus|
.log
FileKey6=%userprofile%\Application Data\Azureus\active|*.bak

[*WM Recorder 10]
LangSecRef=3023
DetectFile=%ProgramFiles%\WM Recorder 10\WMR.exe
Default=False
FileKey1=%ProgramFiles%\WM Recorder 10|log.txt
FileKey2=%ProgramFiles%\WM Recorder 10|urls.txt

[WMP (TFC)]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MediaPlayer\Player
Default=False
FileKey1=%UserProfile%\Local Settings\Application Data\Microsoft\Media Player\Transcoded Files Cache|
.*

[WS FTP (Pro)]
LangSecRef=3022
Detect=HKCU\Software\Ipswitch\WS_FTP
Default=False
FileKey1=%userprofile%\Application Data\Ipswitch\WS_FTP\Logs|
.*

[*Wavosaur (Logs)]
LangSecRef=3023
DetectFile=%ProgramFiles%\Wavosaur\wavosaur.exe
Default=False
FileKey1=%ProgramFiles%\Wavosaur|wavosaur.log

[Webroot SpySweeper]
LangSecRef=3024
Detect=HKCU\Software\Webroot\SpySweeper
FileKey1=%ProgramFiles%\Webroot\Spy Sweeper\Temp|
.*
FileKey2=%appdata%\Webroot\Spy Sweeper\Logs|*Log.txt

[*WinAVI Video Converter (Log)]
LangSecRef=3023
Detect=HKCU\Software\ZjSoft\WinAVI
Default=False
FileKey1=%LocalAppData%\WinAVI|debug.log

[*WinAce 2.0]
LangSecRef=3024
Detect=HKCU\Software\e-merge\WinAce\2.0
Default=False
RegKey1=HKCU\Software\e-merge\WinAce\2.0\Favorites
RegKey2=HKCU\Software\e-merge\WinAce\2.0\MRU Items

[*WinCHM]
LangSecRef=3021
Detect=HKCU\Software\Softany\WinCHM
Default=False
RegKey1=HKCU\Software\Softany\WinCHM|RecentFile1
RegKey2=HKCU\Software\Softany\WinCHM|RecentFile2
RegKey3=HKCU\Software\Softany\WinCHM|RecentFile3
RegKey4=HKCU\Software\Softany\WinCHM|RecentFile4
RegKey5=HKCU\Software\Softany\WinCHM|RecentFile5
RegKey6=HKCU\Software\Softany\WinCHM|RecentFile6

[*WinDiff]
LangSecRef=3024
Detect=HKCU\Software\Microsoft\Windiff
Default=False
RegKey1=HKCU\Software\Microsoft\Windiff|NameLeft
RegKey2=HKCU\Software\Microsoft\Windiff|NameRight

[*WinISO]
LangSecRef=3024
Detect=HKLM\Software\WinISO
Default=False
RegKey1=HKLM\Software\WinISO\Reopen

[*WinImage]
LangSecRef=3024
Detect=HKCU\Software\WinImage
Default=False
RegKey1=HKCU\Software\WinImage|File1
RegKey2=HKCU\Software\WinImage|File2
RegKey3=HKCU\Software\WinImage|File3
RegKey4=HKCU\Software\WinImage|File4
RegKey5=HKCU\Software\WinImage|File5
RegKey6=HKCU\Software\WinImage|File6
RegKey7=HKCU\Software\WinImage|File7
RegKey8=HKCU\Software\WinImage|File8
RegKey9=HKCU\Software\WinImage|File9
RegKey10=HKCU\Software\WinImage|PathExtract

[*WinMerge]
LangSecRef=3024
Detect=HKCU\Software\Thingamahoochie\WinMerge\Files
Default=False
RegKey1=HKCU\Software\Thingamahoochie\WinMerge\Files\Ext
RegKey2=HKCU\Software\Thingamahoochie\WinMerge\Files\Left
RegKey3=HKCU\Software\Thingamahoochie\WinMerge\Files\Right

[*WinPatrol]
LangSecRef=3024
Detect=HKCU\Software\BillP Studios\WinPatrol
Default=False
FileKey1=%ProgramFiles%\BillP Studios\WinPatrol|history.txt

[*WinRAR Comment]
LangSecRef=3024
Detect=HKCU\Software\WinRAR
Default=False
RegKey1=HKCU\Software\WinRAR\General\Info|CommentFile

[*WinRAR SFX]
LangSecRef=3024
Detect=HKCU\Software\WinRAR SFX
Default=False
RegKey1=HKCU\Software\WinRAR SFX

[*WinRAR]
LangSecRef=3024
Detect=HKCU\Software\WinRAR
Default=False
RegKey1=HKCU\Software\WinRAR\ArcHistory
RegKey2=HKCU\Software\WinRAR\General|LastFolder
RegKey3=HKCU\Software\WinRAR\DialogEditHistory\Arcname
RegKey4=HKCU\Software\WinRAR\DialogEditHistory\ExtrPath

[WinWAP]
LangSecRef=3022
Detect=HKCU\Software\Winwap Technologies
Default=False
FileKey1=%userprofile%\WinWAP Temporary Files|
.*

[*WinZip]
LangSecRef=3024
Detect=HKCU\Software\Nico Mak Computing\WinZip
Default=False
RegKey1=HKCU\Software\Nico Mak Computing\WinZip\filemenu
RegKey2=HKCU\Software\Nico Mak Computing\WinZip\extract
RegKey3=HKCU\Software\Nico Mak Computing\WinZip\directories|DefDir
RegKey4=HKCU\Software\Nico Mak Computing\WinZip\directories|ExtractTo
RegKey5=HKCU\Software\Nico Mak Computing\WinZip\directories|gzAddDir
RegKey6=HKCU\Software\Nico Mak Computing\WinZip\directories|zDefDir
RegKey7=HKCU\Software\Nico Mak Computing\WinZip\directories|AddDir
RegKey8=HKCU\Software\Nico Mak Computing\WinZip\directories|gzExtractTo
RegKey9=HKCU\Software\Nico Mak Computing\WinZip\rrs\Opened

[Winamp]
LangSecRef=3023
Detect=HKCU\Software\Winamp
Default=False
FileKey1=%ProgramFiles%\Winamp|winamp.m3u
FileKey2=%ProgramFiles%\Winamp|winamp.m3u8
FileKey3=%ProgramFiles%\Winamp\Plugins\ml|recent.dat
FileKey4=%ProgramFiles%\Winamp\Plugins\ml\cache|
.|RECURSE
FileKey5=%userprofile%\Application Data\Winamp|winamp.m3u
FileKey6=%userprofile%\Application Data\Winamp|winamp.m3u8
FileKey7=%userprofile%\Application Data\Winamp\Plugins\ml|recent.dat
FileKey8=%userprofile%\Application Data\Winamp\Plugins\ml\Cache|
.*|RECURSE

[*Window Size/Location Cache]
LangSecRef=3004
LangRef=3127
WarningRef=3205
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams

[Windows Defender]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Microsoft\Windows Defender
Default=False
FileKey1=%commonappdata%\Microsoft\Windows Defender\Scans\History\Results\Quick|
.*
FileKey2=%commonappdata%\Microsoft\Windows Defender\Scans\History\Results\Resource|.

[Windows Error Reporting]
LangSecRef=3003
LangRef=3149
Default=False
DetectOS=6.0
FileKey1=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportArchive|
.|RECURSE
FileKey2=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportQueue|
.|RECURSE
FileKey3=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportArchive|
.|RECURSE
FileKey4=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportQueue|
.*|RECURSE

[*Windows Live Mail]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Windows Live Mail
Default=False
RegKey1=HKEY_CURRENT_USER\Software\Microsoft\Windows Live Mail|SearchFolderVersion

[Windows Live Messenger]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\MSNMessenger\PerPassportSettings
Default=False
RegKey1=HKCU\Software\Microsoft\MessengerService\ListCache.NET Messenger Service
FileKey1=%appdata%\Microsoft\MSN Messenger|
.sqm|RECURSE

[Windows Live Messenger]
LangSecRef=3022
DetectFile=%ProgramFiles%\Windows Live\Messenger\msnmsgr.exe
Default=False
FileKey1=%USERPROFILE%\Application Data\Microsoft\MSN Messenger|
.*|RECURSE

[*Windows Live Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\MSN Apps\SearchBox
Default=False
RegKey1=HKCU\Software\Microsoft\MSN Apps\SearchBox|History
RegKey2=HKCU\Software\Microsoft\MSN Apps\MSN Toolbar|SearchStrings

[Windows Log Files]
LangSecRef=3003
LangRef=3145
Default=False
FileKey1=%windir%\system32\wbem\Logs|
.log
FileKey2=%windir%\system32\wbem\Logs|.lo_
FileKey3=%windir%|
.log
FileKey4=%windir%|.bak
FileKey5=%windir%|log.txt
FileKey6=%commonappdata%\Microsoft\Dr Watson|
.log
FileKey7=%commonappdata%\Microsoft\Dr Watson|
.dmp
FileKey8=%windir%\Debug|.log
FileKey9=%windir%\Debug\UserMode|
.log
FileKey10=%windir%\Debug\UserMode|.bak
FileKey11=%windir%|SchedLgU.txt
FileKey12=%windir%\security\logs|
.log
FileKey13=%windir%\security\logs|*.old

[Windows ME]
LangSecRef=3025
DetectFile=%windir%\WINFILE.EXE
Default=False
FileKey1=%rootdir%|SCANDISK.LOG
FileKey2=%windir%|
.tmp
FileKey3=%windir%\Application Data|dw.log
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|.
FileKey5=%windir%\APPLOG|.LGC
FileKey6=%windir%\Windows Update Setup Files|
.*

[*Windows Media Player]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MediaPlayer\Player
Default=False
RegKey1=HKCU\Software\Microsoft\MediaPlayer\Player\RecentFileList
RegKey2=HKCU\Software\Microsoft\MediaPlayer\Player\RecentURLList
RegKey3=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayList
RegKey4=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayListIndex
RegKey5=HKCU\Software\Microsoft\MediaPlayer\Player\Settings|SaveAsDir
RegKey6=HKCU\Software\Microsoft\MediaPlayer\AutoComplete\MediaEdit
RegKey7=HKCU\Software\Microsoft\MediaPlayer\Radio\MRUList

[*Windows Movie Maker]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MovieMaker
Default=False
FileKey1=%localappdata%\Microsoft\Movie Maker|MEDIATAB0.DAT

[Windows Update Logs]
LangSecRef=3025
DetectFile=%windir%\SoftwareDistribution\DataStore\Logs
Default=False
FileKey1=%windir%\SoftwareDistribution\DataStore\Logs|
.*

[*Wipe Free Space]
LangSecRef=3004
LangRef=3132
WarningRef=3207
Default=False
DetectOS=5.0
SpecialKey1=N_EX_WIPEFREESPACE

[*Wordweb]
LangSecRef=3021
DetectFile=%ProgramFiles%\WordWeb\wweb32.exe
Default=False
FileKey1=%userprofile%\Application Data\WordWeb|History.txt

[*X-Cleaner (free)]
LangSecRef=3024
DetectFile=%ProgramFiles%\X-Cleaner\XCleaner_free.exe
Default=False
FileKey1=%ProgramFiles%\X-Cleaner|XCL_LOG.txt

[*X-Cleaner (full)]
LangSecRef=3024
DetectFile=%ProgramFiles%\X-Cleaner\XCleaner_full.exe
Default=False
FileKey1=%ProgramFiles%\X-Cleaner|XCL_LOG.txt

[XFire (Logs)]
LangSecRef=3022
Detect=HKLM\Software\Xfire
Default=False
FileKey1=%userprofile%\Application Data\Xfire\chatlog|
.*|RECURSE

[*XML Spy]
LangSecRef=3021
Detect=HKCU\Software\Altova\XML Spy
Default=False
RegKey1=HKCU\Software\Altova\XML Spy\Recent File List
RegKey2=HKCU\Software\Altova\XML Spy\Recent Project List

[*XN Resource Editor]
LangSecRef=3024
Detect=HKCU\Software\Woozle\XN Resource Editor
Default=False
RegKey1=HKCU\Software\Woozle\XN Resource Editor\Recent Files

[*XviD Stats]
LangSecRef=3023
Detect=HKCU\Software\GNU\Xvid
Default=False
RegKey1=HKCU\Software\GNU\Xvid|stats

[*YPOPs]
LangSecRef=3021
DetectFile=%ProgramFiles%\YPOPs\ypops.exe
Default=False
FileKey1=%ProgramFiles%\YPOPs|ypops.log

[Yahoo Messenger (Logs/Cache)]
LangSecRef=3022
Detect=%ProgramFiles%\Yahoo!\Messenger|ypager.log
Default=False
FileKey1=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey2=%ProgramFiles%\Yahoo!\Messenger\Profiles|
.|RECURSE
FileKey3=%ProgramFiles%\Yahoo!\Messenger\Cache|
.|RECURSE
FileKey4=%ProgramFiles%\Yahoo!\Messenger\IMVCache|
.*|RECURSE

[Yahoo Messenger (Logs/Cache)]
LangSecRef=3022
Detect=HKCU\Software\Yahoo\pager
Default=False
FileKey1=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey2=%ProgramFiles%\Yahoo!\Messenger\Profiles|
.|RECURSE
FileKey3=%ProgramFiles%\Yahoo!\Messenger\Cache|
.|RECURSE
FileKey4=%ProgramFiles%\Yahoo!\Messenger\IMVCache|
.*|RECURSE

[*Yahoo! Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Yahoo\Companion
Default=False
RegKey1=HKCU\Software\Yahoo\Companion\SearchHistory

[*ZX32 ZX Spectrum Emulator v1.03]
LangSecRef=3021
Detect=HKCU\Software\VK\zx32\1.03
Default=False
RegKey1=HKCU\Software\VK\zx32\1.03\FileMRU

[*ZipGenius]
LangSecRef=3024
Detect=HKCU\Software\M.Dev Software\ZG5
Default=False
RegKey1=HKCU\Software\M.Dev Software\ZG5\MRU Items
FileKey1=%appdata%\ZipGenius|mru.dat

[*ZipMagic]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Mijenix\ZipMagic
RegKey1=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Recent
RegKey2=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Archive Manager\UnZip To
RegKey3=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\UnZip To
RegKey4=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Zip To

[ZoneAlarm (Logs)]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Zone Labs\ZoneAlarm
Default=False
FileKey1=%windir%\Internet Logs|ZALog
.*

[*eBay Toolbar]
LangSecRef=3022
DetectFile=%ProgramFiles%\eBay\eBay Toolbar2\eBayTBDaemon.exe
Default=False
RegKey1=HKCU\Software\eBay\eBayToolbar\History
RegKey2=HKCU\Software\eBay\eBayToolbar\RecentSearches
FileKey1=%ProgramFiles%\eBay\eBay Toolbar2|toolbar.log
FileKey2=%ProgramFiles%\eBay\eBay Toolbar2|eBayDaemon.log

[*eMule (File Hashes)]
LangSecRef=3022
Detect=HKCU\Software\eMule
Default=False
FileKey1=%ProgramFiles%\eMule\config|known.met
FileKey2=%ProgramFiles%\eMule\config|known2.met

[*eMule (Search History)]
LangSecRef=3022
Detect=HKCU\Software\eMule
Default=False
FileKey1=%ProgramFiles%\eMule\config|AC_SearchStrings.dat

[iSysCleaner]
LangSecRef=3024
DetectFile=%ProgramFiles%\Utils\iSysCleaner\iSysCleaner.exe
Default=False
FileKey1=%ProgramFiles%\Utils\iSysCleaner\traces|
.*

[mIRC]
LangSecRef=3022
Detect=HKCU\Software\mIRC
Default=False
DectectFile=%ProgramFiles%\mirc\mIRC.exe
Filekey1=%ProgramFiles%\mirc\logs|
.*

[neXBC]
LangSecRef=3022
DetectFile=%ProgramFiles%\neXBC\neXBC.exe
Default=False
FileKey1=%ProgramFiles%\neXBC|messages.txt
FileKey2=%ProgramFiles%\neXBC\Logs\Hosted|
.*
FileKey3=%ProgramFiles%\neXBC\Logs\Joined|.

[uTorrent]
LangSecRef=3022
DetectFile=%ProgramFiles%\uTorrent\uTorrent.exe
Default=False
FileKey1=%ProgramFiles%\uTorrent|
.dmp