Jump to content

winapp2.ini from CC site befroe deleting on site.


CSGalloway

Recommended Posts

; CCleaner - Application Cleaning file

 

[*Global]

Revision=2012

NextIDValue=2145

 

;

; WARNING - DO NOT EDIT THIS FILE
; If you would like to create custom entries then create a new file
; called winapp2.ini which follows the same format as this one.
; CCleaner will automatically pick up the new file.
;
; Copyright ?2004-2009 Piriform Ltd, All Rights Reserved.
; This file and it's contents may not be copied or distributed
; without the express permission of the author.
;
; Notes
; ---------------------------------------
; LangSecRef
;  3021 = Applications
;  3022 = Internet
;  3023 = Multimedia
;  3024 = Utilities
;  3025 = Windows
;  3026 = Firefox/Mozilla
;  3027 = Opera
;  3028 = Safari

[*32bit Web Browser]
LangSecRef=3022
DetectFile=%ProgramFiles%\32BITWEB\32BW.exe
Default=False
FileKey1=%ProgramFiles%\32BITWEB\Data|LastURL.dat
FileKey2=%ProgramFiles%\32BITWEB\Data|LastURL.DA0

[*3GP Video Converter]
LangSecRef=3023
Detect=HKCU\Software\ImTOO\3GP Video Converter
Default=False
RegKey1=HKCU\Software\ImTOO\3GP Video Converter\Settings|last_openpath
RegKey2=HKCU\Software\ImTOO\3GP Video Converter\Settings|OuputDir

[*7-Zip]
LangSecRef=3024
Default=False
Detect=HKCU\SOFTWARE\7-ZIP\
RegKey1=HKCU\SOFTWARE\7-ZIP\Compression\ArcHistory
RegKey2=HKCU\SOFTWARE\7-ZIP\Extraction\PathHistory
RegKey3=HKCU\Software\7-Zip\FM|CopyHistory
RegKey4=HKCU\Software\7-Zip\FM|FolderHistory
RegKey5=HKCU\Software\7-Zip\FM|PanelPath0

[*A-squared Free]
LangSecRef=3024
Detect=HKLM\Software\Emsi Software GmbH\a-squared Free
Default=False
FileKey1=%userprofile%\My Documents\a-squared\Reports|*.*
FileKey2=%programfiles%\a-squared Free\Logs|*.*

[*AI Roboform Search]
LangSecRef=3022
Detect=HKCU\Software\Siber Systems
Default=False
RegKey1=HKCU\Software\Siber Systems\RoboForm\Query-MRU

[*AOL AIM Messenger]
Default=False
DetectFile=%userprofile%\Application Data\acccore\caches\bart
FileKey1=%userprofile%\Application Data\acccore\caches\bart|*.*|RECURSE
fileKey2=%userprofile%\Local Settings\Application Data\AIM\Settings\aolbartcache|*.*|RECURSE
LangSecRef=3022

[*AOL Instant Messenger]
LangSecRef=3022
Detect=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion
Default=False
RegKey1=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent IM ScreenNames
RegKey2=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent ScreenNames
RegKey3=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\Users

[*AVG Anti-Spyware]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\AVGAntiSpyware
Default=False
FileKey1=%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5|logfile.txt

[*AVG AntiVirus 8.0]
: Modified to handle AVG Temp folder
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|*.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|*.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|*.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|*.*
FileKey5=%allusersprofile%\Application Data\avg8\temp|*.tmp

[*AVG AntiVirus 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|*.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|*.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|*.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|*.*

[*AVG AntiVirus 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|*.log
FileKey2=%allusersprofile%\Application Data\avg8\scanlogs|*.log
FileKey3=%allusersprofile%\Application Data\avg8\Log|*.xml
FileKey4=%allusersprofile%\Application Data\avg8\update\backup|*.*
FileKey5=%allusersprofile%\Application Data\avg8\Emc\Log|*.log

[*AVG AntiVirus 9.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg9
Default=False
FileKey1=%allusersprofile%\Application Data\avg9\Log|*.log
FileKey2=%allusersprofile%\Application Data\avg9\scanlogs|*.log
FileKey3=%allusersprofile%\Application Data\avg9\Log|*.xml
FileKey4=%allusersprofile%\Application Data\avg9\update\backup|*.*
FileKey5=%allusersprofile%\Application Data\avg9\Emc\Log|*.log

[*AVI Preview]
LangSecRef=3023
Detect=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit www.avipreview.com for more
Default=False
RegKey1=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit www.avipreview.com for more\Recent File List

[*AVS Disc Creator (Logs)]
LangSecRef=3021
Detect=HKLM\Software\AVS\DiscCreator
Default=False
FileKey1=%windir%|coredw.log
FileKey2=%windir%|datawriter.log

[*Ace Utilities]
LangSecRef=3024
Detect=HKCU\Software\Acelogix\Ace Utilities
Default=False
FileKey1=%userprofile%\My Documents\Ace Utilities Backups|*.reg

[*AceHTML 5]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Visicom Media\AceHTML 5 Freeware
RegKey1=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last URLs
RegKey2=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Projects
RegKey3=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Open
RegKey4=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Files

[*Acronis True Image Home]
LangSecRef=3024
Detect=HKCU\Software\Acronis\TrueImageHome
Default=False
FileKey1=%allusersprofile%\Application Data\Acronis\TrueImage\Logs|*.log

[*Acronis True Image]
LangSecRef=3024
Detect=HKCU\Software\Acronis\TrueImage
Default=False
FileKey1=%userprofile%\Application Data\Acronis\TrueImage\Logs|*.log

[*ActiveX and Class Issues]
LangSecRef=3501
LangRef=3603
Default=False
SpecialKey1=R_ACTIVEX

[*Ad-Aware SE Personal]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt

[*Ad-Aware SE Plus]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt

[*Ad-Aware SE Professional]
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
Default=False
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt

[*Adaptec's Audio CD]
LangSecRef=3024
Detect=HKCU\Software\Adaptec
Default=False
RegKey1=HKCU\Software\Adaptec\AUDIO_CD_INFO

[*Adobe Acrobat 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral\cRecentFiles

[*Adobe Acrobat 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\5.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE

[*Adobe Acrobat 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral\cRecentFiles

[*Adobe Acrobat 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\6.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE

[*Adobe Acrobat 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral\cRecentFiles

[*Adobe Acrobat 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\7.0\AVGeneral\cRecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE

[*Adobe Acrobat 8.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral\cRecentFiles

[*Adobe Acrobat Reader 4.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\4.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile1
RegKey2=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile2
RegKey3=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile3
RegKey4=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile4

[*Adobe Acrobat Reader 4.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\4.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile1
RegKey2=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile2
RegKey3=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile3
RegKey4=HKCU\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile4
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE

[*Adobe Acrobat Reader 5.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles

[*Adobe Acrobat Reader 6.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral\cRecentFiles

[*Adobe Acrobat Reader 7.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\7.0\Cache\Search70|*.*
FileKey2=%ProgramFiles%\Adobe\Acrobat 7.0\Reader|*.bak
FileKey3=%ProgramFiles%\Adobe\Acrobat 7.0\ActiveX|*.bak
FileKey4=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\plug_ins|*.bak
FileKey5=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\Updater|*.bak

[*Adobe Flash Player]
LangSecRef=3023
Detect=HKCR\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
Default=False
SpecialKey1=N_FLASH_COOKIES

[*Adobe Illustrator CS4]
LangSecRef=3021
Detect=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator
Default=False
RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator\FileList

[*Adobe ImageReady 7.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\ImageReady 7.0
RegKey1=HKCU\Software\Adobe\ImageReady 7.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 7.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 7.0\Preferences\RecentFiles

[*Adobe ImageReady CS]
LangSecRef=3021
Detect=HKCU\Software\Adobe\ImageReady 8.0
Default=False
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles

[*Adobe ImageReady CS]
LangSecRef=3021
Detect=HKCU\Software\Adobe\ImageReady 8.0
Default=False
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE

[*Adobe Photoshop 5.5]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\5.5
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\5.5\VisitedDirs

[*Adobe Photoshop 5.5]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\5.5
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\5.5\VisitedDirs
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE

[*Adobe Photoshop 6.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\6.0
RegKey1=HKCU\Software\Adobe\Photoshop\6.0\VisitedDirs

[*Adobe Photoshop 7.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\7.0
RegKey1=HKCU\Software\Adobe\Photoshop\7.0\VisitedDirs

[*Adobe Photoshop CS2]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\9.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\9.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
FileKey1=%appdata%\Adobe\CameraRaw\Cache|*.*

[*Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs

[*Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList

[*Adobe Photoshop CS3]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
fileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE

[*Adobe Photoshop CS4]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\11.0
Default=False
RegKey1=HKCU\Software\Adobe\Photoshop\11.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList

[*Adobe Photoshop CS]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Adobe\Photoshop\8.0
RegKey1=HKCU\Software\Adobe\Photoshop\8.0\VisitedDirs

[*Adobe Reader 8.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\8.0\Cache\Search80|*.*

[*Adobe Reader 8]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Adobe\Updater5|*.log
FileKey2=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE

[*Adobe Reader 9.0]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\9.0\Cache\Search90|*.*

[*Adobe Reader 9]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\9.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Updater6|*.log
FileKey2=%LocalAppData%\Adobe\Updater6\Install|*.*|RECURSE

[*Advanced Searchbar]
LangSecRef=3022
Detect= HKCU\Software\Advanced Searchbar\Toolbar
Default=False
RegKey1=HKCU\Software\Advanced Searchbar\Toolbar\Historysearchbox1

[*Ahead Nero Burning Rom 8]
LangSecRef=3021
Detect=HKCU\Software\Nero\Nero8
Default=False
RegKey1=HKCU\Software\Nero\Nero8\Cover Designer\Recent File List
RegKey2=HKCU\Software\Nero\Nero8\Nero - Burning Rom\Recent File List
FileKey1=%userprofile%\Application Data\Nero\Nero8\Nero Burning ROM|*.log

[*Ahead Nero PhotoSnap]
LangSecRef=3021
Detect=HKCU\Software\ahead\Nero PhotoSnap
Default=False
RegKey1=HKCU\Software\ahead\Nero PhotoSnap\Recent File List

[*Ahead NeroSearch]
LangSecRef=3021
Detect=HKCU\Software\Ahead\NeroSearch
Default=False
RegKey1=HKCU\Software\Ahead\NeroSearch\NeroSavedSearches\SavedSearches

[*Ahead NeroVision 2.0]
LangSecRef=3021
Detect=HKCU\Software\ahead\NeroVision\2.0
Default=False
RegKey1=HKCU\Software\ahead\NeroVision\2.0\RecentFiles

[*AkelPad]
LangSecRef=3024
Detect=HKCU\Software\Akelsoft\AkelPad
Default=False
RegKey1=HKCU\Software\Akelsoft\AkelPad\Recent
RegKey2=HKCU\Software\Akelsoft\AkelPad\Search

[*Alcohol 120%]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Alcohol Soft\Alcohol 120%
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 120%\MountedMRU

[*Alcohol 52%]
LangSecRef=3023
Detect=HKCU\Software\Alcohol Soft
Default=False
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 52%\Images
RegKey2=HKCU\Software\Alcohol Soft\Alcohol 52%\MountedMRU\0
RegKey3=HKCU\Software\Alcohol Soft\Alcohol 52%\Basic|Image File Path
RegKey4=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageFilePath
RegKey5=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageName

[*Always Right]
LangSecRef=3024
Detect=HKCU\Software\AlwaysRight
Default=False
FileKey1=%ProgramFiles%\Superhunter\Always Right\FileBackup|*.*
FileKey2=%ProgramFiles%\Superhunter\Always Right\RegBackup|*.*

[*America Online 9.1]
Default=False
DetectFile=%allusersprofile%\Application Data\AOL\C_AOL 9.1
FileKey1=%allusersprofile%\Application Data\AOL\C_AOL 9.1\bart|*.*|RECURSE
FileKey2=%allusersprofile%\Application Data\AOL\C_AOL 9.1\spool|*.*|RECURSE
LangSecRef=3021

[*Amsn - Display Pictures]
LangSecRef=3021
Default=False
Detect=HKCU\Software\aMSN
FileKey1=%userprofile%\amsn\displaypic\cache|*.*

[*Anim8or]
LangSecRef=3021
Detect=HKCU\Software\Silicon Valley Software\Anim8or
Default=False
RegKey1=HKCU\Software\Silicon Valley Software\Anim8or|File1
RegKey2=HKCU\Software\Silicon Valley Software\Anim8or|File2
RegKey3=HKCU\Software\Silicon Valley Software\Anim8or|File3
RegKey4=HKCU\Software\Silicon Valley Software\Anim8or|File4

[*AntiVir Desktop]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Avira\AntiVir Desktop
Default=False
FileKey1=%commonappdata%\Avira\AntiVir Desktop\FAILSAVE|*.*
FileKey2=%commonappdata%\Avira\AntiVir Desktop\INFECTED|*.*
FileKey3=%commonappdata%\Avira\AntiVir Desktop\LOGFILES|*.*
FileKey4=%commonappdata%\Avira\AntiVir Desktop\SYSSAVE|*.*
FileKey5=%commonappdata%\Avira\AntiVir Desktop\TEMP|*.*
FileKey6=%ProgramFiles%\Avira\AntiVir Desktop|*.old
FileKey7=%ProgramFiles%\Avira\AntiVir Desktop|*.tmp
FileKey8=%ProgramFiles%\Avira\AntiVir Desktop\FAILSAFE|*.tmp

[*AntiVir Personal 8]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Avira\AntiVir PersonalEdition Classic
Default=False
FileKey1=%commonappdata%\Avira\AntiVir PersonalEdition Classic\BACKUP\FAILSAFE|*.tmp
FileKey2=%commonappdata%\Avira\AntiVir PersonalEdition Classic\LOGFILES|*.log
FileKey3=%ProgramFiles%\Avira\AntiVir PersonalEdition Classic|*.tmp
FileKey4=%ProgramFiles%\Avira\AntiVir PersonalEdition Classic\FAILSAFE|*.tmp

[*Application Paths]
LangSecRef=3501
LangRef=3606
Default=False
SpecialKey1=R_APP_PATHS

[*Applications]
LangSecRef=3501
LangRef=3604
Default=False
SpecialKey1=R_APP_OPENWITH

[*Arasan Chess]
LangSecRef=3024
Detect=HKCU\Software\Arasan\Arasan
Default=False
RegKey1=HKCU\Software\Arasan\Arasan\Recent File List

[*Ashampoo Burning Studio 7]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Burn Image Project\AddDialog
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Dump Image Project\DumpImage
RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Unknown Project\AddDialog
FileKey1=%appdata%\Ashampoo\Ashampoo Burning Studio 2007\Logs|*.*

[*Ashampoo Burning Studio 9]
LangSecRef=3024
Detect=HKLM\Software\Ashampoo\Ashampoo Burning Studio 2009
Default=False
FileKey1=%appdata%\Ashampoo\Ashampoo Burning Studio 2009|backupmetainfo.xml
FileKey2=%appdata%\Ashampoo\Ashampoo Burning Studio 2009\Logs|*.xml
FileKey3=%appdata%\Ashampoo\Logs|*.txt

[*Ashampoo Burning Studio 5]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\DumpImage
RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Unknown Project\AddDialog

[*Ashampoo Burning Studio 6 Free (Logs)]
LangSecRef=3023
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6
Default=False
FileKey1=%userprofile%\Application Data\Ashampoo\Ashampoo Burning Studio 6 Free\Logs|*.*

[*Ashampoo Burning Studio 6]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Unknown Project\AddDialog

[*Ashampoo Burning Studio 7]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Unknown Project\AddDialog

[*Ashampoo Burning Studio 8]
LangSecRef=3021
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8
Default=False
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8\Data Disc Project\AddDialog

[*Audacity]
LangSecRef=3023
Detect=HKCU\Software\Audacity
Default=False
RegKey1=HKCU\Software\Audacity\Audacity\RecentFiles

[*AusLogics Disk Defrag]
LangSecRef=3024
Detect=HKCU\Software\AusLogics\Disk Defrag\1.x
Default=False
FileKey1=%ProgramFiles%\AusLogics Disk Defrag\reports|*.*

[*AusLogics Registry Defrag]
LangSecRef=3024
Detect=HKCU\Software\AusLogics\Registry Defrag\4.x
Default=False
FileKey1=%ProgramFiles%\AusLogics Registry Defrag\Data\RegistryDefrag|*.*
FileKey2=%ProgramFiles%\AusLogics Registry Defrag\Reports\Registry Defrag|*.*

[*Auslogics Free Utilities]
LangSecRef=3024
Detect=HKCU\Software\Auslogics
Default=False
FileKey1=%appdata%\Auslogics\Disk Defrag\Reports|*.*
FileKey2=%appdata%\Auslogics\Registry Defrag\Logs|*.*
FileKey3=%appdata%\Auslogics\Registry Defrag\Reports|*.*
FileKey4=%appdata%\Auslogics\System Information\Reports|*.*

[*AutoIt3]
LangSecRef=3021
Detect=HKCU\Software\AutoIt v3
Default=False
RegKey1=HKCU\Software\AutoIt v3\Aut2Exe|LastExeDir
RegKey2=HKCU\Software\AutoIt v3\Aut2Exe|LastIcon
RegKey3=HKCU\Software\AutoIt v3\Aut2Exe|LastIconDir
RegKey4=HKCU\Software\AutoIt v3\Aut2Exe|LastScriptDir
FileKey1=%userprofile%|SciTE.*

[*Autocomplete Form History]
LangSecRef=3001
LangRef=3106
WarningRef=3202
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
SpecialKey1=N_INT_AUTOCOMPLETE

[*Avant Browser]
LangSecRef=3022
DetectFile=%ProgramFiles%\Avant Browser\avant.exe
Default=False
FileKey1=%appdata%\Avant Browser|keywords.dat
FileKey2=%appdata%\Avant Browser|pages.dat
FileKey3=%appdata%\Avant Browser|recents.dat
FileKey4=%appdata%\Avant Browser|reopen.dat

[*Avast Antivirus]
LangSecRef=3024
Detect=HKCU\Software\ALWIL Software\Avast
Default=False
FileKey1=%ProgramFiles%\Alwil Software\Avast4\DATA\report|avast.xsl
FileKey2=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Resident protection.txt
FileKey3=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Simple user interface.txt
FileKey4=%ProgramFiles%\Alwil Software\Avast4\DATA\report|Simple user interface*.xml
FileKey5=%ProgramFiles%\Alwil Software\Avast4\DATA\log|*.*

[*Avi-Mux GUI]
LangSecRef=3023
DetectFile=%ProgramFiles%\AVIMuxGUI\AVIMux_GUI.exe
Default=False
FileKey1=%ProgramFiles%\AVIMuxGUI|AVI-Mux GUI - Logfile*
FileKey2=%ProgramFiles%\AVIMuxGUI|*.dmp

[*Avira RootKit Detection]
LangSecRef=3024
DetectFile=%ProgramFiles%\Avira GmbH\Avira RootKit Detection\avirarkd.exe
Default=False
FileKey1=%ProgramFiles%\Avira GmbH\Avira RootKit Detection|avirarkd.log

[*Axialis IconWorkshop]
LangSecRef=3023
Detect=HKCU\Software\Axialis\IconWorkshop
Default=False
RegKey1=HKCU\Software\Axialis\IconWorkshop\Recent File List
RegKey2=HKCU\Software\Axialis\IconWorkshop\CoolBarList
FileKey1=%appdata%\Axialis\Temporary Preview Files|*.*|RECURSE

[*Azureus]
LangSecRef=3022
DetectFile=%userprofile%\Application Data\Azureus\.lock
Default=False
FileKey1=%userprofile%\Application Data\Azureus\tmp|*.*
FileKey2=%userprofile%\Application Data\Azureus|*.bak
FileKey3=%userprofile%\Application Data\Azureus|*.log
FileKey4=%userprofile%\Application Data\Azureus\active|*.bak
FileKey5=%userprofile%\Application Data\Azureus\plugins\advancedstatistics|*.txt
FileKey6=%userprofile%\Application Data\Azureus\plugins\progressbar|*.txt

[*BSPlayer]
LangSecRef=3023
Detect=HKCU\Software\BST\bsplayer
Default=False
RegKey1=HKCU\Software\BST\bsplayer|File0
RegKey2=HKCU\Software\BST\bsplayer|File1
RegKey3=HKCU\Software\BST\bsplayer|File2
RegKey4=HKCU\Software\BST\bsplayer|File3
RegKey5=HKCU\Software\BST\bsplayer|File4
RegKey6=HKCU\Software\BST\bsplayer|File5
RegKey7=HKCU\Software\BST\bsplayer|File6
RegKey8=HKCU\Software\BST\bsplayer|File7
RegKey9=HKCU\Software\BST\bsplayer|File8
RegKey10=HKCU\Software\BST\bsplayer|File9

[*Babylon]
LangSecRef=3024
Detect=HKCU\Software\Babylon\Babylon Translator\UserInfo
Default=False
RegKey1=HKCU\Software\Babylon\Babylon Translator\UserInfo\History

[*BitDefender 9]
LangSecRef=3024
Detect=HKLM\Software\Softwin\BitDefender Antivirus
Default=False
FileKey1=%ProgramFiles%\Softwin\BitDefender9\Logs|*.*

[*BitTorrent]
LangSecRef=3022
DetectFile=%ProgramFiles%\BitTorrent\bittorrent.exe
Default=False
FileKey1=%userprofile%\Application Data\BitTorrent\incomplete|*.*

[*Boinc]
LangSecRef=3024
DetectFile=%ProgramFiles%\BOINC\boinc.exe
Default=False
FileKey1=%ProgramFiles%\BOINC|stdout*.*
FileKey2=%ProgramFiles%\BOINC|stderr*.*

[*Borland C++ Builder 5.0]
LangSecRef=3024
Detect=HKCU\Software\Borland\C++Builder\5.0
Default=False
RegKey1=HKCU\Software\Borland\C++Builder\5.0\Closed Files
RegKey2=HKCU\Software\Borland\C++Builder\5.0\Closed Projects
RegKey3=HKCU\Software\Borland\C++Builder\5.0\Session

[*Borland Developer Studio 2006]
LangSecRef=3024
Detect=HKCU\Software\Borland\BDS\4.0
Default=False
RegKey1=HKCU\Software\Borland\BDS\4.0\Closed Files
RegKey2=HKCU\Software\Borland\BDS\4.0\Closed Projects
KegKey3=HKCU\Software\Borland\BDS\4.0\Session

[*CA Anti-Virus]
LangSecRef=3024
Default=False
Detect=HKLM\SOFTWARE\ComputerAssociates\Anti-Virus
FileKey1=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|*.log
FileKey2=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|*log.txt
FileKey3=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ArcTemp|*.tmp
FileKey4=%commonappdata%\CA\Consumer\AV|*.tmp|RECURSE
FileKey5=%commonappdata%\CA\Consumer\AV|*.txt|RECURSE
FileKey6=%commonappdata%\CA\Consumer\CCube|*.tmp|RECURSE
FileKey7=%commonappdata%\CA\Consumer\CCube|*.txt|RECURSE
FileKey8=%commonappdata%\CA\Consumer\ISS\FeedStore|*.txt|RECURSE
FileKey9=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\ArcTemp|*.*
FileKey10=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\tmp|*.*

[*CDex]
LangSecRef=3024
Detect=HKLM\SOFTWARE\CDex
Default=False
FileKey1=%userprofile%\My Documents\My Music\CDDB|*.txt

[*Centarsia]
LangSecRef=3021
Detect=HKCU\Software\Centarsia
Default=False
RegKey1=HKCU\Software\Centarsia|RecentImage0
RegKey2=HKCU\Software\Centarsia|RecentImage1
RegKey3=HKCU\Software\Centarsia|RecentImage2
RegKey4=HKCU\Software\Centarsia|RecentImage3
RegKey5=HKCU\Software\Centarsia|RecentImage4
RegKey6=HKCU\Software\Centarsia|RecentImage5
RegKey7=HKCU\Software\Centarsia|RecentImage6

[*Chkdsk File Fragments]
LangSecRef=3003
LangRef=3144
Default=False
FileKey1=%SystemDrive%|File*.chk

[*ClamWin]
LangSecRef=3024
Detect=HKCU\Software\ClamWin
Default=False
FileKey1=%allusersprofile%\.clamwin\log|*.*
FileKey2=%userprofile%\.clamwin\log|*.*
FileKey3=%windir%\All Users\.clamwin\log|*.*

[*Clipboard]
LangSecRef=3003
LangRef=3148
Default=False
SpecialKey1=N_TEMP_CLIPBOARD

[*CloneCD]
LangSecRef=3021
Detect=HKLM\Software\SlySoft\CloneCD
Default=False
RegKey1=HKCU\Software\SlySoft\CloneCD\Settings|ImageFileName

[*CoffeeCup GIF Animator]
LangSecRef=3024
Detect=HKCU\Software\CoffeeCup Software\GIF Animator
Default=False
RegKey1=HKCU\Software\CoffeeCup Software\GIF Animator\Settings\MRU

[*Compare It!]
LangSecRef=3021
Detect=HKCU\Software\grigsoft.com\Compare It!
Default=False
RegKey1=HKCU\Software\grigsoft.com\Compare It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Compare It!\dirs
RegKey3=HKCU\Software\grigsoft.com\Compare It!\options|Recent0
RegKey4=HKCU\Software\grigsoft.com\Compare It!\options|Recent1
RegKey5=HKCU\Software\grigsoft.com\Compare It!\options|Recent2
RegKey6=HKCU\Software\grigsoft.com\Compare It!\options|Recent3
RegKey7=HKCU\Software\grigsoft.com\Compare It!\options|Recent4
RegKey8=HKCU\Software\grigsoft.com\Compare It!\options|Recent5
RegKey9=HKCU\Software\grigsoft.com\Compare It!\options|Recent6
RegKey10=HKCU\Software\grigsoft.com\Compare It!\options|Recent7
RegKey11=HKCU\Software\grigsoft.com\Compare It!\options|Recent8
RegKey12=HKCU\Software\grigsoft.com\Compare It!\options|Recent9
RegKey13=HKCU\Software\grigsoft.com\Compare It!\options|Recent10

[*ConTEXT]
LangSecRef=3021
Detect=HKCU\Software\Eden\ConTEXT
Default=False
Regkey1=HKCU\Software\Eden\ConTEXT\FileHistory
Regkey2=HKCU\Software\Eden\ConTEXT\FindHistory

[*Config.msi Folder]
LangSecRef=3025
Default=False
DetectFile=%windir%\system32\msiexec.exe
FileKey1=%systemdrive%\Config.msi|*.*|RECURSE

[*ConvertXToDVD]
LangSecRef=3023
Detect=HKCU\Software\VSO\ConvertXToDVD
Default=False
FileKey1=%userprofile%\Application Data\Vso|*.log

[*Cookies]
LangSecRef=3001
LangRef=3102
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_COOKIES

[*Copernic Desktop Search]
LangSecRef=3021
Detect=HKCU\Software\Copernic\DesktopSearch2
Default=False
RegKey1=HKCU\Software\Copernic\DesktopSearch2\Config\SearchHistory

[*CounterSpy]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Sunbelt Software\CounterSpy
Default=False
FileKey1=%allusersprofile%\Application Data\Sunbelt Software\CounterSpy\Logs|*.*

[*Creative Pro Proteus VX]
LangSecRef=3023
Detect=HKCU\Software\Creative Professional\Proteus VX
Default=False
RegKey1=HKCU\Software\Creative Professional\Proteus VX VSTi\Recent File List

[*Custom File Deletion]
LangSecRef=3024
FileKey1=%allusersprofile%\DRM\Cache|*.*|recurse
FileKey2=%userprofile%\Application Data\Microsoft\Outlook Express\News|cleanup.log
FileKey3=%userprofile%\Cookies|*.*|recurse
FileKey4=%userprofile%\Local Settings\History\History.IE5|*.*|recurse
FileKey5=%userprofile%\Local Settings\Temporary Internet Files\Content.IE5|*.*|recurse
FileKey6=%userprofile%\Local Settings\Temp|*.*|recurse
FileKey7=%userprofile%\UserData|*.*|recurse
FileKey8=%windir%\Prefetch|*.pf|recurse
FileKey9=%windir%\system32\config\systemprofile\Cookies|*.*|recurse
FileKey10=%windir%\system32\config\systemprofile\Local Settings\History\History.IE5|*.*|recurse
FileKey11=%windir%\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5|*.*|recurse
FileKey12=%windir%\Temp|*.*|recurse
FileKey13=C:\Documents and Settings\LocalService\Cookies|*.*|recurse
FileKey14=C:\Documents and Settings\LocalService\Local Settings\History\History.IE5|*.*|recurse
FileKey15=C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5|*.*|recurse

[*Custom Folders]
LangSecRef=3004
LangRef=3129
SpecialKey1=N_EX_CUSTOMFOLDERS

[*CuteFTP Home 7.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Home
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\7.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\7.0\CacheThumbs|*.*|RECURSE

[*CuteFTP Home 8.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Home
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\8.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\8.0\CacheThumbs|*.*|RECURSE

[*CuteFTP Pro 7.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Professional
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\CacheThumbs|*.*|RECURSE

[*CuteFTP Pro 8.0]
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Professional
Default=False
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\CacheThumbs|*.*|RECURSE

[*CuteHTML 2.3]
LangSecRef=3024
Detect=HKCU\Software\GlobalSCAPE\CuteHTML\2.3
Default=False
RegKey1=HKCU\Software\GlobalSCAPE\CuteHTML\2.3\Recent File List

[*DC++]
LangSecRef=3022
DetectFile=%ProgramFiles%\DC++\DCPlusPlus.exe
Default=False
FileKey1=%ProgramFiles%\DC++|files.xml.bz2
FileKey2=%ProgramFiles%\DC++\FileLists|*.*
FileKey3=%ProgramFiles%\DC++\Logs|*.*

[*DU meter]
LangSecRef=3022
Detect=HKCU\SOFTWARE\Hagel\DU Meter
Default=False
FileKey1=%allusersprofile%\Application Data\Hagel Technologies\DU Meter|*.csv

[*DVD Shrink (Analysis Results)]
LangSecRef=3023
Detect=HKCU\Software\DVD Shrink
Default=False
FileKey1=%allusersprofile%\Application Data\DVD Shrink|*.*

[*DVD Shrink]
LangSecRef=3023
Default=False
Detect=HKCU\Software\DVD Shrink\
RegKey1=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent Targets
RegKey2=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent File List
RegKey3=HKCU\Software\DVD Shrink\DVDSHRINK103\TargetFiles
RegKey4=HKCU\Software\DVD Shrink\DVDSHRINK103\SourceFolders

[*DVDx]
LangSecRef=3023
Detect=HKCU\Software\DVDx
Default=False
RegKey1=HKCU\Software\DVDx\LastDir
RegKey2=HKCU\Software\DVDx\LastOutput
FileKey1=%ProgramFiles%\DVDx|*.tmp

[*Delete Index.dat files]
LangSecRef=3001
LangRef=3105
WarningRef=3201
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_INDEXDAT

[*Dependency Walker]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Dependency Walker
Default=False
RegKey1=HKCU\Software\Microsoft\Dependency Walker\Recent File List

[*Desktop Shortcuts]
LangSecRef=3003
LangRef=3613
Default=False
SpecialKey1=F_DESKTOP

[*DivX Movies Cache]
LangSecRef=3023
Detect=HKLM\Software\DivXNetworks
Default=False
FileKey1=%userprofile%\My Documents\My Videos\DivX Movies|*.*|RECURSE
RegKey1=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry1
RegKey2=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry2
RegKey3=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry3
RegKey4=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry4
RegKey5=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry5
RegKey6=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry6

[*Dogpile Toolbar]
LangSecRef=3022
Detect=HCKU\Software\Infospace\DogpileToolbar
Default=False
RegKey1=HCKU\Software\Infospace\DogpileToolbar\History|1-terms

[*Download Accelerator Plus]
LangSecRef=3022
Detect=HKCU\Software\SpeedBit\Download Accelerator
Default=False
RegKey1=HKLM\SOFTWARE\SpeedBit\Download Accelerator\FileList
RegKey2=HKCU\Software\SpeedBit\Download Accelerator\HistoryCombo
RegKey3=HKCU\Software\SpeedBit\Download Accelerator\ADS\SecondMedia
FileKey1=%ProgramFiles%\DAP\Temp|*.*
FileKey2=%ProgramFiles%\DAP\Ads|*.*
FileKey3=%ProgramFiles%\DAP\Log|*.*

[*Driver Cleaner Pro]
LangSecRef=3024
DetectFile=%ProgramFiles%\Driver Cleaner Pro\DCleaner.exe
Default=False
FileKey1=%ProgramFiles%\Driver Cleaner Pro\Log|*.log

[*Dup Detector]
LangSecRef=3023
Detect=HKCU\Software\Prismatic Software\PhotoBatch
Default=False
RegKey1=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastBatFile
RegKey2=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastFold
RegKey3=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSecFold
RegKey4=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSingleFold

[*ESPN Motion Advertisements]
LangSecRef=3023
Detect=HKCU\SOFTWARE\Disney\DIGStream
Default=False
FileKey1=%allusersprofile%\Application Data\DIGStream\ESPNMotion|ad_*.wmv
FileKey2=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*promo*.wmv
FileKey3=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*commercial*.wmv
FileKey4=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*motionbumper*.wmv

[*ESPN Motion]
LangSecRef=3023
Detect=HKCU\SOFTWARE\Disney\DIGStream
Default=False
FileKey1=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*.wmv
FileKey2=%allusersprofile%\Application Data\DIGStream\ESPNMotion|*.tmp

[*Easy CD-DA Extractor]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8
RegKey1=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k80
RegKey2=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k81
RegKey3=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k8c
RegKey4=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k91
RegKey5=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k92
RegKey5=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k92

[*Effective File Search]
LangSecRef=3021
DetectFile=%ProgramFiles%\efs\search.exe
Default=False
FileKey1=%ProgramFiles%\efs|cblist*.dat

[*EmEditor]
LangSecRef=3024
Detect=HKCU\Software\EmSoft\EmEditor v3
Default=False
RegKey1=HKCU\Software\EmSoft\EmEditor v3\Recent File List
RegKey2=HKCU\Software\EmSoft\EmEditor v3\Recent Folder List
RegKey3=HKCU\Software\EmSoft\EmEditor v3\Recent Font List

[*Empty Recycle Bin]
LangSecRef=3003
LangRef=3141
Default=False
SpecialKey1=N_TEMP_RECYCLEBIN

[*Eraser (Log)]
LangSecRef=3024
Detect=HKCU\Software\Heidi Computers Ltd\Eraser\5.5
Default=False
FileKey1=%ProgramFiles%\Eraser|schedlog.txt

[*Essential NetTools 3]
LangSecRef=3022
Detect=HKCU\Software\ENT3
Default=False
RegKey1=HKCU\Software\ENT3\Recent

[*Ewido Anti-Malware (Log)]
LangSecRef=3024
Detect=HKLM\Software\ewido
Default=False
FileKey1=%ProgramFiles%\Ewido\Security Suite|logfile.txt
FileKey2=%ProgramFiles%\Ewido Anti-Malware|logfile.txt

[*ExamDiff Pro]
LangSecRef=3024
Detect=HKCU\Software\PrestoSoft\ExamDiff Pro
Default=False
RegKey1=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Left Files
RegKey2=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Right Files
RegKey3=HCKU\Software\PrestoSoft\ExamDiff Pro\Settings|File 1
RegKey4=HCKU\Software\PrestoSoft\ExamDiff Pro\Settings|File 2

[*ExamDiff]
LangSecRef=3024
Detect=HKCU\Software\PrestoSoft\ExamDiff
Default=False
RegKey1=HKCU\Software\PrestoSoft\ExamDiff\Recent Left Files
RegKey2=HKCU\Software\PrestoSoft\ExamDiff\Recent Right Files
RegKey3=HCKU\Software\PrestoSoft\ExamDiff\Settings|File 1
RegKey4=HCKU\Software\PrestoSoft\ExamDiff\Settings|File 2

[*Excel Viewer]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files

[*ExifPro]
LangSecRef=3023
Detect=HKCU\Software\MKowalski\ExifPro
Default=False
RegKey1=HKCU\Software\MKowalski\ExifPro\1.0\RecentPaths
RegKey2=HKCU\Software\MKowalski\ExifPro\1.0\ResizeDlg\RecentDestPaths
RegKey3=HKCU\Software\MKowalski\ExifPro\1.0\HTMLAlbumGen\RecentDestPaths
RegKey4=HKCU\Software\MKowalski\ExifPro\1.0\Browser\View 0|LastPath
FileKey1=%allusersprofile%\Application Data\MiK\ExifPro|Cache*

[*Exifer]
LangSecRef=3021
Detect=HKCU\Software\Exifer
Default=False
RegKey1=HKCU\Software\Exifer\Browse\History

[*FARManager]
LangSecRef=3021
Detect=HKCU\Software\Far\
Default=False
RegKey1=HKCU\Software\Far\SavedDialogHistory
RegKey2=HKCU\Software\Far\SavedFolderHistory
RegKey3=HKCU\Software\Far\SavedHistory
RegKey4=HKCU\Software\Far\SavedViewHistory

[*FTP Accounts]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Ftp
Default=False
RegKey1=HKCU\Software\Microsoft\Ftp\Accounts

[*FeedDemon]
LangSecRef=3022
Detect=HKCU\Software\Bradbury\FeedDemon\1.0
Default=False
RegKey1=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TypedURLs
RegKey2=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TabbedBrowserUrls

[*FileLocator Pro]
LangSecRef=3024
Detect=HKCU\Software\Mythicsoft\FileLocatorPro
Default=False
RegKey1=HKCU\Software\Mythicsoft\FileLocatorPro\RecentContains
RegKey2=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFileName
RegKey3=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFolders

[*FlashFXP]
LangSecRef=3022
DetectFile=%ProgramFiles%\FlashFXP\flashfxp.exe
Default=False
FileKey1=%ProgramFiles%\FlashFXP|quick.dat

[*FlashGet]
LangSecRef=3022
Detect=HKCU\SOFTWARE\JetCar\JetCar
Default=False
RegKey1=HKCU\SOFTWARE\JetCar\JetCar\DownDir
RegKey2=HKCU\SOFTWARE\JetCar\JetCar\Recent File List
RegKey3=HKCU\SOFTWARE\JetCar\JetCar\SelFolder
FileKey1=%ProgramFiles%\FlashGet|Default.jcd.bak
FileKey2=%ProgramFiles%\FlashGet|Default.bk*
FileKey3=%ProgramFiles%\FlashGet\Torrent|*.*

[*FlashGet]
LangSecRef=3022
Detect=HKCU\Software\JetCar
Default=False
RegKey1=HKCU\Software\JetCar\JetCar|Recent File List
FileKey1=%programfiles%\FlashGet|Default.bk*
FileKey2=%programfiles%\FlashGet|Default.jcd
FileKey3=%programfiles%\FlashGet|Default.jcd.bak

[*Fonts]
LangSecRef=3501
LangRef=3605
Default=False
SpecialKey1=R_FONTS

[*Foobar2000 (Crash Log)]
LangSecRef=3023
Detect=HKLM\Software\foobar2000
Default=False
FileKey1=%programfiles%\foobar2000|failure.txt

[*Forward Observer]
LangSecRef=3021
DetectFile=%Program Files%\AAForwardObserver\AAForwardObserver.exe
Default=False
FileKey1=%Program Files%\AAForwardObserver|FO.log

[*Foxit PDF Editor]
LangSecRef=3021
DetectFile=%ProgramFiles%\Foxit Software\PDF Editor\PDFEdit.exe
Default=False
RegKey1=HKCU\Software\Foxit Software Company\Foxit PDF Editor|Recent File List

[*Foxit Reader]
LangSecRef=3021
Detect=HKCU\Software\Foxit Software\Foxit Reader
Default=False
RegKey1=HKCU\Software\Foxit Software\Foxit Reader\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit Reader\History

[*Free Download Manager]
LangSecRef=3022
DetectFile=%ProgramFiles%\Free Download Manager\fdm.exe
Default=False
RegKey1=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings\Find","What
RegKey2=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings\View","LastDldMoveToFolder
FileKey1=%userprofile%\Application Data\Free Download Manager|downloads.sav
FileKey2=%userprofile%\Application Data\Free Download Manager|uploads.1.sav
FileKey3=%userprofile%\Application Data\Free Download Manager|dlmgrsi.sav
FileKey4=%userprofile%\Application Data\Free Download Manager|downloads.his.sav
FileKey5=%userprofile%\Application Data\Free Download Manager|history.sav
FileKey6=%userprofile%\Application Data\Free Download Manager|sites.sav
FileKey7=%userprofile%\Application Data\Free Download Manager|spider.sav
FileKey8=%userprofile%\Application Data\Free Download Manager|schedules.sav
FileKey9=%userprofile%\Application Data\Free Download Manager|mctasks.sav
FileKey10=%userprofile%\Application Data\Free Download Manager|*.bak

[*Free Registry Defrag]
LangSecRef=3024
Detect=HKCU\Software\Local AppWizard-Generated Applications\RegDefrag
Default=False
FileKey1=%WinDir%\$regcmp$|*.*

[*FreshDownload]
LangSecRef=3022
Detect=HKCU\Software\FreshDevices\FreshDownload
Default=False
RegKey1=HKCU\Software\FreshDevices\FreshDownload\History

[*FrostWire]
LangSecRef=3022
DetectFile=%ProgramFiles%\FrostWire\FrostWire.exe
Default=False
FileKey1=%userprofile%\Application Data\FrostWire|fileurns.cache
FileKey2=%userprofile%\Application Data\FrostWire|createtimes.cache
FileKey3=%userprofile%\Application Data\FrostWire|responses.cache
FileKey4=%userprofile%\Application Data\FrostWire|ttree.cache
FileKey5=%userprofile%\Application Data\FrostWire|gnutella.net
FileKey6=%userprofile%\Application Data\FrostWire|ttroot.cache
FileKey7=%userprofile%\Application Data\FrostWire|fileurns.bak
FileKey8=%userprofile%\Application Data\FrostWire|checkandupdate.txt

[*GIANT AntiSpyware]
LangSecRef=3024
DetectFile=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware\GIANTAntiSpywareMain.exe
Default=False
FileKey1=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|errors.log
FileKey2=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|tracksEraser.log
FileKey3=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|cleaner.log

[*GIMP]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Classes\GIMP-2.0-gbr\shell
filekey1=%userprofile%\.thumbnails\normal|*.*
filekey2=%userprofile%\.gimp-2.4|documents

[*GSpot]
LangSecRef=3024
Detect=HKCU\Software\GSpot Appliance Corp
Default=False
RegKey1=HKCU\Software\GSpot Appliance Corp\GSpot\v2.6 Settings|LastMediaFile

[*Game Maker 4]
LangSecRef=3021
Detect=HKCU\Software\Game Maker 4
Default=False
RegKey1=HKCU\Software\Game Maker 4\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker 4\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker 4\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker 4\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker 4\Preferences|GameDir

[*Game Maker 5]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 5
Default=False
RegKey1=HKCU\Software\Game Maker\Version 5\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 5\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 5\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 5\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 5\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 5\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 5\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 5\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 5\Preferences|GameDir

[*Game Maker 6]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 6
Default=False
RegKey1=HKCU\Software\Game Maker\Version 6\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 6\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 6\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 6\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 6\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 6\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 6\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 6\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 6\Preferences|GameDir

[*Game Maker 7]
LangSecRef=3021
Detect=HKCU\Software\Game Maker\Version 7
Default=False
RegKey1=HKCU\Software\Game Maker\Version 7\Preferences|Recent0
RegKey2=HKCU\Software\Game Maker\Version 7\Preferences|Recent1
RegKey3=HKCU\Software\Game Maker\Version 7\Preferences|Recent2
RegKey4=HKCU\Software\Game Maker\Version 7\Preferences|Recent3
RegKey5=HKCU\Software\Game Maker\Version 7\Preferences|Recent4
RegKey6=HKCU\Software\Game Maker\Version 7\Preferences|Recent5
RegKey7=HKCU\Software\Game Maker\Version 7\Preferences|Recent6
RegKey8=HKCU\Software\Game Maker\Version 7\Preferences|Recent7
RegKey9=HKCU\Software\Game Maker\Version 7\Preferences|GameDir

[*Genie Backup Manager Pro 6.0]
LangSecRef=3024
DetectFile=%userprofile%\Application Data\Genie-soft\GBMPro6
Default=False
FileKey1=%userprofile%\Application Data\Genie-soft\GBMPro6\logs|*.*

[*GetRight]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Headlight\GetRight\
RegKey1=HKCU\Software\Headlight\GetRight\MRU
RegKey2=HKCU\Software\Headlight\GetRight\TypedURLS
RegKey3=HKCU\Software\Headlight\GetRight\Recent File List
FileKey1=%ProgramFiles%\GetRight|GetRight.hst

[*Go!Zilla]
LangSecRef=3022
Detect=%Program Files%\Go!Zilla
Default=False
FileKey1=%ProgramFiles%\Go!Zilla\golog.htm
FileKey2=%ProgramFiles%\Go!Zilla\leech.hst
FileKey3=%ProgramFiles%\Go!Zilla\download.log

[*Google Calendar Sync]
LangSecRef=3022
Detect=HKCU\Software\Google\Google Calendar Sync
Default=False
FileKey1=%userprofile%\Application Data\Google\Google Calendar Sync\logs|*.log

[*Google Chrome - Cookies]
Section=Google Chrome
LangRef=3102
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_COOKIES

[*Google Chrome - Download History]
Section=Google Chrome
LangRef=3163
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_DOWNLOAD

[*Google Chrome - Internet Cache]
Section=Google Chrome
LangRef=3161
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_CACHE

[*Google Chrome - Internet History]
Section=Google Chrome
LangRef=3162
Section = Chrome
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_HISTORY

[*Google Chrome - Saved Form Information]
Section=Google Chrome
LangRef=3164
Default=False
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
SpecialKey1=N_CHROME_FORM

[*Google Deskbar]
LangSecRef=3022
Detect=HKCU\Software\Google\Deskbar
Default=False
RegKey1=HKCU\Software\Google\Deskbar\termhistory
RegKey2=HKCU\Software\Google\Deskbar\urlhistory

[*Google Earth]
LangSecRef=3021
Detect=HKLM\SOFTWARE\Google\Google Earth Plus
; Detect2=HKLM\SOFTWARE\Google\Google Earth Pro
Default=False
FileKey1=%appdata%\Google\GoogleEarth|dbcache.dat
FileKey2=%appdata%\Google\GoogleEarth|dbcache.dat.index
RegKey1=HKCU\Software\Google\Google Earth Plus\Search
RegKey2=HKCU\Software\Google\Google Earth Pro\Search

[*Google Talk]
LangSecRef=3022
DetectFile=%ProgramFiles%\Google\Google Talk
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Google\Google Talk\status|*.txt
FileKey2=%userprofile%\Local Settings\Application Data\Google\Google Talk\chatlogs|*.log

[*Google Toolbar 4.0]
LangSecRef=3022
Detect=HKCU\Software\Google\Google Toolbar
Default=False
FileKey1=%appdata%\Google\Local Search History|*.*

[*Google Toolbar Firefox]
LangSecRef=3022
Default=False
SpecialDetect=DET_MOZILLA_GOOGLE_TOOLBAR
SpecialKey1=N_MOZ_GOOGLE_TOOLBAR

[*Google Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Google\NavClient\1.1
Default=False
RegKey1=HKCU\Software\Google\NavClient\1.1\History
RegKey2=HKCU\Software\Google\NavClient\1.1\Options|KillPopupCount

[*Google Video Player]
LangSecRef=3023
DetectFile=%ProgramFiles%\Google\Google Video Player\GoogleVideoPlayer.exe
Default=False
RegKey1=HKCU\Software\Google\Google Video Player\MRUList

[*GridinSoft Notepad]
LangSecRef=3021
Detect=HKCU\Software\GridinSoft\Notepad3
Default=False
RegKey1=HKCU\Software\GridinSoft\Notepad3\Files
RegKey2=HKCU\Software\GridinSoft\Notepad3\Search|ReplaceTextHistory
RegKey3=HKCU\Software\GridinSoft\Notepad3\Search|TextHistory

[*Grisoft AVG 7.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\Avg7
Default=False
FileKey1=%commonappdata%\Grisoft\Avg7Data|*.log
FileKey2=%commonappdata%\Grisoft\Avg7Data\upd7bin|*.*
FileKey3=%commonappdata%\Grisoft\Avg7Data\$history|*.*
FileKey4=%commonappdata%\Grisoft\Avg7Data\avg7upd|*.log
FileKey5=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|*.*
FileKey6=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey7=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|*.log
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|*.log
FileKey9=%windir%\Application Data\AVG7\Log|*.log

[*Grisoft AVG 7.5]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\Avg7
Default=False
FileKey1=%allusersprofile%\Application Data\Grisoft|*.AVG
FileKey2=%allusersprofile%\Application Data\Grisoft\Avg7Data|*.AVG
FileKey3=%allusersprofile%\Application Data\Grisoft\Avg7Data|*.log
FileKey4=%allusersprofile%\Application Data\Grisoft\Avg7Data\upd7bin|*.*
FileKey5=%allusersprofile%\Application Data\Grisoft\Avg7Data\$history|*.*
FileKey6=%allusersprofile%\Application Data\Grisoft\Avg7Data\avg7upd|*.log
FileKey7=%windir%\All Users\Application Data\Grisoft|*.AVG
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|*.AVG
FileKey9=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|*.*
FileKey10=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey11=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|*.log
FileKey12=%windir%\All Users\Application Data\Grisoft\Avg7Data|*.log
FileKey13=%windir%\Application Data\AVG7\Log|*.log

[*Grisoft AVG 8.0]
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=False
FileKey1=%allusersprofile%\Application Data\avg8\Log|*.log
FileKey2=%allusersprofile%\Application Data\avg8\Log|*.xml
FileKey3=%allusersprofile%\Application Data\avg8\scanlogs|*.log
FileKey4=%allusersprofile%\Application Data\avg8\emc\Log|*.log
FileKey5=%allusersprofile%\Application Data\avg8\update\backup|*.*
FileKey6=%allusersprofile%\Application Data\avg8\download|*.bin

[*GroupWise Messenger]
LangSecRef=3021
Detect=HKCU\Software\Novell\Messenger
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Novell\GroupWise Messenger\history\%user%|*.*

[*HDD Thermometer]
LangSecRef=3024
Detect=HKCU\SOFTWARE\RSD Software, Inc.\HDD Thermometer
Default=False
FileKey1=%allusersprofile%\Application Data\HDD Thermometer|*.log
FileKey2=%allusersprofile%\Application Data\HDD Thermometer\logs|*.log

[*HP Photosmart Premier]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\HP Photo & Imaging
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\HP\Digital Imaging\cache|*.*

[*Help Files]
LangSecRef=3501
LangRef=3607
Default=False
SpecialKey1=R_HELP

[*History]
LangSecRef=3001
LangRef=3103
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_HISTORY

[*HitManPro]
LangSecRef=3024
DetectFile=%ProgramFiles%\Hitman Pro\hitmanpro2.exe
Default=False
FileKey1=%ProgramFiles%\Hitman Pro\logs|*.htm
FileKey2=%ProgramFiles%\Hitman Pro\updates|*.*
FileKey3=%ProgramFiles%\Hitman Pro\downloads|*.*

[*HostsMan]
LangSecRef=3024
DetectFile=%ProgramFiles%\HostsMan\hm.exe
Default=False
FileKey1=%appdata%\abelhadigital.com\HostsServer|block2.log
FileKey2=%appdata%\abelhadigital.com\HostsServer|block1.log

[*Hotbar 3.0]
LangSecRef=3022
Detect=HKCU\Software\Hotbar\
Default=False
RegKey1=HKCU\Software\Hotbar\hotbar\ImagesHistory
FileKey1=%ProgramFiles%\Hotbar\v3.0\dynamic|*.*|RECURSE
FileKey2=%ProgramFiles%\Hotbar\v3.0\static|*.*

[*Hotfix Uninstallers]
LangSecRef=3004
LangRef=3130
DetectOS=|5.2
SpecialKey1=N_EX_HOTFIX

[*HxD Hexeditor]
LangSecRef=3021
Detect=HKCU\Software\Mael\HxD
Default=False
RegKey1=HKCU\Software\Mael\HxD\History Lists\Recent Files

[*IE Toy]
LangSecRef=3024
Detect=HKCU\Software\MySoftware\IEToy
Default=False
FileKey1=%ProgramFiles%\IE Toy\Data|history
FileKey2=%ProgramFiles%\IE Toy\Data|history_ad
RegKey1=HKCU\Software\MySoftware\IEToy|FRAGS_ad
RegKey2=HKCU\Software\MySoftware\IEToy|FRAGS_popup

[*IE7pro]
LangSecRef=3024
Detect=HKCU\Software\IE7pro
Default=False
RegKey1=HKCU\Software\IE7pro\ClosedTabs

[*IIS Log Files]
LangSecRef=3004
LangRef=3146
Detect=HKLM\System\CurrentControlSet\Services\w3svc
DetectOS=|6.0
FileKey1=%windir%\system32\LogFiles|*.*|RECURSE
FileKey2=%SystemDrive%\inetpub\logs\LogFiles|*.*|RECURSE

[*IZArc]
LangSecRef=3024
Detect=HKCU\Software\IZSoftware\IZArc
Default=False
RegKey1=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey2=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey3=HKCU\Software\IZSoftware\IZArc\Recent

[*Icon Cache]
LangSecRef=3002
Default=False
FileKey1=%userprofile%\Local Settings\Application Data|IconCache.db
FileKey2=%LocalAppData%|IconCache.db

[*IconCool Editor]
LangSecRef=3021
DetectFile=%ProgramFiles%\IconCoolEditor\IconCooleditor.exe
Default=False
FileKey1=%ProgramFiles%\IconCoolEditor|IconFileList.src
FileKey2=%ProgramFiles%\IconCoolEditor|Recentlyused.src

[*IdeaSoft Scrapbooks Plus 1.0]
LangSecRef=3021
Detect=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0
Default=False
RegKey1=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0\Recent File List

[*ImgBurn]
LangSecRef=3021
Detect=HKCU\Software\ImgBurn
Default=False
FileKey1=%AppData%\ImgBurn|ImgBurn.log
FileKey2=%AppData%\ImgBurn\Log Files|ImgBurn.log

[*ImgBurn]
LangSecRef=3021
Detect=HKCU\Software\ImgBurn
Default=False
FileKey1=%appdata%\ImgBurn\Log Files|*.*
FileKey2=%appdata%\ImgBurn\IBG Files|*.*
RegKey1=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Destination
RegKey2=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Source
RegKey3=HKCU\Software\ImgBurn|ISOWRITE_RecentFiles_Source

[*Inno Setup]
LangSecRef=3021
Detect=HKCU\Software\Jordan Russell\Inno Setup
Default=False
RegKey1=HKCU\Software\Jordan Russell\Inno Setup\ScriptFileHistoryNew

[*InstallShield Professional]
LangSecRef=3021
Detect=HKCU\Software\InstallShield\InstallShield Professional
Default=False
RegKey1=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU1
RegKey2=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU2
RegKey3=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU3
RegKey4=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU4

[*Installer]
LangSecRef=3501
LangRef=3608
Default=False
SpecialKey1=R_INSTALLER

[*Installshield Developer 7.0]
LangSecRef=3021
Detect=HKCU\Software\InstallShield\Developer\7.0
Default=False
RegKey1=HKCU\Software\InstallShield\Developer\7.0\Recent File List

[*Interface]
LangSecRef=3501
LangRef=3615
Default=False
SpecialKey1=R_INTERFACE

[*Internet Download Manager]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Internet Download Manager
Default=False
FileKey1=%Appdata%\IDM\UrlHistory.txt
FileKey2=%Appdata%\IDM\UrlHistory2.txt

[*Internet Logs]
LangSecRef=3025
DetectFile=%windir%\Internet Logs
Default=False
FileKey1=%windir%\Internet Logs|*.dmp
FileKey2=%windir%\Internet Logs|*.log
FileKey3=%windir%\Internet Logs|*.tmp
FileKey4=%windir%\Internet Logs|*.zip

[*Invalid File Extensions]
LangSecRef=3501
LangRef=3602
Default=False
SpecialKey1=R_FILE_EXTS

[*IsoBuster]
LangSecRef=3021
Detect=HKCU\Software\Smart Projects\IsoBuster
Default=False
RegKey1=HKCU\Software\Smart Projects\IsoBuster|ImageFilePath

[*IsoBuster]
LangSecRef=3023
Detect=HKCU\Software\Smart Projects\IsoBuster
Default=False
RegKey1=HKCU\Software\Smart Projects\IsoBuster\RecentImages

[*Jetico Personal Firewall (Logs)]
LangSecRef=3022
Detect=HKLM\Software\Jetico\Personal Firewall
Default=False
FileKey1=%ProgramFiles%\Jetico\Jetico Personal Firewall|firewall*.log

[*KMPlayer]
LangSecRef=3023
Detect=HKCU\Software\KMPlayer
Default=False
RegKey1=HKCU\Software\KMPlayer\KMP2.0|LastFileName
RegKey2=HKCU\Software\KMPlayer\WideAlbum\(Default Album)

[*Kazaa (Search History)]
LangSecRef=3022
Detect=HKCU\Software\Kazaa
Default=False
RegKey1=HKCU\Software\Kazaa\Search

[*Koffix Blocker]
LangSecRef=3024
DetectFile=%ProgramFiles%\Koffix Blocker\Koffix.exe
Default=False
FileKey1=%userprofile%\My Documents\My Koffix Blocker Logs|*.*

[*Last Download Location]
LangSecRef=3001
LangRef=3108
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
RegKey1=HKCU\Software\Microsoft\Internet Explorer|Download Directory
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Main|Save Directory

[*LeechGet]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Cronosoft\LeechGet
RegKey1=HKCU\Software\Cronosoft\LeechGet\History

[*LimeWire]
LangSecRef=3022
DetectFile=%ProgramFiles%\LimeWire\LimeWire.exe
Default=False
FileKey1=%userprofile%\Incomplete|*.*|RECURSE
FileKey2=%userprofile%\Application Data\LimeWire|fileurns.cache
FileKey3=%userprofile%\Application Data\LimeWire|createtimes.cache
FileKey4=%userprofile%\Application Data\LimeWire|responses.cache
FileKey5=%userprofile%\Application Data\LimeWire|ttree.cache
FileKey6=%userprofile%\Application Data\LimeWire|gnutella.net

[*LogMeIn]
LangSecRef=3022
DetectFile=%ProgramFiles%\Logmein\x86\LogMeIn.exe
Default=False
FileKey1=%ProgramFiles%\Logmein|LMI*.log

[*MP3Gain (Logs)]
LangSecRef=3023
Detect=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis
Default=False
FileKey1=%ProgramFiles%\MP3Gain|*.log

[*MPEG Audio Collection]
LangSecRef=3023
Detect=HKCU\Software\MPEG Audio Collection
Default=False
RegKey1=HKCU\Software\MPEG Audio Collection|LastNameText1
RegKey2=HKCU\Software\MPEG Audio Collection|LastNameText2
RegKey3=HKCU\Software\MPEG Audio Collection|LastNameText3
RegKey4=HKCU\Software\MPEG Audio Collection|LastNameText4
RegKey5=HKCU\Software\MPEG Audio Collection|LastNameText5
RegKey6=HKCU\Software\MPEG Audio Collection|LastNameText6

[*MS Backup (Logs)]
LangSecRef=3025
DetectFile=%SystemRoot%\System32\ntbackup.exe
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Microsoft\Windows NT\NTBackup\Data|*.log

[*MS Direct Draw]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\DirectDraw
Default=False
RegKey1=HKCU\Software\Microsoft\DirectDraw\MostRecentApplicationName

[*MS HTML Help Workshop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\HTML Help Workshop
Default=False
RegKey1=HKCU\Software\Microsoft\HTML Help Workshop\Compressed HTML
RegKey2=HKCU\Software\Microsoft\HTML Help Workshop\Html Titles
RegKey3=HKCU\Software\Microsoft\HTML Help Workshop\Project Files
RegKey4=HKCU\Software\Microsoft\HTML Help Workshop\Recent File List
RegKey5=HKCU\Software\Microsoft\HTML Help Workshop\Settings|LastProject
RegKey6=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Folders
RegKey7=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Recent File List

[*MS Help Workshop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Help Workshop
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft Help Workshop\Cnt Files
RegKey2=HKCU\Software\Microsoft\Microsoft Help Workshop\Forage Files
RegKey3=HKCU\Software\Microsoft\Microsoft Help Workshop\Hlp Files
RegKey4=HKCU\Software\Microsoft\Microsoft Help Workshop\Hpj Files
RegKey5=HKCU\Software\Microsoft\Microsoft Help Workshop\Map Files
RegKey6=HKCU\Software\Microsoft\Microsoft Help Workshop\Recent File List

[*MS Imaging]
LangSecRef=3024
Detect=HKCU\Software\Kodak\Imaging
Default=False
RegKey1=HKCU\Software\Kodak\Imaging\Recent File List

[*MS Management Console]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List

[*MS Office 2003 Script Editor]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\MSE
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\MSE|LastLoadedSolution
Regkey2=HKCU\Software\Microsoft\Office\11.0\MSE\FileMRUList
Regkey3=HKCU\Software\Microsoft\Office\11.0\MSE\ProjectMRUList
Regkey4=HKCU\Software\Microsoft\Office\11.0\MSE\SolutionMRUList

[*MS Office Picture Manager]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office
Default=False
FileKey1=%LocalAppData%\Microsoft\OIS|OIScatalog.cag
FileKey2=%LocalAppData%\Microsoft\OIS\thumbnails|*.*

[*MS Office Publisher 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Publisher
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List

[*MS Paint]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List

[*MS Photo Editor]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor
Default=False
RegKey1=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile1
RegKey2=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile2
RegKey3=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile3
RegKey4=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile4
RegKey5=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType1
RegKey6=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType2
RegKey7=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType3
RegKey8=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType4

[*MS PhotoDraw 2000]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\PhotoDraw\1.0
Default=False
RegKey1=HKCU\Software\Microsoft\PhotoDraw\1.0\Recent File List

[*MS SQL Server 2005]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\FileMRUList
RegKey2=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\ProjectMRUList

[*MS Snapshot Viewer]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Snapshot Viewer
Default=False
RegKey1=HKCU\Software\Microsoft\Snapshot Viewer\Recent File List

[*MS Visual Studio 2005]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\8.0
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\8.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\8.0\ProjectMRUList

[*MS Visual Studio.NET 03]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\7.1
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\7.1\FileMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\7.1|LastLoadedSolution
FileKey1=%userprofile%\Local Settings\Application Data\ApplicationHistory|*.*|REMOVESELF

[*MS Visual Studio.NET 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\7.1
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File1
RegKey2=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File2
RegKey3=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File3
RegKey4=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File4
RegKey5=HKCU\Software\Microsoft\VisualStudio\7.1\ProjectMRUList|File5

[*MS Windows Wallpaper]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU

[*MS Wordpad]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List

[*MS Works 4.0]
LangSecRef=3021
Detect= HKCU\Software\Microsoft\Works\4.0
Default=False
RegKey1=HKCU\Software\Microsoft\Works\4.0\Recent File List

[*MS Works Suite 2006]
LangSecRef=3021
Detect= HKCU\Software\Microsoft\Works\8.0
Default=False
RegKey1=HKCU\Software\Microsoft\Works\8.0\Recent File List

[*MS XML Notepad]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\XML Notepad
Default=False
RegKey1=HKCU\Software\Microsoft\XML Notepad\Recent File List

[*MSConfig]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Shared Tools\MSConfig
Default=False
RegKey1=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandFrom
RegKey2=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandTo
RegKey3=HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSConfig

[*MUI Cache]
LangSecRef=3501
LangRef=3614
Default=False
SpecialKey1=R_MUICACHE

[*MUICache]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\

[*Macromedia Dreamweaver MX]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Macromedia\Dreamweaver MX 2004
RegKey1=HKCU\Software\Macromedia\Dreamweaver MX 2004\Recent File List

[*Macromedia Fireworks 6.0]
LangSecRef=3021
Default=False
Detect=HKCU\Software\Macromedia\Firework 6
RegKey1=HKCU\Software\Macromedia\Firework 6\Recent File List

[*Macromedia Flash 4.0]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 4
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 4\Recent File List

[*Macromedia Flash 5.0]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 5
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 5\Recent File List

[*Macromedia Flash MX 2004]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 7
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 7\Recent File List

[*Macromedia Flash MX]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 6
Default=False
RegKey1=HKCU\Software\Macromedia\Flash 6\Recent File List

[*Macromedia Homesite 5.0]
LangSecRef=3021
Detect=HKCU\Software\Macromedia\HomeSite5
Default=False
RegKey1=HKCU\Software\Macromedia\HomeSite5\RecentFiles

[*Macromedia Shockwave 10]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Shockwave 10
Default=False
RegKey1=Software\Macromedia\Shockwave 10\movies

[*Macromedia Shockwave 8]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Shockwave 8
Default=False
RegKey1=Software\Macromedia\Shockwave 8\movies

[*MagicISO]
LangSecRef=3021
Detect=HKCU\Software\MagicISO
Default=False
RegKey1=HKCU\Software\MagicISO\Reopen

[*Malwarebytes' Anti Malware]
LangSecRef=3024
DetectFile=%ProgramFiles%\Malwarebytes' Anti-Malware\mbam.exe
Default=False
FileKey1=%appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Logs|*.txt
FileKey2=%appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine|*.*

[*Maxthon Browser 2]
LangSecRef=3022
DetectFile=%ProgramFiles%\Maxthon2\Maxthon.exe
Default=False
FileKey1=%ProgramFiles%\Maxthon2\Temp|*.*

[*McAfee SiteAdvisor]
LangSecRef=3024
DetectFile=%appdata%\SiteAdvisor
Default=False
FileKey1=%appdata%\SiteAdvisor|asserts.txt
FileKey2=%allusersdata%\SiteAdvisor|*.log
FileKey3=%commonappdata%\McAfee\MCLOGS\MISP\SAService|SAService*.log

[*Media Player Classic]
LangSecRef=3023
Detect=HKCU\Software\Gabest\Media Player Classic
Default=False
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName

[*Media Player Classic]
LangSecRef=3023
Detect=HKLM\Software\Gabest\Media Player Classic
Default=False
FileKey1=%appdata%\Media Player Classic|default.mpcpl
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName

[*MediaMonkey]
LangSecRef=3023
DetectFile=%ProgramFiles%\MediaMonkey\MediaMonkey.exe
Default=False
FileKey1=%userprofile%\Local Settings\Temp|*.*|RECURSE
FileKey2=%userprofile%\My Documents\My Music\MediaMonkey|MediaMonkey.m3u
FileKey3=%userprofile%\My Documents\My Music\MediaMonkey\Previews|*.*|RECURSE

[*Memory Dumps]
LangSecRef=3003
LangRef=3143
Default=False
FileKey1=%windir%|memory.dmp
FileKey2=%windir%\MiniDump|*.dmp

[*Menu Order Cache]
LangSecRef=3004
LangRef=3125
WarningRef=3203
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder

[*Messenger Plus! Live (Logs)]
LangSecRef=3022
Detect=HKCU\Software\Patchou
Default=False
FileKey1=%userprofile%\My Documents\My Chat Logs|*.*|RECURSE

[*MiTeC DFM Editor]
LangSecRef=3021
Detect=HKCU\Software\MiTeC\DFM Editor
Default=False
RegKey1=HKCU\Software\MiTeC\DFM Editor\5.x\Main\MRUHistory

[*Microangelo 6]
LangSecRef=3021
Detect=HKCU\Software\Eclipsit\Microangelo\Toolset 6
Default=False
RegKey1=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Animator\MRU List
RegKey2=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Librarian\MRU List
RegKey3=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Studio\MRU List

[*Microangelo]
LangSecRef=3021
Detect=HKCU\Software\Impact\Microangelo
Default=False
RegKey1=HKCU\Software\Impact\Microangelo\Animator\MRU List
RegKey2=HKCU\Software\Impact\Microangelo\Librarian\MRU List
RegKey3=HKCU\Software\Impact\Microangelo\Studio\MRU List

[*Microsoft AntiSpyware]
LangSecRef=3024
DetectFile=%ProgramFiles%\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
Default=False
FileKey1=%ProgramFiles%\Microsoft AntiSpyware|errors.log
FileKey2=%ProgramFiles%\Microsoft AntiSpyware|tracksEraser.log
FileKey3=%ProgramFiles%\Microsoft AntiSpyware|cleaner.log

[*Microsoft Visual Studio 6.0]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\6.0
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\6.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\6.0\MenuMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\6.0\ProjectMRUList
RegKey4=HKCU\Software\Microsoft\Visual Basic\6.0\RecentFiles

[*Missing Shared DLLs]
LangSecRef=3501
LangRef=3601
Default=False
SpecialKey1=R_SHARED_DLLS

[*More Windows Explorer]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU

[*Morpheus]
LangSecRef=3022
Default=False
Detect=HKCU\Software\Morpheus
RegKey1=HKCU\Software\Morpheus\Morpheus\Recent File List

[*Mozilla - Cookies]
LangSecRef=3026
LangRef=3102
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_COOKIES

[*Mozilla - Download History]
LangSecRef=3026
LangRef=3163
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_DOWNLOAD

[*Mozilla - Internet Cache]
LangSecRef=3026
LangRef=3161
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_CACHE

[*Mozilla - Internet History]
LangSecRef=3026
LangRef=3162
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_HISTORY

[*Mozilla - Saved Form Information]
LangSecRef=3026
LangRef=3164
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_FORM

[*Mp3tag (Log)]
LangSecRef=3023
Detect=HKLM\Software\Florian Heidenreich\Mp3tag
Default=False
FileKey1=%appdata%\Mp3tag|Mp3tagError.log

[*Mp3tag]
LangSecRef=3021
Detect=HKCU\Software\Moebius\Mp3tag
Default=False
RegKey1=HKCU\Software\Moebius\Mp3tag\Settings|LastDirName
RegKey2=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|0
RegKey3=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|1
RegKey4=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|2
RegKey5=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|3
RegKey6=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|4
RegKey7=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|5
RegKey8=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|6
RegKey9=HKCU\Software\Moebius\Mp3tag\Settings\HistDir|7

[*MusicMatch Jukebox]
LangSecRef=3023
Detect=HKLM\Software\MUSICMATCH\MUSICMATCH Jukebox
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox|*.log
FileKey2=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox|*log.txt
FileKey3=%userprofile%\Local Settings\Application Data\Musicmatch\Jukebox\Cache|*.*
FileKey4=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\TEMP|*.*
FileKey5=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\MMRadio\Cache|*.*

[*MyToolkit]
LangSecRef=3024
Detect=HKCU\Software\FutureFog\MyToolkit\Options
Default=False
RegKey1=HKCU\Software\FutureFog\MyToolkit\Options|LastUsedFolder

[*NA Framework Agent]
LangSecRef=3021
Detect=HKLM\Software\Network Associates\TVD\Shared Components\Framework
Default=False
FileKey1=%allusersprofile%\Application Data\Network Associates\Common Framework\AgentEvents|*.*
FileKey2=%allusersprofile%\Application Data\McAfee\Common Framework\AgentEvents|*.*

[*NSIS]
LangSecRef=3021
Detect=HKLM\Software\NSIS
Default=False
RegKey1=HKLM\Software\NSIS\MRU

[*Nero Burning ROM 9]
LangSecRef=3021
Detect=HKCU\Software\Nero\Nero 9
Default=False
RegKey1=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BrowserDir
RegKey2=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey3=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|WorkingDir
RegKey4=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey5=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BootImageDir
RegKey6=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Recent File List
FileKey1=%appdata%\Nero\Nero 9\Nero Burning ROM|*.log

[*Nero Burning ROM]
LangSecRef=3021
Detect=HKCU\Software\ahead\Nero - Burning Rom
Default=False
RegKey1=HKCU\Software\ahead\Nero - Burning Rom\Settings|BrowserDir
RegKey2=HKCU\Software\ahead\Nero - Burning Rom\Settings|ImageDir
RegKey3=HKCU\Software\ahead\Nero - Burning Rom\Settings|WorkingDir
RegKey4=HKLM\Software\Ahead\Nero - Burning Rom\Settings|ImageDir
RegKey5=HKLM\Software\Ahead\Nero - Burning Rom\Settings|BootImageDir
RegKey6=HKCU\Software\Ahead\Nero - Burning Rom\Recent File List
RegKey7=HKCU\Software\Ahead\Cover Designer\Recent File List
RegKey8=HKCU\Software\Ahead\Nero Wave Editor\Recent File List
FileKey1=%ProgramFiles%\Ahead\Nero|NeroHistory.log

[*Netscape Navigator 4.x]
LangSecRef=3022
Detect=HKCU\Software\Netscape\Netscape Navigator\Main
Default=False
FileKey1=%ProgramFiles%\Netscape\Users\default|netscape.hst
FileKey2=%ProgramFiles%\Netscape\Users\default|cookies.txt
FileKey3=%ProgramFiles%\Netscape\Users\default\cache|*.*

[*Norton AntiVirus]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Symantec\Norton AntiVirus NT\Install\7.50
Default=False
FileKey1=%commonappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey2=%localappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|*.*

[*NoteXpad]
LangSecRef=3021
Detect=HKLM\Software\NoteXpad
Default=False
RegKey1=HKLM\Software\NoteXpad\Recent

[*O&O Defrag]
LangSecRef=3024
Detect=HKCU\Software\O&O\O&O Defrag
Default=False
FileKey1=%userprofile%\My Documents\O&O\O&O Defrag\data\reports|*.*|RECURSE

[*Obsolete Software]
LangSecRef=3501
LangRef=3609
Default=False
SpecialKey1=R_OLDSOFTWARE

[*Office 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel\Recent Files
RegKey2=HKCU\Software\Microsoft\Office\11.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
Regkey3=HKCU\Software\Microsoft\Office\11.0\PowerPoint\Recent File List
Regkey4=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List
Regkey5=HKCU\Software\Microsoft\Office\11.0\InfoPath\Recent File List
RegKey6=HKCU\Software\Microsoft\Office\11.0\Common\Internet\Server Cache
RegKey7=HKCU\Software\Microsoft\Office\11.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\MSPaper 11.0\Persist File Name
RegKey9=HKCU\Software\Microsoft\MSPaper 11.0\Recent File List
RegKey10=HKCU\Software\Microsoft\Office\11.0\Word\Data|Settings
RegKey11=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile1
RegKey12=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile2
RegKey13=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile3
RegKey14=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile4
RegKey15=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile5
RegKey16=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile6
RegKey17=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile7
RegKey18=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile8
RegKey19=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey20=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey21=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU

[*Office 2007]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\12.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey2=HKCU\Software\Microsoft\Office\12.0\Word\File MRU
RegKey3=HKCU\Software\Microsoft\Office\12.0\Excel\File MRU
RegKey4=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU1
RegKey5=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU2
RegKey6=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU3
RegKey7=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU4
RegKey8=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU5
RegKey9=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU6
RegKey10=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU7
RegKey11=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU8
RegKey12=HKCU\Software\Microsoft\Office\12.0\PowerPoint\File MRU
RegKey13=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Save As\File Name MRU
RegKey14=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open\File Name MRU
RegKey15=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Save As\File Name MRU
RegKey16=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Excel\Settings\Save As\File Name MRU
RegKey17=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Publisher\Settings\Save As\File Name MRU
RegKey18=HKCU\Software\Microsoft\Office\12.0\Publisher\Recent File List
RegKey19=HKCU\Software\Microsoft\Office\12.0\InfoPath\Recent File List

[*Office 97]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\8.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\8.0\Excel\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\8.0\Project\Recent File List
RegKey3=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent File List
RegKey4=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent Folder List
RegKey5=HKCU\Software\Microsoft\Office\8.0\Common\Internet\LocationOfComponents
RegKey6=HKCU\Software\Microsoft\Office\8.0\Access\Settings

[*Office XP]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\10.0\Common
Default=False
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\10.0\PowerPoint\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\10.0\Excel\Recent Files
RegKey3=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent File List
RegKey4=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List
RegKey5=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List
RegKey6=HKCU\Software\Microsoft\Office\10.0\Word\Recent Templates
RegKey7=HKCU\Software\Microsoft\Office\10.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\Office\10.0\Word\Data|Settings
RegKey9=HKCU\Software\Microsoft\Office\10.0\Access\Settings

[*Old Prefetch data]
LangSecRef=3004
LangRef=3147
Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OptimalLayout
SpecialKey1=N_INT_PREFETCH

[*OpenOffice 1.14]
LangSecRef=3021
DetectFile=%ProgramFiles%\OpenOffice.org1.1.4\program\soffice.exe
Default=False
FileKey1=%ProgramFiles%\OpenOffice.org1.1.4\user\registry\data\org\openoffice\Office|Common.xcu

[*OpenOffice 2.0]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.0
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu

[*OpenOffice 2.1]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.1
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu

[*OpenOffice 2.3]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.3
Default=False
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu

[*OpenOffice 3.1]
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.1
Default=False
FileKey1=%appdata%\OpenOffice.org\3\user\registry\data\org\openoffice\Office|Common.xcu

[*Opera - Cookies]
LangSecRef=3027
LangRef=3102
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_COOKIES

[*Opera - Internet Cache]
LangSecRef=3027
LangRef=3161
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_CACHE

[*Opera - Internet History]
LangSecRef=3027
LangRef=3162
Default=False
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_HISTORY

[*Opera 9 (Classic)]
LangSecRef=3022
DetectFile=%ProgramFiles%\Opera 9\Opera.exe
Default=False
FileKey1=%ProgramFiles%\Opera 9\profile|cookies4.dat
FileKey2=%ProgramFiles%\Opera 9\profile|global.dat
FileKey3=%ProgramFiles%\Opera 9\profile|vlink4.dat
FileKey4=%ProgramFiles%\Opera 9\profile\cache4|*.*
FileKey5=%ProgramFiles%\Opera 9\profile\cacheOp|*.*

[*Orbit Downloader]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Orbit
Default=False
FileKey1=%appdata%\Orbit\|fileinfo.dat
FileKey2=%appdata%\Orbit\|history.dat
FileKey3=%appdata%\Orbit\|unfinish.dat
FileKey4=%appdata%\Orbit\flink|*.*

[*Other Explorer MRUs]
LangSecRef=3002
LangRef=3124
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\PrnPortsMRU
RegKey4=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU
RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComputerDescriptions
RegKey6=HKLM\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey7=HKCU\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey8=HKLM\Software\Microsoft\DirectDraw\MostRecentApplication|Name
RegKey9=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Id
RegKey10=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Name

[*Outlook 2003]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Outlook
Default=False
RegKey1=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey2=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey3=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
RegKey4=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 1
RegKey5=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 3
FileKey1=%appdata%\Microsoft\Outlook|Outlook.NK2

[*PDF-XChange Viewer]
LangSecRef=3021
Detect=HKCU\Software\Tracker Software\PDFViewer
Default=False
RegKey1=HKCU\Software\Tracker Software\PDFViewer\Documents\LastOpened
RegKey2=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Bars
RegKey3=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Panes

[*PDFCreator]
LangSecRef=3024
Detect=HKCU\Software\PDFCreator
Default=False
RegKey1=HKCU\Software\PDFCreator\Program|LastsaveDirectory

[*PE Module Explorer]
LangSecRef=3024
Detect=HKCU\Software\Woozle\PE Module Explorer
Default=False
RegKey1=HKCU\Software\Woozle\PE Module Explorer\Recent Files

[*Paint Shop Pro 7.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 7
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 7\Recent File List
RegKey2=HKCU\Software\Jasc\Animation Shop 3\Recent File List
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 7\General|FolderHistory
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveAsDirectory
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveCopyDirectory

[*Paint Shop Pro 8.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 8
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 8\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 8\WorkspaceMRU
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdPyScript\RunScript|FileName
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdFile\FileSaveAs|FileFolder
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdNonGraphic\SaveWorkspace|WorkspaceFilename
RegKey6=HKCU\Software\Jasc\Paint Shop Pro 8\ScriptMRU

[*Paint Shop Pro 9.0]
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 9
Default=False
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 9\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 9\WorkspaceMRU
Regkey3=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileOpen|Folder

[*Paint Shop Pro XI]
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\11
Default=False
RegKey1=HKCU\Software\Corel\Paint Shop Pro\11\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\11\WorkspaceMRU
Regkey3=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileOpen|Folder

[*Paint Shop Pro X]
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\10
Default=False
RegKey1=HKCU\Software\Corel\Paint Shop Pro\10\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\10\WorkspaceMRU
Regkey3=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileOpen|Folder

[*Paint.NET]
LangSecRef=3021
Detect=HKCU\Software\Paint.NET
Default=False
RegKey1=HKCU\Software\Paint.NET|MRU0
RegKey2=HKCU\Software\Paint.NET|MRU1
RegKey3=HKCU\Software\Paint.NET|MRU2
RegKey4=HKCU\Software\Paint.NET|MRU3
RegKey5=HKCU\Software\Paint.NET|MRU4
RegKey6=HKCU\Software\Paint.NET|MRU5
RegKey7=HKCU\Software\Paint.NET|MRU6
RegKey8=HKCU\Software\Paint.NET|MRU7
RegKey9=HKCU\Software\Paint.NET|MRU0Thumb
RegKey10=HKCU\Software\Paint.NET|MRU1Thumb
RegKey11=HKCU\Software\Paint.NET|MRU2Thumb
RegKey12=HKCU\Software\Paint.NET|MRU3Thumb
RegKey13=HKCU\Software\Paint.NET|MRU4Thumb
RegKey14=HKCU\Software\Paint.NET|MRU5Thumb
RegKey15=HKCU\Software\Paint.NET|MRU6Thumb
RegKey16=HKCU\Software\Paint.NET|MRU7Thumb

[*Pelles C]
LangSecRef=3021
Detect=HKCU\Software\Pelle Orinius\PellesC
Default=False
RegKey1=HKCU\Software\Pelle Orinius\PellesC\Recent File List
RegKey2=HKCU\Software\Pelle Orinius\PellesC\Recent Project List
RegKey3=HKCU\Software\Pelle Orinius\PellesC\Recent Search List

[*PerfectDisk 7.0]
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\7.0
Default=False
FileKey1=%commonappdata%\Raxco\PerfectDisk\7.0|PerfectDisk.log

[*PerfectDisk 8]
LAngSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\8.0
Default=False
FileKey1=%allusersprofile%\Application Data\Raxco\PerfectDisk\8.0|*.log

[*Phorest]
LangSecRef=3024
Detect=HKCU\Software\FutureFog\Phorest\Options
Default=False
RegKey1=HKCU\Software\FutureFog\Phorest\Options|LastUsedFolder
RegKey2=HKCU\Software\FutureFog\Phorest\Layout|SelectionLeft
RegKey3=HKCU\Software\FutureFog\Phorest\Layout|SelectionTop
RegKey4=HKCU\Software\FutureFog\Phorest\Layout|SelectionWidth
RegKey5=HKCU\Software\FutureFog\Phorest\Layout|SelectionHeight

[*Photo Print Calendar 3.00E Beta]
LangSecRef=3021
Detect=HKLM\SOFTWARE\Computer Institute of Japan, Ltd.\Photo Print Calendar from YOKOHAMA Ver.3.00E beta\3.00E beta
Default=False
FileKey1=%programfiles%\Photo Print Calendar|update.bmp

[*Photoshop CS Filebrowser]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Adobe\Photoshop
FileKey1=%userprofile%\application data\Adobe\FileBrowser\PhotoshopCS|*.*

[*Photoshop CS Filebrowser]
LangSecRef=3021
Default=False
Detect=HKLM\SOFTWARE\Adobe\Photoshop
FileKey1=%userprofile%\application data\Adobe\FileBrowser\PhotoshopCS|*.*
fileKey2=%userprofile%\Local Settings\Application Data\Adobe\Updater5\Install|*.*|RECURSE

[*PicoZip]
LangSecRef=3024
Detect=HKCU\Software\PicoZip
Default=False
RegKey1=HKCU\Software\PicoZip\MRU Items
RegKey2=HKCU\Software\PicoZip\MRUExtract

[*Pok3D]
LangSecRef=3021
DetectFile=%ProgramFiles%\Pok3d\Pok3d.ico
Default=False
FileKey1=%userprofile%\Application Data\Pok3d|*.log
FileKey2=%userprofile%\Application Data\Pok3d|*.dmp

[*PowerArchiver]
LangSecRef=3024
Detect=HKCU\Software\PowerArchiver
Default=False
RegKey1=HKCU\Software\PowerArchiver\Files|Active_File1
RegKey2=HKCU\Software\PowerArchiver\Files|Active_File2
RegKey3=HKCU\Software\PowerArchiver\Files|Active_File3
RegKey4=HKCU\Software\PowerArchiver\Files|Active_File4
RegKey5=HKCU\Software\PowerArchiver\Files|Active_File5
RegKey6=HKCU\Software\PowerArchiver\Files|Extract1
RegKey7=HKCU\Software\PowerArchiver\Files|Extract2
RegKey8=HKCU\Software\PowerArchiver\Files|Extract3
RegKey9=HKCU\Software\PowerArchiver\Files|Extract4
RegKey10=HKCU\Software\PowerArchiver\Files|Extract5
RegKey11=HKCU\Software\PowerArchiver\Files|Last open dir
RegKey12=HKCU\Software\PowerArchiver\Files|Last backup dir
RegKey13=HKCU\Software\PowerArchiver\Files|Last add dir

[*PowerDVD]
LangSecRef=3021
DetectFile=%ProgramFiles%\Cyberlink\PowerDVD\PowerDVD.exe
Default=False
FileKey1=%ProgramFiles%\CyberLink\PowerDVD|*.pls
FileKey2=%userprofile%\My Documents\CyberLink\PowerDVD|*.pls

[*PowerZip]
LangSecRef=3024
Detect=HKCU\Software\Trident Software\PowerZip
Default=False
RegKey1=HKCU\Software\Trident Software\PowerZip\Recent File List

[*QuickPAR]
LangSecRef=3024
Detect=HKCU\Software\QuickPar
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\QuickPar|*.*

[*Quicktime Player Cache]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=False
FileKey1=%localappdata%\Apple Computer\QuickTime\downloads|*.*|RECURSE

[*Quicktime Player]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=False
RegKey1=HKLM\Software\Apple Computer, Inc.\QuickTime\Recent Movies
FileKey1=%userprofile%|QTPlayerSession.xml
FileKey2=%appdata%\Apple Computer\QuickTime|QTPlayerSession.xml

[*Qwest QuickCare]
LangSecRef=3022
Detect=HKLM\Software\QuickCare
Default=False
FileKey1=%allusersprofile%\Application Data\Support.com|*.tmp|RECURSE
FileKey2=%userprofile%\Local Settings\Application Data\SupportSoft|*.tmp|RECURSE

[*ReGet Deluxe]
LangSecRef=3022
Detect=HKCU\Software\ReGet Software\ReGetDx
Default=False
FileKey1=%ProgramFiles%\ReGet Deluxe\history|*.*
RegKey1=HKCU\Software\ReGet Software\ReGetDx\FtpExplorer\Hist
RegKey2=HKCU\Software\ReGet Software\ReGetDx\History
RegKey3=HKCU\Software\ReGet Software\ReGetDx\Search\HistFind

[*Real Player SP]
LangSecRef=3023
Detect=HKCU\Software\RealNetworks\RealPlayer\12.0
Default=False
RegKey1=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins1
RegKey10=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins2
RegKey11=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins3
RegKey12=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins4
RegKey13=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins5
RegKey14=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins6
RegKey15=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins7
RegKey16=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins8
RegKey17=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\LastOpenFileDir
RegKey18=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips1
RegKey19=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips2
RegKey20=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips3
RegKey21=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips4
RegKey22=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips5
RegKey23=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips6
RegKey24=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips7
FileKey1=%appdata%\Real\RealPlayer|RealPlayer-log.txt
FileKey2=%appdata%\Real\RealPlayer\History|*.*

[*Recent Documents]
LangSecRef=3002
LangRef=3121
Default=False
SpecialKey1=N_EX_RECENTDOCS
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

[*Recently Typed URLs]
LangSecRef=3001
LangRef=3104
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
RegKey1=HKCU\Software\Microsoft\Internet Explorer\TypedURLs
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
RegKey3=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU

[*RegAlyzer]
LangSecRef=3024
Detect=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer
Default=False
RegKey1=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|LastKey
RegKey2=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|RemoteListHistory
RegKey3=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|SearchTerm

[*RegEdit]
LangSecRef=3025
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit|LastKey

[*Registry Mechanic]
LangSecRef=3024
Detect=HKLM\Software\PCTools\Registry Mechanic
Default=False
FileKey1=%userprofile%|*.rmbak|RECURSE
FileKey2=%userprofile%|*.rrr|RECURSE
FileKey3=%userprofile%|*.rrr.bak|RECURSE
FileKey4=%userprofile%\Local Settings\Application Data\Microsoft\Windows|*.rmbak
FileKey5=%userprofile%\Local Settings\Application Data\Microsoft\Windows|*.rrr
FileKey6=%userprofile%\Local Settings\Application Data\Microsoft\Windows|*.rrr.bak
FileKey7=%allusersprofile%|*.rmbak|RECURSE
FileKey8=%allusersprofile%|*.rrr|RECURSE
FileKey9=%allusersprofile%|*.rrr.bak|RECURSE
FileKey10=%systemdrive%\Documents and Settings\Guest|*.rmbak|RECURSE
FileKey11=%systemdrive%\Documents and Settings\Guest|*.rrr|RECURSE
FileKey12=%systemdrive%\Documents and Settings\Guest|*.rrr.bak|RECURSE
FileKey13=%systemdrive%\Documents and Settings\LocalService|*.rmbak|RECURSE
FileKey14=%systemdrive%\Documents and Settings\LocalService|*.rrr|RECURSE
FileKey15=%systemdrive%\Documents and Settings\LocalService|*.rrr.bak|RECURSE
FileKey16=%systemdrive%\Documents and Settings\NetworkService|*.rmbak|RECURSE
FileKey17=%systemdrive%\Documents and Settings\NetworkService|*.rrr|RECURSE
FileKey18=%systemdrive%\Documents and Settings\NetworkService|*.rrr.bak|RECURSE
FileKey19=%windir%\system32\config|*.rmbak
FileKey20=%windir%\system32\config|*.rrr
FileKey21=%windir%\system32\config|*.rrr.bak
FileKey22=%ProgramFiles%\Registry Mechanic\Log|compactlog.log
FileKey23=%ProgramFiles%\Registry Mechanic\Log|results.log
FileKey24=%ProgramFiles%\Registry Mechanic\Log|scan.log

[*RegistryFix]
LangSecRef=3024
DetectFile=%ProgramFiles%\RegistryFix\RegistryFix.exe
Default=False
FileKey1=%ProgramFiles%\RegistryFix\logs|*.*

[*Remote Desktop]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Terminal Server Client
Default=False
FileKey1=%localappdata%\Microsoft\Terminal Server Client\Cache|*.*
RegKey1=HKCU\Software\Microsoft\Terminal Server Client\Default

[*Run (in Start Menu)]
LangSecRef=3002
LangRef=3122
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU

[*Run At Startup]
LangSecRef=3501
LangRef=3610
Default=False
SpecialKey1=R_RUNSTARTUP

[*STOIK Smart Resizer]
LangSecRef=3023
Detect=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer\Recent File List
Default=False
RegKey1=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer\Recent File List

[*STOIK Video Converter 2]
LangSecRef=3023
Detect=HKCU\Software\STOIK
Default=False
FileKey1=%appdata%\STOIK\videopak2|*.ini

[*SUPERAntiSpyware (Logs)]
LangSecRef=3024
Detect=HKLM\Software\SUPERAntiSpyware.com\SUPERAntiSpyware
Default=False
FileKey1=%appdata%\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs|*.log

[*SWiSH]
LangSecRef=3023
Detect=HKCU\Software\DJJ Holdings\SWiSH
Default=False
RegKey1=HKCU\Software\DJJ Holdings\SWiSH\Recent File List

[*Safari - Cookies]
LangSecRef=3028
LangRef=3102
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari\Cookies|Cookies.plist

[*Safari - Internet Cache]
LangSecRef=3028
LangRef=3161
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%localappdata%\Apple Computer\Safari|Cache.db

[*Safari - Internet History]
LangSecRef=3028
LangRef=3162
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari|History.plist
FileKey2=%appdata%\Apple Computer\Safari|Downloads.plist
FileKey3=%localappdata%\Apple Computer\Safari\History|*.*

[*Safari - Saved Form Information]
LangSecRef=3028
LangRef=3164
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari|Form Values.plist

[*ScanDefrag (Logs)]
LangSecRef=3024
Detect=HKLM\Software\ScanDefrag
Default=False
FileKey1=%SystemDrive%\ScanDefrag|*.log
FileKey2=%SystemDrive%\ScanDefrag\logs|*.txt

[*Search Assistant Autocomplete]
LangSecRef=3002
LangRef=3123
Detect=HKCU\Software\Microsoft\Search Assistant
Default=False
RegKey1=HKCU\Software\Microsoft\Search Assistant\ACMru

[*Second Copy 2000]
LangSecRef=3021
Detect=HKCU\Software\Centered Systems\Second Copy 2000
Default=False
FileKey1=%ProgramFiles%\SecCopy|log.rtf
FileKey2=%ProgramFiles%\SecCopy|log-old.rtf
RegKey1=HKCU\Software\Centered Systems\Second Copy 2000\MRU

[*SecureCRT]
LangSecRef=3021
Detect=HKCU\Software\VanDyke\SecureCRT
Default=False
FileKey1=%appdata%\VanDyke\SecureCRT\Config|Recent File List.ini
FileKey2=%appdata%\VanDyke\SecureCRT\Config|Recent Script List.ini

[*Shareaza]
LangSecRef=3022
DetectFile=%ProgramFiles%\Shareaza\Shareaza.exe
Default=False
FileKey1=%userprofile%\Local Settings\Application Data\Shareaza\Incomplete|*.*

[*Smart Installer Maker]
LangSecRef=3024
Detect=HKCU\Software\InstallBuilders\Smart Install Maker
Default=False
RegKey1=HKCU\Software\InstallBuilders\Smart Install Maker\Reopen

[*SmartFTP]
LangSecRef=3022
Detect=HKCU\Software\SmartFTP
Default=False
FileKey1=%appdata%\SmartFTP\Cache|*.*|RECURSE
FileKey2=%appdata%\SmartFTP|History.dat

[*SoftThinks CD Creator]
LangSecRef=3021
Detect=HKLM\SOFTWARE\SoftThinks
Default=False
FileKey1=%windir%\CREATOR|*.log

[*Soulseek Beta]
LangSecRef=3022
DetectFile=%ProgramFiles%\Soulseek-Test\slsk.exe
Default=False
FileKey1=%ProgramFiles%\Soulseek-Test|search.cfg

[*Soulseek]
LangSecRef=3022
DetectFile=%ProgramFiles%\Soulseek\slsk.exe
Default=False
FileKey1=%ProgramFiles%\Soulseek|search.cfg

[*Sound Forge 6.0]
LangSecRef=3022
Detect=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics
Default=False
RegKey1=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30110
RegKey2=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30111
RegKey3=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30112
RegKey4=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30113
RegKey5=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30114
RegKey6=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30115

[*SpyBot Search and Destroy]
LangSecRef=3024
Detect=HKCU\Software\Safer Networking Limited\SpybotSnD
Default=False
FileKey1=%commonappdata%\Spybot - Search & Destroy\Logs|*.*
FileKey2=%ProgramFiles%\Spybot - Search & Destroy|advdebug.txt
FileKey3=%commonappdata%\Spybot - Search & Destroy|Statistics.ini
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|*.*
FileKey5=%windir%\All Users\Application Data\Spybot - Search & Destroy|Statistics.ini
FileKey6=%commonappdata%\Spybot - Search & Destroy\Backups|*.log

[*SpyDefense]
LangSecRef=3024
DetectFile=%ProgramFiles%\Everest Labs\Spydefense\sdc.exe
Default=False
FileKey1=%userprofile%\Application Data\Everest Labs\Spydefense\Backups|BF7.tmp
FileKey2=%userprofile%\Application Data\Everest Labs\Spydefense|SpyDefense.log
FileKey3=%userprofile%\Application Data\Everest Labs\Spydefense|History.ini
FileKey3=%userprofile%\Application Data\Everest Labs\Spydefense|Backups.ini

[*Spyware Doctor]
LangSecRef=3024
Detect=HKCU\Software\PCTools\Spyware Doctor
Default=False
FileKey1=%ProgramFiles%\Spyware Doctor\Log|*.*

[*Spyware Terminator]
LangSecRef=3024
Detect=HKCU\Software\Spyware Terminator
Default=False
FileKey1=%ProgramFiles%\Spyware Terminator\|*.err
FileKey2=%ProgramFiles%\Spyware Terminator\|*.old
FileKey3=%ProgramFiles%\Spyware Terminator\update|*.*
FileKey4=%appdata%\Spyware Terminator\Reports\|*.*
FileKey5=%ProgramFiles%\Spyware Terminator\Clamav\|*.old

[*StarOffice 8]
LangSecRef=3021
DetectFile=%ProgramFiles%\Sun\StarOffice 8\program\soffice.exe
Default=False
FileKey1=%appdata%\StarOffice8\user\registry\data\org\openoffice\Office|Common.xcu

[*Start Menu Ordering]
LangSecRef=3501
LangRef=3611
Default=False
SpecialKey1=R_STARTMENUORDER

[*Start Menu Shortcuts]
LangSecRef=3003
LangRef=3612
Default=False
SpecialKey1=F_STARTMENU

[*Sun Java]
LangSecRef=3022
Detect=HKLM\SOFTWARE\JavaSoft\Java Plug-in
Default=False
FileKey1=%appdata%\Sun\Java\Deployment\cache|*.*|RECURSE
FileKey2=%appdata%\Sun\Java\Deployment\javaws\cache|*.*|RECURSE

[*Symantec AntiVirus]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Symantec\Symantec AntiVirus\Install\7.50
Default=False
FileKey1=%commonappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey2=%localappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|*.*

[*Symantec Ghost]
LangSecRef=3024
Detect=HKCU\Software\Symantec\Symantec Ghost
Default=False
RegKey1=HKCU\Software\Symantec\Symantec Ghost\Explorer\Ghost Explorer\Recent File List

[*Synchronize It!]
LangSecRef=3021
Detect=HKCU\Software\grigsoft.com\Synchronize It!
Default=False
RegKey1=HKCU\Software\grigsoft.com\Synchronize It!\Synchronize It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Synchronize It!\Combos

[*TUGZip]
LangSecRef=3024
Detect=HKCU\Software\TUGZip
Default=False
RegKey1=HKCU\Software\TUGZip|mainRecent
RegKey2=HKCU\Software\TUGZip|extrRecent
RegKey3=HKCU\Software\TUGZip|cmpWorkingDir

[*Tag&Rename 3]
LangSecRef=3024
Detect=HKCU\Software\Softpointer\Tag&Rename3\Config
Default=False
RegKey1=HKCU\Software\Softpointer\Tag&Rename3\Config|FCurrentFolder
RegKey2=HKCU\Software\Softpointer\Tag&Rename3\Config|FHistoryList

[*Talkback (Crash Reports)]
LangSecRef=3026
Detect=HKLM\SOFTWARE\FullCircle\TalkBack
Default=False
RegKey1=HKLM\SOFTWARE\FullCircle\TalkBack
FileKey1=%userprofile%\Application Data\Talkback\MozillaOrg\Firefox15|*.*|RECURSE
FileKey2=%userprofile%\Application Data\Talkback\MozillaOrg\Firefox2|*.*|RECURSE
FileKey3=%userprofile%\Application Data\Talkback\MozillaOrg\Thunderbird2|*.*|RECURSE

[*TechSmith DubIt]
LangSecRef=3023
Detect=HKCU\Software\TechSmith\DubIt
Default=False
FileKey1=%ProgramFiles%\TechSmith\DubIt|*.gid
RegKey1=HKCU\Software\TechSmith\DubIt\Recent Audio Files
RegKey2=HKCU\Software\TechSmith\DubIt\Recent Video Files

[*Temporary Files]
LangSecRef=3003
LangRef=3142
Default=False
SpecialKey1=N_TEMP_DIRS

[*Temporary Internet Files]
LangSecRef=3001
LangRef=3101
Detect=HKCU\SOFTWARE\Microsoft\Internet Explorer
Default=False
SpecialKey1=N_INT_TEMP

[*TeraCopy]
LangSecRef=3024
Detect=HKCU\Software\Code Sector\TeraCopy
Default=False
RegKey1=HKCU\Software\Code Sector\TeraCopy|LastTargetFolder
FileKey1=%appdata%\TeraCopy|FileList.dat
FileKey2=%appdata%\TeraCopy|Transfer.log

[*TextPad]
LangSecRef=3021
Detect=HKCU\Software\Helios\TextPad 4
Default=False
RegKey1=HKCU\Software\Helios\TextPad 4\Recent File List
RegKey2=HKCU\Software\Helios\TextPad 4\Recent Strings

[*The Bat]
LangSecRef=3022
Detect=HKCU\Software\RIT\The Bat!
Default=False
FileKey1=%appdata%\The Bat!\cache|*.*

[*The Cleaner]
LangSecRef=3024
DetectFile=%ProgramFiles%\The Cleaner\cleaner.exe
Default=False
FileKey1=%ProgramFiles%\The Cleaner|logfile.txt
FileKey2=%ProgramFiles%\The Cleaner|moolive.log
FileKey3=%ProgramFiles%\The Cleaner|tca.log

[*The GIMP 2.2]
LangSecRef=3021
DetectFile=%userprofile%\.gimp-2.2\gimprc
Default=False
FileKey1=%userprofile%\.gimp-2.2|documents

[*Thumbnail Cache]
LangSecRef=3002
LangRef=3131
DetectOS=6.0
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\Explorer|thumbcache_*.db

[*Tivo Desktop]
LangSecRef=3023
Default=False
Detect=HKCU\SOFTWARE\TiVo\Desktop
FileKey1=%localappdata%\TiVo Desktop\Cache|*.*

[*Tomahawk PDF+]
LangSecRef=3021
Detect=HKCU\Software\NativeWinds\Tomahawk
Default=False
RegKey1=HKCU\Software\NativeWinds\Tomahawk\MRU

[*Total Recorder]
LangSecRef=3023
Detect=HKCU\Software\HighCriteria\TotalRecorder\Recent File List
Default=False
RegKey1=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File1
RegKey2=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File2
RegKey3=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File3
RegKey4=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File4
RegKey5=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File5
RegKey6=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File6
RegKey7=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File7
RegKey8=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File8
RegKey9=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File9

[*Total Uninstall]
LangSecRef=3024
Detect=HKCU\Software\MartS\Total Uninstall
Default=False
FileKey1=%ProgramFiles%\Total Uninstall|Log.txt
FileKey2=%ProgramFiles%\Total Uninstall|*.GID

[*Tray Notifications Cache]
LangSecRef=3004
LangRef=3126
WarningRef=3204
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|IconStreams
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|PastIconsStream
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|IconStreams
RegKey4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|PastIconsStream

[*Trillian]
LangSecRef=3024
Detect=HKLM\Software\Clients\IM\Trillian
Default=False
FileKey1=%ProgramFiles%\Trillian\users\default\instantlookup|*.*
FileKey2=%ProgramFiles%\Trillian\users\default\logs|*.*|RECURSE
FileKey3=%ProgramFiles%\Trillian\users\default\buddyicons|*.*|RECURSE
FileKey4=%ProgramFiles%\Trillian\Crash Files|*.*|RECURSE

[*TuneUp Utilities]
LangSecRef=3024
Detect=HKCU\Software\TuneUp
Default=False
FileKey1=%appdata%\TuneUp Software\TuneUp Utilities\Backups|*.rcb

[*TweakNow PowerPack 2005]
LangSecRef=3024
Detect=HKCU\Software\TweakNow PowerPack
Default=False
FileKey1=%ProgramFiles%\TweakNow PowerPack\Backup|*.*

[*UPX Shell]
LangSecRef=3024
Detect=HKCU\Software\ION Tek\UPX Shell
Default=False
RegKey1=HKCU\Software\ION Tek\UPX Shell\3.x|History

[*Ulead GIF Animator 5.05]
LangSecRef=3024
Detect=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05
Default=False
RegKey1=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05\Recent File List

[*Ulead Smart Saver Pro 3.0]
LangSecRef=3023
Detect=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0
Default=False
RegKey1=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0\Recent File List

[*UltraISO]
LangSecRef=3024
Detect=HKCU\Software\EasyBoot Systems\UltraISO
Default=False
RegKey1=HKCU\Software\EasyBoot Systems\UltraISO\5.0|Reopen
RegKey2=HKCU\Software\EasyBoot Systems\UltraISO\5.0|a
RegKey3=HKCU\Software\EasyBoot Systems\UltraISO\5.0|b
RegKey4=HKCU\Software\EasyBoot Systems\UltraISO\5.0|c
RegKey5=HKCU\Software\EasyBoot Systems\UltraISO\5.0|d
RegKey6=HKCU\Software\EasyBoot Systems\UltraISO\5.0|e
RegKey7=HKCU\Software\EasyBoot Systems\UltraISO\5.0|f
RegKey8=HKCU\Software\EasyBoot Systems\UltraISO\5.0|g
RegKey9=HKCU\Software\EasyBoot Systems\UltraISO\5.0|h
RegKey10=HKCU\Software\EasyBoot Systems\UltraISO\5.0|i

[*Universal Share Downloader]
LangSecRef=3022
DetectFile=%ProgramFiles%\USDownloader\USDownloader.exe
Default=False
FileKey1=%ProgramFiles%\USDownloader|USDownloader.log
FileKey2=%ProgramFiles%\USDownloader|*.bak
FileKey3=%ProgramFiles%\USDownloader|*.bmp
FileKey4=%ProgramFiles%\USDownloader|*.jpg
FileKey5=%ProgramFiles%\USDownloader|*.png

[*User Assist History]
LangSecRef=3004
LangRef=3128
WarningRef=3206
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count

[*VNCViewer 3]
LangSecRef=3024
Default=False
Detect=HKCU\Software\ORL\VNCviewer
RegKey1=HKCU\Software\ORL\VNCviewer\MRU

[*VNCViewer 4]
LangSecRef=3024
Default=False
Detect=HKCU\Software\RealVNC\VNCviewer4
RegKey1=HKCU\Software\RealVNC\VNCviewer4\MRU

[*Valve - Steam (Logs)]
LangSecRef=3023
Detect=HKCU\Software\Valve\Steam
Default=False
FileKey1=%ProgramFiles%\Valve\Steam\SteamLogs|*.log
FileKey2=%ProgramFiles%\Valve\Steam|Steam.log

[*Venis IX]
LangSecRef=3021
Detect=HKCU\Software\Spaceblue\Venis IX
Default=False
RegKey1=HKCU\Software\Spaceblue\Venis IX\FileHistory

[*Ventrilo Client]
LangSecRef=3021
Detect=HKCU\Software\Ventrilo
Default=False
FileKey1=%userprofile%\Application Data\Ventrilo|ventrilo.log
FileKey2=%userprofile%\Application Data\Ventrilo\temp|*.*
FileKey3=%userprofile%\Application Data\Ventrilo\recordings|*.*

[*Ventrilo Server]
LangSecRef=3022
DetectFile=%ProgramFiles%\VentSrv\ventrilo_srv.exe
Default=False
FileKey1=%ProgramFiles%\VentSrv|ventrilo_srv.log

[*VideoGet]
LangSecRef=3022
DetectFile=%ProgramFiles%\VideoGet\VideoGet.exe
Default=False
FileKey1=%ProgramFiles%\VideoGet\Temp|*.*

[*VirtualCloneDrive]
LangSecRef=3021
Detect=HKLM\Software\Elaborate Bytes\VirtualCloneDrive
Default=False
RegKey1=HKLM\Software\Elaborate Bytes\VirtualCloneDrive\0
RegKey2=HKCU\Software\Elaborate Bytes\VirtualCloneDrive\LRU

[*VirtualDub]
LangSecRef=3023
Default=False
Detect=HKCU\Software\Freeware\VirtualDub
RegKey1=HKCU\Software\Freeware\VirtualDub\MRU List

[*VirtualFDD]
LangSecRef=3024
Detect=HKCU\Software\Korbos\VirtualFDD
Default=False
RegKey1=HKCU\Software\Korbos\VirtualFDD\Recent File List

[*Vuze]
LangSecRef=3022
Detect=HKCU\Software\Azureus
Default=False
FileKey1=%appdata%\Azureus\logs|*.log
FileKey2=%appdata%\Azureus\logs\save|*.log
FileKey3=%userprofile%\Application Data\Azureus\tmp|*.*
FileKey4=%userprofile%\Application Data\Azureus|*.bak
FileKey5=%userprofile%\Application Data\Azureus|*.log
FileKey6=%userprofile%\Application Data\Azureus\active|*.bak

[*WM Recorder 10]
LangSecRef=3023
DetectFile=%ProgramFiles%\WM Recorder 10\WMR.exe
Default=False
FileKey1=%ProgramFiles%\WM Recorder 10|log.txt
FileKey2=%ProgramFiles%\WM Recorder 10|urls.txt

[*WMP (TFC)]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MediaPlayer\Player
Default=False
FileKey1=%UserProfile%\Local Settings\Application Data\Microsoft\Media Player\Transcoded Files Cache|*.*

[*WS FTP (Pro)]
LangSecRef=3022
Detect=HKCU\Software\Ipswitch\WS_FTP
Default=False
FileKey1=%userprofile%\Application Data\Ipswitch\WS_FTP\Logs|*.*

[*Wavosaur (Logs)]
LangSecRef=3023
DetectFile=%ProgramFiles%\Wavosaur\wavosaur.exe
Default=False
FileKey1=%ProgramFiles%\Wavosaur|wavosaur.log

[*Webroot SpySweeper]
LangSecRef=3024
Detect=HKCU\Software\Webroot\SpySweeper
FileKey1=%ProgramFiles%\Webroot\Spy Sweeper\Temp|*.*
FileKey2=%appdata%\Webroot\Spy Sweeper\Logs|*Log.txt

[*WinAVI Video Converter (Log)]
LangSecRef=3023
Detect=HKCU\Software\ZjSoft\WinAVI
Default=False
FileKey1=%LocalAppData%\WinAVI|debug.log

[*WinAce 2.0]
LangSecRef=3024
Detect=HKCU\Software\e-merge\WinAce\2.0
Default=False
RegKey1=HKCU\Software\e-merge\WinAce\2.0\Favorites
RegKey2=HKCU\Software\e-merge\WinAce\2.0\MRU Items

[*WinCHM]
LangSecRef=3021
Detect=HKCU\Software\Softany\WinCHM
Default=False
RegKey1=HKCU\Software\Softany\WinCHM|RecentFile1
RegKey2=HKCU\Software\Softany\WinCHM|RecentFile2
RegKey3=HKCU\Software\Softany\WinCHM|RecentFile3
RegKey4=HKCU\Software\Softany\WinCHM|RecentFile4
RegKey5=HKCU\Software\Softany\WinCHM|RecentFile5
RegKey6=HKCU\Software\Softany\WinCHM|RecentFile6

[*WinDiff]
LangSecRef=3024
Detect=HKCU\Software\Microsoft\Windiff
Default=False
RegKey1=HKCU\Software\Microsoft\Windiff|NameLeft
RegKey2=HKCU\Software\Microsoft\Windiff|NameRight

[*WinISO]
LangSecRef=3024
Detect=HKLM\Software\WinISO
Default=False
RegKey1=HKLM\Software\WinISO\Reopen

[*WinImage]
LangSecRef=3024
Detect=HKCU\Software\WinImage
Default=False
RegKey1=HKCU\Software\WinImage|File1
RegKey2=HKCU\Software\WinImage|File2
RegKey3=HKCU\Software\WinImage|File3
RegKey4=HKCU\Software\WinImage|File4
RegKey5=HKCU\Software\WinImage|File5
RegKey6=HKCU\Software\WinImage|File6
RegKey7=HKCU\Software\WinImage|File7
RegKey8=HKCU\Software\WinImage|File8
RegKey9=HKCU\Software\WinImage|File9
RegKey10=HKCU\Software\WinImage|PathExtract

[*WinMerge]
LangSecRef=3024
Detect=HKCU\Software\Thingamahoochie\WinMerge\Files
Default=False
RegKey1=HKCU\Software\Thingamahoochie\WinMerge\Files\Ext
RegKey2=HKCU\Software\Thingamahoochie\WinMerge\Files\Left
RegKey3=HKCU\Software\Thingamahoochie\WinMerge\Files\Right

[*WinPatrol]
LangSecRef=3024
Detect=HKCU\Software\BillP Studios\WinPatrol
Default=False
FileKey1=%ProgramFiles%\BillP Studios\WinPatrol|history.txt

[*WinRAR Comment]
LangSecRef=3024
Detect=HKCU\Software\WinRAR
Default=False
RegKey1=HKCU\Software\WinRAR\General\Info|CommentFile

[*WinRAR SFX]
LangSecRef=3024
Detect=HKCU\Software\WinRAR SFX
Default=False
RegKey1=HKCU\Software\WinRAR SFX

[*WinRAR]
LangSecRef=3024
Detect=HKCU\Software\WinRAR
Default=False
RegKey1=HKCU\Software\WinRAR\ArcHistory
RegKey2=HKCU\Software\WinRAR\General|LastFolder
RegKey3=HKCU\Software\WinRAR\DialogEditHistory\Arcname
RegKey4=HKCU\Software\WinRAR\DialogEditHistory\ExtrPath

[*WinWAP]
LangSecRef=3022
Detect=HKCU\Software\Winwap Technologies
Default=False
FileKey1=%userprofile%\WinWAP Temporary Files|*.*

[*WinZip]
LangSecRef=3024
Detect=HKCU\Software\Nico Mak Computing\WinZip
Default=False
RegKey1=HKCU\Software\Nico Mak Computing\WinZip\filemenu
RegKey2=HKCU\Software\Nico Mak Computing\WinZip\extract
RegKey3=HKCU\Software\Nico Mak Computing\WinZip\directories|DefDir
RegKey4=HKCU\Software\Nico Mak Computing\WinZip\directories|ExtractTo
RegKey5=HKCU\Software\Nico Mak Computing\WinZip\directories|gzAddDir
RegKey6=HKCU\Software\Nico Mak Computing\WinZip\directories|zDefDir
RegKey7=HKCU\Software\Nico Mak Computing\WinZip\directories|AddDir
RegKey8=HKCU\Software\Nico Mak Computing\WinZip\directories|gzExtractTo
RegKey9=HKCU\Software\Nico Mak Computing\WinZip\rrs\Opened

[*Winamp]
LangSecRef=3023
Detect=HKCU\Software\Winamp
Default=False
FileKey1=%ProgramFiles%\Winamp|winamp.m3u
FileKey2=%ProgramFiles%\Winamp|winamp.m3u8
FileKey3=%ProgramFiles%\Winamp\Plugins\ml|recent.dat
FileKey4=%ProgramFiles%\Winamp\Plugins\ml\cache|*.*|RECURSE
FileKey5=%userprofile%\Application Data\Winamp|winamp.m3u
FileKey6=%userprofile%\Application Data\Winamp|winamp.m3u8
FileKey7=%userprofile%\Application Data\Winamp\Plugins\ml|recent.dat
FileKey8=%userprofile%\Application Data\Winamp\Plugins\ml\Cache|*.*|RECURSE

[*Window Size/Location Cache]
LangSecRef=3004
LangRef=3127
WarningRef=3205
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams

[*Windows Defender]
LangSecRef=3024
Detect=HKLM\SOFTWARE\Microsoft\Windows Defender
Default=False
FileKey1=%commonappdata%\Microsoft\Windows Defender\Scans\History\Results\Quick|*.*
FileKey2=%commonappdata%\Microsoft\Windows Defender\Scans\History\Results\Resource|*.*

[*Windows Error Reporting]
LangSecRef=3003
LangRef=3149
Default=False
DetectOS=6.0
FileKey1=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportArchive|*.*|RECURSE
FileKey2=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportQueue|*.*|RECURSE
FileKey3=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportArchive|*.*|RECURSE
FileKey4=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportQueue|*.*|RECURSE

[*Windows Live Mail]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Windows Live Mail
Default=False
RegKey1=HKEY_CURRENT_USER\Software\Microsoft\Windows Live Mail|SearchFolderVersion

[*Windows Live Messenger]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\MSNMessenger\PerPassportSettings
Default=False
RegKey1=HKCU\Software\Microsoft\MessengerService\ListCache\.NET Messenger Service
FileKey1=%appdata%\Microsoft\MSN Messenger|*.sqm|RECURSE

[*Windows Live Messenger]
LangSecRef=3022
DetectFile=%ProgramFiles%\Windows Live\Messenger\msnmsgr.exe
Default=False
FileKey1=%USERPROFILE%\Application Data\Microsoft\MSN Messenger|*.*|RECURSE

[*Windows Live Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\MSN Apps\SearchBox
Default=False
RegKey1=HKCU\Software\Microsoft\MSN Apps\SearchBox|History
RegKey2=HKCU\Software\Microsoft\MSN Apps\MSN Toolbar|SearchStrings

[*Windows Log Files]
LangSecRef=3003
LangRef=3145
Default=False
FileKey1=%windir%\system32\wbem\Logs|*.log
FileKey2=%windir%\system32\wbem\Logs|*.lo_
FileKey3=%windir%|*.log
FileKey4=%windir%|*.bak
FileKey5=%windir%|*log.txt
FileKey6=%commonappdata%\Microsoft\Dr Watson|*.log
FileKey7=%commonappdata%\Microsoft\Dr Watson|*.dmp
FileKey8=%windir%\Debug|*.log
FileKey9=%windir%\Debug\UserMode|*.log
FileKey10=%windir%\Debug\UserMode|*.bak
FileKey11=%windir%|SchedLgU.txt
FileKey12=%windir%\security\logs|*.log
FileKey13=%windir%\security\logs|*.old

[*Windows ME]
LangSecRef=3025
DetectFile=%windir%\WINFILE.EXE
Default=False
FileKey1=%rootdir%|SCANDISK.LOG
FileKey2=%windir%|*.tmp
FileKey3=%windir%\Application Data|dw.log
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|*.*
FileKey5=%windir%\APPLOG|*.LGC
FileKey6=%windir%\Windows Update Setup Files|*.*

[*Windows Media Player]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MediaPlayer\Player
Default=False
RegKey1=HKCU\Software\Microsoft\MediaPlayer\Player\RecentFileList
RegKey2=HKCU\Software\Microsoft\MediaPlayer\Player\RecentURLList
RegKey3=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayList
RegKey4=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayListIndex
RegKey5=HKCU\Software\Microsoft\MediaPlayer\Player\Settings|SaveAsDir
RegKey6=HKCU\Software\Microsoft\MediaPlayer\AutoComplete\MediaEdit
RegKey7=HKCU\Software\Microsoft\MediaPlayer\Radio\MRUList

[*Windows Movie Maker]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MovieMaker
Default=False
FileKey1=%localappdata%\Microsoft\Movie Maker|MEDIATAB0.DAT

[*Windows Update Logs]
LangSecRef=3025
DetectFile=%windir%\SoftwareDistribution\DataStore\Logs
Default=False
FileKey1=%windir%\SoftwareDistribution\DataStore\Logs|*.*

[*Wipe Free Space]
LangSecRef=3004
LangRef=3132
WarningRef=3207
Default=False
DetectOS=5.0
SpecialKey1=N_EX_WIPEFREESPACE

[*Wordweb]
LangSecRef=3021
DetectFile=%ProgramFiles%\WordWeb\wweb32.exe
Default=False
FileKey1=%userprofile%\Application Data\WordWeb|History.txt

[*X-Cleaner (free)]
LangSecRef=3024
DetectFile=%ProgramFiles%\X-Cleaner\XCleaner_free.exe
Default=False
FileKey1=%ProgramFiles%\X-Cleaner|XCL_LOG.txt

[*X-Cleaner (full)]
LangSecRef=3024
DetectFile=%ProgramFiles%\X-Cleaner\XCleaner_full.exe
Default=False
FileKey1=%ProgramFiles%\X-Cleaner|XCL_LOG.txt

[*XFire (Logs)]
LangSecRef=3022
Detect=HKLM\Software\Xfire
Default=False
FileKey1=%userprofile%\Application Data\Xfire\chatlog|*.*|RECURSE

[*XML Spy]
LangSecRef=3021
Detect=HKCU\Software\Altova\XML Spy
Default=False
RegKey1=HKCU\Software\Altova\XML Spy\Recent File List
RegKey2=HKCU\Software\Altova\XML Spy\Recent Project List

[*XN Resource Editor]
LangSecRef=3024
Detect=HKCU\Software\Woozle\XN Resource Editor
Default=False
RegKey1=HKCU\Software\Woozle\XN Resource Editor\Recent Files

[*XviD Stats]
LangSecRef=3023
Detect=HKCU\Software\GNU\Xvid
Default=False
RegKey1=HKCU\Software\GNU\Xvid|stats

[*YPOPs]
LangSecRef=3021
DetectFile=%ProgramFiles%\YPOPs\ypops.exe
Default=False
FileKey1=%ProgramFiles%\YPOPs|ypops.log

[*Yahoo Messenger (Logs/Cache)]
LangSecRef=3022
Detect=%ProgramFiles%\Yahoo!\Messenger|ypager.log
Default=False
FileKey1=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey2=%ProgramFiles%\Yahoo!\Messenger\Profiles|*.*|RECURSE
FileKey3=%ProgramFiles%\Yahoo!\Messenger\Cache|*.*|RECURSE
FileKey4=%ProgramFiles%\Yahoo!\Messenger\IMVCache|*.*|RECURSE

[*Yahoo Messenger (Logs/Cache)]
LangSecRef=3022
Detect=HKCU\Software\Yahoo\pager
Default=False
FileKey1=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey2=%ProgramFiles%\Yahoo!\Messenger\Profiles|*.*|RECURSE
FileKey3=%ProgramFiles%\Yahoo!\Messenger\Cache|*.*|RECURSE
FileKey4=%ProgramFiles%\Yahoo!\Messenger\IMVCache|*.*|RECURSE

[*Yahoo! Toolbar]
LangSecRef=3022
Detect=HKCU\Software\Yahoo\Companion
Default=False
RegKey1=HKCU\Software\Yahoo\Companion\SearchHistory

[*ZX32 ZX Spectrum Emulator v1.03]
LangSecRef=3021
Detect=HKCU\Software\VK\zx32\1.03
Default=False
RegKey1=HKCU\Software\VK\zx32\1.03\FileMRU

[*ZipGenius]
LangSecRef=3024
Detect=HKCU\Software\M.Dev Software\ZG5
Default=False
RegKey1=HKCU\Software\M.Dev Software\ZG5\MRU Items
FileKey1=%appdata%\ZipGenius|mru.dat

[*ZipMagic]
LangSecRef=3024
Default=False
Detect=HKCU\Software\Mijenix\ZipMagic
RegKey1=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Recent
RegKey2=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Archive Manager\UnZip To
RegKey3=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\UnZip To
RegKey4=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Zip To

[*ZoneAlarm (Logs)]
LangSecRef=3022
Detect=HKLM\SOFTWARE\Zone Labs\ZoneAlarm
Default=False
FileKey1=%windir%\Internet Logs|ZALog*.*

[*eBay Toolbar]
LangSecRef=3022
DetectFile=%ProgramFiles%\eBay\eBay Toolbar2\eBayTBDaemon.exe
Default=False
RegKey1=HKCU\Software\eBay\eBayToolbar\History
RegKey2=HKCU\Software\eBay\eBayToolbar\RecentSearches
FileKey1=%ProgramFiles%\eBay\eBay Toolbar2|toolbar.log
FileKey2=%ProgramFiles%\eBay\eBay Toolbar2|eBayDaemon.log

[*eMule (File Hashes)]
LangSecRef=3022
Detect=HKCU\Software\eMule
Default=False
FileKey1=%ProgramFiles%\eMule\config|known.met
FileKey2=%ProgramFiles%\eMule\config|known2.met

[*eMule (Search History)]
LangSecRef=3022
Detect=HKCU\Software\eMule
Default=False
FileKey1=%ProgramFiles%\eMule\config|AC_SearchStrings.dat

[*iSysCleaner]
LangSecRef=3024
DetectFile=%ProgramFiles%\Utils\iSysCleaner\iSysCleaner.exe
Default=False
FileKey1=%ProgramFiles%\Utils\iSysCleaner\traces|*.*

[*mIRC]
LangSecRef=3022
Detect=HKCU\Software\mIRC\
Default=False
DectectFile=%ProgramFiles%\mirc\mIRC.exe
Filekey1=%ProgramFiles%\mirc\logs\|*.*

[*neXBC]
LangSecRef=3022
DetectFile=%ProgramFiles%\neXBC\neXBC.exe
Default=False
FileKey1=%ProgramFiles%\neXBC|messages.txt
FileKey2=%ProgramFiles%\neXBC\Logs\Hosted|*.*
FileKey3=%ProgramFiles%\neXBC\Logs\Joined|*.*

[*uTorrent]
LangSecRef=3022
DetectFile=%ProgramFiles%\uTorrent\uTorrent.exe
Default=False
FileKey1=%ProgramFiles%\uTorrent|*.dmp

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.