Jump to content
CCleaner Community Forums

Winapp2.ini additions


Recommended Posts

Modified:

[VoidTools Search Everything*]
LangSecRef=3024
DetectFile1=%ProgramFiles%\Everything
DetectFile2=%AppData%\Everything
Default=False
FileKey1=%AppData%\Everything|*.csv;*.txt;*.tmp
FileKey2=%ProgramFiles%\Everything|*.csv;*.txt;*.tmp
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Everything|*.txt;*.csv;*.tmp
ExcludeKey1=FILE|%AppData%\Everything\Filters.csv
ExcludeKey2=FILE|%ProgramFiles%\Everything\Filters.csv
ExcludeKey3=FILE|%LocalAppData%\VirtualStore\Program Files*\Everything\Filters.csv

added *.tmp to end of 3 FileKey's listed....

Link to post
Share on other sites

@Winapp2.ini Looks like the new Winapp2.ini file is uploaded, but you forgot to fix the entries mentioned in the links below.

 

http://forum.piriform.com/index.php?showtopic=32310&p=271094

 

http://forum.piriform.com/index.php?showtopic=32310&p=271093

 

I guess his new year wish didn't come true. Well, there is always next year.

Link to post
Share on other sites

New:



[CamStudio Temps*]
LangSecRef=3023
Detect=HKCU\Software\CamStudioOpenSource for Nick
Default=False
FileKey1=%Documents%\My CamStudio Temp Files|*.*

[AIMP 4*]
LangSecRef=3023
DetectFile=%ProgramFiles%\AIMP\AIMP.exe
Default=False
FileKey1=%AppData%\AIMP|*.bak


Link to post
Share on other sites

New Entry

 

[Wondershare MobileGo*]
LangSecRef=3021
Detect=HKCU\SOFTWARE\Wondershare\MobileGo
Default=False
FileKey1=%ProgramFiles%\Wondershare\MobileGo|*.log
FileKey2=%CommonAppData%\Wondershare\Dr.FoneTool\Log|*.txt
FileKey3=%CommonAppData%\Wondershare\WAF\ProductFeatures\LocalLogs|*.*|RECURSE
FileKey4=%CommonAppData%\Wondershare\WAF\ProductFeatures\RemoteLogs|*.*|RECURSE
FileKey5=%AppData%\se_tmp|*.*|REMOVESELF
FileKey6=%AppData%\Wondershare\DataEraser|*.log
FileKey7=%AppData%\Wondershare\Dr.FoneTool\log|*.log
FileKey8=%AppData%\Wondershare\DrFoneAndroidTool\log|*.log
FileKey9=%AppData%\Wondershare\MirrorGo\ImageCache\ADImage|*.*|RECURSE
FileKey10=%AppData%\Wondershare\MirrorGo|*.log
FileKey11=%AppData%\Wondershare\MobileGo|*.log
FileKey12=%AppData%\Wondershare\MobileGo\DeviceImageCache|*.*|RECURSE
FileKey13=%AppData%\Wondershare\MobileGo\iOSTemp|*.*|REMOVESELF
FileKey14=%AppData%\Wondershare\MobileGo\Logs\DeviceConnection|*.*|RECURSE
FileKey15=%AppData%\Wondershare\MobileTransTool|*.log
FileKey16=%AppData%\Wondershare\WsRoot\Logs|*.*|RECURSE

 

Please remove [Wondershare MobileGo for iOS*] entry.

Link to post
Share on other sites

New Entries

 

[3D Builder*]
DetectOS=10.0
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.3DBuilder_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.3DBuilder_*\TempState|*.*|RECURSE

[Get Started*]
DetectOS=10.0
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Getstarted_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Getstarted_*\TempState|*.*|RECURSE

Link to post
Share on other sites

Revised Entries

 

[Cortana*]
Section=3031
Default=False
Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Cortana_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Cortana_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Cortana_*\AC\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Cortana_*\TempState|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\AppCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetCache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetCookies|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\INetHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\Temp|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey19=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalCache|*.*|RECURSE
FileKey20=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\Cache|*.*|RECURSE
FileKey21=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\AppIconCache|*.*|RECURSE
FileKey22=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache|*.*|RECURSE
FileKey23=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\TempState|*.*|RECURSE

Added:
%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\AC\AppCache|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\AppIconCache|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache|*.*|RECURSE


[DRM Traces*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\DRM
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey2=%CommonAppData%\Microsoft\Windows\DRM\PreUpgrade|*.log
FileKey3=%CommonAppData%\Microsoft\Windows\DRM|*.log
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\PreUpgrade|*.log
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM|*.log

Changed entry name from [DRM Cache*] to [DRM Traces*].

Added:
%CommonAppData%\Microsoft\Windows\DRM\PreUpgrade|*.log
%CommonAppData%\Microsoft\Windows\DRM|*.log

[Windows Communications Apps*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Comms\Temp|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\AppCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\PRICache|*.*
FileKey11=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*
FileKey12=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\LiveComm\*\*\DBStore\LogFiles|edbtmp.log
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory

Added: %LocalAppData%\Comms\Temp|*.*|RECURSE

Link to post
Share on other sites

Revised Entry

 

[Action Center*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Notifications\Current

Changed the Detect.

 

Added:
%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE
HKCU\Software\Microsoft\Windows\CurrentVersion\Notifications\Current

Link to post
Share on other sites

Revised Entries

 

Moved some paths from [Log Files More*] into the entries listed below. Two paths, %WinDir%\winsxs|poqexec.log & %WinDir%\inf|*.log*, are still in this entry and they should not be removed. [Log Files More*] can be removed.

 

[Diagnostics Logs*]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\debug\WIA|*.log

[Panther*]
LangSecRef=3025
DetectFile=%Windir%\Panther
Default=False
FileKey1=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log
FileKey2=%WinDir%\Panther\FastCleanup|*.log
FileKey3=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml
FileKey4=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml
 

Link to post
Share on other sites

Revised Entries

 

Moved some paths from [Log Files More*] into the entries listed below. Two paths, %WinDir%\winsxs|poqexec.log & %WinDir%\inf|*.log*, are still in this entry and they should not be removed. [Log Files More*] can be removed.

 is this a mistake?

Link to post
Share on other sites

Revised Entries

 

Moved some paths from [Log Files More*] into the entries listed below. Two paths, %WinDir%\winsxs|poqexec.log & %WinDir%\inf|*.log*, are still in this entry and they should not be removed. [Log Files More*] can be removed.

 

What about FileKey5=%WinDir%|SIGVERIF.TXT?

Link to post
Share on other sites
  • Moderators
Perhaps he means the Winapp2.ini website.

Works for me

Link to post
Share on other sites
  • Moderators

I am on the email list for a few groups on Piriform - there has been a lot of S.P.A.M. the last few days.  Maybe he means he blocked the senders today.....??

There's been a lot of spam around everywhere the last week or so.

 

I'll ask Piriform to check things.

Link to post
Share on other sites

New Entries

[Accounts Control*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.AccountsControl_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.AccountsControl_*\TempState|*.*|RECURSE

[Comms Phone*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.CommsPhone_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.CommsPhone_*\TempState|*.*|RECURSE

[Connectivity Store*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ConnectivityStore_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\TempState|*.*|RECURSE

[Contact Support*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Windows.ContactSupport_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0|*.log
FileKey6=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32|*.log
FileKey9=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Temp|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalCache|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalState\Cache|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\Windows.ContactSupport_*\TempState|*.*|RECURSE

[Lock App*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.LockApp_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.LockApp_*\TempState|*.*|RECURSE

[Maps*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsMaps_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\TempState|*.*|RECURSE

[People*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.People_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.People_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.People_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.People_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.People_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.People_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.People_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.People_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.People_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.People_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.People_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.People_*\TempState|*.*|RECURSE

[Phone*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsPhone_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\TempState|*.*|RECURSE

[QuizUp*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\QuizUp.QuizUp_n36z36qeaxk8a
FileKey1=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey6=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0_32|*.log|RECURSE
FileKey8=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Temp|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalCache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalState\Cache|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\QuizUp.QuizUp_*\TempState|*.*|RECURSE

[scan*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsScan_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsScan_*\TempState|*.*|RECURSE

[shell Experience Host*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\TempState|*.*|RECURSE

[sound Recorder*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\TempState|*.*|RECURSE

[sway*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.Sway_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Office.Sway_*\TempState|*.*|RECURSE

[Windows Feedback*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedback_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0|*.log
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0_32|*.log
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Temp|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\LocalCache|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\LocalState\Cache|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\TempState|*.*|RECURSE

Link to post
Share on other sites

Revised Entries

 

[bing Finance More*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingFinance_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingFinance_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingFinance_*\TempState|*.*|RECURSE

Added:
%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\TokenBroker\Cache|*.*|RECURSE

[bing News More*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingNews_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\PRICache|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingNews_*\LocalState\navigationHistory|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe\SearchHistory

Added:
%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.BingNews_*\AC\TokenBroker\Cache|*.*|RECURSE

[bing Sports More*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingSports_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingSports_*\LocalState\navigationHistory|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingSports_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe\SearchHistory

Added:
%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.BingSports_*\AC\TokenBroker\Cache|*.*|RECURSE

[bing Weather*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingWeather_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log
FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp
FileKey13=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory

Added |RECURSE to some lines.

[Camera*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsCamera_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Camera_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Camera_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.Camera_*\AC\PRICache|*.*
FileKey9=%LocalAppData%\Packages\Microsoft.Camera_*\AC\Temp|*.*
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\AppCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetCache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetCookies|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\INetHistory|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\Temp|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalCache|*.*|RECURSE
FileKey19=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\AppData|*.*|RECURSE
FileKey20=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\Cache|*.*|RECURSE
FileKey21=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe\SearchHistory

Added: Detect2
Added: FileKey 10 thru FileKey21 for Windows 10

[Cloud Experience Host*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\TempState|*.*|RECURSE

Added:
%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\AppCache|*.*|RECURSE

[OneNote*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local|msodata*.dat
FileKey9=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\OTele|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\office15client.microsoft.com|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0\OneNoteOfflineCache_Files|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0\OneNotePagePreviewCache_Files|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0|*.onecache
FileKey15=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe\SearchHistory

Added:
%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\TokenBroker\Cache|*.*|RECURSE
%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com|*.*|RECURSE

[Xbox Identity Provider*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxIdentityProvider_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0|*.log
FileKey5=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32|*.log
FileKey8=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32\NativeImages\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalCache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalState\Cache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\TempState|*.*|RECURSE

Removed |RECURSE from some lines.

 

[XboxApp*]
DetectOS=10.0|
Section=3031
Default=False
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxApp_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log;*.log*
FileKey10=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log
FileKey12=%LocalAppData%\Packages\Microsoft.XboxApp_*\TempState|*.*|RECURSE

Added:
%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log;*.log.
%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log

[Zune Music*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\PRICache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageCache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\PlayReady|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\SearchHistory

Added:
%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\TokenBroker\Cache|*.*|RECURSE

[Zune Video*]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\PRICache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageCache|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\PlayReady|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\TempState|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Database\anonymous|*.log
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe\SearchHistory

Added:
%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\TokenBroker\Cache|*.*|RECURSE

Link to post
Share on other sites

Revised Entry

 

[Plex Media Server*]
LangSecRef=3023
Detect=HKCU\Software\Plex, Inc.\Plex Media Server
Default=False
FileKey1=%ProgramFiles%\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey2=%LocalAppData%\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey3=%LocalAppData%\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey4=%LocalAppData%\Plex Media Server\Logs|*.*|RECURSE
FileKey5=%LocalAppData%\Plex Media Server\Updates|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Logs|*.*|RECURSE
FileKey10=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Updates|*.*|RECURSE

Added:
%LocalAppData%\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
%LocalAppData%\Plex Media Server\Updates|*.*|RECURSE
%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Updates|*.*|RECURSE

Link to post
Share on other sites

New Entry

Windows Disk Cleanup removes these files.

 

[Delivery Optimization Files*]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
RegKey1=HKLM\Software\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Jobs
FileKey1=%WinDir%\Logs\dosvc|*.*|RECURSE
FileKey2=%WinDir%\SoftwareDistribution\DeliveryOptimization|*.*|RECURSE

Link to post
Share on other sites

Revised Entry

 

[Windows Defender More*]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows Defender
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows Defender\Definition Updates\Backup|*.*|RECURSE
FileKey2=%CommonAppData%\Microsoft\Windows Defender\LocalCopy|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\Windows Defender\Network Inspection System\Support|*.txt
FileKey4=%CommonAppData%\Microsoft\Windows Defender\Scans|*.bin;*.bin*
FileKey5=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Service|*.log
FileKey6=%CommonAppData%\Microsoft\Windows Defender\Scans\Scans\History\CacheManager|*.*|RECURSE
FileKey7=%CommonAppData%\Microsoft\Windows Defender\Support|*.*|RECURSE

Added:
%CommonAppData%\Microsoft\Windows Defender\LocalCopy|*.*|RECURSE

Windows Disk Cleanup removes files from this location.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...