cbaumer0628 Posted January 8, 2021 Share Posted January 8, 2021 9 hours ago, SMalik said: Revised Entry Changed: %ProgramFiles%\OpenVPN\Log|*.* to %ProgramFiles%\OpenVPN\Log|*.log There is README.txt file here as well. Added: %UsersProfile%\OpenVPN\log|*.*|RECURSE [OpenVPN *] LangSecRef=3024 DetectFile=%ProgramFiles%\OpenVPN FileKey1=%ProgramFiles%\OpenVPN\Log|*.log FileKey2=%UsersProfile%\OpenVPN\log|*.*|RECURSE @SMalikI believe it's %UserProfile% and NOT %UsersProfile% !! Link to comment Share on other sites More sharing options...
SMalik Posted January 8, 2021 Share Posted January 8, 2021 3 hours ago, cbaumer0628 said: @SMalikI believe it's %UserProfile% and NOT %UsersProfile% !! That is correct. I am sorry. Link to comment Share on other sites More sharing options...
SMalik Posted January 9, 2021 Share Posted January 9, 2021 15 hours ago, SMalik said: That is correct. I am sorry. Revised Entry Changed DetectFile to Detect [OpenVPN *] LangSecRef=3024 Detect=HKLM\SOFTWARE\OpenVPN FileKey1=%ProgramFiles%\OpenVPN\Log|*.log FileKey2=%UserProfile%\OpenVPN\log|*.*|RECURSE Link to comment Share on other sites More sharing options...
APMichael Posted January 11, 2021 Share Posted January 11, 2021 Thanks for the revised entry. Winapp2.ini updates:https://github.com/MoscaDotTo/Winapp2/commit/6fd95e1cfbfe63615ec29b5db529c3a3133cf7cchttps://github.com/MoscaDotTo/Winapp2/commit/7b76252d9f063b2accbfb1fa3d1365873d2f38c5 Winapp3.ini update:https://github.com/MoscaDotTo/Winapp2/commit/3239ff7754e910b645b20f1e24eaa075cc22965b Link to comment Share on other sites More sharing options...
SMalik Posted January 11, 2021 Share Posted January 11, 2021 Revised Entry [Snagit *] LangSecRef=3021 Detect=HKCU\Software\TechSmith\Snagit Warning=This will delete the backups of the captures. FileKey1=%CommonAppData%\TechSmith\Uploader|*.log FileKey2=%Documents%|SnagitDebug.log FileKey3=%LocalAppData%\TechSmith\Logs|*.log FileKey4=%LocalAppData%\TechSmith\Snagit|Tray.bin FileKey5=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE FileKey6=%LocalAppData%\TechSmith\Snagit\DataStore|*.SNAGundo FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico FileKey8=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico FileKey9=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE FileKey10=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log;*.logtmp RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount RegKey5=HKCU\Software\TechSmith\Snagit\11|OutputDirLastUsed RegKey6=HKCU\Software\TechSmith\Snagit\11|VidOutputDirLastUsed RegKey7=HKCU\Software\TechSmith\Snagit\11\SnagItEditor\Tray|Thumbnailsize RegKey8=HKCU\Software\TechSmith\Snagit\12|CaptureCount RegKey9=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount RegKey10=HKCU\Software\TechSmith\Snagit\12|OutputDirLastUsed RegKey11=HKCU\Software\TechSmith\Snagit\12|VidOutputDirLastUsed RegKey12=HKCU\Software\TechSmith\Snagit\12\SnagItEditor\Tray|Thumbnailsize RegKey13=HKCU\Software\TechSmith\Snagit\13|CaptureCount RegKey14=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount RegKey15=HKCU\Software\TechSmith\Snagit\13|OutputDirLastUsed RegKey16=HKCU\Software\TechSmith\Snagit\13|VidOutputDirLastUsed RegKey17=HKCU\Software\TechSmith\Snagit\13\Recent Captures RegKey18=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List RegKey19=HKCU\Software\TechSmith\Snagit\13\SnagItEditor\Tray|Thumbnailsize RegKey20=HKCU\Software\TechSmith\Snagit\18|CaptureCount RegKey21=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount RegKey22=HKCU\Software\TechSmith\Snagit\18|OutputDirLastUsed RegKey23=HKCU\Software\TechSmith\Snagit\18|VidOutputDirLastUsed RegKey24=HKCU\Software\TechSmith\Snagit\18\Recent Captures RegKey25=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List RegKey26=HKCU\Software\TechSmith\Snagit\18\SnagItEditor\Tray|Thumbnailsize RegKey27=HKCU\Software\TechSmith\Snagit\19|CaptureCount RegKey28=HKCU\Software\TechSmith\Snagit\19|CaptureOpenCount RegKey29=HKCU\Software\TechSmith\Snagit\19|OutputDirLastUsed RegKey30=HKCU\Software\TechSmith\Snagit\19|VidOutputDirLastUsed RegKey31=HKCU\Software\TechSmith\Snagit\19\Recent Captures RegKey32=HKCU\Software\TechSmith\Snagit\19\SnagitEditor\Recent File List RegKey33=HKCU\Software\TechSmith\Snagit\19\SnagItEditor\Tray|Thumbnailsize RegKey34=HKCU\Software\TechSmith\Snagit\20|CaptureCount RegKey35=HKCU\Software\TechSmith\Snagit\20|CaptureOpenCount RegKey36=HKCU\Software\TechSmith\Snagit\20|OutputDirLastUsed RegKey37=HKCU\Software\TechSmith\Snagit\20|VidOutputDirLastUsed RegKey38=HKCU\Software\TechSmith\Snagit\20\Recent Captures RegKey39=HKCU\Software\TechSmith\Snagit\20\SnagitEditor\Recent File List RegKey40=HKCU\Software\TechSmith\Snagit\20\SnagItEditor\Tray|Thumbnailsize RegKey41=HKCU\Software\TechSmith\Snagit\21|CaptureCount RegKey42=HKCU\Software\TechSmith\Snagit\21|CaptureOpenCount RegKey43=HKCU\Software\TechSmith\Snagit\21|OutputDirLastUsed RegKey44=HKCU\Software\TechSmith\Snagit\21|VidOutputDirLastUsed RegKey45=HKCU\Software\TechSmith\Snagit\21\Recent Captures RegKey46=HKCU\Software\TechSmith\Snagit\21\SnagitEditor\Recent File List RegKey47=HKCU\Software\TechSmith\Snagit\21\SnagItEditor\Tray|Thumbnailsize RegKey48=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder Removed: %AppData%\TechSmith\Snagit *\Identity|*.* Sign in file %LocalAppData%\TechSmith\Snagit\DataStore|*.SNAG;*.SNAGundo;*.MP4 *.SNAG;*.MP4 are Snagit Editor Library files Added: Support for Snagit 2021 Link to comment Share on other sites More sharing options...
SMalik Posted January 12, 2021 Share Posted January 12, 2021 Revised Entry [Snagit *] LangSecRef=3021 Detect=HKCU\Software\TechSmith\Snagit Warning=This will delete the backups of the captures. FileKey1=%CommonAppData%\TechSmith\Uploader|*.log FileKey2=%Documents%|SnagitDebug.log FileKey3=%LocalAppData%\TechSmith\Logs|*.log FileKey4=%LocalAppData%\TechSmith\Snagit|Tray.bin FileKey5=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE FileKey6=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico FileKey8=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE FileKey9=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log;*.logtmp RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount RegKey5=HKCU\Software\TechSmith\Snagit\11|OutputDirLastUsed RegKey6=HKCU\Software\TechSmith\Snagit\11|VidOutputDirLastUsed RegKey7=HKCU\Software\TechSmith\Snagit\11\SnagItEditor\Tray|Thumbnailsize RegKey8=HKCU\Software\TechSmith\Snagit\12|CaptureCount RegKey9=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount RegKey10=HKCU\Software\TechSmith\Snagit\12|OutputDirLastUsed RegKey11=HKCU\Software\TechSmith\Snagit\12|VidOutputDirLastUsed RegKey12=HKCU\Software\TechSmith\Snagit\12\SnagItEditor\Tray|Thumbnailsize RegKey13=HKCU\Software\TechSmith\Snagit\13|CaptureCount RegKey14=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount RegKey15=HKCU\Software\TechSmith\Snagit\13|OutputDirLastUsed RegKey16=HKCU\Software\TechSmith\Snagit\13|VidOutputDirLastUsed RegKey17=HKCU\Software\TechSmith\Snagit\13\Recent Captures RegKey18=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List RegKey19=HKCU\Software\TechSmith\Snagit\13\SnagItEditor\Tray|Thumbnailsize RegKey20=HKCU\Software\TechSmith\Snagit\18|CaptureCount RegKey21=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount RegKey22=HKCU\Software\TechSmith\Snagit\18|OutputDirLastUsed RegKey23=HKCU\Software\TechSmith\Snagit\18|VidOutputDirLastUsed RegKey24=HKCU\Software\TechSmith\Snagit\18\Recent Captures RegKey25=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List RegKey26=HKCU\Software\TechSmith\Snagit\18\SnagItEditor\Tray|Thumbnailsize RegKey27=HKCU\Software\TechSmith\Snagit\19|CaptureCount RegKey28=HKCU\Software\TechSmith\Snagit\19|CaptureOpenCount RegKey29=HKCU\Software\TechSmith\Snagit\19|OutputDirLastUsed RegKey30=HKCU\Software\TechSmith\Snagit\19|VidOutputDirLastUsed RegKey31=HKCU\Software\TechSmith\Snagit\19\Recent Captures RegKey32=HKCU\Software\TechSmith\Snagit\19\SnagitEditor\Recent File List RegKey33=HKCU\Software\TechSmith\Snagit\19\SnagItEditor\Tray|Thumbnailsize RegKey34=HKCU\Software\TechSmith\Snagit\20|CaptureCount RegKey35=HKCU\Software\TechSmith\Snagit\20|CaptureOpenCount RegKey36=HKCU\Software\TechSmith\Snagit\20|OutputDirLastUsed RegKey37=HKCU\Software\TechSmith\Snagit\20|VidOutputDirLastUsed RegKey38=HKCU\Software\TechSmith\Snagit\20\Recent Captures RegKey39=HKCU\Software\TechSmith\Snagit\20\SnagitEditor\Recent File List RegKey40=HKCU\Software\TechSmith\Snagit\20\SnagItEditor\Tray|Thumbnailsize RegKey41=HKCU\Software\TechSmith\Snagit\21|CaptureCount RegKey42=HKCU\Software\TechSmith\Snagit\21|CaptureOpenCount RegKey43=HKCU\Software\TechSmith\Snagit\21|OutputDirLastUsed RegKey44=HKCU\Software\TechSmith\Snagit\21|VidOutputDirLastUsed RegKey45=HKCU\Software\TechSmith\Snagit\21\Recent Captures RegKey46=HKCU\Software\TechSmith\Snagit\21\SnagitEditor\Recent File List RegKey47=HKCU\Software\TechSmith\Snagit\21\SnagItEditor\Tray|Thumbnailsize RegKey48=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder Removed: %AppData%\TechSmith\Snagit *\Identity|*.* Sign in file %LocalAppData%\TechSmith\Snagit\DataStore|*.SNAG;*.SNAGundo;*.MP4 *.SNAG;*.MP4 are Snagit Editor Library files *.SNAGundo are unsaved fileshttps://support.techsmith.com/hc/en-us/community/posts/360071706912-Can-I-delete-files-on-my-pc-with-the-Snagit-file-type-snagundo-without-losing-any-data- Added: Support for Snagit 2021 Link to comment Share on other sites More sharing options...
SMalik Posted January 15, 2021 Share Posted January 15, 2021 Revised Entry [Windows Logs *] LangSecRef=3025 Detect=HKLM\Software\Microsoft\Windows FileKey1=%CommonAppData%\Microsoft\Diagnosis\DownloadedSettings|*.json.bk FileKey2=%CommonAppData%\Microsoft\Network\Downloader|*.*|RECURSE FileKey3=%CommonAppData%\Microsoft\WDF|*.*|RECURSE FileKey4=%CommonAppData%\Microsoft\Windows Security Health\Logs|*.*|RECURSE FileKey5=%CommonAppData%\USOShared\Logs|*.*|RECURSE FileKey6=%LocalAppData%\ConnectedDevicesPlatform|*.log FileKey7=%LocalAppData%\Diagnostics|*.*|RECURSE FileKey8=%ProgramFiles%\UNP\*Logs|*.* FileKey9=%SystemDrive%\PerfLogs\System\Diagnostics|*.*|RECURSE FileKey10=%SystemDrive%\PerfLogs\System\Performance|*.*|RECURSE FileKey11=%WinDir%\AppCompat\Programs|*.txt;*.xml FileKey12=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml FileKey13=%WinDir%\debug\WIA|*.log FileKey14=%WinDir%\inf|*.log* FileKey15=%WinDir%\Logs\CBS|*.cab FileKey16=%WinDir%\Logs\dosvc|*.*|RECURSE FileKey17=%WinDir%\Logs\NetSetup|*.*|RECURSE FileKey18=%WinDir%\Logs\SIH|*.*|RECURSE FileKey19=%WinDir%\Logs\WindowsBackup|*.etl FileKey20=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log FileKey21=%WinDir%\Panther\FastCleanup|*.log FileKey22=%WinDir%\Panther\Rollback|*.txt FileKey23=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml FileKey24=%WinDir%\repair|setup.log FileKey25=%WinDir%\security\logs|*.*|RECURSE FileKey26=%WinDir%\System32\CatRoot|*.tmp FileKey27=%WinDir%\System32\catroot2|*.chk;*.log;*.jrs;*.txt FileKey28=%WinDir%\System32\LogFiles\HTTPERR|*.log FileKey29=%WinDir%\System32\LogFiles\Scm|*.*|RECURSE FileKey30=%WinDir%\System32\LogFiles\setupcln|*.*|RECURSE FileKey31=%WinDir%\System32\LogFiles\Srt|*.*|RECURSE FileKey32=%WinDir%\System32\LogFiles\WMI|*.*|RECURSE FileKey33=%WinDir%\System32\SleepStudy|*.etl FileKey34=%WinDir%\System32\SleepStudy\ScreenOn|*.etl FileKey35=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml;*.log FileKey36=%WinDir%\System32\WDI\*|snapshot.etl|REMOVESELF FileKey37=%WinDir%\System32\WDI\LogFiles\StartupInfo|*.*|RECURSE RegKey1=HKLM\Software\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications RegKey2=HKLM\Software\Microsoft\Tracing RegKey3=HKLM\Software\Wow6432Node\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications RegKey4=HKLM\Software\Wow6432Node\Microsoft\Tracing Added: %CommonAppData%\Microsoft\Diagnosis\DownloadedSettings|*.json.bk %CommonAppData%\Microsoft\WDF|*.*|RECURSE %WinDir%\System32\CatRoot|*.tmp Link to comment Share on other sites More sharing options...
APMichael Posted January 18, 2021 Share Posted January 18, 2021 Thanks for the revised entries. Winapp2.ini update:https://github.com/MoscaDotTo/Winapp2/commit/dfddbb2f2d46a5e641998d031833ae37b7d0749d Winapp3.ini update:https://github.com/MoscaDotTo/Winapp2/commit/1dd20671c361d9b3b3e203a22ad404a3b1b8a35b Link to comment Share on other sites More sharing options...
siliconman01 Posted January 20, 2021 Share Posted January 20, 2021 Modified entry: [Windows Error Reporting *] Added FileKey6. Some programs such as Malwarebytes sneak a subfolder into folder Crashdumps to store the *.dmp file. [Windows Error Reporting *] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows\Windows Error Reporting FileKey1=%LocalAppData%\PCHealth\ErrorRep\QSignoff|*.* FileKey2=%WinDir%\pchealth\ERRORREP|*.*|RECURSE FileKey3=%WinDir%\pchealth\helpctr\DataColl|*.xml FileKey4=%WinDir%\pchealth\helpctr\OfflineCache|*.*|RECURSE FileKey5=%WinDir%\System32\config\systemprofile\AppData\Local\CrashDumps|*.dmp FileKey6=%WinDir%\System32\config\systemprofile\AppData\Local\CrashDumps\*|*.dmp FileKey7=%WinDir%\System32\config\systemprofile\Local Settings\Application Data\CrashDumps|*.dmp FileKey8=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\CrashDumps|*.dmp FileKey9=%WinDir%\SysWOW64\config\systemprofile\Local Settings\Application Data\CrashDumps|*.dmp RegKey1=HKLM\Software\Microsoft\Windows\Windows Error Reporting\FullLiveKernelReports|LastFullLiveReport RegKey2=HKLM\Software\Microsoft\Windows\Windows Error Reporting\FullLiveKernelReports\win32k.sys RegKey3=HKLM\Software\Microsoft\Windows\Windows Error Reporting\LiveKernelReports\win32k.sys RegKey4=HKLM\Software\Microsoft\Windows\Windows Error Reporting\LocalDumps RegKey5=HKU\.DEFAULT\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation Modified entry: [Snagit *] Added FileKey4 [Snagit *] LangSecRef=3021 Detect=HKCU\Software\TechSmith\Snagit FileKey1=%CommonAppData%\TechSmith\Uploader|*.log FileKey2=%Documents%|SnagitDebug.log FileKey3=%LocalAppData%\TechSmith\Logs|*.log FileKey4=%LocalAppData%\TechSmith\Snagit\*\NativeCrashReporting\Reports|*.dmp|RECURSE FileKey5=%LocalAppData%\TechSmith\Snagit|Tray.bin FileKey6=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico FileKey8=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico FileKey9=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE FileKey10=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log;*.logtmp RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount RegKey5=HKCU\Software\TechSmith\Snagit\11|OutputDirLastUsed RegKey6=HKCU\Software\TechSmith\Snagit\11|VidOutputDirLastUsed RegKey7=HKCU\Software\TechSmith\Snagit\11\SnagItEditor\Tray|Thumbnailsize RegKey8=HKCU\Software\TechSmith\Snagit\12|CaptureCount RegKey9=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount RegKey10=HKCU\Software\TechSmith\Snagit\12|OutputDirLastUsed RegKey11=HKCU\Software\TechSmith\Snagit\12|VidOutputDirLastUsed RegKey12=HKCU\Software\TechSmith\Snagit\12\SnagItEditor\Tray|Thumbnailsize RegKey13=HKCU\Software\TechSmith\Snagit\13|CaptureCount RegKey14=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount RegKey15=HKCU\Software\TechSmith\Snagit\13|OutputDirLastUsed RegKey16=HKCU\Software\TechSmith\Snagit\13|VidOutputDirLastUsed RegKey17=HKCU\Software\TechSmith\Snagit\13\Recent Captures RegKey18=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List RegKey19=HKCU\Software\TechSmith\Snagit\13\SnagItEditor\Tray|Thumbnailsize RegKey20=HKCU\Software\TechSmith\Snagit\18|CaptureCount RegKey21=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount RegKey22=HKCU\Software\TechSmith\Snagit\18|OutputDirLastUsed RegKey23=HKCU\Software\TechSmith\Snagit\18|VidOutputDirLastUsed RegKey24=HKCU\Software\TechSmith\Snagit\18\Recent Captures RegKey25=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List RegKey26=HKCU\Software\TechSmith\Snagit\18\SnagItEditor\Tray|Thumbnailsize RegKey27=HKCU\Software\TechSmith\Snagit\19|CaptureCount RegKey28=HKCU\Software\TechSmith\Snagit\19|CaptureOpenCount RegKey29=HKCU\Software\TechSmith\Snagit\19|OutputDirLastUsed RegKey30=HKCU\Software\TechSmith\Snagit\19|VidOutputDirLastUsed RegKey31=HKCU\Software\TechSmith\Snagit\19\Recent Captures RegKey32=HKCU\Software\TechSmith\Snagit\19\SnagitEditor\Recent File List RegKey33=HKCU\Software\TechSmith\Snagit\19\SnagItEditor\Tray|Thumbnailsize RegKey34=HKCU\Software\TechSmith\Snagit\20|CaptureCount RegKey35=HKCU\Software\TechSmith\Snagit\20|CaptureOpenCount RegKey36=HKCU\Software\TechSmith\Snagit\20|OutputDirLastUsed RegKey37=HKCU\Software\TechSmith\Snagit\20|VidOutputDirLastUsed RegKey38=HKCU\Software\TechSmith\Snagit\20\Recent Captures RegKey39=HKCU\Software\TechSmith\Snagit\20\SnagitEditor\Recent File List RegKey40=HKCU\Software\TechSmith\Snagit\20\SnagItEditor\Tray|Thumbnailsize RegKey41=HKCU\Software\TechSmith\Snagit\21|CaptureCount RegKey42=HKCU\Software\TechSmith\Snagit\21|CaptureOpenCount RegKey43=HKCU\Software\TechSmith\Snagit\21|OutputDirLastUsed RegKey44=HKCU\Software\TechSmith\Snagit\21|VidOutputDirLastUsed RegKey45=HKCU\Software\TechSmith\Snagit\21\Recent Captures RegKey46=HKCU\Software\TechSmith\Snagit\21\SnagitEditor\Recent File List RegKey47=HKCU\Software\TechSmith\Snagit\21\SnagItEditor\Tray|Thumbnailsize RegKey48=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder Windows 10 x64 Pro on ASUS Maximus VIII Extreme motherboard, i7-6700k CPU,H220 X2 Liquid Cooler, 64 gbyte RipJaws DDR4 3200 RAM, Samsung 970 Pro NVMe M.2 500 gbyte SSD + Samsung 850 Pro 512 gbyte SSD, EVGA RTX 3060 Titan graphics card (Home Built System); Windows 11x64 Pro on 512 gigabyte Dell XPS 15 2-in-1 Laptop/tablet and Dell XPS 8940 PC. ASUS RT-AC88U router, 14 tbyte WD My Cloud PR2100 NAS Server, 200 Mbps cable Internet, MS Edge Chromium, MS Office 2021 (Local), Casper 11, DisplayFusion (3 Flat Panel Displays per system): Bitdefender Internet Security 2022, Malwarebytes 4, Quicken, Weather Watcher Live, ThumbsPlus 10, Sticky Password 8, WD Smartware, CyberLink PowerDVD22, MSI AfterBurner, Rainmeter, Windows Sidebar, and many more. Link to comment Share on other sites More sharing options...
APMichael Posted January 25, 2021 Share Posted January 25, 2021 Thanks for the modified entries. Winapp2.ini updates:https://github.com/MoscaDotTo/Winapp2/commit/58f5a7d7667592e203beb546d976c4661d48b4bbhttps://github.com/MoscaDotTo/Winapp2/commit/a42e6500c02f4dc04c938bc1cd295d4c367fa56f Winapp3.ini update:https://github.com/MoscaDotTo/Winapp2/commit/6f7bb028b33484f67efee674a5b2bade00758f9e Link to comment Share on other sites More sharing options...
SMalik Posted January 29, 2021 Share Posted January 29, 2021 New Entry https://superuser.com/questions/1538665/what-does-the-windows-folder-tasks-migrated-do [Tasks Migrated *] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows FileKey1=%WinDir%\System32\Tasks_Migrated|*.*|REMOVESELF Link to comment Share on other sites More sharing options...
APMichael Posted February 1, 2021 Share Posted February 1, 2021 Thanks for the new entry. Winapp2.ini update:https://github.com/MoscaDotTo/Winapp2/commit/a9f00de63c06f14720e2770f24438598af55ef3c Link to comment Share on other sites More sharing options...
SMalik Posted February 3, 2021 Share Posted February 3, 2021 Cortana app package name has changed. The new package is Microsoft.Windows.Search_cw5n1h2txyewy We already have an entry for the new package as [Windows Search *] Please remove [Cortana *], [Cortana Show Me *] entries and name current [Windows Search *] to [Cortana *] Link to comment Share on other sites More sharing options...
APMichael Posted February 3, 2021 Share Posted February 3, 2021 7 hours ago, SMalik said: Cortana app package name has changed. The new package is Microsoft.Windows.Search_cw5n1h2txyewy ... The new "Cortana" app is just a voice-controlled user interface extension for "Windows Search". The new "Cortana" app can now also be removed quite easily and this removes the package "Microsoft.549981C3F5F10_*" and not the package "Microsoft.Windows.Search_*", which is still used for many other search tasks. By the way, the new "Cortana" app has been supported by the existing [Cortana *] entry for months now. In addition, many people still use Windows 8.1 or older Windows 10 versions, so we can't simply remove the existing entries either. So, in summary, everything is correct as it is and there is no reason to change anything. https://www.windowscentral.com/how-uninstall-cortana-windows-10-may-2020-update Link to comment Share on other sites More sharing options...
SMalik Posted February 3, 2021 Share Posted February 3, 2021 I have Windows 10 20H2 (OS Build 19042.782). I just uninstalled Cortana app and it removed Microsoft.Windows.Search_cw5n1h2txyewy package. I have another privacy cleaner program on my system and Microsoft.Windows.Search_cw5n1h2txyewy files are under Cortana entry. Link to comment Share on other sites More sharing options...
SMalik Posted February 5, 2021 Share Posted February 5, 2021 (edited) Revised Entry Added: FileKey2 RegKey1 [3D Viewer *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\LocalCache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\LocalState\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\TempState|*.*|RECURSE RegKey1=HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\PersistedStorageItemTable\MostRecentlyUsed Edited February 5, 2021 by Nergal replaced at member request Link to comment Share on other sites More sharing options...
SMalik Posted February 5, 2021 Share Posted February 5, 2021 Revised Entry Added: %LocalAppData%\Packages\Microsoft.549981C3F5F10_*\AC\TokenBroker\Cache|*.*|RECURSE [Cortana *] LangSecRef=3031 Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.549981C3F5F10_8wekyb3d8bbwe Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Cortana_8wekyb3d8bbwe Detect3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Cortana_cw5n1h2txyewy Detect4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Search_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\Temp|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.*Cortana_*\TempState|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\AC\INet*|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\AC\Temp|*.*|RECURSE FileKey11=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey12=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\LocalCache|*.*|RECURSE FileKey13=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\TempState|*.*|RECURSE FileKey14=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalCache|*.*|RECURSE FileKey15=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\AppIconCache|*.*|RECURSE FileKey16=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache|*.txt ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache\|SettingsCache.txt Link to comment Share on other sites More sharing options...
SMalik Posted February 5, 2021 Share Posted February 5, 2021 Revised Entry Changed the entry name from [Mail and Calendar *] to [Calendar, Mail & People *] Added: FileKey10 [Calendar, Mail & People *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe FileKey1=%LocalAppData%\Comms\Unistore\data|AggregateCache.uca FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*|RECURSE FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalCache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\AppData\Local\Office\*\WebServiceCache\AllUsers\officeclient.microsoft.com|*.*|RECURSE FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState|*.etl;*.log FileKey11=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory Link to comment Share on other sites More sharing options...
SMalik Posted February 5, 2021 Share Posted February 5, 2021 Revised Entry Added: %LocalAppData%\Packages\Microsoft.Windows.Search_*\LocalState\DeviceSearchCache|*.*|RECURSE [Windows Search *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Search_cw5n1h2txyewy FileKey1=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\AppCache|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\INet*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\Temp|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Search_*\LocalCache|*.*|RECURSE FileKey8=%LocalAppData%\Packages\Microsoft.Windows.Search_*\LocalState\AppIconCache|*.*|RECURSE FileKey9=%LocalAppData%\Packages\Microsoft.Windows.Search_*\LocalState\DeviceSearchCache|*.*|RECURSE FileKey10=%LocalAppData%\Packages\Microsoft.Windows.Search_*\TempState|*.*|RECURSE Link to comment Share on other sites More sharing options...
SMalik Posted February 5, 2021 Share Posted February 5, 2021 New Entry [Microsoft To DO *] DetectOS=10.0| LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Todos_8wekyb3d8bbwe FileKey1=%LocalAppData%\Packages\Microsoft.Todos_*\AC\INet*|*.*|RECURSE FileKey2=%LocalAppData%\Packages\Microsoft.Todos_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE FileKey3=%LocalAppData%\Packages\Microsoft.Todos_*\AC\Temp|*.*|RECURSE FileKey4=%LocalAppData%\Packages\Microsoft.Todos_*\LocalCache|*.*|RECURSE FileKey5=%LocalAppData%\Packages\Microsoft.Todos_*\AC\TokenBroker\Cache|*.*|RECURSE FileKey6=%LocalAppData%\Packages\Microsoft.Todos_*\TempState|*.*|RECURSE Link to comment Share on other sites More sharing options...
APMichael Posted February 5, 2021 Share Posted February 5, 2021 Thank you for the revised and new entries. 13 hours ago, SMalik said: ... Changed the entry name from [Mail and Calendar *] to [Calendar, Mail & People *] ... However, the "People" app is not part of the "Mail and Calendar" app. The "People" app has always had its own package "Microsoft.People_*" and its own entry [People *]. https://www.microsoft.com/en-us/p/microsoft-people/9nblggh10pg8https://www.microsoft.com/en-us/p/mail-and-calendar/9wzdncrfhvqm The package of an app can be found out very quickly: just drag and drop the icon to the desktop, right click and choose properties. A search using the package name also works. Just execute these links via "Run": ms-windows-store://pdp/?PFN=Microsoft.People_8wekyb3d8bbwe ms-windows-store://pdp/?PFN=microsoft.windowscommunicationsapps_8wekyb3d8bbwe ms-windows-store://pdp/?PFN=Microsoft.549981C3F5F10_8wekyb3d8bbwe Note: This search only works for apps that are available in the Microsoft Store. (System apps will therefore not be found). Link to comment Share on other sites More sharing options...
SMalik Posted February 5, 2021 Share Posted February 5, 2021 8 hours ago, APMichael said: Thank you for the revised and new entries. However, the "People" app is not part of the "Mail and Calendar" app. The "People" app has always had its own package "Microsoft.People_*" and its own entry [People *]. https://www.microsoft.com/en-us/p/microsoft-people/9nblggh10pg8https://www.microsoft.com/en-us/p/mail-and-calendar/9wzdncrfhvqm The package of an app can be found out very quickly: just drag and drop the icon to the desktop, right click and choose properties. A search using the package name also works. Just execute these links via "Run": ms-windows-store://pdp/?PFN=Microsoft.People_8wekyb3d8bbwe ms-windows-store://pdp/?PFN=microsoft.windowscommunicationsapps_8wekyb3d8bbwe ms-windows-store://pdp/?PFN=Microsoft.549981C3F5F10_8wekyb3d8bbwe Note: This search only works for apps that are available in the Microsoft Store. (System apps will therefore not be found). That is fine but, I think Windows Search entry should be merged into Cortana entry. Link to comment Share on other sites More sharing options...
SMalik Posted February 6, 2021 Share Posted February 6, 2021 3 hours ago, SMalik said: That is fine but, I think Windows Search entry should be merged into Cortana entry. It is pretty confusing. I think we should leave Windows Search entry as is. https://www.groovypost.com/howto/disable-cortana-replace-windows-search/#:~:text=Cortana allows you to search,update%2C you could disable Cortana. Link to comment Share on other sites More sharing options...
SMalik Posted February 6, 2021 Share Posted February 6, 2021 Revised Entry https://ericmathison.com/blog/remove-shellbags-in-windows-for-privacy Removed: RegKey1=HKCU\Local Settings\Software\Microsoft\Windows\Shell\BagMRU RegKey2=HKCU\Local Settings\Software\Microsoft\Windows\Shell\Bags ExcludeKey1=REG|HKCU\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders [Folders View Settings *] LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows Warning=This will reset folders size, view, icon or position settings to default and remove traces of the folders that do not exist anymore. RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags RegKey3=HKCU\Software\Classes\Wow6432Node\Local Settings\Software\Microsoft\Windows\Shell\BagMRU RegKey4=HKCU\Software\Classes\Wow6432Node\Local Settings\Software\Microsoft\Windows\Shell\Bags RegKey5=HKCU\Software\Microsoft\Windows\Shell\BagMRU RegKey6=HKCU\Software\Microsoft\Windows\Shell\Bags RegKey7=HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU RegKey8=HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags ExcludeKey1=REG|HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders ExcludeKey2=REG|HKCU\Software\Classes\Wow6432Node\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders ExcludeKey3=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop ExcludeKey4=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\AllFolders Link to comment Share on other sites More sharing options...
siliconman01 Posted February 6, 2021 Share Posted February 6, 2021 Modified entry: [Quicken *] Added FileKey8/9/10 [Quicken *] LangSecRef=3021 Detect1=HKLM\Software\Intuit\Quicken Detect2=HKLM\Software\Quicken FileKey1=%AppData%\Intuit\Quicken\Log|*.txt;*.log FileKey2=%AppData%\Quicken\Log|*.txt;*.log FileKey3=%CommonAppData%\Intuit\Quicken\Log|*.log FileKey4=%CommonAppData%\Intuit\Quicken\Log\installer|*.*|REMOVESELF FileKey5=%CommonAppData%\Intuit\SendError|*.log FileKey6=%CommonAppData%\Quicken\Inet\QWWebData|Log.old FileKey7=%CommonAppData%\Quicken\Inet\QWWebData\Cache|*.* FileKey8=%CommonAppData%\Quicken\Inet\QWWebData\File System\Origins|Log.old FileKey9=%CommonAppData%\Quicken\Inet\QWWebData\IndexedDB\*|Log.old FileKey10=%CommonAppData%\Quicken\Inet\QWWebData\Local Storage\leveldb|Log.old;*tmp FileKey11=%CommonAppData%\Quicken\Log|*.log FileKey12=%CommonAppData%\Quicken\Log\installer|*.*|REMOVESELF FileKey13=%CommonAppData%\Quicken\SendError|*.log FileKey14=%LocalAppData%\Intuit\Common\Authorization\V1\Logs|*.txt FileKey15=%LocalAppData%\Quicken\Common\Authorization\V1\Logs|*.txt FileKey16=%ProgramFiles%\Quicken\PDFDrv|install.log;InstallPDFConverter.log Windows 10 x64 Pro on ASUS Maximus VIII Extreme motherboard, i7-6700k CPU,H220 X2 Liquid Cooler, 64 gbyte RipJaws DDR4 3200 RAM, Samsung 970 Pro NVMe M.2 500 gbyte SSD + Samsung 850 Pro 512 gbyte SSD, EVGA RTX 3060 Titan graphics card (Home Built System); Windows 11x64 Pro on 512 gigabyte Dell XPS 15 2-in-1 Laptop/tablet and Dell XPS 8940 PC. ASUS RT-AC88U router, 14 tbyte WD My Cloud PR2100 NAS Server, 200 Mbps cable Internet, MS Edge Chromium, MS Office 2021 (Local), Casper 11, DisplayFusion (3 Flat Panel Displays per system): Bitdefender Internet Security 2022, Malwarebytes 4, Quicken, Weather Watcher Live, ThumbsPlus 10, Sticky Password 8, WD Smartware, CyberLink PowerDVD22, MSI AfterBurner, Rainmeter, Windows Sidebar, and many more. Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now