Jump to content

Winapp2.ini additions


Winapp2.ini

Recommended Posts

9 hours ago, SMalik said:

Revised Entry

Changed: %ProgramFiles%\OpenVPN\Log|*.*  to  %ProgramFiles%\OpenVPN\Log|*.log
There is README.txt file here as well.

Added: %UsersProfile%\OpenVPN\log|*.*|RECURSE

[OpenVPN *]
LangSecRef=3024
DetectFile=%ProgramFiles%\OpenVPN
FileKey1=%ProgramFiles%\OpenVPN\Log|*.log
FileKey2=%UsersProfile%\OpenVPN\log|*.*|RECURSE

 

@SMalikI believe it's %UserProfile% and NOT %UsersProfile% !!

Link to comment
Share on other sites

15 hours ago, SMalik said:

That is correct. I am sorry.

Revised Entry

Changed DetectFile to Detect

[OpenVPN *]
LangSecRef=3024
Detect=HKLM\SOFTWARE\OpenVPN
FileKey1=%ProgramFiles%\OpenVPN\Log|*.log
FileKey2=%UserProfile%\OpenVPN\log|*.*|RECURSE

Link to comment
Share on other sites

Revised Entry

[Snagit *]
LangSecRef=3021
Detect=HKCU\Software\TechSmith\Snagit
Warning=This will delete the backups of the captures.
FileKey1=%CommonAppData%\TechSmith\Uploader|*.log
FileKey2=%Documents%|SnagitDebug.log
FileKey3=%LocalAppData%\TechSmith\Logs|*.log
FileKey4=%LocalAppData%\TechSmith\Snagit|Tray.bin
FileKey5=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE
FileKey6=%LocalAppData%\TechSmith\Snagit\DataStore|*.SNAGundo
FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico
FileKey8=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico
FileKey9=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE
FileKey10=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log;*.logtmp
RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder
RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder
RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount
RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount
RegKey5=HKCU\Software\TechSmith\Snagit\11|OutputDirLastUsed
RegKey6=HKCU\Software\TechSmith\Snagit\11|VidOutputDirLastUsed
RegKey7=HKCU\Software\TechSmith\Snagit\11\SnagItEditor\Tray|Thumbnailsize
RegKey8=HKCU\Software\TechSmith\Snagit\12|CaptureCount
RegKey9=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount
RegKey10=HKCU\Software\TechSmith\Snagit\12|OutputDirLastUsed
RegKey11=HKCU\Software\TechSmith\Snagit\12|VidOutputDirLastUsed
RegKey12=HKCU\Software\TechSmith\Snagit\12\SnagItEditor\Tray|Thumbnailsize
RegKey13=HKCU\Software\TechSmith\Snagit\13|CaptureCount
RegKey14=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount
RegKey15=HKCU\Software\TechSmith\Snagit\13|OutputDirLastUsed
RegKey16=HKCU\Software\TechSmith\Snagit\13|VidOutputDirLastUsed
RegKey17=HKCU\Software\TechSmith\Snagit\13\Recent Captures
RegKey18=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List
RegKey19=HKCU\Software\TechSmith\Snagit\13\SnagItEditor\Tray|Thumbnailsize
RegKey20=HKCU\Software\TechSmith\Snagit\18|CaptureCount
RegKey21=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount
RegKey22=HKCU\Software\TechSmith\Snagit\18|OutputDirLastUsed
RegKey23=HKCU\Software\TechSmith\Snagit\18|VidOutputDirLastUsed
RegKey24=HKCU\Software\TechSmith\Snagit\18\Recent Captures
RegKey25=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List
RegKey26=HKCU\Software\TechSmith\Snagit\18\SnagItEditor\Tray|Thumbnailsize
RegKey27=HKCU\Software\TechSmith\Snagit\19|CaptureCount
RegKey28=HKCU\Software\TechSmith\Snagit\19|CaptureOpenCount
RegKey29=HKCU\Software\TechSmith\Snagit\19|OutputDirLastUsed
RegKey30=HKCU\Software\TechSmith\Snagit\19|VidOutputDirLastUsed
RegKey31=HKCU\Software\TechSmith\Snagit\19\Recent Captures
RegKey32=HKCU\Software\TechSmith\Snagit\19\SnagitEditor\Recent File List
RegKey33=HKCU\Software\TechSmith\Snagit\19\SnagItEditor\Tray|Thumbnailsize
RegKey34=HKCU\Software\TechSmith\Snagit\20|CaptureCount
RegKey35=HKCU\Software\TechSmith\Snagit\20|CaptureOpenCount
RegKey36=HKCU\Software\TechSmith\Snagit\20|OutputDirLastUsed
RegKey37=HKCU\Software\TechSmith\Snagit\20|VidOutputDirLastUsed
RegKey38=HKCU\Software\TechSmith\Snagit\20\Recent Captures
RegKey39=HKCU\Software\TechSmith\Snagit\20\SnagitEditor\Recent File List
RegKey40=HKCU\Software\TechSmith\Snagit\20\SnagItEditor\Tray|Thumbnailsize
RegKey41=HKCU\Software\TechSmith\Snagit\21|CaptureCount
RegKey42=HKCU\Software\TechSmith\Snagit\21|CaptureOpenCount
RegKey43=HKCU\Software\TechSmith\Snagit\21|OutputDirLastUsed
RegKey44=HKCU\Software\TechSmith\Snagit\21|VidOutputDirLastUsed
RegKey45=HKCU\Software\TechSmith\Snagit\21\Recent Captures
RegKey46=HKCU\Software\TechSmith\Snagit\21\SnagitEditor\Recent File List
RegKey47=HKCU\Software\TechSmith\Snagit\21\SnagItEditor\Tray|Thumbnailsize
RegKey48=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder

Removed:
%AppData%\TechSmith\Snagit *\Identity|*.*
Sign in file

%LocalAppData%\TechSmith\Snagit\DataStore|*.SNAG;*.SNAGundo;*.MP4
*.SNAG;*.MP4 are Snagit Editor Library files

Added:
Support for Snagit 2021

Link to comment
Share on other sites

Revised Entry

[Snagit *]
LangSecRef=3021
Detect=HKCU\Software\TechSmith\Snagit
Warning=This will delete the backups of the captures.
FileKey1=%CommonAppData%\TechSmith\Uploader|*.log
FileKey2=%Documents%|SnagitDebug.log
FileKey3=%LocalAppData%\TechSmith\Logs|*.log
FileKey4=%LocalAppData%\TechSmith\Snagit|Tray.bin
FileKey5=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE
FileKey6=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico
FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico
FileKey8=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE
FileKey9=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log;*.logtmp
RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder
RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder
RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount
RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount
RegKey5=HKCU\Software\TechSmith\Snagit\11|OutputDirLastUsed
RegKey6=HKCU\Software\TechSmith\Snagit\11|VidOutputDirLastUsed
RegKey7=HKCU\Software\TechSmith\Snagit\11\SnagItEditor\Tray|Thumbnailsize
RegKey8=HKCU\Software\TechSmith\Snagit\12|CaptureCount
RegKey9=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount
RegKey10=HKCU\Software\TechSmith\Snagit\12|OutputDirLastUsed
RegKey11=HKCU\Software\TechSmith\Snagit\12|VidOutputDirLastUsed
RegKey12=HKCU\Software\TechSmith\Snagit\12\SnagItEditor\Tray|Thumbnailsize
RegKey13=HKCU\Software\TechSmith\Snagit\13|CaptureCount
RegKey14=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount
RegKey15=HKCU\Software\TechSmith\Snagit\13|OutputDirLastUsed
RegKey16=HKCU\Software\TechSmith\Snagit\13|VidOutputDirLastUsed
RegKey17=HKCU\Software\TechSmith\Snagit\13\Recent Captures
RegKey18=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List
RegKey19=HKCU\Software\TechSmith\Snagit\13\SnagItEditor\Tray|Thumbnailsize
RegKey20=HKCU\Software\TechSmith\Snagit\18|CaptureCount
RegKey21=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount
RegKey22=HKCU\Software\TechSmith\Snagit\18|OutputDirLastUsed
RegKey23=HKCU\Software\TechSmith\Snagit\18|VidOutputDirLastUsed
RegKey24=HKCU\Software\TechSmith\Snagit\18\Recent Captures
RegKey25=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List
RegKey26=HKCU\Software\TechSmith\Snagit\18\SnagItEditor\Tray|Thumbnailsize
RegKey27=HKCU\Software\TechSmith\Snagit\19|CaptureCount
RegKey28=HKCU\Software\TechSmith\Snagit\19|CaptureOpenCount
RegKey29=HKCU\Software\TechSmith\Snagit\19|OutputDirLastUsed
RegKey30=HKCU\Software\TechSmith\Snagit\19|VidOutputDirLastUsed
RegKey31=HKCU\Software\TechSmith\Snagit\19\Recent Captures
RegKey32=HKCU\Software\TechSmith\Snagit\19\SnagitEditor\Recent File List
RegKey33=HKCU\Software\TechSmith\Snagit\19\SnagItEditor\Tray|Thumbnailsize
RegKey34=HKCU\Software\TechSmith\Snagit\20|CaptureCount
RegKey35=HKCU\Software\TechSmith\Snagit\20|CaptureOpenCount
RegKey36=HKCU\Software\TechSmith\Snagit\20|OutputDirLastUsed
RegKey37=HKCU\Software\TechSmith\Snagit\20|VidOutputDirLastUsed
RegKey38=HKCU\Software\TechSmith\Snagit\20\Recent Captures
RegKey39=HKCU\Software\TechSmith\Snagit\20\SnagitEditor\Recent File List
RegKey40=HKCU\Software\TechSmith\Snagit\20\SnagItEditor\Tray|Thumbnailsize
RegKey41=HKCU\Software\TechSmith\Snagit\21|CaptureCount
RegKey42=HKCU\Software\TechSmith\Snagit\21|CaptureOpenCount
RegKey43=HKCU\Software\TechSmith\Snagit\21|OutputDirLastUsed
RegKey44=HKCU\Software\TechSmith\Snagit\21|VidOutputDirLastUsed
RegKey45=HKCU\Software\TechSmith\Snagit\21\Recent Captures
RegKey46=HKCU\Software\TechSmith\Snagit\21\SnagitEditor\Recent File List
RegKey47=HKCU\Software\TechSmith\Snagit\21\SnagItEditor\Tray|Thumbnailsize
RegKey48=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder

Removed:
%AppData%\TechSmith\Snagit *\Identity|*.*
Sign in file

%LocalAppData%\TechSmith\Snagit\DataStore|*.SNAG;*.SNAGundo;*.MP4
*.SNAG;*.MP4 are Snagit Editor Library files
*.SNAGundo are unsaved files
https://support.techsmith.com/hc/en-us/community/posts/360071706912-Can-I-delete-files-on-my-pc-with-the-Snagit-file-type-snagundo-without-losing-any-data-

Added:
Support for Snagit 2021

Link to comment
Share on other sites

Revised Entry

[Windows Logs *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
FileKey1=%CommonAppData%\Microsoft\Diagnosis\DownloadedSettings|*.json.bk
FileKey2=%CommonAppData%\Microsoft\Network\Downloader|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\WDF|*.*|RECURSE
FileKey4=%CommonAppData%\Microsoft\Windows Security Health\Logs|*.*|RECURSE
FileKey5=%CommonAppData%\USOShared\Logs|*.*|RECURSE
FileKey6=%LocalAppData%\ConnectedDevicesPlatform|*.log
FileKey7=%LocalAppData%\Diagnostics|*.*|RECURSE
FileKey8=%ProgramFiles%\UNP\*Logs|*.*
FileKey9=%SystemDrive%\PerfLogs\System\Diagnostics|*.*|RECURSE
FileKey10=%SystemDrive%\PerfLogs\System\Performance|*.*|RECURSE
FileKey11=%WinDir%\AppCompat\Programs|*.txt;*.xml
FileKey12=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml
FileKey13=%WinDir%\debug\WIA|*.log
FileKey14=%WinDir%\inf|*.log*
FileKey15=%WinDir%\Logs\CBS|*.cab
FileKey16=%WinDir%\Logs\dosvc|*.*|RECURSE
FileKey17=%WinDir%\Logs\NetSetup|*.*|RECURSE
FileKey18=%WinDir%\Logs\SIH|*.*|RECURSE
FileKey19=%WinDir%\Logs\WindowsBackup|*.etl
FileKey20=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log
FileKey21=%WinDir%\Panther\FastCleanup|*.log
FileKey22=%WinDir%\Panther\Rollback|*.txt
FileKey23=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml
FileKey24=%WinDir%\repair|setup.log
FileKey25=%WinDir%\security\logs|*.*|RECURSE
FileKey26=%WinDir%\System32\CatRoot|*.tmp
FileKey27=%WinDir%\System32\catroot2|*.chk;*.log;*.jrs;*.txt
FileKey28=%WinDir%\System32\LogFiles\HTTPERR|*.log
FileKey29=%WinDir%\System32\LogFiles\Scm|*.*|RECURSE
FileKey30=%WinDir%\System32\LogFiles\setupcln|*.*|RECURSE
FileKey31=%WinDir%\System32\LogFiles\Srt|*.*|RECURSE
FileKey32=%WinDir%\System32\LogFiles\WMI|*.*|RECURSE
FileKey33=%WinDir%\System32\SleepStudy|*.etl
FileKey34=%WinDir%\System32\SleepStudy\ScreenOn|*.etl
FileKey35=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml;*.log
FileKey36=%WinDir%\System32\WDI\*|snapshot.etl|REMOVESELF
FileKey37=%WinDir%\System32\WDI\LogFiles\StartupInfo|*.*|RECURSE
RegKey1=HKLM\Software\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications
RegKey2=HKLM\Software\Microsoft\Tracing
RegKey3=HKLM\Software\Wow6432Node\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications
RegKey4=HKLM\Software\Wow6432Node\Microsoft\Tracing

Added:
%CommonAppData%\Microsoft\Diagnosis\DownloadedSettings|*.json.bk
%CommonAppData%\Microsoft\WDF|*.*|RECURSE
%WinDir%\System32\CatRoot|*.tmp

Link to comment
Share on other sites

Modified entry:  [Windows Error Reporting *]

Added FileKey6.  Some programs such as Malwarebytes sneak a subfolder into folder Crashdumps to store the *.dmp file.

[Windows Error Reporting *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\Windows Error Reporting
FileKey1=%LocalAppData%\PCHealth\ErrorRep\QSignoff|*.*
FileKey2=%WinDir%\pchealth\ERRORREP|*.*|RECURSE
FileKey3=%WinDir%\pchealth\helpctr\DataColl|*.xml
FileKey4=%WinDir%\pchealth\helpctr\OfflineCache|*.*|RECURSE
FileKey5=%WinDir%\System32\config\systemprofile\AppData\Local\CrashDumps|*.dmp
FileKey6=%WinDir%\System32\config\systemprofile\AppData\Local\CrashDumps\*|*.dmp
FileKey7=%WinDir%\System32\config\systemprofile\Local Settings\Application Data\CrashDumps|*.dmp
FileKey8=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\CrashDumps|*.dmp
FileKey9=%WinDir%\SysWOW64\config\systemprofile\Local Settings\Application Data\CrashDumps|*.dmp
RegKey1=HKLM\Software\Microsoft\Windows\Windows Error Reporting\FullLiveKernelReports|LastFullLiveReport
RegKey2=HKLM\Software\Microsoft\Windows\Windows Error Reporting\FullLiveKernelReports\win32k.sys
RegKey3=HKLM\Software\Microsoft\Windows\Windows Error Reporting\LiveKernelReports\win32k.sys
RegKey4=HKLM\Software\Microsoft\Windows\Windows Error Reporting\LocalDumps
RegKey5=HKU\.DEFAULT\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation

Modified entry: [Snagit *]

Added FileKey4

[Snagit *]
LangSecRef=3021
Detect=HKCU\Software\TechSmith\Snagit
FileKey1=%CommonAppData%\TechSmith\Uploader|*.log
FileKey2=%Documents%|SnagitDebug.log
FileKey3=%LocalAppData%\TechSmith\Logs|*.log
FileKey4=%LocalAppData%\TechSmith\Snagit\*\NativeCrashReporting\Reports|*.dmp|RECURSE
FileKey5=%LocalAppData%\TechSmith\Snagit|Tray.bin
FileKey6=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE
FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico
FileKey8=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico
FileKey9=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE
FileKey10=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log;*.logtmp
RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder
RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder
RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount
RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount
RegKey5=HKCU\Software\TechSmith\Snagit\11|OutputDirLastUsed
RegKey6=HKCU\Software\TechSmith\Snagit\11|VidOutputDirLastUsed
RegKey7=HKCU\Software\TechSmith\Snagit\11\SnagItEditor\Tray|Thumbnailsize
RegKey8=HKCU\Software\TechSmith\Snagit\12|CaptureCount
RegKey9=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount
RegKey10=HKCU\Software\TechSmith\Snagit\12|OutputDirLastUsed
RegKey11=HKCU\Software\TechSmith\Snagit\12|VidOutputDirLastUsed
RegKey12=HKCU\Software\TechSmith\Snagit\12\SnagItEditor\Tray|Thumbnailsize
RegKey13=HKCU\Software\TechSmith\Snagit\13|CaptureCount
RegKey14=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount
RegKey15=HKCU\Software\TechSmith\Snagit\13|OutputDirLastUsed
RegKey16=HKCU\Software\TechSmith\Snagit\13|VidOutputDirLastUsed
RegKey17=HKCU\Software\TechSmith\Snagit\13\Recent Captures
RegKey18=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List
RegKey19=HKCU\Software\TechSmith\Snagit\13\SnagItEditor\Tray|Thumbnailsize
RegKey20=HKCU\Software\TechSmith\Snagit\18|CaptureCount
RegKey21=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount
RegKey22=HKCU\Software\TechSmith\Snagit\18|OutputDirLastUsed
RegKey23=HKCU\Software\TechSmith\Snagit\18|VidOutputDirLastUsed
RegKey24=HKCU\Software\TechSmith\Snagit\18\Recent Captures
RegKey25=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List
RegKey26=HKCU\Software\TechSmith\Snagit\18\SnagItEditor\Tray|Thumbnailsize
RegKey27=HKCU\Software\TechSmith\Snagit\19|CaptureCount
RegKey28=HKCU\Software\TechSmith\Snagit\19|CaptureOpenCount
RegKey29=HKCU\Software\TechSmith\Snagit\19|OutputDirLastUsed
RegKey30=HKCU\Software\TechSmith\Snagit\19|VidOutputDirLastUsed
RegKey31=HKCU\Software\TechSmith\Snagit\19\Recent Captures
RegKey32=HKCU\Software\TechSmith\Snagit\19\SnagitEditor\Recent File List
RegKey33=HKCU\Software\TechSmith\Snagit\19\SnagItEditor\Tray|Thumbnailsize
RegKey34=HKCU\Software\TechSmith\Snagit\20|CaptureCount
RegKey35=HKCU\Software\TechSmith\Snagit\20|CaptureOpenCount
RegKey36=HKCU\Software\TechSmith\Snagit\20|OutputDirLastUsed
RegKey37=HKCU\Software\TechSmith\Snagit\20|VidOutputDirLastUsed
RegKey38=HKCU\Software\TechSmith\Snagit\20\Recent Captures
RegKey39=HKCU\Software\TechSmith\Snagit\20\SnagitEditor\Recent File List
RegKey40=HKCU\Software\TechSmith\Snagit\20\SnagItEditor\Tray|Thumbnailsize
RegKey41=HKCU\Software\TechSmith\Snagit\21|CaptureCount
RegKey42=HKCU\Software\TechSmith\Snagit\21|CaptureOpenCount
RegKey43=HKCU\Software\TechSmith\Snagit\21|OutputDirLastUsed
RegKey44=HKCU\Software\TechSmith\Snagit\21|VidOutputDirLastUsed
RegKey45=HKCU\Software\TechSmith\Snagit\21\Recent Captures
RegKey46=HKCU\Software\TechSmith\Snagit\21\SnagitEditor\Recent File List
RegKey47=HKCU\Software\TechSmith\Snagit\21\SnagItEditor\Tray|Thumbnailsize
RegKey48=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder

 

Windows 10 x64 Pro on ASUS Maximus VIII Extreme motherboard, i7-6700k CPU,H220 X2 Liquid Cooler, 64 gbyte RipJaws DDR4 3200 RAM, Samsung 970 Pro NVMe M.2 500 gbyte SSD + Samsung 850 Pro 512 gbyte SSD, EVGA RTX 3060 Titan graphics card (Home Built System);  Windows 11x64 Pro on 512 gigabyte Dell XPS 15 2-in-1 Laptop/tablet and Dell XPS 8940 PC.  ASUS RT-AC88U router, 14 tbyte WD My Cloud PR2100 NAS Server, 200 Mbps cable Internet, MS Edge Chromium, MS Office 2021 (Local), Casper 11, DisplayFusion (3 Flat Panel Displays per system):   Latest Bitdefender Internet Security, Quicken, Weather Watcher Live, ThumbsPlus 10, Sticky Password 8, WD Smartware, CyberLink PowerDVD23, MSI AfterBurner, Rainmeter, 8GadgetPack, and many more.

Link to comment
Share on other sites

Cortana app package name has changed. The new package is Microsoft.Windows.Search_cw5n1h2txyewy

We already have an entry for the new package as [Windows Search *]

Please remove [Cortana *], [Cortana Show Me *] entries and name current [Windows Search *] to [Cortana *]

Link to comment
Share on other sites

7 hours ago, SMalik said:

Cortana app package name has changed. The new package is Microsoft.Windows.Search_cw5n1h2txyewy ...

The new "Cortana" app is just a voice-controlled user interface extension for "Windows Search". The new "Cortana" app can now also be removed quite easily and this removes the package "Microsoft.549981C3F5F10_*" and not the package "Microsoft.Windows.Search_*", which is still used for many other search tasks. By the way, the new "Cortana" app has been supported by the existing [Cortana *] entry for months now.

In addition, many people still use Windows 8.1 or older Windows 10 versions, so we can't simply remove the existing entries either.

So, in summary, everything is correct as it is and there is no reason to change anything.

wa2_new_cortana.jpg.c969d7dfd9cedf113a0dddc994eceee4.jpg

https://www.windowscentral.com/how-uninstall-cortana-windows-10-may-2020-update

Link to comment
Share on other sites

I have Windows 10 20H2 (OS Build 19042.782). I just uninstalled Cortana app and it removed Microsoft.Windows.Search_cw5n1h2txyewy package.

I have another privacy cleaner program on my system and Microsoft.Windows.Search_cw5n1h2txyewy files are under Cortana entry.

 

Link to comment
Share on other sites

Revised Entry

Added:
FileKey2
RegKey1

[3D Viewer *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\LocalCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\LocalState\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Microsoft3DViewer_*\TempState|*.*|RECURSE
RegKey1=HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\PersistedStorageItemTable\MostRecentlyUsed

Edited by Nergal
replaced at member request
Link to comment
Share on other sites

Revised Entry

Added:
%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\AC\TokenBroker\Cache|*.*|RECURSE

[Cortana *]
LangSecRef=3031
Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.549981C3F5F10_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Cortana_8wekyb3d8bbwe
Detect3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Cortana_cw5n1h2txyewy
Detect4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Search_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.*Cortana_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.*Cortana_*\TempState|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\AC\INet*|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\AC\Temp|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\LocalCache|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.549981C3F5F10_*\TempState|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalCache|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\AppIconCache|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache|*.txt
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\DeviceSearchCache\|SettingsCache.txt

Link to comment
Share on other sites

Revised Entry

Changed the entry name from [Mail and Calendar *] to [Calendar, Mail & People *]

Added: FileKey10

[Calendar, Mail & People *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Comms\Unistore\data|AggregateCache.uca
FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\AppData\Local\Office\*\WebServiceCache\AllUsers\officeclient.microsoft.com|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState|*.etl;*.log
FileKey11=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory

Link to comment
Share on other sites

Revised Entry

Added: %LocalAppData%\Packages\Microsoft.Windows.Search_*\LocalState\DeviceSearchCache|*.*|RECURSE

[Windows Search *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Search_cw5n1h2txyewy
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.Search_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Search_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.Search_*\LocalState\AppIconCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.Search_*\LocalState\DeviceSearchCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.Search_*\TempState|*.*|RECURSE

Link to comment
Share on other sites

New Entry

[Microsoft To DO *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Todos_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Todos_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Todos_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Todos_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Todos_*\LocalCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Todos_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Todos_*\TempState|*.*|RECURSE

Link to comment
Share on other sites

Thank you for the revised and new entries.

13 hours ago, SMalik said:

... Changed the entry name from [Mail and Calendar *] to [Calendar, Mail & People *] ...

However, the "People" app is not part of the "Mail and Calendar" app. The "People" app has always had its own package "Microsoft.People_*" and its own entry [People *].

https://www.microsoft.com/en-us/p/microsoft-people/9nblggh10pg8
https://www.microsoft.com/en-us/p/mail-and-calendar/9wzdncrfhvqm

The package of an app can be found out very quickly: just drag and drop the icon to the desktop, right click and choose properties.

A search using the package name also works. Just execute these links via "Run":

ms-windows-store://pdp/?PFN=Microsoft.People_8wekyb3d8bbwe
ms-windows-store://pdp/?PFN=microsoft.windowscommunicationsapps_8wekyb3d8bbwe
ms-windows-store://pdp/?PFN=Microsoft.549981C3F5F10_8wekyb3d8bbwe

Note: This search only works for apps that are available in the Microsoft Store. (System apps will therefore not be found).

Link to comment
Share on other sites

8 hours ago, APMichael said:

Thank you for the revised and new entries.

However, the "People" app is not part of the "Mail and Calendar" app. The "People" app has always had its own package "Microsoft.People_*" and its own entry [People *].

https://www.microsoft.com/en-us/p/microsoft-people/9nblggh10pg8
https://www.microsoft.com/en-us/p/mail-and-calendar/9wzdncrfhvqm

The package of an app can be found out very quickly: just drag and drop the icon to the desktop, right click and choose properties.

A search using the package name also works. Just execute these links via "Run":


ms-windows-store://pdp/?PFN=Microsoft.People_8wekyb3d8bbwe
ms-windows-store://pdp/?PFN=microsoft.windowscommunicationsapps_8wekyb3d8bbwe
ms-windows-store://pdp/?PFN=Microsoft.549981C3F5F10_8wekyb3d8bbwe

Note: This search only works for apps that are available in the Microsoft Store. (System apps will therefore not be found).

That is fine but, I think Windows Search entry should be merged into Cortana entry.

Link to comment
Share on other sites

3 hours ago, SMalik said:

That is fine but, I think Windows Search entry should be merged into Cortana entry.

It is pretty confusing. I think we should leave Windows Search entry as is.

https://www.groovypost.com/howto/disable-cortana-replace-windows-search/#:~:text=Cortana allows you to search,update%2C you could disable Cortana.

Link to comment
Share on other sites

Revised Entry

https://ericmathison.com/blog/remove-shellbags-in-windows-for-privacy

Removed:
RegKey1=HKCU\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
RegKey2=HKCU\Local Settings\Software\Microsoft\Windows\Shell\Bags
ExcludeKey1=REG|HKCU\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders

[Folders View Settings *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Warning=This will reset folders size, view, icon or position settings to default and remove traces of the folders that do not exist anymore.
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags
RegKey3=HKCU\Software\Classes\Wow6432Node\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
RegKey4=HKCU\Software\Classes\Wow6432Node\Local Settings\Software\Microsoft\Windows\Shell\Bags
RegKey5=HKCU\Software\Microsoft\Windows\Shell\BagMRU
RegKey6=HKCU\Software\Microsoft\Windows\Shell\Bags
RegKey7=HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU
RegKey8=HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
ExcludeKey1=REG|HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey2=REG|HKCU\Software\Classes\Wow6432Node\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey3=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop
ExcludeKey4=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\AllFolders

Link to comment
Share on other sites

Modified entry:  [Quicken *]

Added FileKey8/9/10


[Quicken *]
LangSecRef=3021
Detect1=HKLM\Software\Intuit\Quicken
Detect2=HKLM\Software\Quicken
FileKey1=%AppData%\Intuit\Quicken\Log|*.txt;*.log
FileKey2=%AppData%\Quicken\Log|*.txt;*.log
FileKey3=%CommonAppData%\Intuit\Quicken\Log|*.log
FileKey4=%CommonAppData%\Intuit\Quicken\Log\installer|*.*|REMOVESELF
FileKey5=%CommonAppData%\Intuit\SendError|*.log
FileKey6=%CommonAppData%\Quicken\Inet\QWWebData|Log.old
FileKey7=%CommonAppData%\Quicken\Inet\QWWebData\Cache|*.*
FileKey8=%CommonAppData%\Quicken\Inet\QWWebData\File System\Origins|Log.old
FileKey9=%CommonAppData%\Quicken\Inet\QWWebData\IndexedDB\*|Log.old
FileKey10=%CommonAppData%\Quicken\Inet\QWWebData\Local Storage\leveldb|Log.old;*tmp
FileKey11=%CommonAppData%\Quicken\Log|*.log
FileKey12=%CommonAppData%\Quicken\Log\installer|*.*|REMOVESELF
FileKey13=%CommonAppData%\Quicken\SendError|*.log
FileKey14=%LocalAppData%\Intuit\Common\Authorization\V1\Logs|*.txt
FileKey15=%LocalAppData%\Quicken\Common\Authorization\V1\Logs|*.txt
FileKey16=%ProgramFiles%\Quicken\PDFDrv|install.log;InstallPDFConverter.log

 

Windows 10 x64 Pro on ASUS Maximus VIII Extreme motherboard, i7-6700k CPU,H220 X2 Liquid Cooler, 64 gbyte RipJaws DDR4 3200 RAM, Samsung 970 Pro NVMe M.2 500 gbyte SSD + Samsung 850 Pro 512 gbyte SSD, EVGA RTX 3060 Titan graphics card (Home Built System);  Windows 11x64 Pro on 512 gigabyte Dell XPS 15 2-in-1 Laptop/tablet and Dell XPS 8940 PC.  ASUS RT-AC88U router, 14 tbyte WD My Cloud PR2100 NAS Server, 200 Mbps cable Internet, MS Edge Chromium, MS Office 2021 (Local), Casper 11, DisplayFusion (3 Flat Panel Displays per system):   Latest Bitdefender Internet Security, Quicken, Weather Watcher Live, ThumbsPlus 10, Sticky Password 8, WD Smartware, CyberLink PowerDVD23, MSI AfterBurner, Rainmeter, 8GadgetPack, and many more.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.