Jump to content

CCleaner can't delete all traces ?


codon

Recommended Posts

CCman come on, let's not get into a discussion here about the text on the ccleaner website and talk about the program.

 

 

Oh dear, this is a little confusing. I was quite prepared to believe Nergal when he said...

 

ccleaner is NOT a privacy program. It is a space clearer.

 

If Nergal's assessment of CCleaner was accurate, then I would have expected other moderators to back his statement especially after I pointed out the inconsistencies with the text on the piriform site. However now it seems as if you are trying to cover over the subject.

 

As Nergal's assessment and piriforms statements are so dissimilar, who are you suggesting the public should believe now ? Nergal or piriform ?

 

 

As for those asking to provide code.

 

The fact that this privacy omission has been around for about 3 years, at least, tells us something about the incumbent testing team. To expect new members to provide all code for the fixes, immediately is not realistic is it ? Repeatedly asking codon to provide you with code is not fair, he has pointed out the bug and taken the time to explain it very well I think. Have you considered the fact he may not know exactly where all the data resides ?

Link to comment
Share on other sites

How about that CCleaner cleans browser cookies, histories etc?

That's not good enough. If you bill CCleaner as a privacy protector - as stated in several places on the website - well, you better be sure you cover all the info. Privacy can be breached by as little as a couple of bytes.

 

All it takes is the wrong set of data bits to implicate you in whatever "investigation" might be at hand. And you gotta admit, that the privacy claim (CCleaner makes) is pretty thin when you look at the stray info the NirSoft utility reports. But you know, that information has been there since the dawn of time, beginning around the XP era.

 

The way I see it is a program will zap the information or it will not. If this type of log seems important enough to erase, well, people will find a way to erase it. Whether it be CCleaner or a competitor, who cares?

Link to comment
Share on other sites

As far as the developers becoming increasingly remote and out-of-reach. That isn't a good thing. Say what you will, but discussions on this forum will drift away from the purpose of supporting CCleaner, a tiny little bit at a time. To be replaced by moderator opinions and activity.

Link to comment
Share on other sites

3 posts in a row, I don't mean to hijack the thread or anything. Just riding along and watching the antics. But if you are going to be cutting out parts of the registry you better be certain of the effects of those actions; and how other programs respond too, like installers and backups and system repair utilities.

 

And forensically, you'll need to overwrite those gaping holes and be sure the data hasn't been duplicated elsewhere.

Link to comment
Share on other sites

Many Shell bags, including all five you show in are recreated by windows during startup because shellbags are created as things are accessed by the computer

why do you write this to me???

didn't you read this!?

  • HKEY_USERS http://de.wikipedia....ssel_HKEY_USERS
    This master key contains the user-specific configuration information of all users who are currently logged on to the system. Only when the user logs in - the configuration data will copied from HKEY_USERS in the user-specific key HKEY_CURRENT_USER

in #31 you see all the deleted keys and values - tested on my mashine - and it works! You wrote CCleaner only cleans for the current user. I wrote all changes happen in HKEY_Users - read the lines above again.

The second two are a user of that machine (and if it's the current user then entry one and two are the exact same entry
We can meet us in "The Red Lion" - may be you mean the one in London and I the one in Würzburg. There is no match

 

Have you understand what I wrote - never! All the things in the screenshots happened. The only nebulous things here are your - sorry - stupid thoughts!

Wake up!

You should do what do you ask me for - my system works - I’m not interested in any winapp2.ini or CCleaner. I was astonished that CCleaner can’t do what I and many friends have had expected.

First I've had only a question, then I found answers and then a greenhorn like you wants ready answers and tested solutions that are themselves not yet found by the developers - what a joke! :rolleyes:

Link to comment
Share on other sites

It isn't the position of the users to provide code or scripting. Particularly if developers are "increasingly remote". Effective dialog in programming can only happen if there is two way communication, clearly there is not. I propose any users that want to generate entries just do the winapp2.ini thing. Nothing more.

 

I don't know *ALL* the details of every registry entry, but doesn't shellbags also store last-known window positions, defaulting to 400 sets of positions? I would not want that cleared. And we also need to consider that some of the entries (in these registry keys, the ones that are topic of this thread) may already be affected by CCleaner.

 

I can tell you I have an understanding of computer forensics, and the only way to be sure is to nuke it from orbit. Having said that, all my "CCleaner activities" focus around how much space I can reclaim - which is a couple of gigs at the end of the month. The smaller the backup the better.

Link to comment
Share on other sites

  • Moderators

as I stated the developers read all threads.

I'm out of this one except when people post against the rules things which was the only thing that I was doing before being pulled into this troll fest

I don't disagree that more could be cleaned

Ccman is correct, it was I who first brought up privacy, and that was what my understanding of it was (and slightly still is). Though the quoted passages seem to come from business pages which of course is a paid license and gets direct developer support. Which brings us to something

keatah you make a good point (many actually but I digress as I am apt to do) and yes as the developers have been forced to focus on other revenue for this free software that does much better than other applications (or than windows itself for which it is meant to clean) they have become less hands on in the forum…of course you could pay the relatively small amount for the pro version and get that back… you may not like it, I know I don't really like it much…until consider what I talked about in the above paragraph…I still don't like it but I understand).

This is a well known software and as I said, you've spent the last week (maybe less) griping about something when a new version is released once a month.

Good night Good Luck Good bye

 

ADVICE FOR USING CCleaner'S REGISTRY INTEGRITY SECTION

DON'T JUST CLEAN EVERYTHING THAT'S CHECKED OFF.

Do your Registry Cleaning in small bits (at the very least Check-mark by Check-mark)

ALWAYS BACKUP THE ENTRY, YOU NEVER KNOW WHAT YOU'LL BREAK IF YOU DON'T.

Support at https://support.ccleaner.com/s/?language=en_US

Pro users file a PRIORITY SUPPORT via email support@ccleaner.com

Link to comment
Share on other sites

CCleaner does what it does very well. And it's easy to forget its free.

 

All this info collated by the nirsoft utility is making quite a stink at work. I feel, though, it will be addressed sooner or later.

Link to comment
Share on other sites

  • Moderators

can someone please get me up to speed on where this thread is heading?

between {edit} sizes, cooking storks and try-outs for a new "So You Think You Can Quote Music Songs" reality TV show, are we trying to improve CC? or are we discussing CC shortcomings? or maybe criticising NisSofer? or even recommending we start using NirSofer in conjunction with CC?

 

the thread seems to be spinning it's wheels... :)

Edited by Nergal
censored due to forum rules

Backup now & backup often.
It's your digital life - protect it with a backup.
Three things are certain; Birth, Death and loss of data. You control the last.

Link to comment
Share on other sites

  • Moderators

my apologies Nergal, I changed the original C word to the correct P word for the male apendage thinking that would be alright.

 

now i know. if i ever need to again, i'll use what my Grandmother always called it; long and dangly bits

Backup now & backup often.
It's your digital life - protect it with a backup.
Three things are certain; Birth, Death and loss of data. You control the last.

Link to comment
Share on other sites

  • Moderators

It's ok I went back and edited the first one, I didn't feel right editing it while I was involved in the thread

 

ADVICE FOR USING CCleaner'S REGISTRY INTEGRITY SECTION

DON'T JUST CLEAN EVERYTHING THAT'S CHECKED OFF.

Do your Registry Cleaning in small bits (at the very least Check-mark by Check-mark)

ALWAYS BACKUP THE ENTRY, YOU NEVER KNOW WHAT YOU'LL BREAK IF YOU DON'T.

Support at https://support.ccleaner.com/s/?language=en_US

Pro users file a PRIORITY SUPPORT via email support@ccleaner.com

Link to comment
Share on other sites

troll fest

 

Thats quite a serious accusation, please quote your evidence or withdraw your comment. Posting unsubstantiated claims is not conduct expected of a moderator.

 

Though the quoted passages seem to come from business pages

 

Again you are misrepresenting, only one of the three quotes is from the business pages. To further compound your misjudgment the CCleaner core is the same on both free and commercial versions, so the quote is relevant.

Link to comment
Share on other sites

Statement

 

I write in my native language, because then I know exactly what I'm saying and I don't want to be misunderstood. Maybe someone can translate it. I think Google cannot do it alone. All the bad mood, all the ignorance - a pity.

 

CCleaner ist ein sehr gutes, mächtiges (auch kostenloses) Programm, das so seinesgleichen sucht. Meine Hochachtung den Entwicklern, die so etwas zustande gebracht haben.

 

Windows ist ein Datensammler, doch ich glaube nicht primär um Benutzer auszuspionieren, sondern um es ihnen einfach zu machen (man denke an die Unix-Zeiten, an die Eingabeaufforderung,etc.). Dieses „Einfach Machen“ birgt allerdings viele Gefahren in sich und viele Programme hinterlassen Spuren und sind nicht so entwickelt, dass sie den Computer so verlassen wie sie ihn vorgefunden haben, wenn man sie deinstalliert.

 

Ich war erstaunt wie viele Rückstände bzw. Reste zu finden waren, nachdem ich CCleaner angewendet hatte. Das kleine Programm von Nir Sofer zeigte allerdings Spuren, von denen ich meinte, sie dürften eigentlich nicht da sein, hatte ich doch die Optionen im Startmenü / Datenschutz abgewählt. Nun sie waren aber da - und sogar von nichtangeschlossenen Wechselmedien! Dies war der Grund mich in diesem Fachforum anzumelden - ich wollte Hilfe und Unterstützung - und natürlich bemühte ich mich auch eine Lösung zu finden.

 

So suchte ich den Ort wo diese Informationen gespeichert waren - zunächst jedoch erfolglos. Ich führte Telefonate mit Softwareentwicklern, fand so einiges im Netz und lernte im Laufe der Suche dazu. Hier eine Vermutung, dort ein Verweis oder ein neuer Begriff. Ich hörte nicht auf, war allerdings zunächst auf der falschen Fährte, nämlich der Forensik. Ich suchte nun ein Program, das in Lage war File-Slack (Ram-Slack & Drive-Slack) und MTF-Slack zu löschen, bzw. zu überschreiben. Auf der Suche danach fand ich nebenbei das Programm von Jürgen Haage - und die Einträge waren mit einem Klick verschwunden.

 

Nir Sofer hat nicht auf die Anfrage geantwortet (er wird zu sehr beschäftigt sein) von wo sein Programm die angezeigten Informationen hat und so galt es über Umwege dahinter zu kommen. Die Informationen waren da und auch in der Registry, doch eben nicht in Klartext. Ich suchte ein Programm, das Veränderungen in der Registry an- und aufzeigen konnte. So kam ich auf diese und deren Unterschlüssel, die gelöscht wurden.

 

HKU\S-1-5-21-/ ̴  ̴  ̴/--1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1

 

Modifiziert wurden diese

 

HKU\S-1-5-21-/  ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\NodeSlots
HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\NodeSlots
HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell\WinPos…
HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell\WinPos…

 

Wenn nun alle Informationen in HKEY_USERS bei der Anmeldung eines Benutzers in HKEY_CURRENT_USER geschrieben werden, nutzt das Leeren der BagMRUs dort (HKCU) nichts, da sie bei jedem Systemstart wieder neu eingelesen werden.

 

Aber auch ohne das Programm von Jürgen Haage geht es. Eine Momentaufnahme bevor man einen oder mehrere neue(n) Ordner anlegt (in diesem Beispiel nur einer), dann eine danach. Beim Vergleich sieht man dann die neuen Einträge in der Registry.

 

Keys added:12

											
HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}

 

Values added:40

										
HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\NodeSlot: 0x00000A1E
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\MRUListEx: FF FF FF FF
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0: 50 00 31 00 00 00 00 00 1B 41 65 00 10 00 00 61 72 00 69 00 00 00 3A 00 08 00 04 00 00 BE 1B 41 FA 5E 1B 41 65 00 2A 00 00 00 17 24 01 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 61 00 72 00 00 00 69 00 00 00 00 00 16 00 00 00
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\MRUListEx: 00 00 00 00 FF FF FF FF
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\MRUListEx: 00 00 00 00 FF FF FF FF
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0: 19 00 2F 43 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\Rev: 0x00000004
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\FFlags: 0x41200001
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\Vid: "{137E7700-3573-11CF-AE69-08002B2E1262}"
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\Mode: 0x00000004
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\LogicalViewMode: 0x00000001
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\IconSize: 0x00000010
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\ColInfo: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 18 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 00 00 00 00 10 01 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 0E 00 00 00 00 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 04 00 00 00 00 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 0C 00 00 00 50 00 00 00
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\Sort: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 00 00 00 00 01 00 00 00
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\GroupView: 0x00000000
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\GroupByKey:FMTID: "{00000000-0000-0000-0000-000000000000}"
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\GroupByKey:PID: 0x00000000
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\GroupByDirection: 0x00000001
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\KnownFolderDerivedFolderType: "{50000098-004F-4462-BB63-71042380B109}"
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\SniffedFolderType: "Generic"
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\NodeSlot: 0x00000A1E
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\MRUListEx: FF FF FF FF
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0: 50 00 31 00 00 00 00 00 1B 41 65 00 10 00 00 61 72 00 69 00 00 00 3A 00 08 00 04 00 00 BE 1B 41 FA 5E 1B 41 65 00 2A 00 00 00 17 24 01 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 61 00 72 00 00 00 69 00 00 00 00 00 16 00 00 00
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\MRUListEx: 00 00 00 00 FF FF FF FF
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\MRUListEx: 00 00 00 00 FF FF FF FF
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0: 19 00 2F 43 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\Rev: 0x00000004
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\FFlags: 0x41200001
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\Vid: "{137E7700-3573-11CF-AE69-08002B2E1262}"
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\Mode: 0x00000004
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\LogicalViewMode: 0x00000001
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\IconSize: 0x00000010
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\ColInfo: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 18 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 00 00 00 00 10 01 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 0E 00 00 00 00 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 04 00 00 00 00 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 0C 00 00 00 50 00 00 00
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\Sort: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 00 00 00 00 01 00 00 00
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\GroupView: 0x00000000
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\GroupByKey:FMTID: "{00000000-0000-0000-0000-000000000000}"
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\GroupByKey:PID: 0x00000000
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\GroupByDirection: 0x00000001
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\KnownFolderDerivedFolderType: "{50000098-004F-4462-BB63-71042380B109}"
			HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590\Shell\SniffedFolderType: "Generic"				

 

Nach der Reinigung mit dem Programm von Jürgen Haage sah es dann so aus [

Keys deleted:6

																														
HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0									

 

Values deleted:12

														

HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\NodeSlot: 0x00000A1E
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\MRUListEx: FF FF FF FF
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0: 50 00 31 00 00 00 00 00 1B 41 65 00 10 00 00 61 72 00 69 00 00 00 3A 00 08 00 04 00 00 BE 1B 41 FA 5E 1B 41 65 00 2A 00 00 00 17 24 01 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 61 00 72 00 00 00 69 00 00 00 00 00 16 00 00 00
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\MRUListEx: 00 00 00 00 FF FF FF FF
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\MRUListEx: 00 00 00 00 FF FF FF FF
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0: 19 00 2F 43 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\NodeSlot: 0x00000A1E
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\MRUListEx: FF FF FF FF
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0: 50 00 31 00 00 00 00 00 1B 41 65 00 10 00 00 61 72 00 69 00 00 00 3A 00 08 00 04 00 00 BE 1B 41 FA 5E 1B 41 65 00 2A 00 00 00 17 24 01 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 61 00 72 00 00 00 69 00 00 00 00 00 16 00 00 00
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\MRUListEx: 00 00 00 00 FF FF FF FF
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\MRUListEx: 00 00 00 00 FF FF FF FF
							HKU\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0: 19 00 2F 43 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

ACHTUNG - Ich habe einige Zahlenpaare wie A5, F1, usw. durch 00 ersetzt!

 

 

 

Ein anderes Programm von Nir Sofer „ShellBagsView“ half mir dann weiter diese Bags-Orte für diesen einen Ordner (2590) zu finden

HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590
HKEY_USERS\S-1-5-21-/ ̴  ̴  ̴/-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590
HKEY_USERS\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590
HKEY_USERS\S-1-5-21-/ ̴  ̴  ̴/-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\2590

- erstaunlich ist hierbei, dass die Eintragungen in den Bags beim Löschen aber anscheinend keine Rolle spielen und weiterhin in der Registry zu finden sind.

 

Zu guter Letzt - ich mache CCleaner keinen Vorwurf, das er (noch) nicht in der Lage ist diese Spuren zu beseitigen - und habe es niemals getan! Kommunikationsschwierigkeiten gibt es auch in meiner Muttersprache - sie potenzieren sich allerdings, wenn man in der jeweiligen Fremdsprache nicht fit ist und sich mühselig auf ein Wörterbuch und das Gelernte aus längst vergangenen Tagen zurückgreifen muss.

 

Aber eines bleibt - es gibt ein Gespür, ein Gefühl für das, was sich Menschen einander antun - und das ist hier kein gutes gewesen.

Edited by Nergal
added code rtags for easier reading
Link to comment
Share on other sites

THANK YOU VERY MUCH CODON !!!!

 

Awesome work ! :D

 

Please do not allow Nergal to deter you from your efforts to help us. He openly admits and seems proud of his demeanor " Interests:being grumpy ".

 

So on behalf of the normal members here who just want to get CCleaner fixed thank you and please continue.

Link to comment
Share on other sites

@CCman

You were acting like a troll when you claimed in post #44 that users were being misled by

"It protects your privacy online and makes your computer faster and more secure."

Alternatively you could have lacked the comprehension that "Last Accessed Date" of rundll.exe is NOT exposed by online activity.

 

In posts #46 and #47 you fail to comprehend a great chunk of text which includes

"You may be leaving your company open to unnecessary review of documents that you have already legitimately deleted"

Please note that the residues of "Last Accessed Date" will not reveal the contents of deleted files.

 

So far as I can see, when you speak on behalf of normal members there are only two of you.

Radonflex may be a third - all we know from one post is that he knows how to

Delete 100% nirsoft activity (on Win7 x64)

I don't take any responsibility for damages at your data or PC !!!!!!!

Please note that Piriform intend CCleaner to be SAFE.

 

I appreciate the potential benefit of destroying evidence of the content of a file,

but heat and fury over the name and last access date of a deleted file leading to a 4 page topic seems a little obsessive to me.

Link to comment
Share on other sites

  • Moderators

@codon

 

This is an English speaking forum staffed by volunteers. Posting in your native language is not going to help anything.

 

@CCman

 

It won't help things if you are not able to stay calm and prevent yourself doing what seems like inciting others to post in order to 'fire' things up. Posting things such as...

 

So on behalf of the normal members here who just want to get CCleaner fixed

 

is a big no. It implies some members are not 'normal' and you are. Also ccleaner is not broken.

 

Now we have all read what has been posted.

 

So unless anything else of a reasonably presented nature is posted regarding this subject I will be closing this thread soon, it has gone so far off track.

 

Support contact

https://support.ccleaner.com/s/contact-form?language=en_US&form=general

or

support@ccleaner.com

 

Link to comment
Share on other sites

This is an English speaking forum staffed by volunteers. Posting in your native language is not going to help anything.

 

He tells you why he had to do it, he was suffering the same deliberate misinterpretation I am having to endure. He felt more confident having to twist words with the trolls in his own language, poor guy was only trying to help !

 

It won't help things if you are not able to stay calm

 

I am calm. If you read my posts in a calm way you cannot in all honesty say I am doing anything other than joining in the discussion. I cannot understand why you would make such an unsubstantiated claim, I appreciate your friends with the long term members here but it is not fair to abuse your position. I would be interested to see how you are misinterpreting my posts. Please quote some better examples where your accusation is more clear.

 

 

It implies some members are not 'normal' and you are.

 

You are projecting your own personality and perception onto my posts. Normal users to me is just the everyday joe public, humble users not a computer expert, long term CCleaner expert or moderator etc.

 

It seems as if a few here are deliberately trying to misinterpret things that are said, why is this ? I hope posts are left unedited so we can clearly see the truth. I suspect you will indeed close the thread as reading through it all kind of proves my point.

 

I would however like to be able to reply to Alan_B as he has demonstrated more trolling behavior towards myself than anyone else on this forum. I hope you have the good conduct as a moderator to allow that. It would also be nice to see a bit of impartiality and equal moderation. I suggest you take another read through the entire thread and reprimand those that deserve it. It would also surprise you to read my posts without the unwarranted ill mannered attitude you have attached to them. Perhaps then you might realise I have been trying to help here !

 

Good grief .... :)

Link to comment
Share on other sites

You were acting like a troll when you claimed in post #44 that users were being misled by

"It protects your privacy online and makes your computer faster and more secure."

 

You have quoted the piriform site and not me. This is known as a "straw man" argument. I suggest you read that post again.

 

I think we can all agree with your assessment of CCleaner.

 

Here I was agreeing with a moderator on the forum, how you twist this into a claim of trolling is beyond me. I think this is a case of "you protesting too much" (if you understand that term). See below.

 

However I think the following text is misleading users.

 

"I THINK" (very important part of that sentence). :)

 

 

Alternatively you could have lacked the comprehension that "Last Accessed Date" of rundll.exe is NOT exposed by online activity.

 

Where did I say it was ? Quote me or retract and apologise.

 

 

In posts #46 and #47 you fail to comprehend a great chunk of text which includes

"You may be leaving your company open to unnecessary review of documents that you have already legitimately deleted"

Please note that the residues of "Last Accessed Date" will not reveal the contents of deleted files.

 

The quote was to demonstrate CCleaners claims of privacy, nothing to do with last access date. Please quote where I said "Last Accessed Date" will actually reveal the contents of deleted files or retract and apologise.

 

I see you choose to snipe at me from the sidelines and when you are asked to provide evidence for your accusations you hide away. You have yet to summon the fortitude to reply to post #11. I see you lost the courage to retain your post #20 where you mocked the moderators over zealousness.

 

Ironic you accuse others of trolling, here are a selection of aggressive (trolling) opening lines from YOU to me whilst I have been a member here. None of which you were able to back up when challenged to do so.

 

 

I disagree with your priorities.
Your concerns do not seem rational.
You were acting like a troll

 

I have been nothing other than polite here, I challenge you to quote me where I have not been !

 

I stand corrected.

 

You most certainly do, yet again !! :D

Link to comment
Share on other sites

Google Translater #63 - some things are strange for me in this translation - hope you'll understand - so please don't laugh.

 

CCleaner is a very good, powerful (and free) program that will detect as his equal. My compliments to the developers who have accomplished something.

 

Windows is a data collector, but I do not primarily to spy on users, but it is easy to make them (think of the Unix times, at the command prompt, etc.). This "Just Do" poses many dangers, however, and many programs leave traces and are not designed to the computer so they leave as they found him when they are uninstalled.

 

I was amazed how many residues or residues were found after I had used CCleaner. The small program by Nir Sofer, however, showed traces of which I thought they should not really be there, I had the options in the start menu / deselected Policy. Now, however, they were there - and even by non-affiliated removable media! This was the reason to sign me in this professional forum - I wanted to help and support - and of course I tried to find a solution.

 

So I looked for the place where the information was stored - initially unsuccessful. I conducted telephone calls with software developers, found so few in the net and learned over the course of this search. Here is a guess, there is a reference or a new concept. I did not stop, however, was initially on the wrong track, namely forensics. I now sought a program that was able to delete file-Slack (Slack & Ram Drive Slack) and MTF-Slack, or to overwrite. Looking for it, I found the way the program by Juergen Haage - and the entries were gone with one click.

 

Nir Sofer has not responded to the request (he is too busy to be) where the program has the information displayed and it was coming to a roundabout way behind. The information was there, and also in the registry, it's not made in plain text. I was looking for a program that was able to show changes in the registry and on. So I came up with this and their sub keys that have been deleted.

HKU \ S-1-5-21 / ̴ ̴ ̴/--1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1

These were modified

HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ NodeSlots
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ NodeSlots
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 ... \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ AllFolders \ Shell \ WinPos
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ AllFolders \ Shell \ WinPos ...

If all informations are written to HKEY_CURRENT_USER from HKEY_USERS when a user logs in, emptying the HKCU-BagMRUs uses nothing at, because they are on every systemstart again re-read.

 

But even without the program by Juergen Haage it goes. A snapshot before you one or more new folder (s) applies (in this example, only one), then after. When comparing you see the new entries in the registry.

 

Keys added: 12

HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590 \ Shell
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590 \ Shell \ {5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590 \ Shell
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590 \ Shell \ {5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}

Values added: 40

HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0 \ NodeSlot: 0x00000A1E
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0 \ MRUListEx: FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0: 50 00 31 00 00 00 00 00 1B 41 65 00 10 00 00 61 72 00 69 00 00 00 3A 00 08 00 04 00 00 41 FA 5E BE 1B 1B 41 65 00 2A 00 00 00 17 24 01 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 61 00 72 00 00 00 69 00 00 00 00 00 16 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ MRUListEx: 00 00 00 00 FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ MRUListEx: 00 00 00 00 FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0: 19 00 2F 43 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local 0x00000004
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local 0x41200001
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local "{137E7700-3573-11CF-AE69-08002B2E1262}"
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local 0x00000004
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local 0x00000001
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local 0x00000010
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 18 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 00 00 00 00 10 01 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 0E 00 00 00 00 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 04 00 00 00 00 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 0C 00 00 00 50 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 00 00 00 00 01 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local 0x00000000
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local "{00000000-0000-0000-0000-000000000000}"
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local 0x00000000
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local 0x00000001
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590 \ Shell \ KnownFolderDerivedFolderType: "{50000098-004F-4462-BB63 -71042380B109} "
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590 \ Shell \ SniffedFolderType: "Generic"
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0 \ NodeSlot: 0x00000A1E
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0 \ MRUListEx: FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0: 50 00 31 00 00 00 00 00 1B 41 65 00 10 00 00 61 72 00 69 00 00 00 3A 00 08 00 04 00 00 41 FA 5E BE 1B 1B 41 65 00 2A 00 00 00 17 24 01 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 61 00 72 00 00 00 69 00 00 00 00 00 16 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ MRUListEx: 00 00 00 00 FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ MRUListEx: 00 00 00 00 FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0: 19 00 2F 43 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local 0x00000004
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local 0x41200001
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local "{137E7700-3573-11CF-AE69-08002B2E1262}"
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local 0x00000004
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local 0x00000001
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local 0x00000010
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 18 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 00 00 00 00 10 01 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 0E 00 00 00 00 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 04 00 00 00 00 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 0C 00 00 00 50 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 30 00 25 00 00 00 00 10 00 00 02 60 00 00 00 00 00 00 00 00 01 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local 0x00000000
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local "{00000000-0000-0000-0000-000000000000}"
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local 0x00000000
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local 0x00000001
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590 \ Shell \ KnownFolderDerivedFolderType: "{50000098-004F-4462-BB63-71042380B109}"
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590 \ Shell \ SniffedFolderType: "Generic"

 

After cleaning with the program by Juergen Haage it looked like this

 

Keys deleted: 6

HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0

Values deleted: 12

HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0 \ NodeSlot: 0x00000A1E
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0 \ MRUListEx: FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0: 50 00 31 00 00 00 00 00 1B 41 65 00 10 00 00 61 72 00 69 00 00 00 3A 00 08 00 04 00 00 41 FA 5E BE 1B 1B 41 65 00 2A 00 00 00 17 24 01 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 61 00 72 00 00 00 69 00 00 00 00 00 16 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ MRUListEx: 00 00 00 00 FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ MRUListEx: 00 00 00 00 FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0: 19 00 2F 43 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0 \ NodeSlot: 0x00000A1E
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0 \ MRUListEx: FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ 0: 50 00 31 00 00 00 00 00 1B 41 65 00 10 00 00 61 72 00 69 00 00 00 3A 00 08 00 04 00 00 41 FA 5E BE 1B 1B 41 65 00 2A 00 00 00 17 24 01 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 61 00 72 00 00 00 69 00 00 00 00 00 16 00 00 00
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0 \ MRUListEx: 00 00 00 00 FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ MRUListEx: 00 00 00 00 FF FF FF FF
HKU \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ BagMRU \ 1 \ 0: 19 00 2F 43 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

WARNING - I have replaced some pairs of numbers such as A5, F1, etc. by 00!

 

 

Another program by Nir Sofer "ShellBagsView" helped me then these bags-locations for this folder to find (2590)

HKEY_CLASSES_ROOT \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590
HKEY_CURRENT_USER \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590
HKEY_USERS \ S-1-5-21 / ̴ ̴ ̴/-1000 \ Software \ Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590
HKEY_USERS \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590
HKEY_USERS \ S-1-5-21 / ̴ ̴ ̴/-1000_Classes \ Local Settings \ Software \ Microsoft \ Windows \ Shell \ Bags \ 2590

- Amazing here is that the entries in the bags when deleting but apparently play no role and continue to be found in the registry.

 

Finally - I do not blame you CCleaner - he (still) not being able to eliminate these signs - and have never done! Communication difficulties, there are in my native language - they multiply, however, when you are in the foreign language is not fit to resort to cumbersome and a dictionary and what they have learned from days gone by have.

 

But one thing remains - there is a feeling, a feeling for what people are doing to each other - and this is not been a good one.

Edited by Nergal
added code tags for easier reading and formatted as per untranslated version
Link to comment
Share on other sites

Thank you once again codon for sticking with this and continuing to make good progress, despite the criticisms. I understand you are trying to write in a foreign language which cannot be easy.

 

Just rise above and please continue. You are helping piriform and everyday users of CCleaner, for which I am grateful.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.