From 41a3acaa1b644badedf7211afd0daecc9b147083 Mon Sep 17 00:00:00 2001 From: Daniel Berteaud Date: Mon, 10 Dec 2018 21:52:18 +0100 Subject: [PATCH] First version of the package, heavily based on the one from TranquilIT --- WAPT/control | 32 + WAPT/icon.png | Bin 0 -> 4717 bytes WAPT/wapt.psproj | 295 + ccleaner.ini | 18 + ccsetup550_slim.exe | 3 + setup.py | 82 + winapp2.ini | 19424 ++++++++++++++++++++++++++++++++++++++++++ 7 files changed, 19854 insertions(+) create mode 100644 WAPT/control create mode 100644 WAPT/icon.png create mode 100644 WAPT/wapt.psproj create mode 100644 ccleaner.ini create mode 100644 ccsetup550_slim.exe create mode 100644 setup.py create mode 100644 winapp2.ini diff --git a/WAPT/control b/WAPT/control new file mode 100644 index 0000000..b23fd72 --- /dev/null +++ b/WAPT/control @@ -0,0 +1,32 @@ +package : fws-ccleaner +version : 5.50.0.6911-1 +architecture : all +section : base +priority : optional +maintainer : Daniel Berteaud +description : Clean and optimize Windows +depends : +conflicts : +maturity : PROD +locale : all +target_os : windows +min_os_version : 5.1 +max_os_version : +min_wapt_version : 1.5 +sources : +installed_size : +impacted_process : ccleaner.exe,ccleaner64.exe +description_fr : Outils de nettoyage et d'optimisation de Windows +description_pl : +description_de : +description_es : +audit_schedule : +editor : Piriform +keywords : +licence : +homepage : http://www.piriform.com/ccleaner/ +package_uuid : +signer : Daniel Berteaud +signer_fingerprint: +signature_date : +signed_attributes : \ No newline at end of file diff --git a/WAPT/icon.png b/WAPT/icon.png new file mode 100644 index 0000000000000000000000000000000000000000..26a4dad924a19af8b83b66964ab05d3f65b23248 GIT binary patch literal 4717 zcmV-z5|ZtSP)ALI((t0b>F%vc0xr?InEd#_r%(BAfumu<+gms{ULv!CVJ>5OicXxGFW#-!-JsJrR!uhAGJGwHz`reoMzV`}= z2re~<2oW!Q6_OZ8E`$^yp^{3bhQ~7FW97x9m0pyB0|9gCzNRK`U8ru=>R4Z&<_oBr zq96kW6jVNJ=JyT!FhI3C0RRwz$g-+tt}yn>AE#b;Y2wwxF8;{Zb$bG`#Y}Q>M;U}rXk|x(OeqP$~`1W0#wVz#o^(% z9{cssV~<5wb+6sCt9SEe!*GjyUKa9XS3nBjToNEtP<5eCXGR@(j8tNA{EcI0Up!o> zm>WL(`L%c47HREp`8*6+ZP802yEH>JOx$tOqmyU<=jTID{ASJ0Yp%X^pO0)Om2wsr z0R$p~LLe0)0ANItArTQs0&;{z#igpDh}ztmS}MQ(_%qWZ6Kg;Jxs3-u6K!ol#2Wt} z#Pl9O7q|g1OQqrGes}B#Ka52JyYIQ(%PV|-PD%-koew1d0TCeqoS%e%005)}AOrv+ z!MUcY?&i*P$$as#XH0)+`+fJVzVw7f0=lRy9xs5Z;;{Sp8OrL0990Ei@#G^>u|34~+e(?`#q9Gcwt)vs;2>n`2n z`Jl$t_bVT^|rkB z@I(G+?1}>iRK_mB&@$gd6R*8G`pchfy`m=;^xDNDA_52m0I`gy_BRAXhTP^(-V|k1 zS`HBbBGXjGtLs58B9IW1h4Q!gb%RD9BQxlCTP1iorQQgco_K62nK}96A4j^nI@Yee zI7;dY*NB*#pMUGWe%fxh+d3MYvbhojs_B%L8DangP@Y?IQbn^=O{UYOvMD4fDjI%& zeKhLvxztF&QssB$)}zJ%NGDe3R)j56W5L96%cyfJ)wP}R+1E~<{>@{N*86-$5YMYy zU5+23Xzt3Z8!X`Wjg?i$J}0U^5Y`|gHK*tZ+Q{9&0Q*P?rDGiu}6Ea+t;^i zC$jS)tEq<&v&rP(uYNJm6?eH5$99NnTbLvf5D>_knvq~>WOiY4{>aQ+aL?XVH{aaY z*=a;0itZBCYAKsbj7}t;`t|pd?%y`-uAwJJfo`IwMl|9t{b{PM$hhJpJaXI}dQnB1u35bbeb=O+*C5%E`slRN|HSWcR;( zW78)-(b(4J)^$Z;KtMo}VBPj@f9hTPt!GmOh_nP)r`J4vcC!7+0KS~#m$7n3FPv|Ij+d=hbLTV_U-2myQfaho8TN25*VC1rf;+ zwd{yMylOR(0*S=};Tk^nJ3lXzz# zW$fN@%@@89Fam!V&L5pDHyW%ftZs}4B8KWn`HzRjkIvb;BCm^DFZ|)SXZrLFg`;=( zud34!xIjW_akEgGO=iYZnXzJ_5(-vKQ*d5;auooil&NeuN%SeGiNg=79C=Aa>@SVbT$3zlCCJpVr9Y<6$cJ6%Cq2c* z?sHGy+22vGf~eTVqB)t&ji(l8%&LsXn{NB~)qD1}t{G@*X?Avl07%4vM4>#9UJ8HgV|6{NpE$KNQw2?jLKUilY?8vQPM4}_Ax#@V z(urvYTemh8PlQwbOO@Q4gLC8Q%)F@T9o@};b71$Lo$q-mUJv6 zK`3Y;%fTCY+k4|XH{9@CIop_i`-ZKV&wqM%YyUvl@cTR-MNuy4c~l}2oG-mQvM%hE zmP4EaNg$GNk$MP#&@NTZ8L@M&x?Z_xSG2sPvmwr|})i~|yT*5f{8%cPj^f_ELIhq`*T#}F=83F+U0U?p9L3gu0KQ?!0zIfZ# zn4%lYCg)P_Q3U|otZ;`b3VJKL3^7 zgQ9eNhO5)@)yEc%!E!Xgf~l%M3qg~^`X;pz^UoX|UE@w{?})nHLAdNtiGY_X3_uEw z+#yLMfdN>SQ*g0zrxD!U?`{uTnf!IT)^`t14MQav>>o)bQ&j?t4W`>>-D-##4X(l} z@s2V-yh#h&q4uRveBKTpUo=)l);;+6sfgR&+gjYS_fsxi{|G>cC`g5yQ4n-4yKvQJzf|0|m{eWM$-3w)*F{B`VCLc`03B{;Sr7rKgbG z5J_$nQIS@sj2_~o1@JfOD-~Lu8JAg_B3wjD3uFP zHp8J{sbZrm5RL^)GYLoK>#iA4HRR;19Y#nZmr`Itw5pZP&G(4Oh0Q^|4T6D3e;`RU?ZMj=+ee)ks--tqc>eDBqt|16W3 zL&Qs>xw!ICiO8kvb=|#bSI%c>#l>79k**X=k>;jK5j928W4@)ug~H@~&y}kKe#c78 zV#ol;ah6ikLlf?Xu5eqglz=XD>B`*bWVI^Iitt*AsK4>x!OwcD<(WfIdnd+@Joum* zi>|+Z|C;?bw)U;A)hJi$p#pUEoz!b838Qa7=IR4z+Y}i>sPTRoUG5M5UOToXi)q<%N>#mIJ%j^!L5| zqaU^sw9n3T1;dqmIq~=tCw}q>H$nq@cU^hgt*x7`Qt&-QDfi!hKO*K5^Fxn6Gcsp} zd+LC&z9E3R$}|;h+sqfUiy5<6Riugvc-wo;!FSS=Q?6)zL%fBXD1o`$ESpMHbJMe< zv$=xu_VB#7ch}vY{amO%_W0lbL%(CGmL*F?mdhB0LYFVl=GAi}BY*nEe;TW^1No!^7HuriA!M{~Q}9>Xx0v|T<= z)#7!rU?3W>7LuwbPyM}k8RYMQ4mCd1*WQhq3#`P$)^+g7bUUj`u>4Y7_bSGi7|+N-IhROReLr=M`F zXh&q{wJjc>=xI}ZUPeyEs+Kd!v=%V@9@oM`Qq?`WCf!sjyLar| zx_ui{@%P{O=K5%Txm1!Qi9iraSu+plRJl1jD`sb;U9G=%m#VujI7S2r1S74te*E0= zV{r{bigFdhEsC#_HqSmfIBrwR+WL*#qMHWlv*|*mV#PhKOnSjFi7`{J*i|VFFGJzZ zm5M`iMXh!FEw|qluB$urt^3*3M4VxfBuYsHl28J1ATCJ&aUe~?yd!#d>@e!;YBo)+ ziAnQ$`)|7Wk)EedH&5>Kh6RNg|MdM8rwduB8Mn$wtY9EP6eC z+qe1r{u+|yLQw&zZ);ogna@o>@WY7CY=zZ&DvAKcAgaRkimOVHStw>_E5AOz=mgxm z_IK6QySP)02Hd66;{1|1mJ9b?vDurP`|0hU^vuugYmOJEW+i}>(m|30gd~Urk(9&{ zRiY`|YB_LwLwE0rO~VW34PfxKSD(J?Q_=YasjCVym5?#i5EaH4pn|9(L!dHIMT$vK zM%}syy82f6i~u`!E^94Ow`I3zYJa@dSE=L^2|9n+a6lp{fw+{MKuXCG6iMe4w&&qT zcHVi1Ti0>r99l*P(7bNLz`cKW=Kk+AN^+PWU5$m(zKeJ zdr$X+h>W1I>7Ijg$4_Pt{a--SY$QcW2~eYlp%h3AnF7cqDF6zAS}OJubt9ouVfoxN z5Ftax08s)EkdQq>7DHm5A@5?Fi?(Xeh|K~r<%~sxg z)2nGVkpiS3N@9#55-=1BGDKP_8nD(6Ap{0;xzQ(pKmZVtpxQx?xM}bnHQda`J3OQ)2DrkDj6Z7LdY0Hl88(}h5!oS3Zj){ zbiPFa0Kk`90+L7)GASiTQV4{@69HrOSH8OcD_?17Zo>EGvP<+B0ny?7^x>CY`R;ej zBS-2{si-K4bVLL|h6>a^Yn26DJmYe0000P*Bmf8?k|Y2nNH<{F;pu3!@7^!%{lXVp zJ34CJ*bfDCfhQuHi_x=Z-gxjwV~;)>u3Cnwlt~fjD2Qr}8)OK;2mk>AFE$bqSHKYm z0wSFh5;6&r*0106<$Jf?a$9|4qjJ$>tYG@kJ~bc`KzerO^h+bvi}bK_li46NT^1cUe?uNf}e z$tMCtvr$#3}(kC9KpQ+ z8bGZd=K$CM6#z}u-OWw0wf)h)fwt}2+Pk{yu(1^-&p!-rtH977+( v_r4uKL_&y_. +# +# ----------------------------------------------------------------------- +from setuphelpers import * +import requests,BeautifulSoup + +uninstallkey = [] + +def install(): + print('Installing CCleaner') + + major_version = control['version'].split('-',1)[0].split('.',2)[0] + minor_version = control['version'].split('-',1)[0].split('.',2)[1] + + version = major_version + minor_version + min_version_registry = major_version + '.' + minor_version + + install_exe_if_needed('ccsetup%s_slim.exe' % version ,silentflags="/S",key="CCleaner",min_version=min_version_registry) + + print("Override settings") + filecopyto("ccleaner.ini", makepath(install_location("CCleaner"),"ccleaner.ini")) + #https://singularlabs.com/software/ccenhancer/download-ccenhancer/ + filecopyto("winapp2.ini", makepath(install_location("CCleaner"),"winapp2.ini")) + + print('Remove desktop shortcut') + remove_desktop_shortcut('CCleaner') + +def session_setup(): + registry_set(HKEY_CURRENT_USER,'software\\Piriform\\CCleaner', 'Monitoring','0') + registry_set(HKEY_CURRENT_USER,'software\\Piriform\\CCleaner', 'SystemMonitoring','0') + registry_set(HKEY_CURRENT_USER,'software\\Piriform\\CCleaner', 'UpdateCheck','0') + registry_set(HKEY_CURRENT_USER,'software\\Piriform\\CCleaner', 'RunICS','0') + registry_set(HKEY_CURRENT_USER,'software\\Piriform\\CCleaner', 'CheckTrialOffer','0') + +def update_package(): + + page = requests.get('https://www.ccleaner.com/fr-fr/ccleaner/download/slim',headers={'User-Agent':'Mozilla/5.0 (Windows NT 6.1; Win64; x64)'}).text + bs = BeautifulSoup.BeautifulSoup(page) + download = bs.find('p', attrs={"class": u"fs-13"}).a["href"] + filename = download.rsplit('/',1)[1] + + # on ne telecharge que si on ne l'a pas deja + if not isfile(filename): + wget(download, filename) + else: + print(u'Setup %s already downloaded' % filename) + + for fn in glob.glob('*.exe'): + if fn != filename : + print('Removing old exe %s' % fn) + remove_file(fn) + + vers = get_file_properties(filename)['ProductVersion'] + os.chdir(os.path.dirname(__file__)) + from waptpackage import PackageEntry + pe = PackageEntry() + pe.load_control_from_wapt(os.getcwd()) + pe.version = vers + '-0' + pe.save_control_to_wapt(os.getcwd()) + + +if __name__ == '__main__': + update_package() + diff --git a/winapp2.ini b/winapp2.ini new file mode 100644 index 0000000..7b33e69 --- /dev/null +++ b/winapp2.ini @@ -0,0 +1,19424 @@ +; Version: 181209 +; # of entries: 2,051 +; +; Winapp2 is fully licensed under the CC-BY-SA-4.0 license agreement. Please refer to our license agreement before using Winapp2: https://github.com/MoscaDotTo/Winapp2/blob/master/License.md +; If you plan on modifying, distributing, and/or hosting Winapp2 for your own program or website, please ask first. +; +; You can get the latest Winapp2 here: https://github.com/MoscaDotTo/Winapp2 +; Any contributions are appreciated. Please refer to our readme to learn to make your own entries here: https://github.com/MoscaDotTo/Winapp2/blob/master/README.md +; Is CCleaner taking too long to load with Winapp2? Then download our Winapp2ool and use the trim function to remove unneeded entries in Winapp2. https://github.com/MoscaDotTo/Winapp2/blob/master/Tools/beta/winapp2ool.exe +; +; Chrome/Chromium based browsers. + +[Application Cache *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\Application Cache|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\Application Cache|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Application Cache|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Application Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\Application Cache|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Application Cache|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\Application Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\Application Cache|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Application Cache|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Application Cache|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Application Cache|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Application Cache|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\Application Cache|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Application Cache|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Application Cache|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\Application Cache|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\Application Cache|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\Application Cache|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\Application Cache|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Application Cache|*.*|RECURSE + +[ART *] +LangSecRef=3029 +DetectFile=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%CommonProgramFiles%\Microsoft\ART\Backup\Google Chrome\*|*.tmp|RECURSE +FileKey2=%CommonProgramFiles%\Microsoft\ART\Backup\Google Chrome\*|Preferences.bak + +[Backup *] +LangSecRef=3029 +DetectFile=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%LocalAppData%\Google\Chrome*\Application|old_chrome.exe +FileKey2=%ProgramFiles%\Google\Chrome*\Application|old_chrome.exe + +[Blob Storage *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\blob_storage|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\blob_storage|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\blob_storage|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\blob_storage|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\blob_storage|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\blob_storage|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\blob_storage|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\blob_storage|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\blob_storage|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\blob_storage|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\blob_storage|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\blob_storage|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\blob_storage|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\blob_storage|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\blob_storage|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\blob_storage|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\blob_storage|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\blob_storage|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\blob_storage|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\blob_storage|*.*|RECURSE + +[Bookmarks Backup *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave|*Bookmarks.bak +FileKey2=%AppData%\Opera Software\Opera*|*Bookmarks.bak +FileKey3=%LocalAppData%\7Star\7Star\User Data\*|*Bookmarks.bak +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|*Bookmarks.bak +FileKey5=%LocalAppData%\Amigo\User Data\*|*Bookmarks.bak +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|*Bookmarks.bak +FileKey7=%LocalAppData%\CentBrowser\User Data\*|*Bookmarks.bak +FileKey8=%LocalAppData%\Chromium\User Data\*|*Bookmarks.bak +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|*Bookmarks.bak +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|*Bookmarks.bak +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|*Bookmarks.bak +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|*Bookmarks.bak +FileKey13=%LocalAppData%\Flock\User Data\*|*Bookmarks.bak +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|*Bookmarks.bak +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|*Bookmarks.bak +FileKey16=%LocalAppData%\RockMelt\User Data\*|*Bookmarks.bak +FileKey17=%LocalAppData%\Slimjet\User Data\*|*Bookmarks.bak +FileKey18=%LocalAppData%\Torch\User Data\*|*Bookmarks.bak +FileKey19=%LocalAppData%\Vivaldi\User Data\*|*Bookmarks.bak +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|*Bookmarks.bak + +[Bookmarks Icons *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +Warning=This will delete all the icons of your bookmarks. The icons will be rebuilt as websites are manually re-visited. +FileKey1=%AppData%\brave|Favicons +FileKey2=%AppData%\Opera Software\Opera*|Favicons +FileKey3=%LocalAppData%\7Star\7Star\User Data\*|Favicons +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|Favicons +FileKey5=%LocalAppData%\Amigo\User Data\*|Favicons +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|Favicons +FileKey7=%LocalAppData%\CentBrowser\User Data\*|Favicons +FileKey8=%LocalAppData%\Chromium\User Data\*|Favicons +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|Favicons +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|Favicons +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|Favicons +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|Favicons +FileKey13=%LocalAppData%\Flock\User Data\*|Favicons +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|Favicons +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|Favicons +FileKey16=%LocalAppData%\RockMelt\User Data\*|Favicons +FileKey17=%LocalAppData%\Slimjet\User Data\*|Favicons +FileKey18=%LocalAppData%\Torch\User Data\*|Favicons +FileKey19=%LocalAppData%\Vivaldi\User Data\*|Favicons +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|Favicons + +[Browser Exit Codes *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\Amigo +Detect3=HKCU\Software\BraveSoftware\Brave-Browser +Detect4=HKCU\Software\CentBrowser +Detect5=HKCU\Software\Chromium\PreferenceMACs +Detect6=HKCU\Software\CocCoc\Browser +Detect7=HKCU\Software\Comodo\Dragon +Detect8=HKCU\Software\Epic Privacy Browser +Detect9=HKCU\Software\Slimjet +Detect10=HKCU\Software\Torch +Detect11=HKCU\Software\Vivaldi +Detect12=HKCU\Software\Yandex\YandexBrowser +DetectFile=%LocalAppData%\Google\Chrome* +Default=False +RegKey1=HKCU\Software\7Star\7Star\BrowserExitCodes +RegKey2=HKCU\Software\Amigo\BrowserExitCodes +RegKey3=HKCU\Software\BraveSoftware\Brave-Browser\BrowserExitCodes +RegKey4=HKCU\Software\CentBrowser\BrowserExitCodes +RegKey5=HKCU\Software\Chromium\BrowserExitCodes +RegKey6=HKCU\Software\CocCoc\Browser\BrowserExitCodes +RegKey7=HKCU\Software\Comodo\Dragon\BrowserExitCodes +RegKey8=HKCU\Software\Epic Privacy Browser\BrowserExitCodes +RegKey9=HKCU\Software\Google\Chrome SxS\BrowserExitCodes +RegKey10=HKCU\Software\Google\Chrome\BrowserExitCodes +RegKey11=HKCU\Software\Slimjet\BrowserExitCodes +RegKey12=HKCU\Software\Torch\BrowserExitCodes +RegKey13=HKCU\Software\Vivaldi\BrowserExitCodes +RegKey14=HKCU\Software\Yandex\YandexBrowser\BrowserExitCodes + +[BrowserMetrics *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave|BrowserMetrics-spare.pma +FileKey2=%AppData%\brave\BrowserMetrics|*.*|RECURSE +FileKey3=%AppData%\Opera Software\Opera*|BrowserMetrics-spare.pma +FileKey4=%AppData%\Opera Software\Opera*\BrowserMetrics|*.*|RECURSE +FileKey5=%LocalAppData%\7Star\7Star\User Data|BrowserMetrics-spare.pma +FileKey6=%LocalAppData%\7Star\7Star\User Data\BrowserMetrics|*.*|RECURSE +FileKey7=%LocalAppData%\360Browser\Browser\User Data|BrowserMetrics-spare.pma +FileKey8=%LocalAppData%\360Browser\Browser\User Data\BrowserMetrics|*.*|RECURSE +FileKey9=%LocalAppData%\Amigo\User Data|BrowserMetrics-spare.pma +FileKey10=%LocalAppData%\Amigo\User Data\BrowserMetrics|*.*|RECURSE +FileKey11=%LocalAppData%\BraveSoftware\Brave-Browser\User Data|BrowserMetrics-spare.pma +FileKey12=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\BrowserMetrics|*.*|RECURSE +FileKey13=%LocalAppData%\CentBrowser\User Data|BrowserMetrics-spare.pma +FileKey14=%LocalAppData%\CentBrowser\User Data\BrowserMetrics|*.*|RECURSE +FileKey15=%LocalAppData%\Chromium\User Data|BrowserMetrics-spare.pma +FileKey16=%LocalAppData%\Chromium\User Data\BrowserMetrics|*.*|RECURSE +FileKey17=%LocalAppData%\CocCoc\Browser\User Data|BrowserMetrics-spare.pma +FileKey18=%LocalAppData%\CocCoc\Browser\User Data\BrowserMetrics|*.*|RECURSE +FileKey19=%LocalAppData%\Comodo\Dragon\User Data|BrowserMetrics-spare.pma +FileKey20=%LocalAppData%\Comodo\Dragon\User Data\BrowserMetrics|*.*|RECURSE +FileKey21=%LocalAppData%\Coowon\Coowon\User Data|BrowserMetrics-spare.pma +FileKey22=%LocalAppData%\Coowon\Coowon\User Data\BrowserMetrics|*.*|RECURSE +FileKey23=%LocalAppData%\Epic Privacy Browser\User Data|BrowserMetrics-spare.pma +FileKey24=%LocalAppData%\Epic Privacy Browser\User Data\BrowserMetrics|*.*|RECURSE +FileKey25=%LocalAppData%\Flock\User Data|BrowserMetrics-spare.pma +FileKey26=%LocalAppData%\Flock\User Data\BrowserMetrics|*.*|RECURSE +FileKey27=%LocalAppData%\Google\Chrome*\User Data|BrowserMetrics-spare.pma +FileKey28=%LocalAppData%\Google\Chrome*\User Data\BrowserMetrics|*.*|RECURSE +FileKey29=%LocalAppData%\MapleStudio\ChromePlus\User Data|BrowserMetrics-spare.pma +FileKey30=%LocalAppData%\MapleStudio\ChromePlus\User Data\BrowserMetrics|*.*|RECURSE +FileKey31=%LocalAppData%\RockMelt\User Data|BrowserMetrics-spare.pma +FileKey32=%LocalAppData%\RockMelt\User Data\BrowserMetrics|*.*|RECURSE +FileKey33=%LocalAppData%\Slimjet\User Data|BrowserMetrics-spare.pma +FileKey34=%LocalAppData%\Slimjet\User Data\BrowserMetrics|*.*|RECURSE +FileKey35=%LocalAppData%\Torch\User Data|BrowserMetrics-spare.pma +FileKey36=%LocalAppData%\Torch\User Data\BrowserMetrics|*.*|RECURSE +FileKey37=%LocalAppData%\Vivaldi\User Data|BrowserMetrics-spare.pma +FileKey38=%LocalAppData%\Vivaldi\User Data\BrowserMetrics|*.*|RECURSE +FileKey39=%LocalAppData%\Yandex\YandexBrowser\User Data|BrowserMetrics-spare.pma +FileKey40=%LocalAppData%\Yandex\YandexBrowser\User Data\BrowserMetrics|*.*|RECURSE + +[Chrome Temps *] +LangSecRef=3029 +DetectFile=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%ProgramFiles%\Google\Chrome*\Temp|*.*|RECURSE + +[Crash Reports *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\Crashpad\reports|*.* +FileKey2=%AppData%\Opera Software\Opera*\Crash Reports\reports|*.* +FileKey3=%LocalAppData%\7Star\7Star\User Data\Crashpad\reports|*.* +FileKey4=%LocalAppData%\360Browser\Browser\User Data\Crashpad\reports|*.* +FileKey5=%LocalAppData%\Amigo\User Data\Crashpad\reports|*.* +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\Crashpad\reports|*.* +FileKey7=%LocalAppData%\CentBrowser\User Data\Crashpad\reports|*.* +FileKey8=%LocalAppData%\Chromium\User Data\Crashpad\reports|*.* +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\Crashpad\reports|*.* +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\Crashpad\reports|*.* +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\Crashpad\reports|*.* +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\Crashpad\reports|*.* +FileKey13=%LocalAppData%\Flock\User Data\Crashpad\reports|*.* +FileKey14=%LocalAppData%\Google\Chrome*\User Data\Crashpad\reports|*.* +FileKey15=%LocalAppData%\Google\CrashReports|*.* +FileKey16=%LocalAppData%\MapleStudio\ChromePlus\User Data\Crashpad\reports|*.* +FileKey17=%LocalAppData%\RockMelt\User Data\Crashpad\reports|*.* +FileKey18=%LocalAppData%\Slimjet\User Data\Crashpad\reports|*.* +FileKey19=%LocalAppData%\Torch\User Data\Crashpad\reports|*.* +FileKey20=%LocalAppData%\Vivaldi\User Data\Crashpad\reports|*.* +FileKey21=%LocalAppData%\Yandex\YandexBrowser\User Data\Crashpad\reports|*.* + +[Data Reduction Proxy *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE + +[Extensions Databases *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\IndexedDB|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\IndexedDB|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\IndexedDB|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\IndexedDB|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\IndexedDB|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\IndexedDB|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\IndexedDB|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\IndexedDB|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\IndexedDB|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\IndexedDB|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\IndexedDB|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\IndexedDB|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\IndexedDB|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\IndexedDB|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\IndexedDB|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\IndexedDB|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\IndexedDB|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\IndexedDB|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\IndexedDB|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\IndexedDB|*.*|RECURSE + +[Extensions State *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\Extension State|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\Extension State|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Extension State|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Extension State|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\Extension State|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Extension State|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\Extension State|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\Extension State|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Extension State|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Extension State|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Extension State|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Extension State|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\Extension State|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Extension State|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Extension State|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\Extension State|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\Extension State|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\Extension State|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\Extension State|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Extension State|*.*|RECURSE + +[FlashPlayer AssetCache *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE + +[FlashPlayer SharedObjects *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE +ExcludeKey1=FILE|%AppData%\brave\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey2=FILE|%AppData%\Opera Software\Opera*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey3=FILE|%LocalAppData%\7Star\7Star\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey4=FILE|%LocalAppData%\360Browser\Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey5=FILE|%LocalAppData%\Amigo\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey6=FILE|%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey7=FILE|%LocalAppData%\CentBrowser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey8=FILE|%LocalAppData%\Chromium\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey9=FILE|%LocalAppData%\CocCoc\Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey10=FILE|%LocalAppData%\Comodo\Dragon\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey11=FILE|%LocalAppData%\Coowon\Coowon\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey12=FILE|%LocalAppData%\Epic Privacy Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey13=FILE|%LocalAppData%\Flock\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey14=FILE|%LocalAppData%\Google\Chrome*\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey15=FILE|%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey16=FILE|%LocalAppData%\RockMelt\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey17=FILE|%LocalAppData%\Slimjet\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey18=FILE|%LocalAppData%\Torch\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey19=FILE|%LocalAppData%\Vivaldi\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol +ExcludeKey20=FILE|%LocalAppData%\Yandex\YandexBrowser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol + +[Google Cloud Messaging *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\GCM Store|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\GCM Store|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\GCM Store|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\GCM Store|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\GCM Store|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\GCM Store|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\GCM Store|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\GCM Store|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\GCM Store|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\GCM Store|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\GCM Store|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\GCM Store|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\GCM Store|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\GCM Store|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\GCM Store|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\GCM Store|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\GCM Store|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\GCM Store|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\GCM Store|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\GCM Store|*.*|RECURSE + +[GPU Cache *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\GPUCache|*.* +FileKey2=%AppData%\Opera Software\Opera*\GPUCache|*.* +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\GPUCache|*.* +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\GPUCache|*.* +FileKey5=%LocalAppData%\Amigo\User Data\*\GPUCache|*.* +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\GPUCache|*.* +FileKey7=%LocalAppData%\CentBrowser\User Data\*\GPUCache|*.* +FileKey8=%LocalAppData%\Chromium\User Data\*\GPUCache|*.* +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\GPUCache|*.* +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\GPUCache|*.* +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\GPUCache|*.* +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\GPUCache|*.* +FileKey13=%LocalAppData%\Flock\User Data\*\GPUCache|*.* +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\GPUCache|*.* +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\GPUCache|*.* +FileKey16=%LocalAppData%\RockMelt\User Data\*\GPUCache|*.* +FileKey17=%LocalAppData%\Slimjet\User Data\*\GPUCache|*.* +FileKey18=%LocalAppData%\Torch\User Data\*\GPUCache|*.* +FileKey19=%LocalAppData%\Vivaldi\User Data\*\GPUCache|*.* +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\GPUCache|*.* + +[HTML5 Storage *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\File System|*.*|REMOVESELF +FileKey2=%AppData%\Opera Software\Opera*\File System|*.*|REMOVESELF +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\File System|*.*|REMOVESELF +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\File System|*.*|REMOVESELF +FileKey5=%LocalAppData%\Amigo\User Data\*\File System|*.*|REMOVESELF +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\File System|*.*|REMOVESELF +FileKey7=%LocalAppData%\CentBrowser\User Data\*\File System|*.*|REMOVESELF +FileKey8=%LocalAppData%\Chromium\User Data\*\File System|*.*|REMOVESELF +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\File System|*.*|REMOVESELF +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\File System|*.*|REMOVESELF +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\File System|*.*|REMOVESELF +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\File System|*.*|REMOVESELF +FileKey13=%LocalAppData%\Flock\User Data\*\File System|*.*|REMOVESELF +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\File System|*.*|REMOVESELF +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\File System|*.*|REMOVESELF +FileKey16=%LocalAppData%\RockMelt\User Data\*\File System|*.*|REMOVESELF +FileKey17=%LocalAppData%\Slimjet\User Data\*\File System|*.*|REMOVESELF +FileKey18=%LocalAppData%\Torch\User Data\*\File System|*.*|REMOVESELF +FileKey19=%LocalAppData%\Vivaldi\User Data\*\File System|*.*|REMOVESELF +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\File System|*.*|REMOVESELF + +[Internet Cache *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey2=%AppData%\Opera Software\Opera*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey3=%LocalAppData%\7Star\7Star\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey5=%LocalAppData%\Amigo\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey7=%LocalAppData%\CentBrowser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey8=%LocalAppData%\Chromium\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey13=%LocalAppData%\Flock\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey16=%LocalAppData%\RockMelt\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey17=%LocalAppData%\Slimjet\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey18=%LocalAppData%\Torch\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey19=%LocalAppData%\Vivaldi\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs + +[Internet History *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave|History +FileKey2=%AppData%\Opera Software\Opera*|History +FileKey3=%LocalAppData%\7Star\7Star\User Data\*|History +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|History +FileKey5=%LocalAppData%\Amigo\User Data\*|History +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|History +FileKey7=%LocalAppData%\CentBrowser\User Data\*|History +FileKey8=%LocalAppData%\Chromium\User Data\*|History +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|History +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|History +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|History +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|History +FileKey13=%LocalAppData%\Flock\User Data\*|History +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|History +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|History +FileKey16=%LocalAppData%\RockMelt\User Data\*|History +FileKey17=%LocalAppData%\Slimjet\User Data\*|History +FileKey18=%LocalAppData%\Torch\User Data\*|History +FileKey19=%LocalAppData%\Vivaldi\User Data\*|History +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|History + +[Jump List Icons *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\JumpListIcons*|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\JumpListIcons*|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\JumpListIcons*|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\JumpListIcons*|*.*|RECURSE + +[Local Storage *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\Local Storage|http*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\Local Storage|http*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Local Storage|http*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Local Storage|http*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\Local Storage|http*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Local Storage|http*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\Local Storage|http*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\Local Storage|http*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Local Storage|http*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Local Storage|http*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Local Storage|http*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Local Storage|http*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\Local Storage|http*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Local Storage|http*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Local Storage|http*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\Local Storage|http*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\Local Storage|http*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\Local Storage|http*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\Local Storage|http*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Local Storage|http*.*|RECURSE + +[Logs *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave|LOG;LOG.old|RECURSE +FileKey2=%AppData%\Opera Software\Opera*|LOG;LOG.old|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\Application|debug.log +FileKey4=%LocalAppData%\7Star\7Star\User Data\*|LOG;LOG.old|RECURSE +FileKey5=%LocalAppData%\360Browser\Browser\Application|debug.log +FileKey6=%LocalAppData%\360Browser\Browser\User Data\*|LOG;LOG.old|RECURSE +FileKey7=%LocalAppData%\Amigo\Application|debug.log +FileKey8=%LocalAppData%\Amigo\User Data\*|LOG;LOG.old|RECURSE +FileKey9=%LocalAppData%\Brave|debug.log +FileKey10=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|LOG;LOG.old|RECURSE +FileKey11=%LocalAppData%\CentBrowser\Application|debug.log +FileKey12=%LocalAppData%\CentBrowser\User Data\*|LOG;LOG.old|RECURSE +FileKey13=%LocalAppData%\Chromium\Application|debug.log +FileKey14=%LocalAppData%\Chromium\User Data\*|LOG;LOG.old|RECURSE +FileKey15=%LocalAppData%\CocCoc\Browser\Application|debug.log +FileKey16=%LocalAppData%\CocCoc\Browser\User Data\*|LOG;LOG.old|RECURSE +FileKey17=%LocalAppData%\Comodo\Dragon\User Data\*|LOG;LOG.old|RECURSE +FileKey18=%LocalAppData%\Coowon\Coowon\Application|debug.log +FileKey19=%LocalAppData%\Coowon\Coowon\User Data\*|LOG;LOG.old|RECURSE +FileKey20=%LocalAppData%\Epic Privacy Browser\Application|debug.log +FileKey21=%LocalAppData%\Epic Privacy Browser\User Data\*|LOG;LOG.old|RECURSE +FileKey22=%LocalAppData%\Flock\Application|debug.log +FileKey23=%LocalAppData%\Flock\User Data\*|LOG;LOG.old|RECURSE +FileKey24=%LocalAppData%\Google\Chrome Cleanup Tool|*.log +FileKey25=%LocalAppData%\Google\Chrome*\Application|debug.log +FileKey26=%LocalAppData%\Google\Chrome*\User Data\*|LOG;LOG.old|RECURSE +FileKey27=%LocalAppData%\Google\Software Reporter Tool|*.log +FileKey28=%LocalAppData%\MapleStudio\ChromePlus\Application|debug.log +FileKey29=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|LOG;LOG.old|RECURSE +FileKey30=%LocalAppData%\Programs\Opera*|debug.log +FileKey31=%LocalAppData%\RockMelt\Application|debug.log +FileKey32=%LocalAppData%\RockMelt\User Data\*|LOG;LOG.old|RECURSE +FileKey33=%LocalAppData%\Slimjet\User Data\*|LOG;LOG.old|RECURSE +FileKey34=%LocalAppData%\Torch\Application|debug.log +FileKey35=%LocalAppData%\Torch\User Data\*|LOG;LOG.old|RECURSE +FileKey36=%LocalAppData%\Vivaldi\Application|debug.log +FileKey37=%LocalAppData%\Vivaldi\User Data\*|LOG;LOG.old|RECURSE +FileKey38=%LocalAppData%\Yandex\YandexBrowser\Application|debug.log +FileKey39=%LocalAppData%\Yandex\YandexBrowser\User Data\*|LOG;LOG.old|RECURSE +FileKey40=%ProgramFiles%\BraveSoftware\Brave-Browser\Application|debug.log +FileKey41=%ProgramFiles%\Comodo\Dragon|debug.log +FileKey42=%ProgramFiles%\Google\Chrome*\Application|debug.log +FileKey43=%ProgramFiles%\Opera*|debug.log +FileKey44=%ProgramFiles%\Slimjet|debug.log +FileKey45=%ProgramFiles%\SRWare Iron|debug.log +FileKey46=%ProgramFiles%\SuperBird|debug.log +FileKey47=%ProgramFiles%\Vivaldi\Application|debug.log + +[Omnibox Shortcuts *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave|Shortcuts +FileKey2=%AppData%\Opera Software\Opera*|Shortcuts +FileKey3=%LocalAppData%\7Star\7Star\User Data\*|Shortcuts +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|Shortcuts +FileKey5=%LocalAppData%\Amigo\User Data\*|Shortcuts +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|Shortcuts +FileKey7=%LocalAppData%\CentBrowser\User Data\*|Shortcuts +FileKey8=%LocalAppData%\Chromium\User Data\*|Shortcuts +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|Shortcuts +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|Shortcuts +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|Shortcuts +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|Shortcuts +FileKey13=%LocalAppData%\Flock\User Data\*|Shortcuts +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|Shortcuts +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|Shortcuts +FileKey16=%LocalAppData%\RockMelt\User Data\*|Shortcuts +FileKey17=%LocalAppData%\Slimjet\User Data\*|Shortcuts +FileKey18=%LocalAppData%\Torch\User Data\*|Shortcuts +FileKey19=%LocalAppData%\Vivaldi\User Data\*|Shortcuts +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|Shortcuts + +[PNaCl Translation Cache *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\PnaclTranslationCache|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\PnaclTranslationCache|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\PnaclTranslationCache|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\PnaclTranslationCache|*.*|RECURSE + +[Quota Manager Data *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave|QuotaManager +FileKey2=%AppData%\Opera Software\Opera*|QuotaManager +FileKey3=%LocalAppData%\7Star\7Star\User Data\*|QuotaManager +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|QuotaManager +FileKey5=%LocalAppData%\Amigo\User Data\*|QuotaManager +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|QuotaManager +FileKey7=%LocalAppData%\CentBrowser\User Data\*|QuotaManager +FileKey8=%LocalAppData%\Chromium\User Data\*|QuotaManager +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|QuotaManager +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|QuotaManager +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|QuotaManager +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|QuotaManager +FileKey13=%LocalAppData%\Flock\User Data\*|QuotaManager +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|QuotaManager +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|QuotaManager +FileKey16=%LocalAppData%\RockMelt\User Data\*|QuotaManager +FileKey17=%LocalAppData%\Slimjet\User Data\*|QuotaManager +FileKey18=%LocalAppData%\Torch\User Data\*|QuotaManager +FileKey19=%LocalAppData%\Vivaldi\User Data\*|QuotaManager +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|QuotaManager + +[Session Storage *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave\Session Storage|*.*|RECURSE +FileKey2=%AppData%\Opera Software\Opera*\Session Storage|*.*|RECURSE +FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Session Storage|*.*|RECURSE +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Session Storage|*.*|RECURSE +FileKey5=%LocalAppData%\Amigo\User Data\*\Session Storage|*.*|RECURSE +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Session Storage|*.*|RECURSE +FileKey7=%LocalAppData%\CentBrowser\User Data\*\Session Storage|*.*|RECURSE +FileKey8=%LocalAppData%\Chromium\User Data\*\Session Storage|*.*|RECURSE +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Session Storage|*.*|RECURSE +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Session Storage|*.*|RECURSE +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Session Storage|*.*|RECURSE +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Session Storage|*.*|RECURSE +FileKey13=%LocalAppData%\Flock\User Data\*\Session Storage|*.*|RECURSE +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Session Storage|*.*|RECURSE +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Session Storage|*.*|RECURSE +FileKey16=%LocalAppData%\RockMelt\User Data\*\Session Storage|*.*|RECURSE +FileKey17=%LocalAppData%\Slimjet\User Data\*\Session Storage|*.*|RECURSE +FileKey18=%LocalAppData%\Torch\User Data\*\Session Storage|*.*|RECURSE +FileKey19=%LocalAppData%\Vivaldi\User Data\*\Session Storage|*.*|RECURSE +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Session Storage|*.*|RECURSE + +[SetupMetrics *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%LocalAppData%\7Star\7Star\Application\SetupMetrics|*.*|REMOVESELF +FileKey2=%LocalAppData%\360Browser\Browser\Application\SetupMetrics|*.*|REMOVESELF +FileKey3=%LocalAppData%\Amigo\Application\SetupMetrics|*.*|REMOVESELF +FileKey4=%LocalAppData%\Brave\SetupMetrics|*.*|REMOVESELF +FileKey5=%LocalAppData%\CentBrowser\Application\SetupMetrics|*.*|REMOVESELF +FileKey6=%LocalAppData%\Chromium\Application\SetupMetrics|*.*|REMOVESELF +FileKey7=%LocalAppData%\CocCoc\Browser\Application\SetupMetrics|*.*|REMOVESELF +FileKey8=%LocalAppData%\Coowon\Coowon\Application\SetupMetrics|*.*|REMOVESELF +FileKey9=%LocalAppData%\Epic Privacy Browser\Application\SetupMetrics|*.*|REMOVESELF +FileKey10=%LocalAppData%\Flock\Application\SetupMetrics|*.*|REMOVESELF +FileKey11=%LocalAppData%\Google\Chrome*\Application\SetupMetrics|*.*|REMOVESELF +FileKey12=%LocalAppData%\MapleStudio\ChromePlus\Application\SetupMetrics|*.*|REMOVESELF +FileKey13=%LocalAppData%\Programs\Opera*\SetupMetrics|*.*|REMOVESELF +FileKey14=%LocalAppData%\RockMelt\Application\SetupMetrics|*.*|REMOVESELF +FileKey15=%LocalAppData%\Torch\Application\SetupMetrics|*.*|REMOVESELF +FileKey16=%LocalAppData%\Vivaldi\Application\SetupMetrics|*.*|REMOVESELF +FileKey17=%LocalAppData%\Yandex\YandexBrowser\Application\SetupMetrics|*.*|REMOVESELF +FileKey18=%ProgramFiles%\BraveSoftware\Brave-Browser\Application\SetupMetrics|*.*|REMOVESELF +FileKey19=%ProgramFiles%\Comodo\Dragon\SetupMetrics|*.*|REMOVESELF +FileKey20=%ProgramFiles%\Google\Chrome*\Application\SetupMetrics|*.*|REMOVESELF +FileKey21=%ProgramFiles%\Opera*\SetupMetrics|*.*|REMOVESELF +FileKey22=%ProgramFiles%\Slimjet\SetupMetrics|*.*|REMOVESELF +FileKey23=%ProgramFiles%\SRWare Iron\SetupMetrics|*.*|REMOVESELF +FileKey24=%ProgramFiles%\SuperBird\SetupMetrics|*.*|REMOVESELF +FileKey25=%ProgramFiles%\Vivaldi\Application\SetupMetrics|*.*|REMOVESELF + +[Updates *] +LangSecRef=3029 +Detect1=HKCU\Software\BraveSoftware\Brave-Browser +Detect2=HKCU\Software\CocCoc\Browser +DetectFile=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%LocalAppData%\CocCoc\Update\Download|*.*|RECURSE +FileKey2=%LocalAppData%\CocCoc\Update\Install|*.*|RECURSE +FileKey3=%LocalAppData%\CocCoc\Update\Offline|*.*|RECURSE +FileKey4=%LocalAppData%\Google\Update\Download|*.*|RECURSE +FileKey5=%LocalAppData%\Google\Update\Install|*.*|RECURSE +FileKey6=%LocalAppData%\Google\Update\Offline|*.*|RECURSE +FileKey7=%ProgramFiles%\BraveSoftware\Update\Download|*.*|RECURSE +FileKey8=%ProgramFiles%\BraveSoftware\Update\Install|*.*|RECURSE +FileKey9=%ProgramFiles%\BraveSoftware\Update\Offline|*.*|RECURSE +FileKey10=%ProgramFiles%\Google\Update\Download|*.*|RECURSE +FileKey11=%ProgramFiles%\Google\Update\Install|*.*|RECURSE +FileKey12=%ProgramFiles%\Google\Update\Offline|*.*|RECURSE + +[Web Data *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +Warning=This will remove Autofill, Autocomplete, Search Engines keyword, Sign-in and Credit Card info. +FileKey1=%AppData%\brave|Web Data +FileKey2=%AppData%\Opera Software\Opera*|Web Data +FileKey3=%LocalAppData%\7Star\7Star\User Data\*|Web Data +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|Web Data +FileKey5=%LocalAppData%\Amigo\User Data\*|Web Data +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|Web Data +FileKey7=%LocalAppData%\CentBrowser\User Data\*|Web Data +FileKey8=%LocalAppData%\Chromium\User Data\*|Web Data +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|Web Data +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|Web Data +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|Web Data +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|Web Data +FileKey13=%LocalAppData%\Flock\User Data\*|Web Data +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|Web Data +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|Web Data +FileKey16=%LocalAppData%\RockMelt\User Data\*|Web Data +FileKey17=%LocalAppData%\Slimjet\User Data\*|Web Data +FileKey18=%LocalAppData%\Torch\User Data\*|Web Data +FileKey19=%LocalAppData%\Vivaldi\User Data\*|Web Data +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|Web Data + +[WebRTC Identity Store *] +LangSecRef=3029 +Detect1=HKCU\Software\7Star\7Star +Detect2=HKCU\Software\360Browser\Browser +Detect3=HKCU\Software\Amigo +Detect4=HKCU\Software\BraveSoftware\Brave-Browser +Detect5=HKCU\Software\CentBrowser +Detect6=HKCU\Software\ChromePlus +Detect7=HKCU\Software\Chromium\PreferenceMACs +Detect8=HKCU\Software\CocCoc\Browser +Detect9=HKCU\Software\Comodo\Dragon +Detect10=HKCU\Software\Coowon\Coowon +Detect11=HKCU\Software\Epic Privacy Browser +Detect12=HKCU\Software\Flock +Detect13=HKCU\Software\Opera Software +Detect14=HKCU\Software\RockMelt +Detect15=HKCU\Software\Slimjet +Detect16=HKCU\Software\Torch +Detect17=HKCU\Software\Vivaldi +Detect18=HKCU\Software\Yandex\YandexBrowser +DetectFile1=%AppData%\brave +DetectFile2=%LocalAppData%\Google\Chrome* +Default=False +FileKey1=%AppData%\brave|WebRTCIdentityStore +FileKey2=%AppData%\Opera Software\Opera*|WebRTCIdentityStore +FileKey3=%LocalAppData%\7Star\7Star\User Data\*|WebRTCIdentityStore +FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|WebRTCIdentityStore +FileKey5=%LocalAppData%\Amigo\User Data\*|WebRTCIdentityStore +FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|WebRTCIdentityStore +FileKey7=%LocalAppData%\CentBrowser\User Data\*|WebRTCIdentityStore +FileKey8=%LocalAppData%\Chromium\User Data\*|WebRTCIdentityStore +FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|WebRTCIdentityStore +FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|WebRTCIdentityStore +FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|WebRTCIdentityStore +FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|WebRTCIdentityStore +FileKey13=%LocalAppData%\Flock\User Data\*|WebRTCIdentityStore +FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|WebRTCIdentityStore +FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|WebRTCIdentityStore +FileKey16=%LocalAppData%\RockMelt\User Data\*|WebRTCIdentityStore +FileKey17=%LocalAppData%\Slimjet\User Data\*|WebRTCIdentityStore +FileKey18=%LocalAppData%\Torch\User Data\*|WebRTCIdentityStore +FileKey19=%LocalAppData%\Vivaldi\User Data\*|WebRTCIdentityStore +FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|WebRTCIdentityStore + +; End of Chrome/Chromium based browsers. +; +; Firefox/Mozilla based browsers. + +[Anti-Phishing Data *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +Warning=This will delete anti-phishing data. +FileKey1=%LocalAppData%\Moonchild Productions\Pale Moon\Profiles\*|urlclassifier3.sqlite +FileKey2=%LocalAppData%\Mozilla\Firefox\Profiles\*|urlclassifier3.sqlite +FileKey3=%LocalAppData%\Mozilla\SeaMonkey\Profiles\*|urlclassifier3.sqlite +FileKey4=%LocalAppData%\Waterfox\Profiles\*|urlclassifier3.sqlite + +[Bookmark Backups *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\bookmarkbackups|*.json* +FileKey2=%AppData%\Mozilla\Firefox\Profiles\*\bookmarkbackups|*.json* +FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles\*\bookmarkbackups|*.json* +FileKey4=%AppData%\Waterfox\Profiles\*\bookmarkbackups|*.json* + +[Bookmark Icons *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +Warning=This will delete all the icons of your bookmarks. The icons will be rebuilt as websites are manually re-visited. +FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*|favicons.sqlite +FileKey2=%AppData%\Mozilla\Firefox\Profiles\*|favicons.sqlite +FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles\*|favicons.sqlite +FileKey4=%AppData%\Waterfox\Profiles\*|favicons.sqlite + +[Corrupt SQLites *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles|*.corrupt|RECURSE +FileKey2=%AppData%\Mozilla\Firefox\Profiles|*.corrupt|RECURSE +FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles|*.corrupt|RECURSE +FileKey4=%AppData%\Waterfox\Profiles|*.corrupt|RECURSE + +[Crash Files *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +FileKey1=%AppData%\Moonchild Productions\Pale Moon\Crash Reports|*.*|RECURSE +FileKey2=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\minidumps|*.* +FileKey3=%AppData%\Mozilla\Firefox\Crash Reports|*.*|RECURSE +FileKey4=%AppData%\Mozilla\Firefox\Profiles\*\minidumps|*.* +FileKey5=%AppData%\Mozilla\SeaMonkey\Crash Reports|*.*|RECURSE +FileKey6=%AppData%\Mozilla\SeaMonkey\Profiles\*\minidumps|*.* +FileKey7=%AppData%\Waterfox\Crash Reports|*.*|RECURSE +FileKey8=%AppData%\Waterfox\Profiles\*\minidumps|*.* + +[DOM Storage *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*|webappsstore.sqlite +FileKey2=%AppData%\Mozilla\Firefox\Profiles\*|webappsstore.sqlite +FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles\*|webappsstore.sqlite +FileKey4=%AppData%\Waterfox\Profiles\*|webappsstore.sqlite + +[Firefox HTML5 Storage *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\storage|*.*|RECURSE +FileKey2=%AppData%\Mozilla\Firefox\Profiles\*\storage|*.*|RECURSE +FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles\*\storage|*.*|RECURSE +FileKey4=%AppData%\Waterfox\Profiles\*\storage|*.*|RECURSE +ExcludeKey1=PATH|%AppData%\Moonchild Productions\Pale Moon\Profiles\*\storage\default\moz-extension*\|*.* +ExcludeKey2=PATH|%AppData%\Mozilla\Firefox\Profiles\*\storage\default\moz-extension*\|*.* +ExcludeKey3=PATH|%AppData%\Mozilla\SeaMonkey\Profiles\*\storage\default\moz-extension*\|*.* +ExcludeKey4=PATH|%AppData%\Waterfox\Profiles\*\storage\default\moz-extension*\|*.* + +[Firefox Logs *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +FileKey1=%AppData%\Moonchild Productions\Pale Moon|*.log|RECURSE +FileKey2=%AppData%\Moonchild Productions\Pale Moon\Profiles|TestPilotErrorLog.*|RECURSE +FileKey3=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\weave\logs|*.* +FileKey4=%AppData%\Mozilla\Firefox|*.log|RECURSE +FileKey5=%AppData%\Mozilla\Firefox\Profiles|TestPilotErrorLog.*|RECURSE +FileKey6=%AppData%\Mozilla\Firefox\Profiles\*\weave\logs|*.* +FileKey7=%AppData%\Mozilla\SeaMonkey|*.log|RECURSE +FileKey8=%AppData%\Mozilla\SeaMonkey\Profiles|TestPilotErrorLog.*|RECURSE +FileKey9=%AppData%\Mozilla\SeaMonkey\Profiles\*\weave\logs|*.* +FileKey10=%AppData%\Waterfox|*.log|RECURSE +FileKey11=%AppData%\Waterfox\Profiles|TestPilotErrorLog.*|RECURSE +FileKey12=%AppData%\Waterfox\Profiles\*\weave\logs|*.* +FileKey13=%CommonAppData%\Mozilla*\logs|*.* +FileKey14=%LocalAppData%\Moonchild Productions\Pale Moon\*\updates|*.*|RECURSE +FileKey15=%LocalAppData%\Mozilla\Firefox\*\updates|*.*|RECURSE +FileKey16=%LocalAppData%\Mozilla\SeaMonkey\*\updates|*.*|RECURSE +FileKey17=%LocalAppData%\Mozilla\Updates|*.*|RECURSE +FileKey18=%LocalAppData%\Waterfox\*\updates|*.*|RECURSE +FileKey19=%ProgramFiles%\Firefox*|*.log +FileKey20=%ProgramFiles%\Mozilla Firefox|*.log +FileKey21=%ProgramFiles%\Mozilla Maintenance Service\logs|*.log +FileKey22=%ProgramFiles%\Pale Moon|*.log +FileKey23=%ProgramFiles%\SeaMonkey|*.log +FileKey24=%ProgramFiles%\Waterfox|*.log + +[Nightly Backups *] +LangSecRef=3026 +DetectFile1=%ProgramFiles%\Mozilla\Nightly +DetectFile2=%ProgramFiles%\Nightly +Default=False +FileKey1=%ProgramFiles%\Mozilla\Nightly.bak|*.*|REMOVESELF +FileKey2=%ProgramFiles%\Nightly.bak|*.*|REMOVESELF + +[Profile Lock File *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*|parent.lock +FileKey2=%AppData%\Mozilla\Firefox\Profiles\*|parent.lock +FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles\*|parent.lock +FileKey4=%AppData%\Waterfox\Profiles\*|parent.lock + +[Startup Cache *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +FileKey1=%LocalAppData%\Moonchild Productions\Pale Moon\Profiles\*\startupCache|*.* +FileKey2=%LocalAppData%\Mozilla\Firefox\Profiles\*\startupCache|*.* +FileKey3=%LocalAppData%\Mozilla\SeaMonkey\Profiles\*\startupCache|*.* +FileKey4=%LocalAppData%\Waterfox\Profiles\*\startupCache|*.* + +[Talkback *] +LangSecRef=3026 +DetectFile=%AppData%\Talkback\MozillaOrg +Default=False +FileKey1=%AppData%\Talkback\MozillaOrg\Firefox*|*.*|RECURSE +FileKey2=%AppData%\Talkback\MozillaOrg\Thunderbird*|*.*|RECURSE +RegKey1=HKLM\Software\FullCircle\TalkBack + +[Telemetry *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*|Telemetry*.* +FileKey2=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\datareporting\archived|*.jsonlz4|RECURSE +FileKey3=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\saved-telemetry-pings|*.* +FileKey4=%AppData%\Mozilla\Firefox\Profiles\*|Telemetry*.* +FileKey5=%AppData%\Mozilla\Firefox\Profiles\*\datareporting\archived|*.jsonlz4|RECURSE +FileKey6=%AppData%\Mozilla\Firefox\Profiles\*\saved-telemetry-pings|*.* +FileKey7=%AppData%\Mozilla\SeaMonkey\Profiles\*|Telemetry*.* +FileKey8=%AppData%\Mozilla\SeaMonkey\Profiles\*\datareporting\archived|*.jsonlz4|RECURSE +FileKey9=%AppData%\Mozilla\SeaMonkey\Profiles\*\saved-telemetry-pings|*.* +FileKey10=%AppData%\Waterfox\Profiles\*|Telemetry*.* +FileKey11=%AppData%\Waterfox\Profiles\*\datareporting\archived|*.jsonlz4|RECURSE +FileKey12=%AppData%\Waterfox\Profiles\*\saved-telemetry-pings|*.* +FileKey13=%LocalAppData%\Moonchild Productions\Pale Moon\Profiles\*|ShutdownDuration.* +FileKey14=%LocalAppData%\Mozilla\Firefox\Profiles\*|ShutdownDuration.* +FileKey15=%LocalAppData%\Mozilla\SeaMonkey\Profiles\*|ShutdownDuration.* +FileKey16=%LocalAppData%\Waterfox\Profiles\*|ShutdownDuration.* + +[Temps *] +LangSecRef=3026 +Detect1=HKLM\Software\Mozilla\Pale Moon +Detect2=HKLM\Software\Mozilla\SeaMonkey +Detect3=HKLM\Software\Mozilla\Waterfox +DetectFile=%AppData%\Mozilla\Firefox +Default=False +FileKey1=%ProgramFiles%\Firefox*|*.tmp|RECURSE +FileKey2=%ProgramFiles%\Mozilla*|*.tmp|RECURSE +FileKey3=%ProgramFiles%\Pale Moon|*.tmp|RECURSE +FileKey4=%ProgramFiles%\SeaMonkey|*.tmp|RECURSE +FileKey5=%ProgramFiles%\Waterfox|*.tmp|RECURSE + +[Waterfox Installer *] +LangSecRef=3026 +Detect=HKLM\Software\Mozilla\Waterfox +Default=False +FileKey1=%AppData%\Waterfox*\Waterfox*\install|*.*|RECURSE + +; End of Firefox/Mozilla based browsers. +; +; Thunderbird entries. + +[Email Index *] +LangSecRef=3030 +Detect1=HKLM\Software\Mozilla\FossaMail +Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird +Default=False +Warning=This will cause your message index to be deleted, searching emails may be slow until it is rebuilt. +FileKey1=%AppData%\FossaMail\Profiles|global-messages-db.sqlite|RECURSE +FileKey2=%AppData%\Thunderbird\Profiles|global-messages-db.sqlite|RECURSE + +[Thunderbird Corrupt SQLites *] +LangSecRef=3030 +Detect1=HKLM\Software\Mozilla\FossaMail +Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird +Default=False +FileKey1=%AppData%\FossaMail\Profiles|*.corrupt|RECURSE +FileKey2=%AppData%\Thunderbird\Profiles|*.corrupt|RECURSE + +[Thunderbird Crash Files *] +LangSecRef=3030 +Detect1=HKLM\Software\Mozilla\FossaMail +Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird +Default=False +FileKey1=%AppData%\FossaMail\Crash Reports|*.*|RECURSE +FileKey2=%AppData%\FossaMail\Profiles\*\Minidumps|*.* +FileKey3=%AppData%\Thunderbird\Crash Reports|*.*|RECURSE +FileKey4=%AppData%\Thunderbird\Profiles\*\Minidumps|*.* + +[Thunderbird DOM Storage *] +LangSecRef=3030 +Detect1=HKLM\Software\Mozilla\FossaMail +Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird +Default=False +FileKey1=%AppData%\FossaMail\Profiles\*|webappsstore.sqlite +FileKey2=%AppData%\Thunderbird\Profiles\*|webappsstore.sqlite + +[Thunderbird Logs *] +LangSecRef=3030 +Detect1=HKLM\Software\Mozilla\FossaMail +Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird +Default=False +FileKey1=%AppData%\FossaMail\Profiles\*|extensions.log;filterlog.html;TestPilotErrorLog.*|RECURSE +FileKey2=%AppData%\Thunderbird\Profiles\*|extensions.log;filterlog.html;TestPilotErrorLog.*|RECURSE +FileKey3=%CommonAppData%\Mozilla*\logs|*.*|RECURSE +FileKey4=%LocalAppData%\FossaMail\Mozilla\*\Updates|*.log|RECURSE +FileKey5=%LocalAppData%\Thunderbird\Mozilla\*\Updates|*.log|RECURSE +FileKey6=%ProgramFiles%\FossaMail|*.log +FileKey7=%ProgramFiles%\Mozilla Thunderbird|*.log + +[Thunderbird Startup Cache *] +LangSecRef=3030 +Detect1=HKLM\Software\Mozilla\FossaMail +Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird +Default=False +FileKey1=%LocalAppData%\FossaMail\Profiles\*\startupCache|*.* +FileKey2=%LocalAppData%\Thunderbird\Profiles\*\startupCache|*.* + +; End of Thunderbird entries. + +[.NET Framework *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\.NETFramework +Default=False +FileKey1=%WinDir%\assembly\NativeImages_*\Temp|*.*|RECURSE +FileKey2=%WinDir%\assembly\t*mp|*.*|REMOVESELF +FileKey3=%WinDir%\Microsoft.NET\Framework*\*\*\Logs|*.*|RECURSE +FileKey4=%WinDir%\Microsoft.NET\Framework*\*\Temporary ASP.NET Files|*.*|REMOVESELF +FileKey5=%WinDir%\Microsoft.NET\Framework*\v4.0.30319\SetupCache|*.*|RECURSE +FileKey6=%WinDir%\System32\URTTemp|*.*|RECURSE +RegKey1=HKCU\Software\Microsoft\.NETFramework\SQM\Apps + +[.NET Framework Isolated Storage *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\.NETFramework +Default=False +FileKey1=%LocalAppData%\IsolatedStorage|*.*|RECURSE + +[.NET Reflector *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Red Gate\.NET Reflector 6 +Default=False +FileKey1=%LocalAppData%\Red Gate\.NET Reflector 6|Reflector.cfg +FileKey2=%LocalAppData%\Red Gate\.NET Reflector 6\Cache|*.*|RECURSE + +[.Thumbnails *] +LangSecRef=3021 +DetectFile=%UserProfile%\.Thumbnails +Default=False +FileKey1=%UserProfile%\.Thumbnails|*.*|RECURSE + +[//N.P.P.D. RUSH//- The milk of Ultraviolet *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\270090 +Default=False +FileKey1=%LocalAppData%\NPPDRUSH|Web Data*|RECURSE +FileKey2=%LocalAppData%\NPPDRUSH\*Cache|*.*|RECURSE + +[1Click DVD Copy Pro *] +LangSecRef=3023 +DetectFile=%CommonAppData%\1click dvd copy pro +Default=False +FileKey1=%CommonAppData%\1click dvd copy pro|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\1click dvd copy pro|*.log + +[3 Stars Of Destiny *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\278530 +Default=False +FileKey1=%AppData%\3Stars|*.tmp + +[3D Builder *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.3DBuilder_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\Temp|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalCache|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalState\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.3DBuilder_*\TempState|*.*|RECURSE + +[3DMark *] +Section=Games +DetectFile=%Documents%\3DMark +Default=False +FileKey1=%Documents%\3DMark|*.log +FileKey2=%Documents%\3DMark\Log|*.*|REMOVESELF +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\3DMark|*.log|RECURSE +FileKey4=%ProgramFiles%\Steam\SteamApps\common\3DMark|*.log|RECURSE + +[3DMark Saved Benchmarks *] +Section=Games +DetectFile=%Documents%\3DMark +Default=False +FileKey1=%Documents%\3DMark|*.3dmark-result + +[3SwitcheD *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\206610 +Default=False +FileKey1=%LocalAppData%\3SwitcheD\cache|*.*|RECURSE + +[4K Video Downloader *] +LangSecRef=3023 +Detect=HKCU\Software\4kdownload.com\4K Video Downloader +Default=False +FileKey1=%LocalAppData%\4kdownload.com\4K Video Downloader\4K Video Downloader|*.xml +RegKey1=HKCU\Software\4kdownload.com\4K Video Downloader\Download|downloadedItems +RegKey2=HKCU\Software\4kdownload.com\4K Video Downloader\Settings|outputPath + +[4K YouTube to MP3 *] +LangSecRef=3023 +Detect=HKCU\Software\4kdownload.com\4K YouTube to MP3 +Default=False +FileKey1=%LocalAppData%\4kdownload.com\4K YouTube to MP3\4K YouTube to MP3|*.xml +RegKey1=HKCU\Software\4kdownload.com\4K YouTube to MP3\Download|downloadedItems +RegKey2=HKCU\Software\4kdownload.com\4K YouTube to MP3\Settings|outputPath + +[4Team Sync2 *] +LangSecRef=3022 +DetectFile=%AppData%\4Team\Sync2 +Default=False +FileKey1=%AppData%\4Team\Sync2|*.log|RECURSE + +[4Team Updater *] +LangSecRef=3022 +DetectFile=%AppData%\4Team\4Team-Updater +Default=False +FileKey1=%AppData%\4Team\4Team-Updater\Logs|*.* + +[7z SFX Builder *] +LangSecRef=3024 +Detect=HKCU\Software\7z SFX Builder +Default=False +RegKey1=HKCU\Software\7z SFX Builder\MRU + +[10 Years After *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\339240 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\10 Years After\10 Years After_Data|output_log.txt +FileKey2=%ProgramFiles%\Steam\SteamApps\common\10 Years After\10 Years After_Data|output_log.txt + +[18 Wheels of Steel *] +Section=Games +Detect=HKCU\Software\ValuSoft +Default=False +FileKey1=%Documents%\18 WoS*|*.log;*.crash + +[32bit Web Browser *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\32BITWEB\32BW.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\32BITWEB\Data|LastURL.dat;LastURL.da0 +FileKey2=%ProgramFiles%\32BITWEB\Data|LastURL.dat;LastURL.da0 + +[140 *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\242820 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\140\140_Data|output_log.txt +FileKey2=%ProgramFiles%\Steam\SteamApps\common\140\140_Data|output_log.txt + +[360 Internet Security *] +LangSecRef=3024 +Detect=HKCU\Software\360Safe +Default=False +FileKey1=%AppData%\360safe\360ScanLog|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\360\360 Internet Security|*.log*|RECURSE +FileKey3=%ProgramFiles%\360\360 Internet Security|*.log*|RECURSE +FileKey4=%SystemDrive%\360SANDBOX|*.log*|RECURSE + +[1000 Amps *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\205690 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\1000 Amps|stdout.txt +FileKey2=%ProgramFiles%\Steam\SteamApps\common\1000 Amps|stdout.txt + +[1954 Alcatraz *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\255280 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\1954 Alcatraz\Alcatraz_Data|output_log.txt +FileKey2=%LocalLowAppData%\Daedalic Entertainment\1954 Alcatraz|*.log +FileKey3=%ProgramFiles%\Steam\SteamApps\common\1954 Alcatraz\Alcatraz_Data|output_log.txt + +[A58-Easytune6 *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\A58-Easytune6 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\A58-Easytune6|*.log +FileKey2=%ProgramFiles%\A58-Easytune6|*.log + +[ABBYY FineReader *] +LangSecRef=3021 +Detect1=HKCU\Software\ABBYY\FineReader\7.00 +Detect2=HKCU\Software\ABBYY\FineReader\8.00 +Detect3=HKCU\Software\ABBYY\FineReader\9.00 +Detect4=HKCU\Software\ABBYY\FineReader\11.00 +Detect5=HKCU\Software\ABBYY\Sprint\5.00 +Default=False +FileKey1=%LocalAppData%\ABBYY\ScanManager\*|scantwain.txt;scanwia.txt;*.bmp +RegKey1=HKCU\Software\ABBYY\FineReader\7.00\Shell\Dialogs|LoadImagePath +RegKey2=HKCU\Software\ABBYY\FineReader\7.00\Shell\Dialogs|SaveImagePath +RegKey3=HKCU\Software\ABBYY\FineReader\7.00\Shell\Dialogs|SaveToPath +RegKey4=HKCU\Software\ABBYY\FineReader\8.00\Shell\Dialogs|LoadImagePath +RegKey5=HKCU\Software\ABBYY\FineReader\8.00\Shell\Dialogs|SaveImagePath +RegKey6=HKCU\Software\ABBYY\FineReader\8.00\Shell\Dialogs|SaveToPath +RegKey7=HKCU\Software\ABBYY\FineReader\8.00\Shell\Options|LastTAScenario +RegKey8=HKCU\Software\ABBYY\FineReader\9.00\Shell\Dialogs|LoadImagePath +RegKey9=HKCU\Software\ABBYY\FineReader\9.00\Shell\Dialogs|SaveImagePath +RegKey10=HKCU\Software\ABBYY\FineReader\9.00\Shell\Dialogs|SaveToPath +RegKey11=HKCU\Software\ABBYY\FineReader\9.00\Shell\Options|LastTAScenario +RegKey12=HKCU\Software\ABBYY\FineReader\11.00\Shell\Dialogs|SaveToPath +RegKey13=HKCU\Software\ABBYY\FineReader\11.00\Shell\Options|LastTAScenario +RegKey14=HKCU\Software\ABBYY\FineReader\11.00\Shell\Options|LastWebFoldersNames + +[Abelssoft GoogleClean *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4281435C-AD1D-4C8A-B9C0-3961C08EF142}_is1 +Default=False +FileKey1=%LocalAppData%\Abelssoft\GoogleClean\log|*.*|REMOVESELF + +[abgx360 *] +LangSecRef=3024 +Detect=HKCU\Software\abgx360gui +Default=False +RegKey1=HKCU\Software\abgx360gui\RecentFiles + +[Ability Office *] +LangSecRef=3021 +Detect=HKCU\Software\Ability 6.0 +Default=False +FileKey1=%Documents%\My Ability Files|*.*|RECURSE +RegKey1=HKCU\Software\Ability 6.0\Ability Database\Recent File List +RegKey2=HKCU\Software\Ability 6.0\Ability PhotoPaint Studio\Recent File List +RegKey3=HKCU\Software\Ability 6.0\Ability PhotoPaint\Recent File List +RegKey4=HKCU\Software\Ability 6.0\Ability Spreadsheet\Recent File List +RegKey5=HKCU\Software\Ability 6.0\Ability Write\Files + +[Ableton Live *] +LangSecRef=3023 +Detect=HKLM\Software\Propellerhead Software\ReWire\Ableton Live Engine +Default=False +FileKey1=%AppData%\Ableton\*\Preferences|AsioLog.txt;Indexer.txt;Log.txt|RECURSE +FileKey2=%AppData%\Ableton\Live Reports\Temp|*.*|REMOVESELF +FileKey3=%AppData%\Ableton\Live Reports\Usage|*.*|REMOVESELF +FileKey4=%CommonAppData%\Ableton\*\Redist|vcredist*.exe +FileKey5=%ProgramFiles%\Ableton\*\Redist|vcredist*.exe + +[Ableton Live Cache *] +LangSecRef=3023 +Detect=HKLM\Software\Propellerhead Software\ReWire\Ableton Live Engine +Default=False +FileKey1=%AppData%\Ableton\Cache|*.*|RECURSE + +[AbsoluteFTP *] +LangSecRef=3022 +Detect=HKCU\Software\Van Dyke Technologies\AbsoluteFTP +Default=False +RegKey1=HKCU\Software\Van Dyke Technologies\AbsoluteFTP\Recent File List + +[AccessData Registry Viewer *] +LangSecRef=3024 +Detect=HKCU\Software\AccessData\Registry Viewer +Default=False +RegKey1=HKCU\Software\AccessData\Registry Viewer\Recent File List + +[Accounts Control *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.AccountsControl_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.AccountsControl_*\TempState|*.*|RECURSE + +[AccurateRip *] +LangSecRef=3023 +Detect1=HKCU\Software\AWSoftware\EAC +Detect2=HKCU\Software\AWSoftware\EACU +Detect3=HKCU\Software\Illustrate\dBpowerAMP +Default=False +FileKey1=%AppData%\AccurateRip\AccurateRipCache|dBAR*.bin + +[AccuWeather *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AccuWeather.AccuWeatherforWindows8_8zz2pj9h1h1d8 +DetectFile=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_8zz2pj9h1h1d8 +Default=False +FileKey1=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.log|RECURSE +FileKey3=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_*\AC\Temp|*.* +FileKey4=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_*\LocalState|*.tmp +FileKey5=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_*\TempState\Bing.Maps\Cache|*.*|RECURSE + +[ACDSee Photo Studio *] +LangSecRef=3023 +Detect1=HKCU\Software\ACD Systems\ACDSee Pro\90 +Detect2=HKCU\Software\ACD Systems\ACDSee Professional\110 +Detect3=HKCU\Software\ACD Systems\ACDSee Standard\210 +Detect4=HKCU\Software\ACD Systems\ACDSee Ultimate\110 +Detect5=HKCU\Software\ACD Systems\ACDSee\60 +Default=False +FileKey1=%LocalAppData%\ACD Systems\ICMCache|*.*|RECURSE +FileKey2=%LocalAppData%\ACD Systems\Logs|*.*|RECURSE +FileKey3=%LocalAppData%\ACD Systems\SavedSearches|*.*|RECURSE +RegKey1=HKCU\Software\ACD Systems\ACDSee Pro\90|HistMCFDestFolder +RegKey2=HKCU\Software\ACD Systems\ACDSee Pro\90|HistPaths +RegKey3=HKCU\Software\ACD Systems\ACDSee Pro\90|LastOptionPageName +RegKey4=HKCU\Software\ACD Systems\ACDSee Pro\90|OpenFolder +RegKey5=HKCU\Software\ACD Systems\ACDSee Pro\90\PrintOptions\OutputContactSheet|ContactSheetFN +RegKey6=HKCU\Software\ACD Systems\ACDSee Pro\90\PrintOptions\OutputContactSheet|ImageMapFN +RegKey7=HKCU\Software\ACD Systems\ACDSee Professional\110|HistMCFDestFolder +RegKey8=HKCU\Software\ACD Systems\ACDSee Professional\110|HistPaths +RegKey9=HKCU\Software\ACD Systems\ACDSee Professional\110|LastOptionPageName +RegKey10=HKCU\Software\ACD Systems\ACDSee Professional\110|OnlineHistPaths +RegKey11=HKCU\Software\ACD Systems\ACDSee Professional\110|OpenFolder +RegKey12=HKCU\Software\ACD Systems\ACDSee Standard\210|HistMCFDestFolder +RegKey13=HKCU\Software\ACD Systems\ACDSee Standard\210|HistPaths +RegKey14=HKCU\Software\ACD Systems\ACDSee Standard\210|LastOptionPageName +RegKey15=HKCU\Software\ACD Systems\ACDSee Standard\210|OnlineHistPaths +RegKey16=HKCU\Software\ACD Systems\ACDSee Standard\210|OpenFolder +RegKey17=HKCU\Software\ACD Systems\ACDSee Ultimate\110|HistMCFDestFolder +RegKey18=HKCU\Software\ACD Systems\ACDSee Ultimate\110|HistPaths +RegKey19=HKCU\Software\ACD Systems\ACDSee Ultimate\110|LastOptionPageName +RegKey20=HKCU\Software\ACD Systems\ACDSee Ultimate\110|OnlineHistPaths +RegKey21=HKCU\Software\ACD Systems\ACDSee Ultimate\110|OpenFolder +RegKey22=HKCU\Software\ACD Systems\ACDSee\60|HistMCFDestFolder +RegKey23=HKCU\Software\ACD Systems\ACDSee\60|HistPaths +RegKey24=HKCU\Software\ACD Systems\ACDSee\60|LastOptionPageName +RegKey25=HKCU\Software\ACD Systems\ACDSee\60|OpenFolder +RegKey26=HKCU\Software\ACD Systems\ACDSee\60\PrintOptions\OutputContactSheet|ContactSheetFN +RegKey27=HKCU\Software\ACD Systems\ACDSee\60\PrintOptions\OutputContactSheet|ImageMapFN +RegKey28=HKCU\Software\ACD Systems\EditLib\Presets\Photo Repair 2|Last Used + +[Ace Explorer Browser *] +LangSecRef=3022 +Detect=HKCU\Software\Ace Explorer\Ace Explorer +Default=False +FileKey1=%AppData%\Ace Explorer|recentclose.ini +RegKey1=HKCU\Software\Ace Explorer\Ace Explorer\Recent File List + +[Ace of Spades *] +Section=Games +DetectFile=%ProgramFiles%\Steam\steamapps\common\aceofspades +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\aceofspades\logs|*.* +FileKey2=%ProgramFiles%\Steam\steamapps\common\aceofspades\logs|*.* + +[Ace Stream *] +LangSecRef=3023 +DetectFile=%AppData%\ACEStream +Default=False +FileKey1=%AppData%\.ACEStream|*.ini +FileKey2=%AppData%\.ACEStream\collected_torrent_files|*.* +FileKey3=%AppData%\ACEStream\engine|*.log +FileKey4=%SystemDrive%\_acestream_cache_|*.*|REMOVESELF + +[Ace Utilities *] +LangSecRef=3024 +Detect=HKCU\Software\Acelogix\Ace Utilities +Default=False +RegKey1=HKCU\Software\Acelogix\Ace Utilities\Settings|UsageHistory + +[Acebyte Utilities *] +LangSecRef=3024 +Detect=HKCU\Software\AceBIT +Default=False +FileKey1=%CommonAppData%\Acebyte\Acebyte Utilities*\Log|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Acebyte\Acebyte Utilities*\Log|*.*|RECURSE + +[Acer Arcade Deluxe *] +Section=Games +DetectFile=%LocalAppData%\Acer Arcade Deluxe +Default=False +FileKey1=%CommonAppData%|ArcadeDexluxe2.log +FileKey2=%LocalAppData%\Acer Arcade Deluxe|*.log +FileKey3=%LocalAppData%\VirtualStore\ProgramData|ArcadeDexluxe2.log + +[AcooBrowser *] +LangSecRef=3022 +Detect=HKCU\Software\AcooBrowser\Acoo Browser +Default=False +RegKey1=HKCU\Software\AcooBrowser\Acoo Browser\Recent Document List +RegKey2=HKCU\Software\AcooBrowser\Acoo Browser\Search\History + +[Acoustica CD Label Maker *] +LangSecRef=3024 +Detect=HKCU\Software\Acoustica\CD Label Maker +Default=False +FileKey1=%AppData%\Acoustica\CD Label Maker\*\cache|*.*|RECURSE +FileKey2=%AppData%\Acoustica\CD Label Maker\cache|*.*|RECURSE +FileKey3=%AppData%\Acoustica\CD Label Maker\shapes|*.* +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Acoustica CD Label Maker\thumbs|*.*|RECURSE +FileKey5=%ProgramFiles%\Acoustica CD Label Maker\thumbs|*.*|RECURSE + +[Acoustica Premium Edition 6 *] +LangSecRef=3023 +Detect=HKCU\Software\Acon Digital\Acoustica Premium Edition 6 +Default=False +RegKey1=HKCU\Software\Acon Digital\Acoustica Premium Edition 6\General|BrowserFolder +RegKey2=HKCU\Software\Acon Digital\Acoustica Premium Edition 6\General|LastAudioDir +RegKey3=HKCU\Software\Acon Digital\Acoustica Premium Edition 6\Recent File List + +[Acrok Video Converter Ultimate *] +LangSecRef=3023 +Detect=HKCU\Software\Acrok Software\Acrok Video Converter Ultimate +Default=False +FileKey1=%AppData%\Acrok\Acrok Video Converter Ultimate|*.dmp +FileKey2=%AppData%\Acrok\Acrok Video Converter Ultimate\log|*.* +FileKey3=%AppData%\Auxre\Blu-ray Plugin|*.log +FileKey4=%UserProfile%\.BDAccess|*.*|RECURSE + +[Action Center *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog +RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Security and Maintenance\Providers\EventLog + +[Active Setup Temp Folder *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Active Setup Temp Folders +Default=False +FileKey1=%WinDir%\msdownld.tmp|*.*|REMOVESELF +RegKey1=HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Active Setup Temp Folders|Folder +RegKey2=HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Active Setup Temp Folders|Folder + +[Active@ Disk Image *] +LangSecRef=3024 +Detect=HKLM\Software\LSoft Technologies\Active Disk Image +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image|*.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE +FileKey3=%ProgramFiles%\LSoft Technologies\Active@ Disk Image|*.txt +FileKey4=%ProgramFiles%\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE + +[Active@ File Recovery *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C34F36E0-4D8B-42E8-90AD-50C76E1AE282}_is1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ File Recovery*|Active File Recovery Log.txt;he_log.txt;*.scn;*.xml +FileKey2=%ProgramFiles%\LSoft Technologies\Active@ File Recovery*|Active File Recovery Log.txt;he_log.txt;*.scn;*.xml + +[Active@ KillDisk *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0F62EFB8-3C1C-4EE6-B6EF-9593007F9B03}_is1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ KillDisk*|*.log;*.xml +FileKey2=%ProgramFiles%\LSoft Technologies\Active@ KillDisk*|*.log;*.xml + +[Ad-Aware Antivirus *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Ad-Aware Antivirus\AdAware.exe +Default=False +FileKey1=%AppData%\Ad-Aware Antivirus\Logs|*.*|RECURSE +FileKey2=%CommonAppData%\Ad-Aware Antivirus\Logs|*.*|RECURSE +FileKey3=%CommonAppData%\Lavasoft\AntiMalware\Events|*.*|RECURSE +FileKey4=%CommonAppData%\Lavasoft\AntiMalware\History|*.*|RECURSE +FileKey5=%CommonAppData%\Lavasoft\AntiMalware\Logs|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Ad-Aware Antivirus\Logs|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Lavasoft\AntiMalware\Events|*.*|RECURSE +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Lavasoft\AntiMalware\History|*.*|RECURSE +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Lavasoft\AntiMalware\Logs|*.*|RECURSE + +[Adaptec's Audio CD *] +LangSecRef=3024 +Detect=HKCU\Software\Adaptec +Default=False +RegKey1=HKCU\Software\Adaptec\AUDIO_CD_INFO + +[Adblock Plus For IE *] +LangSecRef=3022 +Detect=HKLM\Software\Adblock Plus for IE +DetectFile=%LocalAppData%\Adblock Plus for IE +Default=False +FileKey1=%LocalAppData%\Adblock Plus for IE|patterns-backup*.ini +FileKey2=%LocalLowAppData%\Adblock Plus for IE|patterns-backup*.ini +FileKey3=%WinDir%\System32\config\systemprofile\AppData\LocalLow\Adblock Plus for IE|patterns-backup*.ini + +[Adobe Acrobat 2017 *] +LangSecRef=3021 +Detect=HKCU\Software\Adobe\Adobe Acrobat\2017 +Default=False +RegKey1=HKCU\Software\Adobe\Adobe Acrobat\2017\AVGeneral\cRecentFiles +RegKey2=HKCU\Software\Adobe\Adobe Acrobat\2017\AVGeneral\cRecentFolders + +[Adobe Acrobat DC *] +LangSecRef=3021 +Detect=HKLM\Software\Adobe\Adobe Acrobat\DC +Default=False +FileKey1=%LocalAppData%\Adobe\Acrobat\DC|*.lst;UserCache.bin +FileKey2=%LocalAppData%\Adobe\Acrobat\DC\Cache|*.lst +FileKey3=%LocalAppData%\Adobe\Acrobat\DC\ToolsSearchCacheAcro|*.*|RECURSE +FileKey4=%LocalLowAppData%\Adobe\Acrobat\DC\Search|*.*|RECURSE +FileKey5=%LocalLowAppData%\Adobe\AcroCef\DC\Acrobat\Cache|*.*|RECURSE +RegKey1=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionFromPDF\cSettings +RegKey2=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionToPDF\cSettings +RegKey3=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cDockables +RegKey4=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles +RegKey5=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFolders +RegKey6=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentToolsList +RegKey7=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars +RegKey8=HKCU\Software\Adobe\Adobe Acrobat\DC\RememberedViews\cNoCategoryFiles +RegKey9=HKCU\Software\Adobe\Adobe Acrobat\DC\ShareIdentity +RegKey10=HKCU\Software\Adobe\Adobe Synchronizer\DC + +[Adobe Acrobat Distiller XI *] +LangSecRef=3021 +Detect=HKCU\Software\Adobe\Acrobat Distiller\11.0 +Default=False +FileKey1=%AppData%\Adobe\Acrobat\Distiller 11|*.log +FileKey2=%AppData%\Adobe\Acrobat\Distiller 11\Cache|*.* +RegKey1=HKCU\Software\Adobe\Acrobat Distiller\PrinterJobControl + +[Adobe Acrobat Reader 7.0 *] +LangSecRef=3021 +Detect=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Adobe\Acrobat 7.0\ActiveX|*.bak +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Adobe\Acrobat 7.0\Reader|*.bak +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Adobe\Acrobat 7.0\Reader\plug_ins|*.bak +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Adobe\Acrobat 7.0\Reader\Updater|*.bak + +[Adobe Acrobat XI *] +LangSecRef=3021 +Detect=HKCU\Software\Adobe\Adobe Acrobat\11.0 +Default=False +FileKey1=%LocalAppData%\Adobe\Acrobat|*.idx|RECURSE +FileKey2=%LocalAppData%\Adobe\Acrobat\11.0|UserCache.bin + +[Adobe Air *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Adobe\Air +Default=False +FileKey1=%WinDir%\System32\config\systemprofile\AppData\Local\Adobe\AIR\logs|*.* +FileKey2=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Adobe\AIR\logs|*.* + +[Adobe Application Manager *] +LangSecRef=3021 +Detect=HKCU\Software\Adobe +Default=False +FileKey1=%AppData%\Adobe\Acrobat\*\Updater|*.log +FileKey2=%CommonAppData%\Adobe\ARM|*.*|RECURSE +FileKey3=%CommonProgramFiles%\Adobe\Installers|*.log.gz|RECURSE +FileKey4=%LocalAppData%\Adobe\AAMUpdater|*.Log|RECURSE +FileKey5=%LocalAppData%\Adobe\Acrobat\*\Updater|*.log +FileKey6=%LocalAppData%\Adobe\Updater*|*.log|RECURSE + +[Adobe CC *] +LangSecRef=3023 +Detect=HKCU\Software\Adobe\CreativeCloud +Default=False +FileKey1=%AppData%\Adobe\Adobe Media Encoder\*\logs|*.*|RECURSE +FileKey2=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings|PSErrorLog.txt;sniffer-*.txt +FileKey3=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings\CrashLogs|*.*|RECURSE +FileKey4=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings\web-cache-temp|*.*|RECURSE +FileKey5=%AppData%\Adobe\Adobe Photoshop CC *\Logs|*.*|RECURSE +FileKey6=%AppData%\Adobe\CRLogs|*.*|RECURSE +FileKey7=%AppData%\Adobe\dynamiclinkmanager\*\logs|*.*|RECURSE +FileKey8=%AppData%\Adobe\Extension Manager CC\Log|*.*|RECURSE +FileKey9=%AppData%\Adobe\Extension Manager CC\Temp|*.*|RECURSE +FileKey10=%AppData%\Adobe\LogTransport2CC\Logs|*.*|RECURSE +FileKey11=%AppData%\Adobe\Lumetri\*\logs|*.*|RECURSE +FileKey12=%AppData%\Adobe\Premiere Pro\*|Plugin Loading.log +FileKey13=%AppData%\Adobe\Premiere Pro\*\logs|*.*|RECURSE +FileKey14=%CommonProgramFiles%\Adobe\Installers|CoreSyncInstall.log;Install.log +FileKey15=%Documents%\Adobe|*.log +FileKey16=%Documents%\Adobe\Adobe Media Encoder\*|AMEEncodingErrorLog.txt;AMEEncodingLog.txt +FileKey17=%Documents%\Adobe\Adobe Media Encoder\*\logs|*.*|RECURSE +FileKey18=%Documents%\Adobe\Premiere Pro\*|Plugin Loading.log +RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU + +[Adobe Customization Wizard *] +LangSecRef=3021 +Detect1=HKCU\Software\Adobe\Adobe Customization Wizard 8 +Detect2=HKCU\Software\Adobe\Adobe Customization Wizard 9 +Detect3=HKCU\Software\Adobe\Adobe Customization Wizard X +Detect4=HKCU\Software\Adobe\Adobe Customization Wizard XI +Default=False +RegKey1=HKCU\Software\Adobe\Adobe Customization Wizard 8\Recent File List +RegKey2=HKCU\Software\Adobe\Adobe Customization Wizard 9\Recent File List +RegKey3=HKCU\Software\Adobe\Adobe Customization Wizard X\Recent File List +RegKey4=HKCU\Software\Adobe\Adobe Customization Wizard XI\Recent File List + +[Adobe Elements Organizer *] +LangSecRef=3023 +Detect=HKCU\Software\Adobe\Elements Organizer +Default=False +FileKey1=%AppData%\Adobe\amecommand\6.0|Plugin Loading.log +FileKey2=%AppData%\Adobe\Elements Organizer\*\Organizer|*.txt;status.dat +FileKey3=%AppData%\Adobe\Elements Smart Tag Agent\*\Logs|*.log +FileKey4=%AppData%\Adobe\LogTransport2\Logs|*.*|RECURSE +FileKey5=%CommonAppData%|StreamingMediaTechnologyLog.txt +FileKey6=%CommonAppData%\Adobe\Elements Organizer\Catalogs\My Catalog|face.thumb.9.cache;thumb.5.cache +FileKey7=%CommonAppData%\Adobe\Elements Organizer\Catalogs\My Catalog\FaceAnalysis|FaceAnalysis.cache +FileKey8=%CommonAppData%\Adobe\Elements Organizer\Catalogs\My Catalog\WaldoData|waldo.cache +FileKey9=%CommonAppData%\Adobe\Elements Organizer\Catalogs\My Catalog\Watch Folder|*.txt;*.xml +RegKey1=HKCU\Software\Adobe\Elements Organizer\11.0\CurrentMediaFilePath +RegKey2=HKCU\Software\Adobe\Elements Organizer\12.0\CurrentMediaFilePath +RegKey3=HKCU\Software\Adobe\Elements Organizer\13.0\CurrentMediaFilePath +RegKey4=HKCU\Software\Adobe\Elements Organizer\14.0\CurrentMediaFilePath +RegKey5=HKCU\Software\Adobe\Elements Organizer\15.0\CurrentMediaFilePath +RegKey6=HKCU\Software\Adobe\Elements Organizer\16.0\CurrentMediaFilePath +RegKey7=HKCU\Software\Adobe\Elements Organizer\17.0\CurrentMediaFilePath + +[Adobe Flash Player *] +LangSecRef=3023 +Detect=HKCU\Software\Macromedia\FlashPlayer +DetectFile=%AppData%\Adobe\Flash Player +Default=False +FileKey1=%AppData%\Adobe\Flash Player\*Cache|*.*|RECURSE +FileKey2=%WinDir%\System32\Macromed\Flash|FlashInstall*.log;install.log +FileKey3=%WinDir%\SysWOW64\Macromed\Flash|FlashInstall*.log;install.log + +[Adobe Media Cache *] +LangSecRef=3023 +DetectFile=%AppData%\Adobe\Common\Media Cache +Default=False +Warning=Do not use this until all your Premiere projects have been completed. +FileKey1=%AppData%\Adobe\Common\* Cache*|*.*|RECURSE +FileKey2=%AppData%\Adobe\Common\Peak Files|*.*|RECURSE + +[Adobe Photoshop Elements *] +LangSecRef=3023 +Detect=HKCU\Software\Adobe\Photoshop Elements +Default=False +FileKey1=%AppData%\Adobe\LogTransport2\Logs|*.*|RECURSE +FileKey2=%AppData%\Adobe\Photoshop Elements\*\Editor|*.txt +FileKey3=%CommonAppData%\Adobe\Photoshop Elements\File Agent|WatchFolder.3.cache +RegKey1=HKCU\Software\Adobe\Photoshop Elements\11.0\common\settings\Elements MRU +RegKey2=HKCU\Software\Adobe\Photoshop Elements\11.0\CurrentMediaFilePath +RegKey3=HKCU\Software\Adobe\Photoshop Elements\11.0\VisitedDirs|STARTUPIMAGEDIRECTORY +RegKey4=HKCU\Software\Adobe\Photoshop Elements\12.0\common\settings\Elements MRU +RegKey5=HKCU\Software\Adobe\Photoshop Elements\12.0\CurrentMediaFilePath +RegKey6=HKCU\Software\Adobe\Photoshop Elements\12.0\VisitedDirs|STARTUPIMAGEDIRECTORY +RegKey7=HKCU\Software\Adobe\Photoshop Elements\13.0\common\settings\Elements MRU +RegKey8=HKCU\Software\Adobe\Photoshop Elements\13.0\CurrentMediaFilePath +RegKey9=HKCU\Software\Adobe\Photoshop Elements\13.0\VisitedDirs|STARTUPIMAGEDIRECTORY +RegKey10=HKCU\Software\Adobe\Photoshop Elements\14.0\common\settings\Elements MRU +RegKey11=HKCU\Software\Adobe\Photoshop Elements\14.0\CurrentMediaFilePath +RegKey12=HKCU\Software\Adobe\Photoshop Elements\14.0\VisitedDirs|STARTUPIMAGEDIRECTORY +RegKey13=HKCU\Software\Adobe\Photoshop Elements\15.0\common\settings\Elements MRU +RegKey14=HKCU\Software\Adobe\Photoshop Elements\15.0\CurrentMediaFilePath +RegKey15=HKCU\Software\Adobe\Photoshop Elements\15.0\VisitedDirs|STARTUPIMAGEDIRECTORY +RegKey16=HKCU\Software\Adobe\Photoshop Elements\16.0\common\settings\Elements MRU +RegKey17=HKCU\Software\Adobe\Photoshop Elements\16.0\CurrentMediaFilePath +RegKey18=HKCU\Software\Adobe\Photoshop Elements\16.0\VisitedDirs|STARTUPIMAGEDIRECTORY +RegKey19=HKCU\Software\Adobe\Photoshop Elements\17.0\common\settings\Elements MRU +RegKey20=HKCU\Software\Adobe\Photoshop Elements\17.0\CurrentMediaFilePath +RegKey21=HKCU\Software\Adobe\Photoshop Elements\17.0\VisitedDirs|STARTUPIMAGEDIRECTORY + +[Adobe Premiere Elements *] +LangSecRef=3023 +Detect=HKCU\Software\Adobe\Premiere Elements +Default=False +FileKey1=%AppData%\Adobe\Common\Thumbnail Cache|thumbnailDB +FileKey2=%AppData%\Adobe\LogTransport2\Logs|*.*|RECURSE +FileKey3=%AppData%\Adobe\Premiere Elements\*|Plugin Loading.log +FileKey4=%AppData%\Adobe\Premiere Elements\*\logs|*.*|RECURSE +FileKey5=%Documents%\Adobe\Premiere Elements\*|*.log +FileKey6=%Documents%\NewBlueFX\Logs|*.txt +RegKey1=HKCU\Software\Adobe\Premiere Elements\11.0\MRUDocuments +RegKey2=HKCU\Software\Adobe\Premiere Elements\12.0\MRUDocuments +RegKey3=HKCU\Software\Adobe\Premiere Elements\13.0\MRUDocuments +RegKey4=HKCU\Software\Adobe\Premiere Elements\14.0\MRUDocuments +RegKey5=HKCU\Software\Adobe\Premiere Elements\15.0\MRUDocuments +RegKey6=HKCU\Software\Adobe\Premiere Elements\16.0\MRUDocuments +RegKey7=HKCU\Software\Adobe\Premiere Elements\17.0\MRUDocuments + +[Adobe Reader 2017 *] +LangSecRef=3021 +Detect=HKCU\Software\Adobe\Acrobat Reader\2017 +Default=False +RegKey1=HKCU\Software\Adobe\Acrobat Reader\2017\AVGeneral\cRecentFiles +RegKey2=HKCU\Software\Adobe\Acrobat Reader\2017\AVGeneral\cRecentFolders + +[Adobe Reader DC *] +LangSecRef=3021 +Detect=HKLM\Software\Adobe\Acrobat Reader\DC +Default=False +FileKey1=%LocalAppData%\Adobe\Acrobat\DC|UserCache.bin +RegKey1=HKCU\Software\Adobe\Acrobat Reader\DC\AVConversionFromPDF +RegKey2=HKCU\Software\Adobe\Acrobat Reader\DC\AVConversionToPDF +RegKey3=HKCU\Software\Adobe\Acrobat Reader\DC\AVGeneral\cDockables +RegKey4=HKCU\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentToolsList +RegKey5=HKCU\Software\Adobe\Acrobat Reader\DC\AVGeneral\cToolbars +RegKey6=HKCU\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles +RegKey7=HKCU\Software\Adobe\Acrobat Reader\DC\ShareIdentity +RegKey8=HKCU\Software\Adobe\Adobe Synchronizer\DC + +[Adobe Reader Touch *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga +DetectFile=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga +Default=False +FileKey1=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE +FileKey2=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\PRICache|*.* +FileKey3=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\LocalState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga\PersistedPickerData\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga!App\DefaultOpenFileSingle|LastLocation +RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga\PersistedStorageItemTable\MostRecentlyUsed + +[Adobe Reader XI *] +LangSecRef=3021 +Detect=HKCU\Software\Adobe\Acrobat Reader\11.0 +Default=False +RegKey1=HKCU\Software\Adobe\Acrobat Reader\11.0\AVConversionFromPDF +RegKey2=HKCU\Software\Adobe\Acrobat Reader\11.0\AVConversionToPDF +RegKey3=HKCU\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cDockables +RegKey4=HKCU\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cToolbars +RegKey5=HKCU\Software\Adobe\Acrobat Reader\11.0\RememberedViews\cNoCategoryFiles +RegKey6=HKCU\Software\Adobe\Adobe Synchronizer\11.0 + +[Advanced Browser *] +LangSecRef=3022 +DetectFile=%AppData%\Advanced Browser +Default=False +FileKey1=%AppData%\Advanced Browser|keywords.dat;pages.dat;recents.dat + +[Advanced Renamer 3 *] +LangSecRef=3024 +DetectFile=%AppData%\Hulubulu\Advanced Renamer 3 +Default=False +FileKey1=%AppData%\Hulubulu\Advanced Renamer 3\Data\UndoLists|*.* + +[Advanced Searchbar *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\AdvancedSearchbar\advancedsearchbar.dll +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\AdvancedSearchbar\Cache|*.* + +[Advanced System Optimizer 3 *] +LangSecRef=3024 +Detect=HKLM\Software\Systweak\ASO3 +DetectFile=%ProgramFiles%\Advanced System Optimizer 3\ASO3.exe +Default=False +FileKey1=%AppData%\Systweak\ASO3\Driver Updater|*.log +FileKey2=%AppData%\Systweak\ASO3\Registry Cleaner|*.log + +[Advanced System Protector *] +LangSecRef=3024 +Detect=HKCU\Software\Systweak\Advanced System Protector +DetectFile=%ProgramFiles%\Advanced System Protector\AdvancedSystemProtector.exe +Default=False +FileKey1=%AppData%\Systweak\Advanced System Protector\Logs|*.xml + +[Advanced Uninstaller *] +LangSecRef=3024 +Detect1=HKCU\Software\Innovative Solutions\Advanced Uninstaller PRO\9 +Detect2=HKCU\Software\Innovative Solutions\Advanced Uninstaller PRO\10 +Default=False +RegKey1=HKCU\Software\Innovative Solutions\Advanced Uninstaller PRO\9\compress|listHistoryText +RegKey2=HKCU\Software\Innovative Solutions\Advanced Uninstaller PRO\10\compress|listHistoryText + +[AdwCleaner *] +LangSecRef=3024 +Detect=HKLM\Software\AdwCleaner +DetectFile=%SystemDrive%\AdwCleaner +Default=False +FileKey1=%SystemDrive%|AdwCleaner*.txt +FileKey2=%SystemDrive%\AdwCleaner|*.txt +RegKey1=HKLM\Software\AdwCleaner|DeleteCount +RegKey2=HKLM\Software\AdwCleaner|SearchCount +RegKey3=HKLM\Software\Wow6432node\AdwCleaner|DeleteCount +RegKey4=HKLM\Software\Wow6432node\AdwCleaner|SearchCount + +[Aegisub *] +LangSecRef=3023 +Detect=HKLM\Software\Aegisub +Default=False +FileKey1=%AppData%\Aegisub|mru.json +FileKey2=%AppData%\Aegisub\log|*.*|REMOVESELF +FileKey3=%AppData%\Aegisub\recovered|*.*|REMOVESELF +FileKey4=%LocalAppData%\Aegisub\ffms2cache|*.*|REMOVESELF +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Aegisub|*.txt +FileKey6=%ProgramFiles%\Aegisub|*.txt + +[Aegisub Backups *] +LangSecRef=3023 +Detect=HKLM\Software\Aegisub +Default=False +Warning=Aegisub automatically saves a backup copy of each script you open. This will delete them. +FileKey1=%AppData%\Aegisub\autoback|*.*|REMOVESELF +FileKey2=%AppData%\Aegisub\autosave|*.*|REMOVESELF + +[Age of Conan *] +Section=Games +Detect=HKLM\Software\Funcom\Age of Conan +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Funcom\Age of Conan|patcher.log;chrome_debug.log;MiniDump.dmp;CrashLog.txt;ConanPatcher.exe.0.tmp;AgeOfConan.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Funcom\Age of Conan\OldLogs|*.* +FileKey3=%ProgramFiles%\Funcom\Age of Conan|patcher.log;chrome_debug.log;MiniDump.dmp;CrashLog.txt;ConanPatcher.exe.0.tmp;AgeOfConan.log +FileKey4=%ProgramFiles%\Funcom\Age of Conan\OldLogs|*.* + +[Age of Empires *] +Section=Games +Detect1=HKLM\Software\Microsoft\Games\Age of Empires +Detect2=HKLM\Software\Microsoft\Microsoft Games\Age of Empires +Detect3=HKLM\Software\Microsoft\microsoft games\age of empires 3 +Default=False +FileKey1=%Documents%\My Games\Age of Empires 3|*.txt +FileKey2=%Documents%\My Games\Age of Empires 3\RM|*.dmp.txt +FileKey3=%Documents%\My Games\Age of Mythology|*.txt +RegKey1=HKLM\Software\Microsoft\Games\Age of Empires\1.00|Zone +RegKey2=HKLM\Software\Microsoft\Microsoft Games\Age of Empires|Zone +RegKey3=HKLM\Software\Microsoft\Microsoft Games\Age of Empires Expansion\1.0|Zone +RegKey4=HKLM\Software\Microsoft\Microsoft Games\Age of Empires II: The Conquerors Expansion\1.0|Zone +RegKey5=HKLM\Software\Microsoft\Microsoft Games\Age of Empires\2.0|Zone + +[Age of Empires Online *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\105430 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Age Of Empires Online|PatchLog.txt;PatchLogDetail.txt +FileKey2=%ProgramFiles%\Steam\steamapps\common\Age Of Empires Online|PatchLog.txt;PatchLogDetail.txt + +[Age of Oracles Taras Journey *] +Section=Games +DetectFile=%CommonAppData%\JollyBear\Age of Oracles Taras Journey +Default=False +FileKey1=%CommonAppData%\JollyBear\Age of Oracles Taras Journey|error.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\JollyBear\Age of Oracles Taras Journey|error.* + +[Age of Wonders II *] +Section=Games +DetectFile=%ProgramFiles%\Age of Wonders II +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Age of Wonders II|*aow2Log.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Age of Wonders II\Resource\FX\Spell|*.lnk +FileKey3=%ProgramFiles%\Age of Wonders II|*aow2Log.txt +FileKey4=%ProgramFiles%\Age of Wonders II\Resource\FX\Spell|*.lnk + +[Age of Wonders Shadow Magic *] +Section=Games +DetectFile=%ProgramFiles%\Age of Wonders II +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Age of Wonders Shadow Magic|*aowsmLog.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Age of Wonders Shadow Magic\Resource\Maps|*.bak +FileKey3=%ProgramFiles%\Age of Wonders Shadow Magic|*aowsmLog.txt +FileKey4=%ProgramFiles%\Age of Wonders Shadow Magic\Resource\Maps|*.bak + +[Agnitum Outpost Pro *] +LangSecRef=3022 +Detect=HKLM\Software\Agnitum\Outpost Firewall +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Agnitum\Outpost Firewall|op_data.mdb +FileKey2=%ProgramFiles%\Agnitum\Outpost Firewall|op_data.mdb + +[Agomo *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Piriform\Agomo +Default=False +FileKey1=%CommonAppData%\Piriform\Agomo\Logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Agomo\Logs|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Agomo\tmp_update|*.* +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Piriform\Agomo\Logs|*.* +FileKey5=%ProgramFiles%\Agomo\Logs|*.* +FileKey6=%ProgramFiles%\Agomo\tmp_update|*.* + +[AHA Dialer *] +LangSecRef=3022 +Detect=HKLM\System\CurrentControlSet\Services\HWDeviceService.exe +DetectFile=%CommonAppData%\DatacardService\DataCardMonitor.exe +Default=False +FileKey1=%CommonAppData%\DatacardService\log|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\DatacardService\log|*.* + +[AI Roboform *] +LangSecRef=3022 +Detect=HKCU\Software\Siber Systems +Default=False +FileKey1=%AppData%\RoboForm\_*mirrors_|*.*|RECURSE +FileKey2=%Documents%\My RoboForm Data|mru.rfo;cache.rfo|RECURSE +FileKey3=%Documents%\My RoboForm Data\_gsdata_|*.log;*.gss;*.gsl|RECURSE +RegKey1=HKCU\Software\Siber Systems|_InstallerDir +RegKey2=HKCU\Software\Siber Systems\RoboForm\Query-MRU + +[AIDA64 *] +LangSecRef=3021 +Detect=HKCU\Software\FinalWire\AIDA64 +Default=False +FileKey1=%Documents%\AIDA64 Reports|*.*|REMOVESELF + +[Aignes Website-Watcher *] +LangSecRef=3023 +Detect=HKCU\Software\aignes\wswatch +Default=False +FileKey1=%AppData%\aignes\WebSite-Watcher\config\favicons|*.* +FileKey2=%AppData%\aignes\website-watcher\config\log|*.* +FileKey3=%AppData%\aignes\WebSite-Watcher\config\settings|*.cfg_bak* +FileKey4=%AppData%\aignes\website-watcher\config\temp|*.* + +[Aignes Website-Watcher AutoBackup *] +LangSecRef=3023 +Detect=HKCU\Software\aignes\wswatch +Default=False +Warning=This will delete your AutoBackup of your site. +FileKey1=%AppData%\aignes\website-watcher\config\autobackup|*.* + +[Aignes Website-Watcher Bookmarks *] +LangSecRef=3023 +Detect=HKCU\Software\aignes\wswatch +Default=False +FileKey1=%AppData%\aignes\website-watcher\bookmarks|*.* + +[AIM *] +LangSecRef=3022 +DetectFile=%LocalAppData%\AOL\AIM +Default=False +FileKey1=%LocalAppData%\AOL\AIM|*.log|RECURSE +FileKey2=%LocalAppData%\AOL\AIM\cache|*.*|REMOVESELF + +[Aimersoft DRM Media Converter *] +LangSecRef=3023 +Detect=HKLM\Software\Aimersoft\351 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Aimersoft\DRM Media Converter\Log|*.*|REMOVESELF +FileKey2=%ProgramFiles%\Aimersoft\DRM Media Converter\Log|*.*|REMOVESELF + +[Aimersoft Helper Compact *] +LangSecRef=3021 +DetectFile=%CommonProgramFiles%\Aimersoft\Aimersoft Helper Compact +Default=False +FileKey1=%CommonProgramFiles%\Aimersoft\Aimersoft Helper Compact|ProductUpdateLists.xml;ASHelper.exe_temp;ASHelperSetup.exe_temp +FileKey2=%CommonProgramFiles%\Aimersoft\Aimersoft Helper Compact\DATADICT|*.*|RECURSE +FileKey3=%CommonProgramFiles%\Aimersoft\Aimersoft Helper Compact\Log|*.*|RECURSE +FileKey4=%CommonProgramFiles%\Aimersoft\Aimersoft Helper Compact\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Common Files\Aimersoft\Aimersoft Helper Compact|ProductUpdateLists.xml;ASHelper.exe_temp;ASHelperSetup.exe_temp +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Common Files\Aimersoft\Aimersoft Helper Compact\Log|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Common Files\Aimersoft\Aimersoft Helper Compact\Temp|*.*|RECURSE +RegKey1=HKLM\Software\Aimersoft\Aimersoft Helper Compact +RegKey2=HKLM\Software\Wow6432Node\Aimersoft\Aimersoft Helper Compact + +[Aimersoft Video Converter Ultimate *] +LangSecRef=3023 +Detect=HKLM\Software\Aimersoft\Aimersoft Video Converter Ultimate +Default=False +FileKey1=%CommonAppData%\Aimersoft\ProductFeatures\*Logs|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Aimersoft\Video Converter Ultimate\TempThumbDir|*.*|RECURSE +FileKey3=%ProgramFiles%\Aimersoft\Video Converter Ultimate\TempThumbDir|*.*|RECURSE + +[AIMP *] +LangSecRef=3023 +DetectFile1=%ProgramFiles%\AIMP Classic\cAIMP.exe +DetectFile2=%ProgramFiles%\AIMP\AIMP.exe +DetectFile3=%ProgramFiles%\AIMP2\AIMP2.exe +Default=False +FileKey1=%AppData%\AIMP|*.bak +FileKey2=%LocalAppData%\VirtualStore\Program Files*\AIMP*\Data|*.bak|RECURSE +FileKey3=%ProgramFiles%\AIMP*\!Backup|*.*|REMOVESELF +FileKey4=%ProgramFiles%\AIMP*\Data|*.bak|RECURSE + +[AirBuccaneers *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\223630 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\AirBuccaneers\abu_data|output_log.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\AirBuccaneers\logs|*.* +FileKey3=%ProgramFiles%\Steam\Steamapps\common\AirBuccaneers\abu_data|output_log.txt +FileKey4=%ProgramFiles%\Steam\Steamapps\common\AirBuccaneers\logs|*.* + +[Aiseesoft Media Converter Ultimate *] +LangSecRef=3023 +Detect=HKCU\Software\Aiseesoft Studio\Aiseesoft Media Converter Ultimate +Default=False +FileKey1=%LocalAppData%\Aiseesoft Studio\Aiseesoft Media Converter Ultimate|*.txt +RegKey1=HKCU\Software\Aiseesoft Studio\Aiseesoft Media Converter Ultimate\Edit|LastVideoFilePath + +[AlbumPlayer *] +LangSecRef=3023 +DetectFile=%AppData%\AlbumPlayer +Default=False +FileKey1=%SystemDrive%\AlbumPlayerData\Logging|*.*|RECURSE + +[AlbumPlayer Cache *] +LangSecRef=3023 +DetectFile=%AppData%\AlbumPlayer +Default=False +FileKey1=%SystemDrive%\AlbumPlayerData\Cache|*.*|RECURSE + +[Alcohol 52% *] +LangSecRef=3023 +Detect=HKCU\Software\Alcohol Soft +Default=False +RegKey1=HKCU\Software\Alcohol Soft\Alcohol 52%\Basic|Image File Path +RegKey2=HKCU\Software\Alcohol Soft\Alcohol 52%\Images +RegKey3=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageName + +[Alibaba *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Alibaba\AliSetup +Default=False +FileKey1=%LocalAppData%\Alibaba\AliSetup\*|*.log + +[Alien Swarm *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\630 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\alien swarm\swarm|tilegen_log.txt +FileKey2=%ProgramFiles%\Steam\steamapps\common\alien swarm\swarm|tilegen_log.txt + +[Aliens: Colonial Marines *] +Section=Games +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Aliens: Colonial Marines_is1 +Default=False +FileKey1=%Documents%\My Games\Aliens Colonial Marines\PecanGame\Logs|*.* + +[All In One Runtimes *] +LangSecRef=3024 +DetectFile1=%SystemDrive%\AiO-Files +DetectFile2=%SystemDrive%\AiOLog.txt +Default=False +FileKey1=%SystemDrive%|AiOLog.txt +FileKey2=%SystemDrive%\AiO-Files|*.*|RECURSE + +[All Office Converter *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\All Office Converter Platinum +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\All Office Converter Platinum|Eventlog.txt +FileKey2=%ProgramFiles%\All Office Converter Platinum|Eventlog.txt + +[All Zombies Must Die! *] +Section=Games +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\All Zombies Must Die!_is1 +Default=False +FileKey1=%Documents%\My Games\UnrealEngine3\Bzb2Game\Logs|*.* + +[All Zombies Must Die! Installers *] +Section=Games +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\All Zombies Must Die!_is1 +Default=False +FileKey1=%ProgramFiles%\Doublesix Games\All Zombies Must Die!\Prerequisites|*.*|REMOVESELF + +[AllDup *] +LangSecRef=3024 +DetectFile=%AppData%\AllDup +Default=False +FileKey1=%AppData%\AllDup|*.log + +[Alternate File Shredder *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Alternate File Shredder_is1 +Default=False +FileKey1=%AppData%\Alternate\FileShredder|FileShredderLog*.txt + +[Always Right *] +LangSecRef=3024 +Detect=HKCU\Software\AlwaysRight +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Superhunter\Always Right\*Backup|*.* +FileKey2=%ProgramFiles%\Superhunter\Always Right\*Backup|*.* + +[Alwin 6 *] +LangSecRef=3023 +DetectFile=%SystemDrive%\alwin6 +Default=False +FileKey1=%SystemDrive%\alwin6\postgresql\9.0\data\pg_log|*.* + +[AM-DeadLink *] +LangSecRef=3022 +Detect=HKCU\Software\aignes\deadlink +Default=False +FileKey1=%AppData%\aignes\AM-DeadLink|deadlink.log + +[Amaya *] +LangSecRef=3022 +DetectFile=%UserProfile%\amaya +Default=False +FileKey1=%UserProfile%\amaya|list_url_utf8.dat +FileKey2=%UserProfile%\amaya\*|*.*|REMOVESELF + +[Amazing World *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\293500 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\Amazing World\AmazingWorld_Data|output_log.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Amazing World\Cache|*.*|REMOVESELF +FileKey3=%ProgramFiles%\Steam\SteamApps\common\Amazing World\AmazingWorld_Data|output_log.txt +FileKey4=%ProgramFiles%\Steam\SteamApps\Common\Amazing World\Cache|*.*|REMOVESELF + +[Amazon Cloud Player *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Amazon Cloud Player +Default=False +FileKey1=%LocalAppData%\Amazon Cloud Player\Logs|*.* + +[Amazon Downloader *] +LangSecRef=3024 +DetectFile=%Documents%\Amazon Downloader Logs +Default=False +FileKey1=%Documents%\Amazon Downloader Logs|*.*|RECURSE + +[Amazon Kindle for PC *] +LangSecRef=3023 +Detect=HKCU\Software\Amazon\Kindle +Default=False +FileKey1=%LocalAppData%\Amazon\Kindle\Cache|*.*|RECURSE +FileKey2=%LocalAppData%\Amazon\Kindle\Logs|*.txt|RECURSE + +[Amazon Kindle for PC Session *] +LangSecRef=3023 +Detect=HKCU\Software\Amazon\Kindle +Default=False +RegKey1=HKCU\Software\Amazon\Kindle\User Settings|last_getitems_date +RegKey2=HKCU\Software\Amazon\Kindle\User Settings|last_syncmetadata_date +RegKey3=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate0 +RegKey4=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate1 +RegKey5=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate2 +RegKey6=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate3 +RegKey7=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate4 +RegKey8=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate5 +RegKey9=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate6 +RegKey10=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate7 +RegKey11=HKCU\Software\Amazon\Kindle\User Settings|OpenBook + +[Amazon MP3 Downloader *] +LangSecRef=3023 +Detect1=HKCR\Amazon.AmazonMP3DownloaderPlugin +Detect2=HKCR\Software\Amazon\MP3 Downloader +Default=False +FileKey1=%Documents%\Amazon MP3\Logs|*.*|REMOVESELF +FileKey2=%LocalAppData%\Program Files\Amazon\MP3 Downloader|InstallerLog.txt + +[Amazon Music *] +LangSecRef=3024 +Detect=HKCU\Software\Amazon\Amazon Music +Default=False +FileKey1=%LocalAppData%\Amazon Music\Logs|*.* + +[AMD/ATI *] +LangSecRef=3024 +Detect1=HKLM\Software\AMD +Detect2=HKLM\Software\ATI +Detect3=HKLM\Software\ATI Technologies +DetectFile=%ProgramFiles%\ATI Technologies\ATI.ACE +Default=False +FileKey1=%CommonAppData%\AMD\Fuel|*.txt +FileKey2=%CommonAppData%\AMD\KDB|*.log +FileKey3=%LocalAppData%\AMD\Fuel|ClientProxyLog*.* +FileKey4=%LocalAppData%\AMD\GLCache|*.*|RECURSE +FileKey5=%LocalAppData%\ATI\ACE|*.txt +FileKey6=%LocalAppData%\VirtualStore\Program Files*\AMD\amdkmpfd|*.*|REMOVESELF +FileKey7=%LocalAppData%\VirtualStore\Program Files*\AMD\OverDrive|*.log +FileKey8=%LocalAppData%\VirtualStore\Program Files*\ATI Technologies|*.log|RECURSE +FileKey9=%LocalAppData%\VirtualStore\Program Files*\ATI Technologies|cccutil64.txt +FileKey10=%LocalAppData%\VirtualStore\Program Files*\ATI\CIM\Reports|*.* +FileKey11=%LocalAppData%\VirtualStore\ProgramData\AMD\Fuel|*.txt +FileKey12=%LocalAppData%\VirtualStore\ProgramData\AMD\KDB|*.log +FileKey13=%ProgramFiles%\AMD\amdkmpfd|*.*|REMOVESELF +FileKey14=%ProgramFiles%\AMD\OverDrive|*.log +FileKey15=%ProgramFiles%\ATI Technologies|*.log|RECURSE +FileKey16=%ProgramFiles%\ATI Technologies|cccutil64.txt +FileKey17=%ProgramFiles%\ATI\CIM\Reports|*.* +FileKey18=%SystemDrive%\AMD|*.*|REMOVESELF +FileKey19=%SystemDrive%\ATI|*.*|REMOVESELF +FileKey20=%WinDir%\System32|CCCInstall*.log +FileKey21=%WinDir%\SysWOW64|CCCInstall*.log + +[America's Army 2 *] +Section=Games +DetectFile=%ProgramFiles%\USArmy\America's Army 2 +Default=False +FileKey1=%LocalAppData%\AA2DeployClient|debug*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\USArmy\America's Army 2|*.log|RECURSE +FileKey3=%ProgramFiles%\USArmy\America's Army 2|*.log|RECURSE + +[Amnesia The Dark Descent *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\57300 +Default=False +FileKey1=%Documents%\Amnesia|*.log|RECURSE + +[Amsn *] +LangSecRef=3022 +Detect=HKCU\Software\aMSN +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\amsn\scripts\amsn_received|*.incomplete +FileKey2=%ProgramFiles%\amsn\scripts\amsn_received|*.incomplete +FileKey3=%UserProfile%\amsn\*\FT\cache|*.* +FileKey4=%UserProfile%\amsn\*\logs\*|*.log +FileKey5=%UserProfile%\amsn\*\winks\cache\tmp|*.* +FileKey6=%UserProfile%\amsn\displaypic\cache|*.* + +[AMYUNI PDF Converter *] +LangSecRef=3021 +DetectFile=%CommonAppData%\Package Cache\3DBECED19CFC2819A7E0BE14463CF18FC8720D91\amyuni_pdfconverter_5_00 +Default=False +FileKey1=%CommonAppData%\Package Cache\3DBECED19CFC2819A7E0BE14463CF18FC8720D91\amyuni_pdfconverter_5_00|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Package Cache\3DBECED19CFC2819A7E0BE14463CF18FC8720D91\amyuni_pdfconverter_5_00|*.log|RECURSE + +[And Yet It Moves *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\18700 +Default=False +FileKey1=%AppData%\Broken Rules\And Yet It Moves Steam|console.log + +[Android Notifier Desktop *] +LangSecRef=3022 +DetectFile=%UserProfile%\.android\android-notifier-desktop +Default=False +FileKey1=%UserProfile%\.android\android-notifier-desktop|android-notifier-desktop.* + +[Android Studio *] +LangSecRef=3021 +Detect=HKCU\Software\Android Open Source Project\Emulator +Default=False +FileKey1=%UserProfile%\.AndroidStudio2.3\system\log|*.*|REMOVESELF +FileKey2=%UserProfile%\.AndroidStudio2.3\system\tmp|*.* +FileKey3=%UserProfile%\.gradle|*.log|RECURSE + +[Anfibia Switch *] +LangSecRef=3021 +Detect=HKCU\Software\Anfibia Switch +Default=False +FileKey1=%CommonAppData%\Anfibia Switch|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Anfibia Switch|*.log|RECURSE + +[Angry Birds Space *] +Section=Games +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\1ED5AEA5.AngryBirdsSpace_p2gbknwb5d8r2 +DetectFile=%LocalAppData%\Packages\1ED5AEA5.AngryBirdsSpace_p2gbknwb5d8r2 +Default=False +FileKey1=%LocalAppData%\Packages\*.AngryBirdsSpace_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\*.AngryBirdsSpace_*\AC\Microsoft\CryptnetUrlCache\*|*.* + +[Angry Birds Star Wars *] +Section=Games +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\1ED5AEA5.AngryBirdsBlack_p2gbknwb5d8r2 +DetectFile=%LocalAppData%\Packages\1ED5AEA5.AngryBirdsBlack_p2gbknwb5d8r2 +Default=False +FileKey1=%LocalAppData%\Packages\*.AngryBirdsBlack_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\*.AngryBirdsBlack_*\AC\Microsoft\CryptnetUrlCache\*|*.* + +[Anim8or *] +LangSecRef=3021 +Detect=HKCU\Software\Silicon Valley Software\Anim8or +Default=False +RegKey1=HKCU\Software\Silicon Valley Software\Anim8or|File1 +RegKey2=HKCU\Software\Silicon Valley Software\Anim8or|File2 +RegKey3=HKCU\Software\Silicon Valley Software\Anim8or|File3 +RegKey4=HKCU\Software\Silicon Valley Software\Anim8or|File4 + +[Anki Backups *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Anki\Anki.exe +Default=False +FileKey1=%AppData%\.anki\backups|*.* + +[Annie's Millions *] +Section=Games +DetectFile=%AppData%\PoBros\Annies Millions +Default=False +FileKey1=%AppData%\PoBros\Annies Millions|logfile.txt + +[ANNO 2070 *] +Section=Games +DetectFile=%AppData%\Ubisoft\ANNO 2070 +Default=False +FileKey1=%AppData%\Ubisoft\ANNO 2070\Cache|*.*|REMOVESELF +FileKey2=%AppData%\Ubisoft\ANNO 2070\Logs|*.log;*.dmp|RECURSE + +[Antichamber *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\105430 +Default=False +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Antichamber\UDKGame\Logs|*.* + +[Anvisoft Cloud System Booster *] +LangSecRef=3024 +Detect=HKLM\Software\Anvisoft\Cloud System Booster +Default=False +FileKey1=%LocalAppData%\Anvisoft\Anvi Slim Toolbar\FFToobar\tmp|*.*|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Anvisoft\Cloud System Booster|*.log;*.txt +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Anvisoft\Cloud System Booster\logs|*.* +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Anvisoft\Cloud System Booster\reports|*.* +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Anvisoft\Cloud System Booster\VLog|*.* +FileKey6=%ProgramFiles%\Anvisoft\Cloud System Booster|*.log;*.txt +FileKey7=%ProgramFiles%\Anvisoft\Cloud System Booster\logs|*.* +FileKey8=%ProgramFiles%\Anvisoft\Cloud System Booster\reports|*.* +FileKey9=%ProgramFiles%\Anvisoft\Cloud System Booster\VLog|*.* + +[Anvisoft Cloud System Booster Backups *] +LangSecRef=3024 +Detect=HKLM\Software\Anvisoft\Cloud System Booster +Default=False +Warning=This will delete your backups. You will be unable to undo any changes made with Cloud System Booster. +FileKey1=%LocalAppData%\Anvisoft\Anvi Slim Toolbar\FFToobar|*.*|REMOVESELF +FileKey2=%LocalAppData%\Anvisoft\Anvi Slim Toolbar\IEToobar|*.*|REMOVESELF +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Anvisoft\Cloud System Booster\bak|*.* +FileKey4=%ProgramFiles%\Anvisoft\Cloud System Booster\bak|*.* + +[AnvSoft Any Audio Converter *] +LangSecRef=3023 +Detect=HKCU\Software\AnvSoft\Any Audio Converter +Default=False +FileKey1=%AppData%\AnvSoft\Any Audio Converter|*.log + +[AnvSoft Any DVD Converter *] +LangSecRef=3023 +Detect=HKCU\Software\AnvSoft\Any DVD Converter Professional +Default=False +FileKey1=%AppData%\AnvSoft\Any DVD Converter Professional|*.log + +[AnvSoft Any DVD Converter Database *] +LangSecRef=3023 +Detect=HKCU\Software\AnvSoft\Any DVD Converter Professional +Default=False +FileKey1=%AppData%\AnvSoft\Any DVD Converter Professional|*.db + +[AnvSoft Any Video Converter *] +LangSecRef=3023 +Detect=HKCU\Software\AnvSoft\Any Video Converter +Default=False +FileKey1=%AppData%\AnvSoft\Any Video Converter|*.log|RECURSE +FileKey2=%AppData%\AnvSoft\Any Video Converter\thumbs|*.*|RECURSE + +[Anvsoft Any Video Converter Output *] +LangSecRef=3023 +Detect=HKCU\Software\AnvSoft\Any Video Converter +Default=False +Warning=This will delete the contents of your output folder. +FileKey1=%Documents%\Any Video Converter|*.*|RECURSE + +[AnyDVD *] +LangSecRef=3023 +Detect=HKCU\Software\SlySoft\AnyDVD +Default=False +FileKey1=%Documents%\AnyDVD_logs|*.*|REMOVESELF + +[AOL *] +LangSecRef=3022 +Detect=HKCU\Software\America Online +Default=False +FileKey1=%AppData%\AOL\C_AOL*|*.tmp|RECURSE +FileKey2=%CommonAppData%\AOL Downloads|*.*|RECURSE +FileKey3=%CommonAppData%\AOL\C_AOL*|*.tmp|RECURSE +FileKey4=%CommonAppData%\AOL\C_AOL*\bart|*.*|RECURSE +FileKey5=%CommonAppData%\AOL\C_AOL*\spool|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\AOL Downloads|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\ProgramData\AOL\C_AOL*|*.tmp|RECURSE +FileKey8=%LocalAppData%\VirtualStore\ProgramData\AOL\C_AOL*\bart|*.*|RECURSE +FileKey9=%LocalAppData%\VirtualStore\ProgramData\AOL\C_AOL*\spool|*.*|RECURSE +RegKey1=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent IM ScreenNames +RegKey2=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent ScreenNames +RegKey3=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\Users + +[APC PowerChute Personal Edition *] +LangSecRef=3024 +Detect=HKCU\Software\APC\PowerChute Personal Edition +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\APC\PowerChute Personal Edition|PCPELog.txt +FileKey2=%ProgramFiles%\APC\PowerChute Personal Edition|PCPELog.txt +FileKey3=%WinDir%\System32|PCPELog.txt +FileKey4=%WinDir%\SysWOW64|PCPELog.txt + +[ApHeMo *] +LangSecRef=3022 +Detect=HKCU\Software\KC Softwares\ApHeMo +Default=False +FileKey1=%AppData%\ApHeMo|*.log + +[Apple iTunes *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AppleInc.iTunes_nzyj5cx40ttqa +DetectFile=%LocalAppData%\Packages\AppleInc.iTunes_nzyj5cx40ttqa +Default=False +FileKey1=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Local\Apple Computer\iTunes|Cache.db;*.xml +FileKey5=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Local\Microsoft\Windows\Caches|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\iTunes\Cookies|Cookies.binarycookies +FileKey8=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\iTunes\Device Support|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\Logs|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\AppleInc.iTunes_*\SystemAppData\Helium\Cache|*.*|RECURSE +FileKey11=%LocalAppData%\Packages\AppleInc.iTunes_*\TempState|*.*|RECURSE +FileKey12=%WinDir%\System32\config\systemprofile\AppData\Roaming\Apple Computer\Logs|*.*|RECURSE + +[Apple MobileSync Backups *] +LangSecRef=3023 +Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AppleInc.iTunes_nzyj5cx40ttqa +Detect2=HKLM\Software\Apple Computer, Inc. +Default=False +FileKey1=%AppData%\Apple Computer\MobileSync\Backup|*.*|RECURSE +FileKey2=%UserProfile%\Apple\MobileSync\Backup|*.*|RECURSE + +[Application History *] +LangSecRef=3025 +DetectFile=%LocalAppData%\ApplicationHistory +Default=False +FileKey1=%LocalAppData%\ApplicationHistory|*.*|RECURSE + +[Appupdater *] +LangSecRef=3024 +DetectFile=%AppData%\Appupdater +Default=False +FileKey1=%AppData%\Appupdater|appupdaterw.log +FileKey2=%CommonAppData%\Appupdater|*.log +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Appupdater|*.log + +[AQQ *] +LangSecRef=3022 +Detect1=HKCU\Software\MyPortal\AQQ +Detect2=HKCU\Software\Wapster\AQQ +Default=False +FileKey1=%LocalAppData%\MyPortal\AQQ Folder\Profiles\*\Data\*Avatars|*.* +FileKey2=%UserProfile%\WapSter\AQQ Folder\Profiles\*\Data\*Avatars|*.* + +[AQQ Cache *] +LangSecRef=3022 +Detect1=HKCU\Software\MyPortal\AQQ +Detect2=HKCU\Software\Wapster\AQQ +Default=False +FileKey1=%LocalAppData%\MyPortal\AQQ Folder\Profiles\*\Data\*Cache|*.* +FileKey2=%UserProfile%\WapSter\AQQ Folder\Profiles\*\Data\*Cache|*.* + +[AQQ Chat History *] +LangSecRef=3022 +Detect1=HKCU\Software\MyPortal\AQQ +Detect2=HKCU\Software\Wapster\AQQ +Default=False +FileKey1=%LocalAppData%\MyPortal\AQQ Folder\Profiles\*\Data\Archive|*.DC2 +FileKey2=%LocalAppData%\MyPortal\AQQ Folder\Profiles\*\Data\Temp|*.* +FileKey3=%UserProfile%\WapSter\AQQ Folder\Profiles\*\Data\Archive|*.DC2 +FileKey4=%UserProfile%\WapSter\AQQ Folder\Profiles\*\Data\Temp|*.* + +[Arasan Chess *] +Section=Games +Detect=HKCU\Software\Arasan\Arasan +Default=False +RegKey1=HKCU\Software\Arasan\Arasan\Recent File List + +[Arcane Worlds *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\269610 +Default=False +FileKey1=%AppData%\ArcaneWorlds|log.txt + +[ArcSoft MediaConverter *] +LangSecRef=3023 +Detect=HKLM\Software\arcsoft\mediaconverter +Default=False +FileKey1=%AppData%\ArcSoft\ArcSoft MediaConverter\*|saved.proj +FileKey2=%AppData%\ArcSoft\log|*.log + +[Argus Monitor *] +LangSecRef=3024 +Detect=HKCU\Software\Argotronic\Argus Monitor +Default=False +FileKey1=%Documents%|ArgusMonitor_EventLog.txt;ArgusMonitor_CSVLog.csv +FileKey2=%LocalAppData%\VirtualStore\Program Files*|ArgusMonitor_EventLog.txt;ArgusMonitor_CSVLog.csv +FileKey3=%ProgramFiles%|ArgusMonitor_EventLog.txt;ArgusMonitor_CSVLog.csv + +[ARO *] +LangSecRef=3024 +Detect1=HKCU\Software\Sammsoft\ARO\Version 2011 +Detect2=HKCU\Software\Sammsoft\ARO\Version 2013 +Default=False +FileKey1=%AppData%\Sammsoft\ARO\Version *\Logs|*.txt + +[Ashampoo Burning Studio *] +LangSecRef=3021 +Detect1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5 +Detect2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6 +Detect3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7 +Detect4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8 +Detect5=HKCU\Software\Ashampoo\Ashampoo Burning Studio 12 +Detect6=HKCU\Software\Ashampoo\Ashampoo Burning Studio 14 +Detect7=HKCU\Software\Ashampoo\Ashampoo Burning Studio 15 +Detect8=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16 +Detect9=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18 +Detect10=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19 +Detect11=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007 +Detect12=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2009 +Detect13=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016 +Detect14=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017 +Detect15=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018 +Default=False +FileKey1=%AppData%\Ashampoo|*.log;*.txt;*.xml|RECURSE +FileKey2=%LocalAppData%\Ashampoo\BaNT|*.*|RECURSE +RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Burn Image Project\SelectImage +RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\AddDialog +RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\DumpImage +RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Unknown Project\AddDialog +RegKey5=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Burn Image Project\SelectImage +RegKey6=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Data Disc Project\AddDialog +RegKey7=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Unknown Project\AddDialog +RegKey8=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Burn Image Project\SelectImage +RegKey9=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Data Disc Project\AddDialog +RegKey10=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Unknown Project\AddDialog +RegKey11=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8\Data Disc Project\AddDialog +RegKey12=HKCU\Software\Ashampoo\Ashampoo Burning Studio 14\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory +RegKey13=HKCU\Software\Ashampoo\Ashampoo Burning Studio 14\tempFiles +RegKey14=HKCU\Software\Ashampoo\Ashampoo Burning Studio 15\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory +RegKey15=HKCU\Software\Ashampoo\Ashampoo Burning Studio 15\tempFiles +RegKey16=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory +RegKey17=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Backup Project\BackupOptions|CustomLocation +RegKey18=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\BDMV Disc Project\SelectBDMVFolder|BdmvPath +RegKey19=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Browse Image Project\BrowseImageFile|ImagePath +RegKey20=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey21=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey22=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Burn Image Project\SelectImage|ImagePath +RegKey23=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Data Disc Project\DumpImage|ImagePath +RegKey24=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory +RegKey25=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\DVD-Video Disc Project\MoviesPage|Path +RegKey26=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\DVD-Video Disc Project\SaveDialog_authed.CMoviesPage.Movies|InitialDirectory +RegKey27=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Logs +RegKey28=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\tempFiles +RegKey29=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Unknown Project +RegKey30=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VCD Project\SaveDialog_OnAddMovies|InitialDirectory +RegKey31=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VIDEO_TS Disc Project\DumpImage|ImagePath +RegKey32=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath +RegKey33=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory +RegKey34=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Backup Project\BackupOptions|CustomLocation +RegKey35=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\BDMV Disc Project\SelectBDMVFolder|BdmvPath +RegKey36=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Browse Image Project\BrowseImageFile|ImagePath +RegKey37=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey38=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey39=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Burn Image Project\SelectImage|ImagePath +RegKey40=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Data Disc Project\DumpImage|ImagePath +RegKey41=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory +RegKey42=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\DVD-Video Disc Project\MoviesPage|Path +RegKey43=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\DVD-Video Disc Project\SaveDialog_authed.CMoviesPage.Movies|InitialDirectory +RegKey44=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Logs +RegKey45=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\tempFiles +RegKey46=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Unknown Project +RegKey47=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\VCD Project\SaveDialog_OnAddMovies|InitialDirectory +RegKey48=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\VIDEO_TS Disc Project\DumpImage|ImagePath +RegKey49=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath +RegKey50=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory +RegKey51=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Backup Project\BackupOptions|CustomLocation +RegKey52=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\BDMV Disc Project\SelectBDMVFolder|BdmvPath +RegKey53=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Browse Image Project\BrowseImageFile|ImagePath +RegKey54=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey55=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey56=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Burn Image Project\SelectImage|ImagePath +RegKey57=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Data Disc Project\DumpImage|ImagePath +RegKey58=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory +RegKey59=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\DVD-Video Disc Project\MoviesPage|Path +RegKey60=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\DVD-Video Disc Project\SaveDialog_authed.CMoviesPage.Movies|InitialDirectory +RegKey61=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Logs +RegKey62=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\tempFiles +RegKey63=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Unknown Project +RegKey64=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\VCD Project\SaveDialog_OnAddMovies|InitialDirectory +RegKey65=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\VIDEO_TS Disc Project\DumpImage|ImagePath +RegKey66=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath +RegKey67=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Burn Image Project\AddDialog +RegKey68=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Data Disc Project\AddDialog +RegKey69=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Dump Image Project\DumpImage +RegKey70=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Unknown Project\AddDialog +RegKey71=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory +RegKey72=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Backup Project\BackupOptions|CustomLocation +RegKey73=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Browse Image Project\BrowseImageFile|ImagePath +RegKey74=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey75=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey76=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Burn Image Project\SelectImage|ImagePath +RegKey77=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Data Disc Project\DumpImage|ImagePath +RegKey78=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory +RegKey79=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Logs +RegKey80=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\tempFiles +RegKey81=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Unknown Project +RegKey82=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\VCD Project\SaveDialog_OnAddMovies|InitialDirectory +RegKey83=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\VIDEO_TS Disc Project\DumpImage|ImagePath +RegKey84=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath +RegKey85=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory +RegKey86=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Backup Project\BackupOptions|CustomLocation +RegKey87=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Browse Image Project\BrowseImageFile|ImagePath +RegKey88=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey89=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey90=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Burn Image Project\SelectImage|ImagePath +RegKey91=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Data Disc Project\DumpImage|ImagePath +RegKey92=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory +RegKey93=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Logs +RegKey94=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\tempFiles +RegKey95=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Unknown Project +RegKey96=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\VCD Project\SaveDialog_OnAddMovies|InitialDirectory +RegKey97=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\VIDEO_TS Disc Project\DumpImage|ImagePath +RegKey98=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath +RegKey99=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory +RegKey100=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Backup Project\BackupOptions|CustomLocation +RegKey101=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Browse Image Project\BrowseImageFile|ImagePath +RegKey102=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey103=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory +RegKey104=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Burn Image Project\SelectImage|ImagePath +RegKey105=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Data Disc Project\DumpImage|ImagePath +RegKey106=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory +RegKey107=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Logs +RegKey108=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\tempFiles +RegKey109=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Unknown Project +RegKey110=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\VCD Project\SaveDialog_OnAddMovies|InitialDirectory +RegKey111=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\VIDEO_TS Disc Project\DumpImage|ImagePath +RegKey112=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath + +[Ashampoo Snap *] +LangSecRef=3024 +Detect1=HKCU\Software\Ashampoo\Ashampoo Snap 7 +Detect2=HKCU\Software\Ashampoo\Ashampoo Snap 8 +Detect3=HKCU\Software\Ashampoo\Ashampoo Snap 9 +Detect4=HKCU\Software\Ashampoo\Ashampoo Snap 10 +Detect5=HKCU\Software\Ashampoo\Ashampoo Snap 2017 +Detect6=HKCU\Software\Ashampoo\Ashampoo Snap 2018 +Default=False +FileKey1=%AppData%\Ashampoo|*.log;*.txt;*.xml|RECURSE +FileKey2=%LocalAppData%\Ashampoo\BaNT|*.*|RECURSE +FileKey3=%LocalAppData%\CrashRpt\UnsentCrashReports|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Ashampoo\Ashampoo Snap *|_NLogMsg.txt +FileKey5=%ProgramFiles%\Ashampoo\Ashampoo Snap *|_NLogMsg.txt + +[Ashampoo Snap AutoSave *] +LangSecRef=3024 +Detect1=HKCU\Software\Ashampoo\Ashampoo Snap 7 +Detect2=HKCU\Software\Ashampoo\Ashampoo Snap 8 +Detect3=HKCU\Software\Ashampoo\Ashampoo Snap 9 +Detect4=HKCU\Software\Ashampoo\Ashampoo Snap 10 +Default=False +FileKey1=%Pictures%\Ashampoo Snap *\_SNAPDOC|*.*|RECURSE + +[Ashley Jones - The Heart Of Egypt *] +Section=Games +DetectFile=%CommonAppData%\Fenomen Games\Ashley Jones - The Heart Of Egypt +Default=False +FileKey1=%CommonAppData%\Fenomen Games\Ashley Jones - The Heart Of Egypt|*.log + +[AstroGrep *] +LangSecRef=3024 +Detect=HKCU\Software\AstroGrep +Default=False +FileKey1=%AppData%\AstroGrep|AstroGrep.general.config +FileKey2=%AppData%\AstroGrep\Log|*.log + +[ASUS Logs *] +LangSecRef=3024 +DetectFile1=%AppData%\ASUS WebStorage +DetectFile2=%CommonAppData%\Asus +DetectFile3=%ProgramFiles%\ASUS\AI Suite +Default=False +FileKey1=%AppData%\ASUS WebStorage\Logs|*.* +FileKey2=%CommonAppData%\Asus\AsusAppStore|*.log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\ASUS\*|*.log;*log*.txt|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Asus\AsusAppStore|*.log|RECURSE +FileKey5=%ProgramFiles%\ASUS\*|*.log;*log*.txt|RECURSE +FileKey6=%SystemDrive%|wifi.log + +[Atheros Driver *] +LangSecRef=3021 +Detect=HKLM\Atheros +Default=False +FileKey1=%CommonAppData%\Atheros|*.log|RECURSE +FileKey2=%CommonAppData%\Qualcomm Atheros WiFi Driver Installation|*.Log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Atheros|*.log|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Qualcomm Atheros WiFi Driver Installation|*.Log|RECURSE + +[Audials 10 *] +LangSecRef=3023 +Detect=HKLM\Software\RapidSolution\Audials_2013 +Default=False +FileKey1=%AppData%\CrashRpt\UnsentCrashReports|*.dmp;*.log;*.xml|RECURSE +FileKey2=%CommonAppData%\RapidSolution\Audials_2013\ChildMSILogs|*.txt +FileKey3=%LocalAppData%\RapidSolution\Audials_2013\Log|*.log;*.txt|RECURSE +FileKey4=%LocalAppData%\RapidSolution\Audials_Software\RapidSolution\Audials_2013\Log|*.log;*.txt|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\RapidSolution\Audials_2013\ChildMSILogs|*.txt + +[Audio Sliders *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Audio Sliders +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Audio Sliders|*.log +FileKey2=%ProgramFiles%\Audio Sliders|*.log + +[Audio/Video Stats *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%LocalAppData%|DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini + +[AudioGrail *] +LangSecRef=3023 +Detect=HKCU\Software\KC Softwares\AudioGrail +Default=False +FileKey1=%AppData%\KC Softwares\AudioGrail|ag.sel;AudioGrail.log + +[Auslogics BoostSpeed *] +LangSecRef=3024 +Detect=HKCU\Software\Auslogics\BoostSpeed +Default=False +FileKey1=%AppData%\Auslogics|*.htm;*.html;*.log;*.rsc;*.sta;*.xml|RECURSE +FileKey2=%CommonAppData%\Auslogics\BoostSpeed\*.x|*.err;*.htm;*.html;*.log;*.rsc;*.sta;*.xml|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Auslogics\Auslogics BoostSpeed|rdboot.log +FileKey4=%ProgramFiles%\Auslogics\Auslogics BoostSpeed|rdboot.log +RegKey1=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|DiskCleaner.AppLogic.ErrorsFailed +RegKey2=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|DiskCleaner.AppLogic.ErrorsFound +RegKey3=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|DiskCleaner.AppLogic.ErrorsRemoved +RegKey4=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|DiskCleaner.AppLogic.LastScan +RegKey5=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|RegCleaner.AppLogic.ErrorsFailed +RegKey6=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|RegCleaner.AppLogic.ErrorsFound +RegKey7=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|RegCleaner.AppLogic.ErrorsRemoved +RegKey8=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|RegCleaner.AppLogic.LastScan +RegKey9=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|TrackEraser.LastScan.DateTimeHi +RegKey10=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|TrackEraser.LastScan.DateTimeLo +RegKey11=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|TrackEraser.LastScan.FailedToRemove +RegKey12=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|TrackEraser.LastScan.Found +RegKey13=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|TrackEraser.LastScan.Removed +RegKey14=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.DisksList.SelectedDrives +RegKey15=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.DateTime +RegKey16=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.DisksList +RegKey17=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.FilesCount +RegKey18=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsFailed +RegKey19=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsFound +RegKey20=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsRemoved +RegKey21=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal +RegKey22=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.LastScan +RegKey23=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.DisksList.SelectedDrives +RegKey24=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.DateTime +RegKey25=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.DisksList +RegKey26=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.FilesCount +RegKey27=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsFailed +RegKey28=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsFound +RegKey29=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsRemoved +RegKey30=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal +RegKey31=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.LastScan + +[Auslogics Disk Defrag *] +LangSecRef=3024 +Detect1=HKCU\Software\Auslogics\Disk Defrag Portable +Detect2=HKLM\Software\Auslogics\Disk Defrag Portable +Detect3=HKLM\Software\Auslogics\Disk Defrag Professional +Detect4=HKLM\Software\Auslogics\DiskDefrag +Detect5=HKLM\Software\Auslogics\DiskDefrag Portable +Default=False +FileKey1=%AppData%\Auslogics\Disk*Defrag*\Logs|*.*|RECURSE +FileKey2=%AppData%\Auslogics\Disk*Defrag*\Reports|*.*|RECURSE +FileKey3=%CommonAppData%\Auslogics\Disk*Defrag*\*\Reports|*.* +FileKey4=%ProgramFiles%\Auslogics\Disk Defrag Professional|ndefrg.log + +[Auslogics Registry Cleaner *] +LangSecRef=3024 +Detect1=HKCU\Software\Auslogics\Registry Cleaner +Detect2=HKLM\Software\Auslogics\Registry Cleaner\3.x +Detect3=HKLM\Software\Auslogics\Registry Cleaner\4.x +Detect4=HKLM\Software\Auslogics\Registry Cleaner\5.X +Default=False +Warning=This will reset your scan results. +FileKey1=%AppData%\Auslogics|*.htm;*.html;*.log;*.rsc;*.sta;*.xml|RECURSE +FileKey2=%CommonAppData%\Auslogics\Registry Cleaner\*.x|*.htm;*.html;*.log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Auslogics\Registry Cleaner\*.x|*.htm;*.html;*.log|RECURSE +RegKey1=HKCU\Software\Auslogics\Registry Cleaner\2.x\Settings|RegCleaner.AppLogic.ErrorsFailed +RegKey2=HKCU\Software\Auslogics\Registry Cleaner\2.x\Settings|RegCleaner.AppLogic.ErrorsFound +RegKey3=HKCU\Software\Auslogics\Registry Cleaner\2.x\Settings|RegCleaner.AppLogic.ErrorsRemoved +RegKey4=HKCU\Software\Auslogics\Registry Cleaner\2.x\Settings|RegCleaner.AppLogic.LastScan +RegKey5=HKLM\Software\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsFailed +RegKey6=HKLM\Software\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsFound +RegKey7=HKLM\Software\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsRemoved +RegKey8=HKLM\Software\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal +RegKey9=HKLM\Software\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.LastScan +RegKey10=HKLM\Software\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsFailed +RegKey11=HKLM\Software\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsFound +RegKey12=HKLM\Software\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsRemoved +RegKey13=HKLM\Software\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal +RegKey14=HKLM\Software\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.LastScan +RegKey15=HKLM\Software\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsFailed +RegKey16=HKLM\Software\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsFound +RegKey17=HKLM\Software\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsRemoved +RegKey18=HKLM\Software\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal +RegKey19=HKLM\Software\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.LastScan +RegKey20=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsFailed +RegKey21=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsFound +RegKey22=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsRemoved +RegKey23=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal +RegKey24=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.LastScan +RegKey25=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsFailed +RegKey26=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsFound +RegKey27=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsRemoved +RegKey28=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal +RegKey29=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.LastScan +RegKey30=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsFailed +RegKey31=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsFound +RegKey32=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsRemoved +RegKey33=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal +RegKey34=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.LastScan + +[Auslogics Registry Defrag *] +LangSecRef=3024 +Detect=HKCU\Software\Auslogics\Registry Defrag +Default=False +FileKey1=%AppData%\Auslogics\Registry Defrag\Logs|*.* +FileKey2=%AppData%\Auslogics\Registry Defrag\Reports|*.* + +[Auslogics System Information *] +LangSecRef=3024 +Detect=HKCU\Software\Auslogics\System Information +Default=False +FileKey1=%AppData%\Auslogics\System Information|*.* + +[Authhost *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windows.authhost.sso_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\microsoft.windows.authhost.sso_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\PRICache|*.* +FileKey7=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Temp|*.* +FileKey8=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\LocalState\Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\LocalState\navigationHistory|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\TempState|*.*|RECURSE + +[Auto BCC For MS Outlook *] +LangSecRef=3021 +DetectFile=%AppData%\Add-in Express\Auto BCC For Microsoft Outlook +Default=False +FileKey1=%AppData%\Add-in Express\Auto BCC For Microsoft Outlook|*.log + +[Auto Text Expander *] +LangSecRef=3021 +DetectFile=%AppData%\Winsome Technologies\Auto Text Expander 1.0 +Default=False +FileKey1=%AppData%\Winsome Technologies\Auto Text Expander 1.0|*.log + +[Autobahn *] +LangSecRef=3021 +DetectFile=%UserProfile%\.autobahn +Default=False +FileKey1=%UserProfile%\.autobahn|autobahn-log*.* + +[Autodesk Design Review MRU *] +LangSecRef=3023 +Detect=HKCU\Software\AutoDesk\DWF Common +Default=False +RegKey1=HKCU\Software\AutoDesk\DWF Common\Preferences\MRUList + +[AutoIt3 *] +LangSecRef=3021 +Detect=HKCU\Software\AutoIt v3 +Default=False +FileKey1=%UserProfile%|SciTE.* +RegKey1=HKCU\Software\AutoIt v3\Aut2Exe|LastExeDir +RegKey2=HKCU\Software\AutoIt v3\Aut2Exe|LastIcon +RegKey3=HKCU\Software\AutoIt v3\Aut2Exe|LastIconDir +RegKey4=HKCU\Software\AutoIt v3\Aut2Exe|LastScriptDir + +[AutoPlay Devices *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +Warning=This will clear out devices and drives that you've connected to your computer from AutoPlay. +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\KnownDevices + +[AvaFind *] +LangSecRef=3023 +Detect=HKLM\Software\Think Less Do More Services\AVA Find +Default=False +FileKey1=%AppData%\AvaFind Data|*00.db + +[Avant Browser *] +LangSecRef=3022 +Detect=HKCU\Software\Avant Browser +Default=False +FileKey1=%AppData%\Avant Browser|keywords.dat;pages.dat;recents.dat;reopen.dat + +[Avast *] +LangSecRef=3024 +Detect=HKCU\Software\AVAST Software\Avast +Default=False +FileKey1=%CommonAppData%\AVAST Software\Avast|Log.db;backend.txt +FileKey2=%CommonAppData%\AVAST Software\Avast\backup|*.*|RECURSE +FileKey3=%CommonAppData%\AVAST Software\Avast\log|*.* +FileKey4=%CommonAppData%\AVAST Software\Avast\report|*.txt +FileKey5=%CommonAppData%\AVAST Software\Browser|*.*|RECURSE +FileKey6=%CommonAppData%\AVAST Software\Persistent Data\Avast\Logs|*.log +FileKey7=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Avast|Log.db;backend.txt +FileKey8=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Avast\backup|*.*|RECURSE +FileKey9=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Avast\log|*.* +FileKey10=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Avast\report|*.txt +FileKey11=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Browser|*.*|RECURSE +FileKey12=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Persistent Data\Avast\Logs|*.log +RegKey1=HKCU\Software\AVAST Software\Avast Browser Cleanup + +[AVG *] +LangSecRef=3024 +Detect=HKLM\Software\AVG +Default=False +FileKey1=%AppData%\AVG\Antivirus\log|*.*|RECURSE +FileKey2=%CommonAppData%\AVG\Antivirus|*.old +FileKey3=%CommonAppData%\AVG\Antivirus\GrimeFighter2|*.txt +FileKey4=%CommonAppData%\AVG\Antivirus\log|*.log +FileKey5=%CommonAppData%\AVG\Antivirus\opm|*.*|RECURSE +FileKey6=%CommonAppData%\AVG\Antivirus\report|*.*|RECURSE +FileKey7=%CommonAppData%\Avg\Antivirus\SWCUData\Cache|*.*|RECURSE +FileKey8=%CommonAppData%\Avg\Antivirus\SWCUData\icons|*.*|RECURSE +FileKey9=%CommonAppData%\AVG\Persistent Data\Antivirus\Logs|*.*|RECURSE +FileKey10=%LocalAppData%\AVG\log|*.*|RECURSE +FileKey11=%LocalAppData%\AvgSetupLog|*.*|REMOVESELF +FileKey12=%WinDir%\System32\config\systemprofile\AppData\Local\Avg\log|*.*|RECURSE +FileKey13=%WinDir%\System32\config\systemprofile\AppData\Local\AvgSetupLog|*.*|REMOVESELF +FileKey14=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Avg\log|*.*|RECURSE +FileKey15=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\AvgSetupLog|*.*|REMOVESELF +RegKey1=HKLM\Software\AVG\Antivirus\PUB-Detected +RegKey2=HKLM\Software\AVG\Antivirus\PUB-Removed +RegKey3=HKLM\Software\WOW6432Node\AVG\Antivirus\PUB-Detected +RegKey4=HKLM\Software\WOW6432Node\AVG\Antivirus\PUB-Removed + +[AVG PC TuneUp *] +LangSecRef=3024 +Detect1=HKCU\Software\AVG\AWL\RegistryCleaner +Detect2=HKCU\Software\TuneUp +Default=False +FileKey1=%AppData%\AVG\AWL*\CrashDumps|*.* +FileKey2=%AppData%\TuneUp Software\TuneUp Utilities\CrashDumps|*.* +FileKey3=%CommonAppData%|NTUSER.DAT_tureg_new.LOG1;NTUSER.DAT_tureg_new.LOG2;NTUSER.DAT_tureg_old +FileKey4=%CommonAppData%\TuneUp Software\TuneUp Utilities *|*.log|RECURSE +FileKey5=%LocalAppData%\Avg\AWL*\Log|*.log +FileKey6=%LocalAppData%\Avg\dumps\fmw1|*.* +FileKey7=%LocalAppData%\Avg\Log|*.log;zappapi.log.1|RECURSE +FileKey8=%LocalAppData%\Avg\Log\fmw1|*.* +FileKey9=%LocalAppData%\AvgSetupLog|*.*|REMOVESELF +FileKey10=%LocalAppData%\Microsoft\Windows|USRCLASS.DAT_tureg_new.LOG*;USRCLASS.DAT_tureg_old;NTUSER.DAT_tureg_old +FileKey11=%LocalAppData%\TuneUp Software|*.log|RECURSE +FileKey12=%Public%|NTUSER.DAT_tureg_new.LOG1;NTUSER.DAT_tureg_new.LOG2;NTUSER.DAT_tureg_old +FileKey13=%SystemDrive%\Boot|BCD_tureg_new.LOG*;BCD_tureg_old +FileKey14=%SystemDrive%\Documents and Settings\LocalService*|NTUSER.DAT_tureg_new.LOG*;NTUSER.DAT_tureg_old +FileKey15=%SystemDrive%\Documents and Settings\NetworkService*|NTUSER.DAT_tureg_new.LOG*;NTUSER.DAT_tureg_old +FileKey16=%SystemDrive%\Users\Default\AppData\Local\Avg\Log\tu16|*.log +FileKey17=%UserProfile%|NTUSER.DAT_tureg_new.LOG*;NTUSER.DAT_tureg_old +FileKey18=%WinDir%\ServiceProfiles\LocalService|NTUSER.DAT_tureg_new.LOG*;NTUSER.DAT_tureg_old +FileKey19=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows|USRCLASS.DAT_tureg_old;USRCLASS.DAT_tureg_new.LOG* +FileKey20=%WinDir%\ServiceProfiles\NetworkService|NTUSER.DAT_tureg_new.LOG*;NTUSER.DAT_tureg_old +FileKey21=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows|USRCLASS.DAT_tureg_old;USRCLASS.DAT_tureg_new.LOG* +FileKey22=%WinDir%\System32\config|COMPONENTS_tureg_new.LOG*;COMPONENTS_tureg_old;DEFAULT_tureg_new.LOG*;DEFAULT_tureg_old;SAM_tureg_new.LOG*;SAM_tureg_old;SECURITY_tureg_new.LOG*;SECURITY_tureg_old;Software_tureg_new.LOG*;Software_tureg_old;SYSTEM_tureg_new.LOG*;SYSTEM_tureg_old;DRIVERS_tureg_new.LOG*;DRIVERS_tureg_old;Software_tureg_new;SYSTEM_tureg_new +FileKey23=%WinDir%\System32\config\systemprofile\AppData\Local\Avg\Log\fmw1|*.log;*.log.lock +FileKey24=%WinDir%\System32\config\systemprofile\AppData\Local\Avg\Log\tu16|*.log;*.log.lock +FileKey25=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Avg\Log\fmw1|*.log +FileKey26=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Avg\Log\setup1|*.log +FileKey27=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Avg\Log\tu16|*.log + +[Avi-Mux GUI *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\AVIMuxGUI\AVIMux_GUI.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\AVIMuxGUI|AVI-Mux GUI - Logfile*.*;*.dmp +FileKey2=%ProgramFiles%\AVIMuxGUI|AVI-Mux GUI - Logfile*.*;*.dmp + +[AVI Toolbox *] +LangSecRef=3023 +Detect=HKCU\Software\KC Softwares\AVIToolbox +Default=False +FileKey1=%AppData%\KC Softwares\AVI Toolbox|*.log + +[Aviary Photo Editor *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\57AB5DD0.PhotoEditor_6hb943tstq5q8 +DetectFile=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_6hb943tstq5q8 +Default=False +FileKey1=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE +FileKey4=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\AC\Temp|*.* +FileKey6=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\LocalState|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\TempState|*.*|RECURSE + +[Avidemux *] +LangSecRef=3023 +Detect1=HKLM\Software\Avidemux 2.4 +Detect2=HKLM\Software\Avidemux 2.5 +Detect3=HKLM\Software\Avidemux 2.6 +Default=False +FileKey1=%AppData%\avidemux|admlog.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Avidemux*|admlog.txt + +[Avira AntiVir Desktop *] +LangSecRef=3024 +Detect1=HKCU\Software\Avira\Antivirus +Detect2=HKLM\Software\Avira\AntiVir Desktop +Default=False +FileKey1=%CommonAppData%\Avira\AntiVir*\IPM|*.*|RECURSE +FileKey2=%CommonAppData%\Avira\AntiVir*\REPORTS|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Avira GmbH|*.log|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Avira\AntiVir*\IPM|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Avira\AntiVir*\REPORTS|*.* +FileKey6=%ProgramFiles%\Avira GmbH|*.log|RECURSE + +[Avira Phantom VPN *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Avira\VPN +Default=False +FileKey1=%CommonAppData%\Avira\VPN|*.log + +[Avira System Speedup *] +LangSecRef=3024 +Detect1=HKLM\Software\Avira\Speedup +Detect2=HKLM\Software\AviraSpeedup +Default=False +FileKey1=%CommonAppData%\Avira\Launcher\Logfiles|*.log +FileKey2=%CommonAppData%\Avira\SystemSpeedup\Errors|*.* +FileKey3=%CommonAppData%\Avira\SystemSpeedup\Logs|*.* +FileKey4=%LocalAppData%\AviraSpeedup\logs|*.* + +[AVS Audio Converter 6 *] +LangSecRef=3023 +DetectFile=%AppData%\AVS4YOU\AVSAudioConverter6 +Default=False +FileKey1=%AppData%\AVS4YOU\AVSAudioConverter6|recentfiles.* + +[Awesomium *] +LangSecRef=3021 +DetectFile=%AppData%\Awesomium +Default=False +FileKey1=%AppData%\Awesomium|*.log +FileKey2=%AppData%\Awesomium\*|Archived History;History;Cookies +FileKey3=%AppData%\Awesomium\*\Cache|*.*|REMOVESELF +FileKey4=%AppData%\Awesomium\*\Local Storage|*.*|REMOVESELF + +[Axialis IconWorkshop *] +LangSecRef=3023 +Detect=HKCU\Software\Axialis\IconWorkshop +Default=False +FileKey1=%Documents%\Axialis Librarian\Deleted Items|*.del;*.ii +RegKey1=HKCU\Software\Axialis\IconWorkshop\folders|CurrentExportDirectory +RegKey2=HKCU\Software\Axialis\IconWorkshop\folders|CurrentImportDirectory +RegKey3=HKCU\Software\Axialis\IconWorkshop\folders|CurrentOpenDirectory +RegKey4=HKCU\Software\Axialis\IconWorkshop\rss|MostRecentNewsId +RegKey5=HKCU\Software\Axialis\IconWorkshop\rss|News1 +RegKey6=HKCU\Software\Axialis\IconWorkshop\rss|News2 +RegKey7=HKCU\Software\Axialis\IconWorkshop\rss|News3 +RegKey8=HKCU\Software\Axialis\IconWorkshop\rss|News4 +RegKey9=HKCU\Software\Axialis\IconWorkshop\rss|News5 +RegKey10=HKCU\Software\Axialis\IconWorkshop\rss|News6 +RegKey11=HKCU\Software\Axialis\IconWorkshop\rss|News7 +RegKey12=HKCU\Software\Axialis\IconWorkshop\rss|News8 +RegKey13=HKCU\Software\Axialis\IconWorkshop\rss|News9 +RegKey14=HKCU\Software\Axialis\IconWorkshop\rss|News10 +RegKey15=HKCU\Software\Axialis\IconWorkshop\rss|News11 +RegKey16=HKCU\Software\Axialis\IconWorkshop\rss|News12 +RegKey17=HKCU\Software\Axialis\IconWorkshop\rss|News13 +RegKey18=HKCU\Software\Axialis\IconWorkshop\rss|News14 +RegKey19=HKCU\Software\Axialis\IconWorkshop\rss|News15 +RegKey20=HKCU\Software\Axialis\IconWorkshop\rss|News16 +RegKey21=HKCU\Software\Axialis\IconWorkshop\rss|News17 +RegKey22=HKCU\Software\Axialis\IconWorkshop\rss|News18 +RegKey23=HKCU\Software\Axialis\IconWorkshop\rss|News19 +RegKey24=HKCU\Software\Axialis\IconWorkshop\rss|News20 +RegKey25=HKCU\Software\Axialis\IconWorkshop\rss|UnreadNews + +[AzureWave *] +LangSecRef=3022 +DetectFile=%CommonAppData%\AzureWave +Default=False +FileKey1=%CommonAppData%\AzureWave|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\AzureWave|*.log + +[Babylon *] +LangSecRef=3024 +Detect=HKCU\Software\Babylon\Babylon Translator\UserInfo +Default=False +RegKey1=HKCU\Software\Babylon\Babylon Translator\UserInfo\History + +[Backyard Basketball 2004 *] +Section=Games +DetectFile=%ProgramFiles%\Atari\Backyard Basketball 2004 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Atari\Backyard Basketball 2004|*.log +FileKey2=%ProgramFiles%\Atari\Backyard Basketball 2004|*.log + +[Bad Piggies *] +Section=Games +DetectFile=%ProgramFiles%\Rovio\Bad Piggies +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Rovio\Bad Piggies\BadPiggies_Data|output_log.txt +FileKey2=%ProgramFiles%\Rovio\Bad Piggies\BadPiggies_Data|output_log.txt + +[Baidu PC Faster *] +LangSecRef=3024 +Detect=HKCU\Software\Baidu Security +Default=False +FileKey1=%CommonAppData%\Baidu Security\RpData|*.tmp +FileKey2=%Documents%\Baidu Security\Bav\Dump|*.*|REMOVESELF +FileKey3=%Documents%\Baidu Security\PC Faster\*\Dump|*.*|REMOVESELF +FileKey4=%Documents%\Baidu Security\PC Faster\*\log|*.*|REMOVESELF +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Baidu Security\RpData|*.tmp + +[Baidu Spark *] +LangSecRef=3021 +Detect=HKCU\Software\Baidu +Default=False +FileKey1=%CommonAppData%\Baidu\Spark\AutoUpdate\updatelog|*.* + +[Bandicam *] +LangSecRef=3023 +Detect=HKCU\Software\BANDISOFT\BANDICAM +Default=False +Warning=This will delete the contents of your output folder. +FileKey1=%Documents%\Bandicam|*.*|RECURSE + +[Banished *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\242920 +Default=False +FileKey1=%Documents%\Banished\Save|Crash*.dmp + +[Barnes and Noble Desktop Reader *] +LangSecRef=3021 +DetectFile=%AppData%\Barnes & Noble\BNDesktopReader +Default=False +FileKey1=%AppData%\Barnes & Noble\BNDesktopReader\CachedImages|*.* + +[BartVPN *] +LangSecRef=3022 +DetectFile=%LocalAppData%\BartVPN +Default=False +FileKey1=%LocalAppData%\BartVPN|*.log + +[BATExpert *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\BATExpert +Default=False +FileKey1=%AppData%\KC Softwares\BATExpert|*.log + +[Batman: Arkham Asylum *] +Section=Games +Detect1=HKLM\Software\Eidos Interactive Limited\Batman: Arkham Asylum +Detect2=HKLM\Software\RocksteadyLtd\Batman Arkham Asylum +Default=False +FileKey1=%Documents%\*\Batman Arkham Asylum*\BmGame|*.log|RECURSE + +[Batman: Arkham City *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\57400 +Detect2=HKCU\Software\Valve\Steam\Apps\200260 +Detect3=HKLM\Software\Warner Bros\Batman Arkham City +Default=False +FileKey1=%Documents%\WB Games\Batman Arkham City*\BmGame\Logs|*.* + +[Batman: Arkham Origins *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\209000 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Batman Arkham Origins\SinglePlayer\BMGame\Logs|*.* +FileKey2=%ProgramFiles%\Steam\steamapps\common\Batman Arkham Origins\SinglePlayer\BMGame\Logs|*.* + +[Battle Islands *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\305260 +Default=False +FileKey1=%ProgramFiles%\Steam\SteamApps\Common\Battle Islands\BattleIslands_Data|output_log.txt + +[Battle.net *] +Section=Games +Detect=HKCU\Software\Blizzard Entertainment\Battle.net +Default=False +FileKey1=%CommonAppData%\Battle.net|*.log|RECURSE +FileKey2=%CommonAppData%\Battle.net\*\Logs|*.*|RECURSE +FileKey3=%CommonAppData%\Battle.net\Agent\Agent.*\Logs|*.*|RECURSE +FileKey4=%CommonAppData%\Battle.net\Client\Blizzard Launcher.*\Logs|*.*|RECURSE +FileKey5=%CommonAppData%\Battle.net\Setup\*\Logs|*.* +FileKey6=%CommonAppData%\Battle.net\Telemetry|*.* +FileKey7=%LocalAppData%\Battle.net\Errors|*.* +FileKey8=%LocalAppData%\Battle.net\Logs|*.*|RECURSE +FileKey9=%LocalAppData%\Blizzard Entertainment\System Survey|*.log|RECURSE +FileKey10=%LocalAppData%\Blizzard Entertainment\System Survey|log.txt +FileKey11=%LocalAppData%\VirtualStore\ProgramData\Battle.net|*.log|RECURSE +FileKey12=%LocalAppData%\VirtualStore\ProgramData\Battle.net\*\Logs|*.*|RECURSE +FileKey13=%LocalAppData%\VirtualStore\ProgramData\Battle.net\Agent\Agent.*\Logs|*.*|RECURSE +FileKey14=%LocalAppData%\VirtualStore\ProgramData\Battle.net\Client\Blizzard Launcher.*\Logs|*.*|RECURSE + +[Battle.net Cache *] +Section=Games +Detect=HKCU\Software\Blizzard Entertainment\Battle.net +Default=False +FileKey1=%CommonAppData%\Blizzard Entertainment\Battle.net\Cache|*.*|RECURSE +FileKey2=%LocalAppData%\Battle.net\BrowserCache|*.*|RECURSE +FileKey3=%LocalAppData%\Battle.net\Cache|*.*|RECURSE +FileKey4=%LocalAppData%\Blizzard Entertainment\Battle.net\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Blizzard Entertainment\Battle.net\Cache|*.*|RECURSE + +[Battlefield 3 *] +Section=Games +Detect=HKLM\Software\EA Games\Battlefield 3 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Battlefield 3\__Installer|InstallLog.txt +FileKey2=%ProgramFiles%\Origin Games\Battlefield 3\__Installer|InstallLog.txt + +[BB FlashBack/TestAssistant *] +LangSecRef=3023 +Detect1=HKLM\Software\Blueberry Software\BB FlashBack Express +Detect2=HKLM\Software\Blueberry Software\BB FlashBack Pro 4 +Detect3=HKLM\Software\Blueberry Software\BB FlashBack Standard 4 +Detect4=HKLM\Software\Blueberry Software\BB TestAssistant Expert 4 +Detect5=HKLM\Software\Blueberry Software\BB TestAssistant Pro 4 +Default=False +FileKey1=%AppData%\Blueberry|ExportToAVIStat.txt;ExportToQTStat.txt;ExportToSWFStat.txt;ExportToWMVStat.txt;* CrashTracking.xml;* UsageTracking.xml;RecorderStat.txt;RecorderStaticStat.txt +FileKey2=%AppData%\LogSys|*.*|REMOVESELF +FileKey3=%CommonProgramFiles%\Blueberry Software|*.log +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Blueberry Software\*|drvinstlog.txt;*.log +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Common Files\Blueberry Software|*.log +FileKey6=%ProgramFiles%\Blueberry Software\*|drvinstlog.txt;*.log +FileKey7=%WinDir%\system32\MTSLog|*.*|REMOVESELF + +[Beckhoff TwinCat *] +LangSecRef=3021 +Detect=HKCU\Software\Beckhoff +Default=False +FileKey1=%SystemDrive%\TwinCAT\3.1\Components\TcEventLogger\EventConfigurator|~evtCfgTmp*.html +FileKey2=%UserProfile%|*TwinCat*.log;TC*.log;TF*.log + +[Belarc Advisor *] +LangSecRef=3024 +Detect=HKCU\Software\Belarc +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Belarc\*Advisor\System|Progress.Log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Belarc\*Advisor\System\Security\BelNotify|BelNotify.log;History.log;HistoryHF.log +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Belarc\*Advisor\System\Tmp|*.* +FileKey4=%ProgramFiles%\Belarc\*Advisor|install.log +FileKey5=%ProgramFiles%\Belarc\*Advisor\System|Progress.Log +FileKey6=%ProgramFiles%\Belarc\*Advisor\System\Security\BelNotify|BelNotify.log;History.log;HistoryHF.log +FileKey7=%ProgramFiles%\Belarc\*Advisor\System\Tmp|*.* + +[BestBuy Software Installer *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Best Buy Software Installer +Default=False +FileKey1=%CommonAppData%\Best Buy Software Installer\Resources\Cache|*.* + +[Betrayer *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\105430 +Default=False +FileKey1=%Documents%\Betrayer\UDKGame\Logs|*.* + +[Better Explorer *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Better Explorer +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Better Explorer|log.txt +FileKey2=%ProgramFiles%\Better Explorer|log.txt + +[BetterDiscord *] +LangSecRef=3022 +DetectFile=%AppData%\BetterDiscord +Default=False +FileKey1=%AppData%\BetterDiscord|*.log +FileKey2=%AppData%\BetterDiscord\temp|*.*|REMOVESELF + +[Beyond Compare *] +LangSecRef=3021 +Detect=HKCU\Software\Scooter Software\Beyond Compare +Default=False +FileKey1=%AppData%\Scooter Software\Beyond Compare*|*.bak + +[Big City Adventure *] +Section=Games +Detect1=HKCU\Software\JollyBear\Big City Adventure San Francisco +Detect2=HKCU\Software\JollyBear\Big City Adventure Sydney +Default=False +FileKey1=%CommonAppData%\JollyBear\Big City Adventure *|error.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\JollyBear\Big City Adventure *|error.* + +[Big Fish Games *] +Section=Games +Detect=HKCU\Software\Big Fish Games +Default=False +FileKey1=%CommonAppData%\Big Fish Games\Game Manager\resources-old|*.*|RECURSE +FileKey2=%CommonAppData%\Big Fish\Game Manager\Addons\BFGameLauncher|*.log|RECURSE +FileKey3=%CommonAppData%\BigFishCache\GameManager\log|*.txt|RECURSE +FileKey4=%CommonAppData%\BigFishGamesCache\GameManager\log|*.* +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Big Fish Games\Game Manager\resources-old|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Big Fish\Game Manager\Addons\BFGameLauncher|*.log|RECURSE +FileKey7=%LocalAppData%\VirtualStore\ProgramData\BigFishCache\GameManager\log|*.txt|RECURSE +FileKey8=%LocalAppData%\VirtualStore\ProgramData\BigFishGamesCache\GameManager\log|*.* + +[Big Fish Games Installers *] +Section=Games +Detect=HKCU\Software\Big Fish Games +Default=False +FileKey1=%CommonAppData%\BigFishCache|*.exe|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\BigFishCache|*.exe|RECURSE + +[Binding of Isaac *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\250900 +Detect2=HKCU\Software\Valve\Steam\Apps\570660 +Default=False +FileKey1=%Documents%\My Games\Binding of Isaac *|*.dmp;isaacv*.txt;log.txt + +[Bing Dynamic *] +LangSecRef=3023 +DetectFile=%LocalAppData%\Microsoft\Windows\Themes\BingDynamic1.theme +Default=False +Warning=This will cause you to redownload the Bing Dynamic RSS file. +FileKey1=%LocalAppData%\Microsoft\Feeds|http~c~f~fthemeserver~dmicrosoft~dcom~fdefault~daspx~mp*Bing* + +[Bing Finance *] +DetectOS=6.2|6.3 +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingFinance_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.BingFinance_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\PRICache|*.* +FileKey4=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.BingFinance_*\TempState|*.*|RECURSE + +[Bing Food and Drink *] +DetectOS=6.2|6.3 +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingFoodAndDrink_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.BingFoodAndDrink_*\LocalState\Cache|*.*|RECURSE + +[Bing Health and Fitness *] +DetectOS=6.2|6.3 +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingHealthAndFitness_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.BingHealthAndFitness_*\LocalState\Cache|*.*|RECURSE + +[Bing Maps *] +DetectOS=6.2|6.3 +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingMaps_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.BingMaps_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Microsoft\CLR_v4.0|*.log|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\PRICache|*.* +FileKey7=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Temp|*.* +FileKey8=%LocalAppData%\Packages\Microsoft.BingMaps*\LocalState\Bing.Maps|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.BingMaps*\LocalState\MapInstrumentation|*.* +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingMaps_8wekyb3d8bbwe\SearchHistory + +[Bing Search *] +DetectOS=6.2|6.3 +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Bing_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.Bing_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Bing_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Bing_8wekyb3d8bbwe\SearchHistory + +[Bing Sports *] +DetectOS=6.2|6.3 +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.BingSports_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\PRICache|*.* +FileKey4=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.BingSports_*\LocalState\navigationHistory|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.BingSports_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe\SearchHistory + +[Bing Travel *] +DetectOS=6.2|6.3 +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingTravel_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.BingTravel_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\PRICache|*.* +FileKey4=%LocalAppData%\Packages\Microsoft.BingTravel_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingTravel_8wekyb3d8bbwe\SearchHistory + +[BioShock Infinite *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\8870 +Default=False +FileKey1=%Documents%\my games\BioShock Infinite\Benchmarks|*.* + +[BIT.TRIP *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\63700 +Detect2=HKCU\Software\Valve\Steam\Apps\63710 +Default=False +FileKey1=%LocalAppData%\BIT.TRIP *|*.txt + +[Bitcoin *] +LangSecRef=3022 +Detect1=HKCU\Software\Bitcoin +Detect2=HKCU\Software\Bitcoin Core +Detect3=HKLM\Software\Bitcoin Core +Default=False +FileKey1=%AppData%\Bitcoin|*.log;*.old + +[Bitdefender *] +LangSecRef=3024 +Detect1=HKLM\Software\Bitdefender\Bitdefender Internet Security +Detect2=HKLM\Software\Bitdefender\Bitdefender Total Security +Detect3=HKLM\Software\Bitdefender\Bitdefender Total Security 2015 +Detect4=HKLM\Software\Softwin\Bitdefender Antivirus +Default=False +FileKey1=%AppData%\Bitdefender\Desktop\profiles\Logs\*|*.xml +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Softwin\Bitdefender*\Logs|*.* +FileKey3=%ProgramFiles%\Softwin\Bitdefender*\Logs|*.* +FileKey4=%SystemDrive%|bdlog.txt + +[BitTorrent *] +LangSecRef=3022 +DetectFile1=%AppData%\BitTorrent\BitTorrent.exe +DetectFile2=%ProgramFiles%\BitTorrent\BitTorrent.exe +Default=False +FileKey1=%AppData%\BitTorrent\Updates|*.exe + +[BitTorrent Incomplete Downloads *] +LangSecRef=3022 +Detect=HKCU\Software\BitTorrent +Default=False +FileKey1=%AppData%\BitTorrent\incomplete|*.* + +[BitTorrent Sync *] +LangSecRef=3023 +DetectFile=%AppData%\BitTorrent Sync +Default=False +FileKey1=%AppData%\BitTorrent Sync|*.log;*.old + +[BlackBeltPrivacy DarkNet *] +LangSecRef=3023 +DetectFile=%LocalAppData%\BlackBeltPrivacy +Default=False +FileKey1=%LocalAppData%\BlackBeltPrivacy\3rdParty|*.*|RECURSE +FileKey2=%LocalAppData%\BlackBeltPrivacy\darkNet\logs|*.*|RECURSE +FileKey3=%LocalAppData%\BlackBeltPrivacy\Logs|*.*|RECURSE +FileKey4=%LocalAppData%\BlackBeltPrivacy\MicroSip|MicroSIP.log + +[BlackBerry AddinSync *] +LangSecRef=3021 +DetectFile=%AppData%\Research In Motion\BlackBerry\AddinSync +Default=False +FileKey1=%AppData%\Research In Motion\BlackBerry\AddinSync|sync.log + +[BlackBerry Desktop Software *] +LangSecRef=3023 +Detect=HKCU\Software\Research In Motion\BlackBerry +Default=False +FileKey1=%AppData%|Rim*.log +FileKey2=%AppData%\Research In Motion\BlackBerry Desktop|*.dmp +FileKey3=%LocalAppData%\Research In Motion\BlackBerry*Desktop\*\*|*.backup +FileKey4=%LocalAppData%\Research In Motion\BlackBerry*Desktop\*\*\Log|*.html +FileKey5=%LocalAppData%\Research In Motion\BlackBerry*Desktop\Logs|*.*|REMOVESELF + +[BlackBerry Intellisync *] +LangSecRef=3021 +DetectFile=%AppData%\Research In Motion\BlackBerry\Intellisync +Default=False +FileKey1=%AppData%\Research In Motion\BlackBerry\Intellisync|*.log|RECURSE + +[Blade of Destiny *] +Section=Games +DetectFile=%Documents%\BladeofDestiny +Default=False +FileKey1=%Documents%\BladeofDestiny\Consolelog|*.*|RECURSE + +[Blade Symphony *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\225600 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\Blade Symphony\workshop_temp|*.*|RECURSE +FileKey2=%ProgramFiles%\Steam\Steamapps\common\Blade Symphony\workshop_temp|*.*|RECURSE + +[Blades of Time *] +Section=Games +DetectFile=%LocalAppData%\BladesOfTime +Default=False +FileKey1=%LocalAppData%\BladesOfTime\_debuginfo|*.* + +[BleachBit *] +LangSecRef=3024 +Detect=HKCU\Software\BleachBit +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\BleachBit|bleachbit.exe.log +FileKey2=%ProgramFiles%\BleachBit|bleachbit.exe.log + +[Blender *] +LangSecRef=3023 +Detect=HKLM\Software\BlenderFoundation +Default=False +FileKey1=%AppData%\Blender Foundation\Blender\*\config|recent-files.txt + +[Blimb Entertainment AIRSTRIKE3D *] +Section=Games +DetectFile=%ProgramFiles%\Blimb Entertainment\AIRSTRIKE3D +Default=False +FileKey1=%ProgramFiles%\Blimb Entertainment\AIRSTRIKE3D|*.log + +[Blood Bowl: Legendary Edition *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\58520 +Detect2=HKCU\Software\Valve\TestApp58520 +Default=False +FileKey1=%Documents%\BloodBowlLegendary|BB_LE000.log;CEGUI.log;SystemInfo000.log +FileKey2=%Documents%\BloodBowlLegendary\Cache\3d|*.*|REMOVESELF +FileKey3=%Documents%\BloodBowlLegendary\Cache\DB|*.*|REMOVESELF + +[Blue-Cloner *] +LangSecRef=3023 +Detect=HKCU\Software\Blue-cloner +Default=False +FileKey1=%AppData%\Blue-Cloner|*.log +FileKey2=%AppData%\Blue-Cloner\ReadCache|*.*|REMOVESELF +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Blue-Cloner|*.log;*.txt +FileKey4=%ProgramFiles%\Blue-Cloner|*.log;*.txt + +[BlueGriffon *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Disruptive Innovations SARL\BlueGriffon +Default=False +FileKey1=%LocalAppData%\Disruptive Innovations SARL\BlueGriffon\Profiles\*\Cache|*.*|RECURSE + +[BlueSky Interactive *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\BlueSky Interactive +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\BlueSky Interactive\PTP\Settings|*.tmp +FileKey2=%ProgramFiles%\BlueSky Interactive\PTP\Settings|*.tmp + +[BlueStacks *] +LangSecRef=3021 +Detect1=HKCU\Software\Bluestacks +Detect2=HKLM\Software\Bluestacks +Default=False +FileKey1=%LocalAppData%\VirtualStore\ProgramData\BlueStacks|*.log;*.log.*|RECURSE + +[BlueStacks APKs *] +LangSecRef=3021 +Detect1=HKCU\Software\BlueStacks +Detect2=HKLM\Software\BlueStacks +Default=False +FileKey1=%CommonAppData%\BlueStacksSetup|*.apk +FileKey2=%LocalAppData%\VirtualStore\ProgramData\BlueStacksSetup|*.apk + +[BlueStacks Installer *] +LangSecRef=3021 +Detect1=HKCU\Software\Bluestacks +Detect2=HKLM\Software\Bluestacks +Default=False +Warning=You will have to redownload these files in order to reinstall the application. +FileKey1=%LocalAppData%\VirtualStore\ProgramData\BlueStacksSetup|runtimedata_*.zip;runtimedata_*.zip.manifest +FileKey2=%LocalAppData%\VirtualStore\ProgramData\BlueStacksSetup\Images|*.*|REMOVESELF + +[Bluetack Blocklist Manager *] +LangSecRef=3024 +Detect=HKCU\Software\Bluetack\Blocklist Manager +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Bluetack\Blocklist Manager\Cache|*.* +FileKey2=%ProgramFiles%\Bluetack\Blocklist Manager\Cache|*.* + +[Blumentals Easy GIF Animator *] +LangSecRef=3023 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Easy GIF Animator_is1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Easy GIF Animator|*.txt|RECURSE +FileKey2=%ProgramFiles%\Easy GIF Animator|*.txt|RECURSE + +[Blurity *] +LangSecRef=3023 +DetectFile=%AppData%\Blurity +Default=False +FileKey1=%AppData%\Blurity|event.log + +[Boinc *] +LangSecRef=3024 +Detect=HKCU\Software\Space Sciences Laboratory, U.C. Berkeley\BOINC Manager +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\BOINC|stdout*.*;stderr*.* +FileKey2=%ProgramFiles%\BOINC|stdout*.*;stderr*.* + +[Borderlands *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\8980 +Detect2=HKCU\Software\Valve\Steam\Apps\49520 +Detect3=HKLM\Software\Borderlands +Default=False +FileKey1=%Documents%\My Games\Borderlands*\WillowGame\Logs|*.* + +[Borland C++ Builder 5.0 *] +LangSecRef=3024 +Detect=HKCU\Software\Borland\C++Builder\5.0 +Default=False +RegKey1=HKCU\Software\Borland\C++Builder\5.0\Closed Files +RegKey2=HKCU\Software\Borland\C++Builder\5.0\Closed Projects +RegKey3=HKCU\Software\Borland\C++Builder\5.0\Session + +[Borland Delphi 7 *] +LangSecRef=3024 +Detect=HKCU\Software\Borland\Delphi\7.0 +Default=False +RegKey1=HKCU\Software\Borland\Delphi\7.0\Closed Files +RegKey2=HKCU\Software\Borland\Delphi\7.0\Closed Projects +RegKey3=HKCU\Software\Borland\Delphi\7.0\Session + +[Borland Developer Studio 2006 *] +LangSecRef=3024 +Detect=HKCU\Software\Borland\BDS\4.0 +Default=False +RegKey1=HKCU\Software\Borland\BDS\4.0\Closed Files +RegKey2=HKCU\Software\Borland\BDS\4.0\Closed Projects +RegKey3=HKCU\Software\Borland\BDS\4.0\Session + +[BOSS *] +Section=Games +DetectFile=%SystemDrive%\BOSS +Default=False +FileKey1=%SystemDrive%\BOSS\*|BOSSlog.* + +[Box *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\134D4F5B.Box_2qk4zy5s3qmee +DetectFile=%LocalAppData%\Packages\134D4F5B.Box_2qk4zy5s3qmee +Default=False +FileKey1=%LocalAppData%\Packages\*Box_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\*Box_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\*Box_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE +FileKey4=%LocalAppData%\Packages\*Box_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\*Box_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey6=%LocalAppData%\Packages\*Box_*\AC\PRICache|*.* +FileKey7=%LocalAppData%\Packages\*Box_*\AC\Temp|*.* +FileKey8=%LocalAppData%\Packages\*Box_*\LocalState|*.*|RECURSE + +[Brawlhalla Replays *] +Section=Games +DetectFile=%UserProfile%\BrawlhallaReplays +Default=False +Warning=You will delete your saved replays! +FileKey1=%UserProfile%\BrawlhallaReplays|*.replay|REMOVESELF + +[Breevy Backups *] +LangSecRef=3021 +DetectFile=%AppData%\Breevy +Default=False +FileKey1=%AppData%\Breevy\Backups|*.* + +[Broadcom Wireless LAN Driver *] +LangSecRef=3021 +DetectFile=%SystemDrive%\Drivers\Broadcom Wireless LAN Driver +Default=False +FileKey1=%SystemDrive%\Drivers\Broadcom Wireless LAN Driver|*.log|RECURSE + +[Broforce *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\274190 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Broforce\*\Broforce Logs|*.csv +FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Broforce\*\Broforce Logs|*.csv + +[Broken Shortcut Fixer *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\ConsumerSoft\Broken Shortcut Fixer +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\ConsumerSoft\Broken Shortcut Fixer|ht.htm +FileKey2=%ProgramFiles%\ConsumerSoft\Broken Shortcut Fixer|ht.htm + +[Brother P-touch *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Brother\P-touch Update Software +Default=False +FileKey1=%LocalAppData%\Brother\P-touch Update Software|*.log + +[Brother Printer *] +LangSecRef=3024 +Detect=HKLM\Software\Brother +DetectFile=%CommonAppData%\Brother +Default=False +FileKey1=%CommonAppData%\Brother\BrLog|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Brother|*.tmp|RECURSE +FileKey3=%ProgramFiles%\Brother|*.tmp|RECURSE + +[Brothers - A Tale of Two Sons *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\225080 +Default=False +FileKey1=%Documents%\my games\UnrealEngine3\P13\Logs|*.* + +[BrowserSync *] +LangSecRef=3022 +DetectFile=%AppData%\BrowserSync +Default=False +FileKey1=%AppData%\BrowserSync|log.txt + +[BS Player *] +LangSecRef=3021 +Detect1=HKCU\Software\BST\bsplayer +Detect2=HKCU\Software\BST\bsplayerv1 +DetectFile=%ProgramFiles%\Webteh\BSPlayer\bsplayer.exe +Default=False +FileKey1=%AppData%\BSplayer\AC3 Filter|unreg.log;Changes.txt +FileKey2=%AppData%\BSplayer\cache|*.* +FileKey3=%AppData%\BSplayer\FFDShow|unreg.log +FileKey4=%AppData%\BSplayer\Flash Video (FLV)|unreg.log +FileKey5=%AppData%\BSplayer\Haali media splitter|unreg.log +FileKey6=%AppData%\BSplayer\MPEG*decoder|unreg.log +FileKey7=%AppData%\BSplayer\RealMedia splitter|unreg.log +FileKey8=%LocalAppData%\VirtualStore\Program Files*\Webteh\BSplayerPro|*.jpg +FileKey9=%LocalAppData%\VirtualStore\Program Files*\Webteh\BSplayerPro\cache|*.mpos +FileKey10=%ProgramFiles%\Webteh\BSplayerPro|*.jpg +FileKey11=%ProgramFiles%\Webteh\BSplayerPro\cache|*.mpos + +[BSD *] +LangSecRef=3023 +DetectFile=%AppData%\BSD +Default=False +FileKey1=%AppData%\BSD\*\logs|*.*|RECURSE +FileKey2=%AppData%\BSD\MediaWidget\PodCache|*.*|RECURSE + +[Buchstabenzoo BHV *] +LangSecRef=3021 +DetectFile=%AppData%\bhv-gswvs\users +Default=False +FileKey1=%AppData%\bhv-gswvs\users\*\Buchstabenzoo|*.log + +[Bugsplat *] +LangSecRef=3024 +Detect=HKCU\Software\Bugsplat +Default=False +RegKey1=HKCU\Software\Bugsplat\gaspowered\SupremeCommander +RegKey2=HKCU\Software\Bugsplat\lol_beta_riotgames_com\LOL_Public +RegKey3=HKCU\Software\Bugsplat\Pando_win\Pando +RegKey4=HKCU\Software\Bugsplat\Relic\CoH +RegKey5=HKCU\Software\Bugsplat\Relic\RelicDownloader + +[Bullzip PDF Printer *] +LangSecRef=3022 +DetectFile=%AppData%\PDF Writer\Bullzip PDF Printer +Default=False +FileKey1=%AppData%\PDF Writer\Bullzip PDF Printer|user.ini + +[BumpTop *] +LangSecRef=3021 +Detect=HKCU\Software\Bump Technologies, Inc. +Default=False +FileKey1=%AppData%\Bump Technologies, Inc\BumpTop|*log.txt +FileKey2=%AppData%\Bump Technologies, Inc\BumpTop\Cache|*.*|RECURSE +FileKey3=%LocalAppData%\Bump Technologies, Inc\BumpTop\*Cache|*.*|RECURSE +FileKey4=%LocalAppData%\Bump Technologies, Inc\BumpTop\Previous|*.* +FileKey5=%LocalAppData%\Bump Technologies, Inc\BumpTop\Temp|*.* + +[BumpTop StickyNotes *] +LangSecRef=3021 +Detect=HKCU\Software\Bump Technologies, Inc. +Default=False +FileKey1=%UserProfile%\Desktop|StickyNote*.txt + +[Burger Shop *] +Section=Games +Detect1=HKCU\Software\GoBit\BurgerShop +Detect2=HKCU\Software\GoBit\BurgerShop2 +Default=False +FileKey1=%CommonAppData%\GoBit Games\BurgerShop2\*\cached|*.*|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Burger Shop|*.db;*.txt|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Burger Shop\cached|*.*|REMOVESELF +FileKey4=%LocalAppData%\VirtualStore\Program Files*\GoBit Games\Burger Shop 2|*.db;*.txt|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\GoBit Games\BurgerShop2\*\cached|*.*|REMOVESELF +FileKey6=%ProgramFiles%\Burger Shop|*.db;*.txt|RECURSE +FileKey7=%ProgramFiles%\Burger Shop\cached|*.*|REMOVESELF +FileKey8=%ProgramFiles%\GoBit Games\Burger Shop 2|*.db;*.txt|RECURSE + +[Burn Zombie Burn! *] +Section=Games +Detect=HKLM\Software\Burn Zombie Burn +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\P2 Games\Burn Zombie Burn|*.log +FileKey2=%ProgramFiles%\P2 Games\Burn Zombie Burn|*.log + +[Burn Zombie Burn! .NET Installer *] +Section=Games +Detect=HKLM\Software\Burn Zombie Burn +Default=False +Warning=Make sure .NET framwork 3.0 is installed before running this. +FileKey1=%ProgramFiles%\P2 Games\Burn Zombie Burn\REQS\NET|*.*|REMOVESELF + +[Bus-Simulator 2009 *] +Section=Games +DetectFile=%ProgramFiles%\Bus-Simulator 2009 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Bus-Simulator 2009|*.dmp;*.log|RECURSE +FileKey2=%ProgramFiles%\Bus-Simulator 2009|*.dmp;*.log|RECURSE + +[Business Objects Enterprise 11 *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Business Objects\Business Objects Enterprise 11 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Business Objects\Business Objects Enterprise 11\Logging|*.* +FileKey2=%ProgramFiles%\Business Objects\Business Objects Enterprise 11\Logging|*.* + +[CA Security Center *] +LangSecRef=3021 +Detect=HKLM\Software\CA\CAPF +Default=False +FileKey1=%CommonAppData%\CA|*.log;*.txt|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\CA|*.log;*.txt|RECURSE +FileKey3=%LocalLowAppData%\CA\Consumer\APH|*.log + +[Cached Certification Files *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%LocalLowAppData%\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE +FileKey2=%LocalLowAppData%\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE + +[Cached File Extensions *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +Warning=This possibly will reset default programs back to default on Windows 8/8.1. +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts +RegKey2=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts + +[Cached Shell Extensions *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions +Default=False +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached +RegKey2=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached + +[Calendar Magic *] +LangSecRef=3021 +DetectFile1=%ProgramFiles%\EuroSoft\Calendar Magic +DetectFile2=%SystemDrive%\EuroSoft\Calendar Magic +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\EuroSoft\Calendar Magic|debug.txt +FileKey2=%ProgramFiles%\EuroSoft\Calendar Magic|debug.txt +FileKey3=%SystemDrive%\EuroSoft\Calendar Magic|debug.txt + +[Calendar Magic Backup *] +LangSecRef=3021 +DetectFile1=%ProgramFiles%\EuroSoft\Calendar Magic +DetectFile2=%SystemDrive%\EuroSoft\Calendar Magic +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\EuroSoft\Calendar Magic|*.bak +FileKey2=%ProgramFiles%\EuroSoft\Calendar Magic|*.bak +FileKey3=%SystemDrive%\EuroSoft\Calendar Magic|*.bak + +[Calibre *] +LangSecRef=3021 +DetectFile=%LocalAppData%\calibre-cache\jsbrowser +Default=False +FileKey1=%LocalAppData%\calibre-cache\jsbrowser\data*|*.*|RECURSE + +[Call of Atlantis *] +Section=Games +Detect=HKLM\Software\Playrix\Call of Atlantis +Default=False +FileKey1=%CommonAppData%\Playrix Entertainment\Call of Atlantis\Log|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Playrix Entertainment\Call of Atlantis\Log|*.* + +[Call of Juarez *] +Section=Games +Detect1=HKLM\Software\Techland\CallOfJuarez +Detect2=HKLM\Software\Techland\CallofJuarez2 +Default=False +FileKey1=%Documents%\Call Of Juarez*\Out\logs|*.log|RECURSE + +[Camera *] +LangSecRef=3031 +Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe +Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsCamera_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft*Camera_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft*Camera_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft*Camera_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft*Camera_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\Microsoft*Camera_*\AC\PRICache|*.* +FileKey6=%LocalAppData%\Packages\Microsoft*Camera_*\AC\Temp|*.* +FileKey7=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalCache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\AppData|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\Cache|*.*|RECURSE +FileKey11=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe\SearchHistory + +[Cameyo *] +LangSecRef=3021 +Detect=HKCU\Software\VOS +Default=False +FileKey1=%AppData%\VOS|*.*|REMOVESELF +RegKey1=HKCU\Software\VOS + +[CamStudio *] +LangSecRef=3023 +Detect=HKCU\Software\CamStudioOpenSource for Nick +Default=False +FileKey1=%Documents%\My CamStudio Temp Files|*.* + +[Camtasia Studio 9 *] +LangSecRef=3024 +Detect=HKCU\Software\TechSmith\Camtasia Studio\9.0 +Default=False +RegKey1=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Recorder\9.0\General|lstLastSaveDir +RegKey2=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Studio\9.0|ExportAsZipMru +RegKey3=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Studio\9.0|FileSaveAsMru +RegKey4=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Studio\9.0|MRUImportFolder +RegKey5=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Studio\9.0|MRUOpenProjectFolder +RegKey6=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Studio\9.0|RecentRecordingsMru + +[Canon Digital Photo Professional 4 *] +LangSecRef=3021 +Detect=HKLM\Software\Canon_Inc_IC\DPP4 +DetectFile=%ProgramFiles%\Canon\Digital Photo Professional 4 +Default=False +FileKey1=%AppData%\Canon_Inc_IC\DPP4\Application\Temp|*.*|RECURSE +FileKey2=%AppData%\Canon_Inc_IC\DPP4\DppMWare\Cache|*.*|RECURSE +FileKey3=%AppData%\Canon_Inc_IC\ServiceLog\AutoUpdateService|*.txt +FileKey4=%CommonAppData%\Canon_Inc_IC\UniversalInstaller\ServiceLog|*.TXT + +[Canon Printer *] +LangSecRef=3021 +DetectFile=%CommonAppData%\CanonBJ +Default=False +FileKey1=%CommonAppData%\CanonBJ\IJPrinter\CNMWindows|drvlog*;drvlog*.*;plmlog*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\CanonBJ\IJPrinter\CNMWindows|drvlog*;drvlog*.*;plmlog*.*|RECURSE + +[Canon Zoom Browser *] +LangSecRef=3021 +Detect=HKCU\Software\Canon\ZoomBrowser Ex +DetectFile1=%AppData%\ZoomBrowser EX +DetectFile2=%Pictures%\ZbThumbnail.info +Default=False +FileKey1=%Pictures%|ZbThumbnail.info|RECURSE + +[Captcha Brotherhood *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Captcha_Brotherhood +Default=False +FileKey1=%LocalAppData%\Captcha_Brotherhood|solver_logFile.txt;plugin_logFile.txt;solver_captchaLog.txt + +[CasualArts *] +Section=Games +DetectFile=%AppData%\CasualArts +Default=False +FileKey1=%AppData%\casualArts\*|logfile.*;*.txt|RECURSE +FileKey2=%CommonAppData%\casualArts|*.*|REMOVESELF +FileKey3=%LocalAppData%\VirtualStore\ProgramData\casualArts|*.*|REMOVESELF + +[Cave Story+ *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\200900 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\cave story+|log.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\cave story+\data|*.DS_STORE|RECURSE +FileKey3=%ProgramFiles%\Steam\steamapps\common\cave story+|log.txt +FileKey4=%ProgramFiles%\Steam\steamapps\common\cave story+\data|*.DS_STORE|RECURSE + +[CC Magic *] +Section=Games +DetectFile=%Documents%\Electronic Arts\CC Magic\Logs +Default=False +FileKey1=%Documents%\Electronic Arts\CC Magic\Logs|*.log|RECURSE + +[CCDump *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\CCleaner\CCDump.exe +Default=False +Warning=This removes files winapp.ini, winsys.ini, winreg.ini and regkeys.output.txt from the CCleaner folder. +FileKey1=%ProgramFiles%\CCleaner|winapp.ini;winreg.ini;winsys.ini;regkeys.output.txt + +[CCFinder *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Abelssoft\CCfinder +Default=False +FileKey1=%LocalAppData%\FlickrNet|responseCache.dat + +[CCleaner *] +LangSecRef=3024 +Detect=HKCU\Software\Piriform\CCleaner +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\CCleaner|*.log;CCleaner_log*.txt +FileKey2=%ProgramFiles%\CCleaner|*.log;CCleaner_log*.txt +FileKey3=%ProgramFiles%\CCleaner\Setup|*.*|REMOVESELF +FileKey4=%UserProfile%|CCleaner_log*.txt + +[CCTV Security *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\CCTV Security +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Log|*.* +FileKey2=%ProgramFiles%\CCTV Security\Log|*.* + +[CD/DVD Burn Cache *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning +Default=False +Warning=This will wipe all files that are waiting to be burned to a CD/DVD/BD drive. +FileKey1=%LocalAppData%\Microsoft\CD Burning|*.*|RECURSE +FileKey2=%LocalAppData%\Microsoft\Windows\Burn|*.*|RECURSE +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo + +[CDex *] +LangSecRef=3024 +Detect=HKLM\Software\CDex +Default=False +FileKey1=%Music%\CDDB|*.txt + +[Centarsia *] +LangSecRef=3021 +Detect=HKCU\Software\Centarsia +Default=False +RegKey1=HKCU\Software\Centarsia|RecentImage0 +RegKey2=HKCU\Software\Centarsia|RecentImage1 +RegKey3=HKCU\Software\Centarsia|RecentImage2 +RegKey4=HKCU\Software\Centarsia|RecentImage3 +RegKey5=HKCU\Software\Centarsia|RecentImage4 +RegKey6=HKCU\Software\Centarsia|RecentImage5 +RegKey7=HKCU\Software\Centarsia|RecentImage6 + +[Ceville *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\23460 +Default=False +FileKey1=%AppData%|ceville_console_history.txt +FileKey2=%Documents%\Ceville\logs|*.* + +[CFE Exam Prep Course *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\CFE Exam Prep Course +Default=False +FileKey1=%AppData%\ACFEExamPrep|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\CFE Exam Prep Course\Log|*.*|RECURSE +FileKey3=%ProgramFiles%\CFE Exam Prep Course\Log|*.*|RECURSE + +[Chameleon *] +LangSecRef=3024 +DetectFile=%Documents%\Chameleon Files +Default=False +FileKey1=%Documents%\Chameleon Files\Cache|*.*|RECURSE +FileKey2=%Documents%\Chameleon Files\Log|*.*|RECURSE + +[Champions Online *] +Section=Games +Detect1=HKCU\Software\Cryptic\Champions Online +Detect2=HKCU\Software\Valve\Steam\Apps\9880 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\Common\Champions Online\*\Logs\GameClient|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\Common\Champions Online\Champions Online\*\Cache|*.* +FileKey3=%ProgramFiles%\Steam\Steamapps\Common\Champions Online\*\Logs\GameClient|*.* +FileKey4=%ProgramFiles%\Steam\Steamapps\Common\Champions Online\Champions Online\*\Cache|*.* +FileKey5=%Public%\Games\cryptic studios\Champions Online\*\Cache|*.* +FileKey6=%Public%\Games\cryptic studios\Champions Online\*\Logs\GameClient|*.* + +[Cheat Engine *] +LangSecRef=3021 +Detect=HKCU\Software\Cheat Engine +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Cheat Engine*|*.tmp +FileKey2=%ProgramFiles%\Cheat Engine*|*.tmp + +[CheatBook *] +LangSecRef=3021 +Detect=HKLM\Software\CheatBook +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Cheatbook Database *|*cheatlog.txt;*suchlog.txt +FileKey2=%ProgramFiles%\Cheatbook Database *|*cheatlog.txt;*suchlog.txt + +[Chicken Hunter *] +Section=Games +Detect=HKLM\Software\Chicken Hunter +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Chicken Hunter|debug.txt +FileKey2=%ProgramFiles%\Chicken Hunter|debug.txt + +[Chicken Invaders *] +Section=Games +DetectFile1=%AppData%\InterAction studios\CI3demo +DetectFile2=%ProgramFiles%\Chicken*Invaders* +Default=False +FileKey1=%AppData%\InterAction studios|*.log|RECURSE +FileKey2=%CommonAppData%\InterAction studios|*.log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\*\Chicken Invaders*|*.log;*.html;*.png|RECURSE +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Chicken*Invaders*|*.log|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\InterAction studios|*.log|RECURSE +FileKey6=%ProgramFiles%\*\Chicken Invaders*|*.log;*.html;*.png|RECURSE +FileKey7=%ProgramFiles%\Chicken*Invaders*|*.log|RECURSE + +[Children of the Nile *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\17100 +Default=False +FileKey1=%Documents%\Tilted Mill\Children of the Nile|*.log + +[Chivalry: Medieval Warfare *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\219640 +Default=False +FileKey1=%Documents%\My Games\Chivalry Medieval Warfare*\UDKGame\Logs|*.* + +[Chocolatey *] +LangSecRef=3024 +DetectFile=%CommonAppData%\chocolatey +Default=False +FileKey1=%AppData%\ChocolateyGUI\Logs|*.* +FileKey2=%CommonAppData%\chocolatey\lib\*|*.txt +FileKey3=%CommonAppData%\chocolatey\logs|*.log + +[Christmas Adventure - Candy Storm *] +Section=Games +Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Adventure - Candy Storm1.1 +Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Adventure - Candy Stormv1.3 +DetectFile=%ProgramFiles%\Christmas Adventure - Candy Storm +Default=False +FileKey1=%AppData%\Argali|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Christmas Adventure - Candy Storm|*.nfo;*.txt +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Foxy Games\Christmas Adventure - Candy Storm|*.html;*.msi;*.nfo;*.txt;*.url +FileKey4=%ProgramFiles%\Christmas Adventure - Candy Storm|*.nfo;*.txt +FileKey5=%ProgramFiles%\Foxy Games\Christmas Adventure - Candy Storm|*.html;*.msi;*.nfo;*.txt;*.url + +[Christmas Griddlers 2014 *] +Section=Games +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Griddlers 20141.1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\*\Christmas Griddlers*|*.ico;*.html;*msi;*.nfo;*.txt;*.url|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Christmas Griddlers*|*.ico;*.html;*msi;*.nfo;*.txt;*.url|RECURSE +FileKey3=%ProgramFiles%\*\Christmas Griddlers*|*.ico;*.html;*msi;*.nfo;*.txt;*.url|RECURSE +FileKey4=%ProgramFiles%\Christmas Griddlers*|*.ico;*.html;*msi;*.nfo;*.txt;*.url|RECURSE + +[Christmas Wonderland *] +Section=Games +Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 2 +Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 3 1.0 +Detect3=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 4 1.0.4 +Detect4=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 21.0 +Detect5=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 31.0 +Detect6=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 41.1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Christmas Wonderland *|*.html;*.nfo;*.txt;*.url|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Foxy Games\Christmas Wonderland *|*.html;*.nfo;*.txt;*.url|RECURSE +FileKey3=%ProgramFiles%\Christmas Wonderland *|*.html;*.nfo;*.txt;*.url|RECURSE +FileKey4=%ProgramFiles%\Foxy Games\Christmas Wonderland *|*.html;*.nfo;*.txt;*.url|RECURSE +FileKey5=%SystemDrive%\Games\Christmas Wonderland *|*.html;*.nfo;*.txt;*.url|RECURSE + +[Chuzzle Deluxe *] +Section=Games +DetectFile=%ProgramFiles%\HP Games\Chuzzle Deluxe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\HP Games\Chuzzle Deluxe|DEBUG.TXT +FileKey2=%ProgramFiles%\HP Games\Chuzzle Deluxe|DEBUG.TXT + +[Cinema Tycoon *] +Section=Games +Detect1=HKCU\Software\TikGames\Cinema Tycoon Gold +Detect2=HKLM\Software\Big Fish Games\Persistence\GameDB\Cinema Tycoon Gold +Detect3=HKLM\Software\Big Fish Games\Persistence\Install\F2676T1L1 +Detect4=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Cinema Tycoon 2 Movie Mania1.0 +Default=False +FileKey1=%ProgramFiles%\Cinema Tycoon*|flashplayer7_winax.exe;*.txt + +[Cisco Connect *] +LangSecRef=3022 +DetectFile=%CommonAppData%\Cisco Systems\Cisco Connect +Default=False +FileKey1=%CommonAppData%\Cisco Systems\Cisco Connect\Log|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Cisco Systems\Cisco Connect\Log|*.* + +[Cisco HostScan *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Cisco\Cisco HostScan\log +Default=False +FileKey1=%LocalAppData%\Cisco\Cisco HostScan\log|*.log + +[Cities in Motion *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\73010 +Default=False +FileKey1=%Documents%\Cities in Motion|log_metro.txt + +[Citrix ICA Client *] +LangSecRef=3021 +Detect=HKLM\Software\Citrix\ICA Client +Default=False +FileKey1=%AppData%\Citrix\ICA Client\Cache|*.* +FileKey2=%AppData%\Citrix\ICA Client\Cache\zlcache|*.* +FileKey3=%AppData%\ICAClient|wfcwin32.* +FileKey4=%AppData%\ICAClient\Cache|*.* +FileKey5=%AppData%\ICAClient\Cache\zlcache|*.* +RegKey1=HKLM\Software\Citrix\ICA Client\Default + +[Citrix Online Plug-in Web Setup Files *] +LangSecRef=3021 +Detect=HKLM\Software\Citrix\ICA Client +Default=False +FileKey1=%CommonAppData%\Citrix\Citrix Online Plug-in - Web|*.msi;*.cab;eula*.rtf + +[Civilization 5 Installers *] +Section=Games +Detect=HKCU\Software\Firaxis\Civilization5 +Default=False +Warning=This will remove DirectX and Visual C++ installers in your Civilization 5 installation directory. They can be reinstalled in your installation source. +FileKey1=%ProgramFiles%\Civilization V*\DirectX|*.*|REMOVESELF +FileKey2=%ProgramFiles%\Civilization V*\VCRedist|*.*|REMOVESELF + +[Civilization 5 Old Autosaves *] +Section=Games +Detect=HKCU\Software\Firaxis\Civilization5 +Default=False +FileKey1=%Documents%\My Games\Sid Meier's Civilization 5\Saves\*\auto\prev|*.Civ5Save + +[Civilization Cache *] +Section=Games +Detect1=HKCU\Software\Firaxis\Civilization5 +Detect2=HKLM\Software\Firaxis Games +Default=False +FileKey1=%AppData%\My Games\Beyond the Sword\cache|*.dat +FileKey2=%AppData%\My Games\Sid Meier's Civilization *\cache|*.dat +FileKey3=%AppData%\My Games\Warlords\cache|*.dat +FileKey4=%Documents%\My Games\Sid Meier's Civilization *\cache|*.db +FileKey5=%LocalAppData%\My Games\Beyond the Sword\cache|*.dat +FileKey6=%LocalAppData%\My Games\Sid Meier's Civilization *\cache|*.dat +FileKey7=%LocalAppData%\My Games\Warlords\cache|*.dat + +[Civilization Logs *] +Section=Games +Detect1=HKCU\Software\Firaxis\Civilization5 +Detect2=HKLM\Software\Firaxis Games +Default=False +FileKey1=%Documents%\My Games\Beyond the Sword\Logs|*.* +FileKey2=%Documents%\My Games\Sid Meier's Civilization *\Logs|*.* +FileKey3=%Documents%\My Games\Warlords\Logs|*.* +FileKey4=%LocalAppData%\VirtualStore\Program Files*\2K Games\Firaxis Games\Sid Meier's Civilization IV Colonization|*.txt +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Firaxis Games\Sid Meier's Civilization 4|*.txt +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Firaxis Games\Sid Meier's Civilization 4\*|*.txt +FileKey7=%ProgramFiles%\2K Games\Firaxis Games\Sid Meier's Civilization IV Colonization|*.txt +FileKey8=%ProgramFiles%\Firaxis Games\Sid Meier's Civilization 4|*.txt +FileKey9=%ProgramFiles%\Firaxis Games\Sid Meier's Civilization 4\*|*.txt + +[Clam Sentinel *] +LangSecRef=3021 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{060FE577-1BDF-4330-ACCA-B6760AB07191}_is1 +Default=False +FileKey1=%AppData%\ClamSentinel|*.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\ClamSentinel|*.txt +FileKey3=%ProgramFiles%\ClamSentinel|*.txt + +[ClamWin *] +LangSecRef=3021 +Detect1=HKCU\Software\ClamWin +Detect2=HKLM\Software\ClamWin +Default=False +FileKey1=%AppData%\.clamwin\log|*.*|RECURSE +FileKey2=%CommonAppData%\.clamwin\log|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\ClamWin\bin|*.txt +FileKey4=%ProgramFiles%\ClamWin\bin|*.txt + +[ClamWin Portable Failed Updates *] +LangSecRef=3024 +DetectFile=%SystemDrive%\PortableApps\ClamWinPortable\ClamWinPortable.exe +Default=False +FileKey1=%SystemDrive%\PortableApps\ClamWinPortable\Data\db\clamav*|*.*|REMOVESELF + +[ClassicShell MRU *] +LangSecRef=3024 +Detect=HKCU\Software\IvoSoft\ClassicStartMenu +Default=False +RegKey1=HKCU\Software\IvoSoft\ClassicStartMenu\MRU + +[Clean Genius 3 *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\CleanGenius 3\Update +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\CleanGenius 3\Update|update.log +FileKey2=%ProgramFiles%\CleanGenius 3\Update|update.log + +[CleanMyPC Registry Cleaner *] +LangSecRef=3024 +Detect=HKCU\Software\CleanMyPC\CleanMyPC - Registry Cleaner +Default=False +FileKey1=%AppData%\CleanMyPC Software\CleanMyPC Registry Cleaner|fixlog.ini +FileKey2=%WinDir%\$regcmp$|*.*|REMOVESELF + +[CleanUp! *] +LangSecRef=3024 +Detect=HKCU\Software\stevengould.org\CleanUp! +Default=False +FileKey1=%AppData%|CleanUp!.log + +[Clementine *] +LangSecRef=3023 +Detect=HKCU\Software\Clementine +Default=False +FileKey1=%UserProfile%\.config\Clementine\networkcache\http|*.cache|RECURSE + +[Click.to *] +LangSecRef=3021 +DetectFile=%LocalAppData%\click.to +Default=False +FileKey1=%LocalAppData%\click.to|*.txt|RECURSE + +[ClickFree Full Imaging Backup *] +LangSecRef=3024 +DetectFile=%CommonAppData%\ClickFree\FullImagingBackup +Default=False +FileKey1=%CommonAppData%\ClickFree\FullImagingBackup|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\ClickFree\FullImagingBackup|*.log + +[ClipX *] +LangSecRef=3024 +DetectFile=%LocalAppData%\ClipX +Default=False +FileKey1=%LocalAppData%\ClipX\Storage|*.* + +[CloneSpy *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\CloneSpy +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\CloneSpy|CloneSpy.log +FileKey2=%ProgramFiles%\CloneSpy|CloneSpy.log + +[Cloud Experience Host *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalCache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalState\Cache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\TempState|*.*|RECURSE + +[Cloudfogger *] +LangSecRef=3023 +Detect1=HKCU\Software\Cloudfogger +Detect2=HKCU\Software\Cloudfogger.com +Default=False +FileKey1=%AppData%\Cloudfogger|*.log|RECURSE +FileKey2=%LocalAppData%\CrashRpt|*.log|RECURSE + +[Cloudfogger Keys *] +LangSecRef=3023 +Detect1=HKCU\Software\Cloudfogger +Detect2=HKCU\Software\Cloudfogger.com +Default=False +FileKey1=%AppData%\Cloudfogger\Keys|*.*|RECURSE + +[CloudShark Plugin for Wireshark *] +LangSecRef=3024 +DetectFile=%AppData%\Wireshark\plugins\cloudshark +Default=False +FileKey1=%AppData%\Wireshark\plugins\cloudshark\tmp|*.* + +[Clover *] +LangSecRef=3024 +Detect=HKCU\Software\Clover +Default=False +FileKey1=%LocalAppData%\Clover\User Data\Default\JumpListIcons*|*tmp +FileKey2=%LocalAppData%\Clover\User Data\temp|*.*|RECURSE + +[Clover Bookmarks Backup *] +LangSecRef=3024 +Detect=HKCU\Software\Clover +Default=False +FileKey1=%LocalAppData%\Clover\User Data\Default|Bookmarks.bak + +[Clover Session *] +LangSecRef=3024 +Detect=HKCU\Software\Clover +Default=False +FileKey1=%LocalAppData%\Clover\User Data\Default|Current *;Last * + +[CNET Tech Tracker *] +LangSecRef=3024 +Detect=HKCU\Software\CBS Interactive\CNET TechTracker +Default=False +FileKey1=%AppData%\CBS Interactive\CNET TechTracker\data|temp.html;ztempimages*.png;*.db +FileKey2=%AppData%\CBS Interactive\CNET TechTracker\temp|*.*|REMOVESELF +FileKey3=%Documents%\Downloads\CNET TechTracker|*.* +RegKey1=HKCU\Software\CBS Interactive\CNET TechTracker\Recent File List + +[CNET Tech Tracker Backups *] +LangSecRef=3024 +Detect=HKCU\Software\CBS Interactive\CNET TechTracker +Default=False +FileKey1=%AppData%\CBS Interactive\CNET TechTracker|*.bak + +[CNN *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\588E6FFA.CNNAppforWindows_cs8eyncph15zy +DetectFile=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_cs8eyncph15zy +Default=False +FileKey1=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\Microsoft\CLR_v4.0|*.log +FileKey3=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\Microsoft\CLR_v4.0*\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\PRICache|*.* +FileKey5=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\Temp|*.* +FileKey6=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\TempState|*.*|RECURSE + +[CodeGear RAD Studio 2009 *] +LangSecRef=3024 +Detect=HKCU\Software\CodeGear\BDS\6.0 +Default=False +RegKey1=HKCU\Software\CodeGear\BDS\6.0\Closed Files +RegKey2=HKCU\Software\CodeGear\BDS\6.0\Closed Projects +RegKey3=HKCU\Software\CodeGear\BDS\6.0\Session + +[CodeMeter *] +LangSecRef=3023 +DetectFile=%CommonAppData%\CodeMeter +Default=False +FileKey1=%CommonAppData%\CodeMeter\Logs|*.* + +[CoffeeCup GIF Animator *] +LangSecRef=3024 +Detect=HKCU\Software\CoffeeCup Software\GIF Animator +Default=False +RegKey1=HKCU\Software\CoffeeCup Software\GIF Animator\Settings\MRU + +[Cogs *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\26500 +Default=False +FileKey1=%LocalAppData%\Lazy 8 Studio\Cogs|log.txt + +[ColorSchemer *] +LangSecRef=3023 +Detect=HKCU\Software\ColorSchemer +Default=False +FileKey1=%AppData%\ColorSchemer\Studio\*|recentfiles.xml + +[ComboFix *] +LangSecRef=3024 +DetectFile=%SystemDrive%\Qoobox +Default=False +Warning=This will delete ComboFix History. Do not delete until you have reviewed these logs. +FileKey1=%SystemDrive%|ComboFix.txt +FileKey2=%SystemDrive%\*.tmp|*.*|REMOVESELF +FileKey3=%SystemDrive%\Qoobox|*.txt +FileKey4=%SystemDrive%\Qoobox\LastRun|*.*|REMOVESELF +FileKey5=%SystemDrive%\Qoobox\Quarantine|*.log +FileKey6=%SystemDrive%\Qoobox\Test*|*.*|REMOVESELF + +[Comcast Toolbar *] +LangSecRef=3022 +Detect=HKCU\Software\ComcastToolbar +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\ComcastToolbar\Cache|*.* +FileKey2=%ProgramFiles%\ComcastToolbar\Cache|*.* + +[ComicRack *] +LangSecRef=3021 +DetectFile=%LocalAppData%\cYo\ComicRack +Default=False +FileKey1=%LocalAppData%\cYo\ComicRack\Cache\Images|*.*|RECURSE +FileKey2=%LocalAppData%\cYo\ComicRack\Cache\Thumbnails|*.*|RECURSE + +[Common Language Runtime *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%LocalAppData%\Microsoft\CLR_v*.*|*.*|RECURSE +FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\CLR_v*.*|*.*|RECURSE +FileKey3=%WinDir%\System32\config\systemprofile\Local Settings\Application Data\Microsoft\CLR_v*.*|*.*|RECURSE +FileKey4=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\CLR_v*.*|*.*|RECURSE +FileKey5=%WinDir%\SysWOW64\config\systemprofile\Local Settings\Application Data\Microsoft\CLR_v*.*|*.*|RECURSE + +[Comms Phone *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.CommsPhone_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.CommsPhone_*\TempState|*.*|RECURSE + +[Comodo *] +LangSecRef=3024 +Detect=HKCU\Software\ComodoGroup +Default=False +FileKey1=%AppData%\Comodo\CCE\Logs|*.* +FileKey2=%AppData%\ComodoGroup\CSC\Cache|*.* +FileKey3=%CommonAppData%\Comodo Downloader|*.* +FileKey4=%CommonAppData%\Comodo\CisDumps|*.* +FileKey5=%CommonAppData%\Comodo\Firewall Pro|cislogs.sdb +FileKey6=%CommonAppData%\Comodo\Installer|*.* +FileKey7=%LocalAppData%\COMODO|*.tmp +FileKey8=%LocalAppData%\VirtualStore\Program Files*\COMODO\COMODO Internet Security|*.tmp +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Comodo Downloader|*.* +FileKey10=%LocalAppData%\VirtualStore\ProgramData\Comodo\CisDumps|*.* +FileKey11=%LocalAppData%\VirtualStore\ProgramData\Comodo\Installer|*.* +FileKey12=%ProgramFiles%\COMODO\COMODO Internet Security|*.tmp;CRASH.DMP;cmdagent.zip + +[Comodo CertSentry *] +LangSecRef=3022 +Detect=HKLM\Software\COMODO\CertSentry +Default=False +FileKey1=%LocalAppData%\COMODO\CertSentry|*.log + +[Comodo GeekBuddy *] +LangSecRef=3021 +Detect=HKLM\Software\GeekBuddyRSP +DetectFile=%ProgramFiles%\Comodo\GeekBuddy +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Comodo\GeekBuddy\logs|*.*|RECURSE +FileKey2=%ProgramFiles%\Comodo\GeekBuddy\logs|*.*|RECURSE + +[Company of Heroes *] +Section=Games +DetectFile=%Documents%\My Games\Company of Heroes* +Default=False +FileKey1=%Documents%\My Games\Company of Heroes*|*.log +FileKey2=%Documents%\My Games\Company of Heroes*\Cache|*.* +FileKey3=%Documents%\My Games\Company of Heroes*\LogFiles|*.* + +[Compatibility Assistant *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant +Default=False +RegKey1=HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted +RegKey2=HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store +RegKey3=HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted +RegKey4=HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store + +[Conceiva Mezzmo *] +LangSecRef=3023 +Detect=HKLM\Software\Conceiva\Mezzmo +Default=False +FileKey1=%CommonAppData%\Conceiva\*|*.bat;*.exe;*.txt +FileKey2=%CommonAppData%\Conceiva\Mezzmo\CER|*.zip +FileKey3=%LocalAppData%\Conceiva\Logs|*.*|REMOVESELF +FileKey4=%LocalAppData%\Conceiva\Mezzmo|DebugCERwrite.txt +FileKey5=%LocalAppData%\Conceiva\Mezzmo\Temporary_*_Files|*.*|REMOVESELF +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Conceiva\Mezzmo|*.txt +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Conceiva\Mezzmo\Third\MKVToolNix|*.txt +FileKey8=%LocalAppData%\VirtualStore\Program Files*\Conceiva\Mezzmo\Third\OGMDemuxer\doc|*.*|REMOVESELF +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Conceiva\Mezzmo\CER|*.zip +FileKey10=%ProgramFiles%\Conceiva\Mezzmo|*.txt +FileKey11=%ProgramFiles%\Conceiva\Mezzmo\Third\MKVToolNix|*.txt +FileKey12=%ProgramFiles%\Conceiva\Mezzmo\Third\OGMDemuxer\doc|*.*|REMOVESELF +RegKey1=HKCU\Software\Conceiva\Mezzmo\General|LastWatchFolder + +[Conduit *] +LangSecRef=3021 +Detect=HKCU\Software\Conduit +Default=False +FileKey1=%LocalLowAppData%\Conduit\Community Alerts\Log|*.*|REMOVESELF +FileKey2=%LocalLowAppData%\ConduitEngine\CacheIcons|*.* +FileKey3=%LocalLowAppData%\ConduitEngine\Logs|*.* +FileKey4=%WinDir%\System32|ConduitEngine.tmp + +[Connectify Hotspot *] +LangSecRef=3022 +Detect=HKLM\Software\Connectify +Default=False +FileKey1=%CommonAppData%\Connectify\cache|*.time;*.cache;*.runtime +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Connectify\cache|*.time;*.cache;*.runtime +FileKey3=%ProgramFiles%\Connectify\Installer|*.*|REMOVESELF +FileKey4=%ProgramFiles%\Connectify\Portal|*.*|REMOVESELF + +[Connectivity Store *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ConnectivityStore_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\TempState|*.*|RECURSE + +[Conquer Online *] +Section=Games +DetectFile=%ProgramFiles%\NetDragon\Conquer Online 2.0\AutoPatch +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\NetDragon\Conquer Online 2.0\AutoPatch|Update.log +FileKey2=%ProgramFiles%\NetDragon\Conquer Online 2.0\AutoPatch|Update.log + +[Contact Support *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Windows.ContactSupport_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0*|*.log +FileKey4=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0*\UsageLogs|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Temp|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalCache|*.*|RECURSE +FileKey11=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalState\Cache|*.*|RECURSE +FileKey12=%LocalAppData%\Packages\Windows.ContactSupport_*\TempState|*.*|RECURSE + +[Content Delivery Manager *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Favicons|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\MobilityExperience\ImageCache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\OneSettingsResponseCache|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\TargetedContentCache|*.*|RECURSE +FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\TempState|*.*|RECURSE + +[ConTEXT *] +LangSecRef=3021 +Detect=HKCU\Software\Eden\ConTEXT +Default=False +RegKey1=HKCU\Software\Eden\ConTEXT\FileHistory +RegKey2=HKCU\Software\Eden\ConTEXT\FindHistory + +[Cook'n Backups *] +LangSecRef=3021 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Cook'n +Default=False +FileKey1=%Documents%\Cook'n Backups|*.ckn +FileKey2=%Documents%\Cook'n10\Workspace\data|download;dvodb.backup +FileKey3=%Documents%\Cook'n10\Workspace\update|update.zip +FileKey4=%Documents%\Cook'n11\Download|*.* + +[Cook'n Cache *] +LangSecRef=3021 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Cook'n +Default=False +FileKey1=%AppData%\Mozilla\eclipse\Cache|*.* + +[Cook'n Dups *] +LangSecRef=3021 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Cook'n +Default=False +Warning=This removes identical duplicates of the huge Getting Started Guide. +FileKey1=%LocalAppData%\DVO\Cook'n10App\plugins|Getting Started Guide.rtf|RECURSE + +[Cook'n Logs *] +LangSecRef=3021 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Cook'n +Default=False +FileKey1=%Documents%\Cook'n*|*.log|RECURSE +FileKey2=%LocalAppData%\DVO\Cook'n*App|*.log|RECURSE + +[Copernic DesktopSearch4 *] +LangSecRef=3024 +Detect=HKLM\Software\Copernic\DesktopSearch4 +Default=False +FileKey1=%AppData%\Copernic\DesktopSearch4\Logs|*.*|REMOVESELF +FileKey2=%LocalAppData%\Copernic\DesktopSearch4\Logs|*.*|REMOVESELF + +[CopyTo Synchronizer *] +LangSecRef=3024 +Detect=HKCU\Software\kishDesign\CopyTo +Default=False +RegKey1=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder00 +RegKey2=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder01 +RegKey3=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder02 +RegKey4=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder03 +RegKey5=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder04 +RegKey6=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder05 +RegKey7=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder06 +RegKey8=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder07 +RegKey9=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder08 +RegKey10=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder09 +RegKey11=HKCU\Software\kishDesign\CopyTo\settings3|scutname00 +RegKey12=HKCU\Software\kishDesign\CopyTo\settings3|scutname01 +RegKey13=HKCU\Software\kishDesign\CopyTo\settings3|scutname02 +RegKey14=HKCU\Software\kishDesign\CopyTo\settings3|scutname03 +RegKey15=HKCU\Software\kishDesign\CopyTo\settings3|scutname04 +RegKey16=HKCU\Software\kishDesign\CopyTo\settings3|scutname05 +RegKey17=HKCU\Software\kishDesign\CopyTo\settings3|scutname06 +RegKey18=HKCU\Software\kishDesign\CopyTo\settings3|scutname07 +RegKey19=HKCU\Software\kishDesign\CopyTo\settings3|scutname08 +RegKey20=HKCU\Software\kishDesign\CopyTo\settings3|scutname09 +RegKey21=HKCU\Software\kishDesign\CopyTo\settings3|Source00 +RegKey22=HKCU\Software\kishDesign\CopyTo\settings3|Source01 +RegKey23=HKCU\Software\kishDesign\CopyTo\settings3|Source02 +RegKey24=HKCU\Software\kishDesign\CopyTo\settings3|Source03 +RegKey25=HKCU\Software\kishDesign\CopyTo\settings3|Source04 +RegKey26=HKCU\Software\kishDesign\CopyTo\settings3|Source05 +RegKey27=HKCU\Software\kishDesign\CopyTo\settings3|Source06 +RegKey28=HKCU\Software\kishDesign\CopyTo\settings3|Source07 +RegKey29=HKCU\Software\kishDesign\CopyTo\settings3|Source08 +RegKey30=HKCU\Software\kishDesign\CopyTo\settings3|Source09 +RegKey31=HKCU\Software\kishDesign\CopyTo\settings3|target00 +RegKey32=HKCU\Software\kishDesign\CopyTo\settings3|target01 +RegKey33=HKCU\Software\kishDesign\CopyTo\settings3|target02 +RegKey34=HKCU\Software\kishDesign\CopyTo\settings3|target03 +RegKey35=HKCU\Software\kishDesign\CopyTo\settings3|target04 +RegKey36=HKCU\Software\kishDesign\CopyTo\settings3|target05 +RegKey37=HKCU\Software\kishDesign\CopyTo\settings3|target06 +RegKey38=HKCU\Software\kishDesign\CopyTo\settings3|target07 +RegKey39=HKCU\Software\kishDesign\CopyTo\settings3|target08 +RegKey40=HKCU\Software\kishDesign\CopyTo\settings3|target09 + +[CopyTrans *] +LangSecRef=3023 +DetectFile1=%AppData%\WindSolutions\CopyTrans* +DetectFile2=%CommonAppData%\WindSolutions\CopyTrans* +Default=False +FileKey1=%CommonAppData%\WindSolutions|*.txt|RECURSE +FileKey2=%CommonAppData%\WindSolutions\CopyTrans*\Logs|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\WindSolutions|*.txt|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\WindSolutions\CopyTrans*\Logs|*.*|RECURSE + +[Core Temp *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Core Temp +Default=False +FileKey1=%ProgramFiles%\Core Temp|*.csv + +[Corel AfterShot Pro *] +LangSecRef=3023 +Detect=HKCU\Software\Corel\AfterShot Pro V3 +Default=False +FileKey1=%LocalAppData%\Corel\AfterShot Pro *|*.log +FileKey2=%LocalAppData%\Corel\AfterShot Pro *\Cache|*.*|RECURSE + +[Corel Downloads *] +LangSecRef=3021 +DetectFile=%CommonAppData%\Corel\Downloads +Default=False +FileKey1=%CommonAppData%\Corel\Downloads|*.*|RECURSE + +[Corel PaintShop Pro *] +LangSecRef=3023 +Detect1=HKCU\Software\Corel\PaintShop Pro\X4 +Detect2=HKCU\Software\Corel\PaintShop Pro\X5 +Detect3=HKCU\Software\Corel\PaintShop Pro\X6 +Detect4=HKCU\Software\Corel\PaintShop Pro\X7 +Detect5=HKCU\Software\Corel\PaintShop Pro\X10 +Detect6=HKCU\Software\Corel\PhotoDownloader\2 +Default=False +FileKey1=%AppData%\Corel\PaintShop Photo Pro\13\Cache|*.*|RECURSE +FileKey2=%LocalAppData%\Corel|*.db;*.PspCache +FileKey3=%LocalAppData%\Corel PaintShop Pro\*\Cache|*.* +FileKey4=%LocalAppData%\Corel PaintShop Pro\*\Database|*.db +FileKey5=%LocalAppData%\Corel PaintShop Pro\*\Thumbs|*.*|RECURSE +FileKey6=%LocalAppData%\Corel\Thumbs|*.*|RECURSE +RegKey1=HKCU\Software\Corel\PaintShop Pro\X7\CoreMemoryManager\0 +RegKey2=HKCU\Software\Corel\PaintShop Pro\X10\CoreMemoryManager\0 +RegKey3=HKCU\Software\Corel\PhotoDownloader\2\PhotoDownloader\DefaultDownloadFolder +RegKey4=HKCU\Software\Corel\PhotoDownloader\2\PhotoDownloader\DownloadFolder + +[Corel PaintShop Pro AutoPreserve *] +LangSecRef=3023 +Detect1=HKCU\Software\Corel\PaintShop Pro\X6 +Detect2=HKCU\Software\Corel\PaintShop Pro\X7 +Detect3=HKCU\Software\Corel\PaintShop Pro\X10 +Default=False +FileKey1=%Pictures%\Corel Auto-Preserve|*.* + +[Corel VideoStudio Pro *] +LangSecRef=3023 +Detect1=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\14.0 +Detect2=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\15.0 +Detect3=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\16.0 +Detect4=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\17.0 +Default=False +FileKey1=%Documents%\Corel VideoStudio Pro\*.0\AudioTmp|*.* +FileKey2=%Documents%\Corel VideoStudio Pro\*.0\SmartProxy|*.* +RegKey1=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\14.0\Preference|Working Folder +RegKey2=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\15.0\HerRFL +RegKey3=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\16.0\HerRFL +RegKey4=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\17.0\HerRFL + +[CorelDRAW Graphics Suite X7 *] +LangSecRef=3021 +Detect=HKCU\Software\Corel\CorelDRAW\17.0 +Default=False +FileKey1=%CommonAppData%\Bitstream\Font Navigator\6.0\Cache|*.*|RECURSE +FileKey2=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Config|corelpdf.ini;capture.ini +FileKey3=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Connect|Connect.config +FileKey4=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw|FindAndReplaceMRU.xml +FileKey5=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw\Export|dialog.export.web.xml +FileKey6=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw\Presets\HTML Export|default.pst +FileKey7=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw\PreviewCache|*.*|RECURSE +FileKey8=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\PHOTO-PAINT\PreviewCache|*.*|RECURSE +FileKey9=%ProgramFiles%\Corel\CorelDRAW Graphics Suite X7\Setup|*.*|REMOVESELF +RegKey1=HKCU\Software\Bitstream\Font Navigator\6.0\Copy|Folders +RegKey2=HKCU\Software\Bitstream\Font Navigator\6.0\Move|Folders +RegKey3=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\Directories|DrawDocsDir +RegKey4=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\Framework|RecentFiles +RegKey5=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\HTML Export|DestPath +RegKey6=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\NewFromTemplate|BrowseTemplateDir +RegKey7=HKCU\Software\Corel\CorelDRAW\17.0\PHOTO-PAINT\Application Preferences\Framework|RecentFiles + +[Corsair iCue Logs *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Corsair\CUE\Service logs +Default=False +Warning=Disabling "Debug Logging" in iCue will prevent these files from being recreated. +FileKey1=%CommonAppData%\Corsair\CUE\Service logs|Service_Trace*.log + +[Cortana *] +LangSecRef=3031 +Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Cortana_8wekyb3d8bbwe +Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Cortana_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft*Cortana_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft*Cortana_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft*Cortana_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft*Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft*Cortana_*\AC\Temp|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft*Cortana_*\TempState|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalCache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\*Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\TempState|*.*|RECURSE + +[CounterSpy *] +LangSecRef=3024 +Detect=HKLM\Software\Sunbelt Software\CounterSpy +Default=False +FileKey1=%CommonAppData%\Sunbelt Software\CounterSpy\Logs|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sunbelt Software\CounterSpy\Logs|*.* + +[Crayon Physics Deluxe *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\26900 +Default=False +FileKey1=%AppData%\Crayon Physics Deluxe|log.txt +FileKey2=%AppData%\Crayon Physics Deluxe\data\recordings\temp|current_recording.tmp +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\crayon physics deluxe|log.txt +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\crayon physics deluxe\cache|*.* +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\crayon physics deluxe\data\editor|*.tmp +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\crayon physics deluxe\data\recordings\temp|*.tmp +FileKey7=%ProgramFiles%\Steam\steamapps\common\crayon physics deluxe|log.txt +FileKey8=%ProgramFiles%\Steam\steamapps\common\crayon physics deluxe\cache|*.* +FileKey9=%ProgramFiles%\Steam\steamapps\common\crayon physics deluxe\data\editor|*.tmp +FileKey10=%ProgramFiles%\Steam\steamapps\common\crayon physics deluxe\data\recordings\temp|*.tmp + +[Creative Installation Information *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Creative Installation Information +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Creative Installation Information|*.log|RECURSE +FileKey2=%ProgramFiles%\Creative Installation Information|*.log|RECURSE + +[Creative Live! Central 3 *] +LangSecRef=3023 +DetectFile=%AppData%\Creative\Live! Central 3 +Default=False +FileKey1=%AppData%\Creative\Live! Central 3|*.txt|RECURSE + +[Creative Pro Proteus VX *] +LangSecRef=3023 +Detect=HKCU\Software\Creative Professional\Proteus VX +Default=False +RegKey1=HKCU\Software\Creative Professional\Proteus VX VSTi\Recent File List + +[Creative Sound Blaster *] +LangSecRef=3024 +Detect1=HKLM\Software\CREATIVE TECH\Software Installed\Software Update +Detect2=HKLM\Software\CREATIVE TECH\Sound Blaster X-Fi MB +Detect3=HKLM\Software\CREATIVE TECH\Sound Blaster Z-Series Control Panel +Default=False +FileKey1=%CommonAppData%\Creative\Software Update\Cache|*.*|RECURSE +FileKey2=%CommonAppData%\Creative\Software Update\Log|*.* +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Creative\Software Update\Cache|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Creative\Software Update\Log|*.* + +[CrypTool 2 *] +LangSecRef=3024 +Detect=HKCU\Software\CrypTool2.0 +Default=False +FileKey1=%LocalAppData%\CrypTool2\Temp|*.*|REMOVESELF +RegKey1=HKCU\Software\CrypTool2.0|recentFileList + +[Crysis 3 *] +Section=Games +Detect=HKLM\Software\Crytek\Crysis 3 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Crysis 3\LogBackups|*.* +FileKey2=%ProgramFiles%\Origin Games\Crysis 3\LogBackups|*.* +FileKey3=%UserProfile%\Saved Games\Crysis 3|*.Log.txt + +[CrystalDiskInfo *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\CrystalDiskInfo\Smart +Default=False +Warning=This will delete all saved SMART data for history/graph function. +FileKey1=%LocalAppData%\VirtualStore\Program Files*\CrystalDiskInfo\Smart|*.*|RECURSE +FileKey2=%ProgramFiles%\CrystalDiskInfo\Smart|*.*|RECURSE + +[Curse Client *] +Section=Games +Detect=HKCU\Software\Classes\Curse +Default=False +FileKey1=%AppData%\Curse Client|*.log +FileKey2=%AppData%\Curse Client\Logs|*.* +FileKey3=%LocalAppData%\Apps\2.0|*.Log|RECURSE + +[CursorFX *] +LangSecRef=3024 +Detect=HKCU\Software\CursorFX Theme Editor +Default=False +RegKey1=HKCU\Software\CursorFX Theme Editor\Recent File List + +[CustomBrushesMini Paint.Net-Plunging *] +LangSecRef=3021 +DetectFile=%AppData%\CustomBrushesMini +Default=False +FileKey1=%AppData%\CustomBrushesMini\ThumbCache|*.*|RECURSE + +[CuteHTML 2.3 *] +LangSecRef=3024 +Detect=HKCU\Software\GlobalSCAPE\CuteHTML\2.3 +Default=False +RegKey1=HKCU\Software\GlobalSCAPE\CuteHTML\2.3\Recent File List + +[CutePDF Writer *] +LangSecRef=3023 +Detect=HKCU\Software\Acro Software Inc\CPW +Default=False +FileKey1=%LocalAppData%\CutePDF Writer|*.tmp +RegKey1=HKCU\Software\Acro Software Inc\CPW|Filename +RegKey2=HKCU\Software\Acro Software Inc\CPW|Title + +[Cyberduck *] +LangSecRef=3024 +Detect=HKCR\.cyberducklicense +Default=False +FileKey1=%AppData%\Cyberduck|*.log + +[CyberLink AudioDirector *] +LangSecRef=3023 +Detect1=HKCU\Software\CyberLink\AudioDirector4 +Detect2=HKCU\Software\CyberLink\AudioDirector5 +Detect3=HKCU\Software\CyberLink\AudioDirector6 +Detect4=HKCU\Software\CyberLink\AudioDirector7 +Detect5=HKCU\Software\CyberLink\AudioDirector8 +Detect6=HKCU\Software\CyberLink\AudioDirector9 +Default=False +FileKey1=%Documents%\Cyberlink\AudioDirector\*\SplitterIndex|*.*|RECURSE +FileKey2=%LocalAppData%\Cyberlink\AudioDirector\*|*.*|RECURSE +RegKey1=HKCU\Software\CyberLink\AudioDirector4\MediaObj\MediaCache5\Data5 +RegKey2=HKCU\Software\CyberLink\AudioDirector4\MediaObj\MediaCache5\Thumbnail5 +RegKey3=HKCU\Software\CyberLink\AudioDirector5\MediaObj\MediaCache5\Data5 +RegKey4=HKCU\Software\CyberLink\AudioDirector5\MediaObj\MediaCache5\Thumbnail5 +RegKey5=HKCU\Software\CyberLink\AudioDirector6\MediaObj\MediaCache5\Data5 +RegKey6=HKCU\Software\CyberLink\AudioDirector6\MediaObj\MediaCache5\Thumbnail5 +RegKey7=HKCU\Software\CyberLink\AudioDirector7\MediaObj\MediaCache5\Data5 +RegKey8=HKCU\Software\CyberLink\AudioDirector7\MediaObj\MediaCache5\Thumbnail5 +RegKey9=HKCU\Software\CyberLink\AudioDirector8\MediaObj\MediaCache5\Data5 +RegKey10=HKCU\Software\CyberLink\AudioDirector8\MediaObj\MediaCache5\Thumbnail5 +RegKey11=HKCU\Software\CyberLink\AudioDirector9\MediaObj\MediaCache5\Data5 +RegKey12=HKCU\Software\CyberLink\AudioDirector9\MediaObj\MediaCache5\Thumbnail5 + +[CyberLink ColorDirector *] +LangSecRef=3023 +Detect1=HKCU\Software\CyberLink\ColorDirector3 +Detect2=HKCU\Software\CyberLink\ColorDirector4 +Detect3=HKCU\Software\CyberLink\ColorDirector5 +Detect4=HKCU\Software\CyberLink\ColorDirector6 +Detect5=HKCU\Software\CyberLink\ColorDirector7 +Default=False +FileKey1=%LocalAppData%\Cyberlink\ColorDirector\*|*.*|RECURSE +RegKey1=HKCU\Software\CyberLink\ColorDirector3\MediaObj\MediaCache5\Data5 +RegKey2=HKCU\Software\CyberLink\ColorDirector3\MediaObj\MediaCache5\Thumbnail5 +RegKey3=HKCU\Software\CyberLink\ColorDirector4\MediaObj\MediaCache5\Data5 +RegKey4=HKCU\Software\CyberLink\ColorDirector4\MediaObj\MediaCache5\Thumbnail5 +RegKey5=HKCU\Software\CyberLink\ColorDirector5\MediaObj\MediaCache5\Data5 +RegKey6=HKCU\Software\CyberLink\ColorDirector5\MediaObj\MediaCache5\Thumbnail5 +RegKey7=HKCU\Software\CyberLink\ColorDirector6\MediaObj\MediaCache5\Data5 +RegKey8=HKCU\Software\CyberLink\ColorDirector6\MediaObj\MediaCache5\Thumbnail5 +RegKey9=HKCU\Software\CyberLink\ColorDirector7\MediaObj\MediaCache5\Data5 +RegKey10=HKCU\Software\CyberLink\ColorDirector7\MediaObj\MediaCache5\Thumbnail5 + +[CyberLink Crash Files *] +LangSecRef=3023 +Detect=HKCU\Software\CyberLink +Default=False +FileKey1=%CommonAppData%\CyberLink\Boomerang\*|*.xml;*.dmp +FileKey2=%CommonAppData%\CyberLink\PowerDVD*\Boomerang\*|*.xml;*.dmp +FileKey3=%LocalAppData%\VirtualStore\ProgramData\CyberLink\Boomerang\*|*.xml;*.dmp +FileKey4=%LocalAppData%\VirtualStore\ProgramData\CyberLink\PowerDVD*\Boomerang\*|*.xml;*.dmp + +[CyberLink Downloader *] +LangSecRef=3023 +Detect=HKCU\Software\CyberLink\CLDownloader +Default=False +FileKey1=%CommonAppData%\CyberLink\CBE\*|*.*|RECURSE +FileKey2=%CommonAppData%\CyberLink\Downloader|*.*|RECURSE + +[CyberLink Install Files *] +LangSecRef=3023 +Detect=HKCU\Software\CyberLink +Default=False +FileKey1=%CommonAppData%\install_backup|*.*|REMOVESELF +FileKey2=%CommonAppData%\install_clap|*.*|REMOVESELF +FileKey3=%LocalAppData%\VirtualStore\ProgramData\install_backup|*.*|REMOVESELF +FileKey4=%LocalAppData%\VirtualStore\ProgramData\install_clap|*.*|REMOVESELF + +[CyberLink Media Cache *] +LangSecRef=3023 +Detect=HKCU\Software\CyberLink +Default=False +FileKey1=%AppData%\CyberLink\MediaCache|*.*|RECURSE +RegKey1=HKCU\Software\CyberLink\DSSharedMediaInfo\SharedInfoCache +RegKey2=HKCU\Software\CyberLink\MediaCache\Data4 +RegKey3=HKCU\Software\CyberLink\MediaCache\Thumbnail4 +RegKey4=HKCU\Software\CyberLink\MediaCache5\Data5 +RegKey5=HKCU\Software\CyberLink\MediaCache5\Thumbnail5 + +[CyberLink PhotoDirector *] +LangSecRef=3023 +Detect1=HKCU\Software\CyberLink\PhotoDirector3 +Detect2=HKLM\Software\CyberLink\PhotoDirector4 +Detect3=HKLM\Software\CyberLink\PhotoDirector5 +Detect4=HKLM\Software\CyberLink\PhotoDirector6 +Detect5=HKLM\Software\CyberLink\PhotoDirector7 +Detect6=HKLM\Software\CyberLink\PhotoDirector8 +Detect7=HKLM\Software\CyberLink\PhotoDirector9 +Detect8=HKLM\Software\CyberLink\PhotoDirector10 +Default=False +FileKey1=%Pictures%\PhotoDirector\*\*|*.*|RECURSE +ExcludeKey1=PATH|%Pictures%\PhotoDirector\*\*\|*.phd + +[CyberLink Power2Go *] +LangSecRef=3023 +Detect1=HKCU\Software\CyberLink\Power2Go9\9.0 +Detect2=HKCU\Software\CyberLink\Power2Go10\10.0 +Detect3=HKCU\Software\CyberLink\Power2Go11\11.0 +Detect4=HKCU\Software\CyberLink\Power2Go12\12.0 +Default=False +FileKey1=%Documents%\PDRMUSIC.TMP|*.*|REMOVESELF +FileKey2=%LocalAppData%\Cyberlink\Power2Go*|DLDB.db +FileKey3=%Music%|*.tmp +FileKey4=%Pictures%|*.tmp +FileKey5=%ProgramFiles%\Cyberlink\Power2Go*|*.tmp +FileKey6=%ProgramFiles%\Cyberlink\Power2Go*|Thumbs.db|RECURSE +FileKey7=%Public%\Documents\Cyberlink\Power2Go*|MP3Cache.log +RegKey1=HKCU\Software\CyberLink\LabelPrint\Recent File List +RegKey2=HKCU\Software\CyberLink\Power2Go9\9.0|CDRippingPath +RegKey3=HKCU\Software\CyberLink\Power2Go9\9.0|CUEName +RegKey4=HKCU\Software\CyberLink\Power2Go9\9.0|CUEPath +RegKey5=HKCU\Software\CyberLink\Power2Go9\9.0|DestFolder +RegKey6=HKCU\Software\CyberLink\Power2Go9\9.0|DVDFolderPath +RegKey7=HKCU\Software\CyberLink\Power2Go9\9.0|ImagePath +RegKey8=HKCU\Software\CyberLink\Power2Go9\9.0|LastBrowsePath +RegKey9=HKCU\Software\CyberLink\Power2Go9\9.0|LastSaveProjPath +RegKey10=HKCU\Software\CyberLink\Power2Go9\9.0|MonitorPaths +RegKey11=HKCU\Software\CyberLink\Power2Go9\9.0|OpenPrjFilePath +RegKey12=HKCU\Software\CyberLink\Power2Go9\9.0|SelectedFolderPath +RegKey13=HKCU\Software\CyberLink\Power2Go9\9.0\MediaObj\MediaCache5\Data5 +RegKey14=HKCU\Software\CyberLink\Power2Go9\9.0\MediaObj\MediaCache5\Thumbnail5 +RegKey15=HKCU\Software\CyberLink\Power2Go10\10.0|CDRippingPath +RegKey16=HKCU\Software\CyberLink\Power2Go10\10.0|CUEName +RegKey17=HKCU\Software\CyberLink\Power2Go10\10.0|CUEPath +RegKey18=HKCU\Software\CyberLink\Power2Go10\10.0|DestFolder +RegKey19=HKCU\Software\CyberLink\Power2Go10\10.0|DVDFolderPath +RegKey20=HKCU\Software\CyberLink\Power2Go10\10.0|ImagePath +RegKey21=HKCU\Software\CyberLink\Power2Go10\10.0|LastBrowsePath +RegKey22=HKCU\Software\CyberLink\Power2Go10\10.0|LastSaveProjPath +RegKey23=HKCU\Software\CyberLink\Power2Go10\10.0|MonitorPaths +RegKey24=HKCU\Software\CyberLink\Power2Go10\10.0|OpenPrjFilePath +RegKey25=HKCU\Software\CyberLink\Power2Go10\10.0|SelectedFolderPath +RegKey26=HKCU\Software\CyberLink\Power2Go10\10.0\MediaObj\MediaCache5\Data5 +RegKey27=HKCU\Software\CyberLink\Power2Go10\10.0\MediaObj\MediaCache5\Thumbnail5 +RegKey28=HKCU\Software\CyberLink\Power2Go11\11.0|CDRippingPath +RegKey29=HKCU\Software\CyberLink\Power2Go11\11.0|CUEName +RegKey30=HKCU\Software\CyberLink\Power2Go11\11.0|CUEPath +RegKey31=HKCU\Software\CyberLink\Power2Go11\11.0|DestFolder +RegKey32=HKCU\Software\CyberLink\Power2Go11\11.0|DVDFolderPath +RegKey33=HKCU\Software\CyberLink\Power2Go11\11.0|ImagePath +RegKey34=HKCU\Software\CyberLink\Power2Go11\11.0|LastBrowsePath +RegKey35=HKCU\Software\CyberLink\Power2Go11\11.0|LastSaveProjPath +RegKey36=HKCU\Software\CyberLink\Power2Go11\11.0|MonitorPaths +RegKey37=HKCU\Software\CyberLink\Power2Go11\11.0|OpenPrjFilePath +RegKey38=HKCU\Software\CyberLink\Power2Go11\11.0|SelectedFolderPath +RegKey39=HKCU\Software\CyberLink\Power2Go11\11.0\MediaObj\MediaCache5\Data5 +RegKey40=HKCU\Software\CyberLink\Power2Go11\11.0\MediaObj\MediaCache5\Thumbnail5 +RegKey41=HKCU\Software\CyberLink\Power2Go12\12.0|CDRippingPath +RegKey42=HKCU\Software\CyberLink\Power2Go12\12.0|CUEName +RegKey43=HKCU\Software\CyberLink\Power2Go12\12.0|CUEPath +RegKey44=HKCU\Software\CyberLink\Power2Go12\12.0|DestFolder +RegKey45=HKCU\Software\CyberLink\Power2Go12\12.0|DVDFolderPath +RegKey46=HKCU\Software\CyberLink\Power2Go12\12.0|ImagePath +RegKey47=HKCU\Software\CyberLink\Power2Go12\12.0|LastBrowsePath +RegKey48=HKCU\Software\CyberLink\Power2Go12\12.0|LastSaveProjPath +RegKey49=HKCU\Software\CyberLink\Power2Go12\12.0|MonitorPaths +RegKey50=HKCU\Software\CyberLink\Power2Go12\12.0|OpenPrjFilePath +RegKey51=HKCU\Software\CyberLink\Power2Go12\12.0|SelectedFolderPath +RegKey52=HKCU\Software\CyberLink\Power2Go12\12.0\MediaObj\MediaCache5\Data5 +RegKey53=HKCU\Software\CyberLink\Power2Go12\12.0\MediaObj\MediaCache5\Thumbnail5 +RegKey54=HKCU\Software\CyberLink\WaveEditor\2.0|ImportDir +RegKey55=HKCU\Software\CyberLink\WaveEditor\2.0|TempFileDir +RegKey56=HKCU\Software\CyberLink\WaveEditor\2.0|WorkDir + +[Cyberlink PowerCinema *] +LangSecRef=3023 +Detect=HKCU\Software\Cyberlink\PowerCinema +DetectFile=%LocalAppData%\PowerCinema +Default=False +FileKey1=%LocalAppData%\PowerCinema|trace.log;trace.txt + +[CyberLink PowerDirector *] +LangSecRef=3023 +Detect1=HKCU\Software\CyberLink\PowerDirector10 +Detect2=HKCU\Software\CyberLink\PowerDirector11 +Detect3=HKCU\Software\CyberLink\PowerDirector12 +Detect4=HKCU\Software\CyberLink\PowerDirector13 +Detect5=HKCU\Software\CyberLink\PowerDirector14 +Detect6=HKCU\Software\CyberLink\PowerDirector15 +Detect7=HKCU\Software\CyberLink\PowerDirector16 +Detect8=HKCU\Software\CyberLink\PowerDirector17 +Default=False +FileKey1=%AppData%\Cyberlink\PowerDirector\*|Recentfiles.ini +FileKey2=%AppData%\CyberLink\PowerDirector\*\AutoSave|*.*|RECURSE +FileKey3=%AppData%\CyberLink\PowerDirector\*\photoTmp|*.*|RECURSE +FileKey4=%AppData%\Cyberlink\PowerDirector\*\WaveForms|*.*|RECURSE +FileKey5=%Documents%\CyberLink\PowerDirector\*|Snapshot(*).jpg +FileKey6=%Documents%\CyberLink\PowerDirector\*\MyTitles|*.*|RECURSE +FileKey7=%Documents%\Cyberlink\PowerDirector\*\PDRMUSIC.TMP|*.*|REMOVESELF +FileKey8=%Documents%\Cyberlink\PowerDirector\*\PP.TWOPASS|*.*|REMOVESELF +FileKey9=%Documents%\CyberLink\PowerDirector\*\Preview Cache Files|*.* +FileKey10=%Documents%\CyberLink\PowerDirector\*\ShadowEditFiles|*.MPG +FileKey11=%Documents%\CyberLink\PowerDirector\*\SplitterIndex|*.maidx +RegKey1=HKCU\Software\CyberLink\Hanuman +RegKey2=HKCU\Software\CyberLink\PowerDirector10\MediaObj\MediaCache5\Data5 +RegKey3=HKCU\Software\CyberLink\PowerDirector10\MediaObj\MediaCache5\Thumbnail5 +RegKey4=HKCU\Software\CyberLink\PowerDirector11\MediaObj\MediaCache5\Data5 +RegKey5=HKCU\Software\CyberLink\PowerDirector11\MediaObj\MediaCache5\Thumbnail5 +RegKey6=HKCU\Software\CyberLink\PowerDirector12\MediaObj\MediaCache5\Data5 +RegKey7=HKCU\Software\CyberLink\PowerDirector12\MediaObj\MediaCache5\Thumbnail5 +RegKey8=HKCU\Software\CyberLink\PowerDirector13\MediaObj\MediaCache5\Data5 +RegKey9=HKCU\Software\CyberLink\PowerDirector13\MediaObj\MediaCache5\Thumbnail5 +RegKey10=HKCU\Software\CyberLink\PowerDirector14\MediaObj\MediaCache5\Data5 +RegKey11=HKCU\Software\CyberLink\PowerDirector14\MediaObj\MediaCache5\Thumbnail5 +RegKey12=HKCU\Software\CyberLink\PowerDirector15\MediaObj\MediaCache5\Data5 +RegKey13=HKCU\Software\CyberLink\PowerDirector15\MediaObj\MediaCache5\Thumbnail5 +RegKey14=HKCU\Software\CyberLink\PowerDirector16\MediaObj\MediaCache5\Data5 +RegKey15=HKCU\Software\CyberLink\PowerDirector16\MediaObj\MediaCache5\Thumbnail5 +RegKey16=HKCU\Software\CyberLink\PowerDirector17\MediaObj\MediaCache5\Data5 +RegKey17=HKCU\Software\CyberLink\PowerDirector17\MediaObj\MediaCache5\Thumbnail5 +RegKey18=HKCU\Software\CyberLink\PowerDirector17\OldCacheFolder + +[CyberLink PowerDVD *] +LangSecRef=3023 +Detect1=HKCU\Software\CyberLink\PowerDVD15 +Detect2=HKCU\Software\CyberLink\PowerDVD16 +Detect3=HKCU\Software\CyberLink\PowerDVD17 +Detect4=HKCU\Software\CyberLink\PowerDVD18 +Default=False +FileKey1=%CommonAppData%\Cyberlink\Evoparser|*.xml +FileKey2=%LocalAppData%\Cyberlink\DigitalHome|*.log|RECURSE +FileKey3=%LocalAppData%\Cyberlink\PowerDVD*|*.log|RECURSE +FileKey4=%LocalAppData%\Cyberlink\PowerDVD*\cache*|*.*|RECURSE +FileKey5=%LocalAppData%\Cyberlink\PowerDVD*\CL_DMP_Browser|*.*|RECURSE +RegKey1=HKCU\Software\CyberLink\PowerDVD15\CLMPSvc\MediaObj\MediaCache5\Data5 +RegKey2=HKCU\Software\CyberLink\PowerDVD15\CLMPSvc\MediaObj\MediaCache5\ProgramInfo +RegKey3=HKCU\Software\CyberLink\PowerDVD15\CLMPSvc\MediaObj\MediaCache5\Thumbnail5 +RegKey4=HKCU\Software\CyberLink\PowerDVD16\CLMPSvc\MediaObj\MediaCache5\Data5 +RegKey5=HKCU\Software\CyberLink\PowerDVD16\CLMPSvc\MediaObj\MediaCache5\ProgramInfo +RegKey6=HKCU\Software\CyberLink\PowerDVD16\CLMPSvc\MediaObj\MediaCache5\Thumbnail5 +RegKey7=HKCU\Software\CyberLink\PowerDVD17\CLMPSvc\MediaObj\MediaCache5\Data5 +RegKey8=HKCU\Software\CyberLink\PowerDVD17\CLMPSvc\MediaObj\MediaCache5\ProgramInfo +RegKey9=HKCU\Software\CyberLink\PowerDVD17\CLMPSvc\MediaObj\MediaCache5\Thumbnail5 +RegKey10=HKCU\Software\CyberLink\PowerDVD18\CLMPSvc\MediaObj\MediaCache5\Data5 +RegKey11=HKCU\Software\CyberLink\PowerDVD18\CLMPSvc\MediaObj\MediaCache5\ProgramInfo +RegKey12=HKCU\Software\CyberLink\PowerDVD18\CLMPSvc\MediaObj\MediaCache5\Thumbnail5 + +[CyberLink YouCam *] +LangSecRef=3023 +Detect=HKCU\Software\CyberLink\YouCam +Default=False +FileKey1=%Documents%\YouCam|*.tmp + +[CzDC *] +LangSecRef=3022 +DetectFile=%AppData%\CzDC +Default=False +FileKey1=%AppData%\CzDC|*.bak|RECURSE + +[Daemon Tools *] +LangSecRef=3024 +Detect1=HKCU\Software\Disc Soft +Detect2=HKCU\Software\DT Soft +Detect3=HKLM\Software\Disc Soft +Detect4=HKLM\Software\DT Soft +Default=False +FileKey1=%AppData%\DAEMON Tools*|ImgList.dat +FileKey2=%AppData%\DAEMON Tools*\*Cache|*.*|RECURSE +RegKey1=HKCU\Software\Disc Soft\DAEMON Tools Pro\GuiNamespace|MountFolder +RegKey2=HKCU\Software\DT Soft\DAEMON Tools Pro\GuiNamespace|MountFolder + +[Dakota AG *] +LangSecRef=3021 +DetectFile=%SystemDrive%\dakotaag +Default=False +FileKey1=%SystemDrive%\dakotaag|*.log|RECURSE + +[DAMN Hash Calculator *] +LangSecRef=3024 +Detect=HKCU\Software\DAMN\Hash Calculator +Default=False +RegKey1=HKCU\Software\DAMN\Hash Calculator\Settings|LastDir + +[DAMN NFO Viewer *] +LangSecRef=3024 +Detect=HKCU\Software\DAMN\DAMN NFO Viewer +Default=False +RegKey1=HKCU\Software\DAMN\DAMN NFO Viewer|WorkingDirectory +RegKey2=HKCU\Software\DAMN\DAMN NFO Viewer\Recently Viewed Files + +[Damned *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\251170 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Damned|*.log|RECURSE +FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Damned|*.log|RECURSE + +[Dangerous Waters *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\1600 +DetectFile=%ProgramFiles%\Sonalysts Combat Simulations\Dangerous Waters +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Sonalysts Combat Simulations\Dangerous Waters|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Dangerous Waters|*.log +FileKey3=%ProgramFiles%\Sonalysts Combat Simulations\Dangerous Waters|*.log +FileKey4=%ProgramFiles%\Steam\SteamApps\Common\Dangerous Waters|*.log + +[DARK *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\225360 +Default=False +FileKey1=%AppData%\Kalypso Media\Dark|log.txt + +[Dark Blood Online *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\267790 +Default=False +FileKey1=%AppData%\DarkBlood ServiceST|*.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Dark Blood\logs|*.*|RECURSE +FileKey3=%ProgramFiles%\Steam\SteamApps\Common\Dark Blood\logs|*.*|RECURSE + +[Darkspore *] +Section=Games +DetectFile=%ProgramFiles%\Origin Games\Darkspore +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Darkspore|*.log|RECURSE +FileKey2=%ProgramFiles%\Origin Games\Darkspore|*.log|RECURSE + +[Dashlane *] +LangSecRef=3022 +DetectFile=%AppData%\Dashlane +Default=False +FileKey1=%AppData%\Dashlane\*\background_cache|*.*|RECURSE + +[DataTron 7 *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\DataTron7 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\DataTron7|*.GID;*.BAK +FileKey2=%ProgramFiles%\DataTron7|*.GID;*.BAK + +[Daum PotPlayer *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\PotPlayer +Default=False +FileKey1=%LocalAppData%\Daum\PotPlayer\Log|*.xml + +[David FX Basic *] +LangSecRef=3024 +Detect=HKCU\Software\Tobit +Default=False +FileKey1=%SystemDrive%\David\Apps\Dvgrab\Code|*.chk +FileKey2=%SystemDrive%\David\Apps\Postman\Code|*.chk +FileKey3=%SystemDrive%\David\Archive\USER\*\temp|*.* +FileKey4=%SystemDrive%\David\Code|*.old;*.chk;*.log +FileKey5=%SystemDrive%\David\Tld\COMMON|*DAVID.LOG +FileKey6=%SystemDrive%\David\Tld\Port\Extra|*.chk + +[DayZ *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\221100 +Default=False +FileKey1=%LocalAppData%\DayZ|DayZ.mdmp;DayZ.bidmp + +[DBFView *] +LangSecRef=3021 +Detect=HKCU\Software\DBFView +Default=False +RegKey1=HKCU\Software\DBFView\DBFView\Recent File List + +[DC Universe Online *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\24200 +Default=False +FileKey1=%Documents%\My Games\DC Universe Online\Logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\DC Universe Online|.downloadInfo.txt;.downloadStats.txt +FileKey3=%ProgramFiles%\Steam\SteamApps\Common\DC Universe Online|.downloadInfo.txt;.downloadStats.txt + +[Dead Island *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\91310 +Default=False +FileKey1=%Documents%\DeadIsland\out\logs|*.* + +[Dear Esther *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\203810 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\dear esther\dearesther|*.tmp +FileKey2=%ProgramFiles%\Steam\Steamapps\common\dear esther\dearesther|*.tmp +FileKey3=%ProgramFiles%\Steam\Steamapps\common\dear esther\dearesther\resource|*.icns + +[Death to Spies: Moment of Truth *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\34410 +Default=False +FileKey1=%Documents%\My Games\Smersh_MT\Cache|*.* + +[Death Track: Resurrection *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\7840 +Default=False +FileKey1=%Documents%\Skyfallen Entertaiment\DeathTrack\Logs|*.* + +[Debenu *] +LangSecRef=3021 +Detect=HKCU\Software\Debenu +Default=False +FileKey1=%CommonAppData%\Debenu\PDF Tools\Reports\App Log|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Debenu\PDF Tools\Reports\App Log|*.* +RegKey1=HKCU\Software\Debenu\Debenu PDF Maximus 2\MaximusViewerRecentDocs +RegKey2=HKCU\Software\Debenu\Debenu PDF Maximus 2\MaximusViewerRecentFolders + +[DeepBurner *] +LangSecRef=3024 +Detect=HKCU\Software\Astonsoft\DeepBurner +Default=False +FileKey1=%AppData%\DeepBurner|DeepBurner.log + +[Defense Grid: The Awakening *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\18500 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\defensegridtheawakening\Shaders\Generated|*.cache +FileKey2=%ProgramFiles%\Steam\steamapps\common\defensegridtheawakening\Shaders\Generated|*.cache + +[Defraggler *] +LangSecRef=3024 +Detect=HKCU\Software\Piriform\Defraggler +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Defraggler|*.dmp;*statistics*;*.log;Defraggler*.txt +FileKey2=%ProgramFiles%\Defraggler|*.dmp;*statistics*;*.log;Defraggler*.txt +FileKey3=%UserProfile%|Defraggler*.txt + +[Delfix *] +LangSecRef=3024 +DetectFile=%SystemDrive%\DelFix.txt +Default=False +FileKey1=%SystemDrive%|DelFix.txt + +[Dell Installation Files *] +LangSecRef=3024 +Detect1=HKCU\Software\Dell +Detect2=HKLM\Software\Dell +Default=False +Warning=This will delete your Dell installation files. +FileKey1=%SystemDrive%\dell|*.*|REMOVESELF + +[Dell Logs *] +LangSecRef=3024 +Detect1=HKLM\Software\Dell\MUP +Detect2=HKLM\Software\Dell\UpdateService +Detect3=HKLM\Software\PC-Doctor +DetectFile1=%AppData%\Creative\DELL Webcam Center +DetectFile2=%CommonAppData%\Dell +DetectFile3=%LocalAppData%\Dell +DetectFile4=%LocalAppData%\SupportSoft\DellSupportCenter +DetectFile5=%ProgramFiles%\Dell* +Default=False +FileKey1=%AppData%\Creative\DELL Webcam Center|MO_Log.txt +FileKey2=%AppData%\PCDr\*\Logs|*.* +FileKey3=%CommonAppData%\Dell\*\Log|*.* +FileKey4=%CommonAppData%\Dell\*\Logs|*.* +FileKey5=%CommonAppData%\Dell\Drivers\*|*.tmp +FileKey6=%CommonAppData%\Dell\Update|*.txt +FileKey7=%CommonAppData%\Dell\UpdateService\Clients\Update|*.log +FileKey8=%CommonAppData%\PCDr\*\Cache|*.xml +FileKey9=%CommonAppData%\PCDr\*\Cache\archives|*.*|RECURSE +FileKey10=%CommonAppData%\PCDr\*\Cache\BUMA|*.* +FileKey11=%CommonAppData%\PCDr\*\Cache\DriverScan|*.* +FileKey12=%CommonAppData%\PCDr\*\Logs|*.log +FileKey13=%LocalAppData%\Dell\*\Log|*.* +FileKey14=%LocalAppData%\SupportSoft\DellSupportCenter\*\state\logs|*.* +FileKey15=%LocalAppData%\VirtualStore\Program Files*\Dell*|*.log|RECURSE +FileKey16=%LocalAppData%\VirtualStore\ProgramData\Dell\*\Log|*.* +FileKey17=%ProgramFiles%\Dell*|*.log|RECURSE + +[Dell PC Doctor Dumps *] +LangSecRef=3024 +DetectFile=%CommonAppData%\PCDr +Default=False +FileKey1=%CommonAppData%\PCDr|*.dmp|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\PCDr|*.dmp|RECURSE + +[Dependency Walker *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Dependency Walker +Default=False +RegKey1=HKCU\Software\Microsoft\Dependency Walker\Recent File List + +[Deponia *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\214340 +DetectFile=%LocalAppData%\Daedalic Entertainment\Deponia +Default=False +FileKey1=%LocalAppData%\Daedalic Entertainment\Deponia|*.log + +[Desura Game Cache *] +Section=Games +Detect=HKLM\Software\Desura +DetectFile=%ProgramFiles%\Desura +Default=False +FileKey1=%CommonAppData%\Desura\DesuraApp\Cache|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Desura\Cache\games|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Desura\DesuraApp\Cache|*.*|RECURSE +FileKey4=%ProgramFiles%\Desura\Cache\games|*.*|RECURSE + +[Desura Game Installation Tools *] +Section=Games +Detect=HKLM\Software\Desura +DetectFile=%ProgramFiles%\Desura +Default=False +Warning=Don't use this if you have limited bandwidth as they will be re-downloaded on next game installation. +FileKey1=%CommonAppData%\Desura\DesuraApp\tools|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Desura\DesuraApp\tools|*.*|RECURSE +ExcludeKey1=PATH|%CommonAppData%\Desura\DesuraApp\tools\installcheck\|*.* + +[Desura Logs *] +Section=Games +Detect=HKLM\Software\Desura +DetectFile=%ProgramFiles%\Desura +Default=False +FileKey1=%CommonAppData%\Desura\DesuraApp|update_log.txt +FileKey2=%CommonAppData%\Desura\DesuraApp\dumps|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Desura|*.log +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Desura\DesuraApp|update_log.txt +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Desura\DesuraApp\dumps|*.* +FileKey6=%ProgramFiles%\Desura|*.log + +[Desura Update Backups *] +Section=Games +Detect=HKLM\Software\Desura +DetectFile=%ProgramFiles%\Desura +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Desura|*.exe_old +FileKey2=%ProgramFiles%\Desura|*.exe_old + +[Desura Web Cache *] +Section=Games +Detect=HKLM\Software\Desura +DetectFile=%ProgramFiles%\Desura +Default=False +FileKey1=%CommonAppData%\Desura\DesuraApp|webcore_cache.sqlite +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Desura\DesuraApp|webcore_cache.sqlite + +[Deus Ex *] +Section=Games +DetectFile=%SystemDrive%\DeusEx\System +Default=False +FileKey1=%SystemDrive%\DeusEx\System|DeusEx.log;Detected.log + +[Device Icon Downloads *] +LangSecRef=3025 +DetectFile=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads +Default=False +FileKey1=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads|*.tmp + +[Device Manager Cache *] +DetectOS=6.0| +LangSecRef=3025 +Default=False +Warning=This clears cached drivers of connected devices. As soon as you connect a new device, this file regenerates. +FileKey1=%WinDir%\System32\DriverStore|INFCACHE.1 + +[Device Manager Cache XP *] +DetectOS=|5.1 +LangSecRef=3025 +Default=False +Warning=This clears cached drivers of connected devices. As soon as you connect a new device, this file regenerates. +FileKey1=%WinDir%\inf|INFCACHE.1 + +[DeviceDoctor *] +LangSecRef=3024 +DetectFile=%AppData%\DeviceDoctorSoftware\DeviceDoctor +Default=False +FileKey1=%AppData%\DeviceDoctorSoftware\DeviceDoctor\Logs|*.* + +[Devolo Cockpit *] +LangSecRef=3024 +Detect=HKLM\Software\devolo\dLAN +Default=False +FileKey1=%ProgramFiles%\devolo\dlan|dlanhistory.*txt;dlanstats.*xml;support.html;support.zip +FileKey2=%ProgramFiles%\devolo\dlan\updates|*.*|RECURSE + +[Devolutions Remote Desktop Manager *] +LangSecRef=3021 +DetectFile=%AppData%\Devolutions\RemoteDesktopManager +Default=False +FileKey1=%AppData%\Devolutions\RemoteDesktopManager|*.log;*.log.db +FileKey2=%LocalAppData%\Devolutions\RemoteDesktopManager|*.log;*.log.db + +[Dexpot *] +LangSecRef=3024 +Detect=HKCU\Software\Dexpot +Default=False +FileKey1=%AppData%\Dexpot|*.log + +[Diablo 2 *] +Section=Games +Detect=HKCU\Software\Blizzard Entertainment\Diablo II +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Diablo II|bnupdate.log;BnetLog.txt;D*.txt +FileKey2=%ProgramFiles%\Diablo II|bnupdate.log;BnetLog.txt;D*.txt +FileKey3=%SystemDrive%\Diablo II|bnupdate.log;BnetLog.txt;D*.txt + +[Diablo III *] +Section=Games +Detect=HKCU\Software\Blizzard Entertainment\D3 +Default=False +FileKey1=%CommonAppData%\Battle.net\Setup\diablo3_engb\Log|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Diablo III*\Logs|*.* +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Battle.net\Setup\diablo3_engb\Log|*.* +FileKey4=%ProgramFiles%\Diablo III*\Logs|*.* + +[Digi Net Mobile *] +LangSecRef=3021 +DetectFile=%CommonAppData%\Digi Net Mobile +Default=False +FileKey1=%CommonAppData%\Digi Net Mobile\log|*.log;*.txt +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Digi Net Mobile\log|*.log;*.txt + +[Digital Janitor *] +LangSecRef=3024 +Detect=HKCU\Software\Davide Vitelaru\Digital Janitor +Default=False +FileKey1=%AppData%\Digital Janitor|ToSortHistory + +[Digsby *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Digsby +Default=False +FileKey1=%LocalAppData%\Digsby\Logs|*.*|RECURSE +FileKey2=%LocalAppData%\Digsby\Temp|*.*|RECURSE + +[Digsby Cache *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Digsby +Default=False +FileKey1=%LocalAppData%\Digsby\Cache|*.*|RECURSE + +[Digsby Chat Logs *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Digsby +Default=False +FileKey1=%Documents%\Digsby Logs|*.*|RECURSE + +[Direct3D Shader Cache *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%LocalAppData%\D3DSCache|*.*|RECURSE + +[Directory Opus *] +LangSecRef=3024 +Detect=HKLM\Software\GPSoftware\Directory Opus +Default=False +FileKey1=%AppData%\GPSoftware\Directory Opus\Icon Cache Roaming|*.*|RECURSE +FileKey2=%LocalAppData%\GPSoftware\Directory Opus\Thumbnail Cache|*.*|RECURSE + +[Discord *] +LangSecRef=3022 +Detect1=HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Discord +Detect2=HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DiscordCanary +Detect3=HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DiscordPTB +Default=False +FileKey1=%AppData%\discord*|modules.log;*.tmp +FileKey2=%AppData%\discord*\*Cache|*.*|REMOVESELF +FileKey3=%LocalAppData%\Discord*|*.log +FileKey4=%LocalAppData%\Discord*\packages\SquirrelTemp|*.*|REMOVESELF +FileKey5=%LocalAppData%\SquirrelTemp|*.*|REMOVESELF + +[Dishonored *] +Section=Games +Detect=HKCU\Software\Arkane\Dishonored +DetectFile=%Documents%\My Games\Dishonored +Default=False +FileKey1=%Documents%\My Games\Dishonored\DishonoredGame\Logs|*.* + +[Disk Space Fan *] +LangSecRef=3024 +Detect=HKCU\Software\Cookapp\DSF4 +Default=False +FileKey1=%AppData%\DiskSpaceFan|log.txt;history_C.sqlite + +[DiskBoss *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DiskBoss Ultimate +Default=False +FileKey1=%LocalAppData%\DiskBoss Ultimate\data\reports|*.*|REMOVESELF + +[DiskMax *] +LangSecRef=3024 +Detect=HKCU\Software\KoshyJohn.com +Default=False +FileKey1=%AppData%\KoshyJohn.com\DiskMax|DiskMax Log.txt + +[DisplayFusion *] +LangSecRef=3024 +Detect=HKCU\Software\Binary Fortress Software\DisplayFusion +Default=False +FileKey1=%AppData%\DisplayFusion|DisplayFusionSetup.log;DisplayFusionSetup.exe;DisplayFusion.log;DebugInfo.* + +[DivX *] +LangSecRef=3023 +Detect=HKCU\Software\DivX +Default=False +FileKey1=%AppData%\DivX|Font Cache.|RECURSE +FileKey2=%CommonAppData%\DivX|*.log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\DivX|*.log|RECURSE +FileKey4=%Video%\DivX Movies|*.*|RECURSE +RegKey1=HKCU\Software\DivX\Settings\Converter|lastBrowseDir +RegKey2=HKCU\Software\DivX\Settings\Converter|outputDir +RegKey3=HKCU\Software\DivX\Settings\Player\PlayerState|LastOpenFileLocation +RegKey4=HKCU\Software\DivX\Settings\TransferWizard|LastBrwosedDir +RegKey5=HKCU\Software\DivXNetworks\DivX Player|file +RegKey6=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry1 +RegKey7=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry2 +RegKey8=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry3 +RegKey9=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry4 +RegKey10=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry5 +RegKey11=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry6 + +[DLExpert *] +LangSecRef=3021 +Detect=HKCU\Software\Ying3\DLExpert +Default=False +RegKey1=HKCU\Software\Ying3\DLExpert|ftp +RegKey2=HKCU\Software\Ying3\DLExpert|http +RegKey3=HKCU\Software\Ying3\DLExpert\MAIN|ALLFILE +RegKey4=HKCU\Software\Ying3\DLExpert\MAIN|GOOD +RegKey5=HKCU\Software\Ying3\DLExpert\MAIN|GOODURL +RegKey6=HKCU\Software\Ying3\DLExpert\Recent File List + +[DoctorWeb *] +LangSecRef=3024 +DetectFile=%UserProfile%\DoctorWeb\Quarantine +Default=False +FileKey1=%UserProfile%\DoctorWeb\Quarantine|*.*|RECURSE + +[Document Trace Remover *] +LangSecRef=3024 +Detect=HKCU\Software\Smart PC Solutions\Document Trace Remover +Default=False +FileKey1=%AppData%\Smart PC Solutions\Smart Fast PC\Log|*.* +RegKey1=HKCU\Software\Smart PC Solutions\Document Trace Remover|LastFile +RegKey2=HKCU\Software\Smart PC Solutions\Document Trace Remover|LastFolder + +[Dogpile Toolbar *] +LangSecRef=3022 +Detect=HKCU\Software\Infospace\DogpileToolbar +Default=False +RegKey1=HKCU\Software\Infospace\DogpileToolbar\History|1-terms + +[Dollar Dash *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\214320 +Default=False +FileKey1=%Documents%\My Games\DollarDash\PKGame\Logs|*.* + +[Dolphin Emulator *] +Section=Games +DetectFile=%Documents%\Dolphin Emulator +Default=False +FileKey1=%Documents%\Dolphin Emulator\Logs|*.*|RECURSE + +[Don't Starve *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\219740 +Default=False +FileKey1=%Documents%\Klei\DoNotStarve|log.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\dont_starve\bin|log.txt +FileKey3=%ProgramFiles%\Steam\steamapps\common\dont_starve\bin|log.txt + +[Dooble Downloads *] +LangSecRef=3022 +DetectFile=%SystemDrive%\Dooble +Default=False +FileKey1=%SystemDrive%\Dooble\*\.dooble|downloads.db + +[Dooble Internet Traces *] +LangSecRef=3022 +DetectFile=%SystemDrive%\Dooble +Default=False +FileKey1=%SystemDrive%\Dooble\*\.dooble|cookies.db;favicons.fb;history.db +FileKey2=%SystemDrive%\Dooble\*\.dooble\Cache|*.*|REMOVESELF + +[DOOM *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\379720 +Default=False +FileKey1=%LocalAppData%\id Software\DOOM\base\generated\temp|*.* +FileKey2=%UserProfile%\Saved Games\id Software\DOOM\base\generated\temp|*.* + +[Download App *] +LangSecRef=3024 +Detect=HKCU\Software\CBS Interactive\Download App +Default=False +FileKey1=%AppData%\CBS Interactive\Download App|*.log +FileKey2=%AppData%\CBS Interactive\Download App\Cache|*.* + +[Download App Databases *] +LangSecRef=3024 +Detect=HKCU\Software\CBS Interactive\Download App +Default=False +FileKey1=%AppData%\CBS Interactive\Download App\Data|*.db + +[Download App Downloads *] +LangSecRef=3024 +Detect=HKCU\Software\CBS Interactive\Download App +Default=False +FileKey1=%Documents%\Downloads\Download App|*.* + +[Downloaded Installations *] +LangSecRef=3025 +DetectFile=%LocalAppData%\Downloaded Installations +Default=False +FileKey1=%LocalAppData%\Downloaded Installations|*.*|REMOVESELF + +[DownTango *] +LangSecRef=3022 +DetectFile=%LocalAppData%\DownTango +Default=False +FileKey1=%LocalAppData%\DownTango|application.log +FileKey2=%LocalAppData%\DownTango\Logs|log.txt + +[Dr. Despicable’s Dastardly Deeds *] +Section=Games +DetectFile=%AppData%\HitPoint Studios\DrD +Default=False +FileKey1=%AppData%\HitPoint Studios\DrD|logfile.txt + +[Dr. Web CureIt! *] +LangSecRef=3024 +DetectFile=%UserProfile%\Doctor Web +Default=False +FileKey1=%UserProfile%\Doctor Web|*.log + +[DraftSight *] +LangSecRef=3021 +Detect1=HKCU\Software\Dassault Systemes\DraftSight +Detect2=HKLM\Software\Dassualt Systemes\DraftSight +Default=False +FileKey1=%AppData%\DraftSight\*|history.txt;plot.log +FileKey2=%LocalAppData%\Dassault Systemes\DraftSight\cache|*.*|RECURSE + +[Dragon Age: Origins *] +Section=Games +Detect1=HKCU\Software\BioWare\Dragon Age +Detect2=HKLM\Software\BioWare\Dragon Age +Default=False +FileKey1=%CommonAppData%\BioWare\Dragon Age\DA Updater\Logs|*.* +FileKey2=%Documents%\BioWare\Dragon Age\Logs|*.* +FileKey3=%LocalAppData%\VirtualStore\ProgramData\BioWare\Dragon Age\DA Updater\Logs|*.* + +[Dreadnought *] +Section=Games +Detect=HKCU\Software\Grey Box\Dreadnought +Default=False +FileKey1=%LocalAppData%\DreadGame\Saved\Logs|*.log + +[DriveImage XML *] +LangSecRef=3021 +Detect=HKLM\Software\Runtime Software\DIXML +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Runtime Software\DriveImage XML|log.txt +FileKey2=%ProgramFiles%\Runtime Software\DriveImage XML|log.txt + +[Driver Cleaner.NET *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\DriverCleanerDotNET\DriverCleanerDotNET.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\DriverCleanerDotNET\Backup|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\DriverCleanerDotNET\Log|*.* +FileKey3=%ProgramFiles%\DriverCleanerDotNET\Backup|*.*|RECURSE +FileKey4=%ProgramFiles%\DriverCleanerDotNET\Log|*.* + +[Driver Fusion *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Driver Fusion\Logs +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Driver Fusion\Logs|*.*|RECURSE +FileKey2=%ProgramFiles%\Driver Fusion\Logs|*.*|RECURSE + +[Driver Fusion Backup *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Driver Fusion\Backup +Default=False +Warning=This will delete your driver backups. +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Driver Fusion\Backup|*.*|RECURSE +FileKey2=%ProgramFiles%\Driver Fusion\Backup|*.*|RECURSE + +[Driver Installation Files *] +LangSecRef=3025 +DetectFile=%SystemDrive%\Drivers +Default=False +FileKey1=%SystemDrive%\Drivers|*.*|REMOVESELF + +[Driver Magician *] +LangSecRef=3021 +Detect=HKCU\Software\Driver Magician +Default=False +FileKey1=%AppData%\Driver Magician|HiddenUpdate.txt + +[Driver Reinstall Backup *] +LangSecRef=3025 +DetectFile=%WinDir%\System32\ReinstallBackups +Default=False +FileKey1=%WinDir%\System32\ReinstallBackups|*.*|RECURSE + +[Driver Updater *] +LangSecRef=3023 +Detect=HKLM\Software\SuperEasy Software +Default=False +FileKey1=%AppData%\SuperEasy Software\Driver Updater|*.log + +[DriverCure *] +LangSecRef=3024 +Detect=HKCU\Software\ParetoLogic DriverCure +Default=False +FileKey1=%AppData%\DriverCure|LogFile.* + +[DriverEasy Driver Backups *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Easeware\DriverEasy +Default=False +FileKey1=%Documents%\DriverEasy|*.*|RECURSE + +[DriverEasy Driver Installation Files *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Easeware\DriverEasy +Default=False +FileKey1=%AppData%\Easeware\DriverEasy\drivers|*.*|RECURSE + +[DriverGenius *] +LangSecRef=3024 +Detect=HKLM\Software\Driver-Soft\DriverGenius +DetectFile=%ProgramFiles%\Driver-Soft\DriverGenius +Default=False +FileKey1=%CommonAppData%\DriverGenius|*.log +FileKey2=%LocalAppData%\DriverGenius|ScanLog.log +FileKey3=%LocalAppData%\VirtualStore\ProgramData\DriverGenius|*.log + +[DriverMax *] +LangSecRef=3024 +Detect=HKCU\Software\Innovative Solutions\DriverMax +Default=False +FileKey1=%LocalAppData%\Innovative Solutions\DriverMax\Agent|*.tmp;dmxlog.txt +FileKey2=%LocalAppData%\Innovative Solutions\DriverMax\Agent\Downloded Drivers|*.* +FileKey3=%LocalAppData%\Innovative Solutions\DriverMax\Agent\Uploads|*.*|RECURSE +FileKey4=%LocalAppData%\Innovative Solutions\DriverMax\Backup|*.* +FileKey5=%LocalAppData%\Innovative Solutions\DriverMax\LastScan|*.* +FileKey6=%LocalAppData%\Innovative Solutions\DriverMax\Temp*|*.* +FileKey7=%ProgramFiles%\Innovative Solutions\DriverMax|*.log + +[DriverPack Solution *] +LangSecRef=3024 +Detect=HKCU\Software\drpsu +Default=False +Warning=This will delete your bug report. +FileKey1=%AppData%\DRPSu\Logs|*.* +FileKey2=%AppData%\DRPSu\snapshots|*.* +FileKey3=%AppData%\DRPSu\temp|*.* +FileKey4=%Documents%\DRP-Log|*.* +FileKey5=%WinDir%\Logs\DRPLog|*.png;*.txt +FileKey6=%WinDir%\Logs\SysInfo|*.* + +[DriverRadarPro *] +LangSecRef=3024 +Detect=HKCU\Software\NoVirusThanks\DriverRadarPro +Default=False +RegKey1=HKCU\Software\NoVirusThanks\DriverRadarPro|edCopyDrvTo +RegKey2=HKCU\Software\NoVirusThanks\DriverRadarPro|edSaveLogsTo + +[DriverRobot *] +LangSecRef=3024 +Detect=HKCU\Software\Driver Robot +Default=False +FileKey1=%AppData%\Blitware\DriverRobot\Logs|*.* + +[Drivers Installer Assistant *] +LangSecRef=3024 +Detect=HKCU\Software\VB and VBA Program Settings\Drivers Installer Assistant +Default=False +FileKey1=%WinDir%\Logs\DIALog|*.txt + +[DriverUpdate *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Slimware Utilities Inc\DriverUpdate +Default=False +FileKey1=%LocalAppData%\SlimWare Utilities Inc\DriverUpdate\Logs|*.*|RECURSE + +[DriverUpdate Backups *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Slimware Utilities Inc\DriverUpdate +Default=False +FileKey1=%LocalAppData%\Slimware Utilities Inc\DriverUpdate\Backups|*.* + +[DriverUpdate Downloads *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Slimware Utilities Inc\DriverUpdate +Default=False +FileKey1=%LocalAppData%\SlimWare Utilities Inc\DriverUpdate\Downloads|*.*|RECURSE +FileKey2=%LocalAppData%\SlimWare Utilities Inc\DriverUpdate\Images|*.*|RECURSE + +[Dropbox *] +LangSecRef=3024 +Detect=HKCU\Software\Dropbox +Default=False +FileKey1=%AppData%\DropBox|Filecache.db;SigStore.db +FileKey2=%AppData%\DropBox\Bin|*.log +FileKey3=%AppData%\Dropbox\installer|*.*|RECURSE +FileKey4=%AppData%\Dropbox\logs|*.*|RECURSE +FileKey5=%CommonAppData%\Dropbox\Update\Log|*.* +FileKey6=%LocalAppData%\Dropbox\Logs|*.*|RECURSE +FileKey7=%ProgramFiles%\Dropbox\Update\Download|*.*|REMOVESELF + +[Dropbox Cache *] +LangSecRef=3024 +Detect=HKCU\Software\Dropbox +Default=False +Warning=This will remove cached versions of modified and deleted files. +FileKey1=%AppData%\Dropbox\Cache|*.*|RECURSE +FileKey2=%Documents%\Dropbox\.dropbox.cache|*.*|RECURSE +FileKey3=%UserProfile%\Dropbox\.dropbox.cache|*.*|RECURSE + +[DU meter *] +LangSecRef=3022 +Detect=HKCU\Software\Hagel\DU Meter +Default=False +FileKey1=%CommonAppData%\Hagel Technologies\DU Meter|*.csv +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Hagel Technologies\DU Meter|*.csv + +[DuckieTV *] +LangSecRef=3023 +DetectFile=%AppData%\DuckieTV +Default=False +FileKey1=%AppData%\DuckieTV|*.log;*.txt + +[Duke Nukem 3D *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\225140 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\Duke Nukem 3D\bin|stderr.txt;stdout.txt +FileKey2=%ProgramFiles%\Steam\SteamApps\common\Duke Nukem 3D\bin|stderr.txt;stdout.txt + +[DUMo *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\DUMo +Default=False +FileKey1=%AppData%\KC Softwares\DUMo|*.log + +[Dungeon Of The Endless *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\249050 +Default=False +FileKey1=%Documents%\Dungeon of the Endless\Temporary Files|*.* + +[Dungeons - The Dark Lord *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\200550 +Default=False +FileKey1=%AppData%\Kalypso Media\Dungeons - The Dark Lord|log.txt + +[Dup Detector *] +LangSecRef=3023 +Detect=HKCU\Software\Prismatic Software\PhotoBatch +Default=False +RegKey1=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastBatFile +RegKey2=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastFold +RegKey3=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSecFold +RegKey4=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSingleFold + +[Duplicate Cleaner *] +LangSecRef=3024 +DetectFile=%AppData%\DigitalVolcano +Default=False +FileKey1=%AppData%\DigitalVolcano\DuplicateCleaner|*.data +FileKey2=%Documents%|Duplicate Cleaner log.txt + +[DVBDream *] +LangSecRef=3024 +Detect=HKLM\Software\DVBDream +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\dvbdream|*.log;*.bak;*levellog*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\dvbdream\Logs|*.* +FileKey3=%ProgramFiles%\dvbdream|*.log;*.bak;*levellog*|RECURSE +FileKey4=%ProgramFiles%\dvbdream\Logs|*.* +FileKey5=%SystemDrive%\dvbdream|*.log;*.bak;*levellog*|RECURSE +FileKey6=%SystemDrive%\dvbdream\Logs|*.* + +[DVBViewer *] +LangSecRef=3023 +Detect=HKLM\Software\CM&V\DVBViewer +Default=False +FileKey1=%CommonAppData%\CMUV\DVBViewer*|*.bak;*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\CMUV\DVBViewer*|*.bak;*.log + +[DVBViewer Setup Files *] +LangSecRef=3023 +Detect=HKLM\Software\CM&V\DVBViewer +Default=False +Warning=This will prevent a modify installation. You have to download the installer to modify the installation. +FileKey1=%CommonAppData%\CMUV\DVBViewer\backup|*.*|REMOVESELF +FileKey2=%ProgramFiles%\DVBViewer\backup|*.*|REMOVESELF +FileKey3=%ProgramFiles%\DVBViewer\GraphPresets|*.fgp +FileKey4=%ProgramFiles%\DVBViewer\Remotes|*.* +FileKey5=%ProgramFiles%\DVBViewer\setup|*.* +FileKey6=%ProgramFiles%\DVBViewer\Transponders|*.* + +[DVD-Cloner *] +LangSecRef=3023 +Detect1=HKCU\Software\Dvd-cloner +Detect2=HKCU\Software\DVD-Cloner Gold +Detect3=HKCU\Software\iPod-Cloner +Default=False +FileKey1=%AppData%\DVD-Cloner*|*.log +FileKey2=%CommonAppData%\DVD-Cloner*|*.log +FileKey3=%Documents%|Smart.log;Smart_result.log +FileKey4=%LocalAppData%\VirtualStore\Program Files*\DVD-Cloner Platinum\*\readcache|*.* +FileKey5=%LocalAppData%\VirtualStore\Program Files*\DVD-Cloner*|*.log|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\DVD-Cloner*|*.log +FileKey7=%ProgramFiles%\DVD-Cloner Platinum\*\readcache|*.* +FileKey8=%ProgramFiles%\DVD-Cloner*|*.log|RECURSE +FileKey9=%SystemDrive%|dtdlog.txt +FileKey10=%WinDir%\system32|dvdtest10024.dat + +[DVD-Ranger *] +LangSecRef=3021 +Detect=HKLM\Software\DVD-Ranger +Default=False +FileKey1=%CommonAppData%\DVDRanger\DDF626ADdvdcss|*.* +FileKey2=%CommonAppData%\DVDRanger\Logs|*.* +FileKey3=%Documents%\DVDRanger\Screenshots|*.*|RECURSE +FileKey4=%Documents%\DVDRanger\Temp|*.*|REMOVESELF +FileKey5=%LocalAppData%\VirtualStore\ProgramData\DVDRanger\DDF626ADdvdcss|*.* +FileKey6=%LocalAppData%\VirtualStore\ProgramData\DVDRanger\Logs|*.* +FileKey7=%SystemDrive%\DVDRanger|*.*|REMOVESELF + +[DVD Flick *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\DVD Flick\dvdflick.exe +Default=False +FileKey1=%AppData%\DVD Flick|dvdflick.log;report.txt + +[DVD Shrink Analysis Results *] +LangSecRef=3023 +Detect=HKCU\Software\DVD Shrink +Default=False +Warning=Each time you use this you'll have to agree to the DVD Shrink license. +FileKey1=%CommonAppData%\DVD Shrink|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\DVD Shrink|*.* + +[dvdcss *] +LangSecRef=3023 +DetectFile1=%AppData%\.dvdcss +DetectFile2=%AppData%\dvdcss +DetectFile3=%UserProfile%\.dvdcss +Default=False +FileKey1=%AppData%\.dvdcss|*.*|REMOVESELF +FileKey2=%AppData%\dvdcss|*.*|REMOVESELF +FileKey3=%UserProfile%\.dvdcss|*.*|REMOVESELF + +[DVDFab *] +LangSecRef=3023 +Detect1=HKCU\Software\DVDFab +Detect2=HKCU\Software\DVDFab Passkey +Detect3=HKCU\Software\FabPlayer +Default=False +FileKey1=%Documents%\DVDFab*|*.log +FileKey2=%Documents%\DVDFab*\Log|*.*|RECURSE +FileKey3=%Documents%\DVDFab*\SceneData|*.*|RECURSE +FileKey4=%Documents%\DVDFab*\Temp|*.*|RECURSE +FileKey5=%Documents%\PcSetup|*.*|RECURSE +RegKey1=HKCU\Software\FabPlayer|DefaultFile + +[DVDSmith *] +LangSecRef=3023 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DVDSmith Movie Backup_is1 +Default=False +FileKey1=%Documents%\dvdsmith|*.log + +[DVDVideoSoft *] +LangSecRef=3023 +Detect1=HKCU\Software\AppDataLow\Software\DVDVideoSoftTB +Detect2=HKCU\Software\DVDVideoSoft +Default=False +FileKey1=%AppData%\DVDVideoSoft\*\History|*.*|RECURSE +FileKey2=%AppData%\DVDVideoSoft\*Logs|*.*|RECURSE +FileKey3=%Documents%\DVDVideoSoft|*log.txt|RECURSE +FileKey4=%LocalAppData%\DVDVideoSoftTB\Logs|*.*|RECURSE + +[DVDVideoSoft Backup *] +LangSecRef=3024 +Detect=HKCU\Software\DVDVideoSoft +Default=False +FileKey1=%AppData%\DVDVideoSoft\Backup|*.*|RECURSE + +[DVDx *] +LangSecRef=3023 +Detect=HKCU\Software\DVDx +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\DVDx|*.tmp +FileKey2=%ProgramFiles%\DVDx|*.tmp +RegKey1=HKCU\Software\DVDx\LastDir +RegKey2=HKCU\Software\DVDx\LastOutput + +[DxO Photo Suite *] +LangSecRef=3021 +Detect1=HKCU\Software\DxO +Detect2=HKCU\Software\DxO Labs +Detect3=HKCU\Software\DxOLabs +Detect4=HKLM\Software\DxO +Detect5=HKLM\Software\DxO Labs +Detect6=HKLM\Software\DxOLabs +Default=False +FileKey1=%Documents%\DxO * crash*s|*.* +FileKey2=%Documents%\DxO * logs|*.* +FileKey3=%Documents%\DxO*\CrashReports|*.*|RECURSE +FileKey4=%Documents%\DxO*\log|*.* +FileKey5=%LocalAppData%\DxO*\DataCache|*.*|RECURSE +FileKey6=%LocalAppData%\DxO*\DxO*\*Cache|*.*|RECURSE +FileKey7=%LocalAppData%\DxO*\DxO*\CrashReports|*.*|RECURSE +FileKey8=%LocalAppData%\DxO*\DxO*\Logs|*.* +FileKey9=%LocalAppData%\DxO*\Logs|*.* + +[Dyn Updater *] +LangSecRef=3022 +Detect=HKCU\Software\Dyn\Dyn Updater +Default=False +FileKey1=%CommonAppData%\Dyn\Updater|*.log;*.msi +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Dyn\Updater|*.log;*.msi + +[EA Core *] +Section=Games +Detect=HKCU\Software\EA Games\EA Core +Default=False +FileKey1=%CommonAppData%\EA Core\Cache|*.*|REMOVESELF +FileKey2=%CommonAppData%\EA Logs|*.* +FileKey3=%CommonAppData%\Electronic Arts\EA Core\logs|*.* +FileKey4=%LocalAppData%\EA Core\Cache|*.*|REMOVESELF +FileKey5=%LocalAppData%\VirtualStore\ProgramData\EA Core\Cache|*.*|REMOVESELF +FileKey6=%LocalAppData%\VirtualStore\ProgramData\EA Logs|*.* +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Electronic Arts\EA Core\logs|*.* + +[EA Download Manager *] +Section=Games +Detect=HKLM\Software\Electronic Arts\EADM +Default=False +FileKey1=%LocalAppData%\Electronic Arts\EADMUI\Web Cache|*.*|RECURSE + +[Earth 2160 *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\19000 +Default=False +FileKey1=%Documents%\Earth 2160\FontsCache|*.* + +[Earth Alerts Images *] +LangSecRef=3022 +Detect=HKCU\Software\South Wind Technologies\Earth Alerts +Default=False +FileKey1=%AppData%\Earth Alerts\Images|*.*|RECURSE + +[Earth Alerts Messages *] +LangSecRef=3022 +Detect=HKCU\Software\South Wind Technologies\Earth Alerts +Default=False +FileKey1=%AppData%\Earth Alerts\Messages|*.*|RECURSE + +[EaseUS Data Recovery Wizard *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\EaseUS\EaseUS Data Recovery Wizard|*.log +FileKey2=%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard|*.log +ExcludeKey1=FILE|%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard\|install.log + +[EaseUS MobiSaver *] +LangSecRef=3021 +Detect=HKLM\Software\EASEUS\EASEUS IPhone Wizard +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\EaseUS\EaseUS MobiSaver\bin|CommDbg.txt;easeusue.log;PR.log +FileKey2=%ProgramFiles%\EaseUS\EaseUS MobiSaver\bin|CommDbg.txt;easeusue.log;PR.log +FileKey3=%SystemDrive%\EaseUS MobiSaver Temp Backup|*.*|RECURSE + +[EaseUS MobiSaver for Android *] +LangSecRef=3021 +Detect=HKLM\Software\EaseUS\Mobisaver for Android +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\EaseUS\EaseUS MobiSaver for Android\bin|CommDbg.txt;Eaolog;easeusue.log;mbs;PR.log +FileKey2=%ProgramFiles%\EaseUS\EaseUS MobiSaver for Android\bin|CommDbg.txt;Eaolog;easeusue.log;mbs;PR.log +FileKey3=%SystemDrive%\EaseUS MobiSaver for Android Temp Backup|*.*|RECURSE + +[EaseUS Partition Master *] +LangSecRef=3024 +Detect=HKCU\Software\EASEUS\EASEUS Partition Manager +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\EASEUS\EASEUS Partition Master*\bin|*.log +FileKey2=%ProgramFiles%\EASEUS\EASEUS Partition Master*\bin|*.log|RECURSE + +[EaseUS ToDo Backup *] +LangSecRef=3024 +Detect=HKCU\Software\EaseUS\EaseUS Todo Backup +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\EaseUS\Todo Backup\bin|easeus.log;TbLogsysClient.tblog +FileKey2=%ProgramFiles%\EaseUS\Todo Backup\bin|easeus.log;TbLogsysClient.tblog + +[East-Tec Eraser *] +LangSecRef=3024 +Detect=HKLM\Software\East-Tec\east-tec Eraser +Default=False +FileKey1=%CommonAppData%\East-Tec\east-tec Eraser\Updates|*.*|RECURSE +FileKey2=%ProgramFiles%\east-tec Eraser|except.log + +[Easy CD-DA Extractor *] +LangSecRef=3024 +Detect=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8 +Default=False +RegKey1=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k8c +RegKey2=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k80 +RegKey3=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k81 +RegKey4=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k91 +RegKey5=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k92 + +[EasyAntiCheat *] +Section=Games +DetectFile=%AppData%\EasyAntiCheat +Default=False +FileKey1=%AppData%\EasyAntiCheat|*.log|REMOVESELF + +[EasyGPS *] +LangSecRef=3024 +Detect=HKCU\Software\TopoGrafix\EasyGPS +Default=False +FileKey1=%LocalAppData%\TopoGrafix\Error Logs|*.txt +RegKey1=HKCU\Software\TopoGrafix\EasyGPS\Error Log +RegKey2=HKCU\Software\TopoGrafix\EasyGPS\Recent File List + +[eBay Toolbar *] +LangSecRef=3022 +Detect=HKCU\Software\eBay\eBayToolbar +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\eBay\eBay Toolbar*|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\eBay\eBay Toolbar*\eBayhistory|*.*|RECURSE +FileKey3=%ProgramFiles%\eBay\eBay Toolbar*|*.log +FileKey4=%ProgramFiles%\eBay\eBay Toolbar*\eBayhistory|*.*|RECURSE +RegKey1=HKCU\Software\eBay\eBayToolbar\History +RegKey2=HKCU\Software\eBay\eBayToolbar\RecentSearches + +[eBay TurboLister *] +LangSecRef=3021 +Detect1=HKCU\Software\eBay\Turbo lister +Detect2=HKCU\Software\eBay\Turbo lister2 +Default=False +FileKey1=%CommonAppData%\eBay\Turbo Lister*|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\eBay\Turbo Lister*|*.log|RECURSE + +[EC XTRA Timer *] +LangSecRef=3021 +DetectFile=%AppData%\The Toro Company +Default=False +FileKey1=%AppData%\The Toro Company|ECXTRAoutput.txt + +[Edna & Harvey: Harvey's New Eyes *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\219910 +DetectFile=%LocalAppData%\Daedalic Entertainment\Harvey +Default=False +FileKey1=%LocalAppData%\Daedalic Entertainment\Harvey|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\Edna and Harvey Harvey's New Eyes|stderr.txt +FileKey3=%ProgramFiles%\Steam\Steamapps\common\Edna and Harvey Harvey's New Eyes|stderr.txt + +[Effective File Search *] +LangSecRef=3024 +Detect=HKCU\Software\SOW\EFS +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\efs|cblist*.dat +FileKey2=%ProgramFiles%\efs|cblist*.dat + +[Efficient Calendar *] +LangSecRef=3021 +DetectFile=%AppData%\Efficient Calendar +Default=False +FileKey1=%AppData%\Efficient Calendar\MRUItems|*.*|RECURSE + +[Elcomsoft Wireless Security Auditor *] +LangSecRef=3021 +Detect=HKCU\Software\ElcomSoft\Elcomsoft Wireless Security Auditor +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Elcomsoft Password Recovery\Elcomsoft Wireless Security Auditor|*.log +FileKey2=%ProgramFiles%\Elcomsoft Password Recovery\Elcomsoft Wireless Security Auditor|*.log + +[Elder Scrolls Online *] +Section=Games +DetectFile=%Documents%\Elder Scrolls Online +Default=False +FileKey1=%Documents%\Elder Scrolls Online\Errors|*.* +FileKey2=%Documents%\Elder Scrolls Online\Logs|*.* + +[Electric Sheep *] +LangSecRef=3021 +DetectFile=%CommonAppData%\ElectricSheep +Default=False +FileKey1=%CommonAppData%\ElectricSheep\Logs|*.* + +[ElsterFormular *] +LangSecRef=3021 +DetectFile=%AppData%\elsterformular +Default=False +FileKey1=%AppData%\elsterformular\*\log|*.log;*.log.* +FileKey2=%AppData%\elsterformular\*\tmp|*.*|RECURSE +FileKey3=%AppData%\elsterformular\pluginmanager\data|*_cpy.zip +FileKey4=%CommonAppData%\elsterformular\log|*.log +FileKey5=%LocalAppData%\.elfohilfe|*.*|REMOVESELF +FileKey6=%LocalAppData%\elfopatch|*.*|REMOVESELF + +[eM Client *] +LangSecRef=3022 +Detect=HKCU\Software\eM Client +Default=False +FileKey1=%AppData%\eM Client\Logs|*.* + +[Email Address Collector *] +LangSecRef=3022 +DetectFile=%AppData%\DS Development\EAC +Default=False +FileKey1=%AppData%\DS Development\EAC|*.log + +[EmEditor *] +LangSecRef=3024 +Detect=HKCU\Software\EmSoft\EmEditor v3 +Default=False +RegKey1=HKCU\Software\EmSoft\EmEditor v3\Recent File List +RegKey2=HKCU\Software\EmSoft\EmEditor v3\Recent Folder List +RegKey3=HKCU\Software\EmSoft\EmEditor v3\Recent Font List + +[emesene2 *] +LangSecRef=3022 +DetectFile=%AppData%\emesene\emesene2 +Default=False +FileKey1=%AppData%\emesene\emesene2\*\*\*\avatars|*.*|RECURSE +FileKey2=%AppData%\emesene\emesene2\*\*\*avatars|*.*|RECURSE +FileKey3=%AppData%\emesene\emesene2\*\*\log|*.*|RECURSE + +[Emsisoft HiJackFree *] +LangSecRef=3024 +Detect=HKLM\Software\Emsi Software GmbH\a-squared HiJackFree +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Emsisoft HiJackFree|*.old +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Emsisoft HiJackFree\Logs|*.* +FileKey3=%ProgramFiles%\Emsisoft HiJackFree|*.old +FileKey4=%ProgramFiles%\Emsisoft HiJackFree\Logs|*.* + +[EndNote X6 *] +LangSecRef=3021 +Detect=HKLM\Software\ISI ResearchSoft\EndNote +Default=False +FileKey1=%AppData%\EndNote|*.log;*.16 +FileKey2=%CommonAppData%\Thomson.ResearchSoft.Installers|*.*|REMOVESELF +FileKey3=%CommonProgramFiles%\Risxtd|*.LOG;*.txt +FileKey4=%Documents%\My EndNote Library.Data\Trash|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\Program Files*\EndNote X6\Product-Support\ThirdParty\Apache2|NOTICE +FileKey6=%LocalAppData%\VirtualStore\Program Files*\EndNote*|*.txt +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Thomson.ResearchSoft.Installers|*.*|REMOVESELF +FileKey8=%LocalAppData%\VritualStore\Program Files*\Common Files\Risxtd|*.LOG;*.txt +FileKey9=%ProgramFiles%\EndNote X6\Product-Support\ThirdParty\Apache2|NOTICE +FileKey10=%ProgramFiles%\EndNote*|*.txt + +[EnhanceMy8 *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\EnhanceMy8 +Default=False +FileKey1=%AppData%\SeriousBit\EnhanceMy8|Logs.txt +FileKey2=%AppData%\SeriousBit\EnhanceMy8\Backups|*.*|RECURSE + +[Epic Games Launcher *] +Section=Games +Detect=HKCU\Software\Epic Games\EpicGamesLauncher +Default=False +FileKey1=%LocalAppData%\EpicGamesLauncher\Saved\Crashes|*.*|REMOVESELF +FileKey2=%LocalAppData%\EpicGamesLauncher\Saved\Logs|*.*|REMOVESELF + +[Epic Games Launcher Cache *] +Section=Games +Detect=HKCU\Software\Epic Games\EpicGamesLauncher +Default=False +FileKey1=%LocalAppData%\EpicGamesLauncher\Saved\webcache|*.*|REMOVESELF + +[Epson *] +LangSecRef=3021 +Detect=HKCU\Software\EPSON +Default=False +FileKey1=%AppData%\Epson\FAX Utility\FAXLOG|*.* + +[Eraser *] +LangSecRef=3024 +Detect=HKCU\Software\Heidi Computers Ltd\Eraser\5.5 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Eraser|schedlog.txt +FileKey2=%ProgramFiles%\Eraser*|schedlog.txt + +[ESET *] +LangSecRef=3021 +Detect=HKLM\Software\ESET\ESET Security +Default=False +Warning=You may need to run this in safe mode. You should also disable the ERA service to properly clean the ERA files. +FileKey1=%CommonAppData%\ESET\ESET*\Logs|*.*|RECURSE +FileKey2=%CommonAppData%\ESET\ESET*\Oldfiles|*.*|RECURSE +FileKey3=%CommonAppData%\ESET\ESET*\Updfiles|*.*|REMOVESELF +FileKey4=%LocalAppData%\VirtualStore\ProgramData\ESET\ESET*\Logs|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\ESET\ESET*\Oldfiles|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\ESET\ESET*\Updfiles|*.*|REMOVESELF + +[ESET Online Scanner *] +LangSecRef=3024 +Detect=HKLM\Software\ESET\ESET Security +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\ESET\ESET Online Scanner|log.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\ESET\ESET Online Scanner\Modules\data\updfiles\temp|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\ESET\ESET Online Scanner\Quarantine|*.* +FileKey4=%ProgramFiles%\ESET\ESET Online Scanner|log.txt +FileKey5=%ProgramFiles%\ESET\ESET Online Scanner\Modules\data\updfiles\temp|*.* +FileKey6=%ProgramFiles%\ESET\ESET Online Scanner\Quarantine|*.* + +[eSobi *] +LangSecRef=3022 +DetectFile=%AppData%\eSobi +Default=False +FileKey1=%AppData%\eSobi\*\temp|*.*|RECURSE + +[ESPN Cricinfo *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\ESPNCricinfo.ESPNCricinfo_y1atfjxm9t5ma +DetectFile=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_y1atfjxm9t5ma +Default=False +FileKey1=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE +FileKey3=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\PRICache|*.* +FileKey7=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\Temp|*.* +FileKey8=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\LocalState|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\TempState|*.*|RECURSE + +[ESPN FC *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\ESPNCricinfo.ESPNFC_y1atfjxm9t5ma +DetectFile=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_y1atfjxm9t5ma +Default=False +FileKey1=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE +FileKey3=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\AC\PRICache|*.* +FileKey4=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\AC\Temp|*.* +FileKey5=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\LocalState|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\TempState|*.*|RECURSE + +[ESPN Motion *] +LangSecRef=3023 +Detect=HKCU\Software\Disney\DIGStream +Default=False +FileKey1=%CommonAppData%\DIGStream\ESPNMotion|*.wmv;*.tmp +FileKey2=%LocalAppData%\VirtualStore\ProgramData\DIGStream\ESPNMotion|*.wmv;*.tmp + +[Essential NetTools 3 *] +LangSecRef=3022 +Detect=HKCU\Software\ENT3 +Default=False +RegKey1=HKCU\Software\ENT3\Recent + +[EssentialPIM Desktop *] +LangSecRef=3021 +Detect=HKLM\Software\clients\mail\essentialpim pro +DetectFile=%AppData%\EssentialPIM +Default=False +FileKey1=%AppData%\EssentialPIM*\Logs|*.* + +[Euro Truck Simulator *] +Section=Games +Detect1=HKCU\Software\SCS Software +Detect2=HKLM\Software\SCS Software +DetectFile=%ProgramFiles%\Euro Truck Simulator 2 +Default=False +FileKey1=%Documents%\Euro Truck Simulator*|*.log;*log.txt;*.crash + +[Euro Truck Simulator Profile Backups *] +Section=Games +Detect1=HKCU\Software\SCS Software +Detect2=HKLM\Software\SCS Software +Default=False +Warning=This will delete your Euro Truck Simulator profile backups. A profile backup will regenerate at next start. +FileKey1=%Documents%\Euro Truck Simulator*|backups.txt +FileKey2=%Documents%\Euro Truck Simulator*\profiles*.bak|*.*|REMOVESELF + +[EuroSYSTEMS CoCut Professional 2011 *] +LangSecRef=3021 +Detect=HKCU\Software\EuroSYSTEMS\CoCut Professional 2011 +Default=False +FileKey1=%AppData%\EUROSYSTEMS\CoCut Professional 2011 15|*.bak +FileKey2=%LocalAppData%\VirtualStore\Program Files*\EUROSYSTEMS\CoCut Professional 2011|*.log;*.bak;*.tmp +FileKey3=%LocalAppData%\VirtualStore\Program Files*\EUROSYSTEMS\CoCut Professional 2011\log|*.* +FileKey4=%ProgramFiles%\EUROSYSTEMS\CoCut Professional 2011|*.log;*.bak;*.tmp +FileKey5=%ProgramFiles%\EUROSYSTEMS\CoCut Professional 2011\log|*.* + +[EuroSYSTEMS SmartCut Pro *] +LangSecRef=3021 +Detect=HKCU\Software\EuroSYSTEMS +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\EUROSYSTEMS\SmartCut Pro|*.bak;*.tmp +FileKey2=%ProgramFiles%\EUROSYSTEMS\SmartCut Pro|*.bak;*.tmp + +[EVE Online *] +Section=Games +Detect=HKCU\Software\CCP +Default=False +FileKey1=%AppData%\EVEMon|*.bak +FileKey2=%Documents%\EVE\Logs|*.*|RECURSE +FileKey3=%LocalAppData%\CCP\EVE|history.txt + +[Evernote Skitch *] +LangSecRef=3021 +Detect=HKCU\Software\Evernote\Skitch +Default=False +FileKey1=%LocalAppData%\Skitch|logfile.txt +RegKey1=HKCU\Software\Evernote\Skitch|lastDoc + +[Evernote Updates *] +LangSecRef=3021 +Detect=HKCU\Software\Evernote +Default=False +FileKey1=%LocalAppData%\Evernote\Evernote\AutoUpdate|*.exe +FileKey2=%LocalAppData%\Evernote\Evernote\Updates|*.* + +[Everyday Genius: SquareLogic *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\32150 +DetectFile=%AppData%\SquareLogic +Default=False +FileKey1=%AppData%\SquareLogic|*.log + +[Everything *] +LangSecRef=3024 +DetectFile1=%AppData%\Everything +DetectFile2=%ProgramFiles%\Everything +Default=False +FileKey1=%AppData%\Everything|*.csv;*.txt;*.tmp +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Everything|*.txt;*.csv;*.tmp +FileKey3=%ProgramFiles%\Everything|*.csv;*.txt;*.tmp +ExcludeKey1=FILE|%AppData%\Everything\|Filters.csv +ExcludeKey2=FILE|%LocalAppData%\VirtualStore\Program Files*\Everything\|Filters.csv +ExcludeKey3=FILE|%ProgramFiles%\Everything\|Filters.csv + +[Exif Tag Remover *] +LangSecRef=3024 +Detect=HKCU\Software\VB and VBA Program Settings\RL Vision\Exif Tag Remover +Default=False +RegKey1=HKCU\Software\VB and VBA Program Settings\RL Vision\Exif Tag Remover|sLastAddDir +RegKey2=HKCU\Software\VB and VBA Program Settings\RL Vision\Exif Tag Remover|sLastDir + +[Exifer *] +LangSecRef=3024 +Detect=HKCU\Software\Exifer +Default=False +RegKey1=HKCU\Software\Exifer\Browse\History + +[ExifPro *] +LangSecRef=3024 +Detect=HKCU\Software\MKowalski\ExifPro +Default=False +FileKey1=%CommonAppData%\MiK\ExifPro|Cache* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\MiK\ExifPro|Cache* +RegKey1=HKCU\Software\MKowalski\ExifPro\1.0\Browser\View 0|LastPath +RegKey2=HKCU\Software\MKowalski\ExifPro\1.0\HTMLAlbumGen\RecentDestPaths +RegKey3=HKCU\Software\MKowalski\ExifPro\1.0\RecentPaths +RegKey4=HKCU\Software\MKowalski\ExifPro\1.0\ResizeDlg\RecentDestPaths + +[Exodus Cache *] +LangSecRef=3022 +Detect=HKCU\Software\Jabber\Exodus +Default=False +FileKey1=%AppData%\Exodus\avatars|cache.xml + +[Exodus Chat Logs *] +LangSecRef=3022 +Detect=HKCU\Software\Jabber\Exodus +Default=False +FileKey1=%Documents%\Exodus-Logs|*.*|RECURSE + +[Exportizer *] +LangSecRef=3024 +Detect=HKCU\Software\Vitaliy Levchenko\Exportizer 5 +Default=False +RegKey1=HKCU\Software\Vitaliy Levchenko\Exportizer 5\Settings|LastExt +RegKey2=HKLM\Software\ODBC\Temporary (volatile) Jet DSN for process 0x5ac Thread 0x3d8 DBC 0x2bd1e84 Xbase|DefaultDir +RegKey3=HKLM\Software\ODBC\Temporary (volatile) Jet DSN for process 0x858 Thread 0xfb0 DBC 0x2ca3a74 Paradox|DefaultDir + +[EZ Backup Ultimate *] +LangSecRef=3024 +Detect=HKCU\Software\Perception\EZ Backup Ultimate +Default=False +FileKey1=%AppData%\EZ Backup Ultimate|lastlog.html + +[F-Secure Password Manager *] +LangSecRef=3021 +Detect=HKCU\Software\F-Secure +Default=False +FileKey1=%LocalAppData%\F-Secure\Pwmgr|*.log +FileKey2=%LocalAppData%\F-Secure\Pwmgr\LocalStorage|*.*|RECURSE + +[Facebook *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Facebook.Facebook_8xx8rvfyw5nnt +DetectFile=%LocalAppData%\Packages\Facebook.Facebook_8xx8rvfyw5nnt +Default=False +FileKey1=%LocalAppData%\Packages\*Facebook_*\LocalState|*.*|RECURSE + +[Facebook Messenger *] +LangSecRef=3022 +DetectFile=%LocalAppData%\Facebook\Messenger +Default=False +FileKey1=%LocalAppData%\Facebook\Messenger|*.log|RECURSE + +[Facebook Plugin *] +LangSecRef=3022 +Detect=HKCU\Software\Facebook +Default=False +FileKey1=%LocalAppData%\Facebook\CrashReports|*.* + +[Faceprov *] +LangSecRef=3023 +Detect=HKCU\Software\Lenovo +Default=False +FileKey1=%SystemDrive%|Faceprov.* + +[Fallout Shelter *] +Section=Games +Detect1=HKCU\Software\Bethesda\Fallout Shelter +Detect2=HKCU\Software\Valve\Steam\Apps\588430 +Default=False +FileKey1=%LocalAppData%\FalloutShelter|*.log;*.bkp + +[Fantasy Wars *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\63900 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\Fantasy Wars|gui_log.txt +FileKey2=%ProgramFiles%\Steam\Steamapps\common\Fantasy Wars|gui_log.txt + +[FAR Manager *] +LangSecRef=3021 +Detect1=HKCU\Software\Far +Detect2=HKCU\Software\Far2 +Detect3=HKCU\Software\Far18 +Default=False +RegKey1=HKCU\Software\Far\Editor\LastPositions +RegKey2=HKCU\Software\Far\SavedDialogHistory +RegKey3=HKCU\Software\Far\SavedDialogHistory\PersPath +RegKey4=HKCU\Software\Far\SavedFolderHistory +RegKey5=HKCU\Software\Far\SavedHistory +RegKey6=HKCU\Software\Far\SavedViewHistory +RegKey7=HKCU\Software\Far\Viewer\LastPositions +RegKey8=HKCU\Software\Far2\Editor\LastPositions +RegKey9=HKCU\Software\Far2\SavedDialogHistory +RegKey10=HKCU\Software\Far2\SavedDialogHistory\PersPath +RegKey11=HKCU\Software\Far2\SavedFolderHistory +RegKey12=HKCU\Software\Far2\SavedHistory +RegKey13=HKCU\Software\Far2\SavedViewHistory +RegKey14=HKCU\Software\Far2\Viewer\LastPositions +RegKey15=HKCU\Software\Far18\Editor\LastPositions +RegKey16=HKCU\Software\Far18\SavedDialogHistory +RegKey17=HKCU\Software\Far18\SavedDialogHistory\PersPath +RegKey18=HKCU\Software\Far18\SavedFolderHistory +RegKey19=HKCU\Software\Far18\SavedHistory +RegKey20=HKCU\Software\Far18\SavedViewHistory +RegKey21=HKCU\Software\Far18\Viewer\LastPositions + +[Farming Simulator *] +Section=Games +Detect=HKLM\Software\SCS Software +Default=False +FileKey1=%Documents%\My Games\FarmingSimulator*|*.txt +FileKey2=%Documents%\My Games\FarmingSimulator*\pdlc*|*.dlc|REMOVESELF +FileKey3=%Documents%\My Games\FarmingSimulator*\shader_cache|*.shc;*.xml|REMOVESELF + +[Farming Simulator Old Autosaves *] +Section=Games +Detect=HKLM\Software\SCS Software +Default=False +FileKey1=%Documents%\My Games\FarmingSimulator*\savegame*|*.*|REMOVESELF +ExcludeKey1=PATH|%Documents%\My Games\FarmingSimulator*\savegame1\|*.* +ExcludeKey2=PATH|%Documents%\My Games\FarmingSimulator*\savegameBackup\|*.* + +[Fast Clean Pro *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Fastcleanpro +Default=False +FileKey1=%LocalAppData%\Fastcleanpro\logs|*.* + +[Faster Than Light *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\212680 +DetectFile=%Documents%\My Games\FasterThanLight +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\FTL Faster Than Light\crashlogs|*.* +FileKey2=%ProgramFiles%\Steam\steamapps\common\FTL Faster Than Light\crashlogs|*.* + +[FastStone Capture *] +LangSecRef=3024 +Detect=HKCU\Software\FastStone Capture +DetectFile=%AppData%\FastStone\FSC +Default=False +FileKey1=%AppData%\FastStone\FSC|*.bak;fsc.db +FileKey2=%LocalAppData%\FastStone\FSC|fsc.db +RegKey1=HKCU\Software\FastStone|_LastClipPlayed +RegKey2=HKCU\Software\FastStone|_LastRecordingFileName +RegKey3=HKCU\Software\FastStone\APP.FSRecorder\Global|_GrbId +RegKey4=HKCU\Software\FastStone\APP.FSRecorder\Global|_LastClipPlayed +RegKey5=HKCU\Software\FastStone\APP.FSRecorder\Global|_LastRecordingFileName + +[FastStone Image Viewer *] +LangSecRef=3023 +Detect=HKLM\Software\FastStone Image Viewer +Default=False +FileKey1=%AppData%\FastStone\FSIV|FSViewer.db + +[FatBatt *] +LangSecRef=3024 +Detect=HKCU\Software\MiserWare, Inc.\FatBatt +Default=False +FileKey1=%CommonAppData%\MiserWare\FatBatt\logs|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\MiserWare\FatBatt\logs|*.log + +[Feedback Hub *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalCache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalState\DiagOutputDir|*.txt +FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\TempState|*.*|RECURSE + +[Feeds Cache *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Feeds +Default=False +FileKey1=%LocalAppData%\Microsoft\Feeds Cache|*.*|RECURSE + +[FEZ *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\224760 +Default=False +FileKey1=%AppData%\FEZ|Debug Log.txt + +[FFsplit *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\FFsplit +Default=False +FileKey1=%AppData%\FFsplit|FFsourceLog.txt +FileKey2=%AppData%\FFsplit\logs|*.* + +[FIGHTERStools *] +LangSecRef=3024 +Detect=HKCU\Software\Fighters +Default=False +FileKey1=%AppData%\Fighters\*\Logs|*.log;*log.txt +FileKey2=%CommonAppData%\Common Toolkit Suite\Tools\Logs|*.log +FileKey3=%CommonAppData%\Fighters\*\Logs|*.log +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Common Toolkit Suite\Tools\Logs|*.log +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Fighters\*\Logs|*.log + +[File Shredder *] +LangSecRef=3024 +Detect=HKCU\Software\Shredder +Default=False +RegKey1=HKCU\Software\Shredder\{FF14D9EE-48EB-4873-80AC-8E224BEE5823} + +[File Transfer Manager *] +LangSecRef=3025 +DetectFile=%AppData%\Microsoft\File Transfer Manager +Default=False +FileKey1=%AppData%\Microsoft\File Transfer Manager|*.bak + +[File Type Doctor Last Selected *] +LangSecRef=3024 +Detect=HKCU\Software\Creative Element\File Type Doctor +Default=False +RegKey1=HKCU\Software\Creative Element\File Type Doctor|LastSelected + +[FileCleaner *] +LangSecRef=3024 +Detect=HKCU\Software\WebMinds, Inc\FileCleaner +Default=False +FileKey1=%AppData%\FileCleaner|log.txt + +[FileHippo Update Checker *] +LangSecRef=3024 +Detect=HKCU\Software\Filehippo.com\Update Checker +Default=False +FileKey1=%Documents%\My Filehippo Downloads|*.*|RECURSE + +[FileLocator Pro *] +LangSecRef=3024 +Detect=HKCU\Software\Mythicsoft\FileLocatorPro +Default=False +RegKey1=HKCU\Software\Mythicsoft\FileLocatorPro\RecentContains +RegKey2=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFileName +RegKey3=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFolders + +[FileManager *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\FileManager_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\FileManager_*\LocalState|*.jpg + +[FileMind QuickFix *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{92789900-80D0-4B61-B742-7897964A69AB}_is1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Metability Software\FileMindQuickFix|*.log|RECURSE +FileKey2=%ProgramFiles%\Metability Software\FileMindQuickFix|*.log|RECURSE + +[FileZilla *] +LangSecRef=3022 +Detect=HKLM\Software\FileZilla Client +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\FileZilla FTP Client|*.tmp +FileKey2=%ProgramFiles%\FileZilla FTP Client|*.tmp + +[FilmOn *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\FilmOnLiveTVFree.FilmOnLiveTVFree_zx03kxexxb716 +DetectFile=%LocalAppData%\Packages\FilmOnLiveTVFree.FilmOnLiveTVFree_zx03kxexxb716 +Default=False +FileKey1=%LocalAppData%\Packages\FilmOnLiveTVFree.FilmOnLiveTVFree_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\FilmOnLiveTVFree.FilmOnLiveTVFree_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\FilmOnLiveTVFree.FilmOnLiveTVFree_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey4=%LocalAppData%\Packages\FilmOnLiveTVFree.FilmOnLiveTVFree_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\FilmOnLiveTVFree.FilmOnLiveTVFree_zx03kxexxb716\SearchHistory + +[Firebird Project *] +LangSecRef=3023 +Detect=HKLM\Software\Firebird Project +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Firebird\Firebird_2_1|*.log +FileKey2=%ProgramFiles%\Firebird\Firebird_2_1|*.log + +[Fishdom: H2O *] +Section=Games +DetectFile=%AppData%\Playrix Entertainment\Fishdom H2O Final +Default=False +FileKey1=%AppData%\Playrix Entertainment\Fishdom H2O Final|log.html + +[FixCleaner *] +LangSecRef=3024 +DetectFile=%AppData%\FixCleaner +Default=False +FileKey1=%AppData%\FixCleaner\Logs|*.* + +[Flash Media Encoder *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\Adobe\Flash Media Live Encoder * +Default=False +FileKey1=%Video%|fmle*.log + +[FlashFXP *] +LangSecRef=3022 +Detect=HKLM\Software\FlashFXP +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\FlashFXP|quick.dat +FileKey2=%ProgramFiles%\FlashFXP|quick.dat + +[FlashGet *] +LangSecRef=3022 +Detect=HKCU\Software\JetCar +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\FlashGet|Default.bk*;Default.jcd.bak +FileKey2=%ProgramFiles%\FlashGet|Default.bk*;Default.jcd.bak +RegKey1=HKCU\Software\JetCar\JetCar|Recent File List + +[FLEXnet *] +LangSecRef=3021 +Detect=HKCU\Software\FlexNet +Default=False +FileKey1=%CommonAppData%\FLEXnet|*.data_backup.*;*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\FLEXnet|*.data_backup.*;*.log + +[FMV Extractor *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\FMV-Extractor +Default=False +Warning=This will delete all your extracted video files. +FileKey1=%LocalAppData%\VirtualStore\Program Files*\FMV-Extractor\Clip|*.*|RECURSE +FileKey2=%ProgramFiles%\FMV-Extractor\Clip|*.*|RECURSE + +[FolderShare *] +LangSecRef=3022 +DetectFile=%LocalAppData%\FolderShare +Default=False +FileKey1=%LocalAppData%\FolderShare\Logs|*.* + +[FontCache *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Windows +Default=False +FileKey1=%WinDir%\ServiceProfiles\LocalService\AppData\Local\FontCache|~*.dat + +[Foobar2000 *] +LangSecRef=3023 +Detect=HKLM\Software\foobar2000 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\foobar2000|failure.txt +FileKey2=%ProgramFiles%\foobar2000|failure.txt + +[Ford Sync My iTunes *] +LangSecRef=3023 +DetectFile=%AppData%\Ford Motor Company +Default=False +FileKey1=%AppData%\Ford Motor Company\logs|*.* + +[ForgetBox Cache *] +LangSecRef=3022 +Detect=HKCU\Software\ForgetBox SAS +Default=False +FileKey1=%AppData%\ForgetBox\cache|*.*|RECURSE + +[Format Factory *] +LangSecRef=3023 +Detect=HKCU\Software\FreeTime\FormatFactory +Default=False +Warning=This will delete the contents of your output folder. All your converted files will be deleted. +FileKey1=%Documents%\FFOutput|*.*|RECURSE +FileKey2=%SystemDrive%\FFOutput|*.*|RECURSE + +[Forte Agent *] +LangSecRef=3025 +Detect=HKLM\Software\Forte +Default=False +FileKey1=%AppData%\Forte\Agent|errorlog.xml;*.log|RECURSE +FileKey2=%SystemDrive%\My Data\ForteAgent|*.bak;*.log + +[Fortnite *] +Section=Games +DetectFile=%LocalAppData%\FortniteGame +Default=False +FileKey1=%LocalAppData%\FortniteGame\Saved\Crashes|*.*|REMOVESELF +FileKey2=%LocalAppData%\FortniteGame\Saved\Demos|UnsavedReplay*.replay|REMOVESELF +FileKey3=%LocalAppData%\FortniteGame\Saved\Logs|*.*|REMOVESELF + +[Fortnite Cache *] +Section=Games +DetectFile=%LocalAppData%\FortniteGame +Default=False +FileKey1=%LocalAppData%\FortniteGame\Saved\webcache|*.*|REMOVESELF + +[Forward Observer *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\AAForwardObserver\AAForwardObserver.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\AAForwardObserver|FO.log +FileKey2=%ProgramFiles%\AAForwardObserver|FO.log + +[Foxit PhantomPDF *] +LangSecRef=3021 +Detect1=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0 +Detect2=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0 +Detect3=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0 +Detect4=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0 +Default=False +FileKey1=%AppData%\Foxit Software\Foxit PDF Creator\Creator-Log|*.*|RECURSE +FileKey2=%AppData%\Foxit Software\Foxit PhantomPDF\FormFiller|AutoComplete.ds +FileKey3=%AppData%\Foxit Software\RMS|FXRMS_Log.txt +FileKey4=%LocalAppData%\Foxit PhantomPDF\msilog|*.log +FileKey5=%WinDir%\System32\config\systemprofile\AppData\Roaming\Foxit Software\Foxit PDF Creator|*__foxittemp.xml|RECURSE +RegKey1=HKCU\Software\Foxit Software Company\Foxit PDF Editor|Recent File List +RegKey2=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0\Preferences\History +RegKey3=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0\RecentFiles +RegKey4=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\MRU\File MRU +RegKey5=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\MRU\Place MRU +RegKey6=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\plugins\JSPlugins +RegKey7=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\Preferences\History +RegKey8=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\Recent File List +RegKey9=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\CommentPanel\Filter +RegKey10=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Foxit PhantomPDF Advanced Editor\Recent File List +RegKey11=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\MRU\File MRU +RegKey12=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\MRU\Place MRU +RegKey13=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\plugins\JSPlugins +RegKey14=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Preferences\History +RegKey15=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Recent File List +RegKey16=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\CommentPanel\Filter +RegKey17=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\Foxit PhantomPDF Advanced Editor\Recent File List +RegKey18=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\MRU\File MRU +RegKey19=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\MRU\Place MRU +RegKey20=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\plugins\JSPlugins +RegKey21=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\Preferences\History +RegKey22=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\Recent File List + +[Foxit Reader 6.0 *] +LangSecRef=3021 +Detect=HKCU\Software\Foxit Software\Foxit Reader 6.0 +Default=False +FileKey1=%AppData%\Foxit Software\Foxit Reader\StartPage\Start|history.txt +FileKey2=%LocalAppData%\Foxit Reader|*.TXT;*.zip;*.reg +RegKey1=HKCU\Software\Foxit Software\Foxit Reader 6.0\Preferences\History\Options + +[Fractal: Make Blooms Not War *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\61310 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\Fractal\fractal_data|output_log.txt +FileKey2=%ProgramFiles%\Steam\Steamapps\common\Fractal\fractal_data|output_log.txt + +[Fre:ac *] +LangSecRef=3024 +DetectFile=%AppData%\freac +Default=False +FileKey1=%AppData%\Freac\cddb|*.*|REMOVESELF + +[Free Download Manager *] +LangSecRef=3022 +Detect=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager +Default=False +FileKey1=%AppData%\Free Download Manager|downloads.del.sav + +[Free PDF XP *] +LangSecRef=3024 +Detect=HKCU\Software\shbox\FreePdfXP +Default=False +FileKey1=%SystemDrive%|IfpRedmon.log + +[Free Registry Defrag *] +LangSecRef=3024 +Detect=HKCU\Software\Local AppWizard-Generated Applications\RegDefrag +Default=False +FileKey1=%WinDir%\$regcmp$|*.* + +[FreeCommander XE *] +LangSecRef=3021 +DetectFile=%LocalAppData%\FreeCommanderXE +Default=False +FileKey1=%LocalAppData%\FreeCommanderXE\Settings\Bkp_Settings_*|*.*|REMOVESELF +FileKey2=%ProgramFiles%\FreeCommander XE\backup|*.*|REMOVESELF + +[FreeFixer *] +LangSecRef=3024 +DetectFile=%LocalAppData%\FreeFixer +Default=False +FileKey1=%LocalAppData%\FreeFixer|itemtracking.txt +FileKey2=%LocalAppData%\FreeFixer\icons|*.ico|RECURSE +FileKey3=%LocalAppData%\FreeFixer\logs|*.*|RECURSE + +[Freemake Video Downloader *] +LangSecRef=3022 +Detect=HKCU\Software\Freemake\FreemakeVideoDownloader +Default=False +FileKey1=%Documents%\Freemake\FreemakeVideoDownloader|fvd.bin +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Freemake|*.txt +FileKey3=%ProgramFiles%\Freemake|*.txt + +[FrostWire *] +LangSecRef=3022 +Detect=HKLM\Software\FrostWire +Default=False +FileKey1=%AppData%\FrostWire\.AppSpecialShare|*.*|RECURSE +FileKey2=%AppData%\FrostWire\azureus|*.*|RECURSE +FileKey3=%Documents%\FrostWire\Incomplete|*.*|RECURSE + +[Frozen Synapse *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\98200 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\Frozen Synapse|*.log +FileKey2=%ProgramFiles%\Steam\Steamapps\common\Frozen Synapse|*.log + +[Full Bore *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\105430 +Default=False +FileKey1=%Documents%\Full Bore|log.txt + +[Full Tilt Poker *] +Section=Games +DetectFile=%ProgramFiles%\Full Tilt Poker.net +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Full Tilt Poker.net\Cache|*.* +FileKey2=%ProgramFiles%\Full Tilt Poker.net\Cache|*.* + +[G-Data *] +LangSecRef=3023 +Detect=HKCU\Software\G Data +Default=False +FileKey1=%CommonAppData%\G Data\AVK\Log|*.*|RECURSE +FileKey2=%CommonProgramFiles%\G Data\AVKScanP\G Data|*.log;*old +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Common Files\G Data\AVKScanP\G Data|*.log;*old +FileKey4=%LocalAppData%\VirtualStore\Program Files*\G Data\AntiVirus\AVK\UpdatePGM|*.log +FileKey5=%LocalAppData%\VirtualStore\ProgramData\G Data\AVK\Log|*.*|RECURSE +FileKey6=%ProgramFiles%\G Data\AntiVirus\AVK\UpdatePGM|*.log + +[Gadu-Gadu *] +LangSecRef=3022 +Detect=HKCU\Software\Gadu-Gadu +Default=False +FileKey1=%WinDir%|TEMP*.htm* + +[Gajim *] +LangSecRef=3022 +DetectFile=%AppData%\Gajim +Default=False +FileKey1=%AppData%\Gajim|cache.db;Logs.db;gajim.log +FileKey2=%AppData%\Gajim\Avatars|*.* + +[Galaxy *] +Section=Games +Detect=HKCU\Software\GOG.com\Galaxy +Default=False +FileKey1=%CommonAppData%\GOG.com\Galaxy\logs|*.log +FileKey2=%CommonAppData%\GOG.com\Galaxy\temp\desktop-galaxy-updater|*.*|REMOVESELF +FileKey3=%LocalAppData%\VirtualStore\ProgramData*\GOG.com\Galaxy\logs|*.log +FileKey4=%LocalAppData%\VirtualStore\ProgramData*\GOG.com\Galaxy\temp\desktop-galaxy-updater|*.*|REMOVESELF + +[Galaxy Cache *] +Section=Games +Detect=HKCU\Software\GOG.com\Galaxy +Default=False +FileKey1=%CommonAppData%\GOG.com\Galaxy\webcache|*.*|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\ProgramData*\GOG.com\Galaxy\webcache|*.*|REMOVESELF + +[Game Maker *] +LangSecRef=3021 +Detect1=HKCU\Software\Game Maker 4 +Detect2=HKCU\Software\Game Maker\Version 5 +Detect3=HKCU\Software\Game Maker\Version 6 +Detect4=HKCU\Software\Game Maker\Version 7 +Detect5=HKCU\Software\Game Maker\Version 8 +Default=False +RegKey1=HKCU\Software\Game Maker 4\Preferences|GameDir +RegKey2=HKCU\Software\Game Maker 4\Preferences|Recent0 +RegKey3=HKCU\Software\Game Maker 4\Preferences|Recent1 +RegKey4=HKCU\Software\Game Maker 4\Preferences|Recent2 +RegKey5=HKCU\Software\Game Maker 4\Preferences|Recent3 +RegKey6=HKCU\Software\Game Maker\Version 5\Preferences|GameDir +RegKey7=HKCU\Software\Game Maker\Version 5\Preferences|Recent0 +RegKey8=HKCU\Software\Game Maker\Version 5\Preferences|Recent1 +RegKey9=HKCU\Software\Game Maker\Version 5\Preferences|Recent2 +RegKey10=HKCU\Software\Game Maker\Version 5\Preferences|Recent3 +RegKey11=HKCU\Software\Game Maker\Version 5\Preferences|Recent4 +RegKey12=HKCU\Software\Game Maker\Version 5\Preferences|Recent5 +RegKey13=HKCU\Software\Game Maker\Version 5\Preferences|Recent6 +RegKey14=HKCU\Software\Game Maker\Version 5\Preferences|Recent7 +RegKey15=HKCU\Software\Game Maker\Version 6\Preferences|GameDir +RegKey16=HKCU\Software\Game Maker\Version 6\Preferences|Recent0 +RegKey17=HKCU\Software\Game Maker\Version 6\Preferences|Recent1 +RegKey18=HKCU\Software\Game Maker\Version 6\Preferences|Recent2 +RegKey19=HKCU\Software\Game Maker\Version 6\Preferences|Recent3 +RegKey20=HKCU\Software\Game Maker\Version 6\Preferences|Recent4 +RegKey21=HKCU\Software\Game Maker\Version 6\Preferences|Recent5 +RegKey22=HKCU\Software\Game Maker\Version 6\Preferences|Recent6 +RegKey23=HKCU\Software\Game Maker\Version 6\Preferences|Recent7 +RegKey24=HKCU\Software\Game Maker\Version 7\Preferences|GameDir +RegKey25=HKCU\Software\Game Maker\Version 7\Preferences|Recent0 +RegKey26=HKCU\Software\Game Maker\Version 7\Preferences|Recent1 +RegKey27=HKCU\Software\Game Maker\Version 7\Preferences|Recent2 +RegKey28=HKCU\Software\Game Maker\Version 7\Preferences|Recent3 +RegKey29=HKCU\Software\Game Maker\Version 7\Preferences|Recent4 +RegKey30=HKCU\Software\Game Maker\Version 7\Preferences|Recent5 +RegKey31=HKCU\Software\Game Maker\Version 7\Preferences|Recent6 +RegKey32=HKCU\Software\Game Maker\Version 7\Preferences|Recent7 +RegKey33=HKCU\Software\Game Maker\Version 8\Preferences|GameDir +RegKey34=HKCU\Software\Game Maker\Version 8\Preferences|Recent0 +RegKey35=HKCU\Software\Game Maker\Version 8\Preferences|Recent1 +RegKey36=HKCU\Software\Game Maker\Version 8\Preferences|Recent2 +RegKey37=HKCU\Software\Game Maker\Version 8\Preferences|Recent3 +RegKey38=HKCU\Software\Game Maker\Version 8\Preferences|Recent4 +RegKey39=HKCU\Software\Game Maker\Version 8\Preferences|Recent5 +RegKey40=HKCU\Software\Game Maker\Version 8\Preferences|Recent6 +RegKey41=HKCU\Software\Game Maker\Version 8\Preferences|Recent7 + +[Games For Windows *] +Section=Games +DetectFile=%LocalAppData%\Microsoft\GFWLive +Default=False +FileKey1=%CommonAppData%\Microsoft\GFWLive\Install\Logs|*.log +FileKey2=%LocalAppData%\Microsoft\GFWLive|*.log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Microsoft\GFWLive\Install\Logs|*.log +FileKey4=%ProgramFiles%\Microsoft Games for Windows - LIVE\Client|dotNetFx40_Client_setup.exe + +[Games for Windows Live Installers *] +Section=Games +Detect1=HKCR\Installer\Products\81024F76746FC3D4EB268FBCF42ECF5D +Detect2=HKCR\Installer\Products\3128052F989958E40A8727EB849371FE +Default=False +FileKey1=%ProgramFiles%\Microsoft Games for Windows - LIVE\Redist|*.*|RECURSE + +[GameSave Manager *] +LangSecRef=3021 +Detect1=HKCR\GSM_gsba +Detect2=HKCR\GSM_gsdu +Detect3=HKCR\GSM_gsms +Default=False +FileKey1=%AppData%\GameSave Manager*\*Cache*|*.* +FileKey2=%AppData%\GameSave Manager*\TaskLogs|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\GameSave Manager*\settings|*.log;ScanResults.txt|RECURSE +FileKey4=%ProgramFiles%\GameSave Manager*\settings|*.log;ScanResults.txt|RECURSE + +[Gardens Inc. 2 - The Road to Fame *] +Section=Games +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{BBB8E5A9-EE43-491D-9A2D-84172C3C9384}_is1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\*\Gardens Inc. 2*|*.html;*.nfo;*.txt|RECURSE +FileKey2=%ProgramFiles%\*\Gardens Inc. 2*|*.ico;*.html;*msi;*.nfo;*.txt;*.url|RECURSE + +[Gardenscapes *] +Section=Games +DetectFile=%AppData%\Playrix Entertainment\Gardenscapes +Default=False +FileKey1=%AppData%\Playrix Entertainment\Gardenscapes|log.html + +[Garena Messenger *] +Section=Games +Detect=HKCU\Software\Garena\im +DetectFile=%ProgramFiles%\Garena Plus\GarenaMessenger.exe +Default=False +FileKey1=%CommonAppData%\GarenaMessenger|im.log;im.log.* +FileKey2=%CommonAppData%\GarenaMessenger\cache\clan|*.*|RECURSE +FileKey3=%CommonAppData%\GarenaMessenger\cache\customAvatar\buddy|*.* +FileKey4=%CommonAppData%\GarenaMessenger\cache\emoticon|*.* +FileKey5=%CommonAppData%\GarenaMessenger\cache\screencapture|*.* +FileKey6=%CommonAppData%\GarenaMessenger\garena.game.plugins|*.tmp +FileKey7=%CommonAppData%\GarenaMessenger\update*|*.*|RECURSE +FileKey8=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger|im.log;im.log.* +FileKey9=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\cache\clan|*.*|RECURSE +FileKey10=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\cache\customAvatar\buddy|*.* +FileKey11=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\cache\emoticon|*.* +FileKey12=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\cache\screencapture|*.* +FileKey13=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\garena.game.plugins|*.tmp +FileKey14=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\update*|*.*|RECURSE + +[Garmin Express *] +LangSecRef=3024 +Detect=HKCU\Software\Garmin\Express +Default=False +FileKey1=%CommonAppData%\Garmin\Logs|*.log;*.txt|RECURSE +FileKey2=%Documents%\Garmin\Backups\*|*.*|RECURSE + +[GARMIN MapSource *] +LangSecRef=3024 +Detect=HKCU\Software\Garmin\MapSource +Default=False +FileKey1=%AppData%\GARMIN\MapSource\TileCache|*.*|REMOVESELF + +[GasBuddy *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\45351D82.GasBuddy-FindCheapGasPrices_932xwky9axss4 +DetectFile=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_932xwky9axss4 +Default=False +FileKey1=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\PRICache|*.* +FileKey4=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\Temp|*.* +FileKey5=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\TempState|*.*|RECURSE + +[gBurner *] +LangSecRef=3021 +Detect=HKCU\Software\gBurner +Default=False +RegKey1=HKCU\Software\gBurner|Reopen0 +RegKey2=HKCU\Software\gBurner|Reopen1 +RegKey3=HKCU\Software\gBurner|Reopen2 +RegKey4=HKCU\Software\gBurner|Reopen3 + +[GEAR DIFx Installers *] +LangSecRef=3024 +Detect1=HKCR\Installer\Products\CACFC38969C58104B8CE6D8561446C45 +Detect2=HKLM\Software\GEAR Software\DIFx +Detect3=HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EC13FCAF38E85F44B0F1137C7FB5037 +Default=False +FileKey1=%AppData%\34BE82C4-E596-4e99-A191-52C6199EBF69|*.*|REMOVESELF +FileKey2=%AppData%\188F1432-103A-4ffb-80F1-36B633C5C9E1|*.*|REMOVESELF +FileKey3=%AppData%\9223B3E6-70DD-4e2f-965B-DD8E02D2E20B|*.*|REMOVESELF +FileKey4=%AppData%\Downloaded Installations|*.*|REMOVESELF +FileKey5=%CommonAppData%\{755AC846-7372-4AC8-8550-C52491DAA8BD}|*.*|REMOVESELF +FileKey6=%CommonAppData%\34BE82C4-E596-4e99-A191-52C6199EBF69|*.*|REMOVESELF +FileKey7=%CommonAppData%\188F1432-103A-4ffb-80F1-36B633C5C9E1|*.*|REMOVESELF +FileKey8=%CommonAppData%\9223B3E6-70DD-4e2f-965B-DD8E02D2E20B|*.*|REMOVESELF +FileKey9=%CommonAppData%\9727E41D-AD6A-47cd-B9BC-CF630B6013FD|*.*|REMOVESELF +FileKey10=%CommonAppData%\A73B37F8-7A4D-41f4-98A8-7F608CE8B98F|*.*|REMOVESELF +FileKey11=%CommonAppData%\E1864A66-75E3-486a-BD95-D1B7D99A84A7|*.*|REMOVESELF +FileKey12=%LocalAppData%\Downloaded Installations|*.*|REMOVESELF +FileKey13=%ProgramFiles%\34BE82C4-E596-4e99-A191-52C6199EBF69|*.*|REMOVESELF +FileKey14=%ProgramFiles%\38FDB89C-1EBD-4366-84B2-336D12CC3209|*.*|REMOVESELF +FileKey15=%ProgramFiles%\93E26451-CD9A-43A5-A2FA-C42392EA4001|*.*|REMOVESELF +FileKey16=%ProgramFiles%\188F1432-103A-4ffb-80F1-36B633C5C9E1|*.*|REMOVESELF +FileKey17=%ProgramFiles%\9223B3E6-70DD-4e2f-965B-DD8E02D2E20B|*.*|REMOVESELF +FileKey18=%ProgramFiles%\9727E41D-AD6A-47cd-B9BC-CF630B6013FD|*.*|REMOVESELF + +[Geek Unistaller *] +LangSecRef=3024 +Detect=HKCU\Software\Geek Uninstaller +Default=False +FileKey1=%AppData%\Geek Uninstaller|*.log;*cache.dat + +[GeekSquad *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Geek Squad +Default=False +FileKey1=%CommonAppData%\Geek Squad\MRI|EventLog.gsl|RECURSE +FileKey2=%CommonAppData%\Geek Squad\MRI\Automation Reports|*.*|REMOVESELF +FileKey3=%CommonAppData%\Geek Squad\MRI\Downloads|*.*|REMOVESELF +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Geek Squad\MRI|EventLog.gsl|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Geek Squad\MRI\Automation Reports|*.*|REMOVESELF +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Geek Squad\MRI\Downloads|*.*|REMOVESELF + +[Genie-Soft *] +LangSecRef=3024 +Detect=HKCU\Software\Genie-Soft +Default=False +FileKey1=%AppData%\Genie-soft\*\logs|*.* + +[Genieo *] +LangSecRef=3022 +DetectFile=%AppData%\Genieo +Default=False +FileKey1=%AppData%\Genieo\log|*.*|RECURSE +FileKey2=%AppData%\Genieo\sp_cache|*.*|RECURSE +FileKey3=%AppData%\Genieo\tmp|*.*|RECURSE + +[Genymobile *] +LangSecRef=3024 +Detect=HKCU\Software\Genymobile +Default=False +FileKey1=%LocalAppData%\Genymobile|*.log +FileKey2=%UserProfile%\VirtualBox VMs\*|genymotion-player*.log;logcat*.txt + +[Get Started *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Getstarted_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\Temp|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalCache|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalState\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.Getstarted_*\TempState|*.*|RECURSE + +[GetDiz Recent Files List *] +LangSecRef=3021 +Detect=HKCU\Software\Outertech\GetDiz +Default=False +RegKey1=HKCU\Software\Outertech\GetDiz|Recent Files_1 +RegKey2=HKCU\Software\Outertech\GetDiz|Recent Files_2 +RegKey3=HKCU\Software\Outertech\GetDiz|Recent Files_3 +RegKey4=HKCU\Software\Outertech\GetDiz|Recent Files_4 +RegKey5=HKCU\Software\Outertech\GetDiz|Recent Files_5 +RegKey6=HKCU\Software\Outertech\GetDiz|Recent Files_6 +RegKey7=HKCU\Software\Outertech\GetDiz|Recent Files_7 +RegKey8=HKCU\Software\Outertech\GetDiz|Recent Files_8 +RegKey9=HKCU\Software\Outertech\GetDiz|Recent Files_9 +RegKey10=HKCU\Software\Outertech\GetDiz|Recent Files_10 + +[GetFLV *] +LangSecRef=3023 +Detect=HKCU\Software\getflv +Default=False +RegKey1=HKCU\Software\GetFLV|DownloadDir +RegKey2=HKCU\Software\getflv|FLVTitle +RegKey3=HKCU\Software\GetFLV|FLVURL + +[GetRight *] +LangSecRef=3022 +Detect=HKCU\Software\Headlight\GetRight +Default=False +FileKey1=%AppData%\GetRight|GetRight.lst +RegKey1=HKCU\Software\Headlight\GetRight\FileQueue +RegKey2=HKCU\Software\Headlight\GetRight\ResumeServers +RegKey3=HKCU\Software\Headlight\GetRight\Stats +RegKey4=HKCU\Software\Headlight\GetRight\UserAgent + +[GetRightToGo *] +LangSecRef=3022 +Detect=HKCU\Software\Headlight\GetRightToGo +Default=False +FileKey1=%AppData%\GetRightToGo|*.data|RECURSE + +[Getting Over It with Bennett Foddy *] +Section=Games +Detect=HKCU\Software\steam\apps\266490 +Default=False +FileKey1=%LocalLowAppData%\Bennett Foddy\Getting Over It|output_log.txt +FileKey2=%LocalLowAppData%\Bennett Foddy\Getting Over It\Crashes|*.* + +[Ghostbuster *] +LangSecRef=3021 +DetectFile=%AppData%\Ghostbuster +Default=False +FileKey1=%AppData%\Ghostbuster|*.*|REMOVESELF + +[GhostMouse *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\GhostMouse +Default=False +FileKey1=%Documents%\AutomaticSolution Software\GhostMouse\conf\temp|*.tmp + +[GIANT AntiSpyware *] +LangSecRef=3021 +Detect=HKCU\Software\GIANTCompany\AntiSpyware +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\GIANT Company Software\GIANT AntiSpyware|errors.log;cleaner.log;tracksEraser.log +FileKey2=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|errors.log;cleaner.log;tracksEraser.log + +[Gigantic *] +Section=Games +DetectFile=%Documents%\My Games\Gigantic +Default=False +FileKey1=%Documents%\My Games\Gigantic\RxGame\Logs|*.log;*.dmg|RECURSE + +[GigaTribe *] +LangSecRef=3022 +Detect=HKCU\Software\ShalSoft\GigaTribe +Default=False +FileKey1=%LocalAppData%\Shalsoft\Gigatribe\*\re*sources|*.*|RECURSE + +[GIMP *] +LangSecRef=3021 +DetectFile1=%UserProfile%\.gimp-2.2\gimprc +DetectFile2=%UserProfile%\.gimp-2.8 +Default=False +FileKey1=%LocalAppData%|recently-used.xbel +FileKey2=%LocalAppData%\webkit|*.*|REMOVESELF +FileKey3=%UserProfile%\.gimp-2.2|documents + +[Ginger *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Ginger +Default=False +FileKey1=%Documents%\Add-in Express|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ginger|*.log;*.tmp|RECURSE +FileKey3=%ProgramFiles%\Ginger|*.log;*.tmp|RECURSE +FileKey4=%SystemDrive%|GingerSetup.log + +[GitHub *] +LangSecRef=3022 +DetectFile=%LocalAppData%\GitHub +Default=False +FileKey1=%LocalAppData%\GitHub|thelog.txt;*.log;git-log.txt;git-reflog.txt;git-shortlog.txt|RECURSE + +[GitHub Desktop *] +LangSecRef=3022 +Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\GitHubDesktop +Default=False +FileKey1=%AppData%\GitHubDesktop\*Cache|*.*|REMOVESELF +FileKey2=%AppData%\GitHubDesktop\logs|*.*|REMOVESELF +FileKey3=%LocalAppData%\GitHubDesktop|*.log +FileKey4=%LocalAppData%\GitHubDesktop\packages\SquirrelTemp|*.*|REMOVESELF +FileKey5=%LocalAppData%\SquirrelTemp|*.*|REMOVESELF + +[GMG Capsule *] +Section=Games +DetectFile=%LocalAppData%\Green Man Gaming\Capsule +Default=False +FileKey1=%LocalAppData%\Green Man Gaming\Capsule\Logfiles|*.* + +[GMote *] +LangSecRef=3024 +DetectFile=%AppData%\Gmote +Default=False +FileKey1=%AppData%\Gmote|*.log + +[GNU Cache *] +LangSecRef=3021 +Detect=HKCU\Software\GNU +Default=False +FileKey1=%LocalAppData%\GNU\Cache\*|*.*|RECURSE +FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Gnu\Cache|*.*|RECURSE +FileKey3=%WinDir%\System32\config\systemprofile\local settings\application data\gnu\cache|*.*|RECURSE +FileKey4=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\GNU\Cache|*.*|RECURSE + +[GnuCash *] +LangSecRef=3021 +Detect=HKCU\Software\GSettings\org\gnucash +Default=False +Warning=This removes the last open history, auto saves and logs. +FileKey1=%UserProfile%\*|*.gnucash.*.log;*.gnucash.*.gnucash;translog.*.log|RECURSE +RegKey1=HKCU\Software\GSettings\org\gnucash\history + +[Go!Zilla *] +LangSecRef=3022 +Detect=HKCU\Software\Go!Zilla +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Go!Zilla|golog.htm;download.log;leech.hst +FileKey2=%ProgramFiles%\Go!Zilla|golog.htm;download.log;leech.hst + +[Goalscape *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\GoalScape +Default=False +FileKey1=%AppData%\com.goalscape.app.*\Logging|*.*|RECURSE + +[Goat Simulator *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\265930 +Default=False +FileKey1=%Documents%\my games\GoatSim\GoatGame\Logs|*.* + +[Gom Player *] +LangSecRef=3023 +Detect=HKCU\Software\GRETECH\GomPlayer +Default=False +FileKey1=%AppData%\GRETECH\GomPlayer|*.bmk +RegKey1=HKCU\Software\GRETECH\GomPlayer\OPTION|sRecentPLFolder + +[GoodSync *] +LangSecRef=3024 +Detect=HKCU\Software\Siber Systems\GoodSync +Default=False +FileKey1=%AppData%\GoodSync|*.log|RECURSE +FileKey2=%Documents%\_gsdata_|*.log|RECURSE + +[Google Apps Sync *] +LangSecRef=3022 +DetectFile=%LocalAppData%\Google\Google Apps * +Default=False +FileKey1=%LocalAppData%\Google\Google Apps *|*.log|RECURSE + +[Google Calendar Sync *] +LangSecRef=3022 +DetectFile=%LocalAppData%\Google\Google Calendar Sync +Default=False +FileKey1=%LocalAppData%\Google\Google Calendar Sync|*.log|RECURSE + +[Google Drive *] +LangSecRef=3024 +Detect=HKCU\Software\Google\Drive +DetectFile=%ProgramFiles%\Google\Drive\googledrivesync.exe +Default=False +FileKey1=%LocalAppData%\Google\Drive|*.log +FileKey2=%LocalAppData%\Google\Drive\CrashReports|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Google\Drive|*.log +FileKey4=%ProgramFiles%\Google\Drive|*.log + +[Google Earth *] +LangSecRef=3021 +Detect1=HKCU\Software\Google\Google Earth Plus +Detect2=HKCU\Software\Google\Google Earth Pro +Detect3=HKLM\Software\Google\Google Earth Plus +Detect4=HKLM\Software\Google\Google Earth Pro +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Google\GoogleEarth\client|*.log +FileKey2=%LocalLowAppData%\Google\GoogleEarth|*.tmp;*.log|RECURSE +FileKey3=%LocalLowAppData%\Google\GoogleEarth\Cache|*.*|RECURSE +FileKey4=%LocalLowAppData%\Google\GoogleEarth\unified_cache_leveldb_*|*.*|REMOVESELF +FileKey5=%ProgramFiles%\Google\GoogleEarth\client|*.log + +[Google GBScreensaver *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Google\GBScreensaver +Default=False +FileKey1=%LocalAppData%\Google\GBScreensaver|network.log + +[Google Music Manager *] +LangSecRef=3023 +Detect=HKCU\Software\Google\MusicManager +Default=False +FileKey1=%LocalAppData%\Google\MusicManager|*.log + +[Google Picasa2Albums Backup *] +LangSecRef=3021 +Detect=HKCU\Software\Google\Picasa +Default=False +FileKey1=%LocalAppData%\Google\Picasa2Albums\backup|*.*|REMOVESELF + +[Google Talk *] +LangSecRef=3022 +Detect=HKCU\Software\Google\Google Talk +DetectFile=%LocalAppData%\Google\Google Talk Plugin +Default=False +FileKey1=%LocalAppData%\Google\Google Talk Plugin|*.log +FileKey2=%LocalAppData%\Google\Google Talk\avatars|*.* + +[Google Toolbar Notifier *] +LangSecRef=3022 +Detect=HKCU\Software\Google\GoogleToolbarNotifier +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Google\GoogleToolbarNotifier|*.tmp|RECURSE +FileKey2=%ProgramFiles%\Google\GoogleToolbarNotifier|*.tmp|RECURSE + +[Google Video Player *] +LangSecRef=3023 +Detect=HKCU\Software\Google\Google Video Player +Default=False +RegKey1=HKCU\Software\Google\Google Video Player\MRUList + +[GoPlayer *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\GoPlayer +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\GoPlayer|*.log +FileKey2=%ProgramFiles%\GoPlayer|*.log + +[Gotham City Impostors *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\206210 +Default=False +FileKey1=%Documents%\WB Games\Gotham City Impostors - Free To Play|*.log + +[Gothic III *] +Section=Games +Detect=HKCU\Software\JoWooD Productions Software AG\Gothic III +Default=False +FileKey1=%ProgramFiles%\Gothic III|setup*.txt + +[GradeKeeper *] +LangSecRef=3021 +Detect=HKCU\Software\Gradekeeper +Default=False +FileKey1=%AppData%\Gradekeeper|*.* + +[Gratuitous Space Battles *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\41800 +Default=False +FileKey1=%Documents%\My Games\GratuitousSpaceBattles\debug|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\gratuitous space battles\data\temp|*.*|RECURSE +FileKey3=%ProgramFiles%\Steam\Steamapps\common\gratuitous space battles\data\temp|*.*|RECURSE + +[Gravity Guy *] +Section=Games +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MiniclipSA.GravityGuy_gpanv85qtf6rc +DetectFile=%LocalAppData%\Packages\MiniclipSA.GravityGuy_gpanv85qtf6rc +Default=False +FileKey1=%LocalAppData%\Packages\MiniclipSA.GravityGuy_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\MiniclipSA.GravityGuy_*\AC\Microsoft\CryptnetUrlCache\*|*.* + +[Green Ranch *] +Section=Games +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Green RanchFINAL +Default=False +FileKey1=%AppData%\Palaplay\GreenRanch_Survey|*.txt + +[Greenfish Icon Editor Pro *] +LangSecRef=3021 +DetectFile=%LocalAppData%\gfie\recent.txt +Default=False +FileKey1=%LocalAppData%\gfie|recent.txt + +[Greenshot *] +LangSecRef=3024 +DetectFile=%AppData%\Greenshot +Default=False +FileKey1=%LocalAppData%\Greenshot|*.log + +[grepWin *] +LangSecRef=3024 +Detect=HKCU\Software\grepWin +Default=False +RegKey1=HKCU\Software\grepWin|searchpath +RegKey2=HKCU\Software\grepWin\History + +[GridinSoft Notepad *] +LangSecRef=3021 +Detect=HKCU\Software\GridinSoft\Notepad3 +Default=False +RegKey1=HKCU\Software\GridinSoft\Notepad3\Files +RegKey2=HKCU\Software\GridinSoft\Notepad3\Search|ReplaceTextHistory +RegKey3=HKCU\Software\GridinSoft\Notepad3\Search|TextHistory + +[Grim Tales The Wishes CE *] +Section=Games +DetectFile=%AppData%\Elephant Games\Grim Tales The Wishes CE +Default=False +FileKey1=%AppData%\Elephant Games\Grim Tales The Wishes CE|logfile.txt + +[Groove Music *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\PRICache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Temp|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalCache\PlayReady\Cache|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\Database\*|*.log +FileKey11=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageCache|*.*|RECURSE +FileKey12=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageRetrievalFailure|*.*|RECURSE +FileKey13=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageStore|*.*|RECURSE +FileKey14=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\navigationHistory|*.*|RECURSE +FileKey15=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\PlayReady|*.*|RECURSE +FileKey16=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\SearchHistory + +[GroupWise Messenger *] +LangSecRef=3021 +Detect=HKCU\Software\Novell\Messenger +Default=False +FileKey1=%LocalAppData%\Novell\GroupWise Messenger\history\%UserName%|*.* + +[Growl *] +LangSecRef=3024 +Detect=HKCU\Software\Growl +Default=False +FileKey1=%LocalAppData%\Growl\*\History|*.*|RECURSE +FileKey2=%LocalAppData%\Growl\*\ImageCache|*.*|RECURSE +FileKey3=%LocalAppData%\Growl\*\Log|*.*|RECURSE + +[GSpot *] +LangSecRef=3024 +Detect=HKCU\Software\GSpot Appliance Corp +Default=False +RegKey1=HKCU\Software\GSpot Appliance Corp\GSpot\v2.6 Settings|LastMediaFile + +[gSyncit *] +LangSecRef=3022 +DetectFile=%AppData%\gSyncit +Default=False +FileKey1=%AppData%\gSyncit|gsyncit*.* + +[GT Interactive Driver *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\GT Interactive\Driver +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\GT Interactive\Driver|debug.log +FileKey2=%ProgramFiles%\GT Interactive\Driver|debug.log + +[Guild Wars *] +Section=Games +DetectFile=%ProgramFiles%\Guild Wars +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Guild Wars|*.tmp +FileKey2=%ProgramFiles%\Guild Wars|*.tmp + +[Gwent *] +Section=Games +Detect=HKCU\Software\CDProjektRED\Gwent +Default=False +FileKey1=%CommonAppData%\CDProjekt RED\Gwent\Logs|*.log + +[Hacknet *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\365450 +Default=False +FileKey1=%Documents%\My Games\Hacknet\Reports|*.txt + +[Halite *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Halite +Default=False +FileKey1=%LocalAppData%\Halite|HaliteLog.txt|RECURSE + +[Halite Backups *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Halite +Default=False +FileKey1=%LocalAppData%\Halite|Halite.xml.*|RECURSE + +[Halo Spartan Assault *] +Section=Games +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.HaloSpartanAssault_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.HaloSpartanAssault_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.HaloSpartanAssault_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.HaloSpartanAssault_*\AC\Microsoft\CryptnetUrlCache\*|*.* + +[HandBrake *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\HandBrake\Handbrake.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\HandBrake|*.stackdump +FileKey2=%ProgramFiles%\HandBrake|*.stackdump + +[Handle Regshot Reports *] +LangSecRef=3024 +DetectFile=%SystemDrive%\Hive +Default=False +FileKey1=%SystemDrive%\Hive|*.css;*.html;*.reg + +[Handle Regshot Snapshots *] +LangSecRef=3024 +DetectFile=%SystemDrive%\Hive +Default=False +Warning=This will delete all saved snapshots. +FileKey1=%SystemDrive%\Hive|*.hive + +[Handy Backup *] +LangSecRef=3024 +Detect=HKCU\Software\Novosoft\Handy Backup +Default=False +FileKey1=%AppData%\Novosoft\Handy Backup\logs|*.* + +[HappyCloud *] +Section=Games +Detect=HKCU\Software\HappyCloud +Default=False +FileKey1=%CommonAppData%\HappyCloud|*.log +FileKey2=%CommonAppData%\HappyCloud\cache|*.* +FileKey3=%LocalAppData%\VirtualStore\ProgramData\HappyCloud|*.log +FileKey4=%LocalAppData%\VirtualStore\ProgramData\HappyCloud\cache|*.* + +[Hard Drive Inspector *] +LangSecRef=3024 +DetectFile=%CommonAppData%\AltrixSoft\Hard Drive Inspector +Default=False +FileKey1=%CommonAppData%\AltrixSoft\Hard Drive Inspector|log.err +FileKey2=%LocalAppData%\VirtualStore\ProgramData\AltrixSoft\Hard Drive Inspector|log.err + +[Hauppauge WinTV *] +LangSecRef=3024 +Detect=HKLM\Software\Hauppauge +Default=False +FileKey1=%Public%\WinTV|Settings-old.xml +FileKey2=%Public%\WinTV\Channel Database|hcwChanDB_5-lastgood.mdb +FileKey3=%Public%\WinTV\Installation Log|*.*|RECURSE +FileKey4=%Public%\WinTV\Logs|*.log;*.txt +FileKey5=%Public%\WinTV\Logs\minidump|*.*|RECURSE +FileKey6=%SystemDrive%|hcwDriverInstall.txt + +[HDD Health *] +LangSecRef=3022 +Detect=HKLM\System\CurrentControlSet\services\HDDHealth +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\HDD Health|*.tmp +FileKey2=%ProgramFiles%\HDD Health|*.tmp + +[HDD Regenerator *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\HDD Regenerator +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\HDD Regenerator|*.log|RECURSE +FileKey2=%ProgramFiles%\HDD Regenerator|*.log|RECURSE + +[HDD Thermometer *] +LangSecRef=3024 +Detect=HKCU\Software\RSD Software, Inc.\HDD Thermometer +Default=False +FileKey1=%CommonAppData%\HDD Thermometer|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\HDD Thermometer|*.log|RECURSE + +[HDDExpert *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\HDDExpert +Default=False +FileKey1=%AppData%\KC Softwares\HDDExpert|*.log + +[Hedgewars VideoTemp *] +Section=Games +Detect=HKLM\Software\Hedgewars +Default=False +FileKey1=%Documents%\Hedgewars\VideoTemp|*.* + +[Helium Music Manager *] +LangSecRef=3023 +Detect1=HKCU\Software\Intermedia Software\Helium 8 +Detect2=HKCU\Software\Intermedia Software\Helium 9 +Detect3=HKCU\Software\Intermedia Software\Helium 10 +Default=False +FileKey1=%AppData%\Intermedia Software\Helium *\Logs|*.* + +[Heroes of a Broken Land *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\314470 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Heroes of a Broken Land\hobl_data|output_log.txt +FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Heroes of a Broken Land\hobl_data|output_log.txt + +[Heroes of Newerth *] +Section=Games +Detect=HKCU\Software\Heroes of Newerth +Default=False +FileKey1=%Documents%\Heroes of Newerth\game|console.log + +[Hex Chat *] +LangSecRef=3024 +DetectFile=%AppData%\HexChat +Default=False +FileKey1=%AppData%\HexChat\logs|*.*|REMOVESELF +FileKey2=%AppData%\HexChat\scrollback|*.*|REMOVESELF + +[Hi-Rez Studios *] +Section=Games +Detect=HKLM\Software\Hi-Rez Studios +Default=False +FileKey1=%CommonAppData%\Hi-Rez Studios\BrowserCacheTribes\Default|*.*|RECURSE +FileKey2=%CommonAppData%\Hi-Rez Studios\HiPatchService\log|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Hi-Rez Studios\hireztemp|*.* +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Hi-Rez Studios\BrowserCacheTribes\Default|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Hi-Rez Studios\HiPatchService\log|*.* +FileKey6=%ProgramFiles%\Hi-Rez Studios\hireztemp|*.* +FileKey7=%SystemDrive%|HiRezUpdateInstallLog.txt + +[HijackThis Backups *] +LangSecRef=3024 +Detect=HKLM\Software\TrendMicro\HijackThis +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Trend Micro\HijackThis\backups|*.* +FileKey2=%ProgramFiles%\Trend Micro\HijackThis\backups|*.* + +[HitmanPro *] +LangSecRef=3024 +Detect1=HKCU\Software\HitMan Pro +Detect2=HKCU\Software\HitMan Pro 2 +Detect3=HKCU\Software\HitMan Pro 3 +Detect4=HKLM\Software\HitmanPro +Default=False +FileKey1=%CommonAppData%\HitmanPro\Logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Hitman Pro*\downloads|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Hitman Pro*\logs|*.htm +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Hitman Pro*\updates|*.* +FileKey5=%LocalAppData%\VirtualStore\ProgramData\HitmanPro\Logs|*.* +FileKey6=%ProgramFiles%\Hitman Pro*\downloads|*.* +FileKey7=%ProgramFiles%\Hitman Pro*\logs|*.htm +FileKey8=%ProgramFiles%\Hitman Pro*\updates|*.* + +[Holiday Express *] +Section=Games +Detect1=HKLM\Software\GameHouse\Holiday Express +Detect2=HKLM\Software\HipSoft\Holiday Express +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\GameHouse Games Collection\Holiday Express|*.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Holiday Express|*html;*.txt +FileKey3=%ProgramFiles%\GameHouse Games Collection\Holiday Express|*.txt +FileKey4=%ProgramFiles%\Holiday Express|*html;*.txt + +[HomeCinema CyberLink *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\HomeCinema +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\HomeCinema\PowerProducer\Template\Cyberlink\frame|*tmp +FileKey2=%ProgramFiles%\HomeCinema\PowerProducer\Template\Cyberlink\frame|*tmp + +[Honeyview Bookmarks *] +LangSecRef=3023 +Detect=HKCU\Software\Honeyview +Default=False +RegKey1=HKCU\Software\Honeyview\BMPath0 +RegKey2=HKCU\Software\Honeyview\BMPath1 +RegKey3=HKCU\Software\Honeyview\BMPath2 +RegKey4=HKCU\Software\Honeyview\BMPath3 +RegKey5=HKCU\Software\Honeyview\BMPath4 +RegKey6=HKCU\Software\Honeyview\BMPath5 +RegKey7=HKCU\Software\Honeyview\BMPath6 +RegKey8=HKCU\Software\Honeyview\BMPath7 +RegKey9=HKCU\Software\Honeyview\BMPath8 +RegKey10=HKCU\Software\Honeyview\BMPath9 +RegKey11=HKCU\Software\Honeyview\BMPath10 +RegKey12=HKCU\Software\Honeyview\BMPath11 +RegKey13=HKCU\Software\Honeyview\BMPath12 +RegKey14=HKCU\Software\Honeyview\BMPath13 +RegKey15=HKCU\Software\Honeyview\BMPath14 +RegKey16=HKCU\Software\Honeyview\BMPath15 +RegKey17=HKCU\Software\Honeyview\BMPath16 +RegKey18=HKCU\Software\Honeyview\BMPath17 +RegKey19=HKCU\Software\Honeyview\BMPath18 +RegKey20=HKCU\Software\Honeyview\BMPath19 +RegKey21=HKCU\Software\Honeyview\BMPath20 +RegKey22=HKCU\Software\Honeyview\BMPath21 +RegKey23=HKCU\Software\Honeyview\BMPath22 +RegKey24=HKCU\Software\Honeyview\BMPath23 +RegKey25=HKCU\Software\Honeyview\BMPath24 +RegKey26=HKCU\Software\Honeyview\BMPath25 +RegKey27=HKCU\Software\Honeyview\BMPath26 +RegKey28=HKCU\Software\Honeyview\BMPath27 +RegKey29=HKCU\Software\Honeyview\BMPath28 +RegKey30=HKCU\Software\Honeyview\BMPath29 + +[Honeyview MRU *] +LangSecRef=3023 +Detect=HKCU\Software\Honeyview +Default=False +RegKey1=HKCU\Software\Honeyview\RecentFolder0 +RegKey2=HKCU\Software\Honeyview\RecentFolder1 +RegKey3=HKCU\Software\Honeyview\RecentFolder2 +RegKey4=HKCU\Software\Honeyview\RecentFolder3 +RegKey5=HKCU\Software\Honeyview\RecentFolder4 +RegKey6=HKCU\Software\Honeyview\RecentFolder5 +RegKey7=HKCU\Software\Honeyview\RecentFolder6 +RegKey8=HKCU\Software\Honeyview\RecentFolder7 +RegKey9=HKCU\Software\Honeyview\RecentFolder8 +RegKey10=HKCU\Software\Honeyview\RecentFolder9 +RegKey11=HKCU\Software\Honeyview\sRecentFolder +RegKey12=HKCU\Software\Honeyview\sStoreFilePath +RegKey13=HKCU\Software\Honeyview\sStoreFilePath2 +RegKey14=HKCU\Software\Honeyview\transf.sTargetFolder + +[Hostile Makeover *] +Section=Games +DetectFile=%AppData%\Merscom\Hostile Makeover +Default=False +FileKey1=%AppData%\Merscom\Hostile Makeover|logfile.txt + +[HostsMan Backups *] +LangSecRef=3024 +DetectFile=%CommonAppData%\abelhadigital.com\HostsMan +Default=False +FileKey1=%Public%\Documents\HostsMan Backups|*.*|REMOVESELF +FileKey2=%WinDir%\System32\drivers\etc|HOSTS.bak;HOSTS.tmp + +[HostsMan HostsServer *] +LangSecRef=3024 +Detect=HKLM\Software\abelhadigital.com\HostsServer +DetectFile=%ProgramFiles%\HostsMan\hostssrv.exe +Default=False +FileKey1=%AppData%\abelhadigital.com\HostsServer|*.log|RECURSE +FileKey2=%LocalLowAppData%\abelhadigital.com\HostsServer\Logs|*.log + +[Hotbar *] +LangSecRef=3022 +Detect=HKCU\Software\Hotbar +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Hotbar\*\dynamic|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Hotbar\*\static|*.* +FileKey3=%ProgramFiles%\Hotbar\*\dynamic|*.*|RECURSE +FileKey4=%ProgramFiles%\Hotbar\*\static|*.* +RegKey1=HKCU\Software\Hotbar\hotbar\ImagesHistory + +[Hotline Miami *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\219150 +Default=False +FileKey1=%Documents%\My Games\HotlineMiami|debug.log + +[Hotspot Shield *] +LangSecRef=3021 +Detect=HKLM\Software\HotspotShield +DetectFile=%ProgramFiles%\Hotspot Shield\bin\HSSCP.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Hotspot Shield\log|*.log +FileKey2=%LocalLowAppData%\Hotspot_Shield\Logs|*.*|RECURSE +FileKey3=%ProgramFiles%\Hotspot Shield\log|*.log + +[Hover Desk *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\HoverDesk +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\HoverDesk\User|hdcmdrec.txt +FileKey2=%ProgramFiles%\HoverDesk\User|hdcmdrec.txt + +[HP Drive Key Boot Utility *] +LangSecRef=3024 +Detect=HKLM\Software\microsoft\windows\currentversion\uninstall\HP Drive Key Boot Utility +Default=False +FileKey1=%SystemDrive%\CPQSYSTEM|*.*|REMOVESELF + +[HP Guide *] +LangSecRef=3024 +DetectFile=%LocalAppData%\HP Guide +Default=False +FileKey1=%LocalAppData%\HP Guide|log1.* +FileKey2=%LocalAppData%\HP Guide\mp_cache|*.* + +[HP Install Temps *] +LangSecRef=3021 +Detect=HKCU\Software\HP +DetectFile=%CommonAppData%\HP +Default=False +FileKey1=%CommonAppData%\HP\Installer\Temp|*.* +FileKey2=%CommonAppData%\HP\Temp|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\HP\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\HP\Installer\Temp|*.* +FileKey5=%LocalAppData%\VirtualStore\ProgramData\HP\Temp|*.* +FileKey6=%ProgramFiles%\HP\Temp|*.*|RECURSE +FileKey7=%WinDir%|*.dat.temp + +[HP Installation Files *] +LangSecRef=3024 +DetectFile1=%SystemDrive%\HP Universal Print Driver +DetectFile2=%SystemDrive%\swsetup +Default=False +FileKey1=%SystemDrive%\HP Universal Print Driver|*.*|REMOVESELF +FileKey2=%SystemDrive%\swsetup|*.*|REMOVESELF + +[HP Logs *] +LangSecRef=3021 +Detect=HKCU\Software\HP +DetectFile1=%AppData%\hpqlog +DetectFile2=%CommonAppData%\Hewlett-Packard +DetectFile3=%CommonAppData%\HP +DetectFile4=%LocalAppData%\TouchSmartData +DetectFile5=%ProgramFiles%\HPQ\Shared\Sierra Wireless +Default=False +FileKey1=%AppData%\HP\WebRegLogs|WebRegLog.txt +FileKey2=%AppData%\hpqlog|*.log +FileKey3=%CommonAppData%|hpzinstall.log +FileKey4=%CommonAppData%\Hewlett-Packard|*.log*.*;*Log.txt|RECURSE +FileKey5=%CommonAppData%\Hewlett-Packard\HP*\Log*|*.*|RECURSE +FileKey6=%LocalAppData%\TouchSmartData\Log|*.* +FileKey7=%LocalAppData%\VirtualStore\Program Files*\HPQ\Shared\Sierra Wireless|*.log|RECURSE +FileKey8=%LocalAppData%\VirtualStore\ProgramData|hpzinstall.log +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Hewlett-Packard\HP*\Logs|*.*|RECURSE +FileKey10=%ProgramFiles%\HPQ\Shared\Sierra Wireless|*.log|RECURSE +FileKey11=%SystemDrive%\hp\bin\logs|*.log + +[HP MediaSmart Photo *] +LangSecRef=3023 +DetectFile=%LocalAppData%\Hewlett-Packard\MediaSmart\Photo +Default=False +FileKey1=%LocalAppData%\Hewlett-Packard\MediaSmart\Photo|subsys.cache +FileKey2=%LocalAppData%\Hewlett-Packard\MediaSmart\Photo\tm*Cache|*.*|REMOVESELF + +[HP Photosmart Premier *] +LangSecRef=3021 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\HP Photo & Imaging +Default=False +FileKey1=%LocalAppData%\HP\Digital Imaging\cache|*.* + +[HP Printer Control *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AD2F1837.HPPrinterControl_v10z8vjag6ke6 +DetectFile=%LocalAppData%\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6 +Default=False +FileKey1=%LocalAppData%\Packages\*HPPrinterControl_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\*HPPrinterControl_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\*HPPrinterControl_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE +FileKey4=%LocalAppData%\Packages\*HPPrinterControl_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\*HPPrinterControl_*\AC\PRICache|*.* +FileKey6=%LocalAppData%\Packages\*HPPrinterControl_*\AC\Temp|*.* +FileKey7=%LocalAppData%\Packages\*HPPrinterControl_*\LocalState|*.*|RECURSE + +[HP Scan and Capture *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AD2F1837.HPScanandCapture_v10z8vjag6ke6 +DetectFile=%LocalAppData%\Packages\AD2F1837.HPScanandCapture_v10z8vjag6ke6 +Default=False +FileKey1=%LocalAppData%\Packages\*HPScanandCapture_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\*HPScanandCapture_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\*HPScanandCapture_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE +FileKey4=%LocalAppData%\Packages\*HPScanandCapture_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\*HPScanandCapture_*\AC\PRICache|*.* +FileKey6=%LocalAppData%\Packages\*HPScanandCapture_*\AC\Temp|*.* +FileKey7=%LocalAppData%\Packages\*HPScanandCapture_*\LocalState|*.*|RECURSE + +[HP Update *] +LangSecRef=3021 +DetectFile=%AppData%\HPUpdate +Default=False +FileKey1=%AppData%\HpUpdate|*.* + +[HTC Home Apis *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\HTC Home +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\HTC Home\log|*.*|RECURSE +FileKey2=%ProgramFiles%\HTC Home\log|*.*|RECURSE + +[HTC Logs *] +LangSecRef=3022 +Detect=HKCU\Software\Microsoft\Installer\Products\34180280D77760A4BB4517FBA01DBB07\SourceList +Default=False +FileKey1=%SystemDrive%\Temp|HSM*.txt + +[HTC Sync *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\HTC\HTC Sync 3.0 +Default=False +FileKey1=%AppData%\HTC\Logs|*.log + +[HTML Help *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\HTMLHelp +Default=False +Warning=This will remove CHM position, preferences, favorites information. +FileKey1=%AppData%\Microsoft\HTML Help|hh.dat;hhcolreg.dat;*.chw +FileKey2=%CommonAppData%\Microsoft\HTML Help|hhcolreg.dat +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Microsoft\HTML Help|hhcolreg.dat +FileKey4=%WinDir%\Application Data\Microsoft\HTML Help|hh.dat + +[Huawei Modem Driver *] +LangSecRef=3023 +Detect=HKLM\Software\Huawei technologies +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\HUAWEI Modem Driver|*.log +FileKey2=%ProgramFiles%\HUAWEI Modem Driver|*.log + +[HuluDesktop *] +LangSecRef=3023 +DetectFile=%LocalAppData%\HuluDesktop +Default=False +FileKey1=%LocalAppData%\HuluDesktop\Data|*.log + +[HuluPlus *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\HuluLLC.HuluPlus_fphbd361v8tya +Default=False +FileKey1=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey3=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\Temp|*.* +FileKey4=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\LocalState|*.tmp|RECURSE +FileKey5=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\TempState|*.*|RECURSE + +[Huru Beach Party *] +Section=Games +DetectFile=%AppData%\HuruBeachParty +Default=False +FileKey1=%AppData%\HuruBeachParty|*log.html + +[HxD Hexeditor *] +LangSecRef=3021 +Detect=HKCU\Software\Mael\HxD +Default=False +RegKey1=HKCU\Software\Mael\HxD\History Lists\Recent Files + +[Hyper for Youtube *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\19120CensoredUser.HyperforYouTube_c0tqyanwsgfn6 +DetectFile=%LocalAppData%\Packages\19120CensoredUser.HyperforYouTube_c0tqyanwsgfn6 +Default=False +FileKey1=%LocalAppData%\Packages\*.HyperforYouTube_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\*.HyperforYouTube_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\*.HyperforYouTube_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey4=%LocalAppData%\Packages\*.HyperforYouTube_*\LocalState|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\*.HyperforYouTube_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\19120CensoredUser.HyperforYouTube_c0tqyanwsgfn6\SearchHistory + +[HyperSnap 7 *] +LangSecRef=3021 +Detect=HKCU\Software\Hyperionics\HyperSnap 7 +Default=False +FileKey1=%ProgramFiles%\HyperSnap 7|*.url +RegKey1=HKCU\Software\Hyperionics\HyperSnap 7\Recent File List + +[i-Funbox DevTeam *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\i-Funbox DevTeam +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\i-Funbox DevTeam|debug.log +FileKey2=%ProgramFiles%\i-Funbox DevTeam|debug.log + +[I2P NetDb *] +LangSecRef=3022 +DetectFile=%AppData%\I2P +Default=False +FileKey1=%AppData%\I2P\netDb|*.* + +[Icaros *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Icaros +Default=False +FileKey1=%LocalAppData%\Icaros\IcarosCache|*.icdb + +[Icon Cache *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +Warning=You may need to restart explorer.exe for this to take effect. +FileKey1=%LocalAppData%|IconCache.db +FileKey2=%LocalAppData%\Microsoft\Windows\Explorer|iconcache_*.db + +[Icon Explorer *] +LangSecRef=3024 +Detect=HKCU\Software\MiTeC\Icon Explorer +Default=False +RegKey1=HKCU\Software\MiTeC\Icon Explorer\4.x\wnd_icoexp_Main|de_Text +RegKey2=HKCU\Software\MiTeC\Icon Explorer\4.x\wnd_icoexp_Main|ShellTree_StartInFolder + +[IconCool Editor *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\IconCoolEditor\IconCooleditor.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\IconCoolEditor|IconFileList.src;Recentlyused.src +FileKey2=%ProgramFiles%\IconCoolEditor|IconFileList.src;Recentlyused.src + +[Icons from File *] +LangSecRef=3024 +Detect=HKCU\Software\Vitaliy Levchenko\Icons from File +Default=False +RegKey1=HKCU\Software\Vitaliy Levchenko\Icons from File\Recent + +[ID Privacy Shield *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\ID Security Suite\ID Privacy Shield +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\ID Security Suite\ID Privacy Shield\logs|*.*|RECURSE +FileKey2=%ProgramFiles%\ID Security Suite\ID Privacy Shield\logs|*.*|RECURSE + +[IDEA *] +LangSecRef=3021 +Detect1=HKCU\Software\JetBrains\IntelliJ IDEA +Detect2=HKCU\Software\JetBrains\IntelliJ IDEA Community Edition +Default=False +FileKey1=%UserProfile%\.IdeaC*\System\Caches|*.* +FileKey2=%UserProfile%\.IdeaC*\System\Logs|*.* +FileKey3=%UserProfile%\.IdeaC*\System\tmp|*.*|RECURSE +FileKey4=%UserProfile%\.IntelliJIdea12\system\Caches|*.* +FileKey5=%UserProfile%\.IntelliJIdea12\system\log|*.* +FileKey6=%UserProfile%\.IntelliJIdea12\system\tmp|*.*|RECURSE + +[IDEA History *] +LangSecRef=3021 +Detect1=HKCU\Software\JetBrains\IntelliJ IDEA +Detect2=HKCU\Software\JetBrains\IntelliJ IDEA Community Edition +Default=False +FileKey1=%UserProfile%\.IdeaC*\System\LocalHistory|*.* +FileKey2=%UserProfile%\.IntelliJIdea12\system\LocalHistory|*.* + +[IdeaSoft Scrapbooks Plus 1.0 *] +LangSecRef=3021 +Detect=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0 +Default=False +RegKey1=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0\Recent File List + +[IDLE Recent Files *] +LangSecRef=3021 +Detect=HKCU\Software\Python +Default=False +FileKey1=%UserProfile%\.idlerc|recent-files.lst + +[IDPhotoStudio *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\IDPhotoStudio +Default=False +FileKey1=%AppData%\KC Softwares\IDPhotoStudio|*.log + +[IDT NetGUI *] +LangSecRef=3022 +DetectFile=%AppData%\IDT\NetGUI +Default=False +FileKey1=%AppData%\IDT\NetGUI\Log|*.log + +[IE Toy *] +LangSecRef=3024 +Detect=HKCU\Software\MySoftware\IEToy +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\IE Toy\Data|history;history_ad +FileKey2=%ProgramFiles%\IE Toy\Data|history;history_ad +RegKey1=HKCU\Software\MySoftware\IEToy|FRAGS_ad +RegKey2=HKCU\Software\MySoftware\IEToy|FRAGS_popup + +[IE7pro *] +LangSecRef=3022 +Detect=HKCU\Software\IE7pro +Default=False +RegKey1=HKCU\Software\IE7pro\ClosedTabs + +[Ignition *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\Ignition +Default=False +FileKey1=%AppData%\KC Software\Ignition|*.log + +[IISExpress *] +LangSecRef=3022 +DetectFile=%Documents%\IISExpress +Default=False +FileKey1=%Documents%\IISExpress\Logs|*.* +FileKey2=%Documents%\IISExpress\TraceLogFiles|*.*|RECURSE + +[ImgBurn *] +LangSecRef=3021 +Detect=HKCU\Software\ImgBurn +Default=False +RegKey1=HKCU\Software\ImgBurn|ISOREAD_RecentFiles_Destination +RegKey2=HKCU\Software\ImgBurn|ISOREAD_RecentFolders_Destination + +[Immersive Control Panel *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\windows.immersivecontrolpanel_cw5n1h2txyewy +DetectFile=%LocalAppData%\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\PRICache|*.* +FileKey7=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\Temp|*.* +FileKey8=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\LocalState\Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\LocalState\navigationHistory|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\windows.immersivecontrolpanel_cw5n1h2txyewy\SearchHistory + +[Immunet *] +LangSecRef=3021 +Detect=HKLM\Software\Immunet Protect +Default=False +Warning=Immunet service must be stopped to remove log files. +FileKey1=%AppData%\Immunet|*.*|REMOVESELF +FileKey2=%CommonAppData%\Immunet|*.log +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Immunet|*.log|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Immunet|*.log +FileKey5=%ProgramFiles%\Immunet|*.log|RECURSE + +[iMobie *] +LangSecRef=3024 +DetectFile=%AppData%\iMobie +Default=False +FileKey1=%AppData%\iMobie\*|iTunesPrefs +FileKey2=%AppData%\iMobie\*\AutoUpdate|*.*|RECURSE +FileKey3=%AppData%\iMobie\*\Configue|Settings.plist +FileKey4=%AppData%\iMobie\*\EasyLoseFiles|*.*|RECURSE +FileKey5=%AppData%\iMobie\*\ErrorLog|*.*|RECURSE +FileKey6=%AppData%\iMobie\*\Files|*.*|RECURSE +FileKey7=%AppData%\iMobie\*\iMobieConfig|*.*|RECURSE +FileKey8=%AppData%\iMobie\*\TempFiles|*.*|RECURSE +ExcludeKey1=FILE|%AppData%\iMobie\*\iMobieConfig\|ConfigReg.ini + +[iMobie Backups *] +LangSecRef=3024 +DetectFile=%AppData%\iMobie +Default=False +FileKey1=%AppData%\iMobie\*\*Backup|*.*|RECURSE +FileKey2=%AppData%\iMobie\Backup|*.*|RECURSE + +[ImTOO iPad Video Converter *] +LangSecRef=3023 +Detect=HKCU\Software\ImTOO\iPad Video Converter +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\ImTOO\iPad Video Converter|*.log;ERRORLOG.TXT +FileKey2=%ProgramFiles%\ImTOO\iPad Video Converter|*.log;ERRORLOG.TXT + +[ImTOO Video Converter Ultimate *] +LangSecRef=3023 +Detect=HKCU\Software\ImTOO\Video Converter Ultimate +Default=False +FileKey1=%CommonAppData%\ImTOO\Video Converter Ultimate\customdata|settings.old +RegKey1=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_openfile_dir +RegKey2=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_output_dir +RegKey3=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_profile_group +RegKey4=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_profile_url +RegKey5=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|recent_profiles +RegKey6=HKCU\Software\ImTOO\Video Converter Ultimate\Settings\output + +[IMVU *] +LangSecRef=3022 +Detect=HKCU\Software\IMVU +Default=False +FileKey1=%AppData%\IMVU|*.chk|RECURSE +FileKey2=%AppData%\IMVU|*.db;mini.dmp.bak;*.pickle;*.jpg;*.txt;*.log.*;*.log +FileKey3=%AppData%\IMVU\*Cache|*.*|REMOVESELF +FileKey4=%AppData%\IMVUClient|*.icns|RECURSE +FileKey5=%AppData%\IMVUClient\installer|*.*|RECURSE +FileKey6=%AppData%\IMVUClient\ui\profile|*.sqlite;*.js;*.dat;*.mfl +FileKey7=%AppData%\IMVUClient\ui\profile\cache|*.*|REMOVESELF + +[iMyFone Umate *] +LangSecRef=3024 +Detect=HKLM\Software\iMyFone\Umate +Default=False +FileKey1=%ProgramFiles%\iMyFone\iMyFone Umate|mate.log +FileKey2=%ProgramFiles%\iMyFone\iMyFone Umate\cache|*.*|RECURSE +FileKey3=%ProgramFiles%\iMyFone\iMyFone Umate\Log|*.*|RECURSE +FileKey4=%ProgramFiles%\iMyFone\iMyFone Umate\temp|*.*|RECURSE + +[Incredimail *] +LangSecRef=3022 +Detect=HKLM\Software\Clients\Mail\IncrediMail +Default=False +Warning=This will empty the contents of your Deleted and Sent folders +FileKey1=%LocalAppData%\IM\Identities\*\Message Store|deleted items.imm;sent items.imm + +[inFlow Inventory *] +LangSecRef=3021 +DetectFile=%AppData%\inFlow Inventory +Default=False +FileKey1=%AppData%\inFlow Inventory|log.txt +FileKey2=%CommonAppData%\inFlow Inventory\Logs|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\inFlow Inventory\Logs|*.* + +[InkScape *] +LangSecRef=3023 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\inkscape.exe +Default=False +FileKey1=%AppData%\InkScape|*.log|RECURSE +FileKey2=%LocalAppData%|recently-used.xbel +FileKey3=%UserProfile%|.recently-used.xbel + +[Inky *] +LangSecRef=3022 +Detect=HKCU\Software\Inky +Default=False +FileKey1=%LocalAppData%\Arcode\Plugin|*.log|RECURSE +FileKey2=%LocalAppData%\Inky|data_*;f_*;index;*.log +FileKey3=%LocalAppData%\Inky\Local Storage|*.* + +[Inno Setup *] +LangSecRef=3021 +Detect=HKCU\Software\Jordan Russell\Inno Setup +Default=False +RegKey1=HKCU\Software\Jordan Russell\Inno Setup\ScriptFileHistoryNew + +[InnoExtractor *] +LangSecRef=3024 +DetectFile1=%AppData%\InnoExtractor\InnoExtractor.exe +DetectFile2=%LocalAppData%\InnoExtractor\InnoExtractor.exe +DetectFile3=%ProgramFiles%\InnoExtractor\InnoExtractor.exe +DetectFile4=%SystemDrive%\Programs\InnoExtractor\InnoExtractor.exe +Default=False +FileKey1=%AppData%\InnoExtractor|Historial.dat +FileKey2=%LocalAppData%\InnoExtractor|Historial.dat +FileKey3=%ProgramFiles%\InnoExtractor|Historial.dat +FileKey4=%SystemDrive%\Programs\InnoExtractor|Historial.dat + +[InnoTab *] +LangSecRef=3021 +DetectFile=%CommonAppData%\VTech\DA +Default=False +FileKey1=%CommonAppData%\VTech\DA|*.log;InnoTab.txt;IntallLog.txt|RECURSE +FileKey2=%CommonAppData%\VTech\DA\InnoTab\ConsoleLog|*.* +FileKey3=%CommonAppData%\VTech\DA\InnoTab\Games\tmp|*.*|REMOVESELF +FileKey4=%LocalAppData%\VirtualStore\ProgramData\VTech\DA|*.log;InnoTab.txt;IntallLog.txt|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\VTech\DA\InnoTab\ConsoleLog|*.* +FileKey6=%LocalAppData%\VirtualStore\ProgramData\VTech\DA\InnoTab\Games\tmp|*.*|REMOVESELF + +[Inpaint *] +LangSecRef=3021 +Detect=HKCU\Software\Teorex\Inpaint +Default=False +RegKey1=HKCU\Software\Teorex\Inpaint\Recent File List +RegKey2=HKCU\Software\Teorex\Inpaint\RecentFileList + +[inSSIDer Home *] +LangSecRef=3024 +Detect=HKCU\Software\MetaGeek, LLC\inSSIDer Home +Default=False +FileKey1=%LocalAppData%\MetaGeek,_LLC|ConnectionErrorLog;MetaGeek-OUI.backup + +[InstallShield *] +LangSecRef=3024 +Detect=HKCU\Software\InstallShield +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\InstallShield Installation Information|*.log|RECURSE +FileKey2=%ProgramFiles%|_ISTMP1.DIR +FileKey3=%ProgramFiles%\InstallShield Installation Information|*.log|RECURSE +FileKey4=%SystemDrive%|_ISTMP*.DIR +RegKey1=HKCU\Software\InstallShield\16.0\Professional\Recent File List +RegKey2=HKCU\Software\InstallShield\17.0\Professional\Recent File List +RegKey3=HKCU\Software\InstallShield\18.0\Professional\Recent File List +RegKey4=HKCU\Software\InstallShield\19.0\Professional\Recent File List +RegKey5=HKCU\Software\InstallShield\20.0\Professional\Recent File List +RegKey6=HKCU\Software\InstallShield\21.0\Professional\Recent File List +RegKey7=HKCU\Software\InstallShield\InstallShield Cabinet and Log File Viewer\Recent File List +RegKey8=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU1 +RegKey9=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU2 +RegKey10=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU3 +RegKey11=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU4 + +[Instant Dungeon! *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\326720 +Default=False +FileKey1=%AppData%\Instant Dungeon|log.txt + +[Instantbird *] +LangSecRef=3022 +DetectFile=%AppData%\Instantbird +Default=False +FileKey1=%AppData%\Instantbird\Crash Reports|*.*|RECURSE +FileKey2=%AppData%\Instantbird\Profiles|*.corrupt|RECURSE +FileKey3=%AppData%\Instantbird\Profiles\*|extensions.log +FileKey4=%AppData%\Instantbird\Profiles\*\icons|*.*|RECURSE +FileKey5=%AppData%\Instantbird\Profiles\*\logs|*.*|RECURSE +FileKey6=%AppData%\Instantbird\Profiles\*\minidumps|*.*|RECURSE +FileKey7=%LocalAppData%\Instantbird\Profiles\*\*cache|*.*|RECURSE +FileKey8=%LocalAppData%\Instantbird\Profiles\*\Updates|*.log|RECURSE +FileKey9=%ProgramFiles%\Instantbird|install.log + +[InstEd *] +LangSecRef=3024 +Detect=HKCU\Software\instedit.com\insted +Default=False +RegKey1=HKCU\Software\instedit.com\insted\MRU + +[Intel Extreme Tuning Utility *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Intel\Intel Extreme Tuning Utility +Default=False +FileKey1=%CommonAppData%\Intel\Intel Extreme Tuning Utility\Logs|*.* + +[Intel iCLS Client *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Intel\iCLS Client +Default=False +FileKey1=%CommonAppData%\Intel\iCLS Client|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Intel\iCLS Client|*.log + +[Intel Installation Logs *] +LangSecRef=3024 +Detect1=HKCU\Software\Intel +Detect2=HKLM\Software\Intel +Default=False +FileKey1=%CommonAppData%\intel|*.log|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Intel\InfInst|*.*|REMOVESELF +FileKey3=%ProgramFiles%\Intel\InfInst|*.*|REMOVESELF +FileKey4=%SystemDrive%\Intel\Logs|*.*|REMOVESELF +FileKey5=%UserProfile%\Intel\Logs|*.*|REMOVESELF +FileKey6=%WinDir%\debug\intel\logs|*.*|REMOVESELF +FileKey7=%WinDir%\System32\config\systemprofile\Intel\Logs|*.*|REMOVESELF +FileKey8=%WinDir%\SysWOW64\config\systemprofile\Intel\Logs|*.*|REMOVESELF + +[Intel Rapid Storage Technology *] +LangSecRef=3021 +DetectFile=%SystemDrive%\Driver_allOS\MEI\Drivers\MEI\INTERNAL +Default=False +FileKey1=%SystemDrive%\Driver_allOS\MEI\Drivers\MEI\INTERNAL|*.log|RECURSE + +[Intel Storage Counters *] +LangSecRef=3024 +DetectFile=%WinDir%\Inf\Intel Storage Counters +Default=False +FileKey1=%WinDir%\Inf\Intel Storage Counters|*.tmp|RECURSE + +[Inter-Tel Device *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Inter-Tel +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Inter-Tel|*.log|RECURSE +FileKey2=%ProgramFiles%\Inter-Tel|*.log|RECURSE + +[InterAction studios CI2rmdemo *] +Section=Games +DetectFile=%CommonAppData%\InterAction studios\CI2rmdemo +Default=False +FileKey1=%CommonAppData%\InterAction studios\CI2rmdemo|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\InterAction studios\CI2rmdemo|*.log|RECURSE + +[Internet Business Promoter *] +LangSecRef=3022 +DetectFile=%AppData%\IBP +Default=False +FileKey1=%AppData%\IBP|*Log.txt;*.bak|RECURSE + +[Internet Download Manager *] +LangSecRef=3022 +Detect=HKCU\Software\DownloadManager +Default=False +Warning=This will delete unfinished downloads. +FileKey1=%AppData%\IDM|*.Log;*.txt +FileKey2=%AppData%\IDM\DwnlData|*.*|REMOVESELF +FileKey3=%ProgramFiles%\Internet Download Manager|*.log +RegKey1=HKCU\Software\DownloadManager\1 +RegKey2=HKCU\Software\DownloadManager\2 +RegKey3=HKCU\Software\DownloadManager\3 +RegKey4=HKCU\Software\DownloadManager\4 +RegKey5=HKCU\Software\DownloadManager\5 +RegKey6=HKCU\Software\DownloadManager\6 +RegKey7=HKCU\Software\DownloadManager\7 +RegKey8=HKCU\Software\DownloadManager\8 +RegKey9=HKCU\Software\DownloadManager\9 +RegKey10=HKCU\Software\DownloadManager\10 +RegKey11=HKCU\Software\DownloadManager\11 +RegKey12=HKCU\Software\DownloadManager\12 +RegKey13=HKCU\Software\DownloadManager\13 +RegKey14=HKCU\Software\DownloadManager\14 +RegKey15=HKCU\Software\DownloadManager\15 +RegKey16=HKCU\Software\DownloadManager\16 +RegKey17=HKCU\Software\DownloadManager\17 +RegKey18=HKCU\Software\DownloadManager\18 +RegKey19=HKCU\Software\DownloadManager\19 +RegKey20=HKCU\Software\DownloadManager\20 +RegKey21=HKCU\Software\DownloadManager\21 +RegKey22=HKCU\Software\DownloadManager\22 +RegKey23=HKCU\Software\DownloadManager\23 +RegKey24=HKCU\Software\DownloadManager\24 +RegKey25=HKCU\Software\DownloadManager\25 +RegKey26=HKCU\Software\DownloadManager\26 +RegKey27=HKCU\Software\DownloadManager\27 +RegKey28=HKCU\Software\DownloadManager\28 +RegKey29=HKCU\Software\DownloadManager\29 +RegKey30=HKCU\Software\DownloadManager\30 +RegKey31=HKCU\Software\DownloadManager\31 +RegKey32=HKCU\Software\DownloadManager\32 +RegKey33=HKCU\Software\DownloadManager\33 +RegKey34=HKCU\Software\DownloadManager\34 +RegKey35=HKCU\Software\DownloadManager\35 +RegKey36=HKCU\Software\DownloadManager\36 +RegKey37=HKCU\Software\DownloadManager\37 +RegKey38=HKCU\Software\DownloadManager\38 +RegKey39=HKCU\Software\DownloadManager\39 +RegKey40=HKCU\Software\DownloadManager\40 +RegKey41=HKCU\Software\DownloadManager\41 +RegKey42=HKCU\Software\DownloadManager\42 +RegKey43=HKCU\Software\DownloadManager\43 +RegKey44=HKCU\Software\DownloadManager\44 +RegKey45=HKCU\Software\DownloadManager\45 +RegKey46=HKCU\Software\DownloadManager\46 +RegKey47=HKCU\Software\DownloadManager\47 +RegKey48=HKCU\Software\DownloadManager\48 +RegKey49=HKCU\Software\DownloadManager\49 +RegKey50=HKCU\Software\DownloadManager\50 +RegKey51=HKCU\Software\DownloadManager\51 +RegKey52=HKCU\Software\DownloadManager\52 +RegKey53=HKCU\Software\DownloadManager\53 +RegKey54=HKCU\Software\DownloadManager\54 +RegKey55=HKCU\Software\DownloadManager\55 +RegKey56=HKCU\Software\DownloadManager\56 +RegKey57=HKCU\Software\DownloadManager\57 +RegKey58=HKCU\Software\DownloadManager\58 +RegKey59=HKCU\Software\DownloadManager\59 +RegKey60=HKCU\Software\DownloadManager\60 +RegKey61=HKCU\Software\DownloadManager\61 +RegKey62=HKCU\Software\DownloadManager\62 +RegKey63=HKCU\Software\DownloadManager\63 +RegKey64=HKCU\Software\DownloadManager\64 +RegKey65=HKCU\Software\DownloadManager\65 +RegKey66=HKCU\Software\DownloadManager\66 +RegKey67=HKCU\Software\DownloadManager\67 +RegKey68=HKCU\Software\DownloadManager\68 +RegKey69=HKCU\Software\DownloadManager\69 +RegKey70=HKCU\Software\DownloadManager\70 +RegKey71=HKCU\Software\DownloadManager\71 +RegKey72=HKCU\Software\DownloadManager\72 +RegKey73=HKCU\Software\DownloadManager\73 +RegKey74=HKCU\Software\DownloadManager\74 +RegKey75=HKCU\Software\DownloadManager\75 +RegKey76=HKCU\Software\DownloadManager\maxID + +[Internet Explorer *] +LangSecRef=3022 +Detect=HKCU\Software\Microsoft\Internet Explorer +Default=False +FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE +FileKey2=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE +FileKey3=%LocalAppData%\Microsoft\Windows\IECompat*Cache|*.*|RECURSE +FileKey4=%LocalAppData%\Microsoft\Windows\INetCache|*.*|RECURSE +FileKey5=%LocalAppData%\Microsoft\Windows\INetCookies|*.*|RECURSE +FileKey6=%LocalAppData%\Microsoft\Windows\WebCache|*.*|RECURSE +FileKey7=%LocalAppData%\Microsoft\Windows\WebCache.old|*.*|REMOVESELF +FileKey8=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\windows_ie_ac_*\AC\IECompat*Cache|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\IEDownloadHistory|*.*|RECURSE +FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE +FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey15=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\Emie*List|*.*|RECURSE +FileKey16=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*|RECURSE +FileKey17=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*|RECURSE +FileKey18=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE +FileKey19=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE +FileKey20=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE +FileKey21=%WinDir%\System32\config\Systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE +RegKey1=HKCR\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage +RegKey2=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore +RegKey3=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage +RegKey4=HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl +RegKey5=HKCU\Software\Microsoft\Internet Explorer\Recovery\PendingDelete +RegKey6=HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats +ExcludeKey1=FILE|%LocalAppData%\Microsoft\Windows\INetCache\IE\|container.dat +ExcludeKey2=FILE|%LocalAppData%\Packages\windows_ie_ac_*\AC\INetCache\|container.dat + +[Internet Explorer Vault *] +DetectOS=6.2| +LangSecRef=3031 +Detect=HKCU\Software\Microsoft\Internet Explorer +Default=False +Warning=This will clear the saved passwords in the Windows Mail App +FileKey1=%LocalAppData%\Microsoft\Vault\*|*.vcrd + +[Intuit Data Protect *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Intuit\Intuit Data Protect +Default=False +FileKey1=%CommonAppData%\Intuit\Intuit Data Protect|*.log +FileKey2=%LocalAppData%\Intuit\Intuit Data Protect|*.log +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Intuit\Intuit Data Protect|*.log + +[Intuit Entitlement Client *] +LangSecRef=3021 +DetectFile=%CommonAppData%\Intuit\Entitlement Client +Default=False +FileKey1=%CommonAppData%\Intuit\Entitlement Client\*|IntuitEntitlementLog*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Intuit\Entitlement Client\*|IntuitEntitlementLog*.* + +[Intuit PTI *] +LangSecRef=3021 +DetectFile=%AppData%\Intuit\PTI +Default=False +FileKey1=%AppData%\Intuit\PTI\Log|*.* + +[Intuit TurboTax *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\TurboTax* +Default=False +FileKey1=%AppData%\Intuit*|*.log|RECURSE +FileKey2=%CommonAppData%|*.bc +FileKey3=%CommonAppData%\Intuit*|*.log|RECURSE +FileKey4=%CommonAppData%\Intuit\Common\Metrix\*\Logs|*.* +FileKey5=%CommonAppData%\Intuit\Common\QuickBaseClient\*\Logs|*.* +FileKey6=%CommonAppData%\Intuit\Common\Update Service\*\Logs|*.* +FileKey7=%CommonAppData%\Intuit\TurboTax\MSI\*\Logs|*.* +FileKey8=%CommonProgramFiles%\Intuit\Internet Client|Msdun13.exe +FileKey9=%LocalAppData%\VirtualStore\Program Files*\Common Files\Intuit\Internet Client|Msdun13.exe +FileKey10=%LocalAppData%\VirtualStore\Program Files*\TurboTax*|*.txt +FileKey11=%LocalAppData%\VirtualStore\ProgramData|*.bc +FileKey12=%LocalAppData%\VirtualStore\ProgramData\Intuit*|*.log|RECURSE +FileKey13=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\Metrix\*\Logs|*.* +FileKey14=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\QuickBaseClient\*\Logs|*.* +FileKey15=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\Update Service\*\Logs|*.* +FileKey16=%LocalAppData%\VirtualStore\ProgramData\Intuit\TurboTax\MSI\*\Logs|*.* +FileKey17=%ProgramFiles%\TurboTax*|*.txt + +[IObit Advanced SystemCare *] +LangSecRef=3024 +DetectFile1=%AppData%\IObit\Advanced SystemCare V* +DetectFile2=%CommonAppData%\IObit\Advanced SystemCare V* +Default=False +FileKey1=%AppData%\IObit\Advanced SystemCare *|*.log +FileKey2=%AppData%\IObit\Advanced SystemCare *\Boottime|*.log +FileKey3=%AppData%\IObit\Advanced SystemCare *\EmptyFolder|*.*|RECURSE +FileKey4=%AppData%\IObit\Advanced SystemCare *\Log|*.*|RECURSE +FileKey5=%CommonAppData%\IObit\Advanced SystemCare *\Log|*.*|REMOVESELF +FileKey6=%CommonAppData%\IObit\ASCDownloader|*.log +FileKey7=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *|*.log;*.txt|RECURSE +FileKey8=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *\*.cab_Temp|*.*|REMOVESELF +FileKey9=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *\ASCServiceLog|*.*|RECURSE +FileKey10=%LocalAppData%\VirtualStore\ProgramData\IObit\Advanced SystemCare *\Log|*.*|RECURSE +FileKey11=%LocalAppData%\VirtualStore\ProgramData\IObit\ASCDownloader|*.log +FileKey12=%ProgramFiles%\IObit\Advanced SystemCare *|*.log;*.txt|RECURSE +FileKey13=%ProgramFiles%\IObit\Advanced SystemCare *\*.cab_Temp|*.*|REMOVESELF +FileKey14=%ProgramFiles%\IObit\Advanced SystemCare *\ASCServiceLog|*.*|RECURSE +FileKey15=%SystemDrive%\Users\Default\AppData\Roaming\IObit\Advanced SystemCare *|*.log +FileKey16=%WinDir%\System32\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare *|*.log +FileKey17=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare *|*.log + +[IObit Advanced SystemCare Antivirus Backup *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\IObit\Advanced SystemCare Ultimate +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare Ultimate\Antivirus\BackupRec|*.*|RECURSE +FileKey2=%ProgramFiles%\IObit\Advanced SystemCare Ultimate\Antivirus\BackupRec|*.*|RECURSE + +[IObit Driver Booster *] +LangSecRef=3024 +DetectFile=%AppData%\IObit\Driver Booster +Default=False +FileKey1=%AppData%\IObit\Driver Booster|*.log|RECURSE +FileKey2=%ProgramFiles%\IObit\Driver Booster|*.log + +[IObit Game Booster *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\IObit\Game Booster 3 +Default=False +FileKey1=%CommonAppData%\IObit\Game Booster 3|Defrags.ini +FileKey2=%LocalAppData%\VirtualStore\Program Files*\IObit\Game Booster 3|*.log +FileKey3=%LocalAppData%\VirtualStore\Program Files*\IObit\Game Booster 3\FPS|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\Program Files*\IObit\Game Booster 3\Update|Update.tmp +FileKey5=%LocalAppData%\VirtualStore\ProgramData\IObit\Game Booster 3|Defrags.ini +FileKey6=%ProgramFiles%\IObit\Game Booster 3|*.log +FileKey7=%ProgramFiles%\IObit\Game Booster 3\FPS|*.*|RECURSE +FileKey8=%ProgramFiles%\IObit\Game Booster 3\Update|Update.tmp + +[IObit Game Booster Backup *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\IObit\Game Booster 3 +Default=False +Warning=This will delete your GameBox applications. +FileKey1=%CommonAppData%\IObit\Game Booster 3|TweaksBackup.reg +FileKey2=%LocalAppData%\VirtualStore\ProgramData\IObit\Game Booster 3|TweaksBackup.reg + +[IObit KB Downloader *] +LangSecRef=3024 +DetectFile=%CommonAppData%\IObit\KBDownloader +Default=False +FileKey1=%CommonAppData%\IObit\KBDownloader|*.*|RECURSE + +[IObit LiveUpdate *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\IObit\LiveUpdate +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\IObit\LiveUpdate|*.log|RECURSE +FileKey2=%ProgramFiles%\IObit\LiveUpdate|*.log|RECURSE + +[IObit Uninstaller *] +LangSecRef=3024 +DetectFile=%AppData%\IObit\IObit Uninstaller +Default=False +FileKey1=%AppData%\IObit\IObit Uninstaller\*Log|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\IObit\iObit Uninstaller|*.log|RECURSE +FileKey3=%ProgramFiles%\IObit\iObit Uninstaller|*.log|RECURSE + +[iPod-Cloner *] +LangSecRef=3023 +Detect=HKCU\Software\iPod-Cloner +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\iPod-Cloner|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\iPod-Cloner\ReadCache|*.* +FileKey3=%ProgramFiles%\iPod-Cloner|*.log +FileKey4=%ProgramFiles%\iPod-Cloner\ReadCache|*.* +FileKey5=%SystemDrive%|dtdlog.txt + +[iResizer *] +LangSecRef=3021 +Detect=HKCU\Software\Teorex\iResizer +Default=False +RegKey1=HKCU\Software\Teorex\iResizer\RecentFileList + +[iSkysoft Helper Compact *] +LangSecRef=3021 +DetectFile=%CommonProgramFiles%\iSkysoft\iSkysoft Helper Compact +Default=False +FileKey1=%CommonProgramFiles%\iSkysoft\iSkysoft Helper Compact|ProductUpdateLists.xml;ISHelper.exe_temp;ISHelperSetup.exe_temp +FileKey2=%CommonProgramFiles%\iSkysoft\iSkysoft Helper Compact\DATADICT|*.*|RECURSE +FileKey3=%CommonProgramFiles%\iSkysoft\iSkysoft Helper Compact\log|*.*|RECURSE +FileKey4=%CommonProgramFiles%\iSkysoft\iSkysoft Helper Compact\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Common Files\iSkysoft\iSkysoft Helper Compact|ProductUpdateLists.xml;ISHelper.exe_temp;ISHelperSetup.exe_temp +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Common Files\iSkysoft\iSkysoft Helper Compact\log|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Common Files\iSkysoft\iSkysoft Helper Compact\Temp|*.*|RECURSE +RegKey1=HKLM\Software\iSkysoft\iSkysoft Helper Compact +RegKey2=HKLM\Software\Wow6432Node\iSkysoft\iSkysoft Helper Compact + +[iSkysoft Video Converter *] +LangSecRef=3023 +Detect1=HKLM\Software\iSkysoft\iSkysoft Video Converter +Detect2=HKLM\Software\iSkysoft\iSkysoft Video Converter Ultimate +Default=False +FileKey1=%CommonAppData%\iSkysoft Video Converter*|*.dat.bak +FileKey2=%CommonAppData%\iSkysoft Video Converter*\Temp*Dir|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\iSkysoft\Video Converter*\Log|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\Program Files*\iSkysoft\Video Converter*\TempThumbDir|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\iSkysoft Video Converter*|*.dat.bak +FileKey6=%LocalAppData%\VirtualStore\ProgramData\iSkysoft Video Converter*\Temp*Dir|*.*|RECURSE +FileKey7=%ProgramFiles%\iSkysoft\Video Converter*\Log|*.*|RECURSE +FileKey8=%ProgramFiles%\iSkysoft\Video Converter*\TempThumbDir|*.*|RECURSE + +[iSpy *] +LangSecRef=3021 +Detect=HKCU\Software\ISpy\ISPY +Default=False +FileKey1=%AppData%\iSpy\WebServerRoot\Media|*.*|RECURSE +FileKey2=%LocalAppData%\iSpy\WebServerRoot\Media|*.*|RECURSE + +[iSysCleaner *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Utils\iSysCleaner\iSysCleaner.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Utils\iSysCleaner\traces|*.* +FileKey2=%ProgramFiles%\Utils\iSysCleaner\traces|*.* + +[iTunes *] +LangSecRef=3023 +Detect=HKLM\Software\Apple Computer, Inc.\iTunes +Default=False +FileKey1=%AppData%\Apple Computer\iTunes|*.ipcc;*.ipsw;*.log +FileKey2=%AppData%\Apple Computer\iTunes\Cookies|Cookies.binarycookies +FileKey3=%AppData%\Apple Computer\Logs|*.*|RECURSE +FileKey4=%CommonAppData%\Apple Computer\iTunes\iPhone Temporary Files|*.*|RECURSE +FileKey5=%LocalAppData%\Apple Computer\iTunes|Cache.db +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Apple Computer\iTunes\iPhone Temporary Files|*.*|RECURSE +FileKey7=%Music%\iTunes|*.tmp|RECURSE +FileKey8=%Music%\iTunes\Album Artwork\Cache|*.*|RECURSE +FileKey9=%UserProfile%\Apple Computer\logs|*.log +FileKey10=%WinDir%\System32\config\systemprofile\AppData\Roaming\Apple Computer\Logs|*.*|RECURSE +FileKey11=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Apple Computer\Logs|*.*|RECURSE + +[iTunes Previous Libraries *] +LangSecRef=3023 +Detect=HKLM\Software\Apple Computer, Inc.\iTunes +Default=False +FileKey1=%Music%\iTunes\Previous iTunes Libraries|*.*|RECURSE + +[iWisoft Free Video Converter *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\iWisoft Free Video Converter +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\iWisoft Free Video Converter|VideoConverter.log +FileKey2=%ProgramFiles%\iWisoft Free Video Converter|VideoConverter.log + +[iXL *] +LangSecRef=3021 +DetectFile=%AppData%\Fisher-Price\iXL +Default=False +FileKey1=%AppData%\Fisher-Price\iXL\Log|*.* + +[iZotope RX 2 Session Data *] +LangSecRef=3021 +DetectFile=%AppData%\iZotope\iZotope RX 2 Session Data +Default=False +FileKey1=%AppData%\iZotope\iZotope RX 2 Session Data|*.*|RECURSE + +[Jabbear *] +LangSecRef=3022 +Detect=HKCU\Software\Jabbear +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Jabbear|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Jabbear\avatars|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Jabbear\cachedir|*.*|RECURSE +FileKey4=%ProgramFiles%\Jabbear|*.log|RECURSE +FileKey5=%ProgramFiles%\Jabbear\avatars|*.*|RECURSE +FileKey6=%ProgramFiles%\Jabbear\cachedir|*.*|RECURSE + +[Jabbear Chat History *] +LangSecRef=3022 +Detect=HKCU\Software\Jabbear +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Jabbear\Users|*.dat;*.html|RECURSE +FileKey2=%ProgramFiles%\Jabbear\Users|*.dat;*.html|RECURSE + +[Jagex Cache *] +Section=Games +DetectFile=%UserProfile%\jagexcache +Default=False +FileKey1=%UserProfile%\jagex*|*.*|RECURSE +FileKey2=%WinDir%\.jagex*|*.*|REMOVESELF +ExcludeKey1=PATH|%UserProfile%\jagexcache\jagexlauncher\|*.* + +[JAJC *] +LangSecRef=3022 +DetectFile=%UserProfile%\JAJC +Default=False +FileKey1=%UserProfile%\JAJC\Avatars|*.*|RECURSE +FileKey2=%UserProfile%\JAJC\Logs|*.*|RECURSE + +[Jalatext *] +LangSecRef=3021 +DetectFile=%UserProfile%\.jalatext +Default=False +FileKey1=%UserProfile%\.jalatext\log|*.* + +[jAnrufmonitor *] +LangSecRef=3025 +DetectFile=%ProgramFiles%\jAnrufmonitor +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\jAnrufmonitor\data|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\jAnrufmonitor\lib\cache|classloader.cache.log +FileKey3=%LocalAppData%\VirtualStore\Program Files*\jAnrufmonitor\logs|*.* +FileKey4=%ProgramFiles%\jAnrufmonitor\data|*.log +FileKey5=%ProgramFiles%\jAnrufmonitor\lib\cache|classloader.cache.log +FileKey6=%ProgramFiles%\jAnrufmonitor\logs|*.* + +[Jasc Animation Shop *] +LangSecRef=3023 +Detect=HKCU\Software\Jasc\animation shop +Default=False +RegKey1=HKCU\Software\JASC\Animation Shop\Cache + +[Java *] +LangSecRef=3022 +Detect1=HKLM\Software\JavaSoft\Java Plug-in +Detect2=HKLM\Software\JavaSoft\Java Runtime Environment +Detect3=HKLM\Software\JavaSoft\Java Web Start +Default=False +FileKey1=%AppData%\Sun\Java\Deployment\SystemCache|*.*|RECURSE +FileKey2=%CommonAppData%\Oracle\Java\.oracle_jre_usage|*.* +FileKey3=%LocalAppData%\Sun\Java\Deployment\*Cache|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Java\jre*|*PATCH.ERR +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Java\jre*\lib\security|*.bak +FileKey6=%LocalLowAppData%\Sun\Java\Deployment\SystemCache|*.*|RECURSE +FileKey7=%ProgramFiles%\Java\jre*|*PATCH.ERR +FileKey8=%ProgramFiles%\Java\jre*\lib\security|*.bak +FileKey9=%SystemDrive%\Users\*\.oracle_jre_usage|*.*|REMOVESELF +FileKey10=%WinDir%\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\Cache|*.*|RECURSE +FileKey11=%WinDir%\SysWOW64\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\Cache|*.*|RECURSE + +[Java Setup Files *] +LangSecRef=3022 +Detect=HKLM\Software\JavaSoft\Java Runtime Environment +Default=False +FileKey1=%AppData%\Sun\Java\jre*|*.*|REMOVESELF +FileKey2=%CommonAppData%\Oracle\Java\installcache|*.*|RECURSE +FileKey3=%LocalLowAppData%\Oracle\Java\jdk*|*.*|REMOVESELF +FileKey4=%LocalLowAppData%\Oracle\Java\jre*|*.*|REMOVESELF +FileKey5=%LocalLowAppData%\Sun\Java\jdk*|*.*|REMOVESELF +FileKey6=%LocalLowAppData%\Sun\Java\jre*|*.*|REMOVESELF + +[JavaRa *] +LangSecRef=3022 +DetectFile1=%ProgramFiles%\JavaRa 2.0\JavaRa.exe +DetectFile2=%ProgramFiles%\JavaRa\JavaRa.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\JavaRa 2.0|*.log|RECURSE +FileKey2=%ProgramFiles%\JavaRa 2.0|*.log|RECURSE +FileKey3=%SystemDrive%|JavaRa.log + +[JDownloader *] +LangSecRef=3022 +Detect=HKLM\Software\JDownloader +DetectFile=%ProgramFiles%\JDownloader +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\JDownloader*|*.log;updateLog.txt;*.lck;*.log.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\.junique|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\captchas|*.* +FileKey4=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\container|*.* +FileKey5=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\downloads|*.* +FileKey6=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\tmp\linksave|*.* +FileKey7=%ProgramFiles%\JDownloader*|*.log;updateLog.txt;*.lck;*.log.*|RECURSE +FileKey8=%ProgramFiles%\JDownloader*\.junique|*.* +FileKey9=%ProgramFiles%\JDownloader*\captchas|*.* +FileKey10=%ProgramFiles%\JDownloader*\container|*.* +FileKey11=%ProgramFiles%\JDownloader*\downloads|*.* +FileKey12=%ProgramFiles%\JDownloader*\tmp\linksave|*.* +FileKey13=%UserProfile%\.jd_home|JDownloader.log +FileKey14=%UserProfile%\.jd_home\logs|*.0 + +[JDownloader Backup *] +LangSecRef=3022 +Detect=HKLM\Software\JDownloader +DetectFile=%ProgramFiles%\JDownloader +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\backup|*.* +FileKey2=%ProgramFiles%\JDownloader*\backup|*.* + +[JDownloader2 *] +LangSecRef=3022 +Detect=HKLM\Software\Classes\JDownloader2 +DetectFile=%ProgramFiles%\JDownloader 2 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*|JDownloader.log;Updater_*-*-*.log;SessionInstallLog.json.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*\captchas|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*\cfg|CaptchaDialogDimensions_*.json +FileKey4=%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*\logs|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*\tmp|*.*|RECURSE +FileKey6=%ProgramFiles%\JDownloader*2*|JDownloader.log;Updater_*-*-*.log;SessionInstallLog.json.*|RECURSE +FileKey7=%ProgramFiles%\JDownloader*2*\captchas|*.*|RECURSE +FileKey8=%ProgramFiles%\JDownloader*2*\cfg|CaptchaDialogDimensions_*.json +FileKey9=%ProgramFiles%\JDownloader*2*\logs|*.*|RECURSE +FileKey10=%ProgramFiles%\JDownloader*2*\tmp|*.*|RECURSE +ExcludeKey1=PATH|%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*\cfg\|subconf_*.ejs +ExcludeKey2=PATH|%ProgramFiles%\JDownloader*2*\cfg\|subconf_*.ejs + +[jEdit *] +LangSecRef=3021 +DetectFile=%UserProfile%\.jedit +Default=False +FileKey1=%UserProfile%\.jedit|*.log|RECURSE +FileKey2=%UserProfile%\.jedit\jars-cache|*.*|RECURSE + +[JetBrains dotPeek v1.1 *] +LangSecRef=3024 +Detect=HKLM\Software\JetBrains\dotPeek +Default=False +FileKey1=%LocalAppData%\JetBrains\dotPeek\v1.1\Caches|*.*|REMOVESELF + +[Jetclean *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\BlueSprig\JetClean\JetClean.exe +Default=False +FileKey1=%AppData%\BlueSprig\JetClean\Log|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\BlueSprig\JetClean\Update|*.*|REMOVESELF +FileKey3=%ProgramFiles%\BlueSprig\JetClean\Update|*.*|REMOVESELF + +[JetDrive *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\JetDrive +Default=False +FileKey1=%LocalAppData%\Abelssoft\JetDrive|JetDrive.reports.xml +FileKey2=%LocalAppData%\VirtualStore\Program Files*\JetDrive|JetDrive.log +FileKey3=%ProgramFiles%\JetDrive|JetDrive.log + +[Jetico Personal Firewall *] +LangSecRef=3022 +Detect=HKLM\Software\Jetico\Personal Firewall +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Jetico\Jetico Personal Firewall|firewall*.log +FileKey2=%ProgramFiles%\Jetico\Jetico Personal Firewall|firewall*.log + +[Jing *] +LangSecRef=3024 +Detect=HKLM\Software\TechSmith\Jing +Default=False +FileKey1=%LocalAppData%\TechSmith\Jing\DataStore|*.*|RECURSE +FileKey2=%LocalAppData%\TechSmith\Jing\Temp|*.*|RECURSE + +[Jitsi *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Jitsi +Default=False +FileKey1=%AppData%\Jitsi\avatarcache|*.*|RECURSE +FileKey2=%AppData%\Jitsi\Log|*.*|RECURSE + +[Jitsi Chat/File History *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Jitsi +Default=False +FileKey1=%AppData%\Jitsi\History*|*.*|RECURSE + +[Joboshare DVD Toolkit *] +LangSecRef=3023 +Detect=HKCU\Software\Joboshare +Default=False +FileKey1=%Documents%\Joboshare\DVD Copy\ifo_temp|*.*|REMOVESELF +FileKey2=%Documents%\Joboshare\DVD Copy\log|*.*|REMOVESELF +FileKey3=%SystemDrive%|*temp.txt;*test.txt + +[Join.Me *] +LangSecRef=3022 +Detect=HKCU\Software\join.me +Default=False +FileKey1=%LocalAppData%\join.me|*.log + +[Join.Me Install Backups *] +LangSecRef=3022 +Detect=HKCU\Software\join.me +Default=False +Warning=This will remove all old versions of Join.Me that are automatically backed up on each install. +FileKey1=%LocalAppData%\join.me\join.me.*.*.*.*|*.*|REMOVESELF + +[Jojos Fashion Show *] +Section=Games +DetectFile=%AppData%\Gamelab\Jojos Fashion Show +Default=False +FileKey1=%AppData%\Gamelab\Jojos Fashion Show|log.txt + +[Jump Lists *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%AppData%\Microsoft\windows\recent\Automaticdestinations|*.*|RECURSE +FileKey2=%AppData%\Microsoft\windows\recent\CustomDestinations|*.*|RECURSE +ExcludeKey1=FILE|%AppData%\Microsoft\Windows\Recent\AutomaticDestinations\|f01b4d95cf55d32a.automaticDestinations-ms + +[Juniper Networks *] +LangSecRef=3021 +Detect1=HKCU\Software\Juniper Networks +Detect2=HKLM\Software\Juniper Networks +Default=False +FileKey1=%AppData%\Juniper Networks|*.old;*.log|RECURSE +FileKey2=%LocalAppData%\Juniper Networks\Logging|*.* +RegKey1=HKLM\Software\Juniper Networks\Default + +[jv16 PowerTools-X StartupOptimiser *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\jv16 PowerTools X\jv16PT.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\jv16 PowerTools X|StartupOptimizer*.log +FileKey2=%ProgramFiles%\jv16 PowerTools X|StartupOptimizer*.log + +[K-Lite Codec Pack *] +LangSecRef=3023 +Detect=HKLM\Software\KLCodecPack +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\K-Lite*|*.log;*.txt|RECURSE +FileKey2=%ProgramFiles%\K-Lite*|*.log;*.txt|RECURSE +FileKey3=%SystemDrive%|*klcp_itp_*.tmp;*klcp_iph_*.tmp +FileKey4=%UserProfile%\Desktop|klcp_codec_log.txt +RegKey1=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path0 +RegKey2=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path1 +RegKey3=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path2 + +[Kakao Talk *] +LangSecRef=3022 +DetectFile=%LocalAppData%\Kakao\KakaoTalk +Default=False +FileKey1=%LocalAppData%\Kakao\KakaoTalk\Dump|*.*|RECURSE + +[Kalypso Launcher *] +Section=Games +DetectFile=%AppData%\Kalypso Media\Launcher +Default=False +FileKey1=%AppData%\Kalypso Media\Launcher|log_appdata.txt;log.txt + +[Kaspersky *] +LangSecRef=3024 +Detect=HKCU\Software\KasperskyLab +Default=False +Warning=Make sure to disable "Self Defense" before cleaning. +FileKey1=%CommonAppData%\Kaspersky Lab|*.dmp;*.dmp.stat;*.log +FileKey2=%CommonAppData%\Kaspersky Lab\*\Bases\Cache|*.*|RECURSE +FileKey3=%CommonAppData%\Kaspersky Lab\*\Data\Updater\Temporary Files|*.*|RECURSE +FileKey4=%CommonAppData%\Kaspersky Lab\*\Temp|*.* +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Bases\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Data\Updater\Temporary Files|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Temp|*.* +FileKey8=%ProgramFiles%\Kaspersky Lab\NetworkAgent\~dumps|*.* + +[Kaspersky Now *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\KasperskyLab.KasperskyNow_8jx5e25qw3tdc +Default=False +FileKey1=%LocalAppData%\Packages\KasperskyLab.KasperskyNow_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\KasperskyLab.KasperskyNow_*\AC\Microsoft\CLR_v4.0_32|*.log +FileKey3=%LocalAppData%\Packages\KasperskyLab.KasperskyNow_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\KasperskyLab.KasperskyNow_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\KasperskyLab.KasperskyNow_*\LocalCache|*.*|RECURSE + +[Kate's Video Toolkit *] +LangSecRef=3023 +Detect=HKCU\Software\Web Solution Mart\Kate's Video Toolkit +Default=False +FileKey1=%CommonAppData%\Web Solution Mart\*|*.log|RECURSE + +[KCleaner *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\KCleaner +Default=False +FileKey1=%AppData%\KC Softwares\KCleaner|*.log + +[KDE *] +LangSecRef=3021 +Detect=HKCU\Software\KDE.org +Default=False +FileKey1=%UserProfile%\.kde\cache*|*.*|RECURSE + +[KFK *] +LangSecRef=3023 +Detect=HKCU\Software\KC Softwares\KFK +Default=False +FileKey1=%AppData%\KC Softwares\KFK|*.log + +[Killbox *] +LangSecRef=3024 +DetectFile=%SystemDrive%\!Killbox +Default=False +FileKey1=%SystemDrive%\!Killbox\Logs|*.* + +[Killing Floor 2 *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\232090 +Default=False +FileKey1=%Documents%\My Games\KillingFloor2\KFGame\Logs|*.*|RECURSE + +[Kinetic Jump Updater *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Kjs.AppLife.Update +Default=False +FileKey1=%LocalAppData%\Kjs.AppLife.Update|*.log + +[Kingsoft Office *] +LangSecRef=3021 +Detect=HKCU\Software\Kingsoft +Default=False +FileKey1=%AppData%\Kingsoft\*|*.bak +FileKey2=%AppData%\Kingsoft\*\backup|*.* +FileKey3=%AppData%\Kingsoft\*\update\log|*.log +FileKey4=%LocalAppData%\Kingsoft\*\cache\http*|*.* +FileKey5=%ProgramFiles%\Kingsoft\Kingsoft Office\*|update.log + +[KlokworkTeamConsole *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\KlokworkTeamConsole +Default=False +FileKey1=%AppData%\com.mcgraphix.KlokworkTeamConsole\local store|debug.txt + +[KMS Emulator *] +LangSecRef=3024 +DetectFile=%WinDir%\AutoKMS\AutoKMS.exe +Default=False +FileKey1=%WinDir%\AutoKMS|AutoKMS.log + +[Kodak AiO Software Disable Startup *] +LangSecRef=3021 +Detect1=HKLM\Software\Eastman Kodak Company\KODAK AiO Home Center +Detect2=HKLM\Software\Kodak\Kodak AiO Software +Default=False +Warning=Disables the Kodak AiO Software from automatically starting with Windows. Every time you print, it will re-enable itself to start with Windows. +RegKey1=HKLM\Software\Microsoft\Windows\CurrentVersion\Run|EKAIO2StatusMonitor +RegKey2=HKLM\Software\Microsoft\Windows\CurrentVersion\Run|EKStatusMonitor + +[Kodak Logs *] +LangSecRef=3021 +Detect1=HKCU\Software\Kodak +Detect2=HKLM\Software\Eastman Kodak Company\KODAK AiO Home Center +Detect3=HKLM\Software\Kodak\Kodak AiO Software +DetectFile=%AppData%\Kodak\Share Button App +Default=False +FileKey1=%AppData%\Kodak\Share Button App|*.log +FileKey2=%CommonAppData%\Kodak\Diagnostics|*.* +FileKey3=%CommonAppData%\Kodak\Inkjet Logging|*.*|RECURSE +FileKey4=%LocalAppData%|LaunchHomeCenter.log +FileKey5=%LocalAppData%\Kodak\Diagnostics|UploadLog.xml +FileKey6=%LocalAppData%\Kodak\Inkjet Logging|Status Monitor Log.* +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Kodak\Diagnostics|*.* +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Kodak\Inkjet Logging|*.*|RECURSE + +[Kodi *] +LangSecRef=3023 +DetectFile=%AppData%\kodi +Default=False +FileKey1=%AppData%\kodi|*.log;*.dmp +FileKey2=%AppData%\kodi*\userdata\thumbnails|*.*|RECURSE +FileKey3=%AppData%\kodi\addons\packages|*.*|RECURSE +FileKey4=%AppData%\kodi\cache|*.*|RECURSE + +[Koffix Blocker *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Koffix Blocker\Koffix.exe +Default=False +FileKey1=%Documents%\My Koffix Blocker Logs|*.* + +[Koinonein Bittorrent Client *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Koinonein BitTorrent Client\Koinonein BitTorrent Client.exe +Default=False +FileKey1=%LocalAppData%\Koinonein BitTorrent Client*\Application|log.db + +[KoolPlaya *] +LangSecRef=3023 +Detect=HKCU\Software\AKi-Software\Kool-Playa +Default=False +RegKey1=HKCU\Software\AKi-Software\Kool-Playa\VideoHistory +RegKey2=HKCU\Software\AKi-Software\Kool-Playa\Videos +RegKey3=HKCU\Software\AKi-Software\Kool-PlayaX64\VideoHistory +RegKey4=HKCU\Software\AKi-Software\Kool-PlayaX64\Videos + +[LanGuard 10 *] +LangSecRef=3022 +DetectFile=%CommonAppData%\GFI Software\LanGuard 10 +Default=False +FileKey1=%CommonAppData%\GFI Software\LanGuard 10|newfileslog.* +FileKey2=%CommonAppData%\GFI Software\LanGuard 10\*Logs|*.*|RECURSE +FileKey3=%CommonAppData%\GFI Software\LanGuard 10\Cache|*.*|REMOVESELF +FileKey4=%LocalAppData%\VirtualStore\ProgramData\GFI Software\LanGuard 10|newfileslog.* +FileKey5=%LocalAppData%\VirtualStore\ProgramData\GFI Software\LanGuard 10\*Logs|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\GFI Software\LanGuard 10\Cache|*.*|REMOVESELF + +[Launchy *] +LangSecRef=3021 +DetectFile=%AppData%\Launchy +Default=False +FileKey1=%AppData%\Launchy\*-icon-cache|*.* + +[Lavender's Botanicals *] +Section=Games +DetectFile=%AppData%\MysteryStudio\Lavender +Default=False +FileKey1=%AppData%\MysteryStudio\Lavender|*.log + +[League of Legends *] +Section=Games +Detect1=HKCU\Software\Bugsplat\lol_beta_riotgames_com +Detect2=HKCU\Software\Riot Games +Detect3=HKLM\Software\Riot Games +Default=False +FileKey1=%AppData%\LolClient*|*.*|RECURSE +FileKey2=%SystemDrive%\Riot Games\League of Legends|*.log*;*.tmp;*.pandurl;Localization_Errors.txt;*r3dlog.txt;*netlog.txt|RECURSE +FileKey3=%UserProfile%\riotsGamesLogs|*.* + +[Leapfrog Connect *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\LeapFrog\LeapFrog Connect\LeapFrogConnect.exe +Default=False +FileKey1=%CommonAppData%\Leapfrog\LeapFrog Connect\cache\*\cookies|*.* +FileKey2=%CommonAppData%\Leapfrog\LeapFrog Connect\cache\*\data7\*|*.* +FileKey3=%CommonAppData%\Leapfrog\LeapFrog Connect\cache\*\http*|*.* +FileKey4=%CommonAppData%\Leapfrog\LeapFrog Connect\cache\*\prepared|*.* +FileKey5=%CommonAppData%\Leapfrog\LeapFrog Connect\DownloadCache|*.* +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Leapfrog\LeapFrog Connect\cache\*\cookies|*.* +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Leapfrog\LeapFrog Connect\cache\*\data7\*|*.* +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Leapfrog\LeapFrog Connect\cache\*\http*|*.* +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Leapfrog\LeapFrog Connect\cache\*\prepared|*.* +FileKey10=%LocalAppData%\VirtualStore\ProgramData\Leapfrog\LeapFrog Connect\DownloadCache|*.* + +[LeapFTP *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\LeapFTP +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\LeapFTP|stats.dat +FileKey2=%ProgramFiles%\LeapFTP|stats.dat + +[Learn2 Player *] +LangSecRef=3023 +DetectFile=%AppData%\Learn2.com +Default=False +FileKey1=%AppData%\Learn2.com\strunner\StCache|*.*|RECURSE +FileKey2=%LocalAppData%\Learn2.com\strunner\StCache|*.*|RECURSE + +[Leawo Prof. Media *] +LangSecRef=3023 +Detect=HKCU\Software\Leawo Software\SoftwarePassport\Leawo Prof. Media +Default=False +FileKey1=%AppData%\Leawo\Prof. Media|*.xml +FileKey2=%AppData%\Leawo\Prof. Media\Burn|*.log +FileKey3=%AppData%\Leawo\Prof. Media\Burn\MenuTemplate\Cache|*.*|RECURSE +FileKey4=%AppData%\Leawo\Prof. Media\CrashReport|*.*|RECURSE +FileKey5=%AppData%\Leawo\Prof. Media\Download|*.dat;*.db;*log;*.xml +FileKey6=%AppData%\Leawo\Prof. Media\Download\Thumbnails|*.*|RECURSE +FileKey7=%AppData%\Leawo\Prof. Media\Download\WebCache|*.*|RECURSE +FileKey8=%AppData%\Leawo\Prof. Media\Download\WebFiles|*.*|RECURSE +FileKey9=%AppData%\Leawo\Prof. Media\Log|*.*|RECURSE +FileKey10=%LocalAppData%\Leawo Prof\cache|*.*|RECURSE + +[Leawo Video Converter *] +LangSecRef=3023 +DetectFile=%AppData%\Leawo\Video Converter* +Default=False +FileKey1=%AppData%\Leawo\Video Converter*|*.log +FileKey2=%AppData%\Leawo\Video Converter*\CrashReport|*.*|RECURSE +FileKey3=%LocalAppData%\Video Converter*\cache|*.*|RECURSE + +[LEGO Universe *] +Section=Games +DetectFile=%LocalAppData%\LEGO Software\LEGO Universe +Default=False +FileKey1=%LocalAppData%\LEGO Software\LEGO Universe\Log Files|*.* + +[Lenovo SWTOOLS *] +LangSecRef=3025 +DetectFile=%SystemDrive%\SWTOOLS +Default=False +FileKey1=%SystemDrive%\SWTOOLS|*.*|REMOVESELF + +[Lenovo System Update *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Lenovo\SystemUpdate\sessionSE\Repository +Default=False +FileKey1=%CommonAppData%\Lenovo\SystemUpdate\sessionSE\Repository|*.*|RECURSE +FileKey2=%CommonAppData%\Lenovo\SystemUpdate\sessionSE\system\SSClientCommon|*.xml + +[Leviev Sales Information Portal *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Leviev Sales Information Portal +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\JMS|JMSErrors.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Leviev Sales Information Portal|JMSErrors.txt +FileKey3=%ProgramFiles%\JMS|JMSErrors.txt +FileKey4=%ProgramFiles%\Leviev Sales Information Portal|JMSErrors.txt + +[Lexmark Logs *] +LangSecRef=3021 +DetectFile=%CommonAppData%\gn_logs +Default=False +FileKey1=%CommonAppData%\gn_logs\*|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\gn_logs\*|*.* + +[Lexmark Photo Editor *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Lexmark 5200 Series\pheditor.exe +Default=False +RegKey1=HKCU\Software\LexmarkPhoto\Lexmark Photo Software\pheditor\Recent File List + +[Lexware Logs *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Lexware +Default=False +FileKey1=%AppData%\Lexware|*.log|RECURSE +FileKey2=%CommonAppData%\Lexware|*.log;*.logx|RECURSE +FileKey3=%CommonAppData%\Lexware\elster\Log|*.*|REMOVESELF +FileKey4=%CommonAppData%\Lexware\logs|*.*|REMOVESELF +FileKey5=%CommonProgramFiles%\Lexware|*.log|RECURSE +FileKey6=%LocalAppData%\Lexware|*.log;*.logx|RECURSE +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Common Files\Lexware|*.log|RECURSE +FileKey8=%LocalAppData%\VirtualStore\Program Files*\Lexware|*.log|RECURSE +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Lexware|*.log;*.logx|RECURSE +FileKey10=%LocalAppData%\VirtualStore\ProgramData\Lexware\elster\Log|*.*|REMOVESELF +FileKey11=%LocalAppData%\VirtualStore\ProgramData\Lexware\logs|*.*|REMOVESELF +FileKey12=%ProgramFiles%\Lexware|*.log|RECURSE +FileKey13=%SystemDrive%|LxDasi.Log + +[LibreOffice *] +LangSecRef=3021 +Detect=HKLM\Software\LibreOffice +Default=False +FileKey1=%AppData%\LibreOffice\*\User\backup|*.* +FileKey2=%AppData%\LibreOffice\*\User\extensions\shared|log.* +FileKey3=%AppData%\LibreOffice\*\User\temp|*.* +FileKey4=%AppData%\LibreOffice\*\User\uno_packages\cache|log.* +FileKey5=%ProgramFiles%\LibreOffice *.*\program_old*|*.*|REMOVESELF + +[LifeCam *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.LifeCamDashboard_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.LifeCamDashboard_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.LifeCamDashboard_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.LifeCamDashboard_*\AC\PRICache|*.* +FileKey3=%LocalAppData%\Packages\Microsoft.LifeCamDashboard_*\AC\Temp|*.* +FileKey4=%LocalAppData%\Packages\Microsoft.LifeCamDashboard_*\TempState|*.*|RECURSE + +[LightScribe *] +LangSecRef=3023 +Detect=HKCU\Software\LightScribe +Default=False +FileKey1=%CommonAppData%\LightScribe\log|*.xml +FileKey2=%LocalAppData%\VirtualStore\ProgramData\LightScribe\log|*.xml + +[LightShot *] +LangSecRef=3022 +DetectFile=%LocalAppData%\Skillbrains\lightshot +Default=False +FileKey1=%LocalAppData%|updater.log + +[Lili: Child of Geos - Complete Edition *] +Section=Games +Detect=HKCU\Software\Valve\Steam\apps\266490 +Default=False +FileKey1=%Documents%\my games\UnrealEngine3-MazeGame\MazeGame\Logs|*.* + +[LimeWire *] +LangSecRef=3022 +Detect=HKLM\Software\LimeWire +Default=False +FileKey1=%AppData%\LimeWire|fileurns.cache;createtimes.cache;responses.cache;ttree.cache;gnutella.net +FileKey2=%UserProfile%\Incomplete|*.*|RECURSE + +[LinkAlyzer *] +LangSecRef=3024 +Detect=HKCU\Software\Sanderson Forensics\LinkAlyzer +Default=False +RegKey1=HKCU\Software\Sanderson Forensics\LinkAlyzer|LastOpenFolder +RegKey2=HKCU\Software\Sanderson Forensics\LinkAlyzer|LastSaveFolder + +[Listary *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Listary_is1 +Default=False +FileKey1=%AppData%\Listary\CrashRpt|*.*|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Listary|*.log +FileKey3=%ProgramFiles%\Listary|*.log + +[Loadout *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\208090 +Default=False +FileKey1=%LocalAppData%\EdgeOfReality\Loudout\CrashReports|*.* + +[LocalService *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Windows +Default=False +FileKey1=%SystemDrive%\Documents and Settings\LocalService*\Cookies|*.*|RECURSE +FileKey2=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\History|*.*|RECURSE +FileKey3=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\Temp|*.*|RECURSE +FileKey4=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\Temporary Internet Files|*.*|RECURSE +FileKey5=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History|*.*|RECURSE +FileKey6=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE +FileKey7=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Temp|*.*|RECURSE +FileKey8=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies|*.*|REMOVESELF +FileKey9=%WinDir%\ServiceProfiles\LocalService\AppData\LocalLow\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey10=%WinDir%\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|REMOVESELF + +[LocalSystem *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE +FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE +FileKey3=%WinDir%\System32\config\systemprofile\AppData\Local\Temp|*.*|RECURSE +FileKey4=%WinDir%\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE +FileKey5=%WinDir%\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE +FileKey6=%WinDir%\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE +FileKey7=%WinDir%\System32\config\SystemProfile\Application Data\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE +FileKey8=%WinDir%\System32\config\SystemProfile\Application Data\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE +FileKey9=%WinDir%\System32\config\SystemProfile\Cookies|*.*|RECURSE +FileKey10=%WinDir%\System32\config\SystemProfile\History|*.*|RECURSE +FileKey11=%WinDir%\System32\config\SystemProfile\Local Settings\Temp|*.*|RECURSE +FileKey12=%WinDir%\System32\config\SystemProfile\Local Settings\Temporary Internet Files|*.*|RECURSE +FileKey13=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE +FileKey14=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Temp|*.*|RECURSE +FileKey15=%WinDir%\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE +FileKey16=%WinDir%\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE +FileKey17=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE +FileKey18=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\History|*.*|RECURSE + +[Lock App *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.LockApp_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.LockApp_*\TempState|*.*|RECURSE + +[LockHunter *] +LangSecRef=3024 +Detect=HKCU\Software\LockHunter +Default=False +FileKey1=%AppData%\LockHunter|*.txt;*.log +FileKey2=%CommonAppData%\LHService|*.txt;*.log + +[Logitech Camera *] +LangSecRef=3023 +DetectFile=%LocalAppData%\LogiShrd +Default=False +FileKey1=%LocalAppData%\LogiShrd\Vid|*.*|RECURSE + +[Logitech Desktop Messenger *] +LangSecRef=3024 +Detect1=HKCU\Software\Logitech\DesktopMessenger +Detect2=HKLM\Software\Logitech\DesktopMessenger +Detect3=HKLM\Software\Logitech\Logitech Desktop Messenger +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Logitech\Desktop Messenger|*.log;*.bak +FileKey2=%ProgramFiles%\Logitech\Desktop Messenger|*.log;*.bak + +[Logitech Harmony Remote Cache *] +LangSecRef=3021 +Detect=HKCU\Software\JavaSoft\Prefs\Com\Logitech\harmony +Default=False +FileKey1=%UserProfile%\Logitech\browser - logitech\Cache|*.* + +[Logitech Logs *] +LangSecRef=3021 +Detect=HKCU\Software\Logitech\Setpoint +DetectFile=%AppData%\LogiShrd +Default=False +FileKey1=%AppData%\Logishrd|*.log|RECURSE +FileKey2=%AppData%\Logishrd\sp6_Log|*.*|REMOVESELF +FileKey3=%AppData%\LogiShrd\Updater|LuUpdater.log;UpdateList.csv +FileKey4=%CommonAppData%\LogiShrd|*.log|RECURSE +FileKey5=%CommonAppData%\Logishrd\unifying|EngineLog.*;*.txt +FileKey6=%CommonAppData%\Logitech\KHAL\Battery|*.log +FileKey7=%CommonProgramFiles%\logishrd|*.log|RECURSE +FileKey8=%LocalAppData%\VirtualStore\ProgramData\LogiShrd|*.log|RECURSE +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Logishrd\unifying|EngineLog.* +FileKey10=%WinDir%\System32|lvcoinst.log + +[LogMeIn Hamachi *] +LangSecRef=3022 +Detect=HKLM\Software\LogMeIn, Inc. +Default=False +FileKey1=%WinDir%\System32\config\systemprofile\*\*\LogMeIn Hamachi|h2-engine.log;h2-ui.log;*.old;*.bak +FileKey2=%WinDir%\SysWOW64\config\systemprofile\*\*\LogMeIn Hamachi|h2-engine.log;h2-ui.log;*.old;*.bak + +[LoL Summonerinfo *] +Section=Games +DetectFile=%ProgramFiles%\LSI\logs +Default=False +FileKey1=%ProgramFiles%\LSI\logs|*.* + +[LoL Summonerinfo Replays *] +Section=Games +DetectFile=%ProgramFiles%\LSI\replays +Default=False +Warning=This will delete all your saved replays. +FileKey1=%ProgramFiles%\LSI\replays|*.* + +[LOLReplay *] +Section=Games +Detect=HKCU\Software\LOLReplay +Default=False +FileKey1=%Documents%\LOLReplay|*_log.txt;*.log;*.old|RECURSE + +[Lost Photos *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Lost Photos +Default=False +FileKey1=%LocalAppData%\Lost_Photos\*|ResultSearchFile.info +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Lost Photos\Logs|*.* +FileKey3=%ProgramFiles%\Lost Photos\Logs|*.* + +[LotR Online Launcher *] +Section=Games +DetectFile=%LocalAppData%\Turbine\The Lord of the Rings Online\Launcher +Default=False +FileKey1=%LocalAppData%\The Lord Of The Rings Online|*.log +FileKey2=%LocalAppData%\Turbine|*.log|RECURSE + +[Lotus Notes *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\IBM\Lotus\Notes\Data\Cache.NDK +Default=False +FileKey1=%ProgramFiles%\IBM\Lotus\Notes\Data|Cache.NDK + +[Lunascape6 *] +LangSecRef=3022 +Detect=HKLM\Software\Lunascape Corporation +Default=False +FileKey1=%AppData%\lunascape\Lunascape6\ApplicationData|rebar.bmp +FileKey2=%AppData%\lunascape\Lunascape6\ApplicationData\icons|*.*|RECURSE +FileKey3=%AppData%\lunascape\Lunascape6\ApplicationData\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Lunascape\Lunascape6\applicationdata|rebar.bmp +FileKey5=%ProgramFiles%\Lunascape\Lunascape6\applicationdata|rebar.bmp + +[Lunascape6 Backups *] +LangSecRef=3022 +Detect=HKLM\Software\Lunascape Corporation +Default=False +FileKey1=%AppData%\Lunascape\Lunascape6\backup|*.*|RECURSE + +[Lunascape6 History *] +LangSecRef=3022 +Detect=HKLM\Software\Lunascape Corporation +Default=False +Warning=Note: Lunascape will show you a warning next start up. +FileKey1=%AppData%\lunascape\Lunascape6\ApplicationData|history.ld2 +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Lunascape\Lunascape6\applicationdata|history.ld2 +FileKey3=%ProgramFiles%\Lunascape\Lunascape6\applicationdata|history.ld2 + +[Lupinho.Net Hardlink *] +LangSecRef=3023 +Detect=HKLM\Software\Lupinho.Net +Default=False +FileKey1=%LocalAppData%\Lupinho.Net|*.log|RECURSE + +[Lynx Web Browser *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Lynx - web browser +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Lynx - web browser\tmp|*.* +FileKey2=%ProgramFiles%\Lynx - web browser\tmp|*.* + +[Lyrik *] +LangSecRef=3023 +Detect=HKLM\Software\Lyrik +Default=False +FileKey1=%LocalAppData%\Lyrik|*.* + +[Lyx *] +LangSecRef=3021 +DetectFile=%AppData%\LyX2.0 +Default=False +FileKey1=%AppData%\LyX2.0|*.log|RECURSE +FileKey2=%AppData%\LyX2.0\Cache|*.*|RECURSE + +[Macaw *] +LangSecRef=3022 +DetectFile=%AppData%\Macaw +Default=False +FileKey1=%AppData%\Macaw\cef_data|cookies*.*;data*.;index. +FileKey2=%AppData%\Macaw\cef_data\gpucache|*.*|RECURSE +FileKey3=%AppData%\Macaw\cef_data\Local Storage|*.* + +[Machete *] +LangSecRef=3023 +Detect=HKCU\Software\MacheteSoft\Machete +DetectFile=%ProgramFiles%\MacheteSoft\Machete\Machete.exe +Default=False +FileKey1=%AppData%\Machete|MacheteSettings.xml.bak +RegKey1=HKCU\Software\Local AppWizard-Generated Applications\Machete\Recent File List +RegKey2=HKCU\Software\MacheteSoft\Machete\Recent File List + +[Macrium Reflect *] +LangSecRef=3024 +Detect=HKCU\Software\Macrium\Reflect +Default=False +FileKey1=%CommonAppData%\Macrium|*.log|RECURSE +FileKey2=%CommonAppData%\Macrium\Reflect|*.html;*.vsslog +FileKey3=%CommonAppData%\Macrium\waik|waiklog.txt +FileKey4=%SystemDrive%|ref~tmp~.txt;Reflect_Install.log;rescuepe.log + +[Macromedia Shockwave *] +LangSecRef=3023 +Detect1=HKCU\Software\Macromedia\Shockwave 8 +Detect2=HKCU\Software\Macromedia\Shockwave 9 +Default=False +RegKey1=HKCU\Software\Macromedia\Shockwave 8\movies +RegKey2=HKCU\Software\Macromedia\Shockwave 9\movies + +[Magicka *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\42910 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\magicka|errorReport*.txt +FileKey2=%ProgramFiles%\Steam\steamapps\common\magicka|errorReport*.txt + +[MAGIX Installation Manager *] +LangSecRef=3023 +Detect=HKCU\Software\Magix\MAGIX Installation manager +Default=False +FileKey1=%CommonAppData%\MAGIX\*|*.log;*.reg +FileKey2=%CommonAppData%\MAGIX\*\download|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\MAGIX\*|*.log;*.reg +FileKey4=%LocalAppData%\VirtualStore\ProgramData\MAGIX\*\download|*.*|RECURSE + +[MAGIX Video Easy TERRATEC Edition *] +LangSecRef=3023 +Detect=HKLM\Software\MAGIX\Video_easy_3_TerraTec +Default=False +FileKey1=%AppData%\MAGIX\Video_easy_TERRATEC_Edition|*.log|RECURSE + +[MAGIX Video Pro *] +LangSecRef=3023 +Detect1=HKCU\Software\MAGIX AG\Videodeluxe18_pro +Detect2=HKCU\Software\MAGIX AG\Videodeluxe19_pro +Default=False +FileKey1=%AppData%\MAGIX\Video*Pro*|*.log +FileKey2=%Documents%\MAGIX\Video*Pro*\AudioTemp|*.*|RECURSE +RegKey1=HKCU\Software\MAGIX AG\Videodeluxe19_pro\ExportConfigurator\DialogItems|LastFile +RegKey2=HKCU\Software\MAGIX AG\Videodeluxe19_pro\ExportConfigurator\DialogItems|LastPreset + +[MakeHuman *] +LangSecRef=3021 +DetectFile=%Documents%\makehuman +Default=False +FileKey1=%Documents%\makehuman\v1|makehuman.log;makehuman-debug.txt;python_err.txt;python_out.txt +FileKey2=%Documents%\makehuman\v1\cache|*.mhc + +[MAL Updater *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\Mal Updater 2\MalUpdater.exe +Default=False +FileKey1=%AppData%\Mal Updater\*Pics|*.* +FileKey2=%AppData%\Mal Updater\SeasonData|*.* +FileKey3=%AppData%\Mal Updater\Users|*.log|RECURSE + +[Malwarebytes Anti-Exploit *] +LangSecRef=3024 +Detect=HKLM\System\CurrentControlSet\Services\MbaeSvc +DetectFile=%CommonAppData%\Malwarebytes Anti-Exploit +Default=False +FileKey1=%CommonAppData%\Malwarebytes Anti-Exploit|*.log;mbae-default.log.bak;mbae-protector.xpe.bak +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Malwarebytes Anti-Exploit|*.log;mbae-default.log.bak;mbae-protector.xpe.bak +FileKey3=%ProgramFiles%\Malwarebytes Anti-Exploit|mbae-uninstall.log;changelog.txt + +[Malwarebytes Anti-Malware *] +LangSecRef=3024 +Detect=HKCU\Software\Malwarebytes +DetectFile=%ProgramFiles%\Malwarebytes Anti-Malware\mbam.exe +Default=False +Warning=You must manually and temporarily turn off Malwarebytes "self-protection" to remove the logs. +FileKey1=%AppData%\Malwarebytes\Malwarebytes*Anti-Malware\Logs|*.* +FileKey2=%CommonAppData%\Malwarebytes\Malwarebytes*Anti-Malware|mbam-setup.exe +FileKey3=%CommonAppData%\Malwarebytes\Malwarebytes*Anti-Malware\Logs|*.* +FileKey4=%CommonAppData%\Malwarebytes\MBAMService|*.log;*.bak;*.regtrans-ms;*.TM.blf;*-ntuser.dat;*.LOG1;*.LOG2;*-UsrClass.dat +FileKey5=%CommonAppData%\Malwarebytes\MBAMService\logs|*.* +FileKey6=%CommonAppData%\Malwarebytes\MBAMService\ScanResults|*.* +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Malwarebytes\Malwarebytes*Anti-Malware|mbam-setup.exe +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Malwarebytes\Malwarebytes*Anti-Malware\Logs|*.* + +[ManiaPlanet *] +Section=Games +DetectFile=%CommonAppData%\ManiaPlanet +Default=False +FileKey1=%CommonAppData%\ManiaPlanet\Cache|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\ManiaPlanet\Cache|*.* + +[ManyCam *] +LangSecRef=3023 +Detect1=HKCU\Software\ManyCam +Detect2=HKLM\Software\ManyCam +Default=False +FileKey1=%AppData%\ManyCam\Settings\MoviesThumbnails|*.*|RECURSE +FileKey2=%LocalAppData%\ManyCam|*.log|RECURSE +FileKey3=%LocalAppData%\ManyCam\cache\gallery|*.*|RECURSE + +[Maps *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsMaps_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\TempState|*.*|RECURSE + +[Marine Sharpshooter 3 *] +Section=Games +DetectFile=%ProgramFiles%\Groove Games\Marine Sharpshooter 3 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Groove Games\Marine Sharpshooter 3|*.dmp;*.mdmp|RECURSE +FileKey2=%ProgramFiles%\Groove Games\Marine Sharpshooter 3|*.dmp;*.mdmp|RECURSE + +[Mass Downloader *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Mass Downloader +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Mass Downloader|*.bak;massdown.dat;history.dat|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Mass Downloader\Index|*.*|RECURSE +FileKey3=%ProgramFiles%\Mass Downloader|*.bak;massdown.dat;history.dat|RECURSE +FileKey4=%ProgramFiles%\Mass Downloader\Index|*.*|RECURSE + +[Mass Effect *] +Section=Games +Detect1=HKLM\Software\BioWare\Mass Effect +Detect2=HKLM\Software\BioWare\Mass Effect 2 +Detect3=HKLM\Software\BioWare\Mass Effect 3 +Default=False +FileKey1=%Documents%\BioWare\Mass Effect*\BIOGame\Logs|*.* +FileKey2=%Documents%\BioWare\Mass Effect*\Logs|*.* + +[MassTube *] +LangSecRef=3024 +DetectFile1=%AppData%\MassTube\MassTube.exe +DetectFile2=%LocalAppData%\MassTube\MassTube.exe +DetectFile3=%ProgramFiles%\MassTube\MassTube.exe +DetectFile4=%SystemDrive%\Programs\MassTube\MassTube.exe +Default=False +FileKey1=%AppData%\MassTube|Historial.dat +FileKey2=%AppData%\MassTube\Miniaturas|*.jpg +FileKey3=%LocalAppData%\MassTube|Historial.dat +FileKey4=%LocalAppData%\MassTube\Miniaturas|*.jpg +FileKey5=%ProgramFiles%\MassTube|Historial.dat +FileKey6=%ProgramFiles%\MassTube\Miniaturas|*.jpg +FileKey7=%SystemDrive%\Programs\MassTube|Historial.dat +FileKey8=%SystemDrive%\Programs\MassTube\Miniaturas|*.jpg + +[Mavis Beacon *] +LangSecRef=3021 +DetectFile=%AppData%\Broderbund\Mavis +Default=False +FileKey1=%AppData%\Broderbund\Mavis|logfile.* + +[Maxprog iCash *] +LangSecRef=3021 +Detect=HKCR\iCash +Default=False +FileKey1=%Documents%\Maxprog\iCash\Database Logs|*.*|REMOVESELF +FileKey2=%Documents%\Maxprog\iCash\Error Logs|*.*|REMOVESELF +FileKey3=%Documents%\Maxprog\iCash\XML Dumps|*.*|REMOVESELF +FileKey4=%LocalAppData%\VirtualStore\Program Files*\iCash\vlogs|*.*|REMOVESELF +FileKey5=%ProgramFiles%\iCash\vlogs|*.*|REMOVESELF + +[Maxthon Browser *] +LangSecRef=3022 +Detect1=HKCU\Software\Maxthon +Detect2=HKCU\Software\Maxthon2 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Maxthon*\Temp|*.* +FileKey2=%ProgramFiles%\Maxthon*\Temp|*.* + +[Maxthon Browser 3 Backups *] +LangSecRef=3022 +Detect=HKCU\Software\Maxthon3 +Default=False +FileKey1=%AppData%\Maxthon3\Users\*\backup|*.*|RECURSE + +[Maxthon Browser 3 Cookies *] +LangSecRef=3022 +Detect=HKCU\Software\Maxthon3 +Default=False +FileKey1=%AppData%\Maxthon3\Users\*\Cookie|cookie.dat + +[Maxthon Browser 3 History *] +LangSecRef=3022 +Detect=HKCU\Software\Maxthon3 +Default=False +FileKey1=%AppData%\Maxthon3\Users\*\History|history.dat;lasttab.dat + +[Maxthon Browser 3 LocalStorage *] +LangSecRef=3022 +Detect=HKCU\Software\Maxthon3 +Default=False +FileKey1=%AppData%\Maxthon3\Users\*\LocalStorage|*.*|RECURSE + +[McAfee *] +LangSecRef=3024 +Detect=HKLM\Software\McAfee +Default=False +FileKey1=%CommonAppData%\McAfee\AMCore\datreputation\Logs|*.*|RECURSE +FileKey2=%CommonAppData%\McAfee\Common Framework\AgentEvents|*.* +FileKey3=%CommonAppData%\McAfee\CSP\ETW|*.bak +FileKey4=%CommonAppData%\McAfee\Jcm|*.tmp +FileKey5=%CommonAppData%\McAfee\MCLOGS|*.bak;*.log|RECURSE +FileKey6=%CommonAppData%\McAfee\MHN|*.bak +FileKey7=%CommonAppData%\McAfee\modulecoreservice.exe|*.txt +FileKey8=%CommonAppData%\McAfee\MPF|*.tmp +FileKey9=%CommonAppData%\McAfee\MPF\data|*.*|RECURSE +FileKey10=%CommonAppData%\McAfee\MSC\Logs|*.log +FileKey11=%CommonAppData%\McAfee\SiteAdvisor|*.txt|RECURSE +FileKey12=%CommonAppData%\McAfee\Update|*.*|RECURSE +FileKey13=%CommonAppData%\McAfee\VirusScan\Data|*.log;*.old +FileKey14=%CommonAppData%\McAfee\VirusScan\Logs|*.*|RECURSE +FileKey15=%CommonAppData%\Network Associates\Common Framework\AgentEvents|*.* +FileKey16=%LocalAppData%\VirtualStore\ProgramData\McAfee\AMCore\datreputation\Logs|*.*|RECURSE +FileKey17=%LocalAppData%\VirtualStore\ProgramData\McAfee\Common Framework\AgentEvents|*.* +FileKey18=%LocalAppData%\VirtualStore\ProgramData\McAfee\CSP\ETW|*.bak +FileKey19=%LocalAppData%\VirtualStore\ProgramData\McAfee\Jcm|*.tmp +FileKey20=%LocalAppData%\VirtualStore\ProgramData\McAfee\MCLOGS|*.bak;*.log|RECURSE +FileKey21=%LocalAppData%\VirtualStore\ProgramData\McAfee\MHN|*.bak +FileKey22=%LocalAppData%\VirtualStore\ProgramData\McAfee\modulecoreservice.exe|*.txt +FileKey23=%LocalAppData%\VirtualStore\ProgramData\McAfee\MPF|*.tmp +FileKey24=%LocalAppData%\VirtualStore\ProgramData\McAfee\MPF\data|*.*|RECURSE +FileKey25=%LocalAppData%\VirtualStore\ProgramData\McAfee\MSC\Logs|*.log +FileKey26=%LocalAppData%\VirtualStore\ProgramData\McAfee\SiteAdvisor|*.txt|RECURSE +FileKey27=%LocalAppData%\VirtualStore\ProgramData\McAfee\Update|*.*|RECURSE +FileKey28=%LocalAppData%\VirtualStore\ProgramData\McAfee\VirusScan\Data|*.log;*.old +FileKey29=%LocalAppData%\VirtualStore\ProgramData\McAfee\VirusScan\Logs|*.*|RECURSE +FileKey30=%LocalAppData%\VirtualStore\ProgramData\Network Associates\Common Framework\AgentEvents|*.* + +[McPixel *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\220860 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\mcpixel|log.txt +FileKey2=%ProgramFiles%\Steam\Steamapps\common\mcpixel|log.txt + +[Media Center 18 *] +LangSecRef=3023 +Detect=HKCU\Software\J. River\Media Center 18 +Default=False +FileKey1=%AppData%\J River\Media Center 18\Library|field (filename).jmd;field (name).jmd +FileKey2=%Documents%\J River\Media Center 18\Library|*.*|RECURSE + +[Media Jukebox *] +LangSecRef=3023 +Detect=HKCU\Software\J. River\Music Exchange\1.0\Media Jukebox +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\J River\Media Jukebox\Data|*.jmd +FileKey2=%ProgramFiles%\J River\Media Jukebox\Data|*.jmd + +[Media Play Ready Client *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Media.PlayReadyClient_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\PRICache|*.* +FileKey7=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\Temp|*.* +FileKey8=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\LocalState\Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\LocalState\navigationHistory|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\TempState|*.*|RECURSE + +[Media Player Classic *] +LangSecRef=3023 +Detect1=HKCU\Software\Gabest\Media Player Classic +Detect2=HKCU\Software\MPC-BE +Detect3=HKCU\Software\MPC-HC\MPC-HC +Default=False +FileKey1=%AppData%\Media Player Classic|*.dmp +FileKey2=%AppData%\MPC-*|*.dmp +RegKey1=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 0 +RegKey2=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 1 +RegKey3=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 2 +RegKey4=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 3 +RegKey5=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 4 +RegKey6=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 5 +RegKey7=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 6 +RegKey8=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 7 +RegKey9=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 8 +RegKey10=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 9 +RegKey11=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 10 +RegKey12=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 11 +RegKey13=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 12 +RegKey14=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 13 +RegKey15=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 14 +RegKey16=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 15 +RegKey17=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 16 +RegKey18=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 17 +RegKey19=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 18 +RegKey20=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 19 +RegKey21=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 20 + +[MegaCloud *] +LangSecRef=3022 +DetectFile=%AppData%\MegaCloud +Default=False +FileKey1=%AppData%\MegaCloud|*.log|RECURSE +FileKey2=%AppData%\MegaCloud\AutoUpdate\Temp|*.*|RECURSE + +[MemoMaster 5 *] +LangSecRef=3021 +Detect=HKCU\Software\JBSoftware\MemoMaster5 +Default=False +RegKey1=HKCU\Software\JBSoftware\MemoMaster5|FileMRU1 +RegKey2=HKCU\Software\JBSoftware\MemoMaster5|FileMRU2 +RegKey3=HKCU\Software\JBSoftware\MemoMaster5|FileMRU3 +RegKey4=HKCU\Software\JBSoftware\MemoMaster5|FileMRU4 +RegKey5=HKCU\Software\JBSoftware\MemoMaster5|FileMRU5 +RegKey6=HKCU\Software\JBSoftware\MemoMaster5|FileMRU6 +RegKey7=HKCU\Software\JBSoftware\MemoMaster5|FileMRU7 +RegKey8=HKCU\Software\JBSoftware\MemoMaster5|FileMRU8 +RegKey9=HKCU\Software\JBSoftware\MemoMaster5|FileMRU9 +RegKey10=HKCU\Software\JBSoftware\MemoMaster5|FileMRU10 +RegKey11=HKCU\Software\JBSoftware\MemoMaster5|FileMRU11 +RegKey12=HKCU\Software\JBSoftware\MemoMaster5|FileMRU12 +RegKey13=HKCU\Software\JBSoftware\MemoMaster5|FileMRU13 +RegKey14=HKCU\Software\JBSoftware\MemoMaster5|FileMRU14 +RegKey15=HKCU\Software\JBSoftware\MemoMaster5|FileMRU15 + +[Men of War *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\3130 +Detect2=HKCU\Software\Valve\Steam\Apps\7830 +Detect3=HKCU\Software\Valve\Steam\Apps\63940 +Detect4=HKCU\Software\Valve\Steam\Apps\64000 +Detect5=HKCU\Software\Valve\Steam\Apps\204860 +Default=False +FileKey1=%Documents%\My Games\men of war*\log|*.* +FileKey2=%Documents%\My Games\men of war*\shader_cache|*.*|RECURSE +FileKey3=%Documents%\My Games\mow *\log|*.* +FileKey4=%Documents%\My Games\mow *\shader_cache|*.*|RECURSE + +[Mention *] +LangSecRef=3022 +Detect=HKCU\Software\Mention +Default=False +FileKey1=%LocalAppData%\Mention\Mention|WebpageIcons.db;cookies +FileKey2=%LocalAppData%\Mention\Mention\Cache|*.*|RECURSE +FileKey3=%LocalAppData%\Mention\Mention\LocalStorage|*.*|RECURSE + +[Messaging *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Messaging_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Messaging_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Messaging_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.Messaging_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.Messaging_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.Messaging_*\LocalCache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.Messaging_*\LocalState\Cache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.Messaging_*\TempState|*.*|RECURSE + +[Messenger Plus! Live *] +LangSecRef=3022 +Detect=HKCU\Software\Patchou +Default=False +FileKey1=%Documents%\My Chat Logs|*.*|RECURSE + +[Metadata Analyzer *] +LangSecRef=3024 +Detect=HKCU\Software\Smart PC Solutions\Metadata Analyzer +Default=False +RegKey1=HKCU\Software\Smart PC Solutions\Metadata Analyzer|LastFile +RegKey2=HKCU\Software\Smart PC Solutions\Metadata Analyzer|LastFolder + +[Metamorphose *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\metamorphose\metamorphose.exe +Default=False +FileKey1=%AppData%\.metamorphose\undo|*.* + +[Metapad *] +LangSecRef=3021 +Detect=HKCU\Software\metapad +Default=False +RegKey1=HKCU\Software\metapad|szLastDirectory + +[MetaX *] +LangSecRef=3024 +Detect=HKCU\Software\No Bull Software\MetaX +Default=False +FileKey1=%Documents%\MetaX|*.log +RegKey1=HKCU\Software\No Bull Software\MetaX\Preferences|lastDir + +[MetroTwit *] +LangSecRef=3022 +DetectFile=%AppData%\MetroTwit +Default=False +FileKey1=%AppData%\MetroTwit|MetroTwit.backup +FileKey2=%AppData%\MetroTwit\*|User.cache;User.backup +FileKey3=%AppData%\MetroTwit\*\User_Images|*.*|RECURSE + +[Microangelo *] +LangSecRef=3021 +Detect1=HKCU\Software\Eclipsit\Microangelo\Toolset 6 +Detect2=HKCU\Software\Impact\Microangelo +Default=False +RegKey1=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Animator\MRU List +RegKey2=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Librarian\MRU List +RegKey3=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Studio\MRU List +RegKey4=HKCU\Software\Impact\Microangelo\Animator\MRU List +RegKey5=HKCU\Software\Impact\Microangelo\Librarian\MRU List +RegKey6=HKCU\Software\Impact\Microangelo\Studio\MRU List + +[Microsoft Bing Bar *] +LangSecRef=3021 +Detect=HKCU\Software\AppDataLow\Software\Microsoft\BingBar +Default=False +FileKey1=%LocalAppData%\Microsoft\BingBar\Apps|*.tmp|RECURSE + +[Microsoft Deployment Toolkit *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Microsoft Deployment Toolkit +Default=False +Warning=To Get a new Component list, check for Updates in the Management Console! +FileKey1=%ProgramFiles%\Microsoft Deployment Toolkit\Downloads|*.*|RECURSE + +[Microsoft Edge *] +LangSecRef=3022 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\#!00*\INetCookies|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\#!00*\Microsoft\Cryptnet*Cache|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\#!00*\MicrosoftEdge\Cookies|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\Microsoft\Cryptnet*Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\Cookies|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\UrlBlock|*.tmp +FileKey7=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\DataStore\Data\nouser1\*\DBStore|V01*.log;V01*.jrs +FileKey8=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\DataStore\Indexed\Data\nouser1\*|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\ImageStore|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\Recovery\Active|*.dat +FileKey11=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\Temp|*.*|RECURSE +FileKey12=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AppData\User\Default\Indexed DB|*.*|RECURSE +FileKey13=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\LocalState\Favicons\PushNotificationGrouping|*.*|RECURSE +FileKey14=%UserProfile%\MicrosoftEdgeBackups\backups\*|*.*|REMOVESELF +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Recovery\PendingDelete +RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\PersistedPickerData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge\DefaultOpenFileMultiple +RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\PersistedPickerData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge\DefaultOpenFileSingle +RegKey4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\PersistedPickerData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge\DefaultSaveFileSingle + +[Microsoft Edge Favorites Icons *] +LangSecRef=3022 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe +Default=False +Warning=This will delete all the icons of your favorites. The icons will be rebuilt as websites are manually re-visited. +FileKey1=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\Datastore\Data\nouser1\*\Favorites|*.ico + +[Microsoft Expression Web *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Expression\Web Designer +Default=False +RegKey1=HKCU\Software\Microsoft\Expression\Web Designer\FindMRU + +[Microsoft Flight Simulator X *] +Section=Games +Detect=HKLM\Software\Microsoft\Microsoft Games\Flight Simulator\10.0 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Microsoft Games\Microsoft Flight Simulator X|*.log;*.rtf;*.html;*.URL +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Microsoft Games\Microsoft Flight Simulator X\Modules|*.log +FileKey3=%ProgramFiles%\Microsoft Games\Microsoft Flight Simulator X|*.log;*.rtf;*.html;*.URL +FileKey4=%ProgramFiles%\Microsoft Games\Microsoft Flight Simulator X\Modules|*.log +ExcludeKey1=PATH|%ProgramFiles%\Microsoft Games\Microsoft Flight Simulator X\|*kiosk.rtf;*readme.rtf;*Readme.htm + +[Microsoft Message Analyzer *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Microsoft\MessageAnalyzer +Default=False +FileKey1=%Documents%\MessageAnalyzer\Traces|*.*|RECURSE +FileKey2=%LocalAppData%\Microsoft\MessageAnalyzer|*.log + +[Microsoft Mouse and Keyboard Center *] +LangSecRef=3021 +DetectFile1=%ProgramFiles%\Microsoft Device Center +DetectFile2=%ProgramFiles%\Microsoft Mouse and Keyboard Center +Default=False +Warning=This will also delete all app-specific settings. +RegKey1=HKCU\Software\Microsoft\IntelliPoint\AppSpecific +RegKey2=HKCU\Software\Microsoft\IntelliType Pro\AppSpecific + +[Microsoft Outlook Express 5.0 *] +LangSecRef=3022 +Detect=HKCU\Identities\{9745A9A1-95D3-4584-B4E8-C9C2374B3BD3}\Software\Microsoft\Outlook Express\5.0 +Default=False +RegKey1=HKCU\Identities\{9745A9A1-95D3-4584-B4E8-C9C2374B3BD3}\Software\Microsoft\Outlook Express\5.0\Recent Stationery List + +[Microsoft Project 2010 *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\Office\14.0\MS Project +Default=False +RegKey1=HKCU\Software\Microsoft\Office\14.0\MS Project\Recent File List +RegKey2=HKCU\Software\Microsoft\Office\14.0\MS Project\Recent Templates + +[Microsoft Reader *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Reader_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.Reader_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Reader_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Reader_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.Reader_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.Reader_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\Microsoft.Reader_*\AC\PRICache|*.* +FileKey6=%LocalAppData%\Packages\Microsoft.Reader_*\AC\Temp|*.* +FileKey7=%LocalAppData%\Packages\Microsoft.Reader_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Reader_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp +RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Reader_8wekyb3d8bbwe\SearchHistory + +[Microsoft Security Essentials *] +LangSecRef=3021 +Detect1=HKCU\Software\Microsoft\Microsoft Antimalware +Detect2=HKLM\Software\Microsoft\Microsoft Antimalware +Default=False +FileKey1=%CommonAppData%\Microsoft\Microsoft Antimalware\LocalCopy|*.*|RECURSE +FileKey2=%CommonAppData%\Microsoft\Microsoft Antimalware\Network Inspection System\Support|NisLog.txt.bak +FileKey3=%CommonAppData%\Microsoft\Microsoft Antimalware\Scans\History\Service|*.log|RECURSE +FileKey4=%CommonAppData%\Microsoft\Microsoft Security Client\Support|MSSecurityClient*.log +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Service|*.log|RECURSE +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft Security Client\Support|MSSecurityClient*.log + +[Microsoft Silverlight *] +LangSecRef=3023 +Detect=HKCU\Software\Microsoft\Silverlight +Default=False +FileKey1=%LocalLowAppData%\Microsoft\Silverlight|*.*|RECURSE + +[Microsoft Standalone System Sweeper Tool *] +LangSecRef=3024 +Detect=HKCU\Software\Microsoft\Microsoft Standalone System Sweeper Tool +Default=False +FileKey1=%CommonAppData%\Microsoft\Microsoft Standalone System Sweeper Tool\Support|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft Standalone System Sweeper Tool\Support|*.log + +[Microsoft Ultimate Word Games *] +Section=Games +DetectFile=%LocalAppData%\Packages\Microsoft.Studios.Wordament_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Studios.Wordament_*\TempState|*.log + +[Microsoft XNA Game Studio *] +Section=Games +Detect=HKLM\Software\Microsoft\XNA +Default=False +FileKey1=%ProgramFiles%\Microsoft XNA\XNA Game Studio\*\Redist|*.*|REMOVESELF + +[Microsoft.VCLibs *] +LangSecRef=3031 +Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.VCLibs.110.00_8wekyb3d8bbwe +Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.VCLibs.120.00_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.VCLibs.1*0.00_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\PRICache|*.* +FileKey7=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Temp|*.* +FileKey8=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\LocalState\Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\LocalState\navigationHistory|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\TempState|*.*|RECURSE + +[Midori *] +LangSecRef=3022 +Detect=HKLM\Software\Midori +Default=False +FileKey1=%LocalAppData%\Microsoft\Windows\Temporary Internet Files\Midori|*.*|RECURSE +FileKey2=%LocalAppData%\Midori|cookies.db;history.*;session.xbel + +[Migration Wizard *] +LangSecRef=3025 +DetectFile=%WinDir%\System32\migwiz\migwiz.exe +Default=False +FileKey1=%LocalAppData%\MigWiz|*.*|REMOVESELF + +[MiKTeX *] +LangSecRef=3021 +Detect=HKCU\Software\MiKTeX.org\MiKTeX +Default=False +FileKey1=%CommonAppData%\MiKTeX\*\miktex\log|*.log +FileKey2=%LocalAppData%\MiKTeX\*\miktex\log|*.log +FileKey3=%LocalAppData%\VirtualStore\Program Files*\MiKTeX\miktex\config|*.log +FileKey4=%LocalAppData%\VirtualStore\ProgramData\MiKTeX\*\miktex\log|*.log +FileKey5=%ProgramFiles%\MiKTeX\miktex\config|*.log + +[Minecraft *] +Section=Games +DetectFile=%AppData%\.minecraft +Default=False +FileKey1=%AppData%\.minecraft|*.log;*.log.*|RECURSE +FileKey2=%AppData%\.minecraft\crash-reports|*.* +FileKey3=%AppData%\.minecraft\debug|*.* +FileKey4=%AppData%\.minecraft\stats|*.old +FileKey5=%AppData%\java|*.*|REMOVESELF + +[Miranda IM *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Miranda IM +Default=False +FileKey1=%AppData%\Miranda IM\Profiles|*.*|REMOVESELF + +[Miranda IM Chat Log *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Miranda IM +Default=False +FileKey1=%AppData%\Miranda IM\Profiles\*\Logs\Chat|*.*|REMOVESELF + +[mIRC *] +LangSecRef=3022 +Detect=HKCU\Software\mIRC +Default=False +FileKey1=%AppData%\mIRC\Logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\mIRC\logs|*.* +FileKey3=%ProgramFiles%\mIRC\logs|*.* + +[Mirkes.De Tiny Hexer *] +LangSecRef=3021 +Detect=HKCU\Software\mirkes.de\Tiny Hexer +Default=False +FileKey1=%AppData%\mirkes.de\Tiny Hexer\*|*.bak + +[MiTeC DFM Editor *] +LangSecRef=3021 +Detect=HKCU\Software\MiTeC\DFM Editor +Default=False +RegKey1=HKCU\Software\MiTeC\DFM Editor\5.x\Main\MRUHistory + +[MixiDj Toolbar *] +LangSecRef=3022 +DetectFile=%LocalLowAppData%\mixidj_v37 +Default=False +FileKey1=%LocalLowAppData%\mixidj_v37\logs|*.*|RECURSE + +[Mixxx *] +LangSecRef=3023 +DetectFile=%LocalAppData%\Mixxx +Default=False +FileKey1=%LocalAppData%\Mixxx|*.log + +[MKS_Vir Skaner Online *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\SkanerOnline +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\SkanerOnline\Raporty|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\SkanerOnline\tmp|*.* +FileKey3=%ProgramFiles%\SkanerOnline\Raporty|*.* +FileKey4=%ProgramFiles%\SkanerOnline\tmp|*.* +FileKey5=%SystemDrive%|*.cpp.log + +[MMOUI Minion *] +Section=Games +DetectFile=%AppData%\MMOUI\Minion +Default=False +FileKey1=%AppData%\MMOUI\Minion|log.* + +[Mo-Search *] +LangSecRef=3024 +Detect=HKCU\Software\Meauxsoft\Mo-Search +Default=False +FileKey1=%LocalAppData%\Meauxsoft\Mo-Search4.0\Logs|*.* +RegKey1=HKCU\Software\Meauxsoft\Mo-Search\Mo-Search v4.0.13\Last Position + +[Mobile Broadband HL *] +LangSecRef=3021 +DetectFile=%CommonAppData%\MobileBrServ +Default=False +FileKey1=%CommonAppData%\MobileBrServ\log|*.*|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\ProgramData\MobileBrServ\log|*.*|REMOVESELF + +[Mojo *] +LangSecRef=3022 +DetectFile=%AppData%\Deusty\Mojo +Default=False +FileKey1=%AppData%\Deusty\Mojo\*|*.log +FileKey2=%LocalAppData%\Deusty\Mojo|crash*.txt + +[Molotov.tv *] +LangSecRef=3023 +DetectFile=%AppData%\Molotov +Default=False +FileKey1=%AppData%\Molotov|Cookies*;QuotaManager* +FileKey2=%AppData%\Molotov\*Cache|*.* +FileKey3=%AppData%\Molotov\databases|*.* +FileKey4=%AppData%\Molotov\IndexedDB|*.*|RECURSE +FileKey5=%LocalAppData%\Molotov|SquirrelSetup.log + +[MoreTerra *] +Section=Games +DetectFile=%AppData%\MoreTerra +Default=False +FileKey1=%AppData%\MoreTerra\Logs|*.*|RECURSE + +[Morpheus *] +LangSecRef=3023 +Detect=HKCU\Software\Morpheus +Default=False +Warning=This will clear your shared folder and databases. +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Morpheus\DB|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Morpheus\My Shared Folder|*.*|RECURSE +FileKey3=%ProgramFiles%\Morpheus\DB|*.*|RECURSE +FileKey4=%ProgramFiles%\Morpheus\My Shared Folder|*.*|RECURSE + +[Motherboard Monitor 5 *] +LangSecRef=3023 +Detect=HKCU\Software\Alexander van Kaam\MBM 5 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Motherboard Monitor 5\Log|*.*|REMOVESELF +FileKey2=%ProgramFiles%\Motherboard Monitor 5\Log|*.*|REMOVESELF + +[Motorola Device Manager *] +LangSecRef=3024 +DetectFile=%AppData%\Motorola\MotoHelper +Default=False +FileKey1=%AppData%\Motorola\MotoHelper|*.log + +[Mount & Blade *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\22100 +Detect2=HKCU\Software\Valve\Steam\Apps\48700 +Detect3=HKCU\Software\Valve\Steam\Apps\48705 +Detect4=HKCU\Software\Valve\Steam\Apps\48720 +Detect5=HKLM\Software\Mount&Blade +Detect6=HKLM\Software\Mount&Blade Warband +Detect7=HKLM\Software\Mount&Blade With Fire and Sword +Detect8=HKLM\Software\Mount&Blade: Warband - Napoleonic Wars +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Mount&Blade*|rgl_log.txt|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Napoleonic Wars|rgl_log.txt|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Mount&Blade*|rgl_log.txt|RECURSE +FileKey4=%ProgramFiles%\Mount&Blade*|rgl_log.txt|RECURSE +FileKey5=%ProgramFiles%\Napoleonic Wars|rgl_log.txt|RECURSE +FileKey6=%ProgramFiles%\Steam\steamapps\common\Mount&Blade*|rgl_log.txt|RECURSE + +[Mousotron *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Mousotron +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Mousotron|*.log +FileKey2=%ProgramFiles%\Mousotron|*.log + +[Movavi Video Converter *] +LangSecRef=3023 +Detect=HKCU\Software\MOVAVI +Default=False +FileKey1=%LocalAppData%\Movavi\Logs\VideoConverter*|*.* +FileKey2=%LocalAppData%\Movavi\Video Converter|Log.txt + +[Move Media Player *] +LangSecRef=3023 +Detect=HKCU\Software\Move Media Player +Default=False +FileKey1=%AppData%\Move Networks\QMCache00|*.* +FileKey2=%AppData%\Move Networks\temp|*.* + +[Movies & TV *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe* +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\PRICache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Temp|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalCache\PlayReady\Cache|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Database\anonymous|*.log +FileKey11=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageCache|*.*|RECURSE +FileKey12=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageRetrievalFailure|*.*|RECURSE +FileKey13=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageStore|*.*|RECURSE +FileKey14=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\navigationHistory|*.*|RECURSE +FileKey15=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\PlayReady|*.*|RECURSE +FileKey16=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe\SearchHistory\SearchHistory + +[MP3Gain *] +LangSecRef=3023 +Detect=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\MP3Gain|*.log +FileKey2=%ProgramFiles%\MP3Gain|*.log +RegKey1=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis\StartUp|AddFilesPath +RegKey2=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis\StartUp|AddFolderPath +RegKey3=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis\StartUp|ChangeLog +RegKey4=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis\StartUp|ErrLog + +[Mp3Rocket *] +LangSecRef=3023 +DetectFile=%AppData%\Mp3Rocket +Default=False +FileKey1=%AppData%\Mp3Rocket|*.cache + +[Mp3tag *] +LangSecRef=3023 +Detect=HKLM\Software\Florian Heidenreich\Mp3tag +Default=False +FileKey1=%AppData%\Mp3tag|Mp3tagError.log + +[MPEG Audio Collection *] +LangSecRef=3023 +Detect=HKCU\Software\MPEG Audio Collection +Default=False +RegKey1=HKCU\Software\MPEG Audio Collection|LastNameText1 +RegKey2=HKCU\Software\MPEG Audio Collection|LastNameText2 +RegKey3=HKCU\Software\MPEG Audio Collection|LastNameText3 +RegKey4=HKCU\Software\MPEG Audio Collection|LastNameText4 +RegKey5=HKCU\Software\MPEG Audio Collection|LastNameText5 +RegKey6=HKCU\Software\MPEG Audio Collection|LastNameText6 + +[MPlayer *] +LangSecRef=3023 +DetectFile=%LocalAppData%\MPlayer +Default=False +FileKey1=%LocalAppData%\MPlayer|*.cache-3 + +[MS AntiMalware *] +LangSecRef=3025 +DetectFile=%CommonAppData%\Microsoft\Microsoft antimalware +Default=False +Warning=This will make MS Security Essentials think it has never run a scan. +FileKey1=%CommonAppData%\Microsoft\Microsoft antimalware\network inspection system\Support|*.log +FileKey2=%CommonAppData%\Microsoft\Microsoft antimalware\scans\history\results\Quick|*.*|REMOVESELF +FileKey3=%CommonAppData%\Microsoft\Microsoft antimalware\scans\history\results\resource|*.*|REMOVESELF +FileKey4=%CommonAppData%\Microsoft\Microsoft antimalware\scans\history\results\System|*.*|REMOVESELF +FileKey5=%CommonAppData%\Microsoft\Microsoft antimalware\support|*.log;*.txt +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft antimalware\network inspection system\Support|*.log;*.txt +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft antimalware\scans\history\results\Quick|*.*|REMOVESELF +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft antimalware\scans\history\results\resource|*.*|REMOVESELF +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft antimalware\scans\history\results\System|*.*|REMOVESELF +FileKey10=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft antimalware\support|*.log +FileKey11=%SystemDrive%\Documents and Settings\NetworkService*\Temp|MpCmdRun.log +FileKey12=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Temp|MpCmdRun.log + +[MS Backup *] +LangSecRef=3025 +DetectFile=%WinDir%\System32\ntbackup.exe +Default=False +FileKey1=%LocalAppData%\Microsoft\Windows NT\NTBackup\Data|*.log + +[MS Baseline Security Analyzer *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Microsoft Baseline Security Analyzer +Default=False +FileKey1=%LocalAppData%\Microsoft\MBSA\Cache|*.* +FileKey2=%UserProfile%\SecurityScans|*.mbsa + +[MS Clip Organizer *] +LangSecRef=3025 +DetectFile=%AppData%\Microsoft\Clip Organizer +Default=False +FileKey1=%AppData%\Microsoft\Clip Organizer|mstore10.mgc;mstore12.mgc;mstore14.mgc;Offic10.MGC;Offic12.MGC;Offic14.Mgc + +[MS Help Workshop *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Microsoft Help Workshop +Default=False +RegKey1=HKCU\Software\Microsoft\Microsoft Help Workshop\Cnt Files +RegKey2=HKCU\Software\Microsoft\Microsoft Help Workshop\Forage Files +RegKey3=HKCU\Software\Microsoft\Microsoft Help Workshop\Hlp Files +RegKey4=HKCU\Software\Microsoft\Microsoft Help Workshop\Hpj Files +RegKey5=HKCU\Software\Microsoft\Microsoft Help Workshop\Map Files +RegKey6=HKCU\Software\Microsoft\Microsoft Help Workshop\Recent File List + +[MS HTML Help Workshop *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\HTML Help Workshop +Default=False +RegKey1=HKCU\Software\Microsoft\HTML Help Workshop\Compressed HTML +RegKey2=HKCU\Software\Microsoft\HTML Help Workshop\Html Titles +RegKey3=HKCU\Software\Microsoft\HTML Help Workshop\Project Files +RegKey4=HKCU\Software\Microsoft\HTML Help Workshop\Recent File List +RegKey5=HKCU\Software\Microsoft\HTML Help Workshop\Settings|LastProject +RegKey6=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Folders +RegKey7=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Recent File List + +[MS IE6 Installation Temps *] +LangSecRef=3025 +DetectFile1=%SystemDrive%\msdownld.tmp +DetectFile2=%WinDir%\msdownld.tmp +Default=False +FileKey1=%SystemDrive%|msdownld.tmp +FileKey2=%WinDir%|msdownld.tmp + +[MS Imaging *] +LangSecRef=3024 +Detect=HKCU\Software\Kodak\Imaging +Default=False +RegKey1=HKCU\Software\Kodak\Imaging\Recent File List + +[MS Netmeeting *] +LangSecRef=3022 +Detect=HKCU\Software\Microsoft\Conferencing +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\NetMeeting|CallLog.dat +FileKey2=%ProgramFiles%\NetMeeting|CallLog.dat +RegKey1=HKCU\Software\Microsoft\Conferencing\UI\CallMRU + +[MS Notepad *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Notepad +Default=False +RegKey1=HKCU\Software\Microsoft\Notepad|replaceString +RegKey2=HKCU\Software\Microsoft\Notepad|searchString + +[MS Office *] +LangSecRef=3021 +Detect1=HKCU\Software\Microsoft\Office\12.0\Common +Detect2=HKCU\Software\Microsoft\Office\14.0\Common +Detect3=HKCU\Software\Microsoft\Office\15.0\Common +Detect4=HKCU\Software\Microsoft\Office\16.0\Common +Default=False +FileKey1=%AppData%\Microsoft\Document Building Blocks|*.*|RECURSE +FileKey2=%AppData%\Microsoft\Office|*.tmp|RECURSE +FileKey3=%AppData%\Microsoft\OIS|Toolbars.dat +FileKey4=%AppData%\Microsoft\UProof|*.bin;*.XML +FileKey5=%CommonAppData%\Microsoft\ClickToRun\ProductReleases|*.*|RECURSE +FileKey6=%Documents%|~*.ppt;~*.pptx;~*.doc;~*.docx|RECURSE +FileKey7=%LocalAppData%\Microsoft Help|*.* +FileKey8=%LocalAppData%\Microsoft\Office\*|OneNoteOfflineCache.onecache +FileKey9=%LocalAppData%\Microsoft\Office\*\OfficeFileCache|*.*|RECURSE +FileKey10=%LocalAppData%\Microsoft\Office\OTele|*.*|RECURSE +FileKey11=%LocalAppData%\Microsoft\OneNote\*|OneNoteOfflineCache.onecache +FileKey12=%LocalAppData%\Microsoft\OneNote\*\cache|*.*|RECURSE +FileKey13=%LocalAppData%\Microsoft\OneNote\*\OneNoteOfflineCache_Files|*.*|RECURSE +FileKey14=%SystemDrive%|propfix.log +RegKey1=HKCU\Software\Microsoft\Office\11.0\MSE|LastLoadedSolution +RegKey2=HKCU\Software\Microsoft\Office\11.0\MSE\FileMRUList +RegKey3=HKCU\Software\Microsoft\Office\11.0\MSE\ProjectMRUList +RegKey4=HKCU\Software\Microsoft\Office\11.0\MSE\SolutionMRUList +RegKey5=HKCU\Software\Microsoft\Office\12.0\Common\Internet|UseRWHlinkNavigation +RegKey6=HKCU\Software\Microsoft\Office\12.0\Word\Reading Locations +RegKey7=HKCU\Software\Microsoft\Office\14.0\Common\Internet|UseRWHlinkNavigation +RegKey8=HKCU\Software\Microsoft\Office\14.0\Word\Reading Locations +RegKey9=HKCU\Software\Microsoft\Office\15.0\Common\Internet|UseRWHlinkNavigation +RegKey10=HKCU\Software\Microsoft\Office\15.0\Word\Reading Locations +RegKey11=HKCU\Software\Microsoft\Office\16.0\Common\Internet|UseRWHlinkNavigation +RegKey12=HKCU\Software\Microsoft\Office\16.0\Word\Reading Locations +RegKey13=HKCU\Software\Microsoft\Office\Common|FontBmpCache +RegKey14=HKCU\Software\Microsoft\OfficeCustomizeWizard\12.0\RecentFileList +RegKey15=HKCU\Software\Microsoft\OfficeCustomizeWizard\14.0\RecentFileList +RegKey16=HKCU\Software\Microsoft\OfficeCustomizeWizard\15.0\RecentFileList +RegKey17=HKCU\Software\Microsoft\OfficeCustomizeWizard\16.0\RecentFileList + +[MS Office Recent Templates *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\Office +Default=False +FileKey1=%AppData%\Microsoft\Templates|*.xlt;*.xltx;*.pot;*.potx;*.dot;*.dotx +RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\OfficeStart\Web\Templates +RegKey2=HKCU\Software\Microsoft\Office\12.0\Excel\Recent Templates +RegKey3=HKCU\Software\Microsoft\Office\12.0\PowerPoint\Recent Templates +RegKey4=HKCU\Software\Microsoft\Office\12.0\Word\Recent Templates +RegKey5=HKCU\Software\Microsoft\Office\14.0\Common\OfficeStart\Web\Templates +RegKey6=HKCU\Software\Microsoft\Office\14.0\Excel\Recent Templates +RegKey7=HKCU\Software\Microsoft\Office\14.0\PowerPoint\Recent Templates +RegKey8=HKCU\Software\Microsoft\Office\14.0\Word\Recent Templates +RegKey9=HKCU\Software\Microsoft\Office\15.0\Common\OfficeStart\Web\Templates +RegKey10=HKCU\Software\Microsoft\Office\15.0\Excel\Recent Templates +RegKey11=HKCU\Software\Microsoft\Office\15.0\PowerPoint\Recent Templates +RegKey12=HKCU\Software\Microsoft\Office\15.0\Word\Recent Templates +RegKey13=HKCU\Software\Microsoft\Office\16.0\Common\OfficeStart\Web\Templates +RegKey14=HKCU\Software\Microsoft\Office\16.0\Excel\Recent Templates +RegKey15=HKCU\Software\Microsoft\Office\16.0\PowerPoint\Recent Templates +RegKey16=HKCU\Software\Microsoft\Office\16.0\Word\Recent Templates + +[MS Office Unsaved Files *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\Office +Default=False +FileKey1=%AppData%\Microsoft\Excel|*.*|RECURSE +FileKey2=%AppData%\Microsoft\PowerPoint|*.*|RECURSE +FileKey3=%AppData%\Microsoft\Word|*.*|RECURSE +FileKey4=%LocalAppData%\Microsoft\Office\UnsavedFiles|*.*|RECURSE +ExcludeKey1=FILE|%AppData%\Microsoft\Word\|listgal.dat +ExcludeKey2=PATH|%AppData%\Microsoft\Excel\XLSTART\|*.* +ExcludeKey3=PATH|%AppData%\Microsoft\PowerPoint\|PPT*.pcb +ExcludeKey4=PATH|%AppData%\Microsoft\Word\STARTUP\|*.* + +[MS PhotoDraw 2000 *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\PhotoDraw\1.0 +Default=False +RegKey1=HKCU\Software\Microsoft\PhotoDraw\1.0\Recent File List + +[MS Robocopy GUI *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Microsoft Robocopy GUI +Default=False +FileKey1=%AppData%\Microsoft Robocopy GUI\Logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Microsoft\Microsoft Robocopy GUI\Logs|*.* +FileKey3=%ProgramFiles%\Microsoft\Microsoft Robocopy GUI\Logs|*.* + +[MS Search *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%CommonAppData%\Microsoft\Search\Data\Applications\Windows|Windows.edb +FileKey2=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE +FileKey3=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE +FileKey4=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows|Windows.edb +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE +FileKey9=%UserProfile%\Searches|*.search-ms +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery +RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData +RegKey3=HKLM\Software\Microsoft\Windows Search\VolumeInfoCache + +[MS SmallBasic *] +LangSecRef=3021 +DetectFile=%LocalAppData%\SmallBasic\SB.exe.settings.catalog +Default=False +FileKey1=%LocalAppData%\SmallBasic|*.* + +[MS SQL Server *] +LangSecRef=3021 +Detect1=HKCU\Software\Microsoft\Microsoft SQL Server +Detect2=HKLM\Software\Microsoft\Microsoft SQL Server +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Microsoft SQL Server\*\MSSQL\Log|*ERRORLOG*;*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Microsoft SQL Server\*\Setup Bootstrap\LOG|*.*|RECURSE +FileKey3=%ProgramFiles%\Microsoft SQL Server\*\MSSQL\Log|*ERRORLOG*;*.*|RECURSE +FileKey4=%ProgramFiles%\Microsoft SQL Server\*\Setup Bootstrap\LOG|*.*|RECURSE +RegKey1=HKCU\Software\Microsoft\Microsoft SQL Server\80\Tools\Shell\FileMRUList +RegKey2=HKCU\Software\Microsoft\Microsoft SQL Server\80\Tools\Shell\ProjectMRUList +RegKey3=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\FileMRUList +RegKey4=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\ProjectMRUList +RegKey5=HKCU\Software\Microsoft\Microsoft SQL Server\100\Tools\Shell\FileMRUList +RegKey6=HKCU\Software\Microsoft\Microsoft SQL Server\100\Tools\Shell\ProjectMRUList +RegKey7=HKCU\Software\Microsoft\Microsoft SQL Server\110\Tools\Shell\FileMRUList +RegKey8=HKCU\Software\Microsoft\Microsoft SQL Server\110\Tools\Shell\ProjectMRUList +RegKey9=HKLM\Software\Microsoft\Microsoft SQL Server\80\Tools\Shell\FileMRUList +RegKey10=HKLM\Software\Microsoft\Microsoft SQL Server\80\Tools\Shell\ProjectMRUList +RegKey11=HKLM\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\FileMRUList +RegKey12=HKLM\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\ProjectMRUList +RegKey13=HKLM\Software\Microsoft\Microsoft SQL Server\100\Tools\Shell\FileMRUList +RegKey14=HKLM\Software\Microsoft\Microsoft SQL Server\100\Tools\Shell\ProjectMRUList +RegKey15=HKLM\Software\Microsoft\Microsoft SQL Server\110\Tools\Shell\FileMRUList +RegKey16=HKLM\Software\Microsoft\Microsoft SQL Server\110\Tools\Shell\ProjectMRUList + +[MS UserScanProfiles *] +LangSecRef=3025 +DetectFile=%LocalAppData%\Microsoft\UserScanProfiles +Default=False +FileKey1=%LocalAppData%\Microsoft\UserScanProfiles|*.* + +[MS Visual Basic 2010 Express MRU *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VBExpress\10.0 +Default=False +RegKey1=HKCU\Software\Microsoft\VBExpress\10.0\FileMRUList +RegKey2=HKCU\Software\Microsoft\VBExpress\10.0\ProjectMRUList + +[MS Visual Basic 2010 Express Search History *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VBExpress\10.0 +Default=False +RegKey1=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find +RegKey2=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 0 +RegKey3=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 1 +RegKey4=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 2 +RegKey5=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 3 +RegKey6=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 4 +RegKey7=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 5 +RegKey8=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 6 +RegKey9=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 7 +RegKey10=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 8 +RegKey11=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 9 +RegKey12=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 10 +RegKey13=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 11 +RegKey14=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 12 +RegKey15=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 13 +RegKey16=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 14 +RegKey17=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 15 +RegKey18=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 16 +RegKey19=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 17 +RegKey20=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 18 +RegKey21=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 19 +RegKey22=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace +RegKey23=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 0 +RegKey24=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 1 +RegKey25=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 2 +RegKey26=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 3 +RegKey27=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 4 +RegKey28=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 5 +RegKey29=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 6 +RegKey30=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 7 +RegKey31=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 8 +RegKey32=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 9 +RegKey33=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 10 +RegKey34=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 11 +RegKey35=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 12 +RegKey36=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 13 +RegKey37=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 14 +RegKey38=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 15 +RegKey39=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 16 +RegKey40=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 17 +RegKey41=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 18 +RegKey42=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 19 + +[MS Visual C# 2010 Express MRU *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VCSExpress\10.0 +Default=False +RegKey1=HKCU\Software\Microsoft\VCSExpress\10.0\FileMRUList +RegKey2=HKCU\Software\Microsoft\VCSExpress\10.0\ProjectMRUList + +[MS Visual C# 2010 Express Search History *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VCSExpress\10.0 +Default=False +RegKey1=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find +RegKey2=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 0 +RegKey3=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 1 +RegKey4=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 2 +RegKey5=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 3 +RegKey6=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 4 +RegKey7=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 5 +RegKey8=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 6 +RegKey9=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 7 +RegKey10=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 8 +RegKey11=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 9 +RegKey12=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 10 +RegKey13=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 11 +RegKey14=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 12 +RegKey15=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 13 +RegKey16=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 14 +RegKey17=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 15 +RegKey18=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 16 +RegKey19=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 17 +RegKey20=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 18 +RegKey21=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 19 +RegKey22=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace +RegKey23=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 0 +RegKey24=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 1 +RegKey25=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 2 +RegKey26=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 3 +RegKey27=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 4 +RegKey28=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 5 +RegKey29=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 6 +RegKey30=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 7 +RegKey31=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 8 +RegKey32=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 9 +RegKey33=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 10 +RegKey34=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 11 +RegKey35=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 12 +RegKey36=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 13 +RegKey37=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 14 +RegKey38=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 15 +RegKey39=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 16 +RegKey40=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 17 +RegKey41=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 18 +RegKey42=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 19 + +[MS Visual C++ 2010 Express MRU *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VCExpress\10.0 +Default=False +RegKey1=HKCU\Software\Microsoft\VCExpress\10.0\FileMRUList +RegKey2=HKCU\Software\Microsoft\VCExpress\10.0\ProjectMRUList + +[MS Visual C++ 2010 Express Search History *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VCExpress\10.0 +Default=False +RegKey1=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find +RegKey2=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 0 +RegKey3=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 1 +RegKey4=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 2 +RegKey5=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 3 +RegKey6=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 4 +RegKey7=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 5 +RegKey8=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 6 +RegKey9=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 7 +RegKey10=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 8 +RegKey11=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 9 +RegKey12=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 10 +RegKey13=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 11 +RegKey14=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 12 +RegKey15=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 13 +RegKey16=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 14 +RegKey17=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 15 +RegKey18=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 16 +RegKey19=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 17 +RegKey20=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 18 +RegKey21=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 19 +RegKey22=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace +RegKey23=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 0 +RegKey24=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 1 +RegKey25=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 2 +RegKey26=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 3 +RegKey27=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 4 +RegKey28=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 5 +RegKey29=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 6 +RegKey30=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 7 +RegKey31=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 8 +RegKey32=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 9 +RegKey33=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 10 +RegKey34=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 11 +RegKey35=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 12 +RegKey36=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 13 +RegKey37=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 14 +RegKey38=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 15 +RegKey39=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 16 +RegKey40=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 17 +RegKey41=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 18 +RegKey42=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 19 + +[MS Visual Express 10 Backup *] +LangSecRef=3021 +DetectFile=%AppData%\Microsoft\VCExpress\10.0 +Default=False +FileKey1=%AppData%\Microsoft\VCExpress\10.0|*.winprf_backup + +[MS Visual Studio *] +LangSecRef=3021 +Detect=HKLM\Software\Microsoft\VisualStudio +Default=False +FileKey1=%LocalAppData%\Microsoft\VisualStudio\SettingsLogs|*.*|RECURSE +FileKey2=%LocalAppData%\PerfWatson|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Microsoft Visual Studio *\*\Logs|*.*|REMOVESELF +FileKey4=%ProgramFiles%\Microsoft Visual Studio *\*\Logs|*.*|REMOVESELF + +[MS Visual Studio 2017 Installation packages *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VisualStudio +Default=False +FileKey1=%CommonAppData%\Microsoft\VisualStudio\Packages|*.*|RECURSE +ExcludeKey1=PATH|%CommonAppData%\Microsoft\VisualStudio\Packages\_Instances\|*.* + +[MS Visual Studio Backup *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VisualStudio +Default=False +FileKey1=%Documents%\Visual Studio *\Backup Files|*.*|RECURSE + +[MS Visual Studio Caches *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VisualStudio +Default=False +FileKey1=%LocalAppData%\Microsoft\VisualStudio\*\ComponentModelCache|*.* +FileKey2=%LocalAppData%\Microsoft\VisualStudio\*\Extensions|*.cache +FileKey3=%LocalAppData%\Microsoft\VisualStudio\*\ImageLibrary|*.cache +FileKey4=%LocalAppData%\Microsoft\VisualStudio\*\MEFCacheBackup|*.* +FileKey5=%LocalAppData%\Microsoft\VisualStudio\*\Notifications|*.cache +FileKey6=%LocalAppData%\Microsoft\VisualStudio\*\ProjectAssemblies|*.* +FileKey7=%LocalAppData%\Microsoft\VisualStudio\*\TextMateCache|*.* +FileKey8=%LocalAppData%\Microsoft\websiteCache|*.*|RECURSE +FileKey9=%LocalAppData%\NuGet\Cache|*.*|RECURSE +FileKey10=%LocalAppData%\NuGet\v3-cache|*.*|REMOVESELF +FileKey11=%UserProfile%\.nuget|*.*|RECURSE + +[MS Visual Studio MRU *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VisualStudio +Default=False +RegKey1=HKCU\Software\Microsoft\VisualStudio\9.0\FileMRUList +RegKey2=HKCU\Software\Microsoft\VisualStudio\9.0\LastLoadedSolution +RegKey3=HKCU\Software\Microsoft\VisualStudio\9.0\ProjectMRUList +RegKey4=HKCU\Software\Microsoft\VisualStudio\10.0\FileMRUList +RegKey5=HKCU\Software\Microsoft\VisualStudio\10.0\LastLoadedSolution +RegKey6=HKCU\Software\Microsoft\VisualStudio\10.0\ProjectMRUList +RegKey7=HKCU\Software\Microsoft\VisualStudio\11.0\FileMRUList +RegKey8=HKCU\Software\Microsoft\VisualStudio\11.0\LastLoadedSolution +RegKey9=HKCU\Software\Microsoft\VisualStudio\11.0\ProjectMRUList +RegKey10=HKCU\Software\Microsoft\VisualStudio\12.0\FileMRUList +RegKey11=HKCU\Software\Microsoft\VisualStudio\12.0\LastLoadedSolution +RegKey12=HKCU\Software\Microsoft\VisualStudio\12.0\ProjectMRUList +RegKey13=HKCU\Software\Microsoft\VisualStudio\14.0\FileMRUList +RegKey14=HKCU\Software\Microsoft\VisualStudio\14.0\LastLoadedSolution +RegKey15=HKCU\Software\Microsoft\VisualStudio\14.0\ProjectMRUList + +[MS Visual Studio Search History *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\VisualStudio +Default=False +RegKey1=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 0 +RegKey2=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 1 +RegKey3=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 2 +RegKey4=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 3 +RegKey5=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 4 +RegKey6=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 5 +RegKey7=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 6 +RegKey8=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 7 +RegKey9=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 8 +RegKey10=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 9 +RegKey11=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 10 +RegKey12=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 11 +RegKey13=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 12 +RegKey14=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 13 +RegKey15=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 14 +RegKey16=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 15 +RegKey17=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 16 +RegKey18=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 17 +RegKey19=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 18 +RegKey20=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 19 +RegKey21=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 0 +RegKey22=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 1 +RegKey23=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 2 +RegKey24=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 3 +RegKey25=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 4 +RegKey26=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 5 +RegKey27=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 6 +RegKey28=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 7 +RegKey29=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 8 +RegKey30=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 9 +RegKey31=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 10 +RegKey32=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 11 +RegKey33=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 12 +RegKey34=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 13 +RegKey35=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 14 +RegKey36=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 15 +RegKey37=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 16 +RegKey38=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 17 +RegKey39=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 18 +RegKey40=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 19 +RegKey41=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 0 +RegKey42=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 1 +RegKey43=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 2 +RegKey44=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 3 +RegKey45=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 4 +RegKey46=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 5 +RegKey47=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 6 +RegKey48=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 7 +RegKey49=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 8 +RegKey50=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 9 +RegKey51=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 10 +RegKey52=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 11 +RegKey53=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 12 +RegKey54=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 13 +RegKey55=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 14 +RegKey56=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 15 +RegKey57=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 16 +RegKey58=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 17 +RegKey59=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 18 +RegKey60=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 19 +RegKey61=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 0 +RegKey62=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 1 +RegKey63=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 2 +RegKey64=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 3 +RegKey65=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 4 +RegKey66=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 5 +RegKey67=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 6 +RegKey68=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 7 +RegKey69=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 8 +RegKey70=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 9 +RegKey71=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 10 +RegKey72=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 11 +RegKey73=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 12 +RegKey74=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 13 +RegKey75=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 14 +RegKey76=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 15 +RegKey77=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 16 +RegKey78=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 17 +RegKey79=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 18 +RegKey80=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 19 +RegKey81=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 0 +RegKey82=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 1 +RegKey83=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 2 +RegKey84=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 3 +RegKey85=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 4 +RegKey86=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 5 +RegKey87=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 6 +RegKey88=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 7 +RegKey89=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 8 +RegKey90=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 9 +RegKey91=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 10 +RegKey92=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 11 +RegKey93=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 12 +RegKey94=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 13 +RegKey95=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 14 +RegKey96=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 15 +RegKey97=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 16 +RegKey98=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 17 +RegKey99=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 18 +RegKey100=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 19 +RegKey101=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 0 +RegKey102=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 1 +RegKey103=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 2 +RegKey104=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 3 +RegKey105=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 4 +RegKey106=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 5 +RegKey107=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 6 +RegKey108=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 7 +RegKey109=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 8 +RegKey110=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 9 +RegKey111=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 10 +RegKey112=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 11 +RegKey113=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 12 +RegKey114=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 13 +RegKey115=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 14 +RegKey116=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 15 +RegKey117=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 16 +RegKey118=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 17 +RegKey119=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 18 +RegKey120=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 19 +RegKey121=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find +RegKey122=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 0 +RegKey123=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 1 +RegKey124=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 2 +RegKey125=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 3 +RegKey126=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 4 +RegKey127=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 5 +RegKey128=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 6 +RegKey129=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 7 +RegKey130=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 8 +RegKey131=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 9 +RegKey132=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 10 +RegKey133=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 11 +RegKey134=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 12 +RegKey135=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 13 +RegKey136=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 14 +RegKey137=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 15 +RegKey138=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 16 +RegKey139=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 17 +RegKey140=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 18 +RegKey141=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 19 +RegKey142=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace +RegKey143=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 0 +RegKey144=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 1 +RegKey145=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 2 +RegKey146=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 3 +RegKey147=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 4 +RegKey148=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 5 +RegKey149=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 6 +RegKey150=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 7 +RegKey151=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 8 +RegKey152=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 9 +RegKey153=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 10 +RegKey154=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 11 +RegKey155=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 12 +RegKey156=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 13 +RegKey157=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 14 +RegKey158=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 15 +RegKey159=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 16 +RegKey160=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 17 +RegKey161=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 18 +RegKey162=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 19 +RegKey163=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace +RegKey164=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 0 +RegKey165=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 1 +RegKey166=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 2 +RegKey167=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 3 +RegKey168=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 4 +RegKey169=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 5 +RegKey170=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 6 +RegKey171=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 7 +RegKey172=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 8 +RegKey173=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 9 +RegKey174=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 10 +RegKey175=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 11 +RegKey176=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 12 +RegKey177=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 13 +RegKey178=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 14 +RegKey179=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 15 +RegKey180=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 16 +RegKey181=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 17 +RegKey182=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 18 +RegKey183=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 19 + +[MS Windows Game Statistics *] +LangSecRef=3025 +DetectFile=%LocalAppData%\Microsoft Games +Default=False +FileKey1=%LocalAppData%\Microsoft Games|*.xml;*.xml.bak|RECURSE + +[MS Works Suite 2006 *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\Works\8.0 +Default=False +RegKey1=HKCU\Software\Microsoft\Works\8.0\Recent File List + +[MS XML Notepad *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\XML Notepad +Default=False +RegKey1=HKCU\Software\Microsoft\XML Notepad\Recent File List + +[MSConfig *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Shared Tools\MSConfig +Default=False +RegKey1=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandFrom +RegKey2=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandTo +RegKey3=HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSConfig + +[MSI Afterburner Hardware Monitoring *] +LangSecRef=3024 +Detect=HKCU\Software\MSI +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\MSI Afterburner|HardwareMonitoring.hml +FileKey2=%ProgramFiles%\MSI Afterburner|HardwareMonitoring.hml + +[MTA San Andreas 1.3 *] +Section=Games +DetectFile=%ProgramFiles%\MTA San Andreas 1.3\Multi Theft Auto.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\MTA San Andreas 1.3\MTA\logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\MTA San Andreas 1.3\server\mods\deathmatch\backups|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\MTA San Andreas 1.3\server\mods\deathmatch\logs|*.* +FileKey4=%ProgramFiles%\MTA San Andreas 1.3\MTA\logs|*.* +FileKey5=%ProgramFiles%\MTA San Andreas 1.3\server\mods\deathmatch\backups|*.* +FileKey6=%ProgramFiles%\MTA San Andreas 1.3\server\mods\deathmatch\logs|*.* + +[Multi-Edit 2008 *] +LangSecRef=3024 +Detect=HKCU\Software\Multi Edit Software\Multi-Edit\11.0 +Default=False +FileKey1=%AppData%\Multi Edit Software|*.log|RECURSE +FileKey2=%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\Tmp|*.TMP +ExcludeKey1=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|EVOLVE.LOG +ExcludeKey2=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|FILEPANE.LOG +ExcludeKey3=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|INSTALL.LOG +ExcludeKey4=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|POLYSTYLE.LOG +ExcludeKey5=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|TMPLPANE.LOG +ExcludeKey6=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|WINLIST.LOG + +[Multi Commander *] +LangSecRef=3024 +Detect=HKLM\Software\MultiCommander +Default=False +Warning=Close Multi Commander application before using this option. +FileKey1=%AppData%\MultiCommander\Logs|*.log + +[Multi Password Recovery *] +LangSecRef=3021 +Detect=HKLM\System\CurrentControlSet\enum\root\legacy_block_reader +Default=False +RegKey1=HKLM\Software\Classes\.mpf +RegKey2=HKLM\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF} +RegKey3=HKLM\Software\Classes\MPR.DocHostUIHandler +RegKey4=HKLM\System\CurrentControlSet\enum\root\legacy_block_reader +RegKey5=HKLM\System\CurrentControlSet\Services\block_reader + +[MultiBit *] +LangSecRef=3023 +DetectFile=%AppData%\MultiBit +Default=False +FileKey1=%AppData%\MultiBit\log|*.* + +[MultiHasher *] +LangSecRef=3024 +Detect=HKLM\Software\abelhadigital.com\MultiHasher +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\MultiHasher|*.txt;*.zip|RECURSE +FileKey2=%ProgramFiles%\MultiHasher|*.txt;*.zip|RECURSE + +[MultiViewInpaint *] +LangSecRef=3021 +Detect=HKCU\Software\Teorex\MultiViewInpaint +Default=False +RegKey1=HKCU\Software\Teorex\MultiViewInpaint\Recent File List +RegKey2=HKCU\Software\Teorex\MultiViewInpaint\RecentFileList + +[Mumble *] +LangSecRef=3022 +Detect=HKCU\Software\Mumble +Default=False +FileKey1=%AppData%\Mumble|console.txt + +[Murder, She Wrote *] +Section=Games +DetectFile=%AppData%\MysteryStudio\MSW +Default=False +FileKey1=%AppData%\MysteryStudio\MFW|*.log + +[MuseScore *] +LangSecRef=3023 +DetectFile=%LocalAppData%\MusE\MuseScore +Default=False +FileKey1=%LocalAppData%\MusE\MuseScore|cookies.txt + +[MusicBee *] +LangSecRef=3023 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\MusicBee +Default=False +FileKey1=%AppData%\MusicBee|*.dat +FileKey2=%AppData%\MusicBee\InternalCache|*.*|REMOVESELF + +[MusicMatch Jukebox *] +LangSecRef=3023 +Detect=HKLM\Software\MUSICMATCH\MUSICMATCH Jukebox +Default=False +FileKey1=%LocalAppData%\Musicmatch\Jukebox\Cache|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\MUSICMATCH\MUSICMATCH Jukebox|*.log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\MUSICMATCH\Musicmatch Jukebox\MMRadio\Cache|*.*|RECURSE +FileKey4=%ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox|*.log|RECURSE +FileKey5=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\MMRadio\Cache|*.*|RECURSE + +[MusicNet *] +LangSecRef=3023 +DetectFile=%AppData%\MusicNet +Default=False +FileKey1=%AppData%\MusicNet|*.log + +[MWConn *] +LangSecRef=3022 +DetectFile1=%AppData%\Microsoft\Windows\Start Menu\Programs\MWconn +DetectFile2=%AppData%\Microsoft\Windows\Startmenü\Programs\MWconn +DetectFile3=%UserProfile%\Start Menu\Programs\MWconn +DetectFile4=%UserProfile%\Startmenü\Programme\MWconn +Default=False +FileKey1=%AppData%\Microsoft\Windows\Start*\Program*\MWconn|connlog.txt +FileKey2=%UserProfile%\Start*\Program*\MWconn|connlog.txt + +[MWConn SMS *] +LangSecRef=3022 +DetectFile1=%AppData%\Microsoft\Windows\Start Menu\Programs\MWconn +DetectFile2=%AppData%\Microsoft\Windows\Startmenü\Programs\MWconn +DetectFile3=%UserProfile%\Start Menu\Programs\MWconn +DetectFile4=%UserProfile%\Startmenü\Programme\MWconn +Default=False +Warning=This will delete all of your SMS messages. +FileKey1=%AppData%\Microsoft\Windows\Start*\Program*\MWconn\sms_*|*.*|RECURSE +FileKey2=%UserProfile%\Start*\Program*\MWconn\sms_*|*.*|RECURSE + +[My Family Tree *] +LangSecRef=3021 +DetectFile=%LocalAppData%\My Family Tree +Default=False +FileKey1=%LocalAppData%\My Family Tree\MapCache|*.*|RECURSE +FileKey2=%LocalAppData%\My Family Tree\Temp|*.*|RECURSE + +[My Horse and Me *] +Section=Games +Detect=HKLM\Software\My Horse and Me 2 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Atari\Mein Pferd und ich*\System|++ Finish log.txt;++ Start log.txt;*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Atari\My Horse and Me|++ Finish log.txt;++ Start log.txt;*.log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Atari\W!Games\My Horse and Me|++ Finish log.txt;++ Start log.txt;*.log|RECURSE +FileKey4=%ProgramFiles%\Atari\Mein Pferd und ich*\System|++ Finish log.txt;++ Start log.txt;*.log|RECURSE +FileKey5=%ProgramFiles%\Atari\My Horse and Me|++ Finish log.txt;++ Start log.txt;*.log|RECURSE +FileKey6=%ProgramFiles%\Atari\W!Games\My Horse and Me|++ Finish log.txt;++ Start log.txt;*.log|RECURSE + +[My Movies Collection *] +LangSecRef=3023 +DetectFile=%CommonAppData%\My Movies +Default=False +FileKey1=%CommonAppData%\My Movies|vcredist*.*;installerlog.txt;log.txt +FileKey2=%CommonAppData%\My Movies\File Storage\Temp|*.*|RECURSE +FileKey3=%CommonAppData%\My Movies\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\My Movies|installerlog.txt;log.txt +FileKey5=%LocalAppData%\VirtualStore\ProgramData\My Movies\File Storage\Temp|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\My Movies\Temp|*.*|RECURSE + +[My Office *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\LocalCache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\LocalState\AppData\Local\Office\16.0\WebServiceCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\LocalState\Cache|*.*|RECURSE + +[My Riding Stables *] +Section=Games +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyRidingStables +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\My Riding Stables*|*.txt;*.url +FileKey2=%ProgramFiles%\My Riding Stables*|*.txt;*.url + +[My Singing Monsters *] +Section=Games +Detect1=HKLM\Software\Big Fish Games\Persistence\Install\F7664T1L1 +Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\My Singing Monsters1.1 +DetectFile=%ProgramFiles%\My Singing Monsters +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\*\My Singing Monsters|*.log;*.txt|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\My Singing Monsters|*.log;*.txt|RECURSE +FileKey3=%ProgramFiles%\*\My Singing Monsters|dotnetfx35setup.exe;*.html;*.PNG;vcredist_x86.exe;*.log;*.txt|RECURSE +FileKey4=%ProgramFiles%\My Singing Monsters|dotnetfx35setup.exe;vcredist_x86.exe;*.log;*.txt|RECURSE + +[MyCraft *] +Section=Games +DetectFile=%UserProfile%\Desktop\MyCraft +Default=False +FileKey1=%UserProfile%\Desktop\MyCraft|MyCraft Log.* + +[MyDefrag *] +LangSecRef=3021 +Detect=HKCU\Software\MyDefrag +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\MyDefrag *|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\MyDefrag *\LOGs|*.* +FileKey3=%ProgramFiles%\MyDefrag *|*.log +FileKey4=%ProgramFiles%\MyDefrag *\LOGs|*.* + +[MyPhoneExplorer *] +LangSecRef=3024 +Detect=HKCU\Software\MyPhoneExplorer +Default=False +FileKey1=%AppData%\MyPhoneExplorer|Debug.txt + +[MySMS *] +LangSecRef=3022 +Detect=HKCU\Software\sms.at\mysms +Default=False +FileKey1=%LocalAppData%\sms.at\mysms\LocalStorage|*.* +RegKey1=HKCU\Software\sms.at\mysms\cookies + +[MySpaceIM *] +LangSecRef=3022 +Detect=HKCU\Software\Myspace\IM +Default=False +FileKey1=%AppData%\MySpace\IM\Dump|*.* +FileKey2=%AppData%\MySpace\IM\Images|*.* + +[MySQL Workbench *] +LangSecRef=3021 +DetectFile=%AppData%\MySQL\Workbench +Default=False +FileKey1=%AppData%\MySQL\Workbench\cache|*.* +FileKey2=%AppData%\MySQL\Workbench\log|*.log +FileKey3=%AppData%\MySQL\Workbench\sql_history|*.* + +[MyToolkit *] +LangSecRef=3024 +Detect=HKCU\Software\FutureFog\MyToolkit\Options +Default=False +RegKey1=HKCU\Software\FutureFog\MyToolkit\Options|LastUsedFolder + +[myTube! *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\59750RYKENAPPS.435307C335C44_zd92nzxdcatqw +DetectFile=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_zd92nzxdcatqw +Default=False +FileKey1=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\LocalCache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\LocalState\YouTubeCache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\TempState|*.*|RECURSE + +[MyWinLocker *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\EgisTec\mywinlocker 3 +Default=False +FileKey1=%LocalAppData%|mywinlockerinstaller.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\EgisTec\MyWinLocker 3\log|*.* +FileKey3=%ProgramFiles%\EgisTec\MyWinLocker 3\log|*.* + +[Nancy Drew - Secret of Shadow Ranch *] +Section=Games +Detect1=HKLM\Software\Big Fish Games\Persistence\Install\F7041T1L1 +Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Nancy Drew - Secret of Shadow Ranch - Plus Guide1.0 +DetectFile=%ProgramFiles%\Nancy Drew* +Default=False +FileKey1=%ProgramFiles%\*\Nancy Drew*|dxwebsetup.exe;*.html +FileKey2=%ProgramFiles%\Nancy Drew*|dxwebsetup.exe;*.html + +[Natural Selection 2 *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\4920 +DetectFile=%ProgramFiles%\Steam\steamapps\common\Natural Selection 2 +Default=False +Warning=Fixes corrupt cache & cleans cache bloat. The first game & map launch will take longer to load. +FileKey1=%AppData%\Natural Selection 2|log.txt +FileKey2=%AppData%\Natural Selection 2\cache|*.*|RECURSE + +[NBC News *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\msnbc.comDigitalNetwork.msnbc.com_amdjbdaxqsje6 +DetectFile=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_amdjbdaxqsje6 +Default=False +FileKey1=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\Microsoft\CLR_v4.0|*.log +FileKey3=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\PRICache|*.* +FileKey5=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\Temp|*.* +FileKey6=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\TempState|*.*|RECURSE + +[Neostar CMS Station Client *] +LangSecRef=3024 +Detect=HKLM\Software\company\Neostar CMS +Default=False +FileKey1=%ProgramFiles%\Neostar CMS Station\Neostar CMS\Neostar CMS Client\log|*.* +FileKey2=%ProgramFiles%\Neostar CMS Station\Neostar CMS\Neostar CMS Client\StreamServer|*.log +FileKey3=%ProgramFiles%\Neostar CMS Station\Neostar CMS\Neostar CMS Client\StreamServer\log|*.* + +[Nero *] +LangSecRef=3021 +Detect1=HKCU\Software\Ahead +Detect2=HKCU\Software\Nero\Nero8 +Detect3=HKLM\Software\Nero\Nero 11\Nero11Suite +Detect4=HKLM\Software\Nero\Nero 12\Nero12Suite +Default=False +FileKey1=%AppData%\Nero\Nero Burning ROM|*.log +FileKey2=%AppData%\Nero\Nero*\Nero BackItUp\Cache|*.* +FileKey3=%AppData%\Nero\Nero*\Nero Burning ROM|*.log +FileKey4=%AppData%\Nero\Nero*\Nero Recode\AnalysisData|*.dat +FileKey5=%AppData%\Nero\Nero*\Nero Recode\Thumbs|*.* +FileKey6=%AppData%\Nero\Nero*\Nero Vision|*.txt;*.bin +FileKey7=%AppData%\Nero\Nero*\Nero Vision\NVFACache|*.* +FileKey8=%AppData%\Nero\Nero*\Nero3D|*.log +FileKey9=%CommonAppData%\Nero\PeakFiles|*.tmp +FileKey10=%LocalAppData%\Nero\Nero *\Nero Vision\Cache|*.* +FileKey11=%LocalAppData%\Nero\Nero *\Nero Vision\Cache\GraphicObjectCache|*.* +FileKey12=%LocalAppData%\VirtualStore\ProgramData\Nero\PeakFiles|*.tmp +RegKey1=HKCU\Software\ahead\Nero PhotoSnap\Recent File List +RegKey2=HKCU\Software\Ahead\NeroSearch\NeroSavedSearches\SavedSearches +RegKey3=HKCU\Software\ahead\NeroVision\2.0\RecentFiles +RegKey4=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumeLabelAutoTemplate +RegKey5=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumeLabelISOTemplate +RegKey6=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumelabelJolietTemplate +RegKey7=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumeLabelUDFTemplate +RegKey8=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Recent File List +RegKey9=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|EncodingLastDir +RegKey10=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|NeroCompilation +RegKey11=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|TrackSaveDir +RegKey12=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|WorkingDir +RegKey13=HKCU\Software\Nero\Nero 11\Nero CoverDesigner\Recent File List +RegKey14=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumeLabelAutoTemplate +RegKey15=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumeLabelISOTemplate +RegKey16=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumelabelJolietTemplate +RegKey17=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumeLabelUDFTemplate +RegKey18=HKCU\Software\Nero\Nero 11\Nero Express\General|OFDLastAudioDir +RegKey19=HKCU\Software\Nero\Nero 11\Nero Express\General|OFDLastISODir +RegKey20=HKCU\Software\Nero\Nero 11\Nero Express\General|OFDLastVideoDVDKey +RegKey21=HKCU\Software\Nero\Nero 11\Nero Express\Recent File List +RegKey22=HKCU\Software\Nero\Nero 11\Nero Express\Settings|BootImageDir +RegKey23=HKCU\Software\Nero\Nero 11\Nero Express\Settings|BrowserDir +RegKey24=HKCU\Software\Nero\Nero 11\Nero Express\Settings|ImageDir +RegKey25=HKCU\Software\Nero\Nero 11\Nero Express\Settings|NeroCompilation +RegKey26=HKCU\Software\Nero\Nero 11\Nero Express\Settings|TrackSaveDir +RegKey27=HKCU\Software\Nero\Nero 11\Nero Express\Settings|WorkingDir +RegKey28=HKCU\Software\Nero\Nero 11\Nero Toolkit\DiscSpeed\Capture|Folder +RegKey29=HKCU\Software\Nero\Nero 11\Nero Toolkit\DiscSpeed\Save|Folder +RegKey30=HKCU\Software\Nero\Nero 11\Nero Vision\Application|AudioDir +RegKey31=HKCU\Software\Nero\Nero 11\Nero Vision\Application|CaptureDir +RegKey32=HKCU\Software\Nero\Nero 11\Nero Vision\Application|DocDir +RegKey33=HKCU\Software\Nero\Nero 11\Nero Vision\Application|ExportAudioDir +RegKey34=HKCU\Software\Nero\Nero 11\Nero Vision\Application|ExportVideoDir +RegKey35=HKCU\Software\Nero\Nero 11\Nero Vision\Application|ImportVideoDir +RegKey36=HKCU\Software\Nero\Nero 11\Nero Vision\Application|MediaDir +RegKey37=HKCU\Software\Nero\Nero 11\Nero Vision\Application|PicDir +RegKey38=HKCU\Software\Nero\Nero 11\Nero Vision\Application|PicSaveDir +RegKey39=HKCU\Software\Nero\Nero 11\Nero Vision\Application|TmpDir +RegKey40=HKCU\Software\Nero\Nero 11\Nero Vision\Application|VideoDir +RegKey41=HKCU\Software\Nero\Nero 11\Nero WaveEditor\Directories|Last +RegKey42=HKCU\Software\Nero\Nero 11\Nero WaveEditor\Recent File List +RegKey43=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumeLabelAutoTemplate +RegKey44=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumeLabelISOTemplate +RegKey45=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumelabelJolietTemplate +RegKey46=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumeLabelUDFTemplate +RegKey47=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|EncodingLastDir +RegKey48=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|TrackSaveDir +RegKey49=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|WorkingDir +RegKey50=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumeLabelAutoTemplate +RegKey51=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumeLabelISOTemplate +RegKey52=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumelabelJolietTemplate +RegKey53=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumeLabelUDFTemplate +RegKey54=HKCU\Software\Nero\Nero 12\Nero Express\Settings|BootImageDir +RegKey55=HKCU\Software\Nero\Nero 12\Nero Express\Settings|ImageDir +RegKey56=HKCU\Software\Nero\Nero 12\Nero Express\Settings|NeroCompilation +RegKey57=HKCU\Software\Nero\Nero 12\Nero Express\Settings|TrackSaveDir +RegKey58=HKCU\Software\Nero\Nero 12\Nero Toolkit\DiscSpeed\Capture|Folder +RegKey59=HKCU\Software\Nero\Nero 12\Nero Toolkit\DiscSpeed\Save|Folder +RegKey60=HKCU\Software\Nero\Nero 12\Nero Vision\Application|AudioDir +RegKey61=HKCU\Software\Nero\Nero 12\Nero Vision\Application|CaptureDir +RegKey62=HKCU\Software\Nero\Nero 12\Nero Vision\Application|DocDir +RegKey63=HKCU\Software\Nero\Nero 12\Nero Vision\Application|ExportAudioDir +RegKey64=HKCU\Software\Nero\Nero 12\Nero Vision\Application|ExportVideoDir +RegKey65=HKCU\Software\Nero\Nero 12\Nero Vision\Application|ImportVideoDir +RegKey66=HKCU\Software\Nero\Nero 12\Nero Vision\Application|MediaDir +RegKey67=HKCU\Software\Nero\Nero 12\Nero Vision\Application|PicDir +RegKey68=HKCU\Software\Nero\Nero 12\Nero Vision\Application|PicSaveDir +RegKey69=HKCU\Software\Nero\Nero 12\Nero Vision\Application|TmpDir +RegKey70=HKCU\Software\Nero\Nero 12\Nero Vision\Application|VideoDir +RegKey71=HKCU\Software\Nero\Nero 12\Nero WaveEditor\Directories|Last +RegKey72=HKCU\Software\Nero\Nero Blu-ray Player\Settings|DefFolder +RegKey73=HKCU\Software\Nero\Nero8\Cover Designer\Recent File List +RegKey74=HKCU\Software\Nero\Nero8\Nero - Burning Rom\Recent File List + +[Net Vampire *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Net Vampire +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Net Vampire\Data\Jobs|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Net Vampire\Data\Sites|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Net Vampire\Data\State|*.*|RECURSE +FileKey4=%ProgramFiles%\Net Vampire\Data\Jobs|*.*|RECURSE +FileKey5=%ProgramFiles%\Net Vampire\Data\Sites|*.*|RECURSE +FileKey6=%ProgramFiles%\Net Vampire\Data\State|*.*|RECURSE + +[Net2Printer RDP *] +LangSecRef=3021 +DetectFile=%AppData%\Net2Printer RDP Client +Default=False +FileKey1=%AppData%\Net2Printer RDP Client|*.* + +[NetAnts *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\NetAnts +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\NetAnts|netants.job;history.txt +FileKey2=%ProgramFiles%\NetAnts|netants.job;history.txt + +[NetBeans IDE *] +LangSecRef=3021 +DetectFile1=%AppData%\NetBeans +DetectFile2=%UserProfile%\.nbi\log +Default=False +FileKey1=%AppData%\NetBeans\*\var\log|*.*|RECURSE +FileKey2=%UserProfile%\.nbi\log|*.log|RECURSE + +[NetCaptor *] +LangSecRef=3022 +Detect=HKCU\Software\Stilesoft\NetCaptor +Default=False +RegKey1=HKCU\Software\Stilesoft\NetCaptor\CurrentVersion\Last Open Sites + +[Netflix *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\4DF9E0F8.Netflix_mcm4njqhnhss8 +DetectFile=%LocalAppData%\Packages\4DF9E0F8.Netflix_mcm4njqhnhss8 +Default=False +FileKey1=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey4=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\PRICache|*.* +FileKey5=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\Temp|*.* +FileKey6=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AppData\Indexed DB|*.log +FileKey7=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\LocalState|*.tmp|RECURSE +FileKey8=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\LocalState\LiveTile|*.* +FileKey9=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\4DF9E0F8.Netflix_mcm4njqhnhss8\SearchHistory + +[NETGEAR Genie *] +LangSecRef=3024 +Detect=HKLM\Software\NETGEAR Genie +Default=False +FileKey1=%LocalAppData%\NETGEARGenie|*.txt +FileKey2=%LocalAppData%\NETGEARGenie\log|*.log +FileKey3=%LocalAppData%\NETGEARGenie\update_temp|*.* + +[Network Speed Test *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.NetworkSpeedTest_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_*\AC\Microsoft\CLR_v4.0*\UsageLogs|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_*\AC\PRICache|*.* +FileKey4=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_*\AC\Temp|*.* +FileKey5=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_*\TempState|*.*|RECURSE + +[NetworkService *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Windows +Default=False +FileKey1=%SystemDrive%\Documents and Settings\NetworkService*\Cookies|*.*|RECURSE +FileKey2=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\Content.IE5|*.*|RECURSE +FileKey3=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\History|*.*|RECURSE +FileKey4=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\Temp|*.*|RECURSE +FileKey5=%SystemDrive%\Documents and Settings\NetworkService\*Local Settings\Temporary Internet Files|*.*|RECURSE +FileKey6=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Content.IE5|*.*|RECURSE +FileKey7=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History|*.*|RECURSE +FileKey8=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE +FileKey9=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Temp|*.*|RECURSE +FileKey10=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies|*.*|RECURSE +FileKey11=%WinDir%\ServiceProfiles\NetworkService\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE +FileKey12=%WinDir%\ServiceProfiles\NetworkService\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE +FileKey13=%WinDir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE +FileKey14=%WinDir%\ServiceProfiles\NetworkService\debug|*.log + +[Neverwinter *] +Section=Games +Detect=HKCU\Software\Cryptic\Neverwinter +Default=False +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Cryptic Studios|*.log|RECURSE +FileKey2=%ProgramFiles%\Steam\SteamApps\common\Cryptic Studios\localdata|_SWMWindowPosList.txt +FileKey3=%Public%\Games\Cryptic Studios|*.log|RECURSE +FileKey4=%Public%\Games\Cryptic Studios\localdata|_SWMWindowPosList.txt + +[New Yankee 3 - In Santas Service *] +Section=Games +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\New Yankee 3 - In Santas ServiceFinal +Default=False +FileKey1=%AppData%\AlawarEntertainment|*_log.html|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\New Yankee 3 - In Santas Service|*.nfo +FileKey3=%ProgramFiles%\New Yankee 3 - In Santas Service|*.nfo + +[News *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.BingNews_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\PRICache|*.* +FileKey3=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.BingNews_*\LocalState\navigationHistory|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe\SearchHistory + +[Newsbin Pro *] +LangSecRef=3021 +Detect=HKCU\Software\DJI Interprises\Newsbin50 +Default=False +FileKey1=%LocalAppData%\Newsbin|Logfile.txt;Downloaded.db3;DownloadMarker.db3;Downloads.db3* +FileKey2=%LocalAppData%\Newsbin\SPOOL_V6|*.* +FileKey3=%LocalAppData%\Newsbin\temp|*.* + +[Newsleecher *] +LangSecRef=3021 +DetectFile=%AppData%\Newsleecher\Backups +Default=False +FileKey1=%AppData%\Newsleecher\Backups|*.* + +[neXBC *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\neXBC\neXBC.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\neXBC|messages.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\neXBC\Logs\Hosted|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\neXBC\Logs\Joined|*.* +FileKey4=%ProgramFiles%\neXBC|messages.txt +FileKey5=%ProgramFiles%\neXBC\Logs\Hosted|*.* +FileKey6=%ProgramFiles%\neXBC\Logs\Joined|*.* + +[Nextup TextAloud *] +LangSecRef=3021 +Detect=HKCU\Software\NextUpTech\TextAloud3 +Default=False +FileKey1=%LocalAppData%\NextUp\TextAloud|*.adu;*.adl;*.dbg +FileKey2=%LocalAppData%\NextUp\TextAloud\Articles|*.*|RECURSE +RegKey1=HKCU\Software\NextUpTech\TextAloud3|AudioClipFileOpenDirectory +RegKey2=HKCU\Software\NextUpTech\TextAloud3|DocFileOpenDirectory + +[Nexus Mod Manager *] +Section=Games +DetectFile=%Documents%\Nexus Mod Manager +Default=False +FileKey1=%Documents%\Nexus Mod Manager|*.txt + +[NFS Hot Pursuit 2010 Saves *] +Section=Games +Detect=HKCU\Software\Electronic Arts\Need for Speed(TM) Hot Pursuit +Default=False +Warning=This will delete your saved games for NFS Hot Pursuit +FileKey1=%Documents%\Criterion Games|*.*|REMOVESELF + +[Nidhogg *] +Section=Games +DetectFile=%AppData%\Nidhogg +Default=False +FileKey1=%AppData%\Nidhogg|*.log + +[Nikon Capture NX2 *] +LangSecRef=3023 +Detect=HKLM\Software\Nikon\Capture NX 2 +Default=False +FileKey1=%LocalAppData%\Nikon\Capture NX\ThumbnailCache|*.*|RECURSE + +[Nikon ViewNX 2 Pic Viewer *] +LangSecRef=3023 +Detect=HKLM\Software\Nikon\MCA2\ViewNX 2 +Default=False +FileKey1=%LocalAppData%\Nikon\mPT\*\CacheData\Original|*.* +FileKey2=%LocalAppData%\Nikon\mPT\*\CacheData\Others|*.* +FileKey3=%LocalAppData%\Nikon\mPT\*\CacheData\Screen|*.* +FileKey4=%LocalAppData%\Nikon\mPT\*\CacheData\Thumbnail|*.* +FileKey5=%LocalAppData%\Nikon\ViewNX 2\Cache|*.* + +[Nimbuzz *] +LangSecRef=3022 +Detect=HKCU\Software\Nimbuzz +Default=False +FileKey1=%AppData%\nimbuzz|*.log + +[NirSoft AddrView LastUrlAddr *] +LangSecRef=3024 +Detect=HKCU\Software\NirSoft\AddrView +Default=False +RegKey1=HKCU\Software\NirSoft\AddrView|LastUrlAddr + +[NirSoft RegistryChangesView Snapshots *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\NirSoft\RegistryChangesView.exe +Default=False +FileKey1=%ProgramFiles%\NirSoft\RegSnapshot*|*.*|REMOVESELF +FileKey2=%ProgramFiles%\NirSoft\x64\RegSnapshot*|*.*|REMOVESELF + +[NirSoft RegScanner Reports *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\NirSoft RegScanner +DetectFile=%ProgramFiles%\Nirsoft\regscanner.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\NirSoft|report.html +FileKey2=%LocalAppData%\VirtualStore\Program Files*\NirSoft\x64|report.html +FileKey3=%ProgramFiles%\NirSoft|report.html +FileKey4=%ProgramFiles%\NirSoft\x64|report.html + +[Nitro PDF Reader *] +LangSecRef=3024 +Detect=HKCU\Software\Nitro PDF\Reader +Default=False +FileKey1=%AppData%\Nitro|*.log*;*Log.txt*|RECURSE +RegKey1=HKCU\Software\Nitro PDF\Reader\1.0\Recent File List +RegKey2=HKCU\Software\Nitro PDF\Reader\2.0\Recent File List + +[Nitrous Backups *] +Section=Games +DetectFile=%AppData%\.nitrous +Default=False +FileKey1=%AppData%\.nitrous\backups|*.*|REMOVESELF + +[nLite *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\nLite +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\nLite\Presets|*.* +FileKey2=%ProgramFiles%\nLite\Presets|*.* + +[No-IP DUC *] +LangSecRef=3022 +Detect=HKCU\Software\Vitalwerks\DUC +Default=False +FileKey1=%CommonAppData%\Vitalwerks\DUC|*.log +FileKey2=%LocalAppData%\Vitalwerks\DUC|*.log + +[Nokia Music Player *] +LangSecRef=3023 +DetectFile=%LocalAppData%\Nokia\Nokia Music* +Default=False +FileKey1=%LocalAppData%\Nokia\Nokia Music*|*.log + +[Nokia Software Updater *] +LangSecRef=3021 +Detect1=HKCU\Software\Nokia\NSU3 +Detect2=HKLM\Software\Nokia\Nokia Suite +DetectFile1=%CommonAppData%\Nokia\Nokia Service Layer\A +DetectFile2=%CommonProgramFiles%\Nokia\Service Layer\A +Default=False +Warning=This will remove Nokia phone firmwares, applications and other files stored by Nokia Suite Updater. Files will be re-downloaded when updating phone. +FileKey1=%CommonAppData%\Nokia\Nokia Service Layer\A|*.*|REMOVESELF +FileKey2=%CommonProgramFiles%\Nokia\Service Layer\A|*.*|REMOVESELF +FileKey3=%LocalAppData%\Nokia\NSU3\NOSSU2|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Common Files\Nokia\Service Layer\A|*.*|REMOVESELF +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Nokia\Nokia Service Layer\A|*.*|REMOVESELF +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Nokia\Nokia Suite\NOSSU2|*.*|RECURSE +ExcludeKey1=FILE|%LocalAppData%\Nokia\NSU3\NOSSU2\|usergroups.cfg +ExcludeKey2=PATH|%LocalAppData%\Nokia\NSU3\NOSSU2\Flash\|*.* + +[Nokia Suite Installer *] +LangSecRef=3021 +DetectFile=%CommonAppData%\NokiaInstallerCache +Default=False +FileKey1=%CommonAppData%\NokiaInstallerCache\PackageCache|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\NokiaInstallerCache\PackageCache|*.*|RECURSE + +[Norton *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Norton +Default=False +FileKey1=%CommonAppData%\Norton|*.log;*.txt +FileKey2=%CommonAppData%\Norton\LocalDumps|*.dmp +FileKey3=%CommonAppData%\NortonInstaller\Logs|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Norton\LocalDumps|*.dmp +FileKey5=%LocalAppData%\VirtualStore\ProgramData\NortonInstaller\Logs|*.*|RECURSE + +[Norton Power Eraser *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Norton\NPE\NPEsettings.dat +Default=False +Warning=This removes all files of Norton Power Eraser. This tool should be re-downloaded from Symantec after each run. +FileKey1=%CommonAppData%\Norton\NPE|*.*|REMOVESELF +FileKey2=%LocalAppData%\NPE|*.*|REMOVESELF +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Norton\NPE|*.*|REMOVESELF +FileKey4=%UserProfile%\Desktop|NPE.exe + +[Norton Utilities 15 *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Norton Utilities 15\nu.exe +Default=False +FileKey1=%AppData%\Norton Utilities\log|pgscan_*.html + +[Notepad++ *] +LangSecRef=3021 +Detect=HKLM\Software\Notepad++ +Default=False +FileKey1=%AppData%\Notepad++\plugins\config|PluginManagerGpup.xml;PluginManagerPlugins.xml;PluginManagerPlugins.zip +FileKey2=%AppData%\Notepad++\plugins\config\plugin_install_temp|*.*|REMOVESELF +FileKey3=%ProgramFiles%\Notepad++\plugins\disabled|*.* + +[Notepad++ Backups *] +LangSecRef=3021 +Detect=HKLM\Software\Notepad++ +Default=False +FileKey1=%AppData%\Notepad++\backup|*.*|REMOVESELF + +[Notifications *] +DetectOS=10.0| +LangSecRef=3025 +Default=False +FileKey1=%LocalAppData%\Microsoft\Windows\Notifications|*.tmp +FileKey2=%LocalAppData%\Microsoft\Windows\Notifications\wpnidm|*.*|RECURSE +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup +RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications\wpnidm + +[NowSmart Cut *] +LangSecRef=3023 +Detect=HKLM\Software\NowSmart\Cut +Default=False +FileKey1=%LocalAppData%\Cut|log.txt;*.dmp + +[Nox *] +LangSecRef=3024 +Detect=HKLM\Software\BigNox +DetectFile=%UserProfile%\.BigNox +Default=False +FileKey1=%LocalAppData%\Nox|Nox.log.*;*.log +FileKey2=%UserProfile%\.BigNox|*.log;*.log.* +FileKey3=%UserProfile%\vmlogs|Nox.log;Nox.log.* + +[Npcap Loopback Adapter *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Npcap +Default=False +FileKey1=%ProgramFiles%\NpCap|*.log|RECURSE + +[NSIS *] +LangSecRef=3021 +Detect=HKLM\Software\NSIS +Default=False +RegKey1=HKLM\Software\NSIS\MRU + +[NT Registry Optimizer *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\NT Registry Optimizer\NTREGOPT.EXE +Default=False +FileKey1=%LocalAppData%\Microsoft\Windows|UsrClass.bak +FileKey2=%WinDir%\ServiceProfiles\LocalService|NTUSER.bak +FileKey3=%WinDir%\ServiceProfiles\NetworkService|NTUSER.bak +FileKey4=%WinDir%\System32\config|COMPONENTS.bak;SYSTEM.bak;DEFAULT.bak;SAM.bak;SECURITY.bak;Software.bak + +[NTI Backup Now *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\New Tech Infosystems\NTI Backup Now 5 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\New Tech Infosystems\NTI Backup Now 5\logs|*.* +FileKey2=%ProgramFiles%\New Tech Infosystems\NTI Backup Now 5\logs|*.* + +[Nuance Dragon Natually Speaking 12 *] +LangSecRef=3021 +Detect=HKCU\Software\ScanSoft\NaturallySpeaking12 +Default=False +FileKey1=%AppData%\Nuance\NaturallySpeaking12\RIA|*DragonNatuallySpeakingRIA_IE_Shim_log_*.txt + +[Nuclear Dawn Cache *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\17710 +Default=False +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\config\html|*.*|RECURSE +FileKey2=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\cache|*.*|RECURSE +FileKey3=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\downloads|*.*|RECURSE +FileKey4=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\materials\temp|*.vtf|RECURSE + +[Nuclear Dawn Custom Content *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\17710 +Default=False +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps|*corner*;*roadwork*;*rock*;*frost*;*mars*|RECURSE +FileKey2=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\materials\models|*.*|RECURSE +FileKey3=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\materials\sprites|*.*|RECURSE +FileKey4=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\models|*.*|RECURSE +FileKey5=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\sound\quake|*.*|RECURSE + +[Nuclear Dawn Demos/Screenshots *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\17710 +Default=False +Warning=This will remove all demos and screenshots which are not uploaded to steam cloud. +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\donedemos|*.*|RECURSE +FileKey2=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps|*.dem*|RECURSE +FileKey3=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\screenshots|*.*|RECURSE + +[Nuclear Dawn Developer Files *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\17710 +Default=False +Warning=This will remove content used by game, map and community developers. +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\bin|*bsp*;*vtex*;SDKLauncher.exe;modelbrowser.exe|RECURSE +FileKey2=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps|*example*|RECURSE +FileKey3=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps\ai_data|nd_codetest.nav|RECURSE +FileKey4=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\scripts\scripted_props|*.*|REMOVESELF +FileKey5=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\scripts\units|*.*|REMOVESELF +FileKey6=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\scripts\vehicles|*.*|REMOVESELF +FileKey7=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\platform\AddOns|*.*|RECURSE +FileKey8=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\sdk_content|*.*|REMOVESELF +FileKey9=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\sdk_tools|*.*|REMOVESELF + +[Nuclear Dawn Mac/Linux Binaries *] +DetectOS=6.0| +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\17710 +Default=False +Warning=This will remove mac and linux binaries. +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\bin|client.so;client.dylib|RECURSE + +[Nuclear Dawn SK Gamemode *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\17710 +Default=False +Warning=Redownload of skrimish gamemode required to play. Not supported by all servers. +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps|*sk_*|RECURSE + +[Nuclear Dawn Tutorials *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\17710 +Default=False +Warning=This will prevent running of Nuclear Dawn Tutorials but will free over 850mb of disk space. +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps|*training*|RECURSE +FileKey2=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps\ai_data|*training*|RECURSE +FileKey3=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\media|*tutorial*|RECURSE +FileKey4=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\sound\voices\tutorial|*.*|REMOVESELF + +[NVIDIA *] +LangSecRef=3024 +Detect=HKLM\Software\NVIDIA Corporation +Default=False +FileKey1=%AppData%\NVIDIA\*Cache|*.*|RECURSE +FileKey2=%CommonAppData%\NVIDIA|*.log;*.log_backup1;Resource.old;*.bak|RECURSE +FileKey3=%CommonAppData%\NVIDIA Corporation|*.log;*bak;*log.*;*.old;*.stat|RECURSE +FileKey4=%CommonAppData%\NVIDIA Corporation\Downloader|*.*|RECURSE +FileKey5=%CommonAppData%\NVIDIA Corporation\GeForce Experience\Update|*.*|RECURSE +FileKey6=%CommonAppData%\NVIDIA\NvBackend\Updatus\DownloadManager|*.* +FileKey7=%CommonAppData%\NVIDIA\Updatus\DownloadManager|*.* +FileKey8=%LocalAppData%\NVIDIA Corporation|*.log;*.bak;*.old|RECURSE +FileKey9=%LocalAppData%\NVIDIA Corporation\*\CefCache|Cookies;Cookies-journal;QuotaManager;QuotaManager-journal +FileKey10=%LocalAppData%\NVIDIA Corporation\*\CefCache\*Cache|*.*|RECURSE +FileKey11=%LocalAppData%\NVIDIA\NvBackend|*.log;*.bak +FileKey12=%LocalAppData%\VirtualStore\Program Files*\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs|*.* +FileKey13=%LocalAppData%\VirtualStore\ProgramData\NVIDIA|*.log;*.log_backup1;Resource.old;*.bak|RECURSE +FileKey14=%LocalAppData%\VirtualStore\ProgramData\NVIDIA Corporation|*.log;*bak;*log.*;*.old;*.stat|RECURSE +FileKey15=%LocalAppData%\VirtualStore\ProgramData\NVIDIA Corporation\Downloader|*.*|RECURSE +FileKey16=%LocalAppData%\VirtualStore\ProgramData\NVIDIA Corporation\GeForce Experience\Update|*.*|RECURSE +FileKey17=%LocalAppData%\VirtualStore\ProgramData\NVIDIA Corporation\NetService|*.*|RECURSE +FileKey18=%LocalAppData%\VirtualStore\ProgramData\NVIDIA\NvBackend\Updatus\DownloadManager|*.* +FileKey19=%LocalAppData%\VirtualStore\ProgramData\NVIDIA\Updatus\DownloadManager|*.* +FileKey20=%ProgramFiles%\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs|*.* +FileKey21=%SystemDrive%\NvidiaLogging\GFExperience|GridClientLog.log*|RECURSE + +[O&O Defrag *] +LangSecRef=3024 +Detect=HKCU\Software\O&O\O&O Defrag +Default=False +FileKey1=%Documents%\O&O\O&O Defrag\data\reports|*.*|RECURSE + +[OBS *] +LangSecRef=3024 +DetectFile1=%AppData%\OBS +DetectFile2=%AppData%\obs-studio +Default=False +FileKey1=%AppData%\OBS|*.log|RECURSE +FileKey2=%AppData%\OBS\crashDumps|*.* +FileKey3=%AppData%\obs-studio\crashes|*.* +FileKey4=%AppData%\obs-studio\logs|*.* +FileKey5=%AppData%\obs-studio\profiler_data|*.* + +[OcenAudio MRU *] +LangSecRef=3023 +Detect1=HKCU\Software\OcenAudio +Detect2=HKLM\Software\OcenAudio +Default=False +FileKey1=%LocalAppData%\OcenAudio|ocen.database + +[Octoshape *] +LangSecRef=3023 +DetectFile=%LocalAppData%\Octoshape\Octoshape Streaming Services +Default=False +FileKey1=%LocalAppData%\Octoshape\Octoshape Streaming Services\temp|*.* + +[OEM Logs *] +LangSecRef=3021 +DetectFile1=%CommonAppData%\oem +DetectFile2=%SystemDrive%\OEM +DetectFile3=%WinDir%\System32\OEM +DetectFile4=%WinDir%\SysWOW64\OEM +Default=False +FileKey1=%CommonAppData%\oem|*.log|RECURSE +FileKey2=%SystemDrive%\OEM|*.log|RECURSE +FileKey3=%WinDir%\System32\OEM|*.log +FileKey4=%WinDir%\SysWOW64\OEM|*.log + +[Off-Road Drive *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\200230 +Default=False +FileKey1=%Documents%\My Games\PP3\PP3WorkGame\Logs|*.* + +[Office Password Recovery *] +LangSecRef=3024 +Detect=HKCU\Software\Intelore\Office Password Recovery +Default=False +FileKey1=%AppData%\Intelore\Password Recovery\logs|*.* + +[OMNITRACKER *] +LangSecRef=3021 +Detect=HKCU\Software\OmniNet\OmniTracker +Default=False +FileKey1=%LocalAppData%\OMNINET GmbH\OMNITRACKER\Temp|*.*|RECURSE +RegKey1=HKCU\Software\OmniNet\OmniTracker\MRU +RegKey2=HKCU\Software\OmniNet\OmniTracker\SearchTextHistory + +[OneConnect *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.OneConnect_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalCache\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalState\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalState\DiagOutputDir|*.txt +FileKey7=%LocalAppData%\Packages\Microsoft.OneConnect_*\TempState|*.*|RECURSE + +[OneDrive *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\OneDrive +Default=False +FileKey1=%LocalAppData%\Microsoft\OneDrive\logs|*.*|RECURSE +FileKey2=%LocalAppData%\Microsoft\OneDrive\setup\logs|*.*|RECURSE +FileKey3=%LocalAppData%\Microsoft\Windows\OneDrive\logs|*.*|RECURSE + +[OneNote *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local|msodata*.dat +FileKey6=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\office*client.microsoft.com|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\OTele|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0|*.onecache +FileKey9=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0\OneNote*Cache_Files|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe\SearchHistory + +[OneTeam *] +LangSecRef=3022 +Detect=HKCU\Software\OneTeam +Default=False +FileKey1=%AppData%\oneteam\profiles\*\oneteamcachefiles|*.*|RECURSE +FileKey2=%LocalAppData%\oneteam\profiles\*\cache|*.*|RECURSE + +[Online Armor *] +LangSecRef=3021 +Detect=HKLM\Software\Tall Emu\Online Armor +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Tall Emu\Online Armor\Logs|*.* +FileKey2=%ProgramFiles%\Tall Emu\Online Armor\Logs|*.* + +[Ontrack EasyRecovery *] +LangSecRef=3024 +Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{668CC71A-C2AD-4D56-866D-CF300BD1D5BE}_is1 +Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AE695CA4-8847-4462-98CC-023874D29E72}_is1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Kroll Ontrack\Ontrack EasyRecovery*|*erent_log.txt;*erpro_log.txt +FileKey2=%ProgramFiles%\Kroll Ontrack\Ontrack EasyRecovery*|*erent_log.txt;*erpro_log.txt + +[Ookla Speed Test *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Ookla.SpeedtestbyOokla_43tkc6nmykmb6 +DetectFile=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_43tkc6nmykmb6 +Default=False +FileKey1=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey3=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\AC\Temp|*.* +FileKey4=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\LocalState|*.tmp|RECURSE +FileKey5=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\LocalState\Unity\Local.*\Analytics\ArchivedEvents\*|*.*|REMOVESELF +FileKey6=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\TempState|*.*|RECURSE + +[ooVoo Chat History *] +LangSecRef=3022 +Detect=HKCU\Software\ooVoo +Default=False +FileKey1=%AppData%\ooVoo Details\Users|chathistory.db|RECURSE + +[ooVoo Toolbar *] +LangSecRef=3022 +DetectFile=%LocalLowAppData%\oovootoolbar +Default=False +FileKey1=%LocalLowAppData%\oovootoolbar|log.txt + +[OpalCalc *] +LangSecRef=3021 +DetectFile1=%AppData%\OpalCalc_prefs +DetectFile2=%ProgramFiles%\OpalCalc +Default=False +FileKey1=%AppData%\OpalCalc_prefs|lastSession.txt + +[Open Blu-ray to DVD *] +LangSecRef=3023 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Blu-ray to DVD Pro_is1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Blu-ray to DVD*|*.log;*.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Blu-ray to DVD*\ReadCache|*.* +FileKey3=%ProgramFiles%\Blu-ray to DVD*|*.log;*.txt +FileKey4=%ProgramFiles%\Blu-ray to DVD*\ReadCache|*.* + +[Open Blu-ray/DVD Ripper *] +LangSecRef=3023 +Detect1=HKCU\Software\OpenCloner\BDRipper +Detect2=HKCU\Software\OpenCloner\DVDRipper +Default=False +FileKey1=%AppData%\Open * Ripper|O*R_LOG_FILE.txt +FileKey2=%AppData%\Open * Ripper\ReadCache|*.*|REMOVESELF + +[Open with Arguments *] +LangSecRef=3024 +Detect=HKCU\Software\OpenArgs +Default=False +RegKey1=HKCU\Software\OpenArgs\History + +[OpenDNS Updater *] +LangSecRef=3021 +Detect=HKCU\Software\OpenDNS Updater +Default=False +Warning=You must exit OpenDNS Updater in the System Tray to clear log files. +FileKey1=%AppData%\OpenDNS Updater|*.txt + +[OpenFire *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Openfire +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Openfire\Logs|*.* +FileKey2=%ProgramFiles%\Openfire\Logs|*.* + +[OpenMG *] +LangSecRef=3023 +DetectFile=%CommonAppData%\Sony Corporation\OpenMG +Default=False +FileKey1=%CommonAppData%\Sony Corporation\OpenMG|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sony Corporation\OpenMG|*.log + +[OpenMG CD Backups *] +LangSecRef=3023 +DetectFile=%CommonAppData%\Sony Corporation\OpenMG +Default=False +FileKey1=%CommonAppData%\Sony Corporation\OpenMG\CD Walkman\Temp|*.*|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sony Corporation\OpenMG\CD Walkman\Temp|*.*|REMOVESELF + +[OpenMG Jukebox *] +LangSecRef=3023 +DetectFile=%AppData%\Sony\OpenMG Jukebox +Default=False +FileKey1=%AppData%\Sony\OpenMG Jukebox\Temp|*.* + +[OpenOffice.org *] +LangSecRef=3021 +Detect1=HKLM\Software\OpenOffice +Detect2=HKLM\Software\OpenOffice.org +Default=False +FileKey1=%AppData%\OpenOffice*\*\user|*.log;*.log.txt;*.tmp;registrymodifications.xcu;registration.xml|RECURSE +FileKey2=%AppData%\OpenOffice*\*\user\config\imagecache|*.* +FileKey3=%AppData%\OpenOffice*\*\user\registry\cache|*.* +FileKey4=%AppData%\OpenOffice*\*\user\registry\data\org\openoffice\Office|Views.xcu;Writer.xcu;Common.xcu;Histories.xcu +FileKey5=%AppData%\OpenOffice*\*\user\registry\data\org\openoffice\ucb|Hierarchy.xcu;Store.xcu +FileKey6=%ProgramFiles%\OpenOffice*\share\uno_packages\cache\uno_packages|*.tmp;*.log;log.txt + +[OpenOffice.org Setup Files *] +LangSecRef=3021 +Detect1=HKLM\Software\OpenOffice +Detect2=HKLM\Software\OpenOffice.org +Default=False +FileKey1=%UserProfile%\Desktop\OpenOffice.org * Installation Files|*.*|REMOVESELF + +[OpenRA *] +Section=Games +DetectFile=%Documents%\OpenRA +Default=False +FileKey1=%Documents%\OpenRA\Logs|*.* + +[OpenRA Replays *] +Section=Games +DetectFile=%Documents%\OpenRA +Default=False +Warning=This will remove all of your Replays. +FileKey1=%Documents%\OpenRA\Replays|*.*|RECURSE + +[OpenVPN *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\OpenVPN +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\OpenVPN\Log|*.* +FileKey2=%ProgramFiles%\OpenVPN\Log|*.* + +[Opera *] +LangSecRef=3027 +Detect=HKCU\Software\Opera Software +DetectFile=%LocalAppData%\Opera\Opera* +Default=False +FileKey1=%AppData%\Opera Software\Opera*|ssdfp*.* +FileKey2=%LocalAppData%\Opera\Opera*\application_cache|*.*|REMOVESELF +FileKey3=%LocalAppData%\Opera\Opera*\icons|*.*|REMOVESELF +FileKey4=%LocalAppData%\Opera\Opera*\logs|*.*|REMOVESELF +FileKey5=%LocalAppData%\Opera\Opera*\temporary_downloads|*.*|REMOVESELF +FileKey6=%LocalAppData%\Opera\Opera*\thumbnails|*.*|REMOVESELF +FileKey7=%LocalAppData%\Opera\Opera*\vps|*.*|REMOVESELF +RegKey1=HKCU\Software\Opera Software|Last CommandLine v2 + +[Opera 9 Classic *] +LangSecRef=3027 +DetectFile=%ProgramFiles%\Opera 9\Opera.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Opera 9\profile|cookies4.dat;vlink4.dat;global.dat +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Opera 9\profile\cache*|*.* +FileKey3=%ProgramFiles%\Opera 9\profile|cookies4.dat;vlink4.dat;global.dat +FileKey4=%ProgramFiles%\Opera 9\profile\cache*|*.* + +[Optimizer Pro *] +LangSecRef=3024 +Detect=HKCU\Software\Optimizer Pro +Default=False +FileKey1=%AppData%\Optimizer Pro\Log|*.* + +[OptimumLink *] +LangSecRef=3021 +DetectFile=%AppData%\OptimumLink +Default=False +FileKey1=%AppData%\OptimumLink|TrayLogs*.* + +[Orbit Downloader *] +LangSecRef=3022 +Detect=HKLM\Software\Orbit +Default=False +FileKey1=%AppData%\Orbit|history.dat;DownloadList.dat;unfinish.dat;softI.dat;updateslist.xml +FileKey2=%AppData%\Orbit\flink|*.* +FileKey3=%AppData%\Orbit\icon|*.*|RECURSE + +[Orca *] +LangSecRef=3024 +Detect=HKCU\Software\Microsoft\Orca +Default=False +RegKey1=HKCU\Software\Microsoft\Orca\Recent File List + +[Orcs Must Die! Unchained *] +Section=Games +Detect1=HKCU\Software\Robot Entertainment\Orcs Must Die! Unchained +Detect2=HKCU\Software\Valve\Steam\Apps\427270 +Default=False +FileKey1=%Documents%\My Games\Orcs Must Die Unchained\SpitfireGame\Logs|*.log;*.dmg|RECURSE + +[Origin *] +Section=Games +Detect=HKLM\Software\Classes\Origin +Default=False +FileKey1=%CommonAppData%\Origin\*Cache|*.*|RECURSE +FileKey2=%CommonAppData%\Origin\Logs|*.* +FileKey3=%CommonAppData%\Origin\Telemetry|*.* +FileKey4=%LocalAppData%\Origin\Origin\cache|*.*|RECURSE +FileKey5=%LocalAppData%\Origin\Web Cache|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Origin\*Cache|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Origin\Logs|*.* +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Origin\Telemetry|*.* +FileKey9=%SystemDrive%|shared.log + +[Origin Installers *] +Section=Games +Detect=HKLM\Software\Classes\Origin +Default=False +FileKey1=%LocalAppData%\Origin\ThinSetup|*.*|REMOVESELF +FileKey2=%ProgramFiles%\Origin Games|*.cab;vc_red.msi;gfwlivesetup.exe;GamesExplorerIntegrationTool.exe;install.ini;globdata.ini;vcredist.bmp;vc_red.exe;install.exe;install.res.*.dll;eula.*.txt;vcredist_x64.exe;dotNetFx40_Full_setup.exe;dotNetFx40_Full_x86_x64.exe;xnafx40_redist.msi;DSETUP.DLL;oalinst.exe;DXSETUP.EXE;dsetup32.dll;dotnetfx3setup;vcredist_x86.exe;dxwebsetup.exe;xnafx31_redist.msi;dotNetFx35setup.exe;dotnetfx35.exe|RECURSE + +[Osmos *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\29180 +Default=False +FileKey1=%Documents%\Osmos|osmos.log + +[osu! *] +Section=Games +Detect=HKCU\Software\Osu! +Default=False +FileKey1=%LocalAppData%\osu!\logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Osu!|debug-import.txt +FileKey3=%ProgramFiles%\Osu!|debug-import.txt + +[Outlast *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\238320 +Default=False +FileKey1=%Documents%\My Games\Outlast\OLGame\Logs|*.dmp;*.log + +[Outlook 2003 *] +LangSecRef=3021 +Detect=HKCU\Software\Microsoft\Office\11.0\Outlook +Default=False +FileKey1=%AppData%\Microsoft\Outlook|Outlook.NK2 +RegKey1=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 1 +RegKey2=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 2 +RegKey3=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 3 + +[Outlook Appointment Location *] +LangSecRef=3021 +Detect1=HKCU\Software\Microsoft\Office\9.0\Outlook +Detect2=HKCU\Software\Microsoft\Office\11.0\Outlook +Detect3=HKCU\Software\Microsoft\Office\12.0\Outlook +Detect4=HKCU\Software\Microsoft\Office\14.0\Outlook +Detect5=HKCU\Software\Microsoft\Office\15.0\Outlook +Detect6=HKCU\Software\Microsoft\Office\16.0\Outlook +Default=False +Warning=This Will Remove the Most Frequent Appointment Locations from all Outlook Versions. +RegKey1=HKCU\Software\Microsoft\Office\9.0\Outlook\Preferences|LocationMRU +RegKey2=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU +RegKey3=HKCU\Software\Microsoft\Office\12.0\Outlook\Preferences|LocationMRU +RegKey4=HKCU\Software\Microsoft\Office\14.0\Outlook\Preferences|LocationMRU +RegKey5=HKCU\Software\Microsoft\Office\15.0\Outlook\Preferences|LocationMRU +RegKey6=HKCU\Software\Microsoft\Office\16.0\Outlook\Preferences|LocationMRU + +[Outpost Firewall Pro *] +LangSecRef=3021 +Detect=HKLM\Software\Agnitum\Outpost Firewall +Default=False +FileKey1=%CommonAppData%\Agnitum\Security Suite\Feedback\Logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Agnitum\Outpost Firewall Pro\log|*.* +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Agnitum\Security Suite\Feedback\Logs|*.* +FileKey4=%ProgramFiles%\Agnitum\Outpost Firewall Pro\log|*.* + +[Outpost Security Suite *] +LangSecRef=3021 +Detect=HKLM\Software\Agnitum\Security Suite +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Agnitum\Outpost Security Suite Pro\log|*.log +FileKey2=%ProgramFiles%\Agnitum\Outpost Security Suite Pro\log|*.log + +[Overwatch *] +Section=Games +DetectFile=%Documents%\Overwatch +Default=False +FileKey1=%Documents%\Overwatch\Logs|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Overwatch\WebBrowserProxy\cache\browser|*.* +FileKey3=%ProgramFiles%\Overwatch\WebBrowserProxy\cache\browser|*.* +FileKey4=%ProgramFiles%\Overwatch\WebBrowserProxy\logs\browser|*.* + +[OVH HubiC *] +LangSecRef=3021 +Detect=HKCU\Software\OVH\hubiC-browser +Default=False +FileKey1=%LocalAppData%\OVH\hubiC-browser\cache\data7|*.*|RECURSE + +[Oxygen 14 *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Oxygen XML Editor 14 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Oxygen XML Editor 14|*.properties;*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Oxygen XML Editor 14\.install4j|*.log +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Oxygen XML Editor 14\dicts|*.txt;*.html +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Oxygen XML Editor 14\lib|*.txt|RECURSE +FileKey5=%ProgramFiles%\Oxygen XML Editor 14|*.properties;*.log +FileKey6=%ProgramFiles%\Oxygen XML Editor 14\.install4j|*.log +FileKey7=%ProgramFiles%\Oxygen XML Editor 14\dicts|*.txt;*.html +FileKey8=%ProgramFiles%\Oxygen XML Editor 14\lib|*.txt|RECURSE +ExcludeKey1=FILE|%ProgramFiles%\Oxygen XML Editor 14\.install4j\|files.log + +[Pacific Storm *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\11250 +DetectFile=%ProgramFiles%\Buka\Pacific Storm +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Buka\Pacific Storm|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Pacific Storm*|*.log|RECURSE +FileKey3=%ProgramFiles%\Buka\Pacific Storm|*.log|RECURSE +FileKey4=%ProgramFiles%\Steam\SteamApps\Common\Pacific Storm*|*.log|RECURSE + +[Paint 3D *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MSPaint_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.MSPaint_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.MSPaint_*\LocalCache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.MSPaint_*\LocalState|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.MSPaint_*\TempState|*.*|RECURSE + +[Paint.NET *] +LangSecRef=3021 +Detect=HKCU\Software\Paint.NET +Default=False +FileKey1=%LocalAppData%\Paint.NET|*.*|RECURSE +RegKey1=HKCU\Software\Paint.NET|LastFileDialogDirectory + +[Paltalk Messenger *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Paltalk Messenger\paltalk.exe +Default=False +FileKey1=%AppData%\Paltalk|*.*|RECURSE + +[Panda Antivirus *] +LangSecRef=3024 +Detect=HKLM\Software\Panda Security +Default=False +FileKey1=%CommonAppData%\Panda Security\Panda Devices Agent\Logs|*.* +FileKey2=%CommonAppData%\Panda Security\Panda Security Protection|*.log +FileKey3=%CommonAppData%\Panda Security\PSLogs|*.log + +[Pandion *] +LangSecRef=3022 +Detect=HKCU\Software\Pandion +Default=False +FileKey1=%AppData%\Pandion\Avatars|*.*|RECURSE +FileKey2=%AppData%\Pandion\Message Cache|*.*|RECURSE + +[Pandion Chat Logs *] +LangSecRef=3022 +Detect=HKCU\Software\Pandion +Default=False +FileKey1=%AppData%\Pandion\Profiles|*.log;*.buffer|RECURSE + +[Pando *] +LangSecRef=3024 +Detect=HKCU\Software\Pando Networks\Pando +Default=False +Warning=Make sure Pando is totally shut down before using this. +FileKey1=%LocalAppData%\Pando\Pando Files|*.*|RECURSE +ExcludeKey1=PATH|%LocalAppData%\Pando\Pando Files\|*pando.prev.log;*pando.log;*pando.sav;*pando.save;*pando.txt +ExcludeKey2=PATH|%LocalAppData%\Pando\Pando Files\Cert\|*.* + +[Pando Media Booster *] +Section=Games +Detect=HKCU\Software\Pando Networks\PMB +Default=False +FileKey1=%CommonAppData%\PMB Files|*.TOK;*.log +FileKey2=%LocalAppData%\PMB Files\*|*.CT1;*.CT2;*.dat;*.log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\PMB Files|*.TOK;*.log + +[Paragon Hard Disk Manager 12 Suite *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Paragon Software\Hard Disk Manager 12 Suite +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Paragon Software\Hard Disk Manager 12 Suite|*.log +FileKey2=%ProgramFiles%\Paragon Software\Hard Disk Manager 12 Suite|*.log + +[Paragon Hard Disk Manager 14 Suite *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Paragon Software\Hard Disk Manager 14 Suite +Default=False +FileKey1=%CommonAppData%\clonehdd|*.log +FileKey2=%CommonAppData%\createpart|*.log +FileKey3=%CommonAppData%\deletepart|*.log +FileKey4=%CommonAppData%\explauncher|*.log +FileKey5=%CommonAppData%\ftw|*.log +FileKey6=%CommonAppData%\launcher|*.log +FileKey7=%CommonAppData%\logsaver|*.log +FileKey8=%CommonAppData%\migrateos|*.log +FileKey9=%CommonAppData%\redistpart|*.log +FileKey10=%CommonAppData%\vmadjust|*.log +FileKey11=%CommonAppData%\vmcreate|*.log +FileKey12=%CommonAppData%\wipe|*.log +FileKey13=%LocalAppData%\VirtualStore\Program Files*\Paragon Software\Hard Disk Manager 14 Suite\*|BioNtLog.txt;cdb.log;fdisk.txt;pwlog.txt;stubact.log +FileKey14=%LocalAppData%\VirtualStore\Program Files*\Paragon Software\Hard Disk Manager 14 Suite\*\symmpi*|*.txt +FileKey15=%LocalAppData%\VirtualStore\ProgramData\clonehdd|*.log +FileKey16=%LocalAppData%\VirtualStore\ProgramData\createpart|*.log +FileKey17=%LocalAppData%\VirtualStore\ProgramData\deletepart|*.log +FileKey18=%LocalAppData%\VirtualStore\ProgramData\explauncher|*.log +FileKey19=%LocalAppData%\VirtualStore\ProgramData\ftw|*.log +FileKey20=%LocalAppData%\VirtualStore\ProgramData\launcher|*.log +FileKey21=%LocalAppData%\VirtualStore\ProgramData\logsaver|*.log +FileKey22=%LocalAppData%\VirtualStore\ProgramData\migrateos|*.log +FileKey23=%LocalAppData%\VirtualStore\ProgramData\redistpart|*.log +FileKey24=%LocalAppData%\VirtualStore\ProgramData\vmadjust|*.log +FileKey25=%LocalAppData%\VirtualStore\ProgramData\vmcreate|*.log +FileKey26=%ProgramFiles%\Paragon Software\Hard Disk Manager 14 Suite\*|BioNtLog.txt;cdb.log;fdisk.txt;pwlog.txt;stubact.log +FileKey27=%ProgramFiles%\Paragon Software\Hard Disk Manager 14 Suite\*\symmpi*|*.txt +FileKey28=%SystemDrive%\Documents and Settings\LocalService|objsrv.log + +[Paragon Partition Manager 2014 *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Paragon Software\Partition Manager 2014 +Default=False +FileKey1=%CommonAppData%\converthfs|*.log +FileKey2=%CommonAppData%\createpart|*.log +FileKey3=%CommonAppData%\deletepart|*.log +FileKey4=%CommonAppData%\explauncher|*.log +FileKey5=%CommonAppData%\formatpart|*.log +FileKey6=%CommonAppData%\launcher|*.log +FileKey7=%CommonAppData%\logsaver|*.log +FileKey8=%CommonAppData%\redistpart|*.log +FileKey9=%LocalAppData%\VirtualStore\Program Files*\Paragon Software\*\program|BioNtLog.txt;cdb.log;fdisk.txt;pwlog.txt;stubact.log +FileKey10=%LocalAppData%\VirtualStore\ProgramData\converthfs|*.log +FileKey11=%LocalAppData%\VirtualStore\ProgramData\createpart|*.log +FileKey12=%LocalAppData%\VirtualStore\ProgramData\deletepart|*.log +FileKey13=%LocalAppData%\VirtualStore\ProgramData\explauncher|*.log +FileKey14=%LocalAppData%\VirtualStore\ProgramData\formatpart|*.log +FileKey15=%LocalAppData%\VirtualStore\ProgramData\launcher|*.log +FileKey16=%LocalAppData%\VirtualStore\ProgramData\logsaver|*.log +FileKey17=%LocalAppData%\VirtualStore\ProgramData\redistpart|*.log +FileKey18=%ProgramFiles%\Paragon Software\*\program|BioNtLog.txt;cdb.log;fdisk.txt;pwlog.txt;stubact.log +FileKey19=%SystemDrive%\Documents and Settings\LocalService|objsrv.log + +[Paragon Total Defrag 2010 *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Paragon Software\Total Defrag 2010 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Paragon Software\Total Defrag 2010|*.log;biontlog.txt|RECURSE +FileKey2=%ProgramFiles%\Paragon Software\Total Defrag 2010|*.log;biontlog.txt|RECURSE + +[Paramount Dynamic *] +LangSecRef=3023 +DetectFile=%LocalAppData%\Microsoft\Windows\Themes\ParamountDynamic.theme +Default=False +Warning=This will cause you to redownload the Paramount Dynamic RSS file. +FileKey1=%LocalAppData%\Microsoft\Feeds|http~c~f~fthemeserver~dmicrosoft~dcom~fdefault~daspx~mp*Paramount* + +[Paranormal *] +Section=Games +DetectFile=%ProgramFiles%\Desura\Common\paranormal +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Desura\Common\paranormal\UDKGame\Logs|*.* +FileKey2=%ProgramFiles%\Desura\Common\paranormal\UDKGame\Logs|*.* + +[Paranormal Agency *] +Section=Games +DetectFile=%AppData%\Shape Games\Paranormal_v* +Default=False +FileKey1=%AppData%\Shame Games\Paranormal_v*\logs|*.* + +[Partner Application *] +LangSecRef=3022 +DetectFile=%CommonAppData%\Partner +Default=False +FileKey1=%CommonAppData%\Partner|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Partner|*.log + +[Patch My PC *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Patch_My_PC,_LLC +Default=False +FileKey1=%LocalAppData%\Patch_My_PC,_LLC|*.*|RECURSE + +[Path of Exile *] +Section=Games +Detect1=HKCU\Software\GrindingGearGames\Path of Exile +Detect2=HKCU\Software\Valve\Steam\Apps\238960 +Default=False +FileKey1=%Documents%\My Games\Path of Exile\Minimap|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Grinding Gear Games\Path of Exile\Logs|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Path of Exile\logs|*.* +FileKey4=%ProgramFiles%\Grinding Gear Games\Path of Exile\Logs|*.* +FileKey5=%ProgramFiles%\Steam\steamapps\common\Path of Exile\logs|*.* + +[PAYDAY 2 *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\218620 +DetectFile=%LocalAppData%\PAYDAY 2 +Default=False +FileKey1=%LocalAppData%\PAYDAY 2|crash.txt;crashlog.txt + +[PC Doctor *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\PC-Doctor For Windows +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\PC-Doctor For Windows\Logs|*.* +FileKey2=%ProgramFiles%\PC-Doctor For Windows\Logs|*.* + +[PC Optimizer Pro *] +LangSecRef=3024 +DetectFile=%CommonAppData%\PC optimizer pro +Default=False +FileKey1=%CommonAppData%\PC Optimizer Pro\Logs|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\PC Optimizer Pro\Logs|*.* + +[PC Tools Performance Toolkit *] +LangSecRef=3024 +DetectFile=%AppData%\PC Tools Performance Toolkit +Default=False +FileKey1=%AppData%\PC Tools Performance Toolkit\CleanReports|*.* +FileKey2=%CommonAppData%\PC Tools\Performance Toolkit\Defrag\Logs|*.* +FileKey3=%CommonAppData%\PC Tools\Performance Toolkit\Repair\Logs|*.* +FileKey4=%LocalAppData%\VirtualStore\Program Files*\PC Tools\*\~tmp|*.* +FileKey5=%LocalAppData%\VirtualStore\Program Files*\PC Tools\*\Log|*.* +FileKey6=%LocalAppData%\VirtualStore\ProgramData\PC Tools\Performance Toolkit\Defrag\Logs|*.* +FileKey7=%LocalAppData%\VirtualStore\ProgramData\PC Tools\Performance Toolkit\Repair\Logs|*.* +FileKey8=%ProgramFiles%\PC Tools\*\~tmp|*.* +FileKey9=%ProgramFiles%\PC Tools\*\Log|*.* + +[PC Tools sMonitor *] +LangSecRef=3024 +DetectFile=%CommonProgramFiles%\PC Tools\sMonitor +Default=False +FileKey1=%CommonProgramFiles%\PC Tools\sMonitor|cputime.xml;logfile.etl +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Common Files\PC Tools\sMonitor|cputime.xml;logfile.etl + +[PCFresh *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Abelssoft\PCFresh +Default=False +FileKey1=%LocalAppData%\Abelssoft\PCFresh\Backup|*.* + +[PCSX2 *] +Section=Games +DetectFile=%Documents%\PCSX2 +Default=False +FileKey1=%Documents%\PCSX2\logs|*.*|RECURSE + +[PCSX2 Snaps *] +Section=Games +DetectFile=%Documents%\PCSX2 +Default=False +FileKey1=%Documents%\PCSX2\snaps|*.*|RECURSE + +[PDF-XChange Editor *] +LangSecRef=3021 +Detect=HKCU\Software\Tracker Software\PDFXEditor +Default=False +FileKey1=%CommonAppData%\Tracker Software\Update|TrackerUpdate.exe.del + +[PDF-XChange Viewer *] +LangSecRef=3021 +Detect=HKCU\Software\Tracker Software\PDFViewer +Default=False +FileKey1=%CommonAppData%\Tracker Software\TrackerUpdate|TrackerUpdate.exe.del +FileKey2=%LocalAppData%\Tracker Software\LiveUpdate\Updates|*.* +RegKey1=HKCU\Software\Tracker Software\PDFViewer\Documents\LastOpened +RegKey2=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Bars +RegKey3=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Panes + +[PDF Annotator *] +LangSecRef=3021 +Detect=HKCU\Software\GRAHL\PDFAnnotator +Default=False +RegKey1=HKCU\Software\GRAHL\PDFAnnotator\3.0\Files\MRUItems +RegKey2=HKCU\Software\GRAHL\PDFAnnotator\4.0\Files\MRUItems + +[PDF Plus *] +LangSecRef=3021 +DetectFile=%AppData%\Zeon\DocuCom\PDF Plus +Default=False +FileKey1=%AppData%\Zeon\DocuCom\PDF Plus\Log|*.* + +[PDF24 Creator *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\PDF24 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\PDF24|*.log +FileKey2=%ProgramFiles%\PDF24|*.log + +[PE Module Explorer *] +LangSecRef=3024 +Detect=HKCU\Software\Woozle\PE Module Explorer +Default=False +RegKey1=HKCU\Software\Woozle\PE Module Explorer\Recent Files + +[Peerblock *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Peerblock +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Peerblock|*.log;History.db;*.bak;cache.p2b +FileKey2=%ProgramFiles%\Peerblock|*.log;History.db;*.bak;cache.p2b +FileKey3=%ProgramFiles%\Peerblock\lists|*.list.failed* + +[PeerNetworking *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%SystemDrive%\Documents and Settings\LocalService\Application Data\PeerNetworking|*.*|RECURSE +FileKey2=%WinDir%\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking|*.*|RECURSE + +[Pelles C *] +LangSecRef=3021 +Detect=HKCU\Software\Pelle Orinius\PellesC +Default=False +RegKey1=HKCU\Software\Pelle Orinius\PellesC\Recent File List +RegKey2=HKCU\Software\Pelle Orinius\PellesC\Recent Project List +RegKey3=HKCU\Software\Pelle Orinius\PellesC\Recent Search List + +[People *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.People_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.People_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.People_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.People_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.People_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.People_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.People_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.People_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.People_*\TempState|*.*|RECURSE + +[Perfect Registry *] +LangSecRef=3024 +Detect=HKCU\Software\Raxco\PerfectRegistry +Default=False +FileKey1=%AppData%\Raxco\PerfectRegistry|log*.log;TempHLList.rcp + +[PerfectDisk *] +LangSecRef=3024 +Detect=HKCU\Software\Raxco\PerfectDisk +Default=False +FileKey1=%CommonAppData%\Raxco\PerfectDisk\*|*.log;*.txt;PDBootLog +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Raxco\PerfectDisk\*|*.log;*.txt + +[PerfectUpdater *] +LangSecRef=3024 +Detect=HKCU\Software\Raxco\PerfectUpdater +Default=False +Warning=This cleans the installation logs, backup files after updating, and the downloads for new updates used for updating your drivers. +FileKey1=%AppData%\Raxco\PerfectUpdater|*.log +FileKey2=%AppData%\Raxco\PerfectUpdater\Backup|*.* +FileKey3=%AppData%\Raxco\PerfectUpdater\Download|*.* + +[Performance Maintainer *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\PC Starters\Performance Maintainer +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\PC Starters\Performance Maintainer\Backups|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\PC Starters\Performance Maintainer\log*|*.*|RECURSE +FileKey3=%ProgramFiles%\PC Starters\Performance Maintainer\Backups|*.*|RECURSE +FileKey4=%ProgramFiles%\PC Starters\Performance Maintainer\log*|*.*|RECURSE + +[Pet Pals Animal Doctor *] +Section=Games +Detect=HKLM\Software\Legacy Interactive\Pet Pals +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Legacy Interactive\Pet Pals Animal Doctor|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Legacy Interactive\Pet Pals Animal Doctor\jre|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Legacy Interactive\Pet Pals Animal Doctor\temp|*.*|REMOVESELF +FileKey4=%ProgramFiles%\Legacy Interactive\Pet Pals Animal Doctor|*.log +FileKey5=%ProgramFiles%\Legacy Interactive\Pet Pals Animal Doctor\jre|*.* +FileKey6=%ProgramFiles%\Legacy Interactive\Pet Pals Animal Doctor\temp|*.*|REMOVESELF +ExcludeKey1=PATH|%ProgramFiles%\Legacy Interactive\Pet Pals Animal Doctor\jre\bin\|*.* +ExcludeKey2=PATH|%ProgramFiles%\Legacy Interactive\Pet Pals Animal Doctor\jre\lib\|*.* + +[phase-6 *] +LangSecRef=3021 +DetectFile=%UserProfile%\.phase-6 +Default=False +FileKey1=%UserProfile%\.phase-6|window-position.txt +FileKey2=%UserProfile%\.phase-6\logs|phase-6.log + +[Phone *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsPhone_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\TempState|*.*|RECURSE + +[Phorest *] +LangSecRef=3024 +Detect=HKCU\Software\FutureFog\Phorest\Options +Default=False +RegKey1=HKCU\Software\FutureFog\Phorest\Layout|SelectionHeight +RegKey2=HKCU\Software\FutureFog\Phorest\Layout|SelectionLeft +RegKey3=HKCU\Software\FutureFog\Phorest\Layout|SelectionTop +RegKey4=HKCU\Software\FutureFog\Phorest\Layout|SelectionWidth +RegKey5=HKCU\Software\FutureFog\Phorest\Options|LastUsedFolder + +[Photo Print Calendar 3.00E Beta *] +LangSecRef=3021 +Detect=HKLM\Software\Computer Institute of Japan, Ltd.\Photo Print Calendar from YOKOHAMA Ver.3.00E beta\3.00E beta +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Photo Print Calendar|update.bmp +FileKey2=%ProgramFiles%\Photo Print Calendar|update.bmp + +[Photo Stamp Remover *] +LangSecRef=3023 +Detect=HKCU\Software\softorbits\PhotoStampRemover +Default=False +RegKey1=HKCU\Software\softorbits\PhotoStampRemover|currentFile + +[Photo! Editor *] +LangSecRef=3024 +Detect=HKCU\Software\VicMan Software\Photo! Editor +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Photo!\Photo! Editor|*.log +FileKey2=%ProgramFiles%\Photo!\Photo! Editor|*.log +RegKey1=HKCU\Software\VicMan Software\Photo! Editor|LastFolder + +[Photodex ProShow Producer *] +LangSecRef=3021 +Detect=HKCU\Software\Photodex\ProShow +Default=False +FileKey1=%CommonAppData%\Photodex\ProShow|*.log|RECURSE +FileKey2=%CommonAppData%\Photodex\ProShow\FontCache|*.*|REMOVESELF +FileKey3=%CommonAppData%\Photodex\ProShow\Styles\Cache|*.*|REMOVESELF +FileKey4=%CommonAppData%\Photodex\ProShow\Transitions\Cache|*.*|REMOVESELF +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Photodex\ProShow Producer|*.log|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Photodex\ProShow|*.log|RECURSE +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Photodex\ProShow\FontCache|*.*|REMOVESELF +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Photodex\ProShow\Styles\Cache|*.*|REMOVESELF +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Photodex\ProShow\Transitions\Cache|*.*|REMOVESELF +FileKey10=%ProgramFiles%\Photodex\ProShow Producer|*.log|RECURSE +FileKey11=%UserProfile%|proshow-burn.log +ExcludeKey1=FILE|%ProgramFiles%\Photodex\ProShow Producer\pxf\images\|xicons.txt + +[Photos *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalCache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState|*.etl;*.sqlite;*.sqlite-shm;*.sqlite-wal;*.xml +FileKey6=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState\PhotosAppTile|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedPickerData\Microsoft.Windows.Photos_8wekyb3d8bbwe!App\DefaultSaveFileSingle +RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp +RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\MostRecentlyUsed + +[PhotoScissors *] +LangSecRef=3021 +Detect=HKCU\Software\Teorex\PhotoScissors +Default=False +RegKey1=HKCU\Software\Teorex\PhotoScissors\Recent File List +RegKey2=HKCU\Software\Teorex\PhotoScissors\RecentFileList + +[PhotoToFilm *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\PhotoToFilm +Default=False +FileKey1=%AppData%\KC Softwares\PhotoToFilm|*.log + +[PhotoZoom Pro 6 *] +LangSecRef=3023 +Detect=HKCU\Software\BenVista\PhotoZoom Pro 6 +Default=False +RegKey1=HKCU\Software\BenVista\PhotoZoom Pro 6|FileDir +RegKey2=HKCU\Software\BenVista\PhotoZoom Pro 6\Recent Images + +[PHPStorm *] +LangSecRef=3024 +DetectFile=%UserProfile%\.WebIde40 +Default=False +FileKey1=%UserProfile%\.WebIde40\LocalHistory|*.*|RECURSE +FileKey2=%UserProfile%\.WebIde40\Log|*.*|RECURSE +FileKey3=%UserProfile%\.WebIde40\system\caches|*.*|RECURSE +FileKey4=%UserProfile%\.WebIde40\tmp|*.*|RECURSE + +[PhraseExpress *] +LangSecRef=3024 +DetectFile=%Documents%\PhraseExpress +Default=False +FileKey1=%Documents%\PhraseExpress|*.bak + +[PhrozenSoft Databases *] +LangSecRef=3024 +DetectFile=%AppData%\PhrozenSoft +Default=False +FileKey1=%AppData%\PhrozenSoft\PVTUploader|phrzvtu.db + +[Phyxion.net Driver Sweeper *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Phyxion.net\Driver Sweeper\Logs +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Phyxion.net\Driver Sweeper\Logs|*.*|RECURSE +FileKey2=%ProgramFiles%\Phyxion.net\Driver Sweeper\Logs|*.*|RECURSE + +[Phyxion.net Driver Sweeper Backup *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Phyxion.net\Driver Sweeper\Backup +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Phyxion.net\Driver Sweeper\Backup|*.*|RECURSE +FileKey2=%ProgramFiles%\Phyxion.net\Driver Sweeper\Backup|*.*|RECURSE + +[Pidgin *] +LangSecRef=3022 +Detect=HKCU\Software\Pidgin +Default=False +FileKey1=%AppData%\.purple|*.xml~ +FileKey2=%UserProfile%|Recently-Used.xbel + +[Pidgin Chat Logs *] +LangSecRef=3022 +Detect=HKCU\Software\Pidgin +Default=False +FileKey1=%AppData%\.purple\logs|*.*|REMOVESELF + +[Pipy *] +LangSecRef=3021 +DetectFile=%AppData%\Pipy +Default=False +FileKey1=%AppData%\Pipy\Logs|*.* + +[PKWARE PKZIP *] +LangSecRef=3024 +Detect1=HKCU\Software\PKWARE\PKZIP for Windows +Detect2=HKCU\Software\PKWARE\PKZIP70 +Detect3=HKCU\Software\PKWARE\ZIPReader 0 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\PKWARE\PKZIPW|*.log +FileKey2=%ProgramFiles%\PKWARE\PKZIPW|*.log + +[Planet Horse *] +Section=Games +Detect=HKLM\Software\Big Fish Games\Persistence\Install\F6023T1L1 +DetectFile=%ProgramFiles%\Planet Horse +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Planet Horse|output_log.txt|RECURSE +FileKey2=%ProgramFiles%\Planet Horse|output_log.txt|RECURSE + +[Planets Under Attack *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\218510 +Default=False +FileKey1=%Documents%\My Games\Planets Under Attack|*.log + +[Plants vs Zombies *] +Section=Games +DetectFile=%ProgramFiles%\Popcap Games\Plants vs Zombies +Default=False +FileKey1=%ProgramFiles%\Popcap Games\Plants vs Zombies|Install.log + +[PlayFirst Games *] +Section=Games +DetectFile=%AppData%\PlayFirst +Default=False +FileKey1=%AppData%\PlayFirst|logfile.txt|RECURSE + +[Plex Media Server *] +LangSecRef=3023 +Detect=HKCU\Software\Plex, Inc.\Plex Media Server +Default=False +FileKey1=%LocalAppData%\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE +FileKey2=%LocalAppData%\Plex Media Server\Crash Reports|*.*|RECURSE +FileKey3=%LocalAppData%\Plex Media Server\Logs|*.*|RECURSE +FileKey4=%LocalAppData%\Plex Media Server\Updates|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Crash Reports|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Logs|*.*|RECURSE +FileKey8=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Updates|*.*|RECURSE +FileKey9=%LocalAppData%\VirtualStore\Program Files*\Plex\Plex Media Server|*.txt;*.log|RECURSE +FileKey10=%ProgramFiles%\Plex\Plex Media Server|*.txt;*.log|RECURSE +FileKey11=%WinDir%\System32\config\systemprofile\AppData\Local\Plex Media Server\Logs|*.*|RECURSE +FileKey12=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Plex Media Server\Logs|*.*|RECURSE + +[Pogo Games *] +Section=Games +DetectFile=%AppData%\Pogo Games +Default=False +FileKey1=%AppData%\Pogo Games\*\Cache|*.*|REMOVESELF + +[Pointstone Total Privacy *] +LangSecRef=3024 +Detect=HKCU\Software\Pointstone\Total Privacy +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Pointstone\Total Privacy*|*.txt +FileKey2=%ProgramFiles%\Pointstone\Total Privacy*|*.txt + +[Pok3D *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Pok3d +Default=False +FileKey1=%AppData%\Pok3d|*.log;*.dmp + +[PokerStars *] +Section=Games +DetectFile=%LocalAppData%\PokerStars +Default=False +FileKey1=%LocalAppData%\PokerStars\ImgCache|*.* +FileKey2=%LocalAppData%\PokeStars|*.log.* + +[Pokki *] +LangSecRef=3022 +Detect=HKCU\Software\Pokki +Default=False +FileKey1=%LocalAppData%\Pokki|*.log|RECURSE +FileKey2=%LocalAppData%\Pokki\PokkiIconCache|*.*|RECURSE +FileKey3=%LocalAppData%\Pokki\UserData\*|*.bak|RECURSE + +[Pokki Internet Traces *] +LangSecRef=3022 +Detect=HKCU\Software\Pokki +Default=False +FileKey1=%LocalAppData%\Pokki\UserData\*|Cookies*;Favicons*;*History*;Top Sites*;Visited Links;Web Data* +FileKey2=%LocalAppData%\Pokki\UserData\*\Cache|*.*|RECURSE +FileKey3=%LocalAppData%\Pokki\UserData\*\LocalStorage|*.* + +[Polarity *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Polarity +Default=False +FileKey1=%ProgramFiles%\Polarity|*.log + +[Polarity Internet Traces *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Polarity +Default=False +FileKey1=%AppData%\Stanley Lim\Polarity\Cache|*.*|RECURSE +FileKey2=%AppData%\Stanley Lim\Polarity\Favicon|*.* +FileKey3=%UserProfile%\Polarity_Config|downloads_names.ini;downloads_times.ini;downloads_urls.ini;history.ini;history_names.ini;history_times.ini;savedTabs.ini + +[PolyView *] +LangSecRef=3021 +Detect=HKCU\Software\Polybytes\PolyView +Default=False +RegKey1=HKCU\Software\Polybytes\PolyView\Recent File List + +[Portfolio Performance *] +LangSecRef=3021 +DetectFile=%LocalAppData%\PortfolioPerformance +Default=False +FileKey1=%LocalAppData%\PortfolioPerformance\workspace\.metadata|*.lock,*.log + +[PostBox *] +LangSecRef=3021 +DetectFile=%LocalAppData%\PostBox +Default=False +FileKey1=%AppData%\PostBox|*.log|RECURSE +FileKey2=%AppData%\PostBox\Crash Reports|*.*|REMOVESELF +FileKey3=%LocalAppData%\PostBox\Profiles\*\Cache|*.*|REMOVESELF + +[Power Efficiency Diagnostics *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%CommonAppData%\Microsoft\Windows\Power Efficiency Diagnostics|*.xml +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics|*.xml +ExcludeKey1=FILE|%CommonAppData%\Microsoft\Windows\Power Efficiency Diagnostics\|energy-report-latest.xml +ExcludeKey2=FILE|%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\|energy-report-latest.xml + +[PowerISO *] +LangSecRef=3024 +Detect=HKCU\Software\PowerISO +Default=False +FileKey1=%AppData%\PowerISO\Upgrade|*.*|RECURSE + +[PowerShell *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\PowerShell +Default=False +FileKey1=%AppData%\Microsoft\Windows\PowerShell\PSReadline|*.*|RECURSE +FileKey2=%LocalAppData%\Microsoft\Windows\PowerShell\CommandAnalysis|*.*|RECURSE + +[PowerZip *] +LangSecRef=3024 +Detect=HKCU\Software\Trident Software\PowerZip +Default=False +RegKey1=HKCU\Software\Trident Software\PowerZip\Recent File List + +[Predator *] +LangSecRef=3021 +Detect=HKLM\Software\Predator-Usb +Default=False +FileKey1=%CommonAppData%\Predator-Usb\PredatorACE\data|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Predator-Usb\PredatorACE\data|*.log + +[Presentation Foundation *] +LangSecRef=3025 +DetectFile1=%WinDir%\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe +DetectFile2=%WinDir%\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe +DetectFile3=%WinDir%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe +DetectFile4=%WinDir%\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe +DetectFile5=%WinDir%\winsxs\x86_wpf-presentationfontcache_31bf3856ad364e35_6.1.7600.16385_none_056fecf27381a72b\PresentationFontCache.exe +Default=False +FileKey1=%SystemDrive%\Documents and Settings\LocalService\Local Settings\Application Data|FontCache*.dat;~FontCache*.dat;WPFFontCache_v0400-*.dat +FileKey2=%WinDir%\ServiceProfiles\LocalService\AppData\Local|FontCache*.dat;~FontCache*.dat;WPFFontCache_v0400-*.dat + +[Presto Transfer Ultimate *] +LangSecRef=3024 +Detect=HKCU\Software\Perception\Presto Transfer Ultimate +Default=False +FileKey1=%AppData%\Presto Transfer Ultimate|lastlog.html + +[PriceGong *] +LangSecRef=3022 +DetectFile=%AppData%\PriceGong +Default=False +FileKey1=%AppData%\PriceGong\tmp|*.*|RECURSE + +[Prince of Persia T2T *] +Section=Games +DetectFile=%ProgramFiles%\Ubisoft\Prince of Persia T2T +Default=False +FileKey1=%LocalAppData%\Ubisoft\Prince of Persia T2T|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Prince of Persia T2T|*.log +FileKey3=%ProgramFiles%\Ubisoft\Prince of Persia T2T|*.log + +[Print Queue *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +Warning=You may need to halt the print spooler. +FileKey1=%WinDir%\System32\Spool\Printers|*.* + +[Prison Architect *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\233450 +Default=False +FileKey1=%LocalAppData%\Introversion\Prison Architect|debug.txt + +[Privacy Suite *] +LangSecRef=3024 +Detect=HKCU\Software\CyberScrub\Privacy Suite +Default=False +FileKey1=%AppData%\CyberScrub\Privacy Suite|cybscrub.log + +[Private Internet Access VPN *] +LangSecRef=3022 +DetectFile=%AppData%\Titanium\appdata\com.privateinternetaccess.vpn +Default=False +FileKey1=%AppData%\Titanium\appdata\com.privateinternetaccess.vpn|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\pia_manager\log|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\pia_manager\tmp|*.* +FileKey4=%ProgramFiles%\pia_manager\log|*.* +FileKey5=%ProgramFiles%\pia_manager\tmp|*.* +FileKey6=%UserProfile%|.pia_manager_crash.log + +[Privoxy *] +LangSecRef=3022 +Detect=HKCU\Software\Privoxy +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Vidalia Bundle\Privoxy|privoxy.log +FileKey2=%ProgramFiles%\Vidalia Bundle\Privoxy|privoxy.log + +[Procaster *] +LangSecRef=3023 +DetectFile=%LocalAppData%\Procaster +Default=False +FileKey1=%LocalAppData%\Procaster|*.log|RECURSE + +[Processing 2.0 *] +LangSecRef=3024 +DetectFile=%AppData%\Processing +Default=False +FileKey1=%AppData%\Processing\Console|*.* +FileKey2=%AppData%\Processing\Debug|*.* + +[ProcessLasso *] +LangSecRef=3024 +Detect=HKCU\Software\ProcessLasso +Default=False +FileKey1=%AppData%\ProcessLasso|prolasso.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Process Lasso|.logtype5 +FileKey3=%ProgramFiles%\Process Lasso|.logtype5 + +[ProDiscover *] +LangSecRef=3024 +Detect=HKLM\Software\Technology Pathways\ProDiscover +Default=False +RegKey1=HKLM\Software\Technology Pathways\ProDiscover\Recent File List + +[ProFantasy Software CC3 View *] +LangSecRef=3023 +Detect=HKCU\Software\EvolutionComputing +Default=False +RegKey1=HKCU\Software\EvolutionComputing\CC3View|1 +RegKey2=HKCU\Software\EvolutionComputing\CC3View|2 +RegKey3=HKCU\Software\EvolutionComputing\CC3View|3 +RegKey4=HKCU\Software\EvolutionComputing\CC3View|4 +RegKey5=HKCU\Software\EvolutionComputing\CC3View|WorkingDrawing + +[ProgDVB *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\ProgDVB +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\ProgDVB\Logs|*.*|RECURSE +FileKey2=%ProgramFiles%\ProgDVB\Logs|*.*|RECURSE + +[Project64 *] +Section=Games +Detect=HKCU\Software\N64 Emulation +DetectFile=%ProgramFiles%\Project64 * +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Project64 2.*\Logs|*.* +FileKey2=%ProgramFiles%\Project64 2.*\Logs|*.* +RegKey1=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile1 +RegKey2=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile2 +RegKey3=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile3 +RegKey4=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile4 +RegKey5=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile5 +RegKey6=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile6 +RegKey7=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile7 +RegKey8=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile8 +RegKey9=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile9 +RegKey10=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile10 + +[Proteus *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\219680 +Default=False +FileKey1=%Documents%\Proteus\logs|*.* +ExcludeKey1=FILE|%Documents%\Proteus\logs\|rng.txt + +[PS3 Media Server *] +LangSecRef=3023 +Detect=HKCU\Software\PS3 Media Server +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\PS3 Media Server|*log;*.md|RECURSE +FileKey2=%ProgramFiles%\PS3 Media Server|*log;*.md|RECURSE + +[Psi Avatar Cache *] +LangSecRef=3022 +Detect=HKCU\Software\psi-im.org\Psi +DetectFile=%LocalAppData%\Psi+ +Default=False +FileKey1=%LocalAppData%\Psi+\Avatars|*.*|RECURSE +FileKey2=%UserProfile%\PsiData\avatars|*.* + +[Psi Chat Logs *] +LangSecRef=3022 +Detect=HKCU\Software\psi-im.org\Psi +DetectFile=%LocalAppData%\Psi+ +Default=False +FileKey1=%AppData%\Psi+\profiles\*\history|*.*|RECURSE +FileKey2=%UserProfile%\PsiData\profiles\*\history|*.* + +[PSoC Designer 5.4 *] +LangSecRef=3021 +DetectFile=%AppData%\Cypress_Semiconductor\PSoC_Designer_54 +Default=False +FileKey1=%AppData%\Cypress_Semiconductor\PSoC_Designer_54|debug.log;debug.log.* + +[PSPad *] +LangSecRef=3024 +DetectFile=%AppData%\PSpad +Default=False +FileKey1=%AppData%\PSpad|Recent.ini + +[PunkBuster *] +Section=Games +DetectFile=%LocalAppData%\PunkBuster +Default=False +FileKey1=%LocalAppData%\PunkBuster|pbcl.log|RECURSE +FileKey2=%WinDir%\System32\LogFiles\PunkBuster|*.* + +[Puran Defrag *] +LangSecRef=3024 +Detect=HKLM\Software\Puran Software\Puran Defrag +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Puran Defrag|PuranDefrag.html +FileKey2=%ProgramFiles%\Puran Defrag|PuranDefrag.html + +[Pure Networks *] +LangSecRef=3022 +Detect=HKCU\Software\Pure Networks +Default=False +FileKey1=%CommonAppData%\Pure Networks\Log|*.* +FileKey2=%CommonAppData%\Pure Networks\Platform|*.bak +FileKey3=%CommonAppData%\Pure Networks\Platform\minidumps|*.* +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Pure Networks\Log|*.* +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Pure Networks\Platform|*.bak +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Pure Networks\Platform\minidumps|*.* + +[PureRa *] +LangSecRef=3024 +DetectFile=%SystemDrive%\PureRa.txt +Default=False +FileKey1=%SystemDrive%|PureRa.txt + +[Puritan File Destroyer Elite *] +LangSecRef=3023 +Detect=HKCU\Software\Puritan\File Destroyer Elite +Default=False +FileKey1=%CommonAppData%\Puritan\File Destroyer Elite|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Puritan\File Destroyer Elite|*.log|RECURSE + +[Pushbullet *] +LangSecRef=3022 +DetectFile=%AppData%\Pushbullet +Default=False +FileKey1=%AppData%\Pushbullet\pushbullet|*.log + +[Pycharm *] +LangSecRef=3021 +Detect=HKCU\Software\JetBrains\PyCharm +Default=False +FileKey1=%UserProfile%\.PyCharm*\system\caches|*.* +FileKey2=%UserProfile%\.PyCharm*\system\log|*.* + +[Python *] +LangSecRef=3021 +Detect=HKCU\Software\Python +Default=False +FileKey1=%ProgramFiles%\Python*|*.icns|RECURSE +FileKey2=%SystemDrive%\Python*|*.icns|RECURSE + +[qBittorrent *] +LangSecRef=3022 +DetectFile=%LocalAppData%\qBittorrent +Default=False +FileKey1=%LocalAppData%\qBittorrent\cache|*.* +FileKey2=%LocalAppData%\qBittorrent\logs|*.* + +[QIP 2012 *] +LangSecRef=3022 +Detect=HKCU\Software\QIP +DetectFile=%AppData%\QIP +Default=False +FileKey1=%AppData%\QIP\Profiles\*\*Avatars|*.* +FileKey2=%AppData%\QIP\Profiles\*\Jabber|*.* +FileKey3=%AppData%\QIP\Profiles\*\Logs|*.* +FileKey4=%AppData%\QIP\Profiles\*\PicHashes|*.* + +[QIP 2012 Privacy items *] +LangSecRef=3022 +Detect=HKCU\Software\QIP +DetectFile=%AppData%\QIP +Default=False +Warning=Selecting this will delete any contact list backups, chat history, received files, opened tabs settings and other non-encrypted privacy items. +FileKey1=%AppData%\QIP\Profiles\*|session.tabs +FileKey2=%AppData%\QIP\Profiles\*\BackupCL|*.* +FileKey3=%AppData%\QIP\Profiles\*\History|*.*|RECURSE +FileKey4=%AppData%\QIP\Profiles\*\ICQ|*.*|RECURSE +FileKey5=%AppData%\QIP\Profiles\*\RcvdFiles|*.*|RECURSE + +[QQ *] +LangSecRef=3022 +DetectFile=%Documents%\Tencent Files +Default=False +FileKey1=%CommonAppData%\Tencent Files\QQ\Misc|*.*|RECURSE +FileKey2=%Documents%\Tencent Files|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Tencent Files\QQ\Misc|*.*|RECURSE + +[QTTabBar *] +LangSecRef=3024 +Detect=HKCU\Software\Quizo\QTTabBar +Default=False +FileKey1=%AppData%\QTTabBar|*.log +RegKey1=HKCU\Software\Quizo\QTTabBar|TabsOnLastClosedWindow +RegKey2=HKCU\Software\Quizo\QTTabBar\Cache +RegKey3=HKCU\Software\Quizo\QTTabBar\RecentlyClosed + +[QuickBooks *] +LangSecRef=3021 +Detect=HKLM\Software\Intuit\QuickBooks +Default=False +FileKey1=%CommonAppData%\Common Files\Intuit\Quickbooks\qbupdate\log|*.* +FileKey2=%CommonAppData%\Intuit\QBWebConnector\log|*.* +FileKey3=%CommonAppData%\Intuit\Quickbooks|*.log;qbsdklog.txt +FileKey4=%CommonAppData%\Intuit\QuickBooks DB Server Manager|*.log;*.old +FileKey5=%CommonProgramFiles%\Intuit\Quickbooks\QBUpdate\Log|*.* +FileKey6=%LocalAppData%\Intuit\QuickBooks\Log|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Intuit\Quickbooks\QBUpdate\Log|*.* +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Common Files\Intuit\Quickbooks\qbupdate\log|*.* +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Intuit\QBWebConnector\log|*.* +FileKey10=%LocalAppData%\VirtualStore\ProgramData\Intuit\Quickbooks|*.log;qbsdklog.txt +FileKey11=%LocalAppData%\VirtualStore\ProgramData\Intuit\QuickBooks DB Server Manager|*.log;*.old + +[QuickDic History *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\QuickDic +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\QuickDic|QuickDic.ini +FileKey2=%ProgramFiles%\QuickDic|QuickDic.ini + +[Quicken *] +LangSecRef=3021 +Detect1=HKLM\Software\Intuit\Quicken +Detect2=HKLM\Software\Quicken +Default=False +FileKey1=%AppData%\Intuit\Quicken\Log|*.txt;*.log +FileKey2=%AppData%\Quicken\Log|*.txt;*.log +FileKey3=%CommonAppData%\Intuit\Quicken\Log|*.log +FileKey4=%CommonAppData%\Intuit\Quicken\Log\installer|*.*|REMOVESELF +FileKey5=%CommonAppData%\Intuit\SendError|*.log +FileKey6=%CommonAppData%\Quicken\Log|*.log +FileKey7=%CommonAppData%\Quicken\Log\installer|*.*|REMOVESELF +FileKey8=%CommonAppData%\Quicken\SendError|*.log +FileKey9=%LocalAppData%\Intuit\Common\Authorization\V1\Logs|*.txt +FileKey10=%LocalAppData%\Quicken\Common\Authorization\V1\Logs|*.txt +FileKey11=%LocalAppData%\VirtualStore\ProgramData\Intuit\Quicken\Log|*.log +FileKey12=%LocalAppData%\VirtualStore\ProgramData\Intuit\SendError|*.log +FileKey13=%LocalAppData%\VirtualStore\ProgramData\Quicken\Log|*.log +FileKey14=%LocalAppData%\VirtualStore\ProgramData\Quicken\SendError|*.log +FileKey15=%ProgramFiles%\Quicken\PDFDrv|install.log;InstallPDFConverter.log + +[Quicken WillMaker Plus *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Quicken WillMaker Plus * +Default=False +FileKey1=%LocalAppData%\Quicken WillMaker Plus *|web update log.txt + +[QuickPAR *] +LangSecRef=3024 +Detect=HKCU\Software\QuickPar +Default=False +FileKey1=%LocalAppData%\QuickPar|*.* + +[QuickTime Player *] +LangSecRef=3023 +Detect=HKLM\Software\Apple Computer, Inc.\QuickTime +Default=False +RegKey1=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Apple Computer, Inc.\QuickTime\Favorite Movies +RegKey2=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Apple Computer, Inc.\QuickTime\Recent Movies +RegKey3=HKCU\Software\Classes\VirtualStore\MACHINE\Software\WOW6432Node\Apple Computer, Inc.\QuickTime\Favorite Movies +RegKey4=HKCU\Software\Classes\VirtualStore\MACHINE\Software\WOW6432Node\Apple Computer, Inc.\QuickTime\Recent Movies + +[QuizUp *] +Section=Games +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\QuizUp.QuizUp_n36z36qeaxk8a +Default=False +FileKey1=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE +FileKey4=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Temp|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalCache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalState\Cache|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\QuizUp.QuizUp_*\TempState|*.*|RECURSE + +[QupZilla Portable Cookies *] +Section=QupZilla Portable +DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe +Default=False +FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\profile|cookies.dat + +[QupZilla Portable Local App Data *] +Section=QupZilla Portable +DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe +Default=False +FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\QupZillaLocalAppData|*.*|RECURSE + +[QupZilla Portable Network Cache *] +Section=QupZilla Portable +DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe +Default=False +FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\profile\networkcache|*.*|RECURSE + +[QupZilla Portable Session *] +Section=QupZilla Portable +DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe +Default=False +FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\profile|session.dat* + +[QupZilla Portable Thumbnails *] +Section=QupZilla Portable +DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe +Default=False +FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\profile\thumbnails|*.* + +[QupZilla Portable Webpage Icons *] +Section=QupZilla Portable +DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe +Default=False +FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\profile|WebpageIcons.db + +[Qurb4 *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Qurb4 +Default=False +FileKey1=%LocalAppData%\Qurb4|*.log|RECURSE + +[qutIM *] +LangSecRef=3022 +Detect=HKCU\Software\qutIM +Default=False +FileKey1=%AppData%\qutIM\avatars\*|*.*|RECURSE + +[qutIM Chat History *] +LangSecRef=3022 +Detect=HKCU\Software\qutIM +Default=False +FileKey1=%AppData%\qutIM\history|*.*|RECURSE + +[Qwest QuickCare *] +LangSecRef=3022 +Detect=HKLM\Software\QuickCare +Default=False +FileKey1=%CommonAppData%\Support.com|*.tmp|RECURSE +FileKey2=%LocalAppData%\SupportSoft|*.tmp|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Support.com|*.tmp|RECURSE + +[RadeonPro *] +LangSecRef=3024 +DetectFile=%AppData%\RadeonPro +Default=False +FileKey1=%AppData%\RadeonPro|*.old;*.bak;*_bak.*;*.bkp +FileKey2=%AppData%\RadeonPro\Cache|*.*|RECURSE +FileKey3=%AppData%\RadeonPro\Temp|*.*|RECURSE + +[Radialix 2 *] +LangSecRef=3021 +Detect=HKCU\Software\Radialix +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Radialix 2|*diz;*.txt;*.url +FileKey2=%ProgramFiles%\Radialix 2|*diz;*.txt;*.url +FileKey3=%ProgramFiles%\Radialix 2\Tools\UPX|COPYING;LICENSE + +[RadioSure *] +LangSecRef=3023 +Detect=HKCU\Software\RadioSure +Default=False +FileKey1=%LocalAppData%\RadioSure\Log|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\RadioSure\Log|*.* +FileKey3=%ProgramFiles%\RadioSure\Log|*.* + +[Rage *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\9200 +Default=False +FileKey1=%AppData%\id software\rage|*.*|RECURSE + +[Rainlendar 2 *] +LangSecRef=3021 +DetectFile=%UserProfile%\.rainlendar2 +Default=False +FileKey1=%UserProfile%\.rainlendar2|rainlendar2.log + +[Rainlendar 2 Backups *] +LangSecRef=3021 +DetectFile=%UserProfile%\.rainlendar2 +Default=False +FileKey1=%UserProfile%\.rainlendar2\backups|*.*|RECURSE + +[RAMExpert *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\RAMExpert +Default=False +FileKey1=%AppData%\KC Softwares\RAMExpert|*.log + +[Ranch Rush *] +Section=Games +Detect1=HKLM\Software\Big Fish Games\Persistence\Install\F2580T1L1 +Detect2=HKLM\Software\Big Fish Games\Persistence\Install\F5659T1L1 +Detect3=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Ranch Rush1.0 +DetectFile=%ProgramFiles%\Ranch Rush +Default=False +FileKey1=%CommonAppData%\FreshGames\RanchRush\*|*.log;temp_data.ssp +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ranch Rush*|*.html;*.nfo +FileKey3=%LocalAppData%\VirtualStore\ProgramData\FreshGames\RanchRush\*|*.log;temp_data.ssp +FileKey4=%ProgramFiles%\Ranch Rush*|*.html;*.nfo + +[Raptr *] +LangSecRef=3021 +Detect=HKCU\Software\Raptr +DetectFile=%ProgramFiles%\Raptr +Default=False +FileKey1=%AppData%\Raptr|*.log|RECURSE +FileKey2=%AppData%\Raptr\Avatars|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Raptr|*.log +FileKey4=%ProgramFiles%\Raptr|*.log +ExcludeKey1=FILE|%ProgramFiles%\Raptr\|install.log + +[Raptr Chat History *] +Section=Games +Detect=HKCU\Software\Raptr +Default=False +FileKey1=%AppData%\Raptr\Data\*|chat_history.db + +[Razer Software *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Razer +Default=False +FileKey1=%CommonAppData%\Razer\*|DiagnoseReport*.*.txt +FileKey2=%CommonAppData%\Razer\*\Logs|*.* +FileKey3=%CommonAppData%\Razer\Synapse\Accounts\*\DataSync|SyncDate.txt +FileKey4=%CommonAppData%\Razer\Synapse\ProductUpdates\Downloads|*.* +FileKey5=%LocalAppData%\Razer\RzUninstallation\Logs|*.* +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Razer\*|*.log +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Razer\*|DiagnoseReport*.*.txt +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Razer\*\Logs|*.* +FileKey9=%LocalAppData%\VirtualStore\ProgramData\Razer\Synapse\Accounts\*\DataSync|SyncDate.txt +FileKey10=%LocalAppData%\VirtualStore\ProgramData\Razer\Synapse\ProductUpdates\Downloads|*.* +FileKey11=%ProgramFiles%\Razer\*|*.log + +[RCrawler *] +LangSecRef=3024 +Detect=HKLM\Software\4Developers\RCrawler +Default=False +RegKey1=HKLM\Software\4Developers\RCrawler\History +RegKey2=HKLM\Software\4Developers\RCrawler\Settings|LastSearch + +[Real Network Monitor *] +LangSecRef=3022 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Real Network Monitor +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Real Network Monitor|*.xml +FileKey2=%ProgramFiles%\Real Network Monitor|*.xml + +[RealPlayer Converter *] +LangSecRef=3023 +Detect=HKCU\Software\RealNetworks\RealConverter +Default=False +RegKey1=HKCU\Software\RealNetworks\RealJukebox\1.0\Preferences\WatchFolders + +[RealPlayer Database Files *] +LangSecRef=3023 +Detect=HKCU\Software\RealNetworks\RealPlayer +Default=False +FileKey1=%AppData%\Real\RealPlayer\db|*.*|RECURSE + +[Realtek *] +LangSecRef=3024 +Detect=HKLM\Software\Realtek +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Realtek*|*.log;*.txt|RECURSE +FileKey2=%ProgramFiles%\Realtek*|*.*log;*.txt|RECURSE +FileKey3=%ProgramFiles%\Temp|*.*|REMOVESELF +FileKey4=%SystemDrive%|RHDSetup.log +ExcludeKey1=FILE|%ProgramFiles%\Realtek\*\|InstCtrl.txt +ExcludeKey2=FILE|%ProgramFiles%\Realtek\*\|setupctrl.txt + +[Reckless Racing *] +Section=Games +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Studios.RecklessRacingUltimate_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.Studios.RecklessRacingUltimate_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Studios.RecklessRacingUltimate_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Studios.RecklessRacingUltimate_*\AC\Microsoft\CryptnetUrlCache\*|*.* + +[RecollX *] +LangSecRef=3021 +DetectFile=%AppData%\Advansys\RecollX +Default=False +FileKey1=%AppData%\Advansys\RecollX\log|*.*|RECURSE + +[Recuva *] +LangSecRef=3024 +Detect=HKCU\Software\Piriform\Recuva +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Recuva|*.log;Recuva_log*.txt +FileKey2=%ProgramFiles%\Recuva|*.log;Recuva_log*.txt +FileKey3=%UserProfile%|Recuva_log*.txt + +[Reddit To Go! *] +LangSecRef=3031 +DetectFile=%LocalAppData%\Packages\*.RedditToGo_* +Default=False +FileKey1=%LocalAppData%\Packages\*.RedditToGo_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\*.RedditToGo_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\*.RedditToGo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\*.RedditToGo_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\*.RedditToGo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\*.RedditToGo_*\AC\Temp|*.* +FileKey7=%LocalAppData%\Packages\*.RedditToGo_*\RoamingState|history.txt +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\55382ross456.RedditToGo_02dxdbb1qg9kw\SearchHistory + +[Reflector *] +LangSecRef=3021 +DetectFile=%AppData%\Reflector +Default=False +FileKey1=%AppData%\Reflector|*.log;*.dmp + +[Reg Organizer *] +LangSecRef=3024 +Detect=HKCU\Software\ChemTable Software\Reg Organizer +Default=False +FileKey1=%LocalAppData%\ChemTable Software\Reg Organizer|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Reg Organizer|*.txt +FileKey3=%ProgramFiles%\Reg Organizer|*.txt + +[RegAlyzer *] +LangSecRef=3024 +Detect=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer +Default=False +RegKey1=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|LastKey +RegKey2=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|RemoteListHistory +RegKey3=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|SearchTerm + +[RegClean Pro *] +LangSecRef=3024 +Detect=HKCU\Software\Systweak\RegClean Pro +DetectFile=%ProgramFiles%\RegClean Pro\RegCleanPro.exe +Default=False +FileKey1=%AppData%\Systweak\RegClean Pro\Version 6.1|*.log + +[RegEditX *] +LangSecRef=3024 +Detect=HKLM\Software\DCSoft\RegEditX +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\DCSoft\RegEditX\*|RegEditX.sav;RegEditX.bak +RegKey1=HKLM\Software\4Developers\RCrawler\History +RegKey2=HKLM\Software\4Developers\RCrawler\Settings|LastSearch + +[ReGet Deluxe *] +LangSecRef=3022 +Detect=HKCU\Software\ReGet Software\ReGetDx +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\ReGet Deluxe\history|*.* +FileKey2=%ProgramFiles%\ReGet Deluxe\history|*.* +RegKey1=HKCU\Software\ReGet Software\ReGetDx\FtpExplorer\Hist +RegKey2=HKCU\Software\ReGet Software\ReGetDx\History +RegKey3=HKCU\Software\ReGet Software\ReGetDx\Search\HistFind + +[Registrar Registry Manager *] +LangSecRef=3024 +Detect=HKCU\Software\Resplendence Sp\Registrar Registry Manager +Default=False +RegKey1=HKCU\Software\Resplendence Sp\Registrar Registry Manager\Settings|ExportForm.saveDialogExportFilename +RegKey2=HKCU\Software\Resplendence Sp\Registrar Registry Manager\Settings|ExportForm.saveDialogExportInitialDir +RegKey3=HKCU\Software\Resplendence Sp\Registrar Registry Manager\Settings|LastOpenedKey + +[Registry Clean Expert *] +LangSecRef=3023 +Detect=HKCU\Software\SuniSoft\IncUpdate\Registry Clean Expert +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Registry Clean Expert|fixlog.ini +FileKey2=%ProgramFiles%\Registry Clean Expert|fixlog.ini + +[Registry First Aid *] +LangSecRef=3024 +Detect=HKCU\Software\KsL Software\RFA +Default=False +FileKey1=%LocalAppData%\Microsoft\Windows|NTUSER.tmp;UsrClass.tmp +FileKey2=%UserProfile%|NTUSER.tmp;UsrClass.tmp +FileKey3=%WinDir%\ServiceProfiles\*Service|*.tmp;*.tmp.LOG1;*.tmp.LOG2 +FileKey4=%WinDir%\System32\config|*.tmp;*.tmp.LOG1;*.tmp.LOG2 +FileKey5=%WinDir%\System32\config\systemprofile|*.tmp;*.tmp.LOG1;*.tmp.LOG2 +FileKey6=%WinDir%\SysWOW64\config\systemprofile|*.tmp;*.tmp.LOG1;*.tmp.LOG2 + +[Registry Mechanic *] +LangSecRef=3024 +Detect=HKLM\Software\PCTools\Registry Mechanic +Default=False +FileKey1=%AppData%\Registry Mechanic\log|*.html +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Registry Mechanic\log*|*.* +FileKey3=%ProgramFiles%\Registry Mechanic\log*|*.* + +[RegistryFix *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\RegistryFix\RegistryFix.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\RegistryFix\logs|*.* +FileKey2=%ProgramFiles%\RegistryFix\logs|*.* + +[RegServo *] +LangSecRef=3024 +DetectFile=%CommonAppData%\regservo +Default=False +FileKey1=%CommonAppData%\regservo\Logs|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\regservo\Logs|*.*|RECURSE + +[RegToBat *] +LangSecRef=3024 +Detect=HKLM\Software\BlueLife\RegToBat +Default=False +RegKey1=HKLM\Software\BlueLife\RegToBat|LastRegFile + +[RegVac Registry Cleaner *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\RegVac Registry Cleaner +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\RegVac Registry Cleaner|*.xml +FileKey2=%ProgramFiles%\RegVac Registry Cleaner|*.xml + +[RegWork *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\RegWork +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\RegWork\Logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\RegWork\Tmp|*.* +FileKey3=%ProgramFiles%\RegWork\Logs|*.* +FileKey4=%ProgramFiles%\RegWork\Tmp|*.* + +[Reign: Conflict of Nations *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\46380 +Default=False +FileKey1=%LocalAppData%\1C\Reign Conflict of Nations|PSPLog.log + +[Relic Downloader *] +Section=Games +DetectFile=%Documents%\My Games\Company of Heroes* +Default=False +FileKey1=%Documents%\My Games\RelicDownloader|*.log + +[Remote Desktop *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Terminal Server Client +Default=False +Warning=This will reset all Remote Desktop Connection settings. +FileKey1=%Documents%|*.rdp + +[Rename Us *] +LangSecRef=3024 +Detect=HKCU\Software\Vitaliy Levchenko\Renamus +Default=False +RegKey1=HKCU\Software\Vitaliy Levchenko\Renamus\Recent Projects +RegKey2=HKCU\Software\Vitaliy Levchenko\Renamus\Settings|LastFolder + +[Replay Media Catcher *] +LangSecRef=3022 +Detect=HKLM\Software\Applian Technologies\Replay Media Catcher 5 +DetectFile=%AppData%\Replay Media Catcher 4 +Default=False +FileKey1=%AppData%\Replay Media Catcher 4|*.log +FileKey2=%AppData%\Replay Media Catcher 4\History|*.*|REMOVESELF +FileKey3=%LocalAppData%\Replay Media Catcher 5\History|*.*|REMOVESELF +FileKey4=%LocalAppData%\Replay Media Catcher 5\Temp|*.*|REMOVESELF +FileKey5=%LocalAppData%\Replay Media Catcher 5\UrlCache|*.*|REMOVESELF +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Applian Technologies\Replay Media Catcher*|*.html;*.txt;*.rtf +FileKey7=%ProgramFiles%\Applian Technologies\Replay Media Catcher*|*.html;*.txt;*.rtf + +[Resilio Sync *] +LangSecRef=3024 +DetectFile=%AppData%\Resilio Sync +Default=False +FileKey1=%AppData%\Resilio Sync|*.journal;*.journal.zip;*.log;*.old;history.dat + +[Resource Hacker *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Resource Hacker\ResHacker.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Resource Hacker|ResHacker.ini;reshacker.GID +FileKey2=%ProgramFiles%\Resource Hacker|ResHacker.ini;reshacker.GID + +[Restorator 2007 *] +LangSecRef=3021 +Detect=HKCU\Software\Bomers\Restorator +Default=False +RegKey1=HKCU\Software\Bomers\Restorator\Restorator\Current|LastSearchString +RegKey2=HKCU\Software\Bomers\Restorator\Restorator\FindDialog +RegKey3=HKCU\Software\Bomers\Restorator\Restorator\GrabDialog +RegKey4=HKCU\Software\Bomers\Restorator\Restorator\LastFoundFiles +RegKey5=HKCU\Software\Bomers\Restorator\Restorator\MRUList + +[Restore Point Creator *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CC48DE1C-8EC2-43BC-9201-29701CD9AE13}_is1 +Default=False +FileKey1=%CommonAppData%|Restore Point Creator.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Restore Point Creator|*.log;*.txt +FileKey3=%ProgramFiles%\Restore Point Creator|*.log;*.txt + +[ResumeMaker *] +LangSecRef=3021 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D2E80193-7318-4707-A9DE-49AF663ADA73} +Default=False +FileKey1=%CommonAppData%\Individual Software\ResumeMaker\R12|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Individual Software\ResumeMaker\R12|*.log + +[Reus *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\222730 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\Reus|errorReport*.txt +FileKey2=%ProgramFiles%\Steam\SteamApps\common\Reus|errorReport*.txt + +[Revenge of The Titans *] +Section=Games +DetectFile=%UserProfile%\.revenge_of_the_titans_1.80 +Default=False +FileKey1=%UserProfile%\.revenge_of_the_titans_1.80|*.log + +[Revo Uninstaller Backups *] +LangSecRef=3024 +DetectFile=%LocalAppData%\VS Revo group +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\VS Revo Group\Revo Uninstaller Pro|*.bak +FileKey2=%LocalAppData%\VS Revo Group\Revo Uninstaller*\BackupsData|*.*|RECURSE +FileKey3=%ProgramFiles%\VS Revo Group\Revo Uninstaller Pro|*.bak + +[Ride! *] +Section=Games +Detect1=HKLM\Software\Big Fish Games\Persistence\Install\F2440T1L1 +Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Ride! +DetectFile=%ProgramFiles%\Ride! +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Ride!|*.log;*.txt|RECURSE +FileKey2=%ProgramFiles%\Ride!|*.log;*.txt|RECURSE +FileKey3=%ProgramFiles%\Ride!\DirectX9|*.*|REMOVESELF + +[Riding Academy 3D *] +Section=Games +Detect=HKCU\Software\Program-Ace\RidingAcademy3D +Default=False +FileKey1=%LocalAppData%\Riding Academy 3D\logs|*.* + +[Riding Star 3 *] +Section=Games +Detect=HKLM\Software\DTP\Riding Star 3 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Riding Star 3|INSTALL.LOG;log.txt +FileKey2=%ProgramFiles%\Riding Star 3|INSTALL.LOG;log.txt + +[RIFT *] +Section=Games +DetectFile=%Documents%\RIFT +Default=False +FileKey1=%AppData%\RIFT|*.log +FileKey2=%Documents%\RIFT|*.log +FileKey3=%LocalAppData%\VirtualStore\Program Files*\RIFT|*.log +FileKey4=%ProgramFiles%\RIFT|*.log +FileKey5=%Public%\Games\RIFT|*.log +FileKey6=%SystemDrive%\RIFT|*.log + +[Rigs of Rods *] +LangSecRef=3021 +DetectFile=%LocalAppData%\CrashRpt\UnsentCrashReports\Rigs of Rods +Default=False +FileKey1=%LocalAppData%\CrashRpt\UnsentCrashReports\Rigs of Rods_*|*.*|RECURSE + +[Ring Central *] +LangSecRef=3022 +DetectFile=%CommonAppData%\RingCentral +Default=False +FileKey1=%CommonAppData%\RingCentral\LogFiles|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\RingCentral\LogFiles|*.* + +[Rise of Nations *] +Section=Games +Detect1=HKCU\Software\Microsoft\Microsoft Games\Rise of Nations +Detect2=HKCU\Software\Microsoft\Microsoft Games\RiseofNationsExpansion +Default=False +FileKey1=%AppData%\Microsoft Games\Rise of Nations\Logs|*.* + +[Rkill *] +LangSecRef=3024 +DetectFile1=%UserProfile%\Desktop\Rkill +DetectFile2=%UserProfile%\Desktop\Rkill.txt +Default=False +FileKey1=%UserProfile%\Desktop|*rkill*.* +FileKey2=%UserProfile%\Desktop\Rkill|*.*|REMOVESELF + +[Roadkil's Unstoppable Copier *] +LangSecRef=3024 +Detect=HKCU\Software\Roadkil +Default=False +RegKey1=HKCU\Software\Roadkil|Source_Unstp +RegKey2=HKCU\Software\Roadkil|Target_Unstp + +[Roblox *] +Section=Games +DetectFile=%LocalAppData%\Roblox +Default=False +FileKey1=%LocalAppData%\Roblox\Logs|*.*|RECURSE +FileKey2=%LocalLowAppData%\RbxLogs|*.*|RECURSE + +[Roblox Downloads *] +Section=Games +DetectFile=%LocalAppData%\Roblox +Default=False +FileKey1=%LocalAppData%\Roblox\Downloads|*.*|RECURSE + +[RoboBasket3 *] +LangSecRef=3024 +DetectFile=%AppData%\RoboBasket3 +Default=False +Warning=This may prompt you with an error upon trying to view the log. Just click continue. +FileKey1=%AppData%\RoboBasket3|log.database + +[Rochard *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\107800 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\Rochard\Rochard_Data|Output_log.txt +FileKey2=%LocalLowAppData%\Recoil Games\Rochard|journal.txt +FileKey3=%ProgramFiles%\Steam\SteamApps\common\Rochard\Rochard_Data|Output_log.txt + +[Rock of Ages *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\22230 +Detect2=HKLM\Software\ACE Team\Rock of Ages +Default=False +FileKey1=%ProgramFiles%\ATLUS\Rock of Ages\Prerequisites|*.*|REMOVESELF +FileKey2=%ProgramFiles%\Steam\steamapps\common\Rock of Ages\Prerequisites|*.*|REMOVESELF + +[Rocket League *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\252950 +Default=False +FileKey1=%Documents%\My Games\Rocket League\TAGame\Logs|*.* + +[RollBack Rx *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Shield +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Shield|*.log +FileKey2=%ProgramFiles%\Shield|*.log + +[Roxio *] +LangSecRef=3021 +Detect=HKCU\Software\Roxio +Default=False +FileKey1=%AppData%\Roxio Burn\Temp|*.*|RECURSE +FileKey2=%AppData%\Roxio Log Files|*.*|RECURSE +FileKey3=%AppData%\Roxio\Dragon\3.x\*Logs|*.log +FileKey4=%AppData%\Roxio\Dragon\3.x\DiscInfoCache|*.tmp +FileKey5=%CommonAppData%\Roxio|*.log;cardinfo.* +FileKey6=%LocalAppData%|rx_audio.Cache;rx_image32.Cache +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Roxio|*.log;cardinfo.* +FileKey8=%WinDir%\System32\config\systemprofile\AppData\Roaming\Roxio Log Files|*.*|RECURSE +FileKey9=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Roxio Log Files|*.*|RECURSE + +[Roxio Creator Pro *] +LangSecRef=3021 +Detect1=HKCU\Software\Roxio\EMC13 +Detect2=HKCU\Software\Roxio\EMC14 +Default=False +FileKey1=%Documents%\Roxio\Music Disc Creator|*.* +RegKey1=HKCU\Software\Roxio\EMC13\VideoUI\RecentFiles\Catalogs +RegKey2=HKCU\Software\Roxio\EMC14\Label Creator\Recent File List +RegKey3=HKCU\Software\Roxio\EMC14\MusicDiscCreator\Directories +RegKey4=HKCU\Software\Roxio\EMC14\MusicDiscCreator\MediaSelector +RegKey5=HKCU\Software\Roxio\EMC14\PhotoSuite\RoxioPhotoSuite\MRUFiles +RegKey6=HKCU\Software\Roxio\EMC14\SoundEdit\Directories +RegKey7=HKCU\Software\Roxio\EMC14\SoundEdit\MediaSelector +RegKey8=HKCU\Software\Roxio\EMC14\SoundEdit\WaveCache +RegKey9=HKCU\Software\Roxio\EMC14\VideoConvert\Directories +RegKey10=HKCU\Software\Roxio\EMC14\VideoConvert\MediaSelector +RegKey11=HKCU\Software\Roxio\EMC14\VideoUI\RecentFiles\Albums +RegKey12=HKCU\Software\Roxio\EMC14\VideoUI\RecentFiles\Catalogs +RegKey13=HKCU\Software\Roxio\EMC14\VideoUI\RecentFiles\DVD Projects +RegKey14=HKCU\Software\Roxio\EMC14\VideoUI\RecentFiles\Productions +RegKey15=HKLM\Software\Roxio\EMC13\Common SDK\Users +RegKey16=HKLM\Software\Roxio\EMC14\Common SDK\Users +RegKey17=HKLM\Software\Wow6432Node\Roxio\EMC13\Common SDK\Users +RegKey18=HKLM\Software\Wow6432Node\Roxio\EMC14\Common SDK\Users + +[RssBandit *] +LangSecRef=3022 +DetectFile=%AppData%\RssBandit +Default=False +FileKey1=%AppData%\RssBandit|*.bak;*.log + +[rtmpGUI .swfinfo *] +LangSecRef=3024 +DetectFile=%UserProfile%\.swfinfo +Default=False +FileKey1=%UserProfile%|.swfinfo + +[Rust *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\252490 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Rust|debug_steamclient.txt +FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Rust|debug_steamclient.txt + +[SABnzbd *] +LangSecRef=3021 +DetectFile=%LocalAppData%\sabnzbd +Default=False +FileKey1=%LocalAppData%\sabnzbd\admin|history1.db;totals9.sab +FileKey2=%LocalAppData%\sabnzbd\logs|*.* + +[SABnzbd Backup *] +LangSecRef=3022 +Detect=HKCU\Software\SABnzbd +Default=False +FileKey1=%LocalAppData%\SABnzbd|*.bak + +[Safari *] +LangSecRef=3028 +Default=False +DetectFile=%ProgramFiles%\Safari\Safari.exe +FileKey1=%AppData%\Apple Computer\Logs|*.* +FileKey2=%LocalAppData%\Apple Computer\com.apple.Safari.PrivateBrowsing|Cache.db +FileKey3=%LocalAppData%\Apple Computer\Safari|WebpageIcons.db + +[Sage ACT! *] +LangSecRef=3021 +Detect=HKLM\Software\ACT +Default=False +FileKey1=%CommonAppData%\Sage Software, Inc\ACT! by Sage\ActUpdate|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sage Software, Inc\ACT! by Sage\ActUpdate|*.*|RECURSE + +[Sage Simply Accounting *] +LangSecRef=3021 +Detect=HKLM\Software\Sage Software\Simply Accounting +Default=False +FileKey1=%CommonAppData%\Sage Software\Simply Accounting\Download|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sage Software\Simply Accounting\Download|*.*|RECURSE + +[SageThumbs *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\SageThumbs\64\SageThumbs.dll +Default=False +FileKey1=%LocalAppData%|SageThumbs.* + +[SAM Broadcaster *] +LangSecRef=3023 +Detect=HKCU\Software\SAMBC +Default=False +FileKey1=%LocalAppData%\SpacialAudio\SAMBC|*.log|RECURSE +FileKey2=%LocalAppData%\SpacialAudio\SAMBC\backup|*.*|RECURSE + +[Samsung Kies *] +LangSecRef=3023 +Detect1=HKCU\Software\Samsung\Kies2.0 +Detect2=HKCU\Software\Samsung\Kies3.0 +Detect3=HKLM\Software\SAMSUNG\USB_DRIVER +Default=False +FileKey1=%AppData%\Samsung\Kies|*.mlca;*.mlme;*.mlpb;*.mlpgb|RECURSE +FileKey2=%CommonAppData%\Samsung\Device Error Recovery|*.* +FileKey3=%CommonAppData%\Samsung\Kies|Kiesairmessage.log +FileKey4=%Documents%\samsung\Kies3\backup|*.dmp|RECURSE +FileKey5=%Documents%\SelfMV|*.log +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Samsung\Device Error Recovery|*.log +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Samsung\Kies|Kiesairmessage.log + +[Samsung Kies Backup *] +LangSecRef=3023 +Detect1=HKCU\Software\Samsung\Kies2.0 +Detect2=HKCU\Software\Samsung\Kies3.0 +Default=False +Warning=Removing backups will prevent you from restoring your data later. +FileKey1=%Documents%\samsung\Kies*\backup|*.*|RECURSE + +[Samsung Magician *] +LangSecRef=3021 +Detect=HKLM\Software\Samsung Magician +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Samsung\Samsung Magician|*.log;*.txt|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Samsung\Samsung Magician\Log*|*.* +FileKey3=%ProgramFiles%\Samsung Magician\Logs|*.* +FileKey4=%ProgramFiles%\Samsung\Samsung Magician\Log*|*.* +RegKey1=HKCU\Software\Local AppWizard-Generated Applications\SamsungMagician + +[Sanctum *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\91600 +Default=False +FileKey1=%Documents%\My Games\Sanctum\SanctumGame\Logs|*.* + +[Santa Ride! 2 *] +Section=Games +Detect=HKLM\Software\Invictus-Games\Santa Ride 2 +DetectFile=%ProgramFiles%\Invictus Games\Santa Ride! 2\SR2.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Invictus Games\Santa Ride! 2|*.log +FileKey2=%ProgramFiles%\Invictus Games\Santa Ride! 2|*.log + +[Santa's Rampage *] +Section=Games +DetectFile=%ProgramFiles%\*Santa* Rampage +Default=False +FileKey1=%ProgramFiles%\*Santa* Rampage|*.diz;*.nfo;*.txt;*.url;dotNetFx40_Full_setup.exe|RECURSE +FileKey2=%ProgramFiles%\*Santa* Rampage\Redist|*.*|REMOVESELF +FileKey3=%ProgramFiles%\*Santa* Rampage\UDKGame\Logs|*.*|REMOVESELF +ExcludeKey1=FILE|%ProgramFiles%\*Santa* Rampage\UDKGame\CookedPC\|Manifest.txt +ExcludeKey2=PATH|%ProgramFiles%\*Santa* Rampage\Binaries\Win32\|*.* +ExcludeKey3=PATH|%ProgramFiles%\*Santa* Rampage\Binaries\Win64\|*.* +ExcludeKey4=PATH|%ProgramFiles%\*Santa* Rampage\UDKGame\Script\|*.* + +[Sauerbraten *] +Section=Games +DetectFile=%ProgramFiles%\Sauerbraten\bin\sauerbraten.exe +Default=False +FileKey1=%Documents%\My Games\Crash|*.log +FileKey2=%Documents%\My Games\Sauerbraten|log.txt +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Sauerbraten\packages\base|*.bak|RECURSE +FileKey4=%ProgramFiles%\Sauerbraten\packages\base|*.bak|RECURSE + +[SavingsBull *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\SavingsBullFilter +Default=False +FileKey1=%WinDir%\System32|SavingsBullFilterService.log + +[SBMAV Disk Cleaner *] +LangSecRef=3024 +Detect=HKCU\Software\SBMAV Software\Disk Cleaner +Default=False +FileKey1=%AppData%\SBMAV Disk Cleaner|dcleaner.log +FileKey2=%ProgramFiles%\SBMAV Disk Cleaner|*.rtf + +[Scan *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsScan_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.WindowsScan_*\TempState|*.*|RECURSE + +[ScanDefrag *] +LangSecRef=3024 +Detect=HKLM\Software\ScanDefrag +Default=False +FileKey1=%SystemDrive%\ScanDefrag|*.log +FileKey2=%SystemDrive%\ScanDefrag\logs|*.txt + +[Screenpresso *] +LangSecRef=3024 +DetectFile=%AppData%\Learnpulse\Screenpresso +Default=False +FileKey1=%AppData%\Learnpulse\Screenpresso|settings.copy.xml +FileKey2=%Pictures%\Screenpresso\Thumbnails|*.*|RECURSE + +[ScreenShot Index *] +DetectOS=6.2| +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +Warning=This Resets Screenshot Naming Back To "Screenshot (1).png" +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer|ScreenshotIndex + +[Scribe Finished Jobs *] +LangSecRef=3021 +Detect=HKCU\Software\NCH Software\Scribe +Default=False +Warning=This will delete copies of files related you have run through Scribe. +FileKey1=%AppData%\NCH Software\Scribe\Done|*.* + +[Scribus *] +LangSecRef=3023 +DetectFile=%AppData%\Scribus +Default=False +FileKey1=%AppData%\Scribus\scrapbook\tmp|*.*|RECURSE + +[SdfBrowser *] +LangSecRef=3024 +DetectFile=%AppData%\BokorBéla\SdfBrowser +Default=False +FileKey1=%AppData%\BokorBéla\SdfBrowser|*.log + +[Seagate Dashboard *] +LangSecRef=3024 +Detect=HKLM\Software\Seagate\Seagate Dashboard\CurrentVersion +Default=False +FileKey1=%AppData%\Seagate\Seagate Dashboard\logs|MemeoLauncher.exe.log;SeagateDashboard-*.log;MemeoLauncher.exe.log-*.log;MemeoUpdater.exe.log;MemeoUpdater.exe.log-*.log +FileKey2=%WinDir%\System32\config\systemprofile\AppData\Roaming\Seagate\Seagate Dashboard\logs|SeagateDashboardService;SeagateDashboardService-*.log +FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Seagate\Seagate Dashboard\logs|SeagateDashboardService;SeagateDashboardService-*.log + +[Seagate SeaTools for Windows *] +LangSecRef=3024 +Detect=HKLM\Software\SeaToolsforWindows +Default=False +FileKey1=%AppData%\Dexpot|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Seagate\SeaTools for Windows|*.log +FileKey3=%ProgramFiles%\Seagate\SeaTools for Windows|*.log + +[Search History *] +DetectOS=6.2| +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SearchHistory +RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps + +[Second Copy *] +LangSecRef=3024 +Detect=HKCU\Software\Centered Systems\Second Copy 2000 +DetectFile=%LocalAppData%\Centered Systems\Second Copy +Default=False +FileKey1=%LocalAppData%\Centered Systems\Second Copy|log*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\SecCopy|log.rtf;log-old.rtf +FileKey3=%ProgramFiles%\SecCopy|log.rtf;log-old.rtf +RegKey1=HKCU\Software\Centered Systems\Second Copy 2000\MRU + +[SecondLife *] +LangSecRef=3021 +DetectFile=%AppData%\SecondLife +Default=False +FileKey1=%AppData%\SecondLife\*|*.txt|RECURSE +FileKey2=%AppData%\SecondLife\Logs|*.* + +[SecondLife Caches *] +LangSecRef=3021 +DetectFile=%AppData%\SecondLife +Default=False +FileKey1=%AppData%\SecondLife\*\Browser_Profile\Cache|*.*|RECURSE +FileKey2=%AppData%\SecondLife\*\cache|*.*|RECURSE +FileKey3=%AppData%\SecondLife\cache|*.*|RECURSE + +[SecureCRT *] +LangSecRef=3021 +Detect=HKCU\Software\VanDyke\SecureCRT +Default=False +FileKey1=%AppData%\VanDyke\SecureCRT\Config|Recent File List.ini;Recent Script List.ini + +[SecureDownloadManager *] +LangSecRef=3022 +Detect=HKCU\Software\e-academy Inc.\SecureDownloadManager +Default=False +FileKey1=%LocalAppData%\e-academy Inc\SecureDownloadManager|*.log +RegKey1=HKCU\Software\e-academy Inc.\SecureDownloadManager\Recent File list + +[Sendori *] +LangSecRef=3022 +DetectFile=%CommonAppData%\Sendori +Default=False +FileKey1=%CommonAppData%\Sendori|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sendori|*.log + +[Serious Sam *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\41014 +Detect2=HKCU\Software\Valve\Steam\Apps\41070 +Detect3=HKCU\Software\Valve\Steam\Apps\564310 +DetectFile=%ProgramFiles%\Croteam\Serious Sam * +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Croteam\Serious Sam *|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Croteam\Serious Sam *\Temp|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Serious Sam *|*.log +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Serious Sam *\Log|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Serious Sam *\Temp|*.* +FileKey6=%ProgramFiles%\Croteam\Serious Sam *|*.log +FileKey7=%ProgramFiles%\Croteam\Serious Sam *\Temp|*.* +FileKey8=%ProgramFiles%\Steam\SteamApps\Common\Serious Sam *|*.log +FileKey9=%ProgramFiles%\Steam\SteamApps\Common\Serious Sam *\Log|*.*|RECURSE +FileKey10=%ProgramFiles%\Steam\SteamApps\Common\Serious Sam *\Temp|*.* + +[ServeToMe *] +LangSecRef=3023 +DetectFile=%AppData%\ProjectsWithLove\ServeToMe +Default=False +FileKey1=%AppData%\ProjectsWithLove\ServeToMe\Fontcache|*.* + +[Serviio *] +LangSecRef=3024 +Detect=HKLM\Software\Serviio +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Serviio\log|*.* +FileKey2=%ProgramFiles%\Serviio\log|*.* + +[Session Manager *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Windows +Default=False +FileKey1=%WinDir%\AppCompat\Programs|*.txt;*.xml +FileKey2=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml +RegKey1=HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatCache|AppCompatCache +RegKey2=HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatCache|CacheMainSdb +RegKey3=HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatCache|SdbTime + +[SetRegistryKey Leftovers *] +LangSecRef=3025 +Detect=HKCU\Software\Local AppWizard-Generated Applications +Default=False +Warning=Running this entry will cause it to self destruct and no longer appear. This is the intended behavior. +RegKey1=HKCU\Software\Local AppWizard-Generated Applications + +[Shareaza *] +LangSecRef=3022 +Detect=HKCU\Software\BHO Shareaza +Default=False +FileKey1=%LocalAppData%\Shareaza\Incomplete|*.* + +[ShareX *] +LangSecRef=3021 +DetectFile=%Documents%\ShareX +Default=False +FileKey1=%Documents%\ShareX|History.xml +FileKey2=%Documents%\ShareX\Logs|*.*|RECURSE + +[ShareX Backup *] +LangSecRef=3021 +DetectFile=%Documents%\ShareX +Default=False +FileKey1=%Documents%\ShareX|*.avi;*.bak +FileKey2=%Documents%\ShareX\Backup|*.*|RECURSE + +[ShareX Screenshots *] +LangSecRef=3021 +DetectFile=%Documents%\ShareX +Default=False +Warning=This will delete all Screenshots captured by ShareX. +FileKey1=%Documents%\ShareX\Screenshots|*.*|RECURSE + +[Sharing MFU *] +DetectOS=6.2| +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +Warning=This will remove the frequently shared list. This does not remove the Apps listed under sharing. +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SharingMFU + +[Shark Dash *] +Section=Games +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\GAMELOFTSA.SharkDashByGameloft_0pp20fcewvvtj +DetectFile=%LocalAppData%\Packages\GAMELOFTSA.SharkDashByGameloft_0pp20fcewvvtj +Default=False +FileKey1=%LocalAppData%\Packages\GAMELOFTSA.SharkDashByGameloft_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\GAMELOFTSA.SharkDashByGameloft_*\AC\Microsoft\CryptnetUrlCache\*|*.* + +[Shatter *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\20820 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Shatter|log.txt +FileKey2=%ProgramFiles%\Steam\steamapps\common\Shatter|log.txt + +[Shattered Horizon *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\18110 +DetectFile=%LocalAppData%\Futuremark\Shattered Horizon +Default=False +FileKey1=%LocalAppData%\Futuremark\Shattered Horizon\cache|*.*|REMOVESELF +FileKey2=%LocalAppData%\Futuremark\Shattered Horizon\crash_dumps|*.* + +[Shell Experience Host *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\TempState|*.*|RECURSE + +[Shipping Assistant *] +LangSecRef=3021 +DetectFile=%LocalAppData%\ShippingAssistant +Default=False +FileKey1=%LocalAppData%\ShippingAssistant\Logs|*.*|RECURSE + +[ShortKeys *] +LangSecRef=3021 +Detect=HKCU\Software\Insight Software Solutions\ShortKeys +Default=False +RegKey1=HKCU\Software\Insight Software Solutions\ShortKeys\MRU + +[Should I Remove It? *] +LangSecRef=3024 +Detect=HKCU\Software\Reason +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Reason\Should I Remove It|programdata.dat +FileKey2=%ProgramFiles%\Reason\Should I Remove It|programdata.dat +RegKey1=HKCU\Software\Reason\ShouldIRemoveIt\Cache + +[Shuffle Party *] +Section=Games +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ShuffleParty_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.ShuffleParty_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.ShuffleParty_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.ShuffleParty_*\AC\Microsoft\CryptnetUrlCache\*|*.* + +[Signature Verification *] +DetectOS=|5.1 +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%WinDir%|SIGVERIF.TXT + +[SigParser *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\UpdateStar\SigParser\SigParser.exe +Default=False +FileKey1=%AppData%\UpdateStar GmbH\SigParser\3.0.4898.22300|*.log + +[Silent Hunter III *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\15210 +DetectFile=%ProgramFiles%\Ubisoft\SilentHunterIII +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\SilentHunterIII|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\SilentHunterIII|*.log|RECURSE +FileKey3=%ProgramFiles%\Steam\SteamApps\Common\SilentHunterIII|*.log|RECURSE +FileKey4=%ProgramFiles%\Ubisoft\SilentHunterIII|*.log|RECURSE + +[SimCity 4 *] +Section=Games +Detect=HKLM\Software\Maxis\SimCity 4 +Default=False +FileKey1=%Documents%\SimCity 4\Exception Reports|*.mdmp;*.txt +FileKey2=%Documents%\SimCity 4\HTTPCache|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Maxis\SimCity 4 Deluxe\Apps|*.txt +FileKey4=%ProgramFiles%\Maxis\SimCity 4 Deluxe\Apps|*.txt + +[SimCity Societies *] +Section=Games +Detect1=HKLM\Software\Electronic Arts\SimCity Societies +Detect2=HKLM\Software\Electronic Arts\SimCity Societies (tm) Destinations +Default=False +FileKey1=%Documents%\SimCity Societies\Logs|*.* + +[Similarity *] +LangSecRef=3023 +DetectFile=%AppData%\Similarity +Default=False +FileKey1=%AppData%\Similarity|cache.dat +FileKey2=%AppData%\Similarity\logs|*.*|RECURSE + +[SIMS RACER *] +Section=Games +DetectFile1=%CommonAppData%\SIMS\RACER +DetectFile2=%ProgramFiles%\SIMS\RACER +DetectFile3=%SystemDrive%\SIMS\RACER +Default=False +FileKey1=%CommonAppData%\SIMS\RACER|QLOG.txt +FileKey2=%LocalAppData%\VirtualStore\Program*\SIMS\RACER|QLOG.txt +FileKey3=%ProgramFiles%\SIMS\RACER|QLOG.txt +FileKey4=%SystemDrive%\SIMS\RACER|QLOG.txt + +[SiSense *] +LangSecRef=3021 +DetectFile=%AppData%\SiSense +Default=False +FileKey1=%AppData%\SiSense\Prism\logs|*.* +FileKey2=%CommonAppData%\SiSense|*.slog;*.log|RECURSE +FileKey3=%CommonAppData%\SiSense\Logs|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\SiSense|*.slog;*.log|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\SiSense\Logs|*.*|RECURSE + +[SketchUp Make *] +LangSecRef=3021 +Detect=HKCU\Software\SketchUp +Default=False +FileKey1=%AppData%\SketchUp\SketchUp *\SketchUp|~*.tmp +RegKey1=HKCU\Software\SketchUp\SketchUp 2013\Recent File List +RegKey2=HKCU\Software\SketchUp\SketchUp 2014\Recent File List +RegKey3=HKCU\Software\SketchUp\SketchUp 2015\Recent File List +RegKey4=HKCU\Software\SketchUp\SketchUp 2016\Recent File List + +[SKSE *] +Section=Games +DetectFile=%Documents%\My Games\Skyrim\SKSE +Default=False +FileKey1=%Documents%\My Games\Skyrim\SKSE|*.log + +[SkyDrive App *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.microsoftskydrive_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\microsoft.microsoftskydrive_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\PRICache|*.* +FileKey6=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\Temp|*.* +FileKey7=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.microsoftskydrive_8wekyb3d8bbwe\PersistedPickerData\microsoft.microsoftskydrive_8wekyb3d8bbwe!Microsoft.MicrosoftSkyDrive\DefaultOpenFileMultiple|LastLocation +RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.microsoftskydrive_8wekyb3d8bbwe\SearchHistory + +[Skype *] +LangSecRef=3022 +Detect=HKCU\Software\Skype +DetectFile=%ProgramFiles%\Skype For Salesforce +Default=False +FileKey1=%AppData%\Skype|*.tmp;*.db-journal;*.lck;*.lock;cookies.dat|RECURSE +FileKey2=%AppData%\Skype\*\*cache|*.*|RECURSE +FileKey3=%AppData%\Skype\*\httpfe|*.* +FileKey4=%AppData%\Skype\*\logs|*.* +FileKey5=%AppData%\Skype\*\media_messaging\*\asyncdb\tmp|*.* +FileKey6=%AppData%\Skype\*\media_messaging\media_cache*|*.* +FileKey7=%AppData%\Skype\*\qikdb\tmp|*.* +FileKey8=%AppData%\Skype\DataRv|*.* +FileKey9=%AppData%\Skype\DbTemp|*.*|RECURSE +FileKey10=%AppData%\SkypePM|*.ezlog +FileKey11=%CommonAppData%\Skype|SkypeToolbars.msi;Skype.msi|RECURSE +FileKey12=%UserProfile%\Tracing\WPPMedia|*.*|RECURSE + +[Skype Messages *] +LangSecRef=3022 +Detect=HKCU\Software\Skype +Default=False +Warning=This will delete your chat message history! +FileKey1=%AppData%\Skype|offline-storage.data;dc.db|RECURSE +FileKey2=%AppData%\Skype\*\chatsync|*.*|RECURSE + +[Skype Metro *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.SkypeApp_kzf8qxf38zg5c +DetectFile=%LocalAppData%\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.SkypeApp_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.SkypeApp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.* +FileKey3=%LocalAppData%\Packages\Microsoft.SkypeApp_*\AC\PRICache|*.* +FileKey4=%LocalAppData%\Packages\Microsoft.SkypeApp_*\LocalState|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.SkypeApp_*\TempState|*.*|RECURSE + +[SkypeAlyzer *] +LangSecRef=3024 +Detect=HKCU\Software\Raize\CodeSite +Default=False +FileKey1=%LocalAppData%\Raize\CodeSite\5.0|CSDispatcherLog.txt + +[Sleeping Dogs *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\202170 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\SleepingDogs|LogBoot.txt;LogShaders.txt +FileKey2=%ProgramFiles%\Steam\Steamapps\common\SleepingDogs|LogBoot.txt;LogShaders.txt + +[SlimBoat *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\SlimBoat\SlimBoat.exe +Default=False +FileKey1=%LocalAppData%\FlashPeak\SlimBoat\cache|*.*|RECURSE +FileKey2=%LocalAppData%\FlashPeak\SlimBoat\cookies|*.*|RECURSE +FileKey3=%LocalAppData%\FlashPeak\SlimBoat\history|*.*|RECURSE +FileKey4=%LocalAppData%\FlashPeak\SlimBoat\iconcache|*.*|RECURSE +FileKey5=%LocalAppData%\FlashPeak\SlimBoat\LocalStorage|*.*|RECURSE + +[SlimBrowser *] +LangSecRef=3022 +Detect=HKCU\Software\FlashPeak\SlimBrowser +DetectFile=%ProgramFiles%\SlimBrowser\sbframe.exe +Default=False +FileKey1=%AppData%\SlimBrowser|freqsite.txt;RecentCloseW.ini;freqform.txt +FileKey2=%AppData%\SlimBrowser\iconcache|*.*|RECURSE + +[SlimCleaner *] +LangSecRef=3024 +Detect1=HKCU\Software\SlimWare Utilities Inc\SlimCleaner +Detect2=HKCU\Software\SlimWare Utilities Inc\SlimCleaner Plus +Default=False +FileKey1=%CommonAppData%\SlimWare Utilities Inc\Services\SlimService*\Logs|*.log +FileKey2=%LocalAppData%\SlimWare Utilities Inc\SlimCleaner*\Cache|*.*|RECURSE +FileKey3=%LocalAppData%\SlimWare Utilities Inc\SlimCleaner*\Logs|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\Program Files*\SlimCleaner*|*.txt +FileKey5=%LocalAppData%\VirtualStore\ProgramData\SlimWare Utilities Inc\Services\SlimService*\Logs|*.log +FileKey6=%ProgramFiles%\SlimCleaner*|*.txt + +[SlimComputer *] +LangSecRef=3024 +DetectFile=%LocalAppData%\SlimWare Utilities Inc\SlimComputer +Default=False +FileKey1=%LocalAppData%\SlimWare Utilities Inc\SlimComputer\Logs|*.log + +[SlimDrivers *] +LangSecRef=3024 +Detect=HKCU\Software\SlimWare Utilities Inc\SlimDrivers +Default=False +FileKey1=%LocalAppData%\SlimWare Utilities Inc\SlimDrivers\Logs|*.*|RECURSE + +[SlimDrivers Backups *] +LangSecRef=3024 +Detect=HKCU\Software\SlimWare Utilities Inc\SlimDrivers +Default=False +FileKey1=%LocalAppData%\SlimWare Utilities Inc\SlimDrivers\Backups|*.*|RECURSE + +[SlimDrivers Downloads *] +LangSecRef=3024 +Detect=HKCU\Software\SlimWare Utilities Inc\SlimDrivers +Default=False +FileKey1=%LocalAppData%\SlimWare Utilities Inc\SlimDrivers\Downloads|*.*|RECURSE +FileKey2=%LocalAppData%\SlimWare Utilities Inc\SlimDrivers\Images|*.*|RECURSE + +[Smart Explorer *] +LangSecRef=3021 +Detect=HKCU\Software\Smartque\Smart Explorer +Default=False +RegKey1=HKCU\Software\Smartque\Smart Explorer\Opened Pages +RegKey2=HKCU\Software\Smartque\Smart Explorer\Recent Pages + +[Smart Installer Maker *] +LangSecRef=3024 +Detect=HKCU\Software\InstallBuilders\Smart Install Maker +Default=False +RegKey1=HKCU\Software\InstallBuilders\Smart Install Maker\Reopen + +[Smart PDF Creator Pro *] +LangSecRef=3024 +DetectFile=%AppData%\Smart PDF Creator Pro +Default=False +FileKey1=%AppData%\Smart PDF Creator Pro|Smart PDF Creator Pro_log*.* + +[Smileys We Love Toolbar for IE *] +LangSecRef=3022 +Detect=HKCU\Software\SmileysWeLove +DetectFile=%ProgramFiles%\SqueekyChocolate, LLC\Smileys We Love Toolbar for IE\adxregistrator.exe +Default=False +FileKey1=%Documents%\Add-in Express|adxregistrator.log + +[SMPlayer File Settings *] +LangSecRef=3023 +Detect=HKCR\Applications\smplayer.exe +DetectFile=%LocalAppData%\SMPlayer2 +Default=False +FileKey1=%LocalAppData%\SMPlayer2\File_settings|*.*|RECURSE +FileKey2=%UserProfile%\.smplayer\file_settings|*.*|RECURSE + +[SMPlayer Screenshots *] +LangSecRef=3023 +Detect=HKCR\Applications\smplayer.exe +DetectFile=%LocalAppData%\SMPlayer2 +Default=False +FileKey1=%LocalAppData%\SMPlayer2\screenshots|*.*|RECURSE +FileKey2=%Pictures%\smplayer*_screenshots|*.*|RECURSE +FileKey3=%UserProfile%\.smplayer\screenshots|*.*|RECURSE + +[Snagit *] +LangSecRef=3021 +Detect=HKCU\Software\TechSmith\Snagit +Default=False +Warning=This will delete the backups of the captures. +FileKey1=%CommonAppData%\TechSmith\Uploader|*.log +FileKey2=%Documents%|SnagitDebug.log +FileKey3=%LocalAppData%\TechSmith\Logs|*.log +FileKey4=%LocalAppData%\TechSmith\Snagit|Tray.bin +FileKey5=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE +FileKey6=%LocalAppData%\TechSmith\Snagit\DataStore|*.SNAG;*.SNAGundo;*.MP4 +FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico +FileKey8=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico +FileKey9=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE +FileKey10=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log +RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder +RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder +RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount +RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount +RegKey5=HKCU\Software\TechSmith\Snagit\12|CaptureCount +RegKey6=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount +RegKey7=HKCU\Software\TechSmith\Snagit\13|CaptureCount +RegKey8=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount +RegKey9=HKCU\Software\TechSmith\Snagit\13\Recent Captures +RegKey10=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List +RegKey11=HKCU\Software\TechSmith\Snagit\18|CaptureCount +RegKey12=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount +RegKey13=HKCU\Software\TechSmith\Snagit\18\Recent Captures +RegKey14=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List +RegKey15=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder + +[Snapfish Picture Mover *] +LangSecRef=3023 +DetectFile=%AppData%\PictureMover +Default=False +FileKey1=%AppData%\PictureMover\Log|*.* + +[Snip & Sketch *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ScreenSketch_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\AC\Temp|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\LocalCache\Cache|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\LocalState\Cache|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\TempState|*.*|RECURSE + +[Sniper Art of Victory *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\271500 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Sniper Art of Victory\logs|*.* +FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Sniper Art of Victory\logs|*.* + +[Sniper: Ghost Warrior *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\34830 +Default=False +FileKey1=%Documents%\Sniper - Ghost Warrior\out\logs|*.* + +[Snuggle Truck *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\111100 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\snuggle truck\Snuggle Truck_Data|output_log.txt +FileKey2=%ProgramFiles%\Steam\steamapps\common\snuggle truck\Snuggle Truck_Data|output_log.txt + +[Sobees *] +LangSecRef=3022 +DetectFile=%AppData%\sobees Ltd\Sobees +Default=False +FileKey1=%AppData%\sobees Ltd\Sobees\tmp\imagecache|*.*|RECURSE + +[SocialFolders *] +LangSecRef=3022 +DetectFile=%LocalAppData%\ftopia\SocialFolders +Default=False +FileKey1=%LocalAppData%\ftopia\SocialFolders\Cache|*.*|RECURSE +FileKey2=%LocalAppData%\ftopia\SocialFolders\Dumps|*.*|RECURSE + +[Soda Player *] +LangSecRef=3023 +DetectFile=%LocalAppData%\sodaplayer +Default=False +FileKey1=%AppData%\Soda Player|Cookies* +FileKey2=%AppData%\Soda Player\*Cache|*.* +FileKey3=%AppData%\Soda Player\acestream\engine|*.log +FileKey4=%AppData%\Soda Player\Local Storage|*.* +FileKey5=%LocalAppData%\sodaplayer|SquirrelSetup.log +FileKey6=%SystemDrive%\_acestream_cache_|*.*|REMOVESELF + +[SoftCafe MenuPRo *] +LangSecRef=3021 +DetectFile=%AppData%\SoftCafe\MenuPro +Default=False +FileKey1=%AppData%\SoftCafe\MenuPro|*.tmp + +[SoftEther VPN *] +LangSecRef=3024 +Detect=HKCU\Software\SoftEther Project\SoftEther VPN +Default=False +Warning=Exclude installer.cache if you're using SoftEther VPN Client Web Installer. +FileKey1=%ProgramFiles%\SoftEther VPN Client|installer.cache +FileKey2=%ProgramFiles%\SoftEther VPN Client\backup.vpn_client.config|*.config +FileKey3=%ProgramFiles%\SoftEther VPN Client\client_log|*.* +FileKey4=%ProgramFiles%\SoftEther VPN Client\vpn_debug|*.* + +[SoftGrid Client *] +LangSecRef=3022 +DetectFile=%AppData%\SoftGrid Client +Default=False +FileKey1=%AppData%\SoftGrid Client|*.tmp|RECURSE +FileKey2=%AppData%\SoftGrid Client\Icon Cache|*.* +FileKey3=%CommonAppData%\Microsoft\Application Virtualization Client\SoftGrid Client|*.tmp|RECURSE +FileKey4=%LocalAppData%\SoftGrid Client|*.tmp|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Application Virtualization Client\SoftGrid Client|*.tmp|RECURSE + +[Softonic *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Softonic\Softonic.exe +Default=False +FileKey1=%LocalAppData%\Softonic\cache|*.*|RECURSE + +[SoftThinks CD Creator *] +LangSecRef=3021 +Detect=HKLM\Software\SoftThinks +Default=False +FileKey1=%WinDir%\CREATOR|*.log + +[Software Informer *] +LangSecRef=3023 +DetectFile=%AppData%\Software Informer +Default=False +FileKey1=%AppData%\Software Informer\cache\icons|*.tmp + +[Solarix *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\284990 +Default=False +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Solarix\UDKGame\Logs|*.* + +[Sonata *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Sonata +Default=False +FileKey1=%LocalAppData%\Sonata\temp|*.*|RECURSE +FileKey2=%ProgramFiles%\Sonata\update|*.*|RECURSE + +[SongKong *] +LangSecRef=3023 +DetectFile=%AppData%\SongKong +Default=False +FileKey1=%AppData%\SongKong\Logs|*.*|RECURSE + +[Sonic Visualiser *] +LangSecRef=3023 +Detect=HKCU\Software\sonic-visualiser +DetectFile=%UserProfile%\.Sonic Visualiser +Default=False +FileKey1=%UserProfile%\.Sonic Visualiser\cache|*.* +RegKey1=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-0 +RegKey2=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-1 +RegKey3=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-2 +RegKey4=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-3 +RegKey5=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-4 +RegKey6=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-5 +RegKey7=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-6 +RegKey8=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-7 +RegKey9=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-8 +RegKey10=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-9 +RegKey11=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-10 +RegKey12=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-11 +RegKey13=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-12 +RegKey14=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-13 +RegKey15=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-14 +RegKey16=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-15 +RegKey17=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-16 +RegKey18=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-17 +RegKey19=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-18 +RegKey20=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-19 + +[Sonique *] +LangSecRef=3023 +Detect=HKCU\Software\MediaScience\Sonique +Default=False +RegKey1=HKCU\Software\MediaScience\Sonique\Play_History +RegKey2=HKCU\Software\MediaScience\Sonique\URL_History + +[Sony Magic Update *] +LangSecRef=3024 +DetectFile=%AppData%\Sony Corporation\Auto Magic Update Client +Default=False +FileKey1=%AppData%\Sony Corporation\Auto Magic Update Client|*.log + +[Sony Media Go *] +LangSecRef=3021 +Detect=HKCU\Software\Sony Corporation\Media Go +Default=False +FileKey1=%AppData%\Sony\Media Go|*.bkd + +[Sony Media Manager *] +LangSecRef=3023 +DetectFile=%AppData%\Sony\Media Manager +Default=False +FileKey1=%AppData%\Sony\Media Manager|*.log;*log.txt +FileKey2=%AppData%\Sony\Media Manager\Thumbnails|*.*|RECURSE + +[Sony SonicStage *] +LangSecRef=3021 +DetectFile=%AppData%\Sony\SonicStage +Default=False +FileKey1=%AppData%\Sony\SonicStage|*.log +FileKey2=%AppData%\Sony\SonicStage\Temp|*.* + +[Sony Sound Organizer *] +LangSecRef=3024 +DetectFile=%AppData%\Sony Corporation\Sound Organizer +Default=False +FileKey1=%AppData%\Sony Corporation\Sound Organizer|*.log + +[Sony Vegas Pro *] +LangSecRef=3023 +Detect1=HKLM\Software\Sony Creative Software\Vegas +Detect2=HKLM\Software\Sony Media Software\Vegas +Default=False +FileKey1=%AppData%\Sony|*.log +FileKey2=%LocalAppData%\Sony\Vegas Pro\*|*.log + +[Sorcery! Parts 1 And 2 *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\105430 +Default=False +FileKey1=%LocalAppData%\inkle\Sorcery|*.log + +[Soulseek *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Soulseek\slsk.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Soulseek*|search.cfg +FileKey2=%ProgramFiles%\Soulseek*|search.cfg + +[Soulseek NS *] +LangSecRef=3022 +Detect=HKCU\Software\Soulseek2 +Default=False +Warning=This will delete your chat history. +FileKey1=%Documents%\Soulseek Chat Logs\Private|*.txt +RegKey1=HKCU\Software\Soulseek2\config|search + +[SoulseekQt *] +LangSecRef=3022 +Detect=HKLM\Software\SoulseekQt +DetectFile=%ProgramFiles%\SoulseekQt\SoulseekQt.exe +Default=False +Warning=This will delete your chat history. +FileKey1=%LocalAppData%\Soulseek Chat Logs\*|*.log + +[Sound Recorder *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\TempState|*.*|RECURSE + +[SoundMAX *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\Analog Devices\SoundMAX +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Analog Devices\SoundMAX|SMax.log;SMax.log.bak +FileKey2=%ProgramFiles%\Analog Devices\SoundMAX|SMax.log;SMax.log.bak + +[SpaceEngineers *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\244850 +Default=False +FileKey1=%AppData%\SpaceEngineers|*.log + +[SpeedFan *] +LangSecRef=3024 +Detect=HKCU\Software\SpeedFan +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\SpeedFan|debug.nfo;SFLog*.csv +FileKey2=%ProgramFiles%\SpeedFan|debug.nfo;SFLog*.csv + +[SpeedRunners *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\207140 +Default=False +FileKey1=%AppData%|SpeedRunnersLog.txt;TargetInvocationLog.txt + +[SpeedyComputer *] +LangSecRef=3024 +DetectFile=%AppData%\SpeedyComputer +Default=False +FileKey1=%AppData%\SpeedyComputer\Log|*.*|RECURSE + +[SpiderOak *] +LangSecRef=3024 +DetectFile=%AppData%\SpiderOak +Default=False +FileKey1=%AppData%\SpiderOak|*.log|RECURSE +FileKey2=%AppData%\SpiderOak\download_cache|*.* + +[Spiral Knights *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\99900 +Default=False +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Spiral Knights|*.log + +[Splice *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\209790 +Default=False +FileKey1=%Documents%|GALog.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\splice|output_log.txt +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Splice\Splice_Data|output_log.txt +FileKey4=%ProgramFiles%\Steam\steamapps\common\splice|output_log.txt +FileKey5=%ProgramFiles%\Steam\steamapps\common\Splice\Splice_Data|output_log.txt + +[SpongeBob Diner Dash *] +Section=Games +DetectFile=%ProgramFiles%\SpongeBob Diner Dash +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\SpongeBob Diner Dash|logfile.* +FileKey2=%ProgramFiles%\SpongeBob Diner Dash|logfile.* + +[Spooky Mall *] +Section=Games +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spooky Mall1.0 +Default=False +FileKey1=%CommonAppData%\SpookyMall|*.xml_log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Foxy Games\Spooky Mall|*.log +FileKey3=%LocalAppData%\VirtualStore\ProgramData\SpookyMall|*.xml_log +FileKey4=%ProgramFiles%\Foxy Games\Spooky Mall|*.log + +[SporTV *] +LangSecRef=3021 +DetectFile=%LocalAppData%\SporTV +Default=False +FileKey1=%LocalAppData%\SporTV\Logs|*.* + +[Spotflux *] +LangSecRef=3021 +Detect=HKLM\Software\Spotflux +DetectFile=%ProgramFiles%\Spotflux\spotflux.exe +Default=False +FileKey1=%AppData%\.spotflux|*.log + +[Spotify *] +LangSecRef=3023 +DetectFile=%LocalAppData%\Spotify +Default=False +FileKey1=%LocalAppData%\Spotify\Browser|*.*|RECURSE +FileKey2=%LocalAppData%\Spotify\Storage|*.*|RECURSE + +[Spoutcraft *] +Section=Games +DetectFile=%AppData%\.spoutcraft +Default=False +FileKey1=%AppData%\.spoutcraft|*.log +FileKey2=%AppData%\.spoutcraft\logs|*.* + +[Sprint Hero RUU Installer *] +LangSecRef=3023 +DetectFile=%SystemDrive%\ruu_log +Default=False +FileKey1=%SystemDrive%\ruu_log|*.*|REMOVESELF + +[Spybot Search and Destroy 2 *] +LangSecRef=3024 +Detect=HKCU\Software\Safer Networking Limited\Spybot - Search & Destroy 2 +Default=False +FileKey1=%CommonAppData%\Spybot - Search & Destroy\Logs|*.*|RECURSE +FileKey2=%CommonAppData%\Spybot - Search & Destroy\System Configuration Snapshots|*.*|REMOVESELF +FileKey3=%Documents%\ProcAlyzer Dumps|*.*|REMOVESELF +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Spybot - Search & Destroy\Logs|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Spybot - Search & Destroy\System Configuration Snapshots|*.*|REMOVESELF + +[Spybot Search and Destroy History *] +LangSecRef=3024 +Detect=HKLM\Software\Safer Networking Limited\SpybotSnD +Default=False +FileKey1=%CommonAppData%\Spybot – Search & Destroy\Backups|*.*|RECURSE +FileKey2=%CommonAppData%\Spybot – Search & Destroy\Recovery|*.*|RECURSE +FileKey3=%CommonAppData%\Spybot – Search & Destroy\Snapshots*|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Spybot – Search & Destroy\Backups|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Spybot – Search & Destroy\Recovery|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Spybot – Search & Destroy\Snapshots*|*.*|RECURSE + +[Spybot Search and Destroy Hosts Backups *] +LangSecRef=3024 +Detect1=HKCU\Software\Safer Networking Limited\Spybot - Search & Destroy 2 +Detect2=HKLM\Software\Safer Networking Limited\SpybotSnD +Default=False +FileKey1=%WinDir%\System32\drivers\etc|hosts.*.backup + +[Spybot Search and Destroy Updates *] +LangSecRef=3024 +Detect1=HKCU\Software\Safer Networking Limited\Spybot - Search & Destroy 2 +Detect2=HKLM\Software\Safer Networking Limited\SpybotSnD +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Spybot - Search & Destroy 2\Updates|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Spybot - Search & Destroy\Updates|*.zip +FileKey3=%ProgramFiles%\Spybot - Search & Destroy 2\Updates|*.*|RECURSE +FileKey4=%ProgramFiles%\Spybot - Search & Destroy\Updates|*.zip +ExcludeKey1=FILE|%ProgramFiles%\Spybot - Search & Destroy 2\Updates\Downloads\|updates.uid + +[SpyDefense *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Everest Labs\Spydefense\sdc.exe +Default=False +FileKey1=%AppData%\Everest Labs\Spydefense|SpyDefense.log;History.ini;Backups.ini +FileKey2=%AppData%\Everest Labs\Spydefense\Backups|BF7.tmp + +[Spyware Doctor *] +LangSecRef=3024 +Detect=HKCU\Software\PCTools\Spyware Doctor +Default=False +FileKey1=%AppData%\pctsGui|bugreport.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Spyware Doctor\Log|*.* +FileKey3=%ProgramFiles%\Spyware Doctor\Log|*.* + +[Spyware Terminator *] +LangSecRef=3024 +Detect=HKCU\Software\Spyware Terminator +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Spyware Terminator|*.err;*.old|RECURSE +FileKey2=%ProgramFiles%\Spyware Terminator|*.err;*.old|RECURSE + +[SpywareBlaster Update File *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\SpywareBlaster\sbautoupdate.exe +Default=False +Warning=This deletes SWB program updater file, which is no longer needed once a SWB program version update occurs. +FileKey1=%ProgramFiles%\SpywareBlaster|spywareblasterupgrade_latest.exe + +[SQL Anywhere 11 *] +LangSecRef=3021 +DetectFile=%CommonAppData%\SQL Anywhere 11 +Default=False +FileKey1=%CommonAppData%\SQL Anywhere 11\Diagnostics|*.dmp;*.crash_log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\SQL Anywhere 11\Diagnostics|*.dmp;*.crash_log + +[SQLite Expert 3 *] +LangSecRef=3024 +Detect1=HKCU\Software\SQLite Expert\Personal\3.x +Detect2=HKCU\Software\SQLite Expert\Professional\3.x +Default=False +RegKey1=HKCU\Software\SQLite Expert\Personal\3.x\DB +RegKey2=HKCU\Software\SQLite Expert\Professional\3.x\DB + +[SQLite Query *] +LangSecRef=3024 +DetectFile=%AppData%\MiTeC\SQLite Query +Default=False +FileKey1=%AppData%\MiTeC\SQLite Query|*.*|REMOVESELF + +[SSD Fresh *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Abelssoft\SSD Fresh +Default=False +FileKey1=%LocalAppData%\Abelssoft\SSD Fresh|backup.* + +[Star Downloader *] +LangSecRef=3021 +Detect=HKCU\Software\Star Downloader +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Star Downloader|serverstats.txt;LastURLs +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Star Downloader\Partial Downloads|*.*|RECURSE +FileKey3=%ProgramFiles%\Star Downloader|serverstats.txt;LastURLs +FileKey4=%ProgramFiles%\Star Downloader\Partial Downloads|*.*|RECURSE + +[Star Swarm Stress Test *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\267130 +Default=False +FileKey1=%Documents%\Star Swarm|output*.txt + +[Star Trek Online *] +Section=Games +Detect1=HKCU\Software\Cryptic\Star Trek Online +Detect2=HKCU\Software\Valve\Steam\Apps\9900 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\Common\star trek online\Star Trek Online\*\cache|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\steam\steamapps\common\star trek online\star trek online\*\logs\GameClient|*.* +FileKey3=%ProgramFiles%\Steam\Steamapps\Common\star trek online\Star Trek Online\*\cache|*.* +FileKey4=%ProgramFiles%\steam\steamapps\common\star trek online\star trek online\*\logs\GameClient|*.* +FileKey5=%Public%\Games\Cryptic Studios\Star Trek Online\*\Cache|*.* +FileKey6=%Public%\Games\Cryptic Studios\Star Trek Online\*\Logs\GameClient|*.* + +[Star Wars Battlefront II *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\6060 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Star Wars BattleFront II|update*.txt +FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Star Wars BattleFront II|update*.txt + +[Star Wars The Force Unleashed *] +Section=Games +DetectFile=%LocalAppData%\LucasArts\Star Wars The Force Unleashed* +Default=False +FileKey1=%LocalAppData%\LucasArts\Star Wars The Force Unleashed*|*.* + +[Star Wars: The Old Republic *] +Section=Games +Detect=HKLM\Software\BioWare\Star Wars-The Old Republic +Default=False +FileKey1=%Documents%|*Install STAR WARS The Old Republic.log +FileKey2=%LocalAppData%\SWTOR\CrashDump\swtor|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Electronic Arts\BioWare\Star Wars-The Old Republic\betatest\retailclient\Temp|*.log +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Electronic Arts\BioWare\Star Wars-The Old Republic\logs|*.log +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Electronic Arts\BioWare\Star Wars-The Old Republic\swtor\retailclient\swtor\logs|*.log +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Star Wars - The Old Republic\__Installer|InstallLog.txt +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Star Wars - The Old Republic\logs|*.* +FileKey8=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Star Wars - The Old Republic\swtor\retailclient\swtor\logs|*.* +FileKey9=%ProgramFiles%\Electronic Arts\BioWare\Star Wars-The Old Republic\betatest\retailclient\Temp|*.log +FileKey10=%ProgramFiles%\Electronic Arts\BioWare\Star Wars-The Old Republic\logs|*.log +FileKey11=%ProgramFiles%\Electronic Arts\BioWare\Star Wars-The Old Republic\swtor\retailclient\swtor\logs|*.log +FileKey12=%ProgramFiles%\Origin Games\Star Wars - The Old Republic\__Installer|InstallLog.txt +FileKey13=%ProgramFiles%\Origin Games\Star Wars - The Old Republic\logs|*.* +FileKey14=%ProgramFiles%\Origin Games\Star Wars - The Old Republic\swtor\retailclient\swtor\logs|*.* + +[StarCraft II *] +Section=Games +Detect=HKLM\Software\Blizzard Entertainment\StarCraft II +Default=False +FileKey1=%CommonAppData%\Blizzard Entertainment\Starcraft II\Maps\Cache|*.*|RECURSE +FileKey2=%Documents%\StarCraft II\*Logs|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Starcraft II\Logs|*.* +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Blizzard Entertainment\Starcraft II\Maps\Cache|*.*|RECURSE +FileKey5=%ProgramFiles%\Starcraft II\Logs|*.* + +[StarCraft II Editor *] +Section=Games +Detect=HKLM\Software\Blizzard Entertainment\StarCraft II Editor +Default=False +RegKey1=HKCU\Software\Blizzard Entertainment\StarCraft II Editor\Recent Files + +[Stardock Fences *] +LangSecRef=3024 +Detect1=HKLM\Software\Stardock\Misc\Fences +Detect2=HKLM\Software\Stardock\Misc\Fences2 +Default=False +FileKey1=%AppData%\Stardock\Fences\TroubleshootingLog|*.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Stardock\Fences|*.txt +FileKey3=%ProgramFiles%\Stardock\Fences|*.txt + +[Stardock ObjectDock Plus *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Stardock\ObjectDock Plus\ObjectDock.exe +Default=False +FileKey1=%AppData%\Stardock|*.*|REMOVESELF +FileKey2=%CommonAppData%\Stardock|*.*|RECURSE +FileKey3=%LocalAppData%\ODUI|*.*|REMOVESELF +FileKey4=%LocalAppData%\Stardock\ObjectDockPlus|*Backup.ini +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Stardock|*.*|RECURSE + +[StarMoney *] +LangSecRef=3021 +DetectFile=%CommonAppData%\StarMoney* +Default=False +FileKey1=%CommonAppData%\StarMoney *|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\StarMoney *|*.log|RECURSE + +[StarOffice *] +LangSecRef=3021 +DetectFile1=%ProgramFiles%\Sun\StarOffice 8\program\soffice.exe +DetectFile2=%ProgramFiles%\Sun\StarOffice 9\program\soffice.exe +Default=False +FileKey1=%AppData%\StarOffice*\user\registry\data\org\openoffice\Office|Common.xcu + +[Start Menu Cache *] +DetectOS=6.2| +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\UFH +Default=False +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\UFH\SHC +RegKey2=HKLM\Software\Microsoft\Windows\CurrentVersion\UFH\ARP + +[Start Menu Reviver *] +LangSecRef=3024 +Detect=HKLM\Software\Start Menu Reviver +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\ReviverSoft\Start Menu Reviver\Logs|*.* +FileKey2=%ProgramFiles%\ReviverSoft\Start Menu Reviver\Logs|*.* + +[StartMenu8 *] +LangSecRef=3024 +Detect=HKLM\Software\IObit\StartMenu +Default=False +FileKey1=%AppData%\IObit\StartMenu 8|*.log + +[Startup Sentinel *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\Startup Sentinel +Default=False +FileKey1=%AppData%\KC Softwares\Startup Sentinel|*.log + +[StartupStar *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Abelssoft\StartupStar +Default=False +FileKey1=%AppData%\AbelsSoft\StartupStar|*.log + +[StartupStar Backups *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Abelssoft\StartupStar +Default=False +FileKey1=%LocalAppData%\Abelssoft\StartupStar|backup.xml + +[Steam *] +Section=Games +Detect=HKCU\Software\Valve\Steam +Default=False +FileKey1=%AppData%\SteamVR\Logs|*.*|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam|*.log;*log.last;connection_log_*.txt;*_log.txt;remote_connections.txt;vr*_*.txt|RECURSE +FileKey3=%ProgramFiles%\Steam|*.log;*log.last;connection_log_*.txt;*_log.txt;remote_connections.txt;vr*_*.txt|RECURSE +FileKey4=%ProgramFiles%\Steam|*.old +FileKey5=%ProgramFiles%\Steam\vr\runtime\logs|*.*|RECURSE + +[Steam Caches *] +Section=Games +Detect=HKCU\Software\Valve\Steam +Default=False +FileKey1=%LocalAppData%\Steam\htmlcache|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\appcache\httpcache|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\config\cookies|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Steam\config\htmlcache|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Steam\config\overlay*|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Steam\depotcache|*.* +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\shadercache|*.*|RECURSE +FileKey8=%LocalAppData%\VirtualStore\Program Files*\Steam\tenfoot\config\httpcache|*.*|RECURSE +FileKey9=%LocalAppData%\VirtualStore\Program Files*\Steam\tenfoot\config\images\web|*.*|RECURSE +FileKey10=%ProgramFiles%\Steam\appcache\httpcache|*.*|RECURSE +FileKey11=%ProgramFiles%\Steam\config\cookies|*.*|RECURSE +FileKey12=%ProgramFiles%\Steam\config\htmlcache|*.*|RECURSE +FileKey13=%ProgramFiles%\Steam\config\overlay*|*.*|RECURSE +FileKey14=%ProgramFiles%\Steam\depotcache|*.* +FileKey15=%ProgramFiles%\Steam\steamapps\shadercache|*.*|RECURSE +FileKey16=%ProgramFiles%\Steam\tenfoot\config\httpcache|*.*|RECURSE +FileKey17=%ProgramFiles%\Steam\tenfoot\config\images\web|*.*|RECURSE +FileKey18=%ProgramFiles%\Steam\userdata\*\ugcmsgcache|*.*|RECURSE + +[Steam Games *] +Section=Games +Detect=HKCU\Software\Valve\Steam +Default=False +FileKey1=%ProgramFiles%\Steam\steamapps|*.mdmp;*.tmp;*.dmp;*.icns;.DS_Store;logfile.*;*.log;text.txt;*log.txt;log*.txt|RECURSE +FileKey2=%ProgramFiles%\Steam\steamapps\common\*\*\downloads|*.*|RECURSE +FileKey3=%ProgramFiles%\Steam\steamapps\common\*\Cache|*.*|RECURSE +FileKey4=%ProgramFiles%\Steam\steamapps\common\*\config\html|*.*|RECURSE +FileKey5=%ProgramFiles%\Steam\steamapps\common\*\DebugData|*.*|RECURSE +FileKey6=%ProgramFiles%\Steam\Steamapps\temp|*.*|RECURSE +ExcludeKey1=PATH|%ProgramFiles%\Steam\steamapps\common\Supreme Ruler 1936\Cache\|*.* +ExcludeKey2=PATH|%ProgramFiles%\Steam\steamapps\common\Supreme Ruler Cold War\Cache\|*.* +ExcludeKey3=PATH|%ProgramFiles%\Steam\steamapps\common\Supreme Ruler Ultimate\Cache\|*.* + +[Steam Installers *] +Section=Games +Detect=HKCU\Software\Valve\Steam +Default=False +Warning=This entry should only be enabled after you have launched each of your installed Steam games at least once. Deleting these files before then may cause Steam to think the game's installation is broken. After the first launch, these files become useless. +FileKey1=%ProgramFiles%\Steam\Steamapps\common|*redist.msi*;dosbox*.tar.gz;*redist*.exe;*setup*.msi;*pbsvc*.exe;*UPlay*Installer*.exe;WMFADist.exe;SPInstaller.exe;python*.msi;bitmap2substance_installer.exe;perforce*.exe;p4vinst*.exe;mcpp*.*;firewallinstallhelper.dll;gameuxinstallhelper.dll;eadm-installer.exe;wmpappcompat.exe;umdf.exe;Microsoft .NET Framework*.cmd;Microsoft .NET Framework*.bat;NDP*.exe;WMFDist*.exe;PhysX*.msi;PhysX*.exe;*d3dx11*.cat;*d3dx11*.inf;prompt.bat;GDFInstall.exe;DSInstaller.exe;d3d*.exe;directx*.exe;*.msu;Windows*-KB*.exe;cmp.bat;PVRTexTool.exe;wmp11-windowsxp-x86-enu.exe;*.vdk;RGB9RAST*.msi;WIC*.exe;XPSEPC*.exe;msxml6.msi;AdbeRdr*.*;*inst*.vdf;*.cab;*.msp;ac3filter*.exe;GamesExplorerIntegrationTool.exe;install.ini;globdata.ini;install.exe;install.res.*.dll;eula.*.*;DSETUP.DLL;oalinst.exe;dsetup32.dll;D3D*Install.exe;D3D*Install*.dll;dotnetfx*.exe;*vc*red*.exe;*vc*red.msi;WindowsInstaller*.exe;locdata.*.ini;setupres.*.dll;*setup*.exe;wapres.*.dll;*NetFx*.*|RECURSE + +[Steam Packages *] +Section=Games +Detect=HKCU\Software\Valve\Steam +Default=False +Warning=Running this entry is not recommended if you run Steam Client Beta. +FileKey1=%ProgramFiles%\Steam\package|*.zip.* + +[SteamWorld Dig *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\252410 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\SteamWorld Dig|*.mdmp +FileKey2=%ProgramFiles%\Steam\Steamapps\common\SteamWorld Dig|*.mdmp + +[Steed *] +LangSecRef=3022 +DetectFile=%CommonAppData%\Steed +Default=False +FileKey1=%CommonAppData%\Steed\Logs|*.*|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Steed\Logs|*.*|REMOVESELF + +[Stellarium *] +LangSecRef=3021 +DetectFile=%AppData%\Stellarium +Default=False +FileKey1=%AppData%\Stellarium|log.txt +FileKey2=%LocalAppData%\Stellarium\Cache|*.*|RECURSE +FileKey3=%LocalAppData%\stellarium\stellarium\cache|*.*|RECURSE + +[StepMania *] +Section=Games +DetectFile=%AppData%\StepMania* +Default=False +FileKey1=%AppData%\Stepmania*\Logs|*.* + +[Stocks and Futures *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\24877CutthroatSoftware.StocksandFutures_xgnzh3xnefnqe +Default=False +FileKey1=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey3=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\AC\Temp|*.* +FileKey4=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\AppData\Indexed DB|*.log +FileKey5=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\LocalState|*.tmp|RECURSE +FileKey6=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\TempState|*.*|RECURSE + +[STOIK Smart Resizer *] +LangSecRef=3023 +Detect1=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer +Detect2=HKCU\Software\STOIK Smart Resizer 2.0\STOIK Smart Resizer +Detect3=HKCU\Software\STOIK Smart Resizer 3.0\STOIK Smart Resizer +Default=False +RegKey1=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer\Recent File List +RegKey2=HKCU\Software\STOIK Smart Resizer 2.0\STOIK Smart Resizer\Recent File List +RegKey3=HKCU\Software\STOIK Smart Resizer 3.0\STOIK Smart Resizer\Recent File List + +[STOIK Video Converter 2 *] +LangSecRef=3023 +Detect=HKCU\Software\STOIK +Default=False +FileKey1=%AppData%\STOIK\videopak2|*.ini + +[Store *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsStore_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.WindowsStore_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.WindowsStore_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.WindowsStore_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.WindowsStore_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.WindowsStore_*\LocalCache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.WindowsStore_*\LocalState\Cache|*.*|RECURSE + +[Stored Media Player Paths *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +RegKey1=HKCU\Software\Microsoft\Keyboard\Native Media Players + +[Stored MIME Types *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +RegKey1=HKCU\Software\Classes\MIME\Database\Content Type + +[Stored Qt Modules Paths *] +LangSecRef=3021 +Detect=HKCU\Software\Trolltech +Default=False +RegKey1=HKCU\Software\Trolltech\OrganizationDefaults + +[Stranglehold *] +Section=Games +DetectFile=%LocalAppData%\Midway\Stranglehold +Default=False +FileKey1=%LocalAppData%\Midway\Stranglehold|*.log|RECURSE +FileKey2=%LocalAppData%\Midway\Stranglehold\Cache|*.*|REMOVESELF + +[Stream-Cloner *] +LangSecRef=3023 +Detect=HKCU\Software\Stream-Cloner +Default=False +FileKey1=%AppData%\Stream-Cloner|*.log;IeRecentVisit.txt +FileKey2=%AppData%\Stream-Cloner\Cap_images|*.*|REMOVESELF +FileKey3=%AppData%\Stream-Cloner\thumbs|*.*|REMOVESELF + +[Streamripper Winamp *] +LangSecRef=3023 +Detect=HKCU\Software\Streamripper +Default=False +FileKey1=%AppData%\Streamripper|*.*|REMOVESELF + +[Stronghold Crusader *] +Section=Games +DetectFile=%ProgramFiles%\Firefly Studios\Stronghold Crusader +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Firefly Studios\Stronghold Crusader\gfx|*log.txt +FileKey2=%ProgramFiles%\Firefly Studios\Stronghold Crusader\gfx|*log.txt + +[Structured Storage Viewer *] +LangSecRef=3024 +Detect=HKCU\Software\MiTeC\SSViewer +Default=False +RegKey1=HKCU\Software\MiTeC\SSViewer\3.x\wnd_re_Main|MRUHistory + +[Style Jukebox *] +LangSecRef=3023 +DetectFile=%AppData%\Style Jukebox Settings +Default=False +FileKey1=%AppData%\Style Jukebox Settings|*.bmp|RECURSE + +[Sublime Text Backup *] +LangSecRef=3024 +DetectFile=%AppData%\Sublime Text* +Default=False +FileKey1=%AppData%\Sublime Text 3\Backup|*.*|REMOVESELF + +[Sublime Text Session *] +LangSecRef=3024 +DetectFile=%AppData%\Sublime Text* +Default=False +FileKey1=%AppData%\Sublime Text 2\Settings|*.sublime_session +FileKey2=%AppData%\Sublime Text 3\Local|Session.sublime_session +FileKey3=%AppData%\Sublime Text\Options|*.* + +[Success Story *] +Section=Games +DetectFile=%AppData%\Shape Games\SuccessStory +Default=False +FileKey1=%AppData%\Shape Games\SuccessStory\logs|*.* + +[SumatraPDF *] +LangSecRef=3024 +DetectFile=%AppData%\SumatraPDF +Default=False +FileKey1=%AppData%\SumatraPDF\sumatrapdfcache|*.* + +[SUMo *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\SUMo +Default=False +FileKey1=%AppData%\KC Softwares\SUMo|db.bak;SUMo.cache;*.log;errlst.txt + +[SUMo Database *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\SUMo +Default=False +FileKey1=%AppData%\KC Softwares\SUMo|db.sumo + +[SUPERAntiSpyware *] +LangSecRef=3024 +Detect1=HKCU\Software\SUPERAntiSpyware.com\SUPERAntiSpyware +Detect2=HKLM\Software\SUPERAntiSpyware.com\SUPERAntiSpyware +Default=False +FileKey1=%CommonAppData%\!SASCORE\AppLogs|*.dmp;*.SDB +FileKey2=%CommonAppData%\SUPERAntiSpyware.com\SUPERAntiSpyware\Applogs|*.dmp;*.SDB;*.ZIP +FileKey3=%LocalAppData%\VirtualStore\ProgramData\!SASCORE\AppLogs|*.dmp;*.SDB +FileKey4=%LocalAppData%\VirtualStore\ProgramData\SUPERAntiSpyware\Applogs|*.dmp;*.SDB;*.ZIP +FileKey5=%ProgramFiles%\SUPERAntiSpyware|*.tmp + +[SuperMP3Download *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\SuperMp3Download\SuperMp3Download.exe +Default=False +FileKey1=%CommonAppData%\SuperMP3Download|downloadlist.sav +FileKey2=%CommonAppData%\SuperMP3Download\Downloading|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\SuperMP3Download|downloadlist.sav +FileKey4=%LocalAppData%\VirtualStore\ProgramData\SuperMP3Download\Downloading|*.*|RECURSE + +[Superstar Racing *] +Section=Games +DetectFile=%LocalAppData%\Chat Republic Games\Superstar Racing +Default=False +FileKey1=%LocalAppData%\Chat Republic Games\Superstar Racing|log*.* + +[SuperSync *] +LangSecRef=3023 +DetectFile=%AppData%\SuperSync +Default=False +FileKey1=%AppData%\SuperSync\logs|*.* +FileKey2=%AppData%\SuperSync\tmp|*.*|RECURSE + +[SuperWinMenu *] +LangSecRef=3024 +DetectFile=%AppData%\SuperWinMenu +Default=False +FileKey1=%AppData%\SuperWinMenu|*.lastused + +[Sway *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.Sway_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalCache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalState\Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.Office.Sway_*\TempState|*.*|RECURSE + +[Swift *] +LangSecRef=3022 +Detect=HKCU\Software\Swift +Default=False +FileKey1=%AppData%\Swift\Avatars|*.*|RECURSE +FileKey2=%AppData%\Swift\Crashes|*.*|RECURSE + +[Syberfix Helpdesk *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Syberfix\UserSaved\Helpdesk* +Default=False +FileKey1=%LocalAppData%\SyberFix\UserSaved\Helpdesk *|*.log + +[Sylpheed *] +LangSecRef=3022 +DetectFile=%AppData%\Sylpheed +Default=False +FileKey1=%AppData%\Sylpheed|*.bak;*.bak.*;*.log + +[Symantec Ghost *] +LangSecRef=3024 +Detect=HKCU\Software\Symantec\Symantec Ghost +Default=False +RegKey1=HKCU\Software\Symantec\Symantec Ghost\Explorer\Ghost Explorer\Recent File List + +[Symantec SymSilent *] +LangSecRef=3024 +DetectFile=%Public%\Symantec\SymSilent +Default=False +FileKey1=%Public%\Symantec\SymSilent\ccLog|*.* + +[Synchronize It! *] +LangSecRef=3021 +Detect=HKCU\Software\grigsoft.com\Synchronize It! +Default=False +RegKey1=HKCU\Software\grigsoft.com\Synchronize It!\Combos +RegKey2=HKCU\Software\grigsoft.com\Synchronize It!\Synchronize It!\Combos + +[Syncios Cell Phone Backup & Manage *] +LangSecRef=3024 +Detect1=HKCU\Software\Syncios +Detect2=HKCU\Software\Syncios Data Transfer +Default=False +FileKey1=%AppData%\Syncios|android.log;log.txt +FileKey2=%AppData%\Syncios Data Transfer|*.log|RECURSE +FileKey3=%Documents%\Syncios Data Transfer|preference_conf.ini.old.bak + +[Syncovery *] +LangSecRef=3024 +Detect=HKCU\Software\Syncovery +Default=False +FileKey1=%CommonAppData%\Syncovery\Logs|*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Syncovery\Logs|*.log|RECURSE + +[Syncthing *] +LangSecRef=3022 +DetectFile=%LocalAppData%\Syncthing +Default=False +FileKey1=%LocalAppData%\Syncthing|*.log;*.xml.v* +FileKey2=%ProgramFiles%\Syncthing|*.old + +[Synthesia *] +Section=Games +Detect=HKCU\Software\Classes\synthesia +Default=False +FileKey1=%AppData%\Synthesia|log.txt;log-configuration.txt + +[System Explorer *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\System Explorer\SystemExplorer.exe +Default=False +FileKey1=%CommonAppData%\SystemExplorer\snapshots|*.ses + +[System Mechanic *] +LangSecRef=3024 +Detect=HKCU\Software\iolo\System Mechanic +Default=False +FileKey1=%AppData%\iolo\SafetyNet\Temp|*.* +FileKey2=%AppData%\ioloGovernor\logs|*.*|REMOVESELF +FileKey3=%CommonAppData%\iolo|*.xml;*.txt +FileKey4=%CommonAppData%\iolo\ACRSummaryFiles|*.*|REMOVESELF +FileKey5=%CommonAppData%\iolo\logs|*.*|REMOVESELF +FileKey6=%CommonAppData%\iolo\TempResources|*.*|REMOVESELF +FileKey7=%LocalAppData%\VirtualStore\Program Files*\iolo\System Mechanic|*.txt;*.xml +FileKey8=%LocalAppData%\VirtualStore\ProgramData\iolo|*.xml;*.txt +FileKey9=%LocalAppData%\VirtualStore\ProgramData\iolo\ACRSummaryFiles|*.*|REMOVESELF +FileKey10=%LocalAppData%\VirtualStore\ProgramData\iolo\logs|*.*|REMOVESELF +FileKey11=%LocalAppData%\VirtualStore\ProgramData\iolo\TempResources|*.*|REMOVESELF +FileKey12=%ProgramFiles%\iolo\System Mechanic|*.txt;*.xml +FileKey13=%SystemDrive%\Documents and Settings\LocalService\*\iolo|*.*|REMOVESELF +FileKey14=%WinDir%\System32\config|iolo App.evt + +[System Mechanic Snapshots *] +LangSecRef=3024 +Detect=HKCU\Software\iolo\System Mechanic +Default=False +Warning=This will delete System Mechanic System Snapshots Data. +FileKey1=%AppData%\iolo\System Snapshots Data|*.* + +[SysTracer *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SysTracer +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\SysTracer|SysTracerLog.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\SysTracer\tmp|*.*|REMOVESELF +FileKey3=%ProgramFiles%\SysTracer|SysTracerLog.txt +FileKey4=%ProgramFiles%\SysTracer\tmp|*.*|REMOVESELF + +[Tag&Rename *] +LangSecRef=3024 +Detect1=HKCU\Software\Softpointer\Tag&Rename +Detect2=HKCU\Software\Softpointer\Tag&Rename2 +Detect3=HKCU\Software\Softpointer\Tag&Rename3 +Default=False +RegKey1=HKCU\Software\Softpointer\Tag&Rename\Config|FCurrentFolder +RegKey2=HKCU\Software\Softpointer\Tag&Rename\Config|FHistoryList +RegKey3=HKCU\Software\Softpointer\Tag&Rename2\Config|FCurrentFolder +RegKey4=HKCU\Software\Softpointer\Tag&Rename2\Config|FHistoryList +RegKey5=HKCU\Software\Softpointer\Tag&Rename3\Config|FCurrentFolder +RegKey6=HKCU\Software\Softpointer\Tag&Rename3\Config|FHistoryList +RegKey7=HKCU\Software\Softpointer\Tag&Rename3\Config|FileListHeader + +[TAudio Converter *] +LangSecRef=3023 +DetectFile=%AppData%\TAC +Default=False +FileKey1=%AppData%\TAC|log_main.txt + +[Team Crossword *] +Section=Games +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.TeamCrossword_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.TeamCrossword_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey4=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\PRICache|*.* +FileKey5=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\Temp|*.* +FileKey6=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\TempState|*.*|RECURSE + +[Team Fortress 2 *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\440 +Default=False +FileKey1=%ProgramFiles%\Steam\SteamApps\common\Team Fortress 2\config\cookies|*.*|RECURSE +FileKey2=%ProgramFiles%\Steam\SteamApps\common\Team Fortress 2\config\html\AppCache|*.*|RECURSE +FileKey3=%ProgramFiles%\Steam\SteamApps\common\Team Fortress 2\tf\cache|*.*|RECURSE +FileKey4=%ProgramFiles%\Steam\SteamApps\common\Team Fortress 2\tf\download\user_custom|*.*|RECURSE +FileKey5=%ProgramFiles%\Steam\SteamApps\common\Team Fortress 2\tf\materials\temp|*.vtf|RECURSE + +[TeamSpeak 3 *] +LangSecRef=3022 +Detect=HKCU\Software\TeamSpeak 3 Client +Default=False +FileKey1=%LocalAppData%\TeamSpeak 3 Client\config\logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\TeamSpeak 3 Client\config\logs|*.* +FileKey3=%ProgramFiles%\TeamSpeak 3 Client\config\logs|*.* + +[TeamSpeak 3 Chats *] +LangSecRef=3022 +Detect=HKCU\Software\TeamSpeak 3 Client +Default=False +FileKey1=%AppData%\TS3Client\chats|*.*|REMOVESELF + +[TeamViewer *] +LangSecRef=3024 +Detect=HKCU\Software\TeamViewer +Default=False +FileKey1=%AppData%\TeamViewer|*.log;*.mdmp +FileKey2=%LocalAppData%\TeamViewer\*Cache|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\TeamViewer|*.log +FileKey4=%ProgramFiles%\TeamViewer|*.log +FileKey5=%WinDir%\System32|TeamViewer*_Hooks.log +RegKey1=HKCU\Software\TeamViewer\Version5|Last_Machine_Connections +RegKey2=HKCU\Software\TeamViewer\Version5.1|Last_Machine_Connections +RegKey3=HKCU\Software\TeamViewer\Version6|Last_Machine_Connections +RegKey4=HKCU\Software\TeamViewer\Version7|Last_Machine_Connections + +[Technic Launcher *] +Section=Games +DetectFile=%AppData%\.technic* +Default=False +FileKey1=%AppData%\.technic*|*.old;*.log;*.tmp|RECURSE +FileKey2=%AppData%\.technic*\*\logs|*.*|RECURSE +FileKey3=%AppData%\.technic*\cache|*.* +FileKey4=%AppData%\.technic*\temp|*.*|RECURSE + +[Technic Launcher Backups *] +Section=Games +DetectFile=%AppData%\.technic* +Default=False +FileKey1=%AppData%\.technic*\*\Backups|*.*|RECURSE + +[Technic Launcher Screenshots *] +Section=Games +DetectFile=%AppData%\.technic* +Default=False +FileKey1=%AppData%\.technic*\*\Screenshots|*.* + +[TechSmith DubIt *] +LangSecRef=3023 +Detect=HKCU\Software\TechSmith\DubIt +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\TechSmith\DubIt|*.gid +FileKey2=%ProgramFiles%\TechSmith\DubIt|*.gid +RegKey1=HKCU\Software\TechSmith\DubIt\Recent Audio Files +RegKey2=HKCU\Software\TechSmith\DubIt\Recent Video Files + +[TEdit *] +Section=Games +DetectFile=%AppData%\TEdit +Default=False +FileKey1=%AppData%\TEdit\undo|*.*|RECURSE + +[Teeworlds *] +Section=Games +DetectFile=%AppData%\Teeworlds +Default=False +FileKey1=%AppData%\Teeworlds\dumps|*.*|REMOVESELF +FileKey2=%AppData%\Teeworlds\tmp|*.*|REMOVESELF + +[Teeworlds Captures *] +Section=Games +DetectFile=%AppData%\Teeworlds +Default=False +FileKey1=%AppData%\Teeworlds\demos|*.*|REMOVESELF +FileKey2=%AppData%\Teeworlds\Screenshots|*.*|REMOVESELF + +[Teeworlds Downloads / Maps *] +Section=Games +DetectFile=%AppData%\Teeworlds +Default=False +FileKey1=%AppData%\Teeworlds\downloaded*|*.*|REMOVESELF +FileKey2=%AppData%\Teeworlds\maps|*.*|REMOVESELF + +[Tele2 Mobile Partner *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Tele2 Mobile Partner\Tele2 Mobile Partner.exe +Default=False +FileKey1=%CommonAppData%\Tele2 Mobile Partner\log|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Tele2 Mobile Partner\Log|*.txt +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Tele2 Mobile Partner\log|*.* +FileKey4=%ProgramFiles%\Tele2 Mobile Partner\Log|*.txt + +[TEMP Folder *] +LangSecRef=3025 +DetectFile=%CommonAppData%\TEMP +Default=False +FileKey1=%CommonAppData%\TEMP|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\TEMP|*.*|RECURSE + +[TeraCopy *] +LangSecRef=3024 +Detect=HKCU\Software\Code Sector\TeraCopy +Default=False +FileKey1=%AppData%\TeraCopy|FileList.dat;Transfer.log +FileKey2=%AppData%\TeraCopy\History|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\TeraCopy|FileList.dat;Transfer.log +FileKey4=%ProgramFiles%\TeraCopy|FileList.dat;Transfer.log +RegKey1=HKCU\Software\Code Sector\TeraCopy|LastTargetFolder + +[Terraria *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\105600 +Default=False +FileKey1=%Documents%\My Games\Terraria|*.bak;*.wld.bak|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\terraria|client-crashlog.txt +FileKey3=%ProgramFiles%\Steam\steamapps\common\terraria|client-crashlog.txt + +[Tesla Legacy *] +Section=Games +DetectFile=%LocalAppData%\Astar Games\Tesla Legacy +Default=False +FileKey1=%LocalAppData%\Astar Games\Tesla Legacy|*.log + +[TeXnicCenter *] +LangSecRef=3021 +Detect1=HKCU\Software\ToolsCenter\TeXnicCenter +Detect2=HKCU\Software\ToolsCenter\TeXnicCenterNT +Default=False +RegKey1=HKCU\Software\ToolsCenter\TeXnicCenter\Recent File List +RegKey2=HKCU\Software\ToolsCenter\TeXnicCenter\Recent Project List +RegKey3=HKCU\Software\ToolsCenter\TeXnicCenter\Session +RegKey4=HKCU\Software\ToolsCenter\TeXnicCenter\Settings\Options|LastOpenedFolder +RegKey5=HKCU\Software\ToolsCenter\TeXnicCenterNT\Recent File List +RegKey6=HKCU\Software\ToolsCenter\TeXnicCenterNT\Recent Project List +RegKey7=HKCU\Software\ToolsCenter\TeXnicCenterNT\Session +RegKey8=HKCU\Software\ToolsCenter\TeXnicCenterNT\Settings\Options|LastOpenedFolder + +[TGCM *] +LangSecRef=3023 +DetectFile=%AppData%\TGCMLog +Default=False +FileKey1=%AppData%\TGCMLog|*log.txt + +[The Bat *] +LangSecRef=3022 +Detect=HKCU\Software\RIT\The Bat! +Default=False +FileKey1=%AppData%\The Bat!\cache|*.* + +[The Cleaner *] +LangSecRef=3024 +Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cleaner8.exe +Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cleaner9.exe +Default=False +FileKey1=%AppData%\thecleaner|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\The Cleaner|*.log;*.tmp;*.bak|RECURSE +FileKey3=%ProgramFiles%\The Cleaner|*.log;*.tmp;*.bak|RECURSE + +[The Clumsys 2: The Butterfly Effect *] +Section=Games +DetectFile=%LocalAppData%\BanzaiInteractive\Clumsys2 +Default=False +FileKey1=%AppData%\BanzaiInteractive\Clumsys2|logfile.txt + +[The Dream Machine *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\94300 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\The Dream Machine\the_dream_machine.app|*.*|REMOVESELF +FileKey2=%ProgramFiles%\Steam\steamapps\common\The Dream Machine\the_dream_machine.app|*.*|REMOVESELF + +[The Mighty Quest for Epic Loot *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\239220 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\The Mighty Quest For Epic Loot\CrashReport|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\The Mighty Quest For Epic Loot\Log|*.* +FileKey3=%ProgramFiles%\Steam\SteamApps\Common\The Mighty Quest For Epic Loot\CrashReport|*.* +FileKey4=%ProgramFiles%\Steam\SteamApps\Common\The Mighty Quest For Epic Loot\Log|*.* + +[The Mystery of the Mary Celeste *] +Section=Games +DetectFile=%AppData%\Merscom\The Mystery of the Mary Celeste +Default=False +FileKey1=%AppData%\Merscom\The Mystery of the Mary Celeste|logfile.txt + +[The Quran *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\57100Goheer.TheQuran_s6gg0ptmhrgye +DetectFile=%LocalAppData%\Packages\57100Goheer.TheQuran_s6gg0ptmhrgye +Default=False +FileKey1=%LocalAppData%\Packages\*TheQuran_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\*TheQuran_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\*TheQuran_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE +FileKey4=%LocalAppData%\Packages\*TheQuran_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\*TheQuran_*\AC\PRICache|*.* +FileKey6=%LocalAppData%\Packages\*TheQuran_*\AC\Temp|*.* +FileKey7=%LocalAppData%\Packages\*TheQuran_*\LocalState|*.*|RECURSE + +[The Rise of Atlantis *] +Section=Games +DetectFile=%CommonAppData%\TERMINAL Studio\The Rise of Atlantis +Default=False +FileKey1=%CommonAppData%\Terminal Studio\The Rise of Atlantis|log.html +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Terminal Studio\The Rise of Atlantis|log.html + +[The Sims 3 *] +Section=Games +Detect=HKCU\Software\Electronic Arts\Sims 3 +Default=False +FileKey1=%Documents%\Electronic Arts\The Sims 3|*.log;*.mdmp;xcpt*.txt|RECURSE + +[The Sims 3 Cache Files *] +Section=Games +Detect=HKCU\Software\Electronic Arts\Sims 3 +Default=False +FileKey1=%Documents%\Electronic Arts\The Sims 3|socialCache.package;CASPartCache.package;scriptCache.package;compositorCache.package;simCompositorCache.package +FileKey2=%Documents%\Electronic Arts\The Sims 3\Thumbnails|*.* +FileKey3=%Documents%\Electronic Arts\The Sims 3\WorldCaches|*.* + +[The Sims 3 DCBackup Files *] +Section=Games +Detect=HKCU\Software\Electronic Arts\Sims 3 +Default=False +Warning=This may make premium content buggy if deleted. +FileKey1=%Documents%\Electronic arts\The sims 3\DCBackup|*.package +ExcludeKey1=FILE|%Documents%\electronic arts\The sims 3\DCBackup\|ccmerged.package + +[The Sims 4 *] +Section=Games +DetectFile=%Documents%\Electronic Arts\The Sims 4 +Default=False +FileKey1=%Documents%\Electronic Arts\The Sims 4|*.txt;*.log + +[The Sims Medieval *] +Section=Games +Detect=HKLM\Software\Electronic Arts\The Sims Medieval +Default=False +FileKey1=%Documents%\Electronic Arts\The Sims Medieval|*.log;*.xml|RECURSE + +[The Sims Resource Merlin *] +Section=Games +DetectFile=%ProgramFiles%\The Sims Resource\TSR Merlin +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\The Sims Resource\TSR Merlin\Logs|*.* +FileKey2=%ProgramFiles%\The Sims Resource\TSR Merlin\Logs|*.* + +[The Talos Principle *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\257510 +Default=False +FileKey1=%ProgramFiles%\Steam\steamapps\common\The Talos Principle\Log|*.*|RECURSE + +[The Tiny Bang Story *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\96000 +Default=False +FileKey1=%AppData%\Colibri Games\The Tiny Bang Story|logfile.txt + +[The Weather Channel *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\TheWeatherChannel_t3yemqpq4kp7p +DetectFile=%LocalAppData%\Packages\Weather.TheWeatherChannel_t3yemqpq4kp7p +Default=False +FileKey1=%LocalAppData%\Packages\Weather.TheWeatherChannel_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Weather.TheWeatherChannel_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.log|RECURSE +FileKey3=%LocalAppData%\Packages\Weather.TheWeatherChannel_*\AC\Temp|*.* +FileKey4=%LocalAppData%\Packages\Weather.TheWeatherChannel_*\LocalState|*.tmp +FileKey5=%LocalAppData%\Packages\Weather.TheWeatherChannel_*\TempState\Bing.Maps\Cache|*.*|RECURSE + +[The Witcher *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\20900 +Detect2=HKCU\Software\Valve\Steam\Apps\20920 +Default=False +FileKey1=%LocalAppData%\The Witcher 2\temp|*.* +FileKey2=%LocalAppData%\The Witcher\logs|*.* + +[The Women's Murder Club 3: Twice in a Blue Moon *] +Section=Games +DetectFile=%AppData%\Flood Light Games\WMC3 +Default=False +FileKey1=%AppData%\Flood Light Games\WMC3|*.log + +[Thinstall Database *] +LangSecRef=3021 +DetectFile1=%AppData%\Thinstall +DetectFile2=%LocalAppData%\Thinstall +Default=False +Warning=This will remove your Portable's settings. If settings are stored in the program's folder, this is fine. +FileKey1=%AppData%\Thinstall|*.*|REMOVESELF +FileKey2=%LocalAppData%\Thinstall|*.*|REMOVESELF + +[Thomas Was Alone *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\220780 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\thomaswasalone\ThomasWasAlone_Data|output_log.txt +FileKey2=%ProgramFiles%\Steam\Steamapps\common\thomaswasalone\ThomasWasAlone_Data|output_log.txt + +[ThumbsPlus *] +LangSecRef=3023 +Detect=HKCU\Software\Cerious Software Inc. +Default=False +FileKey1=%AppData%\Thumbsplus|*.log;*.bak;*.dmp;*.7z;*.exc;*.png +FileKey2=%ProgramFiles%\Thumbsplus *\Bin|*.log + +[Tific Client *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Tific +Default=False +FileKey1=%LocalAppData%\Tific|*.log|RECURSE + +[TightVNC *] +LangSecRef=3022 +DetectFile=%AppData%\TightVNC +Default=False +FileKey1=%AppData%\TightVNC|*.log + +[TikiOne Steam Cleaner *] +LangSecRef=3024 +DetectFile=%UserProfile%\.tikione +Default=False +FileKey1=%UserProfile%\.tikione\log|*.* + +[Time Adjuster *] +LangSecRef=3021 +Detect=HKCU\Software\IrekZielinskiSoft\TimeAdjuster +Default=False +RegKey1=HKCU\Software\IrekZielinskiSoft\TimeAdjuster|LDIR2 +RegKey2=HKCU\Software\IrekZielinskiSoft\TimeAdjuster|LDIR3 +RegKey3=HKCU\Software\IrekZielinskiSoft\TimeAdjuster|LDIR4 + +[TimeRabbit *] +LangSecRef=3022 +DetectFile=%AppData%\TimeRabbit +Default=False +FileKey1=%AppData%\TimeRabbit\Cache|*.*|RECURSE + +[Timeslips *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Timeslips +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\TimeSlips\Data01\logs|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Timeslips\logs|*.* +FileKey3=%ProgramFiles%\TimeSlips\Data01\logs|*.* +FileKey4=%ProgramFiles%\Timeslips\logs|*.* + +[Tinder++ *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Tinder* +Default=False +FileKey1=%LocalAppData%\Tinder*|*.*|RECURSE + +[Tinseltown Dreams *] +Section=Games +DetectFile=%LocalAppData%\Namco Networks\Tinseltown Dreams +Default=False +FileKey1=%LocalAppData%\Namco Networks\Tinseltown Dreams|errors*.*;log.txt + +[Tipard Converter *] +LangSecRef=3023 +Detect1=HKCU\Software\Tipard Studio\Tipard Total Media Converter +Detect2=HKCU\Software\Tipard Studio\Tipard Total Media Converter Platinum +Detect3=HKCU\Software\Tipard Studio\Tipard Video Converter Ultimate +Default=False +FileKey1=%LocalAppData%\Tipard Studio\Tipard *|*.txt +RegKey1=HKCU\Software\Tipard Studio\Tipard Total Media Converter Platinum\Edit|LastVideoFilePath +RegKey2=HKCU\Software\Tipard Studio\Tipard Total Media Converter\Edit|LastVideoFilePath +RegKey3=HKCU\Software\Tipard Studio\Tipard Video Converter Ultimate\Edit|LastVideoFilePath + +[Tixati *] +LangSecRef=3021 +DetectFile=%AppData%\tixati +Default=False +FileKey1=%AppData%\tixati|upnp_diagnostic_log.txt + +[Tom Clancy's Ghost Recon *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\15300 +DetectFile=%ProgramFiles%\Red Storm Entertainment\Ghost Recon +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Red Storm Entertainment\Ghost Recon|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Ghost Recon|*.log +FileKey3=%ProgramFiles%\Red Storm Entertainment\Ghost Recon|*.log +FileKey4=%ProgramFiles%\Steam\SteamApps\Ghost Recon|*.log + +[Tom Clancy's Rainbow Six 3: Raven Shield *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\19830 +DetectFile=%ProgramFiles%\Red Storm Entertainment\RavenShield +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Red Storm Entertainment\RavenShield|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\RavenShield|*.log +FileKey3=%ProgramFiles%\Red Storm Entertainment\RavenShield|*.log +FileKey4=%ProgramFiles%\Steam\SteamApps\Common\RavenShield|*.log + +[Tom Clancy's Rainbow Six Vegas 2 *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\15120 +DetectFile=%ProgramFiles%\Ubisoft\Tom Clancy's Rainbow Six Vegas 2 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Tom Clancy's Rainbow Six Vegas 2|CrashReport*.*;*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Tom Clancy's Rainbow Six Vegas 2|CrashReport*.*;*.log|RECURSE +FileKey3=%ProgramFiles%\Steam\SteamApps\Common\Tom Clancy's Rainbow Six Vegas 2|CrashReport*.*;*.log|RECURSE +FileKey4=%ProgramFiles%\Ubisoft\Tom Clancy's Rainbow Six Vegas 2|CrashReport*.*;*.log|RECURSE + +[Tomahawk *] +LangSecRef=3023 +Detect=HKCU\Software\Tomahawk +Default=False +FileKey1=%LocalAppData%\Tomahawk|*.log +FileKey2=%LocalAppData%\Tomahawk\Tomahawk\Cache|*.*|RECURSE + +[Tomahawk PDF+ *] +LangSecRef=3021 +Detect=HKCU\Software\NativeWinds\Tomahawk +Default=False +RegKey1=HKCU\Software\NativeWinds\Tomahawk\MRU + +[Tomb Raider *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\203160 +Default=False +FileKey1=%Documents%|TombRaider.log + +[Tomboy *] +LangSecRef=3021 +DetectFile=%LocalAppData%\Tomboy +Default=False +FileKey1=%LocalAppData%\Tomboy|*.log +FileKey2=%LocalAppData%\Tomboy\Cache|*.*|RECURSE + +[TomTom *] +LangSecRef=3021 +Detect1=HKCU\Software\TomTom +Detect2=HKLM\Software\Classes\tomtomhome +Default=False +FileKey1=%AppData%\TomTom\HOME\Profiles\*|Log.txt +FileKey2=%LocalAppData%\TomTom\HOME3|Log.txt +FileKey3=%LocalAppData%\TomTom\HOME3\cache|*.*|RECURSE + +[ToniArts EasyCleaner Duplicates *] +LangSecRef=3024 +Detect=HKLM\Software\ToniArts\EasyCleaner +Default=False +FileKey1=%ProgramFiles%\ToniArts\EasyCleaner|Duplicat.* + +[ToonTown *] +Section=Games +DetectFile=%LocalLowAppData%\Panda3D +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Disney\Disney Online\ToontownOnline|*.log +FileKey2=%LocalLowAppData%\Panda3D\Log|*.* +FileKey3=%ProgramFiles%\Disney\Disney Online\ToontownOnline|*.log + +[ToonTown Rewritten *] +Section=Games +DetectFile=%ProgramFiles%\ToonTown Rewritten +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\ToonTown ReWritten\logs|*.* +FileKey2=%ProgramFiles%\ToonTown ReWritten\logs|*.* + +[TopStyle 5 *] +LangSecRef=3021 +Detect=HKCU\Software\Bradbury\TopStyle\5.0 +Default=False +RegKey1=HKCU\Software\Bradbury\TopStyle\5.0\RecentFiles + +[Torchlight *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\41500 +DetectFile=%AppData%\Runic Games\Torchlight +Default=False +FileKey1=%AppData%\Runic Games\Torchlight|*.log + +[Torchlight 2 *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\200710 +Detect2=HKLM\Software\Runic Games\Torchlight II +Default=False +FileKey1=%Documents%\My Games\runic games\torchlight 2|ogre.log +FileKey2=%Documents%\My Games\Runic Games\Torchlight 2\logs|*.* + +[Torrent Search Log *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Torrent Search +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Torrent Search|*.log +FileKey2=%ProgramFiles%\Torrent Search|*.log + +[TortoiseHg *] +LangSecRef=3021 +Detect=HKCU\Software\tortoisemerge +Default=False +FileKey1=%AppData%\TortoiseHg|*.log;*.old + +[TortoiseSVN *] +LangSecRef=3024 +Detect=HKCU\Software\TortoiseSVN +Default=False +FileKey1=%AppData%\TortoiseSVN|*.* +FileKey2=%LocalAppData%\TSVNCache|*.* + +[TortoiseSVN History *] +LangSecRef=3024 +Detect=HKCU\Software\TortoiseSVN +Default=False +Warning=This will remove your repo paths and last checkout location. +RegKey1=HKCU\Software\TortoiseSVN\History + +[Toshiba BluetoothStack *] +LangSecRef=3024 +Detect=HKLM\Software\Toshiba\BluetoothStack +Default=False +FileKey1=%LocalAppData%\Toshiba\BluetoothStack\V1.0\tosOBEX\Temp|*.* + +[Toshiba Book Place *] +LangSecRef=3021 +DetectFile=%AppData%\Book Place +Default=False +FileKey1=%AppData%\Book Place\Cache|*.*|RECURSE +FileKey2=%AppData%\Book Place\log|*.*|RECURSE + +[Toshiba FlashCards *] +LangSecRef=3021 +DetectFile=%LocalAppData%\TOSHIBA\FlashCards +Default=False +FileKey1=%LocalAppData%\TOSHIBa\FlashCards|log.txt + +[Total Recorder *] +LangSecRef=3023 +Detect=HKCU\Software\HighCriteria\TotalRecorder\Recent File List +Default=False +RegKey1=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File1 +RegKey2=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File2 +RegKey3=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File3 +RegKey4=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File4 +RegKey5=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File5 +RegKey6=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File6 +RegKey7=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File7 +RegKey8=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File8 +RegKey9=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File9 + +[Total Uninstall *] +LangSecRef=3024 +Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall 5_is1 +Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall 6_is1 +Default=False +FileKey1=%CommonAppData%\Martau\Total Uninstall*|*.Folders;*.cache|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Total Uninstall*|*.rtf;*.txt;*.GID|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Martau\Total Uninstall*|*.Folders;*.cache|RECURSE +FileKey4=%ProgramFiles%\Total Uninstall*|*.rtf;*.txt;*.GID|RECURSE + +[Total Uninstall Backups *] +LangSecRef=3024 +Detect1=HKCU\Software\MartS\Total Uninstall +Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall 5_is1 +Detect3=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall 6_is1 +Default=False +Warning=This will delete analyzed programs and backups. +FileKey1=%CommonAppData%\Martau\Total Uninstall*|*.tlg;*.zsns;*.zip|RECURSE +FileKey2=%CommonAppData%\Martau\Total Uninstall*\Analyzed Programs|*.* +FileKey3=%CommonAppData%\Martau\Total Uninstall*\Backup|*.zip +FileKey4=%CommonAppData%\Martau\Total Uninstall*\System Snapshots|*.zsns +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Martau\Total Uninstall*|*.tlg;*.zsns;*.zip|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Martau\Total Uninstall*\Analyzed Programs|*.* +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Martau\Total Uninstall*\Backup|*.zip +FileKey8=%LocalAppData%\VirtualStore\ProgramData\Martau\Total Uninstall*\System Snapshots|*.zsns + +[Towns *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\221020 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\towns|*.log +FileKey2=%ProgramFiles%\Steam\Steamapps\common\towns|*.log + +[TP-Link *] +LangSecRef=3022 +DetectFile=%CommonAppData%\TP-Link +Default=False +FileKey1=%CommonAppData%\TP-Link|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\TP-Link|*.log + +[Trackmania Forever Cache *] +Section=Games +DetectFile=%CommonAppData%\TrackMania +Default=False +FileKey1=%CommonAppData%\TrackMania\Cache|*.* +FileKey2=%CommonAppData%\TrackMania\Cache\ManiaCode|*.* +FileKey3=%LocalAppData%\VirtualStore\ProgramData\TrackMania\Cache|*.* +FileKey4=%LocalAppData%\VirtualStore\ProgramData\TrackMania\Cache\ManiaCode|*.* + +[Trackmania Forever Manialinks *] +Section=Games +DetectFile=%CommonAppData%\TrackMania +Default=False +FileKey1=%CommonAppData%\TrackMania\Manialinks|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\TrackMania\Manialinks|*.* + +[Trackmania Forever Scores *] +Section=Games +DetectFile=%CommonAppData%\TrackMania +Default=False +FileKey1=%CommonAppData%\TrackMania\CampaignsScores|*.* +FileKey2=%CommonAppData%\TrackMania\CampaignsScores\General|*.* +FileKey3=%CommonAppData%\TrackMania\CampaignsScores\UnitedRace|*.* +FileKey4=%CommonAppData%\TrackMania\LadderScores|*.* +FileKey5=%LocalAppData%\VirtualStore\ProgramData\TrackMania\CampaignsScores|*.* +FileKey6=%LocalAppData%\VirtualStore\ProgramData\TrackMania\CampaignsScores\General|*.* +FileKey7=%LocalAppData%\VirtualStore\ProgramData\TrackMania\CampaignsScores\UnitedRace|*.* +FileKey8=%LocalAppData%\VirtualStore\ProgramData\TrackMania\LadderScores|*.* + +[Tracks Eraser Pro *] +LangSecRef=3024 +Detect=HKLM\Software\Acesoft\tracks eraser pro +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Acesoft\Tracks Eraser Pro|te.log +FileKey2=%ProgramFiles%\Acesoft\Tracks Eraser Pro|te.log + +[Trade Manager *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Trademanager +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Trademanager|OneClickEnd.log +FileKey2=%ProgramFiles%\Trademanager|OneClickEnd.log + +[Treesize *] +LangSecRef=3024 +Detect1=HKCU\Software\JAM Software\TreeSize Free +Detect2=HKCU\Software\JAM Software\TreeSize Professional +Default=False +FileKey1=%AppData%\JAM Software\TreeSize *|GlobalOptions.bak0 + +[Trend Micro *] +LangSecRef=3023 +Detect=HKCU\Software\Trend Micro +DetectFile=%CommonAppData%\Trend Micro +Default=False +FileKey1=%CommonAppData%\Trend Micro|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Trend Micro|*.log + +[Trend Micro AntiRansomware Tool *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\AntiRansomware2.0 +Default=False +FileKey1=%CommonAppData%\AntiRansomware|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\AntiRansomware|*.log + +[TrendMicro RUBotted *] +LangSecRef=3024 +Detect=HKLM\Software\TrendMicro\RUBotted +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Trend Micro\RUBotted\DebugLogs|*.*|REMOVESELF +FileKey2=%ProgramFiles%\Trend Micro\RUBotted\DebugLogs|*.*|REMOVESELF + +[Tribes: Ascend *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\17080 +Default=False +FileKey1=%CommonAppData%\Hi-Rez Studios\BrowserCacheTribes\Default\Cache|*.*|RECURSE +FileKey2=%Documents%\My Games\Tribes Ascend\TribesGame\Logs|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\tribes\Binaries\Logs|*.* +FileKey4=%ProgramFiles%\Steam\steamapps\common\tribes\Binaries\Logs|*.* + +[Trillian *] +LangSecRef=3022 +Detect=HKLM\Software\Clients\IM\Trillian +Default=False +FileKey1=%AppData%\Trillian\Crash Files|*.*|RECURSE +FileKey2=%AppData%\Trillian\users\*|buddies.*.xml +FileKey3=%AppData%\Trillian\users\*\cache|*.* +FileKey4=%AppData%\Trillian\users\*\instantlookup|*.* +FileKey5=%AppData%\Trillian\users\*\logs|*.*|RECURSE +FileKey6=%AppData%\Trillian\users\global\skin_cache|*.* +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Trillian\Crash Files|*.*|RECURSE +FileKey8=%LocalAppData%\VirtualStore\Program Files*\Trillian\Users\Default\buddyicons|*.*|RECURSE +FileKey9=%LocalAppData%\VirtualStore\Program Files*\Trillian\Users\Default\instantlookup|*.* +FileKey10=%ProgramFiles%\Trillian\Crash Files|*.*|RECURSE +FileKey11=%ProgramFiles%\Trillian\Users\Default\buddyicons|*.*|RECURSE +FileKey12=%ProgramFiles%\Trillian\Users\Default\instantlookup|*.* + +[Trine *] +Section=Games +Detect1=HKCU\Software\Valve\Steam\Apps\35700 +Detect2=HKCU\Software\Valve\Steam\Apps\35720 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Trine*\log*|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\Trine\_enchanted_edition_\log|*.* +FileKey3=%ProgramFiles%\Steam\SteamApps\Common\Trine*\log*|*.* +FileKey4=%ProgramFiles%\Steam\SteamApps\common\Trine\_enchanted_edition_\log|*.* + +[TrojanHunter *] +LangSecRef=3024 +Detect=HKCU\Software\TrojanHunter +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\TrojanHunter*|Debug.log;DebugLog.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\TrojanHunter*\Scan Reports|*.* +FileKey3=%ProgramFiles%\TrojanHunter*|Debug.log;DebugLog.txt +FileKey4=%ProgramFiles%\TrojanHunter*\Scan Reports|*.* + +[Tropico *] +Section=Games +Detect1=HKCU\Software\Haemimont Games\Tropico 4 +Detect2=HKLM\Software\Haemimont Games\Tropico3 +Default=False +FileKey1=%AppData%\Tropico*\logs|*.*|REMOVESELF +FileKey2=%AppData%\Tropico*\ShaderCache|*.*|REMOVESELF +FileKey3=%ProgramFiles%\Kalypso Media\*|dotnetfx3.exe;dotnetfx35.exe +FileKey4=%ProgramFiles%\Kalypso Media\*\DirectXRedist|*.*|REMOVESELF + +[Trusteer Rapport *] +LangSecRef=3022 +Detect=HKCU\Software\Trusteer\Rapport +Default=False +FileKey1=%CommonAppData%\Trusteer\Rapport\logs|*.* +FileKey2=%LocalAppData%\Trusteer\Rapport\user\logs|*.* +FileKey3=%WinDir%\System32\config\systemprofile\AppData\Local\Trusteer\Rapport\user\logs|*.* + +[Tubebox! *] +LangSecRef=3023 +DetectFile1=%UserProfile%\Start Menu\Programs\TubeBox! +DetectFile2=%UserProfile%\Startmenü\Programme\TubeBox! +Default=False +FileKey1=%UserProfile%\Start*\Program*\TubeBox!|TubeBox!-Log.txt + +[TuneDroid *] +LangSecRef=3023 +DetectFile=%AppData%\TuneDroid +Default=False +FileKey1=%AppData%\TuneDroid\Logs|*.* + +[TuneXP *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\TuneXP +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\TuneXP\docs|*.bak +FileKey2=%ProgramFiles%\TuneXP\docs|*.bak + +[TunnelBear *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\TunnelBear +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\TunnelBear|*.log +FileKey2=%ProgramFiles%\TunnelBear|*.log + +[TV-Browser *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\TV-Browser\tvbrowser.exe +Default=False +FileKey1=%AppData%\TV-Browser\*|java.searchplugin.SearchPlugin.dat* + +[TV_Net *] +LangSecRef=3023 +DetectFile=%LocalLowAppData%\TV_Net +Default=False +FileKey1=%LocalLowAppData%\TV_Net\CacheIcons|*.*|RECURSE +FileKey2=%LocalLowAppData%\TV_Net\Logs|*.*|RECURSE + +[TVersity *] +LangSecRef=3023 +Detect=HKLM\Software\TVersity\Media Server +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\TVersity Codec Pack|*.exe;*.url +FileKey2=%LocalAppData%\VirtualStore\Program Files*\TVersity\Media Server\logs|*.log;*.txt;*.xml;*.zip|RECURSE +FileKey3=%ProgramFiles%\TVersity Codec Pack|*.exe;*.url +FileKey4=%ProgramFiles%\TVersity\Media Server|*.rtf;*.url;*TVersityCodecPackSetup* +FileKey5=%ProgramFiles%\TVersity\Media Server\logs|*.log;*.txt;*.xml;*.zip|RECURSE +FileKey6=%WinDir%\System32|tversity.cookies;TVersityMediaServer.log;*.1;*.2;*.3 +FileKey7=%WinDir%\System32\config\systemprofile\AppData\Local\Temp\TVersity Media Server|*.*|REMOVESELF +FileKey8=%WinDir%\System32\config\systemprofile\Local Settings\Application Data\Temp\TVersity Media Server|*.*|REMOVESELF +ExcludeKey1=FILE|%ProgramFiles%\TVersity Codec Pack\|uninst.exe +ExcludeKey2=PATH|%ProgramFiles%\TVersity\Media Server\|*version.txt;*HOWTO Share Media.txt + +[TVUPlayer *] +LangSecRef=3023 +Detect=HKCU\Software\TVU networks +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\TVUPlayer|log.txt +FileKey2=%ProgramFiles%\TVUPlayer|log.txt + +[TWC Desktop Weather *] +LangSecRef=3021 +DetectFile=%LocalAppData%\The Weather Channel\Desktop\patch +Default=False +FileKey1=%LocalAppData%\The Weather Channel\Desktop\patch|*.* + +[Tweaking.com Windows Repair *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Tweaking.com - Windows Repair (All in One) +DetectFile1=%ProgramFiles%\Tweaking.com +DetectFile2=%SystemDrive%\Tweaking.com_Windows_Repair_Logs +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Tweaking.com\Windows Repair (All in One)\Logs|*.*|REMOVESELF +FileKey2=%ProgramFiles%\Tweaking.com\Windows Repair (All in One)\Logs|*.*|REMOVESELF +FileKey3=%SystemDrive%\Tweaking.com_Windows_Repair_Logs|*.*|REMOVESELF + +[TweakNow PowerPack 2005 *] +LangSecRef=3024 +Detect=HKCU\Software\TweakNow PowerPack +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\TweakNow PowerPack\Backup|*.* +FileKey2=%ProgramFiles%\TweakNow PowerPack\Backup|*.* + +[TweetDeck *] +LangSecRef=3022 +Detect=HKCU\Software\Twitter\TweetDeck +Default=False +Warning=May delete your password and require you to log in again. +FileKey1=%LocalAppData%\Twitter\TweetDeck\localStorage|*.* +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Twitter\TweetDeck|*.log +FileKey3=%ProgramFiles%\Twitter\TweetDeck|*.log + +[Tweetro *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\27761LazywormApplications.Tweetro_5tydn77rr51qw +DetectFile=%LocalAppData%\Packages\27761LazywormApplications.Tweetro_5tydn77rr51qw +Default=False +FileKey1=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\Microsoft\*|*.LOG|RECURSE +FileKey2=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\Microsoft\*\Native Images\Assembly\Temp|*.* +FileKey3=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\Microsoft\*\Native Images\Temp|*.* +FileKey4=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\PRICache|*.* +FileKey6=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\Temp|*.* +FileKey7=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\LocalState\*\PhotoTweets|*.* +FileKey8=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\LocalState\Logs|*.* +FileKey9=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\TempState|*.* + +[Tweetro+ *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\27761LazywormApplications.135450F141EEE_5tydn77rr51qw +DetectFile=%LocalAppData%\Packages\27761LazywormApplications.135450F141EEE_5tydn77rr51qw +Default=False +FileKey1=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\Microsoft\*|*.LOG|RECURSE +FileKey2=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\Microsoft\*\Native Images\Assembly\Temp|*.* +FileKey3=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\Microsoft\*\Native Images\Temp|*.* +FileKey4=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\PRICache|*.* +FileKey6=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\Temp|*.* +FileKey7=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\LocalState\*\PhotoTweets|*.* +FileKey8=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\LocalState\Logs|*.* +FileKey9=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\TempState|*.* + +[Twitter Metro *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\9E2F88E3.Twitter_wgeqdkkx372wm +DetectFile=%LocalAppData%\Packages\9E2F88E3.Twitter_wgeqdkkx372wm +Default=False +FileKey1=%LocalAppData%\Packages\*Twitter_*\AC\INetC*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\*Twitter_*\AC\Microsoft\*|*.LOG|RECURSE +FileKey3=%LocalAppData%\Packages\*Twitter_*\AC\PRICache|*.* +FileKey4=%LocalAppData%\Packages\*Twitter_*\LocalState|*.*|RECURSE + +[Two Worlds Epic Edition *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\1930 +Default=False +FileKey1=%Documents%\TwoWorlds Files\FontsCache|*.tmp + +[Ubisoft Game Launcher *] +Section=Games +DetectFile=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Ubisoft Game Launcher|*.log +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Ubisoft Game Launcher\Cache\assets|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Ubisoft Game Launcher\Cache\http*|*.*|RECURSE +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Ubisoft Game Launcher\Logs|*.* +FileKey5=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher|*.log +FileKey6=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Cache\assets|*.* +FileKey7=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Cache\http*|*.*|RECURSE +FileKey8=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Logs|*.* + +[Ubisoft Game Launcher Installers *] +Section=Games +DetectFile=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher +Default=False +Warning=Make sure to launch all of your installed UPlay games at least once before running this, or they may not launch properly. +FileKey1=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Cache\Installers|*.*|REMOVESELF + +[Ulead GIF Animator 5.05 *] +LangSecRef=3024 +Detect=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05 +Default=False +RegKey1=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05\Recent File List + +[Ultimate Defrag *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Disktrix\UltimateDefrag\Udefrag.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Disktrix\UltimateDefrag|*.db;*Crash.dmp +FileKey2=%ProgramFiles%\Disktrix\UltimateDefrag|*.db;*Crash.dmp + +[UltraDefrag *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UltraDefrag +DetectFile1=%SystemDrive%\PortableApps\UltraDefragPortable\UltraDefragPortable.exe +DetectFile2=%WinDir%\UltraDefrag\ultradefrag.exe +Default=False +FileKey1=%ProgramFiles%\UltraDefrag\logs|*.* +FileKey2=%SystemDrive%|fraglist.luar +FileKey3=%SystemDrive%\PortableApps\UltraDefragPortable\Data|UltraDefragPortable.log +FileKey4=%WinDir%\UltraDefrag\logs|*.log + +[UltraEdit *] +LangSecRef=3021 +Detect=HKCU\Software\IDM Computer Solutions\UltraEdit +Default=False +FileKey1=%AppData%\IDMComp\UltraEdit\autorec|*.*|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\IDM Computer Solutions\UltraEdit|*.txt +FileKey3=%ProgramFiles%\IDM Computer Solutions\UltraEdit|*.txt + +[UltraISO *] +LangSecRef=3024 +Detect=HKCU\Software\EasyBoot Systems +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\UltraISO\backup|*.*|REMOVESELF +FileKey2=%ProgramFiles%\UltraISO\backup|*.*|REMOVESELF +RegKey1=HKCU\Software\EasyBoot Systems\UltraISO\5.0|LogFile +RegKey2=HKCU\Software\EasyBoot Systems\UltraISO\5.0|OpenFolder + +[Ultratron *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\219190 +Default=False +FileKey1=%UserProfile%\.ultratron*|*.log + +[UMPlayer *] +LangSecRef=3023 +DetectFile=%UserProfile%\.umplayer +Default=False +FileKey1=%SystemDrive%\MININT|*.log|RECURSE + +[UMPlayer File Settings *] +LangSecRef=3023 +DetectFile=%UserProfile%\.umplayer +Default=False +FileKey1=%UserProfile%\.umplayer\file_settings|*.*|RECURSE + +[Unchecky *] +LangSecRef=3024 +Detect=HKCU\Software\Unchecky +Default=False +FileKey1=%CommonAppData%\Unchecky|*.log + +[UnHackMe *] +LangSecRef=3024 +Detect=HKLM\Software\Greatis +Default=False +FileKey1=%Documents%\RegRun2|*.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\UnHackMe|*.err;*.txt;*.log|RECURSE +FileKey3=%ProgramFiles%\UnHackMe|*.err;*.txt;*.log|RECURSE + +[Unicenta Open POS *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Unicentaopos* +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Unicentaopos*|*.log +FileKey2=%ProgramFiles%\Unicentaopos*|*.log + +[Unified Remote *] +LangSecRef=3023 +Detect=HKCU\Software\Unified Remote +Default=False +FileKey1=%AppData%\Unified Remote\Logs|*.* + +[Unigine Heaven DX11 Benchmark *] +LangSecRef=3021 +DetectFile=%UserProfile%\Unigine Heaven +Default=False +FileKey1=%UserProfile%\Unigine Heaven|log.html;*.cache +FileKey2=%UserProfile%\Unigine Heaven\save|*.*|REMOVESELF + +[Uninstall Tool *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Tool_is1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Uninstall Tool|*.dmp +FileKey2=%ProgramFiles%\Uninstall Tool|*.dmp + +[Unity Web Player *] +LangSecRef=3023 +Detect=HKCU\Software\Unity\WebPlayer +Default=False +FileKey1=%LocalLowAppData%\Unity\*Player\Cache|*.*|RECURSE + +[Universal Share Downloader *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\USDownloader\USDownloader.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\USDownloader|USDownloader.log;*.bak;*.bmp;*.jpg;*.png +FileKey2=%ProgramFiles%\USDownloader|USDownloader.log;*.bak;*.bmp;*.jpg;*.png + +[Unlocker *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Unlocker\Unlocker.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Unlocker|Unlocker-List.txt +FileKey2=%ProgramFiles%\Unlocker|Unlocker-List.txt + +[Unlockroot *] +LangSecRef=3024 +Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\unlockroot.exe +Detect2=HKLM\Software\UnlockrootPro +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Unlockroot*|*.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Unlockroot\tools|*.zip +FileKey3=%ProgramFiles%\Unlockroot*|*.txt +FileKey4=%ProgramFiles%\Unlockroot*\tools|*.zip + +[UPX Shell *] +LangSecRef=3024 +Detect=HKCU\Software\ION Tek\UPX Shell +Default=False +RegKey1=HKCU\Software\ION Tek\UPX Shell\3.x|History + +[USA Today *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\USATODAY.USATODAY_wy7mw3214mat8 +DetectFile=%LocalAppData%\Packages\USATODAY.USATODAY_wy7mw3214mat8 +Default=False +FileKey1=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\Microsoft\CLR_v4.0|*.log +FileKey3=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\PRICache|*.* +FileKey6=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\Temp|*.* +FileKey7=%LocalAppData%\Packages\USATODAY.USATODAY_*\TempState|*.*|RECURSE + +[USB Disk Security *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\USB Disk Security\USBGuard.exe +Default=False +FileKey1=%AppData%\Zbshareware Lab|*.*|REMOVESELF + +[USB Redirector *] +LangSecRef=3022 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FB9376AC-5253-42a5-AC0A-D306F32FFAD2} +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\USB Redirector|*.log;*.txt +FileKey2=%ProgramFiles%\USB Redirector|*.log;*.txt + +[USB Safely Remove *] +LangSecRef=3024 +Detect=HKCU\Software\SafelyRemove +Default=False +FileKey1=%AppData%\USBSafelyRemove|*.txt +FileKey2=%AppData%\USBSRService|*.txt +FileKey3=%LocalAppData%\VirtualStore\Program Files*\USB Safely Remove|*.DIZ;*.rtf;*.url +FileKey4=%ProgramFiles%\USB Safely Remove|*.DIZ;*.rtf;*.url + +[USBChargerPlus *] +LangSecRef=3021 +DetectFile=%CommonAppData%\USBChargerPlus +Default=False +FileKey1=%CommonAppData%|AsACPLog.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData|AsACPLog.* + +[UsbFix *] +LangSecRef=3023 +Detect=HKCU\Software\UsbFix +Default=False +FileKey1=%SystemDrive%\UsbFix\Log|*.*|REMOVESELF +FileKey2=%SystemDrive%\UsbFix\Quarantine|*.*|REMOVESELF +FileKey3=%UserProfile%\Desktop|UsbFix_Report.txt +RegKey1=HKCU\Software\UsbFix\LastReport + +[User Benchmark *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\User Benchmark\UserBenchMark.exe +Default=False +FileKey1=%SystemDrive%\UserBenchmark|*.*|REMOVESELF + +[uTorrent *] +LangSecRef=3022 +Detect=HKCU\Software\BitTorrent\uTorrent +Default=False +FileKey1=%AppData%\utorrent|*.log;*.dmp;*.bad;*.older;*.benc +FileKey2=%AppData%\utorrent\updates|*.exe +FileKey3=%LocalAppData%\VirtualStore\Program Files*\uTorrent|*.tmp;*.old +FileKey4=%LocalLowAppData%\uTorrentBar\Logs|*.* +FileKey5=%ProgramFiles%\uTorrent|*.tmp;*.old + +[uTorrent ipfilter backup *] +LangSecRef=3022 +DetectFile=%AppData%\uTorrent +Default=False +FileKey1=%AppData%\utorrent|*ipfilter.bak + +[V&V Messenger Chat History *] +LangSecRef=3022 +DetectFile=%AppData%\AJabber +Default=False +FileKey1=%AppData%\AJabber\*\Contacts|*.*|RECURSE + +[Vampix *] +LangSecRef=3023 +Detect=HKCU\Software\KC Softwares\Vampix +Default=False +FileKey1=%AppData%\KC Softwares\Vampix|*.log + +[VCast *] +LangSecRef=3023 +DetectFile=%LocalAppData%\V Cast Media Manager +Default=False +FileKey1=%LocalAppData%\V Cast Media Manager|*.log;backuplog.txt;logfile.txt;*.tmp|RECURSE + +[VCRedist Temp Setup Files *] +LangSecRef=3021 +DetectFile=%SystemDrive%\VC_RED.* +Default=False +FileKey1=%SystemDrive%|eula.1028.txt;eula.1031.txt;eula.1033.txt;eula.1036.txt;eula.1040.txt;eula.1041.txt;eula.1042.txt;eula.2052.txt;eula.3082.txt;globdata.ini;install.exe;install.ini;install.res.1028.dll;install.res.1031.dll;install.res.1033.dll;install.res.1036.dll;install.res.1040.dll;install.res.1041.dll;install.res.1042.dll;install.res.2052.dll;install.res.3082.dll;VC_RED.cab;VC_RED.MSI;vcredist.bmp + +[Venis IX *] +LangSecRef=3021 +Detect=HKCU\Software\Spaceblue\Venis IX +Default=False +RegKey1=HKCU\Software\Spaceblue\Venis IX\FileHistory + +[Ventrilo Chat Logs *] +LangSecRef=3022 +Detect=HKCU\Software\Ventrilo +Default=False +FileKey1=%AppData%\ventrilo\chatlogs|*.*|REMOVESELF + +[Verizon Download Manager *] +LangSecRef=3022 +DetectFile=%LocalAppData%\SupportSoft\Verizondm +Default=False +FileKey1=%LocalAppData%\SupportSoft\verizondm\*\*\logs|*.* + +[Verizon In Home Assistant *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Verizon\IHA_MessageCenter +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Verizon\IHA_MessageCenter\Log|mc-log;mc-log*.* +FileKey2=%ProgramFiles%\Verizon\IHA_MessageCenter\Log|mc-log;mc-log*.* + +[VIA/S3G UniChrome Pro IGP *] +LangSecRef=3024 +Detect=HKLM\Software\S3 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\S3\UChromeP|s3iscfg.log +FileKey2=%ProgramFiles%\S3\UChromeP|s3iscfg.log + +[VideoGet *] +LangSecRef=3022 +Detect=HKCU\Software\Nuclear Coffee\VideoGet +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\VideoGet\Temp|*.* +FileKey2=%ProgramFiles%\VideoGet\Temp|*.* + +[VideoInspector *] +LangSecRef=3023 +Detect=HKCU\Software\KC Softwares\VideoInspector +Default=False +FileKey1=%AppData%\KC Softwares\VideoInspector|*.log + +[VideoMach *] +LangSecRef=3023 +Detect=HKCU\Software\Gromada\VideoMach +Default=False +FileKey1=%Documents%|VideoMach_Log.txt + +[Vim History *] +LangSecRef=3021 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vim +Default=False +FileKey1=%UserProfile%|_viminfo + +[Violett *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\257830 +Default=False +FileKey1=%ProgramFiles%\Steam\SteamApps\Common\Violett|crash.dmp;error.log;output_log.txt;report.ini|RECURSE + +[VirtualBox *] +LangSecRef=3024 +DetectFile=%UserProfile%\.VirtualBox +Default=False +FileKey1=%UserProfile%\.VirtualBox|VBoxSVC.log.*;VBoxSVC.*;*.log;*.log.* +FileKey2=%UserProfile%\VirtualBox VMs\*\Logs|*.log;*.log.* + +[VirtualDJ *] +LangSecRef=3023 +Detect=HKCU\Software\VirtualDJ +Default=False +FileKey1=%Documents%\VirtualDJ\Cache|*.*|RECURSE + +[VirtualDJ Tracklist *] +LangSecRef=3023 +Detect=HKCU\Software\VirtualDJ +Default=False +FileKey1=%Documents%\VirtualDJ\TrackListing|*.* + +[VirtualDub *] +LangSecRef=3023 +Detect=HKCU\Software\VirtualDub.org\VirtualDub +Default=False +RegKey1=HKCU\Software\VirtualDub.org\VirtualDub\MRU List +RegKey2=HKCU\Software\VirtualDub.org\VirtualDub\Saved filespecs + +[VirtualDubMod *] +LangSecRef=3023 +Detect=HKCU\Software\Freeware\VirtualDubMod +Default=False +RegKey1=HKCU\Software\Freeware\VirtualDubMod\MRU List + +[VirtualFDD *] +LangSecRef=3024 +Detect=HKCU\Software\Korbos\VirtualFDD +Default=False +RegKey1=HKCU\Software\Korbos\VirtualFDD\Recent File List + +[VirtuaWin *] +LangSecRef=3021 +DetectFile=%AppData%\VirtuaWin +Default=False +FileKey1=%AppData%\VirtuaWin|virtuawin.log + +[Vizzed Retro Game Room *] +LangSecRef=3023 +DetectFile=%LocalLowAppData%\VizzedRgr +Default=False +FileKey1=%LocalLowAppData%\VizzedRgr\Downloads|*.*|RECURSE +FileKey2=%LocalLowAppData%\VizzedRgr\Roms|*.*|RECURSE + +[VLC Media Player *] +LangSecRef=3023 +Detect=HKLM\Software\VideoLAN\VLC +Default=False +FileKey1=%AppData%\vlc|*.cache-3;ml.xspf.tmp*;vlc-qt-interface.ini.* +FileKey2=%AppData%\vlc\art|*.*|RECURSE +FileKey3=%AppData%\vlc\crashdump*|*.* + +[VMware Player *] +LangSecRef=3024 +Detect=HKLM\Software\VMware, Inc.\VMware Player +Default=False +FileKey1=%Documents%\My Virtual Machines|*.log|RECURSE +FileKey2=%LocalAppData%\VMware|*.log + +[VMware Workstation *] +LangSecRef=3024 +Detect=HKLM\Software\VMware, Inc.\VMware Workstation +Default=False +FileKey1=%CommonAppData%\VMware\hostd|*.log;*.gz|RECURSE +FileKey2=%CommonAppData%\VMware\Installer|*.*|REMOVESELF +FileKey3=%CommonAppData%\VMware\logs|*.log|RECURSE +FileKey4=%CommonAppData%\VMware\VMware vCenter Converter Standalone|*.log;*.gz;*.zip|RECURSE +FileKey5=%Documents%\My Virtual Machines|*.log|RECURSE +FileKey6=%LocalAppData%\VMware|*.log +FileKey7=%LocalAppData%\VMware\VMware vCenter Converter Standalone Client\Logs|*.log;*.gz + +[VNCViewer 5 *] +LangSecRef=3024 +Detect=HKCU\Software\RealVNC\vncviewer +Default=False +FileKey1=%LocalAppData%\RealVNC|*.log +RegKey1=HKCU\Software\RealVNC\vncviewer\MRU + +[Vodafone *] +LangSecRef=3022 +Detect=HKCU\Software\Vodafone +Default=False +FileKey1=%AppData%\Vodafone\Vodafone Mobile Broadband\Log|*.* +FileKey2=%CommonAppData%\Vodafone\Log|*.* +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Vodafone\Vodafone Mobile Broadband\Bin|SwiHpAux.log +FileKey4=%LocalAppData%\VirtualStore\ProgramData\Vodafone\Log|*.* +FileKey5=%ProgramFiles%\Vodafone\Vodafone Mobile Broadband\Bin|SwiHpAux.log +FileKey6=%WinDir%|ModemLog_*.txt + +[Vodafone Database *] +LangSecRef=3022 +Detect=HKCU\Software\Vodafone +Default=False +Warning=This will delete your incoming SMS database. +FileKey1=%AppData%\Vodafone\Vodafone Mobile Broadband\UserData|VodafoneMobileBroadband.mdb + +[VoipBuster *] +LangSecRef=3022 +DetectFile=%AppData%\VoipBuster +Default=False +FileKey1=%AppData%\VoipBuster|*.log +FileKey2=%WinDir%\System32|VoipBuster*.log +FileKey3=%WinDir%\SysWOW64|VoipBuster*.log + +[Vopt 9 *] +LangSecRef=3024 +Detect=HKCU\Software\Golden Bow Systems\Vopt +Default=False +FileKey1=%ProgramFiles%\Golden Bow\Vopt 9|Vopt.log + +[VS Code *] +LangSecRef=3021 +DetectFile=%AppData%\Code +Default=False +FileKey1=%AppData%\Code|cookies* +FileKey2=%AppData%\Code\GPUCache|*.* +FileKey3=%AppData%\Code\Local Storage|*.* +FileKey4=%LocalAppData%\SquirrelTemp|*.log + +[VSO Batcher *] +LangSecRef=3023 +Detect=HKCU\Software\VSO\VSO Batcher +Default=False +FileKey1=%AppData%\Vso\VSO Batcher\1|*.*|RECURSE +RegKey1=HKCU\Software\VSO\VSO Batcher\1|VideoFilesLastFlder + +[VSO Blindwrite *] +LangSecRef=3021 +Detect=HKCU\Software\VSO\Blindwrite +Default=False +FileKey1=%AppData%|pcouffin.log;ezplay.log +FileKey2=%AppData%\VSO|*.log|REMOVESELF +FileKey3=%CommonAppData%\VSO\Blindwrite\*|*.log|REMOVESELF +FileKey4=%Documents%\PcSetup|*.log|REMOVESELF +FileKey5=%LocalAppData%\VirtualStore\ProgramData\VSO\Blindwrite\*|*.log|REMOVESELF +FileKey6=%UserProfile%|timestamp.txt + +[VSO Converter *] +LangSecRef=3023 +Detect1=HKCU\Software\VSO\Blu-ray Converter Ultimate +Detect2=HKCU\Software\VSO\DVD Converter Ultimate +Detect3=HKCU\Software\VSO\VSO Video Converter +Default=False +FileKey1=%AppData%|pcouffin.log +FileKey2=%CommonAppData%\VSO|*.cache +FileKey3=%CommonAppData%\VSO\*Converter*\*\Log|*.log;*.crashlist|REMOVESELF +FileKey4=%CommonAppData%\VSO\vsothumbs|*.*|REMOVESELF +FileKey5=%Documents%\PcSetup|*.log|REMOVESELF +FileKey6=%LocalAppData%\VirtualStore\Program Files*\VSO\*Converter*\*|*.txt +FileKey7=%LocalAppData%\VirtualStore\ProgramData\VSO|*.cache +FileKey8=%LocalAppData%\VirtualStore\ProgramData\VSO\*Converter*\*\Log|*.log;*.crashlist|REMOVESELF +FileKey9=%LocalAppData%\VirtualStore\ProgramData\VSO\vsothumbs|*.*|REMOVESELF +FileKey10=%ProgramFiles%\VSO\*Converter*\*|*.txt +RegKey1=HKCU\Software\VSO\Blu-ray Converter Ultimate\2|BDMVInputFolders +RegKey2=HKCU\Software\VSO\Blu-ray Converter Ultimate\2|ISOInputFolders +RegKey3=HKCU\Software\VSO\Blu-ray Converter Ultimate\2|MediaLabel +RegKey4=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_audio +RegKey5=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_bluray +RegKey6=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_dvd +RegKey7=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_iso +RegKey8=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_subtitle +RegKey9=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_video +RegKey10=HKCU\Software\VSO\DVD Converter Ultimate\2|BDMVInputFolders +RegKey11=HKCU\Software\VSO\DVD Converter Ultimate\2|ISOInputFolders +RegKey12=HKCU\Software\VSO\DVD Converter Ultimate\2|MediaLabel +RegKey13=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_audio +RegKey14=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_bluray +RegKey15=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_dvd +RegKey16=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_iso +RegKey17=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_subtitle +RegKey18=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_video +RegKey19=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_audio +RegKey20=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_bluray +RegKey21=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_dvd +RegKey22=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_iso +RegKey23=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_subtitle +RegKey24=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_video + +[VSO ConvertXToDVD 5 *] +LangSecRef=3023 +Detect=HKCU\Software\VSO\ConvertXtoDVD\5 +Default=False +FileKey1=%AppData%|pcouffin.log +FileKey2=%CommonAppData%\VSO\vsothumbs|*.*|REMOVESELF +FileKey3=%LocalAppData%\VirtualStore\Program Files*\VSO\ConvertX\5|*.log;*.rtf +FileKey4=%LocalAppData%\VirtualStore\ProgramData\VSO\vsothumbs|*.*|REMOVESELF +FileKey5=%ProgramFiles%\VSO\ConvertX\5|*.log;*.rtf + +[VSO CopyTo *] +LangSecRef=3021 +Detect=HKCU\Software\VSO\CopyTo +Default=False +FileKey1=%AppData%|pcouffin.log;ezplay.log +FileKey2=%AppData%\VSO|*.log|REMOVESELF +FileKey3=%CommonAppData%\VSO|*.cache;*.crashlist;*.log;*.vsothumb|RECURSE +FileKey4=%Documents%\PcSetup|*.log|REMOVESELF +FileKey5=%LocalAppData%\VirtualStore\ProgramData\VSO|*.cache;*.crashlist;*.log;*.vsothumb|RECURSE +FileKey6=%UserProfile%|timestamp.txt + +[VSO Downloader *] +LangSecRef=3023 +Detect=HKCU\Software\VSO\VSO Downloader +Default=False +FileKey1=%AppData%\VSO|*.log +FileKey2=%AppData%\VSO\VSO Downloader\*\items|*.item|RECURSE +FileKey3=%CommonAppData%\VSO\VSO Downloader\*\items|*.item|RECURSE +FileKey4=%CommonAppData%\VSO\VSO Downloader\*\log|*.log +FileKey5=%LocalAppData%\VirtualStore\ProgramData\VSO\VSO Downloader\*\items|*.item|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\VSO\VSO Downloader\*\log|*.log + +[VSO Media Player 1 *] +LangSecRef=3023 +Detect=HKCU\Software\VSO\VSO Media Player\1 +Default=False +FileKey1=%AppData%\VSO\VSO Media Player\1|autoresume.xml +FileKey2=%CommonAppData%\VSO|font.cache +FileKey3=%CommonAppData%\VSO\VSO Media Player\1\log|*.log;*.crashlist +FileKey4=%CommonAppData%\VSO\vsothumbs|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\ProgramData\VSO|font.cache +FileKey6=%LocalAppData%\VirtualStore\ProgramData\VSO\VSO Media Player\1\log|*.log;*.crashlist +FileKey7=%LocalAppData%\VirtualStore\ProgramData\VSO\vsothumbs|*.*|RECURSE +RegKey1=HKCU\Software\VSO\VSO Media Player\1\RecentlyOpenedFiles + +[VueScan *] +LangSecRef=3024 +DetectFile1=%ProgramFiles%\VueScan +DetectFile2=%SystemDrive%\VueScan +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\VueScan|*.log|RECURSE +FileKey2=%ProgramFiles%\VueScan|*.log|RECURSE +FileKey3=%SystemDrive%\VueScan|*.log|RECURSE + +[Vuze *] +LangSecRef=3022 +Detect=HKCR\Azureus +Default=False +FileKey1=%AppData%\Azureus\plugins\advancedstatistics|*.txt +FileKey2=%AppData%\Azureus\plugins\progressbar|*.txt +FileKey3=%ProgramFiles%\Vuze|*.log +FileKey4=%ProgramFiles%\Vuze\.install4j|*.log + +[Vuze Dasu Reports *] +LangSecRef=3022 +Detect=HKCR\Azureus +Default=False +Warning=This will delete data from Dasu plugins. You should review the Dasu plugin reports before deleting it. +FileKey1=%AppData%\Azureus\plugins\dasu\reports|*.* + +[W3i *] +LangSecRef=3022 +DetectFile=%CommonAppData%\W3i +Default=False +FileKey1=%CommonAppData%\W3i\InstallQUpdater|*.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\W3i\InstallQUpdater|*.log + +[Walgreens PhotoShow Express CD *] +LangSecRef=3021 +DetectFile=%AppData%\Walgreens\PhotoShow Express CD +Default=False +FileKey1=%AppData%\Walgreens\Photoshow Express CD\Cache|*.*|RECURSE + +[Wallpaper Juggler *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Wallpaper Juggler +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Wallpaper Juggler|*.log +FileKey2=%ProgramFiles%\Wallpaper Juggler|*.log + +[WallWatcher *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Wall Watcher\WallWatcher.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Wall Watcher\Logs|*.* +FileKey2=%ProgramFiles%\Wall Watcher\Logs|*.* + +[War of the Human Tanks *] +Section=Games +DetectFile=%ProgramFiles%\Desura\Common\war-of-the-human-tanks +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Desura\Common\war-of-the-human-tanks\LOG|*.* +FileKey2=%ProgramFiles%\Desura\Common\war-of-the-human-tanks\LOG|*.* + +[War Thunder *] +Section=Games +Detect1=HKCU\Software\Gaijin\WarThunder +Detect2=HKCU\Software\Valve\Steam\Apps\236390 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\War Thunder\.launcher_log|*.txt +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\War Thunder\_debuginfo|*.clog +FileKey3=%LocalAppData%\VirtualStore\Program Files*\War Thunder\.launcher_log|*.txt +FileKey4=%LocalAppData%\VirtualStore\Program Files*\War Thunder\_debuginfo|*.clog +FileKey5=%ProgramFiles%\Steam\SteamApps\common\War Thunder\.launcher_log|*.txt +FileKey6=%ProgramFiles%\Steam\SteamApps\common\War Thunder\_debuginfo|*.clog +FileKey7=%ProgramFiles%\War Thunder\.launcher_log|*.txt +FileKey8=%ProgramFiles%\War Thunder\_debuginfo|*.clog + +[Warcraft III *] +Section=Games +Detect=HKLM\Software\Blizzard Entertainment\Warcraft III +DetectFile=%ProgramFiles%\Warcraft III\Warcraft III.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Warcraft III|*.log;*.html +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Warcraft III\Errors|*.dmp;*.txt +FileKey3=%ProgramFiles%\Warcraft III|*.log;*.html +FileKey4=%ProgramFiles%\Warcraft III\Errors|*.dmp;*.txt +ExcludeKey1=PATH|%ProgramFiles%\Warcraft III\|*CustomKeyInfo.txt;*CustomKeysSample.txt + +[Warcraft III Backup Files *] +Section=Games +Detect=HKLM\Software\Blizzard Entertainment\Warcraft III +Default=False +Warning=This will delete all your Warcraft III backup files. You won't be able to restore from them if something goes wrong. +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Warcraft III|*.bak;*.old|RECURSE +FileKey2=%ProgramFiles%\Warcraft III|*.bak;*.old|RECURSE + +[Warframe *] +Section=Games +Detect=HKCU\Software\Digital Extremes\Warframe +Default=False +FileKey1=%LocalAppData%\Warframe|*.log + +[Warhammer 40000: Dawn of War Gold *] +Section=Games +Detect=HKCU\Software\Valve\Steam\Apps\4570 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Dawn of War Gold\Logfiles|*.* +FileKey2=%ProgramFiles%\Steam\steamapps\common\Dawn of War Gold\Logfiles|*.* + +[WashAndGo *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Abelssoft\WashAndGo +Default=False +FileKey1=%AppData%\Abelssoft\WashAndGo\Log|*.log + +[WashAndGo Backups *] +LangSecRef=3024 +DetectFile=%LocalAppData%\Abelssoft\WashAndGo +Default=False +FileKey1=%Documents%\Abelssoft\WashAndGo\Backups|*.* +FileKey2=%LocalAppData%\Abelssoft\WashAndGo\Backups|*.* + +[Wave Systems Corp *] +LangSecRef=3021 +DetectFile=%AppData%\Wave Systems Corp +Default=False +FileKey1=%AppData%\Wave Systems Corp|DSM_AM.* +FileKey2=%CommonAppData%\Wave Systems Corp|*.log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Wave Systems Corp|*.log|RECURSE +FileKey4=%LocalAppData%\Wave Systems Corp\WCLIENTDLL|errors.txt + +[WavePad *] +LangSecRef=3023 +Detect=HKCU\Software\NCH Software\WavePad +Default=False +RegKey1=HKCU\Software\NCH Software\WavePad\Recent + +[Wavosaur *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\Wavosaur\wavosaur.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Wavosaur|wavosaur.log +FileKey2=%ProgramFiles%\Wavosaur|wavosaur.log + +[Weather *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.BingWeather_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log +FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp +FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE +FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE +FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory + +[Weather It Up *] +LangSecRef=3024 +Detect=HKLM\Software\Weather It Up +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Weather It Up|*.log +FileKey2=%ProgramFiles%\Weather It Up|*.log + +[Weather Watcher Live *] +LangSecRef=3021 +Detect=HKCU\Software\VB and VBA Program Settings\Weather Watcher Live +Default=False +FileKey1=%AppData%\WeatherWatcherLive|WeatherWatcherLive.log +FileKey2=%AppData%\WeatherWatcherLive\Temp|*.* + +[Web Sling Player *] +LangSecRef=3023 +DetectFile=%AppData%\Sling Media\WebSlingPlayer +Default=False +FileKey1=%AppData%\Sling Media\WebSlingPlayer|*.txt;*.log +FileKey2=%AppData%\Sling Media\WebSlingPlayer\*_cache|*.*|RECURSE +FileKey3=%AppData%\Sling Media\WebSlingPlayer\temp|*.*|RECURSE + +[WebConnect *] +LangSecRef=3023 +DetectFile=%LocalAppData%\Ericom +Default=False +FileKey1=%LocalAppData%\Ericom\Ptagent|*.* +FileKey2=%LocalAppData%\Ericom\PtRdp|*.* + +[WebMon *] +LangSecRef=3022 +Detect=HKCU\Software\CM\WebMon +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WebMon|UpdateLog.* +FileKey2=%ProgramFiles%\WebMon|UpdateLog.* + +[WebPI Installer *] +LangSecRef=3025 +DetectFile=%LocalAppData%\Microsoft\Web Platform Installer\logs\webpi +Default=False +FileKey1=%LocalAppData%\Microsoft\Web Platform Installer\logs\webpi|*.txt + +[WebPictures Downloader *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\WebPictures Downloader +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WebPictures Downloader\Projects|*.*|RECURSE +FileKey2=%ProgramFiles%\WebPictures Downloader\Projects|*.*|RECURSE + +[WebReaper *] +LangSecRef=3022 +Detect=HKCU\Software\BlueBeam\WebReaper +Default=False +RegKey1=HKCU\Software\BlueBeam\WebReaper\URL History + +[Webroot SecureAnywhere *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\Webroot\WRSA.exe +Default=False +FileKey1=%CommonAppData%\WRData|WRLog.log +FileKey2=%LocalAppData%\VirtualStore\ProgramData\WRData|WRLog.log + +[WebStorm *] +LangSecRef=3021 +Detect=HKCU\Software\JetBrains\WebStorm +Default=False +FileKey1=%UserProfile%\.WebIde50\system\Caches|*.*|RECURSE +FileKey2=%UserProfile%\.WebIde50\system\LocalHistory|*.*|RECURSE +FileKey3=%UserProfile%\.WebIde50\system\Log|*.*|RECURSE +FileKey4=%UserProfile%\.WebIde50\system\tmp|*.*|RECURSE + +[WebTorrent *] +LangSecRef=3022 +DetectFile=%AppData%\WebTorrent +Default=False +FileKey1=%AppData%\WebTorrent\*Cache|*.* +FileKey2=%LocalAppData%\WebTorrent|*.log + +[WeFi *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\WeFi +Default=False +FileKey1=%CommonAppData%\WeFi\LogFiles|*.*|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\ProgramData\WeFi\LogFiles|*.*|REMOVESELF + +[Western Digital Firmware Updater *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Western Digital +Default=False +FileKey1=%CommonAppData%\Western Digital\Logs\WD Firmware Updater|*.*|REMOVESELF + +[Western Digital SmartWare *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Western Digital +Default=False +FileKey1=%AppData%\Western Digital\WD SmartWare\Logs|*.* +FileKey2=%CommonAppData%\Western Digital\Logs\WD *\*|*.log +FileKey3=%CommonAppData%\Western Digital\WD SmartWare|*.log +FileKey4=%CommonAppData%\Western Digital\WDFME|*.* +FileKey5=%LocalAppData%\VirtualStore\ProgramData\Western Digital\WD SmartWare|*.log +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Western Digital\WDFME|*.* +FileKey7=%LocalAppData%\Western Digital\WD SmartWare|*log.txt +FileKey8=%Public%\Documents\Downloads\WD_SmartWare_Installer_*|*.*|REMOVESELF + +[WhatPulse *] +LangSecRef=3021 +Detect=HKCU\Software\WhatPulse +Default=False +FileKey1=%AppData%\WhatPulse|*.log + +[WhatPulse Backups *] +LangSecRef=3021 +Detect=HKCU\Software\WhatPulse +Default=False +FileKey1=%AppData%\WhatPulse|*.bak + +[Who's On My Wifi *] +LangSecRef=3022 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{010D45A1-093D-4534-8147-4E10E80F81CC}_is1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\IO3O LLC\Who Is On My Wifi\logs|*.* +FileKey2=%ProgramFiles%\IO3O LLC\Who Is On My Wifi\logs|*.* + +[WildTangent *] +LangSecRef=3021 +DetectFile=%AppData%\WildTangent +Default=False +FileKey1=%AppData%\WildTangent\Logs|*.* + +[Winamp *] +LangSecRef=3023 +Detect=HKCU\Software\Winamp +Default=False +Warning=This removes the current playlist. +FileKey1=%AppData%\Winamp|Winamp.m3u;Winamp.m3u8 + +[WinAVI Video Converter *] +LangSecRef=3023 +Detect=HKCU\Software\ZjSoft\WinAVI +Default=False +FileKey1=%LocalAppData%\winavi|debug.log + +[WinCHM *] +LangSecRef=3021 +Detect=HKCU\Software\Softany\WinCHM +Default=False +RegKey1=HKCU\Software\Softany\WinCHM|RecentFile1 +RegKey2=HKCU\Software\Softany\WinCHM|RecentFile2 +RegKey3=HKCU\Software\Softany\WinCHM|RecentFile3 +RegKey4=HKCU\Software\Softany\WinCHM|RecentFile4 +RegKey5=HKCU\Software\Softany\WinCHM|RecentFile5 +RegKey6=HKCU\Software\Softany\WinCHM|RecentFile6 + +[Windows 7 Manager *] +LangSecRef=3024 +Detect=HKCU\Software\Yamicsoft\Windows 7 Manager +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Yamicsoft\Windows 7 Manager\DiskAnalyzerXML|*.* +FileKey2=%ProgramFiles%\Yamicsoft\Windows 7 Manager\DiskAnalyzerXML|*.* + +[Windows Communications Apps *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Comms\Unistore\data|AggregateCache.uca +FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\AppCache|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INet*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\PRICache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\LiveComm\*\*\DBStore\LogFiles|edbtmp.log +FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory + +[Windows Defender *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows Defender +Default=False +FileKey1=%CommonAppData%\Microsoft\Windows Defender\Network Inspection System\Support|*.txt +FileKey2=%CommonAppData%\Microsoft\Windows Defender\Scans|*.bin* +FileKey3=%CommonAppData%\Microsoft\Windows Defender\Scans\History\CacheManager|*.*|RECURSE +FileKey4=%CommonAppData%\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency|*.*|RECURSE +FileKey5=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Service|*.log +FileKey6=%CommonAppData%\Microsoft\Windows Defender\Scans\MetaStore|*.*|RECURSE +FileKey7=%CommonAppData%\Microsoft\Windows Defender\Support|*.*|RECURSE + +[Windows DVD Maker *] +LangSecRef=3023 +Detect=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings +Default=False +RegKey1=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\Browse 2 +RegKey2=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\Browse 5 +RegKey3=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\Browse 7 +RegKey4=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\Browse 128 +RegKey5=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\MRU0 +RegKey6=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\MRU1 +RegKey7=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\MRU2 +RegKey8=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\MRU3 + +[Windows Error Reporting *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows\Windows Error Reporting +Default=False +FileKey1=%LocalAppData%\PCHealth\ErrorRep\QSignoff|*.* +FileKey2=%WinDir%\pchealth\ERRORREP|*.*|RECURSE +FileKey3=%WinDir%\pchealth\helpctr\DataColl|*.xml +FileKey4=%WinDir%\pchealth\helpctr\OfflineCache|*.*|RECURSE +FileKey5=%WinDir%\System32\config\systemprofile\AppData\Local\CrashDumps|*.dmp +FileKey6=%WinDir%\System32\config\systemprofile\Local Settings\Application Data\CrashDumps|*.dmp +FileKey7=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\CrashDumps|*.dmp +FileKey8=%WinDir%\SysWOW64\config\systemprofile\Local Settings\Application Data\CrashDumps|*.dmp +RegKey1=HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation +RegKey2=HKLM\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation +RegKey3=HKLM\Software\Microsoft\Windows\Windows Error Reporting\FullLiveKernelReports|LastFullLiveReport +RegKey4=HKLM\Software\Microsoft\Windows\Windows Error Reporting\FullLiveKernelReports\win32k.sys +RegKey5=HKLM\Software\Microsoft\Windows\Windows Error Reporting\LiveKernelReports\win32k.sys +RegKey6=HKLM\Software\Microsoft\Windows\Windows Error Reporting\LocalDumps +RegKey7=HKU\.DEFAULT\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation + +[Windows ESENT *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\ESENT +Default=False +RegKey1=HKLM\Software\Microsoft\ESENT\Process + +[Windows Experience Index *] +DetectOS=10.0| +LangSecRef=3025 +Default=False +FileKey1=%WinDir%\Performance\WinSAT|*.* +FileKey2=%WinDir%\Performance\WinSAT\DataStore|*.* + +[Windows Feedback *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedback_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0*|*.log +FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0*\UsageLogs|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Temp|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\LocalCache|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\LocalState\Cache|*.*|RECURSE +FileKey11=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\TempState|*.*|RECURSE + +[Windows Image Acquisition *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\WIA +Default=False +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\WIA + +[Windows Installer *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Installer +Default=False +FileKey1=%SystemDrive%\Config.msi|*.*|REMOVESELF +FileKey2=%WinDir%\Installer|*.tmp|RECURSE +FileKey3=%WinDir%\Installer|SourceHash{*};wix{*}.SchedServiceConfig.rmi +FileKey4=%WinDir%\Installer\MSI*.tmp-|*.*|REMOVESELF + +[Windows Live Mail *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows Live Mail +Default=False +Warning=This will reset the read counts, which will be recalculated when WLMail is started. +FileKey1=%LocalAppData%\Microsoft\Windows*Mail|*.log;*.jrs;*.chk;*.rss;*.tmp|RECURSE +FileKey2=%LocalAppData%\Microsoft\Windows*Mail\*|*.MSMessageStore|RECURSE +FileKey3=%LocalAppData%\Microsoft\Windows*Mail\*.tmp|*.*|RECURSE +FileKey4=%LocalAppData%\Microsoft\Windows*Mail\*\Backup|*.*|REMOVESELF +FileKey5=%LocalAppData%\Microsoft\Windows*Mail\Backup|*.*|REMOVESELF +RegKey1=HKCU\Software\Microsoft\Windows Live Mail|SearchFolderVersion + +[Windows Live Messenger *] +LangSecRef=3022 +Detect=HKLM\Software\Microsoft\Windows Live\Messenger +Default=False +FileKey1=%CommonProgramFiles%\Windows Live\.cache|*.*|RECURSE +FileKey2=%LocalAppData%\Microsoft\Messenger|*.uccapilog;*.bak;*.txt|RECURSE +FileKey3=%LocalAppData%\Microsoft\Windows Live|*.log;*.jrs;*.sqm|RECURSE +FileKey4=%LocalAppData%\Microsoft\Windows Live Contacts|*.log;*.jrs|RECURSE +FileKey5=%LocalAppData%\Microsoft\Windows Live Contacts\*\*\*\Backup|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Common Files\Windows Live\.cache|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Windows Live\Messenger|*.bak|RECURSE +FileKey8=%ProgramFiles%\Windows Live\Messenger|*.bak|RECURSE +FileKey9=%WinDir%\System32\config\systemprofile\Documents|wlidsvctrace*.txt +FileKey10=%WinDir%\SysWOW64\config\systemprofile\Documents|wlidsvctrace*.txt + +[Windows Live Messenger Chat History *] +LangSecRef=3022 +Detect=HKLM\Software\Microsoft\Windows Live\Messenger +Default=False +Warning=Removes Windows Live Messenger chat history! +FileKey1=%Documents%\*\*\Histor*|*.* + +[Windows Live Messenger Setup Files *] +LangSecRef=3022 +Detect=HKLM\Software\Microsoft\Windows Live\Messenger +Default=False +Warning=After running this, you will not be able to uninstall Windows Live Essentials components without downloading the installer again. +FileKey1=%LocalLowAppData%\Microsoft\Windows Live\Setup|*.*|REMOVESELF + +[Windows Live Movie Maker *] +LangSecRef=3023 +Detect=HKCU\Software\Microsoft\Windows Live\Movie Maker +Default=False +FileKey1=%LocalAppData%\Microsoft\Windows Live Movie Maker|*.*|RECURSE +RegKey1=HKCU\Software\Microsoft\Windows Live\Movie Maker|browseformusicdirectory +RegKey2=HKCU\Software\Microsoft\Windows Live\Movie Maker|browseforpicturesdirectory +RegKey3=HKCU\Software\Microsoft\Windows Live\Movie Maker|browseforprojectsdirectory +RegKey4=HKCU\Software\Microsoft\Windows Live\Movie Maker|rendertofiledirectory +RegKey5=HKCU\Software\Microsoft\Windows Live\Movie Maker|snapshotfiledirectory +RegKey6=HKCU\Software\Microsoft\Windows Live\Movie Maker\recent + +[Windows Live Photo Gallery *] +LangSecRef=3023 +Detect=HKCU\Software\Microsoft\Windows Live\Photo Gallery +Default=False +FileKey1=%LocalAppData%\Microsoft\Windows Live Photo Gallery|*.*|RECURSE +RegKey1=HKCU\Software\Microsoft\Windows Live\Photo Aquisition\Camera|FinenameTemplate +RegKey2=HKCU\Software\Microsoft\Windows Live\Photo Aquisition\Camera|RootDirectory +RegKey3=HKCU\Software\Microsoft\Windows Live\Photo Gallery|galleryscopedfolders + +[Windows Live Setup *] +LangSecRef=3022 +Detect1=HKCU\Software\Microsoft\Windows Live Mail +Detect2=HKLM\Software\Microsoft\Windows Live +Default=False +FileKey1=%CommonAppData%\Microsoft\WLSetup|*.tmp +FileKey2=%CommonAppData%\Microsoft\WLSetup\*logs|*.*|RECURSE +FileKey3=%CommonAppData%\WLInstaller|*.log +FileKey4=%CommonProgramFiles%\Windows Live\.cache|*.tmp +FileKey5=%LocalAppData%\Microsoft\WLSetup\*logs|*.*|RECURSE +FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\WLSetup|*.tmp +FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\WLSetup\*logs|*.*|RECURSE +FileKey8=%LocalAppData%\VirtualStore\ProgramData\WLInstaller|*.log + +[Windows Live Writer *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows Live Writer +Default=False +FileKey1=%LocalAppData%\Windows Live Writer|*.log + +[Windows Logs *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Windows +Default=False +FileKey1=%CommonAppData%\Microsoft\Network\Downloader|*.*|RECURSE +FileKey2=%CommonAppData%\Microsoft\Windows Security Health\Logs|*.*|RECURSE +FileKey3=%CommonAppData%\USOShared\Logs|*.*|RECURSE +FileKey4=%LocalAppData%\ConnectedDevicesPlatform|*.log +FileKey5=%LocalAppData%\Diagnostics|*.*|RECURSE +FileKey6=%ProgramFiles%\UNP\Logs|*.* +FileKey7=%SystemDrive%\PerfLogs\System\Diagnostics|*.*|RECURSE +FileKey8=%SystemDrive%\PerfLogs\System\Performance|*.*|RECURSE +FileKey9=%WinDir%\debug\WIA|*.log +FileKey10=%WinDir%\inf|*.log* +FileKey11=%WinDir%\Logs\CBS|*.cab +FileKey12=%WinDir%\Logs\dosvc|*.*|RECURSE +FileKey13=%WinDir%\Logs\NetSetup|*.*|RECURSE +FileKey14=%WinDir%\Logs\SIH|*.*|RECURSE +FileKey15=%WinDir%\Logs\WindowsBackup|*.etl +FileKey16=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log +FileKey17=%WinDir%\Panther\FastCleanup|*.log +FileKey18=%WinDir%\Panther\Rollback|*.txt +FileKey19=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml +FileKey20=%WinDir%\repair|setup.log +FileKey21=%WinDir%\security\logs|*.*|RECURSE +FileKey22=%WinDir%\System32\catroot2|*.chk;*.log;*.jrs;*.txt +FileKey23=%WinDir%\System32\LogFiles\HTTPERR|*.log +FileKey24=%WinDir%\System32\LogFiles\Scm|*.*|RECURSE +FileKey25=%WinDir%\System32\LogFiles\setupcln|*.*|RECURSE +FileKey26=%WinDir%\System32\LogFiles\Srt|*.*|RECURSE +FileKey27=%WinDir%\System32\LogFiles\WMI|*.*|RECURSE +FileKey28=%WinDir%\System32\SleepStudy|*.etl +FileKey29=%WinDir%\System32\SleepStudy\ScreenOn|*.etl +FileKey30=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml;*.log +FileKey31=%WinDir%\System32\WDI\*|snapshot.etl|REMOVESELF +FileKey32=%WinDir%\System32\WDI\LogFiles\StartupInfo|*.*|RECURSE +RegKey1=HKLM\Software\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications +RegKey2=HKLM\Software\Microsoft\Tracing +RegKey3=HKLM\Software\Wow6432Node\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications +RegKey4=HKLM\Software\Wow6432Node\Microsoft\Tracing + +[Windows Mail *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows Mail +Default=False +FileKey1=%LocalAppData%\Microsoft\Windows Mail|*.log;*.jrs;*.chk|RECURSE + +[Windows Media Center *] +LangSecRef=3023 +Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center +Default=False +FileKey1=%CommonAppData%\Microsoft\eHome\thmb|TVThumb.db +FileKey2=%LocalAppData%\Microsoft\Ehome|Image.db;Video.db;musicThumbs.db +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Microsoft\eHome\thmb|TVThumb.db +RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\MRU\SettingsMRU + +[Windows Movie Maker *] +LangSecRef=3023 +Detect=HKCU\Software\Microsoft\MovieMaker +Default=False +FileKey1=%LocalAppData%\Microsoft\Movie Maker|MEDIATAB*.DAT + +[Windows MUICache *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache +RegKey2=HKCU\Software\Microsoft\Windows\Shell\MUICache +RegKey3=HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache + +[Windows Photo Gallery *] +LangSecRef=3023 +Detect=HKCU\Software\Microsoft\Windows Photo Gallery +Default=False +RegKey1=HKCU\Software\Microsoft\Windows Photo Gallery\Library\PreviewAssignment\MRU +RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\Camera|FilenameTemplate +RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\Camera|RootDirectory +RegKey4=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\DestinationMru +RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\OpticalMedia|FilenameTemplate +RegKey6=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\OpticalMedia|RootDirectory +RegKey7=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\Scanner|FilenameTemplate +RegKey8=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\Scanner|RootDirectory + +[Windows Photo Viewer *] +LangSecRef=3025 +DetectFile=%AppData%\Microsoft\Windows Photo Viewer +Default=False +FileKey1=%AppData%\Microsoft\Windows Photo Viewer|*.* + +[Windows Photos *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowsphotos_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\microsoft.windowsphotos_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\BackgroundTransferApi|*.down_data;*.up_meta +FileKey3=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\INet*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey6=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\PRICache|*.* +FileKey8=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\Temp|*.* +FileKey9=%LocalAppData%\Packages\microsoft.windowsphotos_*\LocalState|*.log;*.jpg +FileKey10=%LocalAppData%\Packages\microsoft.windowsphotos_*\LocalState\bici|*.sqm +FileKey11=%LocalAppData%\Packages\microsoft.windowsphotos_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowsphotos_8wekyb3d8bbwe\SearchHisto + +[Windows Registry Recovery *] +LangSecRef=3024 +Detect=HKCU\Software\MiTeC\WRR +Default=False +RegKey1=HKCU\Software\MiTeC\WRR\1.x\dlg_wrr_Find\eFind_Items +RegKey2=HKCU\Software\MiTeC\WRR\1.x\Main\MRUHistory + +[Windows Retail Demo *] +LangSecRef=3025 +DetectFile=%CommonAppData%\Microsoft\Windows\RetailDemo +Default=False +FileKey1=%CommonAppData%\Microsoft\Windows\RetailDemo|*.*|REMOVESELF + +[Windows ShellBags *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +Warning=This will reset folders size, view, icon or position settings to default and remove traces of the folders that do not exist anymore. +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU +RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags +RegKey3=HKCU\Software\Microsoft\Windows\Shell\BagMRU +RegKey4=HKCU\Software\Microsoft\Windows\Shell\Bags +RegKey5=HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU +RegKey6=HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags +ExcludeKey1=REG|HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders +ExcludeKey2=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop +ExcludeKey3=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\AllFolders +ExcludeKey4=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Desktop +ExcludeKey5=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\AllFolders + +[Windows Sidebar *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows Sidebar +Default=False +FileKey1=%LocalAppData%\Microsoft\Windows Sidebar\Cache|*.*|RECURSE + +[Windows Store *] +DetectOS=6.2|6.3 +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\winstore_cw5n1h2txyewy +DetectFile=%LocalAppData%\Packages\winstore_cw5n1h2txyewy +Default=False +FileKey1=%LocalAppData%\Packages\winstore_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\winstore_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\winstore_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\winstore_*\AC\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\winstore_*\LocalCache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\winstore_*\LocalState\Cache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\winstore_*\LocalState\LiveTile|*.*|RECURSE + +[Windows Subsystems *] +LangSecRef=3025 +Detect=HKCU\Software\Microsoft\Windows +Default=False +FileKey1=%CommonAppData%\Microsoft\PlayReady|*.hds +FileKey2=%CommonAppData%\Microsoft\PlayReady\Cache|*.* +FileKey3=%CommonAppData%\Microsoft\RAC\PublishedData|*.log;*.jrs +FileKey4=%CommonAppData%\Microsoft\RAC\StateData|*.log;*.jrs +FileKey5=%CommonAppData%\Microsoft\RAC\Temp|*.* +FileKey6=%CommonAppData%\Microsoft\Windows\DRM|*.log +FileKey7=%CommonAppData%\Microsoft\Windows\DRM\Cache|*.*|RECURSE +FileKey8=%CommonAppData%\Microsoft\Windows\DRM\PreUpgrade|*.log +FileKey9=%CommonAppData%\Microsoft\Windows\Sqm\Manifest|*.bin +FileKey10=%CommonAppData%\Microsoft\Windows\Sqm\Sessions|*.psqm;*.sqm +FileKey11=%LocalAppData%\Microsoft\Windows\PRICache|*.*|RECURSE +FileKey12=%LocalAppData%\Microsoft\Windows\SettingSync\metastore|*.jrs +FileKey13=%LocalAppData%\Microsoft\Windows\SettingSync\remotemetastore\*|*.jrs +FileKey14=%LocalAppData%\VirtualStore\ProgramData\Microsoft\PlayReady|*.hds +FileKey15=%LocalAppData%\VirtualStore\ProgramData\Microsoft\PlayReady\Cache|*.* +FileKey16=%LocalAppData%\VirtualStore\ProgramData\Microsoft\RAC\PublishedData|*.log;*.jrs +FileKey17=%LocalAppData%\VirtualStore\ProgramData\Microsoft\RAC\StateData|*.log;*.jrs +FileKey18=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM|*.log +FileKey19=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\Cache|*.*|RECURSE +FileKey20=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\PreUpgrade|*.log +FileKey21=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\Sqm\Manifest|*.bin +FileKey22=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\Sqm\Sessions|*.psqm;*.sqm +FileKey23=%SystemDrive%\spoolerlogs|spooler.xml +FileKey24=%WinDir%\ehome|PRDMOWrapper.log +FileKey25=%WinDir%\System32|PRDMOWrapper.log +FileKey26=%WinDir%\system32\spool|spooler.xml +FileKey27=%WinDir%\System32\sru|*.*|RECURSE +RegKey1=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication +RegKey2=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication +RegKey3=HKCU\Software\Microsoft\Direct3D\MostRecentApplication +RegKey4=HKLM\Software\Microsoft\Direct3D\MostRecentApplication +RegKey5=HKLM\Software\Microsoft\DirectDraw\MostRecentApplication +RegKey6=HKLM\Software\Microsoft\Windows\CurrentVersion\Setup|Installation Sources +RegKey7=HKLM\Software\Wow6432Node\Microsoft\Direct3D\MostRecentApplication +RegKey8=HKLM\Software\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication + +[Windows Update *] +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\WindowsUpdate +Default=False +FileKey1=%WinDir%\Logs\waasmedic|*.*|RECURSE +FileKey2=%WinDir%\Logs\WindowsUpdate|*.*|RECURSE +FileKey3=%WinDir%\SoftwareDistribution\DataStore\Logs|*.*|RECURSE + +[Windows Washer Backups *] +LangSecRef=3024 +Detect=HKCU\Software\Webroot\Window Washer +Default=False +FileKey1=%AppData%\Webroot\Washer\Backup|*.*|RECURSE + +[Windows XP ARPCache *] +DetectOS=|5.1 +LangSecRef=3025 +Detect=HKLM\Software\Microsoft\Windows +Default=False +Warning=This cleans the Add/Remove Programs cache and will fix very large areas of black gaps in it. Using this will cause Add/Remove Programs to take a very long time to load since it will have to rebuild the cache. +RegKey1=HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache + +[Winemaker Extraordinaire *] +Section=Games +DetectFile=%AppData%\UClick\Winemaker Extraordinaire +Default=False +FileKey1=%AppData%\UClick\Winemaker Extraordinaire|logfile.txt + +[WinGate *] +LangSecRef=3021 +Detect=HKCU\Software\Qbik Software\GateKeeper +DetectFile=%ProgramFiles%\WinGate\WinGate.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinGate|*Log.txt;*.log|RECURSE +FileKey2=%LocalAppData%\VirtualStore\Program Files*\WinGate\Logs\Global|*.idx +FileKey3=%ProgramFiles%\WinGate|*Log.txt;*.log|RECURSE +FileKey4=%ProgramFiles%\WinGate\Logs\Global|*.idx + +[WinHasher *] +LangSecRef=3024 +Detect=HKCU\Software\GPF Comics\WinHasher +Default=False +RegKey1=HKCU\Software\GPF Comics\WinHasher|LastDirectory + +[WinHTTrack *] +LangSecRef=3022 +Detect=HKCU\Software\WinHTTrack Website Copier +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinHTTrack|winhttrack.log +FileKey2=%ProgramFiles%\WinHTTrack|winhttrack.log + +[WinImage *] +LangSecRef=3024 +Detect=HKCU\Software\WinImage +Default=False +RegKey1=HKCU\Software\WinImage|File1 +RegKey2=HKCU\Software\WinImage|File2 +RegKey3=HKCU\Software\WinImage|File3 +RegKey4=HKCU\Software\WinImage|File4 +RegKey5=HKCU\Software\WinImage|File5 +RegKey6=HKCU\Software\WinImage|File6 +RegKey7=HKCU\Software\WinImage|File7 +RegKey8=HKCU\Software\WinImage|File8 +RegKey9=HKCU\Software\WinImage|File9 +RegKey10=HKCU\Software\WinImage|PathExtract + +[WinJS *] +LangSecRef=3031 +Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WinJS.1.0_8wekyb3d8bbwe +Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WinJS.2.0_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.WinJS.*.0_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\PRICache|*.* +FileKey7=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Temp|*.* +FileKey8=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\LocalState\*Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\LocalState\navigationHistory|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\TempState|*.*|RECURSE + +[WinMerge *] +LangSecRef=3024 +Detect=HKCU\Software\Thingamahoochie\WinMerge\Files +Default=False +RegKey1=HKCU\Software\Thingamahoochie\WinMerge\Files\Ext +RegKey2=HKCU\Software\Thingamahoochie\WinMerge\Files\Left +RegKey3=HKCU\Software\Thingamahoochie\WinMerge\Files\Option +RegKey4=HKCU\Software\Thingamahoochie\WinMerge\Files\Right + +[WinMount *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\WinMount\WinMount.exe +Default=False +FileKey1=%AppData%\WinMount|*.dat + +[WinPcap *] +LangSecRef=3022 +Detect=HKLM\Software\WinPcap +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinPcap|*.log +FileKey2=%ProgramFiles%\WinPcap|*.log + +[WinRAR *] +LangSecRef=3024 +Detect=HKCU\Software\WinRAR +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinRAR|*.tmp|RECURSE +FileKey2=%ProgramFiles%\WinRAR|*.tmp|RECURSE +RegKey1=HKCU\Software\WinRAR SFX +RegKey2=HKCU\Software\WinRAR\DialogEditHistory +RegKey3=HKCU\Software\WinRAR\General\Info|CommentFile + +[WinRemote *] +LangSecRef=3021 +DetectFile=%CommonAppData%\Banamalon\WinRemoteService +Default=False +FileKey1=%CommonAppData%\Banamalon\WinRemoteService\log|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Banamalon\WinRemoteService\log|*.* + +[WinSAT Shader Cache *] +DetectOS=|6.2 +LangSecRef=3025 +DetectFile=%WinDir%\Performance\WinSAT +Default=False +FileKey1=%WinDir%\Performance\WinSAT|shadercache*.* + +[WinSetupFromUSB *] +LangSecRef=3024 +DetectFile1=%ProgramFiles%\WinSetupFromUSB +DetectFile2=%SystemDrive%\WinSetupFromUSB +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinSetupFromUSB|*.log|RECURSE +FileKey2=%ProgramFiles%\WinSetupFromUSB|*.log|RECURSE +FileKey3=%SystemDrive%\WinSetupFromUSB|*.log|RECURSE + +[WinTK *] +LangSecRef=3024 +DetectFile=%Documents%\WinTK +Default=False +FileKey1=%Documents%\WinTK|ExLog.txt + +[WinToUSB *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinToUSB_is1 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinToUSB\bin|*.log +FileKey2=%ProgramFiles%\WinToUSB\bin|*.log + +[WinWAP *] +LangSecRef=3022 +Detect=HKCU\Software\Winwap Technologies +Default=False +FileKey1=%UserProfile%\WinWAP Temporary Files|*.* + +[WinX YouTube Downloader *] +LangSecRef=3023 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinX YouTube Downloader_is1 +DetectFile=%ProgramFiles%\Digiarty\WinX_YouTube_Downloader\WinX_YouTube_Downloader.exe +Default=False +FileKey1=%AppData%\Digiarty\WinX YouTube Downloader|*.jpg + +[WinZip MRU *] +LangSecRef=3024 +Detect=HKCU\Software\Nico Mak Computing\WinZip +Default=False +RegKey1=HKCU\Software\Nico Mak Computing\WinZip\Mru + +[WinZip Registry Optimizer *] +LangSecRef=3024 +DetectFile=%AppData%\Nico Mak Computing\WinZip Registry Optimizer +Default=False +FileKey1=%AppData%\Nico Mak Computing\WinZip Registry Optimizer\*|log*.* + +[Wire *] +LangSecRef=3022 +DetectFile=%LocalAppData%\wire +Default=False +FileKey1=%AppData%\Wire\Cache|*.* +FileKey2=%AppData%\Wire\GPUCache|*.* + +[Wirecast *] +LangSecRef=3023 +DetectFile=%AppData%\Wirecast +Default=False +FileKey1=%AppData%\Wirecast|*.txt + +[Wise Care 365 *] +LangSecRef=3024 +Detect=HKLM\Software\WiseCleaner\WiseCare365 +Default=False +FileKey1=%AppData%\Wise Care 365|Errorlog.txt;FailToRemove.dat + +[Wise Video/YouTube Downloader *] +LangSecRef=3023 +Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wise Video Downloader_is1 +Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wise Youtube Downloader_is1 +DetectFile1=%ProgramFiles%\Wise\Wise Video Downloader\WiseDownloader.exe +DetectFile2=%ProgramFiles%\Wise\Wise YouTube Downloader\WiseDownloader.exe +Default=False +FileKey1=%AppData%\Wise * Downloader|DownloadList.ini;FileListConfig.ini +FileKey2=%SystemDrive%|urlinfo.txt +FileKey3=%SystemDrive%\ThumbnailCache|*.* + +[Wistron Corp Launch Manager *] +LangSecRef=3024 +Detect=HKLM\Software\Wistron Corp\Launch Manager +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Launch Manager|*.log +FileKey2=%ProgramFiles%\Launch Manager|*.log + +[WM Recorder *] +LangSecRef=3023 +Detect1=HKCU\Software\WMR10 +Detect2=HKCU\Software\WMR11 +Detect3=HKCU\Software\WMR12 +Detect4=HKCU\Software\WMR13 +Detect5=HKCU\Software\WMR14 +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WM Recorder*|log.txt;urls.txt +FileKey2=%ProgramFiles%\WM Recorder*|log.txt;urls.txt + +[Wolf: MP *] +Section=Games +DetectFile=%LocalAppData%\id Software\WolfMP +Default=False +FileKey1=%LocalAppData%\id Software\WolfMP|*.log|RECURSE + +[WolfQuest *] +Section=Games +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9E6AD6CF-1EFF-43E4-86C4-5C00254C3D8E} +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WolfQuest|*.txt|RECURSE +FileKey2=%ProgramFiles%\WolfQuest|*.txt|RECURSE +ExcludeKey1=FILE|%ProgramFiles%\WolfQuest\|Help.txt + +[Wondershare AllMyTube *] +LangSecRef=3022 +Detect=HKLM\Software\Wondershare\Wondershare AllMyTube +Default=False +FileKey1=%AppData%\Wondershare AllMyTube|*.*|RECURSE +FileKey2=%CommonAppData%\Wondershare AllMyTube\ConvertedLibPic|*.*|RECURSE +FileKey3=%CommonAppData%\Wondershare Application Common Data\Download|*.bak;*.xml +FileKey4=%CommonAppData%\Wondershare Application Common Data\Download\MediaLibPic|*.*|RECURSE +FileKey5=%CommonAppData%\Wondershare Application Common Data\Download\SiteLogo|*.*|RECURSE +FileKey6=%CommonAppData%\Wondershare Application Common Data\Download\TempThumbDir|*.*|RECURSE +FileKey7=%CommonAppData%\Wondershare\AllMyTube|*.bak;*.xml +FileKey8=%ProgramFiles%\Wondershare\AllMyTube\Log|*.*|RECURSE + +[Wondershare dr.fone *] +LangSecRef=3021 +Detect1=HKLM\Software\Wondershare\dr.fone toolkit for Android +Detect2=HKLM\Software\Wondershare\dr.fone toolkit for iOS +DetectFile=%ProgramFiles%\Wondershare\drfone +Default=False +FileKey1=%CommonAppData%\Wondershare\dr.fone\log|*.*|RECURSE +FileKey2=%CommonAppData%\Wondershare\DrFone*\log|*.*|RECURSE +FileKey3=%CommonAppData%\Wondershare\DrFoneiOS\DBCache\NormalMode|*.*|RECURSE +FileKey4=%CommonAppData%\Wondershare\WAF\Log|*.*|RECURSE +FileKey5=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE +FileKey6=%CommonAppData%\Wondershare\WSRoot|*.tmp +FileKey7=%CommonAppData%\Wondershare\WSRoot\Logs|*.*|RECURSE + +[Wondershare Helper Compact *] +LangSecRef=3021 +DetectFile=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact +Default=False +FileKey1=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact|ProductUpdateLists.xml;WSHelper.exe_temp;WSHelperSetup.exe_temp +FileKey2=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact\DATADICT|*.*|RECURSE +FileKey3=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact\Log|*.*|RECURSE +FileKey4=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact\Temp|*.*|RECURSE +FileKey5=%LocalAppData%\VirtualStore\Program Files*\Common Files\Wondershare\Wondershare Helper Compact|ProductUpdateLists.xml;WSHelper.exe_temp;WSHelperSetup.exe_temp +FileKey6=%LocalAppData%\VirtualStore\Program Files*\Common Files\Wondershare\Wondershare Helper Compact\Log|*.*|RECURSE +FileKey7=%LocalAppData%\VirtualStore\Program Files*\Common Files\Wondershare\Wondershare Helper Compact\Temp|*.*|RECURSE +RegKey1=HKLM\Software\Wondershare\Wondershare Helper Compact +RegKey2=HKLM\Software\Wow6432Node\Wondershare\Wondershare Helper Compact + +[Wondershare MobileGo *] +LangSecRef=3021 +Detect=HKCU\Software\Wondershare\MobileGo +DetectFile=%AppData%\Wondershare\MobileGo for iOS +Default=False +FileKey1=%AppData%\se_tmp|*.*|REMOVESELF +FileKey2=%AppData%\Wondershare\*Go*|*.log +FileKey3=%AppData%\Wondershare\DataEraser|*.log +FileKey4=%AppData%\Wondershare\Dr.FoneTool\log|*.log +FileKey5=%AppData%\Wondershare\DrFoneAndroidTool\log|*.log +FileKey6=%AppData%\Wondershare\MirrorGo\ImageCache\ADImage|*.*|RECURSE +FileKey7=%AppData%\Wondershare\MobileGo\DeviceImageCache|*.*|RECURSE +FileKey8=%AppData%\Wondershare\MobileGo\iOSTemp|*.*|REMOVESELF +FileKey9=%AppData%\Wondershare\MobileGo\Logs\DeviceConnection|*.*|RECURSE +FileKey10=%AppData%\Wondershare\MobileTransTool|*.log +FileKey11=%AppData%\Wondershare\WsRoot\Logs|*.*|RECURSE +FileKey12=%CommonAppData%\Wondershare\Dr.FoneTool\Log|*.txt +FileKey13=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE +FileKey14=%ProgramFiles%\Wondershare\MobileGo|*.log + +[Wondershare PDF Editor *] +LangSecRef=3021 +Detect=HKLM\Software\Wondershare\Wondershare PDF Editor +Default=False +FileKey1=%AppData%\Wondershare\PDF Editor|HistoryDatas.dat +FileKey2=%AppData%\Wondershare\PDF Editor\Log|*.log + +[Wondershare SafeEraser *] +LangSecRef=3021 +Detect=HKLM\Software\Wondershare\SafeEraser +Default=False +FileKey1=%AppData%\HMYGSetting|*.*|REMOVESELF +FileKey2=%AppData%\HYXDevPsnList|*.*|REMOVESELF +FileKey3=%AppData%\se_tmp|*.*|REMOVESELF +FileKey4=%AppData%\se_tmp_win|*.*|REMOVESELF +FileKey5=%AppData%\Wondershare\SafeEraser|*.log +FileKey6=%AppData%\Wondershare\SafeEraser\Logs\DeviceConnection|*.*|RECURSE +FileKey7=%AppData%\Wondershare\SafeEraser\Logs\iOSTemp|*.*|RECURSE +FileKey8=%ProgramFiles%\Wondershare\SafeEraser\se_tmp_win|*.*|REMOVESELF +FileKey9=%SystemDrive%\se_tmp|*.*|REMOVESELF + +[Wondershare Video Converter Ultimate *] +LangSecRef=3023 +Detect=HKLM\Software\Wondershare\Wondershare Video Converter Ultimate +Default=False +FileKey1=%CommonAppData%\Wondershare\ProductFeatures\*Logs|*.*|RECURSE +FileKey2=%Documents%\Wondershare MediaServer\log|*.*|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Wondershare Video Converter Ultimate\TempThumbDir|*.*|RECURSE +FileKey4=%ProgramFiles%\Wondershare Video Converter Ultimate\TempThumbDir|*.*|RECURSE + +[Wordweb *] +LangSecRef=3021 +Detect=HKCU\Software\WordWeb +Default=False +FileKey1=%AppData%\WordWeb|History.txt + +[World of Warcraft *] +Section=Games +Detect=HKCU\Software\Blizzard Entertainment\World of Warcraft +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\World of Warcraft\Cache|*.*|REMOVESELF +FileKey2=%LocalAppData%\VirtualStore\Program Files*\World of Warcraft\Errors|*.*|REMOVESELF +FileKey3=%LocalAppData%\VirtualStore\Program Files*\World of Warcraft\Logs|*.log +FileKey4=%ProgramFiles%\World of Warcraft\Cache|*.*|REMOVESELF +FileKey5=%ProgramFiles%\World of Warcraft\Errors|*.*|REMOVESELF +FileKey6=%ProgramFiles%\World of Warcraft\Logs|*.log +FileKey7=%Public%\Games\World of Warcraft\Cache|*.*|REMOVESELF +FileKey8=%Public%\games\World of Warcraft\Errors|*.*|REMOVESELF +FileKey9=%Public%\games\World of Warcraft\Logs|*.log +FileKey10=%SystemDrive%\World of Warcraft\Cache|*.*|REMOVESELF +FileKey11=%SystemDrive%\World of Warcraft\Errors|*.*|REMOVESELF +FileKey12=%SystemDrive%\World of Warcraft\Logs|*.log + +[World of Warcraft Backups *] +Section=Games +Detect=HKCU\Software\Blizzard Entertainment\World of Warcraft +Default=False +Warning=This will delete all your World of Warcraft backup files. You won't be able to restore from them if something goes wrong. +FileKey1=%LocalAppData%\VirtualStore\Program Files*\World of Warcraft|*.bak;*.old|RECURSE +FileKey2=%ProgramFiles%\World of Warcraft|*.bak;*.old|RECURSE +FileKey3=%Public%\games\World of Warcraft|*.bak;*.old|RECURSE +FileKey4=%SystemDrive%\World of Warcraft|*.bak;*.old|RECURSE + +[WorldWide Telescope *] +LangSecRef=3021 +Detect=HKCU\Software\Classes\WorldWideTelescope.wtml +Default=False +FileKey1=%LocalAppData%\Microsoft\WorldWideTelescope\dem|*.*|RECURSE +FileKey2=%LocalAppData%\Microsoft\WorldWideTelescope\Imagery|*.*|RECURSE +FileKey3=%LocalAppData%\Microsoft\WorldWideTelescope\tourcache|*.*|RECURSE + +[Wowhead Client *] +Section=Games +Detect=HKCU\Software\Wowhead\WowHead Client +Default=False +FileKey1=%CommonAppData%\wowhead\wowhead client\cache|*.*|REMOVESELF +FileKey2=%CommonAppData%\wowhead\wowhead client\log|*.*|REMOVESELF +FileKey3=%LocalAppData%\VirtualStore\ProgramData\wowhead\wowhead client\cache|*.*|REMOVESELF +FileKey4=%LocalAppData%\VirtualStore\ProgramData\wowhead\wowhead client\log|*.*|REMOVESELF +RegKey1=HKCU\Software\Wowhead\WowHead Client|Statistics + +[WRAL Desktop Alert *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\WRAL Desktop Alert +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\WRAL Desktop Alert|*.log +FileKey2=%ProgramFiles%\WRAL Desktop Alert|*.log + +[WS FTP Pro *] +LangSecRef=3022 +Detect=HKCU\Software\Ipswitch\WS_FTP +Default=False +FileKey1=%AppData%\Ipswitch\WS_FTP\Logs|*.* + +[Wunderlist *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Wunderlist +Default=False +FileKey1=%AppData%\Titanium\appdata\com.wunderkinder.wunderlistdesktop|*.log + +[X-Chat 2 *] +LangSecRef=3022 +DetectFile=%AppData%\X-Chat 2 +Default=False +Warning=This removes Chat Scrollback and Logs. +FileKey1=%AppData%\X-Chat 2\scrollback|*.*|REMOVESELF +FileKey2=%AppData%\X-Chat 2\xchatlogs|*.*|REMOVESELF + +[X-Cleaner *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\X-Cleaner +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\X-Cleaner|XCL_LOG.txt +FileKey2=%ProgramFiles%\X-Cleaner|XCL_LOG.txt + +[X-NetStat *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\X-NetStat Professional\xns5.exe +Default=False +FileKey1=%AppData%\X-NetStat\Logs|*.* + +[Xara Photo & Graphic Designer *] +LangSecRef=3023 +Detect=HKCU\Software\Xara\Xtreme_SE +Default=False +FileKey1=%LocalAppData%\Xara\Xtreme\9.2\Backups|*.*|RECURSE +FileKey2=%LocalAppData%\Xara\Xtreme_SE\6.1\Backups|*.txt +RegKey1=HKCU\Software\Xara\Xtreme\9.2\Options\Recent File List +RegKey2=HKCU\Software\Xara\Xtreme_SE\6.1\Options\Recent File List +RegKey3=HKCU\Software\Xara\Xtreme_SE\6.1\Workspace + +[Xara WebDesigner Backups *] +LangSecRef=3024 +Detect=HKCU\Software\Xara\WebDesigner +Default=False +FileKey1=%LocalAppData%\Xara\WebDesigner\*\Backups|*.*|RECURSE + +[Xara WebDesigner Session *] +LangSecRef=3024 +Detect=HKCU\Software\Xara\WebDesigner +Default=False +RegKey1=HKCU\Software\Xara\WebDesigner\8.0\Workspace\MDI + +[Xbox *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxApp_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalCache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\*Cache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\DiagOutputDir|*.txt +FileKey9=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log +FileKey10=%LocalAppData%\Packages\Microsoft.XboxApp_*\TempState|*.*|RECURSE + +[Xbox Game Overlay *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxGameOverlay_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalCache\Cache|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalState\Cache|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalState\DiagOutputDir|*.txt +FileKey7=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\TempState|*.*|RECURSE + +[Xbox Identity Provider *] +DetectOS=10.0| +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INet*|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0*|*.log +FileKey3=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0*\UsageLogs|*.*|RECURSE +FileKey5=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Temp|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\TokenBroker\Cache|*.*|RECURSE +FileKey7=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalCache|*.*|RECURSE +FileKey8=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalState\Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\TempState|*.*|RECURSE + +[Xbox LIVE Games *] +LangSecRef=3031 +Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxLIVEGames_8wekyb3d8bbwe +DetectFile=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_8wekyb3d8bbwe +Default=False +FileKey1=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\AppCache|*.*|RECURSE +FileKey2=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\INet*|*.*|RECURSE +FileKey3=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE +FileKey4=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\Microsoft\CryptnetUrlCache\*|*.* +FileKey5=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE +FileKey6=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\PRICache|*.* +FileKey7=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\Temp|*.* +FileKey8=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\LocalState\*Cache|*.*|RECURSE +FileKey9=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\LocalState\navigationHistory|*.*|RECURSE +FileKey10=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\LocalState\PlayReady|*.*|RECURSE +FileKey11=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\TempState|*.*|RECURSE +RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxLIVEGames_8wekyb3d8bbwe\SearchHistory + +[Xenocode Sandbox *] +LangSecRef=3021 +Detect=HKCU\Software\Xenocode\SandboxCache +Default=False +FileKey1=%LocalAppData%\Xenocode\Sandbox|*.*|REMOVESELF +FileKey2=%WinDir%\XSxS|*.*|REMOVESELF +RegKey1=HKCU\Software\Xenocode\SandboxCache + +[Xerox Printer Driver *] +LangSecRef=3021 +DetectFile=%CommonAppData%\Xerox\PrinterDriver +Default=False +FileKey1=%CommonAppData%\Xerox\PrinterDriver|*.tmp|RECURSE +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Xerox\PrinterDriver|*.tmp|RECURSE + +[Xfire *] +Section=Games +Detect=HKLM\Software\Xfire +Default=False +Warning=Selecting this will delete any screen shots and videos you have taken, make sure you upload or move any you want to keep so they're not deleted. +FileKey1=%CommonAppData%\Xfire|*.bak +FileKey2=%CommonAppData%\xfire\videos|*.* +FileKey3=%LocalAppData%\VirtualStore\ProgramData\Xfire|*.bak +FileKey4=%LocalAppData%\VirtualStore\ProgramData\xfire\videos|*.* + +[Xfire Updates *] +Section=Games +Detect=HKLM\Software\Xfire +Default=False +FileKey1=%CommonAppData%\Xfire\downloads|*.zip +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Xfire\downloads|*.zip + +[Xilisoft AVI to DVD Converter *] +LangSecRef=3023 +DetectFile=%LocalAppData%\Xilisoft\AVI to DVD Converter +Default=False +FileKey1=%LocalAppData%\Xilisoft\AVI to DVD Converter|log_testing.txt + +[Xmarks *] +LangSecRef=3024 +Detect=HKCU\Software\Xmarks +Default=False +FileKey1=%LocalAppData%\Xmarks|xmarks.log + +[XMind *] +LangSecRef=3021 +DetectFile=%AppData%\XMind +Default=False +FileKey1=%AppData%\XMind|*.log|RECURSE + +[XMLViewer *] +LangSecRef=3024 +Detect=HKCU\Software\MiTeC\XMLViewer +Default=False +RegKey1=HKCU\Software\MiTeC\XMLViewer\4.x\wnd_xmlv_Main\Twnd_xmlv_Main.MRUManager + +[XN Resource Editor *] +LangSecRef=3024 +Detect=HKCU\Software\Woozle\XN Resource Editor +Default=False +RegKey1=HKCU\Software\Woozle\XN Resource Editor\Recent Files + +[XnView *] +LangSecRef=3023 +Detect1=HKCU\Software\XnView +Detect2=HKCU\Software\XnView\XnViewMP +Detect3=HKLM\Software\XnView +Default=False +FileKey1=%AppData%\XnView\cache|*.db +FileKey2=%AppData%\XnViewMP|*.db;category.bak +FileKey3=%LocalAppData%\VirtualStore\Program Files*\XnViewMP|category.bak;*.db +FileKey4=%ProgramFiles%\XnViewMP|category.bak;*.db + +[XPhone *] +LangSecRef=3021 +Detect=HKCU\Software\C4B\Log +Default=False +FileKey1=%LocalAppData%\C4B\Log|*.* + +[Xplorer2 *] +LangSecRef=3024 +Detect=HKCU\Software\ZabaraKatranemia Plc\xplorer2\MainFrame Settings +Default=False +RegKey1=HKCU\Software\ZabaraKatranemia Plc\xplorer2\MainFrame Settings\Folder History + +[XPort 360 *] +LangSecRef=3021 +DetectFile=%AppData%\Datel\XPort 360 +Default=False +FileKey1=%AppData%\Datel\XPort 360\Temp|*.*|REMOVESELF + +[XPressUpdate *] +LangSecRef=3023 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\XPressUpdate.exe +Default=False +FileKey1=%CommonProgramFiles%\XpressUpdate|*.log;*old +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Common Files\XpressUpdate|*.log;*old + +[Xsplit *] +LangSecRef=3023 +Detect=HKLM\Software\Splitmedialabs\XSplit +Default=False +FileKey1=%AppData%\SplitMediaLabs\XSplit|*.log|RECURSE +FileKey2=%CommonAppData%\SplitMediaLabs\XSplit\LocalStore\Temp|*.* +FileKey3=%CommonAppData%\SplitMediaLabs\XSplit\Temp|*.* +FileKey4=%LocalAppData%\SplitMediaLabs\XSplit\*|bwtestlogs.txt +FileKey5=%LocalAppData%\VirtualStore\ProgramData\SplitMediaLabs\XSplit\LocalStore\Temp|*.* +FileKey6=%LocalAppData%\VirtualStore\ProgramData\SplitMediaLabs\XSplit\Temp|*.* + +[XviD *] +LangSecRef=3023 +Detect=HKCU\Software\GNU\Xvid +Default=False +RegKey1=HKCU\Software\GNU\Xvid|stats + +[XWidget *] +LangSecRef=3021 +DetectFile=%Documents%\XWidget +Default=False +FileKey1=%Documents%\XWidget\Cache|*.*|RECURSE + +[XWidget Backup *] +LangSecRef=3021 +DetectFile=%Documents%\XWidget +Default=False +FileKey1=%Documents%\XWidget\Backup|*.*|RECURSE + +[Yahoo Autosync *] +LangSecRef=3022 +Detect=HKCU\Software\Yahoo!\Autosync for Yahoo! +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Yahoo!\Yahoo! Autosync\Logs|*.* +FileKey2=%ProgramFiles%\Yahoo!\Yahoo! Autosync\Logs|*.* + +[Yahoo Companion *] +LangSecRef=3022 +DetectFile=%CommonAppData%\Yahoo! Companion +Default=False +FileKey1=%CommonAppData%\Yahoo! Companion\Cache|*.* +FileKey2=%LocalAppData%\VirtualStore\ProgramData\Yahoo! Companion\Cache|*.* + +[Yahoo Messenger *] +LangSecRef=3022 +Detect=HKCU\Software\Yahoo\Messenger +Default=False +FileKey1=%LocalAppData%\yahoomessenger|SquirrelSetup.log + +[Yahoo Messenger Cache *] +LangSecRef=3022 +Detect=HKCU\Software\Yahoo\Messenger +Default=False +Warning=You will need to reload the App next time its started. Select View, Reload from the menu. +FileKey1=%AppData%\Yahoo Messenger\Cache|*.*|RECURSE + +[YPOPs *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\YPOPs\ypops.exe +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\YPOPs|ypops.log +FileKey2=%ProgramFiles%\YPOPs|ypops.log + +[yWriter5 *] +LangSecRef=3021 +DetectFile=%AppData%\Spacejock Software\yWriter5 +Default=False +FileKey1=%AppData%\Spacejock Software\yWriter5|log.txt +FileKey2=%Documents%\Logs|*.txt + +[Zemana AntiMalware Reports *] +LangSecRef=3024 +Detect1=HKCU\Software\Zemana\AntiMalware +Detect2=HKLM\Software\Zemana\AntiMalware +Default=False +FileKey1=%LocalAppData%\Zemana\Zemana AntiMalware\reports|*.txt + +[Zend Studio 10 *] +LangSecRef=3021 +Detect=HKCU\Software\Zend\ZendStudio +Default=False +FileKey1=%LocalAppData%\VirtualStore\Program Files*\Zend\Zend Studio 10.0.0|*.html +FileKey2=%LocalAppData%\VirtualStore\Program Files*\Zend\Zend Studio 10.0.0|*.log|RECURSE +FileKey3=%LocalAppData%\VirtualStore\Program Files*\Zend\Zend Studio 10.0.0\docs|*.txt|REMOVESELF +FileKey4=%LocalAppData%\VirtualStore\Program Files*\Zend\Zend Studio 10.0.0\features|*.html|RECURSE +FileKey5=%ProgramFiles%\Zend\Zend Studio 10.0.0|*.html +FileKey6=%ProgramFiles%\Zend\Zend Studio 10.0.0|*.log|RECURSE +FileKey7=%ProgramFiles%\Zend\Zend Studio 10.0.0\docs|*.txt|REMOVESELF +FileKey8=%ProgramFiles%\Zend\Zend Studio 10.0.0\features|*.html|RECURSE + +[Zer0 *] +LangSecRef=3024 +Detect=HKCU\Software\KC Softwares\Zer0 +Default=False +FileKey1=%AppData%\KC Softwares\Zer0|*.log + +[Zimbra Desktop *] +LangSecRef=3022 +Detect=HKCU\Software\Zimbra +Default=False +FileKey1=%LocalAppData%\Zimbra\Zimbra Desktop\data\*log|*.* +FileKey2=%LocalAppData%\Zimbra\Zimbra Desktop\data\tmp\diskcache|*.*|RECURSE + +[ZipGenius *] +LangSecRef=3024 +Detect=HKCU\Software\M.Dev Software\ZG5 +Default=False +FileKey1=%AppData%\ZipGenius|mru.dat +RegKey1=HKCU\Software\M.Dev Software\ZG5\MRU Items + +[ZoneAlarm Internet *] +LangSecRef=3021 +Detect=HKLM\Software\Zone Labs\ZoneAlarm +Default=False +FileKey1=%WinDir%\Internet Logs|*.dmp;*.log;*.tmp;*.zip + +[ZoneIDTrimmer *] +LangSecRef=3021 +Detect=HKLM\Software\Gasanov.net\ZoneIDTrimmer +DetectFile=%ProgramFiles%\Gasanov.net\ZoneIDTrimmer\ZoneIDTrimmer.Tool.exe +Default=False +FileKey1=%AppData%\ZoneIDTrimmer\Logs|ZoneIDTrimmer.log + +[Zoner Photo Studio *] +LangSecRef=3022 +Detect1=HKCU\Software\ZONER\Zoner Photo Studio 15 +Detect2=HKCU\Software\ZONER\Zoner Photo Studio 16 +Detect3=HKCU\Software\ZONER\Zoner Photo Studio 18 +DetectFile=%LocalAppData%\Zoner\ZPS 14 +Default=False +FileKey1=%LocalAppData%\Zoner\ZPS *\Cache|*.*|RECURSE +FileKey2=%LocalAppData%\Zoner\ZPS *\CEF|*.log +FileKey3=%LocalAppData%\Zoner\ZPS *\ZPSCache.dat|*.* +FileKey4=%Pictures%|*.uid-zps + +[Zoner Photo Studio AutoSave *] +LangSecRef=3023 +Detect1=HKCU\Software\ZONER\Zoner Photo Studio 15 +Detect2=HKCU\Software\ZONER\Zoner Photo Studio 16 +Detect3=HKCU\Software\ZONER\Zoner Photo Studio 18 +Default=False +FileKey1=%LocalAppData%\Zoner\OriginalsRepository|*.JPG.info;*.JPG.original|RECURSE + +[Zune Transcoded Files Cache *] +LangSecRef=3023 +Detect=HKCU\Software\Microsoft\Zune +Default=False +FileKey1=%LocalAppData%\Microsoft\Zune\Transcoded Files Cache|*.* + +[Zuse *] +LangSecRef=3023 +DetectFile=%AppData%\Zuse +Default=False +FileKey1=%AppData%\Zuse\logs|*.* + +[ZX32 ZX Spectrum Emulator v1.03 *] +LangSecRef=3021 +Detect=HKCU\Software\VK\zx32\1.03 +Default=False +RegKey1=HKCU\Software\VK\zx32\1.03\FileMRU + +[Zynga Games *] +Section=Games +DetectFile=%LocalAppData%\Zynga +Default=False +FileKey1=%LocalAppData%\Zynga\Logs|*.*|RECURSE