wapt-ccleaner/winapp2.ini

19425 lines
797 KiB
INI
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

; Version: 181209
; # of entries: 2,051
;
; Winapp2 is fully licensed under the CC-BY-SA-4.0 license agreement. Please refer to our license agreement before using Winapp2: https://github.com/MoscaDotTo/Winapp2/blob/master/License.md
; If you plan on modifying, distributing, and/or hosting Winapp2 for your own program or website, please ask first.
;
; You can get the latest Winapp2 here: https://github.com/MoscaDotTo/Winapp2
; Any contributions are appreciated. Please refer to our readme to learn to make your own entries here: https://github.com/MoscaDotTo/Winapp2/blob/master/README.md
; Is CCleaner taking too long to load with Winapp2? Then download our Winapp2ool and use the trim function to remove unneeded entries in Winapp2. https://github.com/MoscaDotTo/Winapp2/blob/master/Tools/beta/winapp2ool.exe
;
; Chrome/Chromium based browsers.
[Application Cache *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\Application Cache|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\Application Cache|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Application Cache|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Application Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\Application Cache|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Application Cache|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\Application Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\Application Cache|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Application Cache|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Application Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Application Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Application Cache|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\Application Cache|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Application Cache|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Application Cache|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\Application Cache|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\Application Cache|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\Application Cache|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\Application Cache|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Application Cache|*.*|RECURSE
[ART *]
LangSecRef=3029
DetectFile=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%CommonProgramFiles%\Microsoft\ART\Backup\Google Chrome\*|*.tmp|RECURSE
FileKey2=%CommonProgramFiles%\Microsoft\ART\Backup\Google Chrome\*|Preferences.bak
[Backup *]
LangSecRef=3029
DetectFile=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%LocalAppData%\Google\Chrome*\Application|old_chrome.exe
FileKey2=%ProgramFiles%\Google\Chrome*\Application|old_chrome.exe
[Blob Storage *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\blob_storage|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\blob_storage|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\blob_storage|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\blob_storage|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\blob_storage|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\blob_storage|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\blob_storage|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\blob_storage|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\blob_storage|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\blob_storage|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\blob_storage|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\blob_storage|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\blob_storage|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\blob_storage|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\blob_storage|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\blob_storage|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\blob_storage|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\blob_storage|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\blob_storage|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\blob_storage|*.*|RECURSE
[Bookmarks Backup *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave|*Bookmarks.bak
FileKey2=%AppData%\Opera Software\Opera*|*Bookmarks.bak
FileKey3=%LocalAppData%\7Star\7Star\User Data\*|*Bookmarks.bak
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|*Bookmarks.bak
FileKey5=%LocalAppData%\Amigo\User Data\*|*Bookmarks.bak
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|*Bookmarks.bak
FileKey7=%LocalAppData%\CentBrowser\User Data\*|*Bookmarks.bak
FileKey8=%LocalAppData%\Chromium\User Data\*|*Bookmarks.bak
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|*Bookmarks.bak
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|*Bookmarks.bak
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|*Bookmarks.bak
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|*Bookmarks.bak
FileKey13=%LocalAppData%\Flock\User Data\*|*Bookmarks.bak
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|*Bookmarks.bak
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|*Bookmarks.bak
FileKey16=%LocalAppData%\RockMelt\User Data\*|*Bookmarks.bak
FileKey17=%LocalAppData%\Slimjet\User Data\*|*Bookmarks.bak
FileKey18=%LocalAppData%\Torch\User Data\*|*Bookmarks.bak
FileKey19=%LocalAppData%\Vivaldi\User Data\*|*Bookmarks.bak
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|*Bookmarks.bak
[Bookmarks Icons *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
Warning=This will delete all the icons of your bookmarks. The icons will be rebuilt as websites are manually re-visited.
FileKey1=%AppData%\brave|Favicons
FileKey2=%AppData%\Opera Software\Opera*|Favicons
FileKey3=%LocalAppData%\7Star\7Star\User Data\*|Favicons
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|Favicons
FileKey5=%LocalAppData%\Amigo\User Data\*|Favicons
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|Favicons
FileKey7=%LocalAppData%\CentBrowser\User Data\*|Favicons
FileKey8=%LocalAppData%\Chromium\User Data\*|Favicons
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|Favicons
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|Favicons
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|Favicons
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|Favicons
FileKey13=%LocalAppData%\Flock\User Data\*|Favicons
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|Favicons
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|Favicons
FileKey16=%LocalAppData%\RockMelt\User Data\*|Favicons
FileKey17=%LocalAppData%\Slimjet\User Data\*|Favicons
FileKey18=%LocalAppData%\Torch\User Data\*|Favicons
FileKey19=%LocalAppData%\Vivaldi\User Data\*|Favicons
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|Favicons
[Browser Exit Codes *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\Amigo
Detect3=HKCU\Software\BraveSoftware\Brave-Browser
Detect4=HKCU\Software\CentBrowser
Detect5=HKCU\Software\Chromium\PreferenceMACs
Detect6=HKCU\Software\CocCoc\Browser
Detect7=HKCU\Software\Comodo\Dragon
Detect8=HKCU\Software\Epic Privacy Browser
Detect9=HKCU\Software\Slimjet
Detect10=HKCU\Software\Torch
Detect11=HKCU\Software\Vivaldi
Detect12=HKCU\Software\Yandex\YandexBrowser
DetectFile=%LocalAppData%\Google\Chrome*
Default=False
RegKey1=HKCU\Software\7Star\7Star\BrowserExitCodes
RegKey2=HKCU\Software\Amigo\BrowserExitCodes
RegKey3=HKCU\Software\BraveSoftware\Brave-Browser\BrowserExitCodes
RegKey4=HKCU\Software\CentBrowser\BrowserExitCodes
RegKey5=HKCU\Software\Chromium\BrowserExitCodes
RegKey6=HKCU\Software\CocCoc\Browser\BrowserExitCodes
RegKey7=HKCU\Software\Comodo\Dragon\BrowserExitCodes
RegKey8=HKCU\Software\Epic Privacy Browser\BrowserExitCodes
RegKey9=HKCU\Software\Google\Chrome SxS\BrowserExitCodes
RegKey10=HKCU\Software\Google\Chrome\BrowserExitCodes
RegKey11=HKCU\Software\Slimjet\BrowserExitCodes
RegKey12=HKCU\Software\Torch\BrowserExitCodes
RegKey13=HKCU\Software\Vivaldi\BrowserExitCodes
RegKey14=HKCU\Software\Yandex\YandexBrowser\BrowserExitCodes
[BrowserMetrics *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave|BrowserMetrics-spare.pma
FileKey2=%AppData%\brave\BrowserMetrics|*.*|RECURSE
FileKey3=%AppData%\Opera Software\Opera*|BrowserMetrics-spare.pma
FileKey4=%AppData%\Opera Software\Opera*\BrowserMetrics|*.*|RECURSE
FileKey5=%LocalAppData%\7Star\7Star\User Data|BrowserMetrics-spare.pma
FileKey6=%LocalAppData%\7Star\7Star\User Data\BrowserMetrics|*.*|RECURSE
FileKey7=%LocalAppData%\360Browser\Browser\User Data|BrowserMetrics-spare.pma
FileKey8=%LocalAppData%\360Browser\Browser\User Data\BrowserMetrics|*.*|RECURSE
FileKey9=%LocalAppData%\Amigo\User Data|BrowserMetrics-spare.pma
FileKey10=%LocalAppData%\Amigo\User Data\BrowserMetrics|*.*|RECURSE
FileKey11=%LocalAppData%\BraveSoftware\Brave-Browser\User Data|BrowserMetrics-spare.pma
FileKey12=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\BrowserMetrics|*.*|RECURSE
FileKey13=%LocalAppData%\CentBrowser\User Data|BrowserMetrics-spare.pma
FileKey14=%LocalAppData%\CentBrowser\User Data\BrowserMetrics|*.*|RECURSE
FileKey15=%LocalAppData%\Chromium\User Data|BrowserMetrics-spare.pma
FileKey16=%LocalAppData%\Chromium\User Data\BrowserMetrics|*.*|RECURSE
FileKey17=%LocalAppData%\CocCoc\Browser\User Data|BrowserMetrics-spare.pma
FileKey18=%LocalAppData%\CocCoc\Browser\User Data\BrowserMetrics|*.*|RECURSE
FileKey19=%LocalAppData%\Comodo\Dragon\User Data|BrowserMetrics-spare.pma
FileKey20=%LocalAppData%\Comodo\Dragon\User Data\BrowserMetrics|*.*|RECURSE
FileKey21=%LocalAppData%\Coowon\Coowon\User Data|BrowserMetrics-spare.pma
FileKey22=%LocalAppData%\Coowon\Coowon\User Data\BrowserMetrics|*.*|RECURSE
FileKey23=%LocalAppData%\Epic Privacy Browser\User Data|BrowserMetrics-spare.pma
FileKey24=%LocalAppData%\Epic Privacy Browser\User Data\BrowserMetrics|*.*|RECURSE
FileKey25=%LocalAppData%\Flock\User Data|BrowserMetrics-spare.pma
FileKey26=%LocalAppData%\Flock\User Data\BrowserMetrics|*.*|RECURSE
FileKey27=%LocalAppData%\Google\Chrome*\User Data|BrowserMetrics-spare.pma
FileKey28=%LocalAppData%\Google\Chrome*\User Data\BrowserMetrics|*.*|RECURSE
FileKey29=%LocalAppData%\MapleStudio\ChromePlus\User Data|BrowserMetrics-spare.pma
FileKey30=%LocalAppData%\MapleStudio\ChromePlus\User Data\BrowserMetrics|*.*|RECURSE
FileKey31=%LocalAppData%\RockMelt\User Data|BrowserMetrics-spare.pma
FileKey32=%LocalAppData%\RockMelt\User Data\BrowserMetrics|*.*|RECURSE
FileKey33=%LocalAppData%\Slimjet\User Data|BrowserMetrics-spare.pma
FileKey34=%LocalAppData%\Slimjet\User Data\BrowserMetrics|*.*|RECURSE
FileKey35=%LocalAppData%\Torch\User Data|BrowserMetrics-spare.pma
FileKey36=%LocalAppData%\Torch\User Data\BrowserMetrics|*.*|RECURSE
FileKey37=%LocalAppData%\Vivaldi\User Data|BrowserMetrics-spare.pma
FileKey38=%LocalAppData%\Vivaldi\User Data\BrowserMetrics|*.*|RECURSE
FileKey39=%LocalAppData%\Yandex\YandexBrowser\User Data|BrowserMetrics-spare.pma
FileKey40=%LocalAppData%\Yandex\YandexBrowser\User Data\BrowserMetrics|*.*|RECURSE
[Chrome Temps *]
LangSecRef=3029
DetectFile=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%ProgramFiles%\Google\Chrome*\Temp|*.*|RECURSE
[Crash Reports *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\Crashpad\reports|*.*
FileKey2=%AppData%\Opera Software\Opera*\Crash Reports\reports|*.*
FileKey3=%LocalAppData%\7Star\7Star\User Data\Crashpad\reports|*.*
FileKey4=%LocalAppData%\360Browser\Browser\User Data\Crashpad\reports|*.*
FileKey5=%LocalAppData%\Amigo\User Data\Crashpad\reports|*.*
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\Crashpad\reports|*.*
FileKey7=%LocalAppData%\CentBrowser\User Data\Crashpad\reports|*.*
FileKey8=%LocalAppData%\Chromium\User Data\Crashpad\reports|*.*
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\Crashpad\reports|*.*
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\Crashpad\reports|*.*
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\Crashpad\reports|*.*
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\Crashpad\reports|*.*
FileKey13=%LocalAppData%\Flock\User Data\Crashpad\reports|*.*
FileKey14=%LocalAppData%\Google\Chrome*\User Data\Crashpad\reports|*.*
FileKey15=%LocalAppData%\Google\CrashReports|*.*
FileKey16=%LocalAppData%\MapleStudio\ChromePlus\User Data\Crashpad\reports|*.*
FileKey17=%LocalAppData%\RockMelt\User Data\Crashpad\reports|*.*
FileKey18=%LocalAppData%\Slimjet\User Data\Crashpad\reports|*.*
FileKey19=%LocalAppData%\Torch\User Data\Crashpad\reports|*.*
FileKey20=%LocalAppData%\Vivaldi\User Data\Crashpad\reports|*.*
FileKey21=%LocalAppData%\Yandex\YandexBrowser\User Data\Crashpad\reports|*.*
[Data Reduction Proxy *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\data_reduction_proxy_leveldb|*.*|RECURSE
[Extensions Databases *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\IndexedDB|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\IndexedDB|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\IndexedDB|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\IndexedDB|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\IndexedDB|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\IndexedDB|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\IndexedDB|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\IndexedDB|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\IndexedDB|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\IndexedDB|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\IndexedDB|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\IndexedDB|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\IndexedDB|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\IndexedDB|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\IndexedDB|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\IndexedDB|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\IndexedDB|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\IndexedDB|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\IndexedDB|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\IndexedDB|*.*|RECURSE
[Extensions State *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\Extension State|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\Extension State|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Extension State|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Extension State|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\Extension State|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Extension State|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\Extension State|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\Extension State|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Extension State|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Extension State|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Extension State|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Extension State|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\Extension State|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Extension State|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Extension State|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\Extension State|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\Extension State|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\Extension State|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\Extension State|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Extension State|*.*|RECURSE
[FlashPlayer AssetCache *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache|*.*|RECURSE
[FlashPlayer SharedObjects *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects|*.*|RECURSE
ExcludeKey1=FILE|%AppData%\brave\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey2=FILE|%AppData%\Opera Software\Opera*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey3=FILE|%LocalAppData%\7Star\7Star\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey4=FILE|%LocalAppData%\360Browser\Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey5=FILE|%LocalAppData%\Amigo\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey6=FILE|%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey7=FILE|%LocalAppData%\CentBrowser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey8=FILE|%LocalAppData%\Chromium\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey9=FILE|%LocalAppData%\CocCoc\Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey10=FILE|%LocalAppData%\Comodo\Dragon\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey11=FILE|%LocalAppData%\Coowon\Coowon\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey12=FILE|%LocalAppData%\Epic Privacy Browser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey13=FILE|%LocalAppData%\Flock\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey14=FILE|%LocalAppData%\Google\Chrome*\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey15=FILE|%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey16=FILE|%LocalAppData%\RockMelt\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey17=FILE|%LocalAppData%\Slimjet\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey18=FILE|%LocalAppData%\Torch\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey19=FILE|%LocalAppData%\Vivaldi\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
ExcludeKey20=FILE|%LocalAppData%\Yandex\YandexBrowser\User Data\*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com\support\flashplayer\sys\|settings.sol
[Google Cloud Messaging *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\GCM Store|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\GCM Store|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\GCM Store|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\GCM Store|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\GCM Store|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\GCM Store|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\GCM Store|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\GCM Store|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\GCM Store|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\GCM Store|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\GCM Store|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\GCM Store|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\GCM Store|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\GCM Store|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\GCM Store|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\GCM Store|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\GCM Store|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\GCM Store|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\GCM Store|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\GCM Store|*.*|RECURSE
[GPU Cache *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\GPUCache|*.*
FileKey2=%AppData%\Opera Software\Opera*\GPUCache|*.*
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\GPUCache|*.*
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\GPUCache|*.*
FileKey5=%LocalAppData%\Amigo\User Data\*\GPUCache|*.*
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\GPUCache|*.*
FileKey7=%LocalAppData%\CentBrowser\User Data\*\GPUCache|*.*
FileKey8=%LocalAppData%\Chromium\User Data\*\GPUCache|*.*
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\GPUCache|*.*
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\GPUCache|*.*
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\GPUCache|*.*
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\GPUCache|*.*
FileKey13=%LocalAppData%\Flock\User Data\*\GPUCache|*.*
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\GPUCache|*.*
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\GPUCache|*.*
FileKey16=%LocalAppData%\RockMelt\User Data\*\GPUCache|*.*
FileKey17=%LocalAppData%\Slimjet\User Data\*\GPUCache|*.*
FileKey18=%LocalAppData%\Torch\User Data\*\GPUCache|*.*
FileKey19=%LocalAppData%\Vivaldi\User Data\*\GPUCache|*.*
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\GPUCache|*.*
[HTML5 Storage *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\File System|*.*|REMOVESELF
FileKey2=%AppData%\Opera Software\Opera*\File System|*.*|REMOVESELF
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\File System|*.*|REMOVESELF
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\File System|*.*|REMOVESELF
FileKey5=%LocalAppData%\Amigo\User Data\*\File System|*.*|REMOVESELF
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\File System|*.*|REMOVESELF
FileKey7=%LocalAppData%\CentBrowser\User Data\*\File System|*.*|REMOVESELF
FileKey8=%LocalAppData%\Chromium\User Data\*\File System|*.*|REMOVESELF
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\File System|*.*|REMOVESELF
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\File System|*.*|REMOVESELF
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\File System|*.*|REMOVESELF
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\File System|*.*|REMOVESELF
FileKey13=%LocalAppData%\Flock\User Data\*\File System|*.*|REMOVESELF
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\File System|*.*|REMOVESELF
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\File System|*.*|REMOVESELF
FileKey16=%LocalAppData%\RockMelt\User Data\*\File System|*.*|REMOVESELF
FileKey17=%LocalAppData%\Slimjet\User Data\*\File System|*.*|REMOVESELF
FileKey18=%LocalAppData%\Torch\User Data\*\File System|*.*|REMOVESELF
FileKey19=%LocalAppData%\Vivaldi\User Data\*\File System|*.*|REMOVESELF
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\File System|*.*|REMOVESELF
[Internet Cache *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey2=%AppData%\Opera Software\Opera*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey3=%LocalAppData%\7Star\7Star\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey5=%LocalAppData%\Amigo\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey7=%LocalAppData%\CentBrowser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey8=%LocalAppData%\Chromium\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey13=%LocalAppData%\Flock\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey16=%LocalAppData%\RockMelt\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey17=%LocalAppData%\Slimjet\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey18=%LocalAppData%\Torch\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey19=%LocalAppData%\Vivaldi\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|*.ldb;*.log;CURRENT;LOCK;MANIFEST-*;Network Persistent State;Origin Bound Certs
[Internet History *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave|History
FileKey2=%AppData%\Opera Software\Opera*|History
FileKey3=%LocalAppData%\7Star\7Star\User Data\*|History
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|History
FileKey5=%LocalAppData%\Amigo\User Data\*|History
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|History
FileKey7=%LocalAppData%\CentBrowser\User Data\*|History
FileKey8=%LocalAppData%\Chromium\User Data\*|History
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|History
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|History
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|History
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|History
FileKey13=%LocalAppData%\Flock\User Data\*|History
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|History
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|History
FileKey16=%LocalAppData%\RockMelt\User Data\*|History
FileKey17=%LocalAppData%\Slimjet\User Data\*|History
FileKey18=%LocalAppData%\Torch\User Data\*|History
FileKey19=%LocalAppData%\Vivaldi\User Data\*|History
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|History
[Jump List Icons *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\JumpListIcons*|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\JumpListIcons*|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\JumpListIcons*|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\JumpListIcons*|*.*|RECURSE
[Local Storage *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\Local Storage|http*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\Local Storage|http*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Local Storage|http*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Local Storage|http*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\Local Storage|http*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Local Storage|http*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\Local Storage|http*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\Local Storage|http*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Local Storage|http*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Local Storage|http*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Local Storage|http*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Local Storage|http*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\Local Storage|http*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Local Storage|http*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Local Storage|http*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\Local Storage|http*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\Local Storage|http*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\Local Storage|http*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\Local Storage|http*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Local Storage|http*.*|RECURSE
[Logs *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave|LOG;LOG.old|RECURSE
FileKey2=%AppData%\Opera Software\Opera*|LOG;LOG.old|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\Application|debug.log
FileKey4=%LocalAppData%\7Star\7Star\User Data\*|LOG;LOG.old|RECURSE
FileKey5=%LocalAppData%\360Browser\Browser\Application|debug.log
FileKey6=%LocalAppData%\360Browser\Browser\User Data\*|LOG;LOG.old|RECURSE
FileKey7=%LocalAppData%\Amigo\Application|debug.log
FileKey8=%LocalAppData%\Amigo\User Data\*|LOG;LOG.old|RECURSE
FileKey9=%LocalAppData%\Brave|debug.log
FileKey10=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|LOG;LOG.old|RECURSE
FileKey11=%LocalAppData%\CentBrowser\Application|debug.log
FileKey12=%LocalAppData%\CentBrowser\User Data\*|LOG;LOG.old|RECURSE
FileKey13=%LocalAppData%\Chromium\Application|debug.log
FileKey14=%LocalAppData%\Chromium\User Data\*|LOG;LOG.old|RECURSE
FileKey15=%LocalAppData%\CocCoc\Browser\Application|debug.log
FileKey16=%LocalAppData%\CocCoc\Browser\User Data\*|LOG;LOG.old|RECURSE
FileKey17=%LocalAppData%\Comodo\Dragon\User Data\*|LOG;LOG.old|RECURSE
FileKey18=%LocalAppData%\Coowon\Coowon\Application|debug.log
FileKey19=%LocalAppData%\Coowon\Coowon\User Data\*|LOG;LOG.old|RECURSE
FileKey20=%LocalAppData%\Epic Privacy Browser\Application|debug.log
FileKey21=%LocalAppData%\Epic Privacy Browser\User Data\*|LOG;LOG.old|RECURSE
FileKey22=%LocalAppData%\Flock\Application|debug.log
FileKey23=%LocalAppData%\Flock\User Data\*|LOG;LOG.old|RECURSE
FileKey24=%LocalAppData%\Google\Chrome Cleanup Tool|*.log
FileKey25=%LocalAppData%\Google\Chrome*\Application|debug.log
FileKey26=%LocalAppData%\Google\Chrome*\User Data\*|LOG;LOG.old|RECURSE
FileKey27=%LocalAppData%\Google\Software Reporter Tool|*.log
FileKey28=%LocalAppData%\MapleStudio\ChromePlus\Application|debug.log
FileKey29=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|LOG;LOG.old|RECURSE
FileKey30=%LocalAppData%\Programs\Opera*|debug.log
FileKey31=%LocalAppData%\RockMelt\Application|debug.log
FileKey32=%LocalAppData%\RockMelt\User Data\*|LOG;LOG.old|RECURSE
FileKey33=%LocalAppData%\Slimjet\User Data\*|LOG;LOG.old|RECURSE
FileKey34=%LocalAppData%\Torch\Application|debug.log
FileKey35=%LocalAppData%\Torch\User Data\*|LOG;LOG.old|RECURSE
FileKey36=%LocalAppData%\Vivaldi\Application|debug.log
FileKey37=%LocalAppData%\Vivaldi\User Data\*|LOG;LOG.old|RECURSE
FileKey38=%LocalAppData%\Yandex\YandexBrowser\Application|debug.log
FileKey39=%LocalAppData%\Yandex\YandexBrowser\User Data\*|LOG;LOG.old|RECURSE
FileKey40=%ProgramFiles%\BraveSoftware\Brave-Browser\Application|debug.log
FileKey41=%ProgramFiles%\Comodo\Dragon|debug.log
FileKey42=%ProgramFiles%\Google\Chrome*\Application|debug.log
FileKey43=%ProgramFiles%\Opera*|debug.log
FileKey44=%ProgramFiles%\Slimjet|debug.log
FileKey45=%ProgramFiles%\SRWare Iron|debug.log
FileKey46=%ProgramFiles%\SuperBird|debug.log
FileKey47=%ProgramFiles%\Vivaldi\Application|debug.log
[Omnibox Shortcuts *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave|Shortcuts
FileKey2=%AppData%\Opera Software\Opera*|Shortcuts
FileKey3=%LocalAppData%\7Star\7Star\User Data\*|Shortcuts
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|Shortcuts
FileKey5=%LocalAppData%\Amigo\User Data\*|Shortcuts
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|Shortcuts
FileKey7=%LocalAppData%\CentBrowser\User Data\*|Shortcuts
FileKey8=%LocalAppData%\Chromium\User Data\*|Shortcuts
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|Shortcuts
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|Shortcuts
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|Shortcuts
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|Shortcuts
FileKey13=%LocalAppData%\Flock\User Data\*|Shortcuts
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|Shortcuts
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|Shortcuts
FileKey16=%LocalAppData%\RockMelt\User Data\*|Shortcuts
FileKey17=%LocalAppData%\Slimjet\User Data\*|Shortcuts
FileKey18=%LocalAppData%\Torch\User Data\*|Shortcuts
FileKey19=%LocalAppData%\Vivaldi\User Data\*|Shortcuts
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|Shortcuts
[PNaCl Translation Cache *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\PnaclTranslationCache|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\PnaclTranslationCache|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\PnaclTranslationCache|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\PnaclTranslationCache|*.*|RECURSE
[Quota Manager Data *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave|QuotaManager
FileKey2=%AppData%\Opera Software\Opera*|QuotaManager
FileKey3=%LocalAppData%\7Star\7Star\User Data\*|QuotaManager
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|QuotaManager
FileKey5=%LocalAppData%\Amigo\User Data\*|QuotaManager
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|QuotaManager
FileKey7=%LocalAppData%\CentBrowser\User Data\*|QuotaManager
FileKey8=%LocalAppData%\Chromium\User Data\*|QuotaManager
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|QuotaManager
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|QuotaManager
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|QuotaManager
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|QuotaManager
FileKey13=%LocalAppData%\Flock\User Data\*|QuotaManager
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|QuotaManager
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|QuotaManager
FileKey16=%LocalAppData%\RockMelt\User Data\*|QuotaManager
FileKey17=%LocalAppData%\Slimjet\User Data\*|QuotaManager
FileKey18=%LocalAppData%\Torch\User Data\*|QuotaManager
FileKey19=%LocalAppData%\Vivaldi\User Data\*|QuotaManager
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|QuotaManager
[Session Storage *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave\Session Storage|*.*|RECURSE
FileKey2=%AppData%\Opera Software\Opera*\Session Storage|*.*|RECURSE
FileKey3=%LocalAppData%\7Star\7Star\User Data\*\Session Storage|*.*|RECURSE
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*\Session Storage|*.*|RECURSE
FileKey5=%LocalAppData%\Amigo\User Data\*\Session Storage|*.*|RECURSE
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*\Session Storage|*.*|RECURSE
FileKey7=%LocalAppData%\CentBrowser\User Data\*\Session Storage|*.*|RECURSE
FileKey8=%LocalAppData%\Chromium\User Data\*\Session Storage|*.*|RECURSE
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*\Session Storage|*.*|RECURSE
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*\Session Storage|*.*|RECURSE
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*\Session Storage|*.*|RECURSE
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*\Session Storage|*.*|RECURSE
FileKey13=%LocalAppData%\Flock\User Data\*\Session Storage|*.*|RECURSE
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*\Session Storage|*.*|RECURSE
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*\Session Storage|*.*|RECURSE
FileKey16=%LocalAppData%\RockMelt\User Data\*\Session Storage|*.*|RECURSE
FileKey17=%LocalAppData%\Slimjet\User Data\*\Session Storage|*.*|RECURSE
FileKey18=%LocalAppData%\Torch\User Data\*\Session Storage|*.*|RECURSE
FileKey19=%LocalAppData%\Vivaldi\User Data\*\Session Storage|*.*|RECURSE
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*\Session Storage|*.*|RECURSE
[SetupMetrics *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%LocalAppData%\7Star\7Star\Application\SetupMetrics|*.*|REMOVESELF
FileKey2=%LocalAppData%\360Browser\Browser\Application\SetupMetrics|*.*|REMOVESELF
FileKey3=%LocalAppData%\Amigo\Application\SetupMetrics|*.*|REMOVESELF
FileKey4=%LocalAppData%\Brave\SetupMetrics|*.*|REMOVESELF
FileKey5=%LocalAppData%\CentBrowser\Application\SetupMetrics|*.*|REMOVESELF
FileKey6=%LocalAppData%\Chromium\Application\SetupMetrics|*.*|REMOVESELF
FileKey7=%LocalAppData%\CocCoc\Browser\Application\SetupMetrics|*.*|REMOVESELF
FileKey8=%LocalAppData%\Coowon\Coowon\Application\SetupMetrics|*.*|REMOVESELF
FileKey9=%LocalAppData%\Epic Privacy Browser\Application\SetupMetrics|*.*|REMOVESELF
FileKey10=%LocalAppData%\Flock\Application\SetupMetrics|*.*|REMOVESELF
FileKey11=%LocalAppData%\Google\Chrome*\Application\SetupMetrics|*.*|REMOVESELF
FileKey12=%LocalAppData%\MapleStudio\ChromePlus\Application\SetupMetrics|*.*|REMOVESELF
FileKey13=%LocalAppData%\Programs\Opera*\SetupMetrics|*.*|REMOVESELF
FileKey14=%LocalAppData%\RockMelt\Application\SetupMetrics|*.*|REMOVESELF
FileKey15=%LocalAppData%\Torch\Application\SetupMetrics|*.*|REMOVESELF
FileKey16=%LocalAppData%\Vivaldi\Application\SetupMetrics|*.*|REMOVESELF
FileKey17=%LocalAppData%\Yandex\YandexBrowser\Application\SetupMetrics|*.*|REMOVESELF
FileKey18=%ProgramFiles%\BraveSoftware\Brave-Browser\Application\SetupMetrics|*.*|REMOVESELF
FileKey19=%ProgramFiles%\Comodo\Dragon\SetupMetrics|*.*|REMOVESELF
FileKey20=%ProgramFiles%\Google\Chrome*\Application\SetupMetrics|*.*|REMOVESELF
FileKey21=%ProgramFiles%\Opera*\SetupMetrics|*.*|REMOVESELF
FileKey22=%ProgramFiles%\Slimjet\SetupMetrics|*.*|REMOVESELF
FileKey23=%ProgramFiles%\SRWare Iron\SetupMetrics|*.*|REMOVESELF
FileKey24=%ProgramFiles%\SuperBird\SetupMetrics|*.*|REMOVESELF
FileKey25=%ProgramFiles%\Vivaldi\Application\SetupMetrics|*.*|REMOVESELF
[Updates *]
LangSecRef=3029
Detect1=HKCU\Software\BraveSoftware\Brave-Browser
Detect2=HKCU\Software\CocCoc\Browser
DetectFile=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%LocalAppData%\CocCoc\Update\Download|*.*|RECURSE
FileKey2=%LocalAppData%\CocCoc\Update\Install|*.*|RECURSE
FileKey3=%LocalAppData%\CocCoc\Update\Offline|*.*|RECURSE
FileKey4=%LocalAppData%\Google\Update\Download|*.*|RECURSE
FileKey5=%LocalAppData%\Google\Update\Install|*.*|RECURSE
FileKey6=%LocalAppData%\Google\Update\Offline|*.*|RECURSE
FileKey7=%ProgramFiles%\BraveSoftware\Update\Download|*.*|RECURSE
FileKey8=%ProgramFiles%\BraveSoftware\Update\Install|*.*|RECURSE
FileKey9=%ProgramFiles%\BraveSoftware\Update\Offline|*.*|RECURSE
FileKey10=%ProgramFiles%\Google\Update\Download|*.*|RECURSE
FileKey11=%ProgramFiles%\Google\Update\Install|*.*|RECURSE
FileKey12=%ProgramFiles%\Google\Update\Offline|*.*|RECURSE
[Web Data *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
Warning=This will remove Autofill, Autocomplete, Search Engines keyword, Sign-in and Credit Card info.
FileKey1=%AppData%\brave|Web Data
FileKey2=%AppData%\Opera Software\Opera*|Web Data
FileKey3=%LocalAppData%\7Star\7Star\User Data\*|Web Data
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|Web Data
FileKey5=%LocalAppData%\Amigo\User Data\*|Web Data
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|Web Data
FileKey7=%LocalAppData%\CentBrowser\User Data\*|Web Data
FileKey8=%LocalAppData%\Chromium\User Data\*|Web Data
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|Web Data
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|Web Data
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|Web Data
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|Web Data
FileKey13=%LocalAppData%\Flock\User Data\*|Web Data
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|Web Data
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|Web Data
FileKey16=%LocalAppData%\RockMelt\User Data\*|Web Data
FileKey17=%LocalAppData%\Slimjet\User Data\*|Web Data
FileKey18=%LocalAppData%\Torch\User Data\*|Web Data
FileKey19=%LocalAppData%\Vivaldi\User Data\*|Web Data
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|Web Data
[WebRTC Identity Store *]
LangSecRef=3029
Detect1=HKCU\Software\7Star\7Star
Detect2=HKCU\Software\360Browser\Browser
Detect3=HKCU\Software\Amigo
Detect4=HKCU\Software\BraveSoftware\Brave-Browser
Detect5=HKCU\Software\CentBrowser
Detect6=HKCU\Software\ChromePlus
Detect7=HKCU\Software\Chromium\PreferenceMACs
Detect8=HKCU\Software\CocCoc\Browser
Detect9=HKCU\Software\Comodo\Dragon
Detect10=HKCU\Software\Coowon\Coowon
Detect11=HKCU\Software\Epic Privacy Browser
Detect12=HKCU\Software\Flock
Detect13=HKCU\Software\Opera Software
Detect14=HKCU\Software\RockMelt
Detect15=HKCU\Software\Slimjet
Detect16=HKCU\Software\Torch
Detect17=HKCU\Software\Vivaldi
Detect18=HKCU\Software\Yandex\YandexBrowser
DetectFile1=%AppData%\brave
DetectFile2=%LocalAppData%\Google\Chrome*
Default=False
FileKey1=%AppData%\brave|WebRTCIdentityStore
FileKey2=%AppData%\Opera Software\Opera*|WebRTCIdentityStore
FileKey3=%LocalAppData%\7Star\7Star\User Data\*|WebRTCIdentityStore
FileKey4=%LocalAppData%\360Browser\Browser\User Data\*|WebRTCIdentityStore
FileKey5=%LocalAppData%\Amigo\User Data\*|WebRTCIdentityStore
FileKey6=%LocalAppData%\BraveSoftware\Brave-Browser\User Data\*|WebRTCIdentityStore
FileKey7=%LocalAppData%\CentBrowser\User Data\*|WebRTCIdentityStore
FileKey8=%LocalAppData%\Chromium\User Data\*|WebRTCIdentityStore
FileKey9=%LocalAppData%\CocCoc\Browser\User Data\*|WebRTCIdentityStore
FileKey10=%LocalAppData%\Comodo\Dragon\User Data\*|WebRTCIdentityStore
FileKey11=%LocalAppData%\Coowon\Coowon\User Data\*|WebRTCIdentityStore
FileKey12=%LocalAppData%\Epic Privacy Browser\User Data\*|WebRTCIdentityStore
FileKey13=%LocalAppData%\Flock\User Data\*|WebRTCIdentityStore
FileKey14=%LocalAppData%\Google\Chrome*\User Data\*|WebRTCIdentityStore
FileKey15=%LocalAppData%\MapleStudio\ChromePlus\User Data\*|WebRTCIdentityStore
FileKey16=%LocalAppData%\RockMelt\User Data\*|WebRTCIdentityStore
FileKey17=%LocalAppData%\Slimjet\User Data\*|WebRTCIdentityStore
FileKey18=%LocalAppData%\Torch\User Data\*|WebRTCIdentityStore
FileKey19=%LocalAppData%\Vivaldi\User Data\*|WebRTCIdentityStore
FileKey20=%LocalAppData%\Yandex\YandexBrowser\User Data\*|WebRTCIdentityStore
; End of Chrome/Chromium based browsers.
;
; Firefox/Mozilla based browsers.
[Anti-Phishing Data *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
Warning=This will delete anti-phishing data.
FileKey1=%LocalAppData%\Moonchild Productions\Pale Moon\Profiles\*|urlclassifier3.sqlite
FileKey2=%LocalAppData%\Mozilla\Firefox\Profiles\*|urlclassifier3.sqlite
FileKey3=%LocalAppData%\Mozilla\SeaMonkey\Profiles\*|urlclassifier3.sqlite
FileKey4=%LocalAppData%\Waterfox\Profiles\*|urlclassifier3.sqlite
[Bookmark Backups *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\bookmarkbackups|*.json*
FileKey2=%AppData%\Mozilla\Firefox\Profiles\*\bookmarkbackups|*.json*
FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles\*\bookmarkbackups|*.json*
FileKey4=%AppData%\Waterfox\Profiles\*\bookmarkbackups|*.json*
[Bookmark Icons *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
Warning=This will delete all the icons of your bookmarks. The icons will be rebuilt as websites are manually re-visited.
FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*|favicons.sqlite
FileKey2=%AppData%\Mozilla\Firefox\Profiles\*|favicons.sqlite
FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles\*|favicons.sqlite
FileKey4=%AppData%\Waterfox\Profiles\*|favicons.sqlite
[Corrupt SQLites *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles|*.corrupt|RECURSE
FileKey2=%AppData%\Mozilla\Firefox\Profiles|*.corrupt|RECURSE
FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles|*.corrupt|RECURSE
FileKey4=%AppData%\Waterfox\Profiles|*.corrupt|RECURSE
[Crash Files *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
FileKey1=%AppData%\Moonchild Productions\Pale Moon\Crash Reports|*.*|RECURSE
FileKey2=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\minidumps|*.*
FileKey3=%AppData%\Mozilla\Firefox\Crash Reports|*.*|RECURSE
FileKey4=%AppData%\Mozilla\Firefox\Profiles\*\minidumps|*.*
FileKey5=%AppData%\Mozilla\SeaMonkey\Crash Reports|*.*|RECURSE
FileKey6=%AppData%\Mozilla\SeaMonkey\Profiles\*\minidumps|*.*
FileKey7=%AppData%\Waterfox\Crash Reports|*.*|RECURSE
FileKey8=%AppData%\Waterfox\Profiles\*\minidumps|*.*
[DOM Storage *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*|webappsstore.sqlite
FileKey2=%AppData%\Mozilla\Firefox\Profiles\*|webappsstore.sqlite
FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles\*|webappsstore.sqlite
FileKey4=%AppData%\Waterfox\Profiles\*|webappsstore.sqlite
[Firefox HTML5 Storage *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\storage|*.*|RECURSE
FileKey2=%AppData%\Mozilla\Firefox\Profiles\*\storage|*.*|RECURSE
FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles\*\storage|*.*|RECURSE
FileKey4=%AppData%\Waterfox\Profiles\*\storage|*.*|RECURSE
ExcludeKey1=PATH|%AppData%\Moonchild Productions\Pale Moon\Profiles\*\storage\default\moz-extension*\|*.*
ExcludeKey2=PATH|%AppData%\Mozilla\Firefox\Profiles\*\storage\default\moz-extension*\|*.*
ExcludeKey3=PATH|%AppData%\Mozilla\SeaMonkey\Profiles\*\storage\default\moz-extension*\|*.*
ExcludeKey4=PATH|%AppData%\Waterfox\Profiles\*\storage\default\moz-extension*\|*.*
[Firefox Logs *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
FileKey1=%AppData%\Moonchild Productions\Pale Moon|*.log|RECURSE
FileKey2=%AppData%\Moonchild Productions\Pale Moon\Profiles|TestPilotErrorLog.*|RECURSE
FileKey3=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\weave\logs|*.*
FileKey4=%AppData%\Mozilla\Firefox|*.log|RECURSE
FileKey5=%AppData%\Mozilla\Firefox\Profiles|TestPilotErrorLog.*|RECURSE
FileKey6=%AppData%\Mozilla\Firefox\Profiles\*\weave\logs|*.*
FileKey7=%AppData%\Mozilla\SeaMonkey|*.log|RECURSE
FileKey8=%AppData%\Mozilla\SeaMonkey\Profiles|TestPilotErrorLog.*|RECURSE
FileKey9=%AppData%\Mozilla\SeaMonkey\Profiles\*\weave\logs|*.*
FileKey10=%AppData%\Waterfox|*.log|RECURSE
FileKey11=%AppData%\Waterfox\Profiles|TestPilotErrorLog.*|RECURSE
FileKey12=%AppData%\Waterfox\Profiles\*\weave\logs|*.*
FileKey13=%CommonAppData%\Mozilla*\logs|*.*
FileKey14=%LocalAppData%\Moonchild Productions\Pale Moon\*\updates|*.*|RECURSE
FileKey15=%LocalAppData%\Mozilla\Firefox\*\updates|*.*|RECURSE
FileKey16=%LocalAppData%\Mozilla\SeaMonkey\*\updates|*.*|RECURSE
FileKey17=%LocalAppData%\Mozilla\Updates|*.*|RECURSE
FileKey18=%LocalAppData%\Waterfox\*\updates|*.*|RECURSE
FileKey19=%ProgramFiles%\Firefox*|*.log
FileKey20=%ProgramFiles%\Mozilla Firefox|*.log
FileKey21=%ProgramFiles%\Mozilla Maintenance Service\logs|*.log
FileKey22=%ProgramFiles%\Pale Moon|*.log
FileKey23=%ProgramFiles%\SeaMonkey|*.log
FileKey24=%ProgramFiles%\Waterfox|*.log
[Nightly Backups *]
LangSecRef=3026
DetectFile1=%ProgramFiles%\Mozilla\Nightly
DetectFile2=%ProgramFiles%\Nightly
Default=False
FileKey1=%ProgramFiles%\Mozilla\Nightly.bak|*.*|REMOVESELF
FileKey2=%ProgramFiles%\Nightly.bak|*.*|REMOVESELF
[Profile Lock File *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*|parent.lock
FileKey2=%AppData%\Mozilla\Firefox\Profiles\*|parent.lock
FileKey3=%AppData%\Mozilla\SeaMonkey\Profiles\*|parent.lock
FileKey4=%AppData%\Waterfox\Profiles\*|parent.lock
[Startup Cache *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
FileKey1=%LocalAppData%\Moonchild Productions\Pale Moon\Profiles\*\startupCache|*.*
FileKey2=%LocalAppData%\Mozilla\Firefox\Profiles\*\startupCache|*.*
FileKey3=%LocalAppData%\Mozilla\SeaMonkey\Profiles\*\startupCache|*.*
FileKey4=%LocalAppData%\Waterfox\Profiles\*\startupCache|*.*
[Talkback *]
LangSecRef=3026
DetectFile=%AppData%\Talkback\MozillaOrg
Default=False
FileKey1=%AppData%\Talkback\MozillaOrg\Firefox*|*.*|RECURSE
FileKey2=%AppData%\Talkback\MozillaOrg\Thunderbird*|*.*|RECURSE
RegKey1=HKLM\Software\FullCircle\TalkBack
[Telemetry *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
FileKey1=%AppData%\Moonchild Productions\Pale Moon\Profiles\*|Telemetry*.*
FileKey2=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\datareporting\archived|*.jsonlz4|RECURSE
FileKey3=%AppData%\Moonchild Productions\Pale Moon\Profiles\*\saved-telemetry-pings|*.*
FileKey4=%AppData%\Mozilla\Firefox\Profiles\*|Telemetry*.*
FileKey5=%AppData%\Mozilla\Firefox\Profiles\*\datareporting\archived|*.jsonlz4|RECURSE
FileKey6=%AppData%\Mozilla\Firefox\Profiles\*\saved-telemetry-pings|*.*
FileKey7=%AppData%\Mozilla\SeaMonkey\Profiles\*|Telemetry*.*
FileKey8=%AppData%\Mozilla\SeaMonkey\Profiles\*\datareporting\archived|*.jsonlz4|RECURSE
FileKey9=%AppData%\Mozilla\SeaMonkey\Profiles\*\saved-telemetry-pings|*.*
FileKey10=%AppData%\Waterfox\Profiles\*|Telemetry*.*
FileKey11=%AppData%\Waterfox\Profiles\*\datareporting\archived|*.jsonlz4|RECURSE
FileKey12=%AppData%\Waterfox\Profiles\*\saved-telemetry-pings|*.*
FileKey13=%LocalAppData%\Moonchild Productions\Pale Moon\Profiles\*|ShutdownDuration.*
FileKey14=%LocalAppData%\Mozilla\Firefox\Profiles\*|ShutdownDuration.*
FileKey15=%LocalAppData%\Mozilla\SeaMonkey\Profiles\*|ShutdownDuration.*
FileKey16=%LocalAppData%\Waterfox\Profiles\*|ShutdownDuration.*
[Temps *]
LangSecRef=3026
Detect1=HKLM\Software\Mozilla\Pale Moon
Detect2=HKLM\Software\Mozilla\SeaMonkey
Detect3=HKLM\Software\Mozilla\Waterfox
DetectFile=%AppData%\Mozilla\Firefox
Default=False
FileKey1=%ProgramFiles%\Firefox*|*.tmp|RECURSE
FileKey2=%ProgramFiles%\Mozilla*|*.tmp|RECURSE
FileKey3=%ProgramFiles%\Pale Moon|*.tmp|RECURSE
FileKey4=%ProgramFiles%\SeaMonkey|*.tmp|RECURSE
FileKey5=%ProgramFiles%\Waterfox|*.tmp|RECURSE
[Waterfox Installer *]
LangSecRef=3026
Detect=HKLM\Software\Mozilla\Waterfox
Default=False
FileKey1=%AppData%\Waterfox*\Waterfox*\install|*.*|RECURSE
; End of Firefox/Mozilla based browsers.
;
; Thunderbird entries.
[Email Index *]
LangSecRef=3030
Detect1=HKLM\Software\Mozilla\FossaMail
Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird
Default=False
Warning=This will cause your message index to be deleted, searching emails may be slow until it is rebuilt.
FileKey1=%AppData%\FossaMail\Profiles|global-messages-db.sqlite|RECURSE
FileKey2=%AppData%\Thunderbird\Profiles|global-messages-db.sqlite|RECURSE
[Thunderbird Corrupt SQLites *]
LangSecRef=3030
Detect1=HKLM\Software\Mozilla\FossaMail
Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird
Default=False
FileKey1=%AppData%\FossaMail\Profiles|*.corrupt|RECURSE
FileKey2=%AppData%\Thunderbird\Profiles|*.corrupt|RECURSE
[Thunderbird Crash Files *]
LangSecRef=3030
Detect1=HKLM\Software\Mozilla\FossaMail
Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird
Default=False
FileKey1=%AppData%\FossaMail\Crash Reports|*.*|RECURSE
FileKey2=%AppData%\FossaMail\Profiles\*\Minidumps|*.*
FileKey3=%AppData%\Thunderbird\Crash Reports|*.*|RECURSE
FileKey4=%AppData%\Thunderbird\Profiles\*\Minidumps|*.*
[Thunderbird DOM Storage *]
LangSecRef=3030
Detect1=HKLM\Software\Mozilla\FossaMail
Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird
Default=False
FileKey1=%AppData%\FossaMail\Profiles\*|webappsstore.sqlite
FileKey2=%AppData%\Thunderbird\Profiles\*|webappsstore.sqlite
[Thunderbird Logs *]
LangSecRef=3030
Detect1=HKLM\Software\Mozilla\FossaMail
Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird
Default=False
FileKey1=%AppData%\FossaMail\Profiles\*|extensions.log;filterlog.html;TestPilotErrorLog.*|RECURSE
FileKey2=%AppData%\Thunderbird\Profiles\*|extensions.log;filterlog.html;TestPilotErrorLog.*|RECURSE
FileKey3=%CommonAppData%\Mozilla*\logs|*.*|RECURSE
FileKey4=%LocalAppData%\FossaMail\Mozilla\*\Updates|*.log|RECURSE
FileKey5=%LocalAppData%\Thunderbird\Mozilla\*\Updates|*.log|RECURSE
FileKey6=%ProgramFiles%\FossaMail|*.log
FileKey7=%ProgramFiles%\Mozilla Thunderbird|*.log
[Thunderbird Startup Cache *]
LangSecRef=3030
Detect1=HKLM\Software\Mozilla\FossaMail
Detect2=HKLM\Software\Mozilla\Mozilla Thunderbird
Default=False
FileKey1=%LocalAppData%\FossaMail\Profiles\*\startupCache|*.*
FileKey2=%LocalAppData%\Thunderbird\Profiles\*\startupCache|*.*
; End of Thunderbird entries.
[.NET Framework *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\.NETFramework
Default=False
FileKey1=%WinDir%\assembly\NativeImages_*\Temp|*.*|RECURSE
FileKey2=%WinDir%\assembly\t*mp|*.*|REMOVESELF
FileKey3=%WinDir%\Microsoft.NET\Framework*\*\*\Logs|*.*|RECURSE
FileKey4=%WinDir%\Microsoft.NET\Framework*\*\Temporary ASP.NET Files|*.*|REMOVESELF
FileKey5=%WinDir%\Microsoft.NET\Framework*\v4.0.30319\SetupCache|*.*|RECURSE
FileKey6=%WinDir%\System32\URTTemp|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\.NETFramework\SQM\Apps
[.NET Framework Isolated Storage *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\.NETFramework
Default=False
FileKey1=%LocalAppData%\IsolatedStorage|*.*|RECURSE
[.NET Reflector *]
LangSecRef=3021
DetectFile=%LocalAppData%\Red Gate\.NET Reflector 6
Default=False
FileKey1=%LocalAppData%\Red Gate\.NET Reflector 6|Reflector.cfg
FileKey2=%LocalAppData%\Red Gate\.NET Reflector 6\Cache|*.*|RECURSE
[.Thumbnails *]
LangSecRef=3021
DetectFile=%UserProfile%\.Thumbnails
Default=False
FileKey1=%UserProfile%\.Thumbnails|*.*|RECURSE
[//N.P.P.D. RUSH//- The milk of Ultraviolet *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\270090
Default=False
FileKey1=%LocalAppData%\NPPDRUSH|Web Data*|RECURSE
FileKey2=%LocalAppData%\NPPDRUSH\*Cache|*.*|RECURSE
[1Click DVD Copy Pro *]
LangSecRef=3023
DetectFile=%CommonAppData%\1click dvd copy pro
Default=False
FileKey1=%CommonAppData%\1click dvd copy pro|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\1click dvd copy pro|*.log
[3 Stars Of Destiny *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\278530
Default=False
FileKey1=%AppData%\3Stars|*.tmp
[3D Builder *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.3DBuilder_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.3DBuilder_*\AC\Temp|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.3DBuilder_*\LocalState\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.3DBuilder_*\TempState|*.*|RECURSE
[3DMark *]
Section=Games
DetectFile=%Documents%\3DMark
Default=False
FileKey1=%Documents%\3DMark|*.log
FileKey2=%Documents%\3DMark\Log|*.*|REMOVESELF
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\3DMark|*.log|RECURSE
FileKey4=%ProgramFiles%\Steam\SteamApps\common\3DMark|*.log|RECURSE
[3DMark Saved Benchmarks *]
Section=Games
DetectFile=%Documents%\3DMark
Default=False
FileKey1=%Documents%\3DMark|*.3dmark-result
[3SwitcheD *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\206610
Default=False
FileKey1=%LocalAppData%\3SwitcheD\cache|*.*|RECURSE
[4K Video Downloader *]
LangSecRef=3023
Detect=HKCU\Software\4kdownload.com\4K Video Downloader
Default=False
FileKey1=%LocalAppData%\4kdownload.com\4K Video Downloader\4K Video Downloader|*.xml
RegKey1=HKCU\Software\4kdownload.com\4K Video Downloader\Download|downloadedItems
RegKey2=HKCU\Software\4kdownload.com\4K Video Downloader\Settings|outputPath
[4K YouTube to MP3 *]
LangSecRef=3023
Detect=HKCU\Software\4kdownload.com\4K YouTube to MP3
Default=False
FileKey1=%LocalAppData%\4kdownload.com\4K YouTube to MP3\4K YouTube to MP3|*.xml
RegKey1=HKCU\Software\4kdownload.com\4K YouTube to MP3\Download|downloadedItems
RegKey2=HKCU\Software\4kdownload.com\4K YouTube to MP3\Settings|outputPath
[4Team Sync2 *]
LangSecRef=3022
DetectFile=%AppData%\4Team\Sync2
Default=False
FileKey1=%AppData%\4Team\Sync2|*.log|RECURSE
[4Team Updater *]
LangSecRef=3022
DetectFile=%AppData%\4Team\4Team-Updater
Default=False
FileKey1=%AppData%\4Team\4Team-Updater\Logs|*.*
[7z SFX Builder *]
LangSecRef=3024
Detect=HKCU\Software\7z SFX Builder
Default=False
RegKey1=HKCU\Software\7z SFX Builder\MRU
[10 Years After *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\339240
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\10 Years After\10 Years After_Data|output_log.txt
FileKey2=%ProgramFiles%\Steam\SteamApps\common\10 Years After\10 Years After_Data|output_log.txt
[18 Wheels of Steel *]
Section=Games
Detect=HKCU\Software\ValuSoft
Default=False
FileKey1=%Documents%\18 WoS*|*.log;*.crash
[32bit Web Browser *]
LangSecRef=3022
DetectFile=%ProgramFiles%\32BITWEB\32BW.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\32BITWEB\Data|LastURL.dat;LastURL.da0
FileKey2=%ProgramFiles%\32BITWEB\Data|LastURL.dat;LastURL.da0
[140 *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\242820
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\140\140_Data|output_log.txt
FileKey2=%ProgramFiles%\Steam\SteamApps\common\140\140_Data|output_log.txt
[360 Internet Security *]
LangSecRef=3024
Detect=HKCU\Software\360Safe
Default=False
FileKey1=%AppData%\360safe\360ScanLog|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\360\360 Internet Security|*.log*|RECURSE
FileKey3=%ProgramFiles%\360\360 Internet Security|*.log*|RECURSE
FileKey4=%SystemDrive%\360SANDBOX|*.log*|RECURSE
[1000 Amps *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\205690
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\1000 Amps|stdout.txt
FileKey2=%ProgramFiles%\Steam\SteamApps\common\1000 Amps|stdout.txt
[1954 Alcatraz *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\255280
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\1954 Alcatraz\Alcatraz_Data|output_log.txt
FileKey2=%LocalLowAppData%\Daedalic Entertainment\1954 Alcatraz|*.log
FileKey3=%ProgramFiles%\Steam\SteamApps\common\1954 Alcatraz\Alcatraz_Data|output_log.txt
[A58-Easytune6 *]
LangSecRef=3024
DetectFile=%ProgramFiles%\A58-Easytune6
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\A58-Easytune6|*.log
FileKey2=%ProgramFiles%\A58-Easytune6|*.log
[ABBYY FineReader *]
LangSecRef=3021
Detect1=HKCU\Software\ABBYY\FineReader\7.00
Detect2=HKCU\Software\ABBYY\FineReader\8.00
Detect3=HKCU\Software\ABBYY\FineReader\9.00
Detect4=HKCU\Software\ABBYY\FineReader\11.00
Detect5=HKCU\Software\ABBYY\Sprint\5.00
Default=False
FileKey1=%LocalAppData%\ABBYY\ScanManager\*|scantwain.txt;scanwia.txt;*.bmp
RegKey1=HKCU\Software\ABBYY\FineReader\7.00\Shell\Dialogs|LoadImagePath
RegKey2=HKCU\Software\ABBYY\FineReader\7.00\Shell\Dialogs|SaveImagePath
RegKey3=HKCU\Software\ABBYY\FineReader\7.00\Shell\Dialogs|SaveToPath
RegKey4=HKCU\Software\ABBYY\FineReader\8.00\Shell\Dialogs|LoadImagePath
RegKey5=HKCU\Software\ABBYY\FineReader\8.00\Shell\Dialogs|SaveImagePath
RegKey6=HKCU\Software\ABBYY\FineReader\8.00\Shell\Dialogs|SaveToPath
RegKey7=HKCU\Software\ABBYY\FineReader\8.00\Shell\Options|LastTAScenario
RegKey8=HKCU\Software\ABBYY\FineReader\9.00\Shell\Dialogs|LoadImagePath
RegKey9=HKCU\Software\ABBYY\FineReader\9.00\Shell\Dialogs|SaveImagePath
RegKey10=HKCU\Software\ABBYY\FineReader\9.00\Shell\Dialogs|SaveToPath
RegKey11=HKCU\Software\ABBYY\FineReader\9.00\Shell\Options|LastTAScenario
RegKey12=HKCU\Software\ABBYY\FineReader\11.00\Shell\Dialogs|SaveToPath
RegKey13=HKCU\Software\ABBYY\FineReader\11.00\Shell\Options|LastTAScenario
RegKey14=HKCU\Software\ABBYY\FineReader\11.00\Shell\Options|LastWebFoldersNames
[Abelssoft GoogleClean *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4281435C-AD1D-4C8A-B9C0-3961C08EF142}_is1
Default=False
FileKey1=%LocalAppData%\Abelssoft\GoogleClean\log|*.*|REMOVESELF
[abgx360 *]
LangSecRef=3024
Detect=HKCU\Software\abgx360gui
Default=False
RegKey1=HKCU\Software\abgx360gui\RecentFiles
[Ability Office *]
LangSecRef=3021
Detect=HKCU\Software\Ability 6.0
Default=False
FileKey1=%Documents%\My Ability Files|*.*|RECURSE
RegKey1=HKCU\Software\Ability 6.0\Ability Database\Recent File List
RegKey2=HKCU\Software\Ability 6.0\Ability PhotoPaint Studio\Recent File List
RegKey3=HKCU\Software\Ability 6.0\Ability PhotoPaint\Recent File List
RegKey4=HKCU\Software\Ability 6.0\Ability Spreadsheet\Recent File List
RegKey5=HKCU\Software\Ability 6.0\Ability Write\Files
[Ableton Live *]
LangSecRef=3023
Detect=HKLM\Software\Propellerhead Software\ReWire\Ableton Live Engine
Default=False
FileKey1=%AppData%\Ableton\*\Preferences|AsioLog.txt;Indexer.txt;Log.txt|RECURSE
FileKey2=%AppData%\Ableton\Live Reports\Temp|*.*|REMOVESELF
FileKey3=%AppData%\Ableton\Live Reports\Usage|*.*|REMOVESELF
FileKey4=%CommonAppData%\Ableton\*\Redist|vcredist*.exe
FileKey5=%ProgramFiles%\Ableton\*\Redist|vcredist*.exe
[Ableton Live Cache *]
LangSecRef=3023
Detect=HKLM\Software\Propellerhead Software\ReWire\Ableton Live Engine
Default=False
FileKey1=%AppData%\Ableton\Cache|*.*|RECURSE
[AbsoluteFTP *]
LangSecRef=3022
Detect=HKCU\Software\Van Dyke Technologies\AbsoluteFTP
Default=False
RegKey1=HKCU\Software\Van Dyke Technologies\AbsoluteFTP\Recent File List
[AccessData Registry Viewer *]
LangSecRef=3024
Detect=HKCU\Software\AccessData\Registry Viewer
Default=False
RegKey1=HKCU\Software\AccessData\Registry Viewer\Recent File List
[Accounts Control *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.AccountsControl_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.AccountsControl_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.AccountsControl_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.AccountsControl_*\TempState|*.*|RECURSE
[AccurateRip *]
LangSecRef=3023
Detect1=HKCU\Software\AWSoftware\EAC
Detect2=HKCU\Software\AWSoftware\EACU
Detect3=HKCU\Software\Illustrate\dBpowerAMP
Default=False
FileKey1=%AppData%\AccurateRip\AccurateRipCache|dBAR*.bin
[AccuWeather *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AccuWeather.AccuWeatherforWindows8_8zz2pj9h1h1d8
DetectFile=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_8zz2pj9h1h1d8
Default=False
FileKey1=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.log|RECURSE
FileKey3=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_*\AC\Temp|*.*
FileKey4=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_*\LocalState|*.tmp
FileKey5=%LocalAppData%\Packages\AccuWeather.AccuWeatherforWindows8_*\TempState\Bing.Maps\Cache|*.*|RECURSE
[ACDSee Photo Studio *]
LangSecRef=3023
Detect1=HKCU\Software\ACD Systems\ACDSee Pro\90
Detect2=HKCU\Software\ACD Systems\ACDSee Professional\110
Detect3=HKCU\Software\ACD Systems\ACDSee Standard\210
Detect4=HKCU\Software\ACD Systems\ACDSee Ultimate\110
Detect5=HKCU\Software\ACD Systems\ACDSee\60
Default=False
FileKey1=%LocalAppData%\ACD Systems\ICMCache|*.*|RECURSE
FileKey2=%LocalAppData%\ACD Systems\Logs|*.*|RECURSE
FileKey3=%LocalAppData%\ACD Systems\SavedSearches|*.*|RECURSE
RegKey1=HKCU\Software\ACD Systems\ACDSee Pro\90|HistMCFDestFolder
RegKey2=HKCU\Software\ACD Systems\ACDSee Pro\90|HistPaths
RegKey3=HKCU\Software\ACD Systems\ACDSee Pro\90|LastOptionPageName
RegKey4=HKCU\Software\ACD Systems\ACDSee Pro\90|OpenFolder
RegKey5=HKCU\Software\ACD Systems\ACDSee Pro\90\PrintOptions\OutputContactSheet|ContactSheetFN
RegKey6=HKCU\Software\ACD Systems\ACDSee Pro\90\PrintOptions\OutputContactSheet|ImageMapFN
RegKey7=HKCU\Software\ACD Systems\ACDSee Professional\110|HistMCFDestFolder
RegKey8=HKCU\Software\ACD Systems\ACDSee Professional\110|HistPaths
RegKey9=HKCU\Software\ACD Systems\ACDSee Professional\110|LastOptionPageName
RegKey10=HKCU\Software\ACD Systems\ACDSee Professional\110|OnlineHistPaths
RegKey11=HKCU\Software\ACD Systems\ACDSee Professional\110|OpenFolder
RegKey12=HKCU\Software\ACD Systems\ACDSee Standard\210|HistMCFDestFolder
RegKey13=HKCU\Software\ACD Systems\ACDSee Standard\210|HistPaths
RegKey14=HKCU\Software\ACD Systems\ACDSee Standard\210|LastOptionPageName
RegKey15=HKCU\Software\ACD Systems\ACDSee Standard\210|OnlineHistPaths
RegKey16=HKCU\Software\ACD Systems\ACDSee Standard\210|OpenFolder
RegKey17=HKCU\Software\ACD Systems\ACDSee Ultimate\110|HistMCFDestFolder
RegKey18=HKCU\Software\ACD Systems\ACDSee Ultimate\110|HistPaths
RegKey19=HKCU\Software\ACD Systems\ACDSee Ultimate\110|LastOptionPageName
RegKey20=HKCU\Software\ACD Systems\ACDSee Ultimate\110|OnlineHistPaths
RegKey21=HKCU\Software\ACD Systems\ACDSee Ultimate\110|OpenFolder
RegKey22=HKCU\Software\ACD Systems\ACDSee\60|HistMCFDestFolder
RegKey23=HKCU\Software\ACD Systems\ACDSee\60|HistPaths
RegKey24=HKCU\Software\ACD Systems\ACDSee\60|LastOptionPageName
RegKey25=HKCU\Software\ACD Systems\ACDSee\60|OpenFolder
RegKey26=HKCU\Software\ACD Systems\ACDSee\60\PrintOptions\OutputContactSheet|ContactSheetFN
RegKey27=HKCU\Software\ACD Systems\ACDSee\60\PrintOptions\OutputContactSheet|ImageMapFN
RegKey28=HKCU\Software\ACD Systems\EditLib\Presets\Photo Repair 2|Last Used
[Ace Explorer Browser *]
LangSecRef=3022
Detect=HKCU\Software\Ace Explorer\Ace Explorer
Default=False
FileKey1=%AppData%\Ace Explorer|recentclose.ini
RegKey1=HKCU\Software\Ace Explorer\Ace Explorer\Recent File List
[Ace of Spades *]
Section=Games
DetectFile=%ProgramFiles%\Steam\steamapps\common\aceofspades
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\aceofspades\logs|*.*
FileKey2=%ProgramFiles%\Steam\steamapps\common\aceofspades\logs|*.*
[Ace Stream *]
LangSecRef=3023
DetectFile=%AppData%\ACEStream
Default=False
FileKey1=%AppData%\.ACEStream|*.ini
FileKey2=%AppData%\.ACEStream\collected_torrent_files|*.*
FileKey3=%AppData%\ACEStream\engine|*.log
FileKey4=%SystemDrive%\_acestream_cache_|*.*|REMOVESELF
[Ace Utilities *]
LangSecRef=3024
Detect=HKCU\Software\Acelogix\Ace Utilities
Default=False
RegKey1=HKCU\Software\Acelogix\Ace Utilities\Settings|UsageHistory
[Acebyte Utilities *]
LangSecRef=3024
Detect=HKCU\Software\AceBIT
Default=False
FileKey1=%CommonAppData%\Acebyte\Acebyte Utilities*\Log|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Acebyte\Acebyte Utilities*\Log|*.*|RECURSE
[Acer Arcade Deluxe *]
Section=Games
DetectFile=%LocalAppData%\Acer Arcade Deluxe
Default=False
FileKey1=%CommonAppData%|ArcadeDexluxe2.log
FileKey2=%LocalAppData%\Acer Arcade Deluxe|*.log
FileKey3=%LocalAppData%\VirtualStore\ProgramData|ArcadeDexluxe2.log
[AcooBrowser *]
LangSecRef=3022
Detect=HKCU\Software\AcooBrowser\Acoo Browser
Default=False
RegKey1=HKCU\Software\AcooBrowser\Acoo Browser\Recent Document List
RegKey2=HKCU\Software\AcooBrowser\Acoo Browser\Search\History
[Acoustica CD Label Maker *]
LangSecRef=3024
Detect=HKCU\Software\Acoustica\CD Label Maker
Default=False
FileKey1=%AppData%\Acoustica\CD Label Maker\*\cache|*.*|RECURSE
FileKey2=%AppData%\Acoustica\CD Label Maker\cache|*.*|RECURSE
FileKey3=%AppData%\Acoustica\CD Label Maker\shapes|*.*
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Acoustica CD Label Maker\thumbs|*.*|RECURSE
FileKey5=%ProgramFiles%\Acoustica CD Label Maker\thumbs|*.*|RECURSE
[Acoustica Premium Edition 6 *]
LangSecRef=3023
Detect=HKCU\Software\Acon Digital\Acoustica Premium Edition 6
Default=False
RegKey1=HKCU\Software\Acon Digital\Acoustica Premium Edition 6\General|BrowserFolder
RegKey2=HKCU\Software\Acon Digital\Acoustica Premium Edition 6\General|LastAudioDir
RegKey3=HKCU\Software\Acon Digital\Acoustica Premium Edition 6\Recent File List
[Acrok Video Converter Ultimate *]
LangSecRef=3023
Detect=HKCU\Software\Acrok Software\Acrok Video Converter Ultimate
Default=False
FileKey1=%AppData%\Acrok\Acrok Video Converter Ultimate|*.dmp
FileKey2=%AppData%\Acrok\Acrok Video Converter Ultimate\log|*.*
FileKey3=%AppData%\Auxre\Blu-ray Plugin|*.log
FileKey4=%UserProfile%\.BDAccess|*.*|RECURSE
[Action Center *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\ActionCenterCache|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Security and Maintenance\Providers\EventLog
[Active Setup Temp Folder *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Active Setup Temp Folders
Default=False
FileKey1=%WinDir%\msdownld.tmp|*.*|REMOVESELF
RegKey1=HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Active Setup Temp Folders|Folder
RegKey2=HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Active Setup Temp Folders|Folder
[Active@ Disk Image *]
LangSecRef=3024
Detect=HKLM\Software\LSoft Technologies\Active Disk Image
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
FileKey3=%ProgramFiles%\LSoft Technologies\Active@ Disk Image|*.txt
FileKey4=%ProgramFiles%\LSoft Technologies\Active@ Disk Image\Logs|*.*|RECURSE
[Active@ File Recovery *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C34F36E0-4D8B-42E8-90AD-50C76E1AE282}_is1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ File Recovery*|Active File Recovery Log.txt;he_log.txt;*.scn;*.xml
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ File Recovery*|Active File Recovery Log.txt;he_log.txt;*.scn;*.xml
[Active@ KillDisk *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0F62EFB8-3C1C-4EE6-B6EF-9593007F9B03}_is1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LSoft Technologies\Active@ KillDisk*|*.log;*.xml
FileKey2=%ProgramFiles%\LSoft Technologies\Active@ KillDisk*|*.log;*.xml
[Ad-Aware Antivirus *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Ad-Aware Antivirus\AdAware.exe
Default=False
FileKey1=%AppData%\Ad-Aware Antivirus\Logs|*.*|RECURSE
FileKey2=%CommonAppData%\Ad-Aware Antivirus\Logs|*.*|RECURSE
FileKey3=%CommonAppData%\Lavasoft\AntiMalware\Events|*.*|RECURSE
FileKey4=%CommonAppData%\Lavasoft\AntiMalware\History|*.*|RECURSE
FileKey5=%CommonAppData%\Lavasoft\AntiMalware\Logs|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Ad-Aware Antivirus\Logs|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Lavasoft\AntiMalware\Events|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Lavasoft\AntiMalware\History|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Lavasoft\AntiMalware\Logs|*.*|RECURSE
[Adaptec's Audio CD *]
LangSecRef=3024
Detect=HKCU\Software\Adaptec
Default=False
RegKey1=HKCU\Software\Adaptec\AUDIO_CD_INFO
[Adblock Plus For IE *]
LangSecRef=3022
Detect=HKLM\Software\Adblock Plus for IE
DetectFile=%LocalAppData%\Adblock Plus for IE
Default=False
FileKey1=%LocalAppData%\Adblock Plus for IE|patterns-backup*.ini
FileKey2=%LocalLowAppData%\Adblock Plus for IE|patterns-backup*.ini
FileKey3=%WinDir%\System32\config\systemprofile\AppData\LocalLow\Adblock Plus for IE|patterns-backup*.ini
[Adobe Acrobat 2017 *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\2017
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\2017\AVGeneral\cRecentFiles
RegKey2=HKCU\Software\Adobe\Adobe Acrobat\2017\AVGeneral\cRecentFolders
[Adobe Acrobat DC *]
LangSecRef=3021
Detect=HKLM\Software\Adobe\Adobe Acrobat\DC
Default=False
FileKey1=%LocalAppData%\Adobe\Acrobat\DC|*.lst;UserCache.bin
FileKey2=%LocalAppData%\Adobe\Acrobat\DC\Cache|*.lst
FileKey3=%LocalAppData%\Adobe\Acrobat\DC\ToolsSearchCacheAcro|*.*|RECURSE
FileKey4=%LocalLowAppData%\Adobe\Acrobat\DC\Search|*.*|RECURSE
FileKey5=%LocalLowAppData%\Adobe\AcroCef\DC\Acrobat\Cache|*.*|RECURSE
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionFromPDF\cSettings
RegKey2=HKCU\Software\Adobe\Adobe Acrobat\DC\AVConversionToPDF\cSettings
RegKey3=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cDockables
RegKey4=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles
RegKey5=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFolders
RegKey6=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentToolsList
RegKey7=HKCU\Software\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars
RegKey8=HKCU\Software\Adobe\Adobe Acrobat\DC\RememberedViews\cNoCategoryFiles
RegKey9=HKCU\Software\Adobe\Adobe Acrobat\DC\ShareIdentity
RegKey10=HKCU\Software\Adobe\Adobe Synchronizer\DC
[Adobe Acrobat Distiller XI *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Distiller\11.0
Default=False
FileKey1=%AppData%\Adobe\Acrobat\Distiller 11|*.log
FileKey2=%AppData%\Adobe\Acrobat\Distiller 11\Cache|*.*
RegKey1=HKCU\Software\Adobe\Acrobat Distiller\PrinterJobControl
[Adobe Acrobat Reader 7.0 *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Adobe\Acrobat 7.0\ActiveX|*.bak
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Adobe\Acrobat 7.0\Reader|*.bak
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Adobe\Acrobat 7.0\Reader\plug_ins|*.bak
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Adobe\Acrobat 7.0\Reader\Updater|*.bak
[Adobe Acrobat XI *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\11.0
Default=False
FileKey1=%LocalAppData%\Adobe\Acrobat|*.idx|RECURSE
FileKey2=%LocalAppData%\Adobe\Acrobat\11.0|UserCache.bin
[Adobe Air *]
LangSecRef=3024
DetectFile=%LocalAppData%\Adobe\Air
Default=False
FileKey1=%WinDir%\System32\config\systemprofile\AppData\Local\Adobe\AIR\logs|*.*
FileKey2=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Adobe\AIR\logs|*.*
[Adobe Application Manager *]
LangSecRef=3021
Detect=HKCU\Software\Adobe
Default=False
FileKey1=%AppData%\Adobe\Acrobat\*\Updater|*.log
FileKey2=%CommonAppData%\Adobe\ARM|*.*|RECURSE
FileKey3=%CommonProgramFiles%\Adobe\Installers|*.log.gz|RECURSE
FileKey4=%LocalAppData%\Adobe\AAMUpdater|*.Log|RECURSE
FileKey5=%LocalAppData%\Adobe\Acrobat\*\Updater|*.log
FileKey6=%LocalAppData%\Adobe\Updater*|*.log|RECURSE
[Adobe CC *]
LangSecRef=3023
Detect=HKCU\Software\Adobe\CreativeCloud
Default=False
FileKey1=%AppData%\Adobe\Adobe Media Encoder\*\logs|*.*|RECURSE
FileKey2=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings|PSErrorLog.txt;sniffer-*.txt
FileKey3=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings\CrashLogs|*.*|RECURSE
FileKey4=%AppData%\Adobe\Adobe Photoshop CC *\Adobe Photoshop CC * Settings\web-cache-temp|*.*|RECURSE
FileKey5=%AppData%\Adobe\Adobe Photoshop CC *\Logs|*.*|RECURSE
FileKey6=%AppData%\Adobe\CRLogs|*.*|RECURSE
FileKey7=%AppData%\Adobe\dynamiclinkmanager\*\logs|*.*|RECURSE
FileKey8=%AppData%\Adobe\Extension Manager CC\Log|*.*|RECURSE
FileKey9=%AppData%\Adobe\Extension Manager CC\Temp|*.*|RECURSE
FileKey10=%AppData%\Adobe\LogTransport2CC\Logs|*.*|RECURSE
FileKey11=%AppData%\Adobe\Lumetri\*\logs|*.*|RECURSE
FileKey12=%AppData%\Adobe\Premiere Pro\*|Plugin Loading.log
FileKey13=%AppData%\Adobe\Premiere Pro\*\logs|*.*|RECURSE
FileKey14=%CommonProgramFiles%\Adobe\Installers|CoreSyncInstall.log;Install.log
FileKey15=%Documents%\Adobe|*.log
FileKey16=%Documents%\Adobe\Adobe Media Encoder\*|AMEEncodingErrorLog.txt;AMEEncodingLog.txt
FileKey17=%Documents%\Adobe\Adobe Media Encoder\*\logs|*.*|RECURSE
FileKey18=%Documents%\Adobe\Premiere Pro\*|Plugin Loading.log
RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU
[Adobe Customization Wizard *]
LangSecRef=3021
Detect1=HKCU\Software\Adobe\Adobe Customization Wizard 8
Detect2=HKCU\Software\Adobe\Adobe Customization Wizard 9
Detect3=HKCU\Software\Adobe\Adobe Customization Wizard X
Detect4=HKCU\Software\Adobe\Adobe Customization Wizard XI
Default=False
RegKey1=HKCU\Software\Adobe\Adobe Customization Wizard 8\Recent File List
RegKey2=HKCU\Software\Adobe\Adobe Customization Wizard 9\Recent File List
RegKey3=HKCU\Software\Adobe\Adobe Customization Wizard X\Recent File List
RegKey4=HKCU\Software\Adobe\Adobe Customization Wizard XI\Recent File List
[Adobe Elements Organizer *]
LangSecRef=3023
Detect=HKCU\Software\Adobe\Elements Organizer
Default=False
FileKey1=%AppData%\Adobe\amecommand\6.0|Plugin Loading.log
FileKey2=%AppData%\Adobe\Elements Organizer\*\Organizer|*.txt;status.dat
FileKey3=%AppData%\Adobe\Elements Smart Tag Agent\*\Logs|*.log
FileKey4=%AppData%\Adobe\LogTransport2\Logs|*.*|RECURSE
FileKey5=%CommonAppData%|StreamingMediaTechnologyLog.txt
FileKey6=%CommonAppData%\Adobe\Elements Organizer\Catalogs\My Catalog|face.thumb.9.cache;thumb.5.cache
FileKey7=%CommonAppData%\Adobe\Elements Organizer\Catalogs\My Catalog\FaceAnalysis|FaceAnalysis.cache
FileKey8=%CommonAppData%\Adobe\Elements Organizer\Catalogs\My Catalog\WaldoData|waldo.cache
FileKey9=%CommonAppData%\Adobe\Elements Organizer\Catalogs\My Catalog\Watch Folder|*.txt;*.xml
RegKey1=HKCU\Software\Adobe\Elements Organizer\11.0\CurrentMediaFilePath
RegKey2=HKCU\Software\Adobe\Elements Organizer\12.0\CurrentMediaFilePath
RegKey3=HKCU\Software\Adobe\Elements Organizer\13.0\CurrentMediaFilePath
RegKey4=HKCU\Software\Adobe\Elements Organizer\14.0\CurrentMediaFilePath
RegKey5=HKCU\Software\Adobe\Elements Organizer\15.0\CurrentMediaFilePath
RegKey6=HKCU\Software\Adobe\Elements Organizer\16.0\CurrentMediaFilePath
RegKey7=HKCU\Software\Adobe\Elements Organizer\17.0\CurrentMediaFilePath
[Adobe Flash Player *]
LangSecRef=3023
Detect=HKCU\Software\Macromedia\FlashPlayer
DetectFile=%AppData%\Adobe\Flash Player
Default=False
FileKey1=%AppData%\Adobe\Flash Player\*Cache|*.*|RECURSE
FileKey2=%WinDir%\System32\Macromed\Flash|FlashInstall*.log;install.log
FileKey3=%WinDir%\SysWOW64\Macromed\Flash|FlashInstall*.log;install.log
[Adobe Media Cache *]
LangSecRef=3023
DetectFile=%AppData%\Adobe\Common\Media Cache
Default=False
Warning=Do not use this until all your Premiere projects have been completed.
FileKey1=%AppData%\Adobe\Common\* Cache*|*.*|RECURSE
FileKey2=%AppData%\Adobe\Common\Peak Files|*.*|RECURSE
[Adobe Photoshop Elements *]
LangSecRef=3023
Detect=HKCU\Software\Adobe\Photoshop Elements
Default=False
FileKey1=%AppData%\Adobe\LogTransport2\Logs|*.*|RECURSE
FileKey2=%AppData%\Adobe\Photoshop Elements\*\Editor|*.txt
FileKey3=%CommonAppData%\Adobe\Photoshop Elements\File Agent|WatchFolder.3.cache
RegKey1=HKCU\Software\Adobe\Photoshop Elements\11.0\common\settings\Elements MRU
RegKey2=HKCU\Software\Adobe\Photoshop Elements\11.0\CurrentMediaFilePath
RegKey3=HKCU\Software\Adobe\Photoshop Elements\11.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey4=HKCU\Software\Adobe\Photoshop Elements\12.0\common\settings\Elements MRU
RegKey5=HKCU\Software\Adobe\Photoshop Elements\12.0\CurrentMediaFilePath
RegKey6=HKCU\Software\Adobe\Photoshop Elements\12.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey7=HKCU\Software\Adobe\Photoshop Elements\13.0\common\settings\Elements MRU
RegKey8=HKCU\Software\Adobe\Photoshop Elements\13.0\CurrentMediaFilePath
RegKey9=HKCU\Software\Adobe\Photoshop Elements\13.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey10=HKCU\Software\Adobe\Photoshop Elements\14.0\common\settings\Elements MRU
RegKey11=HKCU\Software\Adobe\Photoshop Elements\14.0\CurrentMediaFilePath
RegKey12=HKCU\Software\Adobe\Photoshop Elements\14.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey13=HKCU\Software\Adobe\Photoshop Elements\15.0\common\settings\Elements MRU
RegKey14=HKCU\Software\Adobe\Photoshop Elements\15.0\CurrentMediaFilePath
RegKey15=HKCU\Software\Adobe\Photoshop Elements\15.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey16=HKCU\Software\Adobe\Photoshop Elements\16.0\common\settings\Elements MRU
RegKey17=HKCU\Software\Adobe\Photoshop Elements\16.0\CurrentMediaFilePath
RegKey18=HKCU\Software\Adobe\Photoshop Elements\16.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey19=HKCU\Software\Adobe\Photoshop Elements\17.0\common\settings\Elements MRU
RegKey20=HKCU\Software\Adobe\Photoshop Elements\17.0\CurrentMediaFilePath
RegKey21=HKCU\Software\Adobe\Photoshop Elements\17.0\VisitedDirs|STARTUPIMAGEDIRECTORY
[Adobe Premiere Elements *]
LangSecRef=3023
Detect=HKCU\Software\Adobe\Premiere Elements
Default=False
FileKey1=%AppData%\Adobe\Common\Thumbnail Cache|thumbnailDB
FileKey2=%AppData%\Adobe\LogTransport2\Logs|*.*|RECURSE
FileKey3=%AppData%\Adobe\Premiere Elements\*|Plugin Loading.log
FileKey4=%AppData%\Adobe\Premiere Elements\*\logs|*.*|RECURSE
FileKey5=%Documents%\Adobe\Premiere Elements\*|*.log
FileKey6=%Documents%\NewBlueFX\Logs|*.txt
RegKey1=HKCU\Software\Adobe\Premiere Elements\11.0\MRUDocuments
RegKey2=HKCU\Software\Adobe\Premiere Elements\12.0\MRUDocuments
RegKey3=HKCU\Software\Adobe\Premiere Elements\13.0\MRUDocuments
RegKey4=HKCU\Software\Adobe\Premiere Elements\14.0\MRUDocuments
RegKey5=HKCU\Software\Adobe\Premiere Elements\15.0\MRUDocuments
RegKey6=HKCU\Software\Adobe\Premiere Elements\16.0\MRUDocuments
RegKey7=HKCU\Software\Adobe\Premiere Elements\17.0\MRUDocuments
[Adobe Reader 2017 *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\2017
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\2017\AVGeneral\cRecentFiles
RegKey2=HKCU\Software\Adobe\Acrobat Reader\2017\AVGeneral\cRecentFolders
[Adobe Reader DC *]
LangSecRef=3021
Detect=HKLM\Software\Adobe\Acrobat Reader\DC
Default=False
FileKey1=%LocalAppData%\Adobe\Acrobat\DC|UserCache.bin
RegKey1=HKCU\Software\Adobe\Acrobat Reader\DC\AVConversionFromPDF
RegKey2=HKCU\Software\Adobe\Acrobat Reader\DC\AVConversionToPDF
RegKey3=HKCU\Software\Adobe\Acrobat Reader\DC\AVGeneral\cDockables
RegKey4=HKCU\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentToolsList
RegKey5=HKCU\Software\Adobe\Acrobat Reader\DC\AVGeneral\cToolbars
RegKey6=HKCU\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles
RegKey7=HKCU\Software\Adobe\Acrobat Reader\DC\ShareIdentity
RegKey8=HKCU\Software\Adobe\Adobe Synchronizer\DC
[Adobe Reader Touch *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga
DetectFile=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga
Default=False
FileKey1=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE
FileKey2=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\PRICache|*.*
FileKey3=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\LocalState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga\PersistedPickerData\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga!App\DefaultOpenFileSingle|LastLocation
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga\PersistedStorageItemTable\MostRecentlyUsed
[Adobe Reader XI *]
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\11.0
Default=False
RegKey1=HKCU\Software\Adobe\Acrobat Reader\11.0\AVConversionFromPDF
RegKey2=HKCU\Software\Adobe\Acrobat Reader\11.0\AVConversionToPDF
RegKey3=HKCU\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cDockables
RegKey4=HKCU\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cToolbars
RegKey5=HKCU\Software\Adobe\Acrobat Reader\11.0\RememberedViews\cNoCategoryFiles
RegKey6=HKCU\Software\Adobe\Adobe Synchronizer\11.0
[Advanced Browser *]
LangSecRef=3022
DetectFile=%AppData%\Advanced Browser
Default=False
FileKey1=%AppData%\Advanced Browser|keywords.dat;pages.dat;recents.dat
[Advanced Renamer 3 *]
LangSecRef=3024
DetectFile=%AppData%\Hulubulu\Advanced Renamer 3
Default=False
FileKey1=%AppData%\Hulubulu\Advanced Renamer 3\Data\UndoLists|*.*
[Advanced Searchbar *]
LangSecRef=3022
DetectFile=%ProgramFiles%\AdvancedSearchbar\advancedsearchbar.dll
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\AdvancedSearchbar\Cache|*.*
[Advanced System Optimizer 3 *]
LangSecRef=3024
Detect=HKLM\Software\Systweak\ASO3
DetectFile=%ProgramFiles%\Advanced System Optimizer 3\ASO3.exe
Default=False
FileKey1=%AppData%\Systweak\ASO3\Driver Updater|*.log
FileKey2=%AppData%\Systweak\ASO3\Registry Cleaner|*.log
[Advanced System Protector *]
LangSecRef=3024
Detect=HKCU\Software\Systweak\Advanced System Protector
DetectFile=%ProgramFiles%\Advanced System Protector\AdvancedSystemProtector.exe
Default=False
FileKey1=%AppData%\Systweak\Advanced System Protector\Logs|*.xml
[Advanced Uninstaller *]
LangSecRef=3024
Detect1=HKCU\Software\Innovative Solutions\Advanced Uninstaller PRO\9
Detect2=HKCU\Software\Innovative Solutions\Advanced Uninstaller PRO\10
Default=False
RegKey1=HKCU\Software\Innovative Solutions\Advanced Uninstaller PRO\9\compress|listHistoryText
RegKey2=HKCU\Software\Innovative Solutions\Advanced Uninstaller PRO\10\compress|listHistoryText
[AdwCleaner *]
LangSecRef=3024
Detect=HKLM\Software\AdwCleaner
DetectFile=%SystemDrive%\AdwCleaner
Default=False
FileKey1=%SystemDrive%|AdwCleaner*.txt
FileKey2=%SystemDrive%\AdwCleaner|*.txt
RegKey1=HKLM\Software\AdwCleaner|DeleteCount
RegKey2=HKLM\Software\AdwCleaner|SearchCount
RegKey3=HKLM\Software\Wow6432node\AdwCleaner|DeleteCount
RegKey4=HKLM\Software\Wow6432node\AdwCleaner|SearchCount
[Aegisub *]
LangSecRef=3023
Detect=HKLM\Software\Aegisub
Default=False
FileKey1=%AppData%\Aegisub|mru.json
FileKey2=%AppData%\Aegisub\log|*.*|REMOVESELF
FileKey3=%AppData%\Aegisub\recovered|*.*|REMOVESELF
FileKey4=%LocalAppData%\Aegisub\ffms2cache|*.*|REMOVESELF
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Aegisub|*.txt
FileKey6=%ProgramFiles%\Aegisub|*.txt
[Aegisub Backups *]
LangSecRef=3023
Detect=HKLM\Software\Aegisub
Default=False
Warning=Aegisub automatically saves a backup copy of each script you open. This will delete them.
FileKey1=%AppData%\Aegisub\autoback|*.*|REMOVESELF
FileKey2=%AppData%\Aegisub\autosave|*.*|REMOVESELF
[Age of Conan *]
Section=Games
Detect=HKLM\Software\Funcom\Age of Conan
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Funcom\Age of Conan|patcher.log;chrome_debug.log;MiniDump.dmp;CrashLog.txt;ConanPatcher.exe.0.tmp;AgeOfConan.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Funcom\Age of Conan\OldLogs|*.*
FileKey3=%ProgramFiles%\Funcom\Age of Conan|patcher.log;chrome_debug.log;MiniDump.dmp;CrashLog.txt;ConanPatcher.exe.0.tmp;AgeOfConan.log
FileKey4=%ProgramFiles%\Funcom\Age of Conan\OldLogs|*.*
[Age of Empires *]
Section=Games
Detect1=HKLM\Software\Microsoft\Games\Age of Empires
Detect2=HKLM\Software\Microsoft\Microsoft Games\Age of Empires
Detect3=HKLM\Software\Microsoft\microsoft games\age of empires 3
Default=False
FileKey1=%Documents%\My Games\Age of Empires 3|*.txt
FileKey2=%Documents%\My Games\Age of Empires 3\RM|*.dmp.txt
FileKey3=%Documents%\My Games\Age of Mythology|*.txt
RegKey1=HKLM\Software\Microsoft\Games\Age of Empires\1.00|Zone
RegKey2=HKLM\Software\Microsoft\Microsoft Games\Age of Empires|Zone
RegKey3=HKLM\Software\Microsoft\Microsoft Games\Age of Empires Expansion\1.0|Zone
RegKey4=HKLM\Software\Microsoft\Microsoft Games\Age of Empires II: The Conquerors Expansion\1.0|Zone
RegKey5=HKLM\Software\Microsoft\Microsoft Games\Age of Empires\2.0|Zone
[Age of Empires Online *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\105430
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Age Of Empires Online|PatchLog.txt;PatchLogDetail.txt
FileKey2=%ProgramFiles%\Steam\steamapps\common\Age Of Empires Online|PatchLog.txt;PatchLogDetail.txt
[Age of Oracles Taras Journey *]
Section=Games
DetectFile=%CommonAppData%\JollyBear\Age of Oracles Taras Journey
Default=False
FileKey1=%CommonAppData%\JollyBear\Age of Oracles Taras Journey|error.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\JollyBear\Age of Oracles Taras Journey|error.*
[Age of Wonders II *]
Section=Games
DetectFile=%ProgramFiles%\Age of Wonders II
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Age of Wonders II|*aow2Log.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Age of Wonders II\Resource\FX\Spell|*.lnk
FileKey3=%ProgramFiles%\Age of Wonders II|*aow2Log.txt
FileKey4=%ProgramFiles%\Age of Wonders II\Resource\FX\Spell|*.lnk
[Age of Wonders Shadow Magic *]
Section=Games
DetectFile=%ProgramFiles%\Age of Wonders II
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Age of Wonders Shadow Magic|*aowsmLog.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Age of Wonders Shadow Magic\Resource\Maps|*.bak
FileKey3=%ProgramFiles%\Age of Wonders Shadow Magic|*aowsmLog.txt
FileKey4=%ProgramFiles%\Age of Wonders Shadow Magic\Resource\Maps|*.bak
[Agnitum Outpost Pro *]
LangSecRef=3022
Detect=HKLM\Software\Agnitum\Outpost Firewall
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Agnitum\Outpost Firewall|op_data.mdb
FileKey2=%ProgramFiles%\Agnitum\Outpost Firewall|op_data.mdb
[Agomo *]
LangSecRef=3024
DetectFile=%CommonAppData%\Piriform\Agomo
Default=False
FileKey1=%CommonAppData%\Piriform\Agomo\Logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Agomo\Logs|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Agomo\tmp_update|*.*
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Piriform\Agomo\Logs|*.*
FileKey5=%ProgramFiles%\Agomo\Logs|*.*
FileKey6=%ProgramFiles%\Agomo\tmp_update|*.*
[AHA Dialer *]
LangSecRef=3022
Detect=HKLM\System\CurrentControlSet\Services\HWDeviceService.exe
DetectFile=%CommonAppData%\DatacardService\DataCardMonitor.exe
Default=False
FileKey1=%CommonAppData%\DatacardService\log|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\DatacardService\log|*.*
[AI Roboform *]
LangSecRef=3022
Detect=HKCU\Software\Siber Systems
Default=False
FileKey1=%AppData%\RoboForm\_*mirrors_|*.*|RECURSE
FileKey2=%Documents%\My RoboForm Data|mru.rfo;cache.rfo|RECURSE
FileKey3=%Documents%\My RoboForm Data\_gsdata_|*.log;*.gss;*.gsl|RECURSE
RegKey1=HKCU\Software\Siber Systems|_InstallerDir
RegKey2=HKCU\Software\Siber Systems\RoboForm\Query-MRU
[AIDA64 *]
LangSecRef=3021
Detect=HKCU\Software\FinalWire\AIDA64
Default=False
FileKey1=%Documents%\AIDA64 Reports|*.*|REMOVESELF
[Aignes Website-Watcher *]
LangSecRef=3023
Detect=HKCU\Software\aignes\wswatch
Default=False
FileKey1=%AppData%\aignes\WebSite-Watcher\config\favicons|*.*
FileKey2=%AppData%\aignes\website-watcher\config\log|*.*
FileKey3=%AppData%\aignes\WebSite-Watcher\config\settings|*.cfg_bak*
FileKey4=%AppData%\aignes\website-watcher\config\temp|*.*
[Aignes Website-Watcher AutoBackup *]
LangSecRef=3023
Detect=HKCU\Software\aignes\wswatch
Default=False
Warning=This will delete your AutoBackup of your site.
FileKey1=%AppData%\aignes\website-watcher\config\autobackup|*.*
[Aignes Website-Watcher Bookmarks *]
LangSecRef=3023
Detect=HKCU\Software\aignes\wswatch
Default=False
FileKey1=%AppData%\aignes\website-watcher\bookmarks|*.*
[AIM *]
LangSecRef=3022
DetectFile=%LocalAppData%\AOL\AIM
Default=False
FileKey1=%LocalAppData%\AOL\AIM|*.log|RECURSE
FileKey2=%LocalAppData%\AOL\AIM\cache|*.*|REMOVESELF
[Aimersoft DRM Media Converter *]
LangSecRef=3023
Detect=HKLM\Software\Aimersoft\351
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Aimersoft\DRM Media Converter\Log|*.*|REMOVESELF
FileKey2=%ProgramFiles%\Aimersoft\DRM Media Converter\Log|*.*|REMOVESELF
[Aimersoft Helper Compact *]
LangSecRef=3021
DetectFile=%CommonProgramFiles%\Aimersoft\Aimersoft Helper Compact
Default=False
FileKey1=%CommonProgramFiles%\Aimersoft\Aimersoft Helper Compact|ProductUpdateLists.xml;ASHelper.exe_temp;ASHelperSetup.exe_temp
FileKey2=%CommonProgramFiles%\Aimersoft\Aimersoft Helper Compact\DATADICT|*.*|RECURSE
FileKey3=%CommonProgramFiles%\Aimersoft\Aimersoft Helper Compact\Log|*.*|RECURSE
FileKey4=%CommonProgramFiles%\Aimersoft\Aimersoft Helper Compact\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Common Files\Aimersoft\Aimersoft Helper Compact|ProductUpdateLists.xml;ASHelper.exe_temp;ASHelperSetup.exe_temp
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Common Files\Aimersoft\Aimersoft Helper Compact\Log|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Common Files\Aimersoft\Aimersoft Helper Compact\Temp|*.*|RECURSE
RegKey1=HKLM\Software\Aimersoft\Aimersoft Helper Compact
RegKey2=HKLM\Software\Wow6432Node\Aimersoft\Aimersoft Helper Compact
[Aimersoft Video Converter Ultimate *]
LangSecRef=3023
Detect=HKLM\Software\Aimersoft\Aimersoft Video Converter Ultimate
Default=False
FileKey1=%CommonAppData%\Aimersoft\ProductFeatures\*Logs|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Aimersoft\Video Converter Ultimate\TempThumbDir|*.*|RECURSE
FileKey3=%ProgramFiles%\Aimersoft\Video Converter Ultimate\TempThumbDir|*.*|RECURSE
[AIMP *]
LangSecRef=3023
DetectFile1=%ProgramFiles%\AIMP Classic\cAIMP.exe
DetectFile2=%ProgramFiles%\AIMP\AIMP.exe
DetectFile3=%ProgramFiles%\AIMP2\AIMP2.exe
Default=False
FileKey1=%AppData%\AIMP|*.bak
FileKey2=%LocalAppData%\VirtualStore\Program Files*\AIMP*\Data|*.bak|RECURSE
FileKey3=%ProgramFiles%\AIMP*\!Backup|*.*|REMOVESELF
FileKey4=%ProgramFiles%\AIMP*\Data|*.bak|RECURSE
[AirBuccaneers *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\223630
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\AirBuccaneers\abu_data|output_log.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\AirBuccaneers\logs|*.*
FileKey3=%ProgramFiles%\Steam\Steamapps\common\AirBuccaneers\abu_data|output_log.txt
FileKey4=%ProgramFiles%\Steam\Steamapps\common\AirBuccaneers\logs|*.*
[Aiseesoft Media Converter Ultimate *]
LangSecRef=3023
Detect=HKCU\Software\Aiseesoft Studio\Aiseesoft Media Converter Ultimate
Default=False
FileKey1=%LocalAppData%\Aiseesoft Studio\Aiseesoft Media Converter Ultimate|*.txt
RegKey1=HKCU\Software\Aiseesoft Studio\Aiseesoft Media Converter Ultimate\Edit|LastVideoFilePath
[AlbumPlayer *]
LangSecRef=3023
DetectFile=%AppData%\AlbumPlayer
Default=False
FileKey1=%SystemDrive%\AlbumPlayerData\Logging|*.*|RECURSE
[AlbumPlayer Cache *]
LangSecRef=3023
DetectFile=%AppData%\AlbumPlayer
Default=False
FileKey1=%SystemDrive%\AlbumPlayerData\Cache|*.*|RECURSE
[Alcohol 52% *]
LangSecRef=3023
Detect=HKCU\Software\Alcohol Soft
Default=False
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 52%\Basic|Image File Path
RegKey2=HKCU\Software\Alcohol Soft\Alcohol 52%\Images
RegKey3=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageName
[Alibaba *]
LangSecRef=3021
DetectFile=%LocalAppData%\Alibaba\AliSetup
Default=False
FileKey1=%LocalAppData%\Alibaba\AliSetup\*|*.log
[Alien Swarm *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\630
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\alien swarm\swarm|tilegen_log.txt
FileKey2=%ProgramFiles%\Steam\steamapps\common\alien swarm\swarm|tilegen_log.txt
[Aliens: Colonial Marines *]
Section=Games
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Aliens: Colonial Marines_is1
Default=False
FileKey1=%Documents%\My Games\Aliens Colonial Marines\PecanGame\Logs|*.*
[All In One Runtimes *]
LangSecRef=3024
DetectFile1=%SystemDrive%\AiO-Files
DetectFile2=%SystemDrive%\AiOLog.txt
Default=False
FileKey1=%SystemDrive%|AiOLog.txt
FileKey2=%SystemDrive%\AiO-Files|*.*|RECURSE
[All Office Converter *]
LangSecRef=3021
DetectFile=%ProgramFiles%\All Office Converter Platinum
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\All Office Converter Platinum|Eventlog.txt
FileKey2=%ProgramFiles%\All Office Converter Platinum|Eventlog.txt
[All Zombies Must Die! *]
Section=Games
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\All Zombies Must Die!_is1
Default=False
FileKey1=%Documents%\My Games\UnrealEngine3\Bzb2Game\Logs|*.*
[All Zombies Must Die! Installers *]
Section=Games
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\All Zombies Must Die!_is1
Default=False
FileKey1=%ProgramFiles%\Doublesix Games\All Zombies Must Die!\Prerequisites|*.*|REMOVESELF
[AllDup *]
LangSecRef=3024
DetectFile=%AppData%\AllDup
Default=False
FileKey1=%AppData%\AllDup|*.log
[Alternate File Shredder *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Alternate File Shredder_is1
Default=False
FileKey1=%AppData%\Alternate\FileShredder|FileShredderLog*.txt
[Always Right *]
LangSecRef=3024
Detect=HKCU\Software\AlwaysRight
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Superhunter\Always Right\*Backup|*.*
FileKey2=%ProgramFiles%\Superhunter\Always Right\*Backup|*.*
[Alwin 6 *]
LangSecRef=3023
DetectFile=%SystemDrive%\alwin6
Default=False
FileKey1=%SystemDrive%\alwin6\postgresql\9.0\data\pg_log|*.*
[AM-DeadLink *]
LangSecRef=3022
Detect=HKCU\Software\aignes\deadlink
Default=False
FileKey1=%AppData%\aignes\AM-DeadLink|deadlink.log
[Amaya *]
LangSecRef=3022
DetectFile=%UserProfile%\amaya
Default=False
FileKey1=%UserProfile%\amaya|list_url_utf8.dat
FileKey2=%UserProfile%\amaya\*|*.*|REMOVESELF
[Amazing World *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\293500
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\Amazing World\AmazingWorld_Data|output_log.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Amazing World\Cache|*.*|REMOVESELF
FileKey3=%ProgramFiles%\Steam\SteamApps\common\Amazing World\AmazingWorld_Data|output_log.txt
FileKey4=%ProgramFiles%\Steam\SteamApps\Common\Amazing World\Cache|*.*|REMOVESELF
[Amazon Cloud Player *]
LangSecRef=3024
DetectFile=%LocalAppData%\Amazon Cloud Player
Default=False
FileKey1=%LocalAppData%\Amazon Cloud Player\Logs|*.*
[Amazon Downloader *]
LangSecRef=3024
DetectFile=%Documents%\Amazon Downloader Logs
Default=False
FileKey1=%Documents%\Amazon Downloader Logs|*.*|RECURSE
[Amazon Kindle for PC *]
LangSecRef=3023
Detect=HKCU\Software\Amazon\Kindle
Default=False
FileKey1=%LocalAppData%\Amazon\Kindle\Cache|*.*|RECURSE
FileKey2=%LocalAppData%\Amazon\Kindle\Logs|*.txt|RECURSE
[Amazon Kindle for PC Session *]
LangSecRef=3023
Detect=HKCU\Software\Amazon\Kindle
Default=False
RegKey1=HKCU\Software\Amazon\Kindle\User Settings|last_getitems_date
RegKey2=HKCU\Software\Amazon\Kindle\User Settings|last_syncmetadata_date
RegKey3=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate0
RegKey4=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate1
RegKey5=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate2
RegKey6=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate3
RegKey7=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate4
RegKey8=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate5
RegKey9=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate6
RegKey10=HKCU\Software\Amazon\Kindle\User Settings|LastSyncDate7
RegKey11=HKCU\Software\Amazon\Kindle\User Settings|OpenBook
[Amazon MP3 Downloader *]
LangSecRef=3023
Detect1=HKCR\Amazon.AmazonMP3DownloaderPlugin
Detect2=HKCR\Software\Amazon\MP3 Downloader
Default=False
FileKey1=%Documents%\Amazon MP3\Logs|*.*|REMOVESELF
FileKey2=%LocalAppData%\Program Files\Amazon\MP3 Downloader|InstallerLog.txt
[Amazon Music *]
LangSecRef=3024
Detect=HKCU\Software\Amazon\Amazon Music
Default=False
FileKey1=%LocalAppData%\Amazon Music\Logs|*.*
[AMD/ATI *]
LangSecRef=3024
Detect1=HKLM\Software\AMD
Detect2=HKLM\Software\ATI
Detect3=HKLM\Software\ATI Technologies
DetectFile=%ProgramFiles%\ATI Technologies\ATI.ACE
Default=False
FileKey1=%CommonAppData%\AMD\Fuel|*.txt
FileKey2=%CommonAppData%\AMD\KDB|*.log
FileKey3=%LocalAppData%\AMD\Fuel|ClientProxyLog*.*
FileKey4=%LocalAppData%\AMD\GLCache|*.*|RECURSE
FileKey5=%LocalAppData%\ATI\ACE|*.txt
FileKey6=%LocalAppData%\VirtualStore\Program Files*\AMD\amdkmpfd|*.*|REMOVESELF
FileKey7=%LocalAppData%\VirtualStore\Program Files*\AMD\OverDrive|*.log
FileKey8=%LocalAppData%\VirtualStore\Program Files*\ATI Technologies|*.log|RECURSE
FileKey9=%LocalAppData%\VirtualStore\Program Files*\ATI Technologies|cccutil64.txt
FileKey10=%LocalAppData%\VirtualStore\Program Files*\ATI\CIM\Reports|*.*
FileKey11=%LocalAppData%\VirtualStore\ProgramData\AMD\Fuel|*.txt
FileKey12=%LocalAppData%\VirtualStore\ProgramData\AMD\KDB|*.log
FileKey13=%ProgramFiles%\AMD\amdkmpfd|*.*|REMOVESELF
FileKey14=%ProgramFiles%\AMD\OverDrive|*.log
FileKey15=%ProgramFiles%\ATI Technologies|*.log|RECURSE
FileKey16=%ProgramFiles%\ATI Technologies|cccutil64.txt
FileKey17=%ProgramFiles%\ATI\CIM\Reports|*.*
FileKey18=%SystemDrive%\AMD|*.*|REMOVESELF
FileKey19=%SystemDrive%\ATI|*.*|REMOVESELF
FileKey20=%WinDir%\System32|CCCInstall*.log
FileKey21=%WinDir%\SysWOW64|CCCInstall*.log
[America's Army 2 *]
Section=Games
DetectFile=%ProgramFiles%\USArmy\America's Army 2
Default=False
FileKey1=%LocalAppData%\AA2DeployClient|debug*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\USArmy\America's Army 2|*.log|RECURSE
FileKey3=%ProgramFiles%\USArmy\America's Army 2|*.log|RECURSE
[Amnesia The Dark Descent *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\57300
Default=False
FileKey1=%Documents%\Amnesia|*.log|RECURSE
[Amsn *]
LangSecRef=3022
Detect=HKCU\Software\aMSN
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\amsn\scripts\amsn_received|*.incomplete
FileKey2=%ProgramFiles%\amsn\scripts\amsn_received|*.incomplete
FileKey3=%UserProfile%\amsn\*\FT\cache|*.*
FileKey4=%UserProfile%\amsn\*\logs\*|*.log
FileKey5=%UserProfile%\amsn\*\winks\cache\tmp|*.*
FileKey6=%UserProfile%\amsn\displaypic\cache|*.*
[AMYUNI PDF Converter *]
LangSecRef=3021
DetectFile=%CommonAppData%\Package Cache\3DBECED19CFC2819A7E0BE14463CF18FC8720D91\amyuni_pdfconverter_5_00
Default=False
FileKey1=%CommonAppData%\Package Cache\3DBECED19CFC2819A7E0BE14463CF18FC8720D91\amyuni_pdfconverter_5_00|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Package Cache\3DBECED19CFC2819A7E0BE14463CF18FC8720D91\amyuni_pdfconverter_5_00|*.log|RECURSE
[And Yet It Moves *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\18700
Default=False
FileKey1=%AppData%\Broken Rules\And Yet It Moves Steam|console.log
[Android Notifier Desktop *]
LangSecRef=3022
DetectFile=%UserProfile%\.android\android-notifier-desktop
Default=False
FileKey1=%UserProfile%\.android\android-notifier-desktop|android-notifier-desktop.*
[Android Studio *]
LangSecRef=3021
Detect=HKCU\Software\Android Open Source Project\Emulator
Default=False
FileKey1=%UserProfile%\.AndroidStudio2.3\system\log|*.*|REMOVESELF
FileKey2=%UserProfile%\.AndroidStudio2.3\system\tmp|*.*
FileKey3=%UserProfile%\.gradle|*.log|RECURSE
[Anfibia Switch *]
LangSecRef=3021
Detect=HKCU\Software\Anfibia Switch
Default=False
FileKey1=%CommonAppData%\Anfibia Switch|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Anfibia Switch|*.log|RECURSE
[Angry Birds Space *]
Section=Games
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\1ED5AEA5.AngryBirdsSpace_p2gbknwb5d8r2
DetectFile=%LocalAppData%\Packages\1ED5AEA5.AngryBirdsSpace_p2gbknwb5d8r2
Default=False
FileKey1=%LocalAppData%\Packages\*.AngryBirdsSpace_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*.AngryBirdsSpace_*\AC\Microsoft\CryptnetUrlCache\*|*.*
[Angry Birds Star Wars *]
Section=Games
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\1ED5AEA5.AngryBirdsBlack_p2gbknwb5d8r2
DetectFile=%LocalAppData%\Packages\1ED5AEA5.AngryBirdsBlack_p2gbknwb5d8r2
Default=False
FileKey1=%LocalAppData%\Packages\*.AngryBirdsBlack_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*.AngryBirdsBlack_*\AC\Microsoft\CryptnetUrlCache\*|*.*
[Anim8or *]
LangSecRef=3021
Detect=HKCU\Software\Silicon Valley Software\Anim8or
Default=False
RegKey1=HKCU\Software\Silicon Valley Software\Anim8or|File1
RegKey2=HKCU\Software\Silicon Valley Software\Anim8or|File2
RegKey3=HKCU\Software\Silicon Valley Software\Anim8or|File3
RegKey4=HKCU\Software\Silicon Valley Software\Anim8or|File4
[Anki Backups *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Anki\Anki.exe
Default=False
FileKey1=%AppData%\.anki\backups|*.*
[Annie's Millions *]
Section=Games
DetectFile=%AppData%\PoBros\Annies Millions
Default=False
FileKey1=%AppData%\PoBros\Annies Millions|logfile.txt
[ANNO 2070 *]
Section=Games
DetectFile=%AppData%\Ubisoft\ANNO 2070
Default=False
FileKey1=%AppData%\Ubisoft\ANNO 2070\Cache|*.*|REMOVESELF
FileKey2=%AppData%\Ubisoft\ANNO 2070\Logs|*.log;*.dmp|RECURSE
[Antichamber *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\105430
Default=False
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Antichamber\UDKGame\Logs|*.*
[Anvisoft Cloud System Booster *]
LangSecRef=3024
Detect=HKLM\Software\Anvisoft\Cloud System Booster
Default=False
FileKey1=%LocalAppData%\Anvisoft\Anvi Slim Toolbar\FFToobar\tmp|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Anvisoft\Cloud System Booster|*.log;*.txt
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Anvisoft\Cloud System Booster\logs|*.*
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Anvisoft\Cloud System Booster\reports|*.*
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Anvisoft\Cloud System Booster\VLog|*.*
FileKey6=%ProgramFiles%\Anvisoft\Cloud System Booster|*.log;*.txt
FileKey7=%ProgramFiles%\Anvisoft\Cloud System Booster\logs|*.*
FileKey8=%ProgramFiles%\Anvisoft\Cloud System Booster\reports|*.*
FileKey9=%ProgramFiles%\Anvisoft\Cloud System Booster\VLog|*.*
[Anvisoft Cloud System Booster Backups *]
LangSecRef=3024
Detect=HKLM\Software\Anvisoft\Cloud System Booster
Default=False
Warning=This will delete your backups. You will be unable to undo any changes made with Cloud System Booster.
FileKey1=%LocalAppData%\Anvisoft\Anvi Slim Toolbar\FFToobar|*.*|REMOVESELF
FileKey2=%LocalAppData%\Anvisoft\Anvi Slim Toolbar\IEToobar|*.*|REMOVESELF
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Anvisoft\Cloud System Booster\bak|*.*
FileKey4=%ProgramFiles%\Anvisoft\Cloud System Booster\bak|*.*
[AnvSoft Any Audio Converter *]
LangSecRef=3023
Detect=HKCU\Software\AnvSoft\Any Audio Converter
Default=False
FileKey1=%AppData%\AnvSoft\Any Audio Converter|*.log
[AnvSoft Any DVD Converter *]
LangSecRef=3023
Detect=HKCU\Software\AnvSoft\Any DVD Converter Professional
Default=False
FileKey1=%AppData%\AnvSoft\Any DVD Converter Professional|*.log
[AnvSoft Any DVD Converter Database *]
LangSecRef=3023
Detect=HKCU\Software\AnvSoft\Any DVD Converter Professional
Default=False
FileKey1=%AppData%\AnvSoft\Any DVD Converter Professional|*.db
[AnvSoft Any Video Converter *]
LangSecRef=3023
Detect=HKCU\Software\AnvSoft\Any Video Converter
Default=False
FileKey1=%AppData%\AnvSoft\Any Video Converter|*.log|RECURSE
FileKey2=%AppData%\AnvSoft\Any Video Converter\thumbs|*.*|RECURSE
[Anvsoft Any Video Converter Output *]
LangSecRef=3023
Detect=HKCU\Software\AnvSoft\Any Video Converter
Default=False
Warning=This will delete the contents of your output folder.
FileKey1=%Documents%\Any Video Converter|*.*|RECURSE
[AnyDVD *]
LangSecRef=3023
Detect=HKCU\Software\SlySoft\AnyDVD
Default=False
FileKey1=%Documents%\AnyDVD_logs|*.*|REMOVESELF
[AOL *]
LangSecRef=3022
Detect=HKCU\Software\America Online
Default=False
FileKey1=%AppData%\AOL\C_AOL*|*.tmp|RECURSE
FileKey2=%CommonAppData%\AOL Downloads|*.*|RECURSE
FileKey3=%CommonAppData%\AOL\C_AOL*|*.tmp|RECURSE
FileKey4=%CommonAppData%\AOL\C_AOL*\bart|*.*|RECURSE
FileKey5=%CommonAppData%\AOL\C_AOL*\spool|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\AOL Downloads|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\AOL\C_AOL*|*.tmp|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\AOL\C_AOL*\bart|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\ProgramData\AOL\C_AOL*\spool|*.*|RECURSE
RegKey1=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent IM ScreenNames
RegKey2=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\recent ScreenNames
RegKey3=HKCU\Software\America Online\AOL Instant Messenger ™\CurrentVersion\Users
[APC PowerChute Personal Edition *]
LangSecRef=3024
Detect=HKCU\Software\APC\PowerChute Personal Edition
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\APC\PowerChute Personal Edition|PCPELog.txt
FileKey2=%ProgramFiles%\APC\PowerChute Personal Edition|PCPELog.txt
FileKey3=%WinDir%\System32|PCPELog.txt
FileKey4=%WinDir%\SysWOW64|PCPELog.txt
[ApHeMo *]
LangSecRef=3022
Detect=HKCU\Software\KC Softwares\ApHeMo
Default=False
FileKey1=%AppData%\ApHeMo|*.log
[Apple iTunes *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AppleInc.iTunes_nzyj5cx40ttqa
DetectFile=%LocalAppData%\Packages\AppleInc.iTunes_nzyj5cx40ttqa
Default=False
FileKey1=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\AppleInc.iTunes_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Local\Apple Computer\iTunes|Cache.db;*.xml
FileKey5=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Local\Microsoft\Windows\Caches|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\LocalLow\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\iTunes\Cookies|Cookies.binarycookies
FileKey8=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\iTunes\Device Support|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\AppleInc.iTunes_*\LocalCache\Roaming\Apple Computer\Logs|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\AppleInc.iTunes_*\SystemAppData\Helium\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\AppleInc.iTunes_*\TempState|*.*|RECURSE
FileKey12=%WinDir%\System32\config\systemprofile\AppData\Roaming\Apple Computer\Logs|*.*|RECURSE
[Apple MobileSync Backups *]
LangSecRef=3023
Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AppleInc.iTunes_nzyj5cx40ttqa
Detect2=HKLM\Software\Apple Computer, Inc.
Default=False
FileKey1=%AppData%\Apple Computer\MobileSync\Backup|*.*|RECURSE
FileKey2=%UserProfile%\Apple\MobileSync\Backup|*.*|RECURSE
[Application History *]
LangSecRef=3025
DetectFile=%LocalAppData%\ApplicationHistory
Default=False
FileKey1=%LocalAppData%\ApplicationHistory|*.*|RECURSE
[Appupdater *]
LangSecRef=3024
DetectFile=%AppData%\Appupdater
Default=False
FileKey1=%AppData%\Appupdater|appupdaterw.log
FileKey2=%CommonAppData%\Appupdater|*.log
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Appupdater|*.log
[AQQ *]
LangSecRef=3022
Detect1=HKCU\Software\MyPortal\AQQ
Detect2=HKCU\Software\Wapster\AQQ
Default=False
FileKey1=%LocalAppData%\MyPortal\AQQ Folder\Profiles\*\Data\*Avatars|*.*
FileKey2=%UserProfile%\WapSter\AQQ Folder\Profiles\*\Data\*Avatars|*.*
[AQQ Cache *]
LangSecRef=3022
Detect1=HKCU\Software\MyPortal\AQQ
Detect2=HKCU\Software\Wapster\AQQ
Default=False
FileKey1=%LocalAppData%\MyPortal\AQQ Folder\Profiles\*\Data\*Cache|*.*
FileKey2=%UserProfile%\WapSter\AQQ Folder\Profiles\*\Data\*Cache|*.*
[AQQ Chat History *]
LangSecRef=3022
Detect1=HKCU\Software\MyPortal\AQQ
Detect2=HKCU\Software\Wapster\AQQ
Default=False
FileKey1=%LocalAppData%\MyPortal\AQQ Folder\Profiles\*\Data\Archive|*.DC2
FileKey2=%LocalAppData%\MyPortal\AQQ Folder\Profiles\*\Data\Temp|*.*
FileKey3=%UserProfile%\WapSter\AQQ Folder\Profiles\*\Data\Archive|*.DC2
FileKey4=%UserProfile%\WapSter\AQQ Folder\Profiles\*\Data\Temp|*.*
[Arasan Chess *]
Section=Games
Detect=HKCU\Software\Arasan\Arasan
Default=False
RegKey1=HKCU\Software\Arasan\Arasan\Recent File List
[Arcane Worlds *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\269610
Default=False
FileKey1=%AppData%\ArcaneWorlds|log.txt
[ArcSoft MediaConverter *]
LangSecRef=3023
Detect=HKLM\Software\arcsoft\mediaconverter
Default=False
FileKey1=%AppData%\ArcSoft\ArcSoft MediaConverter\*|saved.proj
FileKey2=%AppData%\ArcSoft\log|*.log
[Argus Monitor *]
LangSecRef=3024
Detect=HKCU\Software\Argotronic\Argus Monitor
Default=False
FileKey1=%Documents%|ArgusMonitor_EventLog.txt;ArgusMonitor_CSVLog.csv
FileKey2=%LocalAppData%\VirtualStore\Program Files*|ArgusMonitor_EventLog.txt;ArgusMonitor_CSVLog.csv
FileKey3=%ProgramFiles%|ArgusMonitor_EventLog.txt;ArgusMonitor_CSVLog.csv
[ARO *]
LangSecRef=3024
Detect1=HKCU\Software\Sammsoft\ARO\Version 2011
Detect2=HKCU\Software\Sammsoft\ARO\Version 2013
Default=False
FileKey1=%AppData%\Sammsoft\ARO\Version *\Logs|*.txt
[Ashampoo Burning Studio *]
LangSecRef=3021
Detect1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5
Detect2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6
Detect3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7
Detect4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8
Detect5=HKCU\Software\Ashampoo\Ashampoo Burning Studio 12
Detect6=HKCU\Software\Ashampoo\Ashampoo Burning Studio 14
Detect7=HKCU\Software\Ashampoo\Ashampoo Burning Studio 15
Detect8=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16
Detect9=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18
Detect10=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19
Detect11=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007
Detect12=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2009
Detect13=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016
Detect14=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017
Detect15=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018
Default=False
FileKey1=%AppData%\Ashampoo|*.log;*.txt;*.xml|RECURSE
FileKey2=%LocalAppData%\Ashampoo\BaNT|*.*|RECURSE
RegKey1=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Burn Image Project\SelectImage
RegKey2=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\AddDialog
RegKey3=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Data Disc Project\DumpImage
RegKey4=HKCU\Software\Ashampoo\Ashampoo Burning Studio 5\Unknown Project\AddDialog
RegKey5=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Burn Image Project\SelectImage
RegKey6=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Data Disc Project\AddDialog
RegKey7=HKCU\Software\Ashampoo\Ashampoo Burning Studio 6\Unknown Project\AddDialog
RegKey8=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Burn Image Project\SelectImage
RegKey9=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Data Disc Project\AddDialog
RegKey10=HKCU\Software\Ashampoo\Ashampoo Burning Studio 7\Unknown Project\AddDialog
RegKey11=HKCU\Software\Ashampoo\Ashampoo Burning Studio 8\Data Disc Project\AddDialog
RegKey12=HKCU\Software\Ashampoo\Ashampoo Burning Studio 14\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory
RegKey13=HKCU\Software\Ashampoo\Ashampoo Burning Studio 14\tempFiles
RegKey14=HKCU\Software\Ashampoo\Ashampoo Burning Studio 15\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory
RegKey15=HKCU\Software\Ashampoo\Ashampoo Burning Studio 15\tempFiles
RegKey16=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory
RegKey17=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Backup Project\BackupOptions|CustomLocation
RegKey18=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\BDMV Disc Project\SelectBDMVFolder|BdmvPath
RegKey19=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Browse Image Project\BrowseImageFile|ImagePath
RegKey20=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey21=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey22=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Burn Image Project\SelectImage|ImagePath
RegKey23=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Data Disc Project\DumpImage|ImagePath
RegKey24=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory
RegKey25=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\DVD-Video Disc Project\MoviesPage|Path
RegKey26=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\DVD-Video Disc Project\SaveDialog_authed.CMoviesPage.Movies|InitialDirectory
RegKey27=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Logs
RegKey28=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\tempFiles
RegKey29=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\Unknown Project
RegKey30=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VCD Project\SaveDialog_OnAddMovies|InitialDirectory
RegKey31=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VIDEO_TS Disc Project\DumpImage|ImagePath
RegKey32=HKCU\Software\Ashampoo\Ashampoo Burning Studio 16\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath
RegKey33=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory
RegKey34=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Backup Project\BackupOptions|CustomLocation
RegKey35=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\BDMV Disc Project\SelectBDMVFolder|BdmvPath
RegKey36=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Browse Image Project\BrowseImageFile|ImagePath
RegKey37=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey38=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey39=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Burn Image Project\SelectImage|ImagePath
RegKey40=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Data Disc Project\DumpImage|ImagePath
RegKey41=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory
RegKey42=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\DVD-Video Disc Project\MoviesPage|Path
RegKey43=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\DVD-Video Disc Project\SaveDialog_authed.CMoviesPage.Movies|InitialDirectory
RegKey44=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Logs
RegKey45=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\tempFiles
RegKey46=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\Unknown Project
RegKey47=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\VCD Project\SaveDialog_OnAddMovies|InitialDirectory
RegKey48=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\VIDEO_TS Disc Project\DumpImage|ImagePath
RegKey49=HKCU\Software\Ashampoo\Ashampoo Burning Studio 18\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath
RegKey50=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory
RegKey51=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Backup Project\BackupOptions|CustomLocation
RegKey52=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\BDMV Disc Project\SelectBDMVFolder|BdmvPath
RegKey53=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Browse Image Project\BrowseImageFile|ImagePath
RegKey54=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey55=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey56=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Burn Image Project\SelectImage|ImagePath
RegKey57=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Data Disc Project\DumpImage|ImagePath
RegKey58=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory
RegKey59=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\DVD-Video Disc Project\MoviesPage|Path
RegKey60=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\DVD-Video Disc Project\SaveDialog_authed.CMoviesPage.Movies|InitialDirectory
RegKey61=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Logs
RegKey62=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\tempFiles
RegKey63=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\Unknown Project
RegKey64=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\VCD Project\SaveDialog_OnAddMovies|InitialDirectory
RegKey65=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\VIDEO_TS Disc Project\DumpImage|ImagePath
RegKey66=HKCU\Software\Ashampoo\Ashampoo Burning Studio 19\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath
RegKey67=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Burn Image Project\AddDialog
RegKey68=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Data Disc Project\AddDialog
RegKey69=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Dump Image Project\DumpImage
RegKey70=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2007\Unknown Project\AddDialog
RegKey71=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory
RegKey72=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Backup Project\BackupOptions|CustomLocation
RegKey73=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Browse Image Project\BrowseImageFile|ImagePath
RegKey74=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey75=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey76=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Burn Image Project\SelectImage|ImagePath
RegKey77=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Data Disc Project\DumpImage|ImagePath
RegKey78=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory
RegKey79=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Logs
RegKey80=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\tempFiles
RegKey81=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\Unknown Project
RegKey82=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\VCD Project\SaveDialog_OnAddMovies|InitialDirectory
RegKey83=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\VIDEO_TS Disc Project\DumpImage|ImagePath
RegKey84=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2016\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath
RegKey85=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory
RegKey86=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Backup Project\BackupOptions|CustomLocation
RegKey87=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Browse Image Project\BrowseImageFile|ImagePath
RegKey88=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey89=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey90=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Burn Image Project\SelectImage|ImagePath
RegKey91=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Data Disc Project\DumpImage|ImagePath
RegKey92=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory
RegKey93=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Logs
RegKey94=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\tempFiles
RegKey95=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\Unknown Project
RegKey96=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\VCD Project\SaveDialog_OnAddMovies|InitialDirectory
RegKey97=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\VIDEO_TS Disc Project\DumpImage|ImagePath
RegKey98=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2017\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath
RegKey99=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Audio Disc Project\SaveDialog_CPlaylistDlgEx|InitialDirectory
RegKey100=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Backup Project\BackupOptions|CustomLocation
RegKey101=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Browse Image Project\BrowseImageFile|ImagePath
RegKey102=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Browse Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey103=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Burn Image Project\SaveDialog_SelectImageBrowse|InitialDirectory
RegKey104=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Burn Image Project\SelectImage|ImagePath
RegKey105=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Data Disc Project\DumpImage|ImagePath
RegKey106=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Data Disc Project\SaveDialog_AddFilesAndDirs|InitialDirectory
RegKey107=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Logs
RegKey108=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\tempFiles
RegKey109=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\Unknown Project
RegKey110=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\VCD Project\SaveDialog_OnAddMovies|InitialDirectory
RegKey111=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\VIDEO_TS Disc Project\DumpImage|ImagePath
RegKey112=HKCU\Software\Ashampoo\Ashampoo Burning Studio 2018\VIDEO_TS Disc Project\SelectVideoTSFolder|VideoTSPath
[Ashampoo Snap *]
LangSecRef=3024
Detect1=HKCU\Software\Ashampoo\Ashampoo Snap 7
Detect2=HKCU\Software\Ashampoo\Ashampoo Snap 8
Detect3=HKCU\Software\Ashampoo\Ashampoo Snap 9
Detect4=HKCU\Software\Ashampoo\Ashampoo Snap 10
Detect5=HKCU\Software\Ashampoo\Ashampoo Snap 2017
Detect6=HKCU\Software\Ashampoo\Ashampoo Snap 2018
Default=False
FileKey1=%AppData%\Ashampoo|*.log;*.txt;*.xml|RECURSE
FileKey2=%LocalAppData%\Ashampoo\BaNT|*.*|RECURSE
FileKey3=%LocalAppData%\CrashRpt\UnsentCrashReports|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Ashampoo\Ashampoo Snap *|_NLogMsg.txt
FileKey5=%ProgramFiles%\Ashampoo\Ashampoo Snap *|_NLogMsg.txt
[Ashampoo Snap AutoSave *]
LangSecRef=3024
Detect1=HKCU\Software\Ashampoo\Ashampoo Snap 7
Detect2=HKCU\Software\Ashampoo\Ashampoo Snap 8
Detect3=HKCU\Software\Ashampoo\Ashampoo Snap 9
Detect4=HKCU\Software\Ashampoo\Ashampoo Snap 10
Default=False
FileKey1=%Pictures%\Ashampoo Snap *\_SNAPDOC|*.*|RECURSE
[Ashley Jones - The Heart Of Egypt *]
Section=Games
DetectFile=%CommonAppData%\Fenomen Games\Ashley Jones - The Heart Of Egypt
Default=False
FileKey1=%CommonAppData%\Fenomen Games\Ashley Jones - The Heart Of Egypt|*.log
[AstroGrep *]
LangSecRef=3024
Detect=HKCU\Software\AstroGrep
Default=False
FileKey1=%AppData%\AstroGrep|AstroGrep.general.config
FileKey2=%AppData%\AstroGrep\Log|*.log
[ASUS Logs *]
LangSecRef=3024
DetectFile1=%AppData%\ASUS WebStorage
DetectFile2=%CommonAppData%\Asus
DetectFile3=%ProgramFiles%\ASUS\AI Suite
Default=False
FileKey1=%AppData%\ASUS WebStorage\Logs|*.*
FileKey2=%CommonAppData%\Asus\AsusAppStore|*.log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\ASUS\*|*.log;*log*.txt|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Asus\AsusAppStore|*.log|RECURSE
FileKey5=%ProgramFiles%\ASUS\*|*.log;*log*.txt|RECURSE
FileKey6=%SystemDrive%|wifi.log
[Atheros Driver *]
LangSecRef=3021
Detect=HKLM\Atheros
Default=False
FileKey1=%CommonAppData%\Atheros|*.log|RECURSE
FileKey2=%CommonAppData%\Qualcomm Atheros WiFi Driver Installation|*.Log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Atheros|*.log|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Qualcomm Atheros WiFi Driver Installation|*.Log|RECURSE
[Audials 10 *]
LangSecRef=3023
Detect=HKLM\Software\RapidSolution\Audials_2013
Default=False
FileKey1=%AppData%\CrashRpt\UnsentCrashReports|*.dmp;*.log;*.xml|RECURSE
FileKey2=%CommonAppData%\RapidSolution\Audials_2013\ChildMSILogs|*.txt
FileKey3=%LocalAppData%\RapidSolution\Audials_2013\Log|*.log;*.txt|RECURSE
FileKey4=%LocalAppData%\RapidSolution\Audials_Software\RapidSolution\Audials_2013\Log|*.log;*.txt|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\RapidSolution\Audials_2013\ChildMSILogs|*.txt
[Audio Sliders *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Audio Sliders
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Audio Sliders|*.log
FileKey2=%ProgramFiles%\Audio Sliders|*.log
[Audio/Video Stats *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%LocalAppData%|DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[AudioGrail *]
LangSecRef=3023
Detect=HKCU\Software\KC Softwares\AudioGrail
Default=False
FileKey1=%AppData%\KC Softwares\AudioGrail|ag.sel;AudioGrail.log
[Auslogics BoostSpeed *]
LangSecRef=3024
Detect=HKCU\Software\Auslogics\BoostSpeed
Default=False
FileKey1=%AppData%\Auslogics|*.htm;*.html;*.log;*.rsc;*.sta;*.xml|RECURSE
FileKey2=%CommonAppData%\Auslogics\BoostSpeed\*.x|*.err;*.htm;*.html;*.log;*.rsc;*.sta;*.xml|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Auslogics\Auslogics BoostSpeed|rdboot.log
FileKey4=%ProgramFiles%\Auslogics\Auslogics BoostSpeed|rdboot.log
RegKey1=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|DiskCleaner.AppLogic.ErrorsFailed
RegKey2=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|DiskCleaner.AppLogic.ErrorsFound
RegKey3=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|DiskCleaner.AppLogic.ErrorsRemoved
RegKey4=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|DiskCleaner.AppLogic.LastScan
RegKey5=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|RegCleaner.AppLogic.ErrorsFailed
RegKey6=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|RegCleaner.AppLogic.ErrorsFound
RegKey7=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|RegCleaner.AppLogic.ErrorsRemoved
RegKey8=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|RegCleaner.AppLogic.LastScan
RegKey9=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|TrackEraser.LastScan.DateTimeHi
RegKey10=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|TrackEraser.LastScan.DateTimeLo
RegKey11=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|TrackEraser.LastScan.FailedToRemove
RegKey12=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|TrackEraser.LastScan.Found
RegKey13=HKCU\Software\Auslogics\BoostSpeed\5.x\Settings|TrackEraser.LastScan.Removed
RegKey14=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.DisksList.SelectedDrives
RegKey15=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.DateTime
RegKey16=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.DisksList
RegKey17=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.FilesCount
RegKey18=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsFailed
RegKey19=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsFound
RegKey20=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsRemoved
RegKey21=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal
RegKey22=HKLM\Software\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.LastScan
RegKey23=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.DisksList.SelectedDrives
RegKey24=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.DateTime
RegKey25=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.DisksList
RegKey26=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|DiskDefrag.LastDefragment.FilesCount
RegKey27=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsFailed
RegKey28=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsFound
RegKey29=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsRemoved
RegKey30=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal
RegKey31=HKLM\Software\Wow6432Node\Auslogics\BoostSpeed\7.x\Settings|RegCleaner.AppLogic.LastScan
[Auslogics Disk Defrag *]
LangSecRef=3024
Detect1=HKCU\Software\Auslogics\Disk Defrag Portable
Detect2=HKLM\Software\Auslogics\Disk Defrag Portable
Detect3=HKLM\Software\Auslogics\Disk Defrag Professional
Detect4=HKLM\Software\Auslogics\DiskDefrag
Detect5=HKLM\Software\Auslogics\DiskDefrag Portable
Default=False
FileKey1=%AppData%\Auslogics\Disk*Defrag*\Logs|*.*|RECURSE
FileKey2=%AppData%\Auslogics\Disk*Defrag*\Reports|*.*|RECURSE
FileKey3=%CommonAppData%\Auslogics\Disk*Defrag*\*\Reports|*.*
FileKey4=%ProgramFiles%\Auslogics\Disk Defrag Professional|ndefrg.log
[Auslogics Registry Cleaner *]
LangSecRef=3024
Detect1=HKCU\Software\Auslogics\Registry Cleaner
Detect2=HKLM\Software\Auslogics\Registry Cleaner\3.x
Detect3=HKLM\Software\Auslogics\Registry Cleaner\4.x
Detect4=HKLM\Software\Auslogics\Registry Cleaner\5.X
Default=False
Warning=This will reset your scan results.
FileKey1=%AppData%\Auslogics|*.htm;*.html;*.log;*.rsc;*.sta;*.xml|RECURSE
FileKey2=%CommonAppData%\Auslogics\Registry Cleaner\*.x|*.htm;*.html;*.log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Auslogics\Registry Cleaner\*.x|*.htm;*.html;*.log|RECURSE
RegKey1=HKCU\Software\Auslogics\Registry Cleaner\2.x\Settings|RegCleaner.AppLogic.ErrorsFailed
RegKey2=HKCU\Software\Auslogics\Registry Cleaner\2.x\Settings|RegCleaner.AppLogic.ErrorsFound
RegKey3=HKCU\Software\Auslogics\Registry Cleaner\2.x\Settings|RegCleaner.AppLogic.ErrorsRemoved
RegKey4=HKCU\Software\Auslogics\Registry Cleaner\2.x\Settings|RegCleaner.AppLogic.LastScan
RegKey5=HKLM\Software\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsFailed
RegKey6=HKLM\Software\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsFound
RegKey7=HKLM\Software\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsRemoved
RegKey8=HKLM\Software\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal
RegKey9=HKLM\Software\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.LastScan
RegKey10=HKLM\Software\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsFailed
RegKey11=HKLM\Software\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsFound
RegKey12=HKLM\Software\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsRemoved
RegKey13=HKLM\Software\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal
RegKey14=HKLM\Software\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.LastScan
RegKey15=HKLM\Software\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsFailed
RegKey16=HKLM\Software\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsFound
RegKey17=HKLM\Software\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsRemoved
RegKey18=HKLM\Software\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal
RegKey19=HKLM\Software\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.LastScan
RegKey20=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsFailed
RegKey21=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsFound
RegKey22=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsRemoved
RegKey23=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal
RegKey24=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\3.x\Settings|RegCleaner.AppLogic.LastScan
RegKey25=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsFailed
RegKey26=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsFound
RegKey27=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsRemoved
RegKey28=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal
RegKey29=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\4.x\Settings|RegCleaner.AppLogic.LastScan
RegKey30=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsFailed
RegKey31=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsFound
RegKey32=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsRemoved
RegKey33=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.ErrorsRemovedTotal
RegKey34=HKLM\Software\Wow6432Node\Auslogics\Registry Cleaner\5.X\Settings|RegCleaner.AppLogic.LastScan
[Auslogics Registry Defrag *]
LangSecRef=3024
Detect=HKCU\Software\Auslogics\Registry Defrag
Default=False
FileKey1=%AppData%\Auslogics\Registry Defrag\Logs|*.*
FileKey2=%AppData%\Auslogics\Registry Defrag\Reports|*.*
[Auslogics System Information *]
LangSecRef=3024
Detect=HKCU\Software\Auslogics\System Information
Default=False
FileKey1=%AppData%\Auslogics\System Information|*.*
[Authhost *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windows.authhost.sso_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\microsoft.windows.authhost.sso_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\PRICache|*.*
FileKey7=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\LocalState\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\LocalState\navigationHistory|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\microsoft.windows.authhost.sso_*\TempState|*.*|RECURSE
[Auto BCC For MS Outlook *]
LangSecRef=3021
DetectFile=%AppData%\Add-in Express\Auto BCC For Microsoft Outlook
Default=False
FileKey1=%AppData%\Add-in Express\Auto BCC For Microsoft Outlook|*.log
[Auto Text Expander *]
LangSecRef=3021
DetectFile=%AppData%\Winsome Technologies\Auto Text Expander 1.0
Default=False
FileKey1=%AppData%\Winsome Technologies\Auto Text Expander 1.0|*.log
[Autobahn *]
LangSecRef=3021
DetectFile=%UserProfile%\.autobahn
Default=False
FileKey1=%UserProfile%\.autobahn|autobahn-log*.*
[Autodesk Design Review MRU *]
LangSecRef=3023
Detect=HKCU\Software\AutoDesk\DWF Common
Default=False
RegKey1=HKCU\Software\AutoDesk\DWF Common\Preferences\MRUList
[AutoIt3 *]
LangSecRef=3021
Detect=HKCU\Software\AutoIt v3
Default=False
FileKey1=%UserProfile%|SciTE.*
RegKey1=HKCU\Software\AutoIt v3\Aut2Exe|LastExeDir
RegKey2=HKCU\Software\AutoIt v3\Aut2Exe|LastIcon
RegKey3=HKCU\Software\AutoIt v3\Aut2Exe|LastIconDir
RegKey4=HKCU\Software\AutoIt v3\Aut2Exe|LastScriptDir
[AutoPlay Devices *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This will clear out devices and drives that you've connected to your computer from AutoPlay.
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\KnownDevices
[AvaFind *]
LangSecRef=3023
Detect=HKLM\Software\Think Less Do More Services\AVA Find
Default=False
FileKey1=%AppData%\AvaFind Data|*00.db
[Avant Browser *]
LangSecRef=3022
Detect=HKCU\Software\Avant Browser
Default=False
FileKey1=%AppData%\Avant Browser|keywords.dat;pages.dat;recents.dat;reopen.dat
[Avast *]
LangSecRef=3024
Detect=HKCU\Software\AVAST Software\Avast
Default=False
FileKey1=%CommonAppData%\AVAST Software\Avast|Log.db;backend.txt
FileKey2=%CommonAppData%\AVAST Software\Avast\backup|*.*|RECURSE
FileKey3=%CommonAppData%\AVAST Software\Avast\log|*.*
FileKey4=%CommonAppData%\AVAST Software\Avast\report|*.txt
FileKey5=%CommonAppData%\AVAST Software\Browser|*.*|RECURSE
FileKey6=%CommonAppData%\AVAST Software\Persistent Data\Avast\Logs|*.log
FileKey7=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Avast|Log.db;backend.txt
FileKey8=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Avast\backup|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Avast\log|*.*
FileKey10=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Avast\report|*.txt
FileKey11=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Browser|*.*|RECURSE
FileKey12=%LocalAppData%\VirtualStore\ProgramData\AVAST Software\Persistent Data\Avast\Logs|*.log
RegKey1=HKCU\Software\AVAST Software\Avast Browser Cleanup
[AVG *]
LangSecRef=3024
Detect=HKLM\Software\AVG
Default=False
FileKey1=%AppData%\AVG\Antivirus\log|*.*|RECURSE
FileKey2=%CommonAppData%\AVG\Antivirus|*.old
FileKey3=%CommonAppData%\AVG\Antivirus\GrimeFighter2|*.txt
FileKey4=%CommonAppData%\AVG\Antivirus\log|*.log
FileKey5=%CommonAppData%\AVG\Antivirus\opm|*.*|RECURSE
FileKey6=%CommonAppData%\AVG\Antivirus\report|*.*|RECURSE
FileKey7=%CommonAppData%\Avg\Antivirus\SWCUData\Cache|*.*|RECURSE
FileKey8=%CommonAppData%\Avg\Antivirus\SWCUData\icons|*.*|RECURSE
FileKey9=%CommonAppData%\AVG\Persistent Data\Antivirus\Logs|*.*|RECURSE
FileKey10=%LocalAppData%\AVG\log|*.*|RECURSE
FileKey11=%LocalAppData%\AvgSetupLog|*.*|REMOVESELF
FileKey12=%WinDir%\System32\config\systemprofile\AppData\Local\Avg\log|*.*|RECURSE
FileKey13=%WinDir%\System32\config\systemprofile\AppData\Local\AvgSetupLog|*.*|REMOVESELF
FileKey14=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Avg\log|*.*|RECURSE
FileKey15=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\AvgSetupLog|*.*|REMOVESELF
RegKey1=HKLM\Software\AVG\Antivirus\PUB-Detected
RegKey2=HKLM\Software\AVG\Antivirus\PUB-Removed
RegKey3=HKLM\Software\WOW6432Node\AVG\Antivirus\PUB-Detected
RegKey4=HKLM\Software\WOW6432Node\AVG\Antivirus\PUB-Removed
[AVG PC TuneUp *]
LangSecRef=3024
Detect1=HKCU\Software\AVG\AWL\RegistryCleaner
Detect2=HKCU\Software\TuneUp
Default=False
FileKey1=%AppData%\AVG\AWL*\CrashDumps|*.*
FileKey2=%AppData%\TuneUp Software\TuneUp Utilities\CrashDumps|*.*
FileKey3=%CommonAppData%|NTUSER.DAT_tureg_new.LOG1;NTUSER.DAT_tureg_new.LOG2;NTUSER.DAT_tureg_old
FileKey4=%CommonAppData%\TuneUp Software\TuneUp Utilities *|*.log|RECURSE
FileKey5=%LocalAppData%\Avg\AWL*\Log|*.log
FileKey6=%LocalAppData%\Avg\dumps\fmw1|*.*
FileKey7=%LocalAppData%\Avg\Log|*.log;zappapi.log.1|RECURSE
FileKey8=%LocalAppData%\Avg\Log\fmw1|*.*
FileKey9=%LocalAppData%\AvgSetupLog|*.*|REMOVESELF
FileKey10=%LocalAppData%\Microsoft\Windows|USRCLASS.DAT_tureg_new.LOG*;USRCLASS.DAT_tureg_old;NTUSER.DAT_tureg_old
FileKey11=%LocalAppData%\TuneUp Software|*.log|RECURSE
FileKey12=%Public%|NTUSER.DAT_tureg_new.LOG1;NTUSER.DAT_tureg_new.LOG2;NTUSER.DAT_tureg_old
FileKey13=%SystemDrive%\Boot|BCD_tureg_new.LOG*;BCD_tureg_old
FileKey14=%SystemDrive%\Documents and Settings\LocalService*|NTUSER.DAT_tureg_new.LOG*;NTUSER.DAT_tureg_old
FileKey15=%SystemDrive%\Documents and Settings\NetworkService*|NTUSER.DAT_tureg_new.LOG*;NTUSER.DAT_tureg_old
FileKey16=%SystemDrive%\Users\Default\AppData\Local\Avg\Log\tu16|*.log
FileKey17=%UserProfile%|NTUSER.DAT_tureg_new.LOG*;NTUSER.DAT_tureg_old
FileKey18=%WinDir%\ServiceProfiles\LocalService|NTUSER.DAT_tureg_new.LOG*;NTUSER.DAT_tureg_old
FileKey19=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows|USRCLASS.DAT_tureg_old;USRCLASS.DAT_tureg_new.LOG*
FileKey20=%WinDir%\ServiceProfiles\NetworkService|NTUSER.DAT_tureg_new.LOG*;NTUSER.DAT_tureg_old
FileKey21=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows|USRCLASS.DAT_tureg_old;USRCLASS.DAT_tureg_new.LOG*
FileKey22=%WinDir%\System32\config|COMPONENTS_tureg_new.LOG*;COMPONENTS_tureg_old;DEFAULT_tureg_new.LOG*;DEFAULT_tureg_old;SAM_tureg_new.LOG*;SAM_tureg_old;SECURITY_tureg_new.LOG*;SECURITY_tureg_old;Software_tureg_new.LOG*;Software_tureg_old;SYSTEM_tureg_new.LOG*;SYSTEM_tureg_old;DRIVERS_tureg_new.LOG*;DRIVERS_tureg_old;Software_tureg_new;SYSTEM_tureg_new
FileKey23=%WinDir%\System32\config\systemprofile\AppData\Local\Avg\Log\fmw1|*.log;*.log.lock
FileKey24=%WinDir%\System32\config\systemprofile\AppData\Local\Avg\Log\tu16|*.log;*.log.lock
FileKey25=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Avg\Log\fmw1|*.log
FileKey26=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Avg\Log\setup1|*.log
FileKey27=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Avg\Log\tu16|*.log
[Avi-Mux GUI *]
LangSecRef=3023
DetectFile=%ProgramFiles%\AVIMuxGUI\AVIMux_GUI.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\AVIMuxGUI|AVI-Mux GUI - Logfile*.*;*.dmp
FileKey2=%ProgramFiles%\AVIMuxGUI|AVI-Mux GUI - Logfile*.*;*.dmp
[AVI Toolbox *]
LangSecRef=3023
Detect=HKCU\Software\KC Softwares\AVIToolbox
Default=False
FileKey1=%AppData%\KC Softwares\AVI Toolbox|*.log
[Aviary Photo Editor *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\57AB5DD0.PhotoEditor_6hb943tstq5q8
DetectFile=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_6hb943tstq5q8
Default=False
FileKey1=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE
FileKey4=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\AC\Temp|*.*
FileKey6=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\LocalState|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\57AB5DD0.PhotoEditor_*\TempState|*.*|RECURSE
[Avidemux *]
LangSecRef=3023
Detect1=HKLM\Software\Avidemux 2.4
Detect2=HKLM\Software\Avidemux 2.5
Detect3=HKLM\Software\Avidemux 2.6
Default=False
FileKey1=%AppData%\avidemux|admlog.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Avidemux*|admlog.txt
[Avira AntiVir Desktop *]
LangSecRef=3024
Detect1=HKCU\Software\Avira\Antivirus
Detect2=HKLM\Software\Avira\AntiVir Desktop
Default=False
FileKey1=%CommonAppData%\Avira\AntiVir*\IPM|*.*|RECURSE
FileKey2=%CommonAppData%\Avira\AntiVir*\REPORTS|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Avira GmbH|*.log|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Avira\AntiVir*\IPM|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Avira\AntiVir*\REPORTS|*.*
FileKey6=%ProgramFiles%\Avira GmbH|*.log|RECURSE
[Avira Phantom VPN *]
LangSecRef=3024
DetectFile=%CommonAppData%\Avira\VPN
Default=False
FileKey1=%CommonAppData%\Avira\VPN|*.log
[Avira System Speedup *]
LangSecRef=3024
Detect1=HKLM\Software\Avira\Speedup
Detect2=HKLM\Software\AviraSpeedup
Default=False
FileKey1=%CommonAppData%\Avira\Launcher\Logfiles|*.log
FileKey2=%CommonAppData%\Avira\SystemSpeedup\Errors|*.*
FileKey3=%CommonAppData%\Avira\SystemSpeedup\Logs|*.*
FileKey4=%LocalAppData%\AviraSpeedup\logs|*.*
[AVS Audio Converter 6 *]
LangSecRef=3023
DetectFile=%AppData%\AVS4YOU\AVSAudioConverter6
Default=False
FileKey1=%AppData%\AVS4YOU\AVSAudioConverter6|recentfiles.*
[Awesomium *]
LangSecRef=3021
DetectFile=%AppData%\Awesomium
Default=False
FileKey1=%AppData%\Awesomium|*.log
FileKey2=%AppData%\Awesomium\*|Archived History;History;Cookies
FileKey3=%AppData%\Awesomium\*\Cache|*.*|REMOVESELF
FileKey4=%AppData%\Awesomium\*\Local Storage|*.*|REMOVESELF
[Axialis IconWorkshop *]
LangSecRef=3023
Detect=HKCU\Software\Axialis\IconWorkshop
Default=False
FileKey1=%Documents%\Axialis Librarian\Deleted Items|*.del;*.ii
RegKey1=HKCU\Software\Axialis\IconWorkshop\folders|CurrentExportDirectory
RegKey2=HKCU\Software\Axialis\IconWorkshop\folders|CurrentImportDirectory
RegKey3=HKCU\Software\Axialis\IconWorkshop\folders|CurrentOpenDirectory
RegKey4=HKCU\Software\Axialis\IconWorkshop\rss|MostRecentNewsId
RegKey5=HKCU\Software\Axialis\IconWorkshop\rss|News1
RegKey6=HKCU\Software\Axialis\IconWorkshop\rss|News2
RegKey7=HKCU\Software\Axialis\IconWorkshop\rss|News3
RegKey8=HKCU\Software\Axialis\IconWorkshop\rss|News4
RegKey9=HKCU\Software\Axialis\IconWorkshop\rss|News5
RegKey10=HKCU\Software\Axialis\IconWorkshop\rss|News6
RegKey11=HKCU\Software\Axialis\IconWorkshop\rss|News7
RegKey12=HKCU\Software\Axialis\IconWorkshop\rss|News8
RegKey13=HKCU\Software\Axialis\IconWorkshop\rss|News9
RegKey14=HKCU\Software\Axialis\IconWorkshop\rss|News10
RegKey15=HKCU\Software\Axialis\IconWorkshop\rss|News11
RegKey16=HKCU\Software\Axialis\IconWorkshop\rss|News12
RegKey17=HKCU\Software\Axialis\IconWorkshop\rss|News13
RegKey18=HKCU\Software\Axialis\IconWorkshop\rss|News14
RegKey19=HKCU\Software\Axialis\IconWorkshop\rss|News15
RegKey20=HKCU\Software\Axialis\IconWorkshop\rss|News16
RegKey21=HKCU\Software\Axialis\IconWorkshop\rss|News17
RegKey22=HKCU\Software\Axialis\IconWorkshop\rss|News18
RegKey23=HKCU\Software\Axialis\IconWorkshop\rss|News19
RegKey24=HKCU\Software\Axialis\IconWorkshop\rss|News20
RegKey25=HKCU\Software\Axialis\IconWorkshop\rss|UnreadNews
[AzureWave *]
LangSecRef=3022
DetectFile=%CommonAppData%\AzureWave
Default=False
FileKey1=%CommonAppData%\AzureWave|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\AzureWave|*.log
[Babylon *]
LangSecRef=3024
Detect=HKCU\Software\Babylon\Babylon Translator\UserInfo
Default=False
RegKey1=HKCU\Software\Babylon\Babylon Translator\UserInfo\History
[Backyard Basketball 2004 *]
Section=Games
DetectFile=%ProgramFiles%\Atari\Backyard Basketball 2004
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Atari\Backyard Basketball 2004|*.log
FileKey2=%ProgramFiles%\Atari\Backyard Basketball 2004|*.log
[Bad Piggies *]
Section=Games
DetectFile=%ProgramFiles%\Rovio\Bad Piggies
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Rovio\Bad Piggies\BadPiggies_Data|output_log.txt
FileKey2=%ProgramFiles%\Rovio\Bad Piggies\BadPiggies_Data|output_log.txt
[Baidu PC Faster *]
LangSecRef=3024
Detect=HKCU\Software\Baidu Security
Default=False
FileKey1=%CommonAppData%\Baidu Security\RpData|*.tmp
FileKey2=%Documents%\Baidu Security\Bav\Dump|*.*|REMOVESELF
FileKey3=%Documents%\Baidu Security\PC Faster\*\Dump|*.*|REMOVESELF
FileKey4=%Documents%\Baidu Security\PC Faster\*\log|*.*|REMOVESELF
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Baidu Security\RpData|*.tmp
[Baidu Spark *]
LangSecRef=3021
Detect=HKCU\Software\Baidu
Default=False
FileKey1=%CommonAppData%\Baidu\Spark\AutoUpdate\updatelog|*.*
[Bandicam *]
LangSecRef=3023
Detect=HKCU\Software\BANDISOFT\BANDICAM
Default=False
Warning=This will delete the contents of your output folder.
FileKey1=%Documents%\Bandicam|*.*|RECURSE
[Banished *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\242920
Default=False
FileKey1=%Documents%\Banished\Save|Crash*.dmp
[Barnes and Noble Desktop Reader *]
LangSecRef=3021
DetectFile=%AppData%\Barnes & Noble\BNDesktopReader
Default=False
FileKey1=%AppData%\Barnes & Noble\BNDesktopReader\CachedImages|*.*
[BartVPN *]
LangSecRef=3022
DetectFile=%LocalAppData%\BartVPN
Default=False
FileKey1=%LocalAppData%\BartVPN|*.log
[BATExpert *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\BATExpert
Default=False
FileKey1=%AppData%\KC Softwares\BATExpert|*.log
[Batman: Arkham Asylum *]
Section=Games
Detect1=HKLM\Software\Eidos Interactive Limited\Batman: Arkham Asylum
Detect2=HKLM\Software\RocksteadyLtd\Batman Arkham Asylum
Default=False
FileKey1=%Documents%\*\Batman Arkham Asylum*\BmGame|*.log|RECURSE
[Batman: Arkham City *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\57400
Detect2=HKCU\Software\Valve\Steam\Apps\200260
Detect3=HKLM\Software\Warner Bros\Batman Arkham City
Default=False
FileKey1=%Documents%\WB Games\Batman Arkham City*\BmGame\Logs|*.*
[Batman: Arkham Origins *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\209000
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Batman Arkham Origins\SinglePlayer\BMGame\Logs|*.*
FileKey2=%ProgramFiles%\Steam\steamapps\common\Batman Arkham Origins\SinglePlayer\BMGame\Logs|*.*
[Battle Islands *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\305260
Default=False
FileKey1=%ProgramFiles%\Steam\SteamApps\Common\Battle Islands\BattleIslands_Data|output_log.txt
[Battle.net *]
Section=Games
Detect=HKCU\Software\Blizzard Entertainment\Battle.net
Default=False
FileKey1=%CommonAppData%\Battle.net|*.log|RECURSE
FileKey2=%CommonAppData%\Battle.net\*\Logs|*.*|RECURSE
FileKey3=%CommonAppData%\Battle.net\Agent\Agent.*\Logs|*.*|RECURSE
FileKey4=%CommonAppData%\Battle.net\Client\Blizzard Launcher.*\Logs|*.*|RECURSE
FileKey5=%CommonAppData%\Battle.net\Setup\*\Logs|*.*
FileKey6=%CommonAppData%\Battle.net\Telemetry|*.*
FileKey7=%LocalAppData%\Battle.net\Errors|*.*
FileKey8=%LocalAppData%\Battle.net\Logs|*.*|RECURSE
FileKey9=%LocalAppData%\Blizzard Entertainment\System Survey|*.log|RECURSE
FileKey10=%LocalAppData%\Blizzard Entertainment\System Survey|log.txt
FileKey11=%LocalAppData%\VirtualStore\ProgramData\Battle.net|*.log|RECURSE
FileKey12=%LocalAppData%\VirtualStore\ProgramData\Battle.net\*\Logs|*.*|RECURSE
FileKey13=%LocalAppData%\VirtualStore\ProgramData\Battle.net\Agent\Agent.*\Logs|*.*|RECURSE
FileKey14=%LocalAppData%\VirtualStore\ProgramData\Battle.net\Client\Blizzard Launcher.*\Logs|*.*|RECURSE
[Battle.net Cache *]
Section=Games
Detect=HKCU\Software\Blizzard Entertainment\Battle.net
Default=False
FileKey1=%CommonAppData%\Blizzard Entertainment\Battle.net\Cache|*.*|RECURSE
FileKey2=%LocalAppData%\Battle.net\BrowserCache|*.*|RECURSE
FileKey3=%LocalAppData%\Battle.net\Cache|*.*|RECURSE
FileKey4=%LocalAppData%\Blizzard Entertainment\Battle.net\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Blizzard Entertainment\Battle.net\Cache|*.*|RECURSE
[Battlefield 3 *]
Section=Games
Detect=HKLM\Software\EA Games\Battlefield 3
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Battlefield 3\__Installer|InstallLog.txt
FileKey2=%ProgramFiles%\Origin Games\Battlefield 3\__Installer|InstallLog.txt
[BB FlashBack/TestAssistant *]
LangSecRef=3023
Detect1=HKLM\Software\Blueberry Software\BB FlashBack Express
Detect2=HKLM\Software\Blueberry Software\BB FlashBack Pro 4
Detect3=HKLM\Software\Blueberry Software\BB FlashBack Standard 4
Detect4=HKLM\Software\Blueberry Software\BB TestAssistant Expert 4
Detect5=HKLM\Software\Blueberry Software\BB TestAssistant Pro 4
Default=False
FileKey1=%AppData%\Blueberry|ExportToAVIStat.txt;ExportToQTStat.txt;ExportToSWFStat.txt;ExportToWMVStat.txt;* CrashTracking.xml;* UsageTracking.xml;RecorderStat.txt;RecorderStaticStat.txt
FileKey2=%AppData%\LogSys|*.*|REMOVESELF
FileKey3=%CommonProgramFiles%\Blueberry Software|*.log
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Blueberry Software\*|drvinstlog.txt;*.log
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Common Files\Blueberry Software|*.log
FileKey6=%ProgramFiles%\Blueberry Software\*|drvinstlog.txt;*.log
FileKey7=%WinDir%\system32\MTSLog|*.*|REMOVESELF
[Beckhoff TwinCat *]
LangSecRef=3021
Detect=HKCU\Software\Beckhoff
Default=False
FileKey1=%SystemDrive%\TwinCAT\3.1\Components\TcEventLogger\EventConfigurator|~evtCfgTmp*.html
FileKey2=%UserProfile%|*TwinCat*.log;TC*.log;TF*.log
[Belarc Advisor *]
LangSecRef=3024
Detect=HKCU\Software\Belarc
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Belarc\*Advisor\System|Progress.Log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Belarc\*Advisor\System\Security\BelNotify|BelNotify.log;History.log;HistoryHF.log
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Belarc\*Advisor\System\Tmp|*.*
FileKey4=%ProgramFiles%\Belarc\*Advisor|install.log
FileKey5=%ProgramFiles%\Belarc\*Advisor\System|Progress.Log
FileKey6=%ProgramFiles%\Belarc\*Advisor\System\Security\BelNotify|BelNotify.log;History.log;HistoryHF.log
FileKey7=%ProgramFiles%\Belarc\*Advisor\System\Tmp|*.*
[BestBuy Software Installer *]
LangSecRef=3024
DetectFile=%CommonAppData%\Best Buy Software Installer
Default=False
FileKey1=%CommonAppData%\Best Buy Software Installer\Resources\Cache|*.*
[Betrayer *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\105430
Default=False
FileKey1=%Documents%\Betrayer\UDKGame\Logs|*.*
[Better Explorer *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Better Explorer
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Better Explorer|log.txt
FileKey2=%ProgramFiles%\Better Explorer|log.txt
[BetterDiscord *]
LangSecRef=3022
DetectFile=%AppData%\BetterDiscord
Default=False
FileKey1=%AppData%\BetterDiscord|*.log
FileKey2=%AppData%\BetterDiscord\temp|*.*|REMOVESELF
[Beyond Compare *]
LangSecRef=3021
Detect=HKCU\Software\Scooter Software\Beyond Compare
Default=False
FileKey1=%AppData%\Scooter Software\Beyond Compare*|*.bak
[Big City Adventure *]
Section=Games
Detect1=HKCU\Software\JollyBear\Big City Adventure San Francisco
Detect2=HKCU\Software\JollyBear\Big City Adventure Sydney
Default=False
FileKey1=%CommonAppData%\JollyBear\Big City Adventure *|error.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\JollyBear\Big City Adventure *|error.*
[Big Fish Games *]
Section=Games
Detect=HKCU\Software\Big Fish Games
Default=False
FileKey1=%CommonAppData%\Big Fish Games\Game Manager\resources-old|*.*|RECURSE
FileKey2=%CommonAppData%\Big Fish\Game Manager\Addons\BFGameLauncher|*.log|RECURSE
FileKey3=%CommonAppData%\BigFishCache\GameManager\log|*.txt|RECURSE
FileKey4=%CommonAppData%\BigFishGamesCache\GameManager\log|*.*
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Big Fish Games\Game Manager\resources-old|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Big Fish\Game Manager\Addons\BFGameLauncher|*.log|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\BigFishCache\GameManager\log|*.txt|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\BigFishGamesCache\GameManager\log|*.*
[Big Fish Games Installers *]
Section=Games
Detect=HKCU\Software\Big Fish Games
Default=False
FileKey1=%CommonAppData%\BigFishCache|*.exe|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\BigFishCache|*.exe|RECURSE
[Binding of Isaac *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\250900
Detect2=HKCU\Software\Valve\Steam\Apps\570660
Default=False
FileKey1=%Documents%\My Games\Binding of Isaac *|*.dmp;isaacv*.txt;log.txt
[Bing Dynamic *]
LangSecRef=3023
DetectFile=%LocalAppData%\Microsoft\Windows\Themes\BingDynamic1.theme
Default=False
Warning=This will cause you to redownload the Bing Dynamic RSS file.
FileKey1=%LocalAppData%\Microsoft\Feeds|http~c~f~fthemeserver~dmicrosoft~dcom~fdefault~daspx~mp*Bing*
[Bing Finance *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingFinance_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingFinance_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingFinance_*\TempState|*.*|RECURSE
[Bing Food and Drink *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingFoodAndDrink_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingFoodAndDrink_*\LocalState\Cache|*.*|RECURSE
[Bing Health and Fitness *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingHealthAndFitness_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingHealthAndFitness_*\LocalState\Cache|*.*|RECURSE
[Bing Maps *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingMaps_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingMaps_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\PRICache|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.BingMaps*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.BingMaps*\LocalState\Bing.Maps|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingMaps*\LocalState\MapInstrumentation|*.*
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingMaps_8wekyb3d8bbwe\SearchHistory
[Bing Search *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Bing_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.Bing_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Bing_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Bing_8wekyb3d8bbwe\SearchHistory
[Bing Sports *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingSports_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingSports_*\LocalState\navigationHistory|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingSports_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingSports_8wekyb3d8bbwe\SearchHistory
[Bing Travel *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingTravel_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingTravel_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.BingTravel_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingTravel_8wekyb3d8bbwe\SearchHistory
[BioShock Infinite *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\8870
Default=False
FileKey1=%Documents%\my games\BioShock Infinite\Benchmarks|*.*
[BIT.TRIP *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\63700
Detect2=HKCU\Software\Valve\Steam\Apps\63710
Default=False
FileKey1=%LocalAppData%\BIT.TRIP *|*.txt
[Bitcoin *]
LangSecRef=3022
Detect1=HKCU\Software\Bitcoin
Detect2=HKCU\Software\Bitcoin Core
Detect3=HKLM\Software\Bitcoin Core
Default=False
FileKey1=%AppData%\Bitcoin|*.log;*.old
[Bitdefender *]
LangSecRef=3024
Detect1=HKLM\Software\Bitdefender\Bitdefender Internet Security
Detect2=HKLM\Software\Bitdefender\Bitdefender Total Security
Detect3=HKLM\Software\Bitdefender\Bitdefender Total Security 2015
Detect4=HKLM\Software\Softwin\Bitdefender Antivirus
Default=False
FileKey1=%AppData%\Bitdefender\Desktop\profiles\Logs\*|*.xml
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Softwin\Bitdefender*\Logs|*.*
FileKey3=%ProgramFiles%\Softwin\Bitdefender*\Logs|*.*
FileKey4=%SystemDrive%|bdlog.txt
[BitTorrent *]
LangSecRef=3022
DetectFile1=%AppData%\BitTorrent\BitTorrent.exe
DetectFile2=%ProgramFiles%\BitTorrent\BitTorrent.exe
Default=False
FileKey1=%AppData%\BitTorrent\Updates|*.exe
[BitTorrent Incomplete Downloads *]
LangSecRef=3022
Detect=HKCU\Software\BitTorrent
Default=False
FileKey1=%AppData%\BitTorrent\incomplete|*.*
[BitTorrent Sync *]
LangSecRef=3023
DetectFile=%AppData%\BitTorrent Sync
Default=False
FileKey1=%AppData%\BitTorrent Sync|*.log;*.old
[BlackBeltPrivacy DarkNet *]
LangSecRef=3023
DetectFile=%LocalAppData%\BlackBeltPrivacy
Default=False
FileKey1=%LocalAppData%\BlackBeltPrivacy\3rdParty|*.*|RECURSE
FileKey2=%LocalAppData%\BlackBeltPrivacy\darkNet\logs|*.*|RECURSE
FileKey3=%LocalAppData%\BlackBeltPrivacy\Logs|*.*|RECURSE
FileKey4=%LocalAppData%\BlackBeltPrivacy\MicroSip|MicroSIP.log
[BlackBerry AddinSync *]
LangSecRef=3021
DetectFile=%AppData%\Research In Motion\BlackBerry\AddinSync
Default=False
FileKey1=%AppData%\Research In Motion\BlackBerry\AddinSync|sync.log
[BlackBerry Desktop Software *]
LangSecRef=3023
Detect=HKCU\Software\Research In Motion\BlackBerry
Default=False
FileKey1=%AppData%|Rim*.log
FileKey2=%AppData%\Research In Motion\BlackBerry Desktop|*.dmp
FileKey3=%LocalAppData%\Research In Motion\BlackBerry*Desktop\*\*|*.backup
FileKey4=%LocalAppData%\Research In Motion\BlackBerry*Desktop\*\*\Log|*.html
FileKey5=%LocalAppData%\Research In Motion\BlackBerry*Desktop\Logs|*.*|REMOVESELF
[BlackBerry Intellisync *]
LangSecRef=3021
DetectFile=%AppData%\Research In Motion\BlackBerry\Intellisync
Default=False
FileKey1=%AppData%\Research In Motion\BlackBerry\Intellisync|*.log|RECURSE
[Blade of Destiny *]
Section=Games
DetectFile=%Documents%\BladeofDestiny
Default=False
FileKey1=%Documents%\BladeofDestiny\Consolelog|*.*|RECURSE
[Blade Symphony *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\225600
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\Blade Symphony\workshop_temp|*.*|RECURSE
FileKey2=%ProgramFiles%\Steam\Steamapps\common\Blade Symphony\workshop_temp|*.*|RECURSE
[Blades of Time *]
Section=Games
DetectFile=%LocalAppData%\BladesOfTime
Default=False
FileKey1=%LocalAppData%\BladesOfTime\_debuginfo|*.*
[BleachBit *]
LangSecRef=3024
Detect=HKCU\Software\BleachBit
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\BleachBit|bleachbit.exe.log
FileKey2=%ProgramFiles%\BleachBit|bleachbit.exe.log
[Blender *]
LangSecRef=3023
Detect=HKLM\Software\BlenderFoundation
Default=False
FileKey1=%AppData%\Blender Foundation\Blender\*\config|recent-files.txt
[Blimb Entertainment AIRSTRIKE3D *]
Section=Games
DetectFile=%ProgramFiles%\Blimb Entertainment\AIRSTRIKE3D
Default=False
FileKey1=%ProgramFiles%\Blimb Entertainment\AIRSTRIKE3D|*.log
[Blood Bowl: Legendary Edition *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\58520
Detect2=HKCU\Software\Valve\TestApp58520
Default=False
FileKey1=%Documents%\BloodBowlLegendary|BB_LE000.log;CEGUI.log;SystemInfo000.log
FileKey2=%Documents%\BloodBowlLegendary\Cache\3d|*.*|REMOVESELF
FileKey3=%Documents%\BloodBowlLegendary\Cache\DB|*.*|REMOVESELF
[Blue-Cloner *]
LangSecRef=3023
Detect=HKCU\Software\Blue-cloner
Default=False
FileKey1=%AppData%\Blue-Cloner|*.log
FileKey2=%AppData%\Blue-Cloner\ReadCache|*.*|REMOVESELF
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Blue-Cloner|*.log;*.txt
FileKey4=%ProgramFiles%\Blue-Cloner|*.log;*.txt
[BlueGriffon *]
LangSecRef=3021
DetectFile=%LocalAppData%\Disruptive Innovations SARL\BlueGriffon
Default=False
FileKey1=%LocalAppData%\Disruptive Innovations SARL\BlueGriffon\Profiles\*\Cache|*.*|RECURSE
[BlueSky Interactive *]
LangSecRef=3022
DetectFile=%ProgramFiles%\BlueSky Interactive
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\BlueSky Interactive\PTP\Settings|*.tmp
FileKey2=%ProgramFiles%\BlueSky Interactive\PTP\Settings|*.tmp
[BlueStacks *]
LangSecRef=3021
Detect1=HKCU\Software\Bluestacks
Detect2=HKLM\Software\Bluestacks
Default=False
FileKey1=%LocalAppData%\VirtualStore\ProgramData\BlueStacks|*.log;*.log.*|RECURSE
[BlueStacks APKs *]
LangSecRef=3021
Detect1=HKCU\Software\BlueStacks
Detect2=HKLM\Software\BlueStacks
Default=False
FileKey1=%CommonAppData%\BlueStacksSetup|*.apk
FileKey2=%LocalAppData%\VirtualStore\ProgramData\BlueStacksSetup|*.apk
[BlueStacks Installer *]
LangSecRef=3021
Detect1=HKCU\Software\Bluestacks
Detect2=HKLM\Software\Bluestacks
Default=False
Warning=You will have to redownload these files in order to reinstall the application.
FileKey1=%LocalAppData%\VirtualStore\ProgramData\BlueStacksSetup|runtimedata_*.zip;runtimedata_*.zip.manifest
FileKey2=%LocalAppData%\VirtualStore\ProgramData\BlueStacksSetup\Images|*.*|REMOVESELF
[Bluetack Blocklist Manager *]
LangSecRef=3024
Detect=HKCU\Software\Bluetack\Blocklist Manager
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Bluetack\Blocklist Manager\Cache|*.*
FileKey2=%ProgramFiles%\Bluetack\Blocklist Manager\Cache|*.*
[Blumentals Easy GIF Animator *]
LangSecRef=3023
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Easy GIF Animator_is1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Easy GIF Animator|*.txt|RECURSE
FileKey2=%ProgramFiles%\Easy GIF Animator|*.txt|RECURSE
[Blurity *]
LangSecRef=3023
DetectFile=%AppData%\Blurity
Default=False
FileKey1=%AppData%\Blurity|event.log
[Boinc *]
LangSecRef=3024
Detect=HKCU\Software\Space Sciences Laboratory, U.C. Berkeley\BOINC Manager
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\BOINC|stdout*.*;stderr*.*
FileKey2=%ProgramFiles%\BOINC|stdout*.*;stderr*.*
[Borderlands *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\8980
Detect2=HKCU\Software\Valve\Steam\Apps\49520
Detect3=HKLM\Software\Borderlands
Default=False
FileKey1=%Documents%\My Games\Borderlands*\WillowGame\Logs|*.*
[Borland C++ Builder 5.0 *]
LangSecRef=3024
Detect=HKCU\Software\Borland\C++Builder\5.0
Default=False
RegKey1=HKCU\Software\Borland\C++Builder\5.0\Closed Files
RegKey2=HKCU\Software\Borland\C++Builder\5.0\Closed Projects
RegKey3=HKCU\Software\Borland\C++Builder\5.0\Session
[Borland Delphi 7 *]
LangSecRef=3024
Detect=HKCU\Software\Borland\Delphi\7.0
Default=False
RegKey1=HKCU\Software\Borland\Delphi\7.0\Closed Files
RegKey2=HKCU\Software\Borland\Delphi\7.0\Closed Projects
RegKey3=HKCU\Software\Borland\Delphi\7.0\Session
[Borland Developer Studio 2006 *]
LangSecRef=3024
Detect=HKCU\Software\Borland\BDS\4.0
Default=False
RegKey1=HKCU\Software\Borland\BDS\4.0\Closed Files
RegKey2=HKCU\Software\Borland\BDS\4.0\Closed Projects
RegKey3=HKCU\Software\Borland\BDS\4.0\Session
[BOSS *]
Section=Games
DetectFile=%SystemDrive%\BOSS
Default=False
FileKey1=%SystemDrive%\BOSS\*|BOSSlog.*
[Box *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\134D4F5B.Box_2qk4zy5s3qmee
DetectFile=%LocalAppData%\Packages\134D4F5B.Box_2qk4zy5s3qmee
Default=False
FileKey1=%LocalAppData%\Packages\*Box_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*Box_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\*Box_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE
FileKey4=%LocalAppData%\Packages\*Box_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\*Box_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey6=%LocalAppData%\Packages\*Box_*\AC\PRICache|*.*
FileKey7=%LocalAppData%\Packages\*Box_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\*Box_*\LocalState|*.*|RECURSE
[Brawlhalla Replays *]
Section=Games
DetectFile=%UserProfile%\BrawlhallaReplays
Default=False
Warning=You will delete your saved replays!
FileKey1=%UserProfile%\BrawlhallaReplays|*.replay|REMOVESELF
[Breevy Backups *]
LangSecRef=3021
DetectFile=%AppData%\Breevy
Default=False
FileKey1=%AppData%\Breevy\Backups|*.*
[Broadcom Wireless LAN Driver *]
LangSecRef=3021
DetectFile=%SystemDrive%\Drivers\Broadcom Wireless LAN Driver
Default=False
FileKey1=%SystemDrive%\Drivers\Broadcom Wireless LAN Driver|*.log|RECURSE
[Broforce *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\274190
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Broforce\*\Broforce Logs|*.csv
FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Broforce\*\Broforce Logs|*.csv
[Broken Shortcut Fixer *]
LangSecRef=3024
DetectFile=%ProgramFiles%\ConsumerSoft\Broken Shortcut Fixer
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\ConsumerSoft\Broken Shortcut Fixer|ht.htm
FileKey2=%ProgramFiles%\ConsumerSoft\Broken Shortcut Fixer|ht.htm
[Brother P-touch *]
LangSecRef=3021
DetectFile=%LocalAppData%\Brother\P-touch Update Software
Default=False
FileKey1=%LocalAppData%\Brother\P-touch Update Software|*.log
[Brother Printer *]
LangSecRef=3024
Detect=HKLM\Software\Brother
DetectFile=%CommonAppData%\Brother
Default=False
FileKey1=%CommonAppData%\Brother\BrLog|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Brother|*.tmp|RECURSE
FileKey3=%ProgramFiles%\Brother|*.tmp|RECURSE
[Brothers - A Tale of Two Sons *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\225080
Default=False
FileKey1=%Documents%\my games\UnrealEngine3\P13\Logs|*.*
[BrowserSync *]
LangSecRef=3022
DetectFile=%AppData%\BrowserSync
Default=False
FileKey1=%AppData%\BrowserSync|log.txt
[BS Player *]
LangSecRef=3021
Detect1=HKCU\Software\BST\bsplayer
Detect2=HKCU\Software\BST\bsplayerv1
DetectFile=%ProgramFiles%\Webteh\BSPlayer\bsplayer.exe
Default=False
FileKey1=%AppData%\BSplayer\AC3 Filter|unreg.log;Changes.txt
FileKey2=%AppData%\BSplayer\cache|*.*
FileKey3=%AppData%\BSplayer\FFDShow|unreg.log
FileKey4=%AppData%\BSplayer\Flash Video (FLV)|unreg.log
FileKey5=%AppData%\BSplayer\Haali media splitter|unreg.log
FileKey6=%AppData%\BSplayer\MPEG*decoder|unreg.log
FileKey7=%AppData%\BSplayer\RealMedia splitter|unreg.log
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Webteh\BSplayerPro|*.jpg
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Webteh\BSplayerPro\cache|*.mpos
FileKey10=%ProgramFiles%\Webteh\BSplayerPro|*.jpg
FileKey11=%ProgramFiles%\Webteh\BSplayerPro\cache|*.mpos
[BSD *]
LangSecRef=3023
DetectFile=%AppData%\BSD
Default=False
FileKey1=%AppData%\BSD\*\logs|*.*|RECURSE
FileKey2=%AppData%\BSD\MediaWidget\PodCache|*.*|RECURSE
[Buchstabenzoo BHV *]
LangSecRef=3021
DetectFile=%AppData%\bhv-gswvs\users
Default=False
FileKey1=%AppData%\bhv-gswvs\users\*\Buchstabenzoo|*.log
[Bugsplat *]
LangSecRef=3024
Detect=HKCU\Software\Bugsplat
Default=False
RegKey1=HKCU\Software\Bugsplat\gaspowered\SupremeCommander
RegKey2=HKCU\Software\Bugsplat\lol_beta_riotgames_com\LOL_Public
RegKey3=HKCU\Software\Bugsplat\Pando_win\Pando
RegKey4=HKCU\Software\Bugsplat\Relic\CoH
RegKey5=HKCU\Software\Bugsplat\Relic\RelicDownloader
[Bullzip PDF Printer *]
LangSecRef=3022
DetectFile=%AppData%\PDF Writer\Bullzip PDF Printer
Default=False
FileKey1=%AppData%\PDF Writer\Bullzip PDF Printer|user.ini
[BumpTop *]
LangSecRef=3021
Detect=HKCU\Software\Bump Technologies, Inc.
Default=False
FileKey1=%AppData%\Bump Technologies, Inc\BumpTop|*log.txt
FileKey2=%AppData%\Bump Technologies, Inc\BumpTop\Cache|*.*|RECURSE
FileKey3=%LocalAppData%\Bump Technologies, Inc\BumpTop\*Cache|*.*|RECURSE
FileKey4=%LocalAppData%\Bump Technologies, Inc\BumpTop\Previous|*.*
FileKey5=%LocalAppData%\Bump Technologies, Inc\BumpTop\Temp|*.*
[BumpTop StickyNotes *]
LangSecRef=3021
Detect=HKCU\Software\Bump Technologies, Inc.
Default=False
FileKey1=%UserProfile%\Desktop|StickyNote*.txt
[Burger Shop *]
Section=Games
Detect1=HKCU\Software\GoBit\BurgerShop
Detect2=HKCU\Software\GoBit\BurgerShop2
Default=False
FileKey1=%CommonAppData%\GoBit Games\BurgerShop2\*\cached|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Burger Shop|*.db;*.txt|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Burger Shop\cached|*.*|REMOVESELF
FileKey4=%LocalAppData%\VirtualStore\Program Files*\GoBit Games\Burger Shop 2|*.db;*.txt|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\GoBit Games\BurgerShop2\*\cached|*.*|REMOVESELF
FileKey6=%ProgramFiles%\Burger Shop|*.db;*.txt|RECURSE
FileKey7=%ProgramFiles%\Burger Shop\cached|*.*|REMOVESELF
FileKey8=%ProgramFiles%\GoBit Games\Burger Shop 2|*.db;*.txt|RECURSE
[Burn Zombie Burn! *]
Section=Games
Detect=HKLM\Software\Burn Zombie Burn
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\P2 Games\Burn Zombie Burn|*.log
FileKey2=%ProgramFiles%\P2 Games\Burn Zombie Burn|*.log
[Burn Zombie Burn! .NET Installer *]
Section=Games
Detect=HKLM\Software\Burn Zombie Burn
Default=False
Warning=Make sure .NET framwork 3.0 is installed before running this.
FileKey1=%ProgramFiles%\P2 Games\Burn Zombie Burn\REQS\NET|*.*|REMOVESELF
[Bus-Simulator 2009 *]
Section=Games
DetectFile=%ProgramFiles%\Bus-Simulator 2009
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Bus-Simulator 2009|*.dmp;*.log|RECURSE
FileKey2=%ProgramFiles%\Bus-Simulator 2009|*.dmp;*.log|RECURSE
[Business Objects Enterprise 11 *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Business Objects\Business Objects Enterprise 11
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Business Objects\Business Objects Enterprise 11\Logging|*.*
FileKey2=%ProgramFiles%\Business Objects\Business Objects Enterprise 11\Logging|*.*
[CA Security Center *]
LangSecRef=3021
Detect=HKLM\Software\CA\CAPF
Default=False
FileKey1=%CommonAppData%\CA|*.log;*.txt|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\CA|*.log;*.txt|RECURSE
FileKey3=%LocalLowAppData%\CA\Consumer\APH|*.log
[Cached Certification Files *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%LocalLowAppData%\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey2=%LocalLowAppData%\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
[Cached File Extensions *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This possibly will reset default programs back to default on Windows 8/8.1.
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
RegKey2=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
[Cached Shell Extensions *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
RegKey2=HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
[Calendar Magic *]
LangSecRef=3021
DetectFile1=%ProgramFiles%\EuroSoft\Calendar Magic
DetectFile2=%SystemDrive%\EuroSoft\Calendar Magic
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\EuroSoft\Calendar Magic|debug.txt
FileKey2=%ProgramFiles%\EuroSoft\Calendar Magic|debug.txt
FileKey3=%SystemDrive%\EuroSoft\Calendar Magic|debug.txt
[Calendar Magic Backup *]
LangSecRef=3021
DetectFile1=%ProgramFiles%\EuroSoft\Calendar Magic
DetectFile2=%SystemDrive%\EuroSoft\Calendar Magic
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\EuroSoft\Calendar Magic|*.bak
FileKey2=%ProgramFiles%\EuroSoft\Calendar Magic|*.bak
FileKey3=%SystemDrive%\EuroSoft\Calendar Magic|*.bak
[Calibre *]
LangSecRef=3021
DetectFile=%LocalAppData%\calibre-cache\jsbrowser
Default=False
FileKey1=%LocalAppData%\calibre-cache\jsbrowser\data*|*.*|RECURSE
[Call of Atlantis *]
Section=Games
Detect=HKLM\Software\Playrix\Call of Atlantis
Default=False
FileKey1=%CommonAppData%\Playrix Entertainment\Call of Atlantis\Log|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Playrix Entertainment\Call of Atlantis\Log|*.*
[Call of Juarez *]
Section=Games
Detect1=HKLM\Software\Techland\CallOfJuarez
Detect2=HKLM\Software\Techland\CallofJuarez2
Default=False
FileKey1=%Documents%\Call Of Juarez*\Out\logs|*.log|RECURSE
[Camera *]
LangSecRef=3031
Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsCamera_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft*Camera_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft*Camera_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft*Camera_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft*Camera_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\Microsoft*Camera_*\AC\PRICache|*.*
FileKey6=%LocalAppData%\Packages\Microsoft*Camera_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\AppData|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsCamera_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Camera_8wekyb3d8bbwe\SearchHistory
[Cameyo *]
LangSecRef=3021
Detect=HKCU\Software\VOS
Default=False
FileKey1=%AppData%\VOS|*.*|REMOVESELF
RegKey1=HKCU\Software\VOS
[CamStudio *]
LangSecRef=3023
Detect=HKCU\Software\CamStudioOpenSource for Nick
Default=False
FileKey1=%Documents%\My CamStudio Temp Files|*.*
[Camtasia Studio 9 *]
LangSecRef=3024
Detect=HKCU\Software\TechSmith\Camtasia Studio\9.0
Default=False
RegKey1=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Recorder\9.0\General|lstLastSaveDir
RegKey2=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Studio\9.0|ExportAsZipMru
RegKey3=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Studio\9.0|FileSaveAsMru
RegKey4=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Studio\9.0|MRUImportFolder
RegKey5=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Studio\9.0|MRUOpenProjectFolder
RegKey6=HKCU\Software\TechSmith\Camtasia Studio\9.0\Camtasia Studio\9.0|RecentRecordingsMru
[Canon Digital Photo Professional 4 *]
LangSecRef=3021
Detect=HKLM\Software\Canon_Inc_IC\DPP4
DetectFile=%ProgramFiles%\Canon\Digital Photo Professional 4
Default=False
FileKey1=%AppData%\Canon_Inc_IC\DPP4\Application\Temp|*.*|RECURSE
FileKey2=%AppData%\Canon_Inc_IC\DPP4\DppMWare\Cache|*.*|RECURSE
FileKey3=%AppData%\Canon_Inc_IC\ServiceLog\AutoUpdateService|*.txt
FileKey4=%CommonAppData%\Canon_Inc_IC\UniversalInstaller\ServiceLog|*.TXT
[Canon Printer *]
LangSecRef=3021
DetectFile=%CommonAppData%\CanonBJ
Default=False
FileKey1=%CommonAppData%\CanonBJ\IJPrinter\CNMWindows|drvlog*;drvlog*.*;plmlog*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\CanonBJ\IJPrinter\CNMWindows|drvlog*;drvlog*.*;plmlog*.*|RECURSE
[Canon Zoom Browser *]
LangSecRef=3021
Detect=HKCU\Software\Canon\ZoomBrowser Ex
DetectFile1=%AppData%\ZoomBrowser EX
DetectFile2=%Pictures%\ZbThumbnail.info
Default=False
FileKey1=%Pictures%|ZbThumbnail.info|RECURSE
[Captcha Brotherhood *]
LangSecRef=3024
DetectFile=%LocalAppData%\Captcha_Brotherhood
Default=False
FileKey1=%LocalAppData%\Captcha_Brotherhood|solver_logFile.txt;plugin_logFile.txt;solver_captchaLog.txt
[CasualArts *]
Section=Games
DetectFile=%AppData%\CasualArts
Default=False
FileKey1=%AppData%\casualArts\*|logfile.*;*.txt|RECURSE
FileKey2=%CommonAppData%\casualArts|*.*|REMOVESELF
FileKey3=%LocalAppData%\VirtualStore\ProgramData\casualArts|*.*|REMOVESELF
[Cave Story+ *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\200900
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\cave story+|log.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\cave story+\data|*.DS_STORE|RECURSE
FileKey3=%ProgramFiles%\Steam\steamapps\common\cave story+|log.txt
FileKey4=%ProgramFiles%\Steam\steamapps\common\cave story+\data|*.DS_STORE|RECURSE
[CC Magic *]
Section=Games
DetectFile=%Documents%\Electronic Arts\CC Magic\Logs
Default=False
FileKey1=%Documents%\Electronic Arts\CC Magic\Logs|*.log|RECURSE
[CCDump *]
LangSecRef=3024
DetectFile=%ProgramFiles%\CCleaner\CCDump.exe
Default=False
Warning=This removes files winapp.ini, winsys.ini, winreg.ini and regkeys.output.txt from the CCleaner folder.
FileKey1=%ProgramFiles%\CCleaner|winapp.ini;winreg.ini;winsys.ini;regkeys.output.txt
[CCFinder *]
LangSecRef=3024
DetectFile=%LocalAppData%\Abelssoft\CCfinder
Default=False
FileKey1=%LocalAppData%\FlickrNet|responseCache.dat
[CCleaner *]
LangSecRef=3024
Detect=HKCU\Software\Piriform\CCleaner
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\CCleaner|*.log;CCleaner_log*.txt
FileKey2=%ProgramFiles%\CCleaner|*.log;CCleaner_log*.txt
FileKey3=%ProgramFiles%\CCleaner\Setup|*.*|REMOVESELF
FileKey4=%UserProfile%|CCleaner_log*.txt
[CCTV Security *]
LangSecRef=3021
DetectFile=%ProgramFiles%\CCTV Security
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Log|*.*
FileKey2=%ProgramFiles%\CCTV Security\Log|*.*
[CD/DVD Burn Cache *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning
Default=False
Warning=This will wipe all files that are waiting to be burned to a CD/DVD/BD drive.
FileKey1=%LocalAppData%\Microsoft\CD Burning|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\Burn|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo
[CDex *]
LangSecRef=3024
Detect=HKLM\Software\CDex
Default=False
FileKey1=%Music%\CDDB|*.txt
[Centarsia *]
LangSecRef=3021
Detect=HKCU\Software\Centarsia
Default=False
RegKey1=HKCU\Software\Centarsia|RecentImage0
RegKey2=HKCU\Software\Centarsia|RecentImage1
RegKey3=HKCU\Software\Centarsia|RecentImage2
RegKey4=HKCU\Software\Centarsia|RecentImage3
RegKey5=HKCU\Software\Centarsia|RecentImage4
RegKey6=HKCU\Software\Centarsia|RecentImage5
RegKey7=HKCU\Software\Centarsia|RecentImage6
[Ceville *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\23460
Default=False
FileKey1=%AppData%|ceville_console_history.txt
FileKey2=%Documents%\Ceville\logs|*.*
[CFE Exam Prep Course *]
LangSecRef=3021
DetectFile=%ProgramFiles%\CFE Exam Prep Course
Default=False
FileKey1=%AppData%\ACFEExamPrep|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\CFE Exam Prep Course\Log|*.*|RECURSE
FileKey3=%ProgramFiles%\CFE Exam Prep Course\Log|*.*|RECURSE
[Chameleon *]
LangSecRef=3024
DetectFile=%Documents%\Chameleon Files
Default=False
FileKey1=%Documents%\Chameleon Files\Cache|*.*|RECURSE
FileKey2=%Documents%\Chameleon Files\Log|*.*|RECURSE
[Champions Online *]
Section=Games
Detect1=HKCU\Software\Cryptic\Champions Online
Detect2=HKCU\Software\Valve\Steam\Apps\9880
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\Common\Champions Online\*\Logs\GameClient|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\Common\Champions Online\Champions Online\*\Cache|*.*
FileKey3=%ProgramFiles%\Steam\Steamapps\Common\Champions Online\*\Logs\GameClient|*.*
FileKey4=%ProgramFiles%\Steam\Steamapps\Common\Champions Online\Champions Online\*\Cache|*.*
FileKey5=%Public%\Games\cryptic studios\Champions Online\*\Cache|*.*
FileKey6=%Public%\Games\cryptic studios\Champions Online\*\Logs\GameClient|*.*
[Cheat Engine *]
LangSecRef=3021
Detect=HKCU\Software\Cheat Engine
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Cheat Engine*|*.tmp
FileKey2=%ProgramFiles%\Cheat Engine*|*.tmp
[CheatBook *]
LangSecRef=3021
Detect=HKLM\Software\CheatBook
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Cheatbook Database *|*cheatlog.txt;*suchlog.txt
FileKey2=%ProgramFiles%\Cheatbook Database *|*cheatlog.txt;*suchlog.txt
[Chicken Hunter *]
Section=Games
Detect=HKLM\Software\Chicken Hunter
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Chicken Hunter|debug.txt
FileKey2=%ProgramFiles%\Chicken Hunter|debug.txt
[Chicken Invaders *]
Section=Games
DetectFile1=%AppData%\InterAction studios\CI3demo
DetectFile2=%ProgramFiles%\Chicken*Invaders*
Default=False
FileKey1=%AppData%\InterAction studios|*.log|RECURSE
FileKey2=%CommonAppData%\InterAction studios|*.log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\*\Chicken Invaders*|*.log;*.html;*.png|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Chicken*Invaders*|*.log|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\InterAction studios|*.log|RECURSE
FileKey6=%ProgramFiles%\*\Chicken Invaders*|*.log;*.html;*.png|RECURSE
FileKey7=%ProgramFiles%\Chicken*Invaders*|*.log|RECURSE
[Children of the Nile *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\17100
Default=False
FileKey1=%Documents%\Tilted Mill\Children of the Nile|*.log
[Chivalry: Medieval Warfare *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\219640
Default=False
FileKey1=%Documents%\My Games\Chivalry Medieval Warfare*\UDKGame\Logs|*.*
[Chocolatey *]
LangSecRef=3024
DetectFile=%CommonAppData%\chocolatey
Default=False
FileKey1=%AppData%\ChocolateyGUI\Logs|*.*
FileKey2=%CommonAppData%\chocolatey\lib\*|*.txt
FileKey3=%CommonAppData%\chocolatey\logs|*.log
[Christmas Adventure - Candy Storm *]
Section=Games
Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Adventure - Candy Storm1.1
Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Adventure - Candy Stormv1.3
DetectFile=%ProgramFiles%\Christmas Adventure - Candy Storm
Default=False
FileKey1=%AppData%\Argali|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Christmas Adventure - Candy Storm|*.nfo;*.txt
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Foxy Games\Christmas Adventure - Candy Storm|*.html;*.msi;*.nfo;*.txt;*.url
FileKey4=%ProgramFiles%\Christmas Adventure - Candy Storm|*.nfo;*.txt
FileKey5=%ProgramFiles%\Foxy Games\Christmas Adventure - Candy Storm|*.html;*.msi;*.nfo;*.txt;*.url
[Christmas Griddlers 2014 *]
Section=Games
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Griddlers 20141.1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\*\Christmas Griddlers*|*.ico;*.html;*msi;*.nfo;*.txt;*.url|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Christmas Griddlers*|*.ico;*.html;*msi;*.nfo;*.txt;*.url|RECURSE
FileKey3=%ProgramFiles%\*\Christmas Griddlers*|*.ico;*.html;*msi;*.nfo;*.txt;*.url|RECURSE
FileKey4=%ProgramFiles%\Christmas Griddlers*|*.ico;*.html;*msi;*.nfo;*.txt;*.url|RECURSE
[Christmas Wonderland *]
Section=Games
Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 2
Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 3 1.0
Detect3=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 4 1.0.4
Detect4=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 21.0
Detect5=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 31.0
Detect6=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Christmas Wonderland 41.1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Christmas Wonderland *|*.html;*.nfo;*.txt;*.url|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Foxy Games\Christmas Wonderland *|*.html;*.nfo;*.txt;*.url|RECURSE
FileKey3=%ProgramFiles%\Christmas Wonderland *|*.html;*.nfo;*.txt;*.url|RECURSE
FileKey4=%ProgramFiles%\Foxy Games\Christmas Wonderland *|*.html;*.nfo;*.txt;*.url|RECURSE
FileKey5=%SystemDrive%\Games\Christmas Wonderland *|*.html;*.nfo;*.txt;*.url|RECURSE
[Chuzzle Deluxe *]
Section=Games
DetectFile=%ProgramFiles%\HP Games\Chuzzle Deluxe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\HP Games\Chuzzle Deluxe|DEBUG.TXT
FileKey2=%ProgramFiles%\HP Games\Chuzzle Deluxe|DEBUG.TXT
[Cinema Tycoon *]
Section=Games
Detect1=HKCU\Software\TikGames\Cinema Tycoon Gold
Detect2=HKLM\Software\Big Fish Games\Persistence\GameDB\Cinema Tycoon Gold
Detect3=HKLM\Software\Big Fish Games\Persistence\Install\F2676T1L1
Detect4=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Cinema Tycoon 2 Movie Mania1.0
Default=False
FileKey1=%ProgramFiles%\Cinema Tycoon*|flashplayer7_winax.exe;*.txt
[Cisco Connect *]
LangSecRef=3022
DetectFile=%CommonAppData%\Cisco Systems\Cisco Connect
Default=False
FileKey1=%CommonAppData%\Cisco Systems\Cisco Connect\Log|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Cisco Systems\Cisco Connect\Log|*.*
[Cisco HostScan *]
LangSecRef=3021
DetectFile=%LocalAppData%\Cisco\Cisco HostScan\log
Default=False
FileKey1=%LocalAppData%\Cisco\Cisco HostScan\log|*.log
[Cities in Motion *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\73010
Default=False
FileKey1=%Documents%\Cities in Motion|log_metro.txt
[Citrix ICA Client *]
LangSecRef=3021
Detect=HKLM\Software\Citrix\ICA Client
Default=False
FileKey1=%AppData%\Citrix\ICA Client\Cache|*.*
FileKey2=%AppData%\Citrix\ICA Client\Cache\zlcache|*.*
FileKey3=%AppData%\ICAClient|wfcwin32.*
FileKey4=%AppData%\ICAClient\Cache|*.*
FileKey5=%AppData%\ICAClient\Cache\zlcache|*.*
RegKey1=HKLM\Software\Citrix\ICA Client\Default
[Citrix Online Plug-in Web Setup Files *]
LangSecRef=3021
Detect=HKLM\Software\Citrix\ICA Client
Default=False
FileKey1=%CommonAppData%\Citrix\Citrix Online Plug-in - Web|*.msi;*.cab;eula*.rtf
[Civilization 5 Installers *]
Section=Games
Detect=HKCU\Software\Firaxis\Civilization5
Default=False
Warning=This will remove DirectX and Visual C++ installers in your Civilization 5 installation directory. They can be reinstalled in your installation source.
FileKey1=%ProgramFiles%\Civilization V*\DirectX|*.*|REMOVESELF
FileKey2=%ProgramFiles%\Civilization V*\VCRedist|*.*|REMOVESELF
[Civilization 5 Old Autosaves *]
Section=Games
Detect=HKCU\Software\Firaxis\Civilization5
Default=False
FileKey1=%Documents%\My Games\Sid Meier's Civilization 5\Saves\*\auto\prev|*.Civ5Save
[Civilization Cache *]
Section=Games
Detect1=HKCU\Software\Firaxis\Civilization5
Detect2=HKLM\Software\Firaxis Games
Default=False
FileKey1=%AppData%\My Games\Beyond the Sword\cache|*.dat
FileKey2=%AppData%\My Games\Sid Meier's Civilization *\cache|*.dat
FileKey3=%AppData%\My Games\Warlords\cache|*.dat
FileKey4=%Documents%\My Games\Sid Meier's Civilization *\cache|*.db
FileKey5=%LocalAppData%\My Games\Beyond the Sword\cache|*.dat
FileKey6=%LocalAppData%\My Games\Sid Meier's Civilization *\cache|*.dat
FileKey7=%LocalAppData%\My Games\Warlords\cache|*.dat
[Civilization Logs *]
Section=Games
Detect1=HKCU\Software\Firaxis\Civilization5
Detect2=HKLM\Software\Firaxis Games
Default=False
FileKey1=%Documents%\My Games\Beyond the Sword\Logs|*.*
FileKey2=%Documents%\My Games\Sid Meier's Civilization *\Logs|*.*
FileKey3=%Documents%\My Games\Warlords\Logs|*.*
FileKey4=%LocalAppData%\VirtualStore\Program Files*\2K Games\Firaxis Games\Sid Meier's Civilization IV Colonization|*.txt
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Firaxis Games\Sid Meier's Civilization 4|*.txt
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Firaxis Games\Sid Meier's Civilization 4\*|*.txt
FileKey7=%ProgramFiles%\2K Games\Firaxis Games\Sid Meier's Civilization IV Colonization|*.txt
FileKey8=%ProgramFiles%\Firaxis Games\Sid Meier's Civilization 4|*.txt
FileKey9=%ProgramFiles%\Firaxis Games\Sid Meier's Civilization 4\*|*.txt
[Clam Sentinel *]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{060FE577-1BDF-4330-ACCA-B6760AB07191}_is1
Default=False
FileKey1=%AppData%\ClamSentinel|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\ClamSentinel|*.txt
FileKey3=%ProgramFiles%\ClamSentinel|*.txt
[ClamWin *]
LangSecRef=3021
Detect1=HKCU\Software\ClamWin
Detect2=HKLM\Software\ClamWin
Default=False
FileKey1=%AppData%\.clamwin\log|*.*|RECURSE
FileKey2=%CommonAppData%\.clamwin\log|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\ClamWin\bin|*.txt
FileKey4=%ProgramFiles%\ClamWin\bin|*.txt
[ClamWin Portable Failed Updates *]
LangSecRef=3024
DetectFile=%SystemDrive%\PortableApps\ClamWinPortable\ClamWinPortable.exe
Default=False
FileKey1=%SystemDrive%\PortableApps\ClamWinPortable\Data\db\clamav*|*.*|REMOVESELF
[ClassicShell MRU *]
LangSecRef=3024
Detect=HKCU\Software\IvoSoft\ClassicStartMenu
Default=False
RegKey1=HKCU\Software\IvoSoft\ClassicStartMenu\MRU
[Clean Genius 3 *]
LangSecRef=3024
DetectFile=%ProgramFiles%\CleanGenius 3\Update
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\CleanGenius 3\Update|update.log
FileKey2=%ProgramFiles%\CleanGenius 3\Update|update.log
[CleanMyPC Registry Cleaner *]
LangSecRef=3024
Detect=HKCU\Software\CleanMyPC\CleanMyPC - Registry Cleaner
Default=False
FileKey1=%AppData%\CleanMyPC Software\CleanMyPC Registry Cleaner|fixlog.ini
FileKey2=%WinDir%\$regcmp$|*.*|REMOVESELF
[CleanUp! *]
LangSecRef=3024
Detect=HKCU\Software\stevengould.org\CleanUp!
Default=False
FileKey1=%AppData%|CleanUp!.log
[Clementine *]
LangSecRef=3023
Detect=HKCU\Software\Clementine
Default=False
FileKey1=%UserProfile%\.config\Clementine\networkcache\http|*.cache|RECURSE
[Click.to *]
LangSecRef=3021
DetectFile=%LocalAppData%\click.to
Default=False
FileKey1=%LocalAppData%\click.to|*.txt|RECURSE
[ClickFree Full Imaging Backup *]
LangSecRef=3024
DetectFile=%CommonAppData%\ClickFree\FullImagingBackup
Default=False
FileKey1=%CommonAppData%\ClickFree\FullImagingBackup|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\ClickFree\FullImagingBackup|*.log
[ClipX *]
LangSecRef=3024
DetectFile=%LocalAppData%\ClipX
Default=False
FileKey1=%LocalAppData%\ClipX\Storage|*.*
[CloneSpy *]
LangSecRef=3024
DetectFile=%ProgramFiles%\CloneSpy
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\CloneSpy|CloneSpy.log
FileKey2=%ProgramFiles%\CloneSpy|CloneSpy.log
[Cloud Experience Host *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_*\TempState|*.*|RECURSE
[Cloudfogger *]
LangSecRef=3023
Detect1=HKCU\Software\Cloudfogger
Detect2=HKCU\Software\Cloudfogger.com
Default=False
FileKey1=%AppData%\Cloudfogger|*.log|RECURSE
FileKey2=%LocalAppData%\CrashRpt|*.log|RECURSE
[Cloudfogger Keys *]
LangSecRef=3023
Detect1=HKCU\Software\Cloudfogger
Detect2=HKCU\Software\Cloudfogger.com
Default=False
FileKey1=%AppData%\Cloudfogger\Keys|*.*|RECURSE
[CloudShark Plugin for Wireshark *]
LangSecRef=3024
DetectFile=%AppData%\Wireshark\plugins\cloudshark
Default=False
FileKey1=%AppData%\Wireshark\plugins\cloudshark\tmp|*.*
[Clover *]
LangSecRef=3024
Detect=HKCU\Software\Clover
Default=False
FileKey1=%LocalAppData%\Clover\User Data\Default\JumpListIcons*|*tmp
FileKey2=%LocalAppData%\Clover\User Data\temp|*.*|RECURSE
[Clover Bookmarks Backup *]
LangSecRef=3024
Detect=HKCU\Software\Clover
Default=False
FileKey1=%LocalAppData%\Clover\User Data\Default|Bookmarks.bak
[Clover Session *]
LangSecRef=3024
Detect=HKCU\Software\Clover
Default=False
FileKey1=%LocalAppData%\Clover\User Data\Default|Current *;Last *
[CNET Tech Tracker *]
LangSecRef=3024
Detect=HKCU\Software\CBS Interactive\CNET TechTracker
Default=False
FileKey1=%AppData%\CBS Interactive\CNET TechTracker\data|temp.html;ztempimages*.png;*.db
FileKey2=%AppData%\CBS Interactive\CNET TechTracker\temp|*.*|REMOVESELF
FileKey3=%Documents%\Downloads\CNET TechTracker|*.*
RegKey1=HKCU\Software\CBS Interactive\CNET TechTracker\Recent File List
[CNET Tech Tracker Backups *]
LangSecRef=3024
Detect=HKCU\Software\CBS Interactive\CNET TechTracker
Default=False
FileKey1=%AppData%\CBS Interactive\CNET TechTracker|*.bak
[CNN *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\588E6FFA.CNNAppforWindows_cs8eyncph15zy
DetectFile=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_cs8eyncph15zy
Default=False
FileKey1=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\Microsoft\CLR_v4.0|*.log
FileKey3=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\Microsoft\CLR_v4.0*\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\PRICache|*.*
FileKey5=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\AC\Temp|*.*
FileKey6=%LocalAppData%\Packages\588E6FFA.CNNAppforWindows_*\TempState|*.*|RECURSE
[CodeGear RAD Studio 2009 *]
LangSecRef=3024
Detect=HKCU\Software\CodeGear\BDS\6.0
Default=False
RegKey1=HKCU\Software\CodeGear\BDS\6.0\Closed Files
RegKey2=HKCU\Software\CodeGear\BDS\6.0\Closed Projects
RegKey3=HKCU\Software\CodeGear\BDS\6.0\Session
[CodeMeter *]
LangSecRef=3023
DetectFile=%CommonAppData%\CodeMeter
Default=False
FileKey1=%CommonAppData%\CodeMeter\Logs|*.*
[CoffeeCup GIF Animator *]
LangSecRef=3024
Detect=HKCU\Software\CoffeeCup Software\GIF Animator
Default=False
RegKey1=HKCU\Software\CoffeeCup Software\GIF Animator\Settings\MRU
[Cogs *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\26500
Default=False
FileKey1=%LocalAppData%\Lazy 8 Studio\Cogs|log.txt
[ColorSchemer *]
LangSecRef=3023
Detect=HKCU\Software\ColorSchemer
Default=False
FileKey1=%AppData%\ColorSchemer\Studio\*|recentfiles.xml
[ComboFix *]
LangSecRef=3024
DetectFile=%SystemDrive%\Qoobox
Default=False
Warning=This will delete ComboFix History. Do not delete until you have reviewed these logs.
FileKey1=%SystemDrive%|ComboFix.txt
FileKey2=%SystemDrive%\*.tmp|*.*|REMOVESELF
FileKey3=%SystemDrive%\Qoobox|*.txt
FileKey4=%SystemDrive%\Qoobox\LastRun|*.*|REMOVESELF
FileKey5=%SystemDrive%\Qoobox\Quarantine|*.log
FileKey6=%SystemDrive%\Qoobox\Test*|*.*|REMOVESELF
[Comcast Toolbar *]
LangSecRef=3022
Detect=HKCU\Software\ComcastToolbar
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\ComcastToolbar\Cache|*.*
FileKey2=%ProgramFiles%\ComcastToolbar\Cache|*.*
[ComicRack *]
LangSecRef=3021
DetectFile=%LocalAppData%\cYo\ComicRack
Default=False
FileKey1=%LocalAppData%\cYo\ComicRack\Cache\Images|*.*|RECURSE
FileKey2=%LocalAppData%\cYo\ComicRack\Cache\Thumbnails|*.*|RECURSE
[Common Language Runtime *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%LocalAppData%\Microsoft\CLR_v*.*|*.*|RECURSE
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\CLR_v*.*|*.*|RECURSE
FileKey3=%WinDir%\System32\config\systemprofile\Local Settings\Application Data\Microsoft\CLR_v*.*|*.*|RECURSE
FileKey4=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\CLR_v*.*|*.*|RECURSE
FileKey5=%WinDir%\SysWOW64\config\systemprofile\Local Settings\Application Data\Microsoft\CLR_v*.*|*.*|RECURSE
[Comms Phone *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.CommsPhone_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.CommsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.CommsPhone_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.CommsPhone_*\TempState|*.*|RECURSE
[Comodo *]
LangSecRef=3024
Detect=HKCU\Software\ComodoGroup
Default=False
FileKey1=%AppData%\Comodo\CCE\Logs|*.*
FileKey2=%AppData%\ComodoGroup\CSC\Cache|*.*
FileKey3=%CommonAppData%\Comodo Downloader|*.*
FileKey4=%CommonAppData%\Comodo\CisDumps|*.*
FileKey5=%CommonAppData%\Comodo\Firewall Pro|cislogs.sdb
FileKey6=%CommonAppData%\Comodo\Installer|*.*
FileKey7=%LocalAppData%\COMODO|*.tmp
FileKey8=%LocalAppData%\VirtualStore\Program Files*\COMODO\COMODO Internet Security|*.tmp
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Comodo Downloader|*.*
FileKey10=%LocalAppData%\VirtualStore\ProgramData\Comodo\CisDumps|*.*
FileKey11=%LocalAppData%\VirtualStore\ProgramData\Comodo\Installer|*.*
FileKey12=%ProgramFiles%\COMODO\COMODO Internet Security|*.tmp;CRASH.DMP;cmdagent.zip
[Comodo CertSentry *]
LangSecRef=3022
Detect=HKLM\Software\COMODO\CertSentry
Default=False
FileKey1=%LocalAppData%\COMODO\CertSentry|*.log
[Comodo GeekBuddy *]
LangSecRef=3021
Detect=HKLM\Software\GeekBuddyRSP
DetectFile=%ProgramFiles%\Comodo\GeekBuddy
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Comodo\GeekBuddy\logs|*.*|RECURSE
FileKey2=%ProgramFiles%\Comodo\GeekBuddy\logs|*.*|RECURSE
[Company of Heroes *]
Section=Games
DetectFile=%Documents%\My Games\Company of Heroes*
Default=False
FileKey1=%Documents%\My Games\Company of Heroes*|*.log
FileKey2=%Documents%\My Games\Company of Heroes*\Cache|*.*
FileKey3=%Documents%\My Games\Company of Heroes*\LogFiles|*.*
[Compatibility Assistant *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant
Default=False
RegKey1=HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
RegKey2=HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
RegKey3=HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
RegKey4=HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
[Conceiva Mezzmo *]
LangSecRef=3023
Detect=HKLM\Software\Conceiva\Mezzmo
Default=False
FileKey1=%CommonAppData%\Conceiva\*|*.bat;*.exe;*.txt
FileKey2=%CommonAppData%\Conceiva\Mezzmo\CER|*.zip
FileKey3=%LocalAppData%\Conceiva\Logs|*.*|REMOVESELF
FileKey4=%LocalAppData%\Conceiva\Mezzmo|DebugCERwrite.txt
FileKey5=%LocalAppData%\Conceiva\Mezzmo\Temporary_*_Files|*.*|REMOVESELF
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Conceiva\Mezzmo|*.txt
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Conceiva\Mezzmo\Third\MKVToolNix|*.txt
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Conceiva\Mezzmo\Third\OGMDemuxer\doc|*.*|REMOVESELF
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Conceiva\Mezzmo\CER|*.zip
FileKey10=%ProgramFiles%\Conceiva\Mezzmo|*.txt
FileKey11=%ProgramFiles%\Conceiva\Mezzmo\Third\MKVToolNix|*.txt
FileKey12=%ProgramFiles%\Conceiva\Mezzmo\Third\OGMDemuxer\doc|*.*|REMOVESELF
RegKey1=HKCU\Software\Conceiva\Mezzmo\General|LastWatchFolder
[Conduit *]
LangSecRef=3021
Detect=HKCU\Software\Conduit
Default=False
FileKey1=%LocalLowAppData%\Conduit\Community Alerts\Log|*.*|REMOVESELF
FileKey2=%LocalLowAppData%\ConduitEngine\CacheIcons|*.*
FileKey3=%LocalLowAppData%\ConduitEngine\Logs|*.*
FileKey4=%WinDir%\System32|ConduitEngine.tmp
[Connectify Hotspot *]
LangSecRef=3022
Detect=HKLM\Software\Connectify
Default=False
FileKey1=%CommonAppData%\Connectify\cache|*.time;*.cache;*.runtime
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Connectify\cache|*.time;*.cache;*.runtime
FileKey3=%ProgramFiles%\Connectify\Installer|*.*|REMOVESELF
FileKey4=%ProgramFiles%\Connectify\Portal|*.*|REMOVESELF
[Connectivity Store *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ConnectivityStore_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ConnectivityStore_*\TempState|*.*|RECURSE
[Conquer Online *]
Section=Games
DetectFile=%ProgramFiles%\NetDragon\Conquer Online 2.0\AutoPatch
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\NetDragon\Conquer Online 2.0\AutoPatch|Update.log
FileKey2=%ProgramFiles%\NetDragon\Conquer Online 2.0\AutoPatch|Update.log
[Contact Support *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Windows.ContactSupport_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0*|*.log
FileKey4=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CLR_v4.0*\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Windows.ContactSupport_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Windows.ContactSupport_*\LocalState\Cache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Windows.ContactSupport_*\TempState|*.*|RECURSE
[Content Delivery Manager *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\Favicons|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\MobilityExperience\ImageCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\OneSettingsResponseCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\LocalState\TargetedContentCache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.Windows.ContentDeliveryManager_*\TempState|*.*|RECURSE
[ConTEXT *]
LangSecRef=3021
Detect=HKCU\Software\Eden\ConTEXT
Default=False
RegKey1=HKCU\Software\Eden\ConTEXT\FileHistory
RegKey2=HKCU\Software\Eden\ConTEXT\FindHistory
[Cook'n Backups *]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Cook'n
Default=False
FileKey1=%Documents%\Cook'n Backups|*.ckn
FileKey2=%Documents%\Cook'n10\Workspace\data|download;dvodb.backup
FileKey3=%Documents%\Cook'n10\Workspace\update|update.zip
FileKey4=%Documents%\Cook'n11\Download|*.*
[Cook'n Cache *]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Cook'n
Default=False
FileKey1=%AppData%\Mozilla\eclipse\Cache|*.*
[Cook'n Dups *]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Cook'n
Default=False
Warning=This removes identical duplicates of the huge Getting Started Guide.
FileKey1=%LocalAppData%\DVO\Cook'n10App\plugins|Getting Started Guide.rtf|RECURSE
[Cook'n Logs *]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Cook'n
Default=False
FileKey1=%Documents%\Cook'n*|*.log|RECURSE
FileKey2=%LocalAppData%\DVO\Cook'n*App|*.log|RECURSE
[Copernic DesktopSearch4 *]
LangSecRef=3024
Detect=HKLM\Software\Copernic\DesktopSearch4
Default=False
FileKey1=%AppData%\Copernic\DesktopSearch4\Logs|*.*|REMOVESELF
FileKey2=%LocalAppData%\Copernic\DesktopSearch4\Logs|*.*|REMOVESELF
[CopyTo Synchronizer *]
LangSecRef=3024
Detect=HKCU\Software\kishDesign\CopyTo
Default=False
RegKey1=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder00
RegKey2=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder01
RegKey3=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder02
RegKey4=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder03
RegKey5=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder04
RegKey6=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder05
RegKey7=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder06
RegKey8=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder07
RegKey9=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder08
RegKey10=HKCU\Software\kishDesign\CopyTo\settings3|scutFolder09
RegKey11=HKCU\Software\kishDesign\CopyTo\settings3|scutname00
RegKey12=HKCU\Software\kishDesign\CopyTo\settings3|scutname01
RegKey13=HKCU\Software\kishDesign\CopyTo\settings3|scutname02
RegKey14=HKCU\Software\kishDesign\CopyTo\settings3|scutname03
RegKey15=HKCU\Software\kishDesign\CopyTo\settings3|scutname04
RegKey16=HKCU\Software\kishDesign\CopyTo\settings3|scutname05
RegKey17=HKCU\Software\kishDesign\CopyTo\settings3|scutname06
RegKey18=HKCU\Software\kishDesign\CopyTo\settings3|scutname07
RegKey19=HKCU\Software\kishDesign\CopyTo\settings3|scutname08
RegKey20=HKCU\Software\kishDesign\CopyTo\settings3|scutname09
RegKey21=HKCU\Software\kishDesign\CopyTo\settings3|Source00
RegKey22=HKCU\Software\kishDesign\CopyTo\settings3|Source01
RegKey23=HKCU\Software\kishDesign\CopyTo\settings3|Source02
RegKey24=HKCU\Software\kishDesign\CopyTo\settings3|Source03
RegKey25=HKCU\Software\kishDesign\CopyTo\settings3|Source04
RegKey26=HKCU\Software\kishDesign\CopyTo\settings3|Source05
RegKey27=HKCU\Software\kishDesign\CopyTo\settings3|Source06
RegKey28=HKCU\Software\kishDesign\CopyTo\settings3|Source07
RegKey29=HKCU\Software\kishDesign\CopyTo\settings3|Source08
RegKey30=HKCU\Software\kishDesign\CopyTo\settings3|Source09
RegKey31=HKCU\Software\kishDesign\CopyTo\settings3|target00
RegKey32=HKCU\Software\kishDesign\CopyTo\settings3|target01
RegKey33=HKCU\Software\kishDesign\CopyTo\settings3|target02
RegKey34=HKCU\Software\kishDesign\CopyTo\settings3|target03
RegKey35=HKCU\Software\kishDesign\CopyTo\settings3|target04
RegKey36=HKCU\Software\kishDesign\CopyTo\settings3|target05
RegKey37=HKCU\Software\kishDesign\CopyTo\settings3|target06
RegKey38=HKCU\Software\kishDesign\CopyTo\settings3|target07
RegKey39=HKCU\Software\kishDesign\CopyTo\settings3|target08
RegKey40=HKCU\Software\kishDesign\CopyTo\settings3|target09
[CopyTrans *]
LangSecRef=3023
DetectFile1=%AppData%\WindSolutions\CopyTrans*
DetectFile2=%CommonAppData%\WindSolutions\CopyTrans*
Default=False
FileKey1=%CommonAppData%\WindSolutions|*.txt|RECURSE
FileKey2=%CommonAppData%\WindSolutions\CopyTrans*\Logs|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\WindSolutions|*.txt|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\WindSolutions\CopyTrans*\Logs|*.*|RECURSE
[Core Temp *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Core Temp
Default=False
FileKey1=%ProgramFiles%\Core Temp|*.csv
[Corel AfterShot Pro *]
LangSecRef=3023
Detect=HKCU\Software\Corel\AfterShot Pro V3
Default=False
FileKey1=%LocalAppData%\Corel\AfterShot Pro *|*.log
FileKey2=%LocalAppData%\Corel\AfterShot Pro *\Cache|*.*|RECURSE
[Corel Downloads *]
LangSecRef=3021
DetectFile=%CommonAppData%\Corel\Downloads
Default=False
FileKey1=%CommonAppData%\Corel\Downloads|*.*|RECURSE
[Corel PaintShop Pro *]
LangSecRef=3023
Detect1=HKCU\Software\Corel\PaintShop Pro\X4
Detect2=HKCU\Software\Corel\PaintShop Pro\X5
Detect3=HKCU\Software\Corel\PaintShop Pro\X6
Detect4=HKCU\Software\Corel\PaintShop Pro\X7
Detect5=HKCU\Software\Corel\PaintShop Pro\X10
Detect6=HKCU\Software\Corel\PhotoDownloader\2
Default=False
FileKey1=%AppData%\Corel\PaintShop Photo Pro\13\Cache|*.*|RECURSE
FileKey2=%LocalAppData%\Corel|*.db;*.PspCache
FileKey3=%LocalAppData%\Corel PaintShop Pro\*\Cache|*.*
FileKey4=%LocalAppData%\Corel PaintShop Pro\*\Database|*.db
FileKey5=%LocalAppData%\Corel PaintShop Pro\*\Thumbs|*.*|RECURSE
FileKey6=%LocalAppData%\Corel\Thumbs|*.*|RECURSE
RegKey1=HKCU\Software\Corel\PaintShop Pro\X7\CoreMemoryManager\0
RegKey2=HKCU\Software\Corel\PaintShop Pro\X10\CoreMemoryManager\0
RegKey3=HKCU\Software\Corel\PhotoDownloader\2\PhotoDownloader\DefaultDownloadFolder
RegKey4=HKCU\Software\Corel\PhotoDownloader\2\PhotoDownloader\DownloadFolder
[Corel PaintShop Pro AutoPreserve *]
LangSecRef=3023
Detect1=HKCU\Software\Corel\PaintShop Pro\X6
Detect2=HKCU\Software\Corel\PaintShop Pro\X7
Detect3=HKCU\Software\Corel\PaintShop Pro\X10
Default=False
FileKey1=%Pictures%\Corel Auto-Preserve|*.*
[Corel VideoStudio Pro *]
LangSecRef=3023
Detect1=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\14.0
Detect2=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\15.0
Detect3=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\16.0
Detect4=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\17.0
Default=False
FileKey1=%Documents%\Corel VideoStudio Pro\*.0\AudioTmp|*.*
FileKey2=%Documents%\Corel VideoStudio Pro\*.0\SmartProxy|*.*
RegKey1=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\14.0\Preference|Working Folder
RegKey2=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\15.0\HerRFL
RegKey3=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\16.0\HerRFL
RegKey4=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\17.0\HerRFL
[CorelDRAW Graphics Suite X7 *]
LangSecRef=3021
Detect=HKCU\Software\Corel\CorelDRAW\17.0
Default=False
FileKey1=%CommonAppData%\Bitstream\Font Navigator\6.0\Cache|*.*|RECURSE
FileKey2=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Config|corelpdf.ini;capture.ini
FileKey3=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Connect|Connect.config
FileKey4=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw|FindAndReplaceMRU.xml
FileKey5=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw\Export|dialog.export.web.xml
FileKey6=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw\Presets\HTML Export|default.pst
FileKey7=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\Draw\PreviewCache|*.*|RECURSE
FileKey8=%LocalAppData%\Corel\CorelDRAW Graphics Suite X7\PHOTO-PAINT\PreviewCache|*.*|RECURSE
FileKey9=%ProgramFiles%\Corel\CorelDRAW Graphics Suite X7\Setup|*.*|REMOVESELF
RegKey1=HKCU\Software\Bitstream\Font Navigator\6.0\Copy|Folders
RegKey2=HKCU\Software\Bitstream\Font Navigator\6.0\Move|Folders
RegKey3=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\Directories|DrawDocsDir
RegKey4=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\Framework|RecentFiles
RegKey5=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\HTML Export|DestPath
RegKey6=HKCU\Software\Corel\CorelDRAW\17.0\Draw\Application Preferences\NewFromTemplate|BrowseTemplateDir
RegKey7=HKCU\Software\Corel\CorelDRAW\17.0\PHOTO-PAINT\Application Preferences\Framework|RecentFiles
[Corsair iCue Logs *]
LangSecRef=3024
DetectFile=%CommonAppData%\Corsair\CUE\Service logs
Default=False
Warning=Disabling "Debug Logging" in iCue will prevent these files from being recreated.
FileKey1=%CommonAppData%\Corsair\CUE\Service logs|Service_Trace*.log
[Cortana *]
LangSecRef=3031
Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Cortana_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Cortana_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft*Cortana_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft*Cortana_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft*Cortana_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft*Cortana_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft*Cortana_*\AC\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft*Cortana_*\TempState|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\LocalState\*Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Windows.Cortana_*\TempState|*.*|RECURSE
[CounterSpy *]
LangSecRef=3024
Detect=HKLM\Software\Sunbelt Software\CounterSpy
Default=False
FileKey1=%CommonAppData%\Sunbelt Software\CounterSpy\Logs|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sunbelt Software\CounterSpy\Logs|*.*
[Crayon Physics Deluxe *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\26900
Default=False
FileKey1=%AppData%\Crayon Physics Deluxe|log.txt
FileKey2=%AppData%\Crayon Physics Deluxe\data\recordings\temp|current_recording.tmp
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\crayon physics deluxe|log.txt
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\crayon physics deluxe\cache|*.*
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\crayon physics deluxe\data\editor|*.tmp
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\crayon physics deluxe\data\recordings\temp|*.tmp
FileKey7=%ProgramFiles%\Steam\steamapps\common\crayon physics deluxe|log.txt
FileKey8=%ProgramFiles%\Steam\steamapps\common\crayon physics deluxe\cache|*.*
FileKey9=%ProgramFiles%\Steam\steamapps\common\crayon physics deluxe\data\editor|*.tmp
FileKey10=%ProgramFiles%\Steam\steamapps\common\crayon physics deluxe\data\recordings\temp|*.tmp
[Creative Installation Information *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Creative Installation Information
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Creative Installation Information|*.log|RECURSE
FileKey2=%ProgramFiles%\Creative Installation Information|*.log|RECURSE
[Creative Live! Central 3 *]
LangSecRef=3023
DetectFile=%AppData%\Creative\Live! Central 3
Default=False
FileKey1=%AppData%\Creative\Live! Central 3|*.txt|RECURSE
[Creative Pro Proteus VX *]
LangSecRef=3023
Detect=HKCU\Software\Creative Professional\Proteus VX
Default=False
RegKey1=HKCU\Software\Creative Professional\Proteus VX VSTi\Recent File List
[Creative Sound Blaster *]
LangSecRef=3024
Detect1=HKLM\Software\CREATIVE TECH\Software Installed\Software Update
Detect2=HKLM\Software\CREATIVE TECH\Sound Blaster X-Fi MB
Detect3=HKLM\Software\CREATIVE TECH\Sound Blaster Z-Series Control Panel
Default=False
FileKey1=%CommonAppData%\Creative\Software Update\Cache|*.*|RECURSE
FileKey2=%CommonAppData%\Creative\Software Update\Log|*.*
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Creative\Software Update\Cache|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Creative\Software Update\Log|*.*
[CrypTool 2 *]
LangSecRef=3024
Detect=HKCU\Software\CrypTool2.0
Default=False
FileKey1=%LocalAppData%\CrypTool2\Temp|*.*|REMOVESELF
RegKey1=HKCU\Software\CrypTool2.0|recentFileList
[Crysis 3 *]
Section=Games
Detect=HKLM\Software\Crytek\Crysis 3
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Crysis 3\LogBackups|*.*
FileKey2=%ProgramFiles%\Origin Games\Crysis 3\LogBackups|*.*
FileKey3=%UserProfile%\Saved Games\Crysis 3|*.Log.txt
[CrystalDiskInfo *]
LangSecRef=3024
DetectFile=%ProgramFiles%\CrystalDiskInfo\Smart
Default=False
Warning=This will delete all saved SMART data for history/graph function.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\CrystalDiskInfo\Smart|*.*|RECURSE
FileKey2=%ProgramFiles%\CrystalDiskInfo\Smart|*.*|RECURSE
[Curse Client *]
Section=Games
Detect=HKCU\Software\Classes\Curse
Default=False
FileKey1=%AppData%\Curse Client|*.log
FileKey2=%AppData%\Curse Client\Logs|*.*
FileKey3=%LocalAppData%\Apps\2.0|*.Log|RECURSE
[CursorFX *]
LangSecRef=3024
Detect=HKCU\Software\CursorFX Theme Editor
Default=False
RegKey1=HKCU\Software\CursorFX Theme Editor\Recent File List
[CustomBrushesMini Paint.Net-Plunging *]
LangSecRef=3021
DetectFile=%AppData%\CustomBrushesMini
Default=False
FileKey1=%AppData%\CustomBrushesMini\ThumbCache|*.*|RECURSE
[CuteHTML 2.3 *]
LangSecRef=3024
Detect=HKCU\Software\GlobalSCAPE\CuteHTML\2.3
Default=False
RegKey1=HKCU\Software\GlobalSCAPE\CuteHTML\2.3\Recent File List
[CutePDF Writer *]
LangSecRef=3023
Detect=HKCU\Software\Acro Software Inc\CPW
Default=False
FileKey1=%LocalAppData%\CutePDF Writer|*.tmp
RegKey1=HKCU\Software\Acro Software Inc\CPW|Filename
RegKey2=HKCU\Software\Acro Software Inc\CPW|Title
[Cyberduck *]
LangSecRef=3024
Detect=HKCR\.cyberducklicense
Default=False
FileKey1=%AppData%\Cyberduck|*.log
[CyberLink AudioDirector *]
LangSecRef=3023
Detect1=HKCU\Software\CyberLink\AudioDirector4
Detect2=HKCU\Software\CyberLink\AudioDirector5
Detect3=HKCU\Software\CyberLink\AudioDirector6
Detect4=HKCU\Software\CyberLink\AudioDirector7
Detect5=HKCU\Software\CyberLink\AudioDirector8
Detect6=HKCU\Software\CyberLink\AudioDirector9
Default=False
FileKey1=%Documents%\Cyberlink\AudioDirector\*\SplitterIndex|*.*|RECURSE
FileKey2=%LocalAppData%\Cyberlink\AudioDirector\*|*.*|RECURSE
RegKey1=HKCU\Software\CyberLink\AudioDirector4\MediaObj\MediaCache5\Data5
RegKey2=HKCU\Software\CyberLink\AudioDirector4\MediaObj\MediaCache5\Thumbnail5
RegKey3=HKCU\Software\CyberLink\AudioDirector5\MediaObj\MediaCache5\Data5
RegKey4=HKCU\Software\CyberLink\AudioDirector5\MediaObj\MediaCache5\Thumbnail5
RegKey5=HKCU\Software\CyberLink\AudioDirector6\MediaObj\MediaCache5\Data5
RegKey6=HKCU\Software\CyberLink\AudioDirector6\MediaObj\MediaCache5\Thumbnail5
RegKey7=HKCU\Software\CyberLink\AudioDirector7\MediaObj\MediaCache5\Data5
RegKey8=HKCU\Software\CyberLink\AudioDirector7\MediaObj\MediaCache5\Thumbnail5
RegKey9=HKCU\Software\CyberLink\AudioDirector8\MediaObj\MediaCache5\Data5
RegKey10=HKCU\Software\CyberLink\AudioDirector8\MediaObj\MediaCache5\Thumbnail5
RegKey11=HKCU\Software\CyberLink\AudioDirector9\MediaObj\MediaCache5\Data5
RegKey12=HKCU\Software\CyberLink\AudioDirector9\MediaObj\MediaCache5\Thumbnail5
[CyberLink ColorDirector *]
LangSecRef=3023
Detect1=HKCU\Software\CyberLink\ColorDirector3
Detect2=HKCU\Software\CyberLink\ColorDirector4
Detect3=HKCU\Software\CyberLink\ColorDirector5
Detect4=HKCU\Software\CyberLink\ColorDirector6
Detect5=HKCU\Software\CyberLink\ColorDirector7
Default=False
FileKey1=%LocalAppData%\Cyberlink\ColorDirector\*|*.*|RECURSE
RegKey1=HKCU\Software\CyberLink\ColorDirector3\MediaObj\MediaCache5\Data5
RegKey2=HKCU\Software\CyberLink\ColorDirector3\MediaObj\MediaCache5\Thumbnail5
RegKey3=HKCU\Software\CyberLink\ColorDirector4\MediaObj\MediaCache5\Data5
RegKey4=HKCU\Software\CyberLink\ColorDirector4\MediaObj\MediaCache5\Thumbnail5
RegKey5=HKCU\Software\CyberLink\ColorDirector5\MediaObj\MediaCache5\Data5
RegKey6=HKCU\Software\CyberLink\ColorDirector5\MediaObj\MediaCache5\Thumbnail5
RegKey7=HKCU\Software\CyberLink\ColorDirector6\MediaObj\MediaCache5\Data5
RegKey8=HKCU\Software\CyberLink\ColorDirector6\MediaObj\MediaCache5\Thumbnail5
RegKey9=HKCU\Software\CyberLink\ColorDirector7\MediaObj\MediaCache5\Data5
RegKey10=HKCU\Software\CyberLink\ColorDirector7\MediaObj\MediaCache5\Thumbnail5
[CyberLink Crash Files *]
LangSecRef=3023
Detect=HKCU\Software\CyberLink
Default=False
FileKey1=%CommonAppData%\CyberLink\Boomerang\*|*.xml;*.dmp
FileKey2=%CommonAppData%\CyberLink\PowerDVD*\Boomerang\*|*.xml;*.dmp
FileKey3=%LocalAppData%\VirtualStore\ProgramData\CyberLink\Boomerang\*|*.xml;*.dmp
FileKey4=%LocalAppData%\VirtualStore\ProgramData\CyberLink\PowerDVD*\Boomerang\*|*.xml;*.dmp
[CyberLink Downloader *]
LangSecRef=3023
Detect=HKCU\Software\CyberLink\CLDownloader
Default=False
FileKey1=%CommonAppData%\CyberLink\CBE\*|*.*|RECURSE
FileKey2=%CommonAppData%\CyberLink\Downloader|*.*|RECURSE
[CyberLink Install Files *]
LangSecRef=3023
Detect=HKCU\Software\CyberLink
Default=False
FileKey1=%CommonAppData%\install_backup|*.*|REMOVESELF
FileKey2=%CommonAppData%\install_clap|*.*|REMOVESELF
FileKey3=%LocalAppData%\VirtualStore\ProgramData\install_backup|*.*|REMOVESELF
FileKey4=%LocalAppData%\VirtualStore\ProgramData\install_clap|*.*|REMOVESELF
[CyberLink Media Cache *]
LangSecRef=3023
Detect=HKCU\Software\CyberLink
Default=False
FileKey1=%AppData%\CyberLink\MediaCache|*.*|RECURSE
RegKey1=HKCU\Software\CyberLink\DSSharedMediaInfo\SharedInfoCache
RegKey2=HKCU\Software\CyberLink\MediaCache\Data4
RegKey3=HKCU\Software\CyberLink\MediaCache\Thumbnail4
RegKey4=HKCU\Software\CyberLink\MediaCache5\Data5
RegKey5=HKCU\Software\CyberLink\MediaCache5\Thumbnail5
[CyberLink PhotoDirector *]
LangSecRef=3023
Detect1=HKCU\Software\CyberLink\PhotoDirector3
Detect2=HKLM\Software\CyberLink\PhotoDirector4
Detect3=HKLM\Software\CyberLink\PhotoDirector5
Detect4=HKLM\Software\CyberLink\PhotoDirector6
Detect5=HKLM\Software\CyberLink\PhotoDirector7
Detect6=HKLM\Software\CyberLink\PhotoDirector8
Detect7=HKLM\Software\CyberLink\PhotoDirector9
Detect8=HKLM\Software\CyberLink\PhotoDirector10
Default=False
FileKey1=%Pictures%\PhotoDirector\*\*|*.*|RECURSE
ExcludeKey1=PATH|%Pictures%\PhotoDirector\*\*\|*.phd
[CyberLink Power2Go *]
LangSecRef=3023
Detect1=HKCU\Software\CyberLink\Power2Go9\9.0
Detect2=HKCU\Software\CyberLink\Power2Go10\10.0
Detect3=HKCU\Software\CyberLink\Power2Go11\11.0
Detect4=HKCU\Software\CyberLink\Power2Go12\12.0
Default=False
FileKey1=%Documents%\PDRMUSIC.TMP|*.*|REMOVESELF
FileKey2=%LocalAppData%\Cyberlink\Power2Go*|DLDB.db
FileKey3=%Music%|*.tmp
FileKey4=%Pictures%|*.tmp
FileKey5=%ProgramFiles%\Cyberlink\Power2Go*|*.tmp
FileKey6=%ProgramFiles%\Cyberlink\Power2Go*|Thumbs.db|RECURSE
FileKey7=%Public%\Documents\Cyberlink\Power2Go*|MP3Cache.log
RegKey1=HKCU\Software\CyberLink\LabelPrint\Recent File List
RegKey2=HKCU\Software\CyberLink\Power2Go9\9.0|CDRippingPath
RegKey3=HKCU\Software\CyberLink\Power2Go9\9.0|CUEName
RegKey4=HKCU\Software\CyberLink\Power2Go9\9.0|CUEPath
RegKey5=HKCU\Software\CyberLink\Power2Go9\9.0|DestFolder
RegKey6=HKCU\Software\CyberLink\Power2Go9\9.0|DVDFolderPath
RegKey7=HKCU\Software\CyberLink\Power2Go9\9.0|ImagePath
RegKey8=HKCU\Software\CyberLink\Power2Go9\9.0|LastBrowsePath
RegKey9=HKCU\Software\CyberLink\Power2Go9\9.0|LastSaveProjPath
RegKey10=HKCU\Software\CyberLink\Power2Go9\9.0|MonitorPaths
RegKey11=HKCU\Software\CyberLink\Power2Go9\9.0|OpenPrjFilePath
RegKey12=HKCU\Software\CyberLink\Power2Go9\9.0|SelectedFolderPath
RegKey13=HKCU\Software\CyberLink\Power2Go9\9.0\MediaObj\MediaCache5\Data5
RegKey14=HKCU\Software\CyberLink\Power2Go9\9.0\MediaObj\MediaCache5\Thumbnail5
RegKey15=HKCU\Software\CyberLink\Power2Go10\10.0|CDRippingPath
RegKey16=HKCU\Software\CyberLink\Power2Go10\10.0|CUEName
RegKey17=HKCU\Software\CyberLink\Power2Go10\10.0|CUEPath
RegKey18=HKCU\Software\CyberLink\Power2Go10\10.0|DestFolder
RegKey19=HKCU\Software\CyberLink\Power2Go10\10.0|DVDFolderPath
RegKey20=HKCU\Software\CyberLink\Power2Go10\10.0|ImagePath
RegKey21=HKCU\Software\CyberLink\Power2Go10\10.0|LastBrowsePath
RegKey22=HKCU\Software\CyberLink\Power2Go10\10.0|LastSaveProjPath
RegKey23=HKCU\Software\CyberLink\Power2Go10\10.0|MonitorPaths
RegKey24=HKCU\Software\CyberLink\Power2Go10\10.0|OpenPrjFilePath
RegKey25=HKCU\Software\CyberLink\Power2Go10\10.0|SelectedFolderPath
RegKey26=HKCU\Software\CyberLink\Power2Go10\10.0\MediaObj\MediaCache5\Data5
RegKey27=HKCU\Software\CyberLink\Power2Go10\10.0\MediaObj\MediaCache5\Thumbnail5
RegKey28=HKCU\Software\CyberLink\Power2Go11\11.0|CDRippingPath
RegKey29=HKCU\Software\CyberLink\Power2Go11\11.0|CUEName
RegKey30=HKCU\Software\CyberLink\Power2Go11\11.0|CUEPath
RegKey31=HKCU\Software\CyberLink\Power2Go11\11.0|DestFolder
RegKey32=HKCU\Software\CyberLink\Power2Go11\11.0|DVDFolderPath
RegKey33=HKCU\Software\CyberLink\Power2Go11\11.0|ImagePath
RegKey34=HKCU\Software\CyberLink\Power2Go11\11.0|LastBrowsePath
RegKey35=HKCU\Software\CyberLink\Power2Go11\11.0|LastSaveProjPath
RegKey36=HKCU\Software\CyberLink\Power2Go11\11.0|MonitorPaths
RegKey37=HKCU\Software\CyberLink\Power2Go11\11.0|OpenPrjFilePath
RegKey38=HKCU\Software\CyberLink\Power2Go11\11.0|SelectedFolderPath
RegKey39=HKCU\Software\CyberLink\Power2Go11\11.0\MediaObj\MediaCache5\Data5
RegKey40=HKCU\Software\CyberLink\Power2Go11\11.0\MediaObj\MediaCache5\Thumbnail5
RegKey41=HKCU\Software\CyberLink\Power2Go12\12.0|CDRippingPath
RegKey42=HKCU\Software\CyberLink\Power2Go12\12.0|CUEName
RegKey43=HKCU\Software\CyberLink\Power2Go12\12.0|CUEPath
RegKey44=HKCU\Software\CyberLink\Power2Go12\12.0|DestFolder
RegKey45=HKCU\Software\CyberLink\Power2Go12\12.0|DVDFolderPath
RegKey46=HKCU\Software\CyberLink\Power2Go12\12.0|ImagePath
RegKey47=HKCU\Software\CyberLink\Power2Go12\12.0|LastBrowsePath
RegKey48=HKCU\Software\CyberLink\Power2Go12\12.0|LastSaveProjPath
RegKey49=HKCU\Software\CyberLink\Power2Go12\12.0|MonitorPaths
RegKey50=HKCU\Software\CyberLink\Power2Go12\12.0|OpenPrjFilePath
RegKey51=HKCU\Software\CyberLink\Power2Go12\12.0|SelectedFolderPath
RegKey52=HKCU\Software\CyberLink\Power2Go12\12.0\MediaObj\MediaCache5\Data5
RegKey53=HKCU\Software\CyberLink\Power2Go12\12.0\MediaObj\MediaCache5\Thumbnail5
RegKey54=HKCU\Software\CyberLink\WaveEditor\2.0|ImportDir
RegKey55=HKCU\Software\CyberLink\WaveEditor\2.0|TempFileDir
RegKey56=HKCU\Software\CyberLink\WaveEditor\2.0|WorkDir
[Cyberlink PowerCinema *]
LangSecRef=3023
Detect=HKCU\Software\Cyberlink\PowerCinema
DetectFile=%LocalAppData%\PowerCinema
Default=False
FileKey1=%LocalAppData%\PowerCinema|trace.log;trace.txt
[CyberLink PowerDirector *]
LangSecRef=3023
Detect1=HKCU\Software\CyberLink\PowerDirector10
Detect2=HKCU\Software\CyberLink\PowerDirector11
Detect3=HKCU\Software\CyberLink\PowerDirector12
Detect4=HKCU\Software\CyberLink\PowerDirector13
Detect5=HKCU\Software\CyberLink\PowerDirector14
Detect6=HKCU\Software\CyberLink\PowerDirector15
Detect7=HKCU\Software\CyberLink\PowerDirector16
Detect8=HKCU\Software\CyberLink\PowerDirector17
Default=False
FileKey1=%AppData%\Cyberlink\PowerDirector\*|Recentfiles.ini
FileKey2=%AppData%\CyberLink\PowerDirector\*\AutoSave|*.*|RECURSE
FileKey3=%AppData%\CyberLink\PowerDirector\*\photoTmp|*.*|RECURSE
FileKey4=%AppData%\Cyberlink\PowerDirector\*\WaveForms|*.*|RECURSE
FileKey5=%Documents%\CyberLink\PowerDirector\*|Snapshot(*).jpg
FileKey6=%Documents%\CyberLink\PowerDirector\*\MyTitles|*.*|RECURSE
FileKey7=%Documents%\Cyberlink\PowerDirector\*\PDRMUSIC.TMP|*.*|REMOVESELF
FileKey8=%Documents%\Cyberlink\PowerDirector\*\PP.TWOPASS|*.*|REMOVESELF
FileKey9=%Documents%\CyberLink\PowerDirector\*\Preview Cache Files|*.*
FileKey10=%Documents%\CyberLink\PowerDirector\*\ShadowEditFiles|*.MPG
FileKey11=%Documents%\CyberLink\PowerDirector\*\SplitterIndex|*.maidx
RegKey1=HKCU\Software\CyberLink\Hanuman
RegKey2=HKCU\Software\CyberLink\PowerDirector10\MediaObj\MediaCache5\Data5
RegKey3=HKCU\Software\CyberLink\PowerDirector10\MediaObj\MediaCache5\Thumbnail5
RegKey4=HKCU\Software\CyberLink\PowerDirector11\MediaObj\MediaCache5\Data5
RegKey5=HKCU\Software\CyberLink\PowerDirector11\MediaObj\MediaCache5\Thumbnail5
RegKey6=HKCU\Software\CyberLink\PowerDirector12\MediaObj\MediaCache5\Data5
RegKey7=HKCU\Software\CyberLink\PowerDirector12\MediaObj\MediaCache5\Thumbnail5
RegKey8=HKCU\Software\CyberLink\PowerDirector13\MediaObj\MediaCache5\Data5
RegKey9=HKCU\Software\CyberLink\PowerDirector13\MediaObj\MediaCache5\Thumbnail5
RegKey10=HKCU\Software\CyberLink\PowerDirector14\MediaObj\MediaCache5\Data5
RegKey11=HKCU\Software\CyberLink\PowerDirector14\MediaObj\MediaCache5\Thumbnail5
RegKey12=HKCU\Software\CyberLink\PowerDirector15\MediaObj\MediaCache5\Data5
RegKey13=HKCU\Software\CyberLink\PowerDirector15\MediaObj\MediaCache5\Thumbnail5
RegKey14=HKCU\Software\CyberLink\PowerDirector16\MediaObj\MediaCache5\Data5
RegKey15=HKCU\Software\CyberLink\PowerDirector16\MediaObj\MediaCache5\Thumbnail5
RegKey16=HKCU\Software\CyberLink\PowerDirector17\MediaObj\MediaCache5\Data5
RegKey17=HKCU\Software\CyberLink\PowerDirector17\MediaObj\MediaCache5\Thumbnail5
RegKey18=HKCU\Software\CyberLink\PowerDirector17\OldCacheFolder
[CyberLink PowerDVD *]
LangSecRef=3023
Detect1=HKCU\Software\CyberLink\PowerDVD15
Detect2=HKCU\Software\CyberLink\PowerDVD16
Detect3=HKCU\Software\CyberLink\PowerDVD17
Detect4=HKCU\Software\CyberLink\PowerDVD18
Default=False
FileKey1=%CommonAppData%\Cyberlink\Evoparser|*.xml
FileKey2=%LocalAppData%\Cyberlink\DigitalHome|*.log|RECURSE
FileKey3=%LocalAppData%\Cyberlink\PowerDVD*|*.log|RECURSE
FileKey4=%LocalAppData%\Cyberlink\PowerDVD*\cache*|*.*|RECURSE
FileKey5=%LocalAppData%\Cyberlink\PowerDVD*\CL_DMP_Browser|*.*|RECURSE
RegKey1=HKCU\Software\CyberLink\PowerDVD15\CLMPSvc\MediaObj\MediaCache5\Data5
RegKey2=HKCU\Software\CyberLink\PowerDVD15\CLMPSvc\MediaObj\MediaCache5\ProgramInfo
RegKey3=HKCU\Software\CyberLink\PowerDVD15\CLMPSvc\MediaObj\MediaCache5\Thumbnail5
RegKey4=HKCU\Software\CyberLink\PowerDVD16\CLMPSvc\MediaObj\MediaCache5\Data5
RegKey5=HKCU\Software\CyberLink\PowerDVD16\CLMPSvc\MediaObj\MediaCache5\ProgramInfo
RegKey6=HKCU\Software\CyberLink\PowerDVD16\CLMPSvc\MediaObj\MediaCache5\Thumbnail5
RegKey7=HKCU\Software\CyberLink\PowerDVD17\CLMPSvc\MediaObj\MediaCache5\Data5
RegKey8=HKCU\Software\CyberLink\PowerDVD17\CLMPSvc\MediaObj\MediaCache5\ProgramInfo
RegKey9=HKCU\Software\CyberLink\PowerDVD17\CLMPSvc\MediaObj\MediaCache5\Thumbnail5
RegKey10=HKCU\Software\CyberLink\PowerDVD18\CLMPSvc\MediaObj\MediaCache5\Data5
RegKey11=HKCU\Software\CyberLink\PowerDVD18\CLMPSvc\MediaObj\MediaCache5\ProgramInfo
RegKey12=HKCU\Software\CyberLink\PowerDVD18\CLMPSvc\MediaObj\MediaCache5\Thumbnail5
[CyberLink YouCam *]
LangSecRef=3023
Detect=HKCU\Software\CyberLink\YouCam
Default=False
FileKey1=%Documents%\YouCam|*.tmp
[CzDC *]
LangSecRef=3022
DetectFile=%AppData%\CzDC
Default=False
FileKey1=%AppData%\CzDC|*.bak|RECURSE
[Daemon Tools *]
LangSecRef=3024
Detect1=HKCU\Software\Disc Soft
Detect2=HKCU\Software\DT Soft
Detect3=HKLM\Software\Disc Soft
Detect4=HKLM\Software\DT Soft
Default=False
FileKey1=%AppData%\DAEMON Tools*|ImgList.dat
FileKey2=%AppData%\DAEMON Tools*\*Cache|*.*|RECURSE
RegKey1=HKCU\Software\Disc Soft\DAEMON Tools Pro\GuiNamespace|MountFolder
RegKey2=HKCU\Software\DT Soft\DAEMON Tools Pro\GuiNamespace|MountFolder
[Dakota AG *]
LangSecRef=3021
DetectFile=%SystemDrive%\dakotaag
Default=False
FileKey1=%SystemDrive%\dakotaag|*.log|RECURSE
[DAMN Hash Calculator *]
LangSecRef=3024
Detect=HKCU\Software\DAMN\Hash Calculator
Default=False
RegKey1=HKCU\Software\DAMN\Hash Calculator\Settings|LastDir
[DAMN NFO Viewer *]
LangSecRef=3024
Detect=HKCU\Software\DAMN\DAMN NFO Viewer
Default=False
RegKey1=HKCU\Software\DAMN\DAMN NFO Viewer|WorkingDirectory
RegKey2=HKCU\Software\DAMN\DAMN NFO Viewer\Recently Viewed Files
[Damned *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\251170
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Damned|*.log|RECURSE
FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Damned|*.log|RECURSE
[Dangerous Waters *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\1600
DetectFile=%ProgramFiles%\Sonalysts Combat Simulations\Dangerous Waters
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Sonalysts Combat Simulations\Dangerous Waters|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Dangerous Waters|*.log
FileKey3=%ProgramFiles%\Sonalysts Combat Simulations\Dangerous Waters|*.log
FileKey4=%ProgramFiles%\Steam\SteamApps\Common\Dangerous Waters|*.log
[DARK *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\225360
Default=False
FileKey1=%AppData%\Kalypso Media\Dark|log.txt
[Dark Blood Online *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\267790
Default=False
FileKey1=%AppData%\DarkBlood ServiceST|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Dark Blood\logs|*.*|RECURSE
FileKey3=%ProgramFiles%\Steam\SteamApps\Common\Dark Blood\logs|*.*|RECURSE
[Darkspore *]
Section=Games
DetectFile=%ProgramFiles%\Origin Games\Darkspore
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Darkspore|*.log|RECURSE
FileKey2=%ProgramFiles%\Origin Games\Darkspore|*.log|RECURSE
[Dashlane *]
LangSecRef=3022
DetectFile=%AppData%\Dashlane
Default=False
FileKey1=%AppData%\Dashlane\*\background_cache|*.*|RECURSE
[DataTron 7 *]
LangSecRef=3021
DetectFile=%ProgramFiles%\DataTron7
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\DataTron7|*.GID;*.BAK
FileKey2=%ProgramFiles%\DataTron7|*.GID;*.BAK
[Daum PotPlayer *]
LangSecRef=3024
DetectFile=%ProgramFiles%\PotPlayer
Default=False
FileKey1=%LocalAppData%\Daum\PotPlayer\Log|*.xml
[David FX Basic *]
LangSecRef=3024
Detect=HKCU\Software\Tobit
Default=False
FileKey1=%SystemDrive%\David\Apps\Dvgrab\Code|*.chk
FileKey2=%SystemDrive%\David\Apps\Postman\Code|*.chk
FileKey3=%SystemDrive%\David\Archive\USER\*\temp|*.*
FileKey4=%SystemDrive%\David\Code|*.old;*.chk;*.log
FileKey5=%SystemDrive%\David\Tld\COMMON|*DAVID.LOG
FileKey6=%SystemDrive%\David\Tld\Port\Extra|*.chk
[DayZ *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\221100
Default=False
FileKey1=%LocalAppData%\DayZ|DayZ.mdmp;DayZ.bidmp
[DBFView *]
LangSecRef=3021
Detect=HKCU\Software\DBFView
Default=False
RegKey1=HKCU\Software\DBFView\DBFView\Recent File List
[DC Universe Online *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\24200
Default=False
FileKey1=%Documents%\My Games\DC Universe Online\Logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\DC Universe Online|.downloadInfo.txt;.downloadStats.txt
FileKey3=%ProgramFiles%\Steam\SteamApps\Common\DC Universe Online|.downloadInfo.txt;.downloadStats.txt
[Dead Island *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\91310
Default=False
FileKey1=%Documents%\DeadIsland\out\logs|*.*
[Dear Esther *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\203810
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\dear esther\dearesther|*.tmp
FileKey2=%ProgramFiles%\Steam\Steamapps\common\dear esther\dearesther|*.tmp
FileKey3=%ProgramFiles%\Steam\Steamapps\common\dear esther\dearesther\resource|*.icns
[Death to Spies: Moment of Truth *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\34410
Default=False
FileKey1=%Documents%\My Games\Smersh_MT\Cache|*.*
[Death Track: Resurrection *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\7840
Default=False
FileKey1=%Documents%\Skyfallen Entertaiment\DeathTrack\Logs|*.*
[Debenu *]
LangSecRef=3021
Detect=HKCU\Software\Debenu
Default=False
FileKey1=%CommonAppData%\Debenu\PDF Tools\Reports\App Log|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Debenu\PDF Tools\Reports\App Log|*.*
RegKey1=HKCU\Software\Debenu\Debenu PDF Maximus 2\MaximusViewerRecentDocs
RegKey2=HKCU\Software\Debenu\Debenu PDF Maximus 2\MaximusViewerRecentFolders
[DeepBurner *]
LangSecRef=3024
Detect=HKCU\Software\Astonsoft\DeepBurner
Default=False
FileKey1=%AppData%\DeepBurner|DeepBurner.log
[Defense Grid: The Awakening *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\18500
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\defensegridtheawakening\Shaders\Generated|*.cache
FileKey2=%ProgramFiles%\Steam\steamapps\common\defensegridtheawakening\Shaders\Generated|*.cache
[Defraggler *]
LangSecRef=3024
Detect=HKCU\Software\Piriform\Defraggler
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Defraggler|*.dmp;*statistics*;*.log;Defraggler*.txt
FileKey2=%ProgramFiles%\Defraggler|*.dmp;*statistics*;*.log;Defraggler*.txt
FileKey3=%UserProfile%|Defraggler*.txt
[Delfix *]
LangSecRef=3024
DetectFile=%SystemDrive%\DelFix.txt
Default=False
FileKey1=%SystemDrive%|DelFix.txt
[Dell Installation Files *]
LangSecRef=3024
Detect1=HKCU\Software\Dell
Detect2=HKLM\Software\Dell
Default=False
Warning=This will delete your Dell installation files.
FileKey1=%SystemDrive%\dell|*.*|REMOVESELF
[Dell Logs *]
LangSecRef=3024
Detect1=HKLM\Software\Dell\MUP
Detect2=HKLM\Software\Dell\UpdateService
Detect3=HKLM\Software\PC-Doctor
DetectFile1=%AppData%\Creative\DELL Webcam Center
DetectFile2=%CommonAppData%\Dell
DetectFile3=%LocalAppData%\Dell
DetectFile4=%LocalAppData%\SupportSoft\DellSupportCenter
DetectFile5=%ProgramFiles%\Dell*
Default=False
FileKey1=%AppData%\Creative\DELL Webcam Center|MO_Log.txt
FileKey2=%AppData%\PCDr\*\Logs|*.*
FileKey3=%CommonAppData%\Dell\*\Log|*.*
FileKey4=%CommonAppData%\Dell\*\Logs|*.*
FileKey5=%CommonAppData%\Dell\Drivers\*|*.tmp
FileKey6=%CommonAppData%\Dell\Update|*.txt
FileKey7=%CommonAppData%\Dell\UpdateService\Clients\Update|*.log
FileKey8=%CommonAppData%\PCDr\*\Cache|*.xml
FileKey9=%CommonAppData%\PCDr\*\Cache\archives|*.*|RECURSE
FileKey10=%CommonAppData%\PCDr\*\Cache\BUMA|*.*
FileKey11=%CommonAppData%\PCDr\*\Cache\DriverScan|*.*
FileKey12=%CommonAppData%\PCDr\*\Logs|*.log
FileKey13=%LocalAppData%\Dell\*\Log|*.*
FileKey14=%LocalAppData%\SupportSoft\DellSupportCenter\*\state\logs|*.*
FileKey15=%LocalAppData%\VirtualStore\Program Files*\Dell*|*.log|RECURSE
FileKey16=%LocalAppData%\VirtualStore\ProgramData\Dell\*\Log|*.*
FileKey17=%ProgramFiles%\Dell*|*.log|RECURSE
[Dell PC Doctor Dumps *]
LangSecRef=3024
DetectFile=%CommonAppData%\PCDr
Default=False
FileKey1=%CommonAppData%\PCDr|*.dmp|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\PCDr|*.dmp|RECURSE
[Dependency Walker *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Dependency Walker
Default=False
RegKey1=HKCU\Software\Microsoft\Dependency Walker\Recent File List
[Deponia *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\214340
DetectFile=%LocalAppData%\Daedalic Entertainment\Deponia
Default=False
FileKey1=%LocalAppData%\Daedalic Entertainment\Deponia|*.log
[Desura Game Cache *]
Section=Games
Detect=HKLM\Software\Desura
DetectFile=%ProgramFiles%\Desura
Default=False
FileKey1=%CommonAppData%\Desura\DesuraApp\Cache|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Desura\Cache\games|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Desura\DesuraApp\Cache|*.*|RECURSE
FileKey4=%ProgramFiles%\Desura\Cache\games|*.*|RECURSE
[Desura Game Installation Tools *]
Section=Games
Detect=HKLM\Software\Desura
DetectFile=%ProgramFiles%\Desura
Default=False
Warning=Don't use this if you have limited bandwidth as they will be re-downloaded on next game installation.
FileKey1=%CommonAppData%\Desura\DesuraApp\tools|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Desura\DesuraApp\tools|*.*|RECURSE
ExcludeKey1=PATH|%CommonAppData%\Desura\DesuraApp\tools\installcheck\|*.*
[Desura Logs *]
Section=Games
Detect=HKLM\Software\Desura
DetectFile=%ProgramFiles%\Desura
Default=False
FileKey1=%CommonAppData%\Desura\DesuraApp|update_log.txt
FileKey2=%CommonAppData%\Desura\DesuraApp\dumps|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Desura|*.log
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Desura\DesuraApp|update_log.txt
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Desura\DesuraApp\dumps|*.*
FileKey6=%ProgramFiles%\Desura|*.log
[Desura Update Backups *]
Section=Games
Detect=HKLM\Software\Desura
DetectFile=%ProgramFiles%\Desura
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Desura|*.exe_old
FileKey2=%ProgramFiles%\Desura|*.exe_old
[Desura Web Cache *]
Section=Games
Detect=HKLM\Software\Desura
DetectFile=%ProgramFiles%\Desura
Default=False
FileKey1=%CommonAppData%\Desura\DesuraApp|webcore_cache.sqlite
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Desura\DesuraApp|webcore_cache.sqlite
[Deus Ex *]
Section=Games
DetectFile=%SystemDrive%\DeusEx\System
Default=False
FileKey1=%SystemDrive%\DeusEx\System|DeusEx.log;Detected.log
[Device Icon Downloads *]
LangSecRef=3025
DetectFile=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads
Default=False
FileKey1=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads|*.tmp
[Device Manager Cache *]
DetectOS=6.0|
LangSecRef=3025
Default=False
Warning=This clears cached drivers of connected devices. As soon as you connect a new device, this file regenerates.
FileKey1=%WinDir%\System32\DriverStore|INFCACHE.1
[Device Manager Cache XP *]
DetectOS=|5.1
LangSecRef=3025
Default=False
Warning=This clears cached drivers of connected devices. As soon as you connect a new device, this file regenerates.
FileKey1=%WinDir%\inf|INFCACHE.1
[DeviceDoctor *]
LangSecRef=3024
DetectFile=%AppData%\DeviceDoctorSoftware\DeviceDoctor
Default=False
FileKey1=%AppData%\DeviceDoctorSoftware\DeviceDoctor\Logs|*.*
[Devolo Cockpit *]
LangSecRef=3024
Detect=HKLM\Software\devolo\dLAN
Default=False
FileKey1=%ProgramFiles%\devolo\dlan|dlanhistory.*txt;dlanstats.*xml;support.html;support.zip
FileKey2=%ProgramFiles%\devolo\dlan\updates|*.*|RECURSE
[Devolutions Remote Desktop Manager *]
LangSecRef=3021
DetectFile=%AppData%\Devolutions\RemoteDesktopManager
Default=False
FileKey1=%AppData%\Devolutions\RemoteDesktopManager|*.log;*.log.db
FileKey2=%LocalAppData%\Devolutions\RemoteDesktopManager|*.log;*.log.db
[Dexpot *]
LangSecRef=3024
Detect=HKCU\Software\Dexpot
Default=False
FileKey1=%AppData%\Dexpot|*.log
[Diablo 2 *]
Section=Games
Detect=HKCU\Software\Blizzard Entertainment\Diablo II
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Diablo II|bnupdate.log;BnetLog.txt;D*.txt
FileKey2=%ProgramFiles%\Diablo II|bnupdate.log;BnetLog.txt;D*.txt
FileKey3=%SystemDrive%\Diablo II|bnupdate.log;BnetLog.txt;D*.txt
[Diablo III *]
Section=Games
Detect=HKCU\Software\Blizzard Entertainment\D3
Default=False
FileKey1=%CommonAppData%\Battle.net\Setup\diablo3_engb\Log|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Diablo III*\Logs|*.*
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Battle.net\Setup\diablo3_engb\Log|*.*
FileKey4=%ProgramFiles%\Diablo III*\Logs|*.*
[Digi Net Mobile *]
LangSecRef=3021
DetectFile=%CommonAppData%\Digi Net Mobile
Default=False
FileKey1=%CommonAppData%\Digi Net Mobile\log|*.log;*.txt
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Digi Net Mobile\log|*.log;*.txt
[Digital Janitor *]
LangSecRef=3024
Detect=HKCU\Software\Davide Vitelaru\Digital Janitor
Default=False
FileKey1=%AppData%\Digital Janitor|ToSortHistory
[Digsby *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Digsby
Default=False
FileKey1=%LocalAppData%\Digsby\Logs|*.*|RECURSE
FileKey2=%LocalAppData%\Digsby\Temp|*.*|RECURSE
[Digsby Cache *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Digsby
Default=False
FileKey1=%LocalAppData%\Digsby\Cache|*.*|RECURSE
[Digsby Chat Logs *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Digsby
Default=False
FileKey1=%Documents%\Digsby Logs|*.*|RECURSE
[Direct3D Shader Cache *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%LocalAppData%\D3DSCache|*.*|RECURSE
[Directory Opus *]
LangSecRef=3024
Detect=HKLM\Software\GPSoftware\Directory Opus
Default=False
FileKey1=%AppData%\GPSoftware\Directory Opus\Icon Cache Roaming|*.*|RECURSE
FileKey2=%LocalAppData%\GPSoftware\Directory Opus\Thumbnail Cache|*.*|RECURSE
[Discord *]
LangSecRef=3022
Detect1=HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Discord
Detect2=HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DiscordCanary
Detect3=HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DiscordPTB
Default=False
FileKey1=%AppData%\discord*|modules.log;*.tmp
FileKey2=%AppData%\discord*\*Cache|*.*|REMOVESELF
FileKey3=%LocalAppData%\Discord*|*.log
FileKey4=%LocalAppData%\Discord*\packages\SquirrelTemp|*.*|REMOVESELF
FileKey5=%LocalAppData%\SquirrelTemp|*.*|REMOVESELF
[Dishonored *]
Section=Games
Detect=HKCU\Software\Arkane\Dishonored
DetectFile=%Documents%\My Games\Dishonored
Default=False
FileKey1=%Documents%\My Games\Dishonored\DishonoredGame\Logs|*.*
[Disk Space Fan *]
LangSecRef=3024
Detect=HKCU\Software\Cookapp\DSF4
Default=False
FileKey1=%AppData%\DiskSpaceFan|log.txt;history_C.sqlite
[DiskBoss *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DiskBoss Ultimate
Default=False
FileKey1=%LocalAppData%\DiskBoss Ultimate\data\reports|*.*|REMOVESELF
[DiskMax *]
LangSecRef=3024
Detect=HKCU\Software\KoshyJohn.com
Default=False
FileKey1=%AppData%\KoshyJohn.com\DiskMax|DiskMax Log.txt
[DisplayFusion *]
LangSecRef=3024
Detect=HKCU\Software\Binary Fortress Software\DisplayFusion
Default=False
FileKey1=%AppData%\DisplayFusion|DisplayFusionSetup.log;DisplayFusionSetup.exe;DisplayFusion.log;DebugInfo.*
[DivX *]
LangSecRef=3023
Detect=HKCU\Software\DivX
Default=False
FileKey1=%AppData%\DivX|Font Cache.|RECURSE
FileKey2=%CommonAppData%\DivX|*.log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\DivX|*.log|RECURSE
FileKey4=%Video%\DivX Movies|*.*|RECURSE
RegKey1=HKCU\Software\DivX\Settings\Converter|lastBrowseDir
RegKey2=HKCU\Software\DivX\Settings\Converter|outputDir
RegKey3=HKCU\Software\DivX\Settings\Player\PlayerState|LastOpenFileLocation
RegKey4=HKCU\Software\DivX\Settings\TransferWizard|LastBrwosedDir
RegKey5=HKCU\Software\DivXNetworks\DivX Player|file
RegKey6=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry1
RegKey7=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry2
RegKey8=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry3
RegKey9=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry4
RegKey10=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry5
RegKey11=HKCU\Software\DivXNetworks\DivXBrowserPlugin|cacheEntry6
[DLExpert *]
LangSecRef=3021
Detect=HKCU\Software\Ying3\DLExpert
Default=False
RegKey1=HKCU\Software\Ying3\DLExpert|ftp
RegKey2=HKCU\Software\Ying3\DLExpert|http
RegKey3=HKCU\Software\Ying3\DLExpert\MAIN|ALLFILE
RegKey4=HKCU\Software\Ying3\DLExpert\MAIN|GOOD
RegKey5=HKCU\Software\Ying3\DLExpert\MAIN|GOODURL
RegKey6=HKCU\Software\Ying3\DLExpert\Recent File List
[DoctorWeb *]
LangSecRef=3024
DetectFile=%UserProfile%\DoctorWeb\Quarantine
Default=False
FileKey1=%UserProfile%\DoctorWeb\Quarantine|*.*|RECURSE
[Document Trace Remover *]
LangSecRef=3024
Detect=HKCU\Software\Smart PC Solutions\Document Trace Remover
Default=False
FileKey1=%AppData%\Smart PC Solutions\Smart Fast PC\Log|*.*
RegKey1=HKCU\Software\Smart PC Solutions\Document Trace Remover|LastFile
RegKey2=HKCU\Software\Smart PC Solutions\Document Trace Remover|LastFolder
[Dogpile Toolbar *]
LangSecRef=3022
Detect=HKCU\Software\Infospace\DogpileToolbar
Default=False
RegKey1=HKCU\Software\Infospace\DogpileToolbar\History|1-terms
[Dollar Dash *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\214320
Default=False
FileKey1=%Documents%\My Games\DollarDash\PKGame\Logs|*.*
[Dolphin Emulator *]
Section=Games
DetectFile=%Documents%\Dolphin Emulator
Default=False
FileKey1=%Documents%\Dolphin Emulator\Logs|*.*|RECURSE
[Don't Starve *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\219740
Default=False
FileKey1=%Documents%\Klei\DoNotStarve|log.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\dont_starve\bin|log.txt
FileKey3=%ProgramFiles%\Steam\steamapps\common\dont_starve\bin|log.txt
[Dooble Downloads *]
LangSecRef=3022
DetectFile=%SystemDrive%\Dooble
Default=False
FileKey1=%SystemDrive%\Dooble\*\.dooble|downloads.db
[Dooble Internet Traces *]
LangSecRef=3022
DetectFile=%SystemDrive%\Dooble
Default=False
FileKey1=%SystemDrive%\Dooble\*\.dooble|cookies.db;favicons.fb;history.db
FileKey2=%SystemDrive%\Dooble\*\.dooble\Cache|*.*|REMOVESELF
[DOOM *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\379720
Default=False
FileKey1=%LocalAppData%\id Software\DOOM\base\generated\temp|*.*
FileKey2=%UserProfile%\Saved Games\id Software\DOOM\base\generated\temp|*.*
[Download App *]
LangSecRef=3024
Detect=HKCU\Software\CBS Interactive\Download App
Default=False
FileKey1=%AppData%\CBS Interactive\Download App|*.log
FileKey2=%AppData%\CBS Interactive\Download App\Cache|*.*
[Download App Databases *]
LangSecRef=3024
Detect=HKCU\Software\CBS Interactive\Download App
Default=False
FileKey1=%AppData%\CBS Interactive\Download App\Data|*.db
[Download App Downloads *]
LangSecRef=3024
Detect=HKCU\Software\CBS Interactive\Download App
Default=False
FileKey1=%Documents%\Downloads\Download App|*.*
[Downloaded Installations *]
LangSecRef=3025
DetectFile=%LocalAppData%\Downloaded Installations
Default=False
FileKey1=%LocalAppData%\Downloaded Installations|*.*|REMOVESELF
[DownTango *]
LangSecRef=3022
DetectFile=%LocalAppData%\DownTango
Default=False
FileKey1=%LocalAppData%\DownTango|application.log
FileKey2=%LocalAppData%\DownTango\Logs|log.txt
[Dr. Despicables Dastardly Deeds *]
Section=Games
DetectFile=%AppData%\HitPoint Studios\DrD
Default=False
FileKey1=%AppData%\HitPoint Studios\DrD|logfile.txt
[Dr. Web CureIt! *]
LangSecRef=3024
DetectFile=%UserProfile%\Doctor Web
Default=False
FileKey1=%UserProfile%\Doctor Web|*.log
[DraftSight *]
LangSecRef=3021
Detect1=HKCU\Software\Dassault Systemes\DraftSight
Detect2=HKLM\Software\Dassualt Systemes\DraftSight
Default=False
FileKey1=%AppData%\DraftSight\*|history.txt;plot.log
FileKey2=%LocalAppData%\Dassault Systemes\DraftSight\cache|*.*|RECURSE
[Dragon Age: Origins *]
Section=Games
Detect1=HKCU\Software\BioWare\Dragon Age
Detect2=HKLM\Software\BioWare\Dragon Age
Default=False
FileKey1=%CommonAppData%\BioWare\Dragon Age\DA Updater\Logs|*.*
FileKey2=%Documents%\BioWare\Dragon Age\Logs|*.*
FileKey3=%LocalAppData%\VirtualStore\ProgramData\BioWare\Dragon Age\DA Updater\Logs|*.*
[Dreadnought *]
Section=Games
Detect=HKCU\Software\Grey Box\Dreadnought
Default=False
FileKey1=%LocalAppData%\DreadGame\Saved\Logs|*.log
[DriveImage XML *]
LangSecRef=3021
Detect=HKLM\Software\Runtime Software\DIXML
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Runtime Software\DriveImage XML|log.txt
FileKey2=%ProgramFiles%\Runtime Software\DriveImage XML|log.txt
[Driver Cleaner.NET *]
LangSecRef=3024
DetectFile=%ProgramFiles%\DriverCleanerDotNET\DriverCleanerDotNET.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\DriverCleanerDotNET\Backup|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\DriverCleanerDotNET\Log|*.*
FileKey3=%ProgramFiles%\DriverCleanerDotNET\Backup|*.*|RECURSE
FileKey4=%ProgramFiles%\DriverCleanerDotNET\Log|*.*
[Driver Fusion *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Driver Fusion\Logs
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Driver Fusion\Logs|*.*|RECURSE
FileKey2=%ProgramFiles%\Driver Fusion\Logs|*.*|RECURSE
[Driver Fusion Backup *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Driver Fusion\Backup
Default=False
Warning=This will delete your driver backups.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Driver Fusion\Backup|*.*|RECURSE
FileKey2=%ProgramFiles%\Driver Fusion\Backup|*.*|RECURSE
[Driver Installation Files *]
LangSecRef=3025
DetectFile=%SystemDrive%\Drivers
Default=False
FileKey1=%SystemDrive%\Drivers|*.*|REMOVESELF
[Driver Magician *]
LangSecRef=3021
Detect=HKCU\Software\Driver Magician
Default=False
FileKey1=%AppData%\Driver Magician|HiddenUpdate.txt
[Driver Reinstall Backup *]
LangSecRef=3025
DetectFile=%WinDir%\System32\ReinstallBackups
Default=False
FileKey1=%WinDir%\System32\ReinstallBackups|*.*|RECURSE
[Driver Updater *]
LangSecRef=3023
Detect=HKLM\Software\SuperEasy Software
Default=False
FileKey1=%AppData%\SuperEasy Software\Driver Updater|*.log
[DriverCure *]
LangSecRef=3024
Detect=HKCU\Software\ParetoLogic DriverCure
Default=False
FileKey1=%AppData%\DriverCure|LogFile.*
[DriverEasy Driver Backups *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Easeware\DriverEasy
Default=False
FileKey1=%Documents%\DriverEasy|*.*|RECURSE
[DriverEasy Driver Installation Files *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Easeware\DriverEasy
Default=False
FileKey1=%AppData%\Easeware\DriverEasy\drivers|*.*|RECURSE
[DriverGenius *]
LangSecRef=3024
Detect=HKLM\Software\Driver-Soft\DriverGenius
DetectFile=%ProgramFiles%\Driver-Soft\DriverGenius
Default=False
FileKey1=%CommonAppData%\DriverGenius|*.log
FileKey2=%LocalAppData%\DriverGenius|ScanLog.log
FileKey3=%LocalAppData%\VirtualStore\ProgramData\DriverGenius|*.log
[DriverMax *]
LangSecRef=3024
Detect=HKCU\Software\Innovative Solutions\DriverMax
Default=False
FileKey1=%LocalAppData%\Innovative Solutions\DriverMax\Agent|*.tmp;dmxlog.txt
FileKey2=%LocalAppData%\Innovative Solutions\DriverMax\Agent\Downloded Drivers|*.*
FileKey3=%LocalAppData%\Innovative Solutions\DriverMax\Agent\Uploads|*.*|RECURSE
FileKey4=%LocalAppData%\Innovative Solutions\DriverMax\Backup|*.*
FileKey5=%LocalAppData%\Innovative Solutions\DriverMax\LastScan|*.*
FileKey6=%LocalAppData%\Innovative Solutions\DriverMax\Temp*|*.*
FileKey7=%ProgramFiles%\Innovative Solutions\DriverMax|*.log
[DriverPack Solution *]
LangSecRef=3024
Detect=HKCU\Software\drpsu
Default=False
Warning=This will delete your bug report.
FileKey1=%AppData%\DRPSu\Logs|*.*
FileKey2=%AppData%\DRPSu\snapshots|*.*
FileKey3=%AppData%\DRPSu\temp|*.*
FileKey4=%Documents%\DRP-Log|*.*
FileKey5=%WinDir%\Logs\DRPLog|*.png;*.txt
FileKey6=%WinDir%\Logs\SysInfo|*.*
[DriverRadarPro *]
LangSecRef=3024
Detect=HKCU\Software\NoVirusThanks\DriverRadarPro
Default=False
RegKey1=HKCU\Software\NoVirusThanks\DriverRadarPro|edCopyDrvTo
RegKey2=HKCU\Software\NoVirusThanks\DriverRadarPro|edSaveLogsTo
[DriverRobot *]
LangSecRef=3024
Detect=HKCU\Software\Driver Robot
Default=False
FileKey1=%AppData%\Blitware\DriverRobot\Logs|*.*
[Drivers Installer Assistant *]
LangSecRef=3024
Detect=HKCU\Software\VB and VBA Program Settings\Drivers Installer Assistant
Default=False
FileKey1=%WinDir%\Logs\DIALog|*.txt
[DriverUpdate *]
LangSecRef=3024
DetectFile=%LocalAppData%\Slimware Utilities Inc\DriverUpdate
Default=False
FileKey1=%LocalAppData%\SlimWare Utilities Inc\DriverUpdate\Logs|*.*|RECURSE
[DriverUpdate Backups *]
LangSecRef=3024
DetectFile=%LocalAppData%\Slimware Utilities Inc\DriverUpdate
Default=False
FileKey1=%LocalAppData%\Slimware Utilities Inc\DriverUpdate\Backups|*.*
[DriverUpdate Downloads *]
LangSecRef=3024
DetectFile=%LocalAppData%\Slimware Utilities Inc\DriverUpdate
Default=False
FileKey1=%LocalAppData%\SlimWare Utilities Inc\DriverUpdate\Downloads|*.*|RECURSE
FileKey2=%LocalAppData%\SlimWare Utilities Inc\DriverUpdate\Images|*.*|RECURSE
[Dropbox *]
LangSecRef=3024
Detect=HKCU\Software\Dropbox
Default=False
FileKey1=%AppData%\DropBox|Filecache.db;SigStore.db
FileKey2=%AppData%\DropBox\Bin|*.log
FileKey3=%AppData%\Dropbox\installer|*.*|RECURSE
FileKey4=%AppData%\Dropbox\logs|*.*|RECURSE
FileKey5=%CommonAppData%\Dropbox\Update\Log|*.*
FileKey6=%LocalAppData%\Dropbox\Logs|*.*|RECURSE
FileKey7=%ProgramFiles%\Dropbox\Update\Download|*.*|REMOVESELF
[Dropbox Cache *]
LangSecRef=3024
Detect=HKCU\Software\Dropbox
Default=False
Warning=This will remove cached versions of modified and deleted files.
FileKey1=%AppData%\Dropbox\Cache|*.*|RECURSE
FileKey2=%Documents%\Dropbox\.dropbox.cache|*.*|RECURSE
FileKey3=%UserProfile%\Dropbox\.dropbox.cache|*.*|RECURSE
[DU meter *]
LangSecRef=3022
Detect=HKCU\Software\Hagel\DU Meter
Default=False
FileKey1=%CommonAppData%\Hagel Technologies\DU Meter|*.csv
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Hagel Technologies\DU Meter|*.csv
[DuckieTV *]
LangSecRef=3023
DetectFile=%AppData%\DuckieTV
Default=False
FileKey1=%AppData%\DuckieTV|*.log;*.txt
[Duke Nukem 3D *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\225140
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\Duke Nukem 3D\bin|stderr.txt;stdout.txt
FileKey2=%ProgramFiles%\Steam\SteamApps\common\Duke Nukem 3D\bin|stderr.txt;stdout.txt
[DUMo *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\DUMo
Default=False
FileKey1=%AppData%\KC Softwares\DUMo|*.log
[Dungeon Of The Endless *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\249050
Default=False
FileKey1=%Documents%\Dungeon of the Endless\Temporary Files|*.*
[Dungeons - The Dark Lord *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\200550
Default=False
FileKey1=%AppData%\Kalypso Media\Dungeons - The Dark Lord|log.txt
[Dup Detector *]
LangSecRef=3023
Detect=HKCU\Software\Prismatic Software\PhotoBatch
Default=False
RegKey1=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastBatFile
RegKey2=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastFold
RegKey3=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSecFold
RegKey4=HKCU\Software\Prismatic Software\PhotoBatch\Dups|LastSingleFold
[Duplicate Cleaner *]
LangSecRef=3024
DetectFile=%AppData%\DigitalVolcano
Default=False
FileKey1=%AppData%\DigitalVolcano\DuplicateCleaner|*.data
FileKey2=%Documents%|Duplicate Cleaner log.txt
[DVBDream *]
LangSecRef=3024
Detect=HKLM\Software\DVBDream
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\dvbdream|*.log;*.bak;*levellog*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\dvbdream\Logs|*.*
FileKey3=%ProgramFiles%\dvbdream|*.log;*.bak;*levellog*|RECURSE
FileKey4=%ProgramFiles%\dvbdream\Logs|*.*
FileKey5=%SystemDrive%\dvbdream|*.log;*.bak;*levellog*|RECURSE
FileKey6=%SystemDrive%\dvbdream\Logs|*.*
[DVBViewer *]
LangSecRef=3023
Detect=HKLM\Software\CM&V\DVBViewer
Default=False
FileKey1=%CommonAppData%\CMUV\DVBViewer*|*.bak;*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\CMUV\DVBViewer*|*.bak;*.log
[DVBViewer Setup Files *]
LangSecRef=3023
Detect=HKLM\Software\CM&V\DVBViewer
Default=False
Warning=This will prevent a modify installation. You have to download the installer to modify the installation.
FileKey1=%CommonAppData%\CMUV\DVBViewer\backup|*.*|REMOVESELF
FileKey2=%ProgramFiles%\DVBViewer\backup|*.*|REMOVESELF
FileKey3=%ProgramFiles%\DVBViewer\GraphPresets|*.fgp
FileKey4=%ProgramFiles%\DVBViewer\Remotes|*.*
FileKey5=%ProgramFiles%\DVBViewer\setup|*.*
FileKey6=%ProgramFiles%\DVBViewer\Transponders|*.*
[DVD-Cloner *]
LangSecRef=3023
Detect1=HKCU\Software\Dvd-cloner
Detect2=HKCU\Software\DVD-Cloner Gold
Detect3=HKCU\Software\iPod-Cloner
Default=False
FileKey1=%AppData%\DVD-Cloner*|*.log
FileKey2=%CommonAppData%\DVD-Cloner*|*.log
FileKey3=%Documents%|Smart.log;Smart_result.log
FileKey4=%LocalAppData%\VirtualStore\Program Files*\DVD-Cloner Platinum\*\readcache|*.*
FileKey5=%LocalAppData%\VirtualStore\Program Files*\DVD-Cloner*|*.log|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\DVD-Cloner*|*.log
FileKey7=%ProgramFiles%\DVD-Cloner Platinum\*\readcache|*.*
FileKey8=%ProgramFiles%\DVD-Cloner*|*.log|RECURSE
FileKey9=%SystemDrive%|dtdlog.txt
FileKey10=%WinDir%\system32|dvdtest10024.dat
[DVD-Ranger *]
LangSecRef=3021
Detect=HKLM\Software\DVD-Ranger
Default=False
FileKey1=%CommonAppData%\DVDRanger\DDF626ADdvdcss|*.*
FileKey2=%CommonAppData%\DVDRanger\Logs|*.*
FileKey3=%Documents%\DVDRanger\Screenshots|*.*|RECURSE
FileKey4=%Documents%\DVDRanger\Temp|*.*|REMOVESELF
FileKey5=%LocalAppData%\VirtualStore\ProgramData\DVDRanger\DDF626ADdvdcss|*.*
FileKey6=%LocalAppData%\VirtualStore\ProgramData\DVDRanger\Logs|*.*
FileKey7=%SystemDrive%\DVDRanger|*.*|REMOVESELF
[DVD Flick *]
LangSecRef=3023
DetectFile=%ProgramFiles%\DVD Flick\dvdflick.exe
Default=False
FileKey1=%AppData%\DVD Flick|dvdflick.log;report.txt
[DVD Shrink Analysis Results *]
LangSecRef=3023
Detect=HKCU\Software\DVD Shrink
Default=False
Warning=Each time you use this you'll have to agree to the DVD Shrink license.
FileKey1=%CommonAppData%\DVD Shrink|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\DVD Shrink|*.*
[dvdcss *]
LangSecRef=3023
DetectFile1=%AppData%\.dvdcss
DetectFile2=%AppData%\dvdcss
DetectFile3=%UserProfile%\.dvdcss
Default=False
FileKey1=%AppData%\.dvdcss|*.*|REMOVESELF
FileKey2=%AppData%\dvdcss|*.*|REMOVESELF
FileKey3=%UserProfile%\.dvdcss|*.*|REMOVESELF
[DVDFab *]
LangSecRef=3023
Detect1=HKCU\Software\DVDFab
Detect2=HKCU\Software\DVDFab Passkey
Detect3=HKCU\Software\FabPlayer
Default=False
FileKey1=%Documents%\DVDFab*|*.log
FileKey2=%Documents%\DVDFab*\Log|*.*|RECURSE
FileKey3=%Documents%\DVDFab*\SceneData|*.*|RECURSE
FileKey4=%Documents%\DVDFab*\Temp|*.*|RECURSE
FileKey5=%Documents%\PcSetup|*.*|RECURSE
RegKey1=HKCU\Software\FabPlayer|DefaultFile
[DVDSmith *]
LangSecRef=3023
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DVDSmith Movie Backup_is1
Default=False
FileKey1=%Documents%\dvdsmith|*.log
[DVDVideoSoft *]
LangSecRef=3023
Detect1=HKCU\Software\AppDataLow\Software\DVDVideoSoftTB
Detect2=HKCU\Software\DVDVideoSoft
Default=False
FileKey1=%AppData%\DVDVideoSoft\*\History|*.*|RECURSE
FileKey2=%AppData%\DVDVideoSoft\*Logs|*.*|RECURSE
FileKey3=%Documents%\DVDVideoSoft|*log.txt|RECURSE
FileKey4=%LocalAppData%\DVDVideoSoftTB\Logs|*.*|RECURSE
[DVDVideoSoft Backup *]
LangSecRef=3024
Detect=HKCU\Software\DVDVideoSoft
Default=False
FileKey1=%AppData%\DVDVideoSoft\Backup|*.*|RECURSE
[DVDx *]
LangSecRef=3023
Detect=HKCU\Software\DVDx
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\DVDx|*.tmp
FileKey2=%ProgramFiles%\DVDx|*.tmp
RegKey1=HKCU\Software\DVDx\LastDir
RegKey2=HKCU\Software\DVDx\LastOutput
[DxO Photo Suite *]
LangSecRef=3021
Detect1=HKCU\Software\DxO
Detect2=HKCU\Software\DxO Labs
Detect3=HKCU\Software\DxOLabs
Detect4=HKLM\Software\DxO
Detect5=HKLM\Software\DxO Labs
Detect6=HKLM\Software\DxOLabs
Default=False
FileKey1=%Documents%\DxO * crash*s|*.*
FileKey2=%Documents%\DxO * logs|*.*
FileKey3=%Documents%\DxO*\CrashReports|*.*|RECURSE
FileKey4=%Documents%\DxO*\log|*.*
FileKey5=%LocalAppData%\DxO*\DataCache|*.*|RECURSE
FileKey6=%LocalAppData%\DxO*\DxO*\*Cache|*.*|RECURSE
FileKey7=%LocalAppData%\DxO*\DxO*\CrashReports|*.*|RECURSE
FileKey8=%LocalAppData%\DxO*\DxO*\Logs|*.*
FileKey9=%LocalAppData%\DxO*\Logs|*.*
[Dyn Updater *]
LangSecRef=3022
Detect=HKCU\Software\Dyn\Dyn Updater
Default=False
FileKey1=%CommonAppData%\Dyn\Updater|*.log;*.msi
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Dyn\Updater|*.log;*.msi
[EA Core *]
Section=Games
Detect=HKCU\Software\EA Games\EA Core
Default=False
FileKey1=%CommonAppData%\EA Core\Cache|*.*|REMOVESELF
FileKey2=%CommonAppData%\EA Logs|*.*
FileKey3=%CommonAppData%\Electronic Arts\EA Core\logs|*.*
FileKey4=%LocalAppData%\EA Core\Cache|*.*|REMOVESELF
FileKey5=%LocalAppData%\VirtualStore\ProgramData\EA Core\Cache|*.*|REMOVESELF
FileKey6=%LocalAppData%\VirtualStore\ProgramData\EA Logs|*.*
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Electronic Arts\EA Core\logs|*.*
[EA Download Manager *]
Section=Games
Detect=HKLM\Software\Electronic Arts\EADM
Default=False
FileKey1=%LocalAppData%\Electronic Arts\EADMUI\Web Cache|*.*|RECURSE
[Earth 2160 *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\19000
Default=False
FileKey1=%Documents%\Earth 2160\FontsCache|*.*
[Earth Alerts Images *]
LangSecRef=3022
Detect=HKCU\Software\South Wind Technologies\Earth Alerts
Default=False
FileKey1=%AppData%\Earth Alerts\Images|*.*|RECURSE
[Earth Alerts Messages *]
LangSecRef=3022
Detect=HKCU\Software\South Wind Technologies\Earth Alerts
Default=False
FileKey1=%AppData%\Earth Alerts\Messages|*.*|RECURSE
[EaseUS Data Recovery Wizard *]
LangSecRef=3024
DetectFile=%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\EaseUS\EaseUS Data Recovery Wizard|*.log
FileKey2=%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard|*.log
ExcludeKey1=FILE|%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard\|install.log
[EaseUS MobiSaver *]
LangSecRef=3021
Detect=HKLM\Software\EASEUS\EASEUS IPhone Wizard
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\EaseUS\EaseUS MobiSaver\bin|CommDbg.txt;easeusue.log;PR.log
FileKey2=%ProgramFiles%\EaseUS\EaseUS MobiSaver\bin|CommDbg.txt;easeusue.log;PR.log
FileKey3=%SystemDrive%\EaseUS MobiSaver Temp Backup|*.*|RECURSE
[EaseUS MobiSaver for Android *]
LangSecRef=3021
Detect=HKLM\Software\EaseUS\Mobisaver for Android
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\EaseUS\EaseUS MobiSaver for Android\bin|CommDbg.txt;Eaolog;easeusue.log;mbs;PR.log
FileKey2=%ProgramFiles%\EaseUS\EaseUS MobiSaver for Android\bin|CommDbg.txt;Eaolog;easeusue.log;mbs;PR.log
FileKey3=%SystemDrive%\EaseUS MobiSaver for Android Temp Backup|*.*|RECURSE
[EaseUS Partition Master *]
LangSecRef=3024
Detect=HKCU\Software\EASEUS\EASEUS Partition Manager
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\EASEUS\EASEUS Partition Master*\bin|*.log
FileKey2=%ProgramFiles%\EASEUS\EASEUS Partition Master*\bin|*.log|RECURSE
[EaseUS ToDo Backup *]
LangSecRef=3024
Detect=HKCU\Software\EaseUS\EaseUS Todo Backup
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\EaseUS\Todo Backup\bin|easeus.log;TbLogsysClient.tblog
FileKey2=%ProgramFiles%\EaseUS\Todo Backup\bin|easeus.log;TbLogsysClient.tblog
[East-Tec Eraser *]
LangSecRef=3024
Detect=HKLM\Software\East-Tec\east-tec Eraser
Default=False
FileKey1=%CommonAppData%\East-Tec\east-tec Eraser\Updates|*.*|RECURSE
FileKey2=%ProgramFiles%\east-tec Eraser|except.log
[Easy CD-DA Extractor *]
LangSecRef=3024
Detect=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8
Default=False
RegKey1=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k8c
RegKey2=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k80
RegKey3=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k81
RegKey4=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k91
RegKey5=HKCU\Software\Poikosoft\Easy CD-DA Extractor 8|k92
[EasyAntiCheat *]
Section=Games
DetectFile=%AppData%\EasyAntiCheat
Default=False
FileKey1=%AppData%\EasyAntiCheat|*.log|REMOVESELF
[EasyGPS *]
LangSecRef=3024
Detect=HKCU\Software\TopoGrafix\EasyGPS
Default=False
FileKey1=%LocalAppData%\TopoGrafix\Error Logs|*.txt
RegKey1=HKCU\Software\TopoGrafix\EasyGPS\Error Log
RegKey2=HKCU\Software\TopoGrafix\EasyGPS\Recent File List
[eBay Toolbar *]
LangSecRef=3022
Detect=HKCU\Software\eBay\eBayToolbar
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\eBay\eBay Toolbar*|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\eBay\eBay Toolbar*\eBayhistory|*.*|RECURSE
FileKey3=%ProgramFiles%\eBay\eBay Toolbar*|*.log
FileKey4=%ProgramFiles%\eBay\eBay Toolbar*\eBayhistory|*.*|RECURSE
RegKey1=HKCU\Software\eBay\eBayToolbar\History
RegKey2=HKCU\Software\eBay\eBayToolbar\RecentSearches
[eBay TurboLister *]
LangSecRef=3021
Detect1=HKCU\Software\eBay\Turbo lister
Detect2=HKCU\Software\eBay\Turbo lister2
Default=False
FileKey1=%CommonAppData%\eBay\Turbo Lister*|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\eBay\Turbo Lister*|*.log|RECURSE
[EC XTRA Timer *]
LangSecRef=3021
DetectFile=%AppData%\The Toro Company
Default=False
FileKey1=%AppData%\The Toro Company|ECXTRAoutput.txt
[Edna & Harvey: Harvey's New Eyes *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\219910
DetectFile=%LocalAppData%\Daedalic Entertainment\Harvey
Default=False
FileKey1=%LocalAppData%\Daedalic Entertainment\Harvey|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\Edna and Harvey Harvey's New Eyes|stderr.txt
FileKey3=%ProgramFiles%\Steam\Steamapps\common\Edna and Harvey Harvey's New Eyes|stderr.txt
[Effective File Search *]
LangSecRef=3024
Detect=HKCU\Software\SOW\EFS
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\efs|cblist*.dat
FileKey2=%ProgramFiles%\efs|cblist*.dat
[Efficient Calendar *]
LangSecRef=3021
DetectFile=%AppData%\Efficient Calendar
Default=False
FileKey1=%AppData%\Efficient Calendar\MRUItems|*.*|RECURSE
[Elcomsoft Wireless Security Auditor *]
LangSecRef=3021
Detect=HKCU\Software\ElcomSoft\Elcomsoft Wireless Security Auditor
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Elcomsoft Password Recovery\Elcomsoft Wireless Security Auditor|*.log
FileKey2=%ProgramFiles%\Elcomsoft Password Recovery\Elcomsoft Wireless Security Auditor|*.log
[Elder Scrolls Online *]
Section=Games
DetectFile=%Documents%\Elder Scrolls Online
Default=False
FileKey1=%Documents%\Elder Scrolls Online\Errors|*.*
FileKey2=%Documents%\Elder Scrolls Online\Logs|*.*
[Electric Sheep *]
LangSecRef=3021
DetectFile=%CommonAppData%\ElectricSheep
Default=False
FileKey1=%CommonAppData%\ElectricSheep\Logs|*.*
[ElsterFormular *]
LangSecRef=3021
DetectFile=%AppData%\elsterformular
Default=False
FileKey1=%AppData%\elsterformular\*\log|*.log;*.log.*
FileKey2=%AppData%\elsterformular\*\tmp|*.*|RECURSE
FileKey3=%AppData%\elsterformular\pluginmanager\data|*_cpy.zip
FileKey4=%CommonAppData%\elsterformular\log|*.log
FileKey5=%LocalAppData%\.elfohilfe|*.*|REMOVESELF
FileKey6=%LocalAppData%\elfopatch|*.*|REMOVESELF
[eM Client *]
LangSecRef=3022
Detect=HKCU\Software\eM Client
Default=False
FileKey1=%AppData%\eM Client\Logs|*.*
[Email Address Collector *]
LangSecRef=3022
DetectFile=%AppData%\DS Development\EAC
Default=False
FileKey1=%AppData%\DS Development\EAC|*.log
[EmEditor *]
LangSecRef=3024
Detect=HKCU\Software\EmSoft\EmEditor v3
Default=False
RegKey1=HKCU\Software\EmSoft\EmEditor v3\Recent File List
RegKey2=HKCU\Software\EmSoft\EmEditor v3\Recent Folder List
RegKey3=HKCU\Software\EmSoft\EmEditor v3\Recent Font List
[emesene2 *]
LangSecRef=3022
DetectFile=%AppData%\emesene\emesene2
Default=False
FileKey1=%AppData%\emesene\emesene2\*\*\*\avatars|*.*|RECURSE
FileKey2=%AppData%\emesene\emesene2\*\*\*avatars|*.*|RECURSE
FileKey3=%AppData%\emesene\emesene2\*\*\log|*.*|RECURSE
[Emsisoft HiJackFree *]
LangSecRef=3024
Detect=HKLM\Software\Emsi Software GmbH\a-squared HiJackFree
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Emsisoft HiJackFree|*.old
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Emsisoft HiJackFree\Logs|*.*
FileKey3=%ProgramFiles%\Emsisoft HiJackFree|*.old
FileKey4=%ProgramFiles%\Emsisoft HiJackFree\Logs|*.*
[EndNote X6 *]
LangSecRef=3021
Detect=HKLM\Software\ISI ResearchSoft\EndNote
Default=False
FileKey1=%AppData%\EndNote|*.log;*.16
FileKey2=%CommonAppData%\Thomson.ResearchSoft.Installers|*.*|REMOVESELF
FileKey3=%CommonProgramFiles%\Risxtd|*.LOG;*.txt
FileKey4=%Documents%\My EndNote Library.Data\Trash|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\EndNote X6\Product-Support\ThirdParty\Apache2|NOTICE
FileKey6=%LocalAppData%\VirtualStore\Program Files*\EndNote*|*.txt
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Thomson.ResearchSoft.Installers|*.*|REMOVESELF
FileKey8=%LocalAppData%\VritualStore\Program Files*\Common Files\Risxtd|*.LOG;*.txt
FileKey9=%ProgramFiles%\EndNote X6\Product-Support\ThirdParty\Apache2|NOTICE
FileKey10=%ProgramFiles%\EndNote*|*.txt
[EnhanceMy8 *]
LangSecRef=3024
DetectFile=%ProgramFiles%\EnhanceMy8
Default=False
FileKey1=%AppData%\SeriousBit\EnhanceMy8|Logs.txt
FileKey2=%AppData%\SeriousBit\EnhanceMy8\Backups|*.*|RECURSE
[Epic Games Launcher *]
Section=Games
Detect=HKCU\Software\Epic Games\EpicGamesLauncher
Default=False
FileKey1=%LocalAppData%\EpicGamesLauncher\Saved\Crashes|*.*|REMOVESELF
FileKey2=%LocalAppData%\EpicGamesLauncher\Saved\Logs|*.*|REMOVESELF
[Epic Games Launcher Cache *]
Section=Games
Detect=HKCU\Software\Epic Games\EpicGamesLauncher
Default=False
FileKey1=%LocalAppData%\EpicGamesLauncher\Saved\webcache|*.*|REMOVESELF
[Epson *]
LangSecRef=3021
Detect=HKCU\Software\EPSON
Default=False
FileKey1=%AppData%\Epson\FAX Utility\FAXLOG|*.*
[Eraser *]
LangSecRef=3024
Detect=HKCU\Software\Heidi Computers Ltd\Eraser\5.5
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Eraser|schedlog.txt
FileKey2=%ProgramFiles%\Eraser*|schedlog.txt
[ESET *]
LangSecRef=3021
Detect=HKLM\Software\ESET\ESET Security
Default=False
Warning=You may need to run this in safe mode. You should also disable the ERA service to properly clean the ERA files.
FileKey1=%CommonAppData%\ESET\ESET*\Logs|*.*|RECURSE
FileKey2=%CommonAppData%\ESET\ESET*\Oldfiles|*.*|RECURSE
FileKey3=%CommonAppData%\ESET\ESET*\Updfiles|*.*|REMOVESELF
FileKey4=%LocalAppData%\VirtualStore\ProgramData\ESET\ESET*\Logs|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\ESET\ESET*\Oldfiles|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\ESET\ESET*\Updfiles|*.*|REMOVESELF
[ESET Online Scanner *]
LangSecRef=3024
Detect=HKLM\Software\ESET\ESET Security
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\ESET\ESET Online Scanner|log.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\ESET\ESET Online Scanner\Modules\data\updfiles\temp|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\ESET\ESET Online Scanner\Quarantine|*.*
FileKey4=%ProgramFiles%\ESET\ESET Online Scanner|log.txt
FileKey5=%ProgramFiles%\ESET\ESET Online Scanner\Modules\data\updfiles\temp|*.*
FileKey6=%ProgramFiles%\ESET\ESET Online Scanner\Quarantine|*.*
[eSobi *]
LangSecRef=3022
DetectFile=%AppData%\eSobi
Default=False
FileKey1=%AppData%\eSobi\*\temp|*.*|RECURSE
[ESPN Cricinfo *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\ESPNCricinfo.ESPNCricinfo_y1atfjxm9t5ma
DetectFile=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_y1atfjxm9t5ma
Default=False
FileKey1=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey3=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\Microsoft\CLR_v4.0\NativeImages\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\PRICache|*.*
FileKey7=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\LocalState|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\ESPNCricinfo.ESPNCricinfo_*\TempState|*.*|RECURSE
[ESPN FC *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\ESPNCricinfo.ESPNFC_y1atfjxm9t5ma
DetectFile=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_y1atfjxm9t5ma
Default=False
FileKey1=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey3=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\AC\Temp|*.*
FileKey5=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\LocalState|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\ESPNCricinfo.ESPNFC_*\TempState|*.*|RECURSE
[ESPN Motion *]
LangSecRef=3023
Detect=HKCU\Software\Disney\DIGStream
Default=False
FileKey1=%CommonAppData%\DIGStream\ESPNMotion|*.wmv;*.tmp
FileKey2=%LocalAppData%\VirtualStore\ProgramData\DIGStream\ESPNMotion|*.wmv;*.tmp
[Essential NetTools 3 *]
LangSecRef=3022
Detect=HKCU\Software\ENT3
Default=False
RegKey1=HKCU\Software\ENT3\Recent
[EssentialPIM Desktop *]
LangSecRef=3021
Detect=HKLM\Software\clients\mail\essentialpim pro
DetectFile=%AppData%\EssentialPIM
Default=False
FileKey1=%AppData%\EssentialPIM*\Logs|*.*
[Euro Truck Simulator *]
Section=Games
Detect1=HKCU\Software\SCS Software
Detect2=HKLM\Software\SCS Software
DetectFile=%ProgramFiles%\Euro Truck Simulator 2
Default=False
FileKey1=%Documents%\Euro Truck Simulator*|*.log;*log.txt;*.crash
[Euro Truck Simulator Profile Backups *]
Section=Games
Detect1=HKCU\Software\SCS Software
Detect2=HKLM\Software\SCS Software
Default=False
Warning=This will delete your Euro Truck Simulator profile backups. A profile backup will regenerate at next start.
FileKey1=%Documents%\Euro Truck Simulator*|backups.txt
FileKey2=%Documents%\Euro Truck Simulator*\profiles*.bak|*.*|REMOVESELF
[EuroSYSTEMS CoCut Professional 2011 *]
LangSecRef=3021
Detect=HKCU\Software\EuroSYSTEMS\CoCut Professional 2011
Default=False
FileKey1=%AppData%\EUROSYSTEMS\CoCut Professional 2011 15|*.bak
FileKey2=%LocalAppData%\VirtualStore\Program Files*\EUROSYSTEMS\CoCut Professional 2011|*.log;*.bak;*.tmp
FileKey3=%LocalAppData%\VirtualStore\Program Files*\EUROSYSTEMS\CoCut Professional 2011\log|*.*
FileKey4=%ProgramFiles%\EUROSYSTEMS\CoCut Professional 2011|*.log;*.bak;*.tmp
FileKey5=%ProgramFiles%\EUROSYSTEMS\CoCut Professional 2011\log|*.*
[EuroSYSTEMS SmartCut Pro *]
LangSecRef=3021
Detect=HKCU\Software\EuroSYSTEMS
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\EUROSYSTEMS\SmartCut Pro|*.bak;*.tmp
FileKey2=%ProgramFiles%\EUROSYSTEMS\SmartCut Pro|*.bak;*.tmp
[EVE Online *]
Section=Games
Detect=HKCU\Software\CCP
Default=False
FileKey1=%AppData%\EVEMon|*.bak
FileKey2=%Documents%\EVE\Logs|*.*|RECURSE
FileKey3=%LocalAppData%\CCP\EVE|history.txt
[Evernote Skitch *]
LangSecRef=3021
Detect=HKCU\Software\Evernote\Skitch
Default=False
FileKey1=%LocalAppData%\Skitch|logfile.txt
RegKey1=HKCU\Software\Evernote\Skitch|lastDoc
[Evernote Updates *]
LangSecRef=3021
Detect=HKCU\Software\Evernote
Default=False
FileKey1=%LocalAppData%\Evernote\Evernote\AutoUpdate|*.exe
FileKey2=%LocalAppData%\Evernote\Evernote\Updates|*.*
[Everyday Genius: SquareLogic *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\32150
DetectFile=%AppData%\SquareLogic
Default=False
FileKey1=%AppData%\SquareLogic|*.log
[Everything *]
LangSecRef=3024
DetectFile1=%AppData%\Everything
DetectFile2=%ProgramFiles%\Everything
Default=False
FileKey1=%AppData%\Everything|*.csv;*.txt;*.tmp
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Everything|*.txt;*.csv;*.tmp
FileKey3=%ProgramFiles%\Everything|*.csv;*.txt;*.tmp
ExcludeKey1=FILE|%AppData%\Everything\|Filters.csv
ExcludeKey2=FILE|%LocalAppData%\VirtualStore\Program Files*\Everything\|Filters.csv
ExcludeKey3=FILE|%ProgramFiles%\Everything\|Filters.csv
[Exif Tag Remover *]
LangSecRef=3024
Detect=HKCU\Software\VB and VBA Program Settings\RL Vision\Exif Tag Remover
Default=False
RegKey1=HKCU\Software\VB and VBA Program Settings\RL Vision\Exif Tag Remover|sLastAddDir
RegKey2=HKCU\Software\VB and VBA Program Settings\RL Vision\Exif Tag Remover|sLastDir
[Exifer *]
LangSecRef=3024
Detect=HKCU\Software\Exifer
Default=False
RegKey1=HKCU\Software\Exifer\Browse\History
[ExifPro *]
LangSecRef=3024
Detect=HKCU\Software\MKowalski\ExifPro
Default=False
FileKey1=%CommonAppData%\MiK\ExifPro|Cache*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\MiK\ExifPro|Cache*
RegKey1=HKCU\Software\MKowalski\ExifPro\1.0\Browser\View 0|LastPath
RegKey2=HKCU\Software\MKowalski\ExifPro\1.0\HTMLAlbumGen\RecentDestPaths
RegKey3=HKCU\Software\MKowalski\ExifPro\1.0\RecentPaths
RegKey4=HKCU\Software\MKowalski\ExifPro\1.0\ResizeDlg\RecentDestPaths
[Exodus Cache *]
LangSecRef=3022
Detect=HKCU\Software\Jabber\Exodus
Default=False
FileKey1=%AppData%\Exodus\avatars|cache.xml
[Exodus Chat Logs *]
LangSecRef=3022
Detect=HKCU\Software\Jabber\Exodus
Default=False
FileKey1=%Documents%\Exodus-Logs|*.*|RECURSE
[Exportizer *]
LangSecRef=3024
Detect=HKCU\Software\Vitaliy Levchenko\Exportizer 5
Default=False
RegKey1=HKCU\Software\Vitaliy Levchenko\Exportizer 5\Settings|LastExt
RegKey2=HKLM\Software\ODBC\Temporary (volatile) Jet DSN for process 0x5ac Thread 0x3d8 DBC 0x2bd1e84 Xbase|DefaultDir
RegKey3=HKLM\Software\ODBC\Temporary (volatile) Jet DSN for process 0x858 Thread 0xfb0 DBC 0x2ca3a74 Paradox|DefaultDir
[EZ Backup Ultimate *]
LangSecRef=3024
Detect=HKCU\Software\Perception\EZ Backup Ultimate
Default=False
FileKey1=%AppData%\EZ Backup Ultimate|lastlog.html
[F-Secure Password Manager *]
LangSecRef=3021
Detect=HKCU\Software\F-Secure
Default=False
FileKey1=%LocalAppData%\F-Secure\Pwmgr|*.log
FileKey2=%LocalAppData%\F-Secure\Pwmgr\LocalStorage|*.*|RECURSE
[Facebook *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Facebook.Facebook_8xx8rvfyw5nnt
DetectFile=%LocalAppData%\Packages\Facebook.Facebook_8xx8rvfyw5nnt
Default=False
FileKey1=%LocalAppData%\Packages\*Facebook_*\LocalState|*.*|RECURSE
[Facebook Messenger *]
LangSecRef=3022
DetectFile=%LocalAppData%\Facebook\Messenger
Default=False
FileKey1=%LocalAppData%\Facebook\Messenger|*.log|RECURSE
[Facebook Plugin *]
LangSecRef=3022
Detect=HKCU\Software\Facebook
Default=False
FileKey1=%LocalAppData%\Facebook\CrashReports|*.*
[Faceprov *]
LangSecRef=3023
Detect=HKCU\Software\Lenovo
Default=False
FileKey1=%SystemDrive%|Faceprov.*
[Fallout Shelter *]
Section=Games
Detect1=HKCU\Software\Bethesda\Fallout Shelter
Detect2=HKCU\Software\Valve\Steam\Apps\588430
Default=False
FileKey1=%LocalAppData%\FalloutShelter|*.log;*.bkp
[Fantasy Wars *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\63900
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\Fantasy Wars|gui_log.txt
FileKey2=%ProgramFiles%\Steam\Steamapps\common\Fantasy Wars|gui_log.txt
[FAR Manager *]
LangSecRef=3021
Detect1=HKCU\Software\Far
Detect2=HKCU\Software\Far2
Detect3=HKCU\Software\Far18
Default=False
RegKey1=HKCU\Software\Far\Editor\LastPositions
RegKey2=HKCU\Software\Far\SavedDialogHistory
RegKey3=HKCU\Software\Far\SavedDialogHistory\PersPath
RegKey4=HKCU\Software\Far\SavedFolderHistory
RegKey5=HKCU\Software\Far\SavedHistory
RegKey6=HKCU\Software\Far\SavedViewHistory
RegKey7=HKCU\Software\Far\Viewer\LastPositions
RegKey8=HKCU\Software\Far2\Editor\LastPositions
RegKey9=HKCU\Software\Far2\SavedDialogHistory
RegKey10=HKCU\Software\Far2\SavedDialogHistory\PersPath
RegKey11=HKCU\Software\Far2\SavedFolderHistory
RegKey12=HKCU\Software\Far2\SavedHistory
RegKey13=HKCU\Software\Far2\SavedViewHistory
RegKey14=HKCU\Software\Far2\Viewer\LastPositions
RegKey15=HKCU\Software\Far18\Editor\LastPositions
RegKey16=HKCU\Software\Far18\SavedDialogHistory
RegKey17=HKCU\Software\Far18\SavedDialogHistory\PersPath
RegKey18=HKCU\Software\Far18\SavedFolderHistory
RegKey19=HKCU\Software\Far18\SavedHistory
RegKey20=HKCU\Software\Far18\SavedViewHistory
RegKey21=HKCU\Software\Far18\Viewer\LastPositions
[Farming Simulator *]
Section=Games
Detect=HKLM\Software\SCS Software
Default=False
FileKey1=%Documents%\My Games\FarmingSimulator*|*.txt
FileKey2=%Documents%\My Games\FarmingSimulator*\pdlc*|*.dlc|REMOVESELF
FileKey3=%Documents%\My Games\FarmingSimulator*\shader_cache|*.shc;*.xml|REMOVESELF
[Farming Simulator Old Autosaves *]
Section=Games
Detect=HKLM\Software\SCS Software
Default=False
FileKey1=%Documents%\My Games\FarmingSimulator*\savegame*|*.*|REMOVESELF
ExcludeKey1=PATH|%Documents%\My Games\FarmingSimulator*\savegame1\|*.*
ExcludeKey2=PATH|%Documents%\My Games\FarmingSimulator*\savegameBackup\|*.*
[Fast Clean Pro *]
LangSecRef=3024
DetectFile=%LocalAppData%\Fastcleanpro
Default=False
FileKey1=%LocalAppData%\Fastcleanpro\logs|*.*
[Faster Than Light *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\212680
DetectFile=%Documents%\My Games\FasterThanLight
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\FTL Faster Than Light\crashlogs|*.*
FileKey2=%ProgramFiles%\Steam\steamapps\common\FTL Faster Than Light\crashlogs|*.*
[FastStone Capture *]
LangSecRef=3024
Detect=HKCU\Software\FastStone Capture
DetectFile=%AppData%\FastStone\FSC
Default=False
FileKey1=%AppData%\FastStone\FSC|*.bak;fsc.db
FileKey2=%LocalAppData%\FastStone\FSC|fsc.db
RegKey1=HKCU\Software\FastStone|_LastClipPlayed
RegKey2=HKCU\Software\FastStone|_LastRecordingFileName
RegKey3=HKCU\Software\FastStone\APP.FSRecorder\Global|_GrbId
RegKey4=HKCU\Software\FastStone\APP.FSRecorder\Global|_LastClipPlayed
RegKey5=HKCU\Software\FastStone\APP.FSRecorder\Global|_LastRecordingFileName
[FastStone Image Viewer *]
LangSecRef=3023
Detect=HKLM\Software\FastStone Image Viewer
Default=False
FileKey1=%AppData%\FastStone\FSIV|FSViewer.db
[FatBatt *]
LangSecRef=3024
Detect=HKCU\Software\MiserWare, Inc.\FatBatt
Default=False
FileKey1=%CommonAppData%\MiserWare\FatBatt\logs|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\MiserWare\FatBatt\logs|*.log
[Feedback Hub *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\LocalState\DiagOutputDir|*.txt
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedbackHub_*\TempState|*.*|RECURSE
[Feeds Cache *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Feeds
Default=False
FileKey1=%LocalAppData%\Microsoft\Feeds Cache|*.*|RECURSE
[FEZ *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\224760
Default=False
FileKey1=%AppData%\FEZ|Debug Log.txt
[FFsplit *]
LangSecRef=3023
DetectFile=%ProgramFiles%\FFsplit
Default=False
FileKey1=%AppData%\FFsplit|FFsourceLog.txt
FileKey2=%AppData%\FFsplit\logs|*.*
[FIGHTERStools *]
LangSecRef=3024
Detect=HKCU\Software\Fighters
Default=False
FileKey1=%AppData%\Fighters\*\Logs|*.log;*log.txt
FileKey2=%CommonAppData%\Common Toolkit Suite\Tools\Logs|*.log
FileKey3=%CommonAppData%\Fighters\*\Logs|*.log
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Common Toolkit Suite\Tools\Logs|*.log
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Fighters\*\Logs|*.log
[File Shredder *]
LangSecRef=3024
Detect=HKCU\Software\Shredder
Default=False
RegKey1=HKCU\Software\Shredder\{FF14D9EE-48EB-4873-80AC-8E224BEE5823}
[File Transfer Manager *]
LangSecRef=3025
DetectFile=%AppData%\Microsoft\File Transfer Manager
Default=False
FileKey1=%AppData%\Microsoft\File Transfer Manager|*.bak
[File Type Doctor Last Selected *]
LangSecRef=3024
Detect=HKCU\Software\Creative Element\File Type Doctor
Default=False
RegKey1=HKCU\Software\Creative Element\File Type Doctor|LastSelected
[FileCleaner *]
LangSecRef=3024
Detect=HKCU\Software\WebMinds, Inc\FileCleaner
Default=False
FileKey1=%AppData%\FileCleaner|log.txt
[FileHippo Update Checker *]
LangSecRef=3024
Detect=HKCU\Software\Filehippo.com\Update Checker
Default=False
FileKey1=%Documents%\My Filehippo Downloads|*.*|RECURSE
[FileLocator Pro *]
LangSecRef=3024
Detect=HKCU\Software\Mythicsoft\FileLocatorPro
Default=False
RegKey1=HKCU\Software\Mythicsoft\FileLocatorPro\RecentContains
RegKey2=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFileName
RegKey3=HKCU\Software\Mythicsoft\FileLocatorPro\RecentFolders
[FileManager *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\FileManager_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\FileManager_*\LocalState|*.jpg
[FileMind QuickFix *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{92789900-80D0-4B61-B742-7897964A69AB}_is1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Metability Software\FileMindQuickFix|*.log|RECURSE
FileKey2=%ProgramFiles%\Metability Software\FileMindQuickFix|*.log|RECURSE
[FileZilla *]
LangSecRef=3022
Detect=HKLM\Software\FileZilla Client
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\FileZilla FTP Client|*.tmp
FileKey2=%ProgramFiles%\FileZilla FTP Client|*.tmp
[FilmOn *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\FilmOnLiveTVFree.FilmOnLiveTVFree_zx03kxexxb716
DetectFile=%LocalAppData%\Packages\FilmOnLiveTVFree.FilmOnLiveTVFree_zx03kxexxb716
Default=False
FileKey1=%LocalAppData%\Packages\FilmOnLiveTVFree.FilmOnLiveTVFree_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\FilmOnLiveTVFree.FilmOnLiveTVFree_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\FilmOnLiveTVFree.FilmOnLiveTVFree_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey4=%LocalAppData%\Packages\FilmOnLiveTVFree.FilmOnLiveTVFree_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\FilmOnLiveTVFree.FilmOnLiveTVFree_zx03kxexxb716\SearchHistory
[Firebird Project *]
LangSecRef=3023
Detect=HKLM\Software\Firebird Project
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Firebird\Firebird_2_1|*.log
FileKey2=%ProgramFiles%\Firebird\Firebird_2_1|*.log
[Fishdom: H2O *]
Section=Games
DetectFile=%AppData%\Playrix Entertainment\Fishdom H2O Final
Default=False
FileKey1=%AppData%\Playrix Entertainment\Fishdom H2O Final|log.html
[FixCleaner *]
LangSecRef=3024
DetectFile=%AppData%\FixCleaner
Default=False
FileKey1=%AppData%\FixCleaner\Logs|*.*
[Flash Media Encoder *]
LangSecRef=3023
DetectFile=%ProgramFiles%\Adobe\Flash Media Live Encoder *
Default=False
FileKey1=%Video%|fmle*.log
[FlashFXP *]
LangSecRef=3022
Detect=HKLM\Software\FlashFXP
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\FlashFXP|quick.dat
FileKey2=%ProgramFiles%\FlashFXP|quick.dat
[FlashGet *]
LangSecRef=3022
Detect=HKCU\Software\JetCar
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\FlashGet|Default.bk*;Default.jcd.bak
FileKey2=%ProgramFiles%\FlashGet|Default.bk*;Default.jcd.bak
RegKey1=HKCU\Software\JetCar\JetCar|Recent File List
[FLEXnet *]
LangSecRef=3021
Detect=HKCU\Software\FlexNet
Default=False
FileKey1=%CommonAppData%\FLEXnet|*.data_backup.*;*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\FLEXnet|*.data_backup.*;*.log
[FMV Extractor *]
LangSecRef=3023
DetectFile=%ProgramFiles%\FMV-Extractor
Default=False
Warning=This will delete all your extracted video files.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\FMV-Extractor\Clip|*.*|RECURSE
FileKey2=%ProgramFiles%\FMV-Extractor\Clip|*.*|RECURSE
[FolderShare *]
LangSecRef=3022
DetectFile=%LocalAppData%\FolderShare
Default=False
FileKey1=%LocalAppData%\FolderShare\Logs|*.*
[FontCache *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\ServiceProfiles\LocalService\AppData\Local\FontCache|~*.dat
[Foobar2000 *]
LangSecRef=3023
Detect=HKLM\Software\foobar2000
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\foobar2000|failure.txt
FileKey2=%ProgramFiles%\foobar2000|failure.txt
[Ford Sync My iTunes *]
LangSecRef=3023
DetectFile=%AppData%\Ford Motor Company
Default=False
FileKey1=%AppData%\Ford Motor Company\logs|*.*
[ForgetBox Cache *]
LangSecRef=3022
Detect=HKCU\Software\ForgetBox SAS
Default=False
FileKey1=%AppData%\ForgetBox\cache|*.*|RECURSE
[Format Factory *]
LangSecRef=3023
Detect=HKCU\Software\FreeTime\FormatFactory
Default=False
Warning=This will delete the contents of your output folder. All your converted files will be deleted.
FileKey1=%Documents%\FFOutput|*.*|RECURSE
FileKey2=%SystemDrive%\FFOutput|*.*|RECURSE
[Forte Agent *]
LangSecRef=3025
Detect=HKLM\Software\Forte
Default=False
FileKey1=%AppData%\Forte\Agent|errorlog.xml;*.log|RECURSE
FileKey2=%SystemDrive%\My Data\ForteAgent|*.bak;*.log
[Fortnite *]
Section=Games
DetectFile=%LocalAppData%\FortniteGame
Default=False
FileKey1=%LocalAppData%\FortniteGame\Saved\Crashes|*.*|REMOVESELF
FileKey2=%LocalAppData%\FortniteGame\Saved\Demos|UnsavedReplay*.replay|REMOVESELF
FileKey3=%LocalAppData%\FortniteGame\Saved\Logs|*.*|REMOVESELF
[Fortnite Cache *]
Section=Games
DetectFile=%LocalAppData%\FortniteGame
Default=False
FileKey1=%LocalAppData%\FortniteGame\Saved\webcache|*.*|REMOVESELF
[Forward Observer *]
LangSecRef=3021
DetectFile=%ProgramFiles%\AAForwardObserver\AAForwardObserver.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\AAForwardObserver|FO.log
FileKey2=%ProgramFiles%\AAForwardObserver|FO.log
[Foxit PhantomPDF *]
LangSecRef=3021
Detect1=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0
Detect2=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0
Detect3=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0
Detect4=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0
Default=False
FileKey1=%AppData%\Foxit Software\Foxit PDF Creator\Creator-Log|*.*|RECURSE
FileKey2=%AppData%\Foxit Software\Foxit PhantomPDF\FormFiller|AutoComplete.ds
FileKey3=%AppData%\Foxit Software\RMS|FXRMS_Log.txt
FileKey4=%LocalAppData%\Foxit PhantomPDF\msilog|*.log
FileKey5=%WinDir%\System32\config\systemprofile\AppData\Roaming\Foxit Software\Foxit PDF Creator|*__foxittemp.xml|RECURSE
RegKey1=HKCU\Software\Foxit Software Company\Foxit PDF Editor|Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0\Preferences\History
RegKey3=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0\RecentFiles
RegKey4=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\MRU\File MRU
RegKey5=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\MRU\Place MRU
RegKey6=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\plugins\JSPlugins
RegKey7=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\Preferences\History
RegKey8=HKCU\Software\Foxit Software\Foxit PhantomPDF 7.0\Recent File List
RegKey9=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\CommentPanel\Filter
RegKey10=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Foxit PhantomPDF Advanced Editor\Recent File List
RegKey11=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\MRU\File MRU
RegKey12=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\MRU\Place MRU
RegKey13=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\plugins\JSPlugins
RegKey14=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Preferences\History
RegKey15=HKCU\Software\Foxit Software\Foxit PhantomPDF 8.0\Recent File List
RegKey16=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\CommentPanel\Filter
RegKey17=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\Foxit PhantomPDF Advanced Editor\Recent File List
RegKey18=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\MRU\File MRU
RegKey19=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\MRU\Place MRU
RegKey20=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\plugins\JSPlugins
RegKey21=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\Preferences\History
RegKey22=HKCU\Software\Foxit Software\Foxit PhantomPDF 9.0\Recent File List
[Foxit Reader 6.0 *]
LangSecRef=3021
Detect=HKCU\Software\Foxit Software\Foxit Reader 6.0
Default=False
FileKey1=%AppData%\Foxit Software\Foxit Reader\StartPage\Start|history.txt
FileKey2=%LocalAppData%\Foxit Reader|*.TXT;*.zip;*.reg
RegKey1=HKCU\Software\Foxit Software\Foxit Reader 6.0\Preferences\History\Options
[Fractal: Make Blooms Not War *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\61310
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\Fractal\fractal_data|output_log.txt
FileKey2=%ProgramFiles%\Steam\Steamapps\common\Fractal\fractal_data|output_log.txt
[Fre:ac *]
LangSecRef=3024
DetectFile=%AppData%\freac
Default=False
FileKey1=%AppData%\Freac\cddb|*.*|REMOVESELF
[Free Download Manager *]
LangSecRef=3022
Detect=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager
Default=False
FileKey1=%AppData%\Free Download Manager|downloads.del.sav
[Free PDF XP *]
LangSecRef=3024
Detect=HKCU\Software\shbox\FreePdfXP
Default=False
FileKey1=%SystemDrive%|IfpRedmon.log
[Free Registry Defrag *]
LangSecRef=3024
Detect=HKCU\Software\Local AppWizard-Generated Applications\RegDefrag
Default=False
FileKey1=%WinDir%\$regcmp$|*.*
[FreeCommander XE *]
LangSecRef=3021
DetectFile=%LocalAppData%\FreeCommanderXE
Default=False
FileKey1=%LocalAppData%\FreeCommanderXE\Settings\Bkp_Settings_*|*.*|REMOVESELF
FileKey2=%ProgramFiles%\FreeCommander XE\backup|*.*|REMOVESELF
[FreeFixer *]
LangSecRef=3024
DetectFile=%LocalAppData%\FreeFixer
Default=False
FileKey1=%LocalAppData%\FreeFixer|itemtracking.txt
FileKey2=%LocalAppData%\FreeFixer\icons|*.ico|RECURSE
FileKey3=%LocalAppData%\FreeFixer\logs|*.*|RECURSE
[Freemake Video Downloader *]
LangSecRef=3022
Detect=HKCU\Software\Freemake\FreemakeVideoDownloader
Default=False
FileKey1=%Documents%\Freemake\FreemakeVideoDownloader|fvd.bin
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Freemake|*.txt
FileKey3=%ProgramFiles%\Freemake|*.txt
[FrostWire *]
LangSecRef=3022
Detect=HKLM\Software\FrostWire
Default=False
FileKey1=%AppData%\FrostWire\.AppSpecialShare|*.*|RECURSE
FileKey2=%AppData%\FrostWire\azureus|*.*|RECURSE
FileKey3=%Documents%\FrostWire\Incomplete|*.*|RECURSE
[Frozen Synapse *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\98200
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\Frozen Synapse|*.log
FileKey2=%ProgramFiles%\Steam\Steamapps\common\Frozen Synapse|*.log
[Full Bore *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\105430
Default=False
FileKey1=%Documents%\Full Bore|log.txt
[Full Tilt Poker *]
Section=Games
DetectFile=%ProgramFiles%\Full Tilt Poker.net
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Full Tilt Poker.net\Cache|*.*
FileKey2=%ProgramFiles%\Full Tilt Poker.net\Cache|*.*
[G-Data *]
LangSecRef=3023
Detect=HKCU\Software\G Data
Default=False
FileKey1=%CommonAppData%\G Data\AVK\Log|*.*|RECURSE
FileKey2=%CommonProgramFiles%\G Data\AVKScanP\G Data|*.log;*old
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Common Files\G Data\AVKScanP\G Data|*.log;*old
FileKey4=%LocalAppData%\VirtualStore\Program Files*\G Data\AntiVirus\AVK\UpdatePGM|*.log
FileKey5=%LocalAppData%\VirtualStore\ProgramData\G Data\AVK\Log|*.*|RECURSE
FileKey6=%ProgramFiles%\G Data\AntiVirus\AVK\UpdatePGM|*.log
[Gadu-Gadu *]
LangSecRef=3022
Detect=HKCU\Software\Gadu-Gadu
Default=False
FileKey1=%WinDir%|TEMP*.htm*
[Gajim *]
LangSecRef=3022
DetectFile=%AppData%\Gajim
Default=False
FileKey1=%AppData%\Gajim|cache.db;Logs.db;gajim.log
FileKey2=%AppData%\Gajim\Avatars|*.*
[Galaxy *]
Section=Games
Detect=HKCU\Software\GOG.com\Galaxy
Default=False
FileKey1=%CommonAppData%\GOG.com\Galaxy\logs|*.log
FileKey2=%CommonAppData%\GOG.com\Galaxy\temp\desktop-galaxy-updater|*.*|REMOVESELF
FileKey3=%LocalAppData%\VirtualStore\ProgramData*\GOG.com\Galaxy\logs|*.log
FileKey4=%LocalAppData%\VirtualStore\ProgramData*\GOG.com\Galaxy\temp\desktop-galaxy-updater|*.*|REMOVESELF
[Galaxy Cache *]
Section=Games
Detect=HKCU\Software\GOG.com\Galaxy
Default=False
FileKey1=%CommonAppData%\GOG.com\Galaxy\webcache|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\ProgramData*\GOG.com\Galaxy\webcache|*.*|REMOVESELF
[Game Maker *]
LangSecRef=3021
Detect1=HKCU\Software\Game Maker 4
Detect2=HKCU\Software\Game Maker\Version 5
Detect3=HKCU\Software\Game Maker\Version 6
Detect4=HKCU\Software\Game Maker\Version 7
Detect5=HKCU\Software\Game Maker\Version 8
Default=False
RegKey1=HKCU\Software\Game Maker 4\Preferences|GameDir
RegKey2=HKCU\Software\Game Maker 4\Preferences|Recent0
RegKey3=HKCU\Software\Game Maker 4\Preferences|Recent1
RegKey4=HKCU\Software\Game Maker 4\Preferences|Recent2
RegKey5=HKCU\Software\Game Maker 4\Preferences|Recent3
RegKey6=HKCU\Software\Game Maker\Version 5\Preferences|GameDir
RegKey7=HKCU\Software\Game Maker\Version 5\Preferences|Recent0
RegKey8=HKCU\Software\Game Maker\Version 5\Preferences|Recent1
RegKey9=HKCU\Software\Game Maker\Version 5\Preferences|Recent2
RegKey10=HKCU\Software\Game Maker\Version 5\Preferences|Recent3
RegKey11=HKCU\Software\Game Maker\Version 5\Preferences|Recent4
RegKey12=HKCU\Software\Game Maker\Version 5\Preferences|Recent5
RegKey13=HKCU\Software\Game Maker\Version 5\Preferences|Recent6
RegKey14=HKCU\Software\Game Maker\Version 5\Preferences|Recent7
RegKey15=HKCU\Software\Game Maker\Version 6\Preferences|GameDir
RegKey16=HKCU\Software\Game Maker\Version 6\Preferences|Recent0
RegKey17=HKCU\Software\Game Maker\Version 6\Preferences|Recent1
RegKey18=HKCU\Software\Game Maker\Version 6\Preferences|Recent2
RegKey19=HKCU\Software\Game Maker\Version 6\Preferences|Recent3
RegKey20=HKCU\Software\Game Maker\Version 6\Preferences|Recent4
RegKey21=HKCU\Software\Game Maker\Version 6\Preferences|Recent5
RegKey22=HKCU\Software\Game Maker\Version 6\Preferences|Recent6
RegKey23=HKCU\Software\Game Maker\Version 6\Preferences|Recent7
RegKey24=HKCU\Software\Game Maker\Version 7\Preferences|GameDir
RegKey25=HKCU\Software\Game Maker\Version 7\Preferences|Recent0
RegKey26=HKCU\Software\Game Maker\Version 7\Preferences|Recent1
RegKey27=HKCU\Software\Game Maker\Version 7\Preferences|Recent2
RegKey28=HKCU\Software\Game Maker\Version 7\Preferences|Recent3
RegKey29=HKCU\Software\Game Maker\Version 7\Preferences|Recent4
RegKey30=HKCU\Software\Game Maker\Version 7\Preferences|Recent5
RegKey31=HKCU\Software\Game Maker\Version 7\Preferences|Recent6
RegKey32=HKCU\Software\Game Maker\Version 7\Preferences|Recent7
RegKey33=HKCU\Software\Game Maker\Version 8\Preferences|GameDir
RegKey34=HKCU\Software\Game Maker\Version 8\Preferences|Recent0
RegKey35=HKCU\Software\Game Maker\Version 8\Preferences|Recent1
RegKey36=HKCU\Software\Game Maker\Version 8\Preferences|Recent2
RegKey37=HKCU\Software\Game Maker\Version 8\Preferences|Recent3
RegKey38=HKCU\Software\Game Maker\Version 8\Preferences|Recent4
RegKey39=HKCU\Software\Game Maker\Version 8\Preferences|Recent5
RegKey40=HKCU\Software\Game Maker\Version 8\Preferences|Recent6
RegKey41=HKCU\Software\Game Maker\Version 8\Preferences|Recent7
[Games For Windows *]
Section=Games
DetectFile=%LocalAppData%\Microsoft\GFWLive
Default=False
FileKey1=%CommonAppData%\Microsoft\GFWLive\Install\Logs|*.log
FileKey2=%LocalAppData%\Microsoft\GFWLive|*.log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Microsoft\GFWLive\Install\Logs|*.log
FileKey4=%ProgramFiles%\Microsoft Games for Windows - LIVE\Client|dotNetFx40_Client_setup.exe
[Games for Windows Live Installers *]
Section=Games
Detect1=HKCR\Installer\Products\81024F76746FC3D4EB268FBCF42ECF5D
Detect2=HKCR\Installer\Products\3128052F989958E40A8727EB849371FE
Default=False
FileKey1=%ProgramFiles%\Microsoft Games for Windows - LIVE\Redist|*.*|RECURSE
[GameSave Manager *]
LangSecRef=3021
Detect1=HKCR\GSM_gsba
Detect2=HKCR\GSM_gsdu
Detect3=HKCR\GSM_gsms
Default=False
FileKey1=%AppData%\GameSave Manager*\*Cache*|*.*
FileKey2=%AppData%\GameSave Manager*\TaskLogs|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\GameSave Manager*\settings|*.log;ScanResults.txt|RECURSE
FileKey4=%ProgramFiles%\GameSave Manager*\settings|*.log;ScanResults.txt|RECURSE
[Gardens Inc. 2 - The Road to Fame *]
Section=Games
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{BBB8E5A9-EE43-491D-9A2D-84172C3C9384}_is1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\*\Gardens Inc. 2*|*.html;*.nfo;*.txt|RECURSE
FileKey2=%ProgramFiles%\*\Gardens Inc. 2*|*.ico;*.html;*msi;*.nfo;*.txt;*.url|RECURSE
[Gardenscapes *]
Section=Games
DetectFile=%AppData%\Playrix Entertainment\Gardenscapes
Default=False
FileKey1=%AppData%\Playrix Entertainment\Gardenscapes|log.html
[Garena Messenger *]
Section=Games
Detect=HKCU\Software\Garena\im
DetectFile=%ProgramFiles%\Garena Plus\GarenaMessenger.exe
Default=False
FileKey1=%CommonAppData%\GarenaMessenger|im.log;im.log.*
FileKey2=%CommonAppData%\GarenaMessenger\cache\clan|*.*|RECURSE
FileKey3=%CommonAppData%\GarenaMessenger\cache\customAvatar\buddy|*.*
FileKey4=%CommonAppData%\GarenaMessenger\cache\emoticon|*.*
FileKey5=%CommonAppData%\GarenaMessenger\cache\screencapture|*.*
FileKey6=%CommonAppData%\GarenaMessenger\garena.game.plugins|*.tmp
FileKey7=%CommonAppData%\GarenaMessenger\update*|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger|im.log;im.log.*
FileKey9=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\cache\clan|*.*|RECURSE
FileKey10=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\cache\customAvatar\buddy|*.*
FileKey11=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\cache\emoticon|*.*
FileKey12=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\cache\screencapture|*.*
FileKey13=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\garena.game.plugins|*.tmp
FileKey14=%LocalAppData%\VirtualStore\ProgramData\GarenaMessenger\update*|*.*|RECURSE
[Garmin Express *]
LangSecRef=3024
Detect=HKCU\Software\Garmin\Express
Default=False
FileKey1=%CommonAppData%\Garmin\Logs|*.log;*.txt|RECURSE
FileKey2=%Documents%\Garmin\Backups\*|*.*|RECURSE
[GARMIN MapSource *]
LangSecRef=3024
Detect=HKCU\Software\Garmin\MapSource
Default=False
FileKey1=%AppData%\GARMIN\MapSource\TileCache|*.*|REMOVESELF
[GasBuddy *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\45351D82.GasBuddy-FindCheapGasPrices_932xwky9axss4
DetectFile=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_932xwky9axss4
Default=False
FileKey1=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\AC\Temp|*.*
FileKey5=%LocalAppData%\Packages\45351D82.GasBuddy-FindCheapGasPrices_*\TempState|*.*|RECURSE
[gBurner *]
LangSecRef=3021
Detect=HKCU\Software\gBurner
Default=False
RegKey1=HKCU\Software\gBurner|Reopen0
RegKey2=HKCU\Software\gBurner|Reopen1
RegKey3=HKCU\Software\gBurner|Reopen2
RegKey4=HKCU\Software\gBurner|Reopen3
[GEAR DIFx Installers *]
LangSecRef=3024
Detect1=HKCR\Installer\Products\CACFC38969C58104B8CE6D8561446C45
Detect2=HKLM\Software\GEAR Software\DIFx
Detect3=HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EC13FCAF38E85F44B0F1137C7FB5037
Default=False
FileKey1=%AppData%\34BE82C4-E596-4e99-A191-52C6199EBF69|*.*|REMOVESELF
FileKey2=%AppData%\188F1432-103A-4ffb-80F1-36B633C5C9E1|*.*|REMOVESELF
FileKey3=%AppData%\9223B3E6-70DD-4e2f-965B-DD8E02D2E20B|*.*|REMOVESELF
FileKey4=%AppData%\Downloaded Installations|*.*|REMOVESELF
FileKey5=%CommonAppData%\{755AC846-7372-4AC8-8550-C52491DAA8BD}|*.*|REMOVESELF
FileKey6=%CommonAppData%\34BE82C4-E596-4e99-A191-52C6199EBF69|*.*|REMOVESELF
FileKey7=%CommonAppData%\188F1432-103A-4ffb-80F1-36B633C5C9E1|*.*|REMOVESELF
FileKey8=%CommonAppData%\9223B3E6-70DD-4e2f-965B-DD8E02D2E20B|*.*|REMOVESELF
FileKey9=%CommonAppData%\9727E41D-AD6A-47cd-B9BC-CF630B6013FD|*.*|REMOVESELF
FileKey10=%CommonAppData%\A73B37F8-7A4D-41f4-98A8-7F608CE8B98F|*.*|REMOVESELF
FileKey11=%CommonAppData%\E1864A66-75E3-486a-BD95-D1B7D99A84A7|*.*|REMOVESELF
FileKey12=%LocalAppData%\Downloaded Installations|*.*|REMOVESELF
FileKey13=%ProgramFiles%\34BE82C4-E596-4e99-A191-52C6199EBF69|*.*|REMOVESELF
FileKey14=%ProgramFiles%\38FDB89C-1EBD-4366-84B2-336D12CC3209|*.*|REMOVESELF
FileKey15=%ProgramFiles%\93E26451-CD9A-43A5-A2FA-C42392EA4001|*.*|REMOVESELF
FileKey16=%ProgramFiles%\188F1432-103A-4ffb-80F1-36B633C5C9E1|*.*|REMOVESELF
FileKey17=%ProgramFiles%\9223B3E6-70DD-4e2f-965B-DD8E02D2E20B|*.*|REMOVESELF
FileKey18=%ProgramFiles%\9727E41D-AD6A-47cd-B9BC-CF630B6013FD|*.*|REMOVESELF
[Geek Unistaller *]
LangSecRef=3024
Detect=HKCU\Software\Geek Uninstaller
Default=False
FileKey1=%AppData%\Geek Uninstaller|*.log;*cache.dat
[GeekSquad *]
LangSecRef=3024
DetectFile=%CommonAppData%\Geek Squad
Default=False
FileKey1=%CommonAppData%\Geek Squad\MRI|EventLog.gsl|RECURSE
FileKey2=%CommonAppData%\Geek Squad\MRI\Automation Reports|*.*|REMOVESELF
FileKey3=%CommonAppData%\Geek Squad\MRI\Downloads|*.*|REMOVESELF
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Geek Squad\MRI|EventLog.gsl|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Geek Squad\MRI\Automation Reports|*.*|REMOVESELF
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Geek Squad\MRI\Downloads|*.*|REMOVESELF
[Genie-Soft *]
LangSecRef=3024
Detect=HKCU\Software\Genie-Soft
Default=False
FileKey1=%AppData%\Genie-soft\*\logs|*.*
[Genieo *]
LangSecRef=3022
DetectFile=%AppData%\Genieo
Default=False
FileKey1=%AppData%\Genieo\log|*.*|RECURSE
FileKey2=%AppData%\Genieo\sp_cache|*.*|RECURSE
FileKey3=%AppData%\Genieo\tmp|*.*|RECURSE
[Genymobile *]
LangSecRef=3024
Detect=HKCU\Software\Genymobile
Default=False
FileKey1=%LocalAppData%\Genymobile|*.log
FileKey2=%UserProfile%\VirtualBox VMs\*|genymotion-player*.log;logcat*.txt
[Get Started *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Getstarted_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Getstarted_*\AC\Temp|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Getstarted_*\LocalState\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Getstarted_*\TempState|*.*|RECURSE
[GetDiz Recent Files List *]
LangSecRef=3021
Detect=HKCU\Software\Outertech\GetDiz
Default=False
RegKey1=HKCU\Software\Outertech\GetDiz|Recent Files_1
RegKey2=HKCU\Software\Outertech\GetDiz|Recent Files_2
RegKey3=HKCU\Software\Outertech\GetDiz|Recent Files_3
RegKey4=HKCU\Software\Outertech\GetDiz|Recent Files_4
RegKey5=HKCU\Software\Outertech\GetDiz|Recent Files_5
RegKey6=HKCU\Software\Outertech\GetDiz|Recent Files_6
RegKey7=HKCU\Software\Outertech\GetDiz|Recent Files_7
RegKey8=HKCU\Software\Outertech\GetDiz|Recent Files_8
RegKey9=HKCU\Software\Outertech\GetDiz|Recent Files_9
RegKey10=HKCU\Software\Outertech\GetDiz|Recent Files_10
[GetFLV *]
LangSecRef=3023
Detect=HKCU\Software\getflv
Default=False
RegKey1=HKCU\Software\GetFLV|DownloadDir
RegKey2=HKCU\Software\getflv|FLVTitle
RegKey3=HKCU\Software\GetFLV|FLVURL
[GetRight *]
LangSecRef=3022
Detect=HKCU\Software\Headlight\GetRight
Default=False
FileKey1=%AppData%\GetRight|GetRight.lst
RegKey1=HKCU\Software\Headlight\GetRight\FileQueue
RegKey2=HKCU\Software\Headlight\GetRight\ResumeServers
RegKey3=HKCU\Software\Headlight\GetRight\Stats
RegKey4=HKCU\Software\Headlight\GetRight\UserAgent
[GetRightToGo *]
LangSecRef=3022
Detect=HKCU\Software\Headlight\GetRightToGo
Default=False
FileKey1=%AppData%\GetRightToGo|*.data|RECURSE
[Getting Over It with Bennett Foddy *]
Section=Games
Detect=HKCU\Software\steam\apps\266490
Default=False
FileKey1=%LocalLowAppData%\Bennett Foddy\Getting Over It|output_log.txt
FileKey2=%LocalLowAppData%\Bennett Foddy\Getting Over It\Crashes|*.*
[Ghostbuster *]
LangSecRef=3021
DetectFile=%AppData%\Ghostbuster
Default=False
FileKey1=%AppData%\Ghostbuster|*.*|REMOVESELF
[GhostMouse *]
LangSecRef=3024
DetectFile=%ProgramFiles%\GhostMouse
Default=False
FileKey1=%Documents%\AutomaticSolution Software\GhostMouse\conf\temp|*.tmp
[GIANT AntiSpyware *]
LangSecRef=3021
Detect=HKCU\Software\GIANTCompany\AntiSpyware
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\GIANT Company Software\GIANT AntiSpyware|errors.log;cleaner.log;tracksEraser.log
FileKey2=%ProgramFiles%\GIANT Company Software\GIANT AntiSpyware|errors.log;cleaner.log;tracksEraser.log
[Gigantic *]
Section=Games
DetectFile=%Documents%\My Games\Gigantic
Default=False
FileKey1=%Documents%\My Games\Gigantic\RxGame\Logs|*.log;*.dmg|RECURSE
[GigaTribe *]
LangSecRef=3022
Detect=HKCU\Software\ShalSoft\GigaTribe
Default=False
FileKey1=%LocalAppData%\Shalsoft\Gigatribe\*\re*sources|*.*|RECURSE
[GIMP *]
LangSecRef=3021
DetectFile1=%UserProfile%\.gimp-2.2\gimprc
DetectFile2=%UserProfile%\.gimp-2.8
Default=False
FileKey1=%LocalAppData%|recently-used.xbel
FileKey2=%LocalAppData%\webkit|*.*|REMOVESELF
FileKey3=%UserProfile%\.gimp-2.2|documents
[Ginger *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Ginger
Default=False
FileKey1=%Documents%\Add-in Express|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ginger|*.log;*.tmp|RECURSE
FileKey3=%ProgramFiles%\Ginger|*.log;*.tmp|RECURSE
FileKey4=%SystemDrive%|GingerSetup.log
[GitHub *]
LangSecRef=3022
DetectFile=%LocalAppData%\GitHub
Default=False
FileKey1=%LocalAppData%\GitHub|thelog.txt;*.log;git-log.txt;git-reflog.txt;git-shortlog.txt|RECURSE
[GitHub Desktop *]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\GitHubDesktop
Default=False
FileKey1=%AppData%\GitHubDesktop\*Cache|*.*|REMOVESELF
FileKey2=%AppData%\GitHubDesktop\logs|*.*|REMOVESELF
FileKey3=%LocalAppData%\GitHubDesktop|*.log
FileKey4=%LocalAppData%\GitHubDesktop\packages\SquirrelTemp|*.*|REMOVESELF
FileKey5=%LocalAppData%\SquirrelTemp|*.*|REMOVESELF
[GMG Capsule *]
Section=Games
DetectFile=%LocalAppData%\Green Man Gaming\Capsule
Default=False
FileKey1=%LocalAppData%\Green Man Gaming\Capsule\Logfiles|*.*
[GMote *]
LangSecRef=3024
DetectFile=%AppData%\Gmote
Default=False
FileKey1=%AppData%\Gmote|*.log
[GNU Cache *]
LangSecRef=3021
Detect=HKCU\Software\GNU
Default=False
FileKey1=%LocalAppData%\GNU\Cache\*|*.*|RECURSE
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Gnu\Cache|*.*|RECURSE
FileKey3=%WinDir%\System32\config\systemprofile\local settings\application data\gnu\cache|*.*|RECURSE
FileKey4=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\GNU\Cache|*.*|RECURSE
[GnuCash *]
LangSecRef=3021
Detect=HKCU\Software\GSettings\org\gnucash
Default=False
Warning=This removes the last open history, auto saves and logs.
FileKey1=%UserProfile%\*|*.gnucash.*.log;*.gnucash.*.gnucash;translog.*.log|RECURSE
RegKey1=HKCU\Software\GSettings\org\gnucash\history
[Go!Zilla *]
LangSecRef=3022
Detect=HKCU\Software\Go!Zilla
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Go!Zilla|golog.htm;download.log;leech.hst
FileKey2=%ProgramFiles%\Go!Zilla|golog.htm;download.log;leech.hst
[Goalscape *]
LangSecRef=3021
DetectFile=%ProgramFiles%\GoalScape
Default=False
FileKey1=%AppData%\com.goalscape.app.*\Logging|*.*|RECURSE
[Goat Simulator *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\265930
Default=False
FileKey1=%Documents%\my games\GoatSim\GoatGame\Logs|*.*
[Gom Player *]
LangSecRef=3023
Detect=HKCU\Software\GRETECH\GomPlayer
Default=False
FileKey1=%AppData%\GRETECH\GomPlayer|*.bmk
RegKey1=HKCU\Software\GRETECH\GomPlayer\OPTION|sRecentPLFolder
[GoodSync *]
LangSecRef=3024
Detect=HKCU\Software\Siber Systems\GoodSync
Default=False
FileKey1=%AppData%\GoodSync|*.log|RECURSE
FileKey2=%Documents%\_gsdata_|*.log|RECURSE
[Google Apps Sync *]
LangSecRef=3022
DetectFile=%LocalAppData%\Google\Google Apps *
Default=False
FileKey1=%LocalAppData%\Google\Google Apps *|*.log|RECURSE
[Google Calendar Sync *]
LangSecRef=3022
DetectFile=%LocalAppData%\Google\Google Calendar Sync
Default=False
FileKey1=%LocalAppData%\Google\Google Calendar Sync|*.log|RECURSE
[Google Drive *]
LangSecRef=3024
Detect=HKCU\Software\Google\Drive
DetectFile=%ProgramFiles%\Google\Drive\googledrivesync.exe
Default=False
FileKey1=%LocalAppData%\Google\Drive|*.log
FileKey2=%LocalAppData%\Google\Drive\CrashReports|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Google\Drive|*.log
FileKey4=%ProgramFiles%\Google\Drive|*.log
[Google Earth *]
LangSecRef=3021
Detect1=HKCU\Software\Google\Google Earth Plus
Detect2=HKCU\Software\Google\Google Earth Pro
Detect3=HKLM\Software\Google\Google Earth Plus
Detect4=HKLM\Software\Google\Google Earth Pro
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Google\GoogleEarth\client|*.log
FileKey2=%LocalLowAppData%\Google\GoogleEarth|*.tmp;*.log|RECURSE
FileKey3=%LocalLowAppData%\Google\GoogleEarth\Cache|*.*|RECURSE
FileKey4=%LocalLowAppData%\Google\GoogleEarth\unified_cache_leveldb_*|*.*|REMOVESELF
FileKey5=%ProgramFiles%\Google\GoogleEarth\client|*.log
[Google GBScreensaver *]
LangSecRef=3021
DetectFile=%LocalAppData%\Google\GBScreensaver
Default=False
FileKey1=%LocalAppData%\Google\GBScreensaver|network.log
[Google Music Manager *]
LangSecRef=3023
Detect=HKCU\Software\Google\MusicManager
Default=False
FileKey1=%LocalAppData%\Google\MusicManager|*.log
[Google Picasa2Albums Backup *]
LangSecRef=3021
Detect=HKCU\Software\Google\Picasa
Default=False
FileKey1=%LocalAppData%\Google\Picasa2Albums\backup|*.*|REMOVESELF
[Google Talk *]
LangSecRef=3022
Detect=HKCU\Software\Google\Google Talk
DetectFile=%LocalAppData%\Google\Google Talk Plugin
Default=False
FileKey1=%LocalAppData%\Google\Google Talk Plugin|*.log
FileKey2=%LocalAppData%\Google\Google Talk\avatars|*.*
[Google Toolbar Notifier *]
LangSecRef=3022
Detect=HKCU\Software\Google\GoogleToolbarNotifier
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Google\GoogleToolbarNotifier|*.tmp|RECURSE
FileKey2=%ProgramFiles%\Google\GoogleToolbarNotifier|*.tmp|RECURSE
[Google Video Player *]
LangSecRef=3023
Detect=HKCU\Software\Google\Google Video Player
Default=False
RegKey1=HKCU\Software\Google\Google Video Player\MRUList
[GoPlayer *]
LangSecRef=3023
DetectFile=%ProgramFiles%\GoPlayer
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\GoPlayer|*.log
FileKey2=%ProgramFiles%\GoPlayer|*.log
[Gotham City Impostors *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\206210
Default=False
FileKey1=%Documents%\WB Games\Gotham City Impostors - Free To Play|*.log
[Gothic III *]
Section=Games
Detect=HKCU\Software\JoWooD Productions Software AG\Gothic III
Default=False
FileKey1=%ProgramFiles%\Gothic III|setup*.txt
[GradeKeeper *]
LangSecRef=3021
Detect=HKCU\Software\Gradekeeper
Default=False
FileKey1=%AppData%\Gradekeeper|*.*
[Gratuitous Space Battles *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\41800
Default=False
FileKey1=%Documents%\My Games\GratuitousSpaceBattles\debug|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\gratuitous space battles\data\temp|*.*|RECURSE
FileKey3=%ProgramFiles%\Steam\Steamapps\common\gratuitous space battles\data\temp|*.*|RECURSE
[Gravity Guy *]
Section=Games
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MiniclipSA.GravityGuy_gpanv85qtf6rc
DetectFile=%LocalAppData%\Packages\MiniclipSA.GravityGuy_gpanv85qtf6rc
Default=False
FileKey1=%LocalAppData%\Packages\MiniclipSA.GravityGuy_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\MiniclipSA.GravityGuy_*\AC\Microsoft\CryptnetUrlCache\*|*.*
[Green Ranch *]
Section=Games
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Green RanchFINAL
Default=False
FileKey1=%AppData%\Palaplay\GreenRanch_Survey|*.txt
[Greenfish Icon Editor Pro *]
LangSecRef=3021
DetectFile=%LocalAppData%\gfie\recent.txt
Default=False
FileKey1=%LocalAppData%\gfie|recent.txt
[Greenshot *]
LangSecRef=3024
DetectFile=%AppData%\Greenshot
Default=False
FileKey1=%LocalAppData%\Greenshot|*.log
[grepWin *]
LangSecRef=3024
Detect=HKCU\Software\grepWin
Default=False
RegKey1=HKCU\Software\grepWin|searchpath
RegKey2=HKCU\Software\grepWin\History
[GridinSoft Notepad *]
LangSecRef=3021
Detect=HKCU\Software\GridinSoft\Notepad3
Default=False
RegKey1=HKCU\Software\GridinSoft\Notepad3\Files
RegKey2=HKCU\Software\GridinSoft\Notepad3\Search|ReplaceTextHistory
RegKey3=HKCU\Software\GridinSoft\Notepad3\Search|TextHistory
[Grim Tales The Wishes CE *]
Section=Games
DetectFile=%AppData%\Elephant Games\Grim Tales The Wishes CE
Default=False
FileKey1=%AppData%\Elephant Games\Grim Tales The Wishes CE|logfile.txt
[Groove Music *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\PRICache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalCache\PlayReady\Cache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\Database\*|*.log
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageCache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageRetrievalFailure|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\ImageStore|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\LocalState\PlayReady|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.ZuneMusic_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\SearchHistory
[GroupWise Messenger *]
LangSecRef=3021
Detect=HKCU\Software\Novell\Messenger
Default=False
FileKey1=%LocalAppData%\Novell\GroupWise Messenger\history\%UserName%|*.*
[Growl *]
LangSecRef=3024
Detect=HKCU\Software\Growl
Default=False
FileKey1=%LocalAppData%\Growl\*\History|*.*|RECURSE
FileKey2=%LocalAppData%\Growl\*\ImageCache|*.*|RECURSE
FileKey3=%LocalAppData%\Growl\*\Log|*.*|RECURSE
[GSpot *]
LangSecRef=3024
Detect=HKCU\Software\GSpot Appliance Corp
Default=False
RegKey1=HKCU\Software\GSpot Appliance Corp\GSpot\v2.6 Settings|LastMediaFile
[gSyncit *]
LangSecRef=3022
DetectFile=%AppData%\gSyncit
Default=False
FileKey1=%AppData%\gSyncit|gsyncit*.*
[GT Interactive Driver *]
LangSecRef=3024
DetectFile=%ProgramFiles%\GT Interactive\Driver
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\GT Interactive\Driver|debug.log
FileKey2=%ProgramFiles%\GT Interactive\Driver|debug.log
[Guild Wars *]
Section=Games
DetectFile=%ProgramFiles%\Guild Wars
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Guild Wars|*.tmp
FileKey2=%ProgramFiles%\Guild Wars|*.tmp
[Gwent *]
Section=Games
Detect=HKCU\Software\CDProjektRED\Gwent
Default=False
FileKey1=%CommonAppData%\CDProjekt RED\Gwent\Logs|*.log
[Hacknet *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\365450
Default=False
FileKey1=%Documents%\My Games\Hacknet\Reports|*.txt
[Halite *]
LangSecRef=3021
DetectFile=%LocalAppData%\Halite
Default=False
FileKey1=%LocalAppData%\Halite|HaliteLog.txt|RECURSE
[Halite Backups *]
LangSecRef=3021
DetectFile=%LocalAppData%\Halite
Default=False
FileKey1=%LocalAppData%\Halite|Halite.xml.*|RECURSE
[Halo Spartan Assault *]
Section=Games
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.HaloSpartanAssault_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.HaloSpartanAssault_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.HaloSpartanAssault_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.HaloSpartanAssault_*\AC\Microsoft\CryptnetUrlCache\*|*.*
[HandBrake *]
LangSecRef=3024
DetectFile=%ProgramFiles%\HandBrake\Handbrake.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\HandBrake|*.stackdump
FileKey2=%ProgramFiles%\HandBrake|*.stackdump
[Handle Regshot Reports *]
LangSecRef=3024
DetectFile=%SystemDrive%\Hive
Default=False
FileKey1=%SystemDrive%\Hive|*.css;*.html;*.reg
[Handle Regshot Snapshots *]
LangSecRef=3024
DetectFile=%SystemDrive%\Hive
Default=False
Warning=This will delete all saved snapshots.
FileKey1=%SystemDrive%\Hive|*.hive
[Handy Backup *]
LangSecRef=3024
Detect=HKCU\Software\Novosoft\Handy Backup
Default=False
FileKey1=%AppData%\Novosoft\Handy Backup\logs|*.*
[HappyCloud *]
Section=Games
Detect=HKCU\Software\HappyCloud
Default=False
FileKey1=%CommonAppData%\HappyCloud|*.log
FileKey2=%CommonAppData%\HappyCloud\cache|*.*
FileKey3=%LocalAppData%\VirtualStore\ProgramData\HappyCloud|*.log
FileKey4=%LocalAppData%\VirtualStore\ProgramData\HappyCloud\cache|*.*
[Hard Drive Inspector *]
LangSecRef=3024
DetectFile=%CommonAppData%\AltrixSoft\Hard Drive Inspector
Default=False
FileKey1=%CommonAppData%\AltrixSoft\Hard Drive Inspector|log.err
FileKey2=%LocalAppData%\VirtualStore\ProgramData\AltrixSoft\Hard Drive Inspector|log.err
[Hauppauge WinTV *]
LangSecRef=3024
Detect=HKLM\Software\Hauppauge
Default=False
FileKey1=%Public%\WinTV|Settings-old.xml
FileKey2=%Public%\WinTV\Channel Database|hcwChanDB_5-lastgood.mdb
FileKey3=%Public%\WinTV\Installation Log|*.*|RECURSE
FileKey4=%Public%\WinTV\Logs|*.log;*.txt
FileKey5=%Public%\WinTV\Logs\minidump|*.*|RECURSE
FileKey6=%SystemDrive%|hcwDriverInstall.txt
[HDD Health *]
LangSecRef=3022
Detect=HKLM\System\CurrentControlSet\services\HDDHealth
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\HDD Health|*.tmp
FileKey2=%ProgramFiles%\HDD Health|*.tmp
[HDD Regenerator *]
LangSecRef=3024
DetectFile=%ProgramFiles%\HDD Regenerator
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\HDD Regenerator|*.log|RECURSE
FileKey2=%ProgramFiles%\HDD Regenerator|*.log|RECURSE
[HDD Thermometer *]
LangSecRef=3024
Detect=HKCU\Software\RSD Software, Inc.\HDD Thermometer
Default=False
FileKey1=%CommonAppData%\HDD Thermometer|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\HDD Thermometer|*.log|RECURSE
[HDDExpert *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\HDDExpert
Default=False
FileKey1=%AppData%\KC Softwares\HDDExpert|*.log
[Hedgewars VideoTemp *]
Section=Games
Detect=HKLM\Software\Hedgewars
Default=False
FileKey1=%Documents%\Hedgewars\VideoTemp|*.*
[Helium Music Manager *]
LangSecRef=3023
Detect1=HKCU\Software\Intermedia Software\Helium 8
Detect2=HKCU\Software\Intermedia Software\Helium 9
Detect3=HKCU\Software\Intermedia Software\Helium 10
Default=False
FileKey1=%AppData%\Intermedia Software\Helium *\Logs|*.*
[Heroes of a Broken Land *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\314470
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Heroes of a Broken Land\hobl_data|output_log.txt
FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Heroes of a Broken Land\hobl_data|output_log.txt
[Heroes of Newerth *]
Section=Games
Detect=HKCU\Software\Heroes of Newerth
Default=False
FileKey1=%Documents%\Heroes of Newerth\game|console.log
[Hex Chat *]
LangSecRef=3024
DetectFile=%AppData%\HexChat
Default=False
FileKey1=%AppData%\HexChat\logs|*.*|REMOVESELF
FileKey2=%AppData%\HexChat\scrollback|*.*|REMOVESELF
[Hi-Rez Studios *]
Section=Games
Detect=HKLM\Software\Hi-Rez Studios
Default=False
FileKey1=%CommonAppData%\Hi-Rez Studios\BrowserCacheTribes\Default|*.*|RECURSE
FileKey2=%CommonAppData%\Hi-Rez Studios\HiPatchService\log|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Hi-Rez Studios\hireztemp|*.*
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Hi-Rez Studios\BrowserCacheTribes\Default|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Hi-Rez Studios\HiPatchService\log|*.*
FileKey6=%ProgramFiles%\Hi-Rez Studios\hireztemp|*.*
FileKey7=%SystemDrive%|HiRezUpdateInstallLog.txt
[HijackThis Backups *]
LangSecRef=3024
Detect=HKLM\Software\TrendMicro\HijackThis
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Trend Micro\HijackThis\backups|*.*
FileKey2=%ProgramFiles%\Trend Micro\HijackThis\backups|*.*
[HitmanPro *]
LangSecRef=3024
Detect1=HKCU\Software\HitMan Pro
Detect2=HKCU\Software\HitMan Pro 2
Detect3=HKCU\Software\HitMan Pro 3
Detect4=HKLM\Software\HitmanPro
Default=False
FileKey1=%CommonAppData%\HitmanPro\Logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Hitman Pro*\downloads|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Hitman Pro*\logs|*.htm
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Hitman Pro*\updates|*.*
FileKey5=%LocalAppData%\VirtualStore\ProgramData\HitmanPro\Logs|*.*
FileKey6=%ProgramFiles%\Hitman Pro*\downloads|*.*
FileKey7=%ProgramFiles%\Hitman Pro*\logs|*.htm
FileKey8=%ProgramFiles%\Hitman Pro*\updates|*.*
[Holiday Express *]
Section=Games
Detect1=HKLM\Software\GameHouse\Holiday Express
Detect2=HKLM\Software\HipSoft\Holiday Express
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\GameHouse Games Collection\Holiday Express|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Holiday Express|*html;*.txt
FileKey3=%ProgramFiles%\GameHouse Games Collection\Holiday Express|*.txt
FileKey4=%ProgramFiles%\Holiday Express|*html;*.txt
[HomeCinema CyberLink *]
LangSecRef=3023
DetectFile=%ProgramFiles%\HomeCinema
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\HomeCinema\PowerProducer\Template\Cyberlink\frame|*tmp
FileKey2=%ProgramFiles%\HomeCinema\PowerProducer\Template\Cyberlink\frame|*tmp
[Honeyview Bookmarks *]
LangSecRef=3023
Detect=HKCU\Software\Honeyview
Default=False
RegKey1=HKCU\Software\Honeyview\BMPath0
RegKey2=HKCU\Software\Honeyview\BMPath1
RegKey3=HKCU\Software\Honeyview\BMPath2
RegKey4=HKCU\Software\Honeyview\BMPath3
RegKey5=HKCU\Software\Honeyview\BMPath4
RegKey6=HKCU\Software\Honeyview\BMPath5
RegKey7=HKCU\Software\Honeyview\BMPath6
RegKey8=HKCU\Software\Honeyview\BMPath7
RegKey9=HKCU\Software\Honeyview\BMPath8
RegKey10=HKCU\Software\Honeyview\BMPath9
RegKey11=HKCU\Software\Honeyview\BMPath10
RegKey12=HKCU\Software\Honeyview\BMPath11
RegKey13=HKCU\Software\Honeyview\BMPath12
RegKey14=HKCU\Software\Honeyview\BMPath13
RegKey15=HKCU\Software\Honeyview\BMPath14
RegKey16=HKCU\Software\Honeyview\BMPath15
RegKey17=HKCU\Software\Honeyview\BMPath16
RegKey18=HKCU\Software\Honeyview\BMPath17
RegKey19=HKCU\Software\Honeyview\BMPath18
RegKey20=HKCU\Software\Honeyview\BMPath19
RegKey21=HKCU\Software\Honeyview\BMPath20
RegKey22=HKCU\Software\Honeyview\BMPath21
RegKey23=HKCU\Software\Honeyview\BMPath22
RegKey24=HKCU\Software\Honeyview\BMPath23
RegKey25=HKCU\Software\Honeyview\BMPath24
RegKey26=HKCU\Software\Honeyview\BMPath25
RegKey27=HKCU\Software\Honeyview\BMPath26
RegKey28=HKCU\Software\Honeyview\BMPath27
RegKey29=HKCU\Software\Honeyview\BMPath28
RegKey30=HKCU\Software\Honeyview\BMPath29
[Honeyview MRU *]
LangSecRef=3023
Detect=HKCU\Software\Honeyview
Default=False
RegKey1=HKCU\Software\Honeyview\RecentFolder0
RegKey2=HKCU\Software\Honeyview\RecentFolder1
RegKey3=HKCU\Software\Honeyview\RecentFolder2
RegKey4=HKCU\Software\Honeyview\RecentFolder3
RegKey5=HKCU\Software\Honeyview\RecentFolder4
RegKey6=HKCU\Software\Honeyview\RecentFolder5
RegKey7=HKCU\Software\Honeyview\RecentFolder6
RegKey8=HKCU\Software\Honeyview\RecentFolder7
RegKey9=HKCU\Software\Honeyview\RecentFolder8
RegKey10=HKCU\Software\Honeyview\RecentFolder9
RegKey11=HKCU\Software\Honeyview\sRecentFolder
RegKey12=HKCU\Software\Honeyview\sStoreFilePath
RegKey13=HKCU\Software\Honeyview\sStoreFilePath2
RegKey14=HKCU\Software\Honeyview\transf.sTargetFolder
[Hostile Makeover *]
Section=Games
DetectFile=%AppData%\Merscom\Hostile Makeover
Default=False
FileKey1=%AppData%\Merscom\Hostile Makeover|logfile.txt
[HostsMan Backups *]
LangSecRef=3024
DetectFile=%CommonAppData%\abelhadigital.com\HostsMan
Default=False
FileKey1=%Public%\Documents\HostsMan Backups|*.*|REMOVESELF
FileKey2=%WinDir%\System32\drivers\etc|HOSTS.bak;HOSTS.tmp
[HostsMan HostsServer *]
LangSecRef=3024
Detect=HKLM\Software\abelhadigital.com\HostsServer
DetectFile=%ProgramFiles%\HostsMan\hostssrv.exe
Default=False
FileKey1=%AppData%\abelhadigital.com\HostsServer|*.log|RECURSE
FileKey2=%LocalLowAppData%\abelhadigital.com\HostsServer\Logs|*.log
[Hotbar *]
LangSecRef=3022
Detect=HKCU\Software\Hotbar
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Hotbar\*\dynamic|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Hotbar\*\static|*.*
FileKey3=%ProgramFiles%\Hotbar\*\dynamic|*.*|RECURSE
FileKey4=%ProgramFiles%\Hotbar\*\static|*.*
RegKey1=HKCU\Software\Hotbar\hotbar\ImagesHistory
[Hotline Miami *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\219150
Default=False
FileKey1=%Documents%\My Games\HotlineMiami|debug.log
[Hotspot Shield *]
LangSecRef=3021
Detect=HKLM\Software\HotspotShield
DetectFile=%ProgramFiles%\Hotspot Shield\bin\HSSCP.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Hotspot Shield\log|*.log
FileKey2=%LocalLowAppData%\Hotspot_Shield\Logs|*.*|RECURSE
FileKey3=%ProgramFiles%\Hotspot Shield\log|*.log
[Hover Desk *]
LangSecRef=3024
DetectFile=%ProgramFiles%\HoverDesk
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\HoverDesk\User|hdcmdrec.txt
FileKey2=%ProgramFiles%\HoverDesk\User|hdcmdrec.txt
[HP Drive Key Boot Utility *]
LangSecRef=3024
Detect=HKLM\Software\microsoft\windows\currentversion\uninstall\HP Drive Key Boot Utility
Default=False
FileKey1=%SystemDrive%\CPQSYSTEM|*.*|REMOVESELF
[HP Guide *]
LangSecRef=3024
DetectFile=%LocalAppData%\HP Guide
Default=False
FileKey1=%LocalAppData%\HP Guide|log1.*
FileKey2=%LocalAppData%\HP Guide\mp_cache|*.*
[HP Install Temps *]
LangSecRef=3021
Detect=HKCU\Software\HP
DetectFile=%CommonAppData%\HP
Default=False
FileKey1=%CommonAppData%\HP\Installer\Temp|*.*
FileKey2=%CommonAppData%\HP\Temp|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\HP\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\HP\Installer\Temp|*.*
FileKey5=%LocalAppData%\VirtualStore\ProgramData\HP\Temp|*.*
FileKey6=%ProgramFiles%\HP\Temp|*.*|RECURSE
FileKey7=%WinDir%|*.dat.temp
[HP Installation Files *]
LangSecRef=3024
DetectFile1=%SystemDrive%\HP Universal Print Driver
DetectFile2=%SystemDrive%\swsetup
Default=False
FileKey1=%SystemDrive%\HP Universal Print Driver|*.*|REMOVESELF
FileKey2=%SystemDrive%\swsetup|*.*|REMOVESELF
[HP Logs *]
LangSecRef=3021
Detect=HKCU\Software\HP
DetectFile1=%AppData%\hpqlog
DetectFile2=%CommonAppData%\Hewlett-Packard
DetectFile3=%CommonAppData%\HP
DetectFile4=%LocalAppData%\TouchSmartData
DetectFile5=%ProgramFiles%\HPQ\Shared\Sierra Wireless
Default=False
FileKey1=%AppData%\HP\WebRegLogs|WebRegLog.txt
FileKey2=%AppData%\hpqlog|*.log
FileKey3=%CommonAppData%|hpzinstall.log
FileKey4=%CommonAppData%\Hewlett-Packard|*.log*.*;*Log.txt|RECURSE
FileKey5=%CommonAppData%\Hewlett-Packard\HP*\Log*|*.*|RECURSE
FileKey6=%LocalAppData%\TouchSmartData\Log|*.*
FileKey7=%LocalAppData%\VirtualStore\Program Files*\HPQ\Shared\Sierra Wireless|*.log|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData|hpzinstall.log
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Hewlett-Packard\HP*\Logs|*.*|RECURSE
FileKey10=%ProgramFiles%\HPQ\Shared\Sierra Wireless|*.log|RECURSE
FileKey11=%SystemDrive%\hp\bin\logs|*.log
[HP MediaSmart Photo *]
LangSecRef=3023
DetectFile=%LocalAppData%\Hewlett-Packard\MediaSmart\Photo
Default=False
FileKey1=%LocalAppData%\Hewlett-Packard\MediaSmart\Photo|subsys.cache
FileKey2=%LocalAppData%\Hewlett-Packard\MediaSmart\Photo\tm*Cache|*.*|REMOVESELF
[HP Photosmart Premier *]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\HP Photo & Imaging
Default=False
FileKey1=%LocalAppData%\HP\Digital Imaging\cache|*.*
[HP Printer Control *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AD2F1837.HPPrinterControl_v10z8vjag6ke6
DetectFile=%LocalAppData%\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6
Default=False
FileKey1=%LocalAppData%\Packages\*HPPrinterControl_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*HPPrinterControl_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\*HPPrinterControl_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE
FileKey4=%LocalAppData%\Packages\*HPPrinterControl_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\*HPPrinterControl_*\AC\PRICache|*.*
FileKey6=%LocalAppData%\Packages\*HPPrinterControl_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\*HPPrinterControl_*\LocalState|*.*|RECURSE
[HP Scan and Capture *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\AD2F1837.HPScanandCapture_v10z8vjag6ke6
DetectFile=%LocalAppData%\Packages\AD2F1837.HPScanandCapture_v10z8vjag6ke6
Default=False
FileKey1=%LocalAppData%\Packages\*HPScanandCapture_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*HPScanandCapture_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\*HPScanandCapture_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE
FileKey4=%LocalAppData%\Packages\*HPScanandCapture_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\*HPScanandCapture_*\AC\PRICache|*.*
FileKey6=%LocalAppData%\Packages\*HPScanandCapture_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\*HPScanandCapture_*\LocalState|*.*|RECURSE
[HP Update *]
LangSecRef=3021
DetectFile=%AppData%\HPUpdate
Default=False
FileKey1=%AppData%\HpUpdate|*.*
[HTC Home Apis *]
LangSecRef=3021
DetectFile=%ProgramFiles%\HTC Home
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\HTC Home\log|*.*|RECURSE
FileKey2=%ProgramFiles%\HTC Home\log|*.*|RECURSE
[HTC Logs *]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Installer\Products\34180280D77760A4BB4517FBA01DBB07\SourceList
Default=False
FileKey1=%SystemDrive%\Temp|HSM*.txt
[HTC Sync *]
LangSecRef=3024
DetectFile=%ProgramFiles%\HTC\HTC Sync 3.0
Default=False
FileKey1=%AppData%\HTC\Logs|*.log
[HTML Help *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\HTMLHelp
Default=False
Warning=This will remove CHM position, preferences, favorites information.
FileKey1=%AppData%\Microsoft\HTML Help|hh.dat;hhcolreg.dat;*.chw
FileKey2=%CommonAppData%\Microsoft\HTML Help|hhcolreg.dat
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Microsoft\HTML Help|hhcolreg.dat
FileKey4=%WinDir%\Application Data\Microsoft\HTML Help|hh.dat
[Huawei Modem Driver *]
LangSecRef=3023
Detect=HKLM\Software\Huawei technologies
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\HUAWEI Modem Driver|*.log
FileKey2=%ProgramFiles%\HUAWEI Modem Driver|*.log
[HuluDesktop *]
LangSecRef=3023
DetectFile=%LocalAppData%\HuluDesktop
Default=False
FileKey1=%LocalAppData%\HuluDesktop\Data|*.log
[HuluPlus *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\HuluLLC.HuluPlus_fphbd361v8tya
Default=False
FileKey1=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey3=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\AC\Temp|*.*
FileKey4=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\LocalState|*.tmp|RECURSE
FileKey5=%LocalAppData%\Packages\HuluLLC.HuluPlus_*\TempState|*.*|RECURSE
[Huru Beach Party *]
Section=Games
DetectFile=%AppData%\HuruBeachParty
Default=False
FileKey1=%AppData%\HuruBeachParty|*log.html
[HxD Hexeditor *]
LangSecRef=3021
Detect=HKCU\Software\Mael\HxD
Default=False
RegKey1=HKCU\Software\Mael\HxD\History Lists\Recent Files
[Hyper for Youtube *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\19120CensoredUser.HyperforYouTube_c0tqyanwsgfn6
DetectFile=%LocalAppData%\Packages\19120CensoredUser.HyperforYouTube_c0tqyanwsgfn6
Default=False
FileKey1=%LocalAppData%\Packages\*.HyperforYouTube_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*.HyperforYouTube_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\*.HyperforYouTube_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey4=%LocalAppData%\Packages\*.HyperforYouTube_*\LocalState|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\*.HyperforYouTube_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\19120CensoredUser.HyperforYouTube_c0tqyanwsgfn6\SearchHistory
[HyperSnap 7 *]
LangSecRef=3021
Detect=HKCU\Software\Hyperionics\HyperSnap 7
Default=False
FileKey1=%ProgramFiles%\HyperSnap 7|*.url
RegKey1=HKCU\Software\Hyperionics\HyperSnap 7\Recent File List
[i-Funbox DevTeam *]
LangSecRef=3024
DetectFile=%ProgramFiles%\i-Funbox DevTeam
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\i-Funbox DevTeam|debug.log
FileKey2=%ProgramFiles%\i-Funbox DevTeam|debug.log
[I2P NetDb *]
LangSecRef=3022
DetectFile=%AppData%\I2P
Default=False
FileKey1=%AppData%\I2P\netDb|*.*
[Icaros *]
LangSecRef=3024
DetectFile=%LocalAppData%\Icaros
Default=False
FileKey1=%LocalAppData%\Icaros\IcarosCache|*.icdb
[Icon Cache *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=You may need to restart explorer.exe for this to take effect.
FileKey1=%LocalAppData%|IconCache.db
FileKey2=%LocalAppData%\Microsoft\Windows\Explorer|iconcache_*.db
[Icon Explorer *]
LangSecRef=3024
Detect=HKCU\Software\MiTeC\Icon Explorer
Default=False
RegKey1=HKCU\Software\MiTeC\Icon Explorer\4.x\wnd_icoexp_Main|de_Text
RegKey2=HKCU\Software\MiTeC\Icon Explorer\4.x\wnd_icoexp_Main|ShellTree_StartInFolder
[IconCool Editor *]
LangSecRef=3024
DetectFile=%ProgramFiles%\IconCoolEditor\IconCooleditor.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\IconCoolEditor|IconFileList.src;Recentlyused.src
FileKey2=%ProgramFiles%\IconCoolEditor|IconFileList.src;Recentlyused.src
[Icons from File *]
LangSecRef=3024
Detect=HKCU\Software\Vitaliy Levchenko\Icons from File
Default=False
RegKey1=HKCU\Software\Vitaliy Levchenko\Icons from File\Recent
[ID Privacy Shield *]
LangSecRef=3024
DetectFile=%ProgramFiles%\ID Security Suite\ID Privacy Shield
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\ID Security Suite\ID Privacy Shield\logs|*.*|RECURSE
FileKey2=%ProgramFiles%\ID Security Suite\ID Privacy Shield\logs|*.*|RECURSE
[IDEA *]
LangSecRef=3021
Detect1=HKCU\Software\JetBrains\IntelliJ IDEA
Detect2=HKCU\Software\JetBrains\IntelliJ IDEA Community Edition
Default=False
FileKey1=%UserProfile%\.IdeaC*\System\Caches|*.*
FileKey2=%UserProfile%\.IdeaC*\System\Logs|*.*
FileKey3=%UserProfile%\.IdeaC*\System\tmp|*.*|RECURSE
FileKey4=%UserProfile%\.IntelliJIdea12\system\Caches|*.*
FileKey5=%UserProfile%\.IntelliJIdea12\system\log|*.*
FileKey6=%UserProfile%\.IntelliJIdea12\system\tmp|*.*|RECURSE
[IDEA History *]
LangSecRef=3021
Detect1=HKCU\Software\JetBrains\IntelliJ IDEA
Detect2=HKCU\Software\JetBrains\IntelliJ IDEA Community Edition
Default=False
FileKey1=%UserProfile%\.IdeaC*\System\LocalHistory|*.*
FileKey2=%UserProfile%\.IntelliJIdea12\system\LocalHistory|*.*
[IdeaSoft Scrapbooks Plus 1.0 *]
LangSecRef=3021
Detect=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0
Default=False
RegKey1=HKCU\Software\IdeaSoft\Scrapbooks Plus\1.0\Recent File List
[IDLE Recent Files *]
LangSecRef=3021
Detect=HKCU\Software\Python
Default=False
FileKey1=%UserProfile%\.idlerc|recent-files.lst
[IDPhotoStudio *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\IDPhotoStudio
Default=False
FileKey1=%AppData%\KC Softwares\IDPhotoStudio|*.log
[IDT NetGUI *]
LangSecRef=3022
DetectFile=%AppData%\IDT\NetGUI
Default=False
FileKey1=%AppData%\IDT\NetGUI\Log|*.log
[IE Toy *]
LangSecRef=3024
Detect=HKCU\Software\MySoftware\IEToy
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\IE Toy\Data|history;history_ad
FileKey2=%ProgramFiles%\IE Toy\Data|history;history_ad
RegKey1=HKCU\Software\MySoftware\IEToy|FRAGS_ad
RegKey2=HKCU\Software\MySoftware\IEToy|FRAGS_popup
[IE7pro *]
LangSecRef=3022
Detect=HKCU\Software\IE7pro
Default=False
RegKey1=HKCU\Software\IE7pro\ClosedTabs
[Ignition *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\Ignition
Default=False
FileKey1=%AppData%\KC Software\Ignition|*.log
[IISExpress *]
LangSecRef=3022
DetectFile=%Documents%\IISExpress
Default=False
FileKey1=%Documents%\IISExpress\Logs|*.*
FileKey2=%Documents%\IISExpress\TraceLogFiles|*.*|RECURSE
[ImgBurn *]
LangSecRef=3021
Detect=HKCU\Software\ImgBurn
Default=False
RegKey1=HKCU\Software\ImgBurn|ISOREAD_RecentFiles_Destination
RegKey2=HKCU\Software\ImgBurn|ISOREAD_RecentFolders_Destination
[Immersive Control Panel *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\windows.immersivecontrolpanel_cw5n1h2txyewy
DetectFile=%LocalAppData%\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\PRICache|*.*
FileKey7=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\LocalState\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\LocalState\navigationHistory|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\windows.immersivecontrolpanel_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\windows.immersivecontrolpanel_cw5n1h2txyewy\SearchHistory
[Immunet *]
LangSecRef=3021
Detect=HKLM\Software\Immunet Protect
Default=False
Warning=Immunet service must be stopped to remove log files.
FileKey1=%AppData%\Immunet|*.*|REMOVESELF
FileKey2=%CommonAppData%\Immunet|*.log
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Immunet|*.log|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Immunet|*.log
FileKey5=%ProgramFiles%\Immunet|*.log|RECURSE
[iMobie *]
LangSecRef=3024
DetectFile=%AppData%\iMobie
Default=False
FileKey1=%AppData%\iMobie\*|iTunesPrefs
FileKey2=%AppData%\iMobie\*\AutoUpdate|*.*|RECURSE
FileKey3=%AppData%\iMobie\*\Configue|Settings.plist
FileKey4=%AppData%\iMobie\*\EasyLoseFiles|*.*|RECURSE
FileKey5=%AppData%\iMobie\*\ErrorLog|*.*|RECURSE
FileKey6=%AppData%\iMobie\*\Files|*.*|RECURSE
FileKey7=%AppData%\iMobie\*\iMobieConfig|*.*|RECURSE
FileKey8=%AppData%\iMobie\*\TempFiles|*.*|RECURSE
ExcludeKey1=FILE|%AppData%\iMobie\*\iMobieConfig\|ConfigReg.ini
[iMobie Backups *]
LangSecRef=3024
DetectFile=%AppData%\iMobie
Default=False
FileKey1=%AppData%\iMobie\*\*Backup|*.*|RECURSE
FileKey2=%AppData%\iMobie\Backup|*.*|RECURSE
[ImTOO iPad Video Converter *]
LangSecRef=3023
Detect=HKCU\Software\ImTOO\iPad Video Converter
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\ImTOO\iPad Video Converter|*.log;ERRORLOG.TXT
FileKey2=%ProgramFiles%\ImTOO\iPad Video Converter|*.log;ERRORLOG.TXT
[ImTOO Video Converter Ultimate *]
LangSecRef=3023
Detect=HKCU\Software\ImTOO\Video Converter Ultimate
Default=False
FileKey1=%CommonAppData%\ImTOO\Video Converter Ultimate\customdata|settings.old
RegKey1=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_openfile_dir
RegKey2=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_output_dir
RegKey3=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_profile_group
RegKey4=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|last_profile_url
RegKey5=HKCU\Software\ImTOO\Video Converter Ultimate\Settings|recent_profiles
RegKey6=HKCU\Software\ImTOO\Video Converter Ultimate\Settings\output
[IMVU *]
LangSecRef=3022
Detect=HKCU\Software\IMVU
Default=False
FileKey1=%AppData%\IMVU|*.chk|RECURSE
FileKey2=%AppData%\IMVU|*.db;mini.dmp.bak;*.pickle;*.jpg;*.txt;*.log.*;*.log
FileKey3=%AppData%\IMVU\*Cache|*.*|REMOVESELF
FileKey4=%AppData%\IMVUClient|*.icns|RECURSE
FileKey5=%AppData%\IMVUClient\installer|*.*|RECURSE
FileKey6=%AppData%\IMVUClient\ui\profile|*.sqlite;*.js;*.dat;*.mfl
FileKey7=%AppData%\IMVUClient\ui\profile\cache|*.*|REMOVESELF
[iMyFone Umate *]
LangSecRef=3024
Detect=HKLM\Software\iMyFone\Umate
Default=False
FileKey1=%ProgramFiles%\iMyFone\iMyFone Umate|mate.log
FileKey2=%ProgramFiles%\iMyFone\iMyFone Umate\cache|*.*|RECURSE
FileKey3=%ProgramFiles%\iMyFone\iMyFone Umate\Log|*.*|RECURSE
FileKey4=%ProgramFiles%\iMyFone\iMyFone Umate\temp|*.*|RECURSE
[Incredimail *]
LangSecRef=3022
Detect=HKLM\Software\Clients\Mail\IncrediMail
Default=False
Warning=This will empty the contents of your Deleted and Sent folders
FileKey1=%LocalAppData%\IM\Identities\*\Message Store|deleted items.imm;sent items.imm
[inFlow Inventory *]
LangSecRef=3021
DetectFile=%AppData%\inFlow Inventory
Default=False
FileKey1=%AppData%\inFlow Inventory|log.txt
FileKey2=%CommonAppData%\inFlow Inventory\Logs|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\inFlow Inventory\Logs|*.*
[InkScape *]
LangSecRef=3023
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\inkscape.exe
Default=False
FileKey1=%AppData%\InkScape|*.log|RECURSE
FileKey2=%LocalAppData%|recently-used.xbel
FileKey3=%UserProfile%|.recently-used.xbel
[Inky *]
LangSecRef=3022
Detect=HKCU\Software\Inky
Default=False
FileKey1=%LocalAppData%\Arcode\Plugin|*.log|RECURSE
FileKey2=%LocalAppData%\Inky|data_*;f_*;index;*.log
FileKey3=%LocalAppData%\Inky\Local Storage|*.*
[Inno Setup *]
LangSecRef=3021
Detect=HKCU\Software\Jordan Russell\Inno Setup
Default=False
RegKey1=HKCU\Software\Jordan Russell\Inno Setup\ScriptFileHistoryNew
[InnoExtractor *]
LangSecRef=3024
DetectFile1=%AppData%\InnoExtractor\InnoExtractor.exe
DetectFile2=%LocalAppData%\InnoExtractor\InnoExtractor.exe
DetectFile3=%ProgramFiles%\InnoExtractor\InnoExtractor.exe
DetectFile4=%SystemDrive%\Programs\InnoExtractor\InnoExtractor.exe
Default=False
FileKey1=%AppData%\InnoExtractor|Historial.dat
FileKey2=%LocalAppData%\InnoExtractor|Historial.dat
FileKey3=%ProgramFiles%\InnoExtractor|Historial.dat
FileKey4=%SystemDrive%\Programs\InnoExtractor|Historial.dat
[InnoTab *]
LangSecRef=3021
DetectFile=%CommonAppData%\VTech\DA
Default=False
FileKey1=%CommonAppData%\VTech\DA|*.log;InnoTab.txt;IntallLog.txt|RECURSE
FileKey2=%CommonAppData%\VTech\DA\InnoTab\ConsoleLog|*.*
FileKey3=%CommonAppData%\VTech\DA\InnoTab\Games\tmp|*.*|REMOVESELF
FileKey4=%LocalAppData%\VirtualStore\ProgramData\VTech\DA|*.log;InnoTab.txt;IntallLog.txt|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\VTech\DA\InnoTab\ConsoleLog|*.*
FileKey6=%LocalAppData%\VirtualStore\ProgramData\VTech\DA\InnoTab\Games\tmp|*.*|REMOVESELF
[Inpaint *]
LangSecRef=3021
Detect=HKCU\Software\Teorex\Inpaint
Default=False
RegKey1=HKCU\Software\Teorex\Inpaint\Recent File List
RegKey2=HKCU\Software\Teorex\Inpaint\RecentFileList
[inSSIDer Home *]
LangSecRef=3024
Detect=HKCU\Software\MetaGeek, LLC\inSSIDer Home
Default=False
FileKey1=%LocalAppData%\MetaGeek,_LLC|ConnectionErrorLog;MetaGeek-OUI.backup
[InstallShield *]
LangSecRef=3024
Detect=HKCU\Software\InstallShield
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\InstallShield Installation Information|*.log|RECURSE
FileKey2=%ProgramFiles%|_ISTMP1.DIR
FileKey3=%ProgramFiles%\InstallShield Installation Information|*.log|RECURSE
FileKey4=%SystemDrive%|_ISTMP*.DIR
RegKey1=HKCU\Software\InstallShield\16.0\Professional\Recent File List
RegKey2=HKCU\Software\InstallShield\17.0\Professional\Recent File List
RegKey3=HKCU\Software\InstallShield\18.0\Professional\Recent File List
RegKey4=HKCU\Software\InstallShield\19.0\Professional\Recent File List
RegKey5=HKCU\Software\InstallShield\20.0\Professional\Recent File List
RegKey6=HKCU\Software\InstallShield\21.0\Professional\Recent File List
RegKey7=HKCU\Software\InstallShield\InstallShield Cabinet and Log File Viewer\Recent File List
RegKey8=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU1
RegKey9=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU2
RegKey10=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU3
RegKey11=HKCU\Software\InstallShield\InstallShield Professional\6.0\IsCabVu|MRU4
[Instant Dungeon! *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\326720
Default=False
FileKey1=%AppData%\Instant Dungeon|log.txt
[Instantbird *]
LangSecRef=3022
DetectFile=%AppData%\Instantbird
Default=False
FileKey1=%AppData%\Instantbird\Crash Reports|*.*|RECURSE
FileKey2=%AppData%\Instantbird\Profiles|*.corrupt|RECURSE
FileKey3=%AppData%\Instantbird\Profiles\*|extensions.log
FileKey4=%AppData%\Instantbird\Profiles\*\icons|*.*|RECURSE
FileKey5=%AppData%\Instantbird\Profiles\*\logs|*.*|RECURSE
FileKey6=%AppData%\Instantbird\Profiles\*\minidumps|*.*|RECURSE
FileKey7=%LocalAppData%\Instantbird\Profiles\*\*cache|*.*|RECURSE
FileKey8=%LocalAppData%\Instantbird\Profiles\*\Updates|*.log|RECURSE
FileKey9=%ProgramFiles%\Instantbird|install.log
[InstEd *]
LangSecRef=3024
Detect=HKCU\Software\instedit.com\insted
Default=False
RegKey1=HKCU\Software\instedit.com\insted\MRU
[Intel Extreme Tuning Utility *]
LangSecRef=3024
DetectFile=%CommonAppData%\Intel\Intel Extreme Tuning Utility
Default=False
FileKey1=%CommonAppData%\Intel\Intel Extreme Tuning Utility\Logs|*.*
[Intel iCLS Client *]
LangSecRef=3024
DetectFile=%CommonAppData%\Intel\iCLS Client
Default=False
FileKey1=%CommonAppData%\Intel\iCLS Client|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Intel\iCLS Client|*.log
[Intel Installation Logs *]
LangSecRef=3024
Detect1=HKCU\Software\Intel
Detect2=HKLM\Software\Intel
Default=False
FileKey1=%CommonAppData%\intel|*.log|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Intel\InfInst|*.*|REMOVESELF
FileKey3=%ProgramFiles%\Intel\InfInst|*.*|REMOVESELF
FileKey4=%SystemDrive%\Intel\Logs|*.*|REMOVESELF
FileKey5=%UserProfile%\Intel\Logs|*.*|REMOVESELF
FileKey6=%WinDir%\debug\intel\logs|*.*|REMOVESELF
FileKey7=%WinDir%\System32\config\systemprofile\Intel\Logs|*.*|REMOVESELF
FileKey8=%WinDir%\SysWOW64\config\systemprofile\Intel\Logs|*.*|REMOVESELF
[Intel Rapid Storage Technology *]
LangSecRef=3021
DetectFile=%SystemDrive%\Driver_allOS\MEI\Drivers\MEI\INTERNAL
Default=False
FileKey1=%SystemDrive%\Driver_allOS\MEI\Drivers\MEI\INTERNAL|*.log|RECURSE
[Intel Storage Counters *]
LangSecRef=3024
DetectFile=%WinDir%\Inf\Intel Storage Counters
Default=False
FileKey1=%WinDir%\Inf\Intel Storage Counters|*.tmp|RECURSE
[Inter-Tel Device *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Inter-Tel
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Inter-Tel|*.log|RECURSE
FileKey2=%ProgramFiles%\Inter-Tel|*.log|RECURSE
[InterAction studios CI2rmdemo *]
Section=Games
DetectFile=%CommonAppData%\InterAction studios\CI2rmdemo
Default=False
FileKey1=%CommonAppData%\InterAction studios\CI2rmdemo|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\InterAction studios\CI2rmdemo|*.log|RECURSE
[Internet Business Promoter *]
LangSecRef=3022
DetectFile=%AppData%\IBP
Default=False
FileKey1=%AppData%\IBP|*Log.txt;*.bak|RECURSE
[Internet Download Manager *]
LangSecRef=3022
Detect=HKCU\Software\DownloadManager
Default=False
Warning=This will delete unfinished downloads.
FileKey1=%AppData%\IDM|*.Log;*.txt
FileKey2=%AppData%\IDM\DwnlData|*.*|REMOVESELF
FileKey3=%ProgramFiles%\Internet Download Manager|*.log
RegKey1=HKCU\Software\DownloadManager\1
RegKey2=HKCU\Software\DownloadManager\2
RegKey3=HKCU\Software\DownloadManager\3
RegKey4=HKCU\Software\DownloadManager\4
RegKey5=HKCU\Software\DownloadManager\5
RegKey6=HKCU\Software\DownloadManager\6
RegKey7=HKCU\Software\DownloadManager\7
RegKey8=HKCU\Software\DownloadManager\8
RegKey9=HKCU\Software\DownloadManager\9
RegKey10=HKCU\Software\DownloadManager\10
RegKey11=HKCU\Software\DownloadManager\11
RegKey12=HKCU\Software\DownloadManager\12
RegKey13=HKCU\Software\DownloadManager\13
RegKey14=HKCU\Software\DownloadManager\14
RegKey15=HKCU\Software\DownloadManager\15
RegKey16=HKCU\Software\DownloadManager\16
RegKey17=HKCU\Software\DownloadManager\17
RegKey18=HKCU\Software\DownloadManager\18
RegKey19=HKCU\Software\DownloadManager\19
RegKey20=HKCU\Software\DownloadManager\20
RegKey21=HKCU\Software\DownloadManager\21
RegKey22=HKCU\Software\DownloadManager\22
RegKey23=HKCU\Software\DownloadManager\23
RegKey24=HKCU\Software\DownloadManager\24
RegKey25=HKCU\Software\DownloadManager\25
RegKey26=HKCU\Software\DownloadManager\26
RegKey27=HKCU\Software\DownloadManager\27
RegKey28=HKCU\Software\DownloadManager\28
RegKey29=HKCU\Software\DownloadManager\29
RegKey30=HKCU\Software\DownloadManager\30
RegKey31=HKCU\Software\DownloadManager\31
RegKey32=HKCU\Software\DownloadManager\32
RegKey33=HKCU\Software\DownloadManager\33
RegKey34=HKCU\Software\DownloadManager\34
RegKey35=HKCU\Software\DownloadManager\35
RegKey36=HKCU\Software\DownloadManager\36
RegKey37=HKCU\Software\DownloadManager\37
RegKey38=HKCU\Software\DownloadManager\38
RegKey39=HKCU\Software\DownloadManager\39
RegKey40=HKCU\Software\DownloadManager\40
RegKey41=HKCU\Software\DownloadManager\41
RegKey42=HKCU\Software\DownloadManager\42
RegKey43=HKCU\Software\DownloadManager\43
RegKey44=HKCU\Software\DownloadManager\44
RegKey45=HKCU\Software\DownloadManager\45
RegKey46=HKCU\Software\DownloadManager\46
RegKey47=HKCU\Software\DownloadManager\47
RegKey48=HKCU\Software\DownloadManager\48
RegKey49=HKCU\Software\DownloadManager\49
RegKey50=HKCU\Software\DownloadManager\50
RegKey51=HKCU\Software\DownloadManager\51
RegKey52=HKCU\Software\DownloadManager\52
RegKey53=HKCU\Software\DownloadManager\53
RegKey54=HKCU\Software\DownloadManager\54
RegKey55=HKCU\Software\DownloadManager\55
RegKey56=HKCU\Software\DownloadManager\56
RegKey57=HKCU\Software\DownloadManager\57
RegKey58=HKCU\Software\DownloadManager\58
RegKey59=HKCU\Software\DownloadManager\59
RegKey60=HKCU\Software\DownloadManager\60
RegKey61=HKCU\Software\DownloadManager\61
RegKey62=HKCU\Software\DownloadManager\62
RegKey63=HKCU\Software\DownloadManager\63
RegKey64=HKCU\Software\DownloadManager\64
RegKey65=HKCU\Software\DownloadManager\65
RegKey66=HKCU\Software\DownloadManager\66
RegKey67=HKCU\Software\DownloadManager\67
RegKey68=HKCU\Software\DownloadManager\68
RegKey69=HKCU\Software\DownloadManager\69
RegKey70=HKCU\Software\DownloadManager\70
RegKey71=HKCU\Software\DownloadManager\71
RegKey72=HKCU\Software\DownloadManager\72
RegKey73=HKCU\Software\DownloadManager\73
RegKey74=HKCU\Software\DownloadManager\74
RegKey75=HKCU\Software\DownloadManager\75
RegKey76=HKCU\Software\DownloadManager\maxID
[Internet Explorer *]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Internet Explorer
Default=False
FileKey1=%AppData%\Microsoft\Internet Explorer\UserData|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\AppCache|*.*|RECURSE
FileKey3=%LocalAppData%\Microsoft\Windows\IECompat*Cache|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Windows\INetCache|*.*|RECURSE
FileKey5=%LocalAppData%\Microsoft\Windows\INetCookies|*.*|RECURSE
FileKey6=%LocalAppData%\Microsoft\Windows\WebCache|*.*|RECURSE
FileKey7=%LocalAppData%\Microsoft\Windows\WebCache.old|*.*|REMOVESELF
FileKey8=%LocalAppData%\Packages\windows_ie_ac_*\AC\AppCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\windows_ie_ac_*\AC\IECompat*Cache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\windows_ie_ac_*\AC\IEDownloadHistory|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\windows_ie_ac_*\AC\INet*|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey14=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\windows_ie_ac_*\AC\Microsoft\Internet Explorer\Emie*List|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\windows_ie_ac_*\AC\PRICache|*.*|RECURSE
FileKey17=%LocalAppData%\Packages\windows_ie_ac_*\AC\Temp|*.*|RECURSE
FileKey18=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\Cache|*.*|RECURSE
FileKey19=%LocalAppData%\Packages\windows_ie_ac_*\LocalState\navigationHistory|*.*|RECURSE
FileKey20=%LocalAppData%\Packages\windows_ie_ac_*\TempState|*.*|RECURSE
FileKey21=%WinDir%\System32\config\Systemprofile\AppData\Local\Microsoft\Windows\INetCache|*.*|RECURSE
RegKey1=HKCR\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage
RegKey2=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore
RegKey3=HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage
RegKey4=HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl
RegKey5=HKCU\Software\Microsoft\Internet Explorer\Recovery\PendingDelete
RegKey6=HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
ExcludeKey1=FILE|%LocalAppData%\Microsoft\Windows\INetCache\IE\|container.dat
ExcludeKey2=FILE|%LocalAppData%\Packages\windows_ie_ac_*\AC\INetCache\|container.dat
[Internet Explorer Vault *]
DetectOS=6.2|
LangSecRef=3031
Detect=HKCU\Software\Microsoft\Internet Explorer
Default=False
Warning=This will clear the saved passwords in the Windows Mail App
FileKey1=%LocalAppData%\Microsoft\Vault\*|*.vcrd
[Intuit Data Protect *]
LangSecRef=3024
DetectFile=%LocalAppData%\Intuit\Intuit Data Protect
Default=False
FileKey1=%CommonAppData%\Intuit\Intuit Data Protect|*.log
FileKey2=%LocalAppData%\Intuit\Intuit Data Protect|*.log
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Intuit\Intuit Data Protect|*.log
[Intuit Entitlement Client *]
LangSecRef=3021
DetectFile=%CommonAppData%\Intuit\Entitlement Client
Default=False
FileKey1=%CommonAppData%\Intuit\Entitlement Client\*|IntuitEntitlementLog*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Intuit\Entitlement Client\*|IntuitEntitlementLog*.*
[Intuit PTI *]
LangSecRef=3021
DetectFile=%AppData%\Intuit\PTI
Default=False
FileKey1=%AppData%\Intuit\PTI\Log|*.*
[Intuit TurboTax *]
LangSecRef=3021
DetectFile=%ProgramFiles%\TurboTax*
Default=False
FileKey1=%AppData%\Intuit*|*.log|RECURSE
FileKey2=%CommonAppData%|*.bc
FileKey3=%CommonAppData%\Intuit*|*.log|RECURSE
FileKey4=%CommonAppData%\Intuit\Common\Metrix\*\Logs|*.*
FileKey5=%CommonAppData%\Intuit\Common\QuickBaseClient\*\Logs|*.*
FileKey6=%CommonAppData%\Intuit\Common\Update Service\*\Logs|*.*
FileKey7=%CommonAppData%\Intuit\TurboTax\MSI\*\Logs|*.*
FileKey8=%CommonProgramFiles%\Intuit\Internet Client|Msdun13.exe
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Common Files\Intuit\Internet Client|Msdun13.exe
FileKey10=%LocalAppData%\VirtualStore\Program Files*\TurboTax*|*.txt
FileKey11=%LocalAppData%\VirtualStore\ProgramData|*.bc
FileKey12=%LocalAppData%\VirtualStore\ProgramData\Intuit*|*.log|RECURSE
FileKey13=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\Metrix\*\Logs|*.*
FileKey14=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\QuickBaseClient\*\Logs|*.*
FileKey15=%LocalAppData%\VirtualStore\ProgramData\Intuit\Common\Update Service\*\Logs|*.*
FileKey16=%LocalAppData%\VirtualStore\ProgramData\Intuit\TurboTax\MSI\*\Logs|*.*
FileKey17=%ProgramFiles%\TurboTax*|*.txt
[IObit Advanced SystemCare *]
LangSecRef=3024
DetectFile1=%AppData%\IObit\Advanced SystemCare V*
DetectFile2=%CommonAppData%\IObit\Advanced SystemCare V*
Default=False
FileKey1=%AppData%\IObit\Advanced SystemCare *|*.log
FileKey2=%AppData%\IObit\Advanced SystemCare *\Boottime|*.log
FileKey3=%AppData%\IObit\Advanced SystemCare *\EmptyFolder|*.*|RECURSE
FileKey4=%AppData%\IObit\Advanced SystemCare *\Log|*.*|RECURSE
FileKey5=%CommonAppData%\IObit\Advanced SystemCare *\Log|*.*|REMOVESELF
FileKey6=%CommonAppData%\IObit\ASCDownloader|*.log
FileKey7=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *|*.log;*.txt|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *\*.cab_Temp|*.*|REMOVESELF
FileKey9=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare *\ASCServiceLog|*.*|RECURSE
FileKey10=%LocalAppData%\VirtualStore\ProgramData\IObit\Advanced SystemCare *\Log|*.*|RECURSE
FileKey11=%LocalAppData%\VirtualStore\ProgramData\IObit\ASCDownloader|*.log
FileKey12=%ProgramFiles%\IObit\Advanced SystemCare *|*.log;*.txt|RECURSE
FileKey13=%ProgramFiles%\IObit\Advanced SystemCare *\*.cab_Temp|*.*|REMOVESELF
FileKey14=%ProgramFiles%\IObit\Advanced SystemCare *\ASCServiceLog|*.*|RECURSE
FileKey15=%SystemDrive%\Users\Default\AppData\Roaming\IObit\Advanced SystemCare *|*.log
FileKey16=%WinDir%\System32\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare *|*.log
FileKey17=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare *|*.log
[IObit Advanced SystemCare Antivirus Backup *]
LangSecRef=3024
DetectFile=%ProgramFiles%\IObit\Advanced SystemCare Ultimate
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\IObit\Advanced SystemCare Ultimate\Antivirus\BackupRec|*.*|RECURSE
FileKey2=%ProgramFiles%\IObit\Advanced SystemCare Ultimate\Antivirus\BackupRec|*.*|RECURSE
[IObit Driver Booster *]
LangSecRef=3024
DetectFile=%AppData%\IObit\Driver Booster
Default=False
FileKey1=%AppData%\IObit\Driver Booster|*.log|RECURSE
FileKey2=%ProgramFiles%\IObit\Driver Booster|*.log
[IObit Game Booster *]
LangSecRef=3024
DetectFile=%ProgramFiles%\IObit\Game Booster 3
Default=False
FileKey1=%CommonAppData%\IObit\Game Booster 3|Defrags.ini
FileKey2=%LocalAppData%\VirtualStore\Program Files*\IObit\Game Booster 3|*.log
FileKey3=%LocalAppData%\VirtualStore\Program Files*\IObit\Game Booster 3\FPS|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\IObit\Game Booster 3\Update|Update.tmp
FileKey5=%LocalAppData%\VirtualStore\ProgramData\IObit\Game Booster 3|Defrags.ini
FileKey6=%ProgramFiles%\IObit\Game Booster 3|*.log
FileKey7=%ProgramFiles%\IObit\Game Booster 3\FPS|*.*|RECURSE
FileKey8=%ProgramFiles%\IObit\Game Booster 3\Update|Update.tmp
[IObit Game Booster Backup *]
LangSecRef=3024
DetectFile=%ProgramFiles%\IObit\Game Booster 3
Default=False
Warning=This will delete your GameBox applications.
FileKey1=%CommonAppData%\IObit\Game Booster 3|TweaksBackup.reg
FileKey2=%LocalAppData%\VirtualStore\ProgramData\IObit\Game Booster 3|TweaksBackup.reg
[IObit KB Downloader *]
LangSecRef=3024
DetectFile=%CommonAppData%\IObit\KBDownloader
Default=False
FileKey1=%CommonAppData%\IObit\KBDownloader|*.*|RECURSE
[IObit LiveUpdate *]
LangSecRef=3024
DetectFile=%ProgramFiles%\IObit\LiveUpdate
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\IObit\LiveUpdate|*.log|RECURSE
FileKey2=%ProgramFiles%\IObit\LiveUpdate|*.log|RECURSE
[IObit Uninstaller *]
LangSecRef=3024
DetectFile=%AppData%\IObit\IObit Uninstaller
Default=False
FileKey1=%AppData%\IObit\IObit Uninstaller\*Log|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\IObit\iObit Uninstaller|*.log|RECURSE
FileKey3=%ProgramFiles%\IObit\iObit Uninstaller|*.log|RECURSE
[iPod-Cloner *]
LangSecRef=3023
Detect=HKCU\Software\iPod-Cloner
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\iPod-Cloner|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\iPod-Cloner\ReadCache|*.*
FileKey3=%ProgramFiles%\iPod-Cloner|*.log
FileKey4=%ProgramFiles%\iPod-Cloner\ReadCache|*.*
FileKey5=%SystemDrive%|dtdlog.txt
[iResizer *]
LangSecRef=3021
Detect=HKCU\Software\Teorex\iResizer
Default=False
RegKey1=HKCU\Software\Teorex\iResizer\RecentFileList
[iSkysoft Helper Compact *]
LangSecRef=3021
DetectFile=%CommonProgramFiles%\iSkysoft\iSkysoft Helper Compact
Default=False
FileKey1=%CommonProgramFiles%\iSkysoft\iSkysoft Helper Compact|ProductUpdateLists.xml;ISHelper.exe_temp;ISHelperSetup.exe_temp
FileKey2=%CommonProgramFiles%\iSkysoft\iSkysoft Helper Compact\DATADICT|*.*|RECURSE
FileKey3=%CommonProgramFiles%\iSkysoft\iSkysoft Helper Compact\log|*.*|RECURSE
FileKey4=%CommonProgramFiles%\iSkysoft\iSkysoft Helper Compact\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Common Files\iSkysoft\iSkysoft Helper Compact|ProductUpdateLists.xml;ISHelper.exe_temp;ISHelperSetup.exe_temp
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Common Files\iSkysoft\iSkysoft Helper Compact\log|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Common Files\iSkysoft\iSkysoft Helper Compact\Temp|*.*|RECURSE
RegKey1=HKLM\Software\iSkysoft\iSkysoft Helper Compact
RegKey2=HKLM\Software\Wow6432Node\iSkysoft\iSkysoft Helper Compact
[iSkysoft Video Converter *]
LangSecRef=3023
Detect1=HKLM\Software\iSkysoft\iSkysoft Video Converter
Detect2=HKLM\Software\iSkysoft\iSkysoft Video Converter Ultimate
Default=False
FileKey1=%CommonAppData%\iSkysoft Video Converter*|*.dat.bak
FileKey2=%CommonAppData%\iSkysoft Video Converter*\Temp*Dir|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\iSkysoft\Video Converter*\Log|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\iSkysoft\Video Converter*\TempThumbDir|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\iSkysoft Video Converter*|*.dat.bak
FileKey6=%LocalAppData%\VirtualStore\ProgramData\iSkysoft Video Converter*\Temp*Dir|*.*|RECURSE
FileKey7=%ProgramFiles%\iSkysoft\Video Converter*\Log|*.*|RECURSE
FileKey8=%ProgramFiles%\iSkysoft\Video Converter*\TempThumbDir|*.*|RECURSE
[iSpy *]
LangSecRef=3021
Detect=HKCU\Software\ISpy\ISPY
Default=False
FileKey1=%AppData%\iSpy\WebServerRoot\Media|*.*|RECURSE
FileKey2=%LocalAppData%\iSpy\WebServerRoot\Media|*.*|RECURSE
[iSysCleaner *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Utils\iSysCleaner\iSysCleaner.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Utils\iSysCleaner\traces|*.*
FileKey2=%ProgramFiles%\Utils\iSysCleaner\traces|*.*
[iTunes *]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\iTunes
Default=False
FileKey1=%AppData%\Apple Computer\iTunes|*.ipcc;*.ipsw;*.log
FileKey2=%AppData%\Apple Computer\iTunes\Cookies|Cookies.binarycookies
FileKey3=%AppData%\Apple Computer\Logs|*.*|RECURSE
FileKey4=%CommonAppData%\Apple Computer\iTunes\iPhone Temporary Files|*.*|RECURSE
FileKey5=%LocalAppData%\Apple Computer\iTunes|Cache.db
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Apple Computer\iTunes\iPhone Temporary Files|*.*|RECURSE
FileKey7=%Music%\iTunes|*.tmp|RECURSE
FileKey8=%Music%\iTunes\Album Artwork\Cache|*.*|RECURSE
FileKey9=%UserProfile%\Apple Computer\logs|*.log
FileKey10=%WinDir%\System32\config\systemprofile\AppData\Roaming\Apple Computer\Logs|*.*|RECURSE
FileKey11=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Apple Computer\Logs|*.*|RECURSE
[iTunes Previous Libraries *]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\iTunes
Default=False
FileKey1=%Music%\iTunes\Previous iTunes Libraries|*.*|RECURSE
[iWisoft Free Video Converter *]
LangSecRef=3023
DetectFile=%ProgramFiles%\iWisoft Free Video Converter
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\iWisoft Free Video Converter|VideoConverter.log
FileKey2=%ProgramFiles%\iWisoft Free Video Converter|VideoConverter.log
[iXL *]
LangSecRef=3021
DetectFile=%AppData%\Fisher-Price\iXL
Default=False
FileKey1=%AppData%\Fisher-Price\iXL\Log|*.*
[iZotope RX 2 Session Data *]
LangSecRef=3021
DetectFile=%AppData%\iZotope\iZotope RX 2 Session Data
Default=False
FileKey1=%AppData%\iZotope\iZotope RX 2 Session Data|*.*|RECURSE
[Jabbear *]
LangSecRef=3022
Detect=HKCU\Software\Jabbear
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Jabbear|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Jabbear\avatars|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Jabbear\cachedir|*.*|RECURSE
FileKey4=%ProgramFiles%\Jabbear|*.log|RECURSE
FileKey5=%ProgramFiles%\Jabbear\avatars|*.*|RECURSE
FileKey6=%ProgramFiles%\Jabbear\cachedir|*.*|RECURSE
[Jabbear Chat History *]
LangSecRef=3022
Detect=HKCU\Software\Jabbear
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Jabbear\Users|*.dat;*.html|RECURSE
FileKey2=%ProgramFiles%\Jabbear\Users|*.dat;*.html|RECURSE
[Jagex Cache *]
Section=Games
DetectFile=%UserProfile%\jagexcache
Default=False
FileKey1=%UserProfile%\jagex*|*.*|RECURSE
FileKey2=%WinDir%\.jagex*|*.*|REMOVESELF
ExcludeKey1=PATH|%UserProfile%\jagexcache\jagexlauncher\|*.*
[JAJC *]
LangSecRef=3022
DetectFile=%UserProfile%\JAJC
Default=False
FileKey1=%UserProfile%\JAJC\Avatars|*.*|RECURSE
FileKey2=%UserProfile%\JAJC\Logs|*.*|RECURSE
[Jalatext *]
LangSecRef=3021
DetectFile=%UserProfile%\.jalatext
Default=False
FileKey1=%UserProfile%\.jalatext\log|*.*
[jAnrufmonitor *]
LangSecRef=3025
DetectFile=%ProgramFiles%\jAnrufmonitor
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\jAnrufmonitor\data|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\jAnrufmonitor\lib\cache|classloader.cache.log
FileKey3=%LocalAppData%\VirtualStore\Program Files*\jAnrufmonitor\logs|*.*
FileKey4=%ProgramFiles%\jAnrufmonitor\data|*.log
FileKey5=%ProgramFiles%\jAnrufmonitor\lib\cache|classloader.cache.log
FileKey6=%ProgramFiles%\jAnrufmonitor\logs|*.*
[Jasc Animation Shop *]
LangSecRef=3023
Detect=HKCU\Software\Jasc\animation shop
Default=False
RegKey1=HKCU\Software\JASC\Animation Shop\Cache
[Java *]
LangSecRef=3022
Detect1=HKLM\Software\JavaSoft\Java Plug-in
Detect2=HKLM\Software\JavaSoft\Java Runtime Environment
Detect3=HKLM\Software\JavaSoft\Java Web Start
Default=False
FileKey1=%AppData%\Sun\Java\Deployment\SystemCache|*.*|RECURSE
FileKey2=%CommonAppData%\Oracle\Java\.oracle_jre_usage|*.*
FileKey3=%LocalAppData%\Sun\Java\Deployment\*Cache|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Java\jre*|*PATCH.ERR
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Java\jre*\lib\security|*.bak
FileKey6=%LocalLowAppData%\Sun\Java\Deployment\SystemCache|*.*|RECURSE
FileKey7=%ProgramFiles%\Java\jre*|*PATCH.ERR
FileKey8=%ProgramFiles%\Java\jre*\lib\security|*.bak
FileKey9=%SystemDrive%\Users\*\.oracle_jre_usage|*.*|REMOVESELF
FileKey10=%WinDir%\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\Cache|*.*|RECURSE
FileKey11=%WinDir%\SysWOW64\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\Cache|*.*|RECURSE
[Java Setup Files *]
LangSecRef=3022
Detect=HKLM\Software\JavaSoft\Java Runtime Environment
Default=False
FileKey1=%AppData%\Sun\Java\jre*|*.*|REMOVESELF
FileKey2=%CommonAppData%\Oracle\Java\installcache|*.*|RECURSE
FileKey3=%LocalLowAppData%\Oracle\Java\jdk*|*.*|REMOVESELF
FileKey4=%LocalLowAppData%\Oracle\Java\jre*|*.*|REMOVESELF
FileKey5=%LocalLowAppData%\Sun\Java\jdk*|*.*|REMOVESELF
FileKey6=%LocalLowAppData%\Sun\Java\jre*|*.*|REMOVESELF
[JavaRa *]
LangSecRef=3022
DetectFile1=%ProgramFiles%\JavaRa 2.0\JavaRa.exe
DetectFile2=%ProgramFiles%\JavaRa\JavaRa.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\JavaRa 2.0|*.log|RECURSE
FileKey2=%ProgramFiles%\JavaRa 2.0|*.log|RECURSE
FileKey3=%SystemDrive%|JavaRa.log
[JDownloader *]
LangSecRef=3022
Detect=HKLM\Software\JDownloader
DetectFile=%ProgramFiles%\JDownloader
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\JDownloader*|*.log;updateLog.txt;*.lck;*.log.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\.junique|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\captchas|*.*
FileKey4=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\container|*.*
FileKey5=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\downloads|*.*
FileKey6=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\tmp\linksave|*.*
FileKey7=%ProgramFiles%\JDownloader*|*.log;updateLog.txt;*.lck;*.log.*|RECURSE
FileKey8=%ProgramFiles%\JDownloader*\.junique|*.*
FileKey9=%ProgramFiles%\JDownloader*\captchas|*.*
FileKey10=%ProgramFiles%\JDownloader*\container|*.*
FileKey11=%ProgramFiles%\JDownloader*\downloads|*.*
FileKey12=%ProgramFiles%\JDownloader*\tmp\linksave|*.*
FileKey13=%UserProfile%\.jd_home|JDownloader.log
FileKey14=%UserProfile%\.jd_home\logs|*.0
[JDownloader Backup *]
LangSecRef=3022
Detect=HKLM\Software\JDownloader
DetectFile=%ProgramFiles%\JDownloader
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\JDownloader*\backup|*.*
FileKey2=%ProgramFiles%\JDownloader*\backup|*.*
[JDownloader2 *]
LangSecRef=3022
Detect=HKLM\Software\Classes\JDownloader2
DetectFile=%ProgramFiles%\JDownloader 2
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*|JDownloader.log;Updater_*-*-*.log;SessionInstallLog.json.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*\captchas|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*\cfg|CaptchaDialogDimensions_*.json
FileKey4=%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*\logs|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*\tmp|*.*|RECURSE
FileKey6=%ProgramFiles%\JDownloader*2*|JDownloader.log;Updater_*-*-*.log;SessionInstallLog.json.*|RECURSE
FileKey7=%ProgramFiles%\JDownloader*2*\captchas|*.*|RECURSE
FileKey8=%ProgramFiles%\JDownloader*2*\cfg|CaptchaDialogDimensions_*.json
FileKey9=%ProgramFiles%\JDownloader*2*\logs|*.*|RECURSE
FileKey10=%ProgramFiles%\JDownloader*2*\tmp|*.*|RECURSE
ExcludeKey1=PATH|%LocalAppData%\VirtualStore\Program Files*\JDownloader*2*\cfg\|subconf_*.ejs
ExcludeKey2=PATH|%ProgramFiles%\JDownloader*2*\cfg\|subconf_*.ejs
[jEdit *]
LangSecRef=3021
DetectFile=%UserProfile%\.jedit
Default=False
FileKey1=%UserProfile%\.jedit|*.log|RECURSE
FileKey2=%UserProfile%\.jedit\jars-cache|*.*|RECURSE
[JetBrains dotPeek v1.1 *]
LangSecRef=3024
Detect=HKLM\Software\JetBrains\dotPeek
Default=False
FileKey1=%LocalAppData%\JetBrains\dotPeek\v1.1\Caches|*.*|REMOVESELF
[Jetclean *]
LangSecRef=3024
DetectFile=%ProgramFiles%\BlueSprig\JetClean\JetClean.exe
Default=False
FileKey1=%AppData%\BlueSprig\JetClean\Log|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\BlueSprig\JetClean\Update|*.*|REMOVESELF
FileKey3=%ProgramFiles%\BlueSprig\JetClean\Update|*.*|REMOVESELF
[JetDrive *]
LangSecRef=3024
DetectFile=%ProgramFiles%\JetDrive
Default=False
FileKey1=%LocalAppData%\Abelssoft\JetDrive|JetDrive.reports.xml
FileKey2=%LocalAppData%\VirtualStore\Program Files*\JetDrive|JetDrive.log
FileKey3=%ProgramFiles%\JetDrive|JetDrive.log
[Jetico Personal Firewall *]
LangSecRef=3022
Detect=HKLM\Software\Jetico\Personal Firewall
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Jetico\Jetico Personal Firewall|firewall*.log
FileKey2=%ProgramFiles%\Jetico\Jetico Personal Firewall|firewall*.log
[Jing *]
LangSecRef=3024
Detect=HKLM\Software\TechSmith\Jing
Default=False
FileKey1=%LocalAppData%\TechSmith\Jing\DataStore|*.*|RECURSE
FileKey2=%LocalAppData%\TechSmith\Jing\Temp|*.*|RECURSE
[Jitsi *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Jitsi
Default=False
FileKey1=%AppData%\Jitsi\avatarcache|*.*|RECURSE
FileKey2=%AppData%\Jitsi\Log|*.*|RECURSE
[Jitsi Chat/File History *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Jitsi
Default=False
FileKey1=%AppData%\Jitsi\History*|*.*|RECURSE
[Joboshare DVD Toolkit *]
LangSecRef=3023
Detect=HKCU\Software\Joboshare
Default=False
FileKey1=%Documents%\Joboshare\DVD Copy\ifo_temp|*.*|REMOVESELF
FileKey2=%Documents%\Joboshare\DVD Copy\log|*.*|REMOVESELF
FileKey3=%SystemDrive%|*temp.txt;*test.txt
[Join.Me *]
LangSecRef=3022
Detect=HKCU\Software\join.me
Default=False
FileKey1=%LocalAppData%\join.me|*.log
[Join.Me Install Backups *]
LangSecRef=3022
Detect=HKCU\Software\join.me
Default=False
Warning=This will remove all old versions of Join.Me that are automatically backed up on each install.
FileKey1=%LocalAppData%\join.me\join.me.*.*.*.*|*.*|REMOVESELF
[Jojos Fashion Show *]
Section=Games
DetectFile=%AppData%\Gamelab\Jojos Fashion Show
Default=False
FileKey1=%AppData%\Gamelab\Jojos Fashion Show|log.txt
[Jump Lists *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%AppData%\Microsoft\windows\recent\Automaticdestinations|*.*|RECURSE
FileKey2=%AppData%\Microsoft\windows\recent\CustomDestinations|*.*|RECURSE
ExcludeKey1=FILE|%AppData%\Microsoft\Windows\Recent\AutomaticDestinations\|f01b4d95cf55d32a.automaticDestinations-ms
[Juniper Networks *]
LangSecRef=3021
Detect1=HKCU\Software\Juniper Networks
Detect2=HKLM\Software\Juniper Networks
Default=False
FileKey1=%AppData%\Juniper Networks|*.old;*.log|RECURSE
FileKey2=%LocalAppData%\Juniper Networks\Logging|*.*
RegKey1=HKLM\Software\Juniper Networks\Default
[jv16 PowerTools-X StartupOptimiser *]
LangSecRef=3024
DetectFile=%ProgramFiles%\jv16 PowerTools X\jv16PT.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\jv16 PowerTools X|StartupOptimizer*.log
FileKey2=%ProgramFiles%\jv16 PowerTools X|StartupOptimizer*.log
[K-Lite Codec Pack *]
LangSecRef=3023
Detect=HKLM\Software\KLCodecPack
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\K-Lite*|*.log;*.txt|RECURSE
FileKey2=%ProgramFiles%\K-Lite*|*.log;*.txt|RECURSE
FileKey3=%SystemDrive%|*klcp_itp_*.tmp;*klcp_iph_*.tmp
FileKey4=%UserProfile%\Desktop|klcp_codec_log.txt
RegKey1=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path0
RegKey2=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path1
RegKey3=HKCU\Software\Gabest\vsfilter\DefTextPathes|Path2
[Kakao Talk *]
LangSecRef=3022
DetectFile=%LocalAppData%\Kakao\KakaoTalk
Default=False
FileKey1=%LocalAppData%\Kakao\KakaoTalk\Dump|*.*|RECURSE
[Kalypso Launcher *]
Section=Games
DetectFile=%AppData%\Kalypso Media\Launcher
Default=False
FileKey1=%AppData%\Kalypso Media\Launcher|log_appdata.txt;log.txt
[Kaspersky *]
LangSecRef=3024
Detect=HKCU\Software\KasperskyLab
Default=False
Warning=Make sure to disable "Self Defense" before cleaning.
FileKey1=%CommonAppData%\Kaspersky Lab|*.dmp;*.dmp.stat;*.log
FileKey2=%CommonAppData%\Kaspersky Lab\*\Bases\Cache|*.*|RECURSE
FileKey3=%CommonAppData%\Kaspersky Lab\*\Data\Updater\Temporary Files|*.*|RECURSE
FileKey4=%CommonAppData%\Kaspersky Lab\*\Temp|*.*
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Bases\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Data\Updater\Temporary Files|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Kaspersky Lab\*\Temp|*.*
FileKey8=%ProgramFiles%\Kaspersky Lab\NetworkAgent\~dumps|*.*
[Kaspersky Now *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\KasperskyLab.KasperskyNow_8jx5e25qw3tdc
Default=False
FileKey1=%LocalAppData%\Packages\KasperskyLab.KasperskyNow_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\KasperskyLab.KasperskyNow_*\AC\Microsoft\CLR_v4.0_32|*.log
FileKey3=%LocalAppData%\Packages\KasperskyLab.KasperskyNow_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\KasperskyLab.KasperskyNow_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\KasperskyLab.KasperskyNow_*\LocalCache|*.*|RECURSE
[Kate's Video Toolkit *]
LangSecRef=3023
Detect=HKCU\Software\Web Solution Mart\Kate's Video Toolkit
Default=False
FileKey1=%CommonAppData%\Web Solution Mart\*|*.log|RECURSE
[KCleaner *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\KCleaner
Default=False
FileKey1=%AppData%\KC Softwares\KCleaner|*.log
[KDE *]
LangSecRef=3021
Detect=HKCU\Software\KDE.org
Default=False
FileKey1=%UserProfile%\.kde\cache*|*.*|RECURSE
[KFK *]
LangSecRef=3023
Detect=HKCU\Software\KC Softwares\KFK
Default=False
FileKey1=%AppData%\KC Softwares\KFK|*.log
[Killbox *]
LangSecRef=3024
DetectFile=%SystemDrive%\!Killbox
Default=False
FileKey1=%SystemDrive%\!Killbox\Logs|*.*
[Killing Floor 2 *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\232090
Default=False
FileKey1=%Documents%\My Games\KillingFloor2\KFGame\Logs|*.*|RECURSE
[Kinetic Jump Updater *]
LangSecRef=3021
DetectFile=%LocalAppData%\Kjs.AppLife.Update
Default=False
FileKey1=%LocalAppData%\Kjs.AppLife.Update|*.log
[Kingsoft Office *]
LangSecRef=3021
Detect=HKCU\Software\Kingsoft
Default=False
FileKey1=%AppData%\Kingsoft\*|*.bak
FileKey2=%AppData%\Kingsoft\*\backup|*.*
FileKey3=%AppData%\Kingsoft\*\update\log|*.log
FileKey4=%LocalAppData%\Kingsoft\*\cache\http*|*.*
FileKey5=%ProgramFiles%\Kingsoft\Kingsoft Office\*|update.log
[KlokworkTeamConsole *]
LangSecRef=3024
DetectFile=%ProgramFiles%\KlokworkTeamConsole
Default=False
FileKey1=%AppData%\com.mcgraphix.KlokworkTeamConsole\local store|debug.txt
[KMS Emulator *]
LangSecRef=3024
DetectFile=%WinDir%\AutoKMS\AutoKMS.exe
Default=False
FileKey1=%WinDir%\AutoKMS|AutoKMS.log
[Kodak AiO Software Disable Startup *]
LangSecRef=3021
Detect1=HKLM\Software\Eastman Kodak Company\KODAK AiO Home Center
Detect2=HKLM\Software\Kodak\Kodak AiO Software
Default=False
Warning=Disables the Kodak AiO Software from automatically starting with Windows. Every time you print, it will re-enable itself to start with Windows.
RegKey1=HKLM\Software\Microsoft\Windows\CurrentVersion\Run|EKAIO2StatusMonitor
RegKey2=HKLM\Software\Microsoft\Windows\CurrentVersion\Run|EKStatusMonitor
[Kodak Logs *]
LangSecRef=3021
Detect1=HKCU\Software\Kodak
Detect2=HKLM\Software\Eastman Kodak Company\KODAK AiO Home Center
Detect3=HKLM\Software\Kodak\Kodak AiO Software
DetectFile=%AppData%\Kodak\Share Button App
Default=False
FileKey1=%AppData%\Kodak\Share Button App|*.log
FileKey2=%CommonAppData%\Kodak\Diagnostics|*.*
FileKey3=%CommonAppData%\Kodak\Inkjet Logging|*.*|RECURSE
FileKey4=%LocalAppData%|LaunchHomeCenter.log
FileKey5=%LocalAppData%\Kodak\Diagnostics|UploadLog.xml
FileKey6=%LocalAppData%\Kodak\Inkjet Logging|Status Monitor Log.*
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Kodak\Diagnostics|*.*
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Kodak\Inkjet Logging|*.*|RECURSE
[Kodi *]
LangSecRef=3023
DetectFile=%AppData%\kodi
Default=False
FileKey1=%AppData%\kodi|*.log;*.dmp
FileKey2=%AppData%\kodi*\userdata\thumbnails|*.*|RECURSE
FileKey3=%AppData%\kodi\addons\packages|*.*|RECURSE
FileKey4=%AppData%\kodi\cache|*.*|RECURSE
[Koffix Blocker *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Koffix Blocker\Koffix.exe
Default=False
FileKey1=%Documents%\My Koffix Blocker Logs|*.*
[Koinonein Bittorrent Client *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Koinonein BitTorrent Client\Koinonein BitTorrent Client.exe
Default=False
FileKey1=%LocalAppData%\Koinonein BitTorrent Client*\Application|log.db
[KoolPlaya *]
LangSecRef=3023
Detect=HKCU\Software\AKi-Software\Kool-Playa
Default=False
RegKey1=HKCU\Software\AKi-Software\Kool-Playa\VideoHistory
RegKey2=HKCU\Software\AKi-Software\Kool-Playa\Videos
RegKey3=HKCU\Software\AKi-Software\Kool-PlayaX64\VideoHistory
RegKey4=HKCU\Software\AKi-Software\Kool-PlayaX64\Videos
[LanGuard 10 *]
LangSecRef=3022
DetectFile=%CommonAppData%\GFI Software\LanGuard 10
Default=False
FileKey1=%CommonAppData%\GFI Software\LanGuard 10|newfileslog.*
FileKey2=%CommonAppData%\GFI Software\LanGuard 10\*Logs|*.*|RECURSE
FileKey3=%CommonAppData%\GFI Software\LanGuard 10\Cache|*.*|REMOVESELF
FileKey4=%LocalAppData%\VirtualStore\ProgramData\GFI Software\LanGuard 10|newfileslog.*
FileKey5=%LocalAppData%\VirtualStore\ProgramData\GFI Software\LanGuard 10\*Logs|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\GFI Software\LanGuard 10\Cache|*.*|REMOVESELF
[Launchy *]
LangSecRef=3021
DetectFile=%AppData%\Launchy
Default=False
FileKey1=%AppData%\Launchy\*-icon-cache|*.*
[Lavender's Botanicals *]
Section=Games
DetectFile=%AppData%\MysteryStudio\Lavender
Default=False
FileKey1=%AppData%\MysteryStudio\Lavender|*.log
[League of Legends *]
Section=Games
Detect1=HKCU\Software\Bugsplat\lol_beta_riotgames_com
Detect2=HKCU\Software\Riot Games
Detect3=HKLM\Software\Riot Games
Default=False
FileKey1=%AppData%\LolClient*|*.*|RECURSE
FileKey2=%SystemDrive%\Riot Games\League of Legends|*.log*;*.tmp;*.pandurl;Localization_Errors.txt;*r3dlog.txt;*netlog.txt|RECURSE
FileKey3=%UserProfile%\riotsGamesLogs|*.*
[Leapfrog Connect *]
LangSecRef=3021
DetectFile=%ProgramFiles%\LeapFrog\LeapFrog Connect\LeapFrogConnect.exe
Default=False
FileKey1=%CommonAppData%\Leapfrog\LeapFrog Connect\cache\*\cookies|*.*
FileKey2=%CommonAppData%\Leapfrog\LeapFrog Connect\cache\*\data7\*|*.*
FileKey3=%CommonAppData%\Leapfrog\LeapFrog Connect\cache\*\http*|*.*
FileKey4=%CommonAppData%\Leapfrog\LeapFrog Connect\cache\*\prepared|*.*
FileKey5=%CommonAppData%\Leapfrog\LeapFrog Connect\DownloadCache|*.*
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Leapfrog\LeapFrog Connect\cache\*\cookies|*.*
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Leapfrog\LeapFrog Connect\cache\*\data7\*|*.*
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Leapfrog\LeapFrog Connect\cache\*\http*|*.*
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Leapfrog\LeapFrog Connect\cache\*\prepared|*.*
FileKey10=%LocalAppData%\VirtualStore\ProgramData\Leapfrog\LeapFrog Connect\DownloadCache|*.*
[LeapFTP *]
LangSecRef=3022
DetectFile=%ProgramFiles%\LeapFTP
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\LeapFTP|stats.dat
FileKey2=%ProgramFiles%\LeapFTP|stats.dat
[Learn2 Player *]
LangSecRef=3023
DetectFile=%AppData%\Learn2.com
Default=False
FileKey1=%AppData%\Learn2.com\strunner\StCache|*.*|RECURSE
FileKey2=%LocalAppData%\Learn2.com\strunner\StCache|*.*|RECURSE
[Leawo Prof. Media *]
LangSecRef=3023
Detect=HKCU\Software\Leawo Software\SoftwarePassport\Leawo Prof. Media
Default=False
FileKey1=%AppData%\Leawo\Prof. Media|*.xml
FileKey2=%AppData%\Leawo\Prof. Media\Burn|*.log
FileKey3=%AppData%\Leawo\Prof. Media\Burn\MenuTemplate\Cache|*.*|RECURSE
FileKey4=%AppData%\Leawo\Prof. Media\CrashReport|*.*|RECURSE
FileKey5=%AppData%\Leawo\Prof. Media\Download|*.dat;*.db;*log;*.xml
FileKey6=%AppData%\Leawo\Prof. Media\Download\Thumbnails|*.*|RECURSE
FileKey7=%AppData%\Leawo\Prof. Media\Download\WebCache|*.*|RECURSE
FileKey8=%AppData%\Leawo\Prof. Media\Download\WebFiles|*.*|RECURSE
FileKey9=%AppData%\Leawo\Prof. Media\Log|*.*|RECURSE
FileKey10=%LocalAppData%\Leawo Prof\cache|*.*|RECURSE
[Leawo Video Converter *]
LangSecRef=3023
DetectFile=%AppData%\Leawo\Video Converter*
Default=False
FileKey1=%AppData%\Leawo\Video Converter*|*.log
FileKey2=%AppData%\Leawo\Video Converter*\CrashReport|*.*|RECURSE
FileKey3=%LocalAppData%\Video Converter*\cache|*.*|RECURSE
[LEGO Universe *]
Section=Games
DetectFile=%LocalAppData%\LEGO Software\LEGO Universe
Default=False
FileKey1=%LocalAppData%\LEGO Software\LEGO Universe\Log Files|*.*
[Lenovo SWTOOLS *]
LangSecRef=3025
DetectFile=%SystemDrive%\SWTOOLS
Default=False
FileKey1=%SystemDrive%\SWTOOLS|*.*|REMOVESELF
[Lenovo System Update *]
LangSecRef=3024
DetectFile=%CommonAppData%\Lenovo\SystemUpdate\sessionSE\Repository
Default=False
FileKey1=%CommonAppData%\Lenovo\SystemUpdate\sessionSE\Repository|*.*|RECURSE
FileKey2=%CommonAppData%\Lenovo\SystemUpdate\sessionSE\system\SSClientCommon|*.xml
[Leviev Sales Information Portal *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Leviev Sales Information Portal
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\JMS|JMSErrors.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Leviev Sales Information Portal|JMSErrors.txt
FileKey3=%ProgramFiles%\JMS|JMSErrors.txt
FileKey4=%ProgramFiles%\Leviev Sales Information Portal|JMSErrors.txt
[Lexmark Logs *]
LangSecRef=3021
DetectFile=%CommonAppData%\gn_logs
Default=False
FileKey1=%CommonAppData%\gn_logs\*|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\gn_logs\*|*.*
[Lexmark Photo Editor *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Lexmark 5200 Series\pheditor.exe
Default=False
RegKey1=HKCU\Software\LexmarkPhoto\Lexmark Photo Software\pheditor\Recent File List
[Lexware Logs *]
LangSecRef=3021
DetectFile=%LocalAppData%\Lexware
Default=False
FileKey1=%AppData%\Lexware|*.log|RECURSE
FileKey2=%CommonAppData%\Lexware|*.log;*.logx|RECURSE
FileKey3=%CommonAppData%\Lexware\elster\Log|*.*|REMOVESELF
FileKey4=%CommonAppData%\Lexware\logs|*.*|REMOVESELF
FileKey5=%CommonProgramFiles%\Lexware|*.log|RECURSE
FileKey6=%LocalAppData%\Lexware|*.log;*.logx|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Common Files\Lexware|*.log|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Lexware|*.log|RECURSE
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Lexware|*.log;*.logx|RECURSE
FileKey10=%LocalAppData%\VirtualStore\ProgramData\Lexware\elster\Log|*.*|REMOVESELF
FileKey11=%LocalAppData%\VirtualStore\ProgramData\Lexware\logs|*.*|REMOVESELF
FileKey12=%ProgramFiles%\Lexware|*.log|RECURSE
FileKey13=%SystemDrive%|LxDasi.Log
[LibreOffice *]
LangSecRef=3021
Detect=HKLM\Software\LibreOffice
Default=False
FileKey1=%AppData%\LibreOffice\*\User\backup|*.*
FileKey2=%AppData%\LibreOffice\*\User\extensions\shared|log.*
FileKey3=%AppData%\LibreOffice\*\User\temp|*.*
FileKey4=%AppData%\LibreOffice\*\User\uno_packages\cache|log.*
FileKey5=%ProgramFiles%\LibreOffice *.*\program_old*|*.*|REMOVESELF
[LifeCam *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.LifeCamDashboard_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.LifeCamDashboard_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.LifeCamDashboard_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.LifeCamDashboard_*\AC\PRICache|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.LifeCamDashboard_*\AC\Temp|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.LifeCamDashboard_*\TempState|*.*|RECURSE
[LightScribe *]
LangSecRef=3023
Detect=HKCU\Software\LightScribe
Default=False
FileKey1=%CommonAppData%\LightScribe\log|*.xml
FileKey2=%LocalAppData%\VirtualStore\ProgramData\LightScribe\log|*.xml
[LightShot *]
LangSecRef=3022
DetectFile=%LocalAppData%\Skillbrains\lightshot
Default=False
FileKey1=%LocalAppData%|updater.log
[Lili: Child of Geos - Complete Edition *]
Section=Games
Detect=HKCU\Software\Valve\Steam\apps\266490
Default=False
FileKey1=%Documents%\my games\UnrealEngine3-MazeGame\MazeGame\Logs|*.*
[LimeWire *]
LangSecRef=3022
Detect=HKLM\Software\LimeWire
Default=False
FileKey1=%AppData%\LimeWire|fileurns.cache;createtimes.cache;responses.cache;ttree.cache;gnutella.net
FileKey2=%UserProfile%\Incomplete|*.*|RECURSE
[LinkAlyzer *]
LangSecRef=3024
Detect=HKCU\Software\Sanderson Forensics\LinkAlyzer
Default=False
RegKey1=HKCU\Software\Sanderson Forensics\LinkAlyzer|LastOpenFolder
RegKey2=HKCU\Software\Sanderson Forensics\LinkAlyzer|LastSaveFolder
[Listary *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Listary_is1
Default=False
FileKey1=%AppData%\Listary\CrashRpt|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Listary|*.log
FileKey3=%ProgramFiles%\Listary|*.log
[Loadout *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\208090
Default=False
FileKey1=%LocalAppData%\EdgeOfReality\Loudout\CrashReports|*.*
[LocalService *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\LocalService*\Cookies|*.*|RECURSE
FileKey2=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\History|*.*|RECURSE
FileKey3=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\Temp|*.*|RECURSE
FileKey4=%SystemDrive%\Documents and Settings\LocalService*\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey5=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey6=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE
FileKey7=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Temp|*.*|RECURSE
FileKey8=%WinDir%\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies|*.*|REMOVESELF
FileKey9=%WinDir%\ServiceProfiles\LocalService\AppData\LocalLow\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey10=%WinDir%\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|REMOVESELF
[LocalSystem *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE
FileKey3=%WinDir%\System32\config\systemprofile\AppData\Local\Temp|*.*|RECURSE
FileKey4=%WinDir%\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey5=%WinDir%\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey6=%WinDir%\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE
FileKey7=%WinDir%\System32\config\SystemProfile\Application Data\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey8=%WinDir%\System32\config\SystemProfile\Application Data\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey9=%WinDir%\System32\config\SystemProfile\Cookies|*.*|RECURSE
FileKey10=%WinDir%\System32\config\SystemProfile\History|*.*|RECURSE
FileKey11=%WinDir%\System32\config\SystemProfile\Local Settings\Temp|*.*|RECURSE
FileKey12=%WinDir%\System32\config\SystemProfile\Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey13=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE
FileKey14=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Temp|*.*|RECURSE
FileKey15=%WinDir%\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey16=%WinDir%\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey17=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE
FileKey18=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\History|*.*|RECURSE
[Lock App *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.LockApp_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.LockApp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.LockApp_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.LockApp_*\TempState|*.*|RECURSE
[LockHunter *]
LangSecRef=3024
Detect=HKCU\Software\LockHunter
Default=False
FileKey1=%AppData%\LockHunter|*.txt;*.log
FileKey2=%CommonAppData%\LHService|*.txt;*.log
[Logitech Camera *]
LangSecRef=3023
DetectFile=%LocalAppData%\LogiShrd
Default=False
FileKey1=%LocalAppData%\LogiShrd\Vid|*.*|RECURSE
[Logitech Desktop Messenger *]
LangSecRef=3024
Detect1=HKCU\Software\Logitech\DesktopMessenger
Detect2=HKLM\Software\Logitech\DesktopMessenger
Detect3=HKLM\Software\Logitech\Logitech Desktop Messenger
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Logitech\Desktop Messenger|*.log;*.bak
FileKey2=%ProgramFiles%\Logitech\Desktop Messenger|*.log;*.bak
[Logitech Harmony Remote Cache *]
LangSecRef=3021
Detect=HKCU\Software\JavaSoft\Prefs\Com\Logitech\harmony
Default=False
FileKey1=%UserProfile%\Logitech\browser - logitech\Cache|*.*
[Logitech Logs *]
LangSecRef=3021
Detect=HKCU\Software\Logitech\Setpoint
DetectFile=%AppData%\LogiShrd
Default=False
FileKey1=%AppData%\Logishrd|*.log|RECURSE
FileKey2=%AppData%\Logishrd\sp6_Log|*.*|REMOVESELF
FileKey3=%AppData%\LogiShrd\Updater|LuUpdater.log;UpdateList.csv
FileKey4=%CommonAppData%\LogiShrd|*.log|RECURSE
FileKey5=%CommonAppData%\Logishrd\unifying|EngineLog.*;*.txt
FileKey6=%CommonAppData%\Logitech\KHAL\Battery|*.log
FileKey7=%CommonProgramFiles%\logishrd|*.log|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\LogiShrd|*.log|RECURSE
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Logishrd\unifying|EngineLog.*
FileKey10=%WinDir%\System32|lvcoinst.log
[LogMeIn Hamachi *]
LangSecRef=3022
Detect=HKLM\Software\LogMeIn, Inc.
Default=False
FileKey1=%WinDir%\System32\config\systemprofile\*\*\LogMeIn Hamachi|h2-engine.log;h2-ui.log;*.old;*.bak
FileKey2=%WinDir%\SysWOW64\config\systemprofile\*\*\LogMeIn Hamachi|h2-engine.log;h2-ui.log;*.old;*.bak
[LoL Summonerinfo *]
Section=Games
DetectFile=%ProgramFiles%\LSI\logs
Default=False
FileKey1=%ProgramFiles%\LSI\logs|*.*
[LoL Summonerinfo Replays *]
Section=Games
DetectFile=%ProgramFiles%\LSI\replays
Default=False
Warning=This will delete all your saved replays.
FileKey1=%ProgramFiles%\LSI\replays|*.*
[LOLReplay *]
Section=Games
Detect=HKCU\Software\LOLReplay
Default=False
FileKey1=%Documents%\LOLReplay|*_log.txt;*.log;*.old|RECURSE
[Lost Photos *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Lost Photos
Default=False
FileKey1=%LocalAppData%\Lost_Photos\*|ResultSearchFile.info
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Lost Photos\Logs|*.*
FileKey3=%ProgramFiles%\Lost Photos\Logs|*.*
[LotR Online Launcher *]
Section=Games
DetectFile=%LocalAppData%\Turbine\The Lord of the Rings Online\Launcher
Default=False
FileKey1=%LocalAppData%\The Lord Of The Rings Online|*.log
FileKey2=%LocalAppData%\Turbine|*.log|RECURSE
[Lotus Notes *]
LangSecRef=3021
DetectFile=%ProgramFiles%\IBM\Lotus\Notes\Data\Cache.NDK
Default=False
FileKey1=%ProgramFiles%\IBM\Lotus\Notes\Data|Cache.NDK
[Lunascape6 *]
LangSecRef=3022
Detect=HKLM\Software\Lunascape Corporation
Default=False
FileKey1=%AppData%\lunascape\Lunascape6\ApplicationData|rebar.bmp
FileKey2=%AppData%\lunascape\Lunascape6\ApplicationData\icons|*.*|RECURSE
FileKey3=%AppData%\lunascape\Lunascape6\ApplicationData\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Lunascape\Lunascape6\applicationdata|rebar.bmp
FileKey5=%ProgramFiles%\Lunascape\Lunascape6\applicationdata|rebar.bmp
[Lunascape6 Backups *]
LangSecRef=3022
Detect=HKLM\Software\Lunascape Corporation
Default=False
FileKey1=%AppData%\Lunascape\Lunascape6\backup|*.*|RECURSE
[Lunascape6 History *]
LangSecRef=3022
Detect=HKLM\Software\Lunascape Corporation
Default=False
Warning=Note: Lunascape will show you a warning next start up.
FileKey1=%AppData%\lunascape\Lunascape6\ApplicationData|history.ld2
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Lunascape\Lunascape6\applicationdata|history.ld2
FileKey3=%ProgramFiles%\Lunascape\Lunascape6\applicationdata|history.ld2
[Lupinho.Net Hardlink *]
LangSecRef=3023
Detect=HKLM\Software\Lupinho.Net
Default=False
FileKey1=%LocalAppData%\Lupinho.Net|*.log|RECURSE
[Lynx Web Browser *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Lynx - web browser
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Lynx - web browser\tmp|*.*
FileKey2=%ProgramFiles%\Lynx - web browser\tmp|*.*
[Lyrik *]
LangSecRef=3023
Detect=HKLM\Software\Lyrik
Default=False
FileKey1=%LocalAppData%\Lyrik|*.*
[Lyx *]
LangSecRef=3021
DetectFile=%AppData%\LyX2.0
Default=False
FileKey1=%AppData%\LyX2.0|*.log|RECURSE
FileKey2=%AppData%\LyX2.0\Cache|*.*|RECURSE
[Macaw *]
LangSecRef=3022
DetectFile=%AppData%\Macaw
Default=False
FileKey1=%AppData%\Macaw\cef_data|cookies*.*;data*.;index.
FileKey2=%AppData%\Macaw\cef_data\gpucache|*.*|RECURSE
FileKey3=%AppData%\Macaw\cef_data\Local Storage|*.*
[Machete *]
LangSecRef=3023
Detect=HKCU\Software\MacheteSoft\Machete
DetectFile=%ProgramFiles%\MacheteSoft\Machete\Machete.exe
Default=False
FileKey1=%AppData%\Machete|MacheteSettings.xml.bak
RegKey1=HKCU\Software\Local AppWizard-Generated Applications\Machete\Recent File List
RegKey2=HKCU\Software\MacheteSoft\Machete\Recent File List
[Macrium Reflect *]
LangSecRef=3024
Detect=HKCU\Software\Macrium\Reflect
Default=False
FileKey1=%CommonAppData%\Macrium|*.log|RECURSE
FileKey2=%CommonAppData%\Macrium\Reflect|*.html;*.vsslog
FileKey3=%CommonAppData%\Macrium\waik|waiklog.txt
FileKey4=%SystemDrive%|ref~tmp~.txt;Reflect_Install.log;rescuepe.log
[Macromedia Shockwave *]
LangSecRef=3023
Detect1=HKCU\Software\Macromedia\Shockwave 8
Detect2=HKCU\Software\Macromedia\Shockwave 9
Default=False
RegKey1=HKCU\Software\Macromedia\Shockwave 8\movies
RegKey2=HKCU\Software\Macromedia\Shockwave 9\movies
[Magicka *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\42910
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\magicka|errorReport*.txt
FileKey2=%ProgramFiles%\Steam\steamapps\common\magicka|errorReport*.txt
[MAGIX Installation Manager *]
LangSecRef=3023
Detect=HKCU\Software\Magix\MAGIX Installation manager
Default=False
FileKey1=%CommonAppData%\MAGIX\*|*.log;*.reg
FileKey2=%CommonAppData%\MAGIX\*\download|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\MAGIX\*|*.log;*.reg
FileKey4=%LocalAppData%\VirtualStore\ProgramData\MAGIX\*\download|*.*|RECURSE
[MAGIX Video Easy TERRATEC Edition *]
LangSecRef=3023
Detect=HKLM\Software\MAGIX\Video_easy_3_TerraTec
Default=False
FileKey1=%AppData%\MAGIX\Video_easy_TERRATEC_Edition|*.log|RECURSE
[MAGIX Video Pro *]
LangSecRef=3023
Detect1=HKCU\Software\MAGIX AG\Videodeluxe18_pro
Detect2=HKCU\Software\MAGIX AG\Videodeluxe19_pro
Default=False
FileKey1=%AppData%\MAGIX\Video*Pro*|*.log
FileKey2=%Documents%\MAGIX\Video*Pro*\AudioTemp|*.*|RECURSE
RegKey1=HKCU\Software\MAGIX AG\Videodeluxe19_pro\ExportConfigurator\DialogItems|LastFile
RegKey2=HKCU\Software\MAGIX AG\Videodeluxe19_pro\ExportConfigurator\DialogItems|LastPreset
[MakeHuman *]
LangSecRef=3021
DetectFile=%Documents%\makehuman
Default=False
FileKey1=%Documents%\makehuman\v1|makehuman.log;makehuman-debug.txt;python_err.txt;python_out.txt
FileKey2=%Documents%\makehuman\v1\cache|*.mhc
[MAL Updater *]
LangSecRef=3023
DetectFile=%ProgramFiles%\Mal Updater 2\MalUpdater.exe
Default=False
FileKey1=%AppData%\Mal Updater\*Pics|*.*
FileKey2=%AppData%\Mal Updater\SeasonData|*.*
FileKey3=%AppData%\Mal Updater\Users|*.log|RECURSE
[Malwarebytes Anti-Exploit *]
LangSecRef=3024
Detect=HKLM\System\CurrentControlSet\Services\MbaeSvc
DetectFile=%CommonAppData%\Malwarebytes Anti-Exploit
Default=False
FileKey1=%CommonAppData%\Malwarebytes Anti-Exploit|*.log;mbae-default.log.bak;mbae-protector.xpe.bak
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Malwarebytes Anti-Exploit|*.log;mbae-default.log.bak;mbae-protector.xpe.bak
FileKey3=%ProgramFiles%\Malwarebytes Anti-Exploit|mbae-uninstall.log;changelog.txt
[Malwarebytes Anti-Malware *]
LangSecRef=3024
Detect=HKCU\Software\Malwarebytes
DetectFile=%ProgramFiles%\Malwarebytes Anti-Malware\mbam.exe
Default=False
Warning=You must manually and temporarily turn off Malwarebytes "self-protection" to remove the logs.
FileKey1=%AppData%\Malwarebytes\Malwarebytes*Anti-Malware\Logs|*.*
FileKey2=%CommonAppData%\Malwarebytes\Malwarebytes*Anti-Malware|mbam-setup.exe
FileKey3=%CommonAppData%\Malwarebytes\Malwarebytes*Anti-Malware\Logs|*.*
FileKey4=%CommonAppData%\Malwarebytes\MBAMService|*.log;*.bak;*.regtrans-ms;*.TM.blf;*-ntuser.dat;*.LOG1;*.LOG2;*-UsrClass.dat
FileKey5=%CommonAppData%\Malwarebytes\MBAMService\logs|*.*
FileKey6=%CommonAppData%\Malwarebytes\MBAMService\ScanResults|*.*
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Malwarebytes\Malwarebytes*Anti-Malware|mbam-setup.exe
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Malwarebytes\Malwarebytes*Anti-Malware\Logs|*.*
[ManiaPlanet *]
Section=Games
DetectFile=%CommonAppData%\ManiaPlanet
Default=False
FileKey1=%CommonAppData%\ManiaPlanet\Cache|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\ManiaPlanet\Cache|*.*
[ManyCam *]
LangSecRef=3023
Detect1=HKCU\Software\ManyCam
Detect2=HKLM\Software\ManyCam
Default=False
FileKey1=%AppData%\ManyCam\Settings\MoviesThumbnails|*.*|RECURSE
FileKey2=%LocalAppData%\ManyCam|*.log|RECURSE
FileKey3=%LocalAppData%\ManyCam\cache\gallery|*.*|RECURSE
[Maps *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsMaps_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsMaps_*\TempState|*.*|RECURSE
[Marine Sharpshooter 3 *]
Section=Games
DetectFile=%ProgramFiles%\Groove Games\Marine Sharpshooter 3
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Groove Games\Marine Sharpshooter 3|*.dmp;*.mdmp|RECURSE
FileKey2=%ProgramFiles%\Groove Games\Marine Sharpshooter 3|*.dmp;*.mdmp|RECURSE
[Mass Downloader *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Mass Downloader
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Mass Downloader|*.bak;massdown.dat;history.dat|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Mass Downloader\Index|*.*|RECURSE
FileKey3=%ProgramFiles%\Mass Downloader|*.bak;massdown.dat;history.dat|RECURSE
FileKey4=%ProgramFiles%\Mass Downloader\Index|*.*|RECURSE
[Mass Effect *]
Section=Games
Detect1=HKLM\Software\BioWare\Mass Effect
Detect2=HKLM\Software\BioWare\Mass Effect 2
Detect3=HKLM\Software\BioWare\Mass Effect 3
Default=False
FileKey1=%Documents%\BioWare\Mass Effect*\BIOGame\Logs|*.*
FileKey2=%Documents%\BioWare\Mass Effect*\Logs|*.*
[MassTube *]
LangSecRef=3024
DetectFile1=%AppData%\MassTube\MassTube.exe
DetectFile2=%LocalAppData%\MassTube\MassTube.exe
DetectFile3=%ProgramFiles%\MassTube\MassTube.exe
DetectFile4=%SystemDrive%\Programs\MassTube\MassTube.exe
Default=False
FileKey1=%AppData%\MassTube|Historial.dat
FileKey2=%AppData%\MassTube\Miniaturas|*.jpg
FileKey3=%LocalAppData%\MassTube|Historial.dat
FileKey4=%LocalAppData%\MassTube\Miniaturas|*.jpg
FileKey5=%ProgramFiles%\MassTube|Historial.dat
FileKey6=%ProgramFiles%\MassTube\Miniaturas|*.jpg
FileKey7=%SystemDrive%\Programs\MassTube|Historial.dat
FileKey8=%SystemDrive%\Programs\MassTube\Miniaturas|*.jpg
[Mavis Beacon *]
LangSecRef=3021
DetectFile=%AppData%\Broderbund\Mavis
Default=False
FileKey1=%AppData%\Broderbund\Mavis|logfile.*
[Maxprog iCash *]
LangSecRef=3021
Detect=HKCR\iCash
Default=False
FileKey1=%Documents%\Maxprog\iCash\Database Logs|*.*|REMOVESELF
FileKey2=%Documents%\Maxprog\iCash\Error Logs|*.*|REMOVESELF
FileKey3=%Documents%\Maxprog\iCash\XML Dumps|*.*|REMOVESELF
FileKey4=%LocalAppData%\VirtualStore\Program Files*\iCash\vlogs|*.*|REMOVESELF
FileKey5=%ProgramFiles%\iCash\vlogs|*.*|REMOVESELF
[Maxthon Browser *]
LangSecRef=3022
Detect1=HKCU\Software\Maxthon
Detect2=HKCU\Software\Maxthon2
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Maxthon*\Temp|*.*
FileKey2=%ProgramFiles%\Maxthon*\Temp|*.*
[Maxthon Browser 3 Backups *]
LangSecRef=3022
Detect=HKCU\Software\Maxthon3
Default=False
FileKey1=%AppData%\Maxthon3\Users\*\backup|*.*|RECURSE
[Maxthon Browser 3 Cookies *]
LangSecRef=3022
Detect=HKCU\Software\Maxthon3
Default=False
FileKey1=%AppData%\Maxthon3\Users\*\Cookie|cookie.dat
[Maxthon Browser 3 History *]
LangSecRef=3022
Detect=HKCU\Software\Maxthon3
Default=False
FileKey1=%AppData%\Maxthon3\Users\*\History|history.dat;lasttab.dat
[Maxthon Browser 3 LocalStorage *]
LangSecRef=3022
Detect=HKCU\Software\Maxthon3
Default=False
FileKey1=%AppData%\Maxthon3\Users\*\LocalStorage|*.*|RECURSE
[McAfee *]
LangSecRef=3024
Detect=HKLM\Software\McAfee
Default=False
FileKey1=%CommonAppData%\McAfee\AMCore\datreputation\Logs|*.*|RECURSE
FileKey2=%CommonAppData%\McAfee\Common Framework\AgentEvents|*.*
FileKey3=%CommonAppData%\McAfee\CSP\ETW|*.bak
FileKey4=%CommonAppData%\McAfee\Jcm|*.tmp
FileKey5=%CommonAppData%\McAfee\MCLOGS|*.bak;*.log|RECURSE
FileKey6=%CommonAppData%\McAfee\MHN|*.bak
FileKey7=%CommonAppData%\McAfee\modulecoreservice.exe|*.txt
FileKey8=%CommonAppData%\McAfee\MPF|*.tmp
FileKey9=%CommonAppData%\McAfee\MPF\data|*.*|RECURSE
FileKey10=%CommonAppData%\McAfee\MSC\Logs|*.log
FileKey11=%CommonAppData%\McAfee\SiteAdvisor|*.txt|RECURSE
FileKey12=%CommonAppData%\McAfee\Update|*.*|RECURSE
FileKey13=%CommonAppData%\McAfee\VirusScan\Data|*.log;*.old
FileKey14=%CommonAppData%\McAfee\VirusScan\Logs|*.*|RECURSE
FileKey15=%CommonAppData%\Network Associates\Common Framework\AgentEvents|*.*
FileKey16=%LocalAppData%\VirtualStore\ProgramData\McAfee\AMCore\datreputation\Logs|*.*|RECURSE
FileKey17=%LocalAppData%\VirtualStore\ProgramData\McAfee\Common Framework\AgentEvents|*.*
FileKey18=%LocalAppData%\VirtualStore\ProgramData\McAfee\CSP\ETW|*.bak
FileKey19=%LocalAppData%\VirtualStore\ProgramData\McAfee\Jcm|*.tmp
FileKey20=%LocalAppData%\VirtualStore\ProgramData\McAfee\MCLOGS|*.bak;*.log|RECURSE
FileKey21=%LocalAppData%\VirtualStore\ProgramData\McAfee\MHN|*.bak
FileKey22=%LocalAppData%\VirtualStore\ProgramData\McAfee\modulecoreservice.exe|*.txt
FileKey23=%LocalAppData%\VirtualStore\ProgramData\McAfee\MPF|*.tmp
FileKey24=%LocalAppData%\VirtualStore\ProgramData\McAfee\MPF\data|*.*|RECURSE
FileKey25=%LocalAppData%\VirtualStore\ProgramData\McAfee\MSC\Logs|*.log
FileKey26=%LocalAppData%\VirtualStore\ProgramData\McAfee\SiteAdvisor|*.txt|RECURSE
FileKey27=%LocalAppData%\VirtualStore\ProgramData\McAfee\Update|*.*|RECURSE
FileKey28=%LocalAppData%\VirtualStore\ProgramData\McAfee\VirusScan\Data|*.log;*.old
FileKey29=%LocalAppData%\VirtualStore\ProgramData\McAfee\VirusScan\Logs|*.*|RECURSE
FileKey30=%LocalAppData%\VirtualStore\ProgramData\Network Associates\Common Framework\AgentEvents|*.*
[McPixel *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\220860
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\mcpixel|log.txt
FileKey2=%ProgramFiles%\Steam\Steamapps\common\mcpixel|log.txt
[Media Center 18 *]
LangSecRef=3023
Detect=HKCU\Software\J. River\Media Center 18
Default=False
FileKey1=%AppData%\J River\Media Center 18\Library|field (filename).jmd;field (name).jmd
FileKey2=%Documents%\J River\Media Center 18\Library|*.*|RECURSE
[Media Jukebox *]
LangSecRef=3023
Detect=HKCU\Software\J. River\Music Exchange\1.0\Media Jukebox
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\J River\Media Jukebox\Data|*.jmd
FileKey2=%ProgramFiles%\J River\Media Jukebox\Data|*.jmd
[Media Play Ready Client *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Media.PlayReadyClient_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\PRICache|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\LocalState\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\LocalState\navigationHistory|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Media.PlayReadyClient_*\TempState|*.*|RECURSE
[Media Player Classic *]
LangSecRef=3023
Detect1=HKCU\Software\Gabest\Media Player Classic
Detect2=HKCU\Software\MPC-BE
Detect3=HKCU\Software\MPC-HC\MPC-HC
Default=False
FileKey1=%AppData%\Media Player Classic|*.dmp
FileKey2=%AppData%\MPC-*|*.dmp
RegKey1=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 0
RegKey2=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 1
RegKey3=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 2
RegKey4=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 3
RegKey5=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 4
RegKey6=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 5
RegKey7=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 6
RegKey8=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 7
RegKey9=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 8
RegKey10=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 9
RegKey11=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 10
RegKey12=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 11
RegKey13=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 12
RegKey14=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 13
RegKey15=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 14
RegKey16=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 15
RegKey17=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 16
RegKey18=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 17
RegKey19=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 18
RegKey20=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 19
RegKey21=HKCU\Software\Gabest\Media Player Classic\Settings|DVD Position 20
[MegaCloud *]
LangSecRef=3022
DetectFile=%AppData%\MegaCloud
Default=False
FileKey1=%AppData%\MegaCloud|*.log|RECURSE
FileKey2=%AppData%\MegaCloud\AutoUpdate\Temp|*.*|RECURSE
[MemoMaster 5 *]
LangSecRef=3021
Detect=HKCU\Software\JBSoftware\MemoMaster5
Default=False
RegKey1=HKCU\Software\JBSoftware\MemoMaster5|FileMRU1
RegKey2=HKCU\Software\JBSoftware\MemoMaster5|FileMRU2
RegKey3=HKCU\Software\JBSoftware\MemoMaster5|FileMRU3
RegKey4=HKCU\Software\JBSoftware\MemoMaster5|FileMRU4
RegKey5=HKCU\Software\JBSoftware\MemoMaster5|FileMRU5
RegKey6=HKCU\Software\JBSoftware\MemoMaster5|FileMRU6
RegKey7=HKCU\Software\JBSoftware\MemoMaster5|FileMRU7
RegKey8=HKCU\Software\JBSoftware\MemoMaster5|FileMRU8
RegKey9=HKCU\Software\JBSoftware\MemoMaster5|FileMRU9
RegKey10=HKCU\Software\JBSoftware\MemoMaster5|FileMRU10
RegKey11=HKCU\Software\JBSoftware\MemoMaster5|FileMRU11
RegKey12=HKCU\Software\JBSoftware\MemoMaster5|FileMRU12
RegKey13=HKCU\Software\JBSoftware\MemoMaster5|FileMRU13
RegKey14=HKCU\Software\JBSoftware\MemoMaster5|FileMRU14
RegKey15=HKCU\Software\JBSoftware\MemoMaster5|FileMRU15
[Men of War *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\3130
Detect2=HKCU\Software\Valve\Steam\Apps\7830
Detect3=HKCU\Software\Valve\Steam\Apps\63940
Detect4=HKCU\Software\Valve\Steam\Apps\64000
Detect5=HKCU\Software\Valve\Steam\Apps\204860
Default=False
FileKey1=%Documents%\My Games\men of war*\log|*.*
FileKey2=%Documents%\My Games\men of war*\shader_cache|*.*|RECURSE
FileKey3=%Documents%\My Games\mow *\log|*.*
FileKey4=%Documents%\My Games\mow *\shader_cache|*.*|RECURSE
[Mention *]
LangSecRef=3022
Detect=HKCU\Software\Mention
Default=False
FileKey1=%LocalAppData%\Mention\Mention|WebpageIcons.db;cookies
FileKey2=%LocalAppData%\Mention\Mention\Cache|*.*|RECURSE
FileKey3=%LocalAppData%\Mention\Mention\LocalStorage|*.*|RECURSE
[Messaging *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Messaging_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Messaging_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Messaging_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Messaging_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Messaging_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Messaging_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Messaging_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Messaging_*\TempState|*.*|RECURSE
[Messenger Plus! Live *]
LangSecRef=3022
Detect=HKCU\Software\Patchou
Default=False
FileKey1=%Documents%\My Chat Logs|*.*|RECURSE
[Metadata Analyzer *]
LangSecRef=3024
Detect=HKCU\Software\Smart PC Solutions\Metadata Analyzer
Default=False
RegKey1=HKCU\Software\Smart PC Solutions\Metadata Analyzer|LastFile
RegKey2=HKCU\Software\Smart PC Solutions\Metadata Analyzer|LastFolder
[Metamorphose *]
LangSecRef=3024
DetectFile=%ProgramFiles%\metamorphose\metamorphose.exe
Default=False
FileKey1=%AppData%\.metamorphose\undo|*.*
[Metapad *]
LangSecRef=3021
Detect=HKCU\Software\metapad
Default=False
RegKey1=HKCU\Software\metapad|szLastDirectory
[MetaX *]
LangSecRef=3024
Detect=HKCU\Software\No Bull Software\MetaX
Default=False
FileKey1=%Documents%\MetaX|*.log
RegKey1=HKCU\Software\No Bull Software\MetaX\Preferences|lastDir
[MetroTwit *]
LangSecRef=3022
DetectFile=%AppData%\MetroTwit
Default=False
FileKey1=%AppData%\MetroTwit|MetroTwit.backup
FileKey2=%AppData%\MetroTwit\*|User.cache;User.backup
FileKey3=%AppData%\MetroTwit\*\User_Images|*.*|RECURSE
[Microangelo *]
LangSecRef=3021
Detect1=HKCU\Software\Eclipsit\Microangelo\Toolset 6
Detect2=HKCU\Software\Impact\Microangelo
Default=False
RegKey1=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Animator\MRU List
RegKey2=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Librarian\MRU List
RegKey3=HKCU\Software\Eclipsit\Microangelo\Toolset 6\Studio\MRU List
RegKey4=HKCU\Software\Impact\Microangelo\Animator\MRU List
RegKey5=HKCU\Software\Impact\Microangelo\Librarian\MRU List
RegKey6=HKCU\Software\Impact\Microangelo\Studio\MRU List
[Microsoft Bing Bar *]
LangSecRef=3021
Detect=HKCU\Software\AppDataLow\Software\Microsoft\BingBar
Default=False
FileKey1=%LocalAppData%\Microsoft\BingBar\Apps|*.tmp|RECURSE
[Microsoft Deployment Toolkit *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Microsoft Deployment Toolkit
Default=False
Warning=To Get a new Component list, check for Updates in the Management Console!
FileKey1=%ProgramFiles%\Microsoft Deployment Toolkit\Downloads|*.*|RECURSE
[Microsoft Edge *]
LangSecRef=3022
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\#!00*\INetCookies|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\#!00*\Microsoft\Cryptnet*Cache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\#!00*\MicrosoftEdge\Cookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\Microsoft\Cryptnet*Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\Cookies|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\UrlBlock|*.tmp
FileKey7=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\DataStore\Data\nouser1\*\DBStore|V01*.log;V01*.jrs
FileKey8=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\DataStore\Indexed\Data\nouser1\*|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\ImageStore|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\Recovery\Active|*.dat
FileKey11=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\Temp|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AppData\User\Default\Indexed DB|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\LocalState\Favicons\PushNotificationGrouping|*.*|RECURSE
FileKey14=%UserProfile%\MicrosoftEdgeBackups\backups\*|*.*|REMOVESELF
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Recovery\PendingDelete
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\PersistedPickerData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge\DefaultOpenFileMultiple
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\PersistedPickerData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge\DefaultOpenFileSingle
RegKey4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\PersistedPickerData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge\DefaultSaveFileSingle
[Microsoft Edge Favorites Icons *]
LangSecRef=3022
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
Default=False
Warning=This will delete all the icons of your favorites. The icons will be rebuilt as websites are manually re-visited.
FileKey1=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_*\AC\MicrosoftEdge\User\Default\Datastore\Data\nouser1\*\Favorites|*.ico
[Microsoft Expression Web *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Expression\Web Designer
Default=False
RegKey1=HKCU\Software\Microsoft\Expression\Web Designer\FindMRU
[Microsoft Flight Simulator X *]
Section=Games
Detect=HKLM\Software\Microsoft\Microsoft Games\Flight Simulator\10.0
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Microsoft Games\Microsoft Flight Simulator X|*.log;*.rtf;*.html;*.URL
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Microsoft Games\Microsoft Flight Simulator X\Modules|*.log
FileKey3=%ProgramFiles%\Microsoft Games\Microsoft Flight Simulator X|*.log;*.rtf;*.html;*.URL
FileKey4=%ProgramFiles%\Microsoft Games\Microsoft Flight Simulator X\Modules|*.log
ExcludeKey1=PATH|%ProgramFiles%\Microsoft Games\Microsoft Flight Simulator X\|*kiosk.rtf;*readme.rtf;*Readme.htm
[Microsoft Message Analyzer *]
LangSecRef=3024
DetectFile=%LocalAppData%\Microsoft\MessageAnalyzer
Default=False
FileKey1=%Documents%\MessageAnalyzer\Traces|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\MessageAnalyzer|*.log
[Microsoft Mouse and Keyboard Center *]
LangSecRef=3021
DetectFile1=%ProgramFiles%\Microsoft Device Center
DetectFile2=%ProgramFiles%\Microsoft Mouse and Keyboard Center
Default=False
Warning=This will also delete all app-specific settings.
RegKey1=HKCU\Software\Microsoft\IntelliPoint\AppSpecific
RegKey2=HKCU\Software\Microsoft\IntelliType Pro\AppSpecific
[Microsoft Outlook Express 5.0 *]
LangSecRef=3022
Detect=HKCU\Identities\{9745A9A1-95D3-4584-B4E8-C9C2374B3BD3}\Software\Microsoft\Outlook Express\5.0
Default=False
RegKey1=HKCU\Identities\{9745A9A1-95D3-4584-B4E8-C9C2374B3BD3}\Software\Microsoft\Outlook Express\5.0\Recent Stationery List
[Microsoft Project 2010 *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\14.0\MS Project
Default=False
RegKey1=HKCU\Software\Microsoft\Office\14.0\MS Project\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\14.0\MS Project\Recent Templates
[Microsoft Reader *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Reader_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.Reader_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Reader_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Reader_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Reader_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Reader_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\Microsoft.Reader_*\AC\PRICache|*.*
FileKey6=%LocalAppData%\Packages\Microsoft.Reader_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.Reader_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Reader_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Reader_8wekyb3d8bbwe\SearchHistory
[Microsoft Security Essentials *]
LangSecRef=3021
Detect1=HKCU\Software\Microsoft\Microsoft Antimalware
Detect2=HKLM\Software\Microsoft\Microsoft Antimalware
Default=False
FileKey1=%CommonAppData%\Microsoft\Microsoft Antimalware\LocalCopy|*.*|RECURSE
FileKey2=%CommonAppData%\Microsoft\Microsoft Antimalware\Network Inspection System\Support|NisLog.txt.bak
FileKey3=%CommonAppData%\Microsoft\Microsoft Antimalware\Scans\History\Service|*.log|RECURSE
FileKey4=%CommonAppData%\Microsoft\Microsoft Security Client\Support|MSSecurityClient*.log
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Service|*.log|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft Security Client\Support|MSSecurityClient*.log
[Microsoft Silverlight *]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\Silverlight
Default=False
FileKey1=%LocalLowAppData%\Microsoft\Silverlight|*.*|RECURSE
[Microsoft Standalone System Sweeper Tool *]
LangSecRef=3024
Detect=HKCU\Software\Microsoft\Microsoft Standalone System Sweeper Tool
Default=False
FileKey1=%CommonAppData%\Microsoft\Microsoft Standalone System Sweeper Tool\Support|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft Standalone System Sweeper Tool\Support|*.log
[Microsoft Ultimate Word Games *]
Section=Games
DetectFile=%LocalAppData%\Packages\Microsoft.Studios.Wordament_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Studios.Wordament_*\TempState|*.log
[Microsoft XNA Game Studio *]
Section=Games
Detect=HKLM\Software\Microsoft\XNA
Default=False
FileKey1=%ProgramFiles%\Microsoft XNA\XNA Game Studio\*\Redist|*.*|REMOVESELF
[Microsoft.VCLibs *]
LangSecRef=3031
Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.VCLibs.110.00_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.VCLibs.120.00_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.VCLibs.1*0.00_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\PRICache|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\LocalState\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\LocalState\navigationHistory|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.VCLibs.*_*\TempState|*.*|RECURSE
[Midori *]
LangSecRef=3022
Detect=HKLM\Software\Midori
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\Temporary Internet Files\Midori|*.*|RECURSE
FileKey2=%LocalAppData%\Midori|cookies.db;history.*;session.xbel
[Migration Wizard *]
LangSecRef=3025
DetectFile=%WinDir%\System32\migwiz\migwiz.exe
Default=False
FileKey1=%LocalAppData%\MigWiz|*.*|REMOVESELF
[MiKTeX *]
LangSecRef=3021
Detect=HKCU\Software\MiKTeX.org\MiKTeX
Default=False
FileKey1=%CommonAppData%\MiKTeX\*\miktex\log|*.log
FileKey2=%LocalAppData%\MiKTeX\*\miktex\log|*.log
FileKey3=%LocalAppData%\VirtualStore\Program Files*\MiKTeX\miktex\config|*.log
FileKey4=%LocalAppData%\VirtualStore\ProgramData\MiKTeX\*\miktex\log|*.log
FileKey5=%ProgramFiles%\MiKTeX\miktex\config|*.log
[Minecraft *]
Section=Games
DetectFile=%AppData%\.minecraft
Default=False
FileKey1=%AppData%\.minecraft|*.log;*.log.*|RECURSE
FileKey2=%AppData%\.minecraft\crash-reports|*.*
FileKey3=%AppData%\.minecraft\debug|*.*
FileKey4=%AppData%\.minecraft\stats|*.old
FileKey5=%AppData%\java|*.*|REMOVESELF
[Miranda IM *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Miranda IM
Default=False
FileKey1=%AppData%\Miranda IM\Profiles|*.*|REMOVESELF
[Miranda IM Chat Log *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Miranda IM
Default=False
FileKey1=%AppData%\Miranda IM\Profiles\*\Logs\Chat|*.*|REMOVESELF
[mIRC *]
LangSecRef=3022
Detect=HKCU\Software\mIRC
Default=False
FileKey1=%AppData%\mIRC\Logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\mIRC\logs|*.*
FileKey3=%ProgramFiles%\mIRC\logs|*.*
[Mirkes.De Tiny Hexer *]
LangSecRef=3021
Detect=HKCU\Software\mirkes.de\Tiny Hexer
Default=False
FileKey1=%AppData%\mirkes.de\Tiny Hexer\*|*.bak
[MiTeC DFM Editor *]
LangSecRef=3021
Detect=HKCU\Software\MiTeC\DFM Editor
Default=False
RegKey1=HKCU\Software\MiTeC\DFM Editor\5.x\Main\MRUHistory
[MixiDj Toolbar *]
LangSecRef=3022
DetectFile=%LocalLowAppData%\mixidj_v37
Default=False
FileKey1=%LocalLowAppData%\mixidj_v37\logs|*.*|RECURSE
[Mixxx *]
LangSecRef=3023
DetectFile=%LocalAppData%\Mixxx
Default=False
FileKey1=%LocalAppData%\Mixxx|*.log
[MKS_Vir Skaner Online *]
LangSecRef=3024
DetectFile=%ProgramFiles%\SkanerOnline
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\SkanerOnline\Raporty|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\SkanerOnline\tmp|*.*
FileKey3=%ProgramFiles%\SkanerOnline\Raporty|*.*
FileKey4=%ProgramFiles%\SkanerOnline\tmp|*.*
FileKey5=%SystemDrive%|*.cpp.log
[MMOUI Minion *]
Section=Games
DetectFile=%AppData%\MMOUI\Minion
Default=False
FileKey1=%AppData%\MMOUI\Minion|log.*
[Mo-Search *]
LangSecRef=3024
Detect=HKCU\Software\Meauxsoft\Mo-Search
Default=False
FileKey1=%LocalAppData%\Meauxsoft\Mo-Search4.0\Logs|*.*
RegKey1=HKCU\Software\Meauxsoft\Mo-Search\Mo-Search v4.0.13\Last Position
[Mobile Broadband HL *]
LangSecRef=3021
DetectFile=%CommonAppData%\MobileBrServ
Default=False
FileKey1=%CommonAppData%\MobileBrServ\log|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\ProgramData\MobileBrServ\log|*.*|REMOVESELF
[Mojo *]
LangSecRef=3022
DetectFile=%AppData%\Deusty\Mojo
Default=False
FileKey1=%AppData%\Deusty\Mojo\*|*.log
FileKey2=%LocalAppData%\Deusty\Mojo|crash*.txt
[Molotov.tv *]
LangSecRef=3023
DetectFile=%AppData%\Molotov
Default=False
FileKey1=%AppData%\Molotov|Cookies*;QuotaManager*
FileKey2=%AppData%\Molotov\*Cache|*.*
FileKey3=%AppData%\Molotov\databases|*.*
FileKey4=%AppData%\Molotov\IndexedDB|*.*|RECURSE
FileKey5=%LocalAppData%\Molotov|SquirrelSetup.log
[MoreTerra *]
Section=Games
DetectFile=%AppData%\MoreTerra
Default=False
FileKey1=%AppData%\MoreTerra\Logs|*.*|RECURSE
[Morpheus *]
LangSecRef=3023
Detect=HKCU\Software\Morpheus
Default=False
Warning=This will clear your shared folder and databases.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Morpheus\DB|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Morpheus\My Shared Folder|*.*|RECURSE
FileKey3=%ProgramFiles%\Morpheus\DB|*.*|RECURSE
FileKey4=%ProgramFiles%\Morpheus\My Shared Folder|*.*|RECURSE
[Motherboard Monitor 5 *]
LangSecRef=3023
Detect=HKCU\Software\Alexander van Kaam\MBM 5
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Motherboard Monitor 5\Log|*.*|REMOVESELF
FileKey2=%ProgramFiles%\Motherboard Monitor 5\Log|*.*|REMOVESELF
[Motorola Device Manager *]
LangSecRef=3024
DetectFile=%AppData%\Motorola\MotoHelper
Default=False
FileKey1=%AppData%\Motorola\MotoHelper|*.log
[Mount & Blade *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\22100
Detect2=HKCU\Software\Valve\Steam\Apps\48700
Detect3=HKCU\Software\Valve\Steam\Apps\48705
Detect4=HKCU\Software\Valve\Steam\Apps\48720
Detect5=HKLM\Software\Mount&Blade
Detect6=HKLM\Software\Mount&Blade Warband
Detect7=HKLM\Software\Mount&Blade With Fire and Sword
Detect8=HKLM\Software\Mount&Blade: Warband - Napoleonic Wars
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Mount&Blade*|rgl_log.txt|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Napoleonic Wars|rgl_log.txt|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Mount&Blade*|rgl_log.txt|RECURSE
FileKey4=%ProgramFiles%\Mount&Blade*|rgl_log.txt|RECURSE
FileKey5=%ProgramFiles%\Napoleonic Wars|rgl_log.txt|RECURSE
FileKey6=%ProgramFiles%\Steam\steamapps\common\Mount&Blade*|rgl_log.txt|RECURSE
[Mousotron *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Mousotron
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Mousotron|*.log
FileKey2=%ProgramFiles%\Mousotron|*.log
[Movavi Video Converter *]
LangSecRef=3023
Detect=HKCU\Software\MOVAVI
Default=False
FileKey1=%LocalAppData%\Movavi\Logs\VideoConverter*|*.*
FileKey2=%LocalAppData%\Movavi\Video Converter|Log.txt
[Move Media Player *]
LangSecRef=3023
Detect=HKCU\Software\Move Media Player
Default=False
FileKey1=%AppData%\Move Networks\QMCache00|*.*
FileKey2=%AppData%\Move Networks\temp|*.*
[Movies & TV *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe*
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\PRICache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalCache\PlayReady\Cache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\Database\anonymous|*.log
FileKey11=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageCache|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageRetrievalFailure|*.*|RECURSE
FileKey13=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\ImageStore|*.*|RECURSE
FileKey14=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\navigationHistory|*.*|RECURSE
FileKey15=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\LocalState\PlayReady|*.*|RECURSE
FileKey16=%LocalAppData%\Packages\Microsoft.ZuneVideo_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneVideo_8wekyb3d8bbwe\SearchHistory\SearchHistory
[MP3Gain *]
LangSecRef=3023
Detect=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\MP3Gain|*.log
FileKey2=%ProgramFiles%\MP3Gain|*.log
RegKey1=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis\StartUp|AddFilesPath
RegKey2=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis\StartUp|AddFolderPath
RegKey3=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis\StartUp|ChangeLog
RegKey4=HKCU\Software\VB and VBA Program Settings\MP3GainAnalysis\StartUp|ErrLog
[Mp3Rocket *]
LangSecRef=3023
DetectFile=%AppData%\Mp3Rocket
Default=False
FileKey1=%AppData%\Mp3Rocket|*.cache
[Mp3tag *]
LangSecRef=3023
Detect=HKLM\Software\Florian Heidenreich\Mp3tag
Default=False
FileKey1=%AppData%\Mp3tag|Mp3tagError.log
[MPEG Audio Collection *]
LangSecRef=3023
Detect=HKCU\Software\MPEG Audio Collection
Default=False
RegKey1=HKCU\Software\MPEG Audio Collection|LastNameText1
RegKey2=HKCU\Software\MPEG Audio Collection|LastNameText2
RegKey3=HKCU\Software\MPEG Audio Collection|LastNameText3
RegKey4=HKCU\Software\MPEG Audio Collection|LastNameText4
RegKey5=HKCU\Software\MPEG Audio Collection|LastNameText5
RegKey6=HKCU\Software\MPEG Audio Collection|LastNameText6
[MPlayer *]
LangSecRef=3023
DetectFile=%LocalAppData%\MPlayer
Default=False
FileKey1=%LocalAppData%\MPlayer|*.cache-3
[MS AntiMalware *]
LangSecRef=3025
DetectFile=%CommonAppData%\Microsoft\Microsoft antimalware
Default=False
Warning=This will make MS Security Essentials think it has never run a scan.
FileKey1=%CommonAppData%\Microsoft\Microsoft antimalware\network inspection system\Support|*.log
FileKey2=%CommonAppData%\Microsoft\Microsoft antimalware\scans\history\results\Quick|*.*|REMOVESELF
FileKey3=%CommonAppData%\Microsoft\Microsoft antimalware\scans\history\results\resource|*.*|REMOVESELF
FileKey4=%CommonAppData%\Microsoft\Microsoft antimalware\scans\history\results\System|*.*|REMOVESELF
FileKey5=%CommonAppData%\Microsoft\Microsoft antimalware\support|*.log;*.txt
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft antimalware\network inspection system\Support|*.log;*.txt
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft antimalware\scans\history\results\Quick|*.*|REMOVESELF
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft antimalware\scans\history\results\resource|*.*|REMOVESELF
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft antimalware\scans\history\results\System|*.*|REMOVESELF
FileKey10=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Microsoft antimalware\support|*.log
FileKey11=%SystemDrive%\Documents and Settings\NetworkService*\Temp|MpCmdRun.log
FileKey12=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Temp|MpCmdRun.log
[MS Backup *]
LangSecRef=3025
DetectFile=%WinDir%\System32\ntbackup.exe
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows NT\NTBackup\Data|*.log
[MS Baseline Security Analyzer *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Microsoft Baseline Security Analyzer
Default=False
FileKey1=%LocalAppData%\Microsoft\MBSA\Cache|*.*
FileKey2=%UserProfile%\SecurityScans|*.mbsa
[MS Clip Organizer *]
LangSecRef=3025
DetectFile=%AppData%\Microsoft\Clip Organizer
Default=False
FileKey1=%AppData%\Microsoft\Clip Organizer|mstore10.mgc;mstore12.mgc;mstore14.mgc;Offic10.MGC;Offic12.MGC;Offic14.Mgc
[MS Help Workshop *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Help Workshop
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft Help Workshop\Cnt Files
RegKey2=HKCU\Software\Microsoft\Microsoft Help Workshop\Forage Files
RegKey3=HKCU\Software\Microsoft\Microsoft Help Workshop\Hlp Files
RegKey4=HKCU\Software\Microsoft\Microsoft Help Workshop\Hpj Files
RegKey5=HKCU\Software\Microsoft\Microsoft Help Workshop\Map Files
RegKey6=HKCU\Software\Microsoft\Microsoft Help Workshop\Recent File List
[MS HTML Help Workshop *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\HTML Help Workshop
Default=False
RegKey1=HKCU\Software\Microsoft\HTML Help Workshop\Compressed HTML
RegKey2=HKCU\Software\Microsoft\HTML Help Workshop\Html Titles
RegKey3=HKCU\Software\Microsoft\HTML Help Workshop\Project Files
RegKey4=HKCU\Software\Microsoft\HTML Help Workshop\Recent File List
RegKey5=HKCU\Software\Microsoft\HTML Help Workshop\Settings|LastProject
RegKey6=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Folders
RegKey7=HKCU\Software\Microsoft\Microsoft HTML Help Image Editor\Recent File List
[MS IE6 Installation Temps *]
LangSecRef=3025
DetectFile1=%SystemDrive%\msdownld.tmp
DetectFile2=%WinDir%\msdownld.tmp
Default=False
FileKey1=%SystemDrive%|msdownld.tmp
FileKey2=%WinDir%|msdownld.tmp
[MS Imaging *]
LangSecRef=3024
Detect=HKCU\Software\Kodak\Imaging
Default=False
RegKey1=HKCU\Software\Kodak\Imaging\Recent File List
[MS Netmeeting *]
LangSecRef=3022
Detect=HKCU\Software\Microsoft\Conferencing
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\NetMeeting|CallLog.dat
FileKey2=%ProgramFiles%\NetMeeting|CallLog.dat
RegKey1=HKCU\Software\Microsoft\Conferencing\UI\CallMRU
[MS Notepad *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Notepad
Default=False
RegKey1=HKCU\Software\Microsoft\Notepad|replaceString
RegKey2=HKCU\Software\Microsoft\Notepad|searchString
[MS Office *]
LangSecRef=3021
Detect1=HKCU\Software\Microsoft\Office\12.0\Common
Detect2=HKCU\Software\Microsoft\Office\14.0\Common
Detect3=HKCU\Software\Microsoft\Office\15.0\Common
Detect4=HKCU\Software\Microsoft\Office\16.0\Common
Default=False
FileKey1=%AppData%\Microsoft\Document Building Blocks|*.*|RECURSE
FileKey2=%AppData%\Microsoft\Office|*.tmp|RECURSE
FileKey3=%AppData%\Microsoft\OIS|Toolbars.dat
FileKey4=%AppData%\Microsoft\UProof|*.bin;*.XML
FileKey5=%CommonAppData%\Microsoft\ClickToRun\ProductReleases|*.*|RECURSE
FileKey6=%Documents%|~*.ppt;~*.pptx;~*.doc;~*.docx|RECURSE
FileKey7=%LocalAppData%\Microsoft Help|*.*
FileKey8=%LocalAppData%\Microsoft\Office\*|OneNoteOfflineCache.onecache
FileKey9=%LocalAppData%\Microsoft\Office\*\OfficeFileCache|*.*|RECURSE
FileKey10=%LocalAppData%\Microsoft\Office\OTele|*.*|RECURSE
FileKey11=%LocalAppData%\Microsoft\OneNote\*|OneNoteOfflineCache.onecache
FileKey12=%LocalAppData%\Microsoft\OneNote\*\cache|*.*|RECURSE
FileKey13=%LocalAppData%\Microsoft\OneNote\*\OneNoteOfflineCache_Files|*.*|RECURSE
FileKey14=%SystemDrive%|propfix.log
RegKey1=HKCU\Software\Microsoft\Office\11.0\MSE|LastLoadedSolution
RegKey2=HKCU\Software\Microsoft\Office\11.0\MSE\FileMRUList
RegKey3=HKCU\Software\Microsoft\Office\11.0\MSE\ProjectMRUList
RegKey4=HKCU\Software\Microsoft\Office\11.0\MSE\SolutionMRUList
RegKey5=HKCU\Software\Microsoft\Office\12.0\Common\Internet|UseRWHlinkNavigation
RegKey6=HKCU\Software\Microsoft\Office\12.0\Word\Reading Locations
RegKey7=HKCU\Software\Microsoft\Office\14.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\Office\14.0\Word\Reading Locations
RegKey9=HKCU\Software\Microsoft\Office\15.0\Common\Internet|UseRWHlinkNavigation
RegKey10=HKCU\Software\Microsoft\Office\15.0\Word\Reading Locations
RegKey11=HKCU\Software\Microsoft\Office\16.0\Common\Internet|UseRWHlinkNavigation
RegKey12=HKCU\Software\Microsoft\Office\16.0\Word\Reading Locations
RegKey13=HKCU\Software\Microsoft\Office\Common|FontBmpCache
RegKey14=HKCU\Software\Microsoft\OfficeCustomizeWizard\12.0\RecentFileList
RegKey15=HKCU\Software\Microsoft\OfficeCustomizeWizard\14.0\RecentFileList
RegKey16=HKCU\Software\Microsoft\OfficeCustomizeWizard\15.0\RecentFileList
RegKey17=HKCU\Software\Microsoft\OfficeCustomizeWizard\16.0\RecentFileList
[MS Office Recent Templates *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office
Default=False
FileKey1=%AppData%\Microsoft\Templates|*.xlt;*.xltx;*.pot;*.potx;*.dot;*.dotx
RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\OfficeStart\Web\Templates
RegKey2=HKCU\Software\Microsoft\Office\12.0\Excel\Recent Templates
RegKey3=HKCU\Software\Microsoft\Office\12.0\PowerPoint\Recent Templates
RegKey4=HKCU\Software\Microsoft\Office\12.0\Word\Recent Templates
RegKey5=HKCU\Software\Microsoft\Office\14.0\Common\OfficeStart\Web\Templates
RegKey6=HKCU\Software\Microsoft\Office\14.0\Excel\Recent Templates
RegKey7=HKCU\Software\Microsoft\Office\14.0\PowerPoint\Recent Templates
RegKey8=HKCU\Software\Microsoft\Office\14.0\Word\Recent Templates
RegKey9=HKCU\Software\Microsoft\Office\15.0\Common\OfficeStart\Web\Templates
RegKey10=HKCU\Software\Microsoft\Office\15.0\Excel\Recent Templates
RegKey11=HKCU\Software\Microsoft\Office\15.0\PowerPoint\Recent Templates
RegKey12=HKCU\Software\Microsoft\Office\15.0\Word\Recent Templates
RegKey13=HKCU\Software\Microsoft\Office\16.0\Common\OfficeStart\Web\Templates
RegKey14=HKCU\Software\Microsoft\Office\16.0\Excel\Recent Templates
RegKey15=HKCU\Software\Microsoft\Office\16.0\PowerPoint\Recent Templates
RegKey16=HKCU\Software\Microsoft\Office\16.0\Word\Recent Templates
[MS Office Unsaved Files *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office
Default=False
FileKey1=%AppData%\Microsoft\Excel|*.*|RECURSE
FileKey2=%AppData%\Microsoft\PowerPoint|*.*|RECURSE
FileKey3=%AppData%\Microsoft\Word|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Office\UnsavedFiles|*.*|RECURSE
ExcludeKey1=FILE|%AppData%\Microsoft\Word\|listgal.dat
ExcludeKey2=PATH|%AppData%\Microsoft\Excel\XLSTART\|*.*
ExcludeKey3=PATH|%AppData%\Microsoft\PowerPoint\|PPT*.pcb
ExcludeKey4=PATH|%AppData%\Microsoft\Word\STARTUP\|*.*
[MS PhotoDraw 2000 *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\PhotoDraw\1.0
Default=False
RegKey1=HKCU\Software\Microsoft\PhotoDraw\1.0\Recent File List
[MS Robocopy GUI *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Robocopy GUI
Default=False
FileKey1=%AppData%\Microsoft Robocopy GUI\Logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Microsoft\Microsoft Robocopy GUI\Logs|*.*
FileKey3=%ProgramFiles%\Microsoft\Microsoft Robocopy GUI\Logs|*.*
[MS Search *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey2=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey3=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey4=%CommonAppData%\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows|Windows.edb
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore|*.*|RECURSE
FileKey9=%UserProfile%\Searches|*.search-ms
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData
RegKey3=HKLM\Software\Microsoft\Windows Search\VolumeInfoCache
[MS SmallBasic *]
LangSecRef=3021
DetectFile=%LocalAppData%\SmallBasic\SB.exe.settings.catalog
Default=False
FileKey1=%LocalAppData%\SmallBasic|*.*
[MS SQL Server *]
LangSecRef=3021
Detect1=HKCU\Software\Microsoft\Microsoft SQL Server
Detect2=HKLM\Software\Microsoft\Microsoft SQL Server
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Microsoft SQL Server\*\MSSQL\Log|*ERRORLOG*;*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Microsoft SQL Server\*\Setup Bootstrap\LOG|*.*|RECURSE
FileKey3=%ProgramFiles%\Microsoft SQL Server\*\MSSQL\Log|*ERRORLOG*;*.*|RECURSE
FileKey4=%ProgramFiles%\Microsoft SQL Server\*\Setup Bootstrap\LOG|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Microsoft SQL Server\80\Tools\Shell\FileMRUList
RegKey2=HKCU\Software\Microsoft\Microsoft SQL Server\80\Tools\Shell\ProjectMRUList
RegKey3=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\FileMRUList
RegKey4=HKCU\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\ProjectMRUList
RegKey5=HKCU\Software\Microsoft\Microsoft SQL Server\100\Tools\Shell\FileMRUList
RegKey6=HKCU\Software\Microsoft\Microsoft SQL Server\100\Tools\Shell\ProjectMRUList
RegKey7=HKCU\Software\Microsoft\Microsoft SQL Server\110\Tools\Shell\FileMRUList
RegKey8=HKCU\Software\Microsoft\Microsoft SQL Server\110\Tools\Shell\ProjectMRUList
RegKey9=HKLM\Software\Microsoft\Microsoft SQL Server\80\Tools\Shell\FileMRUList
RegKey10=HKLM\Software\Microsoft\Microsoft SQL Server\80\Tools\Shell\ProjectMRUList
RegKey11=HKLM\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\FileMRUList
RegKey12=HKLM\Software\Microsoft\Microsoft SQL Server\90\Tools\Shell\ProjectMRUList
RegKey13=HKLM\Software\Microsoft\Microsoft SQL Server\100\Tools\Shell\FileMRUList
RegKey14=HKLM\Software\Microsoft\Microsoft SQL Server\100\Tools\Shell\ProjectMRUList
RegKey15=HKLM\Software\Microsoft\Microsoft SQL Server\110\Tools\Shell\FileMRUList
RegKey16=HKLM\Software\Microsoft\Microsoft SQL Server\110\Tools\Shell\ProjectMRUList
[MS UserScanProfiles *]
LangSecRef=3025
DetectFile=%LocalAppData%\Microsoft\UserScanProfiles
Default=False
FileKey1=%LocalAppData%\Microsoft\UserScanProfiles|*.*
[MS Visual Basic 2010 Express MRU *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VBExpress\10.0
Default=False
RegKey1=HKCU\Software\Microsoft\VBExpress\10.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VBExpress\10.0\ProjectMRUList
[MS Visual Basic 2010 Express Search History *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VBExpress\10.0
Default=False
RegKey1=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find
RegKey2=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 0
RegKey3=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 1
RegKey4=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 2
RegKey5=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 3
RegKey6=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 4
RegKey7=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 5
RegKey8=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 6
RegKey9=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 7
RegKey10=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 8
RegKey11=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 9
RegKey12=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 10
RegKey13=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 11
RegKey14=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 12
RegKey15=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 13
RegKey16=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 14
RegKey17=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 15
RegKey18=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 16
RegKey19=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 17
RegKey20=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 18
RegKey21=HKCU\Software\Microsoft\VBExpress\10.0\Find|Find 19
RegKey22=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace
RegKey23=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 0
RegKey24=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 1
RegKey25=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 2
RegKey26=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 3
RegKey27=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 4
RegKey28=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 5
RegKey29=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 6
RegKey30=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 7
RegKey31=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 8
RegKey32=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 9
RegKey33=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 10
RegKey34=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 11
RegKey35=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 12
RegKey36=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 13
RegKey37=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 14
RegKey38=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 15
RegKey39=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 16
RegKey40=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 17
RegKey41=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 18
RegKey42=HKCU\Software\Microsoft\VBExpress\10.0\Find|Replace 19
[MS Visual C# 2010 Express MRU *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VCSExpress\10.0
Default=False
RegKey1=HKCU\Software\Microsoft\VCSExpress\10.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VCSExpress\10.0\ProjectMRUList
[MS Visual C# 2010 Express Search History *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VCSExpress\10.0
Default=False
RegKey1=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find
RegKey2=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 0
RegKey3=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 1
RegKey4=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 2
RegKey5=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 3
RegKey6=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 4
RegKey7=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 5
RegKey8=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 6
RegKey9=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 7
RegKey10=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 8
RegKey11=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 9
RegKey12=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 10
RegKey13=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 11
RegKey14=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 12
RegKey15=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 13
RegKey16=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 14
RegKey17=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 15
RegKey18=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 16
RegKey19=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 17
RegKey20=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 18
RegKey21=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Find 19
RegKey22=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace
RegKey23=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 0
RegKey24=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 1
RegKey25=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 2
RegKey26=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 3
RegKey27=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 4
RegKey28=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 5
RegKey29=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 6
RegKey30=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 7
RegKey31=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 8
RegKey32=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 9
RegKey33=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 10
RegKey34=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 11
RegKey35=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 12
RegKey36=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 13
RegKey37=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 14
RegKey38=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 15
RegKey39=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 16
RegKey40=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 17
RegKey41=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 18
RegKey42=HKCU\Software\Microsoft\VCSExpress\10.0\Find|Replace 19
[MS Visual C++ 2010 Express MRU *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VCExpress\10.0
Default=False
RegKey1=HKCU\Software\Microsoft\VCExpress\10.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VCExpress\10.0\ProjectMRUList
[MS Visual C++ 2010 Express Search History *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VCExpress\10.0
Default=False
RegKey1=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find
RegKey2=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 0
RegKey3=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 1
RegKey4=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 2
RegKey5=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 3
RegKey6=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 4
RegKey7=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 5
RegKey8=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 6
RegKey9=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 7
RegKey10=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 8
RegKey11=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 9
RegKey12=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 10
RegKey13=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 11
RegKey14=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 12
RegKey15=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 13
RegKey16=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 14
RegKey17=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 15
RegKey18=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 16
RegKey19=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 17
RegKey20=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 18
RegKey21=HKCU\Software\Microsoft\VCExpress\10.0\Find|Find 19
RegKey22=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace
RegKey23=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 0
RegKey24=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 1
RegKey25=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 2
RegKey26=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 3
RegKey27=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 4
RegKey28=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 5
RegKey29=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 6
RegKey30=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 7
RegKey31=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 8
RegKey32=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 9
RegKey33=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 10
RegKey34=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 11
RegKey35=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 12
RegKey36=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 13
RegKey37=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 14
RegKey38=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 15
RegKey39=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 16
RegKey40=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 17
RegKey41=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 18
RegKey42=HKCU\Software\Microsoft\VCExpress\10.0\Find|Replace 19
[MS Visual Express 10 Backup *]
LangSecRef=3021
DetectFile=%AppData%\Microsoft\VCExpress\10.0
Default=False
FileKey1=%AppData%\Microsoft\VCExpress\10.0|*.winprf_backup
[MS Visual Studio *]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\VisualStudio
Default=False
FileKey1=%LocalAppData%\Microsoft\VisualStudio\SettingsLogs|*.*|RECURSE
FileKey2=%LocalAppData%\PerfWatson|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Microsoft Visual Studio *\*\Logs|*.*|REMOVESELF
FileKey4=%ProgramFiles%\Microsoft Visual Studio *\*\Logs|*.*|REMOVESELF
[MS Visual Studio 2017 Installation packages *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio
Default=False
FileKey1=%CommonAppData%\Microsoft\VisualStudio\Packages|*.*|RECURSE
ExcludeKey1=PATH|%CommonAppData%\Microsoft\VisualStudio\Packages\_Instances\|*.*
[MS Visual Studio Backup *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio
Default=False
FileKey1=%Documents%\Visual Studio *\Backup Files|*.*|RECURSE
[MS Visual Studio Caches *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio
Default=False
FileKey1=%LocalAppData%\Microsoft\VisualStudio\*\ComponentModelCache|*.*
FileKey2=%LocalAppData%\Microsoft\VisualStudio\*\Extensions|*.cache
FileKey3=%LocalAppData%\Microsoft\VisualStudio\*\ImageLibrary|*.cache
FileKey4=%LocalAppData%\Microsoft\VisualStudio\*\MEFCacheBackup|*.*
FileKey5=%LocalAppData%\Microsoft\VisualStudio\*\Notifications|*.cache
FileKey6=%LocalAppData%\Microsoft\VisualStudio\*\ProjectAssemblies|*.*
FileKey7=%LocalAppData%\Microsoft\VisualStudio\*\TextMateCache|*.*
FileKey8=%LocalAppData%\Microsoft\websiteCache|*.*|RECURSE
FileKey9=%LocalAppData%\NuGet\Cache|*.*|RECURSE
FileKey10=%LocalAppData%\NuGet\v3-cache|*.*|REMOVESELF
FileKey11=%UserProfile%\.nuget|*.*|RECURSE
[MS Visual Studio MRU *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\9.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\9.0\LastLoadedSolution
RegKey3=HKCU\Software\Microsoft\VisualStudio\9.0\ProjectMRUList
RegKey4=HKCU\Software\Microsoft\VisualStudio\10.0\FileMRUList
RegKey5=HKCU\Software\Microsoft\VisualStudio\10.0\LastLoadedSolution
RegKey6=HKCU\Software\Microsoft\VisualStudio\10.0\ProjectMRUList
RegKey7=HKCU\Software\Microsoft\VisualStudio\11.0\FileMRUList
RegKey8=HKCU\Software\Microsoft\VisualStudio\11.0\LastLoadedSolution
RegKey9=HKCU\Software\Microsoft\VisualStudio\11.0\ProjectMRUList
RegKey10=HKCU\Software\Microsoft\VisualStudio\12.0\FileMRUList
RegKey11=HKCU\Software\Microsoft\VisualStudio\12.0\LastLoadedSolution
RegKey12=HKCU\Software\Microsoft\VisualStudio\12.0\ProjectMRUList
RegKey13=HKCU\Software\Microsoft\VisualStudio\14.0\FileMRUList
RegKey14=HKCU\Software\Microsoft\VisualStudio\14.0\LastLoadedSolution
RegKey15=HKCU\Software\Microsoft\VisualStudio\14.0\ProjectMRUList
[MS Visual Studio Search History *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio
Default=False
RegKey1=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 0
RegKey2=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 1
RegKey3=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 2
RegKey4=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 3
RegKey5=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 4
RegKey6=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 5
RegKey7=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 6
RegKey8=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 7
RegKey9=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 8
RegKey10=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 9
RegKey11=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 10
RegKey12=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 11
RegKey13=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 12
RegKey14=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 13
RegKey15=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 14
RegKey16=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 15
RegKey17=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 16
RegKey18=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 17
RegKey19=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 18
RegKey20=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Find 19
RegKey21=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 0
RegKey22=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 1
RegKey23=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 2
RegKey24=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 3
RegKey25=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 4
RegKey26=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 5
RegKey27=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 6
RegKey28=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 7
RegKey29=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 8
RegKey30=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 9
RegKey31=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 10
RegKey32=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 11
RegKey33=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 12
RegKey34=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 13
RegKey35=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 14
RegKey36=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 15
RegKey37=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 16
RegKey38=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 17
RegKey39=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 18
RegKey40=HKCU\Software\Microsoft\VisualStudio\9.0\Find|Replace 19
RegKey41=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 0
RegKey42=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 1
RegKey43=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 2
RegKey44=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 3
RegKey45=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 4
RegKey46=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 5
RegKey47=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 6
RegKey48=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 7
RegKey49=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 8
RegKey50=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 9
RegKey51=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 10
RegKey52=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 11
RegKey53=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 12
RegKey54=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 13
RegKey55=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 14
RegKey56=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 15
RegKey57=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 16
RegKey58=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 17
RegKey59=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 18
RegKey60=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Find 19
RegKey61=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 0
RegKey62=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 1
RegKey63=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 2
RegKey64=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 3
RegKey65=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 4
RegKey66=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 5
RegKey67=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 6
RegKey68=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 7
RegKey69=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 8
RegKey70=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 9
RegKey71=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 10
RegKey72=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 11
RegKey73=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 12
RegKey74=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 13
RegKey75=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 14
RegKey76=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 15
RegKey77=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 16
RegKey78=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 17
RegKey79=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 18
RegKey80=HKCU\Software\Microsoft\VisualStudio\10.0\Find|Replace 19
RegKey81=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 0
RegKey82=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 1
RegKey83=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 2
RegKey84=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 3
RegKey85=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 4
RegKey86=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 5
RegKey87=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 6
RegKey88=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 7
RegKey89=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 8
RegKey90=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 9
RegKey91=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 10
RegKey92=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 11
RegKey93=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 12
RegKey94=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 13
RegKey95=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 14
RegKey96=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 15
RegKey97=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 16
RegKey98=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 17
RegKey99=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 18
RegKey100=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Find 19
RegKey101=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 0
RegKey102=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 1
RegKey103=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 2
RegKey104=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 3
RegKey105=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 4
RegKey106=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 5
RegKey107=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 6
RegKey108=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 7
RegKey109=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 8
RegKey110=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 9
RegKey111=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 10
RegKey112=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 11
RegKey113=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 12
RegKey114=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 13
RegKey115=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 14
RegKey116=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 15
RegKey117=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 16
RegKey118=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 17
RegKey119=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 18
RegKey120=HKCU\Software\Microsoft\VisualStudio\11.0\Find|Replace 19
RegKey121=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find
RegKey122=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 0
RegKey123=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 1
RegKey124=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 2
RegKey125=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 3
RegKey126=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 4
RegKey127=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 5
RegKey128=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 6
RegKey129=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 7
RegKey130=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 8
RegKey131=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 9
RegKey132=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 10
RegKey133=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 11
RegKey134=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 12
RegKey135=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 13
RegKey136=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 14
RegKey137=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 15
RegKey138=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 16
RegKey139=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 17
RegKey140=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 18
RegKey141=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Find 19
RegKey142=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace
RegKey143=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 0
RegKey144=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 1
RegKey145=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 2
RegKey146=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 3
RegKey147=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 4
RegKey148=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 5
RegKey149=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 6
RegKey150=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 7
RegKey151=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 8
RegKey152=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 9
RegKey153=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 10
RegKey154=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 11
RegKey155=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 12
RegKey156=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 13
RegKey157=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 14
RegKey158=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 15
RegKey159=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 16
RegKey160=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 17
RegKey161=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 18
RegKey162=HKCU\Software\Microsoft\VisualStudio\12.0\Find|Replace 19
RegKey163=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace
RegKey164=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 0
RegKey165=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 1
RegKey166=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 2
RegKey167=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 3
RegKey168=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 4
RegKey169=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 5
RegKey170=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 6
RegKey171=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 7
RegKey172=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 8
RegKey173=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 9
RegKey174=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 10
RegKey175=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 11
RegKey176=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 12
RegKey177=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 13
RegKey178=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 14
RegKey179=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 15
RegKey180=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 16
RegKey181=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 17
RegKey182=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 18
RegKey183=HKCU\Software\Microsoft\VisualStudio\14.0\Find|Replace 19
[MS Windows Game Statistics *]
LangSecRef=3025
DetectFile=%LocalAppData%\Microsoft Games
Default=False
FileKey1=%LocalAppData%\Microsoft Games|*.xml;*.xml.bak|RECURSE
[MS Works Suite 2006 *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Works\8.0
Default=False
RegKey1=HKCU\Software\Microsoft\Works\8.0\Recent File List
[MS XML Notepad *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\XML Notepad
Default=False
RegKey1=HKCU\Software\Microsoft\XML Notepad\Recent File List
[MSConfig *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Shared Tools\MSConfig
Default=False
RegKey1=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandFrom
RegKey2=HKLM\Software\Microsoft\Shared Tools\MSConfig\ExpandTo
RegKey3=HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSConfig
[MSI Afterburner Hardware Monitoring *]
LangSecRef=3024
Detect=HKCU\Software\MSI
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\MSI Afterburner|HardwareMonitoring.hml
FileKey2=%ProgramFiles%\MSI Afterburner|HardwareMonitoring.hml
[MTA San Andreas 1.3 *]
Section=Games
DetectFile=%ProgramFiles%\MTA San Andreas 1.3\Multi Theft Auto.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\MTA San Andreas 1.3\MTA\logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\MTA San Andreas 1.3\server\mods\deathmatch\backups|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\MTA San Andreas 1.3\server\mods\deathmatch\logs|*.*
FileKey4=%ProgramFiles%\MTA San Andreas 1.3\MTA\logs|*.*
FileKey5=%ProgramFiles%\MTA San Andreas 1.3\server\mods\deathmatch\backups|*.*
FileKey6=%ProgramFiles%\MTA San Andreas 1.3\server\mods\deathmatch\logs|*.*
[Multi-Edit 2008 *]
LangSecRef=3024
Detect=HKCU\Software\Multi Edit Software\Multi-Edit\11.0
Default=False
FileKey1=%AppData%\Multi Edit Software|*.log|RECURSE
FileKey2=%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\Tmp|*.TMP
ExcludeKey1=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|EVOLVE.LOG
ExcludeKey2=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|FILEPANE.LOG
ExcludeKey3=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|INSTALL.LOG
ExcludeKey4=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|POLYSTYLE.LOG
ExcludeKey5=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|TMPLPANE.LOG
ExcludeKey6=FILE|%AppData%\Multi Edit Software\Multi-Edit\11\Config.04\|WINLIST.LOG
[Multi Commander *]
LangSecRef=3024
Detect=HKLM\Software\MultiCommander
Default=False
Warning=Close Multi Commander application before using this option.
FileKey1=%AppData%\MultiCommander\Logs|*.log
[Multi Password Recovery *]
LangSecRef=3021
Detect=HKLM\System\CurrentControlSet\enum\root\legacy_block_reader
Default=False
RegKey1=HKLM\Software\Classes\.mpf
RegKey2=HKLM\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
RegKey3=HKLM\Software\Classes\MPR.DocHostUIHandler
RegKey4=HKLM\System\CurrentControlSet\enum\root\legacy_block_reader
RegKey5=HKLM\System\CurrentControlSet\Services\block_reader
[MultiBit *]
LangSecRef=3023
DetectFile=%AppData%\MultiBit
Default=False
FileKey1=%AppData%\MultiBit\log|*.*
[MultiHasher *]
LangSecRef=3024
Detect=HKLM\Software\abelhadigital.com\MultiHasher
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\MultiHasher|*.txt;*.zip|RECURSE
FileKey2=%ProgramFiles%\MultiHasher|*.txt;*.zip|RECURSE
[MultiViewInpaint *]
LangSecRef=3021
Detect=HKCU\Software\Teorex\MultiViewInpaint
Default=False
RegKey1=HKCU\Software\Teorex\MultiViewInpaint\Recent File List
RegKey2=HKCU\Software\Teorex\MultiViewInpaint\RecentFileList
[Mumble *]
LangSecRef=3022
Detect=HKCU\Software\Mumble
Default=False
FileKey1=%AppData%\Mumble|console.txt
[Murder, She Wrote *]
Section=Games
DetectFile=%AppData%\MysteryStudio\MSW
Default=False
FileKey1=%AppData%\MysteryStudio\MFW|*.log
[MuseScore *]
LangSecRef=3023
DetectFile=%LocalAppData%\MusE\MuseScore
Default=False
FileKey1=%LocalAppData%\MusE\MuseScore|cookies.txt
[MusicBee *]
LangSecRef=3023
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\MusicBee
Default=False
FileKey1=%AppData%\MusicBee|*.dat
FileKey2=%AppData%\MusicBee\InternalCache|*.*|REMOVESELF
[MusicMatch Jukebox *]
LangSecRef=3023
Detect=HKLM\Software\MUSICMATCH\MUSICMATCH Jukebox
Default=False
FileKey1=%LocalAppData%\Musicmatch\Jukebox\Cache|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\MUSICMATCH\MUSICMATCH Jukebox|*.log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\MUSICMATCH\Musicmatch Jukebox\MMRadio\Cache|*.*|RECURSE
FileKey4=%ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox|*.log|RECURSE
FileKey5=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\MMRadio\Cache|*.*|RECURSE
[MusicNet *]
LangSecRef=3023
DetectFile=%AppData%\MusicNet
Default=False
FileKey1=%AppData%\MusicNet|*.log
[MWConn *]
LangSecRef=3022
DetectFile1=%AppData%\Microsoft\Windows\Start Menu\Programs\MWconn
DetectFile2=%AppData%\Microsoft\Windows\Startmenü\Programs\MWconn
DetectFile3=%UserProfile%\Start Menu\Programs\MWconn
DetectFile4=%UserProfile%\Startmenü\Programme\MWconn
Default=False
FileKey1=%AppData%\Microsoft\Windows\Start*\Program*\MWconn|connlog.txt
FileKey2=%UserProfile%\Start*\Program*\MWconn|connlog.txt
[MWConn SMS *]
LangSecRef=3022
DetectFile1=%AppData%\Microsoft\Windows\Start Menu\Programs\MWconn
DetectFile2=%AppData%\Microsoft\Windows\Startmenü\Programs\MWconn
DetectFile3=%UserProfile%\Start Menu\Programs\MWconn
DetectFile4=%UserProfile%\Startmenü\Programme\MWconn
Default=False
Warning=This will delete all of your SMS messages.
FileKey1=%AppData%\Microsoft\Windows\Start*\Program*\MWconn\sms_*|*.*|RECURSE
FileKey2=%UserProfile%\Start*\Program*\MWconn\sms_*|*.*|RECURSE
[My Family Tree *]
LangSecRef=3021
DetectFile=%LocalAppData%\My Family Tree
Default=False
FileKey1=%LocalAppData%\My Family Tree\MapCache|*.*|RECURSE
FileKey2=%LocalAppData%\My Family Tree\Temp|*.*|RECURSE
[My Horse and Me *]
Section=Games
Detect=HKLM\Software\My Horse and Me 2
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Atari\Mein Pferd und ich*\System|++ Finish log.txt;++ Start log.txt;*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Atari\My Horse and Me|++ Finish log.txt;++ Start log.txt;*.log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Atari\W!Games\My Horse and Me|++ Finish log.txt;++ Start log.txt;*.log|RECURSE
FileKey4=%ProgramFiles%\Atari\Mein Pferd und ich*\System|++ Finish log.txt;++ Start log.txt;*.log|RECURSE
FileKey5=%ProgramFiles%\Atari\My Horse and Me|++ Finish log.txt;++ Start log.txt;*.log|RECURSE
FileKey6=%ProgramFiles%\Atari\W!Games\My Horse and Me|++ Finish log.txt;++ Start log.txt;*.log|RECURSE
[My Movies Collection *]
LangSecRef=3023
DetectFile=%CommonAppData%\My Movies
Default=False
FileKey1=%CommonAppData%\My Movies|vcredist*.*;installerlog.txt;log.txt
FileKey2=%CommonAppData%\My Movies\File Storage\Temp|*.*|RECURSE
FileKey3=%CommonAppData%\My Movies\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\My Movies|installerlog.txt;log.txt
FileKey5=%LocalAppData%\VirtualStore\ProgramData\My Movies\File Storage\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\My Movies\Temp|*.*|RECURSE
[My Office *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\LocalState\AppData\Local\Office\16.0\WebServiceCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.MicrosoftOfficeHub_*\LocalState\Cache|*.*|RECURSE
[My Riding Stables *]
Section=Games
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyRidingStables
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\My Riding Stables*|*.txt;*.url
FileKey2=%ProgramFiles%\My Riding Stables*|*.txt;*.url
[My Singing Monsters *]
Section=Games
Detect1=HKLM\Software\Big Fish Games\Persistence\Install\F7664T1L1
Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\My Singing Monsters1.1
DetectFile=%ProgramFiles%\My Singing Monsters
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\*\My Singing Monsters|*.log;*.txt|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\My Singing Monsters|*.log;*.txt|RECURSE
FileKey3=%ProgramFiles%\*\My Singing Monsters|dotnetfx35setup.exe;*.html;*.PNG;vcredist_x86.exe;*.log;*.txt|RECURSE
FileKey4=%ProgramFiles%\My Singing Monsters|dotnetfx35setup.exe;vcredist_x86.exe;*.log;*.txt|RECURSE
[MyCraft *]
Section=Games
DetectFile=%UserProfile%\Desktop\MyCraft
Default=False
FileKey1=%UserProfile%\Desktop\MyCraft|MyCraft Log.*
[MyDefrag *]
LangSecRef=3021
Detect=HKCU\Software\MyDefrag
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\MyDefrag *|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\MyDefrag *\LOGs|*.*
FileKey3=%ProgramFiles%\MyDefrag *|*.log
FileKey4=%ProgramFiles%\MyDefrag *\LOGs|*.*
[MyPhoneExplorer *]
LangSecRef=3024
Detect=HKCU\Software\MyPhoneExplorer
Default=False
FileKey1=%AppData%\MyPhoneExplorer|Debug.txt
[MySMS *]
LangSecRef=3022
Detect=HKCU\Software\sms.at\mysms
Default=False
FileKey1=%LocalAppData%\sms.at\mysms\LocalStorage|*.*
RegKey1=HKCU\Software\sms.at\mysms\cookies
[MySpaceIM *]
LangSecRef=3022
Detect=HKCU\Software\Myspace\IM
Default=False
FileKey1=%AppData%\MySpace\IM\Dump|*.*
FileKey2=%AppData%\MySpace\IM\Images|*.*
[MySQL Workbench *]
LangSecRef=3021
DetectFile=%AppData%\MySQL\Workbench
Default=False
FileKey1=%AppData%\MySQL\Workbench\cache|*.*
FileKey2=%AppData%\MySQL\Workbench\log|*.log
FileKey3=%AppData%\MySQL\Workbench\sql_history|*.*
[MyToolkit *]
LangSecRef=3024
Detect=HKCU\Software\FutureFog\MyToolkit\Options
Default=False
RegKey1=HKCU\Software\FutureFog\MyToolkit\Options|LastUsedFolder
[myTube! *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\59750RYKENAPPS.435307C335C44_zd92nzxdcatqw
DetectFile=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_zd92nzxdcatqw
Default=False
FileKey1=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\LocalCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\LocalState\YouTubeCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\59750RYKENAPPS.435307C335C44_*\TempState|*.*|RECURSE
[MyWinLocker *]
LangSecRef=3024
DetectFile=%ProgramFiles%\EgisTec\mywinlocker 3
Default=False
FileKey1=%LocalAppData%|mywinlockerinstaller.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\EgisTec\MyWinLocker 3\log|*.*
FileKey3=%ProgramFiles%\EgisTec\MyWinLocker 3\log|*.*
[Nancy Drew - Secret of Shadow Ranch *]
Section=Games
Detect1=HKLM\Software\Big Fish Games\Persistence\Install\F7041T1L1
Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Nancy Drew - Secret of Shadow Ranch - Plus Guide1.0
DetectFile=%ProgramFiles%\Nancy Drew*
Default=False
FileKey1=%ProgramFiles%\*\Nancy Drew*|dxwebsetup.exe;*.html
FileKey2=%ProgramFiles%\Nancy Drew*|dxwebsetup.exe;*.html
[Natural Selection 2 *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\4920
DetectFile=%ProgramFiles%\Steam\steamapps\common\Natural Selection 2
Default=False
Warning=Fixes corrupt cache & cleans cache bloat. The first game & map launch will take longer to load.
FileKey1=%AppData%\Natural Selection 2|log.txt
FileKey2=%AppData%\Natural Selection 2\cache|*.*|RECURSE
[NBC News *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\msnbc.comDigitalNetwork.msnbc.com_amdjbdaxqsje6
DetectFile=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_amdjbdaxqsje6
Default=False
FileKey1=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\Microsoft\CLR_v4.0|*.log
FileKey3=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\PRICache|*.*
FileKey5=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\Temp|*.*
FileKey6=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\TempState|*.*|RECURSE
[Neostar CMS Station Client *]
LangSecRef=3024
Detect=HKLM\Software\company\Neostar CMS
Default=False
FileKey1=%ProgramFiles%\Neostar CMS Station\Neostar CMS\Neostar CMS Client\log|*.*
FileKey2=%ProgramFiles%\Neostar CMS Station\Neostar CMS\Neostar CMS Client\StreamServer|*.log
FileKey3=%ProgramFiles%\Neostar CMS Station\Neostar CMS\Neostar CMS Client\StreamServer\log|*.*
[Nero *]
LangSecRef=3021
Detect1=HKCU\Software\Ahead
Detect2=HKCU\Software\Nero\Nero8
Detect3=HKLM\Software\Nero\Nero 11\Nero11Suite
Detect4=HKLM\Software\Nero\Nero 12\Nero12Suite
Default=False
FileKey1=%AppData%\Nero\Nero Burning ROM|*.log
FileKey2=%AppData%\Nero\Nero*\Nero BackItUp\Cache|*.*
FileKey3=%AppData%\Nero\Nero*\Nero Burning ROM|*.log
FileKey4=%AppData%\Nero\Nero*\Nero Recode\AnalysisData|*.dat
FileKey5=%AppData%\Nero\Nero*\Nero Recode\Thumbs|*.*
FileKey6=%AppData%\Nero\Nero*\Nero Vision|*.txt;*.bin
FileKey7=%AppData%\Nero\Nero*\Nero Vision\NVFACache|*.*
FileKey8=%AppData%\Nero\Nero*\Nero3D|*.log
FileKey9=%CommonAppData%\Nero\PeakFiles|*.tmp
FileKey10=%LocalAppData%\Nero\Nero *\Nero Vision\Cache|*.*
FileKey11=%LocalAppData%\Nero\Nero *\Nero Vision\Cache\GraphicObjectCache|*.*
FileKey12=%LocalAppData%\VirtualStore\ProgramData\Nero\PeakFiles|*.tmp
RegKey1=HKCU\Software\ahead\Nero PhotoSnap\Recent File List
RegKey2=HKCU\Software\Ahead\NeroSearch\NeroSavedSearches\SavedSearches
RegKey3=HKCU\Software\ahead\NeroVision\2.0\RecentFiles
RegKey4=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumeLabelAutoTemplate
RegKey5=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumeLabelISOTemplate
RegKey6=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumelabelJolietTemplate
RegKey7=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Compilation|VolumeLabelUDFTemplate
RegKey8=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Recent File List
RegKey9=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|EncodingLastDir
RegKey10=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|NeroCompilation
RegKey11=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|TrackSaveDir
RegKey12=HKCU\Software\Nero\Nero 11\Nero Burning ROM\Settings|WorkingDir
RegKey13=HKCU\Software\Nero\Nero 11\Nero CoverDesigner\Recent File List
RegKey14=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumeLabelAutoTemplate
RegKey15=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumeLabelISOTemplate
RegKey16=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumelabelJolietTemplate
RegKey17=HKCU\Software\Nero\Nero 11\Nero Express\Compilation|VolumeLabelUDFTemplate
RegKey18=HKCU\Software\Nero\Nero 11\Nero Express\General|OFDLastAudioDir
RegKey19=HKCU\Software\Nero\Nero 11\Nero Express\General|OFDLastISODir
RegKey20=HKCU\Software\Nero\Nero 11\Nero Express\General|OFDLastVideoDVDKey
RegKey21=HKCU\Software\Nero\Nero 11\Nero Express\Recent File List
RegKey22=HKCU\Software\Nero\Nero 11\Nero Express\Settings|BootImageDir
RegKey23=HKCU\Software\Nero\Nero 11\Nero Express\Settings|BrowserDir
RegKey24=HKCU\Software\Nero\Nero 11\Nero Express\Settings|ImageDir
RegKey25=HKCU\Software\Nero\Nero 11\Nero Express\Settings|NeroCompilation
RegKey26=HKCU\Software\Nero\Nero 11\Nero Express\Settings|TrackSaveDir
RegKey27=HKCU\Software\Nero\Nero 11\Nero Express\Settings|WorkingDir
RegKey28=HKCU\Software\Nero\Nero 11\Nero Toolkit\DiscSpeed\Capture|Folder
RegKey29=HKCU\Software\Nero\Nero 11\Nero Toolkit\DiscSpeed\Save|Folder
RegKey30=HKCU\Software\Nero\Nero 11\Nero Vision\Application|AudioDir
RegKey31=HKCU\Software\Nero\Nero 11\Nero Vision\Application|CaptureDir
RegKey32=HKCU\Software\Nero\Nero 11\Nero Vision\Application|DocDir
RegKey33=HKCU\Software\Nero\Nero 11\Nero Vision\Application|ExportAudioDir
RegKey34=HKCU\Software\Nero\Nero 11\Nero Vision\Application|ExportVideoDir
RegKey35=HKCU\Software\Nero\Nero 11\Nero Vision\Application|ImportVideoDir
RegKey36=HKCU\Software\Nero\Nero 11\Nero Vision\Application|MediaDir
RegKey37=HKCU\Software\Nero\Nero 11\Nero Vision\Application|PicDir
RegKey38=HKCU\Software\Nero\Nero 11\Nero Vision\Application|PicSaveDir
RegKey39=HKCU\Software\Nero\Nero 11\Nero Vision\Application|TmpDir
RegKey40=HKCU\Software\Nero\Nero 11\Nero Vision\Application|VideoDir
RegKey41=HKCU\Software\Nero\Nero 11\Nero WaveEditor\Directories|Last
RegKey42=HKCU\Software\Nero\Nero 11\Nero WaveEditor\Recent File List
RegKey43=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumeLabelAutoTemplate
RegKey44=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumeLabelISOTemplate
RegKey45=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumelabelJolietTemplate
RegKey46=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Compilation|VolumeLabelUDFTemplate
RegKey47=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|EncodingLastDir
RegKey48=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|TrackSaveDir
RegKey49=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|WorkingDir
RegKey50=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumeLabelAutoTemplate
RegKey51=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumeLabelISOTemplate
RegKey52=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumelabelJolietTemplate
RegKey53=HKCU\Software\Nero\Nero 12\Nero Express\Compilation|VolumeLabelUDFTemplate
RegKey54=HKCU\Software\Nero\Nero 12\Nero Express\Settings|BootImageDir
RegKey55=HKCU\Software\Nero\Nero 12\Nero Express\Settings|ImageDir
RegKey56=HKCU\Software\Nero\Nero 12\Nero Express\Settings|NeroCompilation
RegKey57=HKCU\Software\Nero\Nero 12\Nero Express\Settings|TrackSaveDir
RegKey58=HKCU\Software\Nero\Nero 12\Nero Toolkit\DiscSpeed\Capture|Folder
RegKey59=HKCU\Software\Nero\Nero 12\Nero Toolkit\DiscSpeed\Save|Folder
RegKey60=HKCU\Software\Nero\Nero 12\Nero Vision\Application|AudioDir
RegKey61=HKCU\Software\Nero\Nero 12\Nero Vision\Application|CaptureDir
RegKey62=HKCU\Software\Nero\Nero 12\Nero Vision\Application|DocDir
RegKey63=HKCU\Software\Nero\Nero 12\Nero Vision\Application|ExportAudioDir
RegKey64=HKCU\Software\Nero\Nero 12\Nero Vision\Application|ExportVideoDir
RegKey65=HKCU\Software\Nero\Nero 12\Nero Vision\Application|ImportVideoDir
RegKey66=HKCU\Software\Nero\Nero 12\Nero Vision\Application|MediaDir
RegKey67=HKCU\Software\Nero\Nero 12\Nero Vision\Application|PicDir
RegKey68=HKCU\Software\Nero\Nero 12\Nero Vision\Application|PicSaveDir
RegKey69=HKCU\Software\Nero\Nero 12\Nero Vision\Application|TmpDir
RegKey70=HKCU\Software\Nero\Nero 12\Nero Vision\Application|VideoDir
RegKey71=HKCU\Software\Nero\Nero 12\Nero WaveEditor\Directories|Last
RegKey72=HKCU\Software\Nero\Nero Blu-ray Player\Settings|DefFolder
RegKey73=HKCU\Software\Nero\Nero8\Cover Designer\Recent File List
RegKey74=HKCU\Software\Nero\Nero8\Nero - Burning Rom\Recent File List
[Net Vampire *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Net Vampire
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Net Vampire\Data\Jobs|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Net Vampire\Data\Sites|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Net Vampire\Data\State|*.*|RECURSE
FileKey4=%ProgramFiles%\Net Vampire\Data\Jobs|*.*|RECURSE
FileKey5=%ProgramFiles%\Net Vampire\Data\Sites|*.*|RECURSE
FileKey6=%ProgramFiles%\Net Vampire\Data\State|*.*|RECURSE
[Net2Printer RDP *]
LangSecRef=3021
DetectFile=%AppData%\Net2Printer RDP Client
Default=False
FileKey1=%AppData%\Net2Printer RDP Client|*.*
[NetAnts *]
LangSecRef=3022
DetectFile=%ProgramFiles%\NetAnts
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\NetAnts|netants.job;history.txt
FileKey2=%ProgramFiles%\NetAnts|netants.job;history.txt
[NetBeans IDE *]
LangSecRef=3021
DetectFile1=%AppData%\NetBeans
DetectFile2=%UserProfile%\.nbi\log
Default=False
FileKey1=%AppData%\NetBeans\*\var\log|*.*|RECURSE
FileKey2=%UserProfile%\.nbi\log|*.log|RECURSE
[NetCaptor *]
LangSecRef=3022
Detect=HKCU\Software\Stilesoft\NetCaptor
Default=False
RegKey1=HKCU\Software\Stilesoft\NetCaptor\CurrentVersion\Last Open Sites
[Netflix *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\4DF9E0F8.Netflix_mcm4njqhnhss8
DetectFile=%LocalAppData%\Packages\4DF9E0F8.Netflix_mcm4njqhnhss8
Default=False
FileKey1=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey4=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\PRICache|*.*
FileKey5=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AC\Temp|*.*
FileKey6=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\AppData\Indexed DB|*.log
FileKey7=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\LocalState|*.tmp|RECURSE
FileKey8=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\LocalState\LiveTile|*.*
FileKey9=%LocalAppData%\Packages\4DF9E0F8.Netflix_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\4DF9E0F8.Netflix_mcm4njqhnhss8\SearchHistory
[NETGEAR Genie *]
LangSecRef=3024
Detect=HKLM\Software\NETGEAR Genie
Default=False
FileKey1=%LocalAppData%\NETGEARGenie|*.txt
FileKey2=%LocalAppData%\NETGEARGenie\log|*.log
FileKey3=%LocalAppData%\NETGEARGenie\update_temp|*.*
[Network Speed Test *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.NetworkSpeedTest_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_*\AC\Microsoft\CLR_v4.0*\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_*\AC\Temp|*.*
FileKey5=%LocalAppData%\Packages\Microsoft.NetworkSpeedTest_*\TempState|*.*|RECURSE
[NetworkService *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\NetworkService*\Cookies|*.*|RECURSE
FileKey2=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\Content.IE5|*.*|RECURSE
FileKey3=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\History|*.*|RECURSE
FileKey4=%SystemDrive%\Documents and Settings\NetworkService*\Local Settings\Temp|*.*|RECURSE
FileKey5=%SystemDrive%\Documents and Settings\NetworkService\*Local Settings\Temporary Internet Files|*.*|RECURSE
FileKey6=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Content.IE5|*.*|RECURSE
FileKey7=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History|*.*|RECURSE
FileKey8=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files|*.*|RECURSE
FileKey9=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Temp|*.*|RECURSE
FileKey10=%WinDir%\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies|*.*|RECURSE
FileKey11=%WinDir%\ServiceProfiles\NetworkService\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content|*.*|RECURSE
FileKey12=%WinDir%\ServiceProfiles\NetworkService\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData|*.*|RECURSE
FileKey13=%WinDir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies|*.*|RECURSE
FileKey14=%WinDir%\ServiceProfiles\NetworkService\debug|*.log
[Neverwinter *]
Section=Games
Detect=HKCU\Software\Cryptic\Neverwinter
Default=False
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Cryptic Studios|*.log|RECURSE
FileKey2=%ProgramFiles%\Steam\SteamApps\common\Cryptic Studios\localdata|_SWMWindowPosList.txt
FileKey3=%Public%\Games\Cryptic Studios|*.log|RECURSE
FileKey4=%Public%\Games\Cryptic Studios\localdata|_SWMWindowPosList.txt
[New Yankee 3 - In Santas Service *]
Section=Games
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\New Yankee 3 - In Santas ServiceFinal
Default=False
FileKey1=%AppData%\AlawarEntertainment|*_log.html|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\New Yankee 3 - In Santas Service|*.nfo
FileKey3=%ProgramFiles%\New Yankee 3 - In Santas Service|*.nfo
[News *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingNews_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\PRICache|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingNews_*\LocalState\navigationHistory|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe\SearchHistory
[Newsbin Pro *]
LangSecRef=3021
Detect=HKCU\Software\DJI Interprises\Newsbin50
Default=False
FileKey1=%LocalAppData%\Newsbin|Logfile.txt;Downloaded.db3;DownloadMarker.db3;Downloads.db3*
FileKey2=%LocalAppData%\Newsbin\SPOOL_V6|*.*
FileKey3=%LocalAppData%\Newsbin\temp|*.*
[Newsleecher *]
LangSecRef=3021
DetectFile=%AppData%\Newsleecher\Backups
Default=False
FileKey1=%AppData%\Newsleecher\Backups|*.*
[neXBC *]
LangSecRef=3022
DetectFile=%ProgramFiles%\neXBC\neXBC.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\neXBC|messages.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\neXBC\Logs\Hosted|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\neXBC\Logs\Joined|*.*
FileKey4=%ProgramFiles%\neXBC|messages.txt
FileKey5=%ProgramFiles%\neXBC\Logs\Hosted|*.*
FileKey6=%ProgramFiles%\neXBC\Logs\Joined|*.*
[Nextup TextAloud *]
LangSecRef=3021
Detect=HKCU\Software\NextUpTech\TextAloud3
Default=False
FileKey1=%LocalAppData%\NextUp\TextAloud|*.adu;*.adl;*.dbg
FileKey2=%LocalAppData%\NextUp\TextAloud\Articles|*.*|RECURSE
RegKey1=HKCU\Software\NextUpTech\TextAloud3|AudioClipFileOpenDirectory
RegKey2=HKCU\Software\NextUpTech\TextAloud3|DocFileOpenDirectory
[Nexus Mod Manager *]
Section=Games
DetectFile=%Documents%\Nexus Mod Manager
Default=False
FileKey1=%Documents%\Nexus Mod Manager|*.txt
[NFS Hot Pursuit 2010 Saves *]
Section=Games
Detect=HKCU\Software\Electronic Arts\Need for Speed(TM) Hot Pursuit
Default=False
Warning=This will delete your saved games for NFS Hot Pursuit
FileKey1=%Documents%\Criterion Games|*.*|REMOVESELF
[Nidhogg *]
Section=Games
DetectFile=%AppData%\Nidhogg
Default=False
FileKey1=%AppData%\Nidhogg|*.log
[Nikon Capture NX2 *]
LangSecRef=3023
Detect=HKLM\Software\Nikon\Capture NX 2
Default=False
FileKey1=%LocalAppData%\Nikon\Capture NX\ThumbnailCache|*.*|RECURSE
[Nikon ViewNX 2 Pic Viewer *]
LangSecRef=3023
Detect=HKLM\Software\Nikon\MCA2\ViewNX 2
Default=False
FileKey1=%LocalAppData%\Nikon\mPT\*\CacheData\Original|*.*
FileKey2=%LocalAppData%\Nikon\mPT\*\CacheData\Others|*.*
FileKey3=%LocalAppData%\Nikon\mPT\*\CacheData\Screen|*.*
FileKey4=%LocalAppData%\Nikon\mPT\*\CacheData\Thumbnail|*.*
FileKey5=%LocalAppData%\Nikon\ViewNX 2\Cache|*.*
[Nimbuzz *]
LangSecRef=3022
Detect=HKCU\Software\Nimbuzz
Default=False
FileKey1=%AppData%\nimbuzz|*.log
[NirSoft AddrView LastUrlAddr *]
LangSecRef=3024
Detect=HKCU\Software\NirSoft\AddrView
Default=False
RegKey1=HKCU\Software\NirSoft\AddrView|LastUrlAddr
[NirSoft RegistryChangesView Snapshots *]
LangSecRef=3024
DetectFile=%ProgramFiles%\NirSoft\RegistryChangesView.exe
Default=False
FileKey1=%ProgramFiles%\NirSoft\RegSnapshot*|*.*|REMOVESELF
FileKey2=%ProgramFiles%\NirSoft\x64\RegSnapshot*|*.*|REMOVESELF
[NirSoft RegScanner Reports *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\NirSoft RegScanner
DetectFile=%ProgramFiles%\Nirsoft\regscanner.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\NirSoft|report.html
FileKey2=%LocalAppData%\VirtualStore\Program Files*\NirSoft\x64|report.html
FileKey3=%ProgramFiles%\NirSoft|report.html
FileKey4=%ProgramFiles%\NirSoft\x64|report.html
[Nitro PDF Reader *]
LangSecRef=3024
Detect=HKCU\Software\Nitro PDF\Reader
Default=False
FileKey1=%AppData%\Nitro|*.log*;*Log.txt*|RECURSE
RegKey1=HKCU\Software\Nitro PDF\Reader\1.0\Recent File List
RegKey2=HKCU\Software\Nitro PDF\Reader\2.0\Recent File List
[Nitrous Backups *]
Section=Games
DetectFile=%AppData%\.nitrous
Default=False
FileKey1=%AppData%\.nitrous\backups|*.*|REMOVESELF
[nLite *]
LangSecRef=3024
DetectFile=%ProgramFiles%\nLite
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\nLite\Presets|*.*
FileKey2=%ProgramFiles%\nLite\Presets|*.*
[No-IP DUC *]
LangSecRef=3022
Detect=HKCU\Software\Vitalwerks\DUC
Default=False
FileKey1=%CommonAppData%\Vitalwerks\DUC|*.log
FileKey2=%LocalAppData%\Vitalwerks\DUC|*.log
[Nokia Music Player *]
LangSecRef=3023
DetectFile=%LocalAppData%\Nokia\Nokia Music*
Default=False
FileKey1=%LocalAppData%\Nokia\Nokia Music*|*.log
[Nokia Software Updater *]
LangSecRef=3021
Detect1=HKCU\Software\Nokia\NSU3
Detect2=HKLM\Software\Nokia\Nokia Suite
DetectFile1=%CommonAppData%\Nokia\Nokia Service Layer\A
DetectFile2=%CommonProgramFiles%\Nokia\Service Layer\A
Default=False
Warning=This will remove Nokia phone firmwares, applications and other files stored by Nokia Suite Updater. Files will be re-downloaded when updating phone.
FileKey1=%CommonAppData%\Nokia\Nokia Service Layer\A|*.*|REMOVESELF
FileKey2=%CommonProgramFiles%\Nokia\Service Layer\A|*.*|REMOVESELF
FileKey3=%LocalAppData%\Nokia\NSU3\NOSSU2|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Common Files\Nokia\Service Layer\A|*.*|REMOVESELF
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Nokia\Nokia Service Layer\A|*.*|REMOVESELF
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Nokia\Nokia Suite\NOSSU2|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Nokia\NSU3\NOSSU2\|usergroups.cfg
ExcludeKey2=PATH|%LocalAppData%\Nokia\NSU3\NOSSU2\Flash\|*.*
[Nokia Suite Installer *]
LangSecRef=3021
DetectFile=%CommonAppData%\NokiaInstallerCache
Default=False
FileKey1=%CommonAppData%\NokiaInstallerCache\PackageCache|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\NokiaInstallerCache\PackageCache|*.*|RECURSE
[Norton *]
LangSecRef=3024
DetectFile=%CommonAppData%\Norton
Default=False
FileKey1=%CommonAppData%\Norton|*.log;*.txt
FileKey2=%CommonAppData%\Norton\LocalDumps|*.dmp
FileKey3=%CommonAppData%\NortonInstaller\Logs|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Norton\LocalDumps|*.dmp
FileKey5=%LocalAppData%\VirtualStore\ProgramData\NortonInstaller\Logs|*.*|RECURSE
[Norton Power Eraser *]
LangSecRef=3024
DetectFile=%CommonAppData%\Norton\NPE\NPEsettings.dat
Default=False
Warning=This removes all files of Norton Power Eraser. This tool should be re-downloaded from Symantec after each run.
FileKey1=%CommonAppData%\Norton\NPE|*.*|REMOVESELF
FileKey2=%LocalAppData%\NPE|*.*|REMOVESELF
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Norton\NPE|*.*|REMOVESELF
FileKey4=%UserProfile%\Desktop|NPE.exe
[Norton Utilities 15 *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Norton Utilities 15\nu.exe
Default=False
FileKey1=%AppData%\Norton Utilities\log|pgscan_*.html
[Notepad++ *]
LangSecRef=3021
Detect=HKLM\Software\Notepad++
Default=False
FileKey1=%AppData%\Notepad++\plugins\config|PluginManagerGpup.xml;PluginManagerPlugins.xml;PluginManagerPlugins.zip
FileKey2=%AppData%\Notepad++\plugins\config\plugin_install_temp|*.*|REMOVESELF
FileKey3=%ProgramFiles%\Notepad++\plugins\disabled|*.*
[Notepad++ Backups *]
LangSecRef=3021
Detect=HKLM\Software\Notepad++
Default=False
FileKey1=%AppData%\Notepad++\backup|*.*|REMOVESELF
[Notifications *]
DetectOS=10.0|
LangSecRef=3025
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows\Notifications|*.tmp
FileKey2=%LocalAppData%\Microsoft\Windows\Notifications\wpnidm|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications\wpnidm
[NowSmart Cut *]
LangSecRef=3023
Detect=HKLM\Software\NowSmart\Cut
Default=False
FileKey1=%LocalAppData%\Cut|log.txt;*.dmp
[Nox *]
LangSecRef=3024
Detect=HKLM\Software\BigNox
DetectFile=%UserProfile%\.BigNox
Default=False
FileKey1=%LocalAppData%\Nox|Nox.log.*;*.log
FileKey2=%UserProfile%\.BigNox|*.log;*.log.*
FileKey3=%UserProfile%\vmlogs|Nox.log;Nox.log.*
[Npcap Loopback Adapter *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Npcap
Default=False
FileKey1=%ProgramFiles%\NpCap|*.log|RECURSE
[NSIS *]
LangSecRef=3021
Detect=HKLM\Software\NSIS
Default=False
RegKey1=HKLM\Software\NSIS\MRU
[NT Registry Optimizer *]
LangSecRef=3024
DetectFile=%ProgramFiles%\NT Registry Optimizer\NTREGOPT.EXE
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows|UsrClass.bak
FileKey2=%WinDir%\ServiceProfiles\LocalService|NTUSER.bak
FileKey3=%WinDir%\ServiceProfiles\NetworkService|NTUSER.bak
FileKey4=%WinDir%\System32\config|COMPONENTS.bak;SYSTEM.bak;DEFAULT.bak;SAM.bak;SECURITY.bak;Software.bak
[NTI Backup Now *]
LangSecRef=3024
DetectFile=%ProgramFiles%\New Tech Infosystems\NTI Backup Now 5
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\New Tech Infosystems\NTI Backup Now 5\logs|*.*
FileKey2=%ProgramFiles%\New Tech Infosystems\NTI Backup Now 5\logs|*.*
[Nuance Dragon Natually Speaking 12 *]
LangSecRef=3021
Detect=HKCU\Software\ScanSoft\NaturallySpeaking12
Default=False
FileKey1=%AppData%\Nuance\NaturallySpeaking12\RIA|*DragonNatuallySpeakingRIA_IE_Shim_log_*.txt
[Nuclear Dawn Cache *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\17710
Default=False
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\config\html|*.*|RECURSE
FileKey2=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\cache|*.*|RECURSE
FileKey3=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\downloads|*.*|RECURSE
FileKey4=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\materials\temp|*.vtf|RECURSE
[Nuclear Dawn Custom Content *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\17710
Default=False
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps|*corner*;*roadwork*;*rock*;*frost*;*mars*|RECURSE
FileKey2=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\materials\models|*.*|RECURSE
FileKey3=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\materials\sprites|*.*|RECURSE
FileKey4=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\models|*.*|RECURSE
FileKey5=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\sound\quake|*.*|RECURSE
[Nuclear Dawn Demos/Screenshots *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\17710
Default=False
Warning=This will remove all demos and screenshots which are not uploaded to steam cloud.
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\donedemos|*.*|RECURSE
FileKey2=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps|*.dem*|RECURSE
FileKey3=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\screenshots|*.*|RECURSE
[Nuclear Dawn Developer Files *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\17710
Default=False
Warning=This will remove content used by game, map and community developers.
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\bin|*bsp*;*vtex*;SDKLauncher.exe;modelbrowser.exe|RECURSE
FileKey2=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps|*example*|RECURSE
FileKey3=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps\ai_data|nd_codetest.nav|RECURSE
FileKey4=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\scripts\scripted_props|*.*|REMOVESELF
FileKey5=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\scripts\units|*.*|REMOVESELF
FileKey6=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\scripts\vehicles|*.*|REMOVESELF
FileKey7=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\platform\AddOns|*.*|RECURSE
FileKey8=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\sdk_content|*.*|REMOVESELF
FileKey9=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\sdk_tools|*.*|REMOVESELF
[Nuclear Dawn Mac/Linux Binaries *]
DetectOS=6.0|
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\17710
Default=False
Warning=This will remove mac and linux binaries.
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\bin|client.so;client.dylib|RECURSE
[Nuclear Dawn SK Gamemode *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\17710
Default=False
Warning=Redownload of skrimish gamemode required to play. Not supported by all servers.
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps|*sk_*|RECURSE
[Nuclear Dawn Tutorials *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\17710
Default=False
Warning=This will prevent running of Nuclear Dawn Tutorials but will free over 850mb of disk space.
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps|*training*|RECURSE
FileKey2=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\maps\ai_data|*training*|RECURSE
FileKey3=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\media|*tutorial*|RECURSE
FileKey4=%ProgramFiles%\Steam\SteamApps\common\Nuclear Dawn\nucleardawn\sound\voices\tutorial|*.*|REMOVESELF
[NVIDIA *]
LangSecRef=3024
Detect=HKLM\Software\NVIDIA Corporation
Default=False
FileKey1=%AppData%\NVIDIA\*Cache|*.*|RECURSE
FileKey2=%CommonAppData%\NVIDIA|*.log;*.log_backup1;Resource.old;*.bak|RECURSE
FileKey3=%CommonAppData%\NVIDIA Corporation|*.log;*bak;*log.*;*.old;*.stat|RECURSE
FileKey4=%CommonAppData%\NVIDIA Corporation\Downloader|*.*|RECURSE
FileKey5=%CommonAppData%\NVIDIA Corporation\GeForce Experience\Update|*.*|RECURSE
FileKey6=%CommonAppData%\NVIDIA\NvBackend\Updatus\DownloadManager|*.*
FileKey7=%CommonAppData%\NVIDIA\Updatus\DownloadManager|*.*
FileKey8=%LocalAppData%\NVIDIA Corporation|*.log;*.bak;*.old|RECURSE
FileKey9=%LocalAppData%\NVIDIA Corporation\*\CefCache|Cookies;Cookies-journal;QuotaManager;QuotaManager-journal
FileKey10=%LocalAppData%\NVIDIA Corporation\*\CefCache\*Cache|*.*|RECURSE
FileKey11=%LocalAppData%\NVIDIA\NvBackend|*.log;*.bak
FileKey12=%LocalAppData%\VirtualStore\Program Files*\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs|*.*
FileKey13=%LocalAppData%\VirtualStore\ProgramData\NVIDIA|*.log;*.log_backup1;Resource.old;*.bak|RECURSE
FileKey14=%LocalAppData%\VirtualStore\ProgramData\NVIDIA Corporation|*.log;*bak;*log.*;*.old;*.stat|RECURSE
FileKey15=%LocalAppData%\VirtualStore\ProgramData\NVIDIA Corporation\Downloader|*.*|RECURSE
FileKey16=%LocalAppData%\VirtualStore\ProgramData\NVIDIA Corporation\GeForce Experience\Update|*.*|RECURSE
FileKey17=%LocalAppData%\VirtualStore\ProgramData\NVIDIA Corporation\NetService|*.*|RECURSE
FileKey18=%LocalAppData%\VirtualStore\ProgramData\NVIDIA\NvBackend\Updatus\DownloadManager|*.*
FileKey19=%LocalAppData%\VirtualStore\ProgramData\NVIDIA\Updatus\DownloadManager|*.*
FileKey20=%ProgramFiles%\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs|*.*
FileKey21=%SystemDrive%\NvidiaLogging\GFExperience|GridClientLog.log*|RECURSE
[O&O Defrag *]
LangSecRef=3024
Detect=HKCU\Software\O&O\O&O Defrag
Default=False
FileKey1=%Documents%\O&O\O&O Defrag\data\reports|*.*|RECURSE
[OBS *]
LangSecRef=3024
DetectFile1=%AppData%\OBS
DetectFile2=%AppData%\obs-studio
Default=False
FileKey1=%AppData%\OBS|*.log|RECURSE
FileKey2=%AppData%\OBS\crashDumps|*.*
FileKey3=%AppData%\obs-studio\crashes|*.*
FileKey4=%AppData%\obs-studio\logs|*.*
FileKey5=%AppData%\obs-studio\profiler_data|*.*
[OcenAudio MRU *]
LangSecRef=3023
Detect1=HKCU\Software\OcenAudio
Detect2=HKLM\Software\OcenAudio
Default=False
FileKey1=%LocalAppData%\OcenAudio|ocen.database
[Octoshape *]
LangSecRef=3023
DetectFile=%LocalAppData%\Octoshape\Octoshape Streaming Services
Default=False
FileKey1=%LocalAppData%\Octoshape\Octoshape Streaming Services\temp|*.*
[OEM Logs *]
LangSecRef=3021
DetectFile1=%CommonAppData%\oem
DetectFile2=%SystemDrive%\OEM
DetectFile3=%WinDir%\System32\OEM
DetectFile4=%WinDir%\SysWOW64\OEM
Default=False
FileKey1=%CommonAppData%\oem|*.log|RECURSE
FileKey2=%SystemDrive%\OEM|*.log|RECURSE
FileKey3=%WinDir%\System32\OEM|*.log
FileKey4=%WinDir%\SysWOW64\OEM|*.log
[Off-Road Drive *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\200230
Default=False
FileKey1=%Documents%\My Games\PP3\PP3WorkGame\Logs|*.*
[Office Password Recovery *]
LangSecRef=3024
Detect=HKCU\Software\Intelore\Office Password Recovery
Default=False
FileKey1=%AppData%\Intelore\Password Recovery\logs|*.*
[OMNITRACKER *]
LangSecRef=3021
Detect=HKCU\Software\OmniNet\OmniTracker
Default=False
FileKey1=%LocalAppData%\OMNINET GmbH\OMNITRACKER\Temp|*.*|RECURSE
RegKey1=HKCU\Software\OmniNet\OmniTracker\MRU
RegKey2=HKCU\Software\OmniNet\OmniTracker\SearchTextHistory
[OneConnect *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.OneConnect_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.OneConnect_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalCache\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalState\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.OneConnect_*\LocalState\DiagOutputDir|*.txt
FileKey7=%LocalAppData%\Packages\Microsoft.OneConnect_*\TempState|*.*|RECURSE
[OneDrive *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\OneDrive
Default=False
FileKey1=%LocalAppData%\Microsoft\OneDrive\logs|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\OneDrive\setup\logs|*.*|RECURSE
FileKey3=%LocalAppData%\Microsoft\Windows\OneDrive\logs|*.*|RECURSE
[OneNote *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local|msodata*.dat
FileKey6=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\16.0\WebServiceCache\AllUsers\office*client.microsoft.com|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\Office\OTele|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0|*.onecache
FileKey9=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\LocalState\AppData\Local\OneNote\16.0\OneNote*Cache_Files|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Office.OneNote_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.OneNote_8wekyb3d8bbwe\SearchHistory
[OneTeam *]
LangSecRef=3022
Detect=HKCU\Software\OneTeam
Default=False
FileKey1=%AppData%\oneteam\profiles\*\oneteamcachefiles|*.*|RECURSE
FileKey2=%LocalAppData%\oneteam\profiles\*\cache|*.*|RECURSE
[Online Armor *]
LangSecRef=3021
Detect=HKLM\Software\Tall Emu\Online Armor
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Tall Emu\Online Armor\Logs|*.*
FileKey2=%ProgramFiles%\Tall Emu\Online Armor\Logs|*.*
[Ontrack EasyRecovery *]
LangSecRef=3024
Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{668CC71A-C2AD-4D56-866D-CF300BD1D5BE}_is1
Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AE695CA4-8847-4462-98CC-023874D29E72}_is1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Kroll Ontrack\Ontrack EasyRecovery*|*erent_log.txt;*erpro_log.txt
FileKey2=%ProgramFiles%\Kroll Ontrack\Ontrack EasyRecovery*|*erent_log.txt;*erpro_log.txt
[Ookla Speed Test *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Ookla.SpeedtestbyOokla_43tkc6nmykmb6
DetectFile=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_43tkc6nmykmb6
Default=False
FileKey1=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey3=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\AC\Temp|*.*
FileKey4=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\LocalState|*.tmp|RECURSE
FileKey5=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\LocalState\Unity\Local.*\Analytics\ArchivedEvents\*|*.*|REMOVESELF
FileKey6=%LocalAppData%\Packages\Ookla.SpeedtestbyOokla_*\TempState|*.*|RECURSE
[ooVoo Chat History *]
LangSecRef=3022
Detect=HKCU\Software\ooVoo
Default=False
FileKey1=%AppData%\ooVoo Details\Users|chathistory.db|RECURSE
[ooVoo Toolbar *]
LangSecRef=3022
DetectFile=%LocalLowAppData%\oovootoolbar
Default=False
FileKey1=%LocalLowAppData%\oovootoolbar|log.txt
[OpalCalc *]
LangSecRef=3021
DetectFile1=%AppData%\OpalCalc_prefs
DetectFile2=%ProgramFiles%\OpalCalc
Default=False
FileKey1=%AppData%\OpalCalc_prefs|lastSession.txt
[Open Blu-ray to DVD *]
LangSecRef=3023
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Blu-ray to DVD Pro_is1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Blu-ray to DVD*|*.log;*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Blu-ray to DVD*\ReadCache|*.*
FileKey3=%ProgramFiles%\Blu-ray to DVD*|*.log;*.txt
FileKey4=%ProgramFiles%\Blu-ray to DVD*\ReadCache|*.*
[Open Blu-ray/DVD Ripper *]
LangSecRef=3023
Detect1=HKCU\Software\OpenCloner\BDRipper
Detect2=HKCU\Software\OpenCloner\DVDRipper
Default=False
FileKey1=%AppData%\Open * Ripper|O*R_LOG_FILE.txt
FileKey2=%AppData%\Open * Ripper\ReadCache|*.*|REMOVESELF
[Open with Arguments *]
LangSecRef=3024
Detect=HKCU\Software\OpenArgs
Default=False
RegKey1=HKCU\Software\OpenArgs\History
[OpenDNS Updater *]
LangSecRef=3021
Detect=HKCU\Software\OpenDNS Updater
Default=False
Warning=You must exit OpenDNS Updater in the System Tray to clear log files.
FileKey1=%AppData%\OpenDNS Updater|*.txt
[OpenFire *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Openfire
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Openfire\Logs|*.*
FileKey2=%ProgramFiles%\Openfire\Logs|*.*
[OpenMG *]
LangSecRef=3023
DetectFile=%CommonAppData%\Sony Corporation\OpenMG
Default=False
FileKey1=%CommonAppData%\Sony Corporation\OpenMG|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sony Corporation\OpenMG|*.log
[OpenMG CD Backups *]
LangSecRef=3023
DetectFile=%CommonAppData%\Sony Corporation\OpenMG
Default=False
FileKey1=%CommonAppData%\Sony Corporation\OpenMG\CD Walkman\Temp|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sony Corporation\OpenMG\CD Walkman\Temp|*.*|REMOVESELF
[OpenMG Jukebox *]
LangSecRef=3023
DetectFile=%AppData%\Sony\OpenMG Jukebox
Default=False
FileKey1=%AppData%\Sony\OpenMG Jukebox\Temp|*.*
[OpenOffice.org *]
LangSecRef=3021
Detect1=HKLM\Software\OpenOffice
Detect2=HKLM\Software\OpenOffice.org
Default=False
FileKey1=%AppData%\OpenOffice*\*\user|*.log;*.log.txt;*.tmp;registrymodifications.xcu;registration.xml|RECURSE
FileKey2=%AppData%\OpenOffice*\*\user\config\imagecache|*.*
FileKey3=%AppData%\OpenOffice*\*\user\registry\cache|*.*
FileKey4=%AppData%\OpenOffice*\*\user\registry\data\org\openoffice\Office|Views.xcu;Writer.xcu;Common.xcu;Histories.xcu
FileKey5=%AppData%\OpenOffice*\*\user\registry\data\org\openoffice\ucb|Hierarchy.xcu;Store.xcu
FileKey6=%ProgramFiles%\OpenOffice*\share\uno_packages\cache\uno_packages|*.tmp;*.log;log.txt
[OpenOffice.org Setup Files *]
LangSecRef=3021
Detect1=HKLM\Software\OpenOffice
Detect2=HKLM\Software\OpenOffice.org
Default=False
FileKey1=%UserProfile%\Desktop\OpenOffice.org * Installation Files|*.*|REMOVESELF
[OpenRA *]
Section=Games
DetectFile=%Documents%\OpenRA
Default=False
FileKey1=%Documents%\OpenRA\Logs|*.*
[OpenRA Replays *]
Section=Games
DetectFile=%Documents%\OpenRA
Default=False
Warning=This will remove all of your Replays.
FileKey1=%Documents%\OpenRA\Replays|*.*|RECURSE
[OpenVPN *]
LangSecRef=3024
DetectFile=%ProgramFiles%\OpenVPN
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\OpenVPN\Log|*.*
FileKey2=%ProgramFiles%\OpenVPN\Log|*.*
[Opera *]
LangSecRef=3027
Detect=HKCU\Software\Opera Software
DetectFile=%LocalAppData%\Opera\Opera*
Default=False
FileKey1=%AppData%\Opera Software\Opera*|ssdfp*.*
FileKey2=%LocalAppData%\Opera\Opera*\application_cache|*.*|REMOVESELF
FileKey3=%LocalAppData%\Opera\Opera*\icons|*.*|REMOVESELF
FileKey4=%LocalAppData%\Opera\Opera*\logs|*.*|REMOVESELF
FileKey5=%LocalAppData%\Opera\Opera*\temporary_downloads|*.*|REMOVESELF
FileKey6=%LocalAppData%\Opera\Opera*\thumbnails|*.*|REMOVESELF
FileKey7=%LocalAppData%\Opera\Opera*\vps|*.*|REMOVESELF
RegKey1=HKCU\Software\Opera Software|Last CommandLine v2
[Opera 9 Classic *]
LangSecRef=3027
DetectFile=%ProgramFiles%\Opera 9\Opera.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Opera 9\profile|cookies4.dat;vlink4.dat;global.dat
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Opera 9\profile\cache*|*.*
FileKey3=%ProgramFiles%\Opera 9\profile|cookies4.dat;vlink4.dat;global.dat
FileKey4=%ProgramFiles%\Opera 9\profile\cache*|*.*
[Optimizer Pro *]
LangSecRef=3024
Detect=HKCU\Software\Optimizer Pro
Default=False
FileKey1=%AppData%\Optimizer Pro\Log|*.*
[OptimumLink *]
LangSecRef=3021
DetectFile=%AppData%\OptimumLink
Default=False
FileKey1=%AppData%\OptimumLink|TrayLogs*.*
[Orbit Downloader *]
LangSecRef=3022
Detect=HKLM\Software\Orbit
Default=False
FileKey1=%AppData%\Orbit|history.dat;DownloadList.dat;unfinish.dat;softI.dat;updateslist.xml
FileKey2=%AppData%\Orbit\flink|*.*
FileKey3=%AppData%\Orbit\icon|*.*|RECURSE
[Orca *]
LangSecRef=3024
Detect=HKCU\Software\Microsoft\Orca
Default=False
RegKey1=HKCU\Software\Microsoft\Orca\Recent File List
[Orcs Must Die! Unchained *]
Section=Games
Detect1=HKCU\Software\Robot Entertainment\Orcs Must Die! Unchained
Detect2=HKCU\Software\Valve\Steam\Apps\427270
Default=False
FileKey1=%Documents%\My Games\Orcs Must Die Unchained\SpitfireGame\Logs|*.log;*.dmg|RECURSE
[Origin *]
Section=Games
Detect=HKLM\Software\Classes\Origin
Default=False
FileKey1=%CommonAppData%\Origin\*Cache|*.*|RECURSE
FileKey2=%CommonAppData%\Origin\Logs|*.*
FileKey3=%CommonAppData%\Origin\Telemetry|*.*
FileKey4=%LocalAppData%\Origin\Origin\cache|*.*|RECURSE
FileKey5=%LocalAppData%\Origin\Web Cache|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Origin\*Cache|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Origin\Logs|*.*
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Origin\Telemetry|*.*
FileKey9=%SystemDrive%|shared.log
[Origin Installers *]
Section=Games
Detect=HKLM\Software\Classes\Origin
Default=False
FileKey1=%LocalAppData%\Origin\ThinSetup|*.*|REMOVESELF
FileKey2=%ProgramFiles%\Origin Games|*.cab;vc_red.msi;gfwlivesetup.exe;GamesExplorerIntegrationTool.exe;install.ini;globdata.ini;vcredist.bmp;vc_red.exe;install.exe;install.res.*.dll;eula.*.txt;vcredist_x64.exe;dotNetFx40_Full_setup.exe;dotNetFx40_Full_x86_x64.exe;xnafx40_redist.msi;DSETUP.DLL;oalinst.exe;DXSETUP.EXE;dsetup32.dll;dotnetfx3setup;vcredist_x86.exe;dxwebsetup.exe;xnafx31_redist.msi;dotNetFx35setup.exe;dotnetfx35.exe|RECURSE
[Osmos *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\29180
Default=False
FileKey1=%Documents%\Osmos|osmos.log
[osu! *]
Section=Games
Detect=HKCU\Software\Osu!
Default=False
FileKey1=%LocalAppData%\osu!\logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Osu!|debug-import.txt
FileKey3=%ProgramFiles%\Osu!|debug-import.txt
[Outlast *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\238320
Default=False
FileKey1=%Documents%\My Games\Outlast\OLGame\Logs|*.dmp;*.log
[Outlook 2003 *]
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Outlook
Default=False
FileKey1=%AppData%\Microsoft\Outlook|Outlook.NK2
RegKey1=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 1
RegKey2=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 2
RegKey3=HKCU\Software\Microsoft\Office\11.0\Outlook\Office Finder|MRU 3
[Outlook Appointment Location *]
LangSecRef=3021
Detect1=HKCU\Software\Microsoft\Office\9.0\Outlook
Detect2=HKCU\Software\Microsoft\Office\11.0\Outlook
Detect3=HKCU\Software\Microsoft\Office\12.0\Outlook
Detect4=HKCU\Software\Microsoft\Office\14.0\Outlook
Detect5=HKCU\Software\Microsoft\Office\15.0\Outlook
Detect6=HKCU\Software\Microsoft\Office\16.0\Outlook
Default=False
Warning=This Will Remove the Most Frequent Appointment Locations from all Outlook Versions.
RegKey1=HKCU\Software\Microsoft\Office\9.0\Outlook\Preferences|LocationMRU
RegKey2=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
RegKey3=HKCU\Software\Microsoft\Office\12.0\Outlook\Preferences|LocationMRU
RegKey4=HKCU\Software\Microsoft\Office\14.0\Outlook\Preferences|LocationMRU
RegKey5=HKCU\Software\Microsoft\Office\15.0\Outlook\Preferences|LocationMRU
RegKey6=HKCU\Software\Microsoft\Office\16.0\Outlook\Preferences|LocationMRU
[Outpost Firewall Pro *]
LangSecRef=3021
Detect=HKLM\Software\Agnitum\Outpost Firewall
Default=False
FileKey1=%CommonAppData%\Agnitum\Security Suite\Feedback\Logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Agnitum\Outpost Firewall Pro\log|*.*
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Agnitum\Security Suite\Feedback\Logs|*.*
FileKey4=%ProgramFiles%\Agnitum\Outpost Firewall Pro\log|*.*
[Outpost Security Suite *]
LangSecRef=3021
Detect=HKLM\Software\Agnitum\Security Suite
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Agnitum\Outpost Security Suite Pro\log|*.log
FileKey2=%ProgramFiles%\Agnitum\Outpost Security Suite Pro\log|*.log
[Overwatch *]
Section=Games
DetectFile=%Documents%\Overwatch
Default=False
FileKey1=%Documents%\Overwatch\Logs|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Overwatch\WebBrowserProxy\cache\browser|*.*
FileKey3=%ProgramFiles%\Overwatch\WebBrowserProxy\cache\browser|*.*
FileKey4=%ProgramFiles%\Overwatch\WebBrowserProxy\logs\browser|*.*
[OVH HubiC *]
LangSecRef=3021
Detect=HKCU\Software\OVH\hubiC-browser
Default=False
FileKey1=%LocalAppData%\OVH\hubiC-browser\cache\data7|*.*|RECURSE
[Oxygen 14 *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Oxygen XML Editor 14
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Oxygen XML Editor 14|*.properties;*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Oxygen XML Editor 14\.install4j|*.log
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Oxygen XML Editor 14\dicts|*.txt;*.html
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Oxygen XML Editor 14\lib|*.txt|RECURSE
FileKey5=%ProgramFiles%\Oxygen XML Editor 14|*.properties;*.log
FileKey6=%ProgramFiles%\Oxygen XML Editor 14\.install4j|*.log
FileKey7=%ProgramFiles%\Oxygen XML Editor 14\dicts|*.txt;*.html
FileKey8=%ProgramFiles%\Oxygen XML Editor 14\lib|*.txt|RECURSE
ExcludeKey1=FILE|%ProgramFiles%\Oxygen XML Editor 14\.install4j\|files.log
[Pacific Storm *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\11250
DetectFile=%ProgramFiles%\Buka\Pacific Storm
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Buka\Pacific Storm|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Pacific Storm*|*.log|RECURSE
FileKey3=%ProgramFiles%\Buka\Pacific Storm|*.log|RECURSE
FileKey4=%ProgramFiles%\Steam\SteamApps\Common\Pacific Storm*|*.log|RECURSE
[Paint 3D *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MSPaint_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.MSPaint_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.MSPaint_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.MSPaint_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.MSPaint_*\LocalState|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.MSPaint_*\TempState|*.*|RECURSE
[Paint.NET *]
LangSecRef=3021
Detect=HKCU\Software\Paint.NET
Default=False
FileKey1=%LocalAppData%\Paint.NET|*.*|RECURSE
RegKey1=HKCU\Software\Paint.NET|LastFileDialogDirectory
[Paltalk Messenger *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Paltalk Messenger\paltalk.exe
Default=False
FileKey1=%AppData%\Paltalk|*.*|RECURSE
[Panda Antivirus *]
LangSecRef=3024
Detect=HKLM\Software\Panda Security
Default=False
FileKey1=%CommonAppData%\Panda Security\Panda Devices Agent\Logs|*.*
FileKey2=%CommonAppData%\Panda Security\Panda Security Protection|*.log
FileKey3=%CommonAppData%\Panda Security\PSLogs|*.log
[Pandion *]
LangSecRef=3022
Detect=HKCU\Software\Pandion
Default=False
FileKey1=%AppData%\Pandion\Avatars|*.*|RECURSE
FileKey2=%AppData%\Pandion\Message Cache|*.*|RECURSE
[Pandion Chat Logs *]
LangSecRef=3022
Detect=HKCU\Software\Pandion
Default=False
FileKey1=%AppData%\Pandion\Profiles|*.log;*.buffer|RECURSE
[Pando *]
LangSecRef=3024
Detect=HKCU\Software\Pando Networks\Pando
Default=False
Warning=Make sure Pando is totally shut down before using this.
FileKey1=%LocalAppData%\Pando\Pando Files|*.*|RECURSE
ExcludeKey1=PATH|%LocalAppData%\Pando\Pando Files\|*pando.prev.log;*pando.log;*pando.sav;*pando.save;*pando.txt
ExcludeKey2=PATH|%LocalAppData%\Pando\Pando Files\Cert\|*.*
[Pando Media Booster *]
Section=Games
Detect=HKCU\Software\Pando Networks\PMB
Default=False
FileKey1=%CommonAppData%\PMB Files|*.TOK;*.log
FileKey2=%LocalAppData%\PMB Files\*|*.CT1;*.CT2;*.dat;*.log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\PMB Files|*.TOK;*.log
[Paragon Hard Disk Manager 12 Suite *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Paragon Software\Hard Disk Manager 12 Suite
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Paragon Software\Hard Disk Manager 12 Suite|*.log
FileKey2=%ProgramFiles%\Paragon Software\Hard Disk Manager 12 Suite|*.log
[Paragon Hard Disk Manager 14 Suite *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Paragon Software\Hard Disk Manager 14 Suite
Default=False
FileKey1=%CommonAppData%\clonehdd|*.log
FileKey2=%CommonAppData%\createpart|*.log
FileKey3=%CommonAppData%\deletepart|*.log
FileKey4=%CommonAppData%\explauncher|*.log
FileKey5=%CommonAppData%\ftw|*.log
FileKey6=%CommonAppData%\launcher|*.log
FileKey7=%CommonAppData%\logsaver|*.log
FileKey8=%CommonAppData%\migrateos|*.log
FileKey9=%CommonAppData%\redistpart|*.log
FileKey10=%CommonAppData%\vmadjust|*.log
FileKey11=%CommonAppData%\vmcreate|*.log
FileKey12=%CommonAppData%\wipe|*.log
FileKey13=%LocalAppData%\VirtualStore\Program Files*\Paragon Software\Hard Disk Manager 14 Suite\*|BioNtLog.txt;cdb.log;fdisk.txt;pwlog.txt;stubact.log
FileKey14=%LocalAppData%\VirtualStore\Program Files*\Paragon Software\Hard Disk Manager 14 Suite\*\symmpi*|*.txt
FileKey15=%LocalAppData%\VirtualStore\ProgramData\clonehdd|*.log
FileKey16=%LocalAppData%\VirtualStore\ProgramData\createpart|*.log
FileKey17=%LocalAppData%\VirtualStore\ProgramData\deletepart|*.log
FileKey18=%LocalAppData%\VirtualStore\ProgramData\explauncher|*.log
FileKey19=%LocalAppData%\VirtualStore\ProgramData\ftw|*.log
FileKey20=%LocalAppData%\VirtualStore\ProgramData\launcher|*.log
FileKey21=%LocalAppData%\VirtualStore\ProgramData\logsaver|*.log
FileKey22=%LocalAppData%\VirtualStore\ProgramData\migrateos|*.log
FileKey23=%LocalAppData%\VirtualStore\ProgramData\redistpart|*.log
FileKey24=%LocalAppData%\VirtualStore\ProgramData\vmadjust|*.log
FileKey25=%LocalAppData%\VirtualStore\ProgramData\vmcreate|*.log
FileKey26=%ProgramFiles%\Paragon Software\Hard Disk Manager 14 Suite\*|BioNtLog.txt;cdb.log;fdisk.txt;pwlog.txt;stubact.log
FileKey27=%ProgramFiles%\Paragon Software\Hard Disk Manager 14 Suite\*\symmpi*|*.txt
FileKey28=%SystemDrive%\Documents and Settings\LocalService|objsrv.log
[Paragon Partition Manager 2014 *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Paragon Software\Partition Manager 2014
Default=False
FileKey1=%CommonAppData%\converthfs|*.log
FileKey2=%CommonAppData%\createpart|*.log
FileKey3=%CommonAppData%\deletepart|*.log
FileKey4=%CommonAppData%\explauncher|*.log
FileKey5=%CommonAppData%\formatpart|*.log
FileKey6=%CommonAppData%\launcher|*.log
FileKey7=%CommonAppData%\logsaver|*.log
FileKey8=%CommonAppData%\redistpart|*.log
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Paragon Software\*\program|BioNtLog.txt;cdb.log;fdisk.txt;pwlog.txt;stubact.log
FileKey10=%LocalAppData%\VirtualStore\ProgramData\converthfs|*.log
FileKey11=%LocalAppData%\VirtualStore\ProgramData\createpart|*.log
FileKey12=%LocalAppData%\VirtualStore\ProgramData\deletepart|*.log
FileKey13=%LocalAppData%\VirtualStore\ProgramData\explauncher|*.log
FileKey14=%LocalAppData%\VirtualStore\ProgramData\formatpart|*.log
FileKey15=%LocalAppData%\VirtualStore\ProgramData\launcher|*.log
FileKey16=%LocalAppData%\VirtualStore\ProgramData\logsaver|*.log
FileKey17=%LocalAppData%\VirtualStore\ProgramData\redistpart|*.log
FileKey18=%ProgramFiles%\Paragon Software\*\program|BioNtLog.txt;cdb.log;fdisk.txt;pwlog.txt;stubact.log
FileKey19=%SystemDrive%\Documents and Settings\LocalService|objsrv.log
[Paragon Total Defrag 2010 *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Paragon Software\Total Defrag 2010
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Paragon Software\Total Defrag 2010|*.log;biontlog.txt|RECURSE
FileKey2=%ProgramFiles%\Paragon Software\Total Defrag 2010|*.log;biontlog.txt|RECURSE
[Paramount Dynamic *]
LangSecRef=3023
DetectFile=%LocalAppData%\Microsoft\Windows\Themes\ParamountDynamic.theme
Default=False
Warning=This will cause you to redownload the Paramount Dynamic RSS file.
FileKey1=%LocalAppData%\Microsoft\Feeds|http~c~f~fthemeserver~dmicrosoft~dcom~fdefault~daspx~mp*Paramount*
[Paranormal *]
Section=Games
DetectFile=%ProgramFiles%\Desura\Common\paranormal
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Desura\Common\paranormal\UDKGame\Logs|*.*
FileKey2=%ProgramFiles%\Desura\Common\paranormal\UDKGame\Logs|*.*
[Paranormal Agency *]
Section=Games
DetectFile=%AppData%\Shape Games\Paranormal_v*
Default=False
FileKey1=%AppData%\Shame Games\Paranormal_v*\logs|*.*
[Partner Application *]
LangSecRef=3022
DetectFile=%CommonAppData%\Partner
Default=False
FileKey1=%CommonAppData%\Partner|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Partner|*.log
[Patch My PC *]
LangSecRef=3024
DetectFile=%LocalAppData%\Patch_My_PC,_LLC
Default=False
FileKey1=%LocalAppData%\Patch_My_PC,_LLC|*.*|RECURSE
[Path of Exile *]
Section=Games
Detect1=HKCU\Software\GrindingGearGames\Path of Exile
Detect2=HKCU\Software\Valve\Steam\Apps\238960
Default=False
FileKey1=%Documents%\My Games\Path of Exile\Minimap|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Grinding Gear Games\Path of Exile\Logs|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Path of Exile\logs|*.*
FileKey4=%ProgramFiles%\Grinding Gear Games\Path of Exile\Logs|*.*
FileKey5=%ProgramFiles%\Steam\steamapps\common\Path of Exile\logs|*.*
[PAYDAY 2 *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\218620
DetectFile=%LocalAppData%\PAYDAY 2
Default=False
FileKey1=%LocalAppData%\PAYDAY 2|crash.txt;crashlog.txt
[PC Doctor *]
LangSecRef=3024
DetectFile=%ProgramFiles%\PC-Doctor For Windows
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\PC-Doctor For Windows\Logs|*.*
FileKey2=%ProgramFiles%\PC-Doctor For Windows\Logs|*.*
[PC Optimizer Pro *]
LangSecRef=3024
DetectFile=%CommonAppData%\PC optimizer pro
Default=False
FileKey1=%CommonAppData%\PC Optimizer Pro\Logs|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\PC Optimizer Pro\Logs|*.*
[PC Tools Performance Toolkit *]
LangSecRef=3024
DetectFile=%AppData%\PC Tools Performance Toolkit
Default=False
FileKey1=%AppData%\PC Tools Performance Toolkit\CleanReports|*.*
FileKey2=%CommonAppData%\PC Tools\Performance Toolkit\Defrag\Logs|*.*
FileKey3=%CommonAppData%\PC Tools\Performance Toolkit\Repair\Logs|*.*
FileKey4=%LocalAppData%\VirtualStore\Program Files*\PC Tools\*\~tmp|*.*
FileKey5=%LocalAppData%\VirtualStore\Program Files*\PC Tools\*\Log|*.*
FileKey6=%LocalAppData%\VirtualStore\ProgramData\PC Tools\Performance Toolkit\Defrag\Logs|*.*
FileKey7=%LocalAppData%\VirtualStore\ProgramData\PC Tools\Performance Toolkit\Repair\Logs|*.*
FileKey8=%ProgramFiles%\PC Tools\*\~tmp|*.*
FileKey9=%ProgramFiles%\PC Tools\*\Log|*.*
[PC Tools sMonitor *]
LangSecRef=3024
DetectFile=%CommonProgramFiles%\PC Tools\sMonitor
Default=False
FileKey1=%CommonProgramFiles%\PC Tools\sMonitor|cputime.xml;logfile.etl
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Common Files\PC Tools\sMonitor|cputime.xml;logfile.etl
[PCFresh *]
LangSecRef=3024
DetectFile=%LocalAppData%\Abelssoft\PCFresh
Default=False
FileKey1=%LocalAppData%\Abelssoft\PCFresh\Backup|*.*
[PCSX2 *]
Section=Games
DetectFile=%Documents%\PCSX2
Default=False
FileKey1=%Documents%\PCSX2\logs|*.*|RECURSE
[PCSX2 Snaps *]
Section=Games
DetectFile=%Documents%\PCSX2
Default=False
FileKey1=%Documents%\PCSX2\snaps|*.*|RECURSE
[PDF-XChange Editor *]
LangSecRef=3021
Detect=HKCU\Software\Tracker Software\PDFXEditor
Default=False
FileKey1=%CommonAppData%\Tracker Software\Update|TrackerUpdate.exe.del
[PDF-XChange Viewer *]
LangSecRef=3021
Detect=HKCU\Software\Tracker Software\PDFViewer
Default=False
FileKey1=%CommonAppData%\Tracker Software\TrackerUpdate|TrackerUpdate.exe.del
FileKey2=%LocalAppData%\Tracker Software\LiveUpdate\Updates|*.*
RegKey1=HKCU\Software\Tracker Software\PDFViewer\Documents\LastOpened
RegKey2=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Bars
RegKey3=HKCU\Software\Tracker Software\PDFViewer\Documents\LatestView\Panes
[PDF Annotator *]
LangSecRef=3021
Detect=HKCU\Software\GRAHL\PDFAnnotator
Default=False
RegKey1=HKCU\Software\GRAHL\PDFAnnotator\3.0\Files\MRUItems
RegKey2=HKCU\Software\GRAHL\PDFAnnotator\4.0\Files\MRUItems
[PDF Plus *]
LangSecRef=3021
DetectFile=%AppData%\Zeon\DocuCom\PDF Plus
Default=False
FileKey1=%AppData%\Zeon\DocuCom\PDF Plus\Log|*.*
[PDF24 Creator *]
LangSecRef=3021
DetectFile=%ProgramFiles%\PDF24
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\PDF24|*.log
FileKey2=%ProgramFiles%\PDF24|*.log
[PE Module Explorer *]
LangSecRef=3024
Detect=HKCU\Software\Woozle\PE Module Explorer
Default=False
RegKey1=HKCU\Software\Woozle\PE Module Explorer\Recent Files
[Peerblock *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Peerblock
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Peerblock|*.log;History.db;*.bak;cache.p2b
FileKey2=%ProgramFiles%\Peerblock|*.log;History.db;*.bak;cache.p2b
FileKey3=%ProgramFiles%\Peerblock\lists|*.list.failed*
[PeerNetworking *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%SystemDrive%\Documents and Settings\LocalService\Application Data\PeerNetworking|*.*|RECURSE
FileKey2=%WinDir%\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking|*.*|RECURSE
[Pelles C *]
LangSecRef=3021
Detect=HKCU\Software\Pelle Orinius\PellesC
Default=False
RegKey1=HKCU\Software\Pelle Orinius\PellesC\Recent File List
RegKey2=HKCU\Software\Pelle Orinius\PellesC\Recent Project List
RegKey3=HKCU\Software\Pelle Orinius\PellesC\Recent Search List
[People *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.People_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.People_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.People_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.People_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.People_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.People_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.People_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.People_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.People_*\TempState|*.*|RECURSE
[Perfect Registry *]
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectRegistry
Default=False
FileKey1=%AppData%\Raxco\PerfectRegistry|log*.log;TempHLList.rcp
[PerfectDisk *]
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk
Default=False
FileKey1=%CommonAppData%\Raxco\PerfectDisk\*|*.log;*.txt;PDBootLog
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Raxco\PerfectDisk\*|*.log;*.txt
[PerfectUpdater *]
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectUpdater
Default=False
Warning=This cleans the installation logs, backup files after updating, and the downloads for new updates used for updating your drivers.
FileKey1=%AppData%\Raxco\PerfectUpdater|*.log
FileKey2=%AppData%\Raxco\PerfectUpdater\Backup|*.*
FileKey3=%AppData%\Raxco\PerfectUpdater\Download|*.*
[Performance Maintainer *]
LangSecRef=3024
DetectFile=%ProgramFiles%\PC Starters\Performance Maintainer
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\PC Starters\Performance Maintainer\Backups|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\PC Starters\Performance Maintainer\log*|*.*|RECURSE
FileKey3=%ProgramFiles%\PC Starters\Performance Maintainer\Backups|*.*|RECURSE
FileKey4=%ProgramFiles%\PC Starters\Performance Maintainer\log*|*.*|RECURSE
[Pet Pals Animal Doctor *]
Section=Games
Detect=HKLM\Software\Legacy Interactive\Pet Pals
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Legacy Interactive\Pet Pals Animal Doctor|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Legacy Interactive\Pet Pals Animal Doctor\jre|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Legacy Interactive\Pet Pals Animal Doctor\temp|*.*|REMOVESELF
FileKey4=%ProgramFiles%\Legacy Interactive\Pet Pals Animal Doctor|*.log
FileKey5=%ProgramFiles%\Legacy Interactive\Pet Pals Animal Doctor\jre|*.*
FileKey6=%ProgramFiles%\Legacy Interactive\Pet Pals Animal Doctor\temp|*.*|REMOVESELF
ExcludeKey1=PATH|%ProgramFiles%\Legacy Interactive\Pet Pals Animal Doctor\jre\bin\|*.*
ExcludeKey2=PATH|%ProgramFiles%\Legacy Interactive\Pet Pals Animal Doctor\jre\lib\|*.*
[phase-6 *]
LangSecRef=3021
DetectFile=%UserProfile%\.phase-6
Default=False
FileKey1=%UserProfile%\.phase-6|window-position.txt
FileKey2=%UserProfile%\.phase-6\logs|phase-6.log
[Phone *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsPhone_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsPhone_*\TempState|*.*|RECURSE
[Phorest *]
LangSecRef=3024
Detect=HKCU\Software\FutureFog\Phorest\Options
Default=False
RegKey1=HKCU\Software\FutureFog\Phorest\Layout|SelectionHeight
RegKey2=HKCU\Software\FutureFog\Phorest\Layout|SelectionLeft
RegKey3=HKCU\Software\FutureFog\Phorest\Layout|SelectionTop
RegKey4=HKCU\Software\FutureFog\Phorest\Layout|SelectionWidth
RegKey5=HKCU\Software\FutureFog\Phorest\Options|LastUsedFolder
[Photo Print Calendar 3.00E Beta *]
LangSecRef=3021
Detect=HKLM\Software\Computer Institute of Japan, Ltd.\Photo Print Calendar from YOKOHAMA Ver.3.00E beta\3.00E beta
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Photo Print Calendar|update.bmp
FileKey2=%ProgramFiles%\Photo Print Calendar|update.bmp
[Photo Stamp Remover *]
LangSecRef=3023
Detect=HKCU\Software\softorbits\PhotoStampRemover
Default=False
RegKey1=HKCU\Software\softorbits\PhotoStampRemover|currentFile
[Photo! Editor *]
LangSecRef=3024
Detect=HKCU\Software\VicMan Software\Photo! Editor
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Photo!\Photo! Editor|*.log
FileKey2=%ProgramFiles%\Photo!\Photo! Editor|*.log
RegKey1=HKCU\Software\VicMan Software\Photo! Editor|LastFolder
[Photodex ProShow Producer *]
LangSecRef=3021
Detect=HKCU\Software\Photodex\ProShow
Default=False
FileKey1=%CommonAppData%\Photodex\ProShow|*.log|RECURSE
FileKey2=%CommonAppData%\Photodex\ProShow\FontCache|*.*|REMOVESELF
FileKey3=%CommonAppData%\Photodex\ProShow\Styles\Cache|*.*|REMOVESELF
FileKey4=%CommonAppData%\Photodex\ProShow\Transitions\Cache|*.*|REMOVESELF
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Photodex\ProShow Producer|*.log|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Photodex\ProShow|*.log|RECURSE
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Photodex\ProShow\FontCache|*.*|REMOVESELF
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Photodex\ProShow\Styles\Cache|*.*|REMOVESELF
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Photodex\ProShow\Transitions\Cache|*.*|REMOVESELF
FileKey10=%ProgramFiles%\Photodex\ProShow Producer|*.log|RECURSE
FileKey11=%UserProfile%|proshow-burn.log
ExcludeKey1=FILE|%ProgramFiles%\Photodex\ProShow Producer\pxf\images\|xicons.txt
[Photos *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState|*.etl;*.sqlite;*.sqlite-shm;*.sqlite-wal;*.xml
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\LocalState\PhotosAppTile|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.Photos_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedPickerData\Microsoft.Windows.Photos_8wekyb3d8bbwe!App\DefaultSaveFileSingle
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\MostRecentlyUsed
[PhotoScissors *]
LangSecRef=3021
Detect=HKCU\Software\Teorex\PhotoScissors
Default=False
RegKey1=HKCU\Software\Teorex\PhotoScissors\Recent File List
RegKey2=HKCU\Software\Teorex\PhotoScissors\RecentFileList
[PhotoToFilm *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\PhotoToFilm
Default=False
FileKey1=%AppData%\KC Softwares\PhotoToFilm|*.log
[PhotoZoom Pro 6 *]
LangSecRef=3023
Detect=HKCU\Software\BenVista\PhotoZoom Pro 6
Default=False
RegKey1=HKCU\Software\BenVista\PhotoZoom Pro 6|FileDir
RegKey2=HKCU\Software\BenVista\PhotoZoom Pro 6\Recent Images
[PHPStorm *]
LangSecRef=3024
DetectFile=%UserProfile%\.WebIde40
Default=False
FileKey1=%UserProfile%\.WebIde40\LocalHistory|*.*|RECURSE
FileKey2=%UserProfile%\.WebIde40\Log|*.*|RECURSE
FileKey3=%UserProfile%\.WebIde40\system\caches|*.*|RECURSE
FileKey4=%UserProfile%\.WebIde40\tmp|*.*|RECURSE
[PhraseExpress *]
LangSecRef=3024
DetectFile=%Documents%\PhraseExpress
Default=False
FileKey1=%Documents%\PhraseExpress|*.bak
[PhrozenSoft Databases *]
LangSecRef=3024
DetectFile=%AppData%\PhrozenSoft
Default=False
FileKey1=%AppData%\PhrozenSoft\PVTUploader|phrzvtu.db
[Phyxion.net Driver Sweeper *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Phyxion.net\Driver Sweeper\Logs
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Phyxion.net\Driver Sweeper\Logs|*.*|RECURSE
FileKey2=%ProgramFiles%\Phyxion.net\Driver Sweeper\Logs|*.*|RECURSE
[Phyxion.net Driver Sweeper Backup *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Phyxion.net\Driver Sweeper\Backup
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Phyxion.net\Driver Sweeper\Backup|*.*|RECURSE
FileKey2=%ProgramFiles%\Phyxion.net\Driver Sweeper\Backup|*.*|RECURSE
[Pidgin *]
LangSecRef=3022
Detect=HKCU\Software\Pidgin
Default=False
FileKey1=%AppData%\.purple|*.xml~
FileKey2=%UserProfile%|Recently-Used.xbel
[Pidgin Chat Logs *]
LangSecRef=3022
Detect=HKCU\Software\Pidgin
Default=False
FileKey1=%AppData%\.purple\logs|*.*|REMOVESELF
[Pipy *]
LangSecRef=3021
DetectFile=%AppData%\Pipy
Default=False
FileKey1=%AppData%\Pipy\Logs|*.*
[PKWARE PKZIP *]
LangSecRef=3024
Detect1=HKCU\Software\PKWARE\PKZIP for Windows
Detect2=HKCU\Software\PKWARE\PKZIP70
Detect3=HKCU\Software\PKWARE\ZIPReader 0
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\PKWARE\PKZIPW|*.log
FileKey2=%ProgramFiles%\PKWARE\PKZIPW|*.log
[Planet Horse *]
Section=Games
Detect=HKLM\Software\Big Fish Games\Persistence\Install\F6023T1L1
DetectFile=%ProgramFiles%\Planet Horse
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Planet Horse|output_log.txt|RECURSE
FileKey2=%ProgramFiles%\Planet Horse|output_log.txt|RECURSE
[Planets Under Attack *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\218510
Default=False
FileKey1=%Documents%\My Games\Planets Under Attack|*.log
[Plants vs Zombies *]
Section=Games
DetectFile=%ProgramFiles%\Popcap Games\Plants vs Zombies
Default=False
FileKey1=%ProgramFiles%\Popcap Games\Plants vs Zombies|Install.log
[PlayFirst Games *]
Section=Games
DetectFile=%AppData%\PlayFirst
Default=False
FileKey1=%AppData%\PlayFirst|logfile.txt|RECURSE
[Plex Media Server *]
LangSecRef=3023
Detect=HKCU\Software\Plex, Inc.\Plex Media Server
Default=False
FileKey1=%LocalAppData%\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey2=%LocalAppData%\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey3=%LocalAppData%\Plex Media Server\Logs|*.*|RECURSE
FileKey4=%LocalAppData%\Plex Media Server\Updates|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Cache\PhotoTranscoder|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Crash Reports|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Logs|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Plex Media Server\Updates|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey10=%ProgramFiles%\Plex\Plex Media Server|*.txt;*.log|RECURSE
FileKey11=%WinDir%\System32\config\systemprofile\AppData\Local\Plex Media Server\Logs|*.*|RECURSE
FileKey12=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Plex Media Server\Logs|*.*|RECURSE
[Pogo Games *]
Section=Games
DetectFile=%AppData%\Pogo Games
Default=False
FileKey1=%AppData%\Pogo Games\*\Cache|*.*|REMOVESELF
[Pointstone Total Privacy *]
LangSecRef=3024
Detect=HKCU\Software\Pointstone\Total Privacy
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Pointstone\Total Privacy*|*.txt
FileKey2=%ProgramFiles%\Pointstone\Total Privacy*|*.txt
[Pok3D *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Pok3d
Default=False
FileKey1=%AppData%\Pok3d|*.log;*.dmp
[PokerStars *]
Section=Games
DetectFile=%LocalAppData%\PokerStars
Default=False
FileKey1=%LocalAppData%\PokerStars\ImgCache|*.*
FileKey2=%LocalAppData%\PokeStars|*.log.*
[Pokki *]
LangSecRef=3022
Detect=HKCU\Software\Pokki
Default=False
FileKey1=%LocalAppData%\Pokki|*.log|RECURSE
FileKey2=%LocalAppData%\Pokki\PokkiIconCache|*.*|RECURSE
FileKey3=%LocalAppData%\Pokki\UserData\*|*.bak|RECURSE
[Pokki Internet Traces *]
LangSecRef=3022
Detect=HKCU\Software\Pokki
Default=False
FileKey1=%LocalAppData%\Pokki\UserData\*|Cookies*;Favicons*;*History*;Top Sites*;Visited Links;Web Data*
FileKey2=%LocalAppData%\Pokki\UserData\*\Cache|*.*|RECURSE
FileKey3=%LocalAppData%\Pokki\UserData\*\LocalStorage|*.*
[Polarity *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Polarity
Default=False
FileKey1=%ProgramFiles%\Polarity|*.log
[Polarity Internet Traces *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Polarity
Default=False
FileKey1=%AppData%\Stanley Lim\Polarity\Cache|*.*|RECURSE
FileKey2=%AppData%\Stanley Lim\Polarity\Favicon|*.*
FileKey3=%UserProfile%\Polarity_Config|downloads_names.ini;downloads_times.ini;downloads_urls.ini;history.ini;history_names.ini;history_times.ini;savedTabs.ini
[PolyView *]
LangSecRef=3021
Detect=HKCU\Software\Polybytes\PolyView
Default=False
RegKey1=HKCU\Software\Polybytes\PolyView\Recent File List
[Portfolio Performance *]
LangSecRef=3021
DetectFile=%LocalAppData%\PortfolioPerformance
Default=False
FileKey1=%LocalAppData%\PortfolioPerformance\workspace\.metadata|*.lock,*.log
[PostBox *]
LangSecRef=3021
DetectFile=%LocalAppData%\PostBox
Default=False
FileKey1=%AppData%\PostBox|*.log|RECURSE
FileKey2=%AppData%\PostBox\Crash Reports|*.*|REMOVESELF
FileKey3=%LocalAppData%\PostBox\Profiles\*\Cache|*.*|REMOVESELF
[Power Efficiency Diagnostics *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows\Power Efficiency Diagnostics|*.xml
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics|*.xml
ExcludeKey1=FILE|%CommonAppData%\Microsoft\Windows\Power Efficiency Diagnostics\|energy-report-latest.xml
ExcludeKey2=FILE|%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\|energy-report-latest.xml
[PowerISO *]
LangSecRef=3024
Detect=HKCU\Software\PowerISO
Default=False
FileKey1=%AppData%\PowerISO\Upgrade|*.*|RECURSE
[PowerShell *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\PowerShell
Default=False
FileKey1=%AppData%\Microsoft\Windows\PowerShell\PSReadline|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\PowerShell\CommandAnalysis|*.*|RECURSE
[PowerZip *]
LangSecRef=3024
Detect=HKCU\Software\Trident Software\PowerZip
Default=False
RegKey1=HKCU\Software\Trident Software\PowerZip\Recent File List
[Predator *]
LangSecRef=3021
Detect=HKLM\Software\Predator-Usb
Default=False
FileKey1=%CommonAppData%\Predator-Usb\PredatorACE\data|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Predator-Usb\PredatorACE\data|*.log
[Presentation Foundation *]
LangSecRef=3025
DetectFile1=%WinDir%\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
DetectFile2=%WinDir%\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
DetectFile3=%WinDir%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
DetectFile4=%WinDir%\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
DetectFile5=%WinDir%\winsxs\x86_wpf-presentationfontcache_31bf3856ad364e35_6.1.7600.16385_none_056fecf27381a72b\PresentationFontCache.exe
Default=False
FileKey1=%SystemDrive%\Documents and Settings\LocalService\Local Settings\Application Data|FontCache*.dat;~FontCache*.dat;WPFFontCache_v0400-*.dat
FileKey2=%WinDir%\ServiceProfiles\LocalService\AppData\Local|FontCache*.dat;~FontCache*.dat;WPFFontCache_v0400-*.dat
[Presto Transfer Ultimate *]
LangSecRef=3024
Detect=HKCU\Software\Perception\Presto Transfer Ultimate
Default=False
FileKey1=%AppData%\Presto Transfer Ultimate|lastlog.html
[PriceGong *]
LangSecRef=3022
DetectFile=%AppData%\PriceGong
Default=False
FileKey1=%AppData%\PriceGong\tmp|*.*|RECURSE
[Prince of Persia T2T *]
Section=Games
DetectFile=%ProgramFiles%\Ubisoft\Prince of Persia T2T
Default=False
FileKey1=%LocalAppData%\Ubisoft\Prince of Persia T2T|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Prince of Persia T2T|*.log
FileKey3=%ProgramFiles%\Ubisoft\Prince of Persia T2T|*.log
[Print Queue *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=You may need to halt the print spooler.
FileKey1=%WinDir%\System32\Spool\Printers|*.*
[Prison Architect *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\233450
Default=False
FileKey1=%LocalAppData%\Introversion\Prison Architect|debug.txt
[Privacy Suite *]
LangSecRef=3024
Detect=HKCU\Software\CyberScrub\Privacy Suite
Default=False
FileKey1=%AppData%\CyberScrub\Privacy Suite|cybscrub.log
[Private Internet Access VPN *]
LangSecRef=3022
DetectFile=%AppData%\Titanium\appdata\com.privateinternetaccess.vpn
Default=False
FileKey1=%AppData%\Titanium\appdata\com.privateinternetaccess.vpn|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\pia_manager\log|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\pia_manager\tmp|*.*
FileKey4=%ProgramFiles%\pia_manager\log|*.*
FileKey5=%ProgramFiles%\pia_manager\tmp|*.*
FileKey6=%UserProfile%|.pia_manager_crash.log
[Privoxy *]
LangSecRef=3022
Detect=HKCU\Software\Privoxy
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Vidalia Bundle\Privoxy|privoxy.log
FileKey2=%ProgramFiles%\Vidalia Bundle\Privoxy|privoxy.log
[Procaster *]
LangSecRef=3023
DetectFile=%LocalAppData%\Procaster
Default=False
FileKey1=%LocalAppData%\Procaster|*.log|RECURSE
[Processing 2.0 *]
LangSecRef=3024
DetectFile=%AppData%\Processing
Default=False
FileKey1=%AppData%\Processing\Console|*.*
FileKey2=%AppData%\Processing\Debug|*.*
[ProcessLasso *]
LangSecRef=3024
Detect=HKCU\Software\ProcessLasso
Default=False
FileKey1=%AppData%\ProcessLasso|prolasso.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Process Lasso|.logtype5
FileKey3=%ProgramFiles%\Process Lasso|.logtype5
[ProDiscover *]
LangSecRef=3024
Detect=HKLM\Software\Technology Pathways\ProDiscover
Default=False
RegKey1=HKLM\Software\Technology Pathways\ProDiscover\Recent File List
[ProFantasy Software CC3 View *]
LangSecRef=3023
Detect=HKCU\Software\EvolutionComputing
Default=False
RegKey1=HKCU\Software\EvolutionComputing\CC3View|1
RegKey2=HKCU\Software\EvolutionComputing\CC3View|2
RegKey3=HKCU\Software\EvolutionComputing\CC3View|3
RegKey4=HKCU\Software\EvolutionComputing\CC3View|4
RegKey5=HKCU\Software\EvolutionComputing\CC3View|WorkingDrawing
[ProgDVB *]
LangSecRef=3023
DetectFile=%ProgramFiles%\ProgDVB
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\ProgDVB\Logs|*.*|RECURSE
FileKey2=%ProgramFiles%\ProgDVB\Logs|*.*|RECURSE
[Project64 *]
Section=Games
Detect=HKCU\Software\N64 Emulation
DetectFile=%ProgramFiles%\Project64 *
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Project64 2.*\Logs|*.*
FileKey2=%ProgramFiles%\Project64 2.*\Logs|*.*
RegKey1=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile1
RegKey2=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile2
RegKey3=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile3
RegKey4=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile4
RegKey5=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile5
RegKey6=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile6
RegKey7=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile7
RegKey8=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile8
RegKey9=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile9
RegKey10=HKCU\Software\N64 Emulation\Project64 Version 1.6|RecentFile10
[Proteus *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\219680
Default=False
FileKey1=%Documents%\Proteus\logs|*.*
ExcludeKey1=FILE|%Documents%\Proteus\logs\|rng.txt
[PS3 Media Server *]
LangSecRef=3023
Detect=HKCU\Software\PS3 Media Server
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\PS3 Media Server|*log;*.md|RECURSE
FileKey2=%ProgramFiles%\PS3 Media Server|*log;*.md|RECURSE
[Psi Avatar Cache *]
LangSecRef=3022
Detect=HKCU\Software\psi-im.org\Psi
DetectFile=%LocalAppData%\Psi+
Default=False
FileKey1=%LocalAppData%\Psi+\Avatars|*.*|RECURSE
FileKey2=%UserProfile%\PsiData\avatars|*.*
[Psi Chat Logs *]
LangSecRef=3022
Detect=HKCU\Software\psi-im.org\Psi
DetectFile=%LocalAppData%\Psi+
Default=False
FileKey1=%AppData%\Psi+\profiles\*\history|*.*|RECURSE
FileKey2=%UserProfile%\PsiData\profiles\*\history|*.*
[PSoC Designer 5.4 *]
LangSecRef=3021
DetectFile=%AppData%\Cypress_Semiconductor\PSoC_Designer_54
Default=False
FileKey1=%AppData%\Cypress_Semiconductor\PSoC_Designer_54|debug.log;debug.log.*
[PSPad *]
LangSecRef=3024
DetectFile=%AppData%\PSpad
Default=False
FileKey1=%AppData%\PSpad|Recent.ini
[PunkBuster *]
Section=Games
DetectFile=%LocalAppData%\PunkBuster
Default=False
FileKey1=%LocalAppData%\PunkBuster|pbcl.log|RECURSE
FileKey2=%WinDir%\System32\LogFiles\PunkBuster|*.*
[Puran Defrag *]
LangSecRef=3024
Detect=HKLM\Software\Puran Software\Puran Defrag
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Puran Defrag|PuranDefrag.html
FileKey2=%ProgramFiles%\Puran Defrag|PuranDefrag.html
[Pure Networks *]
LangSecRef=3022
Detect=HKCU\Software\Pure Networks
Default=False
FileKey1=%CommonAppData%\Pure Networks\Log|*.*
FileKey2=%CommonAppData%\Pure Networks\Platform|*.bak
FileKey3=%CommonAppData%\Pure Networks\Platform\minidumps|*.*
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Pure Networks\Log|*.*
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Pure Networks\Platform|*.bak
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Pure Networks\Platform\minidumps|*.*
[PureRa *]
LangSecRef=3024
DetectFile=%SystemDrive%\PureRa.txt
Default=False
FileKey1=%SystemDrive%|PureRa.txt
[Puritan File Destroyer Elite *]
LangSecRef=3023
Detect=HKCU\Software\Puritan\File Destroyer Elite
Default=False
FileKey1=%CommonAppData%\Puritan\File Destroyer Elite|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Puritan\File Destroyer Elite|*.log|RECURSE
[Pushbullet *]
LangSecRef=3022
DetectFile=%AppData%\Pushbullet
Default=False
FileKey1=%AppData%\Pushbullet\pushbullet|*.log
[Pycharm *]
LangSecRef=3021
Detect=HKCU\Software\JetBrains\PyCharm
Default=False
FileKey1=%UserProfile%\.PyCharm*\system\caches|*.*
FileKey2=%UserProfile%\.PyCharm*\system\log|*.*
[Python *]
LangSecRef=3021
Detect=HKCU\Software\Python
Default=False
FileKey1=%ProgramFiles%\Python*|*.icns|RECURSE
FileKey2=%SystemDrive%\Python*|*.icns|RECURSE
[qBittorrent *]
LangSecRef=3022
DetectFile=%LocalAppData%\qBittorrent
Default=False
FileKey1=%LocalAppData%\qBittorrent\cache|*.*
FileKey2=%LocalAppData%\qBittorrent\logs|*.*
[QIP 2012 *]
LangSecRef=3022
Detect=HKCU\Software\QIP
DetectFile=%AppData%\QIP
Default=False
FileKey1=%AppData%\QIP\Profiles\*\*Avatars|*.*
FileKey2=%AppData%\QIP\Profiles\*\Jabber|*.*
FileKey3=%AppData%\QIP\Profiles\*\Logs|*.*
FileKey4=%AppData%\QIP\Profiles\*\PicHashes|*.*
[QIP 2012 Privacy items *]
LangSecRef=3022
Detect=HKCU\Software\QIP
DetectFile=%AppData%\QIP
Default=False
Warning=Selecting this will delete any contact list backups, chat history, received files, opened tabs settings and other non-encrypted privacy items.
FileKey1=%AppData%\QIP\Profiles\*|session.tabs
FileKey2=%AppData%\QIP\Profiles\*\BackupCL|*.*
FileKey3=%AppData%\QIP\Profiles\*\History|*.*|RECURSE
FileKey4=%AppData%\QIP\Profiles\*\ICQ|*.*|RECURSE
FileKey5=%AppData%\QIP\Profiles\*\RcvdFiles|*.*|RECURSE
[QQ *]
LangSecRef=3022
DetectFile=%Documents%\Tencent Files
Default=False
FileKey1=%CommonAppData%\Tencent Files\QQ\Misc|*.*|RECURSE
FileKey2=%Documents%\Tencent Files|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Tencent Files\QQ\Misc|*.*|RECURSE
[QTTabBar *]
LangSecRef=3024
Detect=HKCU\Software\Quizo\QTTabBar
Default=False
FileKey1=%AppData%\QTTabBar|*.log
RegKey1=HKCU\Software\Quizo\QTTabBar|TabsOnLastClosedWindow
RegKey2=HKCU\Software\Quizo\QTTabBar\Cache
RegKey3=HKCU\Software\Quizo\QTTabBar\RecentlyClosed
[QuickBooks *]
LangSecRef=3021
Detect=HKLM\Software\Intuit\QuickBooks
Default=False
FileKey1=%CommonAppData%\Common Files\Intuit\Quickbooks\qbupdate\log|*.*
FileKey2=%CommonAppData%\Intuit\QBWebConnector\log|*.*
FileKey3=%CommonAppData%\Intuit\Quickbooks|*.log;qbsdklog.txt
FileKey4=%CommonAppData%\Intuit\QuickBooks DB Server Manager|*.log;*.old
FileKey5=%CommonProgramFiles%\Intuit\Quickbooks\QBUpdate\Log|*.*
FileKey6=%LocalAppData%\Intuit\QuickBooks\Log|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Intuit\Quickbooks\QBUpdate\Log|*.*
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Common Files\Intuit\Quickbooks\qbupdate\log|*.*
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Intuit\QBWebConnector\log|*.*
FileKey10=%LocalAppData%\VirtualStore\ProgramData\Intuit\Quickbooks|*.log;qbsdklog.txt
FileKey11=%LocalAppData%\VirtualStore\ProgramData\Intuit\QuickBooks DB Server Manager|*.log;*.old
[QuickDic History *]
LangSecRef=3021
DetectFile=%ProgramFiles%\QuickDic
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\QuickDic|QuickDic.ini
FileKey2=%ProgramFiles%\QuickDic|QuickDic.ini
[Quicken *]
LangSecRef=3021
Detect1=HKLM\Software\Intuit\Quicken
Detect2=HKLM\Software\Quicken
Default=False
FileKey1=%AppData%\Intuit\Quicken\Log|*.txt;*.log
FileKey2=%AppData%\Quicken\Log|*.txt;*.log
FileKey3=%CommonAppData%\Intuit\Quicken\Log|*.log
FileKey4=%CommonAppData%\Intuit\Quicken\Log\installer|*.*|REMOVESELF
FileKey5=%CommonAppData%\Intuit\SendError|*.log
FileKey6=%CommonAppData%\Quicken\Log|*.log
FileKey7=%CommonAppData%\Quicken\Log\installer|*.*|REMOVESELF
FileKey8=%CommonAppData%\Quicken\SendError|*.log
FileKey9=%LocalAppData%\Intuit\Common\Authorization\V1\Logs|*.txt
FileKey10=%LocalAppData%\Quicken\Common\Authorization\V1\Logs|*.txt
FileKey11=%LocalAppData%\VirtualStore\ProgramData\Intuit\Quicken\Log|*.log
FileKey12=%LocalAppData%\VirtualStore\ProgramData\Intuit\SendError|*.log
FileKey13=%LocalAppData%\VirtualStore\ProgramData\Quicken\Log|*.log
FileKey14=%LocalAppData%\VirtualStore\ProgramData\Quicken\SendError|*.log
FileKey15=%ProgramFiles%\Quicken\PDFDrv|install.log;InstallPDFConverter.log
[Quicken WillMaker Plus *]
LangSecRef=3021
DetectFile=%LocalAppData%\Quicken WillMaker Plus *
Default=False
FileKey1=%LocalAppData%\Quicken WillMaker Plus *|web update log.txt
[QuickPAR *]
LangSecRef=3024
Detect=HKCU\Software\QuickPar
Default=False
FileKey1=%LocalAppData%\QuickPar|*.*
[QuickTime Player *]
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=False
RegKey1=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Apple Computer, Inc.\QuickTime\Favorite Movies
RegKey2=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Apple Computer, Inc.\QuickTime\Recent Movies
RegKey3=HKCU\Software\Classes\VirtualStore\MACHINE\Software\WOW6432Node\Apple Computer, Inc.\QuickTime\Favorite Movies
RegKey4=HKCU\Software\Classes\VirtualStore\MACHINE\Software\WOW6432Node\Apple Computer, Inc.\QuickTime\Recent Movies
[QuizUp *]
Section=Games
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\QuizUp.QuizUp_n36z36qeaxk8a
Default=False
FileKey1=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0*|*.log|RECURSE
FileKey4=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\Temp|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\QuizUp.QuizUp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalCache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\QuizUp.QuizUp_*\LocalState\Cache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\QuizUp.QuizUp_*\TempState|*.*|RECURSE
[QupZilla Portable Cookies *]
Section=QupZilla Portable
DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe
Default=False
FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\profile|cookies.dat
[QupZilla Portable Local App Data *]
Section=QupZilla Portable
DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe
Default=False
FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\QupZillaLocalAppData|*.*|RECURSE
[QupZilla Portable Network Cache *]
Section=QupZilla Portable
DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe
Default=False
FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\profile\networkcache|*.*|RECURSE
[QupZilla Portable Session *]
Section=QupZilla Portable
DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe
Default=False
FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\profile|session.dat*
[QupZilla Portable Thumbnails *]
Section=QupZilla Portable
DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe
Default=False
FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\profile\thumbnails|*.*
[QupZilla Portable Webpage Icons *]
Section=QupZilla Portable
DetectFile=%SystemDrive%\PortableApps\QupZillaPortable\QupZillaPortable.exe
Default=False
FileKey1=%SystemDrive%\PortableApps\QupZillaPortable\Data\profile|WebpageIcons.db
[Qurb4 *]
LangSecRef=3021
DetectFile=%LocalAppData%\Qurb4
Default=False
FileKey1=%LocalAppData%\Qurb4|*.log|RECURSE
[qutIM *]
LangSecRef=3022
Detect=HKCU\Software\qutIM
Default=False
FileKey1=%AppData%\qutIM\avatars\*|*.*|RECURSE
[qutIM Chat History *]
LangSecRef=3022
Detect=HKCU\Software\qutIM
Default=False
FileKey1=%AppData%\qutIM\history|*.*|RECURSE
[Qwest QuickCare *]
LangSecRef=3022
Detect=HKLM\Software\QuickCare
Default=False
FileKey1=%CommonAppData%\Support.com|*.tmp|RECURSE
FileKey2=%LocalAppData%\SupportSoft|*.tmp|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Support.com|*.tmp|RECURSE
[RadeonPro *]
LangSecRef=3024
DetectFile=%AppData%\RadeonPro
Default=False
FileKey1=%AppData%\RadeonPro|*.old;*.bak;*_bak.*;*.bkp
FileKey2=%AppData%\RadeonPro\Cache|*.*|RECURSE
FileKey3=%AppData%\RadeonPro\Temp|*.*|RECURSE
[Radialix 2 *]
LangSecRef=3021
Detect=HKCU\Software\Radialix
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Radialix 2|*diz;*.txt;*.url
FileKey2=%ProgramFiles%\Radialix 2|*diz;*.txt;*.url
FileKey3=%ProgramFiles%\Radialix 2\Tools\UPX|COPYING;LICENSE
[RadioSure *]
LangSecRef=3023
Detect=HKCU\Software\RadioSure
Default=False
FileKey1=%LocalAppData%\RadioSure\Log|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\RadioSure\Log|*.*
FileKey3=%ProgramFiles%\RadioSure\Log|*.*
[Rage *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\9200
Default=False
FileKey1=%AppData%\id software\rage|*.*|RECURSE
[Rainlendar 2 *]
LangSecRef=3021
DetectFile=%UserProfile%\.rainlendar2
Default=False
FileKey1=%UserProfile%\.rainlendar2|rainlendar2.log
[Rainlendar 2 Backups *]
LangSecRef=3021
DetectFile=%UserProfile%\.rainlendar2
Default=False
FileKey1=%UserProfile%\.rainlendar2\backups|*.*|RECURSE
[RAMExpert *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\RAMExpert
Default=False
FileKey1=%AppData%\KC Softwares\RAMExpert|*.log
[Ranch Rush *]
Section=Games
Detect1=HKLM\Software\Big Fish Games\Persistence\Install\F2580T1L1
Detect2=HKLM\Software\Big Fish Games\Persistence\Install\F5659T1L1
Detect3=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Ranch Rush1.0
DetectFile=%ProgramFiles%\Ranch Rush
Default=False
FileKey1=%CommonAppData%\FreshGames\RanchRush\*|*.log;temp_data.ssp
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ranch Rush*|*.html;*.nfo
FileKey3=%LocalAppData%\VirtualStore\ProgramData\FreshGames\RanchRush\*|*.log;temp_data.ssp
FileKey4=%ProgramFiles%\Ranch Rush*|*.html;*.nfo
[Raptr *]
LangSecRef=3021
Detect=HKCU\Software\Raptr
DetectFile=%ProgramFiles%\Raptr
Default=False
FileKey1=%AppData%\Raptr|*.log|RECURSE
FileKey2=%AppData%\Raptr\Avatars|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Raptr|*.log
FileKey4=%ProgramFiles%\Raptr|*.log
ExcludeKey1=FILE|%ProgramFiles%\Raptr\|install.log
[Raptr Chat History *]
Section=Games
Detect=HKCU\Software\Raptr
Default=False
FileKey1=%AppData%\Raptr\Data\*|chat_history.db
[Razer Software *]
LangSecRef=3024
DetectFile=%CommonAppData%\Razer
Default=False
FileKey1=%CommonAppData%\Razer\*|DiagnoseReport*.*.txt
FileKey2=%CommonAppData%\Razer\*\Logs|*.*
FileKey3=%CommonAppData%\Razer\Synapse\Accounts\*\DataSync|SyncDate.txt
FileKey4=%CommonAppData%\Razer\Synapse\ProductUpdates\Downloads|*.*
FileKey5=%LocalAppData%\Razer\RzUninstallation\Logs|*.*
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Razer\*|*.log
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Razer\*|DiagnoseReport*.*.txt
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Razer\*\Logs|*.*
FileKey9=%LocalAppData%\VirtualStore\ProgramData\Razer\Synapse\Accounts\*\DataSync|SyncDate.txt
FileKey10=%LocalAppData%\VirtualStore\ProgramData\Razer\Synapse\ProductUpdates\Downloads|*.*
FileKey11=%ProgramFiles%\Razer\*|*.log
[RCrawler *]
LangSecRef=3024
Detect=HKLM\Software\4Developers\RCrawler
Default=False
RegKey1=HKLM\Software\4Developers\RCrawler\History
RegKey2=HKLM\Software\4Developers\RCrawler\Settings|LastSearch
[Real Network Monitor *]
LangSecRef=3022
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Real Network Monitor
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Real Network Monitor|*.xml
FileKey2=%ProgramFiles%\Real Network Monitor|*.xml
[RealPlayer Converter *]
LangSecRef=3023
Detect=HKCU\Software\RealNetworks\RealConverter
Default=False
RegKey1=HKCU\Software\RealNetworks\RealJukebox\1.0\Preferences\WatchFolders
[RealPlayer Database Files *]
LangSecRef=3023
Detect=HKCU\Software\RealNetworks\RealPlayer
Default=False
FileKey1=%AppData%\Real\RealPlayer\db|*.*|RECURSE
[Realtek *]
LangSecRef=3024
Detect=HKLM\Software\Realtek
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Realtek*|*.log;*.txt|RECURSE
FileKey2=%ProgramFiles%\Realtek*|*.*log;*.txt|RECURSE
FileKey3=%ProgramFiles%\Temp|*.*|REMOVESELF
FileKey4=%SystemDrive%|RHDSetup.log
ExcludeKey1=FILE|%ProgramFiles%\Realtek\*\|InstCtrl.txt
ExcludeKey2=FILE|%ProgramFiles%\Realtek\*\|setupctrl.txt
[Reckless Racing *]
Section=Games
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Studios.RecklessRacingUltimate_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.Studios.RecklessRacingUltimate_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Studios.RecklessRacingUltimate_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Studios.RecklessRacingUltimate_*\AC\Microsoft\CryptnetUrlCache\*|*.*
[RecollX *]
LangSecRef=3021
DetectFile=%AppData%\Advansys\RecollX
Default=False
FileKey1=%AppData%\Advansys\RecollX\log|*.*|RECURSE
[Recuva *]
LangSecRef=3024
Detect=HKCU\Software\Piriform\Recuva
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Recuva|*.log;Recuva_log*.txt
FileKey2=%ProgramFiles%\Recuva|*.log;Recuva_log*.txt
FileKey3=%UserProfile%|Recuva_log*.txt
[Reddit To Go! *]
LangSecRef=3031
DetectFile=%LocalAppData%\Packages\*.RedditToGo_*
Default=False
FileKey1=%LocalAppData%\Packages\*.RedditToGo_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*.RedditToGo_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\*.RedditToGo_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\*.RedditToGo_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\*.RedditToGo_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\*.RedditToGo_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\*.RedditToGo_*\RoamingState|history.txt
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\55382ross456.RedditToGo_02dxdbb1qg9kw\SearchHistory
[Reflector *]
LangSecRef=3021
DetectFile=%AppData%\Reflector
Default=False
FileKey1=%AppData%\Reflector|*.log;*.dmp
[Reg Organizer *]
LangSecRef=3024
Detect=HKCU\Software\ChemTable Software\Reg Organizer
Default=False
FileKey1=%LocalAppData%\ChemTable Software\Reg Organizer|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Reg Organizer|*.txt
FileKey3=%ProgramFiles%\Reg Organizer|*.txt
[RegAlyzer *]
LangSecRef=3024
Detect=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer
Default=False
RegKey1=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|LastKey
RegKey2=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|RemoteListHistory
RegKey3=HKCU\Software\PepiMK Software\Analysis tools\RegAlyzer|SearchTerm
[RegClean Pro *]
LangSecRef=3024
Detect=HKCU\Software\Systweak\RegClean Pro
DetectFile=%ProgramFiles%\RegClean Pro\RegCleanPro.exe
Default=False
FileKey1=%AppData%\Systweak\RegClean Pro\Version 6.1|*.log
[RegEditX *]
LangSecRef=3024
Detect=HKLM\Software\DCSoft\RegEditX
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\DCSoft\RegEditX\*|RegEditX.sav;RegEditX.bak
RegKey1=HKLM\Software\4Developers\RCrawler\History
RegKey2=HKLM\Software\4Developers\RCrawler\Settings|LastSearch
[ReGet Deluxe *]
LangSecRef=3022
Detect=HKCU\Software\ReGet Software\ReGetDx
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\ReGet Deluxe\history|*.*
FileKey2=%ProgramFiles%\ReGet Deluxe\history|*.*
RegKey1=HKCU\Software\ReGet Software\ReGetDx\FtpExplorer\Hist
RegKey2=HKCU\Software\ReGet Software\ReGetDx\History
RegKey3=HKCU\Software\ReGet Software\ReGetDx\Search\HistFind
[Registrar Registry Manager *]
LangSecRef=3024
Detect=HKCU\Software\Resplendence Sp\Registrar Registry Manager
Default=False
RegKey1=HKCU\Software\Resplendence Sp\Registrar Registry Manager\Settings|ExportForm.saveDialogExportFilename
RegKey2=HKCU\Software\Resplendence Sp\Registrar Registry Manager\Settings|ExportForm.saveDialogExportInitialDir
RegKey3=HKCU\Software\Resplendence Sp\Registrar Registry Manager\Settings|LastOpenedKey
[Registry Clean Expert *]
LangSecRef=3023
Detect=HKCU\Software\SuniSoft\IncUpdate\Registry Clean Expert
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Registry Clean Expert|fixlog.ini
FileKey2=%ProgramFiles%\Registry Clean Expert|fixlog.ini
[Registry First Aid *]
LangSecRef=3024
Detect=HKCU\Software\KsL Software\RFA
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows|NTUSER.tmp;UsrClass.tmp
FileKey2=%UserProfile%|NTUSER.tmp;UsrClass.tmp
FileKey3=%WinDir%\ServiceProfiles\*Service|*.tmp;*.tmp.LOG1;*.tmp.LOG2
FileKey4=%WinDir%\System32\config|*.tmp;*.tmp.LOG1;*.tmp.LOG2
FileKey5=%WinDir%\System32\config\systemprofile|*.tmp;*.tmp.LOG1;*.tmp.LOG2
FileKey6=%WinDir%\SysWOW64\config\systemprofile|*.tmp;*.tmp.LOG1;*.tmp.LOG2
[Registry Mechanic *]
LangSecRef=3024
Detect=HKLM\Software\PCTools\Registry Mechanic
Default=False
FileKey1=%AppData%\Registry Mechanic\log|*.html
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Registry Mechanic\log*|*.*
FileKey3=%ProgramFiles%\Registry Mechanic\log*|*.*
[RegistryFix *]
LangSecRef=3024
DetectFile=%ProgramFiles%\RegistryFix\RegistryFix.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\RegistryFix\logs|*.*
FileKey2=%ProgramFiles%\RegistryFix\logs|*.*
[RegServo *]
LangSecRef=3024
DetectFile=%CommonAppData%\regservo
Default=False
FileKey1=%CommonAppData%\regservo\Logs|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\regservo\Logs|*.*|RECURSE
[RegToBat *]
LangSecRef=3024
Detect=HKLM\Software\BlueLife\RegToBat
Default=False
RegKey1=HKLM\Software\BlueLife\RegToBat|LastRegFile
[RegVac Registry Cleaner *]
LangSecRef=3024
DetectFile=%ProgramFiles%\RegVac Registry Cleaner
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\RegVac Registry Cleaner|*.xml
FileKey2=%ProgramFiles%\RegVac Registry Cleaner|*.xml
[RegWork *]
LangSecRef=3021
DetectFile=%ProgramFiles%\RegWork
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\RegWork\Logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\RegWork\Tmp|*.*
FileKey3=%ProgramFiles%\RegWork\Logs|*.*
FileKey4=%ProgramFiles%\RegWork\Tmp|*.*
[Reign: Conflict of Nations *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\46380
Default=False
FileKey1=%LocalAppData%\1C\Reign Conflict of Nations|PSPLog.log
[Relic Downloader *]
Section=Games
DetectFile=%Documents%\My Games\Company of Heroes*
Default=False
FileKey1=%Documents%\My Games\RelicDownloader|*.log
[Remote Desktop *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Terminal Server Client
Default=False
Warning=This will reset all Remote Desktop Connection settings.
FileKey1=%Documents%|*.rdp
[Rename Us *]
LangSecRef=3024
Detect=HKCU\Software\Vitaliy Levchenko\Renamus
Default=False
RegKey1=HKCU\Software\Vitaliy Levchenko\Renamus\Recent Projects
RegKey2=HKCU\Software\Vitaliy Levchenko\Renamus\Settings|LastFolder
[Replay Media Catcher *]
LangSecRef=3022
Detect=HKLM\Software\Applian Technologies\Replay Media Catcher 5
DetectFile=%AppData%\Replay Media Catcher 4
Default=False
FileKey1=%AppData%\Replay Media Catcher 4|*.log
FileKey2=%AppData%\Replay Media Catcher 4\History|*.*|REMOVESELF
FileKey3=%LocalAppData%\Replay Media Catcher 5\History|*.*|REMOVESELF
FileKey4=%LocalAppData%\Replay Media Catcher 5\Temp|*.*|REMOVESELF
FileKey5=%LocalAppData%\Replay Media Catcher 5\UrlCache|*.*|REMOVESELF
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Applian Technologies\Replay Media Catcher*|*.html;*.txt;*.rtf
FileKey7=%ProgramFiles%\Applian Technologies\Replay Media Catcher*|*.html;*.txt;*.rtf
[Resilio Sync *]
LangSecRef=3024
DetectFile=%AppData%\Resilio Sync
Default=False
FileKey1=%AppData%\Resilio Sync|*.journal;*.journal.zip;*.log;*.old;history.dat
[Resource Hacker *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Resource Hacker\ResHacker.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Resource Hacker|ResHacker.ini;reshacker.GID
FileKey2=%ProgramFiles%\Resource Hacker|ResHacker.ini;reshacker.GID
[Restorator 2007 *]
LangSecRef=3021
Detect=HKCU\Software\Bomers\Restorator
Default=False
RegKey1=HKCU\Software\Bomers\Restorator\Restorator\Current|LastSearchString
RegKey2=HKCU\Software\Bomers\Restorator\Restorator\FindDialog
RegKey3=HKCU\Software\Bomers\Restorator\Restorator\GrabDialog
RegKey4=HKCU\Software\Bomers\Restorator\Restorator\LastFoundFiles
RegKey5=HKCU\Software\Bomers\Restorator\Restorator\MRUList
[Restore Point Creator *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CC48DE1C-8EC2-43BC-9201-29701CD9AE13}_is1
Default=False
FileKey1=%CommonAppData%|Restore Point Creator.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Restore Point Creator|*.log;*.txt
FileKey3=%ProgramFiles%\Restore Point Creator|*.log;*.txt
[ResumeMaker *]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D2E80193-7318-4707-A9DE-49AF663ADA73}
Default=False
FileKey1=%CommonAppData%\Individual Software\ResumeMaker\R12|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Individual Software\ResumeMaker\R12|*.log
[Reus *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\222730
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\Reus|errorReport*.txt
FileKey2=%ProgramFiles%\Steam\SteamApps\common\Reus|errorReport*.txt
[Revenge of The Titans *]
Section=Games
DetectFile=%UserProfile%\.revenge_of_the_titans_1.80
Default=False
FileKey1=%UserProfile%\.revenge_of_the_titans_1.80|*.log
[Revo Uninstaller Backups *]
LangSecRef=3024
DetectFile=%LocalAppData%\VS Revo group
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\VS Revo Group\Revo Uninstaller Pro|*.bak
FileKey2=%LocalAppData%\VS Revo Group\Revo Uninstaller*\BackupsData|*.*|RECURSE
FileKey3=%ProgramFiles%\VS Revo Group\Revo Uninstaller Pro|*.bak
[Ride! *]
Section=Games
Detect1=HKLM\Software\Big Fish Games\Persistence\Install\F2440T1L1
Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Ride!
DetectFile=%ProgramFiles%\Ride!
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Ride!|*.log;*.txt|RECURSE
FileKey2=%ProgramFiles%\Ride!|*.log;*.txt|RECURSE
FileKey3=%ProgramFiles%\Ride!\DirectX9|*.*|REMOVESELF
[Riding Academy 3D *]
Section=Games
Detect=HKCU\Software\Program-Ace\RidingAcademy3D
Default=False
FileKey1=%LocalAppData%\Riding Academy 3D\logs|*.*
[Riding Star 3 *]
Section=Games
Detect=HKLM\Software\DTP\Riding Star 3
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Riding Star 3|INSTALL.LOG;log.txt
FileKey2=%ProgramFiles%\Riding Star 3|INSTALL.LOG;log.txt
[RIFT *]
Section=Games
DetectFile=%Documents%\RIFT
Default=False
FileKey1=%AppData%\RIFT|*.log
FileKey2=%Documents%\RIFT|*.log
FileKey3=%LocalAppData%\VirtualStore\Program Files*\RIFT|*.log
FileKey4=%ProgramFiles%\RIFT|*.log
FileKey5=%Public%\Games\RIFT|*.log
FileKey6=%SystemDrive%\RIFT|*.log
[Rigs of Rods *]
LangSecRef=3021
DetectFile=%LocalAppData%\CrashRpt\UnsentCrashReports\Rigs of Rods
Default=False
FileKey1=%LocalAppData%\CrashRpt\UnsentCrashReports\Rigs of Rods_*|*.*|RECURSE
[Ring Central *]
LangSecRef=3022
DetectFile=%CommonAppData%\RingCentral
Default=False
FileKey1=%CommonAppData%\RingCentral\LogFiles|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\RingCentral\LogFiles|*.*
[Rise of Nations *]
Section=Games
Detect1=HKCU\Software\Microsoft\Microsoft Games\Rise of Nations
Detect2=HKCU\Software\Microsoft\Microsoft Games\RiseofNationsExpansion
Default=False
FileKey1=%AppData%\Microsoft Games\Rise of Nations\Logs|*.*
[Rkill *]
LangSecRef=3024
DetectFile1=%UserProfile%\Desktop\Rkill
DetectFile2=%UserProfile%\Desktop\Rkill.txt
Default=False
FileKey1=%UserProfile%\Desktop|*rkill*.*
FileKey2=%UserProfile%\Desktop\Rkill|*.*|REMOVESELF
[Roadkil's Unstoppable Copier *]
LangSecRef=3024
Detect=HKCU\Software\Roadkil
Default=False
RegKey1=HKCU\Software\Roadkil|Source_Unstp
RegKey2=HKCU\Software\Roadkil|Target_Unstp
[Roblox *]
Section=Games
DetectFile=%LocalAppData%\Roblox
Default=False
FileKey1=%LocalAppData%\Roblox\Logs|*.*|RECURSE
FileKey2=%LocalLowAppData%\RbxLogs|*.*|RECURSE
[Roblox Downloads *]
Section=Games
DetectFile=%LocalAppData%\Roblox
Default=False
FileKey1=%LocalAppData%\Roblox\Downloads|*.*|RECURSE
[RoboBasket3 *]
LangSecRef=3024
DetectFile=%AppData%\RoboBasket3
Default=False
Warning=This may prompt you with an error upon trying to view the log. Just click continue.
FileKey1=%AppData%\RoboBasket3|log.database
[Rochard *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\107800
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\Rochard\Rochard_Data|Output_log.txt
FileKey2=%LocalLowAppData%\Recoil Games\Rochard|journal.txt
FileKey3=%ProgramFiles%\Steam\SteamApps\common\Rochard\Rochard_Data|Output_log.txt
[Rock of Ages *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\22230
Detect2=HKLM\Software\ACE Team\Rock of Ages
Default=False
FileKey1=%ProgramFiles%\ATLUS\Rock of Ages\Prerequisites|*.*|REMOVESELF
FileKey2=%ProgramFiles%\Steam\steamapps\common\Rock of Ages\Prerequisites|*.*|REMOVESELF
[Rocket League *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\252950
Default=False
FileKey1=%Documents%\My Games\Rocket League\TAGame\Logs|*.*
[RollBack Rx *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Shield
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Shield|*.log
FileKey2=%ProgramFiles%\Shield|*.log
[Roxio *]
LangSecRef=3021
Detect=HKCU\Software\Roxio
Default=False
FileKey1=%AppData%\Roxio Burn\Temp|*.*|RECURSE
FileKey2=%AppData%\Roxio Log Files|*.*|RECURSE
FileKey3=%AppData%\Roxio\Dragon\3.x\*Logs|*.log
FileKey4=%AppData%\Roxio\Dragon\3.x\DiscInfoCache|*.tmp
FileKey5=%CommonAppData%\Roxio|*.log;cardinfo.*
FileKey6=%LocalAppData%|rx_audio.Cache;rx_image32.Cache
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Roxio|*.log;cardinfo.*
FileKey8=%WinDir%\System32\config\systemprofile\AppData\Roaming\Roxio Log Files|*.*|RECURSE
FileKey9=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Roxio Log Files|*.*|RECURSE
[Roxio Creator Pro *]
LangSecRef=3021
Detect1=HKCU\Software\Roxio\EMC13
Detect2=HKCU\Software\Roxio\EMC14
Default=False
FileKey1=%Documents%\Roxio\Music Disc Creator|*.*
RegKey1=HKCU\Software\Roxio\EMC13\VideoUI\RecentFiles\Catalogs
RegKey2=HKCU\Software\Roxio\EMC14\Label Creator\Recent File List
RegKey3=HKCU\Software\Roxio\EMC14\MusicDiscCreator\Directories
RegKey4=HKCU\Software\Roxio\EMC14\MusicDiscCreator\MediaSelector
RegKey5=HKCU\Software\Roxio\EMC14\PhotoSuite\RoxioPhotoSuite\MRUFiles
RegKey6=HKCU\Software\Roxio\EMC14\SoundEdit\Directories
RegKey7=HKCU\Software\Roxio\EMC14\SoundEdit\MediaSelector
RegKey8=HKCU\Software\Roxio\EMC14\SoundEdit\WaveCache
RegKey9=HKCU\Software\Roxio\EMC14\VideoConvert\Directories
RegKey10=HKCU\Software\Roxio\EMC14\VideoConvert\MediaSelector
RegKey11=HKCU\Software\Roxio\EMC14\VideoUI\RecentFiles\Albums
RegKey12=HKCU\Software\Roxio\EMC14\VideoUI\RecentFiles\Catalogs
RegKey13=HKCU\Software\Roxio\EMC14\VideoUI\RecentFiles\DVD Projects
RegKey14=HKCU\Software\Roxio\EMC14\VideoUI\RecentFiles\Productions
RegKey15=HKLM\Software\Roxio\EMC13\Common SDK\Users
RegKey16=HKLM\Software\Roxio\EMC14\Common SDK\Users
RegKey17=HKLM\Software\Wow6432Node\Roxio\EMC13\Common SDK\Users
RegKey18=HKLM\Software\Wow6432Node\Roxio\EMC14\Common SDK\Users
[RssBandit *]
LangSecRef=3022
DetectFile=%AppData%\RssBandit
Default=False
FileKey1=%AppData%\RssBandit|*.bak;*.log
[rtmpGUI .swfinfo *]
LangSecRef=3024
DetectFile=%UserProfile%\.swfinfo
Default=False
FileKey1=%UserProfile%|.swfinfo
[Rust *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\252490
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Rust|debug_steamclient.txt
FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Rust|debug_steamclient.txt
[SABnzbd *]
LangSecRef=3021
DetectFile=%LocalAppData%\sabnzbd
Default=False
FileKey1=%LocalAppData%\sabnzbd\admin|history1.db;totals9.sab
FileKey2=%LocalAppData%\sabnzbd\logs|*.*
[SABnzbd Backup *]
LangSecRef=3022
Detect=HKCU\Software\SABnzbd
Default=False
FileKey1=%LocalAppData%\SABnzbd|*.bak
[Safari *]
LangSecRef=3028
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%AppData%\Apple Computer\Logs|*.*
FileKey2=%LocalAppData%\Apple Computer\com.apple.Safari.PrivateBrowsing|Cache.db
FileKey3=%LocalAppData%\Apple Computer\Safari|WebpageIcons.db
[Sage ACT! *]
LangSecRef=3021
Detect=HKLM\Software\ACT
Default=False
FileKey1=%CommonAppData%\Sage Software, Inc\ACT! by Sage\ActUpdate|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sage Software, Inc\ACT! by Sage\ActUpdate|*.*|RECURSE
[Sage Simply Accounting *]
LangSecRef=3021
Detect=HKLM\Software\Sage Software\Simply Accounting
Default=False
FileKey1=%CommonAppData%\Sage Software\Simply Accounting\Download|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sage Software\Simply Accounting\Download|*.*|RECURSE
[SageThumbs *]
LangSecRef=3021
DetectFile=%ProgramFiles%\SageThumbs\64\SageThumbs.dll
Default=False
FileKey1=%LocalAppData%|SageThumbs.*
[SAM Broadcaster *]
LangSecRef=3023
Detect=HKCU\Software\SAMBC
Default=False
FileKey1=%LocalAppData%\SpacialAudio\SAMBC|*.log|RECURSE
FileKey2=%LocalAppData%\SpacialAudio\SAMBC\backup|*.*|RECURSE
[Samsung Kies *]
LangSecRef=3023
Detect1=HKCU\Software\Samsung\Kies2.0
Detect2=HKCU\Software\Samsung\Kies3.0
Detect3=HKLM\Software\SAMSUNG\USB_DRIVER
Default=False
FileKey1=%AppData%\Samsung\Kies|*.mlca;*.mlme;*.mlpb;*.mlpgb|RECURSE
FileKey2=%CommonAppData%\Samsung\Device Error Recovery|*.*
FileKey3=%CommonAppData%\Samsung\Kies|Kiesairmessage.log
FileKey4=%Documents%\samsung\Kies3\backup|*.dmp|RECURSE
FileKey5=%Documents%\SelfMV|*.log
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Samsung\Device Error Recovery|*.log
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Samsung\Kies|Kiesairmessage.log
[Samsung Kies Backup *]
LangSecRef=3023
Detect1=HKCU\Software\Samsung\Kies2.0
Detect2=HKCU\Software\Samsung\Kies3.0
Default=False
Warning=Removing backups will prevent you from restoring your data later.
FileKey1=%Documents%\samsung\Kies*\backup|*.*|RECURSE
[Samsung Magician *]
LangSecRef=3021
Detect=HKLM\Software\Samsung Magician
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Samsung\Samsung Magician|*.log;*.txt|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Samsung\Samsung Magician\Log*|*.*
FileKey3=%ProgramFiles%\Samsung Magician\Logs|*.*
FileKey4=%ProgramFiles%\Samsung\Samsung Magician\Log*|*.*
RegKey1=HKCU\Software\Local AppWizard-Generated Applications\SamsungMagician
[Sanctum *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\91600
Default=False
FileKey1=%Documents%\My Games\Sanctum\SanctumGame\Logs|*.*
[Santa Ride! 2 *]
Section=Games
Detect=HKLM\Software\Invictus-Games\Santa Ride 2
DetectFile=%ProgramFiles%\Invictus Games\Santa Ride! 2\SR2.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Invictus Games\Santa Ride! 2|*.log
FileKey2=%ProgramFiles%\Invictus Games\Santa Ride! 2|*.log
[Santa's Rampage *]
Section=Games
DetectFile=%ProgramFiles%\*Santa* Rampage
Default=False
FileKey1=%ProgramFiles%\*Santa* Rampage|*.diz;*.nfo;*.txt;*.url;dotNetFx40_Full_setup.exe|RECURSE
FileKey2=%ProgramFiles%\*Santa* Rampage\Redist|*.*|REMOVESELF
FileKey3=%ProgramFiles%\*Santa* Rampage\UDKGame\Logs|*.*|REMOVESELF
ExcludeKey1=FILE|%ProgramFiles%\*Santa* Rampage\UDKGame\CookedPC\|Manifest.txt
ExcludeKey2=PATH|%ProgramFiles%\*Santa* Rampage\Binaries\Win32\|*.*
ExcludeKey3=PATH|%ProgramFiles%\*Santa* Rampage\Binaries\Win64\|*.*
ExcludeKey4=PATH|%ProgramFiles%\*Santa* Rampage\UDKGame\Script\|*.*
[Sauerbraten *]
Section=Games
DetectFile=%ProgramFiles%\Sauerbraten\bin\sauerbraten.exe
Default=False
FileKey1=%Documents%\My Games\Crash|*.log
FileKey2=%Documents%\My Games\Sauerbraten|log.txt
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Sauerbraten\packages\base|*.bak|RECURSE
FileKey4=%ProgramFiles%\Sauerbraten\packages\base|*.bak|RECURSE
[SavingsBull *]
LangSecRef=3022
DetectFile=%ProgramFiles%\SavingsBullFilter
Default=False
FileKey1=%WinDir%\System32|SavingsBullFilterService.log
[SBMAV Disk Cleaner *]
LangSecRef=3024
Detect=HKCU\Software\SBMAV Software\Disk Cleaner
Default=False
FileKey1=%AppData%\SBMAV Disk Cleaner|dcleaner.log
FileKey2=%ProgramFiles%\SBMAV Disk Cleaner|*.rtf
[Scan *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsScan_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsScan_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsScan_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsScan_*\TempState|*.*|RECURSE
[ScanDefrag *]
LangSecRef=3024
Detect=HKLM\Software\ScanDefrag
Default=False
FileKey1=%SystemDrive%\ScanDefrag|*.log
FileKey2=%SystemDrive%\ScanDefrag\logs|*.txt
[Screenpresso *]
LangSecRef=3024
DetectFile=%AppData%\Learnpulse\Screenpresso
Default=False
FileKey1=%AppData%\Learnpulse\Screenpresso|settings.copy.xml
FileKey2=%Pictures%\Screenpresso\Thumbnails|*.*|RECURSE
[ScreenShot Index *]
DetectOS=6.2|
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This Resets Screenshot Naming Back To "Screenshot (1).png"
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer|ScreenshotIndex
[Scribe Finished Jobs *]
LangSecRef=3021
Detect=HKCU\Software\NCH Software\Scribe
Default=False
Warning=This will delete copies of files related you have run through Scribe.
FileKey1=%AppData%\NCH Software\Scribe\Done|*.*
[Scribus *]
LangSecRef=3023
DetectFile=%AppData%\Scribus
Default=False
FileKey1=%AppData%\Scribus\scrapbook\tmp|*.*|RECURSE
[SdfBrowser *]
LangSecRef=3024
DetectFile=%AppData%\BokorBéla\SdfBrowser
Default=False
FileKey1=%AppData%\BokorBéla\SdfBrowser|*.log
[Seagate Dashboard *]
LangSecRef=3024
Detect=HKLM\Software\Seagate\Seagate Dashboard\CurrentVersion
Default=False
FileKey1=%AppData%\Seagate\Seagate Dashboard\logs|MemeoLauncher.exe.log;SeagateDashboard-*.log;MemeoLauncher.exe.log-*.log;MemeoUpdater.exe.log;MemeoUpdater.exe.log-*.log
FileKey2=%WinDir%\System32\config\systemprofile\AppData\Roaming\Seagate\Seagate Dashboard\logs|SeagateDashboardService;SeagateDashboardService-*.log
FileKey3=%WinDir%\SysWOW64\config\systemprofile\AppData\Roaming\Seagate\Seagate Dashboard\logs|SeagateDashboardService;SeagateDashboardService-*.log
[Seagate SeaTools for Windows *]
LangSecRef=3024
Detect=HKLM\Software\SeaToolsforWindows
Default=False
FileKey1=%AppData%\Dexpot|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Seagate\SeaTools for Windows|*.log
FileKey3=%ProgramFiles%\Seagate\SeaTools for Windows|*.log
[Search History *]
DetectOS=6.2|
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SearchHistory
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps
[Second Copy *]
LangSecRef=3024
Detect=HKCU\Software\Centered Systems\Second Copy 2000
DetectFile=%LocalAppData%\Centered Systems\Second Copy
Default=False
FileKey1=%LocalAppData%\Centered Systems\Second Copy|log*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\SecCopy|log.rtf;log-old.rtf
FileKey3=%ProgramFiles%\SecCopy|log.rtf;log-old.rtf
RegKey1=HKCU\Software\Centered Systems\Second Copy 2000\MRU
[SecondLife *]
LangSecRef=3021
DetectFile=%AppData%\SecondLife
Default=False
FileKey1=%AppData%\SecondLife\*|*.txt|RECURSE
FileKey2=%AppData%\SecondLife\Logs|*.*
[SecondLife Caches *]
LangSecRef=3021
DetectFile=%AppData%\SecondLife
Default=False
FileKey1=%AppData%\SecondLife\*\Browser_Profile\Cache|*.*|RECURSE
FileKey2=%AppData%\SecondLife\*\cache|*.*|RECURSE
FileKey3=%AppData%\SecondLife\cache|*.*|RECURSE
[SecureCRT *]
LangSecRef=3021
Detect=HKCU\Software\VanDyke\SecureCRT
Default=False
FileKey1=%AppData%\VanDyke\SecureCRT\Config|Recent File List.ini;Recent Script List.ini
[SecureDownloadManager *]
LangSecRef=3022
Detect=HKCU\Software\e-academy Inc.\SecureDownloadManager
Default=False
FileKey1=%LocalAppData%\e-academy Inc\SecureDownloadManager|*.log
RegKey1=HKCU\Software\e-academy Inc.\SecureDownloadManager\Recent File list
[Sendori *]
LangSecRef=3022
DetectFile=%CommonAppData%\Sendori
Default=False
FileKey1=%CommonAppData%\Sendori|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Sendori|*.log
[Serious Sam *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\41014
Detect2=HKCU\Software\Valve\Steam\Apps\41070
Detect3=HKCU\Software\Valve\Steam\Apps\564310
DetectFile=%ProgramFiles%\Croteam\Serious Sam *
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Croteam\Serious Sam *|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Croteam\Serious Sam *\Temp|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Serious Sam *|*.log
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Serious Sam *\Log|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Serious Sam *\Temp|*.*
FileKey6=%ProgramFiles%\Croteam\Serious Sam *|*.log
FileKey7=%ProgramFiles%\Croteam\Serious Sam *\Temp|*.*
FileKey8=%ProgramFiles%\Steam\SteamApps\Common\Serious Sam *|*.log
FileKey9=%ProgramFiles%\Steam\SteamApps\Common\Serious Sam *\Log|*.*|RECURSE
FileKey10=%ProgramFiles%\Steam\SteamApps\Common\Serious Sam *\Temp|*.*
[ServeToMe *]
LangSecRef=3023
DetectFile=%AppData%\ProjectsWithLove\ServeToMe
Default=False
FileKey1=%AppData%\ProjectsWithLove\ServeToMe\Fontcache|*.*
[Serviio *]
LangSecRef=3024
Detect=HKLM\Software\Serviio
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Serviio\log|*.*
FileKey2=%ProgramFiles%\Serviio\log|*.*
[Session Manager *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%\AppCompat\Programs|*.txt;*.xml
FileKey2=%WinDir%\AppCompat\Programs\Install|*.txt;*.xml
RegKey1=HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatCache|AppCompatCache
RegKey2=HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatCache|CacheMainSdb
RegKey3=HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatCache|SdbTime
[SetRegistryKey Leftovers *]
LangSecRef=3025
Detect=HKCU\Software\Local AppWizard-Generated Applications
Default=False
Warning=Running this entry will cause it to self destruct and no longer appear. This is the intended behavior.
RegKey1=HKCU\Software\Local AppWizard-Generated Applications
[Shareaza *]
LangSecRef=3022
Detect=HKCU\Software\BHO Shareaza
Default=False
FileKey1=%LocalAppData%\Shareaza\Incomplete|*.*
[ShareX *]
LangSecRef=3021
DetectFile=%Documents%\ShareX
Default=False
FileKey1=%Documents%\ShareX|History.xml
FileKey2=%Documents%\ShareX\Logs|*.*|RECURSE
[ShareX Backup *]
LangSecRef=3021
DetectFile=%Documents%\ShareX
Default=False
FileKey1=%Documents%\ShareX|*.avi;*.bak
FileKey2=%Documents%\ShareX\Backup|*.*|RECURSE
[ShareX Screenshots *]
LangSecRef=3021
DetectFile=%Documents%\ShareX
Default=False
Warning=This will delete all Screenshots captured by ShareX.
FileKey1=%Documents%\ShareX\Screenshots|*.*|RECURSE
[Sharing MFU *]
DetectOS=6.2|
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This will remove the frequently shared list. This does not remove the Apps listed under sharing.
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SharingMFU
[Shark Dash *]
Section=Games
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\GAMELOFTSA.SharkDashByGameloft_0pp20fcewvvtj
DetectFile=%LocalAppData%\Packages\GAMELOFTSA.SharkDashByGameloft_0pp20fcewvvtj
Default=False
FileKey1=%LocalAppData%\Packages\GAMELOFTSA.SharkDashByGameloft_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\GAMELOFTSA.SharkDashByGameloft_*\AC\Microsoft\CryptnetUrlCache\*|*.*
[Shatter *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\20820
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Shatter|log.txt
FileKey2=%ProgramFiles%\Steam\steamapps\common\Shatter|log.txt
[Shattered Horizon *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\18110
DetectFile=%LocalAppData%\Futuremark\Shattered Horizon
Default=False
FileKey1=%LocalAppData%\Futuremark\Shattered Horizon\cache|*.*|REMOVESELF
FileKey2=%LocalAppData%\Futuremark\Shattered Horizon\crash_dumps|*.*
[Shell Experience Host *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Windows.ShellExperienceHost_*\TempState|*.*|RECURSE
[Shipping Assistant *]
LangSecRef=3021
DetectFile=%LocalAppData%\ShippingAssistant
Default=False
FileKey1=%LocalAppData%\ShippingAssistant\Logs|*.*|RECURSE
[ShortKeys *]
LangSecRef=3021
Detect=HKCU\Software\Insight Software Solutions\ShortKeys
Default=False
RegKey1=HKCU\Software\Insight Software Solutions\ShortKeys\MRU
[Should I Remove It? *]
LangSecRef=3024
Detect=HKCU\Software\Reason
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Reason\Should I Remove It|programdata.dat
FileKey2=%ProgramFiles%\Reason\Should I Remove It|programdata.dat
RegKey1=HKCU\Software\Reason\ShouldIRemoveIt\Cache
[Shuffle Party *]
Section=Games
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ShuffleParty_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ShuffleParty_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ShuffleParty_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ShuffleParty_*\AC\Microsoft\CryptnetUrlCache\*|*.*
[Signature Verification *]
DetectOS=|5.1
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%WinDir%|SIGVERIF.TXT
[SigParser *]
LangSecRef=3024
DetectFile=%ProgramFiles%\UpdateStar\SigParser\SigParser.exe
Default=False
FileKey1=%AppData%\UpdateStar GmbH\SigParser\3.0.4898.22300|*.log
[Silent Hunter III *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\15210
DetectFile=%ProgramFiles%\Ubisoft\SilentHunterIII
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\SilentHunterIII|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\SilentHunterIII|*.log|RECURSE
FileKey3=%ProgramFiles%\Steam\SteamApps\Common\SilentHunterIII|*.log|RECURSE
FileKey4=%ProgramFiles%\Ubisoft\SilentHunterIII|*.log|RECURSE
[SimCity 4 *]
Section=Games
Detect=HKLM\Software\Maxis\SimCity 4
Default=False
FileKey1=%Documents%\SimCity 4\Exception Reports|*.mdmp;*.txt
FileKey2=%Documents%\SimCity 4\HTTPCache|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Maxis\SimCity 4 Deluxe\Apps|*.txt
FileKey4=%ProgramFiles%\Maxis\SimCity 4 Deluxe\Apps|*.txt
[SimCity Societies *]
Section=Games
Detect1=HKLM\Software\Electronic Arts\SimCity Societies
Detect2=HKLM\Software\Electronic Arts\SimCity Societies (tm) Destinations
Default=False
FileKey1=%Documents%\SimCity Societies\Logs|*.*
[Similarity *]
LangSecRef=3023
DetectFile=%AppData%\Similarity
Default=False
FileKey1=%AppData%\Similarity|cache.dat
FileKey2=%AppData%\Similarity\logs|*.*|RECURSE
[SIMS RACER *]
Section=Games
DetectFile1=%CommonAppData%\SIMS\RACER
DetectFile2=%ProgramFiles%\SIMS\RACER
DetectFile3=%SystemDrive%\SIMS\RACER
Default=False
FileKey1=%CommonAppData%\SIMS\RACER|QLOG.txt
FileKey2=%LocalAppData%\VirtualStore\Program*\SIMS\RACER|QLOG.txt
FileKey3=%ProgramFiles%\SIMS\RACER|QLOG.txt
FileKey4=%SystemDrive%\SIMS\RACER|QLOG.txt
[SiSense *]
LangSecRef=3021
DetectFile=%AppData%\SiSense
Default=False
FileKey1=%AppData%\SiSense\Prism\logs|*.*
FileKey2=%CommonAppData%\SiSense|*.slog;*.log|RECURSE
FileKey3=%CommonAppData%\SiSense\Logs|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\SiSense|*.slog;*.log|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\SiSense\Logs|*.*|RECURSE
[SketchUp Make *]
LangSecRef=3021
Detect=HKCU\Software\SketchUp
Default=False
FileKey1=%AppData%\SketchUp\SketchUp *\SketchUp|~*.tmp
RegKey1=HKCU\Software\SketchUp\SketchUp 2013\Recent File List
RegKey2=HKCU\Software\SketchUp\SketchUp 2014\Recent File List
RegKey3=HKCU\Software\SketchUp\SketchUp 2015\Recent File List
RegKey4=HKCU\Software\SketchUp\SketchUp 2016\Recent File List
[SKSE *]
Section=Games
DetectFile=%Documents%\My Games\Skyrim\SKSE
Default=False
FileKey1=%Documents%\My Games\Skyrim\SKSE|*.log
[SkyDrive App *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.microsoftskydrive_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\microsoft.microsoftskydrive_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\PRICache|*.*
FileKey6=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\microsoft.microsoftskydrive_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.microsoftskydrive_8wekyb3d8bbwe\PersistedPickerData\microsoft.microsoftskydrive_8wekyb3d8bbwe!Microsoft.MicrosoftSkyDrive\DefaultOpenFileMultiple|LastLocation
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.microsoftskydrive_8wekyb3d8bbwe\SearchHistory
[Skype *]
LangSecRef=3022
Detect=HKCU\Software\Skype
DetectFile=%ProgramFiles%\Skype For Salesforce
Default=False
FileKey1=%AppData%\Skype|*.tmp;*.db-journal;*.lck;*.lock;cookies.dat|RECURSE
FileKey2=%AppData%\Skype\*\*cache|*.*|RECURSE
FileKey3=%AppData%\Skype\*\httpfe|*.*
FileKey4=%AppData%\Skype\*\logs|*.*
FileKey5=%AppData%\Skype\*\media_messaging\*\asyncdb\tmp|*.*
FileKey6=%AppData%\Skype\*\media_messaging\media_cache*|*.*
FileKey7=%AppData%\Skype\*\qikdb\tmp|*.*
FileKey8=%AppData%\Skype\DataRv|*.*
FileKey9=%AppData%\Skype\DbTemp|*.*|RECURSE
FileKey10=%AppData%\SkypePM|*.ezlog
FileKey11=%CommonAppData%\Skype|SkypeToolbars.msi;Skype.msi|RECURSE
FileKey12=%UserProfile%\Tracing\WPPMedia|*.*|RECURSE
[Skype Messages *]
LangSecRef=3022
Detect=HKCU\Software\Skype
Default=False
Warning=This will delete your chat message history!
FileKey1=%AppData%\Skype|offline-storage.data;dc.db|RECURSE
FileKey2=%AppData%\Skype\*\chatsync|*.*|RECURSE
[Skype Metro *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.SkypeApp_kzf8qxf38zg5c
DetectFile=%LocalAppData%\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.SkypeApp_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.SkypeApp_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.SkypeApp_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.SkypeApp_*\LocalState|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.SkypeApp_*\TempState|*.*|RECURSE
[SkypeAlyzer *]
LangSecRef=3024
Detect=HKCU\Software\Raize\CodeSite
Default=False
FileKey1=%LocalAppData%\Raize\CodeSite\5.0|CSDispatcherLog.txt
[Sleeping Dogs *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\202170
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\SleepingDogs|LogBoot.txt;LogShaders.txt
FileKey2=%ProgramFiles%\Steam\Steamapps\common\SleepingDogs|LogBoot.txt;LogShaders.txt
[SlimBoat *]
LangSecRef=3022
DetectFile=%ProgramFiles%\SlimBoat\SlimBoat.exe
Default=False
FileKey1=%LocalAppData%\FlashPeak\SlimBoat\cache|*.*|RECURSE
FileKey2=%LocalAppData%\FlashPeak\SlimBoat\cookies|*.*|RECURSE
FileKey3=%LocalAppData%\FlashPeak\SlimBoat\history|*.*|RECURSE
FileKey4=%LocalAppData%\FlashPeak\SlimBoat\iconcache|*.*|RECURSE
FileKey5=%LocalAppData%\FlashPeak\SlimBoat\LocalStorage|*.*|RECURSE
[SlimBrowser *]
LangSecRef=3022
Detect=HKCU\Software\FlashPeak\SlimBrowser
DetectFile=%ProgramFiles%\SlimBrowser\sbframe.exe
Default=False
FileKey1=%AppData%\SlimBrowser|freqsite.txt;RecentCloseW.ini;freqform.txt
FileKey2=%AppData%\SlimBrowser\iconcache|*.*|RECURSE
[SlimCleaner *]
LangSecRef=3024
Detect1=HKCU\Software\SlimWare Utilities Inc\SlimCleaner
Detect2=HKCU\Software\SlimWare Utilities Inc\SlimCleaner Plus
Default=False
FileKey1=%CommonAppData%\SlimWare Utilities Inc\Services\SlimService*\Logs|*.log
FileKey2=%LocalAppData%\SlimWare Utilities Inc\SlimCleaner*\Cache|*.*|RECURSE
FileKey3=%LocalAppData%\SlimWare Utilities Inc\SlimCleaner*\Logs|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\SlimCleaner*|*.txt
FileKey5=%LocalAppData%\VirtualStore\ProgramData\SlimWare Utilities Inc\Services\SlimService*\Logs|*.log
FileKey6=%ProgramFiles%\SlimCleaner*|*.txt
[SlimComputer *]
LangSecRef=3024
DetectFile=%LocalAppData%\SlimWare Utilities Inc\SlimComputer
Default=False
FileKey1=%LocalAppData%\SlimWare Utilities Inc\SlimComputer\Logs|*.log
[SlimDrivers *]
LangSecRef=3024
Detect=HKCU\Software\SlimWare Utilities Inc\SlimDrivers
Default=False
FileKey1=%LocalAppData%\SlimWare Utilities Inc\SlimDrivers\Logs|*.*|RECURSE
[SlimDrivers Backups *]
LangSecRef=3024
Detect=HKCU\Software\SlimWare Utilities Inc\SlimDrivers
Default=False
FileKey1=%LocalAppData%\SlimWare Utilities Inc\SlimDrivers\Backups|*.*|RECURSE
[SlimDrivers Downloads *]
LangSecRef=3024
Detect=HKCU\Software\SlimWare Utilities Inc\SlimDrivers
Default=False
FileKey1=%LocalAppData%\SlimWare Utilities Inc\SlimDrivers\Downloads|*.*|RECURSE
FileKey2=%LocalAppData%\SlimWare Utilities Inc\SlimDrivers\Images|*.*|RECURSE
[Smart Explorer *]
LangSecRef=3021
Detect=HKCU\Software\Smartque\Smart Explorer
Default=False
RegKey1=HKCU\Software\Smartque\Smart Explorer\Opened Pages
RegKey2=HKCU\Software\Smartque\Smart Explorer\Recent Pages
[Smart Installer Maker *]
LangSecRef=3024
Detect=HKCU\Software\InstallBuilders\Smart Install Maker
Default=False
RegKey1=HKCU\Software\InstallBuilders\Smart Install Maker\Reopen
[Smart PDF Creator Pro *]
LangSecRef=3024
DetectFile=%AppData%\Smart PDF Creator Pro
Default=False
FileKey1=%AppData%\Smart PDF Creator Pro|Smart PDF Creator Pro_log*.*
[Smileys We Love Toolbar for IE *]
LangSecRef=3022
Detect=HKCU\Software\SmileysWeLove
DetectFile=%ProgramFiles%\SqueekyChocolate, LLC\Smileys We Love Toolbar for IE\adxregistrator.exe
Default=False
FileKey1=%Documents%\Add-in Express|adxregistrator.log
[SMPlayer File Settings *]
LangSecRef=3023
Detect=HKCR\Applications\smplayer.exe
DetectFile=%LocalAppData%\SMPlayer2
Default=False
FileKey1=%LocalAppData%\SMPlayer2\File_settings|*.*|RECURSE
FileKey2=%UserProfile%\.smplayer\file_settings|*.*|RECURSE
[SMPlayer Screenshots *]
LangSecRef=3023
Detect=HKCR\Applications\smplayer.exe
DetectFile=%LocalAppData%\SMPlayer2
Default=False
FileKey1=%LocalAppData%\SMPlayer2\screenshots|*.*|RECURSE
FileKey2=%Pictures%\smplayer*_screenshots|*.*|RECURSE
FileKey3=%UserProfile%\.smplayer\screenshots|*.*|RECURSE
[Snagit *]
LangSecRef=3021
Detect=HKCU\Software\TechSmith\Snagit
Default=False
Warning=This will delete the backups of the captures.
FileKey1=%CommonAppData%\TechSmith\Uploader|*.log
FileKey2=%Documents%|SnagitDebug.log
FileKey3=%LocalAppData%\TechSmith\Logs|*.log
FileKey4=%LocalAppData%\TechSmith\Snagit|Tray.bin
FileKey5=%LocalAppData%\TechSmith\Snagit\CrashDumps|*.*|RECURSE
FileKey6=%LocalAppData%\TechSmith\Snagit\DataStore|*.SNAG;*.SNAGundo;*.MP4
FileKey7=%LocalAppData%\TechSmith\Snagit\DataStore\AppIcons|*.ico
FileKey8=%LocalAppData%\TechSmith\Snagit\DataStore\WebSiteIcons|*.ico
FileKey9=%LocalAppData%\TechSmith\Snagit\Thumbnails|*.*|RECURSE
FileKey10=%LocalAppData%\TechSmith\Snagit\TrackerbirdFiles|*.log
RegKey1=HKCU\Software\TechSmith\Snagit\9|StampCustomFolder
RegKey2=HKCU\Software\TechSmith\Snagit\10|StampCustomFolder
RegKey3=HKCU\Software\TechSmith\Snagit\11|CaptureCount
RegKey4=HKCU\Software\TechSmith\Snagit\11|CaptureOpenCount
RegKey5=HKCU\Software\TechSmith\Snagit\12|CaptureCount
RegKey6=HKCU\Software\TechSmith\Snagit\12|CaptureOpenCount
RegKey7=HKCU\Software\TechSmith\Snagit\13|CaptureCount
RegKey8=HKCU\Software\TechSmith\Snagit\13|CaptureOpenCount
RegKey9=HKCU\Software\TechSmith\Snagit\13\Recent Captures
RegKey10=HKCU\Software\TechSmith\Snagit\13\SnagitEditor\Recent File List
RegKey11=HKCU\Software\TechSmith\Snagit\18|CaptureCount
RegKey12=HKCU\Software\TechSmith\Snagit\18|CaptureOpenCount
RegKey13=HKCU\Software\TechSmith\Snagit\18\Recent Captures
RegKey14=HKCU\Software\TechSmith\Snagit\18\SnagitEditor\Recent File List
RegKey15=HKCU\Software\TechSmith\Snagit\Stamps|StampCustomFolder
[Snapfish Picture Mover *]
LangSecRef=3023
DetectFile=%AppData%\PictureMover
Default=False
FileKey1=%AppData%\PictureMover\Log|*.*
[Snip & Sketch *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ScreenSketch_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\AC\Temp|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\LocalCache\Cache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\LocalState\Cache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.ScreenSketch_*\TempState|*.*|RECURSE
[Sniper Art of Victory *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\271500
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Sniper Art of Victory\logs|*.*
FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Sniper Art of Victory\logs|*.*
[Sniper: Ghost Warrior *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\34830
Default=False
FileKey1=%Documents%\Sniper - Ghost Warrior\out\logs|*.*
[Snuggle Truck *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\111100
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\snuggle truck\Snuggle Truck_Data|output_log.txt
FileKey2=%ProgramFiles%\Steam\steamapps\common\snuggle truck\Snuggle Truck_Data|output_log.txt
[Sobees *]
LangSecRef=3022
DetectFile=%AppData%\sobees Ltd\Sobees
Default=False
FileKey1=%AppData%\sobees Ltd\Sobees\tmp\imagecache|*.*|RECURSE
[SocialFolders *]
LangSecRef=3022
DetectFile=%LocalAppData%\ftopia\SocialFolders
Default=False
FileKey1=%LocalAppData%\ftopia\SocialFolders\Cache|*.*|RECURSE
FileKey2=%LocalAppData%\ftopia\SocialFolders\Dumps|*.*|RECURSE
[Soda Player *]
LangSecRef=3023
DetectFile=%LocalAppData%\sodaplayer
Default=False
FileKey1=%AppData%\Soda Player|Cookies*
FileKey2=%AppData%\Soda Player\*Cache|*.*
FileKey3=%AppData%\Soda Player\acestream\engine|*.log
FileKey4=%AppData%\Soda Player\Local Storage|*.*
FileKey5=%LocalAppData%\sodaplayer|SquirrelSetup.log
FileKey6=%SystemDrive%\_acestream_cache_|*.*|REMOVESELF
[SoftCafe MenuPRo *]
LangSecRef=3021
DetectFile=%AppData%\SoftCafe\MenuPro
Default=False
FileKey1=%AppData%\SoftCafe\MenuPro|*.tmp
[SoftEther VPN *]
LangSecRef=3024
Detect=HKCU\Software\SoftEther Project\SoftEther VPN
Default=False
Warning=Exclude installer.cache if you're using SoftEther VPN Client Web Installer.
FileKey1=%ProgramFiles%\SoftEther VPN Client|installer.cache
FileKey2=%ProgramFiles%\SoftEther VPN Client\backup.vpn_client.config|*.config
FileKey3=%ProgramFiles%\SoftEther VPN Client\client_log|*.*
FileKey4=%ProgramFiles%\SoftEther VPN Client\vpn_debug|*.*
[SoftGrid Client *]
LangSecRef=3022
DetectFile=%AppData%\SoftGrid Client
Default=False
FileKey1=%AppData%\SoftGrid Client|*.tmp|RECURSE
FileKey2=%AppData%\SoftGrid Client\Icon Cache|*.*
FileKey3=%CommonAppData%\Microsoft\Application Virtualization Client\SoftGrid Client|*.tmp|RECURSE
FileKey4=%LocalAppData%\SoftGrid Client|*.tmp|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Application Virtualization Client\SoftGrid Client|*.tmp|RECURSE
[Softonic *]
LangSecRef=3021
DetectFile=%LocalAppData%\Softonic\Softonic.exe
Default=False
FileKey1=%LocalAppData%\Softonic\cache|*.*|RECURSE
[SoftThinks CD Creator *]
LangSecRef=3021
Detect=HKLM\Software\SoftThinks
Default=False
FileKey1=%WinDir%\CREATOR|*.log
[Software Informer *]
LangSecRef=3023
DetectFile=%AppData%\Software Informer
Default=False
FileKey1=%AppData%\Software Informer\cache\icons|*.tmp
[Solarix *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\284990
Default=False
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Solarix\UDKGame\Logs|*.*
[Sonata *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Sonata
Default=False
FileKey1=%LocalAppData%\Sonata\temp|*.*|RECURSE
FileKey2=%ProgramFiles%\Sonata\update|*.*|RECURSE
[SongKong *]
LangSecRef=3023
DetectFile=%AppData%\SongKong
Default=False
FileKey1=%AppData%\SongKong\Logs|*.*|RECURSE
[Sonic Visualiser *]
LangSecRef=3023
Detect=HKCU\Software\sonic-visualiser
DetectFile=%UserProfile%\.Sonic Visualiser
Default=False
FileKey1=%UserProfile%\.Sonic Visualiser\cache|*.*
RegKey1=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-0
RegKey2=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-1
RegKey3=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-2
RegKey4=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-3
RegKey5=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-4
RegKey6=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-5
RegKey7=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-6
RegKey8=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-7
RegKey9=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-8
RegKey10=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-9
RegKey11=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-10
RegKey12=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-11
RegKey13=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-12
RegKey14=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-13
RegKey15=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-14
RegKey16=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-15
RegKey17=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-16
RegKey18=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-17
RegKey19=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-18
RegKey20=HKCU\Software\sonic-visualiser\Sonic Visualiser\RecentFiles|recent-19
[Sonique *]
LangSecRef=3023
Detect=HKCU\Software\MediaScience\Sonique
Default=False
RegKey1=HKCU\Software\MediaScience\Sonique\Play_History
RegKey2=HKCU\Software\MediaScience\Sonique\URL_History
[Sony Magic Update *]
LangSecRef=3024
DetectFile=%AppData%\Sony Corporation\Auto Magic Update Client
Default=False
FileKey1=%AppData%\Sony Corporation\Auto Magic Update Client|*.log
[Sony Media Go *]
LangSecRef=3021
Detect=HKCU\Software\Sony Corporation\Media Go
Default=False
FileKey1=%AppData%\Sony\Media Go|*.bkd
[Sony Media Manager *]
LangSecRef=3023
DetectFile=%AppData%\Sony\Media Manager
Default=False
FileKey1=%AppData%\Sony\Media Manager|*.log;*log.txt
FileKey2=%AppData%\Sony\Media Manager\Thumbnails|*.*|RECURSE
[Sony SonicStage *]
LangSecRef=3021
DetectFile=%AppData%\Sony\SonicStage
Default=False
FileKey1=%AppData%\Sony\SonicStage|*.log
FileKey2=%AppData%\Sony\SonicStage\Temp|*.*
[Sony Sound Organizer *]
LangSecRef=3024
DetectFile=%AppData%\Sony Corporation\Sound Organizer
Default=False
FileKey1=%AppData%\Sony Corporation\Sound Organizer|*.log
[Sony Vegas Pro *]
LangSecRef=3023
Detect1=HKLM\Software\Sony Creative Software\Vegas
Detect2=HKLM\Software\Sony Media Software\Vegas
Default=False
FileKey1=%AppData%\Sony|*.log
FileKey2=%LocalAppData%\Sony\Vegas Pro\*|*.log
[Sorcery! Parts 1 And 2 *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\105430
Default=False
FileKey1=%LocalAppData%\inkle\Sorcery|*.log
[Soulseek *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Soulseek\slsk.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Soulseek*|search.cfg
FileKey2=%ProgramFiles%\Soulseek*|search.cfg
[Soulseek NS *]
LangSecRef=3022
Detect=HKCU\Software\Soulseek2
Default=False
Warning=This will delete your chat history.
FileKey1=%Documents%\Soulseek Chat Logs\Private|*.txt
RegKey1=HKCU\Software\Soulseek2\config|search
[SoulseekQt *]
LangSecRef=3022
Detect=HKLM\Software\SoulseekQt
DetectFile=%ProgramFiles%\SoulseekQt\SoulseekQt.exe
Default=False
Warning=This will delete your chat history.
FileKey1=%LocalAppData%\Soulseek Chat Logs\*|*.log
[Sound Recorder *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsSoundRecorder_*\TempState|*.*|RECURSE
[SoundMAX *]
LangSecRef=3023
DetectFile=%ProgramFiles%\Analog Devices\SoundMAX
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Analog Devices\SoundMAX|SMax.log;SMax.log.bak
FileKey2=%ProgramFiles%\Analog Devices\SoundMAX|SMax.log;SMax.log.bak
[SpaceEngineers *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\244850
Default=False
FileKey1=%AppData%\SpaceEngineers|*.log
[SpeedFan *]
LangSecRef=3024
Detect=HKCU\Software\SpeedFan
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\SpeedFan|debug.nfo;SFLog*.csv
FileKey2=%ProgramFiles%\SpeedFan|debug.nfo;SFLog*.csv
[SpeedRunners *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\207140
Default=False
FileKey1=%AppData%|SpeedRunnersLog.txt;TargetInvocationLog.txt
[SpeedyComputer *]
LangSecRef=3024
DetectFile=%AppData%\SpeedyComputer
Default=False
FileKey1=%AppData%\SpeedyComputer\Log|*.*|RECURSE
[SpiderOak *]
LangSecRef=3024
DetectFile=%AppData%\SpiderOak
Default=False
FileKey1=%AppData%\SpiderOak|*.log|RECURSE
FileKey2=%AppData%\SpiderOak\download_cache|*.*
[Spiral Knights *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\99900
Default=False
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Spiral Knights|*.log
[Splice *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\209790
Default=False
FileKey1=%Documents%|GALog.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\splice|output_log.txt
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Splice\Splice_Data|output_log.txt
FileKey4=%ProgramFiles%\Steam\steamapps\common\splice|output_log.txt
FileKey5=%ProgramFiles%\Steam\steamapps\common\Splice\Splice_Data|output_log.txt
[SpongeBob Diner Dash *]
Section=Games
DetectFile=%ProgramFiles%\SpongeBob Diner Dash
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\SpongeBob Diner Dash|logfile.*
FileKey2=%ProgramFiles%\SpongeBob Diner Dash|logfile.*
[Spooky Mall *]
Section=Games
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spooky Mall1.0
Default=False
FileKey1=%CommonAppData%\SpookyMall|*.xml_log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Foxy Games\Spooky Mall|*.log
FileKey3=%LocalAppData%\VirtualStore\ProgramData\SpookyMall|*.xml_log
FileKey4=%ProgramFiles%\Foxy Games\Spooky Mall|*.log
[SporTV *]
LangSecRef=3021
DetectFile=%LocalAppData%\SporTV
Default=False
FileKey1=%LocalAppData%\SporTV\Logs|*.*
[Spotflux *]
LangSecRef=3021
Detect=HKLM\Software\Spotflux
DetectFile=%ProgramFiles%\Spotflux\spotflux.exe
Default=False
FileKey1=%AppData%\.spotflux|*.log
[Spotify *]
LangSecRef=3023
DetectFile=%LocalAppData%\Spotify
Default=False
FileKey1=%LocalAppData%\Spotify\Browser|*.*|RECURSE
FileKey2=%LocalAppData%\Spotify\Storage|*.*|RECURSE
[Spoutcraft *]
Section=Games
DetectFile=%AppData%\.spoutcraft
Default=False
FileKey1=%AppData%\.spoutcraft|*.log
FileKey2=%AppData%\.spoutcraft\logs|*.*
[Sprint Hero RUU Installer *]
LangSecRef=3023
DetectFile=%SystemDrive%\ruu_log
Default=False
FileKey1=%SystemDrive%\ruu_log|*.*|REMOVESELF
[Spybot Search and Destroy 2 *]
LangSecRef=3024
Detect=HKCU\Software\Safer Networking Limited\Spybot - Search & Destroy 2
Default=False
FileKey1=%CommonAppData%\Spybot - Search & Destroy\Logs|*.*|RECURSE
FileKey2=%CommonAppData%\Spybot - Search & Destroy\System Configuration Snapshots|*.*|REMOVESELF
FileKey3=%Documents%\ProcAlyzer Dumps|*.*|REMOVESELF
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Spybot - Search & Destroy\Logs|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Spybot - Search & Destroy\System Configuration Snapshots|*.*|REMOVESELF
[Spybot Search and Destroy History *]
LangSecRef=3024
Detect=HKLM\Software\Safer Networking Limited\SpybotSnD
Default=False
FileKey1=%CommonAppData%\Spybot Search & Destroy\Backups|*.*|RECURSE
FileKey2=%CommonAppData%\Spybot Search & Destroy\Recovery|*.*|RECURSE
FileKey3=%CommonAppData%\Spybot Search & Destroy\Snapshots*|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Spybot Search & Destroy\Backups|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Spybot Search & Destroy\Recovery|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Spybot Search & Destroy\Snapshots*|*.*|RECURSE
[Spybot Search and Destroy Hosts Backups *]
LangSecRef=3024
Detect1=HKCU\Software\Safer Networking Limited\Spybot - Search & Destroy 2
Detect2=HKLM\Software\Safer Networking Limited\SpybotSnD
Default=False
FileKey1=%WinDir%\System32\drivers\etc|hosts.*.backup
[Spybot Search and Destroy Updates *]
LangSecRef=3024
Detect1=HKCU\Software\Safer Networking Limited\Spybot - Search & Destroy 2
Detect2=HKLM\Software\Safer Networking Limited\SpybotSnD
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Spybot - Search & Destroy 2\Updates|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Spybot - Search & Destroy\Updates|*.zip
FileKey3=%ProgramFiles%\Spybot - Search & Destroy 2\Updates|*.*|RECURSE
FileKey4=%ProgramFiles%\Spybot - Search & Destroy\Updates|*.zip
ExcludeKey1=FILE|%ProgramFiles%\Spybot - Search & Destroy 2\Updates\Downloads\|updates.uid
[SpyDefense *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Everest Labs\Spydefense\sdc.exe
Default=False
FileKey1=%AppData%\Everest Labs\Spydefense|SpyDefense.log;History.ini;Backups.ini
FileKey2=%AppData%\Everest Labs\Spydefense\Backups|BF7.tmp
[Spyware Doctor *]
LangSecRef=3024
Detect=HKCU\Software\PCTools\Spyware Doctor
Default=False
FileKey1=%AppData%\pctsGui|bugreport.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Spyware Doctor\Log|*.*
FileKey3=%ProgramFiles%\Spyware Doctor\Log|*.*
[Spyware Terminator *]
LangSecRef=3024
Detect=HKCU\Software\Spyware Terminator
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Spyware Terminator|*.err;*.old|RECURSE
FileKey2=%ProgramFiles%\Spyware Terminator|*.err;*.old|RECURSE
[SpywareBlaster Update File *]
LangSecRef=3024
DetectFile=%ProgramFiles%\SpywareBlaster\sbautoupdate.exe
Default=False
Warning=This deletes SWB program updater file, which is no longer needed once a SWB program version update occurs.
FileKey1=%ProgramFiles%\SpywareBlaster|spywareblasterupgrade_latest.exe
[SQL Anywhere 11 *]
LangSecRef=3021
DetectFile=%CommonAppData%\SQL Anywhere 11
Default=False
FileKey1=%CommonAppData%\SQL Anywhere 11\Diagnostics|*.dmp;*.crash_log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\SQL Anywhere 11\Diagnostics|*.dmp;*.crash_log
[SQLite Expert 3 *]
LangSecRef=3024
Detect1=HKCU\Software\SQLite Expert\Personal\3.x
Detect2=HKCU\Software\SQLite Expert\Professional\3.x
Default=False
RegKey1=HKCU\Software\SQLite Expert\Personal\3.x\DB
RegKey2=HKCU\Software\SQLite Expert\Professional\3.x\DB
[SQLite Query *]
LangSecRef=3024
DetectFile=%AppData%\MiTeC\SQLite Query
Default=False
FileKey1=%AppData%\MiTeC\SQLite Query|*.*|REMOVESELF
[SSD Fresh *]
LangSecRef=3024
DetectFile=%LocalAppData%\Abelssoft\SSD Fresh
Default=False
FileKey1=%LocalAppData%\Abelssoft\SSD Fresh|backup.*
[Star Downloader *]
LangSecRef=3021
Detect=HKCU\Software\Star Downloader
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Star Downloader|serverstats.txt;LastURLs
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Star Downloader\Partial Downloads|*.*|RECURSE
FileKey3=%ProgramFiles%\Star Downloader|serverstats.txt;LastURLs
FileKey4=%ProgramFiles%\Star Downloader\Partial Downloads|*.*|RECURSE
[Star Swarm Stress Test *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\267130
Default=False
FileKey1=%Documents%\Star Swarm|output*.txt
[Star Trek Online *]
Section=Games
Detect1=HKCU\Software\Cryptic\Star Trek Online
Detect2=HKCU\Software\Valve\Steam\Apps\9900
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\Common\star trek online\Star Trek Online\*\cache|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\steam\steamapps\common\star trek online\star trek online\*\logs\GameClient|*.*
FileKey3=%ProgramFiles%\Steam\Steamapps\Common\star trek online\Star Trek Online\*\cache|*.*
FileKey4=%ProgramFiles%\steam\steamapps\common\star trek online\star trek online\*\logs\GameClient|*.*
FileKey5=%Public%\Games\Cryptic Studios\Star Trek Online\*\Cache|*.*
FileKey6=%Public%\Games\Cryptic Studios\Star Trek Online\*\Logs\GameClient|*.*
[Star Wars Battlefront II *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\6060
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Star Wars BattleFront II|update*.txt
FileKey2=%ProgramFiles%\Steam\SteamApps\Common\Star Wars BattleFront II|update*.txt
[Star Wars The Force Unleashed *]
Section=Games
DetectFile=%LocalAppData%\LucasArts\Star Wars The Force Unleashed*
Default=False
FileKey1=%LocalAppData%\LucasArts\Star Wars The Force Unleashed*|*.*
[Star Wars: The Old Republic *]
Section=Games
Detect=HKLM\Software\BioWare\Star Wars-The Old Republic
Default=False
FileKey1=%Documents%|*Install STAR WARS The Old Republic.log
FileKey2=%LocalAppData%\SWTOR\CrashDump\swtor|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Electronic Arts\BioWare\Star Wars-The Old Republic\betatest\retailclient\Temp|*.log
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Electronic Arts\BioWare\Star Wars-The Old Republic\logs|*.log
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Electronic Arts\BioWare\Star Wars-The Old Republic\swtor\retailclient\swtor\logs|*.log
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Star Wars - The Old Republic\__Installer|InstallLog.txt
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Star Wars - The Old Republic\logs|*.*
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Origin Games\Star Wars - The Old Republic\swtor\retailclient\swtor\logs|*.*
FileKey9=%ProgramFiles%\Electronic Arts\BioWare\Star Wars-The Old Republic\betatest\retailclient\Temp|*.log
FileKey10=%ProgramFiles%\Electronic Arts\BioWare\Star Wars-The Old Republic\logs|*.log
FileKey11=%ProgramFiles%\Electronic Arts\BioWare\Star Wars-The Old Republic\swtor\retailclient\swtor\logs|*.log
FileKey12=%ProgramFiles%\Origin Games\Star Wars - The Old Republic\__Installer|InstallLog.txt
FileKey13=%ProgramFiles%\Origin Games\Star Wars - The Old Republic\logs|*.*
FileKey14=%ProgramFiles%\Origin Games\Star Wars - The Old Republic\swtor\retailclient\swtor\logs|*.*
[StarCraft II *]
Section=Games
Detect=HKLM\Software\Blizzard Entertainment\StarCraft II
Default=False
FileKey1=%CommonAppData%\Blizzard Entertainment\Starcraft II\Maps\Cache|*.*|RECURSE
FileKey2=%Documents%\StarCraft II\*Logs|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Starcraft II\Logs|*.*
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Blizzard Entertainment\Starcraft II\Maps\Cache|*.*|RECURSE
FileKey5=%ProgramFiles%\Starcraft II\Logs|*.*
[StarCraft II Editor *]
Section=Games
Detect=HKLM\Software\Blizzard Entertainment\StarCraft II Editor
Default=False
RegKey1=HKCU\Software\Blizzard Entertainment\StarCraft II Editor\Recent Files
[Stardock Fences *]
LangSecRef=3024
Detect1=HKLM\Software\Stardock\Misc\Fences
Detect2=HKLM\Software\Stardock\Misc\Fences2
Default=False
FileKey1=%AppData%\Stardock\Fences\TroubleshootingLog|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Stardock\Fences|*.txt
FileKey3=%ProgramFiles%\Stardock\Fences|*.txt
[Stardock ObjectDock Plus *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Stardock\ObjectDock Plus\ObjectDock.exe
Default=False
FileKey1=%AppData%\Stardock|*.*|REMOVESELF
FileKey2=%CommonAppData%\Stardock|*.*|RECURSE
FileKey3=%LocalAppData%\ODUI|*.*|REMOVESELF
FileKey4=%LocalAppData%\Stardock\ObjectDockPlus|*Backup.ini
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Stardock|*.*|RECURSE
[StarMoney *]
LangSecRef=3021
DetectFile=%CommonAppData%\StarMoney*
Default=False
FileKey1=%CommonAppData%\StarMoney *|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\StarMoney *|*.log|RECURSE
[StarOffice *]
LangSecRef=3021
DetectFile1=%ProgramFiles%\Sun\StarOffice 8\program\soffice.exe
DetectFile2=%ProgramFiles%\Sun\StarOffice 9\program\soffice.exe
Default=False
FileKey1=%AppData%\StarOffice*\user\registry\data\org\openoffice\Office|Common.xcu
[Start Menu Cache *]
DetectOS=6.2|
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\UFH
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\UFH\SHC
RegKey2=HKLM\Software\Microsoft\Windows\CurrentVersion\UFH\ARP
[Start Menu Reviver *]
LangSecRef=3024
Detect=HKLM\Software\Start Menu Reviver
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\ReviverSoft\Start Menu Reviver\Logs|*.*
FileKey2=%ProgramFiles%\ReviverSoft\Start Menu Reviver\Logs|*.*
[StartMenu8 *]
LangSecRef=3024
Detect=HKLM\Software\IObit\StartMenu
Default=False
FileKey1=%AppData%\IObit\StartMenu 8|*.log
[Startup Sentinel *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\Startup Sentinel
Default=False
FileKey1=%AppData%\KC Softwares\Startup Sentinel|*.log
[StartupStar *]
LangSecRef=3024
DetectFile=%LocalAppData%\Abelssoft\StartupStar
Default=False
FileKey1=%AppData%\AbelsSoft\StartupStar|*.log
[StartupStar Backups *]
LangSecRef=3024
DetectFile=%LocalAppData%\Abelssoft\StartupStar
Default=False
FileKey1=%LocalAppData%\Abelssoft\StartupStar|backup.xml
[Steam *]
Section=Games
Detect=HKCU\Software\Valve\Steam
Default=False
FileKey1=%AppData%\SteamVR\Logs|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam|*.log;*log.last;connection_log_*.txt;*_log.txt;remote_connections.txt;vr*_*.txt|RECURSE
FileKey3=%ProgramFiles%\Steam|*.log;*log.last;connection_log_*.txt;*_log.txt;remote_connections.txt;vr*_*.txt|RECURSE
FileKey4=%ProgramFiles%\Steam|*.old
FileKey5=%ProgramFiles%\Steam\vr\runtime\logs|*.*|RECURSE
[Steam Caches *]
Section=Games
Detect=HKCU\Software\Valve\Steam
Default=False
FileKey1=%LocalAppData%\Steam\htmlcache|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\appcache\httpcache|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\config\cookies|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Steam\config\htmlcache|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Steam\config\overlay*|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Steam\depotcache|*.*
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\shadercache|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Steam\tenfoot\config\httpcache|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Steam\tenfoot\config\images\web|*.*|RECURSE
FileKey10=%ProgramFiles%\Steam\appcache\httpcache|*.*|RECURSE
FileKey11=%ProgramFiles%\Steam\config\cookies|*.*|RECURSE
FileKey12=%ProgramFiles%\Steam\config\htmlcache|*.*|RECURSE
FileKey13=%ProgramFiles%\Steam\config\overlay*|*.*|RECURSE
FileKey14=%ProgramFiles%\Steam\depotcache|*.*
FileKey15=%ProgramFiles%\Steam\steamapps\shadercache|*.*|RECURSE
FileKey16=%ProgramFiles%\Steam\tenfoot\config\httpcache|*.*|RECURSE
FileKey17=%ProgramFiles%\Steam\tenfoot\config\images\web|*.*|RECURSE
FileKey18=%ProgramFiles%\Steam\userdata\*\ugcmsgcache|*.*|RECURSE
[Steam Games *]
Section=Games
Detect=HKCU\Software\Valve\Steam
Default=False
FileKey1=%ProgramFiles%\Steam\steamapps|*.mdmp;*.tmp;*.dmp;*.icns;.DS_Store;logfile.*;*.log;text.txt;*log.txt;log*.txt|RECURSE
FileKey2=%ProgramFiles%\Steam\steamapps\common\*\*\downloads|*.*|RECURSE
FileKey3=%ProgramFiles%\Steam\steamapps\common\*\Cache|*.*|RECURSE
FileKey4=%ProgramFiles%\Steam\steamapps\common\*\config\html|*.*|RECURSE
FileKey5=%ProgramFiles%\Steam\steamapps\common\*\DebugData|*.*|RECURSE
FileKey6=%ProgramFiles%\Steam\Steamapps\temp|*.*|RECURSE
ExcludeKey1=PATH|%ProgramFiles%\Steam\steamapps\common\Supreme Ruler 1936\Cache\|*.*
ExcludeKey2=PATH|%ProgramFiles%\Steam\steamapps\common\Supreme Ruler Cold War\Cache\|*.*
ExcludeKey3=PATH|%ProgramFiles%\Steam\steamapps\common\Supreme Ruler Ultimate\Cache\|*.*
[Steam Installers *]
Section=Games
Detect=HKCU\Software\Valve\Steam
Default=False
Warning=This entry should only be enabled after you have launched each of your installed Steam games at least once. Deleting these files before then may cause Steam to think the game's installation is broken. After the first launch, these files become useless.
FileKey1=%ProgramFiles%\Steam\Steamapps\common|*redist.msi*;dosbox*.tar.gz;*redist*.exe;*setup*.msi;*pbsvc*.exe;*UPlay*Installer*.exe;WMFADist.exe;SPInstaller.exe;python*.msi;bitmap2substance_installer.exe;perforce*.exe;p4vinst*.exe;mcpp*.*;firewallinstallhelper.dll;gameuxinstallhelper.dll;eadm-installer.exe;wmpappcompat.exe;umdf.exe;Microsoft .NET Framework*.cmd;Microsoft .NET Framework*.bat;NDP*.exe;WMFDist*.exe;PhysX*.msi;PhysX*.exe;*d3dx11*.cat;*d3dx11*.inf;prompt.bat;GDFInstall.exe;DSInstaller.exe;d3d*.exe;directx*.exe;*.msu;Windows*-KB*.exe;cmp.bat;PVRTexTool.exe;wmp11-windowsxp-x86-enu.exe;*.vdk;RGB9RAST*.msi;WIC*.exe;XPSEPC*.exe;msxml6.msi;AdbeRdr*.*;*inst*.vdf;*.cab;*.msp;ac3filter*.exe;GamesExplorerIntegrationTool.exe;install.ini;globdata.ini;install.exe;install.res.*.dll;eula.*.*;DSETUP.DLL;oalinst.exe;dsetup32.dll;D3D*Install.exe;D3D*Install*.dll;dotnetfx*.exe;*vc*red*.exe;*vc*red.msi;WindowsInstaller*.exe;locdata.*.ini;setupres.*.dll;*setup*.exe;wapres.*.dll;*NetFx*.*|RECURSE
[Steam Packages *]
Section=Games
Detect=HKCU\Software\Valve\Steam
Default=False
Warning=Running this entry is not recommended if you run Steam Client Beta.
FileKey1=%ProgramFiles%\Steam\package|*.zip.*
[SteamWorld Dig *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\252410
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\SteamWorld Dig|*.mdmp
FileKey2=%ProgramFiles%\Steam\Steamapps\common\SteamWorld Dig|*.mdmp
[Steed *]
LangSecRef=3022
DetectFile=%CommonAppData%\Steed
Default=False
FileKey1=%CommonAppData%\Steed\Logs|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Steed\Logs|*.*|REMOVESELF
[Stellarium *]
LangSecRef=3021
DetectFile=%AppData%\Stellarium
Default=False
FileKey1=%AppData%\Stellarium|log.txt
FileKey2=%LocalAppData%\Stellarium\Cache|*.*|RECURSE
FileKey3=%LocalAppData%\stellarium\stellarium\cache|*.*|RECURSE
[StepMania *]
Section=Games
DetectFile=%AppData%\StepMania*
Default=False
FileKey1=%AppData%\Stepmania*\Logs|*.*
[Stocks and Futures *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\24877CutthroatSoftware.StocksandFutures_xgnzh3xnefnqe
Default=False
FileKey1=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey3=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\AC\Temp|*.*
FileKey4=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\AppData\Indexed DB|*.log
FileKey5=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\LocalState|*.tmp|RECURSE
FileKey6=%LocalAppData%\Packages\24877CutthroatSoftware.StocksandFutures_*\TempState|*.*|RECURSE
[STOIK Smart Resizer *]
LangSecRef=3023
Detect1=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer
Detect2=HKCU\Software\STOIK Smart Resizer 2.0\STOIK Smart Resizer
Detect3=HKCU\Software\STOIK Smart Resizer 3.0\STOIK Smart Resizer
Default=False
RegKey1=HKCU\Software\STOIK Smart Resizer 1.0\STOIK Smart Resizer\Recent File List
RegKey2=HKCU\Software\STOIK Smart Resizer 2.0\STOIK Smart Resizer\Recent File List
RegKey3=HKCU\Software\STOIK Smart Resizer 3.0\STOIK Smart Resizer\Recent File List
[STOIK Video Converter 2 *]
LangSecRef=3023
Detect=HKCU\Software\STOIK
Default=False
FileKey1=%AppData%\STOIK\videopak2|*.ini
[Store *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsStore_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsStore_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsStore_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsStore_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsStore_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsStore_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsStore_*\LocalState\Cache|*.*|RECURSE
[Stored Media Player Paths *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
RegKey1=HKCU\Software\Microsoft\Keyboard\Native Media Players
[Stored MIME Types *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
RegKey1=HKCU\Software\Classes\MIME\Database\Content Type
[Stored Qt Modules Paths *]
LangSecRef=3021
Detect=HKCU\Software\Trolltech
Default=False
RegKey1=HKCU\Software\Trolltech\OrganizationDefaults
[Stranglehold *]
Section=Games
DetectFile=%LocalAppData%\Midway\Stranglehold
Default=False
FileKey1=%LocalAppData%\Midway\Stranglehold|*.log|RECURSE
FileKey2=%LocalAppData%\Midway\Stranglehold\Cache|*.*|REMOVESELF
[Stream-Cloner *]
LangSecRef=3023
Detect=HKCU\Software\Stream-Cloner
Default=False
FileKey1=%AppData%\Stream-Cloner|*.log;IeRecentVisit.txt
FileKey2=%AppData%\Stream-Cloner\Cap_images|*.*|REMOVESELF
FileKey3=%AppData%\Stream-Cloner\thumbs|*.*|REMOVESELF
[Streamripper Winamp *]
LangSecRef=3023
Detect=HKCU\Software\Streamripper
Default=False
FileKey1=%AppData%\Streamripper|*.*|REMOVESELF
[Stronghold Crusader *]
Section=Games
DetectFile=%ProgramFiles%\Firefly Studios\Stronghold Crusader
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Firefly Studios\Stronghold Crusader\gfx|*log.txt
FileKey2=%ProgramFiles%\Firefly Studios\Stronghold Crusader\gfx|*log.txt
[Structured Storage Viewer *]
LangSecRef=3024
Detect=HKCU\Software\MiTeC\SSViewer
Default=False
RegKey1=HKCU\Software\MiTeC\SSViewer\3.x\wnd_re_Main|MRUHistory
[Style Jukebox *]
LangSecRef=3023
DetectFile=%AppData%\Style Jukebox Settings
Default=False
FileKey1=%AppData%\Style Jukebox Settings|*.bmp|RECURSE
[Sublime Text Backup *]
LangSecRef=3024
DetectFile=%AppData%\Sublime Text*
Default=False
FileKey1=%AppData%\Sublime Text 3\Backup|*.*|REMOVESELF
[Sublime Text Session *]
LangSecRef=3024
DetectFile=%AppData%\Sublime Text*
Default=False
FileKey1=%AppData%\Sublime Text 2\Settings|*.sublime_session
FileKey2=%AppData%\Sublime Text 3\Local|Session.sublime_session
FileKey3=%AppData%\Sublime Text\Options|*.*
[Success Story *]
Section=Games
DetectFile=%AppData%\Shape Games\SuccessStory
Default=False
FileKey1=%AppData%\Shape Games\SuccessStory\logs|*.*
[SumatraPDF *]
LangSecRef=3024
DetectFile=%AppData%\SumatraPDF
Default=False
FileKey1=%AppData%\SumatraPDF\sumatrapdfcache|*.*
[SUMo *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\SUMo
Default=False
FileKey1=%AppData%\KC Softwares\SUMo|db.bak;SUMo.cache;*.log;errlst.txt
[SUMo Database *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\SUMo
Default=False
FileKey1=%AppData%\KC Softwares\SUMo|db.sumo
[SUPERAntiSpyware *]
LangSecRef=3024
Detect1=HKCU\Software\SUPERAntiSpyware.com\SUPERAntiSpyware
Detect2=HKLM\Software\SUPERAntiSpyware.com\SUPERAntiSpyware
Default=False
FileKey1=%CommonAppData%\!SASCORE\AppLogs|*.dmp;*.SDB
FileKey2=%CommonAppData%\SUPERAntiSpyware.com\SUPERAntiSpyware\Applogs|*.dmp;*.SDB;*.ZIP
FileKey3=%LocalAppData%\VirtualStore\ProgramData\!SASCORE\AppLogs|*.dmp;*.SDB
FileKey4=%LocalAppData%\VirtualStore\ProgramData\SUPERAntiSpyware\Applogs|*.dmp;*.SDB;*.ZIP
FileKey5=%ProgramFiles%\SUPERAntiSpyware|*.tmp
[SuperMP3Download *]
LangSecRef=3023
DetectFile=%ProgramFiles%\SuperMp3Download\SuperMp3Download.exe
Default=False
FileKey1=%CommonAppData%\SuperMP3Download|downloadlist.sav
FileKey2=%CommonAppData%\SuperMP3Download\Downloading|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\SuperMP3Download|downloadlist.sav
FileKey4=%LocalAppData%\VirtualStore\ProgramData\SuperMP3Download\Downloading|*.*|RECURSE
[Superstar Racing *]
Section=Games
DetectFile=%LocalAppData%\Chat Republic Games\Superstar Racing
Default=False
FileKey1=%LocalAppData%\Chat Republic Games\Superstar Racing|log*.*
[SuperSync *]
LangSecRef=3023
DetectFile=%AppData%\SuperSync
Default=False
FileKey1=%AppData%\SuperSync\logs|*.*
FileKey2=%AppData%\SuperSync\tmp|*.*|RECURSE
[SuperWinMenu *]
LangSecRef=3024
DetectFile=%AppData%\SuperWinMenu
Default=False
FileKey1=%AppData%\SuperWinMenu|*.lastused
[Sway *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Office.Sway_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Office.Sway_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.Office.Sway_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Office.Sway_*\TempState|*.*|RECURSE
[Swift *]
LangSecRef=3022
Detect=HKCU\Software\Swift
Default=False
FileKey1=%AppData%\Swift\Avatars|*.*|RECURSE
FileKey2=%AppData%\Swift\Crashes|*.*|RECURSE
[Syberfix Helpdesk *]
LangSecRef=3021
DetectFile=%LocalAppData%\Syberfix\UserSaved\Helpdesk*
Default=False
FileKey1=%LocalAppData%\SyberFix\UserSaved\Helpdesk *|*.log
[Sylpheed *]
LangSecRef=3022
DetectFile=%AppData%\Sylpheed
Default=False
FileKey1=%AppData%\Sylpheed|*.bak;*.bak.*;*.log
[Symantec Ghost *]
LangSecRef=3024
Detect=HKCU\Software\Symantec\Symantec Ghost
Default=False
RegKey1=HKCU\Software\Symantec\Symantec Ghost\Explorer\Ghost Explorer\Recent File List
[Symantec SymSilent *]
LangSecRef=3024
DetectFile=%Public%\Symantec\SymSilent
Default=False
FileKey1=%Public%\Symantec\SymSilent\ccLog|*.*
[Synchronize It! *]
LangSecRef=3021
Detect=HKCU\Software\grigsoft.com\Synchronize It!
Default=False
RegKey1=HKCU\Software\grigsoft.com\Synchronize It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Synchronize It!\Synchronize It!\Combos
[Syncios Cell Phone Backup & Manage *]
LangSecRef=3024
Detect1=HKCU\Software\Syncios
Detect2=HKCU\Software\Syncios Data Transfer
Default=False
FileKey1=%AppData%\Syncios|android.log;log.txt
FileKey2=%AppData%\Syncios Data Transfer|*.log|RECURSE
FileKey3=%Documents%\Syncios Data Transfer|preference_conf.ini.old.bak
[Syncovery *]
LangSecRef=3024
Detect=HKCU\Software\Syncovery
Default=False
FileKey1=%CommonAppData%\Syncovery\Logs|*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Syncovery\Logs|*.log|RECURSE
[Syncthing *]
LangSecRef=3022
DetectFile=%LocalAppData%\Syncthing
Default=False
FileKey1=%LocalAppData%\Syncthing|*.log;*.xml.v*
FileKey2=%ProgramFiles%\Syncthing|*.old
[Synthesia *]
Section=Games
Detect=HKCU\Software\Classes\synthesia
Default=False
FileKey1=%AppData%\Synthesia|log.txt;log-configuration.txt
[System Explorer *]
LangSecRef=3024
DetectFile=%ProgramFiles%\System Explorer\SystemExplorer.exe
Default=False
FileKey1=%CommonAppData%\SystemExplorer\snapshots|*.ses
[System Mechanic *]
LangSecRef=3024
Detect=HKCU\Software\iolo\System Mechanic
Default=False
FileKey1=%AppData%\iolo\SafetyNet\Temp|*.*
FileKey2=%AppData%\ioloGovernor\logs|*.*|REMOVESELF
FileKey3=%CommonAppData%\iolo|*.xml;*.txt
FileKey4=%CommonAppData%\iolo\ACRSummaryFiles|*.*|REMOVESELF
FileKey5=%CommonAppData%\iolo\logs|*.*|REMOVESELF
FileKey6=%CommonAppData%\iolo\TempResources|*.*|REMOVESELF
FileKey7=%LocalAppData%\VirtualStore\Program Files*\iolo\System Mechanic|*.txt;*.xml
FileKey8=%LocalAppData%\VirtualStore\ProgramData\iolo|*.xml;*.txt
FileKey9=%LocalAppData%\VirtualStore\ProgramData\iolo\ACRSummaryFiles|*.*|REMOVESELF
FileKey10=%LocalAppData%\VirtualStore\ProgramData\iolo\logs|*.*|REMOVESELF
FileKey11=%LocalAppData%\VirtualStore\ProgramData\iolo\TempResources|*.*|REMOVESELF
FileKey12=%ProgramFiles%\iolo\System Mechanic|*.txt;*.xml
FileKey13=%SystemDrive%\Documents and Settings\LocalService\*\iolo|*.*|REMOVESELF
FileKey14=%WinDir%\System32\config|iolo App.evt
[System Mechanic Snapshots *]
LangSecRef=3024
Detect=HKCU\Software\iolo\System Mechanic
Default=False
Warning=This will delete System Mechanic System Snapshots Data.
FileKey1=%AppData%\iolo\System Snapshots Data|*.*
[SysTracer *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SysTracer
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\SysTracer|SysTracerLog.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\SysTracer\tmp|*.*|REMOVESELF
FileKey3=%ProgramFiles%\SysTracer|SysTracerLog.txt
FileKey4=%ProgramFiles%\SysTracer\tmp|*.*|REMOVESELF
[Tag&Rename *]
LangSecRef=3024
Detect1=HKCU\Software\Softpointer\Tag&Rename
Detect2=HKCU\Software\Softpointer\Tag&Rename2
Detect3=HKCU\Software\Softpointer\Tag&Rename3
Default=False
RegKey1=HKCU\Software\Softpointer\Tag&Rename\Config|FCurrentFolder
RegKey2=HKCU\Software\Softpointer\Tag&Rename\Config|FHistoryList
RegKey3=HKCU\Software\Softpointer\Tag&Rename2\Config|FCurrentFolder
RegKey4=HKCU\Software\Softpointer\Tag&Rename2\Config|FHistoryList
RegKey5=HKCU\Software\Softpointer\Tag&Rename3\Config|FCurrentFolder
RegKey6=HKCU\Software\Softpointer\Tag&Rename3\Config|FHistoryList
RegKey7=HKCU\Software\Softpointer\Tag&Rename3\Config|FileListHeader
[TAudio Converter *]
LangSecRef=3023
DetectFile=%AppData%\TAC
Default=False
FileKey1=%AppData%\TAC|log_main.txt
[Team Crossword *]
Section=Games
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.TeamCrossword_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.TeamCrossword_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\Microsoft\CLR_v4.0_32\UsageLogs|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey4=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\PRICache|*.*
FileKey5=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\AC\Temp|*.*
FileKey6=%LocalAppData%\Packages\Microsoft.TeamCrossword_*\TempState|*.*|RECURSE
[Team Fortress 2 *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\440
Default=False
FileKey1=%ProgramFiles%\Steam\SteamApps\common\Team Fortress 2\config\cookies|*.*|RECURSE
FileKey2=%ProgramFiles%\Steam\SteamApps\common\Team Fortress 2\config\html\AppCache|*.*|RECURSE
FileKey3=%ProgramFiles%\Steam\SteamApps\common\Team Fortress 2\tf\cache|*.*|RECURSE
FileKey4=%ProgramFiles%\Steam\SteamApps\common\Team Fortress 2\tf\download\user_custom|*.*|RECURSE
FileKey5=%ProgramFiles%\Steam\SteamApps\common\Team Fortress 2\tf\materials\temp|*.vtf|RECURSE
[TeamSpeak 3 *]
LangSecRef=3022
Detect=HKCU\Software\TeamSpeak 3 Client
Default=False
FileKey1=%LocalAppData%\TeamSpeak 3 Client\config\logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\TeamSpeak 3 Client\config\logs|*.*
FileKey3=%ProgramFiles%\TeamSpeak 3 Client\config\logs|*.*
[TeamSpeak 3 Chats *]
LangSecRef=3022
Detect=HKCU\Software\TeamSpeak 3 Client
Default=False
FileKey1=%AppData%\TS3Client\chats|*.*|REMOVESELF
[TeamViewer *]
LangSecRef=3024
Detect=HKCU\Software\TeamViewer
Default=False
FileKey1=%AppData%\TeamViewer|*.log;*.mdmp
FileKey2=%LocalAppData%\TeamViewer\*Cache|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\TeamViewer|*.log
FileKey4=%ProgramFiles%\TeamViewer|*.log
FileKey5=%WinDir%\System32|TeamViewer*_Hooks.log
RegKey1=HKCU\Software\TeamViewer\Version5|Last_Machine_Connections
RegKey2=HKCU\Software\TeamViewer\Version5.1|Last_Machine_Connections
RegKey3=HKCU\Software\TeamViewer\Version6|Last_Machine_Connections
RegKey4=HKCU\Software\TeamViewer\Version7|Last_Machine_Connections
[Technic Launcher *]
Section=Games
DetectFile=%AppData%\.technic*
Default=False
FileKey1=%AppData%\.technic*|*.old;*.log;*.tmp|RECURSE
FileKey2=%AppData%\.technic*\*\logs|*.*|RECURSE
FileKey3=%AppData%\.technic*\cache|*.*
FileKey4=%AppData%\.technic*\temp|*.*|RECURSE
[Technic Launcher Backups *]
Section=Games
DetectFile=%AppData%\.technic*
Default=False
FileKey1=%AppData%\.technic*\*\Backups|*.*|RECURSE
[Technic Launcher Screenshots *]
Section=Games
DetectFile=%AppData%\.technic*
Default=False
FileKey1=%AppData%\.technic*\*\Screenshots|*.*
[TechSmith DubIt *]
LangSecRef=3023
Detect=HKCU\Software\TechSmith\DubIt
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\TechSmith\DubIt|*.gid
FileKey2=%ProgramFiles%\TechSmith\DubIt|*.gid
RegKey1=HKCU\Software\TechSmith\DubIt\Recent Audio Files
RegKey2=HKCU\Software\TechSmith\DubIt\Recent Video Files
[TEdit *]
Section=Games
DetectFile=%AppData%\TEdit
Default=False
FileKey1=%AppData%\TEdit\undo|*.*|RECURSE
[Teeworlds *]
Section=Games
DetectFile=%AppData%\Teeworlds
Default=False
FileKey1=%AppData%\Teeworlds\dumps|*.*|REMOVESELF
FileKey2=%AppData%\Teeworlds\tmp|*.*|REMOVESELF
[Teeworlds Captures *]
Section=Games
DetectFile=%AppData%\Teeworlds
Default=False
FileKey1=%AppData%\Teeworlds\demos|*.*|REMOVESELF
FileKey2=%AppData%\Teeworlds\Screenshots|*.*|REMOVESELF
[Teeworlds Downloads / Maps *]
Section=Games
DetectFile=%AppData%\Teeworlds
Default=False
FileKey1=%AppData%\Teeworlds\downloaded*|*.*|REMOVESELF
FileKey2=%AppData%\Teeworlds\maps|*.*|REMOVESELF
[Tele2 Mobile Partner *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Tele2 Mobile Partner\Tele2 Mobile Partner.exe
Default=False
FileKey1=%CommonAppData%\Tele2 Mobile Partner\log|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Tele2 Mobile Partner\Log|*.txt
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Tele2 Mobile Partner\log|*.*
FileKey4=%ProgramFiles%\Tele2 Mobile Partner\Log|*.txt
[TEMP Folder *]
LangSecRef=3025
DetectFile=%CommonAppData%\TEMP
Default=False
FileKey1=%CommonAppData%\TEMP|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\TEMP|*.*|RECURSE
[TeraCopy *]
LangSecRef=3024
Detect=HKCU\Software\Code Sector\TeraCopy
Default=False
FileKey1=%AppData%\TeraCopy|FileList.dat;Transfer.log
FileKey2=%AppData%\TeraCopy\History|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\TeraCopy|FileList.dat;Transfer.log
FileKey4=%ProgramFiles%\TeraCopy|FileList.dat;Transfer.log
RegKey1=HKCU\Software\Code Sector\TeraCopy|LastTargetFolder
[Terraria *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\105600
Default=False
FileKey1=%Documents%\My Games\Terraria|*.bak;*.wld.bak|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\terraria|client-crashlog.txt
FileKey3=%ProgramFiles%\Steam\steamapps\common\terraria|client-crashlog.txt
[Tesla Legacy *]
Section=Games
DetectFile=%LocalAppData%\Astar Games\Tesla Legacy
Default=False
FileKey1=%LocalAppData%\Astar Games\Tesla Legacy|*.log
[TeXnicCenter *]
LangSecRef=3021
Detect1=HKCU\Software\ToolsCenter\TeXnicCenter
Detect2=HKCU\Software\ToolsCenter\TeXnicCenterNT
Default=False
RegKey1=HKCU\Software\ToolsCenter\TeXnicCenter\Recent File List
RegKey2=HKCU\Software\ToolsCenter\TeXnicCenter\Recent Project List
RegKey3=HKCU\Software\ToolsCenter\TeXnicCenter\Session
RegKey4=HKCU\Software\ToolsCenter\TeXnicCenter\Settings\Options|LastOpenedFolder
RegKey5=HKCU\Software\ToolsCenter\TeXnicCenterNT\Recent File List
RegKey6=HKCU\Software\ToolsCenter\TeXnicCenterNT\Recent Project List
RegKey7=HKCU\Software\ToolsCenter\TeXnicCenterNT\Session
RegKey8=HKCU\Software\ToolsCenter\TeXnicCenterNT\Settings\Options|LastOpenedFolder
[TGCM *]
LangSecRef=3023
DetectFile=%AppData%\TGCMLog
Default=False
FileKey1=%AppData%\TGCMLog|*log.txt
[The Bat *]
LangSecRef=3022
Detect=HKCU\Software\RIT\The Bat!
Default=False
FileKey1=%AppData%\The Bat!\cache|*.*
[The Cleaner *]
LangSecRef=3024
Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cleaner8.exe
Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cleaner9.exe
Default=False
FileKey1=%AppData%\thecleaner|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\The Cleaner|*.log;*.tmp;*.bak|RECURSE
FileKey3=%ProgramFiles%\The Cleaner|*.log;*.tmp;*.bak|RECURSE
[The Clumsys 2: The Butterfly Effect *]
Section=Games
DetectFile=%LocalAppData%\BanzaiInteractive\Clumsys2
Default=False
FileKey1=%AppData%\BanzaiInteractive\Clumsys2|logfile.txt
[The Dream Machine *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\94300
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\The Dream Machine\the_dream_machine.app|*.*|REMOVESELF
FileKey2=%ProgramFiles%\Steam\steamapps\common\The Dream Machine\the_dream_machine.app|*.*|REMOVESELF
[The Mighty Quest for Epic Loot *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\239220
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\The Mighty Quest For Epic Loot\CrashReport|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\The Mighty Quest For Epic Loot\Log|*.*
FileKey3=%ProgramFiles%\Steam\SteamApps\Common\The Mighty Quest For Epic Loot\CrashReport|*.*
FileKey4=%ProgramFiles%\Steam\SteamApps\Common\The Mighty Quest For Epic Loot\Log|*.*
[The Mystery of the Mary Celeste *]
Section=Games
DetectFile=%AppData%\Merscom\The Mystery of the Mary Celeste
Default=False
FileKey1=%AppData%\Merscom\The Mystery of the Mary Celeste|logfile.txt
[The Quran *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\57100Goheer.TheQuran_s6gg0ptmhrgye
DetectFile=%LocalAppData%\Packages\57100Goheer.TheQuran_s6gg0ptmhrgye
Default=False
FileKey1=%LocalAppData%\Packages\*TheQuran_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*TheQuran_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\*TheQuran_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey4=%LocalAppData%\Packages\*TheQuran_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\*TheQuran_*\AC\PRICache|*.*
FileKey6=%LocalAppData%\Packages\*TheQuran_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\*TheQuran_*\LocalState|*.*|RECURSE
[The Rise of Atlantis *]
Section=Games
DetectFile=%CommonAppData%\TERMINAL Studio\The Rise of Atlantis
Default=False
FileKey1=%CommonAppData%\Terminal Studio\The Rise of Atlantis|log.html
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Terminal Studio\The Rise of Atlantis|log.html
[The Sims 3 *]
Section=Games
Detect=HKCU\Software\Electronic Arts\Sims 3
Default=False
FileKey1=%Documents%\Electronic Arts\The Sims 3|*.log;*.mdmp;xcpt*.txt|RECURSE
[The Sims 3 Cache Files *]
Section=Games
Detect=HKCU\Software\Electronic Arts\Sims 3
Default=False
FileKey1=%Documents%\Electronic Arts\The Sims 3|socialCache.package;CASPartCache.package;scriptCache.package;compositorCache.package;simCompositorCache.package
FileKey2=%Documents%\Electronic Arts\The Sims 3\Thumbnails|*.*
FileKey3=%Documents%\Electronic Arts\The Sims 3\WorldCaches|*.*
[The Sims 3 DCBackup Files *]
Section=Games
Detect=HKCU\Software\Electronic Arts\Sims 3
Default=False
Warning=This may make premium content buggy if deleted.
FileKey1=%Documents%\Electronic arts\The sims 3\DCBackup|*.package
ExcludeKey1=FILE|%Documents%\electronic arts\The sims 3\DCBackup\|ccmerged.package
[The Sims 4 *]
Section=Games
DetectFile=%Documents%\Electronic Arts\The Sims 4
Default=False
FileKey1=%Documents%\Electronic Arts\The Sims 4|*.txt;*.log
[The Sims Medieval *]
Section=Games
Detect=HKLM\Software\Electronic Arts\The Sims Medieval
Default=False
FileKey1=%Documents%\Electronic Arts\The Sims Medieval|*.log;*.xml|RECURSE
[The Sims Resource Merlin *]
Section=Games
DetectFile=%ProgramFiles%\The Sims Resource\TSR Merlin
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\The Sims Resource\TSR Merlin\Logs|*.*
FileKey2=%ProgramFiles%\The Sims Resource\TSR Merlin\Logs|*.*
[The Talos Principle *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\257510
Default=False
FileKey1=%ProgramFiles%\Steam\steamapps\common\The Talos Principle\Log|*.*|RECURSE
[The Tiny Bang Story *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\96000
Default=False
FileKey1=%AppData%\Colibri Games\The Tiny Bang Story|logfile.txt
[The Weather Channel *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\TheWeatherChannel_t3yemqpq4kp7p
DetectFile=%LocalAppData%\Packages\Weather.TheWeatherChannel_t3yemqpq4kp7p
Default=False
FileKey1=%LocalAppData%\Packages\Weather.TheWeatherChannel_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Weather.TheWeatherChannel_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.log|RECURSE
FileKey3=%LocalAppData%\Packages\Weather.TheWeatherChannel_*\AC\Temp|*.*
FileKey4=%LocalAppData%\Packages\Weather.TheWeatherChannel_*\LocalState|*.tmp
FileKey5=%LocalAppData%\Packages\Weather.TheWeatherChannel_*\TempState\Bing.Maps\Cache|*.*|RECURSE
[The Witcher *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\20900
Detect2=HKCU\Software\Valve\Steam\Apps\20920
Default=False
FileKey1=%LocalAppData%\The Witcher 2\temp|*.*
FileKey2=%LocalAppData%\The Witcher\logs|*.*
[The Women's Murder Club 3: Twice in a Blue Moon *]
Section=Games
DetectFile=%AppData%\Flood Light Games\WMC3
Default=False
FileKey1=%AppData%\Flood Light Games\WMC3|*.log
[Thinstall Database *]
LangSecRef=3021
DetectFile1=%AppData%\Thinstall
DetectFile2=%LocalAppData%\Thinstall
Default=False
Warning=This will remove your Portable's settings. If settings are stored in the program's folder, this is fine.
FileKey1=%AppData%\Thinstall|*.*|REMOVESELF
FileKey2=%LocalAppData%\Thinstall|*.*|REMOVESELF
[Thomas Was Alone *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\220780
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\thomaswasalone\ThomasWasAlone_Data|output_log.txt
FileKey2=%ProgramFiles%\Steam\Steamapps\common\thomaswasalone\ThomasWasAlone_Data|output_log.txt
[ThumbsPlus *]
LangSecRef=3023
Detect=HKCU\Software\Cerious Software Inc.
Default=False
FileKey1=%AppData%\Thumbsplus|*.log;*.bak;*.dmp;*.7z;*.exc;*.png
FileKey2=%ProgramFiles%\Thumbsplus *\Bin|*.log
[Tific Client *]
LangSecRef=3021
DetectFile=%LocalAppData%\Tific
Default=False
FileKey1=%LocalAppData%\Tific|*.log|RECURSE
[TightVNC *]
LangSecRef=3022
DetectFile=%AppData%\TightVNC
Default=False
FileKey1=%AppData%\TightVNC|*.log
[TikiOne Steam Cleaner *]
LangSecRef=3024
DetectFile=%UserProfile%\.tikione
Default=False
FileKey1=%UserProfile%\.tikione\log|*.*
[Time Adjuster *]
LangSecRef=3021
Detect=HKCU\Software\IrekZielinskiSoft\TimeAdjuster
Default=False
RegKey1=HKCU\Software\IrekZielinskiSoft\TimeAdjuster|LDIR2
RegKey2=HKCU\Software\IrekZielinskiSoft\TimeAdjuster|LDIR3
RegKey3=HKCU\Software\IrekZielinskiSoft\TimeAdjuster|LDIR4
[TimeRabbit *]
LangSecRef=3022
DetectFile=%AppData%\TimeRabbit
Default=False
FileKey1=%AppData%\TimeRabbit\Cache|*.*|RECURSE
[Timeslips *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Timeslips
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\TimeSlips\Data01\logs|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Timeslips\logs|*.*
FileKey3=%ProgramFiles%\TimeSlips\Data01\logs|*.*
FileKey4=%ProgramFiles%\Timeslips\logs|*.*
[Tinder++ *]
LangSecRef=3021
DetectFile=%LocalAppData%\Tinder*
Default=False
FileKey1=%LocalAppData%\Tinder*|*.*|RECURSE
[Tinseltown Dreams *]
Section=Games
DetectFile=%LocalAppData%\Namco Networks\Tinseltown Dreams
Default=False
FileKey1=%LocalAppData%\Namco Networks\Tinseltown Dreams|errors*.*;log.txt
[Tipard Converter *]
LangSecRef=3023
Detect1=HKCU\Software\Tipard Studio\Tipard Total Media Converter
Detect2=HKCU\Software\Tipard Studio\Tipard Total Media Converter Platinum
Detect3=HKCU\Software\Tipard Studio\Tipard Video Converter Ultimate
Default=False
FileKey1=%LocalAppData%\Tipard Studio\Tipard *|*.txt
RegKey1=HKCU\Software\Tipard Studio\Tipard Total Media Converter Platinum\Edit|LastVideoFilePath
RegKey2=HKCU\Software\Tipard Studio\Tipard Total Media Converter\Edit|LastVideoFilePath
RegKey3=HKCU\Software\Tipard Studio\Tipard Video Converter Ultimate\Edit|LastVideoFilePath
[Tixati *]
LangSecRef=3021
DetectFile=%AppData%\tixati
Default=False
FileKey1=%AppData%\tixati|upnp_diagnostic_log.txt
[Tom Clancy's Ghost Recon *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\15300
DetectFile=%ProgramFiles%\Red Storm Entertainment\Ghost Recon
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Red Storm Entertainment\Ghost Recon|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Ghost Recon|*.log
FileKey3=%ProgramFiles%\Red Storm Entertainment\Ghost Recon|*.log
FileKey4=%ProgramFiles%\Steam\SteamApps\Ghost Recon|*.log
[Tom Clancy's Rainbow Six 3: Raven Shield *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\19830
DetectFile=%ProgramFiles%\Red Storm Entertainment\RavenShield
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Red Storm Entertainment\RavenShield|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\RavenShield|*.log
FileKey3=%ProgramFiles%\Red Storm Entertainment\RavenShield|*.log
FileKey4=%ProgramFiles%\Steam\SteamApps\Common\RavenShield|*.log
[Tom Clancy's Rainbow Six Vegas 2 *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\15120
DetectFile=%ProgramFiles%\Ubisoft\Tom Clancy's Rainbow Six Vegas 2
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Tom Clancy's Rainbow Six Vegas 2|CrashReport*.*;*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Tom Clancy's Rainbow Six Vegas 2|CrashReport*.*;*.log|RECURSE
FileKey3=%ProgramFiles%\Steam\SteamApps\Common\Tom Clancy's Rainbow Six Vegas 2|CrashReport*.*;*.log|RECURSE
FileKey4=%ProgramFiles%\Ubisoft\Tom Clancy's Rainbow Six Vegas 2|CrashReport*.*;*.log|RECURSE
[Tomahawk *]
LangSecRef=3023
Detect=HKCU\Software\Tomahawk
Default=False
FileKey1=%LocalAppData%\Tomahawk|*.log
FileKey2=%LocalAppData%\Tomahawk\Tomahawk\Cache|*.*|RECURSE
[Tomahawk PDF+ *]
LangSecRef=3021
Detect=HKCU\Software\NativeWinds\Tomahawk
Default=False
RegKey1=HKCU\Software\NativeWinds\Tomahawk\MRU
[Tomb Raider *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\203160
Default=False
FileKey1=%Documents%|TombRaider.log
[Tomboy *]
LangSecRef=3021
DetectFile=%LocalAppData%\Tomboy
Default=False
FileKey1=%LocalAppData%\Tomboy|*.log
FileKey2=%LocalAppData%\Tomboy\Cache|*.*|RECURSE
[TomTom *]
LangSecRef=3021
Detect1=HKCU\Software\TomTom
Detect2=HKLM\Software\Classes\tomtomhome
Default=False
FileKey1=%AppData%\TomTom\HOME\Profiles\*|Log.txt
FileKey2=%LocalAppData%\TomTom\HOME3|Log.txt
FileKey3=%LocalAppData%\TomTom\HOME3\cache|*.*|RECURSE
[ToniArts EasyCleaner Duplicates *]
LangSecRef=3024
Detect=HKLM\Software\ToniArts\EasyCleaner
Default=False
FileKey1=%ProgramFiles%\ToniArts\EasyCleaner|Duplicat.*
[ToonTown *]
Section=Games
DetectFile=%LocalLowAppData%\Panda3D
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Disney\Disney Online\ToontownOnline|*.log
FileKey2=%LocalLowAppData%\Panda3D\Log|*.*
FileKey3=%ProgramFiles%\Disney\Disney Online\ToontownOnline|*.log
[ToonTown Rewritten *]
Section=Games
DetectFile=%ProgramFiles%\ToonTown Rewritten
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\ToonTown ReWritten\logs|*.*
FileKey2=%ProgramFiles%\ToonTown ReWritten\logs|*.*
[TopStyle 5 *]
LangSecRef=3021
Detect=HKCU\Software\Bradbury\TopStyle\5.0
Default=False
RegKey1=HKCU\Software\Bradbury\TopStyle\5.0\RecentFiles
[Torchlight *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\41500
DetectFile=%AppData%\Runic Games\Torchlight
Default=False
FileKey1=%AppData%\Runic Games\Torchlight|*.log
[Torchlight 2 *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\200710
Detect2=HKLM\Software\Runic Games\Torchlight II
Default=False
FileKey1=%Documents%\My Games\runic games\torchlight 2|ogre.log
FileKey2=%Documents%\My Games\Runic Games\Torchlight 2\logs|*.*
[Torrent Search Log *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Torrent Search
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Torrent Search|*.log
FileKey2=%ProgramFiles%\Torrent Search|*.log
[TortoiseHg *]
LangSecRef=3021
Detect=HKCU\Software\tortoisemerge
Default=False
FileKey1=%AppData%\TortoiseHg|*.log;*.old
[TortoiseSVN *]
LangSecRef=3024
Detect=HKCU\Software\TortoiseSVN
Default=False
FileKey1=%AppData%\TortoiseSVN|*.*
FileKey2=%LocalAppData%\TSVNCache|*.*
[TortoiseSVN History *]
LangSecRef=3024
Detect=HKCU\Software\TortoiseSVN
Default=False
Warning=This will remove your repo paths and last checkout location.
RegKey1=HKCU\Software\TortoiseSVN\History
[Toshiba BluetoothStack *]
LangSecRef=3024
Detect=HKLM\Software\Toshiba\BluetoothStack
Default=False
FileKey1=%LocalAppData%\Toshiba\BluetoothStack\V1.0\tosOBEX\Temp|*.*
[Toshiba Book Place *]
LangSecRef=3021
DetectFile=%AppData%\Book Place
Default=False
FileKey1=%AppData%\Book Place\Cache|*.*|RECURSE
FileKey2=%AppData%\Book Place\log|*.*|RECURSE
[Toshiba FlashCards *]
LangSecRef=3021
DetectFile=%LocalAppData%\TOSHIBA\FlashCards
Default=False
FileKey1=%LocalAppData%\TOSHIBa\FlashCards|log.txt
[Total Recorder *]
LangSecRef=3023
Detect=HKCU\Software\HighCriteria\TotalRecorder\Recent File List
Default=False
RegKey1=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File1
RegKey2=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File2
RegKey3=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File3
RegKey4=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File4
RegKey5=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File5
RegKey6=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File6
RegKey7=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File7
RegKey8=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File8
RegKey9=HKCU\Software\HighCriteria\TotalRecorder\Recent File list|File9
[Total Uninstall *]
LangSecRef=3024
Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall 5_is1
Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall 6_is1
Default=False
FileKey1=%CommonAppData%\Martau\Total Uninstall*|*.Folders;*.cache|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Total Uninstall*|*.rtf;*.txt;*.GID|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Martau\Total Uninstall*|*.Folders;*.cache|RECURSE
FileKey4=%ProgramFiles%\Total Uninstall*|*.rtf;*.txt;*.GID|RECURSE
[Total Uninstall Backups *]
LangSecRef=3024
Detect1=HKCU\Software\MartS\Total Uninstall
Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall 5_is1
Detect3=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Total Uninstall 6_is1
Default=False
Warning=This will delete analyzed programs and backups.
FileKey1=%CommonAppData%\Martau\Total Uninstall*|*.tlg;*.zsns;*.zip|RECURSE
FileKey2=%CommonAppData%\Martau\Total Uninstall*\Analyzed Programs|*.*
FileKey3=%CommonAppData%\Martau\Total Uninstall*\Backup|*.zip
FileKey4=%CommonAppData%\Martau\Total Uninstall*\System Snapshots|*.zsns
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Martau\Total Uninstall*|*.tlg;*.zsns;*.zip|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Martau\Total Uninstall*\Analyzed Programs|*.*
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Martau\Total Uninstall*\Backup|*.zip
FileKey8=%LocalAppData%\VirtualStore\ProgramData\Martau\Total Uninstall*\System Snapshots|*.zsns
[Towns *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\221020
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\Steamapps\common\towns|*.log
FileKey2=%ProgramFiles%\Steam\Steamapps\common\towns|*.log
[TP-Link *]
LangSecRef=3022
DetectFile=%CommonAppData%\TP-Link
Default=False
FileKey1=%CommonAppData%\TP-Link|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\TP-Link|*.log
[Trackmania Forever Cache *]
Section=Games
DetectFile=%CommonAppData%\TrackMania
Default=False
FileKey1=%CommonAppData%\TrackMania\Cache|*.*
FileKey2=%CommonAppData%\TrackMania\Cache\ManiaCode|*.*
FileKey3=%LocalAppData%\VirtualStore\ProgramData\TrackMania\Cache|*.*
FileKey4=%LocalAppData%\VirtualStore\ProgramData\TrackMania\Cache\ManiaCode|*.*
[Trackmania Forever Manialinks *]
Section=Games
DetectFile=%CommonAppData%\TrackMania
Default=False
FileKey1=%CommonAppData%\TrackMania\Manialinks|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\TrackMania\Manialinks|*.*
[Trackmania Forever Scores *]
Section=Games
DetectFile=%CommonAppData%\TrackMania
Default=False
FileKey1=%CommonAppData%\TrackMania\CampaignsScores|*.*
FileKey2=%CommonAppData%\TrackMania\CampaignsScores\General|*.*
FileKey3=%CommonAppData%\TrackMania\CampaignsScores\UnitedRace|*.*
FileKey4=%CommonAppData%\TrackMania\LadderScores|*.*
FileKey5=%LocalAppData%\VirtualStore\ProgramData\TrackMania\CampaignsScores|*.*
FileKey6=%LocalAppData%\VirtualStore\ProgramData\TrackMania\CampaignsScores\General|*.*
FileKey7=%LocalAppData%\VirtualStore\ProgramData\TrackMania\CampaignsScores\UnitedRace|*.*
FileKey8=%LocalAppData%\VirtualStore\ProgramData\TrackMania\LadderScores|*.*
[Tracks Eraser Pro *]
LangSecRef=3024
Detect=HKLM\Software\Acesoft\tracks eraser pro
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Acesoft\Tracks Eraser Pro|te.log
FileKey2=%ProgramFiles%\Acesoft\Tracks Eraser Pro|te.log
[Trade Manager *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Trademanager
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Trademanager|OneClickEnd.log
FileKey2=%ProgramFiles%\Trademanager|OneClickEnd.log
[Treesize *]
LangSecRef=3024
Detect1=HKCU\Software\JAM Software\TreeSize Free
Detect2=HKCU\Software\JAM Software\TreeSize Professional
Default=False
FileKey1=%AppData%\JAM Software\TreeSize *|GlobalOptions.bak0
[Trend Micro *]
LangSecRef=3023
Detect=HKCU\Software\Trend Micro
DetectFile=%CommonAppData%\Trend Micro
Default=False
FileKey1=%CommonAppData%\Trend Micro|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Trend Micro|*.log
[Trend Micro AntiRansomware Tool *]
LangSecRef=3021
DetectFile=%ProgramFiles%\AntiRansomware2.0
Default=False
FileKey1=%CommonAppData%\AntiRansomware|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\AntiRansomware|*.log
[TrendMicro RUBotted *]
LangSecRef=3024
Detect=HKLM\Software\TrendMicro\RUBotted
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Trend Micro\RUBotted\DebugLogs|*.*|REMOVESELF
FileKey2=%ProgramFiles%\Trend Micro\RUBotted\DebugLogs|*.*|REMOVESELF
[Tribes: Ascend *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\17080
Default=False
FileKey1=%CommonAppData%\Hi-Rez Studios\BrowserCacheTribes\Default\Cache|*.*|RECURSE
FileKey2=%Documents%\My Games\Tribes Ascend\TribesGame\Logs|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\tribes\Binaries\Logs|*.*
FileKey4=%ProgramFiles%\Steam\steamapps\common\tribes\Binaries\Logs|*.*
[Trillian *]
LangSecRef=3022
Detect=HKLM\Software\Clients\IM\Trillian
Default=False
FileKey1=%AppData%\Trillian\Crash Files|*.*|RECURSE
FileKey2=%AppData%\Trillian\users\*|buddies.*.xml
FileKey3=%AppData%\Trillian\users\*\cache|*.*
FileKey4=%AppData%\Trillian\users\*\instantlookup|*.*
FileKey5=%AppData%\Trillian\users\*\logs|*.*|RECURSE
FileKey6=%AppData%\Trillian\users\global\skin_cache|*.*
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Trillian\Crash Files|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\Program Files*\Trillian\Users\Default\buddyicons|*.*|RECURSE
FileKey9=%LocalAppData%\VirtualStore\Program Files*\Trillian\Users\Default\instantlookup|*.*
FileKey10=%ProgramFiles%\Trillian\Crash Files|*.*|RECURSE
FileKey11=%ProgramFiles%\Trillian\Users\Default\buddyicons|*.*|RECURSE
FileKey12=%ProgramFiles%\Trillian\Users\Default\instantlookup|*.*
[Trine *]
Section=Games
Detect1=HKCU\Software\Valve\Steam\Apps\35700
Detect2=HKCU\Software\Valve\Steam\Apps\35720
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\Common\Trine*\log*|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\Trine\_enchanted_edition_\log|*.*
FileKey3=%ProgramFiles%\Steam\SteamApps\Common\Trine*\log*|*.*
FileKey4=%ProgramFiles%\Steam\SteamApps\common\Trine\_enchanted_edition_\log|*.*
[TrojanHunter *]
LangSecRef=3024
Detect=HKCU\Software\TrojanHunter
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\TrojanHunter*|Debug.log;DebugLog.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\TrojanHunter*\Scan Reports|*.*
FileKey3=%ProgramFiles%\TrojanHunter*|Debug.log;DebugLog.txt
FileKey4=%ProgramFiles%\TrojanHunter*\Scan Reports|*.*
[Tropico *]
Section=Games
Detect1=HKCU\Software\Haemimont Games\Tropico 4
Detect2=HKLM\Software\Haemimont Games\Tropico3
Default=False
FileKey1=%AppData%\Tropico*\logs|*.*|REMOVESELF
FileKey2=%AppData%\Tropico*\ShaderCache|*.*|REMOVESELF
FileKey3=%ProgramFiles%\Kalypso Media\*|dotnetfx3.exe;dotnetfx35.exe
FileKey4=%ProgramFiles%\Kalypso Media\*\DirectXRedist|*.*|REMOVESELF
[Trusteer Rapport *]
LangSecRef=3022
Detect=HKCU\Software\Trusteer\Rapport
Default=False
FileKey1=%CommonAppData%\Trusteer\Rapport\logs|*.*
FileKey2=%LocalAppData%\Trusteer\Rapport\user\logs|*.*
FileKey3=%WinDir%\System32\config\systemprofile\AppData\Local\Trusteer\Rapport\user\logs|*.*
[Tubebox! *]
LangSecRef=3023
DetectFile1=%UserProfile%\Start Menu\Programs\TubeBox!
DetectFile2=%UserProfile%\Startmenü\Programme\TubeBox!
Default=False
FileKey1=%UserProfile%\Start*\Program*\TubeBox!|TubeBox!-Log.txt
[TuneDroid *]
LangSecRef=3023
DetectFile=%AppData%\TuneDroid
Default=False
FileKey1=%AppData%\TuneDroid\Logs|*.*
[TuneXP *]
LangSecRef=3021
DetectFile=%ProgramFiles%\TuneXP
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\TuneXP\docs|*.bak
FileKey2=%ProgramFiles%\TuneXP\docs|*.bak
[TunnelBear *]
LangSecRef=3022
DetectFile=%ProgramFiles%\TunnelBear
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\TunnelBear|*.log
FileKey2=%ProgramFiles%\TunnelBear|*.log
[TV-Browser *]
LangSecRef=3021
DetectFile=%ProgramFiles%\TV-Browser\tvbrowser.exe
Default=False
FileKey1=%AppData%\TV-Browser\*|java.searchplugin.SearchPlugin.dat*
[TV_Net *]
LangSecRef=3023
DetectFile=%LocalLowAppData%\TV_Net
Default=False
FileKey1=%LocalLowAppData%\TV_Net\CacheIcons|*.*|RECURSE
FileKey2=%LocalLowAppData%\TV_Net\Logs|*.*|RECURSE
[TVersity *]
LangSecRef=3023
Detect=HKLM\Software\TVersity\Media Server
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\TVersity Codec Pack|*.exe;*.url
FileKey2=%LocalAppData%\VirtualStore\Program Files*\TVersity\Media Server\logs|*.log;*.txt;*.xml;*.zip|RECURSE
FileKey3=%ProgramFiles%\TVersity Codec Pack|*.exe;*.url
FileKey4=%ProgramFiles%\TVersity\Media Server|*.rtf;*.url;*TVersityCodecPackSetup*
FileKey5=%ProgramFiles%\TVersity\Media Server\logs|*.log;*.txt;*.xml;*.zip|RECURSE
FileKey6=%WinDir%\System32|tversity.cookies;TVersityMediaServer.log;*.1;*.2;*.3
FileKey7=%WinDir%\System32\config\systemprofile\AppData\Local\Temp\TVersity Media Server|*.*|REMOVESELF
FileKey8=%WinDir%\System32\config\systemprofile\Local Settings\Application Data\Temp\TVersity Media Server|*.*|REMOVESELF
ExcludeKey1=FILE|%ProgramFiles%\TVersity Codec Pack\|uninst.exe
ExcludeKey2=PATH|%ProgramFiles%\TVersity\Media Server\|*version.txt;*HOWTO Share Media.txt
[TVUPlayer *]
LangSecRef=3023
Detect=HKCU\Software\TVU networks
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\TVUPlayer|log.txt
FileKey2=%ProgramFiles%\TVUPlayer|log.txt
[TWC Desktop Weather *]
LangSecRef=3021
DetectFile=%LocalAppData%\The Weather Channel\Desktop\patch
Default=False
FileKey1=%LocalAppData%\The Weather Channel\Desktop\patch|*.*
[Tweaking.com Windows Repair *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Tweaking.com - Windows Repair (All in One)
DetectFile1=%ProgramFiles%\Tweaking.com
DetectFile2=%SystemDrive%\Tweaking.com_Windows_Repair_Logs
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Tweaking.com\Windows Repair (All in One)\Logs|*.*|REMOVESELF
FileKey2=%ProgramFiles%\Tweaking.com\Windows Repair (All in One)\Logs|*.*|REMOVESELF
FileKey3=%SystemDrive%\Tweaking.com_Windows_Repair_Logs|*.*|REMOVESELF
[TweakNow PowerPack 2005 *]
LangSecRef=3024
Detect=HKCU\Software\TweakNow PowerPack
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\TweakNow PowerPack\Backup|*.*
FileKey2=%ProgramFiles%\TweakNow PowerPack\Backup|*.*
[TweetDeck *]
LangSecRef=3022
Detect=HKCU\Software\Twitter\TweetDeck
Default=False
Warning=May delete your password and require you to log in again.
FileKey1=%LocalAppData%\Twitter\TweetDeck\localStorage|*.*
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Twitter\TweetDeck|*.log
FileKey3=%ProgramFiles%\Twitter\TweetDeck|*.log
[Tweetro *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\27761LazywormApplications.Tweetro_5tydn77rr51qw
DetectFile=%LocalAppData%\Packages\27761LazywormApplications.Tweetro_5tydn77rr51qw
Default=False
FileKey1=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\Microsoft\*|*.LOG|RECURSE
FileKey2=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\Microsoft\*\Native Images\Assembly\Temp|*.*
FileKey3=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\Microsoft\*\Native Images\Temp|*.*
FileKey4=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\PRICache|*.*
FileKey6=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\LocalState\*\PhotoTweets|*.*
FileKey8=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\LocalState\Logs|*.*
FileKey9=%LocalAppData%\Packages\*LazywormApplications.tweetro_*\TempState|*.*
[Tweetro+ *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\27761LazywormApplications.135450F141EEE_5tydn77rr51qw
DetectFile=%LocalAppData%\Packages\27761LazywormApplications.135450F141EEE_5tydn77rr51qw
Default=False
FileKey1=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\Microsoft\*|*.LOG|RECURSE
FileKey2=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\Microsoft\*\Native Images\Assembly\Temp|*.*
FileKey3=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\Microsoft\*\Native Images\Temp|*.*
FileKey4=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\PRICache|*.*
FileKey6=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\LocalState\*\PhotoTweets|*.*
FileKey8=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\LocalState\Logs|*.*
FileKey9=%LocalAppData%\Packages\*LazywormApplications.135450F141EEE_*\TempState|*.*
[Twitter Metro *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\9E2F88E3.Twitter_wgeqdkkx372wm
DetectFile=%LocalAppData%\Packages\9E2F88E3.Twitter_wgeqdkkx372wm
Default=False
FileKey1=%LocalAppData%\Packages\*Twitter_*\AC\INetC*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*Twitter_*\AC\Microsoft\*|*.LOG|RECURSE
FileKey3=%LocalAppData%\Packages\*Twitter_*\AC\PRICache|*.*
FileKey4=%LocalAppData%\Packages\*Twitter_*\LocalState|*.*|RECURSE
[Two Worlds Epic Edition *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\1930
Default=False
FileKey1=%Documents%\TwoWorlds Files\FontsCache|*.tmp
[Ubisoft Game Launcher *]
Section=Games
DetectFile=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Ubisoft Game Launcher|*.log
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Ubisoft Game Launcher\Cache\assets|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Ubisoft Game Launcher\Cache\http*|*.*|RECURSE
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Ubisoft\Ubisoft Game Launcher\Logs|*.*
FileKey5=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher|*.log
FileKey6=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Cache\assets|*.*
FileKey7=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Cache\http*|*.*|RECURSE
FileKey8=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Logs|*.*
[Ubisoft Game Launcher Installers *]
Section=Games
DetectFile=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher
Default=False
Warning=Make sure to launch all of your installed UPlay games at least once before running this, or they may not launch properly.
FileKey1=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Cache\Installers|*.*|REMOVESELF
[Ulead GIF Animator 5.05 *]
LangSecRef=3024
Detect=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05
Default=False
RegKey1=HKCU\Software\Ulead Systems\Ulead GIF Animator\5.05\Recent File List
[Ultimate Defrag *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Disktrix\UltimateDefrag\Udefrag.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Disktrix\UltimateDefrag|*.db;*Crash.dmp
FileKey2=%ProgramFiles%\Disktrix\UltimateDefrag|*.db;*Crash.dmp
[UltraDefrag *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UltraDefrag
DetectFile1=%SystemDrive%\PortableApps\UltraDefragPortable\UltraDefragPortable.exe
DetectFile2=%WinDir%\UltraDefrag\ultradefrag.exe
Default=False
FileKey1=%ProgramFiles%\UltraDefrag\logs|*.*
FileKey2=%SystemDrive%|fraglist.luar
FileKey3=%SystemDrive%\PortableApps\UltraDefragPortable\Data|UltraDefragPortable.log
FileKey4=%WinDir%\UltraDefrag\logs|*.log
[UltraEdit *]
LangSecRef=3021
Detect=HKCU\Software\IDM Computer Solutions\UltraEdit
Default=False
FileKey1=%AppData%\IDMComp\UltraEdit\autorec|*.*|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\IDM Computer Solutions\UltraEdit|*.txt
FileKey3=%ProgramFiles%\IDM Computer Solutions\UltraEdit|*.txt
[UltraISO *]
LangSecRef=3024
Detect=HKCU\Software\EasyBoot Systems
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\UltraISO\backup|*.*|REMOVESELF
FileKey2=%ProgramFiles%\UltraISO\backup|*.*|REMOVESELF
RegKey1=HKCU\Software\EasyBoot Systems\UltraISO\5.0|LogFile
RegKey2=HKCU\Software\EasyBoot Systems\UltraISO\5.0|OpenFolder
[Ultratron *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\219190
Default=False
FileKey1=%UserProfile%\.ultratron*|*.log
[UMPlayer *]
LangSecRef=3023
DetectFile=%UserProfile%\.umplayer
Default=False
FileKey1=%SystemDrive%\MININT|*.log|RECURSE
[UMPlayer File Settings *]
LangSecRef=3023
DetectFile=%UserProfile%\.umplayer
Default=False
FileKey1=%UserProfile%\.umplayer\file_settings|*.*|RECURSE
[Unchecky *]
LangSecRef=3024
Detect=HKCU\Software\Unchecky
Default=False
FileKey1=%CommonAppData%\Unchecky|*.log
[UnHackMe *]
LangSecRef=3024
Detect=HKLM\Software\Greatis
Default=False
FileKey1=%Documents%\RegRun2|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\UnHackMe|*.err;*.txt;*.log|RECURSE
FileKey3=%ProgramFiles%\UnHackMe|*.err;*.txt;*.log|RECURSE
[Unicenta Open POS *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Unicentaopos*
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Unicentaopos*|*.log
FileKey2=%ProgramFiles%\Unicentaopos*|*.log
[Unified Remote *]
LangSecRef=3023
Detect=HKCU\Software\Unified Remote
Default=False
FileKey1=%AppData%\Unified Remote\Logs|*.*
[Unigine Heaven DX11 Benchmark *]
LangSecRef=3021
DetectFile=%UserProfile%\Unigine Heaven
Default=False
FileKey1=%UserProfile%\Unigine Heaven|log.html;*.cache
FileKey2=%UserProfile%\Unigine Heaven\save|*.*|REMOVESELF
[Uninstall Tool *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Tool_is1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Uninstall Tool|*.dmp
FileKey2=%ProgramFiles%\Uninstall Tool|*.dmp
[Unity Web Player *]
LangSecRef=3023
Detect=HKCU\Software\Unity\WebPlayer
Default=False
FileKey1=%LocalLowAppData%\Unity\*Player\Cache|*.*|RECURSE
[Universal Share Downloader *]
LangSecRef=3022
DetectFile=%ProgramFiles%\USDownloader\USDownloader.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\USDownloader|USDownloader.log;*.bak;*.bmp;*.jpg;*.png
FileKey2=%ProgramFiles%\USDownloader|USDownloader.log;*.bak;*.bmp;*.jpg;*.png
[Unlocker *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Unlocker\Unlocker.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Unlocker|Unlocker-List.txt
FileKey2=%ProgramFiles%\Unlocker|Unlocker-List.txt
[Unlockroot *]
LangSecRef=3024
Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\unlockroot.exe
Detect2=HKLM\Software\UnlockrootPro
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Unlockroot*|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Unlockroot\tools|*.zip
FileKey3=%ProgramFiles%\Unlockroot*|*.txt
FileKey4=%ProgramFiles%\Unlockroot*\tools|*.zip
[UPX Shell *]
LangSecRef=3024
Detect=HKCU\Software\ION Tek\UPX Shell
Default=False
RegKey1=HKCU\Software\ION Tek\UPX Shell\3.x|History
[USA Today *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\USATODAY.USATODAY_wy7mw3214mat8
DetectFile=%LocalAppData%\Packages\USATODAY.USATODAY_wy7mw3214mat8
Default=False
FileKey1=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\Microsoft\CLR_v4.0|*.log
FileKey3=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\PRICache|*.*
FileKey6=%LocalAppData%\Packages\USATODAY.USATODAY_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\USATODAY.USATODAY_*\TempState|*.*|RECURSE
[USB Disk Security *]
LangSecRef=3024
DetectFile=%ProgramFiles%\USB Disk Security\USBGuard.exe
Default=False
FileKey1=%AppData%\Zbshareware Lab|*.*|REMOVESELF
[USB Redirector *]
LangSecRef=3022
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FB9376AC-5253-42a5-AC0A-D306F32FFAD2}
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\USB Redirector|*.log;*.txt
FileKey2=%ProgramFiles%\USB Redirector|*.log;*.txt
[USB Safely Remove *]
LangSecRef=3024
Detect=HKCU\Software\SafelyRemove
Default=False
FileKey1=%AppData%\USBSafelyRemove|*.txt
FileKey2=%AppData%\USBSRService|*.txt
FileKey3=%LocalAppData%\VirtualStore\Program Files*\USB Safely Remove|*.DIZ;*.rtf;*.url
FileKey4=%ProgramFiles%\USB Safely Remove|*.DIZ;*.rtf;*.url
[USBChargerPlus *]
LangSecRef=3021
DetectFile=%CommonAppData%\USBChargerPlus
Default=False
FileKey1=%CommonAppData%|AsACPLog.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData|AsACPLog.*
[UsbFix *]
LangSecRef=3023
Detect=HKCU\Software\UsbFix
Default=False
FileKey1=%SystemDrive%\UsbFix\Log|*.*|REMOVESELF
FileKey2=%SystemDrive%\UsbFix\Quarantine|*.*|REMOVESELF
FileKey3=%UserProfile%\Desktop|UsbFix_Report.txt
RegKey1=HKCU\Software\UsbFix\LastReport
[User Benchmark *]
LangSecRef=3024
DetectFile=%ProgramFiles%\User Benchmark\UserBenchMark.exe
Default=False
FileKey1=%SystemDrive%\UserBenchmark|*.*|REMOVESELF
[uTorrent *]
LangSecRef=3022
Detect=HKCU\Software\BitTorrent\uTorrent
Default=False
FileKey1=%AppData%\utorrent|*.log;*.dmp;*.bad;*.older;*.benc
FileKey2=%AppData%\utorrent\updates|*.exe
FileKey3=%LocalAppData%\VirtualStore\Program Files*\uTorrent|*.tmp;*.old
FileKey4=%LocalLowAppData%\uTorrentBar\Logs|*.*
FileKey5=%ProgramFiles%\uTorrent|*.tmp;*.old
[uTorrent ipfilter backup *]
LangSecRef=3022
DetectFile=%AppData%\uTorrent
Default=False
FileKey1=%AppData%\utorrent|*ipfilter.bak
[V&V Messenger Chat History *]
LangSecRef=3022
DetectFile=%AppData%\AJabber
Default=False
FileKey1=%AppData%\AJabber\*\Contacts|*.*|RECURSE
[Vampix *]
LangSecRef=3023
Detect=HKCU\Software\KC Softwares\Vampix
Default=False
FileKey1=%AppData%\KC Softwares\Vampix|*.log
[VCast *]
LangSecRef=3023
DetectFile=%LocalAppData%\V Cast Media Manager
Default=False
FileKey1=%LocalAppData%\V Cast Media Manager|*.log;backuplog.txt;logfile.txt;*.tmp|RECURSE
[VCRedist Temp Setup Files *]
LangSecRef=3021
DetectFile=%SystemDrive%\VC_RED.*
Default=False
FileKey1=%SystemDrive%|eula.1028.txt;eula.1031.txt;eula.1033.txt;eula.1036.txt;eula.1040.txt;eula.1041.txt;eula.1042.txt;eula.2052.txt;eula.3082.txt;globdata.ini;install.exe;install.ini;install.res.1028.dll;install.res.1031.dll;install.res.1033.dll;install.res.1036.dll;install.res.1040.dll;install.res.1041.dll;install.res.1042.dll;install.res.2052.dll;install.res.3082.dll;VC_RED.cab;VC_RED.MSI;vcredist.bmp
[Venis IX *]
LangSecRef=3021
Detect=HKCU\Software\Spaceblue\Venis IX
Default=False
RegKey1=HKCU\Software\Spaceblue\Venis IX\FileHistory
[Ventrilo Chat Logs *]
LangSecRef=3022
Detect=HKCU\Software\Ventrilo
Default=False
FileKey1=%AppData%\ventrilo\chatlogs|*.*|REMOVESELF
[Verizon Download Manager *]
LangSecRef=3022
DetectFile=%LocalAppData%\SupportSoft\Verizondm
Default=False
FileKey1=%LocalAppData%\SupportSoft\verizondm\*\*\logs|*.*
[Verizon In Home Assistant *]
LangSecRef=3021
DetectFile=%ProgramFiles%\Verizon\IHA_MessageCenter
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Verizon\IHA_MessageCenter\Log|mc-log;mc-log*.*
FileKey2=%ProgramFiles%\Verizon\IHA_MessageCenter\Log|mc-log;mc-log*.*
[VIA/S3G UniChrome Pro IGP *]
LangSecRef=3024
Detect=HKLM\Software\S3
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\S3\UChromeP|s3iscfg.log
FileKey2=%ProgramFiles%\S3\UChromeP|s3iscfg.log
[VideoGet *]
LangSecRef=3022
Detect=HKCU\Software\Nuclear Coffee\VideoGet
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\VideoGet\Temp|*.*
FileKey2=%ProgramFiles%\VideoGet\Temp|*.*
[VideoInspector *]
LangSecRef=3023
Detect=HKCU\Software\KC Softwares\VideoInspector
Default=False
FileKey1=%AppData%\KC Softwares\VideoInspector|*.log
[VideoMach *]
LangSecRef=3023
Detect=HKCU\Software\Gromada\VideoMach
Default=False
FileKey1=%Documents%|VideoMach_Log.txt
[Vim History *]
LangSecRef=3021
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vim
Default=False
FileKey1=%UserProfile%|_viminfo
[Violett *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\257830
Default=False
FileKey1=%ProgramFiles%\Steam\SteamApps\Common\Violett|crash.dmp;error.log;output_log.txt;report.ini|RECURSE
[VirtualBox *]
LangSecRef=3024
DetectFile=%UserProfile%\.VirtualBox
Default=False
FileKey1=%UserProfile%\.VirtualBox|VBoxSVC.log.*;VBoxSVC.*;*.log;*.log.*
FileKey2=%UserProfile%\VirtualBox VMs\*\Logs|*.log;*.log.*
[VirtualDJ *]
LangSecRef=3023
Detect=HKCU\Software\VirtualDJ
Default=False
FileKey1=%Documents%\VirtualDJ\Cache|*.*|RECURSE
[VirtualDJ Tracklist *]
LangSecRef=3023
Detect=HKCU\Software\VirtualDJ
Default=False
FileKey1=%Documents%\VirtualDJ\TrackListing|*.*
[VirtualDub *]
LangSecRef=3023
Detect=HKCU\Software\VirtualDub.org\VirtualDub
Default=False
RegKey1=HKCU\Software\VirtualDub.org\VirtualDub\MRU List
RegKey2=HKCU\Software\VirtualDub.org\VirtualDub\Saved filespecs
[VirtualDubMod *]
LangSecRef=3023
Detect=HKCU\Software\Freeware\VirtualDubMod
Default=False
RegKey1=HKCU\Software\Freeware\VirtualDubMod\MRU List
[VirtualFDD *]
LangSecRef=3024
Detect=HKCU\Software\Korbos\VirtualFDD
Default=False
RegKey1=HKCU\Software\Korbos\VirtualFDD\Recent File List
[VirtuaWin *]
LangSecRef=3021
DetectFile=%AppData%\VirtuaWin
Default=False
FileKey1=%AppData%\VirtuaWin|virtuawin.log
[Vizzed Retro Game Room *]
LangSecRef=3023
DetectFile=%LocalLowAppData%\VizzedRgr
Default=False
FileKey1=%LocalLowAppData%\VizzedRgr\Downloads|*.*|RECURSE
FileKey2=%LocalLowAppData%\VizzedRgr\Roms|*.*|RECURSE
[VLC Media Player *]
LangSecRef=3023
Detect=HKLM\Software\VideoLAN\VLC
Default=False
FileKey1=%AppData%\vlc|*.cache-3;ml.xspf.tmp*;vlc-qt-interface.ini.*
FileKey2=%AppData%\vlc\art|*.*|RECURSE
FileKey3=%AppData%\vlc\crashdump*|*.*
[VMware Player *]
LangSecRef=3024
Detect=HKLM\Software\VMware, Inc.\VMware Player
Default=False
FileKey1=%Documents%\My Virtual Machines|*.log|RECURSE
FileKey2=%LocalAppData%\VMware|*.log
[VMware Workstation *]
LangSecRef=3024
Detect=HKLM\Software\VMware, Inc.\VMware Workstation
Default=False
FileKey1=%CommonAppData%\VMware\hostd|*.log;*.gz|RECURSE
FileKey2=%CommonAppData%\VMware\Installer|*.*|REMOVESELF
FileKey3=%CommonAppData%\VMware\logs|*.log|RECURSE
FileKey4=%CommonAppData%\VMware\VMware vCenter Converter Standalone|*.log;*.gz;*.zip|RECURSE
FileKey5=%Documents%\My Virtual Machines|*.log|RECURSE
FileKey6=%LocalAppData%\VMware|*.log
FileKey7=%LocalAppData%\VMware\VMware vCenter Converter Standalone Client\Logs|*.log;*.gz
[VNCViewer 5 *]
LangSecRef=3024
Detect=HKCU\Software\RealVNC\vncviewer
Default=False
FileKey1=%LocalAppData%\RealVNC|*.log
RegKey1=HKCU\Software\RealVNC\vncviewer\MRU
[Vodafone *]
LangSecRef=3022
Detect=HKCU\Software\Vodafone
Default=False
FileKey1=%AppData%\Vodafone\Vodafone Mobile Broadband\Log|*.*
FileKey2=%CommonAppData%\Vodafone\Log|*.*
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Vodafone\Vodafone Mobile Broadband\Bin|SwiHpAux.log
FileKey4=%LocalAppData%\VirtualStore\ProgramData\Vodafone\Log|*.*
FileKey5=%ProgramFiles%\Vodafone\Vodafone Mobile Broadband\Bin|SwiHpAux.log
FileKey6=%WinDir%|ModemLog_*.txt
[Vodafone Database *]
LangSecRef=3022
Detect=HKCU\Software\Vodafone
Default=False
Warning=This will delete your incoming SMS database.
FileKey1=%AppData%\Vodafone\Vodafone Mobile Broadband\UserData|VodafoneMobileBroadband.mdb
[VoipBuster *]
LangSecRef=3022
DetectFile=%AppData%\VoipBuster
Default=False
FileKey1=%AppData%\VoipBuster|*.log
FileKey2=%WinDir%\System32|VoipBuster*.log
FileKey3=%WinDir%\SysWOW64|VoipBuster*.log
[Vopt 9 *]
LangSecRef=3024
Detect=HKCU\Software\Golden Bow Systems\Vopt
Default=False
FileKey1=%ProgramFiles%\Golden Bow\Vopt 9|Vopt.log
[VS Code *]
LangSecRef=3021
DetectFile=%AppData%\Code
Default=False
FileKey1=%AppData%\Code|cookies*
FileKey2=%AppData%\Code\GPUCache|*.*
FileKey3=%AppData%\Code\Local Storage|*.*
FileKey4=%LocalAppData%\SquirrelTemp|*.log
[VSO Batcher *]
LangSecRef=3023
Detect=HKCU\Software\VSO\VSO Batcher
Default=False
FileKey1=%AppData%\Vso\VSO Batcher\1|*.*|RECURSE
RegKey1=HKCU\Software\VSO\VSO Batcher\1|VideoFilesLastFlder
[VSO Blindwrite *]
LangSecRef=3021
Detect=HKCU\Software\VSO\Blindwrite
Default=False
FileKey1=%AppData%|pcouffin.log;ezplay.log
FileKey2=%AppData%\VSO|*.log|REMOVESELF
FileKey3=%CommonAppData%\VSO\Blindwrite\*|*.log|REMOVESELF
FileKey4=%Documents%\PcSetup|*.log|REMOVESELF
FileKey5=%LocalAppData%\VirtualStore\ProgramData\VSO\Blindwrite\*|*.log|REMOVESELF
FileKey6=%UserProfile%|timestamp.txt
[VSO Converter *]
LangSecRef=3023
Detect1=HKCU\Software\VSO\Blu-ray Converter Ultimate
Detect2=HKCU\Software\VSO\DVD Converter Ultimate
Detect3=HKCU\Software\VSO\VSO Video Converter
Default=False
FileKey1=%AppData%|pcouffin.log
FileKey2=%CommonAppData%\VSO|*.cache
FileKey3=%CommonAppData%\VSO\*Converter*\*\Log|*.log;*.crashlist|REMOVESELF
FileKey4=%CommonAppData%\VSO\vsothumbs|*.*|REMOVESELF
FileKey5=%Documents%\PcSetup|*.log|REMOVESELF
FileKey6=%LocalAppData%\VirtualStore\Program Files*\VSO\*Converter*\*|*.txt
FileKey7=%LocalAppData%\VirtualStore\ProgramData\VSO|*.cache
FileKey8=%LocalAppData%\VirtualStore\ProgramData\VSO\*Converter*\*\Log|*.log;*.crashlist|REMOVESELF
FileKey9=%LocalAppData%\VirtualStore\ProgramData\VSO\vsothumbs|*.*|REMOVESELF
FileKey10=%ProgramFiles%\VSO\*Converter*\*|*.txt
RegKey1=HKCU\Software\VSO\Blu-ray Converter Ultimate\2|BDMVInputFolders
RegKey2=HKCU\Software\VSO\Blu-ray Converter Ultimate\2|ISOInputFolders
RegKey3=HKCU\Software\VSO\Blu-ray Converter Ultimate\2|MediaLabel
RegKey4=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_audio
RegKey5=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_bluray
RegKey6=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_dvd
RegKey7=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_iso
RegKey8=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_subtitle
RegKey9=HKCU\Software\VSO\Blu-ray Converter Ultimate\3|input_MRUfiles_video
RegKey10=HKCU\Software\VSO\DVD Converter Ultimate\2|BDMVInputFolders
RegKey11=HKCU\Software\VSO\DVD Converter Ultimate\2|ISOInputFolders
RegKey12=HKCU\Software\VSO\DVD Converter Ultimate\2|MediaLabel
RegKey13=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_audio
RegKey14=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_bluray
RegKey15=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_dvd
RegKey16=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_iso
RegKey17=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_subtitle
RegKey18=HKCU\Software\VSO\DVD Converter Ultimate\3|input_MRUfiles_video
RegKey19=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_audio
RegKey20=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_bluray
RegKey21=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_dvd
RegKey22=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_iso
RegKey23=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_subtitle
RegKey24=HKCU\Software\VSO\VSO Video Converter\1|input_MRUfiles_video
[VSO ConvertXToDVD 5 *]
LangSecRef=3023
Detect=HKCU\Software\VSO\ConvertXtoDVD\5
Default=False
FileKey1=%AppData%|pcouffin.log
FileKey2=%CommonAppData%\VSO\vsothumbs|*.*|REMOVESELF
FileKey3=%LocalAppData%\VirtualStore\Program Files*\VSO\ConvertX\5|*.log;*.rtf
FileKey4=%LocalAppData%\VirtualStore\ProgramData\VSO\vsothumbs|*.*|REMOVESELF
FileKey5=%ProgramFiles%\VSO\ConvertX\5|*.log;*.rtf
[VSO CopyTo *]
LangSecRef=3021
Detect=HKCU\Software\VSO\CopyTo
Default=False
FileKey1=%AppData%|pcouffin.log;ezplay.log
FileKey2=%AppData%\VSO|*.log|REMOVESELF
FileKey3=%CommonAppData%\VSO|*.cache;*.crashlist;*.log;*.vsothumb|RECURSE
FileKey4=%Documents%\PcSetup|*.log|REMOVESELF
FileKey5=%LocalAppData%\VirtualStore\ProgramData\VSO|*.cache;*.crashlist;*.log;*.vsothumb|RECURSE
FileKey6=%UserProfile%|timestamp.txt
[VSO Downloader *]
LangSecRef=3023
Detect=HKCU\Software\VSO\VSO Downloader
Default=False
FileKey1=%AppData%\VSO|*.log
FileKey2=%AppData%\VSO\VSO Downloader\*\items|*.item|RECURSE
FileKey3=%CommonAppData%\VSO\VSO Downloader\*\items|*.item|RECURSE
FileKey4=%CommonAppData%\VSO\VSO Downloader\*\log|*.log
FileKey5=%LocalAppData%\VirtualStore\ProgramData\VSO\VSO Downloader\*\items|*.item|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\VSO\VSO Downloader\*\log|*.log
[VSO Media Player 1 *]
LangSecRef=3023
Detect=HKCU\Software\VSO\VSO Media Player\1
Default=False
FileKey1=%AppData%\VSO\VSO Media Player\1|autoresume.xml
FileKey2=%CommonAppData%\VSO|font.cache
FileKey3=%CommonAppData%\VSO\VSO Media Player\1\log|*.log;*.crashlist
FileKey4=%CommonAppData%\VSO\vsothumbs|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\ProgramData\VSO|font.cache
FileKey6=%LocalAppData%\VirtualStore\ProgramData\VSO\VSO Media Player\1\log|*.log;*.crashlist
FileKey7=%LocalAppData%\VirtualStore\ProgramData\VSO\vsothumbs|*.*|RECURSE
RegKey1=HKCU\Software\VSO\VSO Media Player\1\RecentlyOpenedFiles
[VueScan *]
LangSecRef=3024
DetectFile1=%ProgramFiles%\VueScan
DetectFile2=%SystemDrive%\VueScan
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\VueScan|*.log|RECURSE
FileKey2=%ProgramFiles%\VueScan|*.log|RECURSE
FileKey3=%SystemDrive%\VueScan|*.log|RECURSE
[Vuze *]
LangSecRef=3022
Detect=HKCR\Azureus
Default=False
FileKey1=%AppData%\Azureus\plugins\advancedstatistics|*.txt
FileKey2=%AppData%\Azureus\plugins\progressbar|*.txt
FileKey3=%ProgramFiles%\Vuze|*.log
FileKey4=%ProgramFiles%\Vuze\.install4j|*.log
[Vuze Dasu Reports *]
LangSecRef=3022
Detect=HKCR\Azureus
Default=False
Warning=This will delete data from Dasu plugins. You should review the Dasu plugin reports before deleting it.
FileKey1=%AppData%\Azureus\plugins\dasu\reports|*.*
[W3i *]
LangSecRef=3022
DetectFile=%CommonAppData%\W3i
Default=False
FileKey1=%CommonAppData%\W3i\InstallQUpdater|*.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\W3i\InstallQUpdater|*.log
[Walgreens PhotoShow Express CD *]
LangSecRef=3021
DetectFile=%AppData%\Walgreens\PhotoShow Express CD
Default=False
FileKey1=%AppData%\Walgreens\Photoshow Express CD\Cache|*.*|RECURSE
[Wallpaper Juggler *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Wallpaper Juggler
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Wallpaper Juggler|*.log
FileKey2=%ProgramFiles%\Wallpaper Juggler|*.log
[WallWatcher *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Wall Watcher\WallWatcher.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Wall Watcher\Logs|*.*
FileKey2=%ProgramFiles%\Wall Watcher\Logs|*.*
[War of the Human Tanks *]
Section=Games
DetectFile=%ProgramFiles%\Desura\Common\war-of-the-human-tanks
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Desura\Common\war-of-the-human-tanks\LOG|*.*
FileKey2=%ProgramFiles%\Desura\Common\war-of-the-human-tanks\LOG|*.*
[War Thunder *]
Section=Games
Detect1=HKCU\Software\Gaijin\WarThunder
Detect2=HKCU\Software\Valve\Steam\Apps\236390
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\War Thunder\.launcher_log|*.txt
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Steam\SteamApps\common\War Thunder\_debuginfo|*.clog
FileKey3=%LocalAppData%\VirtualStore\Program Files*\War Thunder\.launcher_log|*.txt
FileKey4=%LocalAppData%\VirtualStore\Program Files*\War Thunder\_debuginfo|*.clog
FileKey5=%ProgramFiles%\Steam\SteamApps\common\War Thunder\.launcher_log|*.txt
FileKey6=%ProgramFiles%\Steam\SteamApps\common\War Thunder\_debuginfo|*.clog
FileKey7=%ProgramFiles%\War Thunder\.launcher_log|*.txt
FileKey8=%ProgramFiles%\War Thunder\_debuginfo|*.clog
[Warcraft III *]
Section=Games
Detect=HKLM\Software\Blizzard Entertainment\Warcraft III
DetectFile=%ProgramFiles%\Warcraft III\Warcraft III.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Warcraft III|*.log;*.html
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Warcraft III\Errors|*.dmp;*.txt
FileKey3=%ProgramFiles%\Warcraft III|*.log;*.html
FileKey4=%ProgramFiles%\Warcraft III\Errors|*.dmp;*.txt
ExcludeKey1=PATH|%ProgramFiles%\Warcraft III\|*CustomKeyInfo.txt;*CustomKeysSample.txt
[Warcraft III Backup Files *]
Section=Games
Detect=HKLM\Software\Blizzard Entertainment\Warcraft III
Default=False
Warning=This will delete all your Warcraft III backup files. You won't be able to restore from them if something goes wrong.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Warcraft III|*.bak;*.old|RECURSE
FileKey2=%ProgramFiles%\Warcraft III|*.bak;*.old|RECURSE
[Warframe *]
Section=Games
Detect=HKCU\Software\Digital Extremes\Warframe
Default=False
FileKey1=%LocalAppData%\Warframe|*.log
[Warhammer 40000: Dawn of War Gold *]
Section=Games
Detect=HKCU\Software\Valve\Steam\Apps\4570
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Steam\steamapps\common\Dawn of War Gold\Logfiles|*.*
FileKey2=%ProgramFiles%\Steam\steamapps\common\Dawn of War Gold\Logfiles|*.*
[WashAndGo *]
LangSecRef=3024
DetectFile=%LocalAppData%\Abelssoft\WashAndGo
Default=False
FileKey1=%AppData%\Abelssoft\WashAndGo\Log|*.log
[WashAndGo Backups *]
LangSecRef=3024
DetectFile=%LocalAppData%\Abelssoft\WashAndGo
Default=False
FileKey1=%Documents%\Abelssoft\WashAndGo\Backups|*.*
FileKey2=%LocalAppData%\Abelssoft\WashAndGo\Backups|*.*
[Wave Systems Corp *]
LangSecRef=3021
DetectFile=%AppData%\Wave Systems Corp
Default=False
FileKey1=%AppData%\Wave Systems Corp|DSM_AM.*
FileKey2=%CommonAppData%\Wave Systems Corp|*.log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Wave Systems Corp|*.log|RECURSE
FileKey4=%LocalAppData%\Wave Systems Corp\WCLIENTDLL|errors.txt
[WavePad *]
LangSecRef=3023
Detect=HKCU\Software\NCH Software\WavePad
Default=False
RegKey1=HKCU\Software\NCH Software\WavePad\Recent
[Wavosaur *]
LangSecRef=3023
DetectFile=%ProgramFiles%\Wavosaur\wavosaur.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Wavosaur|wavosaur.log
FileKey2=%ProgramFiles%\Wavosaur|wavosaur.log
[Weather *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingWeather_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CLR_v4.0|*.log
FileKey4=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\PRICache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingWeather_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState|*.tmp
FileKey10=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.BingWeather_*\LocalState\navigationHistory|*.*|RECURSE
FileKey12=%LocalAppData%\Packages\Microsoft.BingWeather_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingWeather_8wekyb3d8bbwe\SearchHistory
[Weather It Up *]
LangSecRef=3024
Detect=HKLM\Software\Weather It Up
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Weather It Up|*.log
FileKey2=%ProgramFiles%\Weather It Up|*.log
[Weather Watcher Live *]
LangSecRef=3021
Detect=HKCU\Software\VB and VBA Program Settings\Weather Watcher Live
Default=False
FileKey1=%AppData%\WeatherWatcherLive|WeatherWatcherLive.log
FileKey2=%AppData%\WeatherWatcherLive\Temp|*.*
[Web Sling Player *]
LangSecRef=3023
DetectFile=%AppData%\Sling Media\WebSlingPlayer
Default=False
FileKey1=%AppData%\Sling Media\WebSlingPlayer|*.txt;*.log
FileKey2=%AppData%\Sling Media\WebSlingPlayer\*_cache|*.*|RECURSE
FileKey3=%AppData%\Sling Media\WebSlingPlayer\temp|*.*|RECURSE
[WebConnect *]
LangSecRef=3023
DetectFile=%LocalAppData%\Ericom
Default=False
FileKey1=%LocalAppData%\Ericom\Ptagent|*.*
FileKey2=%LocalAppData%\Ericom\PtRdp|*.*
[WebMon *]
LangSecRef=3022
Detect=HKCU\Software\CM\WebMon
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WebMon|UpdateLog.*
FileKey2=%ProgramFiles%\WebMon|UpdateLog.*
[WebPI Installer *]
LangSecRef=3025
DetectFile=%LocalAppData%\Microsoft\Web Platform Installer\logs\webpi
Default=False
FileKey1=%LocalAppData%\Microsoft\Web Platform Installer\logs\webpi|*.txt
[WebPictures Downloader *]
LangSecRef=3022
DetectFile=%ProgramFiles%\WebPictures Downloader
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WebPictures Downloader\Projects|*.*|RECURSE
FileKey2=%ProgramFiles%\WebPictures Downloader\Projects|*.*|RECURSE
[WebReaper *]
LangSecRef=3022
Detect=HKCU\Software\BlueBeam\WebReaper
Default=False
RegKey1=HKCU\Software\BlueBeam\WebReaper\URL History
[Webroot SecureAnywhere *]
LangSecRef=3024
DetectFile=%ProgramFiles%\Webroot\WRSA.exe
Default=False
FileKey1=%CommonAppData%\WRData|WRLog.log
FileKey2=%LocalAppData%\VirtualStore\ProgramData\WRData|WRLog.log
[WebStorm *]
LangSecRef=3021
Detect=HKCU\Software\JetBrains\WebStorm
Default=False
FileKey1=%UserProfile%\.WebIde50\system\Caches|*.*|RECURSE
FileKey2=%UserProfile%\.WebIde50\system\LocalHistory|*.*|RECURSE
FileKey3=%UserProfile%\.WebIde50\system\Log|*.*|RECURSE
FileKey4=%UserProfile%\.WebIde50\system\tmp|*.*|RECURSE
[WebTorrent *]
LangSecRef=3022
DetectFile=%AppData%\WebTorrent
Default=False
FileKey1=%AppData%\WebTorrent\*Cache|*.*
FileKey2=%LocalAppData%\WebTorrent|*.log
[WeFi *]
LangSecRef=3024
DetectFile=%ProgramFiles%\WeFi
Default=False
FileKey1=%CommonAppData%\WeFi\LogFiles|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\ProgramData\WeFi\LogFiles|*.*|REMOVESELF
[Western Digital Firmware Updater *]
LangSecRef=3024
DetectFile=%CommonAppData%\Western Digital
Default=False
FileKey1=%CommonAppData%\Western Digital\Logs\WD Firmware Updater|*.*|REMOVESELF
[Western Digital SmartWare *]
LangSecRef=3024
DetectFile=%CommonAppData%\Western Digital
Default=False
FileKey1=%AppData%\Western Digital\WD SmartWare\Logs|*.*
FileKey2=%CommonAppData%\Western Digital\Logs\WD *\*|*.log
FileKey3=%CommonAppData%\Western Digital\WD SmartWare|*.log
FileKey4=%CommonAppData%\Western Digital\WDFME|*.*
FileKey5=%LocalAppData%\VirtualStore\ProgramData\Western Digital\WD SmartWare|*.log
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Western Digital\WDFME|*.*
FileKey7=%LocalAppData%\Western Digital\WD SmartWare|*log.txt
FileKey8=%Public%\Documents\Downloads\WD_SmartWare_Installer_*|*.*|REMOVESELF
[WhatPulse *]
LangSecRef=3021
Detect=HKCU\Software\WhatPulse
Default=False
FileKey1=%AppData%\WhatPulse|*.log
[WhatPulse Backups *]
LangSecRef=3021
Detect=HKCU\Software\WhatPulse
Default=False
FileKey1=%AppData%\WhatPulse|*.bak
[Who's On My Wifi *]
LangSecRef=3022
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{010D45A1-093D-4534-8147-4E10E80F81CC}_is1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\IO3O LLC\Who Is On My Wifi\logs|*.*
FileKey2=%ProgramFiles%\IO3O LLC\Who Is On My Wifi\logs|*.*
[WildTangent *]
LangSecRef=3021
DetectFile=%AppData%\WildTangent
Default=False
FileKey1=%AppData%\WildTangent\Logs|*.*
[Winamp *]
LangSecRef=3023
Detect=HKCU\Software\Winamp
Default=False
Warning=This removes the current playlist.
FileKey1=%AppData%\Winamp|Winamp.m3u;Winamp.m3u8
[WinAVI Video Converter *]
LangSecRef=3023
Detect=HKCU\Software\ZjSoft\WinAVI
Default=False
FileKey1=%LocalAppData%\winavi|debug.log
[WinCHM *]
LangSecRef=3021
Detect=HKCU\Software\Softany\WinCHM
Default=False
RegKey1=HKCU\Software\Softany\WinCHM|RecentFile1
RegKey2=HKCU\Software\Softany\WinCHM|RecentFile2
RegKey3=HKCU\Software\Softany\WinCHM|RecentFile3
RegKey4=HKCU\Software\Softany\WinCHM|RecentFile4
RegKey5=HKCU\Software\Softany\WinCHM|RecentFile5
RegKey6=HKCU\Software\Softany\WinCHM|RecentFile6
[Windows 7 Manager *]
LangSecRef=3024
Detect=HKCU\Software\Yamicsoft\Windows 7 Manager
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Yamicsoft\Windows 7 Manager\DiskAnalyzerXML|*.*
FileKey2=%ProgramFiles%\Yamicsoft\Windows 7 Manager\DiskAnalyzerXML|*.*
[Windows Communications Apps *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Comms\Unistore\data|AggregateCache.uca
FileKey2=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\AppCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\INet*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\PRICache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\AC\Temp|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\LocalState\LiveComm\*\*\DBStore\LogFiles|edbtmp.log
FileKey10=%LocalAppData%\Packages\microsoft.windowscommunicationsapps_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SearchHistory
[Windows Defender *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows Defender
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows Defender\Network Inspection System\Support|*.txt
FileKey2=%CommonAppData%\Microsoft\Windows Defender\Scans|*.bin*
FileKey3=%CommonAppData%\Microsoft\Windows Defender\Scans\History\CacheManager|*.*|RECURSE
FileKey4=%CommonAppData%\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency|*.*|RECURSE
FileKey5=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Service|*.log
FileKey6=%CommonAppData%\Microsoft\Windows Defender\Scans\MetaStore|*.*|RECURSE
FileKey7=%CommonAppData%\Microsoft\Windows Defender\Support|*.*|RECURSE
[Windows DVD Maker *]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings
Default=False
RegKey1=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\Browse 2
RegKey2=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\Browse 5
RegKey3=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\Browse 7
RegKey4=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\Browse 128
RegKey5=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\MRU0
RegKey6=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\MRU1
RegKey7=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\MRU2
RegKey8=HKCU\Software\Microsoft\Microsoft DVD Wizard Settings\MRU3
[Windows Error Reporting *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\Windows Error Reporting
Default=False
FileKey1=%LocalAppData%\PCHealth\ErrorRep\QSignoff|*.*
FileKey2=%WinDir%\pchealth\ERRORREP|*.*|RECURSE
FileKey3=%WinDir%\pchealth\helpctr\DataColl|*.xml
FileKey4=%WinDir%\pchealth\helpctr\OfflineCache|*.*|RECURSE
FileKey5=%WinDir%\System32\config\systemprofile\AppData\Local\CrashDumps|*.dmp
FileKey6=%WinDir%\System32\config\systemprofile\Local Settings\Application Data\CrashDumps|*.dmp
FileKey7=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\CrashDumps|*.dmp
FileKey8=%WinDir%\SysWOW64\config\systemprofile\Local Settings\Application Data\CrashDumps|*.dmp
RegKey1=HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation
RegKey2=HKLM\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation
RegKey3=HKLM\Software\Microsoft\Windows\Windows Error Reporting\FullLiveKernelReports|LastFullLiveReport
RegKey4=HKLM\Software\Microsoft\Windows\Windows Error Reporting\FullLiveKernelReports\win32k.sys
RegKey5=HKLM\Software\Microsoft\Windows\Windows Error Reporting\LiveKernelReports\win32k.sys
RegKey6=HKLM\Software\Microsoft\Windows\Windows Error Reporting\LocalDumps
RegKey7=HKU\.DEFAULT\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation
[Windows ESENT *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\ESENT
Default=False
RegKey1=HKLM\Software\Microsoft\ESENT\Process
[Windows Experience Index *]
DetectOS=10.0|
LangSecRef=3025
Default=False
FileKey1=%WinDir%\Performance\WinSAT|*.*
FileKey2=%WinDir%\Performance\WinSAT\DataStore|*.*
[Windows Feedback *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WindowsFeedback_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0*|*.log
FileKey4=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CLR_v4.0*\UsageLogs|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\Temp|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\LocalCache|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\LocalState\Cache|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.WindowsFeedback_*\TempState|*.*|RECURSE
[Windows Image Acquisition *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\WIA
Default=False
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\WIA
[Windows Installer *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Installer
Default=False
FileKey1=%SystemDrive%\Config.msi|*.*|REMOVESELF
FileKey2=%WinDir%\Installer|*.tmp|RECURSE
FileKey3=%WinDir%\Installer|SourceHash{*};wix{*}.SchedServiceConfig.rmi
FileKey4=%WinDir%\Installer\MSI*.tmp-|*.*|REMOVESELF
[Windows Live Mail *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows Live Mail
Default=False
Warning=This will reset the read counts, which will be recalculated when WLMail is started.
FileKey1=%LocalAppData%\Microsoft\Windows*Mail|*.log;*.jrs;*.chk;*.rss;*.tmp|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows*Mail\*|*.MSMessageStore|RECURSE
FileKey3=%LocalAppData%\Microsoft\Windows*Mail\*.tmp|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Windows*Mail\*\Backup|*.*|REMOVESELF
FileKey5=%LocalAppData%\Microsoft\Windows*Mail\Backup|*.*|REMOVESELF
RegKey1=HKCU\Software\Microsoft\Windows Live Mail|SearchFolderVersion
[Windows Live Messenger *]
LangSecRef=3022
Detect=HKLM\Software\Microsoft\Windows Live\Messenger
Default=False
FileKey1=%CommonProgramFiles%\Windows Live\.cache|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Messenger|*.uccapilog;*.bak;*.txt|RECURSE
FileKey3=%LocalAppData%\Microsoft\Windows Live|*.log;*.jrs;*.sqm|RECURSE
FileKey4=%LocalAppData%\Microsoft\Windows Live Contacts|*.log;*.jrs|RECURSE
FileKey5=%LocalAppData%\Microsoft\Windows Live Contacts\*\*\*\Backup|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Common Files\Windows Live\.cache|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Windows Live\Messenger|*.bak|RECURSE
FileKey8=%ProgramFiles%\Windows Live\Messenger|*.bak|RECURSE
FileKey9=%WinDir%\System32\config\systemprofile\Documents|wlidsvctrace*.txt
FileKey10=%WinDir%\SysWOW64\config\systemprofile\Documents|wlidsvctrace*.txt
[Windows Live Messenger Chat History *]
LangSecRef=3022
Detect=HKLM\Software\Microsoft\Windows Live\Messenger
Default=False
Warning=Removes Windows Live Messenger chat history!
FileKey1=%Documents%\*\*\Histor*|*.*
[Windows Live Messenger Setup Files *]
LangSecRef=3022
Detect=HKLM\Software\Microsoft\Windows Live\Messenger
Default=False
Warning=After running this, you will not be able to uninstall Windows Live Essentials components without downloading the installer again.
FileKey1=%LocalLowAppData%\Microsoft\Windows Live\Setup|*.*|REMOVESELF
[Windows Live Movie Maker *]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\Windows Live\Movie Maker
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows Live Movie Maker|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows Live\Movie Maker|browseformusicdirectory
RegKey2=HKCU\Software\Microsoft\Windows Live\Movie Maker|browseforpicturesdirectory
RegKey3=HKCU\Software\Microsoft\Windows Live\Movie Maker|browseforprojectsdirectory
RegKey4=HKCU\Software\Microsoft\Windows Live\Movie Maker|rendertofiledirectory
RegKey5=HKCU\Software\Microsoft\Windows Live\Movie Maker|snapshotfiledirectory
RegKey6=HKCU\Software\Microsoft\Windows Live\Movie Maker\recent
[Windows Live Photo Gallery *]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\Windows Live\Photo Gallery
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows Live Photo Gallery|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Windows Live\Photo Aquisition\Camera|FinenameTemplate
RegKey2=HKCU\Software\Microsoft\Windows Live\Photo Aquisition\Camera|RootDirectory
RegKey3=HKCU\Software\Microsoft\Windows Live\Photo Gallery|galleryscopedfolders
[Windows Live Setup *]
LangSecRef=3022
Detect1=HKCU\Software\Microsoft\Windows Live Mail
Detect2=HKLM\Software\Microsoft\Windows Live
Default=False
FileKey1=%CommonAppData%\Microsoft\WLSetup|*.tmp
FileKey2=%CommonAppData%\Microsoft\WLSetup\*logs|*.*|RECURSE
FileKey3=%CommonAppData%\WLInstaller|*.log
FileKey4=%CommonProgramFiles%\Windows Live\.cache|*.tmp
FileKey5=%LocalAppData%\Microsoft\WLSetup\*logs|*.*|RECURSE
FileKey6=%LocalAppData%\VirtualStore\ProgramData\Microsoft\WLSetup|*.tmp
FileKey7=%LocalAppData%\VirtualStore\ProgramData\Microsoft\WLSetup\*logs|*.*|RECURSE
FileKey8=%LocalAppData%\VirtualStore\ProgramData\WLInstaller|*.log
[Windows Live Writer *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows Live Writer
Default=False
FileKey1=%LocalAppData%\Windows Live Writer|*.log
[Windows Logs *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\Network\Downloader|*.*|RECURSE
FileKey2=%CommonAppData%\Microsoft\Windows Security Health\Logs|*.*|RECURSE
FileKey3=%CommonAppData%\USOShared\Logs|*.*|RECURSE
FileKey4=%LocalAppData%\ConnectedDevicesPlatform|*.log
FileKey5=%LocalAppData%\Diagnostics|*.*|RECURSE
FileKey6=%ProgramFiles%\UNP\Logs|*.*
FileKey7=%SystemDrive%\PerfLogs\System\Diagnostics|*.*|RECURSE
FileKey8=%SystemDrive%\PerfLogs\System\Performance|*.*|RECURSE
FileKey9=%WinDir%\debug\WIA|*.log
FileKey10=%WinDir%\inf|*.log*
FileKey11=%WinDir%\Logs\CBS|*.cab
FileKey12=%WinDir%\Logs\dosvc|*.*|RECURSE
FileKey13=%WinDir%\Logs\NetSetup|*.*|RECURSE
FileKey14=%WinDir%\Logs\SIH|*.*|RECURSE
FileKey15=%WinDir%\Logs\WindowsBackup|*.etl
FileKey16=%WinDir%\Panther|cbs.log;DDACLSys.log;miglog.xml;Migrep.html;PostGatherPnPList.log;PreGatherPnPList.log
FileKey17=%WinDir%\Panther\FastCleanup|*.log
FileKey18=%WinDir%\Panther\Rollback|*.txt
FileKey19=%WinDir%\Panther\UnattendGC|diagerr.xml;diagwrn.xml
FileKey20=%WinDir%\repair|setup.log
FileKey21=%WinDir%\security\logs|*.*|RECURSE
FileKey22=%WinDir%\System32\catroot2|*.chk;*.log;*.jrs;*.txt
FileKey23=%WinDir%\System32\LogFiles\HTTPERR|*.log
FileKey24=%WinDir%\System32\LogFiles\Scm|*.*|RECURSE
FileKey25=%WinDir%\System32\LogFiles\setupcln|*.*|RECURSE
FileKey26=%WinDir%\System32\LogFiles\Srt|*.*|RECURSE
FileKey27=%WinDir%\System32\LogFiles\WMI|*.*|RECURSE
FileKey28=%WinDir%\System32\SleepStudy|*.etl
FileKey29=%WinDir%\System32\SleepStudy\ScreenOn|*.etl
FileKey30=%WinDir%\System32\sysprep\Panther\IE|diagerr.xml;diagwrn.xml;*.log
FileKey31=%WinDir%\System32\WDI\*|snapshot.etl|REMOVESELF
FileKey32=%WinDir%\System32\WDI\LogFiles\StartupInfo|*.*|RECURSE
RegKey1=HKLM\Software\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications
RegKey2=HKLM\Software\Microsoft\Tracing
RegKey3=HKLM\Software\Wow6432Node\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications
RegKey4=HKLM\Software\Wow6432Node\Microsoft\Tracing
[Windows Mail *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows Mail
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows Mail|*.log;*.jrs;*.chk|RECURSE
[Windows Media Center *]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center
Default=False
FileKey1=%CommonAppData%\Microsoft\eHome\thmb|TVThumb.db
FileKey2=%LocalAppData%\Microsoft\Ehome|Image.db;Video.db;musicThumbs.db
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Microsoft\eHome\thmb|TVThumb.db
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\MRU\SettingsMRU
[Windows Movie Maker *]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MovieMaker
Default=False
FileKey1=%LocalAppData%\Microsoft\Movie Maker|MEDIATAB*.DAT
[Windows MUICache *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
RegKey2=HKCU\Software\Microsoft\Windows\Shell\MUICache
RegKey3=HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache
[Windows Photo Gallery *]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\Windows Photo Gallery
Default=False
RegKey1=HKCU\Software\Microsoft\Windows Photo Gallery\Library\PreviewAssignment\MRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\Camera|FilenameTemplate
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\Camera|RootDirectory
RegKey4=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\DestinationMru
RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\OpticalMedia|FilenameTemplate
RegKey6=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\OpticalMedia|RootDirectory
RegKey7=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\Scanner|FilenameTemplate
RegKey8=HKCU\Software\Microsoft\Windows\CurrentVersion\Photo Aquisition\Scanner|RootDirectory
[Windows Photo Viewer *]
LangSecRef=3025
DetectFile=%AppData%\Microsoft\Windows Photo Viewer
Default=False
FileKey1=%AppData%\Microsoft\Windows Photo Viewer|*.*
[Windows Photos *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowsphotos_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\microsoft.windowsphotos_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\BackgroundTransferApi|*.down_data;*.up_meta
FileKey3=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\INet*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey6=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\PRICache|*.*
FileKey8=%LocalAppData%\Packages\microsoft.windowsphotos_*\AC\Temp|*.*
FileKey9=%LocalAppData%\Packages\microsoft.windowsphotos_*\LocalState|*.log;*.jpg
FileKey10=%LocalAppData%\Packages\microsoft.windowsphotos_*\LocalState\bici|*.sqm
FileKey11=%LocalAppData%\Packages\microsoft.windowsphotos_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft.windowsphotos_8wekyb3d8bbwe\SearchHisto
[Windows Registry Recovery *]
LangSecRef=3024
Detect=HKCU\Software\MiTeC\WRR
Default=False
RegKey1=HKCU\Software\MiTeC\WRR\1.x\dlg_wrr_Find\eFind_Items
RegKey2=HKCU\Software\MiTeC\WRR\1.x\Main\MRUHistory
[Windows Retail Demo *]
LangSecRef=3025
DetectFile=%CommonAppData%\Microsoft\Windows\RetailDemo
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows\RetailDemo|*.*|REMOVESELF
[Windows ShellBags *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
Warning=This will reset folders size, view, icon or position settings to default and remove traces of the folders that do not exist anymore.
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags
RegKey3=HKCU\Software\Microsoft\Windows\Shell\BagMRU
RegKey4=HKCU\Software\Microsoft\Windows\Shell\Bags
RegKey5=HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU
RegKey6=HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
ExcludeKey1=REG|HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey2=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop
ExcludeKey3=REG|HKCU\Software\Microsoft\Windows\Shell\Bags\AllFolders
ExcludeKey4=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Desktop
ExcludeKey5=REG|HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\AllFolders
[Windows Sidebar *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows Sidebar
Default=False
FileKey1=%LocalAppData%\Microsoft\Windows Sidebar\Cache|*.*|RECURSE
[Windows Store *]
DetectOS=6.2|6.3
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\winstore_cw5n1h2txyewy
DetectFile=%LocalAppData%\Packages\winstore_cw5n1h2txyewy
Default=False
FileKey1=%LocalAppData%\Packages\winstore_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\winstore_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\winstore_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\winstore_*\AC\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\winstore_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\winstore_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\winstore_*\LocalState\LiveTile|*.*|RECURSE
[Windows Subsystems *]
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows
Default=False
FileKey1=%CommonAppData%\Microsoft\PlayReady|*.hds
FileKey2=%CommonAppData%\Microsoft\PlayReady\Cache|*.*
FileKey3=%CommonAppData%\Microsoft\RAC\PublishedData|*.log;*.jrs
FileKey4=%CommonAppData%\Microsoft\RAC\StateData|*.log;*.jrs
FileKey5=%CommonAppData%\Microsoft\RAC\Temp|*.*
FileKey6=%CommonAppData%\Microsoft\Windows\DRM|*.log
FileKey7=%CommonAppData%\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey8=%CommonAppData%\Microsoft\Windows\DRM\PreUpgrade|*.log
FileKey9=%CommonAppData%\Microsoft\Windows\Sqm\Manifest|*.bin
FileKey10=%CommonAppData%\Microsoft\Windows\Sqm\Sessions|*.psqm;*.sqm
FileKey11=%LocalAppData%\Microsoft\Windows\PRICache|*.*|RECURSE
FileKey12=%LocalAppData%\Microsoft\Windows\SettingSync\metastore|*.jrs
FileKey13=%LocalAppData%\Microsoft\Windows\SettingSync\remotemetastore\*|*.jrs
FileKey14=%LocalAppData%\VirtualStore\ProgramData\Microsoft\PlayReady|*.hds
FileKey15=%LocalAppData%\VirtualStore\ProgramData\Microsoft\PlayReady\Cache|*.*
FileKey16=%LocalAppData%\VirtualStore\ProgramData\Microsoft\RAC\PublishedData|*.log;*.jrs
FileKey17=%LocalAppData%\VirtualStore\ProgramData\Microsoft\RAC\StateData|*.log;*.jrs
FileKey18=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM|*.log
FileKey19=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\Cache|*.*|RECURSE
FileKey20=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\DRM\PreUpgrade|*.log
FileKey21=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\Sqm\Manifest|*.bin
FileKey22=%LocalAppData%\VirtualStore\ProgramData\Microsoft\Windows\Sqm\Sessions|*.psqm;*.sqm
FileKey23=%SystemDrive%\spoolerlogs|spooler.xml
FileKey24=%WinDir%\ehome|PRDMOWrapper.log
FileKey25=%WinDir%\System32|PRDMOWrapper.log
FileKey26=%WinDir%\system32\spool|spooler.xml
FileKey27=%WinDir%\System32\sru|*.*|RECURSE
RegKey1=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
RegKey2=HKCU\Software\Classes\VirtualStore\MACHINE\Software\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication
RegKey3=HKCU\Software\Microsoft\Direct3D\MostRecentApplication
RegKey4=HKLM\Software\Microsoft\Direct3D\MostRecentApplication
RegKey5=HKLM\Software\Microsoft\DirectDraw\MostRecentApplication
RegKey6=HKLM\Software\Microsoft\Windows\CurrentVersion\Setup|Installation Sources
RegKey7=HKLM\Software\Wow6432Node\Microsoft\Direct3D\MostRecentApplication
RegKey8=HKLM\Software\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication
[Windows Update *]
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\WindowsUpdate
Default=False
FileKey1=%WinDir%\Logs\waasmedic|*.*|RECURSE
FileKey2=%WinDir%\Logs\WindowsUpdate|*.*|RECURSE
FileKey3=%WinDir%\SoftwareDistribution\DataStore\Logs|*.*|RECURSE
[Windows Washer Backups *]
LangSecRef=3024
Detect=HKCU\Software\Webroot\Window Washer
Default=False
FileKey1=%AppData%\Webroot\Washer\Backup|*.*|RECURSE
[Windows XP ARPCache *]
DetectOS=|5.1
LangSecRef=3025
Detect=HKLM\Software\Microsoft\Windows
Default=False
Warning=This cleans the Add/Remove Programs cache and will fix very large areas of black gaps in it. Using this will cause Add/Remove Programs to take a very long time to load since it will have to rebuild the cache.
RegKey1=HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache
[Winemaker Extraordinaire *]
Section=Games
DetectFile=%AppData%\UClick\Winemaker Extraordinaire
Default=False
FileKey1=%AppData%\UClick\Winemaker Extraordinaire|logfile.txt
[WinGate *]
LangSecRef=3021
Detect=HKCU\Software\Qbik Software\GateKeeper
DetectFile=%ProgramFiles%\WinGate\WinGate.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinGate|*Log.txt;*.log|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\WinGate\Logs\Global|*.idx
FileKey3=%ProgramFiles%\WinGate|*Log.txt;*.log|RECURSE
FileKey4=%ProgramFiles%\WinGate\Logs\Global|*.idx
[WinHasher *]
LangSecRef=3024
Detect=HKCU\Software\GPF Comics\WinHasher
Default=False
RegKey1=HKCU\Software\GPF Comics\WinHasher|LastDirectory
[WinHTTrack *]
LangSecRef=3022
Detect=HKCU\Software\WinHTTrack Website Copier
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinHTTrack|winhttrack.log
FileKey2=%ProgramFiles%\WinHTTrack|winhttrack.log
[WinImage *]
LangSecRef=3024
Detect=HKCU\Software\WinImage
Default=False
RegKey1=HKCU\Software\WinImage|File1
RegKey2=HKCU\Software\WinImage|File2
RegKey3=HKCU\Software\WinImage|File3
RegKey4=HKCU\Software\WinImage|File4
RegKey5=HKCU\Software\WinImage|File5
RegKey6=HKCU\Software\WinImage|File6
RegKey7=HKCU\Software\WinImage|File7
RegKey8=HKCU\Software\WinImage|File8
RegKey9=HKCU\Software\WinImage|File9
RegKey10=HKCU\Software\WinImage|PathExtract
[WinJS *]
LangSecRef=3031
Detect1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WinJS.1.0_8wekyb3d8bbwe
Detect2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.WinJS.2.0_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.WinJS.*.0_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\PRICache|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\LocalState\*Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\LocalState\navigationHistory|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.WinJS.*.*_*\TempState|*.*|RECURSE
[WinMerge *]
LangSecRef=3024
Detect=HKCU\Software\Thingamahoochie\WinMerge\Files
Default=False
RegKey1=HKCU\Software\Thingamahoochie\WinMerge\Files\Ext
RegKey2=HKCU\Software\Thingamahoochie\WinMerge\Files\Left
RegKey3=HKCU\Software\Thingamahoochie\WinMerge\Files\Option
RegKey4=HKCU\Software\Thingamahoochie\WinMerge\Files\Right
[WinMount *]
LangSecRef=3024
DetectFile=%ProgramFiles%\WinMount\WinMount.exe
Default=False
FileKey1=%AppData%\WinMount|*.dat
[WinPcap *]
LangSecRef=3022
Detect=HKLM\Software\WinPcap
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinPcap|*.log
FileKey2=%ProgramFiles%\WinPcap|*.log
[WinRAR *]
LangSecRef=3024
Detect=HKCU\Software\WinRAR
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinRAR|*.tmp|RECURSE
FileKey2=%ProgramFiles%\WinRAR|*.tmp|RECURSE
RegKey1=HKCU\Software\WinRAR SFX
RegKey2=HKCU\Software\WinRAR\DialogEditHistory
RegKey3=HKCU\Software\WinRAR\General\Info|CommentFile
[WinRemote *]
LangSecRef=3021
DetectFile=%CommonAppData%\Banamalon\WinRemoteService
Default=False
FileKey1=%CommonAppData%\Banamalon\WinRemoteService\log|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Banamalon\WinRemoteService\log|*.*
[WinSAT Shader Cache *]
DetectOS=|6.2
LangSecRef=3025
DetectFile=%WinDir%\Performance\WinSAT
Default=False
FileKey1=%WinDir%\Performance\WinSAT|shadercache*.*
[WinSetupFromUSB *]
LangSecRef=3024
DetectFile1=%ProgramFiles%\WinSetupFromUSB
DetectFile2=%SystemDrive%\WinSetupFromUSB
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinSetupFromUSB|*.log|RECURSE
FileKey2=%ProgramFiles%\WinSetupFromUSB|*.log|RECURSE
FileKey3=%SystemDrive%\WinSetupFromUSB|*.log|RECURSE
[WinTK *]
LangSecRef=3024
DetectFile=%Documents%\WinTK
Default=False
FileKey1=%Documents%\WinTK|ExLog.txt
[WinToUSB *]
LangSecRef=3024
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinToUSB_is1
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WinToUSB\bin|*.log
FileKey2=%ProgramFiles%\WinToUSB\bin|*.log
[WinWAP *]
LangSecRef=3022
Detect=HKCU\Software\Winwap Technologies
Default=False
FileKey1=%UserProfile%\WinWAP Temporary Files|*.*
[WinX YouTube Downloader *]
LangSecRef=3023
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinX YouTube Downloader_is1
DetectFile=%ProgramFiles%\Digiarty\WinX_YouTube_Downloader\WinX_YouTube_Downloader.exe
Default=False
FileKey1=%AppData%\Digiarty\WinX YouTube Downloader|*.jpg
[WinZip MRU *]
LangSecRef=3024
Detect=HKCU\Software\Nico Mak Computing\WinZip
Default=False
RegKey1=HKCU\Software\Nico Mak Computing\WinZip\Mru
[WinZip Registry Optimizer *]
LangSecRef=3024
DetectFile=%AppData%\Nico Mak Computing\WinZip Registry Optimizer
Default=False
FileKey1=%AppData%\Nico Mak Computing\WinZip Registry Optimizer\*|log*.*
[Wire *]
LangSecRef=3022
DetectFile=%LocalAppData%\wire
Default=False
FileKey1=%AppData%\Wire\Cache|*.*
FileKey2=%AppData%\Wire\GPUCache|*.*
[Wirecast *]
LangSecRef=3023
DetectFile=%AppData%\Wirecast
Default=False
FileKey1=%AppData%\Wirecast|*.txt
[Wise Care 365 *]
LangSecRef=3024
Detect=HKLM\Software\WiseCleaner\WiseCare365
Default=False
FileKey1=%AppData%\Wise Care 365|Errorlog.txt;FailToRemove.dat
[Wise Video/YouTube Downloader *]
LangSecRef=3023
Detect1=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wise Video Downloader_is1
Detect2=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wise Youtube Downloader_is1
DetectFile1=%ProgramFiles%\Wise\Wise Video Downloader\WiseDownloader.exe
DetectFile2=%ProgramFiles%\Wise\Wise YouTube Downloader\WiseDownloader.exe
Default=False
FileKey1=%AppData%\Wise * Downloader|DownloadList.ini;FileListConfig.ini
FileKey2=%SystemDrive%|urlinfo.txt
FileKey3=%SystemDrive%\ThumbnailCache|*.*
[Wistron Corp Launch Manager *]
LangSecRef=3024
Detect=HKLM\Software\Wistron Corp\Launch Manager
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Launch Manager|*.log
FileKey2=%ProgramFiles%\Launch Manager|*.log
[WM Recorder *]
LangSecRef=3023
Detect1=HKCU\Software\WMR10
Detect2=HKCU\Software\WMR11
Detect3=HKCU\Software\WMR12
Detect4=HKCU\Software\WMR13
Detect5=HKCU\Software\WMR14
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WM Recorder*|log.txt;urls.txt
FileKey2=%ProgramFiles%\WM Recorder*|log.txt;urls.txt
[Wolf: MP *]
Section=Games
DetectFile=%LocalAppData%\id Software\WolfMP
Default=False
FileKey1=%LocalAppData%\id Software\WolfMP|*.log|RECURSE
[WolfQuest *]
Section=Games
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9E6AD6CF-1EFF-43E4-86C4-5C00254C3D8E}
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WolfQuest|*.txt|RECURSE
FileKey2=%ProgramFiles%\WolfQuest|*.txt|RECURSE
ExcludeKey1=FILE|%ProgramFiles%\WolfQuest\|Help.txt
[Wondershare AllMyTube *]
LangSecRef=3022
Detect=HKLM\Software\Wondershare\Wondershare AllMyTube
Default=False
FileKey1=%AppData%\Wondershare AllMyTube|*.*|RECURSE
FileKey2=%CommonAppData%\Wondershare AllMyTube\ConvertedLibPic|*.*|RECURSE
FileKey3=%CommonAppData%\Wondershare Application Common Data\Download|*.bak;*.xml
FileKey4=%CommonAppData%\Wondershare Application Common Data\Download\MediaLibPic|*.*|RECURSE
FileKey5=%CommonAppData%\Wondershare Application Common Data\Download\SiteLogo|*.*|RECURSE
FileKey6=%CommonAppData%\Wondershare Application Common Data\Download\TempThumbDir|*.*|RECURSE
FileKey7=%CommonAppData%\Wondershare\AllMyTube|*.bak;*.xml
FileKey8=%ProgramFiles%\Wondershare\AllMyTube\Log|*.*|RECURSE
[Wondershare dr.fone *]
LangSecRef=3021
Detect1=HKLM\Software\Wondershare\dr.fone toolkit for Android
Detect2=HKLM\Software\Wondershare\dr.fone toolkit for iOS
DetectFile=%ProgramFiles%\Wondershare\drfone
Default=False
FileKey1=%CommonAppData%\Wondershare\dr.fone\log|*.*|RECURSE
FileKey2=%CommonAppData%\Wondershare\DrFone*\log|*.*|RECURSE
FileKey3=%CommonAppData%\Wondershare\DrFoneiOS\DBCache\NormalMode|*.*|RECURSE
FileKey4=%CommonAppData%\Wondershare\WAF\Log|*.*|RECURSE
FileKey5=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE
FileKey6=%CommonAppData%\Wondershare\WSRoot|*.tmp
FileKey7=%CommonAppData%\Wondershare\WSRoot\Logs|*.*|RECURSE
[Wondershare Helper Compact *]
LangSecRef=3021
DetectFile=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact
Default=False
FileKey1=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact|ProductUpdateLists.xml;WSHelper.exe_temp;WSHelperSetup.exe_temp
FileKey2=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact\DATADICT|*.*|RECURSE
FileKey3=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact\Log|*.*|RECURSE
FileKey4=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact\Temp|*.*|RECURSE
FileKey5=%LocalAppData%\VirtualStore\Program Files*\Common Files\Wondershare\Wondershare Helper Compact|ProductUpdateLists.xml;WSHelper.exe_temp;WSHelperSetup.exe_temp
FileKey6=%LocalAppData%\VirtualStore\Program Files*\Common Files\Wondershare\Wondershare Helper Compact\Log|*.*|RECURSE
FileKey7=%LocalAppData%\VirtualStore\Program Files*\Common Files\Wondershare\Wondershare Helper Compact\Temp|*.*|RECURSE
RegKey1=HKLM\Software\Wondershare\Wondershare Helper Compact
RegKey2=HKLM\Software\Wow6432Node\Wondershare\Wondershare Helper Compact
[Wondershare MobileGo *]
LangSecRef=3021
Detect=HKCU\Software\Wondershare\MobileGo
DetectFile=%AppData%\Wondershare\MobileGo for iOS
Default=False
FileKey1=%AppData%\se_tmp|*.*|REMOVESELF
FileKey2=%AppData%\Wondershare\*Go*|*.log
FileKey3=%AppData%\Wondershare\DataEraser|*.log
FileKey4=%AppData%\Wondershare\Dr.FoneTool\log|*.log
FileKey5=%AppData%\Wondershare\DrFoneAndroidTool\log|*.log
FileKey6=%AppData%\Wondershare\MirrorGo\ImageCache\ADImage|*.*|RECURSE
FileKey7=%AppData%\Wondershare\MobileGo\DeviceImageCache|*.*|RECURSE
FileKey8=%AppData%\Wondershare\MobileGo\iOSTemp|*.*|REMOVESELF
FileKey9=%AppData%\Wondershare\MobileGo\Logs\DeviceConnection|*.*|RECURSE
FileKey10=%AppData%\Wondershare\MobileTransTool|*.log
FileKey11=%AppData%\Wondershare\WsRoot\Logs|*.*|RECURSE
FileKey12=%CommonAppData%\Wondershare\Dr.FoneTool\Log|*.txt
FileKey13=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE
FileKey14=%ProgramFiles%\Wondershare\MobileGo|*.log
[Wondershare PDF Editor *]
LangSecRef=3021
Detect=HKLM\Software\Wondershare\Wondershare PDF Editor
Default=False
FileKey1=%AppData%\Wondershare\PDF Editor|HistoryDatas.dat
FileKey2=%AppData%\Wondershare\PDF Editor\Log|*.log
[Wondershare SafeEraser *]
LangSecRef=3021
Detect=HKLM\Software\Wondershare\SafeEraser
Default=False
FileKey1=%AppData%\HMYGSetting|*.*|REMOVESELF
FileKey2=%AppData%\HYXDevPsnList|*.*|REMOVESELF
FileKey3=%AppData%\se_tmp|*.*|REMOVESELF
FileKey4=%AppData%\se_tmp_win|*.*|REMOVESELF
FileKey5=%AppData%\Wondershare\SafeEraser|*.log
FileKey6=%AppData%\Wondershare\SafeEraser\Logs\DeviceConnection|*.*|RECURSE
FileKey7=%AppData%\Wondershare\SafeEraser\Logs\iOSTemp|*.*|RECURSE
FileKey8=%ProgramFiles%\Wondershare\SafeEraser\se_tmp_win|*.*|REMOVESELF
FileKey9=%SystemDrive%\se_tmp|*.*|REMOVESELF
[Wondershare Video Converter Ultimate *]
LangSecRef=3023
Detect=HKLM\Software\Wondershare\Wondershare Video Converter Ultimate
Default=False
FileKey1=%CommonAppData%\Wondershare\ProductFeatures\*Logs|*.*|RECURSE
FileKey2=%Documents%\Wondershare MediaServer\log|*.*|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Wondershare Video Converter Ultimate\TempThumbDir|*.*|RECURSE
FileKey4=%ProgramFiles%\Wondershare Video Converter Ultimate\TempThumbDir|*.*|RECURSE
[Wordweb *]
LangSecRef=3021
Detect=HKCU\Software\WordWeb
Default=False
FileKey1=%AppData%\WordWeb|History.txt
[World of Warcraft *]
Section=Games
Detect=HKCU\Software\Blizzard Entertainment\World of Warcraft
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\World of Warcraft\Cache|*.*|REMOVESELF
FileKey2=%LocalAppData%\VirtualStore\Program Files*\World of Warcraft\Errors|*.*|REMOVESELF
FileKey3=%LocalAppData%\VirtualStore\Program Files*\World of Warcraft\Logs|*.log
FileKey4=%ProgramFiles%\World of Warcraft\Cache|*.*|REMOVESELF
FileKey5=%ProgramFiles%\World of Warcraft\Errors|*.*|REMOVESELF
FileKey6=%ProgramFiles%\World of Warcraft\Logs|*.log
FileKey7=%Public%\Games\World of Warcraft\Cache|*.*|REMOVESELF
FileKey8=%Public%\games\World of Warcraft\Errors|*.*|REMOVESELF
FileKey9=%Public%\games\World of Warcraft\Logs|*.log
FileKey10=%SystemDrive%\World of Warcraft\Cache|*.*|REMOVESELF
FileKey11=%SystemDrive%\World of Warcraft\Errors|*.*|REMOVESELF
FileKey12=%SystemDrive%\World of Warcraft\Logs|*.log
[World of Warcraft Backups *]
Section=Games
Detect=HKCU\Software\Blizzard Entertainment\World of Warcraft
Default=False
Warning=This will delete all your World of Warcraft backup files. You won't be able to restore from them if something goes wrong.
FileKey1=%LocalAppData%\VirtualStore\Program Files*\World of Warcraft|*.bak;*.old|RECURSE
FileKey2=%ProgramFiles%\World of Warcraft|*.bak;*.old|RECURSE
FileKey3=%Public%\games\World of Warcraft|*.bak;*.old|RECURSE
FileKey4=%SystemDrive%\World of Warcraft|*.bak;*.old|RECURSE
[WorldWide Telescope *]
LangSecRef=3021
Detect=HKCU\Software\Classes\WorldWideTelescope.wtml
Default=False
FileKey1=%LocalAppData%\Microsoft\WorldWideTelescope\dem|*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\WorldWideTelescope\Imagery|*.*|RECURSE
FileKey3=%LocalAppData%\Microsoft\WorldWideTelescope\tourcache|*.*|RECURSE
[Wowhead Client *]
Section=Games
Detect=HKCU\Software\Wowhead\WowHead Client
Default=False
FileKey1=%CommonAppData%\wowhead\wowhead client\cache|*.*|REMOVESELF
FileKey2=%CommonAppData%\wowhead\wowhead client\log|*.*|REMOVESELF
FileKey3=%LocalAppData%\VirtualStore\ProgramData\wowhead\wowhead client\cache|*.*|REMOVESELF
FileKey4=%LocalAppData%\VirtualStore\ProgramData\wowhead\wowhead client\log|*.*|REMOVESELF
RegKey1=HKCU\Software\Wowhead\WowHead Client|Statistics
[WRAL Desktop Alert *]
LangSecRef=3024
DetectFile=%ProgramFiles%\WRAL Desktop Alert
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\WRAL Desktop Alert|*.log
FileKey2=%ProgramFiles%\WRAL Desktop Alert|*.log
[WS FTP Pro *]
LangSecRef=3022
Detect=HKCU\Software\Ipswitch\WS_FTP
Default=False
FileKey1=%AppData%\Ipswitch\WS_FTP\Logs|*.*
[Wunderlist *]
LangSecRef=3022
DetectFile=%ProgramFiles%\Wunderlist
Default=False
FileKey1=%AppData%\Titanium\appdata\com.wunderkinder.wunderlistdesktop|*.log
[X-Chat 2 *]
LangSecRef=3022
DetectFile=%AppData%\X-Chat 2
Default=False
Warning=This removes Chat Scrollback and Logs.
FileKey1=%AppData%\X-Chat 2\scrollback|*.*|REMOVESELF
FileKey2=%AppData%\X-Chat 2\xchatlogs|*.*|REMOVESELF
[X-Cleaner *]
LangSecRef=3024
DetectFile=%ProgramFiles%\X-Cleaner
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\X-Cleaner|XCL_LOG.txt
FileKey2=%ProgramFiles%\X-Cleaner|XCL_LOG.txt
[X-NetStat *]
LangSecRef=3024
DetectFile=%ProgramFiles%\X-NetStat Professional\xns5.exe
Default=False
FileKey1=%AppData%\X-NetStat\Logs|*.*
[Xara Photo & Graphic Designer *]
LangSecRef=3023
Detect=HKCU\Software\Xara\Xtreme_SE
Default=False
FileKey1=%LocalAppData%\Xara\Xtreme\9.2\Backups|*.*|RECURSE
FileKey2=%LocalAppData%\Xara\Xtreme_SE\6.1\Backups|*.txt
RegKey1=HKCU\Software\Xara\Xtreme\9.2\Options\Recent File List
RegKey2=HKCU\Software\Xara\Xtreme_SE\6.1\Options\Recent File List
RegKey3=HKCU\Software\Xara\Xtreme_SE\6.1\Workspace
[Xara WebDesigner Backups *]
LangSecRef=3024
Detect=HKCU\Software\Xara\WebDesigner
Default=False
FileKey1=%LocalAppData%\Xara\WebDesigner\*\Backups|*.*|RECURSE
[Xara WebDesigner Session *]
LangSecRef=3024
Detect=HKCU\Software\Xara\WebDesigner
Default=False
RegKey1=HKCU\Software\Xara\WebDesigner\8.0\Workspace\MDI
[Xbox *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxApp_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxApp_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState|*.log*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\*Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\DiagOutputDir|*.txt
FileKey9=%LocalAppData%\Packages\Microsoft.XboxApp_*\LocalState\SmartGlass|*.log
FileKey10=%LocalAppData%\Packages\Microsoft.XboxApp_*\TempState|*.*|RECURSE
[Xbox Game Overlay *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxGameOverlay_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\Microsoft\CryptnetUrlCache\*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\AC\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalCache\Cache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalState\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\LocalState\DiagOutputDir|*.txt
FileKey7=%LocalAppData%\Packages\Microsoft.XboxGameOverlay_*\TempState|*.*|RECURSE
[Xbox Identity Provider *]
DetectOS=10.0|
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\INet*|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0*|*.log
FileKey3=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0*\NativeImages\Temp|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Microsoft\CLR_v4.0*\UsageLogs|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\Temp|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\AC\TokenBroker\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalCache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\LocalState\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.XboxIdentityProvider_*\TempState|*.*|RECURSE
[Xbox LIVE Games *]
LangSecRef=3031
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxLIVEGames_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_8wekyb3d8bbwe
Default=False
FileKey1=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\INet*|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\Microsoft\CryptnetUrlCache\*|*.*
FileKey5=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\PRICache|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\LocalState\*Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\LocalState\navigationHistory|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\LocalState\PlayReady|*.*|RECURSE
FileKey11=%LocalAppData%\Packages\Microsoft.XboxLIVEGames_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.XboxLIVEGames_8wekyb3d8bbwe\SearchHistory
[Xenocode Sandbox *]
LangSecRef=3021
Detect=HKCU\Software\Xenocode\SandboxCache
Default=False
FileKey1=%LocalAppData%\Xenocode\Sandbox|*.*|REMOVESELF
FileKey2=%WinDir%\XSxS|*.*|REMOVESELF
RegKey1=HKCU\Software\Xenocode\SandboxCache
[Xerox Printer Driver *]
LangSecRef=3021
DetectFile=%CommonAppData%\Xerox\PrinterDriver
Default=False
FileKey1=%CommonAppData%\Xerox\PrinterDriver|*.tmp|RECURSE
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Xerox\PrinterDriver|*.tmp|RECURSE
[Xfire *]
Section=Games
Detect=HKLM\Software\Xfire
Default=False
Warning=Selecting this will delete any screen shots and videos you have taken, make sure you upload or move any you want to keep so they're not deleted.
FileKey1=%CommonAppData%\Xfire|*.bak
FileKey2=%CommonAppData%\xfire\videos|*.*
FileKey3=%LocalAppData%\VirtualStore\ProgramData\Xfire|*.bak
FileKey4=%LocalAppData%\VirtualStore\ProgramData\xfire\videos|*.*
[Xfire Updates *]
Section=Games
Detect=HKLM\Software\Xfire
Default=False
FileKey1=%CommonAppData%\Xfire\downloads|*.zip
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Xfire\downloads|*.zip
[Xilisoft AVI to DVD Converter *]
LangSecRef=3023
DetectFile=%LocalAppData%\Xilisoft\AVI to DVD Converter
Default=False
FileKey1=%LocalAppData%\Xilisoft\AVI to DVD Converter|log_testing.txt
[Xmarks *]
LangSecRef=3024
Detect=HKCU\Software\Xmarks
Default=False
FileKey1=%LocalAppData%\Xmarks|xmarks.log
[XMind *]
LangSecRef=3021
DetectFile=%AppData%\XMind
Default=False
FileKey1=%AppData%\XMind|*.log|RECURSE
[XMLViewer *]
LangSecRef=3024
Detect=HKCU\Software\MiTeC\XMLViewer
Default=False
RegKey1=HKCU\Software\MiTeC\XMLViewer\4.x\wnd_xmlv_Main\Twnd_xmlv_Main.MRUManager
[XN Resource Editor *]
LangSecRef=3024
Detect=HKCU\Software\Woozle\XN Resource Editor
Default=False
RegKey1=HKCU\Software\Woozle\XN Resource Editor\Recent Files
[XnView *]
LangSecRef=3023
Detect1=HKCU\Software\XnView
Detect2=HKCU\Software\XnView\XnViewMP
Detect3=HKLM\Software\XnView
Default=False
FileKey1=%AppData%\XnView\cache|*.db
FileKey2=%AppData%\XnViewMP|*.db;category.bak
FileKey3=%LocalAppData%\VirtualStore\Program Files*\XnViewMP|category.bak;*.db
FileKey4=%ProgramFiles%\XnViewMP|category.bak;*.db
[XPhone *]
LangSecRef=3021
Detect=HKCU\Software\C4B\Log
Default=False
FileKey1=%LocalAppData%\C4B\Log|*.*
[Xplorer2 *]
LangSecRef=3024
Detect=HKCU\Software\ZabaraKatranemia Plc\xplorer2\MainFrame Settings
Default=False
RegKey1=HKCU\Software\ZabaraKatranemia Plc\xplorer2\MainFrame Settings\Folder History
[XPort 360 *]
LangSecRef=3021
DetectFile=%AppData%\Datel\XPort 360
Default=False
FileKey1=%AppData%\Datel\XPort 360\Temp|*.*|REMOVESELF
[XPressUpdate *]
LangSecRef=3023
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\XPressUpdate.exe
Default=False
FileKey1=%CommonProgramFiles%\XpressUpdate|*.log;*old
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Common Files\XpressUpdate|*.log;*old
[Xsplit *]
LangSecRef=3023
Detect=HKLM\Software\Splitmedialabs\XSplit
Default=False
FileKey1=%AppData%\SplitMediaLabs\XSplit|*.log|RECURSE
FileKey2=%CommonAppData%\SplitMediaLabs\XSplit\LocalStore\Temp|*.*
FileKey3=%CommonAppData%\SplitMediaLabs\XSplit\Temp|*.*
FileKey4=%LocalAppData%\SplitMediaLabs\XSplit\*|bwtestlogs.txt
FileKey5=%LocalAppData%\VirtualStore\ProgramData\SplitMediaLabs\XSplit\LocalStore\Temp|*.*
FileKey6=%LocalAppData%\VirtualStore\ProgramData\SplitMediaLabs\XSplit\Temp|*.*
[XviD *]
LangSecRef=3023
Detect=HKCU\Software\GNU\Xvid
Default=False
RegKey1=HKCU\Software\GNU\Xvid|stats
[XWidget *]
LangSecRef=3021
DetectFile=%Documents%\XWidget
Default=False
FileKey1=%Documents%\XWidget\Cache|*.*|RECURSE
[XWidget Backup *]
LangSecRef=3021
DetectFile=%Documents%\XWidget
Default=False
FileKey1=%Documents%\XWidget\Backup|*.*|RECURSE
[Yahoo Autosync *]
LangSecRef=3022
Detect=HKCU\Software\Yahoo!\Autosync for Yahoo!
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Yahoo!\Yahoo! Autosync\Logs|*.*
FileKey2=%ProgramFiles%\Yahoo!\Yahoo! Autosync\Logs|*.*
[Yahoo Companion *]
LangSecRef=3022
DetectFile=%CommonAppData%\Yahoo! Companion
Default=False
FileKey1=%CommonAppData%\Yahoo! Companion\Cache|*.*
FileKey2=%LocalAppData%\VirtualStore\ProgramData\Yahoo! Companion\Cache|*.*
[Yahoo Messenger *]
LangSecRef=3022
Detect=HKCU\Software\Yahoo\Messenger
Default=False
FileKey1=%LocalAppData%\yahoomessenger|SquirrelSetup.log
[Yahoo Messenger Cache *]
LangSecRef=3022
Detect=HKCU\Software\Yahoo\Messenger
Default=False
Warning=You will need to reload the App next time its started. Select View, Reload from the menu.
FileKey1=%AppData%\Yahoo Messenger\Cache|*.*|RECURSE
[YPOPs *]
LangSecRef=3021
DetectFile=%ProgramFiles%\YPOPs\ypops.exe
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\YPOPs|ypops.log
FileKey2=%ProgramFiles%\YPOPs|ypops.log
[yWriter5 *]
LangSecRef=3021
DetectFile=%AppData%\Spacejock Software\yWriter5
Default=False
FileKey1=%AppData%\Spacejock Software\yWriter5|log.txt
FileKey2=%Documents%\Logs|*.txt
[Zemana AntiMalware Reports *]
LangSecRef=3024
Detect1=HKCU\Software\Zemana\AntiMalware
Detect2=HKLM\Software\Zemana\AntiMalware
Default=False
FileKey1=%LocalAppData%\Zemana\Zemana AntiMalware\reports|*.txt
[Zend Studio 10 *]
LangSecRef=3021
Detect=HKCU\Software\Zend\ZendStudio
Default=False
FileKey1=%LocalAppData%\VirtualStore\Program Files*\Zend\Zend Studio 10.0.0|*.html
FileKey2=%LocalAppData%\VirtualStore\Program Files*\Zend\Zend Studio 10.0.0|*.log|RECURSE
FileKey3=%LocalAppData%\VirtualStore\Program Files*\Zend\Zend Studio 10.0.0\docs|*.txt|REMOVESELF
FileKey4=%LocalAppData%\VirtualStore\Program Files*\Zend\Zend Studio 10.0.0\features|*.html|RECURSE
FileKey5=%ProgramFiles%\Zend\Zend Studio 10.0.0|*.html
FileKey6=%ProgramFiles%\Zend\Zend Studio 10.0.0|*.log|RECURSE
FileKey7=%ProgramFiles%\Zend\Zend Studio 10.0.0\docs|*.txt|REMOVESELF
FileKey8=%ProgramFiles%\Zend\Zend Studio 10.0.0\features|*.html|RECURSE
[Zer0 *]
LangSecRef=3024
Detect=HKCU\Software\KC Softwares\Zer0
Default=False
FileKey1=%AppData%\KC Softwares\Zer0|*.log
[Zimbra Desktop *]
LangSecRef=3022
Detect=HKCU\Software\Zimbra
Default=False
FileKey1=%LocalAppData%\Zimbra\Zimbra Desktop\data\*log|*.*
FileKey2=%LocalAppData%\Zimbra\Zimbra Desktop\data\tmp\diskcache|*.*|RECURSE
[ZipGenius *]
LangSecRef=3024
Detect=HKCU\Software\M.Dev Software\ZG5
Default=False
FileKey1=%AppData%\ZipGenius|mru.dat
RegKey1=HKCU\Software\M.Dev Software\ZG5\MRU Items
[ZoneAlarm Internet *]
LangSecRef=3021
Detect=HKLM\Software\Zone Labs\ZoneAlarm
Default=False
FileKey1=%WinDir%\Internet Logs|*.dmp;*.log;*.tmp;*.zip
[ZoneIDTrimmer *]
LangSecRef=3021
Detect=HKLM\Software\Gasanov.net\ZoneIDTrimmer
DetectFile=%ProgramFiles%\Gasanov.net\ZoneIDTrimmer\ZoneIDTrimmer.Tool.exe
Default=False
FileKey1=%AppData%\ZoneIDTrimmer\Logs|ZoneIDTrimmer.log
[Zoner Photo Studio *]
LangSecRef=3022
Detect1=HKCU\Software\ZONER\Zoner Photo Studio 15
Detect2=HKCU\Software\ZONER\Zoner Photo Studio 16
Detect3=HKCU\Software\ZONER\Zoner Photo Studio 18
DetectFile=%LocalAppData%\Zoner\ZPS 14
Default=False
FileKey1=%LocalAppData%\Zoner\ZPS *\Cache|*.*|RECURSE
FileKey2=%LocalAppData%\Zoner\ZPS *\CEF|*.log
FileKey3=%LocalAppData%\Zoner\ZPS *\ZPSCache.dat|*.*
FileKey4=%Pictures%|*.uid-zps
[Zoner Photo Studio AutoSave *]
LangSecRef=3023
Detect1=HKCU\Software\ZONER\Zoner Photo Studio 15
Detect2=HKCU\Software\ZONER\Zoner Photo Studio 16
Detect3=HKCU\Software\ZONER\Zoner Photo Studio 18
Default=False
FileKey1=%LocalAppData%\Zoner\OriginalsRepository|*.JPG.info;*.JPG.original|RECURSE
[Zune Transcoded Files Cache *]
LangSecRef=3023
Detect=HKCU\Software\Microsoft\Zune
Default=False
FileKey1=%LocalAppData%\Microsoft\Zune\Transcoded Files Cache|*.*
[Zuse *]
LangSecRef=3023
DetectFile=%AppData%\Zuse
Default=False
FileKey1=%AppData%\Zuse\logs|*.*
[ZX32 ZX Spectrum Emulator v1.03 *]
LangSecRef=3021
Detect=HKCU\Software\VK\zx32\1.03
Default=False
RegKey1=HKCU\Software\VK\zx32\1.03\FileMRU
[Zynga Games *]
Section=Games
DetectFile=%LocalAppData%\Zynga
Default=False
FileKey1=%LocalAppData%\Zynga\Logs|*.*|RECURSE