From 7f256aa25f1b893ba8b0b5efaa0ba52b3109d81e Mon Sep 17 00:00:00 2001 From: novaceb881 <57820130+novaceb881@users.noreply.github.com> Date: Mon, 18 Nov 2019 12:24:37 +0100 Subject: [PATCH] Update Winapp2.ini (#420) --- Winapp2.ini | 623 +++++++++++++++++++++++++++++++++++++++++++++------- 1 file changed, 540 insertions(+), 83 deletions(-) diff --git a/Winapp2.ini b/Winapp2.ini index 8cd8b735b..6b679a87f 100644 --- a/Winapp2.ini +++ b/Winapp2.ini @@ -1,5 +1,5 @@ ; Version: 191104 -; # of entries: 2,177 +; # of entries: 2,233 ; ; Winapp2.ini is fully licensed under the CC-BY-SA-4.0 license agreement. Please refer to our license agreement before using Winapp2.ini: https://github.com/MoscaDotTo/Winapp2/blob/master/License.md ; If you plan on modifying, distributing, and/or hosting Winapp2.ini for your own program or website, please ask first. @@ -2589,6 +2589,18 @@ Default=False FileKey1=%CommonAppData%\Acer\CareCenter\DebugLog\SurfaceCheck|log*.txt FileKey2=%ProgramFiles%\Acer\Care Center\DebugLog|*.log +[Acer eSupport *] +LangSecRef=3024 +DetectFile=%SystemDrive%\eSupport\eDriver +Default=False +FileKey1=%SystemDrive%\eSupport\eDriver\Software|*.log;URLLog.dat|RECURSE + +[Acer GameZone *] +Section=Games +DetectFile=%ProgramFiles%\Acer GameZone +Default=False +FileKey1=%ProgramFiles%\Acer GameZone|*.log|RECURSE + [AcooBrowser *] LangSecRef=3022 Detect=HKCU\Software\AcooBrowser\Acoo Browser @@ -2908,9 +2920,10 @@ Default=False RegKey1=HKCU\Software\Adobe\Acrobat Reader\11.0\AVConversionFromPDF RegKey2=HKCU\Software\Adobe\Acrobat Reader\11.0\AVConversionToPDF RegKey3=HKCU\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cDockables -RegKey4=HKCU\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cToolbars -RegKey5=HKCU\Software\Adobe\Acrobat Reader\11.0\RememberedViews\cNoCategoryFiles -RegKey6=HKCU\Software\Adobe\Adobe Synchronizer\11.0 +RegKey4=HKCU\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cRecentFolders +RegKey5=HKCU\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cToolbars +RegKey6=HKCU\Software\Adobe\Acrobat Reader\11.0\RememberedViews\cNoCategoryFiles +RegKey7=HKCU\Software\Adobe\Adobe Synchronizer\11.0 [Advanced Browser *] LangSecRef=3022 @@ -2937,7 +2950,8 @@ LangSecRef=3024 Detect=HKCU\Software\Systweak\Advanced System Protector DetectFile=%ProgramFiles%\Advanced System Protector\AdvancedSystemProtector.exe Default=False -FileKey1=%AppData%\Systweak\Advanced System Protector\Logs|*.xml +FileKey1=%AppData%\Systweak\Advanced System Protector|*log.txt;*.log|RECURSE +FileKey2=%AppData%\Systweak\Advanced System Protector\Logs|*.xml [Advanced Uninstaller *] LangSecRef=3024 @@ -3126,6 +3140,12 @@ Default=False FileKey1=%ProgramFiles%\Steam\Steamapps\common\AirBuccaneers\abu_data|output_log.txt FileKey2=%ProgramFiles%\Steam\Steamapps\common\AirBuccaneers\logs|*.* +[AirPcap *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Riverbed\AirPcap\driver +Default=False +FileKey1=%ProgramFiles%\Riverbed\AirPcap\driver|*.log + [AirStrike 3D *] Section=Games DetectFile=%ProgramFiles%\Blimb Entertainment\AIRSTRIKE3D @@ -3366,6 +3386,13 @@ DetectFile=%UserProfile%\.android\android-notifier-desktop Default=False FileKey1=%UserProfile%\.android\android-notifier-desktop|android-notifier-desktop.* +[Android SDK Tools *] +LangSecRef=3023 +Detect=HKLM\Software\Android SDK Tools +Default=False +FileKey1=%AppData%\Android\android-sdk\temp|*.*|REMOVESELF +FileKey2=%UserProfile%\.android\cache|*.*|REMOVESELF + [Android Studio *] LangSecRef=3021 Detect=HKCU\Software\Android Open Source Project\Emulator @@ -3809,6 +3836,12 @@ FileKey2=%CommonAppData%\Asus\AsusAppStore|*.log|RECURSE FileKey3=%ProgramFiles%\ASUS\*|*.log;*log*.txt|RECURSE FileKey4=%SystemDrive%|wifi.log +[ASUS SmartCore *] +LangSecRef=3024 +Detect=HKLM\Software\ASUS\SmartCore +Default=False +FileKey1=%ProgramFiles%\ASUS\SmartCore|*.log;*.tmp|RECURSE + [Atheros Driver *] LangSecRef=3024 Detect=HKLM\Software\Atheros @@ -4067,10 +4100,13 @@ FileKey8=%CommonAppData%\Avg\Antivirus\SWCUData\icons|*.*|RECURSE FileKey9=%CommonAppData%\AVG\Persistent Data\Antivirus\Logs|*.*|RECURSE FileKey10=%LocalAppData%\AVG\log|*.*|RECURSE FileKey11=%LocalAppData%\AvgSetupLog|*.*|REMOVESELF -FileKey12=%WinDir%\System32\config\systemprofile\AppData\Local\Avg\log|*.*|RECURSE -FileKey13=%WinDir%\System32\config\systemprofile\AppData\Local\AvgSetupLog|*.*|REMOVESELF -FileKey14=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Avg\log|*.*|RECURSE -FileKey15=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\AvgSetupLog|*.*|REMOVESELF +FileKey12=%LocalAppData%\MFAData\logs|*.log;*.log.* +FileKey13=%WinDir%\System32\config\systemprofile\AppData\Local\Avg\log|*.*|RECURSE +FileKey14=%WinDir%\System32\config\systemprofile\AppData\Local\AvgSetupLog|*.*|REMOVESELF +FileKey15=%WinDir%\System32\config\systemprofile\AppData\Local\MFAData\logs|*.* +FileKey16=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\Avg\log|*.*|RECURSE +FileKey17=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\AvgSetupLog|*.*|REMOVESELF +FileKey18=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\MFAData\logs|*.* RegKey1=HKLM\Software\AVG\Antivirus\PUB-Detected RegKey2=HKLM\Software\AVG\Antivirus\PUB-Removed RegKey3=HKLM\Software\Wow6432Node\AVG\Antivirus\PUB-Detected @@ -4392,6 +4428,7 @@ LangSecRef=3021 Detect=HKCU\Software\Scooter Software\Beyond Compare Default=False FileKey1=%AppData%\Scooter Software\Beyond Compare*|*.bak +RegKey1=HKCU\Software\Scooter Software\Beyond Compare\Recent [Big City Adventure *] Section=Games @@ -4556,7 +4593,8 @@ LangSecRef=3022 DetectFile1=%AppData%\BitTorrent\BitTorrent.exe DetectFile2=%ProgramFiles%\BitTorrent\BitTorrent.exe Default=False -FileKey1=%AppData%\BitTorrent\Updates|*.exe +FileKey1=%AppData%\BitTorrent\ie|*.tmp +FileKey2=%AppData%\BitTorrent\Updates|*.exe [BitTorrent Incomplete Downloads *] LangSecRef=3022 @@ -5386,6 +5424,13 @@ DetectFile=%ProgramFiles%\CleanGenius 3\Update Default=False FileKey1=%ProgramFiles%\CleanGenius 3\Update|update.log +[Clean Master *] +LangSecRef=3024 +Detect=HKCU\Software\cmcm\cleanMaster +Default=False +FileKey1=%ProgramFiles%\Clean Master|*.log* +FileKey2=%ProgramFiles%\Clean Master\log|*.* + [CleanMyPC Registry Cleaner *] LangSecRef=3024 Detect=HKCU\Software\CleanMyPC\CleanMyPC - Registry Cleaner @@ -5621,7 +5666,7 @@ RegKey4=HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags [Complete Internet Repair *] LangSecRef=3024 -DetectFile=%ProgramFiles%\Rizonesoft\Complete Internet Repair\ComIntRep.exe +DetectFile=%AppData%\Rizonesoft\ComIntRep Default=False FileKey1=%AppData%\Rizonesoft\ComIntRep\Logging|*.*|RECURSE @@ -5648,6 +5693,13 @@ FileKey2=%LocalLowAppData%\ConduitEngine\CacheIcons|*.* FileKey3=%LocalLowAppData%\ConduitEngine\Logs|*.* FileKey4=%WinDir%\System32|ConduitEngine.tmp +[Conexant Logs *] +LangSecRef=3024 +Detect=HKCU\Software\Conexant +Default=False +FileKey1=%CommonAppData%\Conexant\UCILogs\COINST|*.log +FileKey2=%Public%|CAFADEBUG.log + [Connectify Hotspot *] LangSecRef=3022 Detect=HKLM\Software\Connectify @@ -6318,7 +6370,8 @@ RegKey2=HKCU\Software\DT Soft\DAEMON Tools Pro\GuiNamespace|MountFolder LangSecRef=3021 DetectFile=%SystemDrive%\dakotaag Default=False -FileKey1=%SystemDrive%\dakotaag|*.log|RECURSE +FileKey1=%Documents%|dakotaDeinstallieren.log +FileKey2=%SystemDrive%\dakotaag|*.log|RECURSE [DAMN Hash Calculator *] LangSecRef=3024 @@ -6391,6 +6444,12 @@ DetectFile=%ProgramFiles%\DataTron7 Default=False FileKey1=%ProgramFiles%\DataTron7|*.GID;*.BAK +[DATEV *] +LangSecRef=3021 +DetectFile=%SystemDrive%\DATEV +Default=False +FileKey1=%SystemDrive%\DATEV\LOG|*.log|RECURSE + [David FX Basic *] LangSecRef=3024 Detect=HKCU\Software\Tobit @@ -6776,12 +6835,19 @@ Detect=HKCU\Software\Dexpot Default=False FileKey1=%AppData%\Dexpot|*.log +[DFX *] +LangSecRef=3021 +Detect=HKCU\Software\DFX +Default=False +FileKey1=%LocalAppData%\DFX\*|dfx_skin.txt +FileKey2=%LocalAppData%\DFX\*\Tmp|*.*|REMOVESELF + [Diablo II *] Section=Games Detect=HKCU\Software\Blizzard Entertainment\Diablo II Default=False -FileKey1=%ProgramFiles%\Diablo II|bnupdate.log;BnetLog.txt;D*.txt -FileKey2=%SystemDrive%\Diablo II|bnupdate.log;BnetLog.txt;D*.txt +FileKey1=%ProgramFiles%\Diablo II|*.log;BnetLog.txt;D*.txt +FileKey2=%SystemDrive%\Diablo II|*.log;BnetLog.txt;D*.txt [Diablo III *] Section=Games @@ -6882,7 +6948,8 @@ FileKey2=%CommonAppData%\Binary Fortress Software\DisplayFusion|DisplayFusionSet [DivX *] LangSecRef=3023 -Detect=HKCU\Software\DivX +Detect1=HKCU\Software\DivX +Detect2=HKLM\Software\DivXNetworks Default=False FileKey1=%AppData%\DivX|Font Cache.|RECURSE FileKey2=%CommonAppData%\DivX|*.log|RECURSE @@ -6969,6 +7036,12 @@ Default=False FileKey1=%LocalAppData%\id Software\DOOM\base\generated\temp|*.* FileKey2=%UserProfile%\Saved Games\id Software\DOOM\base\generated\temp|*.* +[Double Vision Browser 3.0 *] +LangSecRef=3022 +Detect=HKCU\Software\Sincell\Double Vision 3.0.0 +Default=False +FileKey1=%ProgramFiles%\Sincell\Double Vision 3.0.0\Logs|*.* + [Download App *] LangSecRef=3024 Detect=HKCU\Software\CBS Interactive\Download App @@ -7001,6 +7074,12 @@ DetectFile=%AppData%\HitPoint Studios\DrD Default=False FileKey1=%AppData%\HitPoint Studios\DrD|logfile.txt +[Dr. Hardware 2014 Report *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dr. Hardware 2014_is1 +Default=False +FileKey1=%UserProfile%|Report_drhard.txt + [Dr. Web CureIt! *] LangSecRef=3024 DetectFile=%UserProfile%\Doctor Web @@ -7023,6 +7102,25 @@ Default=False FileKey1=%CommonAppData%\BioWare\Dragon Age\DA Updater\Logs|*.* FileKey2=%Documents%\BioWare\Dragon Age\Logs|*.* +[Dragon UnPACKer 5 *] +LangSecRef=3024 +Detect=HKCU\Software\Dragon Software\Dragon UnPACKer 5 +Default=False +FileKey1=%ProgramFiles%\Dragon UnPACKer 5|*.log;*.diz +RegKey1=HKCU\Software\Dragon Software\Dragon UnPACKer 5\HyperRipper|Source +RegKey2=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|LastFilterIndex +RegKey3=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|LastFilterIndex_Hash +RegKey4=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|Recent_0 +RegKey5=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|Recent_1 +RegKey6=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|Recent_2 +RegKey7=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|Recent_3 +RegKey8=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|Recent_4 +RegKey9=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|Recent_5 +RegKey10=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|Recent_6 +RegKey11=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|Recent_7 +RegKey12=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|Recent_8 +RegKey13=HKCU\Software\Dragon Software\Dragon UnPACKer 5\Options|Recent_9 + [Dreadnought *] Section=Games Detect=HKCU\Software\Grey Box\Dreadnought @@ -7103,7 +7201,17 @@ Detect=HKLM\Software\Driver-Soft\DriverGenius DetectFile=%ProgramFiles%\Driver-Soft\DriverGenius Default=False FileKey1=%CommonAppData%\DriverGenius|*.log -FileKey2=%LocalAppData%\DriverGenius|ScanLog.log +FileKey2=%CommonAppData%\DriverGenius\InstalledUpdates|*.* +FileKey3=%CommonAppData%\DriverGenius\Temp|*.* +FileKey4=%LocalAppData%\DriverGenius|ScanLog.log + +[DriverGenius Downloads *] +LangSecRef=3024 +Detect=HKLM\Software\Driver-Soft\DriverGenius +DetectFile=%ProgramFiles%\Driver-Soft\DriverGenius +Default=False +Warning=This will delete the downloaded drivers. +FileKey1=%CommonAppData%\DriverGenius\Downloads|*.* [DriverMax *] LangSecRef=3024 @@ -7539,6 +7647,67 @@ DetectFile=%AppData%\Efficient Calendar Default=False FileKey1=%AppData%\Efficient Calendar\MRUItems|*.*|RECURSE +[Elcomsoft Advanced Archive Password Recovery *] +LangSecRef=3021 +Detect=HKCU\Software\ElcomSoft\Advanced Archive Password Recovery +Default=False +FileKey1=%ProgramFiles%\Elcomsoft Password Recovery\Advanced Archive Password Recovery|*.log;*log.txt +RegKey1=HKCU\Software\ElcomSoft\Advanced Archive Password Recovery\Paths +RegKey2=HKCU\Software\ElcomSoft\Advanced Archive Password Recovery\Recent Files + +[Elcomsoft Advanced EFS Data Recovery *] +LangSecRef=3021 +Detect=HKCU\Software\ElcomSoft\Advanced EFS Data Recovery +Default=False +FileKey1=%SystemDrive%|aefsdr.log + +[Elcomsoft Advanced Office Password Recovery *] +LangSecRef=3021 +Detect=HKCU\Software\ElcomSoft\Advanced Office Password Recovery +Default=False +FileKey1=%ProgramFiles%\Elcomsoft Password Recovery\Advanced Office Password Recovery|*.log;*log.txt +RegKey1=HKCU\Software\ElcomSoft\Advanced Office Password Recovery|Recent file 1 +RegKey2=HKCU\Software\ElcomSoft\Advanced Office Password Recovery|Recent file 2 +RegKey3=HKCU\Software\ElcomSoft\Advanced Office Password Recovery|Recent file 3 +RegKey4=HKCU\Software\ElcomSoft\Advanced Office Password Recovery|Recent file 4 +RegKey5=HKCU\Software\ElcomSoft\Advanced Office Password Recovery|Recent file 5 +RegKey6=HKCU\Software\ElcomSoft\Advanced Office Password Recovery|Recent file 6 +RegKey7=HKCU\Software\ElcomSoft\Advanced Office Password Recovery|Recent file 7 +RegKey8=HKCU\Software\ElcomSoft\Advanced Office Password Recovery|Recent file 8 +RegKey9=HKCU\Software\ElcomSoft\Advanced Office Password Recovery|Recent file 9 +RegKey10=HKCU\Software\ElcomSoft\Advanced Office Password Recovery|Recent file 10 + +[Elcomsoft Advanced PDF Password Recovery *] +LangSecRef=3021 +Detect=HKCU\Software\ElcomSoft\Advanced PDF Password Recovery +Default=False +FileKey1=%ProgramFiles%\Elcomsoft Password Recovery\Advanced PDF Password Recovery|*.log;*log.txt +RegKey1=HKCU\Software\ElcomSoft\Advanced PDF Password Recovery\Recent Files + +[Elcomsoft Distributed Password Recovery *] +LangSecRef=3021 +Detect=HKCU\Software\ElcomSoft\Distributed Password Recovery +Default=False +FileKey1=%CommonAppData%\Elcomsoft Password Recovery\Distributed Password Recovery\Logs|*.* + +[Elcomsoft Internet Password Breaker *] +LangSecRef=3021 +Detect=HKCU\Software\ElcomSoft\Elcomsoft Internet Password Breaker +Default=False +FileKey1=%ProgramFiles%\Elcomsoft Password Recovery\Elcomsoft Internet Password Breaker|*.log;*log.txt + +[Elcomsoft Phone Password Breaker *] +LangSecRef=3021 +Detect=HKCU\Software\ElcomSoft\Elcomsoft Phone Password Breaker +Default=False +FileKey1=%AppData%\Elcomsoft\Elcomsoft Phone Password Breaker|*.log + +[Elcomsoft Proactive Password Auditor *] +LangSecRef=3021 +Detect=HKCU\Software\ElcomSoft\Elcomsoft Proactive Password Auditor +Default=False +FileKey1=%ProgramFiles%\Elcomsoft Password Recovery\Proactive Password Auditor|*.log;*log.txt + [Elcomsoft Wireless Security Auditor *] LangSecRef=3021 Detect=HKCU\Software\ElcomSoft\Elcomsoft Wireless Security Auditor @@ -7574,6 +7743,12 @@ DetectFile=%AppData%\DS Development\EAC Default=False FileKey1=%AppData%\DS Development\EAC|*.log +[EmailTray *] +LangSecRef=3024 +Detect=HKCU\Software\EmailTray +Default=False +FileKey1=%LocalLowAppData%\EmailTray|*.log|RECURSE + [EmEditor *] LangSecRef=3024 Detect=HKCU\Software\EmSoft\EmEditor v3 @@ -7737,6 +7912,7 @@ LangSecRef=3021 Detect=HKCU\Software\EuroSYSTEMS Default=False FileKey1=%ProgramFiles%\EUROSYSTEMS\SmartCut Pro|*.bak;*.tmp +FileKey2=%ProgramFiles%\EUROSYSTEMS\SmartCut Pro\Temp|*.*|RECURSE [EVE Online *] Section=Games @@ -8089,7 +8265,8 @@ RegKey1=HKCU\Software\JetCar\JetCar|Recent File List [FLEXnet *] LangSecRef=3021 -Detect=HKCU\Software\FlexNet +Detect1=HKCU\Software\FlexNet +Detect2=HKLM\System\CurrentControlSet\services\FLEXnet Licensing Service Default=False FileKey1=%CommonAppData%\FLEXnet|*.data_backup.*;*.log @@ -8439,12 +8616,18 @@ Default=False FileKey1=%CommonAppData%\Garmin\Logs|*.log;*.txt|RECURSE FileKey2=%Documents%\Garmin\Backups\*|*.*|RECURSE -[GARMIN MapSource *] +[Garmin MapSource *] LangSecRef=3024 Detect=HKCU\Software\Garmin\MapSource Default=False FileKey1=%AppData%\GARMIN\MapSource\TileCache|*.*|REMOVESELF +[GarrysMod Cache *] +Section=Games +DetectFile=%ProgramFiles%\Steam\steamapps\common\GarrysMod +Default=False +FileKey1=%ProgramFiles%\Steam\steamapps\common\GarrysMod|*.cache|RECURSE + [GasBuddy *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\45351D82.GasBuddy-FindCheapGasPrices_932xwky9axss4 @@ -8482,14 +8665,15 @@ FileKey7=%CommonAppData%\188F1432-103A-4ffb-80F1-36B633C5C9E1|*.*|REMOVESELF FileKey8=%CommonAppData%\9223B3E6-70DD-4e2f-965B-DD8E02D2E20B|*.*|REMOVESELF FileKey9=%CommonAppData%\9727E41D-AD6A-47cd-B9BC-CF630B6013FD|*.*|REMOVESELF FileKey10=%CommonAppData%\A73B37F8-7A4D-41f4-98A8-7F608CE8B98F|*.*|REMOVESELF -FileKey11=%CommonAppData%\E1864A66-75E3-486a-BD95-D1B7D99A84A7|*.*|REMOVESELF -FileKey12=%LocalAppData%\Downloaded Installations|*.*|REMOVESELF -FileKey13=%ProgramFiles%\34BE82C4-E596-4e99-A191-52C6199EBF69|*.*|REMOVESELF -FileKey14=%ProgramFiles%\38FDB89C-1EBD-4366-84B2-336D12CC3209|*.*|REMOVESELF -FileKey15=%ProgramFiles%\93E26451-CD9A-43A5-A2FA-C42392EA4001|*.*|REMOVESELF -FileKey16=%ProgramFiles%\188F1432-103A-4ffb-80F1-36B633C5C9E1|*.*|REMOVESELF -FileKey17=%ProgramFiles%\9223B3E6-70DD-4e2f-965B-DD8E02D2E20B|*.*|REMOVESELF -FileKey18=%ProgramFiles%\9727E41D-AD6A-47cd-B9BC-CF630B6013FD|*.*|REMOVESELF +FileKey11=%CommonAppData%\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB|*.log|RECURSE +FileKey12=%CommonAppData%\E1864A66-75E3-486a-BD95-D1B7D99A84A7|*.*|REMOVESELF +FileKey13=%LocalAppData%\Downloaded Installations|*.*|REMOVESELF +FileKey14=%ProgramFiles%\34BE82C4-E596-4e99-A191-52C6199EBF69|*.*|REMOVESELF +FileKey15=%ProgramFiles%\38FDB89C-1EBD-4366-84B2-336D12CC3209|*.*|REMOVESELF +FileKey16=%ProgramFiles%\93E26451-CD9A-43A5-A2FA-C42392EA4001|*.*|REMOVESELF +FileKey17=%ProgramFiles%\188F1432-103A-4ffb-80F1-36B633C5C9E1|*.*|REMOVESELF +FileKey18=%ProgramFiles%\9223B3E6-70DD-4e2f-965B-DD8E02D2E20B|*.*|REMOVESELF +FileKey19=%ProgramFiles%\9727E41D-AD6A-47cd-B9BC-CF630B6013FD|*.*|REMOVESELF [Geek Uninstaller *] LangSecRef=3024 @@ -8768,6 +8952,13 @@ Detect=HKCU\Software\Google\Picasa Default=False FileKey1=%LocalAppData%\Google\Picasa2Albums\backup|*.*|REMOVESELF +[Google Talk *] +LangSecRef=3022 +Detect=HKCU\Software\Google\Google Talk +Default=False +FileKey1=%LocalAppData%\Google\Google Talk\avatars|*.* +FileKey2=%ProgramFiles%\Google\Google Talk|*.log + [Google Toolbar Notifier *] LangSecRef=3022 Detect=HKCU\Software\Google\GoogleToolbarNotifier @@ -8964,9 +9155,10 @@ FileKey2=%LocalAppData%\Packages\Microsoft.HaloSpartanAssault_*\AC\Microsoft\Cry [HandBrake *] LangSecRef=3024 -DetectFile=%ProgramFiles%\HandBrake\Handbrake.exe +DetectFile=%ProgramFiles%\HandBrake Default=False -FileKey1=%ProgramFiles%\HandBrake|*.stackdump +FileKey1=%AppData%\HandBrake\logs|*.*|REMOVESELF +FileKey2=%ProgramFiles%\HandBrake|*.stackdump [Handle Regshot Reports *] LangSecRef=3024 @@ -9040,6 +9232,7 @@ Section=Games Detect=HKCU\Software\Blizzard Entertainment\Hearthstone Default=False FileKey1=%LocalAppData%\Blizzard\Hearthstone\Logs|*.* +FileKey2=%ProgramFiles%\Hearthstone|*.log;*.log.txt;*.dmp|RECURSE [Hearthstone Cache *] Section=Games @@ -9047,11 +9240,12 @@ Detect=HKCU\Software\Blizzard Entertainment\Hearthstone Default=False FileKey1=%LocalAppData%\Blizzard\Hearthstone\Cache|*.*|RECURSE -[Hedgewars VideoTemp *] +[Hedgewars *] Section=Games Detect=HKLM\Software\Hedgewars Default=False -FileKey1=%Documents%\Hedgewars\VideoTemp|*.* +FileKey1=%Documents%\Hedgewars\Logs|*.* +FileKey2=%Documents%\Hedgewars\VideoTemp|*.* [Helium Music Manager *] LangSecRef=3023 @@ -9118,6 +9312,14 @@ FileKey1=%CommonAppData%\HitmanPro\Logs|*.* FileKey2=%ProgramFiles%\Hitman Pro*\downloads|*.* FileKey3=%ProgramFiles%\Hitman Pro*\logs|*.htm FileKey4=%ProgramFiles%\Hitman Pro*\updates|*.* +FileKey5=%WinDir%\System32|HitmanPro*.log +FileKey6=%WinDir%\SysWOW64|HitmanPro*.log + +[HM NIS Edit *] +LangSecRef=3021 +Detect=HKCU\Software\HM Software\Nis Edit +Default=False +RegKey1=HKCU\Software\HM Software\Nis Edit\Recent [Holiday Express *] Section=Games @@ -9276,8 +9478,9 @@ DetectFile=%CommonAppData%\HP Default=False FileKey1=%CommonAppData%\HP\Installer\Temp|*.* FileKey2=%CommonAppData%\HP\Temp|*.* -FileKey3=%ProgramFiles%\HP\Temp|*.*|RECURSE -FileKey4=%WinDir%|*.dat.temp +FileKey3=%LocalAppData%\HP\AtInstall|*.log;*log.txt|RECURSE +FileKey4=%ProgramFiles%\HP\Temp|*.*|RECURSE +FileKey5=%WinDir%|*.dat.temp [HP Installation Files *] LangSecRef=3024 @@ -9376,11 +9579,12 @@ FileKey1=%AppData%\Microsoft\HTML Help|hh.dat;hhcolreg.dat;*.chw FileKey2=%CommonAppData%\Microsoft\HTML Help|hhcolreg.dat FileKey3=%WinDir%\Application Data\Microsoft\HTML Help|hh.dat -[Huawei Modem Driver *] +[Huawei Logs *] LangSecRef=3023 Detect=HKLM\Software\Huawei technologies Default=False -FileKey1=%ProgramFiles%\HUAWEI Modem Driver|*.log +FileKey1=%ProgramFiles%\BILDmobil\Log|*.* +FileKey2=%ProgramFiles%\HUAWEI Modem Driver|*.log [Hulu *] LangSecRef=3031 @@ -9424,12 +9628,14 @@ FileKey4=%LocalAppData%\Packages\*.HyperforYouTube_*\LocalState|*.*|RECURSE FileKey5=%LocalAppData%\Packages\*.HyperforYouTube_*\TempState|*.*|RECURSE RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\19120CensoredUser.HyperforYouTube_c0tqyanwsgfn6\SearchHistory -[HyperSnap 7 *] +[HyperSnap *] LangSecRef=3021 -Detect=HKCU\Software\Hyperionics\HyperSnap 7 +Detect1=HKCU\Software\Hyperionics\HyperSnap 7 +Detect2=HKCU\Software\Hyperionics\HyperSnap 8 Default=False -FileKey1=%ProgramFiles%\HyperSnap 7|*.url +FileKey1=%ProgramFiles%\HyperSnap *|*.url RegKey1=HKCU\Software\Hyperionics\HyperSnap 7\Recent File List +RegKey2=HKCU\Software\Hyperionics\HyperSnap 8\Recent File List [I2P NetDb *] LangSecRef=3022 @@ -9779,17 +9985,19 @@ Detect1=HKCU\Software\Intel Detect2=HKLM\Software\Intel Default=False FileKey1=%CommonAppData%\Intel|*.log;*.log.bak|RECURSE -FileKey2=%CommonAppData%\Intel\*\Logs|*.* -FileKey3=%ProgramFiles%\Intel\*|*.log;*Log.txt|RECURSE -FileKey4=%ProgramFiles%\Intel\InfInst|*.*|REMOVESELF -FileKey5=%SystemDrive%\Driver_allOS\MEI\Drivers\MEI\INTERNAL|*.log|RECURSE -FileKey6=%SystemDrive%\Intel\Logs|*.*|REMOVESELF -FileKey7=%UserProfile%\Intel\Logs|*.*|REMOVESELF -FileKey8=%WinDir%\debug\Intel\Logs|*.*|REMOVESELF -FileKey9=%WinDir%\System32|Default_error_Stack-*.txt;Gms.log -FileKey10=%WinDir%\System32\config\systemprofile\Intel\Logs|*.*|REMOVESELF -FileKey11=%WinDir%\SysWOW64|Gms.log -FileKey12=%WinDir%\SysWOW64\config\systemprofile\Intel\Logs|*.*|REMOVESELF +FileKey2=%CommonAppData%\Intel(R) Update Manager\AppData|ium.log +FileKey3=%CommonAppData%\Intel\*\Logs|*.* +FileKey4=%ProgramFiles%\Intel\*|*.log;*Log.txt|RECURSE +FileKey5=%ProgramFiles%\Intel\InfInst|*.*|REMOVESELF +FileKey6=%SystemDrive%|IFRToolLog.txt +FileKey7=%SystemDrive%\Driver_allOS\MEI\Drivers\MEI\INTERNAL|*.log|RECURSE +FileKey8=%SystemDrive%\Intel\Logs|*.*|REMOVESELF +FileKey9=%UserProfile%\Intel\Logs|*.*|REMOVESELF +FileKey10=%WinDir%\debug\Intel\Logs|*.*|REMOVESELF +FileKey11=%WinDir%\System32|Default_error_Stack-*.txt;Gms.log +FileKey12=%WinDir%\System32\config\systemprofile\Intel\Logs|*.*|REMOVESELF +FileKey13=%WinDir%\SysWOW64|Gms.log +FileKey14=%WinDir%\SysWOW64\config\systemprofile\Intel\Logs|*.*|REMOVESELF [Intel Shader Cache *] LangSecRef=3024 @@ -10049,6 +10257,30 @@ DetectFile=%ProgramFiles%\IObit\LiveUpdate Default=False FileKey1=%ProgramFiles%\IObit\LiveUpdate|*.log|RECURSE +[IObit Malware Fighter *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\IObit\IObit Malware Fighter +Default=False +FileKey1=%ProgramFiles%\IObit\IObit Malware Fighter\log|*.*|RECURSE + +[IObit Smart Defrag 3 *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\IObit\Smart Defrag 3 +Default=False +FileKey1=%ProgramFiles%\IObit\Smart Defrag 3\Temp|*.*|RECURSE + +[IObit Start Menu 8 Freeware Programs Installer *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\IObit\Start Menu 8 +Default=False +FileKey1=%ProgramFiles%\IObit\Start Menu 8\Freeware|*.exe + +[IObit Surfing Protection *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\IObit\Surfing Protection +Default=False +FileKey1=%ProgramFiles%\IObit\Surfing Protection|*.log + [IObit Uninstaller *] LangSecRef=3024 DetectFile=%AppData%\IObit\IObit Uninstaller @@ -10056,6 +10288,12 @@ Default=False FileKey1=%AppData%\IObit\IObit Uninstaller\*Log|*.log FileKey2=%ProgramFiles%\IObit\iObit Uninstaller|*.log|RECURSE +[Iperius Backup *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Iperius Backup +Default=False +FileKey1=%CommonAppData%\IperiusBackup\Logs|*.*|RECURSE + [iPod-Cloner *] LangSecRef=3023 Detect=HKCU\Software\iPod-Cloner @@ -10091,6 +10329,12 @@ FileKey2=%CommonAppData%\iSkysoft Video Converter*\Temp*Dir|*.*|RECURSE FileKey3=%ProgramFiles%\iSkysoft\Video Converter*\Log|*.*|RECURSE FileKey4=%ProgramFiles%\iSkysoft\Video Converter*\TempThumbDir|*.*|RECURSE +[IsoBuster *] +LangSecRef=3021 +Detect=HKCU\Software\Smart Projects\IsoBuster +Default=False +RegKey1=HKCU\Software\Smart Projects\IsoBuster\RecentImages + [iSpy *] LangSecRef=3021 Detect=HKCU\Software\ISpy\ISPY @@ -10432,7 +10676,8 @@ FileKey1=%CommonAppData%\Kaspersky Lab|*.dmp;*.dmp.stat;*.log FileKey2=%CommonAppData%\Kaspersky Lab\*\Bases\Cache|*.*|RECURSE FileKey3=%CommonAppData%\Kaspersky Lab\*\Data\Updater\Temporary Files|*.*|RECURSE FileKey4=%CommonAppData%\Kaspersky Lab\*\Temp|*.* -FileKey5=%ProgramFiles%\Kaspersky Lab\NetworkAgent\~dumps|*.* +FileKey5=%CommonAppData%\Kaspersky Lab\UCPStorage|ucp_agent.bin.bak +FileKey6=%ProgramFiles%\Kaspersky Lab\NetworkAgent\~dumps|*.* [Kaspersky Now *] LangSecRef=3031 @@ -10728,6 +10973,12 @@ DetectFile=%LocalAppData%\Skillbrains\lightshot Default=False FileKey1=%LocalAppData%|updater.log +[Lightworks *] +LangSecRef=3021 +Detect=HKLM\Software\Lightworks +Default=False +FileKey1=%Public%\Documents\Lightworks\Logs|*.*|REMOVESELF + [Lili: Child of Geos - Complete Edition *] Section=Games Detect=HKCU\Software\Valve\Steam\apps\266490 @@ -10795,7 +11046,7 @@ Detect1=HKCU\Software\Logitech\DesktopMessenger Detect2=HKLM\Software\Logitech\DesktopMessenger Detect3=HKLM\Software\Logitech\Logitech Desktop Messenger Default=False -FileKey1=%ProgramFiles%\Logitech\Desktop Messenger|*.log;*.bak +FileKey1=%ProgramFiles%\Logitech\Desktop Messenger|*.log;*.bak|RECURSE [Logitech Harmony Remote Cache *] LangSecRef=3021 @@ -10919,7 +11170,7 @@ LangSecRef=3024 Detect=HKCU\Software\Macrium\Reflect Default=False FileKey1=%CommonAppData%\Macrium|*.log|RECURSE -FileKey2=%CommonAppData%\Macrium\Reflect|*.html;*.vsslog +FileKey2=%CommonAppData%\Macrium\Reflect|*.html;*.vsslog;*.tmp FileKey3=%CommonAppData%\Macrium\waik|waiklog.txt FileKey4=%SystemDrive%|ref~tmp~.txt;Reflect_Install.log;rescuepe.log @@ -11083,6 +11334,12 @@ DetectFile=%AppData%\Broderbund\Mavis Default=False FileKey1=%AppData%\Broderbund\Mavis|logfile.* +[Max Recorder *] +LangSecRef=3023 +Detect=HKLM\Software\MaxRecorder +Default=False +FileKey1=%LocalAppData%\MaxRecorder|*.tmp|RECURSE + [Maxprog iCash *] LangSecRef=3021 Detect=HKCR\iCash @@ -11125,7 +11382,8 @@ FileKey1=%AppData%\Maxthon3\Users\*\LocalStorage|*.*|RECURSE [McAfee *] LangSecRef=3024 -Detect=HKLM\Software\McAfee +Detect1=HKCU\Software\SiteAdvisor +Detect2=HKLM\Software\McAfee Default=False FileKey1=%CommonAppData%\McAfee\AMCore\datreputation\Logs|*.*|RECURSE FileKey2=%CommonAppData%\McAfee\Common Framework\AgentEvents|*.* @@ -11136,12 +11394,15 @@ FileKey6=%CommonAppData%\McAfee\MHN|*.bak FileKey7=%CommonAppData%\McAfee\modulecoreservice.exe|*.txt FileKey8=%CommonAppData%\McAfee\MPF|*.tmp FileKey9=%CommonAppData%\McAfee\MPF\data|*.*|RECURSE -FileKey10=%CommonAppData%\McAfee\MSC\Logs|*.log -FileKey11=%CommonAppData%\McAfee\SiteAdvisor|*.txt|RECURSE -FileKey12=%CommonAppData%\McAfee\Update|*.*|RECURSE -FileKey13=%CommonAppData%\McAfee\VirusScan\Data|*.log;*.old -FileKey14=%CommonAppData%\McAfee\VirusScan\Logs|*.*|RECURSE -FileKey15=%CommonAppData%\Network Associates\Common Framework\AgentEvents|*.* +FileKey10=%CommonAppData%\McAfee\MSC\Cache|McSubDB.Bak +FileKey11=%CommonAppData%\McAfee\MSC\Logs|*.log +FileKey12=%CommonAppData%\McAfee\SiteAdvisor|*.txt;*.log;log.txt|RECURSE +FileKey13=%CommonAppData%\McAfee\Uninstall.exe|log.txt +FileKey14=%CommonAppData%\McAfee\Update|*.*|RECURSE +FileKey15=%CommonAppData%\McAfee\VirusScan\Data|*.log;*.old +FileKey16=%CommonAppData%\McAfee\VirusScan\Logs|*.*|RECURSE +FileKey17=%CommonAppData%\Network Associates\Common Framework\AgentEvents|*.* +FileKey18=%ProgramData%\McAfee\SiteAdvisor|*.tmp|RECURSE [McPixel *] Section=Games @@ -11542,7 +11803,7 @@ FileKey3=%ProgramFiles%\MiKTeX\miktex\config|*.log Section=Games DetectFile=%AppData%\.minecraft Default=False -FileKey1=%AppData%\.minecraft|*.log;*.log.*|RECURSE +FileKey1=%AppData%\.minecraft|*.log;*.log.*;nativelog.txt|RECURSE FileKey2=%AppData%\.minecraft\crash-reports|*.* FileKey3=%AppData%\.minecraft\debug|*.* FileKey4=%AppData%\.minecraft\stats|*.old @@ -11715,9 +11976,20 @@ FileKey1=%ProgramFiles%\Motherboard Monitor 5\Log|*.*|REMOVESELF [Motorola Device Manager *] LangSecRef=3024 -DetectFile=%AppData%\Motorola\MotoHelper +Detect=HKLM\Software\Motorola Default=False FileKey1=%AppData%\Motorola\MotoHelper|*.log +FileKey2=%CommonAppData%\Motorola\SUE|*.log +FileKey3=%ProgramFiles%\Motorola|*.log|RECURSE +FileKey4=%ProgramFiles%\Motorola Mobility\DeviceSoftwareUpdate|*.log +FileKey5=%ProgramFiles%\Motorola Mobility\Motorola Device Manager|*.log + +[Motorola Device Manager Firmwares *] +LangSecRef=3024 +Detect=HKLM\Software\Motorola +Default=False +Warning=This will delete your Firmwares. You have to download again. +FileKey1=%CommonAppData%\Motorola\SUE\Firmwares|*.* [Mount & Blade *] Section=Games @@ -12700,6 +12972,12 @@ Default=False FileKey1=%ProgramFiles%\MyDefrag *|*.log FileKey2=%ProgramFiles%\MyDefrag *\LOGs|*.* +[MyPC Backup *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\MyPC Backup +Default=False +FileKey1=%ProgramFiles%\MyPC Backup\log|*.* + [MyPhoneExplorer *] LangSecRef=3024 Detect=HKCU\Software\MyPhoneExplorer @@ -12770,6 +13048,20 @@ Warning=Fixes corrupt cache and cleans cache bloat. The first game and map launc FileKey1=%AppData%\Natural Selection 2|log.txt FileKey2=%AppData%\Natural Selection 2\cache|*.*|RECURSE +[NaturalReader Free 12 *] +LangSecRef=3021 +Detect=HKLM\Software\Naturalreaderfree +Default=False +FileKey1=%Documents%\Naturalsoft|nrtemp.txt +FileKey2=%Documents%\Naturalsoft\log|*.*|RECURSE +FileKey3=%ProgramFiles%\Naturalsoft\Free12\log|*.* + +[NaturalReader Free 12 Setup Files *] +LangSecRef=3021 +Detect=HKLM\Software\Naturalreaderfree +Default=False +FileKey1=%Documents%\Naturalsoft|*.msi|RECURSE + [NBC News *] LangSecRef=3031 Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\msnbc.comDigitalNetwork.msnbc.com_amdjbdaxqsje6 @@ -12781,6 +13073,12 @@ FileKey4=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\PRICache FileKey5=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\AC\Temp|*.* FileKey6=%LocalAppData%\Packages\msnbc.comDigitalNetwork.msnbc.com_*\TempState|*.*|RECURSE +[NCH Software Switch Audio-Converter *] +LangSecRef=3023 +Detect=HKCU\Software\NCH Software\Switch +Default=False +FileKey1=%AppData%\NCH Software\Switch\Logs|*.*|RECURSE + [Neostar CMS Station Client *] LangSecRef=3024 Detect=HKLM\Software\company\Neostar CMS @@ -13132,6 +13430,15 @@ DetectFile=%LocalAppData%\NordVPN Default=False FileKey1=%LocalAppData%\NordVPN\logs|*.* +[Norman Security Suite *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Norman +Default=False +FileKey1=%ProgramFiles%\Norman|*.log +FileKey2=%ProgramFiles%\Norman\Download|*.* +FileKey3=%ProgramFiles%\Norman\Logs|*.* +FileKey4=%ProgramFiles%\Norman\Temp|*.* + [Norton *] LangSecRef=3024 DetectFile=%CommonAppData%\Norton @@ -13140,6 +13447,12 @@ FileKey1=%CommonAppData%\Norton|*.log;*.txt FileKey2=%CommonAppData%\Norton\LocalDumps|*.dmp FileKey3=%CommonAppData%\NortonInstaller\Logs|*.*|RECURSE +[Norton Online Backup *] +LangSecRef=3024 +DetectFile=%CommonAppData%\Symantec\Norton Online Backup +Default=False +FileKey1=%CommonAppData%\Symantec\Norton Online Backup|*.log.txt;*.log|RECURSE + [Norton Power Eraser *] LangSecRef=3024 DetectFile=%CommonAppData%\Norton\NPE\NPEsettings.dat @@ -13355,8 +13668,9 @@ DetectFile4=%WinDir%\SysWOW64\OEM Default=False FileKey1=%CommonAppData%\oem|*.log|RECURSE FileKey2=%SystemDrive%\OEM|*.log|RECURSE -FileKey3=%WinDir%\System32\OEM|*.log -FileKey4=%WinDir%\SysWOW64\OEM|*.log +FileKey3=%WinDir%\oem|*.log;*.log.txt|RECURSE +FileKey4=%WinDir%\System32\OEM|*.log +FileKey5=%WinDir%\SysWOW64\OEM|*.log [Off-Road Drive *] Section=Games @@ -13526,7 +13840,8 @@ FileKey2=%AppData%\OpenOffice*\*\user\config\imagecache|*.* FileKey3=%AppData%\OpenOffice*\*\user\registry\cache|*.* FileKey4=%AppData%\OpenOffice*\*\user\registry\data\org\openoffice\Office|Views.xcu;Writer.xcu;Common.xcu;Histories.xcu FileKey5=%AppData%\OpenOffice*\*\user\registry\data\org\openoffice\ucb|Hierarchy.xcu;Store.xcu -FileKey6=%ProgramFiles%\OpenOffice*\share\uno_packages\cache\uno_packages|*.tmp;*.log;log.txt +FileKey6=%ProgramFiles%\OpenOffice*\program|*.log|RECURSE +FileKey7=%ProgramFiles%\OpenOffice*\share\uno_packages\cache\uno_packages|*.tmp;*.log;log.txt [OpenOffice.org Setup Files *] LangSecRef=3021 @@ -13863,6 +14178,13 @@ DetectFile=%CommonAppData%\PC optimizer pro Default=False FileKey1=%CommonAppData%\PC Optimizer Pro\Logs|*.* +[PC TechZone Merlin InstantFeedback *] +LangSecRef=3024 +DetectFile=%ProgramFiles%\PC TechZone\Merlin InstantFeedback +Default=False +FileKey1=%ProgramFiles%\PC TechZone\Merlin InstantFeedback|Log.txt;seller.txt;InstantFeedback.exe.UnhandledExceptionLog.txt;*.tmp +FileKey2=%ProgramFiles%\PC TechZone\Merlin InstantFeedback\Logs|*.* + [PC Tools Performance Toolkit *] LangSecRef=3024 DetectFile=%AppData%\PC Tools Performance Toolkit @@ -13927,6 +14249,12 @@ Default=False RegKey1=HKCU\Software\GRAHL\PDFAnnotator\3.0\Files\MRUItems RegKey2=HKCU\Software\GRAHL\PDFAnnotator\4.0\Files\MRUItems +[PDF Editor 4 *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PDF Editor 4 +Default=False +FileKey1=%ProgramFiles%\PDF Editor 4|*.log;*.diz + [PDF Plus *] LangSecRef=3021 DetectFile=%AppData%\Zeon\DocuCom\PDF Plus @@ -13959,6 +14287,13 @@ Default=False FileKey1=%SystemDrive%\Documents and Settings\LocalService\Application Data\PeerNetworking|*.*|RECURSE FileKey2=%WinDir%\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking|*.*|RECURSE +[Pegasus Mail *] +LangSecRef=3024 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pegasus Mail +Default=False +FileKey1=%SystemDrive%\PMAIL\MAIL|SYSLOG.PM +FileKey2=%SystemDrive%\PMAIL\Programs|*.log + [Pelles C *] LangSecRef=3021 Detect=HKCU\Software\Pelle Orinius\PellesC @@ -14367,12 +14702,14 @@ DetectFile=%AppData%\PriceGong Default=False FileKey1=%AppData%\PriceGong\tmp|*.*|RECURSE -[Prince of Persia: The Two Thrones *] +[Prince of Persia *] Section=Games +Detect1=HKLM\Software\Ubisoft\Prince of Persia The Sands of Time +Detect2=HKLM\Software\Ubisoft\Prince of Persia Warrior Within DetectFile=%ProgramFiles%\Ubisoft\Prince of Persia T2T Default=False -FileKey1=%LocalAppData%\Ubisoft\Prince of Persia T2T|*.log -FileKey2=%ProgramFiles%\Ubisoft\Prince of Persia T2T|*.log +FileKey1=%LocalAppData%\Ubisoft\Prince of Persia *|*.log +FileKey2=%ProgramFiles%\Ubisoft\Prince of Persia *|*.log;POPError.DAT [Print 3D *] DetectOS=10.0| @@ -15183,6 +15520,7 @@ Detect1=HKCU\Software\Microsoft\Microsoft Games\Rise of Nations Detect2=HKCU\Software\Microsoft\Microsoft Games\RiseofNationsExpansion Default=False FileKey1=%AppData%\Microsoft Games\Rise of Nations\Logs|*.* +FileKey2=%ProgramFiles%\Microsoft Games\Rise of Nations\Logs|*.* [Rise of the Tomb Raider *] Section=Games @@ -15453,6 +15791,22 @@ Default=False FileKey1=%SystemDrive%\ScanDefrag|*.log FileKey2=%SystemDrive%\ScanDefrag\logs|*.txt +[ScanSnap *] +LangSecRef=3021 +Detect=HKCU\Software\PFU\ScanToOffice +DetectFile1=%ProgramFiles%\Common Files\PFU\ScanSnap\ScanToOffice +DetectFile2=%ProgramFiles%\PFU\ScanSnap +Default=False +FileKey1=%CommonProgramFiles%\PFU\ScanSnap\ScanToOffice|*.log|RECURSE +FileKey2=%LocalAppData%\PFU|*.log|RECURSE +FileKey3=%LocalAppData%\PFU\SSFolderTemp|*.*|RECURSE +FileKey4=%ProgramFiles%\PFU|*.log|RECURSE +FileKey5=%WinDir%\System32\config\systemprofile\AppData\Local\PFU|*.log|RECURSE +FileKey6=%WinDir%\System32\config\systemprofile\AppData\Local\PFU\SSFolderTemp|*.*|RECURSE +FileKey7=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\PFU|*.log|RECURSE +FileKey8=%WinDir%\SysWOW64\config\systemprofile\AppData\Local\PFU\SSFolderTemp|*.*|RECURSE +RegKey1=HKCU\Software\PFU\ScanToOffice\History + [Screenpresso *] LangSecRef=3024 DetectFile=%AppData%\Learnpulse\Screenpresso @@ -16199,6 +16553,14 @@ Default=False FileKey1=%AppData%\Sony\Media Manager|*.log;*log.txt FileKey2=%AppData%\Sony\Media Manager\Thumbnails|*.*|RECURSE +[Sony Mobile Emma *] +LangSecRef=3021 +Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Emma +Default=False +FileKey1=%ProgramFiles%\Sony Mobile\Emma\log|*.* +FileKey2=%ProgramFiles%\Sony Mobile\Emma\temp|*.* +FileKey3=%ProgramFiles%\Sony Mobile\Emma\workspace\.metadata|.log + [Sony SonicStage *] LangSecRef=3021 DetectFile=%AppData%\Sony\SonicStage @@ -16212,6 +16574,12 @@ DetectFile=%AppData%\Sony Corporation\Sound Organizer Default=False FileKey1=%AppData%\Sony Corporation\Sound Organizer|*.log +[Sony VAIO *] +LangSecRef=3024 +Detect=HKLM\Software\Sony Corporation +Default=False +FileKey1=%CommonAppData%\Sony Corporation\VAIO *|*.log;Log.txt + [Sony Vegas Pro *] LangSecRef=3023 Detect1=HKLM\Software\Sony Creative Software\Vegas @@ -16220,6 +16588,12 @@ Default=False FileKey1=%AppData%\Sony|*.log FileKey2=%LocalAppData%\Sony\Vegas Pro\*|*.log +[Sony Xperia Flashtool *] +LangSecRef=3024 +Detect=HKLM\Software\Flashtool +Default=False +FileKey1=%SystemDrive%\Flashtool|*.log + [Sorcery! Parts 1 and 2 *] Section=Games Detect=HKCU\Software\Valve\Steam\Apps\105430 @@ -17161,6 +17535,13 @@ FileKey2=%AppData%\TeraCopy\History|*.* FileKey3=%ProgramFiles%\TeraCopy|FileList.dat;Transfer.log RegKey1=HKCU\Software\Code Sector\TeraCopy|LastTargetFolder +[Terasology *] +Section=Games +DetectFile=%AppData%\.terasology +Default=False +FileKey1=%AppData%\.terasology|*.log +FileKey2=%AppData%\.terasology\logs|*.*|REMOVESELF + [Terraria *] Section=Games Detect=HKCU\Software\Valve\Steam\Apps\105600 @@ -17464,6 +17845,31 @@ DetectFile=%AppData%\tixati Default=False FileKey1=%AppData%\tixati|upnp_diagnostic_log.txt +[Tixati Incomplete Pieces *] +LangSecRef=3021 +DetectFile=%AppData%\tixati +Default=False +Warning=This will delete your incomplete pieces. Just delete, if you really need. +FileKey1=%AppData%\tixati\incomplete-pieces|*.* + +[Tobit David *] +LangSecRef=3024 +Detect=HKCU\Software\Tobit +Default=False +FileKey1=%SystemDrive%\David\Apps\Dvgrab\Code|*.chk +FileKey2=%SystemDrive%\David\Apps\Postman\Code|*.chk +FileKey3=%SystemDrive%\David\Apps\Webbox\Code|*.log +FileKey4=%SystemDrive%\David\Archive\SYSTEM\DAVID\Errlog|*.* +FileKey5=%SystemDrive%\David\Archive\SYSTEM\pbxpense\log|*.* +FileKey6=%SystemDrive%\David\Archive\USER\*\system\trash|*.* +FileKey7=%SystemDrive%\David\Archive\USER\*\temp|*.* +FileKey8=%SystemDrive%\David\Code|*.old;*.chk;*.log +FileKey9=%SystemDrive%\David\Code\Database\MSSQL*DAVID\MSSQL\LOG|ERRORLOG;ERRORLOG.*;FDLAUNCHERRORLOG;FDLAUNCHERRORLOG.*;log_*.trc;SQL*.LOG* +FileKey10=%SystemDrive%\David\Code\Temp|*.* +FileKey11=%SystemDrive%\David\Import\System|I*.001 +FileKey12=%SystemDrive%\David\Tld\COMMON|*DAVID.LOG +FileKey13=%SystemDrive%\David\Tld\Port\Extra|*.chk + [Tom Clancy's Ghost Recon *] Section=Games Detect=HKCU\Software\Valve\Steam\Apps\15300 @@ -17697,10 +18103,12 @@ FileKey1=%AppData%\JAM Software\TreeSize *|GlobalOptions.bak0 [Trend Micro *] LangSecRef=3023 -Detect=HKCU\Software\Trend Micro +Detect1=HKCU\Software\Trend Micro +Detect2=HKLM\Software\TrendMicro DetectFile=%CommonAppData%\Trend Micro Default=False FileKey1=%CommonAppData%\Trend Micro|*.log +FileKey2=%ProgramFiles%\Trend Micro|*.log;URLLog.dat|RECURSE [Trend Micro AntiRansomware Tool *] LangSecRef=3021 @@ -17708,11 +18116,12 @@ DetectFile=%ProgramFiles%\AntiRansomware2.0 Default=False FileKey1=%CommonAppData%\AntiRansomware|*.log -[TrendMicro RUBotted *] +[Trend Micro RUBotted *] LangSecRef=3024 Detect=HKLM\Software\TrendMicro\RUBotted Default=False -FileKey1=%ProgramFiles%\Trend Micro\RUBotted\DebugLogs|*.*|REMOVESELF +FileKey1=%CommonAppData%\Trend Micro\RUBotted\Logs|*.*|REMOVESELF +FileKey2=%ProgramFiles%\Trend Micro\RUBotted\DebugLogs|*.*|REMOVESELF [Tribes: Ascend *] Section=Games @@ -17922,11 +18331,17 @@ Detect=HKCU\Software\Valve\Steam\Apps\1930 Default=False FileKey1=%Documents%\TwoWorlds Files\FontsCache|*.tmp +[Tzip *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\Tzip +Default=False +FileKey1=%ProgramFiles%\Tzip|*.temp + [Ubisoft Game Launcher *] Section=Games DetectFile=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher Default=False -FileKey1=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher|*.log +FileKey1=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher|*.log;orbitdll_*_log.txt;launcher_log.txt;Installed_files.txt;version.txt FileKey2=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Cache\assets|*.* FileKey3=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Cache\http*|*.*|RECURSE FileKey4=%ProgramFiles%\Ubisoft\Ubisoft Game Launcher\Logs|*.* @@ -18139,6 +18554,17 @@ Detect=HKCU\Software\Microsoft\Windows Default=False RegKey1=HKU\.DEFAULT\Software\Classes\Local Settings\MrtCache +[V - The File Viewer *] +LangSecRef=3024 +Detect=HKCU\Software\Prineas\FileViewer +Default=False +FileKey1=%AppData%\V|*.log +RegKey1=HKCU\Software\Prineas\FileViewer\History +RegKey2=HKCU\Software\Prineas\FileViewer\PathC +RegKey3=HKCU\Software\Prineas\FileViewer\QathH +RegKey4=HKCU\Software\Prineas\FileViewer\VCurrentPath +RegKey5=HKCU\Software\Prineas\FileViewer\VCurrentPath1 + [V&V Messenger Chat History *] LangSecRef=3022 DetectFile=%AppData%\AJabber @@ -18273,6 +18699,13 @@ DetectFile=%AppData%\VirtuaWin Default=False FileKey1=%AppData%\VirtuaWin|virtuawin.log +[Vizible Player *] +LangSecRef=3023 +Detect=HKLM\Software\Vizible +Default=False +FileKey1=%AppData%\Vizible Player\3DClient|*.log +FileKey2=%ProgramFiles%\Vizible Player\Dependencies|*.log + [Vizzed Retro Game Room *] LangSecRef=3023 DetectFile=%LocalLowAppData%\VizzedRgr @@ -18311,17 +18744,11 @@ FileKey7=%LocalAppData%\VMware\VMware vCenter Converter Standalone Client\Logs|* LangSecRef=3022 Detect=HKCU\Software\Vodafone Default=False -FileKey1=%AppData%\Vodafone\Vodafone Mobile Broadband\Log|*.* -FileKey2=%CommonAppData%\Vodafone\Log|*.* -FileKey3=%ProgramFiles%\Vodafone\Vodafone Mobile Broadband\Bin|SwiHpAux.log -FileKey4=%WinDir%|ModemLog_*.txt - -[Vodafone Database *] -LangSecRef=3022 -Detect=HKCU\Software\Vodafone -Default=False -Warning=This will delete your incoming SMS database. -FileKey1=%AppData%\Vodafone\Vodafone Mobile Broadband\UserData|VodafoneMobileBroadband.mdb +FileKey1=%AppData%\Vodafone\Vodafone Mobile *\Log|*.* +FileKey2=%AppData%\Vodafone\Vodafone Mobile Connect\Temp|*.* +FileKey3=%CommonAppData%\Vodafone\Log|*.* +FileKey4=%ProgramFiles%\Vodafone\Vodafone Mobile Broadband\Bin|SwiHpAux.log +FileKey5=%WinDir%|ModemLog_*.txt [Voice Recorder *] DetectOS=10.0| @@ -18554,6 +18981,15 @@ Default=False FileKey1=%Documents%\Abelssoft\WashAndGo\Backups|*.* FileKey2=%LocalAppData%\Abelssoft\WashAndGo\Backups|*.* +[Watto Studios Game Extractor *] +LangSecRef=3021 +DetectFile=%ProgramFiles%\Game Extractor +Default=False +FileKey1=%ProgramFiles%\Game Extractor\extract|*.* +FileKey2=%ProgramFiles%\Game Extractor\logs|*.* +FileKey3=%ProgramFiles%\Game Extractor\previews|*.* +FileKey4=%ProgramFiles%\Game Extractor\temp|*.* + [Wave Systems Corp *] LangSecRef=3021 DetectFile=%AppData%\Wave Systems Corp @@ -18756,6 +19192,13 @@ RegKey4=HKCU\Software\Softany\WinCHM|RecentFile4 RegKey5=HKCU\Software\Softany\WinCHM|RecentFile5 RegKey6=HKCU\Software\Softany\WinCHM|RecentFile6 +[WinDjView *] +LangSecRef=3024 +Detect=HKCU\Software\Andrew Zhezherun\WinDjView +Default=False +RegKey1=HKCU\Software\Andrew Zhezherun\WinDjView\Documents +RegKey2=HKCU\Software\Andrew Zhezherun\WinDjView\Recent File List + [Windows 7 Manager *] LangSecRef=3024 Detect=HKCU\Software\Yamicsoft\Windows 7 Manager @@ -18784,7 +19227,7 @@ RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentV LangSecRef=3024 Detect=HKLM\Software\Microsoft\Windows Defender Default=False -FileKey1=%CommonAppData%\Microsoft\Windows Defender\Network Inspection System\Support|*.txt +FileKey1=%CommonAppData%\Microsoft\Windows Defender\Network Inspection System\Support|*.txt;NisLog.txt.bak FileKey2=%CommonAppData%\Microsoft\Windows Defender\Scans|*.bin* FileKey3=%CommonAppData%\Microsoft\Windows Defender\Scans\BackupStore|*.* FileKey4=%CommonAppData%\Microsoft\Windows Defender\Scans\History\CacheManager|*.*|RECURSE @@ -18873,6 +19316,7 @@ FileKey8=%LocalAppData%\Packages\Microsoft.WindowsFileManager_*\TempState|*.*|RE LangSecRef=3025 Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\WIA Default=False +FileKey1=%UserProfile%|Sti_Trace.log RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\WIA [Windows Installer *] @@ -19258,7 +19702,7 @@ FileKey1=%ProgramFiles%\WinPcap|*.log LangSecRef=3024 Detect=HKCU\Software\WinRAR Default=False -FileKey1=%ProgramFiles%\WinRAR|*.tmp|RECURSE +FileKey1=%ProgramFiles%\WinRAR|*.tmp;*.diz|RECURSE RegKey1=HKCU\Software\WinRAR SFX RegKey2=HKCU\Software\WinRAR\DialogEditHistory RegKey3=HKCU\Software\WinRAR\General\Info|CommentFile @@ -19408,6 +19852,12 @@ FileKey5=%CommonAppData%\Wondershare\WAF\ProductFeatures\*Logs|*.*|RECURSE FileKey6=%CommonAppData%\Wondershare\WSRoot|*.tmp FileKey7=%CommonAppData%\Wondershare\WSRoot\Logs|*.*|RECURSE +[Wondershare Filmora 9 *] +LangSecRef=3023 +DetectFile=%ProgramFiles%\Wondershare\Filmora9 +Default=False +FileKey1=%ProgramFiles%\Wondershare\Filmora9\log|*.*|REMOVESELF + [Wondershare Helper Compact *] LangSecRef=3021 Detect=HKLM\Software\Wondershare\Wondershare Helper Compact @@ -19654,6 +20104,13 @@ FileKey1=%LocalAppData%\Xenocode\Sandbox|*.*|REMOVESELF FileKey2=%WinDir%\XSxS|*.*|REMOVESELF RegKey1=HKCU\Software\Xenocode\SandboxCache +[XeroBank Browser *] +LangSecRef=3022 +DetectFile=%ProgramFiles%\XeroBank +Default=False +FileKey1=%ProgramFiles%\XeroBank\App\Browser\temp|*.*|RECURSE +FileKey2=%UserProfile%\Desktop|xBBrowser_Client.log + [Xerox Printer Driver *] LangSecRef=3021 DetectFile=%CommonAppData%\Xerox\PrinterDriver