HEUR:Trojan.Win32.Generic (Kaspersky), Gen:Variant.Graftor.143298 (B) (Emsisoft), Gen:Variant.Graftor.143298 (AdAware), Trojan.Win32.Swrort.3.FD, GenericInjector.YR, GenericDownloader.YR (Lavasoft MAS)Behaviour: Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 59befa5b532e081e080665ee6be88751
SHA1: cb6cc1449151d4a2a490471168fd3786951d7874
SHA256: b35b1a08b4bd0a517b98425cb6b772255886b1aee781d4ca593390fac8134ca3
SSDeep: 98304:LBEU4hyNSFE9qo4pqY60rKogw6sgbqXOLQVEIX/gjPLOqlajvBd :LBExkN5wo4YntZqXAQVZAdla1d
Size: 7262720 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: BorlandDelphi30, BorlandDelphiv30, MicrosoftWindowsShortcutfile, BorlandDelphiv60v70_v2, UPolyXv05_v6
Company: no certificate found
Created at: 2014-05-21 00:57:29
Analyzed on: Windows7 SP1 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
1.exe:2104
%original file name%.exe:1744
The Trojan injects its code into the following process(es):
ccleaner.exe:704
svchost.exe:2208
Explorer.EXE:244
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process 1.exe:2104 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\system\RealTek.exe (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm2.txt (240 bytes)
The process %original file name%.exe:1744 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1.exe (355 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ccleaner.exe (1023 bytes)
The process ccleaner.exe:704 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabBDB3.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarBDB4.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\ACF244F1A10D4DBED0D88EBA0C43A9B5_16756CC7371BB76A269719AA1471E96C (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPS1JHSL\app_cc_pro_trialkey[1].htm (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9D23VSCD2FF435EXK196.temp (388 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30EV4AVE\verify[1].htm (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\ACF244F1A10D4DBED0D88EBA0C43A9B5_16756CC7371BB76A269719AA1471E96C (1476 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabBDB3.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarBDB4.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite-wal (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\webappsstore.sqlite-shm (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\webappsstore.sqlite-wal (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite-shm (0 bytes)
Registry activity
The process 1.exe:2104 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Policies" = "C:\Windows\System\RealTek.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
"Policies" = "C:\Windows\System\RealTek.exe"
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6QMO85S6-1733-836C-Q44E-7J4GSXLDW1N6}]
"StubPath" = "C:\Windows\System\RealTek.exe Restart"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"HKCU" = "C:\Windows\System\RealTek.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HKLM" = "C:\Windows\System\RealTek.exe"
The process %original file name%.exe:1744 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
"AutoDetect" = "1"
[HKCU\Software\Classes\Local Settings\MuiCache\2F\52C64B7E]
"LanguageList" = "en-US, en"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process ccleaner.exe:704 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASMANCS]
"MaxFileSize" = "1048576"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"DefaultConnectionSettings" = "46 00 00 00 09 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASMANCS]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASAPI32]
"EnableConsoleTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASAPI32]
"FileDirectory" = "%windir%\tracing"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Piriform\CCleaner]
"CheckTrialOffer" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad]
"WpadLastNetwork" = "{24C5EDBC-2851-452A-B521-5DA992F6C1B5}"
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASAPI32]
"FileTracingMask" = "4294901760"
"MaxFileSize" = "1048576"
[HKCU\Software\Classes\Local Settings\MuiCache\2F\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASMANCS]
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASAPI32]
"ConsoleTracingMask" = "4294901760"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{24C5EDBC-2851-452A-B521-5DA992F6C1B5}]
"WpadDecision" = "3"
"WpadDecisionTime" = "00 81 75 E4 A7 3F D2 01"
[HKCU\Software\Piriform\CCleaner]
"CookiesToSave" = "*.piriform.com|accounts.google.com|google.com|twitter.com|www.google.com"
"WipeFreeSpaceDrives" = "C:\"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{24C5EDBC-2851-452A-B521-5DA992F6C1B5}]
"WpadNetworkName" = "Network 2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-e1-da-d8]
"WpadDecision" = "3"
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 36 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASMANCS]
"FileDirectory" = "%windir%\tracing"
[HKCU\Software\Piriform\CCleaner]
"UpdateKey" = "11/16/2016 03:22:20 AM"
"RunICS" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASMANCS]
"ConsoleTracingMask" = "4294901760"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{24C5EDBC-2851-452A-B521-5DA992F6C1B5}]
"WpadDecisionReason" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASMANCS]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\ccleaner_RASAPI32]
"EnableFileTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-e1-da-d8]
"WpadDecisionTime" = "00 81 75 E4 A7 3F D2 01"
[HKCU\Software\Piriform\CCleaner]
"Monitoring" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Piriform\CCleaner]
"AutoICS"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Piriform\CCleaner]
"AutoUpdateNotificationExpiryTime"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
Dropped PE files
MD5 | File path |
---|---|
41e6991464486950b579959d73b147b7 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\1.exe |
5c35525cebe7b59fafa05d5e98d7edef | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\ccleaner.exe |
41e6991464486950b579959d73b147b7 | c:\Windows\system\RealTek.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
1.exe:2104
%original file name%.exe:1744 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\Windows\system\RealTek.exe (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm2.txt (240 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1.exe (355 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ccleaner.exe (1023 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabBDB3.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarBDB4.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\ACF244F1A10D4DBED0D88EBA0C43A9B5_16756CC7371BB76A269719AA1471E96C (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPS1JHSL\app_cc_pro_trialkey[1].htm (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9D23VSCD2FF435EXK196.temp (388 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30EV4AVE\verify[1].htm (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\ACF244F1A10D4DBED0D88EBA0C43A9B5_16756CC7371BB76A269719AA1471E96C (1476 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"HKCU" = "C:\Windows\System\RealTek.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HKLM" = "C:\Windows\System\RealTek.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 107396 | 107520 | 4.12735 | 01533a91ffd8645ef6a142a593f4aa64 |
.itext | 114688 | 924 | 1024 | 3.88634 | 20894a025910939e783ee5d5256af819 |
.data | 118784 | 5968 | 6144 | 2.53724 | c094adcb96037eb97b5e8ab75f963b70 |
.bss | 126976 | 20176 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 147456 | 2628 | 3072 | 3.03848 | 092a36a3a57b1f95cc6d9fc3960d7967 |
.didata | 151552 | 200 | 512 | 1.00165 | 5b257e7c5ea93a234d727ea81632f1c0 |
.tls | 155648 | 12 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rdata | 159744 | 24 | 512 | 0.146134 | bddc5700da0f621e57518f2044e4e27e |
.reloc | 163840 | 9128 | 9216 | 4.46153 | 039eb167249e892269462dfd91d2f53e |
.rsrc | 176128 | 7133608 | 7133696 | 4.52976 | df51975354314dd3df8eaed1576f102f |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://cdn.globalsigncdn.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8EJH | |
hxxp://ocsp.globalsign.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8EJH | 104.16.25.216 |
license.piriform.com | 151.101.60.64 |
www.piriform.com | 151.101.60.64 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8EJH HTTP/1.1
Cache-Control: max-age = 10800
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 13 Oct 2016 07:50:34 GMT
If-None-Match: "6b9ba9eca642c891cc02365fc6161341647bd9fc"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 16 Nov 2016 01:22:33 GMT
Content-Type: application/ocsp-response
Content-Length: 1518
Connection: keep-alive
Set-Cookie: __cfduid=ddb9e2b76cf8b034eda1305d17feb12381479259353; expires=Thu, 16-Nov-17 01:22:33 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Tue, 15 Nov 2016 23:34:02 GMT
Expires: Sat, 19 Nov 2016 23:34:02 GMT
ETag: "a0f4457357a81716e36a12673e96055fcd518fd3"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 302721ef379c40be-HAM
0..........0..... .....0......0...0.......T.S...H/.L*..,..S.r..20161115233402Z0n0l0D0... .........W......#....*..2..1..`{f.E....P/}..4....K........DN.BG....20161115233402Z....20161119233402Z0...*.H................V..R!%..f.p7........R..4`|...=!..*fu8....s2.|r'c...;.G....S..R{.*....Z....I....Pb..bN.{O.....9.A.G..>.......$.A.SB..F.......!....\.w.X.4.4}.%c/,{n.cG!..bo'l4',...d...?A....9..g.I-.7.......I.p....:Y..&c../.T....6....Wl...2.q.....B.Q.mk...N.....n...-....e....0...0...0..........HD.....O.R..$W0...*.H........0W1.0...U....BE1.0...U....GlobalSign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...161007000000Z..170115000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/..U...(GlobalSign OCSP for Root R1 - Signer 1.10.."0...*.H.............0.........Z""...s..r..Dd.#Da]%...?..`....!.9.d.......P.....k@.c...Jv........T...0R(..66.~}...SoL..%..y.....c...#. ..#.2.Ng..aH..uB.}...z..(.8R..r....xDb..I. .(.[..IY<..y8c>.0Qg.i......j..t....h!.........ax. XH4....p..v...E..;;.3hzpj...Q.<[B.....6.q.g.M}.A..X.IaH ..........0..0...U...........0...U.%..0... .......0...U.......0.0...U.......T.S...H/.L*..,..S.r0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U. .E0C0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/repository/0...*.H..............|..0...7..bp../I...y1i.'a.y...k.1......k...B.......t.Y..8J.J.1.|..bT....?e.Y..%....._n..yn.4.....c.....O(....K....,.7..e...f..M.I...O.y/u?.....ek..........\..)........vz...g. ......b{.8...& .1..2.<..n...O..(El...m!.R.6;...JH....hT..1..m5*.......9/....6..)..
<<< skipped >>>
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
ccleaner.exe_704:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
8%uEP3
8%uEP3
SSSSSSSSSh
SSSSSSSSSh
SSSSSSSSSSh
SSSSSSSSSSh
u%f;]
u%f;]
SSSSSSSSShJ
SSSSSSSSShJ
SSSSSSSSShM
SSSSSSSSShM
SSSSSSSSShD
SSSSSSSSShD
SSSSSSSSShG
SSSSSSSSShG
t.Wj$j
t.Wj$j
SSSSSSSSShQ
SSSSSSSSShQ
G
G
G
G
|$F.tMf
|$F.tMf
~$)~()|$
~$)~()|$
xSSSh
xSSSh
FTPjKS
FTPjKS
FtPj;S
FtPj;S
C.PjRV
C.PjRV
X
X
Ht>Ht.HHt
Ht>Ht.HHt
<.tz>
<.tz>
t%8X
t%8X
t\HtEHt.Ht
t\HtEHt.Ht
H.SVW3
H.SVW3
.FGy"
.FGy"
f;S.si
f;S.si
u u
u u
,4,56,789
,4,56,789
t:Ht.Ht"Ht
t:Ht.Ht"Ht
,t:It.Iu;
,t:It.Iu;
SSShX
SSShX
SSSh$}j
SSSh$}j
SSSSSSSSSh]
SSSSSSSSSh]
SSSSSSSSSh^
SSSSSSSSSh^
SSSSSSSSSh`
SSSSSSSSSh`
PSSSSSSh
PSSSSSSh
~WVSSSSSSh
~WVSSSSSSh
SSSSh
SSSSh
QSSSSh
QSSSSh
PSShd
PSShd
SSSSSSSSSh
SSSSSSSSSh
SSSSSSSSSh7
SSSSSSSSSh7
SSSSSSSSSSh5
SSSSSSSSSSh5
SSSSSSSSSh:
SSSSSSSSSh:
%uASW
%uASW
SSSSSSSSShW
SSSSSSSSShW
SSSSSSSSShV
SSSSSSSSShV
SSSSSSSSShe
SSSSSSSSShe
SSSSSSSSShY
SSSSSSSSShY
SSSSSSSSSShX
SSSSSSSSSShX
SSSSSSSSShU
SSSSSSSSShU
SSSSSSSSShZ
SSSSSSSSShZ
uCSSSh
uCSSSh
SSSSSSSSShT
SSSSSSSSShT
SSSSSSSSSha
SSSSSSSSSha
SSSSSSSSShc
SSSSSSSSShc
SSSSSSSSSh5
SSSSSSSSSh5
d$ SSSSSSSSSSh
d$ SSSSSSSSSSh
SSSSSSSSShk
SSSSSSSSShk
98tCP
98tCP
SSSSSSSSShN
SSSSSSSSShN
SSSSSSSSShC
SSSSSSSSShC
SSSSSSSSh
SSSSSSSSh
SSSSSSSSSShi
SSSSSSSSSShi
SSSSSSSSSh
SSSSSSSSSh
SSSSSSSSSh#
SSSSSSSSSh#
SSSSSSSSShP
SSSSSSSSShP
SSSSSSSSSh"
SSSSSSSSSh"
SSSSSSSSSh
SSSSSSSSSh
SSSSSSSSSh'
SSSSSSSSSh'
SSSSSSSSSh_
SSSSSSSSSh_
tCHt4Ht.Ht(Ht
tCHt4Ht.Ht(Ht
SSSSSSSSSh%
SSSSSSSSSh%
SSSSSSSSSh!
SSSSSSSSSh!
SSSSSSSSSh$
SSSSSSSSSh$
SSSSSSSSShu
SSSSSSSSShu
SSSSSSSSSh=
SSSSSSSSSh=
SSSSSSSSShx
SSSSSSSSShx
SSSSSSSSShy
SSSSSSSSShy
SSSSSSSSShz
SSSSSSSSShz
SSSSSSSSSh|
SSSSSSSSSh|
SSSSSSSSSh}
SSSSSSSSSh}
SSSSSSSSSh>
SSSSSSSSSh>
SSSSSSSSSh~
SSSSSSSSSh~
SSSSSSSSSh?
SSSSSSSSSh?
SSSSSSSSShv
SSSSSSSSShv
SSSSSSSSShw
SSSSSSSSShw
SSSSSSSSSh{
SSSSSSSSSh{
SSSSSSSSShp
SSSSSSSSShp
SSSSSSSSShj
SSSSSSSSShj
SSSSSSSSSSh`
SSSSSSSSSSh`
SSSSSSSSShb
SSSSSSSSShb
SSSSSSSSShd
SSSSSSSSShd
SSSSSSSSSShf
SSSSSSSSSShf
SSSSSSSSShg
SSSSSSSSShg
SSSSSSSSSShl
SSSSSSSSSShl
SSSSSSSSShm
SSSSSSSSShm
SSSSSSSSSh1
SSSSSSSSSh1
SSSSSSSSSh2
SSSSSSSSSh2
SSSSSSSh
SSSSSSSh
SSSSSSSSShE
SSSSSSSSShE
v%Sjd
v%Sjd
SSSSSSSSShB
SSSSSSSSShB
u1SSh
u1SSh
SSSSh
SSSSh
AKv.AKv
AKv.AKv
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag
boost::filesystem::directory_iterator::operator
boost::filesystem::directory_iterator::operator
kernel32.dll
kernel32.dll
Visual C CRT: Not enough memory to complete call to strerror.
Visual C CRT: Not enough memory to complete call to strerror.
portuguese-brazilian
portuguese-brazilian
GetProcessWindowStation
GetProcessWindowStation
Broken pipe
Broken pipe
Inappropriate I/O control operation
Inappropriate I/O control operation
Operation not permitted
Operation not permitted
operator
operator
%d / %m / %y
%d / %m / %y
%I : %M : %S %p
%I : %M : %S %p
%m / %d / %y
%m / %d / %y
%b %d %H : %M : %S %Y
%b %d %H : %M : %S %Y
3.8.1
3.8.1
SQLite format 3
SQLite format 3
CREATE TABLE sqlite_master(
CREATE TABLE sqlite_master(
sql text
sql text
CREATE TEMP TABLE sqlite_temp_master(
CREATE TEMP TABLE sqlite_temp_master(
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLYS
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLYS
ZwQueryKey
ZwQueryKey
D:\Dev\boost\boost_1_54\boost/exception/detail/exception_ptr.hpp
D:\Dev\boost\boost_1_54\boost/exception/detail/exception_ptr.hpp
1836216166
1836216166
1953261156
1953261156
boost thread: trying joining itself
boost thread: trying joining itself
RegOpenKeyTransactedW
RegOpenKeyTransactedW
RegCreateKeyTransactedW
RegCreateKeyTransactedW
RegDeleteKeyTransactedW
RegDeleteKeyTransactedW
RegDeleteKeyExW
RegDeleteKeyExW
LOGGING LIB internal error - should NEVER happen. Please report this to the author of the lib
LOGGING LIB internal error - should NEVER happen. Please report this to the author of the lib
%s_%s_%d-d-d_d-d-d.log
%s_%s_%d-d-d_d-d-d.log
P3D
P3D
private\Net\Mozilla.cpp
private\Net\Mozilla.cpp
UPDATE moz_places SET frecency = -MAX(visit_count, 1) WHERE id IN(SELECT h.id FROM moz_places h WHERE EXISTS (SELECT id FROM moz_bookmarks WHERE fk = h.id) OR EXISTS (SELECT id FROM moz_annos WHERE place_id = h.id AND expiration =
UPDATE moz_places SET frecency = -MAX(visit_count, 1) WHERE id IN(SELECT h.id FROM moz_places h WHERE EXISTS (SELECT id FROM moz_bookmarks WHERE fk = h.id) OR EXISTS (SELECT id FROM moz_annos WHERE place_id = h.id AND expiration =
UPDATE moz_places SET frecency = 0 WHERE id IN (SELECT h.id FROM moz_places h LEFT OUTER JOIN moz_bookmarks b ON h.id = b.fk WHERE frecency
UPDATE moz_places SET frecency = 0 WHERE id IN (SELECT h.id FROM moz_places h LEFT OUTER JOIN moz_bookmarks b ON h.id = b.fk WHERE frecency
CleanHistory - SQLite error:
CleanHistory - SQLite error:
SELECT h.id FROM moz_places h
SELECT h.id FROM moz_places h
LEFT OUTER JOIN moz_historyvisits v ON h.id = v.place_id
LEFT OUTER JOIN moz_historyvisits v ON h.id = v.place_id
LEFT OUTER JOIN moz_bookmarks b ON h.id = b.fk
LEFT OUTER JOIN moz_bookmarks b ON h.id = b.fk
LEFT OUTER JOIN moz_annos a ON h.id = a.place_id
LEFT OUTER JOIN moz_annos a ON h.id = a.place_id
WHERE v.id IS NULL AND b.id IS NULL AND a.id IS NULL AND SUBSTR(h.url, 1, 6) 'place:')
WHERE v.id IS NULL AND b.id IS NULL AND a.id IS NULL AND SUBSTR(h.url, 1, 6) 'place:')
CleanDownloadHistory - SQLite error:
CleanDownloadHistory - SQLite error:
CleanPasswords - SQLite error:
CleanPasswords - SQLite error:
CleanPasswordsExceptions - SQLite error:
CleanPasswordsExceptions - SQLite error:
SrClient.dll
SrClient.dll
P3D
P3D
Cookie:%s%s
Cookie:%s%s
{9E175BB4-F52A-11D8-B9A5-505054503030}
{9E175BB4-F52A-11D8-B9A5-505054503030}
{30c3f6cd-98b5-11cf-bb82-00aa00bdce0b}
{30c3f6cd-98b5-11cf-bb82-00aa00bdce0b}
hXXp://
hXXp://
7b81be6a-ce2b-4676-a29e-eb907a5126c5
7b81be6a-ce2b-4676-a29e-eb907a5126c5
1.3.6.1.4.1.311.2.1.12
1.3.6.1.4.1.311.2.1.12
URLString
URLString
ux
ux
WindowsCreateString
WindowsCreateString
WindowsDeleteString
WindowsDeleteString
app.launch.web_url
app.launch.web_url
extensions.settings.
extensions.settings.
extensions.known_disabled
extensions.known_disabled
extensions.settings
extensions.settings
profile.name
profile.name
google.services.username
google.services.username
X:X:X:X:X:X
X:X:X:X:X:X
041ULKGbv7meLDmSgUyrkw==
041ULKGbv7meLDmSgUyrkw==
: this object doesn't support resynchronization
: this object doesn't support resynchronization
StreamTransformation: this object doesn't support random access
StreamTransformation: this object doesn't support random access
RandomNumberStore: CopyRangeTo2() is not supported by this store
RandomNumberStore: CopyRangeTo2() is not supported by this store
%s-%s-%s-%s-%s
%s-%s-%s-%s-%s
X;
X;
%s>
%s>
%s="%s"
%s="%s"
%s='%s'
%s='%s'
version="%s"
version="%s"
encoding="%s"
encoding="%s"
standalone="%s"
standalone="%s"
: this object does't support a special last block
: this object does't support a special last block
: this object doesn't support multiple channels
: this object doesn't support multiple channels
is not a valid key length
is not a valid key length
operation failed with error
operation failed with error
WerReportAddDump
WerReportAddDump
WerReportCloseHandle
WerReportCloseHandle
WerReportCreate
WerReportCreate
WerReportSubmit
WerReportSubmit
%d_byte ptr
%d_byte ptr
0xX
0xX
0xX
0xX
-0xX
-0xX
[0xI64X] ANOMALY: REX prefix before legacy prefix 0xX
[0xI64X] ANOMALY: REX prefix before legacy prefix 0xX
[0xI64X] ANOMALY: Duplicate prefix 0xX
[0xI64X] ANOMALY: Duplicate prefix 0xX
[0xI64X] ERROR: Reached maximum prefix count %d
[0xI64X] ERROR: Reached maximum prefix count %d
[0xI64X] ANOMALY: Reached maximum prefix count %d
[0xI64X] ANOMALY: Reached maximum prefix count %d
[0xI64X] ERROR: Invalid opcode 0xX
[0xI64X] ERROR: Invalid opcode 0xX
[0xI64X] ERROR: Invalid two byte opcode 0xX 0xX
[0xI64X] ERROR: Invalid two byte opcode 0xX 0xX
[0xI64X] ERROR: Opcode 0xX 0xX ("%s") illegal in 64-bit mode
[0xI64X] ERROR: Opcode 0xX 0xX ("%s") illegal in 64-bit mode
[0xI64X] ERROR: Opcode 0xX 0xX ("%s") illegal with 16-bit operand size
[0xI64X] ERROR: Opcode 0xX 0xX ("%s") illegal with 16-bit operand size
[0xI64X] ERROR: Illegal SSE instruction opcode 0xX 0xX prefix 0xX
[0xI64X] ERROR: Illegal SSE instruction opcode 0xX 0xX prefix 0xX
[0xI64X] ERROR: Illegal SSE instruction opcode 0xX 0xX prefix 0xX extension %d
[0xI64X] ERROR: Illegal SSE instruction opcode 0xX 0xX prefix 0xX extension %d
[0xI64X] ERROR: Invalid group opcode 0xX 0xX extension 0xX
[0xI64X] ERROR: Invalid group opcode 0xX 0xX extension 0xX
[0xI64X] ERROR: Opcode 0xX ("%s") illegal in 64-bit mode
[0xI64X] ERROR: Opcode 0xX ("%s") illegal in 64-bit mode
[0xI64X] ERROR: Opcode 0xX ("%s") illegal with 16-bit operand size
[0xI64X] ERROR: Opcode 0xX ("%s") illegal with 16-bit operand size
[0xI64X] ERROR: Invalid group opcode 0xX extension 0xX
[0xI64X] ERROR: Invalid group opcode 0xX extension 0xX
[0xI64X] ERROR: Illegal opcode 0xX 0xX modrm 0xX
[0xI64X] ERROR: Illegal opcode 0xX 0xX modrm 0xX
[0xI64X] ERROR: Invalid FPU opcode 0xX modrm extension 0xX (index 0xX)
[0xI64X] ERROR: Invalid FPU opcode 0xX modrm extension 0xX (index 0xX)
[0xI64X] ANOMALY: operand size prefix used with 3DNOW instruction
[0xI64X] ANOMALY: operand size prefix used with 3DNOW instruction
[0xI64X] ERROR: Illegal opcode 0xX 0xX suffix 0xX
[0xI64X] ERROR: Illegal opcode 0xX 0xX suffix 0xX
[0xI64X] ERROR: Instruction "%s" (opcode 0xX) can't be used in 16-bit X86
[0xI64X] ERROR: Instruction "%s" (opcode 0xX) can't be used in 16-bit X86
[0xI64X] ERROR: Instruction "%s" (opcode 0xX) can only be used in X86-64
[0xI64X] ERROR: Instruction "%s" (opcode 0xX) can only be used in X86-64
[0xI64X] ANOMALY: operand size prefix used with FPU/MMX/SSEx
[0xI64X] ANOMALY: operand size prefix used with FPU/MMX/SSEx
[0xI64X] ANOMALY: use of operand size prefix meaningless when REX.w=1
[0xI64X] ANOMALY: use of operand size prefix meaningless when REX.w=1
[0xI64X] ANOMALY: use of REX.w is meaningless (default operand size is 64)
[0xI64X] ANOMALY: use of REX.w is meaningless (default operand size is 64)
[0xI64X] ANOMALY: unexpected segment 0xX
[0xI64X] ANOMALY: unexpected segment 0xX
[0xI64X] ERROR: Illegal use of lock prefix for instruction "%s"
[0xI64X] ERROR: Illegal use of lock prefix for instruction "%s"
[0xI64X] ERROR: maximum instruction length reached ("%s")
[0xI64X] ERROR: maximum instruction length reached ("%s")
[0xI64X] ANOMALY: ENTER has invalid operand 2
[0xI64X] ANOMALY: ENTER has invalid operand 2
[0xI64X] ANOMALY: ENTER has invalid operand 3
[0xI64X] ANOMALY: ENTER has invalid operand 3
[0xI64X] ANOMALY: ret has invalid operand 1
[0xI64X] ANOMALY: ret has invalid operand 1
[0xI64X] ANOMALY: retf has invalid operand 1
[0xI64X] ANOMALY: retf has invalid operand 1
[0xI64X] ANOMALY: Instruction "%s" is modifying the stack
[0xI64X] ANOMALY: Instruction "%s" is modifying the stack
[0xI64X] ANOMALY: "%s" has invalid stack change 0xX
[0xI64X] ANOMALY: "%s" has invalid stack change 0xX
%s:[%s]
%s:[%s]
0xX=
0xX=
]=0xX
]=0xX
[0xI64X] ANOMALY: Unexpected operand size prefix
[0xI64X] ANOMALY: Unexpected operand size prefix
%s 0xX:[
%s 0xX:[
%s %s:[
%s %s:[
[0xI64X] ERROR: mod != 3 for AMODE_PR ("%s")
[0xI64X] ERROR: mod != 3 for AMODE_PR ("%s")
[0xI64X] ERROR: invalid mmx register %d for AMODE_PR ("%s")
[0xI64X] ERROR: invalid mmx register %d for AMODE_PR ("%s")
[0xI64X] ERROR: AMODE_PR illegal in 16-bit mode ("%s")
[0xI64X] ERROR: AMODE_PR illegal in 16-bit mode ("%s")
[0xI64X] ERROR: mod != 3 for AMODE_VR ("%s")
[0xI64X] ERROR: mod != 3 for AMODE_VR ("%s")
[0xI64X] ERROR: AMODE_VR illegal in 16-bit mode ("%s")
[0xI64X] ERROR: AMODE_VR illegal in 16-bit mode ("%s")
[0xI64X] ERROR: invalid mmx register %d for AMODE_P ("%s")
[0xI64X] ERROR: invalid mmx register %d for AMODE_P ("%s")
[0xI64X] ERROR: AMODE_P illegal in 16-bit mode ("%s")
[0xI64X] ERROR: AMODE_P illegal in 16-bit mode ("%s")
[0xI64X] ERROR: mod != 3 for AMODE_R ("%s")
[0xI64X] ERROR: mod != 3 for AMODE_R ("%s")
seg_X
seg_X
[0xI64X] ERROR: mod = 3 for AMODE_M ("%s")
[0xI64X] ERROR: mod = 3 for AMODE_M ("%s")
[0xI64X] ERROR: mod = 3 for AMODE_E with OPTYPE_p ("%s")
[0xI64X] ERROR: mod = 3 for AMODE_E with OPTYPE_p ("%s")
?#%X.y
?#%X.y
H:\Piriform\CCleaner\branches\v5.12\bin\CCleaner\Release\CCleaner.pdb
H:\Piriform\CCleaner\branches\v5.12\bin\CCleaner\Release\CCleaner.pdb
RPCRT4.dll
RPCRT4.dll
GetProcessHeap
GetProcessHeap
GetWindowsDirectoryW
GetWindowsDirectoryW
WaitNamedPipeW
WaitNamedPipeW
TransactNamedPipe
TransactNamedPipe
SetNamedPipeHandleState
SetNamedPipeHandleState
KERNEL32.dll
KERNEL32.dll
EnumWindows
EnumWindows
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
GetKeyState
GetKeyState
SetWindowsHookExW
SetWindowsHookExW
UnhookWindowsHookEx
UnhookWindowsHookEx
CreateDialogIndirectParamW
CreateDialogIndirectParamW
ExitWindowsEx
ExitWindowsEx
GetAsyncKeyState
GetAsyncKeyState
USER32.dll
USER32.dll
SetViewportOrgEx
SetViewportOrgEx
GDI32.dll
GDI32.dll
COMDLG32.dll
COMDLG32.dll
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
RegDeleteKeyW
RegDeleteKeyW
RegQueryInfoKeyW
RegQueryInfoKeyW
RegEnumKeyExW
RegEnumKeyExW
RegCreateKeyExW
RegCreateKeyExW
RegNotifyChangeKeyValue
RegNotifyChangeKeyValue
RegLoadKeyW
RegLoadKeyW
RegUnLoadKeyW
RegUnLoadKeyW
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteW
ShellExecuteW
ShellExecuteExW
ShellExecuteExW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
PathIsURLW
PathIsURLW
PathCreateFromUrlW
PathCreateFromUrlW
SHLWAPI.dll
SHLWAPI.dll
COMCTL32.dll
COMCTL32.dll
MSIMG32.dll
MSIMG32.dll
GdiplusShutdown
GdiplusShutdown
gdiplus.dll
gdiplus.dll
UxTheme.dll
UxTheme.dll
WTSAPI32.dll
WTSAPI32.dll
NETAPI32.dll
NETAPI32.dll
CertFindCertificateInStore
CertFindCertificateInStore
CertGetNameStringW
CertGetNameStringW
CertFreeCertificateContext
CertFreeCertificateContext
CryptMsgGetParam
CryptMsgGetParam
CertCloseStore
CertCloseStore
CryptMsgClose
CryptMsgClose
CRYPT32.dll
CRYPT32.dll
WINTRUST.dll
WINTRUST.dll
ESENT.dll
ESENT.dll
IPHLPAPI.DLL
IPHLPAPI.DLL
VERSION.dll
VERSION.dll
DeleteUrlCacheEntryW
DeleteUrlCacheEntryW
DeleteUrlCacheEntryA
DeleteUrlCacheEntryA
FindFirstUrlCacheEntryW
FindFirstUrlCacheEntryW
FindNextUrlCacheEntryW
FindNextUrlCacheEntryW
FindCloseUrlCache
FindCloseUrlCache
FindFirstUrlCacheEntryExW
FindFirstUrlCacheEntryExW
FindNextUrlCacheEntryExW
FindNextUrlCacheEntryExW
InternetOpenUrlW
InternetOpenUrlW
HttpQueryInfoW
HttpQueryInfoW
InternetCrackUrlW
InternetCrackUrlW
HttpSendRequestW
HttpSendRequestW
HttpAddRequestHeadersW
HttpAddRequestHeadersW
HttpOpenRequestW
HttpOpenRequestW
WININET.dll
WININET.dll
GetCPInfo
GetCPInfo
.?AVwindows_file_codecvt@@
.?AVwindows_file_codecvt@@
zcÃ
zcÃ
.?AUIOperation@Piriform@@
.?AUIOperation@Piriform@@
.?AV?$IOperationImpl@UIOperation@Piriform@@@Piriform@@
.?AV?$IOperationImpl@UIOperation@Piriform@@@Piriform@@
.?AV?$sp_counted_impl_p@UDPIInfo@CImageManager_@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@UDPIInfo@CImageManager_@Piriform@@@detail@boost@@
.?AV?$bind_t@XV?$mf1@XV?$IActivationEvents2AsyncImpl@VCActivationEvents2Marshaller@Piriform@@UIActivationEvents2@2@@Piriform@@ABV?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@_mfi@boost@@V?$list2@V?$value@PAV?$IActivationEvents2AsyncImpl@VCActivationEvents2Marshaller@Piriform@@UIActivationEvents2@2@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$bind_t@XV?$mf1@XV?$IActivationEvents2AsyncImpl@VCActivationEvents2Marshaller@Piriform@@UIActivationEvents2@2@@Piriform@@ABV?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@_mfi@boost@@V?$list2@V?$value@PAV?$IActivationEvents2AsyncImpl@VCActivationEvents2Marshaller@Piriform@@UIActivationEvents2@2@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
SQLITE_
SQLITE_
d-d-d d:d:d
d-d-d d:d:d
d:d:d
d:d:d
d-d-d
d-d-d
failed to allocate %u bytes of memory
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
failed memory resize %u to %u bytes
922337203685477580
922337203685477580
API call with %s database connection pointer
API call with %s database connection pointer
RowKey
RowKey
os_win.c:%d: (%lu) %s(%s) - %s
os_win.c:%d: (%lu) %s(%s) - %s
delayed %dms for lock/sharing conflict
delayed %dms for lock/sharing conflict
%s-shm
%s-shm
%s%s%s
%s%s%s
recovered %d pages from %s
recovered %d pages from %s
recovered %d frames from WAL file %s
recovered %d frames from WAL file %s
cannot limit WAL size: %s
cannot limit WAL size: %s
invalid page number %d
invalid page number %d
2nd reference to page %d
2nd reference to page %d
Failed to read ptrmap key=%d
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
%d of %d pages missing from overflow list starting at %d
failed to get page %d
failed to get page %d
freelist leaf count too big on page %d
freelist leaf count too big on page %d
Page %d:
Page %d:
unable to get the page. error code=%d
unable to get the page. error code=%d
btreeInitPage() returns error code %d
btreeInitPage() returns error code %d
On tree page %d cell %d:
On tree page %d cell %d:
On page %d at right child:
On page %d at right child:
Corruption detected in cell %d on page %d
Corruption detected in cell %d on page %d
Multiple uses for byte %d of page %d
Multiple uses for byte %d of page %d
Fragmentation of %d bytes reported as %d on page %d
Fragmentation of %d bytes reported as %d on page %d
Page %d is never used
Page %d is never used
Pointer map page %d is referenced
Pointer map page %d is referenced
Outstanding page count goes from %d to %d during this analysis
Outstanding page count goes from %d to %d during this analysis
unknown database %s
unknown database %s
keyinfo(%d
keyinfo(%d
%s(%d)
%s(%d)
%s-mjXXXXXX9XXz
%s-mjXXXXXX9XXz
MJ delete: %s
MJ delete: %s
MJ collide: %s
MJ collide: %s
-mjX9X
-mjX9X
foreign key constraint failed
foreign key constraint failed
unable to use function %s in the requested context
unable to use function %s in the requested context
bind on a busy prepared statement: [%s]
bind on a busy prepared statement: [%s]
zeroblob(%d)
zeroblob(%d)
abort at %d in [%s]: %s
abort at %d in [%s]: %s
constraint failed at %d in [%s]
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
cannot open savepoint - SQL statements in progress
no such savepoint: %s
no such savepoint: %s
cannot release savepoint - SQL statements in progress
cannot release savepoint - SQL statements in progress
cannot commit transaction - SQL statements in progress
cannot commit transaction - SQL statements in progress
sqlite_temp_master
sqlite_temp_master
sqlite_master
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
cannot change %s wal mode from within a transaction
cannot change %s wal mode from within a transaction
database table is locked: %s
database table is locked: %s
statement aborts at %d: [%s] %s
statement aborts at %d: [%s] %s
cannot open value of type %s
cannot open value of type %s
cannot open virtual table: %s
cannot open virtual table: %s
cannot open view: %s
cannot open view: %s
no such column: "%s"
no such column: "%s"
foreign key
foreign key
indexed
indexed
cannot open %s column for writing
cannot open %s column for writing
misuse of aliased aggregate %s
misuse of aliased aggregate %s
%s: %s.%s.%s
%s: %s.%s.%s
%s: %s.%s
%s: %s.%s
%s: %s
%s: %s
%s prohibited in partial index WHERE clauses
%s prohibited in partial index WHERE clauses
%s prohibited in CHECK constraints
%s prohibited in CHECK constraints
not authorized to use function: %s
not authorized to use function: %s
%r %s BY term out of range - should be between 1 and %d
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
too many terms in %s BY clause
Expression tree is too large (maximum depth %d)
Expression tree is too large (maximum depth %d)
variable number must be between ?1 and ?%d
variable number must be between ?1 and ?%d
too many SQL variables
too many SQL variables
too many columns in %s
too many columns in %s
EXECUTE %s%s SUBQUERY %d
EXECUTE %s%s SUBQUERY %d
misuse of aggregate: %s()
misuse of aggregate: %s()
%.*s"%w"%s
%.*s"%w"%s
%s%.*s"%w"
%s%.*s"%w"
sqlite_rename_table
sqlite_rename_table
sqlite_rename_trigger
sqlite_rename_trigger
sqlite_rename_parent
sqlite_rename_parent
%s OR name=%Q
%s OR name=%Q
type='trigger' AND (%s)
type='trigger' AND (%s)
sqlite_
sqlite_
table %s may not be altered
table %s may not be altered
there is already another table or index with this name: %s
there is already another table or index with this name: %s
view %s may not be altered
view %s may not be altered
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
Cannot add a PRIMARY KEY column
Cannot add a PRIMARY KEY column
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
sqlite_altertab_%s
sqlite_altertab_%s
sqlite_stat1
sqlite_stat1
sqlite_stat3
sqlite_stat3
sqlite_stat4
sqlite_stat4
CREATE TABLE %Q.%s(%s)
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE %s=%Q
DELETE FROM %Q.%s WHERE %s=%Q
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
invalid name: "%s"
invalid name: "%s"
too many attached databases - max %d
too many attached databases - max %d
database %s is already in use
database %s is already in use
unable to open database: %s
unable to open database: %s
no such database: %s
no such database: %s
cannot detach database %s
cannot detach database %s
database %s is locked
database %s is locked
sqlite_detach
sqlite_detach
sqlite_attach
sqlite_attach
%s %T cannot reference objects in database %s
%s %T cannot reference objects in database %s
%s cannot use variables
%s cannot use variables
access to %s.%s.%s is prohibited
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
object name reserved for internal use: %s
there is already an index named %s
there is already an index named %s
too many columns on %s
too many columns on %s
duplicate column name: %s
duplicate column name: %s
default value of column [%s] is not constant
default value of column [%s] is not constant
table "%s" has more than one primary key
table "%s" has more than one primary key
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
CREATE %s %.*s
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE TABLE %Q.sqlite_sequence(name,seq)
CREATE TABLE %Q.sqlite_sequence(name,seq)
view %s is circularly defined
view %s is circularly defined
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
sqlite_stat%d
sqlite_stat%d
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
sqlite_stat
sqlite_stat
table %s may not be dropped
table %s may not be dropped
use DROP TABLE to delete table %s
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
use DROP VIEW to delete view %s
foreign key on %s should reference only one column of table %T
foreign key on %s should reference only one column of table %T
cannot create a TEMP index on non-TEMP table "%s"
cannot create a TEMP index on non-TEMP table "%s"
number of columns in foreign key does not match the number of columns in the referenced table
number of columns in foreign key does not match the number of columns in the referenced table
unknown column "%s" in foreign key definition
unknown column "%s" in foreign key definition
indexed columns are not unique
indexed columns are not unique
table %s may not be indexed
table %s may not be indexed
views may not be indexed
views may not be indexed
virtual tables may not be indexed
virtual tables may not be indexed
there is already a table named %s
there is already a table named %s
index %s already exists
index %s already exists
sqlite_autoindex_%s_%d
sqlite_autoindex_%s_%d
table %s has no column named %s
table %s has no column named %s
CREATE%s INDEX %.*s
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
no such index: %S
no such index: %S
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
a JOIN clause is required before %s
a JOIN clause is required before %s
unable to identify the object to be reindexed
unable to identify the object to be reindexed
no such collation sequence: %s
no such collation sequence: %s
table %s may not be modified
table %s may not be modified
cannot modify %s because it is a view
cannot modify %s because it is a view
sqlite_version
sqlite_version
sqlite_source_id
sqlite_source_id
sqlite_log
sqlite_log
sqlite_compileoption_used
sqlite_compileoption_used
sqlite_compileoption_get
sqlite_compileoption_get
foreign key mismatch - "%w" referencing "%w"
foreign key mismatch - "%w" referencing "%w"
table %S has %d columns but %d values were supplied
table %S has %d columns but %d values were supplied
%d values for %d columns
%d values for %d columns
table %S has no column named %s
table %S has no column named %s
%s.%s may not be NULL
%s.%s may not be NULL
constraint %s failed
constraint %s failed
PRIMARY KEY must be unique
PRIMARY KEY must be unique
sqlite3_extension_init
sqlite3_extension_init
%s.%s
%s.%s
unable to open shared library [%s]
unable to open shared library [%s]
sqlite3_
sqlite3_
no entry point [%s] in shared library [%s]
no entry point [%s] in shared library [%s]
error during initialization: %s
error during initialization: %s
automatic extension loading failed: %s
automatic extension loading failed: %s
defer_foreign_keys
defer_foreign_keys
foreign_key_check
foreign_key_check
foreign_key_list
foreign_key_list
foreign_keys
foreign_keys
*** in database %s ***
*** in database %s ***
unsupported encoding: %s
unsupported encoding: %s
malformed database schema (%s)
malformed database schema (%s)
%s - %s
%s - %s
unsupported file format
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
database schema is locked: %s
database schema is locked: %s
unknown or unsupported join type: %T %T%s%T
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
cannot join using column %s - column not present in both tables
USE TEMP B-TREE FOR %s
USE TEMP B-TREE FOR %s
COMPOUND SUBQUERIES %d AND %d %s(%s)
COMPOUND SUBQUERIES %d AND %d %s(%s)
%s:%d
%s:%d
ORDER BY clause should come after %s not before
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
LIMIT clause should come after %s not before
SELECTs to the left and right of %s do not have the same number of result columns
SELECTs to the left and right of %s do not have the same number of result columns
no such index: %s
no such index: %s
sqlite_sq_%p
sqlite_sq_%p
too many references to "%s": max 65535
too many references to "%s": max 65535
%s.%s.%s
%s.%s.%s
no such table: %s
no such table: %s
SCAN TABLE %s%s%s
SCAN TABLE %s%s%s
sqlite3_get_table() called with two or more incompatible queries
sqlite3_get_table() called with two or more incompatible queries
cannot create %s trigger on view: %S
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
cannot create INSTEAD OF trigger on table: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
no such trigger: %S
no such trigger: %S
-- TRIGGER %s
-- TRIGGER %s
no such column: %s
no such column: %s
cannot VACUUM - SQL statements in progress
cannot VACUUM - SQL statements in progress
PRAGMA vacuum_db.synchronous=OFF
PRAGMA vacuum_db.synchronous=OFF
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor failed: %s
vtable constructor failed: %s
vtable constructor did not declare schema: %s
vtable constructor did not declare schema: %s
no such module: %s
no such module: %s
automatic index on %s(%s)
automatic index on %s(%s)
table %s: xBestIndex returned an invalid plan
table %s: xBestIndex returned an invalid plan
%s SUBQUERY %d
%s SUBQUERY %d
%s TABLE %s
%s TABLE %s
%s AS %s
%s AS %s
%s USING AUTOMATIC %sINDEX%.0s%s
%s USING AUTOMATIC %sINDEX%.0s%s
%s USING %sINDEX %s%s
%s USING %sINDEX %s%s
%s USING INTEGER PRIMARY KEY
%s USING INTEGER PRIMARY KEY
%s (rowid=?)
%s (rowid=?)
%s (rowid>? AND rowid)
%s (rowid>? AND rowid)
%s (rowid>?)
%s (rowid>?)
%s (rowid)
%s (rowid)
%s VIRTUAL TABLE INDEX %d:%s
%s VIRTUAL TABLE INDEX %d:%s
%s.xBestIndex() malfunction
%s.xBestIndex() malfunction
at most %d tables in a join
at most %d tables in a join
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
SQL logic error or missing database
SQL logic error or missing database
unknown operation
unknown operation
large file support is disabled
large file support is disabled
unknown database: %s
unknown database: %s
no such %s mode: %s
no such %s mode: %s
%s mode not allowed: %s
%s mode not allowed: %s
no such vfs: %s
no such vfs: %s
database corruption at line %d of [%.10s]
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
cannot open file at line %d of [%.10s]
.?AV?$CKeyboardFocusImpl@VCCleanerListViewImpl@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCCleanerListViewImpl@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCFilterComboCtrl@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCFilterComboCtrl@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCButtonEx@Piriform@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCButtonEx@Piriform@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCCustomComboBox@Piriform@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCCustomComboBox@Piriform@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCCheckListViewCtrlEx@Piriform@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCCheckListViewCtrlEx@Piriform@@@Piriform@@
.?AV?$bind_t@XV?$mf1@XV?$CCookiesEventsExAsync@VCIntelligentCookieScan@@UICookiesEventsEx@Piriform@@@Piriform@@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@_mfi@boost@@V?$list2@V?$value@PAV?$CCookiesEventsExAsync@VCIntelligentCookieScan@@UICookiesEventsEx@Piriform@@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$bind_t@XV?$mf1@XV?$CCookiesEventsExAsync@VCIntelligentCookieScan@@UICookiesEventsEx@Piriform@@@Piriform@@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@_mfi@boost@@V?$list2@V?$value@PAV?$CCookiesEventsExAsync@VCIntelligentCookieScan@@UICookiesEventsEx@Piriform@@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$CKeyboardFocusImpl@VCRegistryListViewImpl@Piriform@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCRegistryListViewImpl@Piriform@@@Piriform@@
.?AV?$bind_t@XV?$mf1@XV?$ICookiesEventsExAsyncImpl@VCOptionsCookiesCtrl@@UICookiesEventsEx@Piriform@@@Piriform@@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@_mfi@boost@@V?$list2@V?$value@PAV?$ICookiesEventsExAsyncImpl@VCOptionsCookiesCtrl@@UICookiesEventsEx@Piriform@@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$bind_t@XV?$mf1@XV?$ICookiesEventsExAsyncImpl@VCOptionsCookiesCtrl@@UICookiesEventsEx@Piriform@@@Piriform@@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@_mfi@boost@@V?$list2@V?$value@PAV?$ICookiesEventsExAsyncImpl@VCOptionsCookiesCtrl@@UICookiesEventsEx@Piriform@@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$CKeyboardFocusImpl@VCStartUpListViewImpl@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCStartUpListViewImpl@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCDuplicateListViewImpl@Piriform@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCDuplicateListViewImpl@Piriform@@@Piriform@@
.?AV?$bind_t@XV?$mf1@XV?$IEventsExImpl@VCToolsDuplicateCtrl@@UIDuplicateEvents@Piriform@@@Piriform@@PB_W@_mfi@boost@@V?$list2@V?$value@PAV?$IDuplicateEventsAsyncImpl@VCToolsDuplicateCtrl@@UIDuplicateEvents@Piriform@@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$bind_t@XV?$mf1@XV?$IEventsExImpl@VCToolsDuplicateCtrl@@UIDuplicateEvents@Piriform@@@Piriform@@PB_W@_mfi@boost@@V?$list2@V?$value@PAV?$IDuplicateEventsAsyncImpl@VCToolsDuplicateCtrl@@UIDuplicateEvents@Piriform@@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$bind_t@XV?$mf1@XV?$IDuplicateEventsExImpl@VCToolsDuplicateCtrl@@UIDuplicateEvents@Piriform@@@Piriform@@PB_W@_mfi@boost@@V?$list2@V?$value@PAV?$IDuplicateEventsAsyncImpl@VCToolsDuplicateCtrl@@UIDuplicateEvents@Piriform@@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$bind_t@XV?$mf1@XV?$IDuplicateEventsExImpl@VCToolsDuplicateCtrl@@UIDuplicateEvents@Piriform@@@Piriform@@PB_W@_mfi@boost@@V?$list2@V?$value@PAV?$IDuplicateEventsAsyncImpl@VCToolsDuplicateCtrl@@UIDuplicateEvents@Piriform@@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$CKeyboardFocusImpl@VCSystemAnalyzerFilesListViewImpl@Piriform@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCSystemAnalyzerFilesListViewImpl@Piriform@@@Piriform@@
.?AV?$bind_t@XV?$mf1@XV?$IEventsExImpl@VCToolsSystemAnalyzerCtrl@@UISystemAnalyzerEvents@Piriform@@@Piriform@@PB_W@_mfi@boost@@V?$list2@V?$value@PAV?$ISystemAnalyzerEventsAsyncImpl@VCToolsSystemAnalyzerCtrl@@UISystemAnalyzerEvents@Piriform@@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$bind_t@XV?$mf1@XV?$IEventsExImpl@VCToolsSystemAnalyzerCtrl@@UISystemAnalyzerEvents@Piriform@@@Piriform@@PB_W@_mfi@boost@@V?$list2@V?$value@PAV?$ISystemAnalyzerEventsAsyncImpl@VCToolsSystemAnalyzerCtrl@@UISystemAnalyzerEvents@Piriform@@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$CKeyboardFocusImpl@VCSystemRestoreListView@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCSystemRestoreListView@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCUninstallListViewImpl@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCUninstallListViewImpl@@@Piriform@@
.?AU?$forward_to_logger@U?$return_str@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@V?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@ostream_like@gather@logging@boost@@U?$ts_write@U?$format_write@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@U?$simple@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@@format_and_write@34@U?$simple@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@@msg_route@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@Vmutex_win32@threading@34@@array@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@destination@logging@boost@@Vmutex_win32@threading@34@@array@34@@writer@logging@boost@@@writer@45@@logging@boost@@
.?AU?$forward_to_logger@U?$return_str@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@V?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@ostream_like@gather@logging@boost@@U?$ts_write@U?$format_write@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@U?$simple@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@@format_and_write@34@U?$simple@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@@msg_route@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@Vmutex_win32@threading@34@@array@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@destination@logging@boost@@Vmutex_win32@threading@34@@array@34@@writer@logging@boost@@@writer@45@@logging@boost@@
.?AU?$common_base_holder@U?$return_str@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@V?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@ostream_like@gather@logging@boost@@U?$ts_write@U?$format_write@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@U?$simple@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@@format_and_write@34@U?$simple@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@@msg_route@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@Vmutex_win32@threading@34@@array@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@destination@logging@boost@@Vmutex_win32@threading@34@@array@34@@writer@logging@boost@@@writer@45@@detail@logging@boost@@
.?AU?$common_base_holder@U?$return_str@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@V?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@ostream_like@gather@logging@boost@@U?$ts_write@U?$format_write@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@U?$simple@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@@format_and_write@34@U?$simple@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@@msg_route@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@Vmutex_win32@threading@34@@array@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@destination@logging@boost@@Vmutex_win32@threading@34@@array@34@@writer@logging@boost@@@writer@45@@detail@logging@boost@@
.?AU?$logger_base@U?$return_str@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@V?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@ostream_like@gather@logging@boost@@U?$ts_write@U?$format_write@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@U?$simple@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@@format_and_write@34@U?$simple@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@@msg_route@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@Vmutex_win32@threading@34@@array@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@destination@logging@boost@@Vmutex_win32@threading@34@@array@34@@writer@logging@boost@@@writer@45@Uoverride@45@@logging@boost@@
.?AU?$logger_base@U?$return_str@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@V?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@ostream_like@gather@logging@boost@@U?$ts_write@U?$format_write@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@U?$simple@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@@format_and_write@34@U?$simple@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@@msg_route@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@Vmutex_win32@threading@34@@array@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@destination@logging@boost@@Vmutex_win32@threading@34@@array@34@@writer@logging@boost@@@writer@45@Uoverride@45@@logging@boost@@
.?AU?$logger@U?$return_str@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@V?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@ostream_like@gather@logging@boost@@U?$ts_write@U?$format_write@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@U?$simple@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@@format_and_write@34@U?$simple@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@@msg_route@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@Vmutex_win32@threading@34@@array@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@destination@logging@boost@@Vmutex_win32@threading@34@@array@34@@writer@logging@boost@@@writer@45@@logging@boost@@
.?AU?$logger@U?$return_str@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@V?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@ostream_like@gather@logging@boost@@U?$ts_write@U?$format_write@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@U?$simple@U?$cache_string_one_str@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@optimize@logging@boost@@@format_and_write@34@U?$simple@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@U1destination@34@Ulock_resource@default_types@34@@msg_route@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@formatter@logging@boost@@Vmutex_win32@threading@34@@array@34@V?$shared_ptr_holder@U?$base@Udefault_@logging@boost@@U123@@destination@logging@boost@@Vmutex_win32@threading@34@@array@34@@writer@logging@boost@@@writer@45@@logging@boost@@
.?AV?$IOperationImpl@UISecureDelete2@IO@Piriform@@@Piriform@@
.?AV?$IOperationImpl@UISecureDelete2@IO@Piriform@@@Piriform@@
.?AVHexEncoder@CryptoPP@@
.?AVHexEncoder@CryptoPP@@
.PAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.PAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.PB_W
.PB_W
.?AVCRegKey@ATL@@
.?AVCRegKey@ATL@@
.?AVCRegKeyEx@Registry@Piriform@@
.?AVCRegKeyEx@Registry@Piriform@@
.?AV?$sp_counted_impl_p@UWebNavigate@Shell@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@UWebNavigate@Shell@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCWindowsServicesRule@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCWindowsServicesRule@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerPreviousWindowsInstallation@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerPreviousWindowsInstallation@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerWindowsEventLogs@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerWindowsEventLogs@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerNetworkPasswords@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerNetworkPasswords@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeLastDownloadLocation@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeLastDownloadLocation@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeFlashCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeFlashCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeCompactDatabases@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeCompactDatabases@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeSession@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeSession@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeSavedPasswords@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeSavedPasswords@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeFormHistory@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeFormHistory@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeDownload@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeDownload@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeHistory@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeHistory@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeCache@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerChromeCache@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerSafariSavedPasswords@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerSafariSavedPasswords@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeSession@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeSession@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeCompactDatabases@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeCompactDatabases@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeFormHistory@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeFormHistory@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeDownload@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeDownload@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeCookies@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeCookies@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeHistory@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$RuleBase@VCCleanerChromeHistory@Piriform@@@Opera@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaSession@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaSession@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaRecentlyTypedUrls@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaRecentlyTypedUrls@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaLastDownloadLocation@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaLastDownloadLocation@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaSavedPasswords@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaSavedPasswords@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaWebsiteIcons@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaWebsiteIcons@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaHistory@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaHistory@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaCache@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerOperaCache@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaSitePreferences@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaSitePreferences@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaCompactDatabases@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaCompactDatabases@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaGoogleToolbar@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaGoogleToolbar@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaSession@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaSession@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaSavedPasswords@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaSavedPasswords@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaFormHistory@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaFormHistory@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaDownload@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaDownload@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaHistory@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaHistory@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaCache@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCCleanerMozillaCache@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCSavedPasswords@Edge@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCSavedPasswords@Edge@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCSavedPasswords@IE@Rules@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCSavedPasswords@IE@Rules@Piriform@@@detail@boost@@
.?AVCCleanerChromeSession@Piriform@@
.?AVCCleanerChromeSession@Piriform@@
.?AV?$RuleBase@VCCleanerChromeSession@Piriform@@@Opera@Rules@Piriform@@
.?AV?$RuleBase@VCCleanerChromeSession@Piriform@@@Opera@Rules@Piriform@@
.?AUISQLiteEvents@Piriform@@
.?AUISQLiteEvents@Piriform@@
.?AVCCleanerChromeCookies@Piriform@@
.?AVCCleanerChromeCookies@Piriform@@
.?AV?$RuleBase@VCCleanerChromeCookies@Piriform@@@Opera@Rules@Piriform@@
.?AV?$RuleBase@VCCleanerChromeCookies@Piriform@@@Opera@Rules@Piriform@@
.?AVCCleanerChromeCompactDatabases@Piriform@@
.?AVCCleanerChromeCompactDatabases@Piriform@@
.?AV?$RuleBase@VCCleanerChromeCompactDatabases@Piriform@@@Opera@Rules@Piriform@@
.?AV?$RuleBase@VCCleanerChromeCompactDatabases@Piriform@@@Opera@Rules@Piriform@@
.?AVCCleanerChromeFormHistory@Piriform@@
.?AVCCleanerChromeFormHistory@Piriform@@
.?AV?$RuleBase@VCCleanerChromeFormHistory@Piriform@@@Opera@Rules@Piriform@@
.?AV?$RuleBase@VCCleanerChromeFormHistory@Piriform@@@Opera@Rules@Piriform@@
.?AVCCleanerChromeDownload@Piriform@@
.?AVCCleanerChromeDownload@Piriform@@
.?AV?$RuleBase@VCCleanerChromeDownload@Piriform@@@Opera@Rules@Piriform@@
.?AV?$RuleBase@VCCleanerChromeDownload@Piriform@@@Opera@Rules@Piriform@@
.?AVCCleanerChromeHistory@Piriform@@
.?AVCCleanerChromeHistory@Piriform@@
.?AV?$RuleBase@VCCleanerChromeHistory@Piriform@@@Opera@Rules@Piriform@@
.?AV?$RuleBase@VCCleanerChromeHistory@Piriform@@@Opera@Rules@Piriform@@
.?AV?$sp_counted_impl_p@VCppSQLite3DB@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCppSQLite3DB@@@detail@boost@@
.?AVCppSQLite3Exception@@
.?AVCppSQLite3Exception@@
.?AV?$sp_counted_impl_p@URuleKeyInfo@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@URuleKeyInfo@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCOperaStartUpManager@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCOperaStartUpManager@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCChromeStartUpManager@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCChromeStartUpManager@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCMozillaStartUpManager@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCMozillaStartUpManager@Piriform@@@detail@boost@@
.?AVCEnumRegKey@Registry@Piriform@@
.?AVCEnumRegKey@Registry@Piriform@@
.?AVCSavedPasswords@IE@Rules@Piriform@@
.?AVCSavedPasswords@IE@Rules@Piriform@@
.?AV?$sp_counted_impl_p@VCOperaSuperCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCOperaSuperCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCWindowsEventManager@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCWindowsEventManager@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCOperaOfflineCacheCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCOperaOfflineCacheCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCMozillaOfflineCacheCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCMozillaOfflineCacheCookies@Piriform@@@detail@boost@@
.?AVCCleanerPreviousWindowsInstallation@Piriform@@
.?AVCCleanerPreviousWindowsInstallation@Piriform@@
.?AVCCleanerSafariSavedPasswords@Piriform@@
.?AVCCleanerSafariSavedPasswords@Piriform@@
.?AVCCleanerMozillaCompactDatabases@Piriform@@
.?AVCCleanerMozillaCompactDatabases@Piriform@@
.?AVCCleanerWindowsEventLogs@Piriform@@
.?AVCCleanerWindowsEventLogs@Piriform@@
.?AVCCleanerNetworkPasswords@Piriform@@
.?AVCCleanerNetworkPasswords@Piriform@@
.?AVCCleanerChromeFlashCookies@Piriform@@
.?AVCCleanerChromeFlashCookies@Piriform@@
.?AVCCleanerChromeSavedPasswords@Piriform@@
.?AVCCleanerChromeSavedPasswords@Piriform@@
.?AVCCleanerChromeLastDownloadLocation@Piriform@@
.?AVCCleanerChromeLastDownloadLocation@Piriform@@
.?AVCCleanerChromeCache@Piriform@@
.?AVCCleanerChromeCache@Piriform@@
.?AVCCleanerMozillaCache@Piriform@@
.?AVCCleanerMozillaCache@Piriform@@
.?AVCCleanerMozillaCacheBase@Piriform@@
.?AVCCleanerMozillaCacheBase@Piriform@@
.?AVCCleanerOperaCookies@Piriform@@
.?AVCCleanerOperaCookies@Piriform@@
.?AVCCleanerOperaWebsiteIcons@Piriform@@
.?AVCCleanerOperaWebsiteIcons@Piriform@@
.?AVCCleanerOperaSavedPasswords@Piriform@@
.?AVCCleanerOperaSavedPasswords@Piriform@@
.?AVCCleanerOperaRecentlyTypedUrls@Piriform@@
.?AVCCleanerOperaRecentlyTypedUrls@Piriform@@
.?AVCCleanerOperaLastDownloadLocation@Piriform@@
.?AVCCleanerOperaLastDownloadLocation@Piriform@@
.?AVCCleanerOperaSession@Piriform@@
.?AVCCleanerOperaSession@Piriform@@
.?AVCCleanerOperaHistory@Piriform@@
.?AVCCleanerOperaHistory@Piriform@@
.?AVCCleanerOperaCache@Piriform@@
.?AVCCleanerOperaCache@Piriform@@
.?AVCCleanerMozillaSitePreferences@Piriform@@
.?AVCCleanerMozillaSitePreferences@Piriform@@
.?AVCCleanerMozillaGoogleToolbar@Piriform@@
.?AVCCleanerMozillaGoogleToolbar@Piriform@@
.?AVCCleanerMozillaSession@Piriform@@
.?AVCCleanerMozillaSession@Piriform@@
.?AVCCleanerMozillaSavedPasswords@Piriform@@
.?AVCCleanerMozillaSavedPasswords@Piriform@@
.?AVCCleanerMozillaFormHistory@Piriform@@
.?AVCCleanerMozillaFormHistory@Piriform@@
.?AVCCleanerMozillaCookies@Piriform@@
.?AVCCleanerMozillaCookies@Piriform@@
.?AVCCleanerMozillaDownload@Piriform@@
.?AVCCleanerMozillaDownload@Piriform@@
.?AVCCleanerMozillaHistory@Piriform@@
.?AVCCleanerMozillaHistory@Piriform@@
.?AVCSavedPasswords@Edge@Rules@Piriform@@
.?AVCSavedPasswords@Edge@Rules@Piriform@@
.?AVCWindowsServicesRule@Piriform@@
.?AVCWindowsServicesRule@Piriform@@
.?AV?$sp_counted_impl_p@VCppSQLite3Query@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCppSQLite3Query@@@detail@boost@@
.?AVCChromeIndexedDB@Piriform@@
.?AVCChromeIndexedDB@Piriform@@
.?AVCChromeStorageDatabases@Piriform@@
.?AVCChromeStorageDatabases@Piriform@@
.?AVCChromeSuperCookies@Piriform@@
.?AVCChromeSuperCookies@Piriform@@
.?AVCChromeCookies@Piriform@@
.?AVCChromeCookies@Piriform@@
.?AV?$sp_counted_impl_p@UOperaOfflineCacheCookieInfo@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@UOperaOfflineCacheCookieInfo@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@UOperaSuperCookieInfo@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@UOperaSuperCookieInfo@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@UDomainEntry@COperaCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@UDomainEntry@COperaCookies@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VTag@Opera@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VTag@Opera@Piriform@@@detail@boost@@
.?AVCOperaOfflineCacheCookies@Piriform@@
.?AVCOperaOfflineCacheCookies@Piriform@@
.?AVCOperaSuperCookies@Piriform@@
.?AVCOperaSuperCookies@Piriform@@
.?AVCOperaCookies@Piriform@@
.?AVCOperaCookies@Piriform@@
.?AUIOperaCookies@Piriform@@
.?AUIOperaCookies@Piriform@@
.?AUIOperaCookiesEnumerator@Piriform@@
.?AUIOperaCookiesEnumerator@Piriform@@
.?AV?$sp_counted_impl_p@UMozillaCacheInfo@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@UMozillaCacheInfo@Piriform@@@detail@boost@@
.?AUIMozillaCacheEvents@Piriform@@
.?AUIMozillaCacheEvents@Piriform@@
.?AVCMozillaOfflineCacheCookies@Piriform@@
.?AVCMozillaOfflineCacheCookies@Piriform@@
.?AVCMozillaStorage@Piriform@@
.?AVCMozillaStorage@Piriform@@
.?AVCMozillaIndexedDB@Piriform@@
.?AVCMozillaIndexedDB@Piriform@@
.?AVCMozillaCookies@Piriform@@
.?AVCMozillaCookies@Piriform@@
.?AUIMozillaCacheManager@Piriform@@
.?AUIMozillaCacheManager@Piriform@@
.?AU?$IAsyncOperationWithProgress_impl@VCDeploymentResult@WinRT@Piriform@@UDeploymentProgress@23@@WinRT@Piriform@@
.?AU?$IAsyncOperationWithProgress_impl@VCDeploymentResult@WinRT@Piriform@@UDeploymentProgress@23@@WinRT@Piriform@@
.?AVCAsyncOperationWithProgress@WinRT@Piriform@@
.?AVCAsyncOperationWithProgress@WinRT@Piriform@@
.?AV?$sp_counted_impl_p@VCMozillaApps@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCMozillaApps@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCMozillaPlugins@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCMozillaPlugins@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCMozillaExtensions@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCMozillaExtensions@Piriform@@@detail@boost@@
.?AVCMozillaStartUpManager@Piriform@@
.?AVCMozillaStartUpManager@Piriform@@
.?AV?$sp_counted_impl_p@VCChromePlugins@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCChromePlugins@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCChromeAddOns@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCChromeAddOns@Piriform@@@detail@boost@@
.?AVCChromeStartUpManager@Piriform@@
.?AVCChromeStartUpManager@Piriform@@
.?AVCOperaStartUpManager@Piriform@@
.?AVCOperaStartUpManager@Piriform@@
.?AVCOperaToolbar@Piriform@@
.?AVCOperaToolbar@Piriform@@
.?AVCOperaPersistentResources@Piriform@@
.?AVCOperaPersistentResources@Piriform@@
.?AVCOperaBookmarks@Piriform@@
.?AVCOperaBookmarks@Piriform@@
.?AVCOperaDatabaseBookmarksProvider@Piriform@@
.?AVCOperaDatabaseBookmarksProvider@Piriform@@
.?AVCWindowsEventManager@Piriform@@
.?AVCWindowsEventManager@Piriform@@
.?AUIWindowsEventManager@Piriform@@
.?AUIWindowsEventManager@Piriform@@
.?AV?$sp_counted_impl_p@VCOperaDatabaseBookmarksProvider@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCOperaDatabaseBookmarksProvider@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCChromeJSONBookmarksProvider@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VCChromeJSONBookmarksProvider@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VPrefsFile@Mozilla@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VPrefsFile@Mozilla@Piriform@@@detail@boost@@
.?AVCMozillaExtensions@Piriform@@
.?AVCMozillaExtensions@Piriform@@
.?AV?$sp_counted_impl_p@VPluginFile@CMozillaPlugins@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@VPluginFile@CMozillaPlugins@Piriform@@@detail@boost@@
.?AVCMozillaPlugins@Piriform@@
.?AVCMozillaPlugins@Piriform@@
.?AVCMozillaApps@Piriform@@
.?AVCMozillaApps@Piriform@@
.?AV?$sp_counted_impl_p@UPreferencesContext@CChromeAddOns@Piriform@@@detail@boost@@
.?AV?$sp_counted_impl_p@UPreferencesContext@CChromeAddOns@Piriform@@@detail@boost@@
.?AVCChromeAddOns@Piriform@@
.?AVCChromeAddOns@Piriform@@
.?AVCChromePlugins@Piriform@@
.?AVCChromePlugins@Piriform@@
.?AVCChromeJSONBookmarksProvider@Piriform@@
.?AVCChromeJSONBookmarksProvider@Piriform@@
.?AV?$CKeyboardFocusImpl@VCCheckComboBox@@@Piriform@@
.?AV?$CKeyboardFocusImpl@VCCheckComboBox@@@Piriform@@
.?AV?$CForwardedKeysEditT@VCWindow@ATL@@@@
.?AV?$CForwardedKeysEditT@VCWindow@ATL@@@@
.?AVCppSQLite3DB@@
.?AVCppSQLite3DB@@
.?AVCppSQLite3Statement@@
.?AVCppSQLite3Statement@@
.?AVCppSQLite3Query@@
.?AVCppSQLite3Query@@
.?AV?$VariableKeyLength@$0BA@$03$0DI@$00$03$0A@@CryptoPP@@
.?AV?$VariableKeyLength@$0BA@$03$0DI@$00$03$0A@@CryptoPP@@
.?AVSimpleKeyingInterface@CryptoPP@@
.?AVSimpleKeyingInterface@CryptoPP@@
.?AV?$SimpleKeyingInterfaceImpl@V?$TwoBases@VBlockCipher@CryptoPP@@UBlowfish_Info@2@@CryptoPP@@V12@@CryptoPP@@
.?AV?$SimpleKeyingInterfaceImpl@V?$TwoBases@VBlockCipher@CryptoPP@@UBlowfish_Info@2@@CryptoPP@@V12@@CryptoPP@@
.?AV?$AlgorithmImpl@V?$SimpleKeyingInterfaceImpl@V?$TwoBases@VBlockCipher@CryptoPP@@UBlowfish_Info@2@@CryptoPP@@V12@@CryptoPP@@V12@@CryptoPP@@
.?AV?$AlgorithmImpl@V?$SimpleKeyingInterfaceImpl@V?$TwoBases@VBlockCipher@CryptoPP@@UBlowfish_Info@2@@CryptoPP@@V12@@CryptoPP@@V12@@CryptoPP@@
.PAVRandomNumberGenerator@CryptoPP@@
.PAVRandomNumberGenerator@CryptoPP@@
.?AUIActivationExEvents@Piriform@@
.?AUIActivationExEvents@Piriform@@
.?AV?$bind_t@XV?$mf2@XV?$IAutoUpdateEventsAsyncImpl@VCAutoUpdateEventsMarshaller@Piriform@@UIUpdateEvents@2@@Piriform@@ABV?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@_N@_mfi@boost@@V?$list3@V?$value@PAV?$IAutoUpdateEventsAsyncImpl@VCAutoUpdateEventsMarshaller@Piriform@@UIUpdateEvents@2@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@V?$value@_N@23@@_bi@3@@_bi@boost@@
.?AV?$bind_t@XV?$mf2@XV?$IAutoUpdateEventsAsyncImpl@VCAutoUpdateEventsMarshaller@Piriform@@UIUpdateEvents@2@@Piriform@@ABV?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@_N@_mfi@boost@@V?$list3@V?$value@PAV?$IAutoUpdateEventsAsyncImpl@VCAutoUpdateEventsMarshaller@Piriform@@UIUpdateEvents@2@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@V?$value@_N@23@@_bi@3@@_bi@boost@@
.?AV?$bind_t@XV?$mf1@XV?$IAutoUpdateEventsAsyncImpl@VCAutoUpdateEventsMarshaller@Piriform@@UIUpdateEvents@2@@Piriform@@ABV?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@_mfi@boost@@V?$list2@V?$value@PAV?$IAutoUpdateEventsAsyncImpl@VCAutoUpdateEventsMarshaller@Piriform@@UIUpdateEvents@2@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AV?$bind_t@XV?$mf1@XV?$IAutoUpdateEventsAsyncImpl@VCAutoUpdateEventsMarshaller@Piriform@@UIUpdateEvents@2@@Piriform@@ABV?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@_mfi@boost@@V?$list2@V?$value@PAV?$IAutoUpdateEventsAsyncImpl@VCAutoUpdateEventsMarshaller@Piriform@@UIUpdateEvents@2@@Piriform@@@_bi@boost@@V?$value@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@23@@_bi@3@@_bi@boost@@
.?AVIActivationExEventsImpl@Piriform@@
.?AVIActivationExEventsImpl@Piriform@@
.?AVexecution_error@TinyXPath@@
.?AVexecution_error@TinyXPath@@
.?AUNoChannelSupport@BufferedTransformation@CryptoPP@@
.?AUNoChannelSupport@BufferedTransformation@CryptoPP@@
.?AVInvalidKeyLength@CryptoPP@@
.?AVInvalidKeyLength@CryptoPP@@
.PAV?$basic_istream@DU?$char_traits@D@std@@@std@@
.PAV?$basic_istream@DU?$char_traits@D@std@@@std@@
.PAV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.PAV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$VariableKeyLength@$0BA@$0BA@$0CA@$07$03$0A@@CryptoPP@@
.?AV?$VariableKeyLength@$0BA@$0BA@$0CA@$07$03$0A@@CryptoPP@@
.?AV?$SimpleKeyingInterfaceImpl@V?$TwoBases@VBlockCipher@CryptoPP@@URijndael_Info@2@@CryptoPP@@V12@@CryptoPP@@
.?AV?$SimpleKeyingInterfaceImpl@V?$TwoBases@VBlockCipher@CryptoPP@@URijndael_Info@2@@CryptoPP@@V12@@CryptoPP@@
.?AV?$AlgorithmImpl@V?$SimpleKeyingInterfaceImpl@V?$TwoBases@VBlockCipher@CryptoPP@@URijndael_Info@2@@CryptoPP@@V12@@CryptoPP@@V12@@CryptoPP@@
.?AV?$AlgorithmImpl@V?$SimpleKeyingInterfaceImpl@V?$TwoBases@VBlockCipher@CryptoPP@@URijndael_Info@2@@CryptoPP@@V12@@CryptoPP@@V12@@CryptoPP@@
.?AUAMFUnsupportedItem@SolApi@@
.?AUAMFUnsupportedItem@SolApi@@
.?AV?$sp_counted_impl_pd@PAUAMFUnsupportedItem@SolApi@@V?$sp_ms_deleter@UAMFUnsupportedItem@SolApi@@@detail@boost@@@detail@boost@@
.?AV?$sp_counted_impl_pd@PAUAMFUnsupportedItem@SolApi@@V?$sp_ms_deleter@UAMFUnsupportedItem@SolApi@@@detail@boost@@@detail@boost@@
.?AV?$sp_ms_deleter@UAMFUnsupportedItem@SolApi@@@detail@boost@@
.?AV?$sp_ms_deleter@UAMFUnsupportedItem@SolApi@@@detail@boost@@
'AJs.OS
'AJs.OS
>.BR~
>.BR~
5.BEYn
5.BEYn
Thawte Certification1
Thawte Certification1
hXXp://ocsp.thawte.com0
hXXp://ocsp.thawte.com0
.hXXp://crl.thawte.com/ThawteTimestampingCA.crl0
.hXXp://crl.thawte.com/ThawteTimestampingCA.crl0
hXXp://ts-ocsp.ws.symantec.com07
hXXp://ts-ocsp.ws.symantec.com07
hXXp://ts-aia.ws.symantec.com/tss-ca-g2.cer0
hXXp://ts-aia.ws.symantec.com/tss-ca-g2.cer0
hXXp://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
hXXp://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
hXXp://sv.symcb.com/sv.crl0f
hXXp://sv.symcb.com/sv.crl0f
hXXps://d.symcb.com/cps0%
hXXps://d.symcb.com/cps0%
hXXps://d.symcb.com/rpa0
hXXps://d.symcb.com/rpa0
hXXp://sv.symcd.com0&
hXXp://sv.symcd.com0&
hXXp://sv.symcb.com/sv.crt0
hXXp://sv.symcb.com/sv.crt0
hXXp://s2.symcb.com0
hXXp://s2.symcb.com0
hXXp://VVV.symauth.com/cps0(
hXXp://VVV.symauth.com/cps0(
hXXp://VVV.symauth.com/rpa00
hXXp://VVV.symauth.com/rpa00
hXXp://s1.symcb.com/pca3-g5.crl0
hXXp://s1.symcb.com/pca3-g5.crl0
; 3002 = Windows Explorer
; 3002 = Windows Explorer
Detect1=HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Spartan_cw5n1h2txyewy
Detect1=HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Spartan_cw5n1h2txyewy
Detect2=HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
Detect2=HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
DetectFile1=%LocalAppData%\Packages\Microsoft.Windows.Spartan_cw5n1h2txyewy
DetectFile1=%LocalAppData%\Packages\Microsoft.Windows.Spartan_cw5n1h2txyewy
DetectFile2=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
DetectFile2=%LocalAppData%\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
SpecialKey1=N_EDGE_TEMP
SpecialKey1=N_EDGE_TEMP
SpecialKey1=N_EDGE_HISTORY
SpecialKey1=N_EDGE_HISTORY
SpecialKey1=N_EDGE_COOKIES
SpecialKey1=N_EDGE_COOKIES
SpecialKey1=N_EDGE_DOWNLOAD_HISTORY
SpecialKey1=N_EDGE_DOWNLOAD_HISTORY
SpecialKey1=N_EDGE_SESSION
SpecialKey1=N_EDGE_SESSION
[Microsoft Edge - Recently Typed URLs]
[Microsoft Edge - Recently Typed URLs]
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.spartan_cw5n1h2txyewy\Spartan\TypedURLs
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.spartan_cw5n1h2txyewy\Spartan\TypedURLs
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.spartan_cw5n1h2txyewy\Spartan\TypedURLsTime
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.spartan_cw5n1h2txyewy\Spartan\TypedURLsTime
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.spartan_cw5n1h2txyewy\Spartan\TypedURLsVisitCount
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.spartan_cw5n1h2txyewy\Spartan\TypedURLsVisitCount
RegKey4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLs
RegKey4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLs
RegKey5=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsTime
RegKey5=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsTime
RegKey6=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsVisitCount
RegKey6=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsVisitCount
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.spartan_cw5n1h2txyewy\Spartan\IntelliForms\FormData
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.spartan_cw5n1h2txyewy\Spartan\IntelliForms\FormData
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\IntelliForms\FormData
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\IntelliForms\FormData
[Microsoft Edge - Saved Passwords]
[Microsoft Edge - Saved Passwords]
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.spartan_cw5n1h2txyewy\Spartan\IntelliForms\Storage2
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.spartan_cw5n1h2txyewy\Spartan\IntelliForms\Storage2
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\IntelliForms\Storage2
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\IntelliForms\Storage2
SpecialKey1=N_EDGE_PASSWORD
SpecialKey1=N_EDGE_PASSWORD
SpecialKey1=N_INT_TEMP
SpecialKey1=N_INT_TEMP
SpecialKey1=N_INT_HISTORY
SpecialKey1=N_INT_HISTORY
RegKey1=HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
RegKey1=HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
SpecialKey1=N_INT_COOKIES
SpecialKey1=N_INT_COOKIES
[Recently Typed URLs]
[Recently Typed URLs]
RegKey1=HKCU\Software\Microsoft\Internet Explorer\TypedURLs
RegKey1=HKCU\Software\Microsoft\Internet Explorer\TypedURLs
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
RegKey3=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU
RegKey3=HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU
[Delete Index.dat files]
[Delete Index.dat files]
SpecialKey1=N_INT_INDEXDAT
SpecialKey1=N_INT_INDEXDAT
RegKey1=HKCU\Software\Microsoft\Internet Explorer|Download Directory
RegKey1=HKCU\Software\Microsoft\Internet Explorer|Download Directory
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Main|Save Directory
RegKey2=HKCU\Software\Microsoft\Internet Explorer\Main|Save Directory
SpecialKey1=N_INT_LAST_DOWNLOAD_LOCATION
SpecialKey1=N_INT_LAST_DOWNLOAD_LOCATION
SpecialKey1=N_INT_AUTOCOMPLETE
SpecialKey1=N_INT_AUTOCOMPLETE
[Saved Passwords]
[Saved Passwords]
SpecialKey1=N_INT_PASSWORD
SpecialKey1=N_INT_PASSWORD
SpecialKey1=N_EX_RECENTDOCS
SpecialKey1=N_EX_RECENTDOCS
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
RegKey1=HKCU\Software\Microsoft\Search Assistant\ACMru
RegKey1=HKCU\Software\Microsoft\Search Assistant\ACMru
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\PrnPortsMRU
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\PrnPortsMRU
RegKey4=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU
RegKey4=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU
RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComputerDescriptions
RegKey5=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComputerDescriptions
RegKey6=HKLM\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey6=HKLM\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey7=HKCU\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey7=HKCU\Software\Microsoft\Direct3D\MostRecentApplication|Name
RegKey8=HKLM\Software\Microsoft\DirectDraw\MostRecentApplication
RegKey8=HKLM\Software\Microsoft\DirectDraw\MostRecentApplication
RegKey9=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Id
RegKey9=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Id
RegKey10=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Name
RegKey10=HKCU\Software\Microsoft\DirectInput\MostRecentApplication|Name
RegKey11=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
RegKey11=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
RegKey12=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths
RegKey12=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths
RegKey13=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit|LastKey
RegKey13=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit|LastKey
RegKey14=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU
RegKey14=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU
RegKey15=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpapers\Images
RegKey15=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpapers\Images
SpecialKey1=N_TEMP_RECYCLEBIN
SpecialKey1=N_TEMP_RECYCLEBIN
SpecialKey1=N_TEMP_DIRS
SpecialKey1=N_TEMP_DIRS
SpecialKey1=N_TEMP_CLIPBOARD
SpecialKey1=N_TEMP_CLIPBOARD
FileKey1=%windir%|memory.dmp
FileKey1=%windir%|memory.dmp
FileKey2=%windir%\MiniDump|*.dmp
FileKey2=%windir%\MiniDump|*.dmp
FileKey3=%LocalAppData%\CrashDumps|*.dmp
FileKey3=%LocalAppData%\CrashDumps|*.dmp
FileKey1=%SystemDrive%|File*.chk
FileKey1=%SystemDrive%|File*.chk
[Windows Log Files]
[Windows Log Files]
FileKey1=%SystemDirectory%\wbem\Logs|*.log
FileKey1=%SystemDirectory%\wbem\Logs|*.log
FileKey2=%SystemDirectory%\wbem\Logs|*.lo_
FileKey2=%SystemDirectory%\wbem\Logs|*.lo_
FileKey3=%windir%|*.log
FileKey3=%windir%|*.log
FileKey4=%windir%|*.bak
FileKey4=%windir%|*.bak
FileKey5=%windir%|*log.txt
FileKey5=%windir%|*log.txt
FileKey6=%commonappdata%\Microsoft\Dr Watson|*.log
FileKey6=%commonappdata%\Microsoft\Dr Watson|*.log
FileKey7=%commonappdata%\Microsoft\Dr Watson|*.dmp
FileKey7=%commonappdata%\Microsoft\Dr Watson|*.dmp
FileKey8=%windir%\Debug|*.log
FileKey8=%windir%\Debug|*.log
FileKey9=%windir%\Debug\UserMode|*.log
FileKey9=%windir%\Debug\UserMode|*.log
FileKey10=%windir%\Debug\UserMode|*.bak
FileKey10=%windir%\Debug\UserMode|*.bak
FileKey11=%windir%|SchedLgU.txt
FileKey11=%windir%|SchedLgU.txt
FileKey12=%windir%\security\logs|*.log
FileKey12=%windir%\security\logs|*.log
FileKey13=%windir%\security\logs|*.old
FileKey13=%windir%\security\logs|*.old
FileKey14=%windir%\SoftwareDistribution|*.log
FileKey14=%windir%\SoftwareDistribution|*.log
FileKey15=%windir%\Logs|*.log|RECURSE
FileKey15=%windir%\Logs|*.log|RECURSE
FileKey16=%windir%\ServiceProfiles\LocalService\AppData|*.Log|RECURSE
FileKey16=%windir%\ServiceProfiles\LocalService\AppData|*.Log|RECURSE
FileKey17=%windir%\ServiceProfiles\NetworkService\AppData|*.Log|RECURSE
FileKey17=%windir%\ServiceProfiles\NetworkService\AppData|*.Log|RECURSE
FileKey18=%LocalAppData%\Microsoft\Windows|*.log|RECURSE
FileKey18=%LocalAppData%\Microsoft\Windows|*.log|RECURSE
FileKey19=%AppData%\Microsoft\Windows|*.log|RECURSE
FileKey19=%AppData%\Microsoft\Windows|*.log|RECURSE
FileKey20=%windir%\Microsoft.NET|*.log|RECURSE
FileKey20=%windir%\Microsoft.NET|*.log|RECURSE
FileKey21=%LocalAppData%\MigWiz|*.log
FileKey21=%LocalAppData%\MigWiz|*.log
FileKey22=%LocalAppData%\MigWiz|*.xml
FileKey22=%LocalAppData%\MigWiz|*.xml
FileKey23=%windir%\inf|setupapi.app.log
FileKey23=%windir%\inf|setupapi.app.log
FileKey24=%windir%\inf|setupapi.dev.log
FileKey24=%windir%\inf|setupapi.dev.log
FileKey25=%windir%\Panther\UnattendGC|setupact.log
FileKey25=%windir%\Panther\UnattendGC|setupact.log
FileKey26=%windir%\Panther\UnattendGC|setuperr.log
FileKey26=%windir%\Panther\UnattendGC|setuperr.log
FileKey27=%windir%\Panther|setupact.log
FileKey27=%windir%\Panther|setupact.log
FileKey28=%windir%\Panther|setuperr.log
FileKey28=%windir%\Panther|setuperr.log
FileKey29=%WinDir%\ModemLogs|*.txt
FileKey29=%WinDir%\ModemLogs|*.txt
FileKey30=%WinDir%\Performance\WinSAT|winsat.log
FileKey30=%WinDir%\Performance\WinSAT|winsat.log
FileKey31=%LocalAppData%\Microsoft\CLR_v4.0\*|*.log
FileKey31=%LocalAppData%\Microsoft\CLR_v4.0\*|*.log
FileKey32=%LocalAppData%\Microsoft\CLR_v4.0_32\*|*.log
FileKey32=%LocalAppData%\Microsoft\CLR_v4.0_32\*|*.log
FileKey33=%SystemDirectory%\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0\*|*.log
FileKey33=%SystemDirectory%\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0\*|*.log
FileKey34=%SystemDirectory%\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0_32\*|*.log
FileKey34=%SystemDirectory%\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0_32\*|*.log
[Windows Error Reporting]
[Windows Error Reporting]
FileKey1=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportArchive|*.*|RECURSE
FileKey1=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportArchive|*.*|RECURSE
FileKey2=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportQueue|*.*|RECURSE
FileKey2=%ALLUSERSPROFILE%\Microsoft\Windows\WER\ReportQueue|*.*|RECURSE
FileKey3=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportArchive|*.*|RECURSE
FileKey3=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportArchive|*.*|RECURSE
FileKey4=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportQueue|*.*|RECURSE
FileKey4=%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportQueue|*.*|RECURSE
FileKey5=%LocalAppData%\ElevatedDiagnostics|*.*|REMOVESELF
FileKey5=%LocalAppData%\ElevatedDiagnostics|*.*|REMOVESELF
RegKey1=HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation
RegKey1=HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation
RegKey2=HKLM\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation
RegKey2=HKLM\Software\Microsoft\Windows\Windows Error Reporting\Debug|StoreLocation
SpecialKey1=N_EX_DNS_CACHE
SpecialKey1=N_EX_DNS_CACHE
FileKey1=%WinDir%\System32|FNTCACHE.DAT
FileKey1=%WinDir%\System32|FNTCACHE.DAT
FileKey2=%LocalAppData%|GDIPFONTCACHEV1.DAT
FileKey2=%LocalAppData%|GDIPFONTCACHEV1.DAT
FileKey3=%windir%\ServiceProfiles\LocalService\AppData\Local|FontCache*.dat
FileKey3=%windir%\ServiceProfiles\LocalService\AppData\Local|FontCache*.dat
[Windows Event Logs]
[Windows Event Logs]
SpecialKey1=N_EX_WINDOWS_EVENT_LOGS
SpecialKey1=N_EX_WINDOWS_EVENT_LOGS
Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OptimalLayout
Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OptimalLayout
SpecialKey1=N_INT_PREFETCH
SpecialKey1=N_INT_PREFETCH
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|IconStreams
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|IconStreams
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|PastIconsStream
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify|PastIconsStream
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|IconStreams
RegKey3=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|IconStreams
RegKey4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|PastIconsStream
RegKey4=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify|PastIconsStream
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams
SpecialKey1=N_EX_ENVIRONMENT_PATH
SpecialKey1=N_EX_ENVIRONMENT_PATH
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
RegKey2=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
RegKey3=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
RegKey4=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
RegKey4=HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
FileKey1=%SystemDirectory%\LogFiles|*.*|RECURSE
FileKey1=%SystemDirectory%\LogFiles|*.*|RECURSE
FileKey2=%SystemDrive%\inetpub\logs\LogFiles|*.*|RECURSE
FileKey2=%SystemDrive%\inetpub\logs\LogFiles|*.*|RECURSE
ExcludeKey1=PATH|%SystemDirectory%\LogFiles\|SCM
ExcludeKey1=PATH|%SystemDirectory%\LogFiles\|SCM
SpecialKey1=N_EX_HOTFIX
SpecialKey1=N_EX_HOTFIX
[Old Windows Installation]
[Old Windows Installation]
DetectFile1=%SystemDrive%\Windows.old*
DetectFile1=%SystemDrive%\Windows.old*
DetectFile2=%SystemDrive%\$WINDOWS.~Q
DetectFile2=%SystemDrive%\$WINDOWS.~Q
DetectFile3=%SystemDrive%\$INPLACE.~TR
DetectFile3=%SystemDrive%\$INPLACE.~TR
SpecialKey1=N_EX_PREVIOUS_WINDOWS_INSTALLATION
SpecialKey1=N_EX_PREVIOUS_WINDOWS_INSTALLATION
SpecialKey1=N_EX_CUSTOMFOLDERS
SpecialKey1=N_EX_CUSTOMFOLDERS
SpecialKey1=F_STARTMENU
SpecialKey1=F_STARTMENU
SpecialKey1=F_DESKTOP
SpecialKey1=F_DESKTOP
SpecialKey1=N_EX_THUMBNAIL_CACHE
SpecialKey1=N_EX_THUMBNAIL_CACHE
FileKey1=%LocalAppData%\Microsoft\Windows\Explorer|thumbcache_*.db
FileKey1=%LocalAppData%\Microsoft\Windows\Explorer|thumbcache_*.db
FileKey2=%LocalAppData%\Microsoft\Windows\Explorer\ThumbCacheToDelete|thm*.tmp
FileKey2=%LocalAppData%\Microsoft\Windows\Explorer\ThumbCacheToDelete|thm*.tmp
SpecialKey1=N_EX_WIPE_MFT_FREE_SPACE
SpecialKey1=N_EX_WIPE_MFT_FREE_SPACE
SpecialKey2=N_EX_WIPEFREESPACE
SpecialKey2=N_EX_WIPEFREESPACE
SpecialKey1=N_EX_JUMP_LISTS
SpecialKey1=N_EX_JUMP_LISTS
[Network Passwords]
[Network Passwords]
RegKey1=HKCU\Software\Microsoft\Ftp\Accounts
RegKey1=HKCU\Software\Microsoft\Ftp\Accounts
SpecialKey1=N_EX_NETWORK_PASSWORDS; CCleaner - Registry Cleaning file
SpecialKey1=N_EX_NETWORK_PASSWORDS; CCleaner - Registry Cleaning file
SpecialKey1=R_SHARED_DLLS
SpecialKey1=R_SHARED_DLLS
SpecialKey1=R_FILE_EXTS
SpecialKey1=R_FILE_EXTS
SpecialKey1=R_ACTIVEX
SpecialKey1=R_ACTIVEX
SpecialKey1=R_INTERFACE
SpecialKey1=R_INTERFACE
SpecialKey1=R_APP_OPENWITH
SpecialKey1=R_APP_OPENWITH
SpecialKey1=R_FONTS
SpecialKey1=R_FONTS
SpecialKey1=R_APP_PATHS
SpecialKey1=R_APP_PATHS
SpecialKey1=R_HELP
SpecialKey1=R_HELP
SpecialKey1=R_INSTALLER
SpecialKey1=R_INSTALLER
SpecialKey1=R_OLDSOFTWARE
SpecialKey1=R_OLDSOFTWARE
SpecialKey1=R_RUNSTARTUP
SpecialKey1=R_RUNSTARTUP
SpecialKey1=R_STARTMENUORDER
SpecialKey1=R_STARTMENUORDER
SpecialKey1=R_MUICACHE
SpecialKey1=R_MUICACHE
SpecialKey1=R_SOUND_EVENTS
SpecialKey1=R_SOUND_EVENTS
[Windows Services]
[Windows Services]
SpecialKey1=R_WINDOWS_SERVICES
SpecialKey1=R_WINDOWS_SERVICES
; called winapp2.ini which follows the same format as this one.
; called winapp2.ini which follows the same format as this one.
; 3025 = Windows
; 3025 = Windows
; 3026 = Firefox/Mozilla
; 3026 = Firefox/Mozilla
; 3027 = Opera
; 3027 = Opera
; 3029 = Google Chrome
; 3029 = Google Chrome
; 3031 = Windows Store
; 3031 = Windows Store
[Mozilla - Internet Cache]
[Mozilla - Internet Cache]
SpecialDetect=DET_MOZILLA
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_CACHE
SpecialKey1=N_MOZ_CACHE
[Mozilla - Internet History]
[Mozilla - Internet History]
SpecialKey1=N_MOZ_HISTORY
SpecialKey1=N_MOZ_HISTORY
[Mozilla - Download History]
[Mozilla - Download History]
SpecialKey1=N_MOZ_DOWNLOAD
SpecialKey1=N_MOZ_DOWNLOAD
[Mozilla - Cookies]
[Mozilla - Cookies]
SpecialKey1=N_MOZ_COOKIES
SpecialKey1=N_MOZ_COOKIES
[Mozilla - Saved Form Information]
[Mozilla - Saved Form Information]
SpecialKey1=N_MOZ_FORM
SpecialKey1=N_MOZ_FORM
[Mozilla - Saved Passwords]
[Mozilla - Saved Passwords]
SpecialKey1=N_MOZ_PASSWORD
SpecialKey1=N_MOZ_PASSWORD
[Mozilla - Session]
[Mozilla - Session]
SpecialKey1=N_MOZ_SESSION
SpecialKey1=N_MOZ_SESSION
[Mozilla - Site Preferences]
[Mozilla - Site Preferences]
SpecialKey1=N_MOZ_SITE_PREFERENCES
SpecialKey1=N_MOZ_SITE_PREFERENCES
[Mozilla - Compact Databases]
[Mozilla - Compact Databases]
SpecialKey1=N_MOZ_COMPACT_DATABASES
SpecialKey1=N_MOZ_COMPACT_DATABASES
SpecialKey1=N_THUNDERBIRD_CACHE
SpecialKey1=N_THUNDERBIRD_CACHE
SpecialKey1=N_THUNDERBIRD_HISTORY
SpecialKey1=N_THUNDERBIRD_HISTORY
SpecialKey1=N_THUNDERBIRD_DOWNLOAD
SpecialKey1=N_THUNDERBIRD_DOWNLOAD
SpecialKey1=N_THUNDERBIRD_COOKIES
SpecialKey1=N_THUNDERBIRD_COOKIES
SpecialKey1=N_THUNDERBIRD_FORM
SpecialKey1=N_THUNDERBIRD_FORM
[Thunderbird - Saved Passwords]
[Thunderbird - Saved Passwords]
SpecialKey1=N_THUNDERBIRD_PASSWORD
SpecialKey1=N_THUNDERBIRD_PASSWORD
SpecialKey1=N_THUNDERBIRD_SESSION
SpecialKey1=N_THUNDERBIRD_SESSION
SpecialKey1=N_THUNDERBIRD_SITE_PREFERENCES
SpecialKey1=N_THUNDERBIRD_SITE_PREFERENCES
SpecialKey1=N_THUNDERBIRD_COMPACT_DATABASES
SpecialKey1=N_THUNDERBIRD_COMPACT_DATABASES
[Opera - Internet Cache]
[Opera - Internet Cache]
SpecialDetect=DET_OPERA
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_CACHE
SpecialKey1=N_OPERA_CACHE
[Opera - Internet History]
[Opera - Internet History]
SpecialKey1=N_OPERA_HISTORY
SpecialKey1=N_OPERA_HISTORY
[Opera - Cookies]
[Opera - Cookies]
SpecialKey1=N_OPERA_COOKIES
SpecialKey1=N_OPERA_COOKIES
[Opera - Download History]
[Opera - Download History]
SpecialKey1=N_OPERA_DOWNLOAD
SpecialKey1=N_OPERA_DOWNLOAD
[Opera - Recently Typed URLs]
[Opera - Recently Typed URLs]
SpecialKey1=N_OPERA_RECENTLY_TYPED_URLS
SpecialKey1=N_OPERA_RECENTLY_TYPED_URLS
[Opera - Last Download Location]
[Opera - Last Download Location]
SpecialKey1=N_OPERA_LAST_DOWNLOAD_LOCATION
SpecialKey1=N_OPERA_LAST_DOWNLOAD_LOCATION
[Opera - Saved Passwords]
[Opera - Saved Passwords]
SpecialKey1=N_OPERA_PASSWORD
SpecialKey1=N_OPERA_PASSWORD
[Opera - Session]
[Opera - Session]
SpecialKey1=N_OPERA_SESSION
SpecialKey1=N_OPERA_SESSION
[Opera - Saved Form Information]
[Opera - Saved Form Information]
SpecialKey1=N_OPERA_FORM
SpecialKey1=N_OPERA_FORM
[Opera - Website Icons]
[Opera - Website Icons]
SpecialKey1=N_OPERA_WEBSITE_ICONS
SpecialKey1=N_OPERA_WEBSITE_ICONS
[Opera - Compact Databases]
[Opera - Compact Databases]
SpecialKey1=N_OPERA_COMPACT_DATABASES
SpecialKey1=N_OPERA_COMPACT_DATABASES
DetectFile=%ProgramFiles%\Safari\Safari.exe
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%localappdata%\Apple Computer\Safari|Cache.db
FileKey1=%localappdata%\Apple Computer\Safari|Cache.db
FileKey1=%appdata%\Apple Computer\Safari|History.plist
FileKey1=%appdata%\Apple Computer\Safari|History.plist
FileKey2=%appdata%\Apple Computer\Safari|LastSession.plist
FileKey2=%appdata%\Apple Computer\Safari|LastSession.plist
FileKey3=%appdata%\Apple Computer\Safari|TopSites.plist
FileKey3=%appdata%\Apple Computer\Safari|TopSites.plist
FileKey4=%appdata%\Apple Computer\Safari|Downloads.plist
FileKey4=%appdata%\Apple Computer\Safari|Downloads.plist
FileKey5=%localappdata%\Apple Computer\Safari\History|*.*
FileKey5=%localappdata%\Apple Computer\Safari\History|*.*
FileKey6=%localappdata%\Apple Computer\Safari\Webpage Previews|*.*|RECURSE
FileKey6=%localappdata%\Apple Computer\Safari\Webpage Previews|*.*|RECURSE
SpecialKey1=N_SAFARI_HISTORY
SpecialKey1=N_SAFARI_HISTORY
SpecialKey1=N_SAFARI_COOKIES
SpecialKey1=N_SAFARI_COOKIES
FileKey1=%appdata%\Apple Computer\Safari|Form Values.plist
FileKey1=%appdata%\Apple Computer\Safari|Form Values.plist
[Safari - Saved Passwords]
[Safari - Saved Passwords]
SpecialDetect=DET_SAFARI_PASSWORD
SpecialDetect=DET_SAFARI_PASSWORD
SpecialKey1=N_SAFARI_PASSWORD
SpecialKey1=N_SAFARI_PASSWORD
[Google Chrome - Internet Cache]
[Google Chrome - Internet Cache]
SpecialDetect=DET_CHROME
SpecialDetect=DET_CHROME
SpecialKey1=N_CHROME_CACHE
SpecialKey1=N_CHROME_CACHE
[Google Chrome - Internet History]
[Google Chrome - Internet History]
Section = Chrome
Section = Chrome
SpecialKey1=N_CHROME_HISTORY
SpecialKey1=N_CHROME_HISTORY
[Google Chrome - Download History]
[Google Chrome - Download History]
SpecialKey1=N_CHROME_DOWNLOAD
SpecialKey1=N_CHROME_DOWNLOAD
[Google Chrome - Last Download Location]
[Google Chrome - Last Download Location]
SpecialKey1=N_CHROME_LAST_DOWNLOAD_LOCATION
SpecialKey1=N_CHROME_LAST_DOWNLOAD_LOCATION
[Google Chrome - Cookies]
[Google Chrome - Cookies]
SpecialKey1=N_CHROME_COOKIES
SpecialKey1=N_CHROME_COOKIES
[Google Chrome - Saved Form Information]
[Google Chrome - Saved Form Information]
SpecialKey1=N_CHROME_FORM
SpecialKey1=N_CHROME_FORM
[Google Chrome - Saved Passwords]
[Google Chrome - Saved Passwords]
SpecialKey1=N_CHROME_PASSWORD
SpecialKey1=N_CHROME_PASSWORD
[Google Chrome - Session]
[Google Chrome - Session]
SpecialKey1=N_CHROME_SESSION
SpecialKey1=N_CHROME_SESSION
[Google Chrome - Compact Databases]
[Google Chrome - Compact Databases]
SpecialKey1=N_CHROME_COMPACT_DATABASES
SpecialKey1=N_CHROME_COMPACT_DATABASES
RegKey1=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\7.0\Cache\Search70|*.*
FileKey1=%localappdata%\Adobe\Acrobat\7.0\Cache\Search70|*.*
FileKey2=%ProgramFiles%\Adobe\Acrobat 7.0\Reader|*.bak
FileKey2=%ProgramFiles%\Adobe\Acrobat 7.0\Reader|*.bak
FileKey3=%ProgramFiles%\Adobe\Acrobat 7.0\ActiveX|*.bak
FileKey3=%ProgramFiles%\Adobe\Acrobat 7.0\ActiveX|*.bak
FileKey4=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\plug_ins|*.bak
FileKey4=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\plug_ins|*.bak
FileKey5=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\Updater|*.bak
FileKey5=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\Updater|*.bak
RegKey1=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\8.0\Cache\Search80|*.*
FileKey1=%localappdata%\Adobe\Acrobat\8.0\Cache\Search80|*.*
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Acrobat\9.0\Cache\Search|*.*
FileKey1=%LocalAppData%\Adobe\Acrobat\9.0\Cache\Search|*.*
FileKey2=%LocalLowAppData%\Adobe\Acrobat\9.0\Search|*.*
FileKey2=%LocalLowAppData%\Adobe\Acrobat\9.0\Search|*.*
RegKey1=HKCU\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Acrobat\10.0\Cache\Search|*.*
FileKey1=%LocalAppData%\Adobe\Acrobat\10.0\Cache\Search|*.*
FileKey2=%LocalLowAppData%\Adobe\Acrobat\10.0\Search|*.*
FileKey2=%LocalLowAppData%\Adobe\Acrobat\10.0\Search|*.*
RegKey1=HKCU\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Acrobat\11.0\Cache\Search|*.*
FileKey1=%LocalAppData%\Adobe\Acrobat\11.0\Cache\Search|*.*
FileKey2=%LocalLowAppData%\Adobe\Acrobat\11.0\Search|*.*
FileKey2=%LocalLowAppData%\Adobe\Acrobat\11.0\Search|*.*
RegKey1=HKCU\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles
RegKey2=HKCU\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFolders
RegKey2=HKCU\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFolders
FileKey1=%LocalAppData%\Adobe\Acrobat\DC\Cache|*.lst
FileKey1=%LocalAppData%\Adobe\Acrobat\DC\Cache|*.lst
FileKey2=%LocalAppData%\Adobe\Acrobat\DC|*.lst
FileKey2=%LocalAppData%\Adobe\Acrobat\DC|*.lst
FileKey3=%LocalLowAppData%\Adobe\Acrobat\DC\Search|*.*
FileKey3=%LocalLowAppData%\Adobe\Acrobat\DC\Search|*.*
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\9.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\9.0\AVGeneral\cRecentFiles
FileKey3=%LocalAppData%\Adobe\Acrobat\9.0\Cache|*.lst
FileKey3=%LocalAppData%\Adobe\Acrobat\9.0\Cache|*.lst
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\10.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\10.0\AVGeneral\cRecentFiles
FileKey3=%LocalAppData%\Adobe\Acrobat\10.0\Cache|*.lst
FileKey3=%LocalAppData%\Adobe\Acrobat\10.0\Cache|*.lst
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\11.0\AVGeneral\cRecentFiles
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\11.0\AVGeneral\cRecentFiles
RegKey2=HKCU\Software\Adobe\Adobe Acrobat\11.0\CompoundDocs\cStoredBinder
RegKey2=HKCU\Software\Adobe\Adobe Acrobat\11.0\CompoundDocs\cStoredBinder
FileKey1=%LocalAppData%\Adobe\Acrobat\11.0\Cache\|*.*
FileKey1=%LocalAppData%\Adobe\Acrobat\11.0\Cache\|*.*
RegKey1=HKCU\Software\Adobe\ImageReady 7.0\Preferences\URLHistory
RegKey1=HKCU\Software\Adobe\ImageReady 7.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 7.0\Preferences|SaveDir
RegKey2=HKCU\Software\Adobe\ImageReady 7.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 7.0\Preferences\RecentFiles
RegKey3=HKCU\Software\Adobe\ImageReady 7.0\Preferences\RecentFiles
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles
RegKey1=HKCU\Software\Adobe\Photoshop\6.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\6.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\7.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\7.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\8.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\8.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\9.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\9.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
FileKey1=%appdata%\Adobe\CameraRaw\Cache|*.*
FileKey1=%appdata%\Adobe\CameraRaw\Cache|*.*
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\11.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\11.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\12.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\12.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\60.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Photoshop\60.0\VisitedDirs
RegKey1=HKCU\Software\Adobe\Elements Organizer\12.0\CurrentMediaFilePath
RegKey1=HKCU\Software\Adobe\Elements Organizer\12.0\CurrentMediaFilePath
RegKey2=HKCU\Software\Adobe\Photoshop Elements\12.0\CurrentMediaFilePath
RegKey2=HKCU\Software\Adobe\Photoshop Elements\12.0\CurrentMediaFilePath
RegKey3=HKCU\Software\Adobe\Photoshop Elements\12.0\common\settings\Elements MRU
RegKey3=HKCU\Software\Adobe\Photoshop Elements\12.0\common\settings\Elements MRU
RegKey4=HKCU\Software\Adobe\Photoshop Elements\12.0\VisitedDirs|STARTUPIMAGEDIRECTORY
RegKey4=HKCU\Software\Adobe\Photoshop Elements\12.0\VisitedDirs|STARTUPIMAGEDIRECTORY
FileKey1=%CommonAppData%\Adobe\Photoshop Elements\12.0\Locale\*_*\Photo Creations\temp|*.dat
FileKey1=%CommonAppData%\Adobe\Photoshop Elements\12.0\Locale\*_*\Photo Creations\temp|*.dat
FileKey2=%AppData%\Adobe\Elements Organizer\12.0\Organizer|Log.txt
FileKey2=%AppData%\Adobe\Elements Organizer\12.0\Organizer|Log.txt
FileKey3=%CommonAppData%\Adobe\Elements Organizer\Catalogs\My Catalog|face.thumb.9.cache;thumb.5.cache
FileKey3=%CommonAppData%\Adobe\Elements Organizer\Catalogs\My Catalog|face.thumb.9.cache;thumb.5.cache
RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator\FileList
RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator\FileList
FileKey1=%LocalAppData%\Adobe\Air\Logs|*.*
FileKey1=%LocalAppData%\Adobe\Air\Logs|*.*
RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU\Dreamweaver\FileList
RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU\Dreamweaver\FileList
RegKey2=HKCU\Software\Adobe\Dreamweaver CS6\Recent File List
RegKey2=HKCU\Software\Adobe\Dreamweaver CS6\Recent File List
FileKey1=%ProgramFiles%\Adobe\Adobe Premiere Pro CC\cache|*-*-*.cache
FileKey1=%ProgramFiles%\Adobe\Adobe Premiere Pro CC\cache|*-*-*.cache
FileKey2=%ProgramFiles%\Adobe\Adobe Premiere Pro CC\Required\data\cache|*.pcache
FileKey2=%ProgramFiles%\Adobe\Adobe Premiere Pro CC\Required\data\cache|*.pcache
FileKey3=%AppData%\Adobe\dynamiclinkmanager\7.0\logs|*.log
FileKey3=%AppData%\Adobe\dynamiclinkmanager\7.0\logs|*.log
FileKey4=%AppData%\Adobe\Lumetri\7.0\log|*.log
FileKey4=%AppData%\Adobe\Lumetri\7.0\log|*.log
FileKey5=%AppData%\Adobe\Premiere Pro\7.0\logs|*.log
FileKey5=%AppData%\Adobe\Premiere Pro\7.0\logs|*.log
FileKey6=%AppData%\Adobe\Premiere Pro\7.0|Plugin Loading.log
FileKey6=%AppData%\Adobe\Premiere Pro\7.0|Plugin Loading.log
FileKey7=%AppData%\Adobe\Common\Media Cache Files|*.mediasrc
FileKey7=%AppData%\Adobe\Common\Media Cache Files|*.mediasrc
FileKey8=%AppData%\Adobe\Common\Media Cache|*.mediasrc
FileKey8=%AppData%\Adobe\Common\Media Cache|*.mediasrc
RegKey1=HKCU\Software\Adobe\Premiere Elements\12.0\MRUDocuments
RegKey1=HKCU\Software\Adobe\Premiere Elements\12.0\MRUDocuments
FileKey1=%AppData%\Adobe\Common\Thumbnail Cache|thumbnailDB
FileKey1=%AppData%\Adobe\Common\Thumbnail Cache|thumbnailDB
FileKey2=%AppData%\Adobe\Premiere Elements\12.0\logs|*.log
FileKey2=%AppData%\Adobe\Premiere Elements\12.0\logs|*.log
FileKey3=%AppData%\Adobe\Premiere Elements\12.0|Plugin Loading.log;CAHeadless Plugin Loading.log
FileKey3=%AppData%\Adobe\Premiere Elements\12.0|Plugin Loading.log;CAHeadless Plugin Loading.log
FileKey4=%AppData%\Adobe\Premiere Elements 12.0\12.0\logs|*.log
FileKey4=%AppData%\Adobe\Premiere Elements 12.0\12.0\logs|*.log
FileKey1=%AppData%\Adobe\Acrobat\Distiller 10|messages.log
FileKey1=%AppData%\Adobe\Acrobat\Distiller 10|messages.log
FileKey2=%AppData%\Adobe\Acrobat\Distiller 10\Cache|*.*|RECURSE
FileKey2=%AppData%\Adobe\Acrobat\Distiller 10\Cache|*.*|RECURSE
DetectFile=%ProgramFiles%\AdvancedSearchbar\advancedsearchbar.dll
DetectFile=%ProgramFiles%\AdvancedSearchbar\advancedsearchbar.dll
FileKey1=%ProgramFiles%\AdvancedSearchbar\Cache|*.*
FileKey1=%ProgramFiles%\AdvancedSearchbar\Cache|*.*
RegKey1=HKCU\Software\Advanced Searchbar\Toolbar\Historysearchbox1
RegKey1=HKCU\Software\Advanced Searchbar\Toolbar\Historysearchbox1
RegKey1=HKCU\Software\Yahoo\Companion\SearchHistory
RegKey1=HKCU\Software\Yahoo\Companion\SearchHistory
[Windows Live Toolbar]
[Windows Live Toolbar]
RegKey1=HKCU\Software\Microsoft\MSN Apps\SearchBox|History
RegKey1=HKCU\Software\Microsoft\MSN Apps\SearchBox|History
RegKey2=HKCU\Software\Microsoft\MSN Apps\MSN Toolbar|SearchStrings
RegKey2=HKCU\Software\Microsoft\MSN Apps\MSN Toolbar|SearchStrings
RegKey1=HKCU\Software\Google\NavClient\1.1\History
RegKey1=HKCU\Software\Google\NavClient\1.1\History
RegKey2=HKCU\Software\Google\NavClient\1.1\Options|KillPopupCount
RegKey2=HKCU\Software\Google\NavClient\1.1\Options|KillPopupCount
FileKey1=%appdata%\Google\Local Search History|*.*
FileKey1=%appdata%\Google\Local Search History|*.*
RegKey1=HKCU\Software\Google\Deskbar\termhistory
RegKey1=HKCU\Software\Google\Deskbar\termhistory
RegKey2=HKCU\Software\Google\Deskbar\urlhistory
RegKey2=HKCU\Software\Google\Deskbar\urlhistory
FileKey1=%localappdata%\Google\Google Calendar Sync\logs|*.log
FileKey1=%localappdata%\Google\Google Calendar Sync\logs|*.log
FileKey1=%localappdata%\Google\Google Talk\status|*.txt
FileKey1=%localappdata%\Google\Google Talk\status|*.txt
FileKey2=%localappdata%\Google\Google Talk\chatlogs|*.log
FileKey2=%localappdata%\Google\Google Talk\chatlogs|*.log
FileKey1=%AppData%\Christofer Persson\Kantaris Media Player|*.jpg
FileKey1=%AppData%\Christofer Persson\Kantaris Media Player|*.jpg
RegKey1=HKCU\Software\KMPlayer\KMP2.0|LastFileName
RegKey1=HKCU\Software\KMPlayer\KMP2.0|LastFileName
RegKey2=HKCU\Software\KMPlayer\WideAlbum\(Default Album)
RegKey2=HKCU\Software\KMPlayer\WideAlbum\(Default Album)
RegKey3=HKCU\Software\KMPlayer\albumart|LastAlbumName
RegKey3=HKCU\Software\KMPlayer\albumart|LastAlbumName
[Windows Media Player]
[Windows Media Player]
RegKey1=HKCU\Software\Microsoft\MediaPlayer\Player\RecentFileList
RegKey1=HKCU\Software\Microsoft\MediaPlayer\Player\RecentFileList
RegKey2=HKCU\Software\Microsoft\MediaPlayer\Player\RecentURLList
RegKey2=HKCU\Software\Microsoft\MediaPlayer\Player\RecentURLList
RegKey3=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayList
RegKey3=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayList
RegKey4=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayListIndex
RegKey4=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayListIndex
RegKey5=HKCU\Software\Microsoft\MediaPlayer\Player\Settings|SaveAsDir
RegKey5=HKCU\Software\Microsoft\MediaPlayer\Player\Settings|SaveAsDir
RegKey6=HKCU\Software\Microsoft\MediaPlayer\AutoComplete\MediaEdit
RegKey6=HKCU\Software\Microsoft\MediaPlayer\AutoComplete\MediaEdit
RegKey7=HKCU\Software\Microsoft\MediaPlayer\Radio\MRUList
RegKey7=HKCU\Software\Microsoft\MediaPlayer\Radio\MRUList
RegKey8=HKCU\Software\Microsoft\MediaPlayer\Services\MediaGuide|CachedIconPath
RegKey8=HKCU\Software\Microsoft\MediaPlayer\Services\MediaGuide|CachedIconPath
RegKey9=HKCU\Software\Microsoft\MediaPlayer\Services\MediaGuide|CachedLargeLogoPath
RegKey9=HKCU\Software\Microsoft\MediaPlayer\Services\MediaGuide|CachedLargeLogoPath
FileKey1=%LocalAppData%\Microsoft\Media Player|lastplayed.wpl
FileKey1=%LocalAppData%\Microsoft\Media Player|lastplayed.wpl
FileKey2=%LocalAppData%\Microsoft\Media Player|cacheentry*.*|RECURSE
FileKey2=%LocalAppData%\Microsoft\Media Player|cacheentry*.*|RECURSE
FileKey3=%LocalAppData%\Microsoft\Media Player\Art Cache\LocalMLS|*.*|RECURSE
FileKey3=%LocalAppData%\Microsoft\Media Player\Art Cache\LocalMLS|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Media Player\Transcoded Files Cache|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Media Player\Transcoded Files Cache|*.*|RECURSE
[Windows Media Center]
[Windows Media Center]
DetectFile=%windir%\ehome\ehshell.exe
DetectFile=%windir%\ehome\ehshell.exe
FileKey1=%CommonAppData%\Microsoft\eHome\logs|*.*
FileKey1=%CommonAppData%\Microsoft\eHome\logs|*.*
FileKey2=%LocalAppData%\Microsoft\eHome|playlistcache.db
FileKey2=%LocalAppData%\Microsoft\eHome|playlistcache.db
FileKey3=%PUBLIC%\Recorded TV\TempRec\TempSBE|*.*|RECURSE
FileKey3=%PUBLIC%\Recorded TV\TempRec\TempSBE|*.*|RECURSE
RegKey1=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips1
RegKey1=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips2
RegKey2=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips3
RegKey3=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips4
RegKey4=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips5
RegKey5=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips6
RegKey6=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips7
RegKey7=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips8
RegKey8=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins1
RegKey9=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins1
RegKey10=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins2
RegKey10=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins2
RegKey11=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins3
RegKey11=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins3
RegKey12=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins4
RegKey12=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins4
RegKey13=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins5
RegKey13=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins5
RegKey14=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins6
RegKey14=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins6
RegKey15=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins7
RegKey15=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins7
RegKey16=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins8
RegKey16=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins8
RegKey17=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\LastOpenFileDir
RegKey17=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\LastOpenFileDir
RegKey18=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips1
RegKey18=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips1
RegKey19=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips2
RegKey19=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips2
RegKey20=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips3
RegKey20=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips3
RegKey21=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips4
RegKey21=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips4
RegKey22=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips5
RegKey22=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips5
RegKey23=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips6
RegKey23=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips6
RegKey24=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips7
RegKey24=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips7
FileKey1=%AppData%\Real\RealOne Player|cookies.txt;ctd.dat;realplayer.ste
FileKey1=%AppData%\Real\RealOne Player|cookies.txt;ctd.dat;realplayer.ste
FileKey2=%AppData%\Real\RealOne Player\History|*.*
FileKey2=%AppData%\Real\RealOne Player\History|*.*
FileKey3=%AppData%\Real\RealPlayer|cookies.txt;ctd.dat;realplayer.ste
FileKey3=%AppData%\Real\RealPlayer|cookies.txt;ctd.dat;realplayer.ste
FileKey4=%AppData%\Real\RealPlayer\History|*.*
FileKey4=%AppData%\Real\RealPlayer\History|*.*
FileKey5=%AppData%\Real\RealPlayer\ErrorLogs|*.*
FileKey5=%AppData%\Real\RealPlayer\ErrorLogs|*.*
FileKey6=%AppData%\Real\RealPlayer\WatchFolders|*.log|RECURSE
FileKey6=%AppData%\Real\RealPlayer\WatchFolders|*.log|RECURSE
FileKey7=%ProgramFiles%\Common Files\Real\Update_OB|RealPlayer-log.txt
FileKey7=%ProgramFiles%\Common Files\Real\Update_OB|RealPlayer-log.txt
RegKey1=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips1
RegKey1=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips2
RegKey2=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips3
RegKey3=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips4
RegKey4=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips5
RegKey5=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips6
RegKey6=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips7
RegKey7=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips8
RegKey8=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins1
RegKey9=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins1
RegKey10=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins2
RegKey10=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins2
RegKey11=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins3
RegKey11=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins3
RegKey12=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins4
RegKey12=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins4
RegKey13=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins5
RegKey13=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins5
RegKey14=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins6
RegKey14=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins6
RegKey15=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins7
RegKey15=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins7
RegKey16=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins8
RegKey16=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins8
RegKey17=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\LastOpenFileDir
RegKey17=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\LastOpenFileDir
RegKey18=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips1
RegKey18=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips1
RegKey19=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips2
RegKey19=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips2
RegKey20=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips3
RegKey20=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips3
RegKey21=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips4
RegKey21=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips4
RegKey22=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips5
RegKey22=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips5
RegKey23=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips6
RegKey23=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips6
RegKey24=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips7
RegKey24=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips7
RegKey25=HKCU\Software\RealNetworks\RealConverter\12.0\Preferences\BrowsePath
RegKey25=HKCU\Software\RealNetworks\RealConverter\12.0\Preferences\BrowsePath
RegKey26=HKCU\Software\RealNetworks\RealConverter\12.0\Preferences\DestinationPath
RegKey26=HKCU\Software\RealNetworks\RealConverter\12.0\Preferences\DestinationPath
RegKey27=HKCU\Software\RealNetworks\RealTrimmer\12.0\Preferences\BrowsePath
RegKey27=HKCU\Software\RealNetworks\RealTrimmer\12.0\Preferences\BrowsePath
FileKey1=%AppData%\Real\RealPlayer|cookies.txt;ctd.dat;realplayer.ste;RealPlayer-log.txt
FileKey1=%AppData%\Real\RealPlayer|cookies.txt;ctd.dat;realplayer.ste;RealPlayer-log.txt
FileKey2=%AppData%\Real\RealPlayer\History|*.*
FileKey2=%AppData%\Real\RealPlayer\History|*.*
FileKey3=%AppData%\Real\RealPlayer\ErrorLogs|*.*
FileKey3=%AppData%\Real\RealPlayer\ErrorLogs|*.*
FileKey4=%AppData%\Real\RealPlayer\WatchFolders|*.log|RECURSE
FileKey4=%AppData%\Real\RealPlayer\WatchFolders|*.log|RECURSE
RegKey1=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips1
RegKey1=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips2
RegKey2=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips3
RegKey3=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips4
RegKey4=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips5
RegKey5=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips6
RegKey6=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips7
RegKey7=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips8
RegKey8=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\LastOpenFileDir
RegKey9=HKCU\Software\RealNetworks\RealPlayer\15.0\Preferences\LastOpenFileDir
RegKey10=HKCU\Software\RealNetworks\RealConverter\15.0\Preferences\BrowsePath
RegKey10=HKCU\Software\RealNetworks\RealConverter\15.0\Preferences\BrowsePath
RegKey11=HKCU\Software\RealNetworks\RealConverter\15.0\Preferences\DestinationPath
RegKey11=HKCU\Software\RealNetworks\RealConverter\15.0\Preferences\DestinationPath
RegKey12=HKCU\Software\RealNetworks\RealTrimmer\15.0\Preferences\BrowsePath
RegKey12=HKCU\Software\RealNetworks\RealTrimmer\15.0\Preferences\BrowsePath
FileKey1=%AppData%\Real\RealPlayer|realplayer.ste;RealPlayer-log.txt
FileKey1=%AppData%\Real\RealPlayer|realplayer.ste;RealPlayer-log.txt
FileKey4=%AppData%\Real\RealPlayer\WatchFolders|*.log
FileKey4=%AppData%\Real\RealPlayer\WatchFolders|*.log
RegKey1=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips1
RegKey1=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips2
RegKey2=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips3
RegKey3=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips4
RegKey4=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips5
RegKey5=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips6
RegKey6=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips7
RegKey7=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips8
RegKey8=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\LastOpenFileDir
RegKey9=HKCU\Software\RealNetworks\RealPlayer\16.0\Preferences\LastOpenFileDir
RegKey10=HKCU\Software\RealNetworks\RealConverter\16.0\Preferences\BrowsePath
RegKey10=HKCU\Software\RealNetworks\RealConverter\16.0\Preferences\BrowsePath
RegKey11=HKCU\Software\RealNetworks\RealConverter\16.0\Preferences\DestinationPath
RegKey11=HKCU\Software\RealNetworks\RealConverter\16.0\Preferences\DestinationPath
RegKey12=HKCU\Software\RealNetworks\RealTrimmer\16.0\Preferences\BrowsePath
RegKey12=HKCU\Software\RealNetworks\RealTrimmer\16.0\Preferences\BrowsePath
RegKey1=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips1
RegKey1=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips2
RegKey2=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips3
RegKey3=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips4
RegKey4=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips5
RegKey5=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips6
RegKey6=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips7
RegKey7=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips8
RegKey8=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\LastOpenFileDir
RegKey9=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\LastOpenFileDir
RegKey10=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips1
RegKey10=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips1
RegKey11=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips2
RegKey11=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips2
RegKey12=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips3
RegKey12=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips3
RegKey13=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips4
RegKey13=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips4
RegKey14=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips5
RegKey14=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips5
RegKey15=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips6
RegKey15=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips6
RegKey16=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips7
RegKey16=HKCU\Software\RealNetworks\RealPlayer\17.0\Preferences\OpenLocationClips7
FileKey1=%AppData%\Real\RealPlayer\Temp|*.*
FileKey1=%AppData%\Real\RealPlayer\Temp|*.*
FileKey2=%ProgramFiles%\Real\RealPlayer\RPDS|install.log
FileKey2=%ProgramFiles%\Real\RealPlayer\RPDS|install.log
FileKey3=%CommonAppData%\Real\RealPlayer|*-log.txt;S-*
FileKey3=%CommonAppData%\Real\RealPlayer|*-log.txt;S-*
FileKey4=%CommonAppData%\RPDS\Content\images|*.jpg
FileKey4=%CommonAppData%\RPDS\Content\images|*.jpg
FileKey5=%CommonAppData%\Real\RPDS\Logs|*.log;error.log*
FileKey5=%CommonAppData%\Real\RPDS\Logs|*.log;error.log*
FileKey6=%AppData%\Real\RealPlayer|RealPlayer-log.txt
FileKey6=%AppData%\Real\RealPlayer|RealPlayer-log.txt
FileKey7=%AppData%\Real\RealPlayer\ErrorLogs|*.log
FileKey7=%AppData%\Real\RealPlayer\ErrorLogs|*.log
FileKey8=%AppData%\Real\RealPlayer\History|*.*
FileKey8=%AppData%\Real\RealPlayer\History|*.*
FileKey9=%AppData%\Real\RealPlayer\ThumbsCache|*.*|RECURSE
FileKey9=%AppData%\Real\RealPlayer\ThumbsCache|*.*|RECURSE
FileKey10=%AppData%\Real\RealPlayer\WatchFolders|*_scan*
FileKey10=%AppData%\Real\RealPlayer\WatchFolders|*_scan*
FileKey11=%ProgramFiles%\Real\RealPlayer\common|cookies.txt
FileKey11=%ProgramFiles%\Real\RealPlayer\common|cookies.txt
ExcludeKey1=FILE|%AppData%\Real\RealPlayer\WatchFolders\*scan.out
ExcludeKey1=FILE|%AppData%\Real\RealPlayer\WatchFolders\*scan.out
RegKey1=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips1
RegKey1=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips2
RegKey2=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips3
RegKey3=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips4
RegKey4=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips5
RegKey5=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips6
RegKey6=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips7
RegKey7=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips8
RegKey8=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\LastOpenFileDir
RegKey9=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\LastOpenFileDir
RegKey10=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips1
RegKey10=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips1
RegKey11=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips2
RegKey11=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips2
RegKey12=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips3
RegKey12=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips3
RegKey13=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips4
RegKey13=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips4
RegKey14=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips5
RegKey14=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips5
RegKey15=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips6
RegKey15=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips6
RegKey16=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips7
RegKey16=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips7
RegKey17=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips8
RegKey17=HKCU\Software\RealNetworks\RealPlayer\18.0\Preferences\OpenLocationClips8
FileKey4=%CommonAppData%\Real\RPDS\Content\images|*.jpg
FileKey4=%CommonAppData%\Real\RPDS\Content\images|*.jpg
RegKey1=HKLM\Software\Apple Computer, Inc.\QuickTime\Recent Movies
RegKey1=HKLM\Software\Apple Computer, Inc.\QuickTime\Recent Movies
FileKey1=%LocalLowAppData%\Apple Computer\QuickTime\downloads|*.*|RECURSE
FileKey1=%LocalLowAppData%\Apple Computer\QuickTime\downloads|*.*|RECURSE
FileKey2=%localappdata%\Apple Computer\QuickTime\downloads|*.*|RECURSE
FileKey2=%localappdata%\Apple Computer\QuickTime\downloads|*.*|RECURSE
FileKey3=%localappdata%\Apple Computer\QuickTime|QTPlayerSession.xml
FileKey3=%localappdata%\Apple Computer\QuickTime|QTPlayerSession.xml
FileKey4=%appdata%\Apple Computer\QuickTime|QTPlayerSession.xml
FileKey4=%appdata%\Apple Computer\QuickTime|QTPlayerSession.xml
FileKey5=%CommonAppData%\Apple Computer\Installer Cache\QuickTime*|QuickTime.msi.backup
FileKey5=%CommonAppData%\Apple Computer\Installer Cache\QuickTime*|QuickTime.msi.backup
FileKey6=%userprofile%|QTPlayerSession.xml
FileKey6=%userprofile%|QTPlayerSession.xml
Detect=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit VVV.avipreview.com for more
Detect=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit VVV.avipreview.com for more
RegKey1=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit VVV.avipreview.com for more\Recent File List
RegKey1=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit VVV.avipreview.com for more\Recent File List
DetectFile=%ProgramFiles%\Steam\Steam.exe
DetectFile=%ProgramFiles%\Steam\Steam.exe
FileKey1=%ProgramFiles%\Steam|*.mdmp;*.log
FileKey1=%ProgramFiles%\Steam|*.mdmp;*.log
FileKey2=%ProgramFiles%\Steam\Dumps|*.*|RECURSE
FileKey2=%ProgramFiles%\Steam\Dumps|*.*|RECURSE
FileKey3=%ProgramFiles%\Steam\Logs|*.*|RECURSE
FileKey3=%ProgramFiles%\Steam\Logs|*.*|RECURSE
DetectFile=%ProgramFiles%\Xfire\Xfire.exe
DetectFile=%ProgramFiles%\Xfire\Xfire.exe
FileKey1=%CommonAppData%\Xfire|*-*-*-*-*-*-*.log;xfire_exe_log.txt;xfire_toucan_log.txt
FileKey1=%CommonAppData%\Xfire|*-*-*-*-*-*-*.log;xfire_exe_log.txt;xfire_toucan_log.txt
FileKey2=%ProgramFiles%\Xfire|*-*-*-*-*-*-*.log;xfire_exe_log.txt;xfire_toucan_log.txt
FileKey2=%ProgramFiles%\Xfire|*-*-*-*-*-*-*.log;xfire_exe_log.txt;xfire_toucan_log.txt
RegKey1=HKCU\Software\Altova\XML Spy\Recent File List
RegKey1=HKCU\Software\Altova\XML Spy\Recent File List
RegKey2=HKCU\Software\Altova\XML Spy\Recent Project List
RegKey2=HKCU\Software\Altova\XML Spy\Recent Project List
DetectFile=%AppData%\com.oxygenxml\
DetectFile=%AppData%\com.oxygenxml\
FileKey1=%AppData%\com.oxygenxml\usageData|usageData.xml
FileKey1=%AppData%\com.oxygenxml\usageData|usageData.xml
FileKey2=%AppData%\com.oxygenxml|file.history
FileKey2=%AppData%\com.oxygenxml|file.history
FileKey3=%AppData%\com.oxygenxml|project.history
FileKey3=%AppData%\com.oxygenxml|project.history
RegKey1=HKCU\Software\DJJ Holdings\SWiSH\Recent File List
RegKey1=HKCU\Software\DJJ Holdings\SWiSH\Recent File List
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 7\Recent File List
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 7\Recent File List
RegKey2=HKCU\Software\Jasc\Animation Shop 3\Recent File List
RegKey2=HKCU\Software\Jasc\Animation Shop 3\Recent File List
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 7\General|FolderHistory
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 7\General|FolderHistory
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveAsDirectory
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveAsDirectory
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveCopyDirectory
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveCopyDirectory
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 8\Recent File List
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 8\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 8\WorkspaceMRU
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 8\WorkspaceMRU
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdPyScript\RunScript|FileName
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdPyScript\RunScript|FileName
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdFile\FileSaveAs|FileFolder
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdNonGraphic\SaveWorkspace|WorkspaceFilename
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdNonGraphic\SaveWorkspace|WorkspaceFilename
RegKey6=HKCU\Software\Jasc\Paint Shop Pro 8\ScriptMRU
RegKey6=HKCU\Software\Jasc\Paint Shop Pro 8\ScriptMRU
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 9\Recent File List
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 9\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 9\WorkspaceMRU
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 9\WorkspaceMRU
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileSaveAs|FileFolder
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileOpen|Folder
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileOpen|Folder
RegKey1=HKCU\Software\Corel\Paint Shop Pro\10\Recent File List
RegKey1=HKCU\Software\Corel\Paint Shop Pro\10\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\10\WorkspaceMRU
RegKey2=HKCU\Software\Corel\Paint Shop Pro\10\WorkspaceMRU
RegKey3=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileSaveAs|FileFolder
RegKey3=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileOpen|Folder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileOpen|Folder
RegKey1=HKCU\Software\Corel\Paint Shop Pro\11\Recent File List
RegKey1=HKCU\Software\Corel\Paint Shop Pro\11\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\11\WorkspaceMRU
RegKey2=HKCU\Software\Corel\Paint Shop Pro\11\WorkspaceMRU
RegKey3=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileSaveAs|FileFolder
RegKey3=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileOpen|Folder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileOpen|Folder
RegKey1=HKCU\Software\Corel\Paint Shop Pro\12\Recent File List
RegKey1=HKCU\Software\Corel\Paint Shop Pro\12\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\12\WorkspaceMRU
RegKey2=HKCU\Software\Corel\Paint Shop Pro\12\WorkspaceMRU
RegKey3=HKCU\Software\Corel\Paint Shop Pro\12\CmdFile\FileSaveAs|FileFolder
RegKey3=HKCU\Software\Corel\Paint Shop Pro\12\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\12\CmdFile\FileOpen|Folder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\12\CmdFile\FileOpen|Folder
RegKey5=HKCU\Software\Corel\Paint Shop Pro\12.5\Recent File List
RegKey5=HKCU\Software\Corel\Paint Shop Pro\12.5\Recent File List
RegKey6=HKCU\Software\Corel\Paint Shop Pro\12.5\WorkspaceMRU
RegKey6=HKCU\Software\Corel\Paint Shop Pro\12.5\WorkspaceMRU
RegKey7=HKCU\Software\Corel\Paint Shop Pro\12.5\CmdFile\FileSaveAs|FileFolder
RegKey7=HKCU\Software\Corel\Paint Shop Pro\12.5\CmdFile\FileSaveAs|FileFolder
RegKey8=HKCU\Software\Corel\Paint Shop Pro\12.5\CmdFile\FileOpen|Folder
RegKey8=HKCU\Software\Corel\Paint Shop Pro\12.5\CmdFile\FileOpen|Folder
RegKey1=HKCU\Software\Corel\Paint Shop Pro\13\Recent File List
RegKey1=HKCU\Software\Corel\Paint Shop Pro\13\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\13\WorkspaceMRU
RegKey2=HKCU\Software\Corel\Paint Shop Pro\13\WorkspaceMRU
RegKey3=HKCU\Software\Corel\Paint Shop Pro\13\CmdFile\FileSaveAs|FileFolder
RegKey3=HKCU\Software\Corel\Paint Shop Pro\13\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\13\CmdFile\FileOpen|Folder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\13\CmdFile\FileOpen|Folder
RegKey1=HKCU\Software\Corel\PaintShop Pro\X4\Recent File List
RegKey1=HKCU\Software\Corel\PaintShop Pro\X4\Recent File List
RegKey2=HKCU\Software\Corel\PaintShop Pro\X4\UI Customization\EN\WorkspaceMRU
RegKey2=HKCU\Software\Corel\PaintShop Pro\X4\UI Customization\EN\WorkspaceMRU
RegKey3=HKCU\Software\Corel\PaintShop Pro\X4\CmdFile\FileSaveAs|FileFolder
RegKey3=HKCU\Software\Corel\PaintShop Pro\X4\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\PaintShop Pro\X4\CmdFile\FileOpen|Folder
RegKey4=HKCU\Software\Corel\PaintShop Pro\X4\CmdFile\FileOpen|Folder
RegKey5=HKCU\Software\Corel\PaintShop Pro\X4\ScriptMRU
RegKey5=HKCU\Software\Corel\PaintShop Pro\X4\ScriptMRU
RegKey1=HKCU\Software\Corel\PaintShop Pro\X5\Recent File List
RegKey1=HKCU\Software\Corel\PaintShop Pro\X5\Recent File List
RegKey2=HKCU\Software\Corel\PaintShop Pro\X5\UI Customization\EN\WorkspaceMRU
RegKey2=HKCU\Software\Corel\PaintShop Pro\X5\UI Customization\EN\WorkspaceMRU
RegKey3=HKCU\Software\Corel\PaintShop Pro\X5\CmdFile\FileSaveAs|FileFolder
RegKey3=HKCU\Software\Corel\PaintShop Pro\X5\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\PaintShop Pro\X5\CmdFile\FileOpen|Folder
RegKey4=HKCU\Software\Corel\PaintShop Pro\X5\CmdFile\FileOpen|Folder
RegKey5=HKCU\Software\Corel\PaintShop Pro\X5\ScriptMRU
RegKey5=HKCU\Software\Corel\PaintShop Pro\X5\ScriptMRU
RegKey1=HKCU\Software\Corel\PaintShop Pro\X6\Recent File List
RegKey1=HKCU\Software\Corel\PaintShop Pro\X6\Recent File List
RegKey2=HKCU\Software\Corel\PaintShop Pro\X6\CmdFile\FileSaveAs|FileFolder
RegKey2=HKCU\Software\Corel\PaintShop Pro\X6\CmdFile\FileSaveAs|FileFolder
RegKey3=HKCU\Software\Corel\PaintShop Pro\X6\CmdFile\FileOpen|Folder
RegKey3=HKCU\Software\Corel\PaintShop Pro\X6\CmdFile\FileOpen|Folder
RegKey4=HKCU\Software\Corel\PaintShop Pro\X6\ScriptMRU
RegKey4=HKCU\Software\Corel\PaintShop Pro\X6\ScriptMRU
FileKey1=%ProgramFiles%\Corel\Corel PaintShop Pro X6\PlugIns\*|*.log
FileKey1=%ProgramFiles%\Corel\Corel PaintShop Pro X6\PlugIns\*|*.log
FileKey2=%LocalAppData%\Corel PaintShop Pro\16.0\Thumbs|*.*|RECURSE
FileKey2=%LocalAppData%\Corel PaintShop Pro\16.0\Thumbs|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Works\4.0\Recent File List
RegKey1=HKCU\Software\Microsoft\Works\4.0\Recent File List
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\8.0\Excel\Recent File List
RegKey1=HKCU\Software\Microsoft\Office\8.0\Excel\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\8.0\Project\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\8.0\Project\Recent File List
RegKey3=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent File List
RegKey3=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent File List
RegKey4=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent Folder List
RegKey4=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent Folder List
RegKey5=HKCU\Software\Microsoft\Office\8.0\Common\Internet\LocationOfComponents
RegKey5=HKCU\Software\Microsoft\Office\8.0\Common\Internet\LocationOfComponents
RegKey6=HKCU\Software\Microsoft\Office\8.0\Access\Settings
RegKey6=HKCU\Software\Microsoft\Office\8.0\Access\Settings
RegKey1=HKCU\Software\Microsoft\Office\10.0\PowerPoint\Recent File List
RegKey1=HKCU\Software\Microsoft\Office\10.0\PowerPoint\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\10.0\Excel\Recent Files
RegKey2=HKCU\Software\Microsoft\Office\10.0\Excel\Recent Files
RegKey3=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent File List
RegKey3=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent File List
RegKey4=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List
RegKey4=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List
RegKey5=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List
RegKey5=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List
RegKey6=HKCU\Software\Microsoft\Office\10.0\Word\Recent Templates
RegKey6=HKCU\Software\Microsoft\Office\10.0\Word\Recent Templates
RegKey7=HKCU\Software\Microsoft\Office\10.0\Common\Internet|UseRWHlinkNavigation
RegKey7=HKCU\Software\Microsoft\Office\10.0\Common\Internet|UseRWHlinkNavigation
FileKey1=%AppData%\Microsoft\Office\Recent|*.*
FileKey1=%AppData%\Microsoft\Office\Recent|*.*
FileKey2=%AppData%\Microsoft\Office|*.tmp|RECURSE
FileKey2=%AppData%\Microsoft\Office|*.tmp|RECURSE
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel\Recent Files
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel\Recent Files
RegKey2=HKCU\Software\Microsoft\Office\11.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey2=HKCU\Software\Microsoft\Office\11.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey3=HKCU\Software\Microsoft\Office\11.0\PowerPoint\Recent File List
RegKey3=HKCU\Software\Microsoft\Office\11.0\PowerPoint\Recent File List
RegKey4=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List
RegKey4=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List
RegKey5=HKCU\Software\Microsoft\Office\11.0\InfoPath\Recent File List
RegKey5=HKCU\Software\Microsoft\Office\11.0\InfoPath\Recent File List
RegKey6=HKCU\Software\Microsoft\Office\11.0\Common\Internet\Server Cache
RegKey6=HKCU\Software\Microsoft\Office\11.0\Common\Internet\Server Cache
RegKey7=HKCU\Software\Microsoft\Office\11.0\Common\Internet|UseRWHlinkNavigation
RegKey7=HKCU\Software\Microsoft\Office\11.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\MSPaper 11.0\Persist File Name
RegKey8=HKCU\Software\Microsoft\MSPaper 11.0\Persist File Name
RegKey9=HKCU\Software\Microsoft\MSPaper 11.0\Recent File List
RegKey9=HKCU\Software\Microsoft\MSPaper 11.0\Recent File List
RegKey10=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile1
RegKey10=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile1
RegKey11=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile2
RegKey11=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile2
RegKey12=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile3
RegKey12=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile3
RegKey13=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile4
RegKey13=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile4
RegKey14=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile5
RegKey14=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile5
RegKey15=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile6
RegKey15=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile6
RegKey16=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile7
RegKey16=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile7
RegKey17=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile8
RegKey17=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile8
RegKey18=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey18=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey19=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey19=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey20=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
RegKey20=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
RegKey21=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files
RegKey21=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files
RegKey22=HKCU\Software\Microsoft\Office\Common|FontBmpCache
RegKey22=HKCU\Software\Microsoft\Office\Common|FontBmpCache
RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey2=HKCU\Software\Microsoft\Office\12.0\Word\File MRU
RegKey2=HKCU\Software\Microsoft\Office\12.0\Word\File MRU
RegKey3=HKCU\Software\Microsoft\Office\12.0\Excel\File MRU
RegKey3=HKCU\Software\Microsoft\Office\12.0\Excel\File MRU
RegKey4=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU1
RegKey4=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU1
RegKey5=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU2
RegKey5=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU2
RegKey6=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU3
RegKey6=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU3
RegKey7=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU4
RegKey7=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU4
RegKey8=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU5
RegKey8=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU5
RegKey9=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU6
RegKey9=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU6
RegKey10=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU7
RegKey10=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU7
RegKey11=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU8
RegKey11=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU8
RegKey12=HKCU\Software\Microsoft\Office\12.0\PowerPoint\File MRU
RegKey12=HKCU\Software\Microsoft\Office\12.0\PowerPoint\File MRU
RegKey13=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Save As\File Name MRU
RegKey13=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Save As\File Name MRU
RegKey14=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open\File Name MRU
RegKey14=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open\File Name MRU
RegKey15=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Save As\File Name MRU
RegKey15=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Save As\File Name MRU
RegKey16=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Excel\Settings\Save As\File Name MRU
RegKey16=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Excel\Settings\Save As\File Name MRU
RegKey17=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Publisher\Settings\Save As\File Name MRU
RegKey17=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Publisher\Settings\Save As\File Name MRU
RegKey18=HKCU\Software\Microsoft\Office\12.0\Publisher\Recent File List
RegKey18=HKCU\Software\Microsoft\Office\12.0\Publisher\Recent File List
RegKey19=HKCU\Software\Microsoft\Office\12.0\InfoPath\Recent File List
RegKey19=HKCU\Software\Microsoft\Office\12.0\InfoPath\Recent File List
RegKey20=HKCU\Software\Microsoft\Office\12.0\Excel Viewer\Viewer File MRU
RegKey20=HKCU\Software\Microsoft\Office\12.0\Excel Viewer\Viewer File MRU
RegKey21=HKCU\Software\Microsoft\Office\12.0\Clip Organizer\Search\Last Query
RegKey21=HKCU\Software\Microsoft\Office\12.0\Clip Organizer\Search\Last Query
FileKey3=%LocalAppData%\Microsoft\Office\14.0\OfficeFileCache|*.*|RECURSE
FileKey3=%LocalAppData%\Microsoft\Office\14.0\OfficeFileCache|*.*|RECURSE
RegKey1=HKCU\Software\Microsoft\Office\14.0\Access\File MRU
RegKey1=HKCU\Software\Microsoft\Office\14.0\Access\File MRU
RegKey2=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Default Database Path\File Name MRU
RegKey2=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Default Database Path\File Name MRU
RegKey3=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Default Theme for New Databases\File Name MRU
RegKey3=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Default Theme for New Databases\File Name MRU
RegKey4=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\File New Database\File Name MRU
RegKey4=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\File New Database\File Name MRU
RegKey5=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\File Open\File Name MRU
RegKey5=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\File Open\File Name MRU
RegKey6=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\File Save\File Name MRU
RegKey6=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\File Save\File Name MRU
RegKey7=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Open\File Name MRU
RegKey7=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Open\File Name MRU
RegKey8=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Save As\File Name MRU
RegKey8=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Save As\File Name MRU
RegKey9=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Default Database Path\File Name MRU
RegKey9=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Default Database Path\File Name MRU
RegKey10=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Default Theme for New Databases\File Name MRU
RegKey10=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Default Theme for New Databases\File Name MRU
RegKey11=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\File New Database\File Name MRU
RegKey11=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\File New Database\File Name MRU
RegKey12=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\File Open\File Name MRU
RegKey12=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\File Open\File Name MRU
RegKey13=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\File Save\File Name MRU
RegKey13=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\File Save\File Name MRU
RegKey14=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Open\File Name MRU
RegKey14=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Open\File Name MRU
RegKey15=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Save As\File Name MRU
RegKey15=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Save As\File Name MRU
RegKey16=HKCU\Software\Microsoft\Office\14.0\Word\File MRU
RegKey16=HKCU\Software\Microsoft\Office\14.0\Word\File MRU
RegKey17=HKCU\Software\Microsoft\Office\14.0\Word\Place MRU
RegKey17=HKCU\Software\Microsoft\Office\14.0\Word\Place MRU
RegKey18=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\Browse\File Name MRU
RegKey18=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\Browse\File Name MRU
RegKey19=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\File Open\File Name MRU
RegKey19=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\File Open\File Name MRU
RegKey20=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\File Save\File Name MRU
RegKey20=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\File Save\File Name MRU
RegKey21=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\Modify Location\File Name MRU
RegKey21=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\Modify Location\File Name MRU
RegKey22=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\Save As\File Name MRU
RegKey22=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\Save As\File Name MRU
RegKey23=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\Browse\File Name MRU
RegKey23=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\Browse\File Name MRU
RegKey24=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\File Open\File Name MRU
RegKey24=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\File Open\File Name MRU
RegKey25=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\File Save\File Name MRU
RegKey25=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\File Save\File Name MRU
RegKey26=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\Modify Location\File Name MRU
RegKey26=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\Modify Location\File Name MRU
RegKey27=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey27=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey28=HKCU\Software\Microsoft\Office\14.0\Excel\File MRU
RegKey28=HKCU\Software\Microsoft\Office\14.0\Excel\File MRU
RegKey29=HKCU\Software\Microsoft\Office\14.0\Excel\Place MRU
RegKey29=HKCU\Software\Microsoft\Office\14.0\Excel\Place MRU
RegKey30=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\Browse\File Name MRU
RegKey30=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\Browse\File Name MRU
RegKey31=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\File Open\File Name MRU
RegKey31=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\File Open\File Name MRU
RegKey32=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\File Save\File Name MRU
RegKey32=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\File Save\File Name MRU
RegKey33=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\Modify Location\File Name MRU
RegKey33=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\Modify Location\File Name MRU
RegKey34=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\Save As\File Name MRU
RegKey34=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\Save As\File Name MRU
RegKey35=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\Browse\File Name MRU
RegKey35=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\Browse\File Name MRU
RegKey36=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\File Open\File Name MRU
RegKey36=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\File Open\File Name MRU
RegKey37=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\File Save\File Name MRU
RegKey37=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\File Save\File Name MRU
RegKey38=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\Modify Location\File Name MRU
RegKey38=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\Modify Location\File Name MRU
RegKey39=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\Save As\File Name MRU
RegKey39=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\Save As\File Name MRU
RegKey40=HKCU\Software\Microsoft\Office\14.0\Publisher\File MRU
RegKey40=HKCU\Software\Microsoft\Office\14.0\Publisher\File MRU
RegKey41=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\File Open\File Name MRU
RegKey41=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\File Open\File Name MRU
RegKey42=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\File Save\File Name MRU
RegKey42=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\File Save\File Name MRU
RegKey43=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\Open Publication\File Name MRU
RegKey43=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\Open Publication\File Name MRU
RegKey44=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\Save As\File Name MRU
RegKey44=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\Save As\File Name MRU
RegKey45=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\File Open\File Name MRU
RegKey45=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\File Open\File Name MRU
RegKey46=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\File Save\File Name MRU
RegKey46=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\File Save\File Name MRU
RegKey47=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\Open Publication\File Name MRU
RegKey47=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\Open Publication\File Name MRU
RegKey48=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\Save As\File Name MRU
RegKey48=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\Save As\File Name MRU
RegKey49=HKCU\Software\Microsoft\Office\14.0\PowerPoint\File MRU
RegKey49=HKCU\Software\Microsoft\Office\14.0\PowerPoint\File MRU
RegKey50=HKCU\Software\Microsoft\Office\14.0\PowerPoint\Place MRU
RegKey50=HKCU\Software\Microsoft\Office\14.0\PowerPoint\Place MRU
RegKey51=HKCU\Software\Microsoft\Office\14.0\PowerPoint\RecentFolderList
RegKey51=HKCU\Software\Microsoft\Office\14.0\PowerPoint\RecentFolderList
RegKey52=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\Browse\File Name MRU
RegKey52=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\Browse\File Name MRU
RegKey53=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\File Open\File Name MRU
RegKey53=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\File Open\File Name MRU
RegKey54=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\File Save\File Name MRU
RegKey54=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\File Save\File Name MRU
RegKey55=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\Open\File Name MRU
RegKey55=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\Open\File Name MRU
RegKey56=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\Save As\File Name MRU
RegKey56=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\Save As\File Name MRU
RegKey57=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Browse\File Name MRU
RegKey57=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Browse\File Name MRU
RegKey58=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\File Open\File Name MRU
RegKey58=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\File Open\File Name MRU
RegKey59=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\File Save\File Name MRU
RegKey59=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\File Save\File Name MRU
RegKey60=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Open\File Name MRU
RegKey60=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Open\File Name MRU
RegKey61=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Save As\File Name MRU
RegKey61=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Save As\File Name MRU
RegKey62=HKCU\Software\Microsoft\Office\14.0\InfoPath\Designer File MRU
RegKey62=HKCU\Software\Microsoft\Office\14.0\InfoPath\Designer File MRU
RegKey63=HKCU\Software\Microsoft\Office\14.0\InfoPath\Filler File MRU
RegKey63=HKCU\Software\Microsoft\Office\14.0\InfoPath\Filler File MRU
RegKey64=HKCU\Software\Microsoft\Office\14.0\InfoPath\Recent Templates
RegKey64=HKCU\Software\Microsoft\Office\14.0\InfoPath\Recent Templates
RegKey65=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Browse\File Name MRU
RegKey65=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Browse\File Name MRU
RegKey66=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\File Open\File Name MRU
RegKey66=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\File Open\File Name MRU
RegKey67=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\File Save\File Name MRU
RegKey67=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\File Save\File Name MRU
RegKey68=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Open\File Name MRU
RegKey68=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Open\File Name MRU
RegKey69=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Open in Design Mode\File Name MRU
RegKey69=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Open in Design Mode\File Name MRU
RegKey70=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Save As\File Name MRU
RegKey70=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Save As\File Name MRU
RegKey71=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Browse\File Name MRU
RegKey71=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Browse\File Name MRU
RegKey72=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\File Open\File Name MRU
RegKey72=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\File Open\File Name MRU
RegKey73=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\File Save\File Name MRU
RegKey73=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\File Save\File Name MRU
RegKey74=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open\File Name MRU
RegKey74=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open\File Name MRU
RegKey75=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open in Design Mode\File Name MRU
RegKey75=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open in Design Mode\File Name MRU
RegKey76=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Save As\File Name MRU
RegKey76=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Save As\File Name MRU
RegKey77=HKCU\Software\Microsoft\Office\14.0\OneNote\OpenNotebooks
RegKey77=HKCU\Software\Microsoft\Office\14.0\OneNote\OpenNotebooks
RegKey78=HKCU\Software\Microsoft\Office\14.0\OneNote\RecentNotebooks
RegKey78=HKCU\Software\Microsoft\Office\14.0\OneNote\RecentNotebooks
RegKey79=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\File Open\File Name MRU
RegKey79=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\File Open\File Name MRU
RegKey80=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\File Save\File Name MRU
RegKey80=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\File Save\File Name MRU
RegKey81=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Open Backup\File Name MRU
RegKey81=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Open Backup\File Name MRU
RegKey82=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Open Notebook\File Name MRU
RegKey82=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Open Notebook\File Name MRU
RegKey83=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Save As\File Name MRU
RegKey83=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Save As\File Name MRU
RegKey84=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Select File\File Name MRU
RegKey84=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Select File\File Name MRU
RegKey85=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Select Folder\File Name MRU
RegKey85=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Select Folder\File Name MRU
RegKey86=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\File Open\File Name MRU
RegKey86=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\File Open\File Name MRU
RegKey87=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\File Save\File Name MRU
RegKey87=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\File Save\File Name MRU
RegKey88=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Open Backup\File Name MRU
RegKey88=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Open Backup\File Name MRU
RegKey89=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Open Notebook\File Name MRU
RegKey89=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Open Notebook\File Name MRU
RegKey90=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Save As\File Name MRU
RegKey90=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Save As\File Name MRU
RegKey91=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Select File\File Name MRU
RegKey91=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Select File\File Name MRU
RegKey92=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Select Folder\File Name MRU
RegKey92=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Select Folder\File Name MRU
RegKey93=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\Create or Open Outlook Data File\File Name MRU
RegKey93=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\Create or Open Outlook Data File\File Name MRU
RegKey94=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\File Open\File Name MRU
RegKey94=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\File Open\File Name MRU
RegKey95=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\File Save\File Name MRU
RegKey95=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\File Save\File Name MRU
RegKey96=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\Open Calendar\File Name MRU
RegKey96=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\Open Calendar\File Name MRU
RegKey97=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\Open Outlook Data File\File Name MRU
RegKey97=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\Open Outlook Data File\File Name MRU
RegKey98=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\Create or Open Outlook Data File\File Name MRU
RegKey98=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\Create or Open Outlook Data File\File Name MRU
RegKey99=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\File Open\File Name MRU
RegKey99=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\File Open\File Name MRU
RegKey100=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\File Save\File Name MRU
RegKey100=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\File Save\File Name MRU
RegKey101=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\Open Calendar\File Name MRU
RegKey101=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\Open Calendar\File Name MRU
RegKey102=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\Open Outlook Data File\File Name MRU
RegKey102=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\Open Outlook Data File\File Name MRU
RegKey103=HKCU\Software\Microsoft\Office\14.0\Clip Organizer\Search\Last Query
RegKey103=HKCU\Software\Microsoft\Office\14.0\Clip Organizer\Search\Last Query
RegKey104=HKCU\Software\Microsoft\Office\Common|FontBmpCache
RegKey104=HKCU\Software\Microsoft\Office\Common|FontBmpCache
RegKey105=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Friendly1
RegKey105=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Friendly1
RegKey106=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Friendly2
RegKey106=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Friendly2
RegKey107=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Friendly3
RegKey107=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Friendly3
RegKey108=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Friendly4
RegKey108=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Friendly4
RegKey109=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Template1
RegKey109=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Template1
RegKey110=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Template2
RegKey110=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Template2
RegKey111=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Template3
RegKey111=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Template3
RegKey112=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Template4
RegKey112=HKCU\Software\Microsoft\Office\14.0\Visio\Recent Templates|Template4
RegKey113=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile1
RegKey113=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile1
RegKey114=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile2
RegKey114=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile2
RegKey115=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile3
RegKey115=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile3
RegKey116=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile4
RegKey116=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile4
RegKey117=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile5
RegKey117=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile5
RegKey118=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile6
RegKey118=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile6
RegKey119=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile7
RegKey119=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile7
RegKey120=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile8
RegKey120=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile8
RegKey121=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile9
RegKey121=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile9
RegKey122=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile10
RegKey122=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile10
RegKey123=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile11
RegKey123=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile11
RegKey124=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile12
RegKey124=HKCU\Software\Microsoft\Office\14.0\Visio\Application|LastFile12
RegKey125=HKCU\Software\Microsoft\Office\14.0\Outlook\Search
RegKey125=HKCU\Software\Microsoft\Office\14.0\Outlook\Search
FileKey2=%LocalAppData%\Microsoft\MSOIdentityCRL\production\temp|*.*_sync
FileKey2=%LocalAppData%\Microsoft\MSOIdentityCRL\production\temp|*.*_sync
FileKey3=%AppData%\Microsoft\PowerPoint\Sync\Temp|*.*
FileKey3=%AppData%\Microsoft\PowerPoint\Sync\Temp|*.*
RegKey1=HKCU\Software\Microsoft\Office\15.0\Access\File MRU
RegKey1=HKCU\Software\Microsoft\Office\15.0\Access\File MRU
RegKey2=HKCU\Software\Microsoft\Office\15.0\Word\File MRU
RegKey2=HKCU\Software\Microsoft\Office\15.0\Word\File MRU
RegKey3=HKCU\Software\Microsoft\Office\15.0\Word\Place MRU
RegKey3=HKCU\Software\Microsoft\Office\15.0\Word\Place MRU
RegKey4=HKCU\Software\Microsoft\Office\15.0\Excel\File MRU
RegKey4=HKCU\Software\Microsoft\Office\15.0\Excel\File MRU
RegKey5=HKCU\Software\Microsoft\Office\15.0\Excel\Place MRU
RegKey5=HKCU\Software\Microsoft\Office\15.0\Excel\Place MRU
RegKey6=HKCU\Software\Microsoft\Office\15.0\Publisher\File MRU
RegKey6=HKCU\Software\Microsoft\Office\15.0\Publisher\File MRU
RegKey7=HKCU\Software\Microsoft\Office\15.0\PowerPoint\File MRU
RegKey7=HKCU\Software\Microsoft\Office\15.0\PowerPoint\File MRU
RegKey8=HKCU\Software\Microsoft\Office\15.0\PowerPoint\Place MRU
RegKey8=HKCU\Software\Microsoft\Office\15.0\PowerPoint\Place MRU
RegKey9=HKCU\Software\Microsoft\Office\15.0\OneNote\RecentNotebooks
RegKey9=HKCU\Software\Microsoft\Office\15.0\OneNote\RecentNotebooks
RegKey10=HKCU\Software\Microsoft\Office\15.0\Word\User MRU
RegKey10=HKCU\Software\Microsoft\Office\15.0\Word\User MRU
RegKey11=HKCU\Software\Microsoft\Office\15.0\Excel\User MRU
RegKey11=HKCU\Software\Microsoft\Office\15.0\Excel\User MRU
RegKey12=HKCU\Software\Microsoft\Office\15.0\Access\User MRU
RegKey12=HKCU\Software\Microsoft\Office\15.0\Access\User MRU
RegKey13=HKCU\Software\Microsoft\Office\15.0\Publisher\User MRU
RegKey13=HKCU\Software\Microsoft\Office\15.0\Publisher\User MRU
RegKey14=HKCU\Software\Microsoft\Office\15.0\PowerPoint\User MRU
RegKey14=HKCU\Software\Microsoft\Office\15.0\PowerPoint\User MRU
ExcludeKey1=FILE|%AppData%\Microsoft\Office\Recent\|Welcome to Word.LNK
ExcludeKey1=FILE|%AppData%\Microsoft\Office\Recent\|Welcome to Word.LNK
ExcludeKey2=FILE|%AppData%\Microsoft\Office\Recent\|Welcome to Publisher.LNK
ExcludeKey2=FILE|%AppData%\Microsoft\Office\Recent\|Welcome to Publisher.LNK
ExcludeKey3=FILE|%AppData%\Microsoft\Office\Recent\|Welcome to OneNote.LNK
ExcludeKey3=FILE|%AppData%\Microsoft\Office\Recent\|Welcome to OneNote.LNK
FileKey2=%LocalAppData%\Microsoft\MSOIdentityCRL\production\temp|._sync
FileKey2=%LocalAppData%\Microsoft\MSOIdentityCRL\production\temp|._sync
FileKey4=%LocalAppData%\Microsoft\Office\16.0\WebServiceCache|*.*|RECURSE
FileKey4=%LocalAppData%\Microsoft\Office\16.0\WebServiceCache|*.*|RECURSE
FileKey5=%LocalAppData%\Microsoft\Office\16.0\OfficeFileCache|*.*
FileKey5=%LocalAppData%\Microsoft\Office\16.0\OfficeFileCache|*.*
RegKey1=HKCU\Software\Microsoft\Office\16.0\Access\File MRU
RegKey1=HKCU\Software\Microsoft\Office\16.0\Access\File MRU
RegKey2=HKCU\Software\Microsoft\Office\16.0\Word\File MRU
RegKey2=HKCU\Software\Microsoft\Office\16.0\Word\File MRU
RegKey3=HKCU\Software\Microsoft\Office\16.0\Word\Place MRU
RegKey3=HKCU\Software\Microsoft\Office\16.0\Word\Place MRU
RegKey4=HKCU\Software\Microsoft\Office\16.0\Excel\File MRU
RegKey4=HKCU\Software\Microsoft\Office\16.0\Excel\File MRU
RegKey5=HKCU\Software\Microsoft\Office\16.0\Excel\Place MRU
RegKey5=HKCU\Software\Microsoft\Office\16.0\Excel\Place MRU
RegKey6=HKCU\Software\Microsoft\Office\16.0\Publisher\File MRU
RegKey6=HKCU\Software\Microsoft\Office\16.0\Publisher\File MRU
RegKey7=HKCU\Software\Microsoft\Office\16.0\PowerPoint\File MRU
RegKey7=HKCU\Software\Microsoft\Office\16.0\PowerPoint\File MRU
RegKey8=HKCU\Software\Microsoft\Office\16.0\PowerPoint\Place MRU
RegKey8=HKCU\Software\Microsoft\Office\16.0\PowerPoint\Place MRU
RegKey9=HKCU\Software\Microsoft\Office\16.0\OneNote\RecentNotebooks
RegKey9=HKCU\Software\Microsoft\Office\16.0\OneNote\RecentNotebooks
RegKey10=HKCU\Software\Microsoft\Office\16.0\Word\User MRU
RegKey10=HKCU\Software\Microsoft\Office\16.0\Word\User MRU
RegKey11=HKCU\Software\Microsoft\Office\16.0\Excel\User MRU
RegKey11=HKCU\Software\Microsoft\Office\16.0\Excel\User MRU
RegKey12=HKCU\Software\Microsoft\Office\16.0\Access\User MRU
RegKey12=HKCU\Software\Microsoft\Office\16.0\Access\User MRU
RegKey13=HKCU\Software\Microsoft\Office\16.0\Publisher\User MRU
RegKey13=HKCU\Software\Microsoft\Office\16.0\Publisher\User MRU
RegKey14=HKCU\Software\Microsoft\Office\16.0\PowerPoint\User MRU
RegKey14=HKCU\Software\Microsoft\Office\16.0\PowerPoint\User MRU
ExcludeKey1=FILE|%AppData%\Microsoft\Office\Recent|Welcome to Word.LNK
ExcludeKey1=FILE|%AppData%\Microsoft\Office\Recent|Welcome to Word.LNK
ExcludeKey2=FILE|%AppData%\Microsoft\Office\Recent|Welcome to Publisher.LNK
ExcludeKey2=FILE|%AppData%\Microsoft\Office\Recent|Welcome to Publisher.LNK
ExcludeKey3=FILE|%AppData%\Microsoft\Office\Recent|Welcome to OneNote.LNK
ExcludeKey3=FILE|%AppData%\Microsoft\Office\Recent|Welcome to OneNote.LNK
RegKey1=HKCU\Software\InstallShield\Developer\7.0\Recent File List
RegKey1=HKCU\Software\InstallShield\Developer\7.0\Recent File List
RegKey1=HKCU\Software\Macromedia\Flash 4\Recent File List
RegKey1=HKCU\Software\Macromedia\Flash 4\Recent File List
RegKey1=HKCU\Software\Macromedia\Flash 5\Recent File List
RegKey1=HKCU\Software\Macromedia\Flash 5\Recent File List
RegKey1=HKCU\Software\Macromedia\Flash 6\Recent File List
RegKey1=HKCU\Software\Macromedia\Flash 6\Recent File List
RegKey1=HKCU\Software\Macromedia\Flash 7\Recent File List
RegKey1=HKCU\Software\Macromedia\Flash 7\Recent File List
Detect=HKCR\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
Detect=HKCR\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
DetectFile=%SystemDirectory%\Macromed\flash\flashplayer.xpt
DetectFile=%SystemDirectory%\Macromed\flash\flashplayer.xpt
SpecialKey1=N_FLASH_COOKIES
SpecialKey1=N_FLASH_COOKIES
RegKey1=HKCU\Software\Macromedia\FlashPlayer|RecentMovie1
RegKey1=HKCU\Software\Macromedia\FlashPlayer|RecentMovie1
RegKey2=HKCU\Software\Macromedia\FlashPlayer|RecentMovie2
RegKey2=HKCU\Software\Macromedia\FlashPlayer|RecentMovie2
RegKey3=HKCU\Software\Macromedia\FlashPlayer|RecentMovie3
RegKey3=HKCU\Software\Macromedia\FlashPlayer|RecentMovie3
RegKey4=HKCU\Software\Macromedia\FlashPlayer|RecentMovie4
RegKey4=HKCU\Software\Macromedia\FlashPlayer|RecentMovie4
RegKey5=HKCU\Software\Macromedia\FlashPlayer|RecentMovie5
RegKey5=HKCU\Software\Macromedia\FlashPlayer|RecentMovie5
RegKey6=HKCU\Software\Macromedia\FlashPlayer|RecentMovie6
RegKey6=HKCU\Software\Macromedia\FlashPlayer|RecentMovie6
RegKey7=HKCU\Software\Macromedia\FlashPlayer|RecentMovie7
RegKey7=HKCU\Software\Macromedia\FlashPlayer|RecentMovie7
RegKey8=HKCU\Software\Macromedia\FlashPlayer|RecentMovie8
RegKey8=HKCU\Software\Macromedia\FlashPlayer|RecentMovie8
RegKey9=HKCU\Software\Macromedia\FlashPlayer|RecentMovie9
RegKey9=HKCU\Software\Macromedia\FlashPlayer|RecentMovie9
RegKey1=HKCU\Software\Macromedia\HomeSite5\RecentFiles
RegKey1=HKCU\Software\Macromedia\HomeSite5\RecentFiles
RegKey1=HKCU\Software\Macromedia\Firework 6\Recent File List
RegKey1=HKCU\Software\Macromedia\Firework 6\Recent File List
RegKey1=HKCU\Software\Adobe\Fireworks\12.0\ini\Recent File List
RegKey1=HKCU\Software\Adobe\Fireworks\12.0\ini\Recent File List
FileKey1=%AppData%\Adobe\Fireworks CS6|Project_Log.htm;Web_Log.htm
FileKey1=%AppData%\Adobe\Fireworks CS6|Project_Log.htm;Web_Log.htm
RegKey1=HKCU\Software\Macromedia\Dreamweaver MX 2004\Recent File List
RegKey1=HKCU\Software\Macromedia\Dreamweaver MX 2004\Recent File List
RegKey1=HKCU\Software\Macromedia\Shockwave 10\movies
RegKey1=HKCU\Software\Macromedia\Shockwave 10\movies
RegKey2=HKCU\Software\AppDataLow\Software\Macromedia\Shockwave 10\movies
RegKey2=HKCU\Software\AppDataLow\Software\Macromedia\Shockwave 10\movies
RegKey3=HKCU\Software\AppDataLow\Software\Macromedia\Shockwave 10\statistics
RegKey3=HKCU\Software\AppDataLow\Software\Macromedia\Shockwave 10\statistics
FileKey1=%LocalLowAppData%\Macromedia\Shockwave Player|Shockwave Log
FileKey1=%LocalLowAppData%\Macromedia\Shockwave Player|Shockwave Log
RegKey1=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\moviestats\movies
RegKey1=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\moviestats\movies
RegKey2=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\moviestats\sessions
RegKey2=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\moviestats\sessions
RegKey3=HKCU\Software\Adobe\Shockwave 11\moviestats\movies
RegKey3=HKCU\Software\Adobe\Shockwave 11\moviestats\movies
RegKey4=HKCU\Software\Adobe\Shockwave 11\moviestats\sessions
RegKey4=HKCU\Software\Adobe\Shockwave 11\moviestats\sessions
RegKey5=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\movies
RegKey5=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\movies
RegKey6=HKCU\Software\Adobe\Shockwave 11\movies
RegKey6=HKCU\Software\Adobe\Shockwave 11\movies
RegKey7=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\statistics
RegKey7=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\statistics
FileKey1=%LocalLowAppData%\Adobe\Shockwave Player 11|Shockwave Log
FileKey1=%LocalLowAppData%\Adobe\Shockwave Player 11|Shockwave Log
FileKey1=%LocalAppData%\Microsoft\Silverlight\is|*.*|RECURSE
FileKey1=%LocalAppData%\Microsoft\Silverlight\is|*.*|RECURSE
FileKey2=%LocalLowAppData%\Microsoft\Silverlight\is|*.*|RECURSE
FileKey2=%LocalLowAppData%\Microsoft\Silverlight\is|*.*|RECURSE
FileKey3=%LocalLowAppData%\Microsoft\Silverlight|*.tmp
FileKey3=%LocalLowAppData%\Microsoft\Silverlight|*.tmp
ExcludeKey1=FILE|%LocalAppData%\Microsoft\Silverlight\is\*\|disabled.dat
ExcludeKey1=FILE|%LocalAppData%\Microsoft\Silverlight\is\*\|disabled.dat
ExcludeKey2=FILE|%LocalLowAppData%\Microsoft\Silverlight\is\*\|disabled.dat
ExcludeKey2=FILE|%LocalLowAppData%\Microsoft\Silverlight\is\*\|disabled.dat
RegKey1=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0\Recent File List
RegKey1=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0\Recent File List
FileKey1=%commonappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey1=%commonappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey2=%localappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey2=%localappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|*.*
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|*.*
FileKey1=%commonappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey1=%commonappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey2=%localappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey2=%localappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|*.log
RegKey1=HKCU\Software\Microsoft\Snapshot Viewer\Recent File List
RegKey1=HKCU\Software\Microsoft\Snapshot Viewer\Recent File List
FileKey1=%localappdata%\Microsoft\Terminal Server Client\Cache|*.*
FileKey1=%localappdata%\Microsoft\Terminal Server Client\Cache|*.*
RegKey1=HKCU\Software\Microsoft\Terminal Server Client\Default
RegKey1=HKCU\Software\Microsoft\Terminal Server Client\Default
ExcludeKey1=REG|HKCU\Software\Microsoft\Terminal Server Client\Default\AddIns
ExcludeKey1=REG|HKCU\Software\Microsoft\Terminal Server Client\Default\AddIns
RegKey1=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List
RegKey1=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List
RegKey1=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile1
RegKey1=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile1
RegKey2=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile2
RegKey2=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile2
RegKey3=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile3
RegKey3=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile3
RegKey4=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile4
RegKey4=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile4
RegKey5=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType1
RegKey5=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType1
RegKey6=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType2
RegKey6=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType2
RegKey7=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType3
RegKey7=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType3
RegKey8=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType4
RegKey8=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType4
DetectFile=%CommonAppData%\Microsoft\Search
DetectFile=%CommonAppData%\Microsoft\Search
FileKey1=%CommonAppData%\Microsoft\Search|*.log|RECURSE
FileKey1=%CommonAppData%\Microsoft\Search|*.log|RECURSE
FileKey1=%LocalAppData%\Microsoft\Windows\ConnectedSearch\History|*.lnk
FileKey1=%LocalAppData%\Microsoft\Windows\ConnectedSearch\History|*.lnk
RegKey1=HKCU\Software\ahead\Nero - Burning Rom\Settings|BrowserDir
RegKey1=HKCU\Software\ahead\Nero - Burning Rom\Settings|BrowserDir
RegKey2=HKCU\Software\ahead\Nero - Burning Rom\Settings|ImageDir
RegKey2=HKCU\Software\ahead\Nero - Burning Rom\Settings|ImageDir
RegKey3=HKCU\Software\ahead\Nero - Burning Rom\Settings|WorkingDir
RegKey3=HKCU\Software\ahead\Nero - Burning Rom\Settings|WorkingDir
RegKey4=HKLM\Software\Ahead\Nero - Burning Rom\Settings|ImageDir
RegKey4=HKLM\Software\Ahead\Nero - Burning Rom\Settings|ImageDir
RegKey5=HKLM\Software\Ahead\Nero - Burning Rom\Settings|BootImageDir
RegKey5=HKLM\Software\Ahead\Nero - Burning Rom\Settings|BootImageDir
RegKey6=HKCU\Software\Ahead\Nero - Burning Rom\Recent File List
RegKey6=HKCU\Software\Ahead\Nero - Burning Rom\Recent File List
RegKey7=HKCU\Software\Ahead\Cover Designer\Recent File List
RegKey7=HKCU\Software\Ahead\Cover Designer\Recent File List
RegKey8=HKCU\Software\Ahead\Nero Wave Editor\Recent File List
RegKey8=HKCU\Software\Ahead\Nero Wave Editor\Recent File List
FileKey1=%ProgramFiles%\Ahead\Nero|NeroHistory.log
FileKey1=%ProgramFiles%\Ahead\Nero|NeroHistory.log
RegKey1=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BrowserDir
RegKey1=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BrowserDir
RegKey2=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey2=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey3=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|WorkingDir
RegKey3=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|WorkingDir
RegKey4=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BootImageDir
RegKey4=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BootImageDir
RegKey5=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Recent File List
RegKey5=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Recent File List
FileKey1=%appdata%\Nero\Nero 9\Nero Burning ROM|*.log
FileKey1=%appdata%\Nero\Nero 9\Nero Burning ROM|*.log
RegKey1=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|BrowserDir
RegKey1=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|BrowserDir
RegKey2=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|ImageDir
RegKey2=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|ImageDir
RegKey3=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|WorkingDir
RegKey3=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|WorkingDir
RegKey4=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|BootImageDir
RegKey4=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|BootImageDir
RegKey5=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|NeroCompilation
RegKey5=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|NeroCompilation
RegKey6=HKCU\Software\Nero\Nero 10\Nero\Recent File List
RegKey6=HKCU\Software\Nero\Nero 10\Nero\Recent File List
FileKey1=%appdata%\Nero\Nero 10\Nero Burning ROM|*.log
FileKey1=%appdata%\Nero\Nero 10\Nero Burning ROM|*.log
RegKey1=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|BrowserDir
RegKey1=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|BrowserDir
RegKey2=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|ImageDir
RegKey2=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|ImageDir
RegKey3=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|WorkingDir
RegKey3=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|WorkingDir
RegKey4=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|BootImageDir
RegKey4=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|BootImageDir
RegKey5=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|NeroCompilation
RegKey5=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|NeroCompilation
RegKey6=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings\NeroIsoListView|IsoPath
RegKey6=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings\NeroIsoListView|IsoPath
RegKey7=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Recent File List
RegKey7=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Recent File List
RegKey8=HKCU\Software\Nero\Nero 15\Nero Burning ROM\AutoSave|LastAutoSave
RegKey8=HKCU\Software\Nero\Nero 15\Nero Burning ROM\AutoSave|LastAutoSave
RegKey9=HKCU\Software\Nero\Nero 15\Nero Burning ROM\General|LastSaveTrackPath
RegKey9=HKCU\Software\Nero\Nero 15\Nero Burning ROM\General|LastSaveTrackPath
FileKey1=%AppData%\Nero\Nero 15\Nero Burning ROM|NeroHistory.log
FileKey1=%AppData%\Nero\Nero 15\Nero Burning ROM|NeroHistory.log
RegKey1=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Recent File List
RegKey1=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Recent File List
RegKey2=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|BrowserDir
RegKey2=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|BrowserDir
RegKey3=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|ImageDir
RegKey3=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|ImageDir
RegKey4=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|NeroCompilation
RegKey4=HKCU\Software\Nero\Nero 12\Nero Burning ROM\Settings|NeroCompilation
RegKey5=HKCU\Software\Nero\Nero 12\Nero Express\Recent File List
RegKey5=HKCU\Software\Nero\Nero 12\Nero Express\Recent File List
RegKey6=HKCU\Software\Nero\Nero 12\Nero Express\Settings|WorkingDir
RegKey6=HKCU\Software\Nero\Nero 12\Nero Express\Settings|WorkingDir
RegKey7=HKCU\Software\Nero\Nero 12\Nero Express\Settings|BrowserDir
RegKey7=HKCU\Software\Nero\Nero 12\Nero Express\Settings|BrowserDir
RegKey8=HKCU\Software\Nero\Nero 12\Nero Express\General|OFDLastISODir
RegKey8=HKCU\Software\Nero\Nero 12\Nero Express\General|OFDLastISODir
RegKey9=HKCU\Software\Nero\Nero 12\Nero Express\General|OFDLastAudioDir
RegKey9=HKCU\Software\Nero\Nero 12\Nero Express\General|OFDLastAudioDir
RegKey10=HKCU\Software\Nero\Nero 12\Nero Express\General|OFDLastVideoDVDKey
RegKey10=HKCU\Software\Nero\Nero 12\Nero Express\General|OFDLastVideoDVDKey
RegKey11=HKCU\Software\Nero\Nero 12\Nero WaveEditor\Recent File List
RegKey11=HKCU\Software\Nero\Nero 12\Nero WaveEditor\Recent File List
RegKey12=HKCU\Software\Nero\Nero 12\Nero CoverDesigner\Recent File List
RegKey12=HKCU\Software\Nero\Nero 12\Nero CoverDesigner\Recent File List
FileKey1=%CommonAppData%\Nero\PeakFiles|*.tmp
FileKey1=%CommonAppData%\Nero\PeakFiles|*.tmp
FileKey2=%AppData%\Nero\Nero 12\Nero Recode\AnalysisData|*.jpg;*.xml
FileKey2=%AppData%\Nero\Nero 12\Nero Recode\AnalysisData|*.jpg;*.xml
FileKey3=%AppData%\Nero\Nero 12\Nero BackItUp\Cache|*.txt
FileKey3=%AppData%\Nero\Nero 12\Nero BackItUp\Cache|*.txt
FileKey4=%AppData%\Nero\Nero 12\Nero Burning ROM|*.log;*Burning*.dmp
FileKey4=%AppData%\Nero\Nero 12\Nero Burning ROM|*.log;*Burning*.dmp
FileKey5=%AppData%\Nero\Nero 12\Nero3D|Direct3D.log
FileKey5=%AppData%\Nero\Nero 12\Nero3D|Direct3D.log
FileKey6=%AppData%\Nero\Nero 12\Nero Vision|NeroVideoLog.txt
FileKey6=%AppData%\Nero\Nero 12\Nero Vision|NeroVideoLog.txt
FileKey7=%SystemDrive%\Windows\SysWOW64|*-NeroRescueAgent.txt
FileKey7=%SystemDrive%\Windows\SysWOW64|*-NeroRescueAgent.txt
RegKey1=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|WorkingDir
RegKey1=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|WorkingDir
RegKey2=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|BootImageDir
RegKey2=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|BootImageDir
RegKey3=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings\NeroIsoListView|IsoPath
RegKey3=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings\NeroIsoListView|IsoPath
RegKey4=HKCU\Software\Nero\Nero 15\Nero Burning ROM\AutoSave|LastAutoSave
RegKey4=HKCU\Software\Nero\Nero 15\Nero Burning ROM\AutoSave|LastAutoSave
RegKey5=HKCU\Software\Nero\Nero 15\Nero Burning ROM\General|LastSaveTrackPath
RegKey5=HKCU\Software\Nero\Nero 15\Nero Burning ROM\General|LastSaveTrackPath
RegKey6=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Recent File List
RegKey6=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Recent File List
RegKey7=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|BrowserDir
RegKey7=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|BrowserDir
RegKey8=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|ImageDir
RegKey8=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|ImageDir
RegKey9=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|NeroCompilation
RegKey9=HKCU\Software\Nero\Nero 15\Nero Burning ROM\Settings|NeroCompilation
RegKey10=HKCU\Software\Nero\Nero 15\Nero Express\Recent File List
RegKey10=HKCU\Software\Nero\Nero 15\Nero Express\Recent File List
RegKey11=HKCU\Software\Nero\Nero 15\Nero Express\Settings|WorkingDir
RegKey11=HKCU\Software\Nero\Nero 15\Nero Express\Settings|WorkingDir
RegKey12=HKCU\Software\Nero\Nero 15\Nero Express\Settings|BrowserDir
RegKey12=HKCU\Software\Nero\Nero 15\Nero Express\Settings|BrowserDir
RegKey13=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastISODir
RegKey13=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastISODir
RegKey14=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastAudioDir
RegKey14=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastAudioDir
RegKey15=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastVideoDVDKey
RegKey15=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastVideoDVDKey
RegKey16=HKCU\Software\Nero\Nero 15\Nero WaveEditor\Recent File List
RegKey16=HKCU\Software\Nero\Nero 15\Nero WaveEditor\Recent File List
RegKey17=HKCU\Software\Nero\Nero 15\Nero CoverDesigner\Recent File List
RegKey17=HKCU\Software\Nero\Nero 15\Nero CoverDesigner\Recent File List
FileKey2=%AppData%\Nero\Nero 15\Nero Recode\AnalysisData|*.jpg;*.xml
FileKey2=%AppData%\Nero\Nero 15\Nero Recode\AnalysisData|*.jpg;*.xml
FileKey3=%AppData%\Nero\Nero 15\Nero BackItUp\Cache|*.txt
FileKey3=%AppData%\Nero\Nero 15\Nero BackItUp\Cache|*.txt
FileKey4=%AppData%\Nero\Nero 15\Nero Burning ROM|*.log;*Burning*.dmp
FileKey4=%AppData%\Nero\Nero 15\Nero Burning ROM|*.log;*Burning*.dmp
FileKey5=%SystemDrive%\Windows\SysWOW64|*-NeroRescueAgent.txt
FileKey5=%SystemDrive%\Windows\SysWOW64|*-NeroRescueAgent.txt
FileKey6=%AppData%\Nero\Nero 15\Nero3D|Direct3D.log
FileKey6=%AppData%\Nero\Nero 15\Nero3D|Direct3D.log
FileKey7=%AppData%\Nero\Nero 15\Nero Vision|NeroVideoLog.txt
FileKey7=%AppData%\Nero\Nero 15\Nero Vision|NeroVideoLog.txt
FileKey8=%AppData%\Nero\Nero 15\Nero Welcome|LogFile.txt
FileKey8=%AppData%\Nero\Nero 15\Nero Welcome|LogFile.txt
FileKey9=%AppData%\Nero\Nero Blu-ray Player|LogFile.txt
FileKey9=%AppData%\Nero\Nero Blu-ray Player|LogFile.txt
FileKey10=%AppData%\Nero\OnlineServices|LoadData.tmp;LoadData_bak.tmp
FileKey10=%AppData%\Nero\OnlineServices|LoadData.tmp;LoadData_bak.tmp
FileKey11=%AppData%\Nero\ControlCenter|Sync.log
FileKey11=%AppData%\Nero\ControlCenter|Sync.log
FileKey12=%CommonAppData%\Nero\Nero 11\ACME|ACME.log
FileKey12=%CommonAppData%\Nero\Nero 11\ACME|ACME.log
FileKey13=%CommonAppData%\Nero\ACME|ACME.log
FileKey13=%CommonAppData%\Nero\ACME|ACME.log
FileKey1=%AppData%\Nero\Nero 11\Nero Vision|*.log;*.txt
FileKey1=%AppData%\Nero\Nero 11\Nero Vision|*.log;*.txt
FileKey2=%AppData%\Nero\Nero 11\Nero Vision\Log|*.*
FileKey2=%AppData%\Nero\Nero 11\Nero Vision\Log|*.*
FileKey3=%AppData%\Nero\Nero 11\Nero Vision\NVFACache|*.*
FileKey3=%AppData%\Nero\Nero 11\Nero Vision\NVFACache|*.*
FileKey4=%AppData%\Nero\Nero 11\Nero3D|*.log
FileKey4=%AppData%\Nero\Nero 11\Nero3D|*.log
FileKey1=%AppData%\Nero\Nero 10\Nero Vision\Log|*.*
FileKey1=%AppData%\Nero\Nero 10\Nero Vision\Log|*.*
FileKey2=%AppData%\Nero\Nero 10\Nero Vision\NVFACache|*.*
FileKey2=%AppData%\Nero\Nero 10\Nero Vision\NVFACache|*.*
FileKey3=%AppData%\Nero\Nero 10\Nero Vision|*.txt
FileKey3=%AppData%\Nero\Nero 10\Nero Vision|*.txt
FileKey4=%AppData%\Nero\Nero 10\Nero3D|*.log
FileKey4=%AppData%\Nero\Nero 10\Nero3D|*.log
FileKey1=%AppData%\Nero\Nero 15\Nero BackItUp\Cache|*.txt
FileKey1=%AppData%\Nero\Nero 15\Nero BackItUp\Cache|*.txt
RegKey1=HKCU\Software\Nero\Nero 15\Nero Express\Recent File List
RegKey1=HKCU\Software\Nero\Nero 15\Nero Express\Recent File List
RegKey2=HKCU\Software\Nero\Nero 15\Nero Express\Settings|WorkingDir
RegKey2=HKCU\Software\Nero\Nero 15\Nero Express\Settings|WorkingDir
RegKey3=HKCU\Software\Nero\Nero 15\Nero Express\Settings|BrowserDir
RegKey3=HKCU\Software\Nero\Nero 15\Nero Express\Settings|BrowserDir
RegKey4=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastISODir
RegKey4=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastISODir
RegKey5=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastAudioDir
RegKey5=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastAudioDir
RegKey6=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastVideoDVDKey
RegKey6=HKCU\Software\Nero\Nero 15\Nero Express\General|OFDLastVideoDVDKey
RegKey1=HKCU\Software\e-merge\WinAce\2.0\Favorites
RegKey1=HKCU\Software\e-merge\WinAce\2.0\Favorites
RegKey2=HKCU\Software\e-merge\WinAce\2.0\MRU Items
RegKey2=HKCU\Software\e-merge\WinAce\2.0\MRU Items
FileKey1=%commonappdata%\Spybot - Search & Destroy\Logs|*.*
FileKey1=%commonappdata%\Spybot - Search & Destroy\Logs|*.*
FileKey2=%ProgramFiles%\Spybot - Search & Destroy|advdebug.txt
FileKey2=%ProgramFiles%\Spybot - Search & Destroy|advdebug.txt
FileKey3=%commonappdata%\Spybot - Search & Destroy|Statistics.ini
FileKey3=%commonappdata%\Spybot - Search & Destroy|Statistics.ini
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|*.*
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|*.*
FileKey5=%windir%\All Users\Application Data\Spybot - Search & Destroy|Statistics.ini
FileKey5=%windir%\All Users\Application Data\Spybot - Search & Destroy|Statistics.ini
FileKey6=%commonappdata%\Spybot - Search & Destroy\Backups|*.log
FileKey6=%commonappdata%\Spybot - Search & Destroy\Backups|*.log
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal|defs.ref.old
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional|defs.ref.old
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional|defs.ref.old
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus|defs.ref.old
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus|defs.ref.old
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware\Ad-Aware.exe
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware\Ad-Aware.exe
Filekey1=%commonappdata%\Lavasoft\Ad-Aware\Logs|*.log
Filekey1=%commonappdata%\Lavasoft\Ad-Aware\Logs|*.log
[Webroot SpySweeper]
[Webroot SpySweeper]
Detect=HKCU\Software\Webroot\SpySweeper
Detect=HKCU\Software\Webroot\SpySweeper
FileKey1=%ProgramFiles%\Webroot\Spy Sweeper\Temp|*.*
FileKey1=%ProgramFiles%\Webroot\Spy Sweeper\Temp|*.*
FileKey2=%appdata%\Webroot\Spy Sweeper\Logs|*Log.txt
FileKey2=%appdata%\Webroot\Spy Sweeper\Logs|*Log.txt
DetectFile=%ProgramFiles%\Driver Cleaner Pro\DCleaner.exe
DetectFile=%ProgramFiles%\Driver Cleaner Pro\DCleaner.exe
FileKey1=%ProgramFiles%\Driver Cleaner Pro\Log|*.log
FileKey1=%ProgramFiles%\Driver Cleaner Pro\Log|*.log
RegKey1=HKCU\Software\Kazaa\Search
RegKey1=HKCU\Software\Kazaa\Search
FileKey1=%ProgramFiles%\Netscape\Users\default|netscape.hst;cookies.txt
FileKey1=%ProgramFiles%\Netscape\Users\default|netscape.hst;cookies.txt
FileKey2=%ProgramFiles%\Netscape\Users\default\cache|*.*
FileKey2=%ProgramFiles%\Netscape\Users\default\cache|*.*
RegKey1=HKCU\Software\Microsoft\VisualStudio\6.0\FileMRUList
RegKey1=HKCU\Software\Microsoft\VisualStudio\6.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\6.0\MenuMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\6.0\MenuMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\6.0\ProjectMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\6.0\ProjectMRUList
RegKey4=HKCU\Software\Microsoft\Visual Basic\6.0\RecentFiles
RegKey4=HKCU\Software\Microsoft\Visual Basic\6.0\RecentFiles
RegKey1=HKCU\Software\Axialis\IconWorkshop\Recent File List
RegKey1=HKCU\Software\Axialis\IconWorkshop\Recent File List
RegKey2=HKCU\Software\Axialis\IconWorkshop\Axialis Recent Files
RegKey2=HKCU\Software\Axialis\IconWorkshop\Axialis Recent Files
RegKey3=HKCU\Software\Axialis\IconWorkshop\CoolBarList
RegKey3=HKCU\Software\Axialis\IconWorkshop\CoolBarList
FileKey1=%appdata%\Axialis\Temporary Preview Files|*.*|RECURSE
FileKey1=%appdata%\Axialis\Temporary Preview Files|*.*|RECURSE
FileKey2=%LocalAppData%\Axialis\Temporary Preview Files|*.*|RECURSE
FileKey2=%LocalAppData%\Axialis\Temporary Preview Files|*.*|RECURSE
FileKey1=%ProgramFiles%\eMule\config|AC_SearchStrings.dat
FileKey1=%ProgramFiles%\eMule\config|AC_SearchStrings.dat
FileKey2=%LocalAppData%\eMule\config|AC_SearchStrings.dat
FileKey2=%LocalAppData%\eMule\config|AC_SearchStrings.dat
FileKey3=%CommonAppData%\eMule\config|AC_SearchStrings.dat
FileKey3=%CommonAppData%\eMule\config|AC_SearchStrings.dat
FileKey1=%ProgramFiles%\eMule\config|known.met;known2.met;known2_64.met
FileKey1=%ProgramFiles%\eMule\config|known.met;known2.met;known2_64.met
FileKey2=%LocalAppData%\eMule\config|known.met;known2.met;known2_64.met
FileKey2=%LocalAppData%\eMule\config|known.met;known2.met;known2_64.met
FileKey3=%CommonAppData%\eMule\config|known.met;known2.met;known2_64.met
FileKey3=%CommonAppData%\eMule\config|known.met;known2.met;known2_64.met
RegKey1=HKLM\Software\WinISO\Reopen
RegKey1=HKLM\Software\WinISO\Reopen
RegKey1=HKCU\Software\Smart Projects\IsoBuster|ImageFilePath
RegKey1=HKCU\Software\Smart Projects\IsoBuster|ImageFilePath
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName
RegKey4=HKCU\Software\MPC-HC\MPC-HC\Recent File List
RegKey4=HKCU\Software\MPC-HC\MPC-HC\Recent File List
RegKey5=HKCU\Software\MPC-HC\MPC-HC\Recent Dub List
RegKey5=HKCU\Software\MPC-HC\MPC-HC\Recent Dub List
RegKey6=HKCU\Software\MPC-HC\MPC-HC\Capture|FileName
RegKey6=HKCU\Software\MPC-HC\MPC-HC\Capture|FileName
RegKey7=HKCU\Software\MPC-BE\Recent File List
RegKey7=HKCU\Software\MPC-BE\Recent File List
RegKey8=HKCU\Software\MPC-BE\Recent Dub List
RegKey8=HKCU\Software\MPC-BE\Recent Dub List
RegKey9=HKCU\Software\MPC-BE\Capture|FileName
RegKey9=HKCU\Software\MPC-BE\Capture|FileName
FileKey1=%appdata%\Media Player Classic|default.mpcpl
FileKey1=%appdata%\Media Player Classic|default.mpcpl
FileKey2=%appdata%\MPC-HC|default.mpcpl
FileKey2=%appdata%\MPC-HC|default.mpcpl
FileKey3=%appdata%\MPC-BE|default.mpcpl
FileKey3=%appdata%\MPC-BE|default.mpcpl
RegKey1=HKCU\Software\BST\bsplayer|File0
RegKey1=HKCU\Software\BST\bsplayer|File0
RegKey2=HKCU\Software\BST\bsplayer|File1
RegKey2=HKCU\Software\BST\bsplayer|File1
RegKey3=HKCU\Software\BST\bsplayer|File2
RegKey3=HKCU\Software\BST\bsplayer|File2
RegKey4=HKCU\Software\BST\bsplayer|File3
RegKey4=HKCU\Software\BST\bsplayer|File3
RegKey5=HKCU\Software\BST\bsplayer|File4
RegKey5=HKCU\Software\BST\bsplayer|File4
RegKey6=HKCU\Software\BST\bsplayer|File5
RegKey6=HKCU\Software\BST\bsplayer|File5
RegKey7=HKCU\Software\BST\bsplayer|File6
RegKey7=HKCU\Software\BST\bsplayer|File6
RegKey8=HKCU\Software\BST\bsplayer|File7
RegKey8=HKCU\Software\BST\bsplayer|File7
RegKey9=HKCU\Software\BST\bsplayer|File8
RegKey9=HKCU\Software\BST\bsplayer|File8
RegKey10=HKCU\Software\BST\bsplayer|File9
RegKey10=HKCU\Software\BST\bsplayer|File9
DetectFile=%ProgramFiles%\videolan\vlc\vlc.exe
DetectFile=%ProgramFiles%\videolan\vlc\vlc.exe
FileKey1=%appdata%\vlc\art\artistalbum\|*.*|REMOVESELF
FileKey1=%appdata%\vlc\art\artistalbum\|*.*|REMOVESELF
FileKey2=%appdata%\vlc\art\arturl\|*.*|REMOVESELF
FileKey2=%appdata%\vlc\art\arturl\|*.*|REMOVESELF
[MediaMonkey]
[MediaMonkey]
Detect=HKCU\Software\MediaMonkey
Detect=HKCU\Software\MediaMonkey
DetectFile=%ProgramFiles%\MediaMonkey\MediaMonkey.exe
DetectFile=%ProgramFiles%\MediaMonkey\MediaMonkey.exe
FileKey1=%localappdata%\MediaMonkey|MediaMonkey.m3u
FileKey1=%localappdata%\MediaMonkey|MediaMonkey.m3u
FileKey2=%localappdata%\MediaMonkey\Previews|*.*|RECURSE
FileKey2=%localappdata%\MediaMonkey\Previews|*.*|RECURSE
FileKey1=%ProgramFiles%\Winamp\Plugins\ml|recent.dat
FileKey1=%ProgramFiles%\Winamp\Plugins\ml|recent.dat
FileKey2=%ProgramFiles%\Winamp\Plugins\ml\cache|*.*|RECURSE
FileKey2=%ProgramFiles%\Winamp\Plugins\ml\cache|*.*|RECURSE
FileKey3=%AppData%\Winamp\Plugins\ml|recent.dat
FileKey3=%AppData%\Winamp\Plugins\ml|recent.dat
FileKey4=%AppData%\Winamp\Plugins\ml\Cache|*.*|RECURSE
FileKey4=%AppData%\Winamp\Plugins\ml\Cache|*.*|RECURSE
FileKey1=%LocalAppData%\Musicmatch\Jukebox|*.log;*log.txt
FileKey1=%LocalAppData%\Musicmatch\Jukebox|*.log;*log.txt
FileKey2=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\TEMP|*.*
FileKey2=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\TEMP|*.*
RegKey1=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30110
RegKey1=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30110
RegKey2=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30111
RegKey2=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30111
RegKey3=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30112
RegKey3=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30112
RegKey4=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30113
RegKey4=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30113
RegKey5=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30114
RegKey5=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30114
RegKey6=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30115
RegKey6=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30115
RegKey1=HKCU\Software\Audacity\Audacity\RecentFiles
RegKey1=HKCU\Software\Audacity\Audacity\RecentFiles
[Windows Live Messenger]
[Windows Live Messenger]
Detect=HKCU\Software\Microsoft\MSNMessenger\PerPassportSettings
Detect=HKCU\Software\Microsoft\MSNMessenger\PerPassportSettings
RegKey1=HKCU\Software\Microsoft\MessengerService\ListCache\.NET Messenger Service
RegKey1=HKCU\Software\Microsoft\MessengerService\ListCache\.NET Messenger Service
FileKey1=%AppData%\Microsoft\MSN Messenger|*.sqm|RECURSE
FileKey1=%AppData%\Microsoft\MSN Messenger|*.sqm|RECURSE
FileKey2=%LocalAppData%\Microsoft\Messenger|*.uccapilog;*.bak
FileKey2=%LocalAppData%\Microsoft\Messenger|*.uccapilog;*.bak
FileKey3=%UserProfile%\Tracing|WindowsLiveMessenger*.uccapilog;WindowsLiveMessenger*.uccapilog.bak
FileKey3=%UserProfile%\Tracing|WindowsLiveMessenger*.uccapilog;WindowsLiveMessenger*.uccapilog.bak
DetectFile=%ProgramFiles%\Skype\Phone\Skype.exe
DetectFile=%ProgramFiles%\Skype\Phone\Skype.exe
FileKey1=%AppData%\Skype|temp*
FileKey1=%AppData%\Skype|temp*
DetectFile=%ProgramFiles%\AIM\aim.exe
DetectFile=%ProgramFiles%\AIM\aim.exe
FileKey1=%AppData%\acccore\caches\bart|*.*|RECURSE
FileKey1=%AppData%\acccore\caches\bart|*.*|RECURSE
FileKey2=%AppData%\acccore\caches\users|*.*|REMOVESELF
FileKey2=%AppData%\acccore\caches\users|*.*|REMOVESELF
FileKey3=%LocalAppData%\AIM\Settings\aolbartcache|*.*|RECURSE
FileKey3=%LocalAppData%\AIM\Settings\aolbartcache|*.*|RECURSE
DetectFile2=%AppData%\Camfrog\history.db
DetectFile2=%AppData%\Camfrog\history.db
FileKey1=%LocalAppData%\CrashRpt|*.*|REMOVESELF
FileKey1=%LocalAppData%\CrashRpt|*.*|REMOVESELF
FileKey2=%AppData%\Camfrog\cache|*.*|RECURSE
FileKey2=%AppData%\Camfrog\cache|*.*|RECURSE
DetectFile1=%ProgramFiles%\Miranda IM\miranda32.exe
DetectFile1=%ProgramFiles%\Miranda IM\miranda32.exe
DetectFile2=%ProgramFiles%\Miranda IM\miranda64.exe
DetectFile2=%ProgramFiles%\Miranda IM\miranda64.exe
FileKey1=%AppData%\Miranda|*.jpg|REMOVESELF
FileKey1=%AppData%\Miranda|*.jpg|REMOVESELF
DetectFile=%ProgramFiles%\Pidgin\pidgin.exe
DetectFile=%ProgramFiles%\Pidgin\pidgin.exe
FileKey1=%AppData%\.purple\autoaccept|*.*|REMOVESELF
FileKey1=%AppData%\.purple\autoaccept|*.*|REMOVESELF
FileKey2=%AppData%\.purple\icons|*.*
FileKey2=%AppData%\.purple\icons|*.*
DetectFile=%ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe
DetectFile=%ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe
FileKey1=%ProgramFiles%\Yahoo!\Messenger\Cache|*.*|RECURSE
FileKey1=%ProgramFiles%\Yahoo!\Messenger\Cache|*.*|RECURSE
FileKey2=%ProgramFiles%\Yahoo!\Messenger\IMVCache|*.*|RECURSE
FileKey2=%ProgramFiles%\Yahoo!\Messenger\IMVCache|*.*|RECURSE
FileKey3=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey3=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey4=%ProgramFiles%\Yahoo!\Messenger\Logs|*.*
FileKey4=%ProgramFiles%\Yahoo!\Messenger\Logs|*.*
FileKey5=%ProgramFiles%\Yahoo!\Messenger\Games|*.gif|RECURSE
FileKey5=%ProgramFiles%\Yahoo!\Messenger\Games|*.gif|RECURSE
DetectFile=%ProgramFiles%\ooVoo\ooVoo.exe
DetectFile=%ProgramFiles%\ooVoo\ooVoo.exe
FileKey1=%AppData%\ooVoo Details\cache|*.*
FileKey1=%AppData%\ooVoo Details\cache|*.*
FileKey2=%AppData%\ooVoo Details\logs|*.*
FileKey2=%AppData%\ooVoo Details\logs|*.*
DetectFile1=%ProgramFiles%\TeamSpeak 3 Client\ts3client_win32.exe
DetectFile1=%ProgramFiles%\TeamSpeak 3 Client\ts3client_win32.exe
DetectFile2=%ProgramFiles%\TeamSpeak 3 Client\ts3client_win64.exe
DetectFile2=%ProgramFiles%\TeamSpeak 3 Client\ts3client_win64.exe
FileKey1=%AppData%\TS3Client\cache|*.*|REMOVESELF
FileKey1=%AppData%\TS3Client\cache|*.*|REMOVESELF
FileKey2=%AppData%\TS3Client\Logs|*.*
FileKey2=%AppData%\TS3Client\Logs|*.*
DetectFile=%ProgramFiles%\Ventrilo\Ventrilo.exe
DetectFile=%ProgramFiles%\Ventrilo\Ventrilo.exe
FileKey1=%AppData%\Ventrilo|ventrilo.log
FileKey1=%AppData%\Ventrilo|ventrilo.log
FileKey2=%AppData%\Ventrilo\temp|*.*
FileKey2=%AppData%\Ventrilo\temp|*.*
FileKey3=%AppData%\Ventrilo\recordings|*.*
FileKey3=%AppData%\Ventrilo\recordings|*.*
DetectFile=%ProgramFiles%\VentSrv\ventrilo_srv.exe
DetectFile=%ProgramFiles%\VentSrv\ventrilo_srv.exe
FileKey1=%ProgramFiles%\VentSrv|ventrilo_srv.log
FileKey1=%ProgramFiles%\VentSrv|ventrilo_srv.log
FileKey1=%AppData%\MySpace\IM\Install|*.*
FileKey1=%AppData%\MySpace\IM\Install|*.*
FileKey2=%AppData%\MySpace\IM\Logs|*.*
FileKey2=%AppData%\MySpace\IM\Logs|*.*
FileKey1=%AppData%\Acronis\TrueImage\Logs|*.log
FileKey1=%AppData%\Acronis\TrueImage\Logs|*.log
FileKey2=%AppData%\Acronis\TrueImageHome\Logs|*.log
FileKey2=%AppData%\Acronis\TrueImageHome\Logs|*.log
FileKey3=%CommonAppData%\Acronis\TrueImage\Logs|*.log
FileKey3=%CommonAppData%\Acronis\TrueImage\Logs|*.log
FileKey4=%CommonAppData%\Acronis\TrueImageHome\Logs|*.log
FileKey4=%CommonAppData%\Acronis\TrueImageHome\Logs|*.log
RegKey1=HKCU\Software\Nico Mak Computing\WinZip\filemenu
RegKey1=HKCU\Software\Nico Mak Computing\WinZip\filemenu
RegKey2=HKCU\Software\Nico Mak Computing\WinZip\extract
RegKey2=HKCU\Software\Nico Mak Computing\WinZip\extract
RegKey3=HKCU\Software\Nico Mak Computing\WinZip\directories|DefDir
RegKey3=HKCU\Software\Nico Mak Computing\WinZip\directories|DefDir
RegKey4=HKCU\Software\Nico Mak Computing\WinZip\directories|ExtractTo
RegKey4=HKCU\Software\Nico Mak Computing\WinZip\directories|ExtractTo
RegKey5=HKCU\Software\Nico Mak Computing\WinZip\directories|gzAddDir
RegKey5=HKCU\Software\Nico Mak Computing\WinZip\directories|gzAddDir
RegKey6=HKCU\Software\Nico Mak Computing\WinZip\directories|zDefDir
RegKey6=HKCU\Software\Nico Mak Computing\WinZip\directories|zDefDir
RegKey7=HKCU\Software\Nico Mak Computing\WinZip\directories|AddDir
RegKey7=HKCU\Software\Nico Mak Computing\WinZip\directories|AddDir
RegKey8=HKCU\Software\Nico Mak Computing\WinZip\directories|gzExtractTo
RegKey8=HKCU\Software\Nico Mak Computing\WinZip\directories|gzExtractTo
RegKey9=HKCU\Software\Nico Mak Computing\WinZip\rrs\Opened
RegKey9=HKCU\Software\Nico Mak Computing\WinZip\rrs\Opened
RegKey10=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|0
RegKey10=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|0
RegKey11=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|1
RegKey11=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|1
RegKey12=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|2
RegKey12=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|2
RegKey13=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|3
RegKey13=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|3
RegKey14=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|4
RegKey14=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|4
RegKey15=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|5
RegKey15=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|5
RegKey16=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|6
RegKey16=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|6
RegKey17=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|7
RegKey17=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|7
RegKey18=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|8
RegKey18=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|8
RegKey19=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|9
RegKey19=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|9
RegKey20=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|10
RegKey20=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|10
RegKey21=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|11
RegKey21=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|11
RegKey22=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|12
RegKey22=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|12
RegKey23=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|13
RegKey23=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|13
RegKey24=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|14
RegKey24=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|14
RegKey25=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|15
RegKey25=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|15
RegKey26=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|16
RegKey26=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|16
RegKey27=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|17
RegKey27=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|17
RegKey28=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|18
RegKey28=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|18
RegKey29=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|19
RegKey29=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|19
RegKey30=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|20
RegKey30=HKCU\Software\Nico Mak Computing\WinZip\mru\archives|20
FileKey1=%AppData%\WinZip\WINZIPSCANNER\Registry Cleaner|log_*.log
FileKey1=%AppData%\WinZip\WINZIPSCANNER\Registry Cleaner|log_*.log
FileKey2=%AppData%\WinZip\WINZIPSCANNER\System Cleaner|log_*.log
FileKey2=%AppData%\WinZip\WINZIPSCANNER\System Cleaner|log_*.log
RegKey1=HKCU\Software\WinRAR\ArcHistory
RegKey1=HKCU\Software\WinRAR\ArcHistory
RegKey2=HKCU\Software\WinRAR\General|LastFolder
RegKey2=HKCU\Software\WinRAR\General|LastFolder
RegKey3=HKCU\Software\WinRAR\DialogEditHistory\Arcname
RegKey3=HKCU\Software\WinRAR\DialogEditHistory\Arcname
RegKey4=HKCU\Software\WinRAR\DialogEditHistory\ExtrPath
RegKey4=HKCU\Software\WinRAR\DialogEditHistory\ExtrPath
RegKey5=HKCU\Software\WinRAR\DialogEditHistory\FindArcNames
RegKey5=HKCU\Software\WinRAR\DialogEditHistory\FindArcNames
RegKey6=HKCU\Software\WinRAR\DialogEditHistory\FindNames
RegKey6=HKCU\Software\WinRAR\DialogEditHistory\FindNames
RegKey7=HKCU\Software\WinRAR\DialogEditHistory\FindText
RegKey7=HKCU\Software\WinRAR\DialogEditHistory\FindText
RegKey8=HKCU\Software\WinRAR\DialogEditHistory\ArcCmtName
RegKey8=HKCU\Software\WinRAR\DialogEditHistory\ArcCmtName
RegKey1=HKCU\Software\7-Zip\Compression\ArcHistory
RegKey1=HKCU\Software\7-Zip\Compression\ArcHistory
RegKey2=HKCU\Software\7-Zip\Extraction\PathHistory
RegKey2=HKCU\Software\7-Zip\Extraction\PathHistory
RegKey3=HKCU\Software\7-Zip\FM|CopyHistory
RegKey3=HKCU\Software\7-Zip\FM|CopyHistory
RegKey4=HKCU\Software\7-Zip\FM|FolderHistory
RegKey4=HKCU\Software\7-Zip\FM|FolderHistory
RegKey5=HKCU\Software\7-Zip\FM|PanelPath0
RegKey5=HKCU\Software\7-Zip\FM|PanelPath0
RegKey6=HKCU\Software\7-Zip\Compression|ArcHistory
RegKey6=HKCU\Software\7-Zip\Compression|ArcHistory
RegKey7=HKCU\Software\7-Zip\Extraction|PathHistory
RegKey7=HKCU\Software\7-Zip\Extraction|PathHistory
RegKey1=HKCU\Software\Bitberry\BitZipper\Open
RegKey1=HKCU\Software\Bitberry\BitZipper\Open
RegKey2=HKCU\Software\Bitberry\BitZipper\Preferences|ExtractLastFolder
RegKey2=HKCU\Software\Bitberry\BitZipper\Preferences|ExtractLastFolder
RegKey3=HKCU\Software\Bitberry\BitZipper\Preferences|AddLastFolder
RegKey3=HKCU\Software\Bitberry\BitZipper\Preferences|AddLastFolder
RegKey4=HKCU\Software\Bitberry\BitZipper\Preferences|NewLastFolder
RegKey4=HKCU\Software\Bitberry\BitZipper\Preferences|NewLastFolder
RegKey5=HKCU\Software\Bitberry\BitZipper\Preferences|OpenLastFolder
RegKey5=HKCU\Software\Bitberry\BitZipper\Preferences|OpenLastFolder
RegKey6=HKCU\Software\Bitberry\BitZipper\Preferences\FolderMRU
RegKey6=HKCU\Software\Bitberry\BitZipper\Preferences\FolderMRU
RegKey7=HKCU\Software\Bitberry\BitZipper\Preferences\FilterMRU
RegKey7=HKCU\Software\Bitberry\BitZipper\Preferences\FilterMRU
RegKey1=HKCU\Software\PowerArchiver\Files|Active_File1
RegKey1=HKCU\Software\PowerArchiver\Files|Active_File1
RegKey2=HKCU\Software\PowerArchiver\Files|Active_File2
RegKey2=HKCU\Software\PowerArchiver\Files|Active_File2
RegKey3=HKCU\Software\PowerArchiver\Files|Active_File3
RegKey3=HKCU\Software\PowerArchiver\Files|Active_File3
RegKey4=HKCU\Software\PowerArchiver\Files|Active_File4
RegKey4=HKCU\Software\PowerArchiver\Files|Active_File4
RegKey5=HKCU\Software\PowerArchiver\Files|Active_File5
RegKey5=HKCU\Software\PowerArchiver\Files|Active_File5
RegKey6=HKCU\Software\PowerArchiver\Files|Extract1
RegKey6=HKCU\Software\PowerArchiver\Files|Extract1
RegKey7=HKCU\Software\PowerArchiver\Files|Extract2
RegKey7=HKCU\Software\PowerArchiver\Files|Extract2
RegKey8=HKCU\Software\PowerArchiver\Files|Extract3
RegKey8=HKCU\Software\PowerArchiver\Files|Extract3
RegKey9=HKCU\Software\PowerArchiver\Files|Extract4
RegKey9=HKCU\Software\PowerArchiver\Files|Extract4
RegKey10=HKCU\Software\PowerArchiver\Files|Extract5
RegKey10=HKCU\Software\PowerArchiver\Files|Extract5
RegKey11=HKCU\Software\PowerArchiver\Files|Last open dir
RegKey11=HKCU\Software\PowerArchiver\Files|Last open dir
RegKey12=HKCU\Software\PowerArchiver\Files|Last backup dir
RegKey12=HKCU\Software\PowerArchiver\Files|Last backup dir
RegKey13=HKCU\Software\PowerArchiver\Files|Last add dir
RegKey13=HKCU\Software\PowerArchiver\Files|Last add dir
RegKey1=HKCU\Software\PowerArchiverInt\Files|Last open dirW
RegKey1=HKCU\Software\PowerArchiverInt\Files|Last open dirW
RegKey2=HKCU\Software\PowerArchiverInt\Files|Last backup dirW
RegKey2=HKCU\Software\PowerArchiverInt\Files|Last backup dirW
RegKey3=HKCU\Software\PowerArchiverInt\Files|Last add dirW
RegKey3=HKCU\Software\PowerArchiverInt\Files|Last add dirW
RegKey4=HKCU\Software\PowerArchiverInt\Files|Active_File1W
RegKey4=HKCU\Software\PowerArchiverInt\Files|Active_File1W
RegKey5=HKCU\Software\PowerArchiverInt\Files|Active_File2W
RegKey5=HKCU\Software\PowerArchiverInt\Files|Active_File2W
RegKey6=HKCU\Software\PowerArchiverInt\Files|Active_File3W
RegKey6=HKCU\Software\PowerArchiverInt\Files|Active_File3W
RegKey7=HKCU\Software\PowerArchiverInt\Files|Active_File4W
RegKey7=HKCU\Software\PowerArchiverInt\Files|Active_File4W
RegKey8=HKCU\Software\PowerArchiverInt\Files|Active_File5W
RegKey8=HKCU\Software\PowerArchiverInt\Files|Active_File5W
RegKey9=HKCU\Software\PowerArchiverInt\Files|Active_File6W
RegKey9=HKCU\Software\PowerArchiverInt\Files|Active_File6W
RegKey10=HKCU\Software\PowerArchiverInt\Files|Active_File7W
RegKey10=HKCU\Software\PowerArchiverInt\Files|Active_File7W
RegKey11=HKCU\Software\PowerArchiverInt\Files|Active_File8W
RegKey11=HKCU\Software\PowerArchiverInt\Files|Active_File8W
RegKey12=HKCU\Software\PowerArchiverInt\Files|Active_File9W
RegKey12=HKCU\Software\PowerArchiverInt\Files|Active_File9W
RegKey13=HKCU\Software\PowerArchiverInt\Files|Active_File10W
RegKey13=HKCU\Software\PowerArchiverInt\Files|Active_File10W
RegKey14=HKCU\Software\PowerArchiverInt\Files|Active_File11W
RegKey14=HKCU\Software\PowerArchiverInt\Files|Active_File11W
RegKey15=HKCU\Software\PowerArchiverInt\Files|Active_File12W
RegKey15=HKCU\Software\PowerArchiverInt\Files|Active_File12W
RegKey16=HKCU\Software\PowerArchiverInt\Files|Active_File13W
RegKey16=HKCU\Software\PowerArchiverInt\Files|Active_File13W
RegKey17=HKCU\Software\PowerArchiverInt\Files|Active_File14W
RegKey17=HKCU\Software\PowerArchiverInt\Files|Active_File14W
RegKey18=HKCU\Software\PowerArchiverInt\Files|Active_File15W
RegKey18=HKCU\Software\PowerArchiverInt\Files|Active_File15W
RegKey19=HKCU\Software\PowerArchiverInt\Files|Extract1W
RegKey19=HKCU\Software\PowerArchiverInt\Files|Extract1W
RegKey20=HKCU\Software\PowerArchiverInt\Files|Extract2W
RegKey20=HKCU\Software\PowerArchiverInt\Files|Extract2W
RegKey21=HKCU\Software\PowerArchiverInt\Files|Extract3W
RegKey21=HKCU\Software\PowerArchiverInt\Files|Extract3W
RegKey22=HKCU\Software\PowerArchiverInt\Files|Extract4W
RegKey22=HKCU\Software\PowerArchiverInt\Files|Extract4W
RegKey23=HKCU\Software\PowerArchiverInt\Files|Extract5W
RegKey23=HKCU\Software\PowerArchiverInt\Files|Extract5W
RegKey24=HKCU\Software\PowerArchiverInt\Files|Extract6W
RegKey24=HKCU\Software\PowerArchiverInt\Files|Extract6W
RegKey25=HKCU\Software\PowerArchiverInt\Files|Extract7W
RegKey25=HKCU\Software\PowerArchiverInt\Files|Extract7W
RegKey26=HKCU\Software\PowerArchiverInt\Files|Extract8W
RegKey26=HKCU\Software\PowerArchiverInt\Files|Extract8W
RegKey27=HKCU\Software\PowerArchiverInt\Files|Extract9W
RegKey27=HKCU\Software\PowerArchiverInt\Files|Extract9W
RegKey28=HKCU\Software\PowerArchiverInt\Files|Extract10W
RegKey28=HKCU\Software\PowerArchiverInt\Files|Extract10W
RegKey29=HKCU\Software\PowerArchiverInt\Files|SelDir1W
RegKey29=HKCU\Software\PowerArchiverInt\Files|SelDir1W
RegKey30=HKCU\Software\PowerArchiverInt\Files|SelDir2W
RegKey30=HKCU\Software\PowerArchiverInt\Files|SelDir2W
RegKey31=HKCU\Software\PowerArchiverInt\Files|SelDir3W
RegKey31=HKCU\Software\PowerArchiverInt\Files|SelDir3W
RegKey32=HKCU\Software\PowerArchiverInt\Files|SelDir4W
RegKey32=HKCU\Software\PowerArchiverInt\Files|SelDir4W
RegKey33=HKCU\Software\PowerArchiverInt\Files|SelDir5W
RegKey33=HKCU\Software\PowerArchiverInt\Files|SelDir5W
RegKey34=HKCU\Software\PowerArchiverInt\Files|BFile1W
RegKey34=HKCU\Software\PowerArchiverInt\Files|BFile1W
RegKey35=HKCU\Software\PowerArchiverInt\Files|BFile2W
RegKey35=HKCU\Software\PowerArchiverInt\Files|BFile2W
RegKey36=HKCU\Software\PowerArchiverInt\Files|BFile3W
RegKey36=HKCU\Software\PowerArchiverInt\Files|BFile3W
RegKey37=HKCU\Software\PowerArchiverInt\Files|BFile4W
RegKey37=HKCU\Software\PowerArchiverInt\Files|BFile4W
RegKey38=HKCU\Software\PowerArchiverInt\Files|BFile5W
RegKey38=HKCU\Software\PowerArchiverInt\Files|BFile5W
RegKey1=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Recent
RegKey1=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Recent
RegKey2=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Archive Manager\UnZip To
RegKey2=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Archive Manager\UnZip To
RegKey3=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\UnZip To
RegKey3=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\UnZip To
RegKey4=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Zip To
RegKey4=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Zip To
RegKey1=HKCU\Software\PicoZip\MRU Items
RegKey1=HKCU\Software\PicoZip\MRU Items
RegKey2=HKCU\Software\PicoZip\MRUExtract
RegKey2=HKCU\Software\PicoZip\MRUExtract
RegKey1=HKCU\Software\PKWARE\PKZIP70\History
RegKey1=HKCU\Software\PKWARE\PKZIP70\History
Detect3=HKLM\SOFTWARE\JavaSoft\Java Web Start
Detect3=HKLM\SOFTWARE\JavaSoft\Java Web Start
FileKey1=%AppData%\Sun\Java\Deployment\cache|*.*|RECURSE
FileKey1=%AppData%\Sun\Java\Deployment\cache|*.*|RECURSE
FileKey2=%AppData%\Sun\Java\Deployment\javaws\cache|*.*|RECURSE
FileKey2=%AppData%\Sun\Java\Deployment\javaws\cache|*.*|RECURSE
FileKey3=%AppData%\Sun\Java\Deployment\Log|*.*
FileKey3=%AppData%\Sun\Java\Deployment\Log|*.*
FileKey4=%AppData%\Sun\Java\Deployment\tmp|*.*|RECURSE
FileKey4=%AppData%\Sun\Java\Deployment\tmp|*.*|RECURSE
FileKey5=%LocalLowAppData%\Sun\Java\Deployment\cache|*.*|RECURSE
FileKey5=%LocalLowAppData%\Sun\Java\Deployment\cache|*.*|RECURSE
FileKey6=%LocalLowAppData%\Sun\Java\Deployment\Log|*.*
FileKey6=%LocalLowAppData%\Sun\Java\Deployment\Log|*.*
FileKey7=%WinDir%\System32|jupdate*.log
FileKey7=%WinDir%\System32|jupdate*.log
FileKey8=%WinDir%\SysWOW64|jupdate*.log
FileKey8=%WinDir%\SysWOW64|jupdate*.log
FileKey9=%AppData%\java\webview|*.*
FileKey9=%AppData%\java\webview|*.*
ExcludeKey1=FILE|%AppData%\java\webview\.lock
ExcludeKey1=FILE|%AppData%\java\webview\.lock
RegKey1=HKCU\Software\FreshDevices\FreshDownload\History
RegKey1=HKCU\Software\FreshDevices\FreshDownload\History
[Windows Movie Maker]
[Windows Movie Maker]
FileKey1=%localappdata%\Microsoft\Movie Maker|MEDIATAB0.DAT
FileKey1=%localappdata%\Microsoft\Movie Maker|MEDIATAB0.DAT
RegKey1=HKCU\Software\Helios\TextPad 4\Recent File List
RegKey1=HKCU\Software\Helios\TextPad 4\Recent File List
RegKey2=HKCU\Software\Helios\TextPad 4\Recent Strings
RegKey2=HKCU\Software\Helios\TextPad 4\Recent Strings
RegKey1=HKCU\Software\Freeware\VirtualDub\MRU List
RegKey1=HKCU\Software\Freeware\VirtualDub\MRU List
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit|LastKey
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit|LastKey
DetectFile2=%LocalAppData%\Microsoft\Windows\GameExplorer
DetectFile2=%LocalAppData%\Microsoft\Windows\GameExplorer
FileKey1=%LocalAppData%\Microsoft Games|*.xml.bak|RECURSE
FileKey1=%LocalAppData%\Microsoft Games|*.xml.bak|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\GameExplorer\GameStatistics|*.*|REMOVESELF
FileKey2=%LocalAppData%\Microsoft\Windows\GameExplorer\GameStatistics|*.*|REMOVESELF
FileKey3=%LocalAppData%\Microsoft\GFWLive|*.log|RECURSE
FileKey3=%LocalAppData%\Microsoft\GFWLive|*.log|RECURSE
RegKey1=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last URLs
RegKey1=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last URLs
RegKey2=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Projects
RegKey2=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Projects
RegKey3=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Open
RegKey3=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Open
RegKey4=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Files
RegKey4=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Files
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 120%\MountedMRU
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 120%\MountedMRU
RegKey2=HKCU\Software\Alcohol Soft\Alcohol 120%\Basic\Image Finder|Current Dir
RegKey2=HKCU\Software\Alcohol Soft\Alcohol 120%\Basic\Image Finder|Current Dir
RegKey3=HKCU\Software\Alcohol Soft\Alcohol 120%\Options\Burning Wizard|ImageFile
RegKey3=HKCU\Software\Alcohol Soft\Alcohol 120%\Options\Burning Wizard|ImageFile
FileKey1=%ProgramFiles%\Alcohol Soft\Alcohol 120|alcohol.log
FileKey1=%ProgramFiles%\Alcohol Soft\Alcohol 120|alcohol.log
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 52%\MountedMRU
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 52%\MountedMRU
RegKey2=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageFilePath
RegKey2=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageFilePath
RegKey3=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageFileName
RegKey3=HKCU\Software\Alcohol Soft\Alcohol 52%\Options\Image Making Wizard|ImageFileName
RegKey4=HKCU\Software\Alcohol Soft\Alcohol 52%\Basic\Image Finder|Current Dir
RegKey4=HKCU\Software\Alcohol Soft\Alcohol 52%\Basic\Image Finder|Current Dir
RegKey1=HKCU\Software\Cronosoft\LeechGet\History
RegKey1=HKCU\Software\Cronosoft\LeechGet\History
RegKey1=HKCU\Software\Headlight\GetRight\MRU
RegKey1=HKCU\Software\Headlight\GetRight\MRU
RegKey2=HKCU\Software\Headlight\GetRight\TypedURLS
RegKey2=HKCU\Software\Headlight\GetRight\TypedURLS
RegKey3=HKCU\Software\Headlight\GetRight\Recent File List
RegKey3=HKCU\Software\Headlight\GetRight\Recent File List
FileKey1=%ProgramFiles%\GetRight|GetRight.hst
FileKey1=%ProgramFiles%\GetRight|GetRight.hst
DetectFile=%CommonAppData%\Speedbit\DAP
DetectFile=%CommonAppData%\Speedbit\DAP
RegKey1=HKLM\SOFTWARE\SpeedBit\Download Accelerator\FileList
RegKey1=HKLM\SOFTWARE\SpeedBit\Download Accelerator\FileList
RegKey2=HKCU\Software\SpeedBit\Download Accelerator\HistoryCombo
RegKey2=HKCU\Software\SpeedBit\Download Accelerator\HistoryCombo
RegKey3=HKCU\Software\SpeedBit\Download Accelerator\ADS\SecondMedia
RegKey3=HKCU\Software\SpeedBit\Download Accelerator\ADS\SecondMedia
FileKey1=%ProgramFiles%\DAP\Temp|*.*
FileKey1=%ProgramFiles%\DAP\Temp|*.*
FileKey2=%ProgramFiles%\DAP\Ads|*.*
FileKey2=%ProgramFiles%\DAP\Ads|*.*
FileKey3=%ProgramFiles%\DAP\Log|*.*
FileKey3=%ProgramFiles%\DAP\Log|*.*
FileKey4=%CommonAppData%\Speedbit\DAP\Log|*.*
FileKey4=%CommonAppData%\Speedbit\DAP\Log|*.*
FileKey5=%CommonAppData%\Speedbit\DAP\temp|*.tmp
FileKey5=%CommonAppData%\Speedbit\DAP\temp|*.tmp
FileKey6=%CommonAppData%\Speedbit\DAP\History|*.dat|RECURSE
FileKey6=%CommonAppData%\Speedbit\DAP\History|*.dat|RECURSE
DetectFile=%ProgramFiles%\Free Download Manager\fdm.exe
DetectFile=%ProgramFiles%\Free Download Manager\fdm.exe
RegKey1=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings|Find
RegKey1=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings|Find
RegKey2=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings|History
RegKey2=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings|History
FileKey1=%AppData%\Free Download Manager|*.bak;dlmgrsi.sav;downloads.his.sav;history.sav;spider.sav
FileKey1=%AppData%\Free Download Manager|*.bak;dlmgrsi.sav;downloads.his.sav;history.sav;spider.sav
FileKey1=%AppData%\Internet Download Accelerator|history.xml
FileKey1=%AppData%\Internet Download Accelerator|history.xml
FileKey2=%AppData%\Internet Download Accelerator\temp|*.hnt;lastnews.*;playflv.html
FileKey2=%AppData%\Internet Download Accelerator\temp|*.hnt;lastnews.*;playflv.html
FileKey3=%AppData%\Internet Download Accelerator\temp\Preview|*.*
FileKey3=%AppData%\Internet Download Accelerator\temp\Preview|*.*
FileKey4=%AppData%\Internet Download Accelerator\lists|default.xml
FileKey4=%AppData%\Internet Download Accelerator\lists|default.xml
FileKey1=%AppData%\IDM|UrlHistory*.txt;foldresHistory.txt
FileKey1=%AppData%\IDM|UrlHistory*.txt;foldresHistory.txt
FileKey2=%AppData%\IDM\DwnlData\*|Log.log
FileKey2=%AppData%\IDM\DwnlData\*|Log.log
FileKey3=%CommonAppData%\IDM\Cache|*.*
FileKey3=%CommonAppData%\IDM\Cache|*.*
FileKey4=%AppData%\IDM\Grabber\Projects|project*.bak
FileKey4=%AppData%\IDM\Grabber\Projects|project*.bak
FileKey1=%AppData%\Orbit|fileinfo.dat;filesave.dat
FileKey1=%AppData%\Orbit|fileinfo.dat;filesave.dat
RegKey1=HKCU\Software\Morpheus\Morpheus\Recent File List
RegKey1=HKCU\Software\Morpheus\Morpheus\Recent File List
RegKey1=HKCU\Software\ORL\VNCviewer\MRU
RegKey1=HKCU\Software\ORL\VNCviewer\MRU
RegKey1=HKCU\Software\RealVNC\VNCviewer4\MRU
RegKey1=HKCU\Software\RealVNC\VNCviewer4\MRU
RegKey1=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent Targets
RegKey1=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent Targets
RegKey2=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent File List
RegKey2=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent File List
RegKey3=HKCU\Software\DVD Shrink\DVDSHRINK103\TargetFiles
RegKey3=HKCU\Software\DVD Shrink\DVDSHRINK103\TargetFiles
RegKey4=HKCU\Software\DVD Shrink\DVDSHRINK103\SourceFolders
RegKey4=HKCU\Software\DVD Shrink\DVDSHRINK103\SourceFolders
FileKey1=%localappdata%\TiVo Desktop\Cache|*.*
FileKey1=%localappdata%\TiVo Desktop\Cache|*.*
FileKey1=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|*.log;*log.txt
FileKey1=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|*.log;*log.txt
FileKey2=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ArcTemp|*.tmp
FileKey2=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ArcTemp|*.tmp
FileKey3=%CommonAppData%\CA\Consumer\AV|*.tmp;*.txt|RECURSE
FileKey3=%CommonAppData%\CA\Consumer\AV|*.tmp;*.txt|RECURSE
FileKey4=%CommonAppData%\CA\Consumer\CCube|*.tmp;*.txt|RECURSE
FileKey4=%CommonAppData%\CA\Consumer\CCube|*.tmp;*.txt|RECURSE
FileKey5=%CommonAppData%\CA\Consumer\ISS\FeedStore|*.txt|RECURSE
FileKey5=%CommonAppData%\CA\Consumer\ISS\FeedStore|*.txt|RECURSE
FileKey6=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\ArcTemp|*.*
FileKey6=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\ArcTemp|*.*
FileKey7=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\tmp|*.*
FileKey7=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\tmp|*.*
FileKey1=%windir%\Internet Logs|ZALog*.*
FileKey1=%windir%\Internet Logs|ZALog*.*
RegKey1=HKCU\Software\Google\Google Earth Plus\Search
RegKey1=HKCU\Software\Google\Google Earth Plus\Search
RegKey2=HKCU\Software\Google\Google Earth Pro\Search
RegKey2=HKCU\Software\Google\Google Earth Pro\Search
FileKey1=%AppData%\Google\GoogleEarth|dbcache.dat
FileKey1=%AppData%\Google\GoogleEarth|dbcache.dat
FileKey2=%AppData%\Google\GoogleEarth|dbcache.dat.index
FileKey2=%AppData%\Google\GoogleEarth|dbcache.dat.index
FileKey3=%LocalAppData%\Google\GoogleEarth|dbcache.dat
FileKey3=%LocalAppData%\Google\GoogleEarth|dbcache.dat
FileKey4=%localappdata%\Google\GoogleEarth|dbcache.dat.index
FileKey4=%localappdata%\Google\GoogleEarth|dbcache.dat.index
FileKey5=%LocalLowAppData%\Google\GoogleEarth|dbcache.dat
FileKey5=%LocalLowAppData%\Google\GoogleEarth|dbcache.dat
FileKey6=%LocalLowAppData%\Google\GoogleEarth|dbcache.dat.index
FileKey6=%LocalLowAppData%\Google\GoogleEarth|dbcache.dat.index
FileKey7=%LocalLowAppData%\Google\GoogleEarth\webdata|*.*
FileKey7=%LocalLowAppData%\Google\GoogleEarth\webdata|*.*
FileKey8=%LocalLowAppData%\Google\GoogleEarth\unified_cache_leveldb_*|*.*
FileKey8=%LocalLowAppData%\Google\GoogleEarth\unified_cache_leveldb_*|*.*
FileKey1=%commonappdata%\Raxco\PerfectDisk\7.0|PerfectDisk.log
FileKey1=%commonappdata%\Raxco\PerfectDisk\7.0|PerfectDisk.log
FileKey1=%AppData%\Daemon Tools lite\iconscache|*.*
FileKey1=%AppData%\Daemon Tools lite\iconscache|*.*
FileKey2=%AppData%\DAEMON Tools Lite|imagecatalog.xml
FileKey2=%AppData%\DAEMON Tools Lite|imagecatalog.xml
FileKey3=%AppData%\DAEMON Tools|imagecatalog.xml
FileKey3=%AppData%\DAEMON Tools|imagecatalog.xml
FileKey4=%AppData%\DAEMON Tools Pro|imagecatalog.xml
FileKey4=%AppData%\DAEMON Tools Pro|imagecatalog.xml
DetectFile=%AppData%\Azureus\.lock
DetectFile=%AppData%\Azureus\.lock
FileKey1=%AppData%\Azureus\logs|*.*|RECURSE
FileKey1=%AppData%\Azureus\logs|*.*|RECURSE
FileKey2=%AppData%\Azureus\logs\save|*.log
FileKey2=%AppData%\Azureus\logs\save|*.log
FileKey3=%AppData%\Azureus\tmp|*.*|RECURSE
FileKey3=%AppData%\Azureus\tmp|*.*|RECURSE
FileKey4=%AppData%\Azureus|*.bak;*.log
FileKey4=%AppData%\Azureus|*.bak;*.log
FileKey5=%AppData%\Azureus\active|*.bak
FileKey5=%AppData%\Azureus\active|*.bak
DetectFile=%ProgramFiles%\BitTorrent\BitTorrent.exe
DetectFile=%ProgramFiles%\BitTorrent\BitTorrent.exe
FileKey1=%appdata%\BitTorrent|*.old
FileKey1=%appdata%\BitTorrent|*.old
DetectFile=%ProgramFiles%\FrostWire\FrostWire.exe
DetectFile=%ProgramFiles%\FrostWire\FrostWire.exe
FileKey1=%AppData%\FrostWire|*.cache;*.bak;gnutella.net;checkandupdate.txt
FileKey1=%AppData%\FrostWire|*.cache;*.bak;gnutella.net;checkandupdate.txt
FileKey2=%AppData%\FrostWire\image_cache|*.*|REMOVESELF
FileKey2=%AppData%\FrostWire\image_cache|*.*|REMOVESELF
DetectFile=%ProgramFiles%\uTorrent\uTorrent.exe
DetectFile=%ProgramFiles%\uTorrent\uTorrent.exe
FileKey1=%ProgramFiles%\uTorrent|*.dmp
FileKey1=%ProgramFiles%\uTorrent|*.dmp
FileKey2=%AppData%\utorrent|*.old
FileKey2=%AppData%\utorrent|*.old
FileKey3=%AppData%\utorrent\dlimagecache|*.*|RECURSE
FileKey3=%AppData%\utorrent\dlimagecache|*.*|RECURSE
FileKey4=%AppData%\uTorrent\ie|*.tmp
FileKey4=%AppData%\uTorrent\ie|*.tmp
FileKey5=%LocalLowAppData%\uTorrentBar\CacheIcons|*.*
FileKey5=%LocalLowAppData%\uTorrentBar\CacheIcons|*.*
DetectFile=%ProgramFiles%\Shareaza Applications\Shareaza\Shareaza.exe
DetectFile=%ProgramFiles%\Shareaza Applications\Shareaza\Shareaza.exe
FileKey1=%LocalAppData%\Shareaza\Temp|*.*
FileKey1=%LocalAppData%\Shareaza\Temp|*.*
FileKey2=%LocalAppData%\Shareaza|shistory.im
FileKey2=%LocalAppData%\Shareaza|shistory.im
FileKey3=%LocalAppData%\Shareaza\Artwork|*.*
FileKey3=%LocalAppData%\Shareaza\Artwork|*.*
DetectFile=%ProgramFiles%\iMesh Applications\iMesh\iMesh.exe
DetectFile=%ProgramFiles%\iMesh Applications\iMesh\iMesh.exe
FileKey1=%LocalAppData%\iMesh\Temp|*.*
FileKey1=%LocalAppData%\iMesh\Temp|*.*
FileKey2=%LocalAppData%\iMesh|shistory.im
FileKey2=%LocalAppData%\iMesh|shistory.im
FileKey3=%LocalAppData%\iMesh\Artwork|*.*
FileKey3=%LocalAppData%\iMesh\Artwork|*.*
DetectFile=%ProgramFiles%\BearShare Applications\BearShare\BearShare.exe
DetectFile=%ProgramFiles%\BearShare Applications\BearShare\BearShare.exe
FileKey1=%LocalAppData%\BearShare\Temp|*.*
FileKey1=%LocalAppData%\BearShare\Temp|*.*
FileKey2=%LocalAppData%\BearShare|shistory.im
FileKey2=%LocalAppData%\BearShare|shistory.im
FileKey3=%LocalAppData%\BearShare\Artwork|*.*
FileKey3=%LocalAppData%\BearShare\Artwork|*.*
DetectFile=%ProgramFiles%\DC \DCPlusPlus.exe
DetectFile=%ProgramFiles%\DC \DCPlusPlus.exe
FileKey1=%ProgramFiles%\DC |files.xml.bz2
FileKey1=%ProgramFiles%\DC |files.xml.bz2
FileKey2=%ProgramFiles%\DC \FileLists|*.*
FileKey2=%ProgramFiles%\DC \FileLists|*.*
FileKey3=%ProgramFiles%\DC \Logs|*.*
FileKey3=%ProgramFiles%\DC \Logs|*.*
FileKey4=%LocalAppData%\DC |files.xml.bz2
FileKey4=%LocalAppData%\DC |files.xml.bz2
FileKey5=%LocalAppData%\DC \FileLists|*.*
FileKey5=%LocalAppData%\DC \FileLists|*.*
FileKey6=%LocalAppData%\DC \Logs|*.*
FileKey6=%LocalAppData%\DC \Logs|*.*
DetectFile=%ProgramFiles%\Ares\Ares.exe
DetectFile=%ProgramFiles%\Ares\Ares.exe
Regkey1=HKCU\Software\Ares\Search.History
Regkey1=HKCU\Software\Ares\Search.History
[CuteFTP Pro 7.0]
[CuteFTP Pro 7.0]
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Professional
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Professional
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\Cache|*.*|RECURSE
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\CacheThumbs|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\CacheThumbs|*.*|RECURSE
[CuteFTP Home 7.0]
[CuteFTP Home 7.0]
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Home
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Home
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\7.0\Cache|*.*|RECURSE
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\7.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\7.0\CacheThumbs|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\7.0\CacheThumbs|*.*|RECURSE
[CuteFTP Pro 8.0]
[CuteFTP Pro 8.0]
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Professional
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Professional
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\Cache|*.*|RECURSE
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\CacheThumbs|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\CacheThumbs|*.*|RECURSE
[CuteFTP Home 8.0]
[CuteFTP Home 8.0]
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Home
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Home
RegKey1=HKCU\Software\GlobalSCAPE\CuteFTP 8 Home\Recent|LastSiteID
RegKey1=HKCU\Software\GlobalSCAPE\CuteFTP 8 Home\Recent|LastSiteID
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Home\8.0\Cache|*.*|RECURSE
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Home\8.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Home\8.0\CacheThumbs|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Home\8.0\CacheThumbs|*.*|RECURSE
FileKey3=%AppData%\GlobalSCAPE\CuteFTP Home\8.0|*.log|RECURSE
FileKey3=%AppData%\GlobalSCAPE\CuteFTP Home\8.0|*.log|RECURSE
[CuteFTP 9]
[CuteFTP 9]
Detect=HKU\.DEFAULT\Software\Globalscape\CuteFTP 9
Detect=HKU\.DEFAULT\Software\Globalscape\CuteFTP 9
Detect2=HKLM\SOFTWARE\Wow6432Node\Globalscape\CuteFTP 9
Detect2=HKLM\SOFTWARE\Wow6432Node\Globalscape\CuteFTP 9
RegKey1=HKCU\Software\Globalscape\CuteFTP 9\Recent|LastSiteID
RegKey1=HKCU\Software\Globalscape\CuteFTP 9\Recent|LastSiteID
FileKey1=%LocalAppData%\Globalscape\CuteFTP\9.0\Cache|*.*
FileKey1=%LocalAppData%\Globalscape\CuteFTP\9.0\Cache|*.*
FileKey2=%LocalAppData%\Globalscape\CuteFTP\9.0\CacheThumbs|*.*
FileKey2=%LocalAppData%\Globalscape\CuteFTP\9.0\CacheThumbs|*.*
FileKey3=%AppData%\Globalscape\CuteFTP\9.0\Logs|*-*_*.log
FileKey3=%AppData%\Globalscape\CuteFTP\9.0\Logs|*-*_*.log
FileKey4=%CommonAppData%\Globalscape\CuteFTP 9|TRB_BACKUP.dat;TR_BACKUP.dat
FileKey4=%CommonAppData%\Globalscape\CuteFTP 9|TRB_BACKUP.dat;TR_BACKUP.dat
[Core FTP]
[Core FTP]
Detect=HKCU\Software\FTPWare
Detect=HKCU\Software\FTPWare
FileKey1=%AppData%\CoreFTP|*.dir
FileKey1=%AppData%\CoreFTP|*.dir
FileKey2=%ProgramFiles%\CoreFTP|COREFTP.LOG
FileKey2=%ProgramFiles%\CoreFTP|COREFTP.LOG
FileKey1=%AppData%\FileZilla|recentservers.xml;search.xml
FileKey1=%AppData%\FileZilla|recentservers.xml;search.xml
[SmartFTP]
[SmartFTP]
Detect=HKCU\Software\SmartFTP
Detect=HKCU\Software\SmartFTP
RegKey1=HKCU\Software\SmartFTP\Client 2.0\Settings\History\Items
RegKey1=HKCU\Software\SmartFTP\Client 2.0\Settings\History\Items
FileKey1=%AppData%\SmartFTP\Client 2.0\Log|*.*|RECURSE
FileKey1=%AppData%\SmartFTP\Client 2.0\Log|*.*|RECURSE
FileKey2=%AppData%\SmartFTP\Client 2.0\Storage|*.*
FileKey2=%AppData%\SmartFTP\Client 2.0\Storage|*.*
FileKey1=%allusersprofile%\.clamwin\log|*.*
FileKey1=%allusersprofile%\.clamwin\log|*.*
FileKey2=%userprofile%\.clamwin\log|*.*
FileKey2=%userprofile%\.clamwin\log|*.*
FileKey3=%windir%\All Users\.clamwin\log|*.*
FileKey3=%windir%\All Users\.clamwin\log|*.*
FileKey1=%ProgramFiles%\Ewido\Security Suite|logfile.txt
FileKey1=%ProgramFiles%\Ewido\Security Suite|logfile.txt
FileKey2=%ProgramFiles%\Ewido Anti-Malware|logfile.txt
FileKey2=%ProgramFiles%\Ewido Anti-Malware|logfile.txt
FileKey1=%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5|logfile.txt
FileKey1=%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5|logfile.txt
DetectFile1=%ProgramFiles%\Malwarebytes' Anti-Malware\mbam.exe
DetectFile1=%ProgramFiles%\Malwarebytes' Anti-Malware\mbam.exe
DetectFile2=%ProgramFiles%\Malwarebytes Anti-Malware\mbam.exe
DetectFile2=%ProgramFiles%\Malwarebytes Anti-Malware\mbam.exe
FileKey1=%appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Logs|*.txt
FileKey1=%appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Logs|*.txt
FileKey2=%appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine|*.*
FileKey2=%appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine|*.*
FileKey3=%CommonAppData%\Malwarebytes\Malwarebytes Anti-Malware\Logs|*.xml
FileKey3=%CommonAppData%\Malwarebytes\Malwarebytes Anti-Malware\Logs|*.xml
FileKey4=%CommonAppData%\Malwarebytes\Malwarebytes Anti-Malware\Quarantine|*.*
FileKey4=%CommonAppData%\Malwarebytes\Malwarebytes Anti-Malware\Quarantine|*.*
FileKey1=%ProgramFiles%\Spyware Terminator\update|*.*
FileKey1=%ProgramFiles%\Spyware Terminator\update|*.*
FileKey2=%AppData%\Spyware Terminator\Reports|*.*
FileKey2=%AppData%\Spyware Terminator\Reports|*.*
Detect=HKLM\Software\SUPERAntiSpyware.com\SUPERAntiSpyware
Detect=HKLM\Software\SUPERAntiSpyware.com\SUPERAntiSpyware
FileKey1=%AppData%\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs|*.log
FileKey1=%AppData%\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs|*.log
FileKey2=%AppData%\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs|*.dmp;*.SDB
FileKey2=%AppData%\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs|*.dmp;*.SDB
FileKey1=%MyDocuments%\a-squared Free\Reports|*.txt
FileKey1=%MyDocuments%\a-squared Free\Reports|*.txt
RegKey1=HKCU\Software\Foxit Software\Foxit Reader\Recent File List
RegKey1=HKCU\Software\Foxit Software\Foxit Reader\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit Reader\History
RegKey2=HKCU\Software\Foxit Software\Foxit Reader\History
RegKey1=HKCU\Software\Foxit Software\Foxit Reader 6.0\Recent File List
RegKey1=HKCU\Software\Foxit Software\Foxit Reader 6.0\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit Reader 6.0\RecentFiles
RegKey2=HKCU\Software\Foxit Software\Foxit Reader 6.0\RecentFiles
RegKey3=HKCU\Software\Foxit Software\Foxit Reader 6.0\Preferences\History\LastOpen
RegKey3=HKCU\Software\Foxit Software\Foxit Reader 6.0\Preferences\History\LastOpen
RegKey4=HKCU\Software\Foxit Software\Foxit Reader 6.0\Preferences\History\LastSession
RegKey4=HKCU\Software\Foxit Software\Foxit Reader 6.0\Preferences\History\LastSession
RegKey5=HKCU\Software\Foxit Software\Foxit Reader 6.0\Preferences\Others|csInitialOpenDir
RegKey5=HKCU\Software\Foxit Software\Foxit Reader 6.0\Preferences\Others|csInitialOpenDir
RegKey6=HKCU\Software\Foxit Software\Foxit Reader 6.0\ImageTool|ImageDefPath
RegKey6=HKCU\Software\Foxit Software\Foxit Reader 6.0\ImageTool|ImageDefPath
FileKey1=%LocalAppData%\Foxit Reader\|*_old.DMP
FileKey1=%LocalAppData%\Foxit Reader\|*_old.DMP
FileKey2=%AppData%\Foxit Software\Foxit Reader\Foxit Cloud\DownloadCache|*.cache
FileKey2=%AppData%\Foxit Software\Foxit Reader\Foxit Cloud\DownloadCache|*.cache
FileKey3=%AppData%\Foxit Software\Foxit Reader\Foxit Cloud\FileIDCache|*.ids
FileKey3=%AppData%\Foxit Software\Foxit Reader\Foxit Cloud\FileIDCache|*.ids
FileKey4=%AppData%\Foxit Software\Foxit Reader\Foxit Cloud|foxitcloud.log
FileKey4=%AppData%\Foxit Software\Foxit Reader\Foxit Cloud|foxitcloud.log
RegKey1=HKCU\Software\Foxit Software\Foxit Reader 7.0\Recent File List
RegKey1=HKCU\Software\Foxit Software\Foxit Reader 7.0\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit Reader 7.0\RecentFiles
RegKey2=HKCU\Software\Foxit Software\Foxit Reader 7.0\RecentFiles
RegKey3=HKCU\Software\Foxit Software\Foxit Reader 7.0\Preferences\History\LastOpen
RegKey3=HKCU\Software\Foxit Software\Foxit Reader 7.0\Preferences\History\LastOpen
RegKey4=HKCU\Software\Foxit Software\Foxit Reader 7.0\Preferences\History\LastSession
RegKey4=HKCU\Software\Foxit Software\Foxit Reader 7.0\Preferences\History\LastSession
RegKey5=HKCU\Software\Foxit Software\Foxit Reader 7.0\Preferences\Others|csInitialOpenDir
RegKey5=HKCU\Software\Foxit Software\Foxit Reader 7.0\Preferences\Others|csInitialOpenDir
RegKey6=HKCU\Software\Foxit Software\Foxit Reader 7.0\ImageTool|ImageDefPath
RegKey6=HKCU\Software\Foxit Software\Foxit Reader 7.0\ImageTool|ImageDefPath
FileKey3=%AppData%\Foxit Software\Foxit Reader\Foxit Cloud\FileIDCache|*.fcd
FileKey3=%AppData%\Foxit Software\Foxit Reader\Foxit Cloud\FileIDCache|*.fcd
[Paint.NET]
[Paint.NET]
Detect=HKCU\Software\Paint.NET
Detect=HKCU\Software\Paint.NET
RegKey1=HKCU\Software\Paint.NET|MRU0
RegKey1=HKCU\Software\Paint.NET|MRU0
RegKey2=HKCU\Software\Paint.NET|MRU1
RegKey2=HKCU\Software\Paint.NET|MRU1
RegKey3=HKCU\Software\Paint.NET|MRU2
RegKey3=HKCU\Software\Paint.NET|MRU2
RegKey4=HKCU\Software\Paint.NET|MRU3
RegKey4=HKCU\Software\Paint.NET|MRU3
RegKey5=HKCU\Software\Paint.NET|MRU4
RegKey5=HKCU\Software\Paint.NET|MRU4
RegKey6=HKCU\Software\Paint.NET|MRU5
RegKey6=HKCU\Software\Paint.NET|MRU5
RegKey7=HKCU\Software\Paint.NET|MRU6
RegKey7=HKCU\Software\Paint.NET|MRU6
RegKey8=HKCU\Software\Paint.NET|MRU7
RegKey8=HKCU\Software\Paint.NET|MRU7
RegKey9=HKCU\Software\Paint.NET|MRU0Thumb
RegKey9=HKCU\Software\Paint.NET|MRU0Thumb
RegKey10=HKCU\Software\Paint.NET|MRU1Thumb
RegKey10=HKCU\Software\Paint.NET|MRU1Thumb
RegKey11=HKCU\Software\Paint.NET|MRU2Thumb
RegKey11=HKCU\Software\Paint.NET|MRU2Thumb
RegKey12=HKCU\Software\Paint.NET|MRU3Thumb
RegKey12=HKCU\Software\Paint.NET|MRU3Thumb
RegKey13=HKCU\Software\Paint.NET|MRU4Thumb
RegKey13=HKCU\Software\Paint.NET|MRU4Thumb
RegKey14=HKCU\Software\Paint.NET|MRU5Thumb
RegKey14=HKCU\Software\Paint.NET|MRU5Thumb
RegKey15=HKCU\Software\Paint.NET|MRU6Thumb
RegKey15=HKCU\Software\Paint.NET|MRU6Thumb
RegKey16=HKCU\Software\Paint.NET|MRU7Thumb
RegKey16=HKCU\Software\Paint.NET|MRU7Thumb
RegKey17=HKCU\Software\Paint.NET|File/MostRecent/Path0
RegKey17=HKCU\Software\Paint.NET|File/MostRecent/Path0
RegKey18=HKCU\Software\Paint.NET|File/MostRecent/Path1
RegKey18=HKCU\Software\Paint.NET|File/MostRecent/Path1
RegKey19=HKCU\Software\Paint.NET|File/MostRecent/Path2
RegKey19=HKCU\Software\Paint.NET|File/MostRecent/Path2
RegKey20=HKCU\Software\Paint.NET|File/MostRecent/Path3
RegKey20=HKCU\Software\Paint.NET|File/MostRecent/Path3
RegKey21=HKCU\Software\Paint.NET|File/MostRecent/Path4
RegKey21=HKCU\Software\Paint.NET|File/MostRecent/Path4
RegKey22=HKCU\Software\Paint.NET|File/MostRecent/Path5
RegKey22=HKCU\Software\Paint.NET|File/MostRecent/Path5
RegKey23=HKCU\Software\Paint.NET|File/MostRecent/Path6
RegKey23=HKCU\Software\Paint.NET|File/MostRecent/Path6
RegKey24=HKCU\Software\Paint.NET|File/MostRecent/Path7
RegKey24=HKCU\Software\Paint.NET|File/MostRecent/Path7
RegKey25=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail0
RegKey25=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail0
RegKey26=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail1
RegKey26=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail1
RegKey27=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail2
RegKey27=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail2
RegKey28=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail3
RegKey28=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail3
RegKey29=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail4
RegKey29=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail4
RegKey30=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail5
RegKey30=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail5
RegKey31=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail6
RegKey31=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail6
RegKey32=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail7
RegKey32=HKCU\Software\Paint.NET|File/MostRecent/Thumbnail7
DetectFile=%ProgramFiles%\OpenOffice.org1.1.4\program\soffice.exe
DetectFile=%ProgramFiles%\OpenOffice.org1.1.4\program\soffice.exe
FileKey1=%ProgramFiles%\OpenOffice.org1.1.4\user\registry\data\org\openoffice\Office|Common.xcu
FileKey1=%ProgramFiles%\OpenOffice.org1.1.4\user\registry\data\org\openoffice\Office|Common.xcu
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.0
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.0
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.1
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.1
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.0
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.0
Detect2=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.1
Detect2=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.1
Detect3=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.2
Detect3=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.2
Detect4=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.0
Detect4=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.0
Detect5=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.1
Detect5=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.1
Detect6=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.2
Detect6=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.2
Detect7=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.3
Detect7=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.3
Detect8=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.3
Detect8=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.3
FileKey1=%appdata%\OpenOffice.org\3\user\registry\data\org\openoffice\Office|Histories.xcu
FileKey1=%appdata%\OpenOffice.org\3\user\registry\data\org\openoffice\Office|Histories.xcu
Detect=HKLM\SOFTWARE\Wow6432Node\OpenOffice\OpenOffice\4.0.0
Detect=HKLM\SOFTWARE\Wow6432Node\OpenOffice\OpenOffice\4.0.0
Detect2=HKLM\SOFTWARE\OpenOffice\OpenOffice\4.0.0
Detect2=HKLM\SOFTWARE\OpenOffice\OpenOffice\4.0.0
FileKey1=%AppData%\OpenOffice\4\user\backup|*.ubackup
FileKey1=%AppData%\OpenOffice\4\user\backup|*.ubackup
FileKey2=%AppData%\OpenOffice\4\user\temp|document_io_logring.txt
FileKey2=%AppData%\OpenOffice\4\user\temp|document_io_logring.txt
FileKey3=%AppData%\OpenOffice\4\user\uno_packages\cache|log.txt;*.cache
FileKey3=%AppData%\OpenOffice\4\user\uno_packages\cache|log.txt;*.cache
FileKey4=%ProgramFiles%\OpenOffice 4\presets\backup|*.cbackup
FileKey4=%ProgramFiles%\OpenOffice 4\presets\backup|*.cbackup
FileKey5=%ProgramFiles%\OpenOffice 4\presets\temp|*.tmp
FileKey5=%ProgramFiles%\OpenOffice 4\presets\temp|*.tmp
FileKey6=%ProgramFiles%\OpenOffice 4\presets\uno_packages\cache|log.txt
FileKey6=%ProgramFiles%\OpenOffice 4\presets\uno_packages\cache|log.txt
FileKey1=%commonappdata%\Grisoft\Avg7Data|*.log
FileKey1=%commonappdata%\Grisoft\Avg7Data|*.log
FileKey2=%commonappdata%\Grisoft\Avg7Data\upd7bin|*.*
FileKey2=%commonappdata%\Grisoft\Avg7Data\upd7bin|*.*
FileKey3=%commonappdata%\Grisoft\Avg7Data\$history|*.*
FileKey3=%commonappdata%\Grisoft\Avg7Data\$history|*.*
FileKey4=%commonappdata%\Grisoft\Avg7Data\avg7upd|*.log
FileKey4=%commonappdata%\Grisoft\Avg7Data\avg7upd|*.log
FileKey5=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|*.*
FileKey5=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|*.*
FileKey6=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey6=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey7=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|*.log
FileKey7=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|*.log
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|*.log
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|*.log
FileKey9=%windir%\Application Data\AVG7\Log|*.log
FileKey9=%windir%\Application Data\AVG7\Log|*.log
FileKey1=%CommonAppData%\avg8\Log|*.log;*.xml
FileKey1=%CommonAppData%\avg8\Log|*.log;*.xml
FileKey2=%CommonAppData%\avg8\scanlogs|*.log
FileKey2=%CommonAppData%\avg8\scanlogs|*.log
FileKey3=%CommonAppData%\avg8\update\backup|*.*
FileKey3=%CommonAppData%\avg8\update\backup|*.*
FileKey4=%CommonAppData%\avg8\Emc\Log|*.log
FileKey4=%CommonAppData%\avg8\Emc\Log|*.log
FileKey1=%CommonAppData%\avg9\Log|*.log;*.xml
FileKey1=%CommonAppData%\avg9\Log|*.log;*.xml
FileKey2=%CommonAppData%\avg9\scanlogs|*.log
FileKey2=%CommonAppData%\avg9\scanlogs|*.log
FileKey3=%CommonAppData%\avg9\update\backup|*.*
FileKey3=%CommonAppData%\avg9\update\backup|*.*
FileKey4=%CommonAppData%\avg9\Emc\Log|*.log
FileKey4=%CommonAppData%\avg9\Emc\Log|*.log
FileKey1=%CommonAppData%\avg10\Log|*.log;*.xml
FileKey1=%CommonAppData%\avg10\Log|*.log;*.xml
FileKey2=%CommonAppData%\avg10\scanlogs|*.log
FileKey2=%CommonAppData%\avg10\scanlogs|*.log
FileKey3=%CommonAppData%\avg10\update\backup|*.*
FileKey3=%CommonAppData%\avg10\update\backup|*.*
FileKey4=%CommonAppData%\avg10\Emc\Log|*.log
FileKey4=%CommonAppData%\avg10\Emc\Log|*.log
FileKey5=%CommonAppData%\avg10\IDS\config|*List.zip.bak
FileKey5=%CommonAppData%\avg10\IDS\config|*List.zip.bak
FileKey6=%CommonAppData%\avg10\IDS\profile|globalLoadable.bak
FileKey6=%CommonAppData%\avg10\IDS\profile|globalLoadable.bak
FileKey7=%CommonAppData%\avg10\Temp|*.tmp
FileKey7=%CommonAppData%\avg10\Temp|*.tmp
FileKey1=%CommonAppData%\AVG2012\Log|*.log;history.xml
FileKey1=%CommonAppData%\AVG2012\Log|*.log;history.xml
FileKey2=%CommonAppData%\AVG2012\scanlogs|*.log
FileKey2=%CommonAppData%\AVG2012\scanlogs|*.log
FileKey3=%CommonAppData%\AVG2012\update\backup|*.*
FileKey3=%CommonAppData%\AVG2012\update\backup|*.*
FileKey4=%CommonAppData%\AVG2012\Emc\Log|*.log
FileKey4=%CommonAppData%\AVG2012\Emc\Log|*.log
FileKey5=%CommonAppData%\AVG2012\IDS\config|*List.zip.bak
FileKey5=%CommonAppData%\AVG2012\IDS\config|*List.zip.bak
FileKey6=%CommonAppData%\AVG2012\IDS\profile|globalLoadable.bak
FileKey6=%CommonAppData%\AVG2012\IDS\profile|globalLoadable.bak
FileKey7=%CommonAppData%\AVG2012\Temp|*.tmp
FileKey7=%CommonAppData%\AVG2012\Temp|*.tmp
FileKey1=%CommonAppData%\AVG2013\Log|*.log;history.xml
FileKey1=%CommonAppData%\AVG2013\Log|*.log;history.xml
FileKey2=%CommonAppData%\AVG2013\scanlogs|*.log
FileKey2=%CommonAppData%\AVG2013\scanlogs|*.log
FileKey3=%CommonAppData%\AVG2013\update\backup|*.*
FileKey3=%CommonAppData%\AVG2013\update\backup|*.*
FileKey4=%CommonAppData%\AVG2013\Emc\Log|*.log
FileKey4=%CommonAppData%\AVG2013\Emc\Log|*.log
FileKey5=%CommonAppData%\AVG2013\IDS\config|*List.zip.bak
FileKey5=%CommonAppData%\AVG2013\IDS\config|*List.zip.bak
FileKey6=%CommonAppData%\AVG2013\IDS\profile|globalLoadable.bak
FileKey6=%CommonAppData%\AVG2013\IDS\profile|globalLoadable.bak
FileKey7=%CommonAppData%\AVG2013\Temp|*.tmp
FileKey7=%CommonAppData%\AVG2013\Temp|*.tmp
FileKey1=%CommonAppData%\Avira\AntiVir Desktop|*.old
FileKey1=%CommonAppData%\Avira\AntiVir Desktop|*.old
FileKey2=%CommonAppData%\Avira\AntiVir Desktop|*.tmp
FileKey2=%CommonAppData%\Avira\AntiVir Desktop|*.tmp
FileKey3=%CommonAppData%\Avira\Antivir Desktop\BACKUP\FAILSAFE|*.tmp
FileKey3=%CommonAppData%\Avira\Antivir Desktop\BACKUP\FAILSAFE|*.tmp
FileKey4=%CommonAppData%\Avira\AntiVir Desktop\LOGFILES|*.*
FileKey4=%CommonAppData%\Avira\AntiVir Desktop\LOGFILES|*.*
FileKey5=%CommonAppData%\Avira\AntiVir Desktop\TEMP|*.*
FileKey5=%CommonAppData%\Avira\AntiVir Desktop\TEMP|*.*
FileKey6=%CommonAppData%\Avira\My Avira\Logfiles|*.*
FileKey6=%CommonAppData%\Avira\My Avira\Logfiles|*.*
FileKey7=%CommonAppData%\Avira\My Avira\Temp|*.*
FileKey7=%CommonAppData%\Avira\My Avira\Temp|*.*
FileKey8=%ProgramFiles%\Avira\AntiVir Desktop|*.old
FileKey8=%ProgramFiles%\Avira\AntiVir Desktop|*.old
FileKey9=%ProgramFiles%\Avira\AntiVir Desktop|*.tmp
FileKey9=%ProgramFiles%\Avira\AntiVir Desktop|*.tmp
FileKey10=%ProgramFiles%\Avira\AntiVir Desktop\FAILSAFE|*.tmp
FileKey10=%ProgramFiles%\Avira\AntiVir Desktop\FAILSAFE|*.tmp
FileKey11=%CommonAppData%\Avira\Antivirus|*.old
FileKey11=%CommonAppData%\Avira\Antivirus|*.old
FileKey12=%CommonAppData%\Avira\Antivirus|*.tmp
FileKey12=%CommonAppData%\Avira\Antivirus|*.tmp
FileKey13=%CommonAppData%\Avira\Antivirus\BACKUP\FAILSAFE|*.tmp
FileKey13=%CommonAppData%\Avira\Antivirus\BACKUP\FAILSAFE|*.tmp
FileKey14=%CommonAppData%\Avira\Antivirus\LOGFILES|*.*
FileKey14=%CommonAppData%\Avira\Antivirus\LOGFILES|*.*
FileKey15=%CommonAppData%\Avira\Antivirus\TEMP|*.*
FileKey15=%CommonAppData%\Avira\Antivirus\TEMP|*.*
FileKey16=%CommonAppData%\Avira\Launcher\Logfiles|*.*
FileKey16=%CommonAppData%\Avira\Launcher\Logfiles|*.*
FileKey17=%CommonAppData%\Avira\Launcher\Temp|*.*
FileKey17=%CommonAppData%\Avira\Launcher\Temp|*.*
FileKey18=%ProgramFiles%\Avira\Antivirus|*.old
FileKey18=%ProgramFiles%\Avira\Antivirus|*.old
FileKey19=%ProgramFiles%\Avira\Antivirus|*.tmp
FileKey19=%ProgramFiles%\Avira\Antivirus|*.tmp
FileKey20=%ProgramFiles%\Avira\Antivirus\FAILSAFE|*.tmp
FileKey20=%ProgramFiles%\Avira\Antivirus\FAILSAFE|*.tmp
FileKey1=%ProgramFiles%\Alwil Software\Avast4\DATA\report|avast.xsl;Resident protection.txt;Simple user interface.txt;Simple user interface*.xml
FileKey1=%ProgramFiles%\Alwil Software\Avast4\DATA\report|avast.xsl;Resident protection.txt;Simple user interface.txt;Simple user interface*.xml
FileKey2=%ProgramFiles%\Alwil Software\Avast4\DATA\log|*.*
FileKey2=%ProgramFiles%\Alwil Software\Avast4\DATA\log|*.*
FileKey1=%ProgramData%\Alwil Software\Avast5\report|avast.xsl;avast.xsl;Resident protection.txt;Simple user interface.txt;Simple user interface*.xml
FileKey1=%ProgramData%\Alwil Software\Avast5\report|avast.xsl;avast.xsl;Resident protection.txt;Simple user interface.txt;Simple user interface*.xml
FileKey2=%ProgramData%\Alwil Software\Avast5\log|*.*
FileKey2=%ProgramData%\Alwil Software\Avast5\log|*.*
FileKey1=%CommonAppData%\AVAST Software\Avast\log|*.txt;*.log
FileKey1=%CommonAppData%\AVAST Software\Avast\log|*.txt;*.log
FileKey2=%CommonAppData%\AVAST Software\Avast\Spamconf|*.bin.tmp*
FileKey2=%CommonAppData%\AVAST Software\Avast\Spamconf|*.bin.tmp*
FileKey3=%CommonAppData%\AVAST Software\Avast\report|*.txt
FileKey3=%CommonAppData%\AVAST Software\Avast\report|*.txt
FileKey4=%AppData%\AVAST Software\Avast\Cache|*.*
FileKey4=%AppData%\AVAST Software\Avast\Cache|*.*
ExcludeKey1=FILE|%AppData%\AVAST Software\Avast\Cache\Cookies
ExcludeKey1=FILE|%AppData%\AVAST Software\Avast\Cache\Cookies
ExcludeKey2=FILE|%AppData%\AVAST Software\Avast\Cache\Cookies-journal
ExcludeKey2=FILE|%AppData%\AVAST Software\Avast\Cache\Cookies-journal
FileKey1=%ProgramFiles%\BitDefender\BitDefender 2009\Logs|*.*|RECURSE
FileKey1=%ProgramFiles%\BitDefender\BitDefender 2009\Logs|*.*|RECURSE
FileKey2=%CommonAppData%\BitDefender\Desktop\Profiles\Logs|*.xml|RECURSE
FileKey2=%CommonAppData%\BitDefender\Desktop\Profiles\Logs|*.xml|RECURSE
FileKey3=%AppData%\BitDefender\Desktop\Profiles\Logs|*.xml|RECURSE
FileKey3=%AppData%\BitDefender\Desktop\Profiles\Logs|*.xml|RECURSE
RegKey1=HKCU\Software\TUGZip|mainRecent
RegKey1=HKCU\Software\TUGZip|mainRecent
RegKey2=HKCU\Software\TUGZip|extrRecent
RegKey2=HKCU\Software\TUGZip|extrRecent
RegKey3=HKCU\Software\TUGZip|cmpWorkingDir
RegKey3=HKCU\Software\TUGZip|cmpWorkingDir
[Windows Defender]
[Windows Defender]
Detect=HKLM\SOFTWARE\Microsoft\Windows Defender
Detect=HKLM\SOFTWARE\Microsoft\Windows Defender
DetectFile=%ProgramFiles%\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
DetectFile=%ProgramFiles%\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
FileKey1=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Results\Quick|*.*
FileKey1=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Results\Quick|*.*
FileKey2=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Results\Resource|*.*
FileKey2=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Results\Resource|*.*
FileKey3=%CommonAppData%\Microsoft\Windows Defender\Support|*.log
FileKey3=%CommonAppData%\Microsoft\Windows Defender\Support|*.log
FileKey4=%ProgramFiles%\Microsoft AntiSpyware|errors.log;tracksEraser.log;cleaner.log
FileKey4=%ProgramFiles%\Microsoft AntiSpyware|errors.log;tracksEraser.log;cleaner.log
RegKey1=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey1=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey2=HKCU\Software\IZSoftware\IZArc\Recent
RegKey2=HKCU\Software\IZSoftware\IZArc\Recent
RegKey3=HKCU\Software\IZSoftware\IZArc\History
RegKey3=HKCU\Software\IZSoftware\IZArc\History
[Google Toolbar Firefox]
[Google Toolbar Firefox]
SpecialDetect=DET_MOZILLA_GOOGLE_TOOLBAR
SpecialDetect=DET_MOZILLA_GOOGLE_TOOLBAR
SpecialKey1=N_MOZ_GOOGLE_TOOLBAR
SpecialKey1=N_MOZ_GOOGLE_TOOLBAR
FileKey1=%LocalAppData%\Microsoft\Search Enhancement Pack\Search Box Extension|searchhs.dat
FileKey1=%LocalAppData%\Microsoft\Search Enhancement Pack\Search Box Extension|searchhs.dat
FileKey2=%LocalLowAppData%\Microsoft\Search Enhancement Pack\Search Box Extension|searchhs.dat
FileKey2=%LocalLowAppData%\Microsoft\Search Enhancement Pack\Search Box Extension|searchhs.dat
FileKey1=%LocalAppData%\Microsoft\OIS|OIScatalog.cag
FileKey1=%LocalAppData%\Microsoft\OIS|OIScatalog.cag
FileKey2=%LocalAppData%\Microsoft\OIS\thumbnails|*.*
FileKey2=%LocalAppData%\Microsoft\OIS\thumbnails|*.*
DetectFile=%ProgramFiles%\Imgburn\imgburn.exe
DetectFile=%ProgramFiles%\Imgburn\imgburn.exe
RegKey1=HKCU\Software\ImgBurn|ISOBUILD_MRUBootImage
RegKey1=HKCU\Software\ImgBurn|ISOBUILD_MRUBootImage
RegKey2=HKCU\Software\ImgBurn|ISOBUILD_MRUDeviceName
RegKey2=HKCU\Software\ImgBurn|ISOBUILD_MRUDeviceName
RegKey3=HKCU\Software\ImgBurn|ISOBUILD_MRUSourceFile
RegKey3=HKCU\Software\ImgBurn|ISOBUILD_MRUSourceFile
RegKey4=HKCU\Software\ImgBurn|ISOBUILD_MRUSourceFolder
RegKey4=HKCU\Software\ImgBurn|ISOBUILD_MRUSourceFolder
RegKey5=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Destination
RegKey5=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Destination
RegKey6=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Source
RegKey6=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Source
RegKey7=HKCU\Software\ImgBurn|ISOBUILD_RecentFolders_Destination
RegKey7=HKCU\Software\ImgBurn|ISOBUILD_RecentFolders_Destination
RegKey8=HKCU\Software\ImgBurn|ISOWRITE_MRUDeviceName
RegKey8=HKCU\Software\ImgBurn|ISOWRITE_MRUDeviceName
RegKey9=HKCU\Software\ImgBurn|ISOWRITE_RecentFiles_Source
RegKey9=HKCU\Software\ImgBurn|ISOWRITE_RecentFiles_Source
RegKey10=HKCU\Software\ImgBurn|FILELOCATIONS_ProjectFiles
RegKey10=HKCU\Software\ImgBurn|FILELOCATIONS_ProjectFiles
RegKey11=HKCU\Software\ImgBurn|FILELOCATIONS_QueueFiles
RegKey11=HKCU\Software\ImgBurn|FILELOCATIONS_QueueFiles
FileKey1=%AppData%\ImgBurn|ImgBurn.log
FileKey1=%AppData%\ImgBurn|ImgBurn.log
FileKey2=%AppData%\ImgBurn\IBG Files|*.*
FileKey2=%AppData%\ImgBurn\IBG Files|*.*
FileKey3=%AppData%\imgburn\graph data files|*.*
FileKey3=%AppData%\imgburn\graph data files|*.*
FileKey4=%AppData%\imgburn\Log Files|*.*
FileKey4=%AppData%\imgburn\Log Files|*.*
RegKey1=HKCU\Software\SlySoft\CloneCD\Settings|ImageFileName
RegKey1=HKCU\Software\SlySoft\CloneCD\Settings|ImageFileName
RegKey1=HKCU\Software\Elaborate Bytes\VirtualCloneDrive\LRU
RegKey1=HKCU\Software\Elaborate Bytes\VirtualCloneDrive\LRU
FileKey1=%ProgramFiles%\BillP Studios\WinPatrol|WinPatrolLog.*
FileKey1=%ProgramFiles%\BillP Studios\WinPatrol|WinPatrolLog.*
FileKey2=%SystemDrive%|HijackPatrol.log
FileKey2=%SystemDrive%|HijackPatrol.log
FileKey1=%LocalAppData%\LogMeIn Hamachi|*.log
FileKey1=%LocalAppData%\LogMeIn Hamachi|*.log
FileKey2=%LocalAppData%\LogMeIn Hamachi|*.old
FileKey2=%LocalAppData%\LogMeIn Hamachi|*.old
FileKey3=%LocalAppData%\LogMeIn Hamachi|*.bak
FileKey3=%LocalAppData%\LogMeIn Hamachi|*.bak
FileKey4=%ProgramFiles%\Logmein|LMI*.log
FileKey4=%ProgramFiles%\Logmein|LMI*.log
FileKey5=%ProgramData%\Logmein|LMI*.log
FileKey5=%ProgramData%\Logmein|LMI*.log
FileKey1=%AppData%\Ashampoo\Ashampoo Burning Studio 10|backupmetainfo.xml
FileKey1=%AppData%\Ashampoo\Ashampoo Burning Studio 10|backupmetainfo.xml
FileKey2=%AppData%\Ashampoo\Ashampoo Burning Studio 10\Log|*.xml
FileKey2=%AppData%\Ashampoo\Ashampoo Burning Studio 10\Log|*.xml
FileKey3=%AppData%\Ashampoo\Log|*.txt
FileKey3=%AppData%\Ashampoo\Log|*.txt
FileKey1=%AppData%\Ashampoo\Ashampoo Burning Studio 11|backupmetainfo.xml
FileKey1=%AppData%\Ashampoo\Ashampoo Burning Studio 11|backupmetainfo.xml
FileKey2=%AppData%\Ashampoo\Ashampoo Burning Studio 11\Log|*.xml
FileKey2=%AppData%\Ashampoo\Ashampoo Burning Studio 11\Log|*.xml
FileKey1=%AppData%\Ashampoo\Ashampoo Burning Studio 14\log|*log.txt
FileKey1=%AppData%\Ashampoo\Ashampoo Burning Studio 14\log|*log.txt
FileKey2=%AppData%\Ashampoo\Ashampoo Burning Studio 14\log|*.xml
FileKey2=%AppData%\Ashampoo\Ashampoo Burning Studio 14\log|*.xml
RegKey1=HKCU\Software\PrestoSoft\ExamDiff\AutoPick
RegKey1=HKCU\Software\PrestoSoft\ExamDiff\AutoPick
RegKey2=HKCU\Software\PrestoSoft\ExamDiff\Recent Find Strings
RegKey2=HKCU\Software\PrestoSoft\ExamDiff\Recent Find Strings
RegKey3=HKCU\Software\PrestoSoft\ExamDiff\Recent Left Files
RegKey3=HKCU\Software\PrestoSoft\ExamDiff\Recent Left Files
RegKey4=HKCU\Software\PrestoSoft\ExamDiff\Recent Right Files
RegKey4=HKCU\Software\PrestoSoft\ExamDiff\Recent Right Files
RegKey5=HKCU\Software\PrestoSoft\ExamDiff\Settings|File 1
RegKey5=HKCU\Software\PrestoSoft\ExamDiff\Settings|File 1
RegKey6=HKCU\Software\PrestoSoft\ExamDiff\Settings|File 2
RegKey6=HKCU\Software\PrestoSoft\ExamDiff\Settings|File 2
RegKey1=HKCU\Software\PrestoSoft\ExamDiff Pro\AutoPick
RegKey1=HKCU\Software\PrestoSoft\ExamDiff Pro\AutoPick
RegKey2=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Find Strings Bin
RegKey2=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Find Strings Bin
RegKey3=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Left Directories
RegKey3=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Left Directories
RegKey4=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Left Files
RegKey4=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Left Files
RegKey5=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Right Directories
RegKey5=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Right Directories
RegKey6=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Right Files
RegKey6=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Right Files
RegKey7=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Session Files
RegKey7=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Session Files
RegKey8=HKCU\Software\PrestoSoft\ExamDiff Pro\Settings|File 1
RegKey8=HKCU\Software\PrestoSoft\ExamDiff Pro\Settings|File 1
RegKey9=HKCU\Software\PrestoSoft\ExamDiff Pro\Settings|File 2
RegKey9=HKCU\Software\PrestoSoft\ExamDiff Pro\Settings|File 2
Detect=HKCU\Software\grigsoft.com\Compare It!
Detect=HKCU\Software\grigsoft.com\Compare It!
RegKey1=HKCU\Software\grigsoft.com\Compare It!\Combos
RegKey1=HKCU\Software\grigsoft.com\Compare It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Compare It!\dirs
RegKey2=HKCU\Software\grigsoft.com\Compare It!\dirs
RegKey3=HKCU\Software\grigsoft.com\Compare It!\options|Recent0
RegKey3=HKCU\Software\grigsoft.com\Compare It!\options|Recent0
RegKey4=HKCU\Software\grigsoft.com\Compare It!\options|Recent1
RegKey4=HKCU\Software\grigsoft.com\Compare It!\options|Recent1
RegKey5=HKCU\Software\grigsoft.com\Compare It!\options|Recent2
RegKey5=HKCU\Software\grigsoft.com\Compare It!\options|Recent2
RegKey6=HKCU\Software\grigsoft.com\Compare It!\options|Recent3
RegKey6=HKCU\Software\grigsoft.com\Compare It!\options|Recent3
RegKey7=HKCU\Software\grigsoft.com\Compare It!\options|Recent4
RegKey7=HKCU\Software\grigsoft.com\Compare It!\options|Recent4
RegKey8=HKCU\Software\grigsoft.com\Compare It!\options|Recent5
RegKey8=HKCU\Software\grigsoft.com\Compare It!\options|Recent5
RegKey9=HKCU\Software\grigsoft.com\Compare It!\options|Recent6
RegKey9=HKCU\Software\grigsoft.com\Compare It!\options|Recent6
RegKey10=HKCU\Software\grigsoft.com\Compare It!\options|Recent7
RegKey10=HKCU\Software\grigsoft.com\Compare It!\options|Recent7
RegKey11=HKCU\Software\grigsoft.com\Compare It!\options|Recent8
RegKey11=HKCU\Software\grigsoft.com\Compare It!\options|Recent8
RegKey12=HKCU\Software\grigsoft.com\Compare It!\options|Recent9
RegKey12=HKCU\Software\grigsoft.com\Compare It!\options|Recent9
RegKey13=HKCU\Software\grigsoft.com\Compare It!\options|Recent10
RegKey13=HKCU\Software\grigsoft.com\Compare It!\options|Recent10
RegKey1=HKCU\Software\Microsoft\Windiff|NameLeft
RegKey1=HKCU\Software\Microsoft\Windiff|NameLeft
RegKey2=HKCU\Software\Microsoft\Windiff|NameRight
RegKey2=HKCU\Software\Microsoft\Windiff|NameRight
RegKey1=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TypedURLs
RegKey1=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TypedURLs
RegKey2=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TabbedBrowserUrls
RegKey2=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TabbedBrowserUrls
RegKey3=HKCU\Software\Bradbury\FeedDemon\1.0\SearchFeedKeywords
RegKey3=HKCU\Software\Bradbury\FeedDemon\1.0\SearchFeedKeywords
[Last.FM]
[Last.FM]
DetectFile=%ProgramFiles%\Last.fm\LastFM.exe
DetectFile=%ProgramFiles%\Last.fm\LastFM.exe
FileKey1=%LocalAppData%\Last.fm\client\cache|*.*
FileKey1=%LocalAppData%\Last.fm\client\cache|*.*
FileKey2=%LocalAppData%\Last.fm\client|*.log
FileKey2=%LocalAppData%\Last.fm\client|*.log
FileKey1=%LocalAppData%\Pando\Pando Files|*.log
FileKey1=%LocalAppData%\Pando\Pando Files|*.log
DetectFile=%ProgramFiles%\Sandboxie\Start.exe
DetectFile=%ProgramFiles%\Sandboxie\Start.exe
FileKey1=%SystemDrive%\Sandbox\%UserName%|*.*|RECURSE
FileKey1=%SystemDrive%\Sandbox\%UserName%|*.*|RECURSE
ExcludeKey1=FILE|%SystemDrive%\Sandbox\%UserName%\DONT-USE.TXT
ExcludeKey1=FILE|%SystemDrive%\Sandbox\%UserName%\DONT-USE.TXT
ExcludeKey2=FILE|%SystemDrive%\Sandbox\%UserName%\desktop.ini
ExcludeKey2=FILE|%SystemDrive%\Sandbox\%UserName%\desktop.ini
RegKey1=HKCU\Software\TechSmith\SnagIt\9\Recent Captures
RegKey1=HKCU\Software\TechSmith\SnagIt\9\Recent Captures
RegKey2=HKCU\Software\TechSmith\SnagIt\9\SnagItEditor\Recent File List
RegKey2=HKCU\Software\TechSmith\SnagIt\9\SnagItEditor\Recent File List
FileKey1=%LocalAppData%\TechSmith\SnagIt|Tray.bin
FileKey1=%LocalAppData%\TechSmith\SnagIt|Tray.bin
RegKey1=HKCU\Software\TechSmith\SnagIt\10\Recent Captures
RegKey1=HKCU\Software\TechSmith\SnagIt\10\Recent Captures
RegKey2=HKCU\Software\TechSmith\SnagIt\10\SnagItEditor\Recent File List
RegKey2=HKCU\Software\TechSmith\SnagIt\10\SnagItEditor\Recent File List
FileKey2=%LocalAppData%\TechSmith\SnagIt\DataStore\AppIcons|*.*
FileKey2=%LocalAppData%\TechSmith\SnagIt\DataStore\AppIcons|*.*
FileKey3=%LocalAppData%\TechSmith\SnagIt\DataStore\WebSiteIcons|*.*
FileKey3=%LocalAppData%\TechSmith\SnagIt\DataStore\WebSiteIcons|*.*
FileKey4=%LocalAppData%\TechSmith\SnagIt\Thumbnails|*.*
FileKey4=%LocalAppData%\TechSmith\SnagIt\Thumbnails|*.*
RegKey1=HKCU\Software\TechSmith\SnagIt\11\Recent Captures
RegKey1=HKCU\Software\TechSmith\SnagIt\11\Recent Captures
RegKey2=HKCU\Software\TechSmith\SnagIt\11\SnagItEditor\Recent File List
RegKey2=HKCU\Software\TechSmith\SnagIt\11\SnagItEditor\Recent File List
RegKey1=HKCU\Software\TechSmith\SnagIt\12\Recent Captures
RegKey1=HKCU\Software\TechSmith\SnagIt\12\Recent Captures
RegKey2=HKCU\Software\TechSmith\SnagIt\12\SnagItEditor\Recent File List
RegKey2=HKCU\Software\TechSmith\SnagIt\12\SnagItEditor\Recent File List
FileKey2=%LocalAppData%\TechSmith\SnagIt\DataStore\AppIcons|*.ico
FileKey2=%LocalAppData%\TechSmith\SnagIt\DataStore\AppIcons|*.ico
FileKey3=%LocalAppData%\TechSmith\SnagIt\DataStore\WebSiteIcons|*.ico
FileKey3=%LocalAppData%\TechSmith\SnagIt\DataStore\WebSiteIcons|*.ico
FileKey1=%AppData%\Ditto|ditto.db
FileKey1=%AppData%\Ditto|ditto.db
FileKey1=%LocalAppData%\Evernote\Evernote\Logs|*.*
FileKey1=%LocalAppData%\Evernote\Evernote\Logs|*.*
FileKey1=%AppData%\I2P\logs|*.*
FileKey1=%AppData%\I2P\logs|*.*
DetectFile=%CommonAppData%\McAfee\MCLOGS
DetectFile=%CommonAppData%\McAfee\MCLOGS
FileKey1=%CommonAppData%\McAfee\MCLOGS|*.log|RECURSE
FileKey1=%CommonAppData%\McAfee\MCLOGS|*.log|RECURSE
FileKey1=%CommonAppData%\Raxco\PerfectDisk\8.0|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\8.0|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\9.0|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\9.0|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\10.0|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\10.0|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\11.0|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\11.0|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\12.0|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\12.0|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\12.5|PDBootLog
FileKey1=%CommonAppData%\Raxco\PerfectDisk\12.5|PDBootLog
RegKey1=HKCU\Software\PowerISO|Reopen0
RegKey1=HKCU\Software\PowerISO|Reopen0
RegKey2=HKCU\Software\PowerISO|Reopen1
RegKey2=HKCU\Software\PowerISO|Reopen1
RegKey3=HKCU\Software\PowerISO|Reopen2
RegKey3=HKCU\Software\PowerISO|Reopen2
RegKey4=HKCU\Software\PowerISO|Reopen3
RegKey4=HKCU\Software\PowerISO|Reopen3
RegKey5=HKCU\Software\PowerISO|ExtractPath0
RegKey5=HKCU\Software\PowerISO|ExtractPath0
RegKey6=HKCU\Software\PowerISO|ExtractPath1
RegKey6=HKCU\Software\PowerISO|ExtractPath1
RegKey7=HKCU\Software\PowerISO|ExtractPath2
RegKey7=HKCU\Software\PowerISO|ExtractPath2
RegKey8=HKCU\Software\PowerISO|ExtractPath3
RegKey8=HKCU\Software\PowerISO|ExtractPath3
RegKey9=HKCU\Software\PowerISO|ExtractPath4
RegKey9=HKCU\Software\PowerISO|ExtractPath4
RegKey10=HKCU\Software\PowerISO|ExtractPath5
RegKey10=HKCU\Software\PowerISO|ExtractPath5
RegKey11=HKCU\Software\PowerISO|ExtractPath6
RegKey11=HKCU\Software\PowerISO|ExtractPath6
RegKey12=HKCU\Software\PowerISO|ExtractPath7
RegKey12=HKCU\Software\PowerISO|ExtractPath7
RegKey1=HKCU\Software\EasyBoot Systems\UltraISO\5.0|Reopen
RegKey1=HKCU\Software\EasyBoot Systems\UltraISO\5.0|Reopen
RegKey2=HKCU\Software\EasyBoot Systems\UltraISO\5.0|a
RegKey2=HKCU\Software\EasyBoot Systems\UltraISO\5.0|a
RegKey3=HKCU\Software\EasyBoot Systems\UltraISO\5.0|b
RegKey3=HKCU\Software\EasyBoot Systems\UltraISO\5.0|b
RegKey4=HKCU\Software\EasyBoot Systems\UltraISO\5.0|c
RegKey4=HKCU\Software\EasyBoot Systems\UltraISO\5.0|c
RegKey5=HKCU\Software\EasyBoot Systems\UltraISO\5.0|d
RegKey5=HKCU\Software\EasyBoot Systems\UltraISO\5.0|d
RegKey6=HKCU\Software\EasyBoot Systems\UltraISO\5.0|e
RegKey6=HKCU\Software\EasyBoot Systems\UltraISO\5.0|e
RegKey7=HKCU\Software\EasyBoot Systems\UltraISO\5.0|f
RegKey7=HKCU\Software\EasyBoot Systems\UltraISO\5.0|f
RegKey8=HKCU\Software\EasyBoot Systems\UltraISO\5.0|g
RegKey8=HKCU\Software\EasyBoot Systems\UltraISO\5.0|g
RegKey9=HKCU\Software\EasyBoot Systems\UltraISO\5.0|h
RegKey9=HKCU\Software\EasyBoot Systems\UltraISO\5.0|h
RegKey10=HKCU\Software\EasyBoot Systems\UltraISO\5.0|i
RegKey10=HKCU\Software\EasyBoot Systems\UltraISO\5.0|i
DetectFile=%UserProfile%\.gimp-2.4
DetectFile=%UserProfile%\.gimp-2.4
FileKey1=%UserProfile%\.thumbnails\normal|*.*
FileKey1=%UserProfile%\.thumbnails\normal|*.*
FileKey2=%UserProfile%\.gimp-2.4|documents
FileKey2=%UserProfile%\.gimp-2.4|documents
DetectFile=%UserProfile%\.gimp-2.6
DetectFile=%UserProfile%\.gimp-2.6
DetectFile=%UserProfile%\.gimp-2.8
DetectFile=%UserProfile%\.gimp-2.8
FileKey1=%AppData%\Go!Zilla|GoZilla.hst
FileKey1=%AppData%\Go!Zilla|GoZilla.hst
RegKey1=HKCU\Software\MagicISO\Reopen
RegKey1=HKCU\Software\MagicISO\Reopen
FileKey1=%LocalAppData%\Microsoft\zune\art cache|*.*|REMOVESELF
FileKey1=%LocalAppData%\Microsoft\zune\art cache|*.*|REMOVESELF
FileKey2=%LocalAppData%\Microsoft\Zune|NowPlaying.dat
FileKey2=%LocalAppData%\Microsoft\Zune|NowPlaying.dat
RegKey1=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU0
RegKey1=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU0
RegKey2=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU1
RegKey2=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU1
RegKey3=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU2
RegKey3=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU2
RegKey4=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU3
RegKey4=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU3
RegKey5=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU4
RegKey5=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU4
RegKey6=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU5
RegKey6=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU5
RegKey7=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU6
RegKey7=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU6
RegKey8=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU7
RegKey8=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU7
RegKey9=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU8
RegKey9=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU8
RegKey10=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU9
RegKey10=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU9
FileKey1=%AppData%\FastStone\FSIV|HisFolderList.db
FileKey1=%AppData%\FastStone\FSIV|HisFolderList.db
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\FSCapture.exe
Detect=HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\FSCapture.exe
RegKey1=HKCU\Software\FastStone|_GrbId
RegKey1=HKCU\Software\FastStone|_GrbId
FileKey1=%LocalAppData%\FastStone\FSC\EditWith|*.*
FileKey1=%LocalAppData%\FastStone\FSC\EditWith|*.*
FileKey2=%LocalAppData%\FastStone\FSC\Email|*.*
FileKey2=%LocalAppData%\FastStone\FSC\Email|*.*
FileKey3=%LocalAppData%\FastStone\FSC\FTP|*.*
FileKey3=%LocalAppData%\FastStone\FSC\FTP|*.*
RegKey1=HKCU\Software\Akelsoft\AkelPad\Recent
RegKey1=HKCU\Software\Akelsoft\AkelPad\Recent
RegKey2=HKCU\Software\Akelsoft\AkelPad\Search
RegKey2=HKCU\Software\Akelsoft\AkelPad\Search
FileKey1=%AppData%\notepad |session.xml
FileKey1=%AppData%\notepad |session.xml
RegKey1=HKLM\Software\NoteXpad\Recent
RegKey1=HKLM\Software\NoteXpad\Recent
FileKey1=%ProgramFiles%\DCSoft\RegEditX\x86|RegEditX.sav
FileKey1=%ProgramFiles%\DCSoft\RegEditX\x86|RegEditX.sav
FileKey2=%ProgramFiles%\DCSoft\RegEditX\x64|RegEditX.sav
FileKey2=%ProgramFiles%\DCSoft\RegEditX\x64|RegEditX.sav
FileKey3=%ProgramFiles%\DCSoft\RegEditX\x86|RegEditX.bak
FileKey3=%ProgramFiles%\DCSoft\RegEditX\x86|RegEditX.bak
FileKey4=%ProgramFiles%\DCSoft\RegEditX\x64|RegEditX.bak
FileKey4=%ProgramFiles%\DCSoft\RegEditX\x64|RegEditX.bak
RegKey1=HKCU\Software\Foxit Software\Foxit Reader 5.0\Recent File List
RegKey1=HKCU\Software\Foxit Software\Foxit Reader 5.0\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit Reader 5.0\RecentFiles
RegKey2=HKCU\Software\Foxit Software\Foxit Reader 5.0\RecentFiles
RegKey3=HKCU\Software\Foxit Software\Foxit Reader 5.0\Preferences\History\LastOpen
RegKey3=HKCU\Software\Foxit Software\Foxit Reader 5.0\Preferences\History\LastOpen
RegKey4=HKCU\Software\Foxit Software\Foxit Reader 5.0\Preferences\History\LastSession
RegKey4=HKCU\Software\Foxit Software\Foxit Reader 5.0\Preferences\History\LastSession
RegKey5=HKCU\Software\Foxit Software\Foxit Reader 5.0\Preferences\Others|csInitialOpenDir
RegKey5=HKCU\Software\Foxit Software\Foxit Reader 5.0\Preferences\Others|csInitialOpenDir
DetectFile=%ProgramFiles%\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe
DetectFile=%ProgramFiles%\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe
RegKey1=HKCU\Software\ACD Systems\ACDSee\140|LastOptionPage
RegKey1=HKCU\Software\ACD Systems\ACDSee\140|LastOptionPage
RegKey2=HKCU\Software\ACD Systems\ACDSee\140|LastOptionPageName
RegKey2=HKCU\Software\ACD Systems\ACDSee\140|LastOptionPageName
RegKey3=HKCU\Software\ACD Systems\ACDSee\140|OpenFolder
RegKey3=HKCU\Software\ACD Systems\ACDSee\140|OpenFolder
RegKey4=HKCU\Software\ACD Systems\ACDSee\140|HistSearchFileName
RegKey4=HKCU\Software\ACD Systems\ACDSee\140|HistSearchFileName
RegKey5=HKCU\Software\ACD Systems\ACDSee\140|HistSearchQuickText
RegKey5=HKCU\Software\ACD Systems\ACDSee\140|HistSearchQuickText
RegKey6=HKCU\Software\ACD Systems\ACDSee\140|SimpleSearchHistory
RegKey6=HKCU\Software\ACD Systems\ACDSee\140|SimpleSearchHistory
RegKey1=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|FileSaveAsMru
RegKey1=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|FileSaveAsMru
RegKey2=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|ExportAsZipMru
RegKey2=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|ExportAsZipMru
RegKey3=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|MRUImportFolder
RegKey3=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|MRUImportFolder
RegKey4=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|MRUOpenProjectFolder
RegKey4=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|MRUOpenProjectFolder
RegKey5=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|MRUBatchAddFilesProjectsFolder
RegKey5=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|MRUBatchAddFilesProjectsFolder
RegKey6=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|MRUImportExportCaptions
RegKey6=HKCU\Software\TechSmith\Camtasia Studio\7.0\Camtasia Studio\7.0|MRUImportExportCaptions
RegKey1=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Recorder\8.0\General|lstLastSaveDir
RegKey1=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Recorder\8.0\General|lstLastSaveDir
RegKey2=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Studio\8.0|ExportAsZipMru
RegKey2=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Studio\8.0|ExportAsZipMru
RegKey3=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Studio\8.0|FileSaveAsMru
RegKey3=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Studio\8.0|FileSaveAsMru
RegKey4=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Studio\8.0|MRUImportFolder
RegKey4=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Studio\8.0|MRUImportFolder
RegKey5=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Studio\8.0|MRUOpenProjectFolder
RegKey5=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Studio\8.0|MRUOpenProjectFolder
RegKey6=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Studio\8.0|RecentRecordingsMru
RegKey6=HKCU\Software\TechSmith\Camtasia Studio\8.0\Camtasia Studio\8.0|RecentRecordingsMru
FileKey1=%AppData%\CoffeeCup Software\CoffeeCup HTML Editor\Settings|mru.ini
FileKey1=%AppData%\CoffeeCup Software\CoffeeCup HTML Editor\Settings|mru.ini
FileKey2=%AppData%\CoffeeCup Software\CoffeeCup HTML Editor\Settings|links.ini
FileKey2=%AppData%\CoffeeCup Software\CoffeeCup HTML Editor\Settings|links.ini
FileKey3=%AppData%\CoffeeCup Software\CoffeeCup HTML Editor\Settings|lastopen.dat
FileKey3=%AppData%\CoffeeCup Software\CoffeeCup HTML Editor\Settings|lastopen.dat
FileKey1=%appdata%\AnvSoft\Any Video Converter Ultimate|history*.db
FileKey1=%appdata%\AnvSoft\Any Video Converter Ultimate|history*.db
FileKey2=%appdata%\AnvSoft\Any Video Converter Ultimate|*.log
FileKey2=%appdata%\AnvSoft\Any Video Converter Ultimate|*.log
FileKey1=%ProgramFiles%\Freemake\Freemake Video Downloader|trace.log
FileKey1=%ProgramFiles%\Freemake\Freemake Video Downloader|trace.log
FileKey2=%CommonAppData%\Freemake\FreemakeVideoDownloader|*.txt
FileKey2=%CommonAppData%\Freemake\FreemakeVideoDownloader|*.txt
FileKey3=%Documents%\Freemake\FreemakeVideoDownloader\History\Thumbnails|*.*
FileKey3=%Documents%\Freemake\FreemakeVideoDownloader\History\Thumbnails|*.*
FileKey4=%Documents%\Freemake\FreemakeVideoDownloader\History|*.xml
FileKey4=%Documents%\Freemake\FreemakeVideoDownloader\History|*.xml
FileKey1=%CommonAppData%\Freemake\FreemakeAudioConverter|*.txt
FileKey1=%CommonAppData%\Freemake\FreemakeAudioConverter|*.txt
RegKey1=HKCU\Software\Freemake\FreemakeAudioConverter|InitVideoFileDirectory
RegKey1=HKCU\Software\Freemake\FreemakeAudioConverter|InitVideoFileDirectory
RegKey2=HKCU\Software\Freemake\FreemakeAudioConverter|InitAudioFileDirectory
RegKey2=HKCU\Software\Freemake\FreemakeAudioConverter|InitAudioFileDirectory
RegKey3=HKCU\Software\Freemake\FreemakeAudioConverter|InitImageFileDirectory
RegKey3=HKCU\Software\Freemake\FreemakeAudioConverter|InitImageFileDirectory
FileKey1=%CommonAppData%\Freemake\FreemakeVideoConverter|*.txt
FileKey1=%CommonAppData%\Freemake\FreemakeVideoConverter|*.txt
RegKey1=HKCU\Software\Freemake\FreemakeVideoConverter|InitVideoFileDirectory
RegKey1=HKCU\Software\Freemake\FreemakeVideoConverter|InitVideoFileDirectory
RegKey2=HKCU\Software\Freemake\FreemakeVideoConverter|InitAudioFileDirectory
RegKey2=HKCU\Software\Freemake\FreemakeVideoConverter|InitAudioFileDirectory
RegKey3=HKCU\Software\Freemake\FreemakeVideoConverter|InitImageFileDirectory
RegKey3=HKCU\Software\Freemake\FreemakeVideoConverter|InitImageFileDirectory
RegKey4=HKCU\Software\Freemake\FreemakeVideoConverter|CurrentDVDDirectory
RegKey4=HKCU\Software\Freemake\FreemakeVideoConverter|CurrentDVDDirectory
RegKey5=HKCU\Software\Freemake\FreemakeVideoConverter|AudioForSlideshow_0
RegKey5=HKCU\Software\Freemake\FreemakeVideoConverter|AudioForSlideshow_0
RegKey6=HKCU\Software\Freemake\FreemakeVideoConverter|AudioForSlideshow_1
RegKey6=HKCU\Software\Freemake\FreemakeVideoConverter|AudioForSlideshow_1
RegKey7=HKCU\Software\Freemake\FreemakeVideoConverter|AudioForSlideshow_2
RegKey7=HKCU\Software\Freemake\FreemakeVideoConverter|AudioForSlideshow_2
RegKey8=HKCU\Software\Freemake\FreemakeVideoConverter|InitAudioDirectoryForSlideshow
RegKey8=HKCU\Software\Freemake\FreemakeVideoConverter|InitAudioDirectoryForSlideshow
RegKey9=HKCU\Software\Freemake\FreemakeVideoConverter|OutputDVDDirectory
RegKey9=HKCU\Software\Freemake\FreemakeVideoConverter|OutputDVDDirectory
RegKey10=HKCU\Software\Freemake\FreemakeVideoConverter|DVDOutputPath_0
RegKey10=HKCU\Software\Freemake\FreemakeVideoConverter|DVDOutputPath_0
RegKey11=HKCU\Software\Freemake\FreemakeVideoConverter|OutputPath1
RegKey11=HKCU\Software\Freemake\FreemakeVideoConverter|OutputPath1
RegKey12=HKCU\Software\Freemake\FreemakeVideoConverter|OutputPath2
RegKey12=HKCU\Software\Freemake\FreemakeVideoConverter|OutputPath2
RegKey13=HKCU\Software\Freemake\FreemakeVideoConverter|OutputPath3
RegKey13=HKCU\Software\Freemake\FreemakeVideoConverter|OutputPath3
RegKey14=HKCU\Software\Freemake\FreemakeVideoConverter|OutputPath4
RegKey14=HKCU\Software\Freemake\FreemakeVideoConverter|OutputPath4
RegKey15=HKCU\Software\Freemake\FreemakeVideoConverter|OutputDirectory
RegKey15=HKCU\Software\Freemake\FreemakeVideoConverter|OutputDirectory
FileKey1=%AppData%\Vso|*.log
FileKey1=%AppData%\Vso|*.log
FileKey2=%Documents%\PcSetup|*.log|REMOVESELF
FileKey2=%Documents%\PcSetup|*.log|REMOVESELF
FileKey3=%CommonAppData%\VSO|*.cache
FileKey3=%CommonAppData%\VSO|*.cache
FileKey4=%CommonAppData%\VSO\ConvertXToDVD\5\log|*.log;*.crashlist|REMOVESELF
FileKey4=%CommonAppData%\VSO\ConvertXToDVD\5\log|*.log;*.crashlist|REMOVESELF
RegKey1=HKCU\Software\VSO\ConvertXtoDVD\4.0|Dvd_Folder
RegKey1=HKCU\Software\VSO\ConvertXtoDVD\4.0|Dvd_Folder
RegKey2=HKCU\Software\VSO\ConvertXtoDVD\4.0\settings\Gen_MRU_Pathes
RegKey2=HKCU\Software\VSO\ConvertXtoDVD\4.0\settings\Gen_MRU_Pathes
RegKey3=HKCU\Software\VSO\ConvertXtoDVD\5\Gen_MRU_Pathes
RegKey3=HKCU\Software\VSO\ConvertXtoDVD\5\Gen_MRU_Pathes
FileKey1=%CommonAppData%\VSO\Blu-ray Converter Ultimate\2\Log|*.log
FileKey1=%CommonAppData%\VSO\Blu-ray Converter Ultimate\2\Log|*.log
FileKey1=%CommonAppData%\VSO\DVD Converter Ultimate\2\Log|*.log
FileKey1=%CommonAppData%\VSO\DVD Converter Ultimate\2\Log|*.log
FileKey1=%AppData%\AIMP3|AIMP3.bak
FileKey1=%AppData%\AIMP3|AIMP3.bak
FileKey2=%AppData%\AIMP3|AIMP3ate.bak
FileKey2=%AppData%\AIMP3|AIMP3ate.bak
FileKey3=%AppData%\AIMP3|AIMP3lib.bak
FileKey3=%AppData%\AIMP3|AIMP3lib.bak
FileKey4=%AppData%\AIMP3|AIMP3ac.bak
FileKey4=%AppData%\AIMP3|AIMP3ac.bak
FileKey1=%AppData%\Corel\Messages|*.*|RECURSE
FileKey1=%AppData%\Corel\Messages|*.*|RECURSE
FileKey2=%AppData%\Ulead Systems\Corel VideoStudio Pro\14.0\en-US|VS_Pro.log
FileKey2=%AppData%\Ulead Systems\Corel VideoStudio Pro\14.0\en-US|VS_Pro.log
FileKey3=%Documents%\Corel VideoStudio Pro\14.0\SmartProxy|*.upx
FileKey3=%Documents%\Corel VideoStudio Pro\14.0\SmartProxy|*.upx
RegKey1=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\14.0\HerRFL
RegKey1=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\14.0\HerRFL
RegKey2=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\14.0\Library Manager|Latest Export Folder
RegKey2=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\14.0\Library Manager|Latest Export Folder
RegKey3=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\14.0\VIO\Recent Dir
RegKey3=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\14.0\VIO\Recent Dir
ExcludeKey1=FILE|%AppData%\Corel\Messages|*.policy
ExcludeKey1=FILE|%AppData%\Corel\Messages|*.policy
FileKey2=%AppData%\Ulead Systems\Corel VideoStudio Pro\15.0\en-US|VS_Pro.log
FileKey2=%AppData%\Ulead Systems\Corel VideoStudio Pro\15.0\en-US|VS_Pro.log
FileKey3=%Documents%\Corel VideoStudio Pro\15.0\SmartProxy|*.upx
FileKey3=%Documents%\Corel VideoStudio Pro\15.0\SmartProxy|*.upx
RegKey1=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\15.0\HerRFL
RegKey1=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\15.0\HerRFL
RegKey2=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\15.0\Library Manager|Latest Export Folder
RegKey2=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\15.0\Library Manager|Latest Export Folder
RegKey3=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\15.0\VIO\Recent Dir
RegKey3=HKCU\Software\Ulead Systems\Corel VideoStudio Pro\15.0\VIO\Recent Dir
RegKey1=HKCU\Software\ESTsoft\ALZip\MRUOpen
RegKey1=HKCU\Software\ESTsoft\ALZip\MRUOpen
RegKey2=HKCU\Software\ESTsoft\ALZip\MRUExtract
RegKey2=HKCU\Software\ESTsoft\ALZip\MRUExtract
FileKey1=%LocalAppData%\Cyberlink\PhotoDirector\3.0|*.cache
FileKey1=%LocalAppData%\Cyberlink\PhotoDirector\3.0|*.cache
FileKey1=%AppData%\CyberLink\MediaCache|*.*
FileKey1=%AppData%\CyberLink\MediaCache|*.*
FileKey2=%AppData%\CyberLink\PowerDirector\10.0|Recentfiles.ini
FileKey2=%AppData%\CyberLink\PowerDirector\10.0|Recentfiles.ini
FileKey3=%AppData%\CyberLink\PowerDirector\10.0\DSPCache|*.*|RECURSE
FileKey3=%AppData%\CyberLink\PowerDirector\10.0\DSPCache|*.*|RECURSE
FileKey4=%AppData%\CyberLink\PowerDirector\10.0\photoTmp|*.*|RECURSE
FileKey4=%AppData%\CyberLink\PowerDirector\10.0\photoTmp|*.*|RECURSE
FileKey5=%AppData%\CyberLink\PowerDirector\10.0\SpltrCache|*.*|RECURSE
FileKey5=%AppData%\CyberLink\PowerDirector\10.0\SpltrCache|*.*|RECURSE
RegKey1=HKCU\Software\CyberLink\Hanuman\Waveform
RegKey1=HKCU\Software\CyberLink\Hanuman\Waveform
RegKey2=HKCU\Software\CyberLink\MediaCache5\Data5
RegKey2=HKCU\Software\CyberLink\MediaCache5\Data5
RegKey3=HKCU\Software\CyberLink\MediaCache5\Thumbnail5
RegKey3=HKCU\Software\CyberLink\MediaCache5\Thumbnail5
RegKey1=HKCU\Software\CyberLink\PowerDirector12\MediaObj\MediaCache5\Data5
RegKey1=HKCU\Software\CyberLink\PowerDirector12\MediaObj\MediaCache5\Data5
RegKey2=HKCU\Software\CyberLink\PowerDirector12\MediaObj\MediaCache5\Thumbnail5
RegKey2=HKCU\Software\CyberLink\PowerDirector12\MediaObj\MediaCache5\Thumbnail5
RegKey3=HKCU\Software\CyberLink\PowerDirector12|ImportFilePath
RegKey3=HKCU\Software\CyberLink\PowerDirector12|ImportFilePath
FileKey1=%CommonAppData%\CyberLink\PowerDirector\12.0\AnalyzeCacheFiles|CLZoetrope.fdb
FileKey1=%CommonAppData%\CyberLink\PowerDirector\12.0\AnalyzeCacheFiles|CLZoetrope.fdb
FileKey2=%AppData%\CyberLink\PowerDirector\12.0\DSPCache|*.*|RECURSE
FileKey2=%AppData%\CyberLink\PowerDirector\12.0\DSPCache|*.*|RECURSE
FileKey3=%AppData%\CyberLink\PowerDirector\12.0\photoTmp|*.*
FileKey3=%AppData%\CyberLink\PowerDirector\12.0\photoTmp|*.*
FileKey4=%AppData%\CyberLink\PowerDirector\12.0\SpltrCache|*.*
FileKey4=%AppData%\CyberLink\PowerDirector\12.0\SpltrCache|*.*
FileKey5=%AppData%\CyberLink\PowerDirector\12.0\WaveForms|PD_0000.txt
FileKey5=%AppData%\CyberLink\PowerDirector\12.0\WaveForms|PD_0000.txt
FileKey6=%AppData%\CyberLink\PowerDirector\12.0|Recentfiles.ini
FileKey6=%AppData%\CyberLink\PowerDirector\12.0|Recentfiles.ini
FileKey7=%AppData%\CyberLink\MediaCache|*.*
FileKey7=%AppData%\CyberLink\MediaCache|*.*
RegKey1=HKCU\Software\CyberLink\AudioDirector4\MediaObj\MediaCache5\Data5
RegKey1=HKCU\Software\CyberLink\AudioDirector4\MediaObj\MediaCache5\Data5
FileKey1=%CommonAppData%\CyberLink\Downloader|Item0.bak;Item1.bak;Item2.bak;Item3.bak;Item4.bak
FileKey1=%CommonAppData%\CyberLink\Downloader|Item0.bak;Item1.bak;Item2.bak;Item3.bak;Item4.bak
FileKey2=%CommonAppData%\install_clap|*.*|RECURSE
FileKey2=%CommonAppData%\install_clap|*.*|RECURSE
FileKey3=%LocalAppData%\Cyberlink\AudioDirector\4.0\Temp|*.txt;*.pk
FileKey3=%LocalAppData%\Cyberlink\AudioDirector\4.0\Temp|*.txt;*.pk
FileKey1=%AppData%\DivX\Player|Media Library
FileKey1=%AppData%\DivX\Player|Media Library
RegKey1=HKCU\Software\UniExtract\Directory
RegKey1=HKCU\Software\UniExtract\Directory
RegKey2=HKCU\Software\UniExtract\File
RegKey2=HKCU\Software\UniExtract\File
FileKey1=%AppData%\4Sync|*.log
FileKey1=%AppData%\4Sync|*.log
FileKey1=%AppData%\Copernic\*\Searches|*.*|RECURSE
FileKey1=%AppData%\Copernic\*\Searches|*.*|RECURSE
RegKey1=HKCU\Software\Copernic\DesktopSearch2\Config\SearchHistory
RegKey1=HKCU\Software\Copernic\DesktopSearch2\Config\SearchHistory
FileKey1=%Documents%\DVDFab|*.log|RECURSE
FileKey1=%Documents%\DVDFab|*.log|RECURSE
FileKey2=%Documents%\DVDFab Passkey|*.log|RECURSE
FileKey2=%Documents%\DVDFab Passkey|*.log|RECURSE
Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\inkscape.exe
Detect=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\inkscape.exe
FileKey1=%AppData%\InkScape|*.log|RECURSE
FileKey1=%AppData%\InkScape|*.log|RECURSE
FileKey2=%UserProfile%|.recently-used.xbel
FileKey2=%UserProfile%|.recently-used.xbel
FileKey1=%AppData%\Anonymizer\Anonymizer Universal|*.log
FileKey1=%AppData%\Anonymizer\Anonymizer Universal|*.log
FileKey1=%AppData%\GG\Profiles\*\*Cache|*|RECURSE
FileKey1=%AppData%\GG\Profiles\*\*Cache|*|RECURSE
FileKey2=%AppData%\GG\logs|*.log
FileKey2=%AppData%\GG\logs|*.log
FileKey3=%AppData%\GG\Crash Reports|*|RECURSE
FileKey3=%AppData%\GG\Crash Reports|*|RECURSE
FileKey4=%AppData%\Gadu-Gadu 10\Profiles\*\*Cache|*|RECURSE
FileKey4=%AppData%\Gadu-Gadu 10\Profiles\*\*Cache|*|RECURSE
FileKey5=%AppData%\Gadu-Gadu 10\logs|*.log
FileKey5=%AppData%\Gadu-Gadu 10\logs|*.log
FileKey6=%AppData%\Gadu-Gadu 10\Crash Reports|*|RECURSE
FileKey6=%AppData%\Gadu-Gadu 10\Crash Reports|*|RECURSE
FileKey7=%AppData%\Gadu-Gadu\Profiles\*\*Cache|*|RECURSE
FileKey7=%AppData%\Gadu-Gadu\Profiles\*\*Cache|*|RECURSE
FileKey8=%AppData%\Gadu-Gadu\logs|*.log
FileKey8=%AppData%\Gadu-Gadu\logs|*.log
FileKey9=%AppData%\Gadu-Gadu\Crash Reports|*|RECURSE
FileKey9=%AppData%\Gadu-Gadu\Crash Reports|*|RECURSE
FileKey10=%AppData%\Nowe Gadu-Gadu\Profiles\*\*Cache|*|RECURSE
FileKey10=%AppData%\Nowe Gadu-Gadu\Profiles\*\*Cache|*|RECURSE
FileKey11=%AppData%\Nowe Gadu-Gadu\logs|*.log
FileKey11=%AppData%\Nowe Gadu-Gadu\logs|*.log
FileKey12=%AppData%\Nowe Gadu-Gadu\Crash Reports|*|RECURSE
FileKey12=%AppData%\Nowe Gadu-Gadu\Crash Reports|*|RECURSE
FileKey13=%LocalAppData%\GG\Profiles\*\*Cache|*|RECURSE
FileKey13=%LocalAppData%\GG\Profiles\*\*Cache|*|RECURSE
FileKey14=%LocalAppData%\GG\logs|*.log
FileKey14=%LocalAppData%\GG\logs|*.log
FileKey15=%LocalAppData%\GG\Crash Reports|*|RECURSE
FileKey15=%LocalAppData%\GG\Crash Reports|*|RECURSE
FileKey16=%LocalAppData%\Gadu-Gadu 10\Profiles\*\*Cache|*|RECURSE
FileKey16=%LocalAppData%\Gadu-Gadu 10\Profiles\*\*Cache|*|RECURSE
FileKey17=%LocalAppData%\Gadu-Gadu 10\logs|*.log
FileKey17=%LocalAppData%\Gadu-Gadu 10\logs|*.log
FileKey18=%LocalAppData%\Gadu-Gadu 10\Crash Reports|*|RECURSE
FileKey18=%LocalAppData%\Gadu-Gadu 10\Crash Reports|*|RECURSE
FileKey19=%LocalAppData%\Gadu-Gadu\Profiles\*\*Cache|*|RECURSE
FileKey19=%LocalAppData%\Gadu-Gadu\Profiles\*\*Cache|*|RECURSE
FileKey20=%LocalAppData%\Gadu-Gadu\logs|*.log
FileKey20=%LocalAppData%\Gadu-Gadu\logs|*.log
FileKey21=%LocalAppData%\Gadu-Gadu\Crash Reports|*|RECURSE
FileKey21=%LocalAppData%\Gadu-Gadu\Crash Reports|*|RECURSE
FileKey22=%LocalAppData%\Nowe Gadu-Gadu\Profiles\*\*Cache|*|RECURSE
FileKey22=%LocalAppData%\Nowe Gadu-Gadu\Profiles\*\*Cache|*|RECURSE
FileKey23=%LocalAppData%\Nowe Gadu-Gadu\logs|*.log
FileKey23=%LocalAppData%\Nowe Gadu-Gadu\logs|*.log
FileKey24=%LocalAppData%\Nowe Gadu-Gadu\Crash Reports|*|RECURSE
FileKey24=%LocalAppData%\Nowe Gadu-Gadu\Crash Reports|*|RECURSE
RegKey1=HKCU\Software\Foxit Software\Foxit PhantomPDF 5.0\Recent File List
RegKey1=HKCU\Software\Foxit Software\Foxit PhantomPDF 5.0\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0\Recent File List
RegKey3=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0\Foxit PhantomPDF Advanced Editor\Recent File List
RegKey3=HKCU\Software\Foxit Software\Foxit PhantomPDF 6.0\Foxit PhantomPDF Advanced Editor\Recent File List
Detect2=HKCU\Software\PDFCreator.net
Detect2=HKCU\Software\PDFCreator.net
FileKey1=%ProgramFiles%\PDFCreator|SetupLog.txt
FileKey1=%ProgramFiles%\PDFCreator|SetupLog.txt
FileKey2=%AppData%\pdfforge\Images2PDF|Print-*.log
FileKey2=%AppData%\pdfforge\Images2PDF|Print-*.log
FileKey3=%AppData%\pdfforge\Images2PDF|PrintPDF-*.log
FileKey3=%AppData%\pdfforge\Images2PDF|PrintPDF-*.log
FileKey4=%AppData%\pdfforge\Images2PDF\Tmp|*.prnt|REMOVESELF
FileKey4=%AppData%\pdfforge\Images2PDF\Tmp|*.prnt|REMOVESELF
FileKey5=%LocalAppData%\Temp\PDFCreator\Spool|*.*
FileKey5=%LocalAppData%\Temp\PDFCreator\Spool|*.*
FileKey6=%LocalAppData%\PDFCreator|PDFCreator.log
FileKey6=%LocalAppData%\PDFCreator|PDFCreator.log
RegKey1=HKCU\Software\PDFCreator\Program|LastsaveDirectory
RegKey1=HKCU\Software\PDFCreator\Program|LastsaveDirectory
FileKey1=%AppData%\PDF Architect\Thumbnails|*.*
FileKey1=%AppData%\PDF Architect\Thumbnails|*.*
RegKey1=HKCU\Software\PDF Architect\Recent File List
RegKey1=HKCU\Software\PDF Architect\Recent File List
RegKey2=HKCU\Software\PDF Architect 2\Options\RecentDocuments\List
RegKey2=HKCU\Software\PDF Architect 2\Options\RecentDocuments\List
FileKey1=%AppData%\Firetrust\MailWasher\logs|*.*|RECURSE
FileKey1=%AppData%\Firetrust\MailWasher\logs|*.*|RECURSE
FileKey2=%AppData%\Firetrust\MailWasher|log_*|RECURSE
FileKey2=%AppData%\Firetrust\MailWasher|log_*|RECURSE
FileKey3=%AppData%\Firetrust\MailWasher|regex.txt
FileKey3=%AppData%\Firetrust\MailWasher|regex.txt
FileKey4=%AppData%\Firetrust\MailWasher|updatesAIU.txt
FileKey4=%AppData%\Firetrust\MailWasher|updatesAIU.txt
ExcludeKey1=FILE|%AppData%\Firetrust\MailWasher\cache|*mwp_exw.dat;*mwp_conv.dat;*mwp_inw.dat;*mwp_pmap.dat;*MWP.db3
ExcludeKey1=FILE|%AppData%\Firetrust\MailWasher\cache|*mwp_exw.dat;*mwp_conv.dat;*mwp_inw.dat;*mwp_pmap.dat;*MWP.db3
FileKey1=%AppData%\Samsung\Kies|UpdateLog.txt;UpdateList.txt;*.log|RECURSE
FileKey1=%AppData%\Samsung\Kies|UpdateLog.txt;UpdateList.txt;*.log|RECURSE
FileKey2=%AppData%\Samsung\Kies\UpdateTemp|*.*|RECURSE
FileKey2=%AppData%\Samsung\Kies\UpdateTemp|*.*|RECURSE
FileKey3=%CommonAppData%\Samsung\Kies|ConnectionManager.log;Kiesairmessage.log
FileKey3=%CommonAppData%\Samsung\Kies|ConnectionManager.log;Kiesairmessage.log
FileKey4=%AppData%\Samsung\Kies\TempFiles|*.*|RECURSE
FileKey4=%AppData%\Samsung\Kies\TempFiles|*.*|RECURSE
FileKey5=%CommonAppData%\Samsung\Device Error Recovery|*.log
FileKey5=%CommonAppData%\Samsung\Device Error Recovery|*.log
FileKey6=%LocalAppData%\Temp\KiesTemporary|*.dll
FileKey6=%LocalAppData%\Temp\KiesTemporary|*.dll
FileKey1=%ProgramFiles%\Connectify|install.log
FileKey1=%ProgramFiles%\Connectify|install.log
FileKey2=%CommonAppData%\Connectify\logs|*.log
FileKey2=%CommonAppData%\Connectify\logs|*.log
ExcludeKey1=%CommonAppData%\Connectify\logs|deamon.log
ExcludeKey1=%CommonAppData%\Connectify\logs|deamon.log
FileKey1=%AppData%\NCH Software\Scribe\Logs|*.*
FileKey1=%AppData%\NCH Software\Scribe\Logs|*.*
FileKey1=%AppData%\GRETECH\GomPlayer\Log|*.*
FileKey1=%AppData%\GRETECH\GomPlayer\Log|*.*
FileKey2=%AppData%\GRETECH\GomPlayer\DCache|*.*
FileKey2=%AppData%\GRETECH\GomPlayer\DCache|*.*
RegKey1=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME000
RegKey1=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME000
RegKey2=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME001
RegKey2=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME001
RegKey3=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME002
RegKey3=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME002
RegKey4=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME003
RegKey4=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME003
RegKey5=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME004
RegKey5=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME004
RegKey6=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME005
RegKey6=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME005
RegKey7=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME006
RegKey7=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME006
RegKey8=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME007
RegKey8=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME007
RegKey9=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME008
RegKey9=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME008
RegKey10=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME009
RegKey10=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME009
RegKey11=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME010
RegKey11=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME010
RegKey12=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME011
RegKey12=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME011
RegKey13=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME012
RegKey13=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME012
RegKey14=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME013
RegKey14=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME013
RegKey15=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME014
RegKey15=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME014
RegKey16=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME015
RegKey16=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME015
RegKey17=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME016
RegKey17=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME016
RegKey18=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME017
RegKey18=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME017
RegKey19=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME018
RegKey19=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME018
RegKey20=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME019
RegKey20=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME019
RegKey21=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME020
RegKey21=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME020
RegKey22=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME021
RegKey22=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME021
RegKey23=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME022
RegKey23=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME022
RegKey24=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME023
RegKey24=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME023
RegKey25=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME024
RegKey25=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME024
RegKey26=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME025
RegKey26=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME025
RegKey27=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME026
RegKey27=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME026
RegKey28=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME027
RegKey28=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME027
RegKey29=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME028
RegKey29=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME028
RegKey30=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME029
RegKey30=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME029
RegKey31=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME030
RegKey31=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME030
RegKey32=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME031
RegKey32=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME031
RegKey33=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME032
RegKey33=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME032
RegKey34=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME033
RegKey34=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME033
RegKey35=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME034
RegKey35=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME034
RegKey36=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME035
RegKey36=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME035
RegKey37=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME036
RegKey37=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME036
RegKey38=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME037
RegKey38=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME037
RegKey39=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME038
RegKey39=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME038
RegKey40=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME039
RegKey40=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME039
RegKey41=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME040
RegKey41=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME040
RegKey42=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME041
RegKey42=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME041
RegKey43=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME042
RegKey43=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME042
RegKey44=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME043
RegKey44=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME043
RegKey45=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME044
RegKey45=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME044
RegKey46=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME045
RegKey46=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME045
RegKey47=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME046
RegKey47=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME046
RegKey48=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME047
RegKey48=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME047
RegKey49=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME048
RegKey49=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME048
RegKey50=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME049
RegKey50=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIANAME049
RegKey51=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS000
RegKey51=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS000
RegKey52=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS001
RegKey52=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS001
RegKey53=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS002
RegKey53=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS002
RegKey54=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS003
RegKey54=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS003
RegKey55=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS004
RegKey55=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS004
RegKey56=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS005
RegKey56=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS005
RegKey57=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS006
RegKey57=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS006
RegKey58=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS007
RegKey58=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS007
RegKey59=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS008
RegKey59=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS008
RegKey60=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS009
RegKey60=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS009
RegKey61=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS010
RegKey61=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS010
RegKey62=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS011
RegKey62=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS011
RegKey63=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS012
RegKey63=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS012
RegKey64=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS013
RegKey64=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS013
RegKey65=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS014
RegKey65=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS014
RegKey66=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS015
RegKey66=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS015
RegKey67=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS016
RegKey67=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS016
RegKey68=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS017
RegKey68=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS017
RegKey69=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS018
RegKey69=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS018
RegKey70=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS019
RegKey70=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS019
RegKey71=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS020
RegKey71=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS020
RegKey72=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS021
RegKey72=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS021
RegKey73=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS022
RegKey73=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS022
RegKey74=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS023
RegKey74=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS023
RegKey75=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS024
RegKey75=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS024
RegKey76=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS025
RegKey76=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS025
RegKey77=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS026
RegKey77=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS026
RegKey78=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS027
RegKey78=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS027
RegKey79=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS028
RegKey79=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS028
RegKey80=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS029
RegKey80=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS029
RegKey81=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS030
RegKey81=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS030
RegKey82=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS031
RegKey82=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS031
RegKey83=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS032
RegKey83=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS032
RegKey84=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS033
RegKey84=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS033
RegKey85=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS034
RegKey85=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS034
RegKey86=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS035
RegKey86=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS035
RegKey87=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS036
RegKey87=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS036
RegKey88=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS037
RegKey88=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS037
RegKey89=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS038
RegKey89=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS038
RegKey90=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS039
RegKey90=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS039
RegKey91=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS040
RegKey91=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS040
RegKey92=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS041
RegKey92=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS041
RegKey93=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS042
RegKey93=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS042
RegKey94=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS043
RegKey94=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS043
RegKey95=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS044
RegKey95=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS044
RegKey96=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS045
RegKey96=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS045
RegKey97=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS046
RegKey97=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS046
RegKey98=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS047
RegKey98=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS047
RegKey99=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS048
RegKey99=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS048
RegKey100=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS049
RegKey100=HKCU\Software\GRETECH\GomPlayer\OPTION|_RECENTMEDIAPOS049
RegKey101=HKCU\Software\GRETECH\GomPlayer\OPTION|sRecentFolder
RegKey101=HKCU\Software\GRETECH\GomPlayer\OPTION|sRecentFolder
RegKey102=HKCU\Software\GRETECH\GomPlayer\OPTION|sRecentFile
RegKey102=HKCU\Software\GRETECH\GomPlayer\OPTION|sRecentFile
RegKey103=HKCU\Software\GRETECH\GomPlayer\OPTION|sRecentURL
RegKey103=HKCU\Software\GRETECH\GomPlayer\OPTION|sRecentURL
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.SkypeApp_kzf8qxf38zg5c
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.SkypeApp_kzf8qxf38zg5c
DetectFile=%LocalAppData%\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c
DetectFile=%LocalAppData%\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c
FileKey1=%LocalAppData%\Packages\Microsoft.SkypeApp_*\AC\Temp|*.*
FileKey1=%LocalAppData%\Packages\Microsoft.SkypeApp_*\AC\Temp|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.SkypeApp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.SkypeApp_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.SkypeApp_*\LocalState\*\logs|*.skypelog
FileKey3=%LocalAppData%\Packages\Microsoft.SkypeApp_*\LocalState\*\logs|*.skypelog
FileKey4=%LocalAppData%\Packages\Microsoft.SkypeApp_*\TempState\Sync_*TempCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.SkypeApp_*\TempState\Sync_*TempCache|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.SkypeApp_*\Settings|LastModified.txt
FileKey5=%LocalAppData%\Packages\Microsoft.SkypeApp_*\Settings|LastModified.txt
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.SkypeApp_kzf8qxf38zg5c\SearchHistory
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.SkypeApp_kzf8qxf38zg5c\SearchHistory
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.SkypeApp_kzf8qxf38zg5c\PSR\AddedContactSince
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.SkypeApp_kzf8qxf38zg5c\PSR\AddedContactSince
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\9E2F88E3.Twitter_wgeqdkkx372wm
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\9E2F88E3.Twitter_wgeqdkkx372wm
DetectFile=%LocalAppData%\Packages\9E2F88E3.Twitter_wgeqdkkx372wm
DetectFile=%LocalAppData%\Packages\9E2F88E3.Twitter_wgeqdkkx372wm
FileKey1=%LocalAppData%\Packages\*Twitter_*\AC\Microsoft\CLR_v4.0\|Twitter-*.LOG|RECURSE
FileKey1=%LocalAppData%\Packages\*Twitter_*\AC\Microsoft\CLR_v4.0\|Twitter-*.LOG|RECURSE
FileKey2=%LocalAppData%\Packages\*Twitter_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey2=%LocalAppData%\Packages\*Twitter_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey3=%LocalAppData%\Packages\*Twitter_*\AC\Microsoft\CryptnetUrlCache\MetaData|Twitter-*.*
FileKey3=%LocalAppData%\Packages\*Twitter_*\AC\Microsoft\CryptnetUrlCache\MetaData|Twitter-*.*
FileKey4=%LocalAppData%\Packages\*Twitter_*\AC\Temp|*.*
FileKey4=%LocalAppData%\Packages\*Twitter_*\AC\Temp|*.*
FileKey5=%LocalAppData%\Packages\*Twitter_*\LocalState\CameraPicker\|*.png|RECURSE
FileKey5=%LocalAppData%\Packages\*Twitter_*\LocalState\CameraPicker\|*.png|RECURSE
FileKey6=%LocalAppData%\Packages\*Twitter_*\TempState|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\*Twitter_*\TempState|*.*|RECURSE
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\9E2F88E3.Twitter_wgeqdkkx372wm\SearchHistory
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\9E2F88E3.Twitter_wgeqdkkx372wm\SearchHistory
ExcludeKey1=FILE|%LocalAppData%\Packages\*Twitter_*\AC\Microsoft\CryptnetUrlCache\Content\|Twitter-SyncNow.db
ExcludeKey1=FILE|%LocalAppData%\Packages\*Twitter_*\AC\Microsoft\CryptnetUrlCache\Content\|Twitter-SyncNow.db
DetectFile=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga
DetectFile=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_ynb6jyjzte8ga
FileKey1=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\INetCache|*.*
FileKey1=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\INetCache|*.*
FileKey2=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\INetCookies|*.*
FileKey2=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\INetCookies|*.*
FileKey3=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\INetHistory|*.*
FileKey3=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\INetHistory|*.*
FileKey4=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\Microsoft\CLR_v4.0\UsageLogs|AdobeReader*.log
FileKey4=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\Microsoft\CLR_v4.0\UsageLogs|AdobeReader*.log
FileKey5=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\Temp|*.*
FileKey5=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\AC\Temp|*.*
FileKey6=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\LocalState\*\logs|Adobe-*.log
FileKey6=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\LocalState\*\logs|Adobe-*.log
FileKey7=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\TempState|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\AdobeSystemsIncorporated.AdobeReader_*\TempState|*.*|RECURSE
DetectFile=%LocalAppData%\Packages\Microsoft.Bing_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.Bing_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.Bing_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey1=%LocalAppData%\Packages\Microsoft.Bing_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.Bing_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.Bing_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.Bing_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.Bing_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Bing_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.Bing_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Bing_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.Bing_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.Bing_*\AC\AppCache|*.*
FileKey6=%LocalAppData%\Packages\Microsoft.Bing_*\AC\AppCache|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.Bing_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.Bing_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.Bing_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.Bing_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.Bing_*\AC\PRICache|*_sync.dac
FileKey9=%LocalAppData%\Packages\Microsoft.Bing_*\AC\PRICache|*_sync.dac
FileKey10=%LocalAppData%\Packages\Microsoft.Bing_*\TempState|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.Bing_*\TempState|*.*|RECURSE
DetectFile=%LocalAppData%\Packages\Microsoft.BingFinance_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingFinance_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey1=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*
FileKey6=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.BingFinance_*\LocalState\Cache|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.BingFinance_*\LocalState\Cache|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.BingFinance_*\LocalState\navigationHistory|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingFinance_*\LocalState\navigationHistory|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\Internet Explorer\DOMStore|*.*
FileKey9=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\Microsoft\Internet Explorer\DOMStore|*.*
FileKey10=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\PriAppCache|*.*
FileKey10=%LocalAppData%\Packages\Microsoft.BingFinance_*\AC\PriAppCache|*.*
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingfinance_8wekyb3d8bbwe\Internet Explorer\DOMStorage\microsoft.bingfinance\SearchHistory
RegKey1=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingfinance_8wekyb3d8bbwe\Internet Explorer\DOMStorage\microsoft.bingfinance\SearchHistory
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingfinance_8wekyb3d8bbwe\Internet Explorer\DOMStorage\microsoft.bingfinance\RecentVisit
RegKey2=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingfinance_8wekyb3d8bbwe\Internet Explorer\DOMStorage\microsoft.bingfinance\RecentVisit
DetectFile=%LocalAppData%\Packages\Microsoft.BingMaps_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingMaps_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey1=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingMaps_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingMaps_*\LocalState\Cache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingMaps_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingMaps_*\TempState|*.state
FileKey7=%LocalAppData%\Packages\Microsoft.BingMaps_*\TempState|*.state
DetectFile=%LocalAppData%\Packages\Microsoft.BingNews_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingNews_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey1=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\AppCache|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\AppCache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Temp|*.*
FileKey8=%LocalAppData%\Packages\Microsoft.BingNews_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingNews_*\LocalState\Cache|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey10=%LocalAppData%\Packages\Microsoft.BingNews_*\TempState|*.sync
FileKey10=%LocalAppData%\Packages\Microsoft.BingNews_*\TempState|*.sync
FileKey11=%LocalAppData%\Packages\Microsoft.BingNews*\LocalState\appCache|*.rfc
FileKey11=%LocalAppData%\Packages\Microsoft.BingNews*\LocalState\appCache|*.rfc
FileKey12=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.log
FileKey12=%LocalAppData%\Packages\Microsoft.BingNews_*\AC\Microsoft\CLR_v4.0\UsageLogs|*.log
[Bing Sports]
[Bing Sports]
DetectFile=%LocalAppData%\Packages\Microsoft.BingSports_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingSports_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey1=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*
FileKey6=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.BingSports_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingSports_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingSports_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.BingSports_*\LocalState\Cache|_sessionState2.xml
ExcludeKey1=FILE|%LocalAppData%\Packages\Microsoft.BingSports_*\LocalState\Cache|_sessionState2.xml
DetectFile=%LocalAppData%\Packages\Microsoft.BingTravel_8wekyb3d8bbwe
DetectFile=%LocalAppData%\Packages\Microsoft.BingTravel_8wekyb3d8bbwe
FileKey1=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey1=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey2=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey3=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\INetCache|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\INetCookies|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\INetHistory|*.*|RECURSE
FileKey6=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\Temp|*.*
FileKey6=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\Temp|*.*
FileKey7=%LocalAppData%\Packages\Microsoft.BingTravel_*\LocalState\Cache|*.*|RECURSE
FileKey7=%LocalAppData%\Packages\Microsoft.BingTravel_*\LocalState\Cache|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingTravel_*\LocalState\navigationHistory|*.*|RECURSE
FileKey8=%LocalAppData%\Packages\Microsoft.BingTravel_*\LocalState\navigationHistory|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey9=%LocalAppData%\Packages\Microsoft.BingTravel_*\AC\Microsoft\Internet Explorer\DOMStore|*.*|RECURSE
FileKey1=%LocalAppData%\Sony\ErrorReport|*.erpt
FileKey1=%LocalAppData%\Sony\ErrorReport|*.erpt
FileKey2=%LocalAppData%\Sony\Vegas Pro\12.0|*.log
FileKey2=%LocalAppData%\Sony\Vegas Pro\12.0|*.log
FileKey3=%AppData%\Sony|SCS_INSTALLER_1.log
FileKey3=%AppData%\Sony|SCS_INSTALLER_1.log
FileKey4=%AppData%\Sony|*.dmp
FileKey4=%AppData%\Sony|*.dmp
FileKey5=%AppData%\Sony\Vegas Pro\12.0|localstorage_*.tmp
FileKey5=%AppData%\Sony\Vegas Pro\12.0|localstorage_*.tmp
FileKey6=%AppData%\Sony\Vegas Pro\12.0|_lastsession.log
FileKey6=%AppData%\Sony\Vegas Pro\12.0|_lastsession.log
FileKey1=%AppData%\GPSoftware\Directory Opus\Logs|*.*
FileKey1=%AppData%\GPSoftware\Directory Opus\Logs|*.*
FileKey2=%LocalAppData%\GPSoftware\Directory Opus\State Data\MRU|find_name.osd
FileKey2=%LocalAppData%\GPSoftware\Directory Opus\State Data\MRU|find_name.osd
FileKey3=%LocalAppData%\GPSoftware\Directory Opus\State Data\MRU|find_path.osd
FileKey3=%LocalAppData%\GPSoftware\Directory Opus\State Data\MRU|find_path.osd
FileKey4=%LocalAppData%\GPSoftware\Directory Opus\State Data\MRU|zippy.osd
FileKey4=%LocalAppData%\GPSoftware\Directory Opus\State Data\MRU|zippy.osd
FileKey5=%AppData%\GPSoftware\Directory Opus\Thumbnail Cache|*_do.cache
FileKey5=%AppData%\GPSoftware\Directory Opus\Thumbnail Cache|*_do.cache
RegKey1=HKLM\SOFTWARE\Wow6432Node\GPSoftware\Directory Opus\10.5.2.0|ItemListFilter
RegKey1=HKLM\SOFTWARE\Wow6432Node\GPSoftware\Directory Opus\10.5.2.0|ItemListFilter
FileKey1=%SystemDrive%\NVIDIA|*.*|REMOVESELF
FileKey1=%SystemDrive%\NVIDIA|*.*|REMOVESELF
FileKey2=%SystemDrive%\NV|*.*|REMOVESELF
FileKey2=%SystemDrive%\NV|*.*|REMOVESELF
FileKey1=%ProgramData%\Canneverbe Limited\CDBurnerXP\*.*.*.*|OperationLog.log
FileKey1=%ProgramData%\Canneverbe Limited\CDBurnerXP\*.*.*.*|OperationLog.log
FileKey2=%AppData%\Canneverbe Limited\CDBurnerXP|StarBurn.log
FileKey2=%AppData%\Canneverbe Limited\CDBurnerXP|StarBurn.log
FileKey3=%AppData%\Canneverbe Limited\CDBurnerXP\*.*.*.*|*.tmp
FileKey3=%AppData%\Canneverbe Limited\CDBurnerXP\*.*.*.*|*.tmp
RegKey1=HKCU\Software\Canneverbe Limited\CDBurnerXP\PathsPrev
RegKey1=HKCU\Software\Canneverbe Limited\CDBurnerXP\PathsPrev
FileKey1=%AppData%\IDMComp\UltraEdit|projects.lst
FileKey1=%AppData%\IDMComp\UltraEdit|projects.lst
FileKey2=%AppData%\IDMComp\Common\FTP Accounts|IdmFTPAccounts_bak.txt
FileKey2=%AppData%\IDMComp\Common\FTP Accounts|IdmFTPAccounts_bak.txt
FileKey3=%LocalAppData%\Downloaded Installations\UltraEdit\*|UltraEdit_.msi
FileKey3=%LocalAppData%\Downloaded Installations\UltraEdit\*|UltraEdit_.msi
FileKey1=%CommonAppData%\Photodex\ProShow|photodex-presenter-install.log
FileKey1=%CommonAppData%\Photodex\ProShow|photodex-presenter-install.log
FileKey2=%CommonAppData%\Photodex\ProShow Producer|photodex-presenter-install.log
FileKey2=%CommonAppData%\Photodex\ProShow Producer|photodex-presenter-install.log
FileKey3=%ProgramFiles%\Photodex\ProShow Producer|install.log
FileKey3=%ProgramFiles%\Photodex\ProShow Producer|install.log
FileKey1=%AppData%\SketchUp\SketchUp 2013\SketchUp|~*.tmp
FileKey1=%AppData%\SketchUp\SketchUp 2013\SketchUp|~*.tmp
RegKey1=HKCU\Software\SketchUp\SketchUp 2013\Recent File List
RegKey1=HKCU\Software\SketchUp\SketchUp 2013\Recent File List
Detect3=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Handbrake.exe
Detect3=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Handbrake.exe
FileKey1=%AppData%\HandBrake\logs|*.txt
FileKey1=%AppData%\HandBrake\logs|*.txt
FileKey2=%AppData%\HandBrake\HandBrake\*|*.tmp
FileKey2=%AppData%\HandBrake\HandBrake\*|*.tmp
RegKey1=HKCU\Software\ABBYY\FineReader\11.00\Shell\MainFrame\RecentFileList
RegKey1=HKCU\Software\ABBYY\FineReader\11.00\Shell\MainFrame\RecentFileList
RegKey2=HKCU\Software\ABBYY\FineReader\11.00\Shell\Dialogs|LoadImagePath
RegKey2=HKCU\Software\ABBYY\FineReader\11.00\Shell\Dialogs|LoadImagePath
RegKey3=HKCU\Software\ABBYY\FineReader\11.00\Shell\Dialogs|SaveImagePath
RegKey3=HKCU\Software\ABBYY\FineReader\11.00\Shell\Dialogs|SaveImagePath
FileKey1=%ProgramFiles%\ABBYY FineReader 11|ABBYY FineReader 11.log
FileKey1=%ProgramFiles%\ABBYY FineReader 11|ABBYY FineReader 11.log
FileKey2=%ProgramData%\ABBYY\Bonus.ScreenshotReader\11.00|*.thumbnail
FileKey2=%ProgramData%\ABBYY\Bonus.ScreenshotReader\11.00|*.thumbnail
FileKey3=%ProgramData%\ABBYY\FineReader\11.00\Licenses|ProductLicensing.log
FileKey3=%ProgramData%\ABBYY\FineReader\11.00\Licenses|ProductLicensing.log
FileKey1=%AppData%\The Bat!|TheBat_Exceptions.log
FileKey1=%AppData%\The Bat!|TheBat_Exceptions.log
FileKey2=%AppData%\The Bat!\*|ACCOUNT_LOG.TXT
FileKey2=%AppData%\The Bat!\*|ACCOUNT_LOG.TXT
FileKey1=%commonprogramfiles%\Wondershare\Wondershare Helper Compact\log\Data|*.*|RECURSE
FileKey1=%commonprogramfiles%\Wondershare\Wondershare Helper Compact\log\Data|*.*|RECURSE
FileKey2=%ProgramFiles%\Wondershare\Video Converter Ultimate\Log|*.*
FileKey2=%ProgramFiles%\Wondershare\Video Converter Ultimate\Log|*.*
FileKey3=%CommonAppData%\Wondershare Video Converter Ultimate|*.dat.bak
FileKey3=%CommonAppData%\Wondershare Video Converter Ultimate|*.dat.bak
FileKey4=%CommonAppData%\Wondershare Video Converter Ultimate\TempSiteIconDir|*.*
FileKey4=%CommonAppData%\Wondershare Video Converter Ultimate\TempSiteIconDir|*.*
FileKey5=%CommonAppData%\Wondershare Video Converter Ultimate\TempThumbDir|*.*
FileKey5=%CommonAppData%\Wondershare Video Converter Ultimate\TempThumbDir|*.*
FileKey1=%LocalAppData%\Sublime Text 3\Index|LOG.old
FileKey1=%LocalAppData%\Sublime Text 3\Index|LOG.old
FileKey2=%LocalAppData%\Sublime Text 3\Index|00*.log
FileKey2=%LocalAppData%\Sublime Text 3\Index|00*.log
FileKey1=%LocalAppData%\Google\Picasa2|network.log;network_expwebsites.log
FileKey1=%LocalAppData%\Google\Picasa2|network.log;network_expwebsites.log
FileKey2=%LocalAppData%\Google\GBScreensaver|network.log
FileKey2=%LocalAppData%\Google\GBScreensaver|network.log
FileKey3=%LocalAppData%\Google\Google Auto Backup|network.log
FileKey3=%LocalAppData%\Google\Google Auto Backup|network.log
FileKey4=%LocalAppData%\Google\Picasa2\cache|*.*|RECURSE
FileKey4=%LocalAppData%\Google\Picasa2\cache|*.*|RECURSE
FileKey5=%LocalAppData%\Google\Picasa2\temp|*.*|RECURSE
FileKey5=%LocalAppData%\Google\Picasa2\temp|*.*|RECURSE
FileKey6=%LocalAppData%\Google\Picasa2\tmp|PluginRec.dat;PluginRec.dat_bak
FileKey6=%LocalAppData%\Google\Picasa2\tmp|PluginRec.dat;PluginRec.dat_bak
RegKey1=HKCU\Software\Kingsoft\Office\6.0\et\RecentFiles
RegKey1=HKCU\Software\Kingsoft\Office\6.0\et\RecentFiles
RegKey2=HKCU\Software\Kingsoft\Office\6.0\et\RecentFunction
RegKey2=HKCU\Software\Kingsoft\Office\6.0\et\RecentFunction
RegKey3=HKCU\Software\Kingsoft\Office\6.0\wpp\RecentFiles
RegKey3=HKCU\Software\Kingsoft\Office\6.0\wpp\RecentFiles
RegKey4=HKCU\Software\Kingsoft\Office\6.0\wps\RecentFiles
RegKey4=HKCU\Software\Kingsoft\Office\6.0\wps\RecentFiles
FileKey1=%AppData%\Kingsoft\*|*.bak2
FileKey1=%AppData%\Kingsoft\*|*.bak2
FileKey2=%CommonAppData%\Kingsoft\Office6\LocalTemp|*.*
FileKey2=%CommonAppData%\Kingsoft\Office6\LocalTemp|*.*
FileKey3=%LocalAppData%\Kingsoft\et\cache\http|*.*|RECURSE
FileKey3=%LocalAppData%\Kingsoft\et\cache\http|*.*|RECURSE
FileKey4=%LocalAppData%\Kingsoft\et\cache\https|*.*|RECURSE
FileKey4=%LocalAppData%\Kingsoft\et\cache\https|*.*|RECURSE
FileKey5=%LocalAppData%\Kingsoft\wpp\cache\http|*.*|RECURSE
FileKey5=%LocalAppData%\Kingsoft\wpp\cache\http|*.*|RECURSE
FileKey6=%LocalAppData%\Kingsoft\wps\cache\http|*.*|RECURSE
FileKey6=%LocalAppData%\Kingsoft\wps\cache\http|*.*|RECURSE
FileKey7=%LocalAppData%\Kingsoft\wps\cache\https|*.*|RECURSE
FileKey7=%LocalAppData%\Kingsoft\wps\cache\https|*.*|RECURSE
FileKey8=%AppData%\Kingsoft\office6\backup|*.*
FileKey8=%AppData%\Kingsoft\office6\backup|*.*
FileKey9=%AppData%\Kingsoft\office6\log\*|*.log
FileKey9=%AppData%\Kingsoft\office6\log\*|*.log
FileKey10=%AppData%\Kingsoft\office6\update\log|*.log
FileKey10=%AppData%\Kingsoft\office6\update\log|*.log
FileKey11=%AppData%\Kingsoft\office6\update\down|*.src
FileKey11=%AppData%\Kingsoft\office6\update\down|*.src
FileKey12=%AppData%\Kingsoft\office6\update\dump|*.dmp
FileKey12=%AppData%\Kingsoft\office6\update\dump|*.dmp
FileKey13=%AppData%\Kingsoft\office6\update\log\package|*.pkg
FileKey13=%AppData%\Kingsoft\office6\update\log\package|*.pkg
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Facebook.Facebook_8xx8rvfyw5nnt
Detect=HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Facebook.Facebook_8xx8rvfyw5nnt
FileKey1=%LocalAppData%\Packages\*Facebook_*\AC\AppCache|*.*|RECURSE
FileKey1=%LocalAppData%\Packages\*Facebook_*\AC\AppCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*Facebook_*\AC\INetCache|*.*|RECURSE
FileKey2=%LocalAppData%\Packages\*Facebook_*\AC\INetCache|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\*Facebook_*\AC\INetCookies|*.*|RECURSE
FileKey3=%LocalAppData%\Packages\*Facebook_*\AC\INetCookies|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\*Facebook_*\AC\INetHistory|*.*|RECURSE
FileKey4=%LocalAppData%\Packages\*Facebook_*\AC\INetHistory|*.*|RECURSE
FileKey5=%LocalAppData%\Packages\*Facebook_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey5=%LocalAppData%\Packages\*Facebook_*\AC\Microsoft\CLR_v4.0|*.log|RECURSE
FileKey6=%LocalAppData%\Packages\*Facebook_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey6=%LocalAppData%\Packages\*Facebook_*\AC\Microsoft\CryptnetUrlCache\Content|*.*
FileKey7=%LocalAppData%\Packages\*Facebook_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey7=%LocalAppData%\Packages\*Facebook_*\AC\Microsoft\CryptnetUrlCache\MetaData|*.*
FileKey8=%LocalAppData%\Packages\*Facebook_*\AC\PRICache|*.*
FileKey8=%LocalAppData%\Packages\*Facebook_*\AC\PRICache|*.*
FileKey9=%LocalAppData%\Packages\*Facebook_*\AC\Temp|*.*
FileKey9=%LocalAppData%\Packages\*Facebook_*\AC\Temp|*.*
RegKey1=Software\Xilisoft\Video Converter Platinum\Settings|last_output_dir
RegKey1=Software\Xilisoft\Video Converter Platinum\Settings|last_output_dir
RegKey2=Software\Xilisoft\Video Converter Platinum\Settings|last_profile_group
RegKey2=Software\Xilisoft\Video Converter Platinum\Settings|last_profile_group
RegKey3=Software\Xilisoft\Video Converter Platinum\Settings|last_profile_url
RegKey3=Software\Xilisoft\Video Converter Platinum\Settings|last_profile_url
RegKey4=Software\Xilisoft\Video Converter Platinum\Settings|recent_profiles
RegKey4=Software\Xilisoft\Video Converter Platinum\Settings|recent_profiles
RegKey5=Software\Xilisoft\Video Converter Platinum\Settings\output
RegKey5=Software\Xilisoft\Video Converter Platinum\Settings\output
Filekey1=%CommonAppData%\Xilisoft\Video Converter Platinum\customdata|settings.old
Filekey1=%CommonAppData%\Xilisoft\Video Converter Platinum\customdata|settings.old
RegKey1=Software\Xilisoft\DVD Ripper Ultimate SE\Settings|last_output_dir
RegKey1=Software\Xilisoft\DVD Ripper Ultimate SE\Settings|last_output_dir
RegKey2=Software\Xilisoft\DVD Ripper Ultimate SE\Settings|last_profile_group
RegKey2=Software\Xilisoft\DVD Ripper Ultimate SE\Settings|last_profile_group
RegKey3=Software\Xilisoft\DVD Ripper Ultimate SE\Settings|last_profile_url
RegKey3=Software\Xilisoft\DVD Ripper Ultimate SE\Settings|last_profile_url
RegKey4=Software\Xilisoft\DVD Ripper Ultimate SE\Settings|recent_profiles
RegKey4=Software\Xilisoft\DVD Ripper Ultimate SE\Settings|recent_profiles
RegKey5=Software\Xilisoft\DVD Ripper Ultimate SE\Settings\output
RegKey5=Software\Xilisoft\DVD Ripper Ultimate SE\Settings\output
FileKey1=%CommonAppData%\Xilisoft\DVD Ripper Ultimate SE\customdata|settings.old
FileKey1=%CommonAppData%\Xilisoft\DVD Ripper Ultimate SE\customdata|settings.old
RegKey1=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder0
RegKey1=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder0
RegKey2=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder1
RegKey2=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder1
RegKey3=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder2
RegKey3=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder2
RegKey4=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder3
RegKey4=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder3
RegKey5=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder4
RegKey5=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder4
RegKey6=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder5
RegKey6=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder5
RegKey7=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder6
RegKey7=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder6
RegKey8=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder7
RegKey8=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder7
RegKey9=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder8
RegKey9=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder8
RegKey10=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder9
RegKey10=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder9
RegKey11=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder10
RegKey11=HKCU\Software\Illustrate\dBpoweramp|dMCLastFolder10
RegKey12=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\AAC (Advanced Audio Compression)|DMCUserFolderStr
RegKey12=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\AAC (Advanced Audio Compression)|DMCUserFolderStr
RegKey13=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\Aiff|DMCUserFolderStr
RegKey13=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\Aiff|DMCUserFolderStr
RegKey14=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\Apple Lossless|DMCUserFolderStr
RegKey14=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\Apple Lossless|DMCUserFolderStr
RegKey15=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\FLAC|DMCUserFolderStr
RegKey15=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\FLAC|DMCUserFolderStr
RegKey16=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\mp3 (Lame)|DMCUserFolderStr
RegKey16=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\mp3 (Lame)|DMCUserFolderStr
RegKey17=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\ogg vorbis|DMCUserFolderStr
RegKey17=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\ogg vorbis|DMCUserFolderStr
RegKey18=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\Wave|DMCUserFolderStr
RegKey18=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\Wave|DMCUserFolderStr
RegKey19=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\Windows Media Audio 10|DMCUserFolderStr
RegKey19=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\Windows Media Audio 10|DMCUserFolderStr
RegKey20=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\[Multi Encoder]|DMCUserFolderStr
RegKey20=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\[Multi Encoder]|DMCUserFolderStr
RegKey21=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\Test Conversion|DMCUserFolderStr
RegKey21=HKCU\Software\Illustrate\dBpoweramp\dMCCodec\Test Conversion|DMCUserFolderStr
RegKey22=HKCU\Software\Illustrate\dBpoweramp|LastAccessedFolder
RegKey22=HKCU\Software\Illustrate\dBpoweramp|LastAccessedFolder
FileKey1=%LocalAppData%\2BrightSparks\SyncBackFree\Logs|*.*
FileKey1=%LocalAppData%\2BrightSparks\SyncBackFree\Logs|*.*
FileKey2=%LocalAppData%\2BrightSparks\SyncBackFree|Debug*.txt
FileKey2=%LocalAppData%\2BrightSparks\SyncBackFree|Debug*.txt
FileKey1=%ProgramFiles%\Wondershare Video Converter Pro\TempThumbDir|*.*|RECURSE
FileKey1=%ProgramFiles%\Wondershare Video Converter Pro\TempThumbDir|*.*|RECURSE
FileKey2=%ProgramFiles%\Wondershare Video Converter Pro\Log|*.*|RECURSE
FileKey2=%ProgramFiles%\Wondershare Video Converter Pro\Log|*.*|RECURSE
FileKey3=%CommonAppData%\Wondershare Video Converter Pro|*.dat.bak
FileKey3=%CommonAppData%\Wondershare Video Converter Pro|*.dat.bak
FileKey4=%CommonAppData%\Wondershare Video Converter Pro\TempSiteIconDir|*.*
FileKey4=%CommonAppData%\Wondershare Video Converter Pro\TempSiteIconDir|*.*
FileKey5=%CommonAppData%\Wondershare Video Converter Pro\TempThumbDir|*.*
FileKey5=%CommonAppData%\Wondershare Video Converter Pro\TempThumbDir|*.*
FileKey6=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact\Temp|video*.exe
FileKey6=%CommonProgramFiles%\Wondershare\Wondershare Helper Compact\Temp|video*.exe
FileKey7=%ProgramFiles%\Wondershare\Video Converter Pro\Output|Thumbnail.dat
FileKey7=%ProgramFiles%\Wondershare\Video Converter Pro\Output|Thumbnail.dat
FileKey1=%ProgramFiles%\Aimersoft\Video Converter Ultimate\Log|*.*
FileKey1=%ProgramFiles%\Aimersoft\Video Converter Ultimate\Log|*.*
FileKey2=%ProgramFiles%\Aimersoft\Video Converter Ultimate\Snapshot|snap*.dat
FileKey2=%ProgramFiles%\Aimersoft\Video Converter Ultimate\Snapshot|snap*.dat
FileKey3=%ProgramFiles%\Common Files\Aimersoft\Aimersoft Helper Compact\log|*.*|RECURSE
FileKey3=%ProgramFiles%\Common Files\Aimersoft\Aimersoft Helper Compact\log|*.*|RECURSE
FileKey4=%CommonAppData%\Aimersoft Video Converter Ultimate\TempSiteIconDir|*.*
FileKey4=%CommonAppData%\Aimersoft Video Converter Ultimate\TempSiteIconDir|*.*
FileKey5=%CommonAppData%\Aimersoft Video Converter Ultimate\TempThumbDir|*.*
FileKey5=%CommonAppData%\Aimersoft Video Converter Ultimate\TempThumbDir|*.*
FileKey6=%CommonAppData%\Aimersoft Video Converter Ultimate|*.dat.bak
FileKey6=%CommonAppData%\Aimersoft Video Converter Ultimate|*.dat.bak
FileKey7=%LocalAppData%\Aimersoft\ASHelper|*.exe.tmp
FileKey7=%LocalAppData%\Aimersoft\ASHelper|*.exe.tmp
FileKey8=%AppData%\Aimersoft Video Converter Ultimate\Temp|*.*
FileKey8=%AppData%\Aimersoft Video Converter Ultimate\Temp|*.*
RegKey1=HKCU\Software\Stardock\WindowBlinds\WB5.ini\Recent
RegKey1=HKCU\Software\Stardock\WindowBlinds\WB5.ini\Recent
FileKey1=%Public%\Documents\Stardock\WindowBlinds|StardockB*.dmp
FileKey1=%Public%\Documents\Stardock\WindowBlinds|StardockB*.dmp
RegKey1=HKCU\Software\Nitro\Pro\9.0\Recent File List
RegKey1=HKCU\Software\Nitro\Pro\9.0\Recent File List
RegKey2=HKCU\Software\Nitro\Pro\9.0\Settings\Preferences\kPreferences|kCurrentOpenPath
RegKey2=HKCU\Software\Nitro\Pro\9.0\Settings\Preferences\kPreferences|kCurrentOpenPath
FileKey1=%CommonProgramFiles%\Nitro\Pro\9.0|*.backup
FileKey1=%CommonProgramFiles%\Nitro\Pro\9.0|*.backup
FileKey2=%CommonAppData%\Package Cache|*.rsm
FileKey2=%CommonAppData%\Package Cache|*.rsm
FileKey3=%AppData%\Downloaded Installations|*_temp.msi|RECURSE
FileKey3=%AppData%\Downloaded Installations|*_temp.msi|RECURSE
FileKey4=%AppData%\Nitro\Pro\9.0|DocLog.txt
FileKey4=%AppData%\Nitro\Pro\9.0|DocLog.txt
RegKey1=HKCU\Software\Nitro PDF\Reader\3.0\Recent File List
RegKey1=HKCU\Software\Nitro PDF\Reader\3.0\Recent File List
FileKey1=%Documents%\VirtualDJ\TrackListing|tracklist.txt
FileKey1=%Documents%\VirtualDJ\TrackListing|tracklist.txt
[Format Factory 3.3.5]
[Format Factory 3.3.5]
RegKey1=HKCU\Software\FreeTime\FormatFactory|LastUse
RegKey1=HKCU\Software\FreeTime\FormatFactory|LastUse
FileKey1=%Documents%\FormatFactory|*.task
FileKey1=%Documents%\FormatFactory|*.task
RegKey1=HKCU\Software\TeamViewer\Version9|MRU
RegKey1=HKCU\Software\TeamViewer\Version9|MRU
FileKey1=%ProgramFiles%\TeamViewer\*|*.tmp|RECURSE
FileKey1=%ProgramFiles%\TeamViewer\*|*.tmp|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\TeamViewer\*|*.tmp|RECURSE
FileKey2=%LocalAppData%\VirtualStore\Program Files*\TeamViewer\*|*.tmp|RECURSE
FileKey3=%ProgramFiles%\TeamViewer\Version9|Connections_incoming.txt
FileKey3=%ProgramFiles%\TeamViewer\Version9|Connections_incoming.txt
FileKey4=%AppData%\TeamViewer|Connections.txt
FileKey4=%AppData%\TeamViewer|Connections.txt
FileKey5=%AppData%\TeamViewer\MRU\RemoteSupport|*.tvc
FileKey5=%AppData%\TeamViewer\MRU\RemoteSupport|*.tvc
FileKey1=%LocalAppData%\Microsoft\SkyDrive\logs|*.log;*.etl
FileKey1=%LocalAppData%\Microsoft\SkyDrive\logs|*.log;*.etl
RegKey1=HKCU\Software\RealVNC\vncviewer\MRU
RegKey1=HKCU\Software\RealVNC\vncviewer\MRU
FileKey1=%LocalAppData%\RealVNC|vncviewer.log
FileKey1=%LocalAppData%\RealVNC|vncviewer.log
Detect=HKCU\Software\Softpointer\Tag&Rename3.7\Config
Detect=HKCU\Software\Softpointer\Tag&Rename3.7\Config
RegKey1=HKCU\Software\Softpointer\Tag&Rename3.7\Config|CurrentFolder
RegKey1=HKCU\Software\Softpointer\Tag&Rename3.7\Config|CurrentFolder
RegKey2=HKCU\Software\Softpointer\Tag&Rename3.7\Config|HistoryList
RegKey2=HKCU\Software\Softpointer\Tag&Rename3.7\Config|HistoryList
DetectFile=%ProgramFiles%\Tango\Tango.exe
DetectFile=%ProgramFiles%\Tango\Tango.exe
FileKey1=%LocalAppData%\tango|call_log.dat
FileKey1=%LocalAppData%\tango|call_log.dat
[PhotoScape 3.6.5]
[PhotoScape 3.6.5]
FileKey1=%AppData%\PhotoScape|*.lst;*.cfg;*.jpg
FileKey1=%AppData%\PhotoScape|*.lst;*.cfg;*.jpg
FileKey1=%CommonAppData%\BlueStacks\logs|*.log;*.log.*|RECURSE
FileKey1=%CommonAppData%\BlueStacks\logs|*.log;*.log.*|RECURSE
FileKey2=%LocalAppData%\BlueStacks\logs|*.log
FileKey2=%LocalAppData%\BlueStacks\logs|*.log
FileKey3=%CommonAppData%\BlueStacksSetup\Images\|*.*|REMOVESELF
FileKey3=%CommonAppData%\BlueStacksSetup\Images\|*.*|REMOVESELF
FileKey4=%CommonAppData%\BlueStacksSetup|runtimedata_*.zip;runtimedata_*.zip.manifest
FileKey4=%CommonAppData%\BlueStacksSetup|runtimedata_*.zip;runtimedata_*.zip.manifest
FileKey5=%CommonAppData%\BlueStacksSetup|bstInstall.log
FileKey5=%CommonAppData%\BlueStacksSetup|bstInstall.log
ExcludeKey1=FILE|%CommonAppData%\BlueStacks\logs\core.log
ExcludeKey1=FILE|%CommonAppData%\BlueStacks\logs\core.log
ExcludeKey2=FILE|%CommonAppData%\BlueStacks\logs\BlueStacksUpdater.log
ExcludeKey2=FILE|%CommonAppData%\BlueStacks\logs\BlueStacksUpdater.log
ExcludeKey3=FILE|%CommonAppData%\BlueStacks\logs\BlueStacksUsers.log
ExcludeKey3=FILE|%CommonAppData%\BlueStacks\logs\BlueStacksUsers.log
[ManyCam 4.0.109]
[ManyCam 4.0.109]
RegKey1=HKCU\Software\Visicom Media\ManyCam\ui|open_media_folder
RegKey1=HKCU\Software\Visicom Media\ManyCam\ui|open_media_folder
RegKey2=HKCU\Software\Visicom Media\ManyCam\ui|open_audio_folder
RegKey2=HKCU\Software\Visicom Media\ManyCam\ui|open_audio_folder
RegKey3=HKCU\Software\Visicom Media\ManyCam\ui|open_game_folder
RegKey3=HKCU\Software\Visicom Media\ManyCam\ui|open_game_folder
RegKey4=HKCU\Software\Visicom Media\ManyCam\ui|open_playlist_folder
RegKey4=HKCU\Software\Visicom Media\ManyCam\ui|open_playlist_folder
FileKey1=%LocalAppData%\ManyCam\game_capture|*.log
FileKey1=%LocalAppData%\ManyCam\game_capture|*.log
FileKey1=%AppData%\XnView|XnView.db;category.bak
FileKey1=%AppData%\XnView|XnView.db;category.bak
FileKey2=%ProgramFiles%\XnView|category.bak
FileKey2=%ProgramFiles%\XnView|category.bak
FileKey3=%LocalAppData%\VirtualStore\Program Files*\XnView|category.bak
FileKey3=%LocalAppData%\VirtualStore\Program Files*\XnView|category.bak
FileKey4=%ProgramFiles%\XnView\cache|*.db
FileKey4=%ProgramFiles%\XnView\cache|*.db
FileKey5=%LocalAppData%\VirtualStore\Program Files*\XnView\cache|*.dbPA
FileKey5=%LocalAppData%\VirtualStore\Program Files*\XnView\cache|*.dbPA
...aLp
...aLp
1.sHwR
1.sHwR
Z.VxU
Z.VxU
fz@A%d
fz@A%d
wAA%d FX
wAA%d FX
MMMH%S
MMMH%S
q6.JZ'
q6.JZ'
ox%F/
ox%F/
-a}S,
-a}S,
E.SU9
E.SU9
%F*E#
%F*E#
dJH%S
dJH%S
xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/"
xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/"
xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/"
xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/"
xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#"
xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#"
xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/"
xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/"
xmlns:dc="hXXp://purl.org/dc/elements/1.1/"
xmlns:dc="hXXp://purl.org/dc/elements/1.1/"
xmlns:tiff="hXXp://ns.adobe.com/tiff/1.0/"
xmlns:tiff="hXXp://ns.adobe.com/tiff/1.0/"
xmlns:exif="hXXp://ns.adobe.com/exif/1.0/">
xmlns:exif="hXXp://ns.adobe.com/exif/1.0/">
Adobe Photoshop CC 2015 (Windows)
Adobe Photoshop CC 2015 (Windows)
xmp.iid:4be171b1-d8e4-fc45-972d-d7a264b0676d
xmp.iid:4be171b1-d8e4-fc45-972d-d7a264b0676d
adobe:docid:photoshop:43035dd0-8221-11e5-a09b-ae5e2a8faf78
adobe:docid:photoshop:43035dd0-8221-11e5-a09b-ae5e2a8faf78
xmp.did:0c662d1c-d4f7-9d47-88de-776ec96f35df
xmp.did:0c662d1c-d4f7-9d47-88de-776ec96f35df
xmp.iid:0c662d1c-d4f7-9d47-88de-776ec96f35df
xmp.iid:0c662d1c-d4f7-9d47-88de-776ec96f35df
Adobe Photoshop CC 2015 (Windows)
Adobe Photoshop CC 2015 (Windows)
xmp.iid:4be171b1-d8e4-fc45-972d-d7a264b0676d
xmp.iid:4be171b1-d8e4-fc45-972d-d7a264b0676d
08/12/15
08/12/15
g>.CI
g>.CI
.ktz
.ktz
.lTgP
.lTgP
@%.PI
@%.PI
L.wL^OIzE
L.wL^OIzE
_w}
_w}
Paint.NET v3.5.11G
Paint.NET v3.5.11G
}R
}R
(iTXtXML:com.adobe.xmp
(iTXtXML:com.adobe.xmp
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> ^
" id="W5M0MpCehiHzreSzNTczkc9d"?> ^
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> I
" id="W5M0MpCehiHzreSzNTczkc9d"?> I
v.INNN.$!
v.INNN.$!
juY.PKC
juY.PKC
%cl}n
%cl}n
Q-O}odr
Q-O}odr
%U:i
%U:i
u.Sz]
u.Sz]
K.miW
K.miW
fgS.ka
fgS.ka
}2{%s
}2{%s
ai.rY
ai.rY
R!'.wr
R!'.wr
U%UR:W
U%UR:W
v'%D`'
v'%D`'
TI%XH
TI%XH
mSgL%M
mSgL%M
0>@%c
0>@%c
).OK5M
).OK5M
.xDr":c
.xDr":c
&h%2U]
&h%2U]
}@
}@
p,)
p,)
p.QqQ
p.QqQ
G.MNn
G.MNn
hxW5[
hxW5[
j.uEn
j.uEn
.YxuwO
.YxuwO
P(Å’DUq
P(Å’DUq
%X~ib
%X~ib
.qGSA
.qGSA
C.VrA
C.VrA
.prVWx
.prVWx
Ip.Rt
Ip.Rt
iTXtXML:com.adobe.xmp
iTXtXML:com.adobe.xmp
xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/">
xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/">
Adobe Fireworks CS6 (Windows)
Adobe Fireworks CS6 (Windows)
xmlns:dc="hXXp://purl.org/dc/elements/1.1/">
xmlns:dc="hXXp://purl.org/dc/elements/1.1/">
%F@$M5
%F@$M5
%XBJq x^F
%XBJq x^F
i%S#ElWOO
i%S#ElWOO
h6.Jq
h6.Jq
}).EA
}).EA
)%xi.
)%xi.
M}%s=~
M}%s=~
%U=hE
%U=hE
-
-
*.Yf:(
*.Yf:(
"""!"""!'''
"""!"""!'''
Piriform CCleanerTruePs
Piriform CCleanerTruePs
3&414@4{5
3&414@4{5
9"90959
9"90959
4&50;\;1
4&50;\;1
5_7V7]7
5_7V7]7
2(3`3'4>4~4
2(3`3'4>4~4
7&7.747:7^7
7&7.747:7^7
0#0(0.0?0
0#0(0.0?0
7"7(70767
7"7(70767
0%0X0t091K1Y1~1
0%0X0t091K1Y1~1
2,21262
2,21262
00R0
00R0
4'4.4;4^4
4'4.4;4^4
4-595}5
4-595}5
4!4/484=4
4!4/484=4
6%6-636[6
6%6-636[6
5 5,52575=5
5 5,52575=5
: :$:(:,:0:4:8:<:>
: :$:(:,:0:4:8:<:>
> >$>(>,>0>4>8>
> >$>(>,>0>4>8>
4O4W4
4O4W4
0%1*1@1[1
0%1*1@1[1
77K7
77K7
3"3&3*3.323
3"3&3*3.323
4 4:4,5>5
4 4:4,5>5
:%:,:3:9:
:%:,:3:9:
> >1>?>^>
> >1>?>^>
0%0u1
0%0u1
0"060;0[0
0"060;0[0
?6?;?@?|?
?6?;?@?|?
9!9)909{9
9!9)909{9
5]5T5
5]5T5
2 2u3
2 2u3
8'92999@9
8'92999@9
;#;'; ;/;3;:;
;#;'; ;/;3;:;
111>1]1}1
111>1]1}1
6-7}7
6-7}7
> >$>(>,>0>
> >$>(>,>0>
5,6064686
5,6064686
; ;$;(;,;0;4;8;
; ;$;(;,;0;4;8;
> >4>8?
> >4>8?
; ;$;(;,;0;4;8;
; ;$;(;,;0;4;8;
3 3$3(3,3034383
3 3$3(3,3034383
6 6$6(6,60646
6 6$6(6,60646
1 1$1(1,1014181
1 1$1(1,1014181
5 5$5(5,50545
5 5$5(5,50545
8 8$8(8,808
8 8$8(8,808
> >$>(>,>0>4>
> >$>(>,>0>4>
= =$=(=,=0=4=8=
= =$=(=,=0=4=8=
6 6$6(6,6064686
6 6$6(6,6064686
7 7$7(7,707
7 7$7(7,707
8 8$8(8,80848
8 8$8(8,80848
; ;
; ;
?,?8?\?|?
?,?8?\?|?
:$:,:8:\:|:
:$:,:8:\:|:
5,585\5|5
5,585\5|5
4$4,484\4|4
4$4,484\4|4
2$2,282\2|2
2$2,282\2|2
7$7,787\7|7
7$7,787\7|7
3,383@3\3|3
3,383@3\3|3
8,848@8|8
8,848@8|8
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
- floating point support not loaded
- floating point support not loaded
WUSER32.DLL
WUSER32.DLL
Breakpad/1.0 (Windows)
Breakpad/1.0 (Windows)
888816666554443
888816666554443
6666554443
6666554443
!6666554443
!6666554443
%s[%d]: %s
%s[%d]: %s
SQLITE_OK
SQLITE_OK
SQLITE_ERROR
SQLITE_ERROR
SQLITE_INTERNAL
SQLITE_INTERNAL
SQLITE_PERM
SQLITE_PERM
SQLITE_ABORT
SQLITE_ABORT
SQLITE_BUSY
SQLITE_BUSY
SQLITE_LOCKED
SQLITE_LOCKED
SQLITE_NOMEM
SQLITE_NOMEM
SQLITE_READONLY
SQLITE_READONLY
SQLITE_INTERRUPT
SQLITE_INTERRUPT
SQLITE_IOERR
SQLITE_IOERR
SQLITE_CORRUPT
SQLITE_CORRUPT
SQLITE_NOTFOUND
SQLITE_NOTFOUND
SQLITE_FULL
SQLITE_FULL
SQLITE_CANTOPEN
SQLITE_CANTOPEN
SQLITE_PROTOCOL
SQLITE_PROTOCOL
SQLITE_EMPTY
SQLITE_EMPTY
SQLITE_SCHEMA
SQLITE_SCHEMA
SQLITE_TOOBIG
SQLITE_TOOBIG
SQLITE_CONSTRAINT
SQLITE_CONSTRAINT
SQLITE_MISMATCH
SQLITE_MISMATCH
SQLITE_MISUSE
SQLITE_MISUSE
SQLITE_NOLFS
SQLITE_NOLFS
SQLITE_AUTH
SQLITE_AUTH
SQLITE_FORMAT
SQLITE_FORMAT
SQLITE_RANGE
SQLITE_RANGE
SQLITE_ROW
SQLITE_ROW
SQLITE_DONE
SQLITE_DONE
CPPSQLITE_ERROR
CPPSQLITE_ERROR
select count(*) from sqlite_master where type='table' and name='%s'
select count(*) from sqlite_master where type='table' and name='%s'
Re&port
Re&port
XMessageBox.ini
XMessageBox.ini
%s = %d
%s = %d
RegKey
RegKey
FileKey
FileKey
SpecialKey
SpecialKey
ScriptKey
ScriptKey
ExcludeKey
ExcludeKey
ccleaner.ini
ccleaner.ini
portable.dat
portable.dat
%m/%d/%Y %I:%M:%S %p
%m/%d/%Y %I:%M:%S %p
h%d/%d/%d %d:%d:%d %s
h%d/%d/%d %d:%d:%d %s
MSG_CONFIRMCLEAN
MSG_CONFIRMCLEAN
MSG_WARNMOZCACHE
MSG_WARNMOZCACHE
MSG_WARNMOZHISTORY
MSG_WARNMOZHISTORY
MSG_WARNTHUNDERBIRDCACHE
MSG_WARNTHUNDERBIRDCACHE
MSG_WARNTHUNDERBIRDHISTORY
MSG_WARNTHUNDERBIRDHISTORY
MSG_WARNOPERACACHE
MSG_WARNOPERACACHE
MSG_WARNCHROMECACHE
MSG_WARNCHROMECACHE
ShowFirefoxCleanWarning
ShowFirefoxCleanWarning
ShowGoogleChromeCleanWarning
ShowGoogleChromeCleanWarning
ShowOperaCleanWarning
ShowOperaCleanWarning
ShowWebCacheCleanWarning
ShowWebCacheCleanWarning
%s%s%s%d%s
%s%s%s%d%s
Google Chrome
Google Chrome
h*64.exe
h*64.exe
/select,"%s"
/select,"%s"
hGoogle Chrome
hGoogle Chrome
h%d%%
h%d%%
user32.dll
user32.dll
Software\Microsoft\Windows\CurrentVersion\Uninstall
Software\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages
Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache
Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache
Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache
Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache
Packages\windows_ie_ac_001\AC\Microsoft\Internet Explorer\DOMStore
Packages\windows_ie_ac_001\AC\Microsoft\Internet Explorer\DOMStore
Mozilla/4.0 (CCleaner, %s)
Mozilla/4.0 (CCleaner, %s)
%d.%d%s%d
%d.%d%s%d
hXXps://VVV.piriform.com/inapp/ccshop
hXXps://VVV.piriform.com/inapp/ccshop
%s?a=%s&p=%s&c=%s&v=%s&l=%s&mk=%s&o=%s
%s?a=%s&p=%s&c=%s&v=%s&l=%s&mk=%s&o=%s
&itag=%s
&itag=%s
&pid=%s
&pid=%s
pid=%s
pid=%s
LKey
LKey
OnNavigateError = %d - %s
OnNavigateError = %d - %s
Clicked on %s (tag:%s)
Clicked on %s (tag:%s)
All (*.*)
All (*.*)
#HttpOnly_
#HttpOnly_
DOMStore:hXXp://
DOMStore:hXXp://
DOMStore:hXXps://
DOMStore:hXXps://
hPiriform::Breakpad::CKeyboardHook::Message::B4E8893A-C6C1-4c98-BFFC-B81923F8C77D
hPiriform::Breakpad::CKeyboardHook::Message::B4E8893A-C6C1-4c98-BFFC-B81923F8C77D
hhXXp://VVV.piriform.com/go/app_cc_reg_renew
hhXXp://VVV.piriform.com/go/app_cc_reg_renew
hXXp://VVV.piriform.com/auto
hXXp://VVV.piriform.com/auto
hhXXp://VVV.piriform.com/ccleaner/update
hhXXp://VVV.piriform.com/ccleaner/update
*64.exe
*64.exe
shell32.dll
shell32.dll
*.png
*.png
Error: %d - %s
Error: %d - %s
Text Files (*.txt)
Text Files (*.txt)
*.txt
*.txt
install.txt
install.txt
%s %s
%s %s
PSAPI.DLL
PSAPI.DLL
\regedit.exe
\regedit.exe
regedit.exe
regedit.exe
rundll32.exe
rundll32.exe
*%commonprogramfiles%*
*%commonprogramfiles%*
%CommonProgramW6432%
%CommonProgramW6432%
%commonprogramfiles%
%commonprogramfiles%
1|1|1|1|0|0|0
1|1|1|1|0|0|0
SystemAnalyzer.txt
SystemAnalyzer.txt
h/select,"%s"
h/select,"%s"
startup.txt
startup.txt
*\desktop.ini
*\desktop.ini
Analyzing file content - %d
Analyzing file content - %d
duplicate.txt
duplicate.txt
%s - %s %c
%s - %s %c
hPackages\windows_ie_ac_001\AC\Microsoft\Internet Explorer\DOMStore
hPackages\windows_ie_ac_001\AC\Microsoft\Internet Explorer\DOMStore
Piriform.CCleaner
Piriform.CCleaner
hXXp://VVV.piriform.com
hXXp://VVV.piriform.com
hXXp://VVV.piriform.com/ccleaner
hXXp://VVV.piriform.com/ccleaner
hXXp://VVV.piriform.com/go/app_cc_home_help
hXXp://VVV.piriform.com/go/app_cc_home_help
hXXp://VVV.piriform.com/go/app_cc_home_icon
hXXp://VVV.piriform.com/go/app_cc_home_icon
hXXp://VVV.piriform.com/go/app_cc_home_title
hXXp://VVV.piriform.com/go/app_cc_home_title
hXXp://VVV.piriform.com/go/app_cc_home_pear
hXXp://VVV.piriform.com/go/app_cc_home_pear
hXXp://VVV.piriform.com/go/app_cc_reg_purchase
hXXp://VVV.piriform.com/go/app_cc_reg_purchase
hXXp://VVV.piriform.com/go/app_cc_tracking
hXXp://VVV.piriform.com/go/app_cc_tracking
license.ini
license.ini
LicenseKey
LicenseKey
autotrial.dat
autotrial.dat
business.dat
business.dat
update.ini
update.ini
hRecently Typed URLs
hRecently Typed URLs
Mozilla - Cookies
Mozilla - Cookies
Opera - Cookies
Opera - Cookies
Google Chrome - Cookies
Google Chrome - Cookies
Delete Index.dat files
Delete Index.dat files
user.dat
user.dat
ntuser.dat
ntuser.dat
usrclass.dat
usrclass.dat
v%d.d.d
v%d.d.d
%s%s%s%s%s
%s%s%s%s%s
%d.d.d
%d.d.d
%s.ini
%s.ini
ResourceID_%d
ResourceID_%d
FIREFOX
FIREFOX
CHROME
CHROME
OPERA
OPERA
hbranding.dll
hbranding.dll
v1.00.001
v1.00.001
v2.00.001
v2.00.001
hXXp://VVV.piriform.com/go/app_cc_reg_renew
hXXp://VVV.piriform.com/go/app_cc_reg_renew
hXXp://VVV.piriform.com/ccleaner/update
hXXp://VVV.piriform.com/ccleaner/update
Piriform::Breakpad::CKeyboardHook::Message::B4E8893A-C6C1-4c98-BFFC-B81923F8C77D
Piriform::Breakpad::CKeyboardHook::Message::B4E8893A-C6C1-4c98-BFFC-B81923F8C77D
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_USERS
HKEY_USERS
HKEY_CURRENT_USER
HKEY_CURRENT_USER
history.txt
history.txt
cookies.txt
cookies.txt
hXXp://VVV.piriform.com/go/app_cc_social_facebook
hXXp://VVV.piriform.com/go/app_cc_social_facebook
hhXXp://VVV.piriform.com/go/app_cc_social_twitter
hhXXp://VVV.piriform.com/go/app_cc_social_twitter
hXXp://VVV.piriform.com/go/app_cc_social_googleplus
hXXp://VVV.piriform.com/go/app_cc_social_googleplus
hXXp://VVV.piriform.com/go/app_cc_social_youtube
hXXp://VVV.piriform.com/go/app_cc_social_youtube
%s?a=%s&v=%s&l=%s
%s?a=%s&v=%s&l=%s
hhXXp://VVV.piriform.com/go/app_cc_home_help
hhXXp://VVV.piriform.com/go/app_cc_home_help
0x%x: %s
0x%x: %s
Error activating - %s
Error activating - %s
Error activating - %d: %s
Error activating - %d: %s
&t=%s
&t=%s
&id=%d&bt=%d
&id=%d&bt=%d
hXXps://license.piriform.com/activate/?p=%s&c=%s&cv=%s&l=%s&lk=%s&mk=%s
hXXps://license.piriform.com/activate/?p=%s&c=%s&cv=%s&l=%s&lk=%s&mk=%s
hXXps://VVV.piriform.com/go/app_cc_be_trialkey
hXXps://VVV.piriform.com/go/app_cc_be_trialkey
hXXps://VVV.piriform.com/go/app_cc_pro_trialkey
hXXps://VVV.piriform.com/go/app_cc_pro_trialkey
hXXps://license.piriform.com/verify
hXXps://license.piriform.com/verify
hXXps://license.piriform.com/activate
hXXps://license.piriform.com/activate
a=%s&
a=%s&
%s/?%sp=%s&c=%s&cv=%s&l=%s&lk=%s&mk=%s
%s/?%sp=%s&c=%s&cv=%s&l=%s&lk=%s&mk=%s
64.exe
64.exe
hhXXp://VVV.piriform.com/go/app_cc_reg_purchase
hhXXp://VVV.piriform.com/go/app_cc_reg_purchase
hLicenseKey
hLicenseKey
hautotrial.dat
hautotrial.dat
hbusiness.dat
hbusiness.dat
Registry Key
Registry Key
cc_%ddd_ddd.reg
cc_%ddd_ddd.reg
Reg Files (*.reg)
Reg Files (*.reg)
*.reg
*.reg
SpecialKey1
SpecialKey1
registry.txt
registry.txt
CCScanreg.txt
CCScanreg.txt
*.piriform.com
*.piriform.com
login.live.com
login.live.com
mail.google.com
mail.google.com
VVV.google.com/accounts
VVV.google.com/accounts
google.com/accounts
google.com/accounts
google.com
google.com
VVV.google.com
VVV.google.com
accounts.google.com
accounts.google.com
webmail.earthlink.net
webmail.earthlink.net
mail.netscape.com
mail.netscape.com
mail.yahoo.com
mail.yahoo.com
yahoo.com
yahoo.com
webmail.aol.com
webmail.aol.com
my.screenname.aol.com
my.screenname.aol.com
fastmail.fm
fastmail.fm
mail.lycos.com
mail.lycos.com
mail.ru
mail.ru
auth.me.com
auth.me.com
ovi.com/services/signin
ovi.com/services/signin
login.comcast.net
login.comcast.net
VVV.mail.lycos.com
VVV.mail.lycos.com
mail.aol.com
mail.aol.com
icloud.com
icloud.com
screenname.aol.com
screenname.aol.com
aol.com
aol.com
facebook.com
facebook.com
twitter.com
twitter.com
%d / %d
%d / %d
Error %d - %s
Error %d - %s
%%.Þ
%%.Þ
%%.ß
%%.ß
iMozilla/4.0 (CCleaner, %s)
iMozilla/4.0 (CCleaner, %s)
log.txt
log.txt
*dllhost.exe
*dllhost.exe
dllhost.exe
dllhost.exe
i*/Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}*
i*/Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}*
File %s does not exist.
File %s does not exist.
iexplore.exe
iexplore.exe
spartan.exe
spartan.exe
edge.exe
edge.exe
webcache.exe
webcache.exe
MicrosoftEdge.exe
MicrosoftEdge.exe
MicrosoftEdgeCP.exe
MicrosoftEdgeCP.exe
- %s %c
- %s %c
iShowFirefoxCleanWarning
iShowFirefoxCleanWarning
iShowGoogleChromeCleanWarning
iShowGoogleChromeCleanWarning
iShowOperaCleanWarning
iShowOperaCleanWarning
iShowWebCacheCleanWarning
iShowWebCacheCleanWarning
iPiriform::Breakpad::CKeyboardHook::Message::B4E8893A-C6C1-4c98-BFFC-B81923F8C77D
iPiriform::Breakpad::CKeyboardHook::Message::B4E8893A-C6C1-4c98-BFFC-B81923F8C77D
\macromedia.com\support\flashplayer\sys\
\macromedia.com\support\flashplayer\sys\
settings.sol
settings.sol
Shockwave Flash\macromedia.com\support\flashplayer\sys\
Shockwave Flash\macromedia.com\support\flashplayer\sys\
*\Shockwave Flash\*\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol
*\Shockwave Flash\*\#SharedObjects\*\macromedia.com\support\flashplayer\sys\settings.sol
*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com*
*\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*\macromedia.com*
macromedia.com
macromedia.com
com.apple.Safari.plist
com.apple.Safari.plist
WebpageIcons.db
WebpageIcons.db
CCleaner requires Windows XP or later.
CCleaner requires Windows XP or later.
CCleaner64.exe
CCleaner64.exe
ccleaner_checkpoint.dat
ccleaner_checkpoint.dat
hXXp://VVV.piriform.com/go/app_cc_privacy_policy?a=%s&v=%s&l=%s
hXXp://VVV.piriform.com/go/app_cc_privacy_policy?a=%s&v=%s&l=%s
Error loading branding.dll %s- 0x%x: %s
Error loading branding.dll %s- 0x%x: %s
Extra error loading branding.dll %s- 0x%x: %s
Extra error loading branding.dll %s- 0x%x: %s
branding.dll
branding.dll
iv1.00.001
iv1.00.001
iv%d.d.d
iv%d.d.d
?a=%s&v=%s&l=%s
?a=%s&v=%s&l=%s
ihXXp://VVV.piriform.com/go/app_cc_home_title
ihXXp://VVV.piriform.com/go/app_cc_home_title
ihXXp://VVV.piriform.com/go/app_cc_home_pear
ihXXp://VVV.piriform.com/go/app_cc_home_pear
iPackages\windows_ie_ac_001\AC\Microsoft\Internet Explorer\DOMStore
iPackages\windows_ie_ac_001\AC\Microsoft\Internet Explorer\DOMStore
*/Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}*
*/Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}*
/export
/export
uninst.exe
uninst.exe
Uninstall.lnk
Uninstall.lnk
3.18.1708
3.18.1708
CCInfo.txt
CCInfo.txt
CCVERSION=%s
CCVERSION=%s
CCEDITION=%s
CCEDITION=%s
CCREGISTERED=%s
CCREGISTERED=%s
OS=%s
OS=%s
CPU=%s
CPU=%s
RAM=%s
RAM=%s
GPU=%s
GPU=%s
i%m/%d/%Y %I:%M:%S %p
i%m/%d/%Y %I:%M:%S %p
%s|%s|%s|%s
%s|%s|%s|%s
%s (%s %d%%)
%s (%s %d%%)
%s (%s)
%s (%s)
ZAdvapi32.dll
ZAdvapi32.dll
DHKEY_CURRENT_CONFIG
DHKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_DYN_DATA
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_DATA
R_WINDOWS_SERVICES
R_WINDOWS_SERVICES
N_INT_PASSWORD
N_INT_PASSWORD
N_EDGE_PASSWORD
N_EDGE_PASSWORD
N_MOZ_PASSWORD
N_MOZ_PASSWORD
N_THUNDERBIRD_PASSWORD
N_THUNDERBIRD_PASSWORD
N_OPERA_CACHE
N_OPERA_CACHE
N_OPERA_HISTORY
N_OPERA_HISTORY
N_OPERA_COOKIES
N_OPERA_COOKIES
N_OPERA_WEBSITE_ICONS
N_OPERA_WEBSITE_ICONS
N_OPERA_PASSWORD
N_OPERA_PASSWORD
N_OPERA_LAST_DOWNLOAD_LOCATION
N_OPERA_LAST_DOWNLOAD_LOCATION
N_OPERA_RECENTLY_TYPED_URLS
N_OPERA_RECENTLY_TYPED_URLS
N_OPERA_SESSION
N_OPERA_SESSION
N_OPERA_HISTORY_15
N_OPERA_HISTORY_15
N_OPERA_COOKIES_15
N_OPERA_COOKIES_15
N_OPERA_DOWNLOAD
N_OPERA_DOWNLOAD
N_OPERA_FORM
N_OPERA_FORM
N_OPERA_COMPACT_DATABASES
N_OPERA_COMPACT_DATABASES
N_OPERA_SESSION_15
N_OPERA_SESSION_15
N_SAFARI_PASSWORD
N_SAFARI_PASSWORD
N_CHROME_CACHE
N_CHROME_CACHE
N_CHROME_COOKIES
N_CHROME_COOKIES
N_CHROME_HISTORY
N_CHROME_HISTORY
N_CHROME_DOWNLOAD
N_CHROME_DOWNLOAD
N_CHROME_FORM
N_CHROME_FORM
N_CHROME_PASSWORD
N_CHROME_PASSWORD
N_CHROME_SESSION
N_CHROME_SESSION
N_CHROME_COMPACT_DATABASES
N_CHROME_COMPACT_DATABASES
N_CHROME_FLASH_COOKIES
N_CHROME_FLASH_COOKIES
N_CHROME_LAST_DOWNLOAD_LOCATION
N_CHROME_LAST_DOWNLOAD_LOCATION
N_EX_NETWORK_PASSWORDS
N_EX_NETWORK_PASSWORDS
N_EX_WINDOWS_EVENT_LOGS
N_EX_WINDOWS_EVENT_LOGS
N_EX_PREVIOUS_WINDOWS_INSTALLATION
N_EX_PREVIOUS_WINDOWS_INSTALLATION
comctl32.dll
comctl32.dll
uxtheme.dll
uxtheme.dll
/|%'" ><:>
/|%'" ><:>
@%s%s
@%s%s
Kernel32.dll
Kernel32.dll
%d Files
%d Files
oSP%d
oSP%d
SOFTWARE\Microsoft\Windows NT\CurrentVersion
SOFTWARE\Microsoft\Windows NT\CurrentVersion
Windows 95
Windows 95
Windows 98
Windows 98
Windows ME
Windows ME
Windows NT
Windows NT
Windows 2000
Windows 2000
Windows XP
Windows XP
Windows Server 2003
Windows Server 2003
Windows Vista
Windows Vista
Windows Server 2008
Windows Server 2008
Windows Server 2008 R2
Windows Server 2008 R2
Windows 7
Windows 7
Windows 8
Windows 8
Windows 8.1
Windows 8.1
Windows Server 2012
Windows Server 2012
Windows Server 2012 R2
Windows Server 2012 R2
Windows 10
Windows 10
Windows
Windows
%sGB RAM
%sGB RAM
%sMB RAM
%sMB RAM
Web Server
Web Server
Zkernel32.dll
Zkernel32.dll
\\.\%s
\\.\%s
\\?\%s%s%s
\\?\%s%s%s
%s\%s
%s\%s
ntdll.dll
ntdll.dll
fmifs.dll
fmifs.dll
*$Recycle.Bin*
*$Recycle.Bin*
*desktop.ini
*desktop.ini
desktop.ini
desktop.ini
Windows.UI.Core.CoreWindow
Windows.UI.Core.CoreWindow
\DosDevices\%s
\DosDevices\%s
Dv%d.d.d
Dv%d.d.d
wininet.dll
wininet.dll
Unknown error = %d
Unknown error = %d
?%%%d
?%%%d
Portugu
Portugu
s (Portuguese)
s (Portuguese)
s do Brasil (Brazilian Portuguese)
s do Brasil (Brazilian Portuguese)
lang-*.dll
lang-*.dll
Y.dll
Y.dll
DShowOperaCleanWarning
DShowOperaCleanWarning
UpdateKey
UpdateKey
\StringFileInfo\xx\%s
\StringFileInfo\xx\%s
?usrclass.dat
?usrclass.dat
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
%CommonProgramFiles%
%CommonProgramFiles%
%CommonProgramFiles(x86)%
%CommonProgramFiles(x86)%
*%systemdirectory%*
*%systemdirectory%*
%systemdirectory%
%systemdirectory%
%SystemDirectory32%
%SystemDirectory32%
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
{A520A1A4-1780-4FF6-BD18-167343C5AF16}
{A520A1A4-1780-4FF6-BD18-167343C5AF16}
%s_Classes
%s_Classes
Microsoft\Windows
Microsoft\Windows
?Software\Microsoft\Windows\CurrentVersion\Run
?Software\Microsoft\Windows\CurrentVersion\Run
b%s%s%s%s
b%s%s%s%s
%s|%s
%s|%s
%s|%s%s%s%s%s
%s|%s%s%s%s%s
|%s|%d|%s
|%s|%d|%s
Microsoft\Windows\WebCache
Microsoft\Windows\WebCache
WebCacheV01.dat
WebCacheV01.dat
WebCacheV24.dat
WebCacheV24.dat
\Microsoft\Windows\Wininet
\Microsoft\Windows\Wininet
%s\%s\%s
%s\%s\%s
@%s.ini
@%s.ini
Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
Recently Typed URLs
Recently Typed URLs
DPRAGMA %s;
DPRAGMA %s;
SELECT id, name, value, host, path, expiry, isSecure, isHttpOnly FROM moz_cookies;
SELECT id, name, value, host, path, expiry, isSecure, isHttpOnly FROM moz_cookies;
webappsstore2
webappsstore2
SELECT scope FROM webappsstore2;
SELECT scope FROM webappsstore2;
webappsstore
webappsstore
SELECT domain FROM webappsstore;
SELECT domain FROM webappsstore;
SELECT h.id FROM moz_places h
SELECT h.id FROM moz_places h
SELECT b.id FROM moz_bookmarks b
SELECT b.id FROM moz_bookmarks b
SELECT a.id FROM moz_annos a
SELECT a.id FROM moz_annos a
select clientID,Key,Generation,DataSize from moz_cache;
select clientID,Key,Generation,DataSize from moz_cache;
thunderbird.exe
thunderbird.exe
firefox.exe
firefox.exe
mozilla.exe
mozilla.exe
seamonkey.exe
seamonkey.exe
palemoon.exe
palemoon.exe
songbird.exe
songbird.exe
k-meleon.exe
k-meleon.exe
icedragon.exe
icedragon.exe
cyberfox.exe
cyberfox.exe
compatibility.ini
compatibility.ini
application.ini
application.ini
profiles.ini
profiles.ini
user_pref("%s", %s);
user_pref("%s", %s);
%d));
%d));
DELETE FROM moz_places WHERE id IN (SELECT h.id FROM moz_places h WHERE h.id IN (
DELETE FROM moz_places WHERE id IN (SELECT h.id FROM moz_places h WHERE h.id IN (
NOT EXISTS (SELECT b.id FROM moz_bookmarks b WHERE b.fk = h.id)
NOT EXISTS (SELECT b.id FROM moz_bookmarks b WHERE b.fk = h.id)
NOT EXISTS (SELECT a.id FROM moz_annos a WHERE a.place_id = h.id))
NOT EXISTS (SELECT a.id FROM moz_annos a WHERE a.place_id = h.id))
DELETE FROM moz_favicons WHERE id IN (SELECT f.id FROM moz_favicons f LEFT OUTER JOIN moz_places h ON f.id = h.favicon_id WHERE h.favicon_id IS NULL)
DELETE FROM moz_favicons WHERE id IN (SELECT f.id FROM moz_favicons f LEFT OUTER JOIN moz_places h ON f.id = h.favicon_id WHERE h.favicon_id IS NULL)
delete from moz_hosts where id = %s
delete from moz_hosts where id = %s
DELETE FROM moz_deleted_logins
DELETE FROM moz_deleted_logins
DELETE FROM moz_logins
DELETE FROM moz_logins
%localappdata%\Google\Chrome\Application\chrome.exe
%localappdata%\Google\Chrome\Application\chrome.exe
%ProgramFiles%\Google\Chrome\Application\chrome.exe
%ProgramFiles%\Google\Chrome\Application\chrome.exe
%localappdata%\Flock\Application\flock.exe
%localappdata%\Flock\Application\flock.exe
%ProgramFiles%\Flock\Application\flock.exe
%ProgramFiles%\Flock\Application\flock.exe
%localappdata%\Google\Chrome SxS\Application\chrome.exe
%localappdata%\Google\Chrome SxS\Application\chrome.exe
%ProgramFiles%\Google\Chrome SxS\Application\chrome.exe
%ProgramFiles%\Google\Chrome SxS\Application\chrome.exe
%localappdata%\SRWare Iron\iron.exe
%localappdata%\SRWare Iron\iron.exe
%ProgramFiles%\SRWare Iron\iron.exe
%ProgramFiles%\SRWare Iron\iron.exe
%ProgramFiles%\Chromium\chrome.exe
%ProgramFiles%\Chromium\chrome.exe
%localappdata%\Chromium\chrome.exe
%localappdata%\Chromium\chrome.exe
%ProgramFiles%\Chromium\Application\chrome.exe
%ProgramFiles%\Chromium\Application\chrome.exe
%localappdata%\Chromium\Application\chrome.exe
%localappdata%\Chromium\Application\chrome.exe
%AppData%\ChromePlus\chrome.exe
%AppData%\ChromePlus\chrome.exe
%localappdata%\RockMelt\Application\rockmelt.exe
%localappdata%\RockMelt\Application\rockmelt.exe
%ProgramFiles%\RockMelt\Application\rockmelt.exe
%ProgramFiles%\RockMelt\Application\rockmelt.exe
%LocalAppData%\Comodo\Dragon\dragon.exe
%LocalAppData%\Comodo\Dragon\dragon.exe
%ProgramFiles%\Comodo\Dragon\dragon.exe
%ProgramFiles%\Comodo\Dragon\dragon.exe
%LocalAppData%\MapleStudio\ChromePlus\Application\Chrome.exe
%LocalAppData%\MapleStudio\ChromePlus\Application\Chrome.exe
%AppData%\MapleStudio\ChromePlus\Application\Chrome.exe
%AppData%\MapleStudio\ChromePlus\Application\Chrome.exe
%ProgramFiles%\baidu\Spark\chrome.exe
%ProgramFiles%\baidu\Spark\chrome.exe
%localappdata%\Torch\Application\torch.exe
%localappdata%\Torch\Application\torch.exe
%localappdata%\Yandex\YandexBrowser\Application\browser.exe
%localappdata%\Yandex\YandexBrowser\Application\browser.exe
chrome.exe
chrome.exe
flock.exe
flock.exe
iron.exe
iron.exe
rockmelt.exe
rockmelt.exe
dragon.exe
dragon.exe
spark.exe
spark.exe
torch.exe
torch.exe
browser.exe
browser.exe
operaprefs.ini
operaprefs.ini
\cookies4.dat
\cookies4.dat
\pstorage\psindex.dat
\pstorage\psindex.dat
\application_cache\cache_groups.xml
\application_cache\cache_groups.xml
opera.exe
opera.exe
.Pepper Data
.Pepper Data
index.dat
index.dat
ID=%d
ID=%d
PR=%d
PR=%d
DA=%s
DA=%s
RK=%s
RK=%s
RU=%d
RU=%d
CK=%d
CK=%d
SK=%s
SK=%s
VK=%s
VK=%s
VA=%s
VA=%s
CR=%d
CR=%d
PF=%d
PF=%d
EI=%d
EI=%d
FL=%d
FL=%d
IIT=%d
IIT=%d
FI=%d
FI=%d
SI=%d
SI=%d
%d/%d/%d %d:%d:%d %s
%d/%d/%d %d:%d:%d %s
microsoftedge.exe
microsoftedge.exe
safari.exe
safari.exe
windows...
windows...
windows
windows
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
.Startup
.Startup
.CommonStartup
.CommonStartup
{%s-%s-%s-%s-%s}
{%s-%s-%s-%s-%s}
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
WindowsInstaller
WindowsInstaller
ParentKeyName
ParentKeyName
msiexec.exe /X%s
msiexec.exe /X%s
msiexec.exe
msiexec.exe
/fpecms %s
/fpecms %s
SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\
SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\
msiexec
msiexec
*.ico
*.ico
*setup.exe
*setup.exe
*msiexec.exe
*msiexec.exe
*.dll
*.dll
*.exe
*.exe
imageres.dll
imageres.dll
"%s" %s
"%s" %s
msiexec.exe %s%s/X%s
msiexec.exe %s%s/X%s
@%s%s%s%s%s
@%s%s%s%s%s
Kernel32.DLL
Kernel32.DLL
SELECT ProcessId, CommandLine, ExecutablePath FROM Win32_Process where ProcessID=%d
SELECT ProcessId, CommandLine, ExecutablePath FROM Win32_Process where ProcessID=%d
Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved
Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved
mscoree.dll
mscoree.dll
Software\Microsoft\Windows\CurrentVersion\Ext\Settings
Software\Microsoft\Windows\CurrentVersion\Ext\Settings
{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}
{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}
{E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16}
{E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16}
*.lnk
*.lnk
Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder
Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder
hkey
hkey
%Commonprogramfiles%
%Commonprogramfiles%
*\%s\*
*\%s\*
%s|%s|%s
%s|%s|%s
|%s|%s|%s
|%s|%s|%s
Windows Shutdown
Windows Shutdown
Windows Boot
Windows Boot
Cancelled Operation
Cancelled Operation
D%s-%d
D%s-%d
%d - %s
%d - %s
CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell
CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell
CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\
CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\
@ntuser.dat
@ntuser.dat
%userprofile%\Local Settings\Temporary Internet Files
%userprofile%\Local Settings\Temporary Internet Files
Packages\windows_ie_ac_*\AC\INetCache
Packages\windows_ie_ac_*\AC\INetCache
Packages\windows_ie_ac_*\AC\AppCache
Packages\windows_ie_ac_*\AC\AppCache
SuggestedSites.dat
SuggestedSites.dat
container.dat
container.dat
%userprofile%\AppData\Local\Microsoft\Windows\History
%userprofile%\AppData\Local\Microsoft\Windows\History
%userprofile%\Local Settings\History\History.IE5
%userprofile%\Local Settings\History\History.IE5
Microsoft\Windows\History
Microsoft\Windows\History
%userprofile%
%userprofile%
Local Settings\History\History.IE5
Local Settings\History\History.IE5
\Microsoft\Windows\
\Microsoft\Windows\
Packages\windows_ie_ac_*\AC\INetHistory
Packages\windows_ie_ac_*\AC\INetHistory
InetCpl.cpl, ClearMyTracksByProcess 1
InetCpl.cpl, ClearMyTracksByProcess 1
RunDll32.exe
RunDll32.exe
*Low\History.IE5*
*Low\History.IE5*
%LocalAppData%\Packages\windows_ie_ac_001\AC\INetCookies
%LocalAppData%\Packages\windows_ie_ac_001\AC\INetCookies
*.xml
*.xml
*\windows_ie_ac_001\AC\*
*\windows_ie_ac_001\AC\*
iexplore.exe*
iexplore.exe*
pstorec.dll
pstorec.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
%s_%d
%s_%d
@WebpageIcons.db
@WebpageIcons.db
//NoLogo "%s"
//NoLogo "%s"
cscript.exe
cscript.exe
history.dat
history.dat
places.sqlite
places.sqlite
urlbarhistory.sqlite
urlbarhistory.sqlite
prefs.js
prefs.js
*\k-meleon*prefs.js
*\k-meleon*prefs.js
user_pref("kmeleon.MRU.URL
user_pref("kmeleon.MRU.URL
downloads.rdf
downloads.rdf
downloads.sqlite
downloads.sqlite
cookies.sqlite
cookies.sqlite
SiteSecurityServiceState.txt
SiteSecurityServiceState.txt
webappsstore.sqlite
webappsstore.sqlite
*.sqlite
*.sqlite
\indexedDB
\indexedDB
permissions.sqlite
permissions.sqlite
index.sqlite
index.sqlite
*\storage\*\http *
*\storage\*\http *
*\storage\*\https *
*\storage\*\https *
*index.sqlite
*index.sqlite
*\indexedDB\*.sqlite
*\indexedDB\*.sqlite
*\OfflineCache\index.sqlite
*\OfflineCache\index.sqlite
*\permissions.sqlite
*\permissions.sqlite
formhistory.dat
formhistory.dat
formhistory.sqlite
formhistory.sqlite
signons.txt
signons.txt
signons2.txt
signons2.txt
signons3.txt
signons3.txt
signons.sqlite
signons.sqlite
logins.json
logins.json
signon.SignonFileName
signon.SignonFileName
\prefs.js
\prefs.js
sessionstore.js
sessionstore.js
sessionstore.bak
sessionstore.bak
sessionstore.js;sessionstore.bak*
sessionstore.js;sessionstore.bak*
sessionCheckpoints.json
sessionCheckpoints.json
session.json
session.json
user_pref("kmeleon.plugins.sessions2
user_pref("kmeleon.plugins.sessions2
*\sessionstore.js
*\sessionstore.js
searchhistory.xml
searchhistory.xml
content-prefs.sqlite
content-prefs.sqlite
*-journal;*.tmp
*-journal;*.tmp
global.dat
global.dat
global_history.dat
global_history.dat
search_field_history.dat
search_field_history.dat
opera.dir
opera.dir
download.dat
download.dat
vlink4.dat
vlink4.dat
autosave.win
autosave.win
autosave.win.bak
autosave.win.bak
session.db
session.db
session.dbak
session.dbak
opera6.ini
opera6.ini
opera.exe*
opera.exe*
typed_history.xml
typed_history.xml
wand.dat
wand.dat
Login Data
Login Data
*.idx
*.idx
cookies4.dat
cookies4.dat
*.dat
*.dat
cache_groups.xml
cache_groups.xml
psindex.dat
psindex.dat
$Recycle.Bin
$Recycle.Bin
\cache.trash
\cache.trash
\cache.trash*\
\cache.trash*\
*.old;*.tmp
*.old;*.tmp
%localappdata%\Google\Chrome\User Data\Default\Cache
%localappdata%\Google\Chrome\User Data\Default\Cache
%localappdata%\Google\Chrome\User Data\Default\Media Cache
%localappdata%\Google\Chrome\User Data\Default\Media Cache
%localappdata%\Google\Chrome\User Data\Default\GPUCache
%localappdata%\Google\Chrome\User Data\Default\GPUCache
%localappdata%\Google\Chrome\User Data\Default\Application Cache
%localappdata%\Google\Chrome\User Data\Default\Application Cache
*\JumpListIcons*\*.tmp
*\JumpListIcons*\*.tmp
\Origin Bound Certs
\Origin Bound Certs
*.localstorage
*.localstorage
*.indexeddb
*.indexeddb
\IndexedDB
\IndexedDB
host_key
host_key
http_*.indexeddb.leveldb
http_*.indexeddb.leveldb
https_*.indexeddb.leveldb
https_*.indexeddb.leveldb
Databases.db
Databases.db
Origin Bound Certs
Origin Bound Certs
*databases\http_*_0*
*databases\http_*_0*
*databases\https_*_0*
*databases\https_*_0*
*\IndexedDB\http_*.indexeddb.leveldb\*
*\IndexedDB\http_*.indexeddb.leveldb\*
*\IndexedDB\https_*.indexeddb.leveldb\*
*\IndexedDB\https_*.indexeddb.leveldb\*
\Web Data
\Web Data
History Index*.*
History Index*.*
*.tmp
*.tmp
Web Data
Web Data
\Login Data
\Login Data
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Thumbnail Cache
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Thumbnail Cache
databases\Databases.db
databases\Databases.db
keychain.plist
keychain.plist
Apple Computer\Safari\Bookmarks.plist
Apple Computer\Safari\Bookmarks.plist
\cookies.plist
\cookies.plist
\Cookies.binarycookies
\Cookies.binarycookies
\StorageTracker.db
\StorageTracker.db
\ApplicationCache.db
\ApplicationCache.db
manifestURL
manifestURL
ApplicationCache.db
ApplicationCache.db
StorageTracker.db
StorageTracker.db
cookies.plist
cookies.plist
Cookies.binarycookies
Cookies.binarycookies
%SystemDrive%
%SystemDrive%
\Windows.old*
\Windows.old*
\$WINDOWS.~Q
\$WINDOWS.~Q
\\?\%s
\\?\%s
*\microsoft.microsoftedge_8wekyb3d8bbwe\*
*\microsoft.microsoftedge_8wekyb3d8bbwe\*
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\Cache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\Cache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\AppCache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\AppCache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\INetCache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\INetCache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\Cache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\Cache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\AppCache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\AppCache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\INetCache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\INetCache
Packages\Microsoft.Windows.Spartan_cw5n1h2txyewy\AC\Spartan\User\Default\AppCache
Packages\Microsoft.Windows.Spartan_cw5n1h2txyewy\AC\Spartan\User\Default\AppCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\Cache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\Cache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\AppCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\AppCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\AppCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\AppCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\Cache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\Cache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\AppCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\AppCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\INetCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\INetCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\User\Default\AppCache
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\User\Default\AppCache
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\History
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\History
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\INetHistory
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\INetHistory
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\History
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\History
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\INetHistory
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\INetHistory
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\History
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\History
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetHistory
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetHistory
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\History
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\History
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\INetHistory
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\INetHistory
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\Cookies
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\Cookies
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\INetCookies
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\INetCookies
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\Cookies
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\Cookies
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\INetCookies
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\INetCookies
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\Cookies
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\Cookies
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetCookies
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetCookies
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\Cookies
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\Cookies
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\INetCookies
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\INetCookies
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\User\Default\DOMStore
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\User\Default\DOMStore
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\User\Default\DOMStore
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\User\Default\DOMStore
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\DOMStore
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\DOMStore
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\User\Default\DOMStore
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\User\Default\DOMStore
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\User\Default\DownloadHistory
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\Spartan\User\Default\DownloadHistory
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\User\Default\DownloadHistory
Packages\microsoft.windows.spartan_cw5n1h2txyewy\AC\#!*\Spartan\User\Default\DownloadHistory
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\DownloadHistory
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\DownloadHistory
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\User\Default\DownloadHistory
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!*\MicrosoftEdge\User\Default\DownloadHistory
Packages\Microsoft.Windows.Spartan_cw5n1h2txyewy\AC\MicrosoftEdge\User\Default\Recovery
Packages\Microsoft.Windows.Spartan_cw5n1h2txyewy\AC\MicrosoftEdge\User\Default\Recovery
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\Recovery
Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\Recovery
@.bmp
@.bmp
.jpeg
.jpeg
.wave
.wave
.midi
.midi
.html
.html
%s\UserChoice
%s\UserChoice
%s\OpenWithProgids
%s\OpenWithProgids
%s\OpenWithList
%s\OpenWithList
{e8cc4cbe-fdff-11d0-b865-00a0c9081c1d}
{e8cc4cbe-fdff-11d0-b865-00a0c9081c1d}
{B2D2142A-9055-4C37-B3FA-EEFDD4C1DC59}
{B2D2142A-9055-4C37-B3FA-EEFDD4C1DC59}
msmsgs.exe
msmsgs.exe
{D2B7A809-15DC-40B4-A1E1-C61EA97191DB}
{D2B7A809-15DC-40B4-A1E1-C61EA97191DB}
{66228C13-C5A0-4552-B1C0-5B6FDD59CCF7}
{66228C13-C5A0-4552-B1C0-5B6FDD59CCF7}
HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
Software\Microsoft\Windows\CurrentVersion\Uninstall\
Software\Microsoft\Windows\CurrentVersion\Uninstall\
mozillaplugins
mozillaplugins
%s\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
%s\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
CLSID\%s
CLSID\%s
Software\Classes\CLSID\%s
Software\Classes\CLSID\%s
{00020424-0000-0000-C000-000000000046}
{00020424-0000-0000-C000-000000000046}
{E64169B3-3592-47d2-816E-602C5C13F328}
{E64169B3-3592-47d2-816E-602C5C13F328}
{9B4CD3E6-4981-101B-9CA8-9240CE2738AE}
{9B4CD3E6-4981-101B-9CA8-9240CE2738AE}
%systemroot%
%systemroot%
%systemroot%\system32
%systemroot%\system32
ImagePath - %s
ImagePath - %s
select * from meta where key='last_compatible_version';
select * from meta where key='last_compatible_version';
select host_key, creation_utc from cookies;
select host_key, creation_utc from cookies;
origin_bound_certs
origin_bound_certs
select origin, creation_time from origin_bound_certs;
select origin, creation_time from origin_bound_certs;
ie7_logins
ie7_logins
SELECT url_hash, password_value, date_created FROM ie7_logins;
SELECT url_hash, password_value, date_created FROM ie7_logins;
logins
logins
SELECT origin_url, action_url, username_element, username_value, password_element, password_value, submit_element, signon_realm, ssl_valid, preferred, date_created, blacklisted_by_user, scheme FROM logins;
SELECT origin_url, action_url, username_element, username_value, password_element, password_value, submit_element, signon_realm, ssl_valid, preferred, date_created, blacklisted_by_user, scheme FROM logins;
bookmarks.db
bookmarks.db
stash.db
stash.db
favorites.db
favorites.db
%s\cookies
%s\cookies
%s\Origin Bound Certs
%s\Origin Bound Certs
select host_key,creation_utc from cookies;
select host_key,creation_utc from cookies;
*Origin Bound Certs
*Origin Bound Certs
select origin as host_key, creation_time as creation_utc from origin_bound_certs;
select origin as host_key, creation_time as creation_utc from origin_bound_certs;
delete from origin_bound_certs where creation_time not in (
delete from origin_bound_certs where creation_time not in (
delete from origin_bound_certs;
delete from origin_bound_certs;
%s\Local Storage
%s\Local Storage
%s\IndexedDB
%s\IndexedDB
http_
http_
https_
https_
%s\databases\Databases.db
%s\databases\Databases.db
delete from urls where starred_id NOT in (select id from starred) or starred_id = 0
delete from urls where starred_id NOT in (select id from starred) or starred_id = 0
delete from segments where url_id not in (Select id from urls)
delete from segments where url_id not in (Select id from urls)
delete from keyword_search_terms
delete from keyword_search_terms
select id, url, favicon_id from urls
select id, url, favicon_id from urls
delete from urls where id = %s
delete from urls where id = %s
select id, url from omni_box_shortcuts
select id, url from omni_box_shortcuts
delete from omni_box_shortcuts where id = '%s'
delete from omni_box_shortcuts where id = '%s'
select * from meta where key='Default Search Provider ID';
select * from meta where key='Default Search Provider ID';
delete from keywords where show_in_default_list = 0 and safe_for_autoreplace = 1
delete from keywords where show_in_default_list = 0 and safe_for_autoreplace = 1
and id != %d
and id != %d
select id, favicon_id from urls
select id, favicon_id from urls
delete from thumbnails where url_id not in (
delete from thumbnails where url_id not in (
select id, page_url, icon_id from icon_mapping
select id, page_url, icon_id from icon_mapping
page_url
page_url
delete from icon_mapping where id = %s
delete from icon_mapping where id = %s
delete from thumbnails where url_id not in (Select id from icon_mapping)
delete from thumbnails where url_id not in (Select id from icon_mapping)
Update urls Set visit_count = 0, last_visit_time = 0, typed_count = 0, favicon_id = 0
Update urls Set visit_count = 0, last_visit_time = 0, typed_count = 0, favicon_id = 0
downloads_url_chains
downloads_url_chains
delete from %s
delete from %s
delete from ie7_logins
delete from ie7_logins
delete from logins
delete from logins
\Google\Chrome\User Data
\Google\Chrome\User Data
\Google\Chrome SxS\User Data
\Google\Chrome SxS\User Data
\MapleStudio\ChromePlus\User Data
\MapleStudio\ChromePlus\User Data
\ChromePlus\ChromePlusUserData
\ChromePlus\ChromePlusUserData
@\Opera
@\Opera
Opera*
Opera*
\Opera\Opera\profile
\Opera\Opera\profile
\Opera\Opera7\profile
\Opera\Opera7\profile
\Opera\Opera75\profile
\Opera\Opera75\profile
\Opera\Opera 8 Beta\profile
\Opera\Opera 8 Beta\profile
\Opera\Opera 9 Beta\profile
\Opera\Opera 9 Beta\profile
\Opera\Opera 9\profile
\Opera\Opera 9\profile
\Opera\Opera 10 Beta
\Opera\Opera 10 Beta
\Opera\Opera
\Opera\Opera
\Opera\Opera 10
\Opera\Opera 10
\Opera Software\Opera Stable
\Opera Software\Opera Stable
\Opera Software\Opera Next
\Opera Software\Opera Next
\Opera Software\Opera Developer
\Opera Software\Opera Developer
\Opera\profile
\Opera\profile
\Opera 9\profile
\Opera 9\profile
%Program Files%\Opera\profile
%Program Files%\Opera\profile
%Program Files%\Opera 9\profile
%Program Files%\Opera 9\profile
lhXXp://
lhXXp://
hXXps://
hXXps://
DET_OPERA
DET_OPERA
DET_MOZILLA
DET_MOZILLA
DET_MOZILLA_GOOGLE_TOOLBAR
DET_MOZILLA_GOOGLE_TOOLBAR
DET_SAFARI_PASSWORD
DET_SAFARI_PASSWORD
%ProgramFiles%\Safari\Safari.exe
%ProgramFiles%\Safari\Safari.exe
DET_CHROME
DET_CHROME
C:\Windows\Cookies
C:\Windows\Cookies
\Cookies.plist
\Cookies.plist
Windows Registry Editor Version 5.00
Windows Registry Editor Version 5.00
[%s%s%s]
[%s%s%s]
x,
x,
\Mozilla\Firefox
\Mozilla\Firefox
\Mozilla
\Mozilla
\Mozilla\SeaMonkey
\Mozilla\SeaMonkey
\profiles.ini
\profiles.ini
\Profiles\profiles.ini
\Profiles\profiles.ini
https
https
\cookies.txt
\cookies.txt
\SiteSecurityServiceState.txt
\SiteSecurityServiceState.txt
\cookies.sqlite
\cookies.sqlite
\webappsstore.sqlite
\webappsstore.sqlite
select scope from webappsstore2;
select scope from webappsstore2;
select domain from webappsstore;
select domain from webappsstore;
*cookies.sqlite
*cookies.sqlite
*webappsstore.sqlite
*webappsstore.sqlite
delete from %s where %s not in (
delete from %s where %s not in (
delete from %s;
delete from %s;
%s\indexedDB
%s\indexedDB
http
http
https
https
https
https
delete from moz_cache where Key like 'http%//
delete from moz_cache where Key like 'http%//
delete from moz_hosts where id=%d and type='offline-app' and permission=1;
delete from moz_hosts where id=%d and type='offline-app' and permission=1;
4llX-%X
4llX-%X
DelegateExecute
DelegateExecute
T.targetsize-16
T.targetsize-16
.targetsize-20
.targetsize-20
.targetsize-24
.targetsize-24
.targetsize-30
.targetsize-30
.targetsize-32
.targetsize-32
.targetsize-36
.targetsize-36
.targetsize-40
.targetsize-40
.targetsize-48
.targetsize-48
.targetsize-60
.targetsize-60
.targetsize-64
.targetsize-64
.targetsize-72
.targetsize-72
.targetsize-96
.targetsize-96
.scale-80
.scale-80
.scale-100
.scale-100
.scale-125
.scale-125
.scale-140
.scale-140
.scale-150
.scale-150
.scale-200
.scale-200
.scale-400
.scale-400
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Families\
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Families\
AppxManifest.xml
AppxManifest.xml
Windows.Management.Deployment.PackageManager
Windows.Management.Deployment.PackageManager
@edge.exe
@edge.exe
microsoftedgecp.exe
microsoftedgecp.exe
@Windows.Security.Credentials.PasswordVault
@Windows.Security.Credentials.PasswordVault
@opera6.adr
@opera6.adr
bookmarks.adr
bookmarks.adr
persistent.txt
persistent.txt
icons\persistent.txt
icons\persistent.txt
*.ini
*.ini
Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon
Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon
advapi32.dll
advapi32.dll
SOFTWARE\Apple Inc.\Apple Application Support
SOFTWARE\Apple Inc.\Apple Application Support
plUtil.exe
plUtil.exe
-convert xml1 "%s" -o "%s"
-convert xml1 "%s" -o "%s"
-convert binary1 "%s" -o "%s"
-convert binary1 "%s" -o "%s"
select url, iconID from PageURL;
select url, iconID from PageURL;
delete from IconData where iconID not in (%s);
delete from IconData where iconID not in (%s);
delete from IconInfo where iconID not in (%s);
delete from IconInfo where iconID not in (%s);
delete from PageURL where iconID not in (%s);
delete from PageURL where iconID not in (%s);
delete from PageURL;
delete from PageURL;
UPDATE sqlite_sequence SET seq=0;
UPDATE sqlite_sequence SET seq=0;
%s\LocalStorage
%s\LocalStorage
%s\LocalStorage\StorageTracker.db
%s\LocalStorage\StorageTracker.db
delete from Origins where origin = "%s";
delete from Origins where origin = "%s";
%s\Databases\Databases.db
%s\Databases\Databases.db
delete from Origins where origin in (select origin from databases where guid not in ("%s"));
delete from Origins where origin in (select origin from databases where guid not in ("%s"));
delete from Databases where guid not in ("%s");
delete from Databases where guid not in ("%s");
delete from sqlite_sequence where name = 'Databases';
delete from sqlite_sequence where name = 'Databases';
%s\ApplicationCache.db
%s\ApplicationCache.db
select manifestURL, id from CacheGroups;
select manifestURL, id from CacheGroups;
delete from CacheAllowsAllNetworkRequests where cache in (select id from caches where cacheGroup not in ("%s"));
delete from CacheAllowsAllNetworkRequests where cache in (select id from caches where cacheGroup not in ("%s"));
delete from CacheEntries where cache in (select id from caches where cacheGroup not in ("%s"));
delete from CacheEntries where cache in (select id from caches where cacheGroup not in ("%s"));
delete from CacheGroups where id not in ("%s");
delete from CacheGroups where id not in ("%s");
delete from CacheResourceData where id in (Select resource from CacheEntries where cache in (select id from caches where cacheGroup not in ("%s")));
delete from CacheResourceData where id in (Select resource from CacheEntries where cache in (select id from caches where cacheGroup not in ("%s")));
delete from CacheResources where id in (Select resource from CacheEntries where cache in (select id from caches where cacheGroup not in ("%s")));
delete from CacheResources where id in (Select resource from CacheEntries where cache in (select id from caches where cacheGroup not in ("%s")));
delete from CacheWhitelistURLs where cache in (select id from caches where cacheGroup not in ("%s"));
delete from CacheWhitelistURLs where cache in (select id from caches where cacheGroup not in ("%s"));
delete from FallbackURLs where cache in (select id from caches where cacheGroup not in ("%s"));
delete from FallbackURLs where cache in (select id from caches where cacheGroup not in ("%s"));
delete from caches where cacheGroup not in ("%s");
delete from caches where cacheGroup not in ("%s");
delete from CacheWhitelistURLs;
delete from CacheWhitelistURLs;
delete from FallbackURLs;
delete from FallbackURLs;
@SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
@SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\App Paths
Software\Microsoft\Windows\CurrentVersion\App Paths
Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
Software\Microsoft\Windows\Help
Software\Microsoft\Windows\Help
Software\Microsoft\Windows\HTML Help
Software\Microsoft\Windows\HTML Help
Software\Microsoft\Windows\CurrentVersion\Installer\Folders
Software\Microsoft\Windows\CurrentVersion\Installer\Folders
Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache
Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects
Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs
Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs
Software\Microsoft\Windows\ShellNoRoam\MUICache
Software\Microsoft\Windows\ShellNoRoam\MUICache
Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Software\Classes\%s
Software\Classes\%s
%s%s%d
%s%s%d
SOFTWARE\Classes%s%s
SOFTWARE\Classes%s%s
Dselect url from favorites;
Dselect url from favorites;
select url from snapshots;
select url from snapshots;
select url from sites;
select url from sites;
bcombase.dll
bcombase.dll
%s|%s|%s|%s|%s
%s|%s|%s|%s|%s
*extensions.json
*extensions.json
addons[id=%s]
addons[id=%s]
Update addon Set active = %d, userDisabled = %d Where id = '%s'
Update addon Set active = %d, userDisabled = %d Where id = '%s'
extensions.pendingOperations
extensions.pendingOperations
Select location from addon Where id = '%s'
Select location from addon Where id = '%s'
addons.json
addons.json
addons.sqlite
addons.sqlite
Select creator From addon where id = '%s'
Select creator From addon where id = '%s'
extensions.json
extensions.json
extensions.sqlite
extensions.sqlite
Select addon.id, locale.name, locale.description, addon.active, addon.userDisabled, addon.appDisabled, locale.creator, addon.type, addon.defaultLocale, addon.descriptor, addon.location, addon.version, addon.pendingUninstall, addon.installDate, addon.updateDate
Select addon.id, locale.name, locale.description, addon.active, addon.userDisabled, addon.appDisabled, locale.creator, addon.type, addon.defaultLocale, addon.descriptor, addon.location, addon.version, addon.pendingUninstall, addon.installDate, addon.updateDate
From addon Inner Join locale On addon.defaultLocale = locale.id
From addon Inner Join locale On addon.defaultLocale = locale.id
Where addon.type = 'extension'
Where addon.type = 'extension'
Update addon Set pendingUninstall = 1 Where id = '%s'
Update addon Set pendingUninstall = 1 Where id = '%s'
plugin.state.
plugin.state.
media.gmp-provider.enabled
media.gmp-provider.enabled
gmp-*.*
gmp-*.*
media.%s.version
media.%s.version
media.%s.enabled
media.%s.enabled
.info
.info
\pluginreg.dat
\pluginreg.dat
*\prefs.js
*\prefs.js
media.gmp-%s.enabled
media.gmp-%s.enabled
@webapps\webapps.json
@webapps\webapps.json
webapps
webapps
chrome-extension_%s_0
chrome-extension_%s_0
.localstorage
.localstorage
@plugins.plugins_list
@plugins.plugins_list
@"url":
@"url":
A%s.%d
A%s.%d
A%d.%d
A%d.%d
SELECT %s FROM %s
SELECT %s FROM %s
WHERE %s
WHERE %s
SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\
SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\
%s\Connection
%s\Connection
%s_%s=
%s_%s=
bWinInet.dll
bWinInet.dll
hXXps://*
hXXps://*
DhXXps://VVV.piriform.com/go/app_cc_get_update?v=%s&l=%s&o=%s
DhXXps://VVV.piriform.com/go/app_cc_get_update?v=%s&l=%s&o=%s
%s?v=%s&l=%s&o=%s
%s?v=%s&l=%s&o=%s
&a=%s
&a=%s
%s.exe
%s.exe
J%c%c%c%c
J%c%c%c%c
J0x%x: %s
J0x%x: %s
hXXps://license.piriform.com/update/?p=%s&c=%s&cv=%s&l=%s&o=%s&lk=%s&mk=%s
hXXps://license.piriform.com/update/?p=%s&c=%s&cv=%s&l=%s&o=%s&lk=%s&mk=%s
%s/INSTDIR='%s' /L=%s
%s/INSTDIR='%s' /L=%s
/COMMANDLINE='%s'
/COMMANDLINE='%s'
%s?p=%s&v=%s&l=%s&o=%s
%s?p=%s&v=%s&l=%s&o=%s
&lk=%s
&lk=%s
&mk=%s
&mk=%s
Error updating CCleaner %s- 0x%x: %s
Error updating CCleaner %s- 0x%x: %s
Extra error updating CCleaner %s- 0x%x: %s
Extra error updating CCleaner %s- 0x%x: %s
Mozilla/4.0
Mozilla/4.0
hXXp://crash-reports.piriform.com/submit
hXXp://crash-reports.piriform.com/submit
Send Report
Send Report
Report sent successfully.
Report sent successfully.
Error sending report: too many reports.
Error sending report: too many reports.
Error sending report.
Error sending report.
@Piriform::Breakpad::CKeyboardHook::Message::B4E8893A-C6C1-4c98-BFFC-B81923F8C77D
@Piriform::Breakpad::CKeyboardHook::Message::B4E8893A-C6C1-4c98-BFFC-B81923F8C77D
Iwer.dll
Iwer.dll
tCCleaner Consent Key
tCCleaner Consent Key
CCleaner.exe
CCleaner.exe
CCleaner crash report
CCleaner crash report
NTDLL.DLL
NTDLL.DLL
KERNEL32.DLL
KERNEL32.DLL
dbghelp.dll
dbghelp.dll
rpcrt4.dll
rpcrt4.dll
%s\%s.dmp
%s\%s.dmp
%d minutes remaining
%d minutes remaining
%sXX
%sXX
x-x-x-xx-xxxxxx
x-x-x-xx-xxxxxx
Disassembler->Instruction.Address == Address
Disassembler->Instruction.Address == Address
Disassembler->Instruction.Length
Disassembler->Instruction.Length
X86Instruction->SrcAddressIndex == OperandIndex || X86Instruction->DstAddressIndex == OperandIndex
X86Instruction->SrcAddressIndex == OperandIndex || X86Instruction->DstAddressIndex == OperandIndex
!(Operand->Length & 1)
!(Operand->Length & 1)
X86Instruction->OperandSize == 2
X86Instruction->OperandSize == 2
Instruction->OpcodeLength == 2 && X86Instruction->HasModRM && Instruction->OperandCount == 2
Instruction->OpcodeLength == 2 && X86Instruction->HasModRM && Instruction->OperandCount == 2
X86Instruction->OperandSize == 8
X86Instruction->OperandSize == 8
X86Instruction->OperandSize >= 4
X86Instruction->OperandSize >= 4
!(Instruction->Operands[0].Flags & 0x7F)
!(Instruction->Operands[0].Flags & 0x7F)
!(Instruction->Operands[1].Flags & 0x7F)
!(Instruction->Operands[1].Flags & 0x7F)
!(Instruction->Operands[2].Flags & 0x7F)
!(Instruction->Operands[2].Flags & 0x7F)
Instruction->OperandCount == 1
Instruction->OperandCount == 1
!Instruction->CodeBranch.AddressOffset
!Instruction->CodeBranch.AddressOffset
Operand1->Length
Operand1->Length
Operand1->Flags & OP_ADDRESS
Operand1->Flags & OP_ADDRESS
Operand1->Type == OPTYPE_OFFSET
Operand1->Type == OPTYPE_OFFSET
!(Operand1->Flags & (OP_GLOBAL|OP_FAR))
!(Operand1->Flags & (OP_GLOBAL|OP_FAR))
!Instruction->DataDst.Count
!Instruction->DataDst.Count
!Instruction->DataSrc.Count
!Instruction->DataSrc.Count
Operand->Length
Operand->Length
Instruction->OperandCount == 1 && Operand1->Length
Instruction->OperandCount == 1 && Operand1->Length
!(Operand->Flags & 0x7F)
!(Operand->Flags & 0x7F)
>Operand->Flags & (OP_EXEC|OP_SRC|OP_DST)
>Operand->Flags & (OP_EXEC|OP_SRC|OP_DST)
>OperandIndex
>OperandIndex
OperandIndex == 1
OperandIndex == 1
Operand->Length == 1
Operand->Length == 1
X86Instruction->OperandSize >= Operand->Length
X86Instruction->OperandSize >= Operand->Length
(Operand->Flags & OP_EXEC) && (Instruction->Groups & ITYPE_EXEC)
(Operand->Flags & OP_EXEC) && (Instruction->Groups & ITYPE_EXEC)
(Operand)->TargetAddress
(Operand)->TargetAddress
(Operand)->Length
(Operand)->Length
(Operand)->Flags & OP_FAR
(Operand)->Flags & OP_FAR
[!((Operand)->Flags & OP_FAR)
[!((Operand)->Flags & OP_FAR)
X86_Registers[Operand->Register]
X86_Registers[Operand->Register]
Operand->Length
Operand->Length
*.jpg
*.jpg
*.raw
*.raw
*.gif
*.gif
*.jpeg
*.jpeg
*.bmp
*.bmp
*.tif
*.tif
*.tiff
*.tiff
*.psd
*.psd
*.mp3
*.mp3
*.wma
*.wma
*.ogg
*.ogg
*.wav
*.wav
*.aac
*.aac
*.flac
*.flac
*.aif
*.aif
*.aiff
*.aiff
*.aifc
*.aifc
*.aifr
*.aifr
*.midi
*.midi
*.mid
*.mid
*.rmi
*.rmi
*.mp2
*.mp2
*.doc
*.doc
*.xls
*.xls
*.ppt
*.ppt
*.odt
*.odt
*.ods
*.ods
*.docx
*.docx
*.xlsx
*.xlsx
*.pptx
*.pptx
*.odc
*.odc
*.pps
*.pps
*.avi
*.avi
*.mov
*.mov
*.mpg
*.mpg
*.mp4
*.mp4
*.flv
*.flv
*.wmv
*.wmv
*.mpeg
*.mpeg
*.mpe
*.mpe
*.mpv
*.mpv
*.ifv
*.ifv
*.zip
*.zip
*.zipx
*.zipx
*.rar
*.rar
*.ace
*.ace
*.arj
*.arj
*.cab
*.cab
*.tar
*.tar
*.eml
*.eml
*.pst
*.pst
*.ost
*.ost
\\.\Scsi%d:
\\.\Scsi%d:
ATA/ATAPI-%d
ATA/ATAPI-%d
ATA-%d
ATA-%d
---- [Xh]
---- [Xh]
Assertion failed: %s, file %s, line %d
Assertion failed: %s, file %s, line %d
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ccleaner.exe
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ccleaner.exe
1, 0, 0, 1
1, 0, 0, 1
Import
Import
Export
Export
Total support
Total support
Only delete files in Windows Temp folders older than 48 hours
Only delete files in Windows Temp folders older than 48 hours
v1.31.325
v1.31.325
You can download the latest version, report bugs and submit feature requestes at the follwoing website :)
You can download the latest version, report bugs and submit feature requestes at the follwoing website :)
(e.g. *.zip;*.rar)
(e.g. *.zip;*.rar)
This will allow CCleaner to keep your persistent logins for websites, such as Hotmail, GMail and Yahoo Mail
This will allow CCleaner to keep your persistent logins for websites, such as Hotmail, GMail and Yahoo Mail
{8856F961-340A-11D0-A96B-00C04FD705A2}
{8856F961-340A-11D0-A96B-00C04FD705A2}
Go to Website
Go to Website
License Key:
License Key:
Crash report
Crash report
The system and other applications have not been affected. A report has been created that you can send to Piriform to help identify the problem.
The system and other applications have not been affected. A report has been created that you can send to Piriform to help identify the problem.
testEClick here to visit the CCleaner website at VVV.piriform.com/ccleaner
testEClick here to visit the CCleaner website at VVV.piriform.com/ccleaner
Would you like to visit the website to download it?8Click here to visit the Piriform website at Piriform.com
Would you like to visit the website to download it?8Click here to visit the Piriform website at Piriform.com
No issues were selected..Do you want to backup changes to the registry?
No issues were selected..Do you want to backup changes to the registry?
%1 removed.EDetails of files to be deleted (Note: No files have been deleted yet)
%1 removed.EDetails of files to be deleted (Note: No files have been deleted yet)
%1 cache cleaning was skipped..Firefox Temporary Internet Cache (%1 files) %2
%1 cache cleaning was skipped..Firefox Temporary Internet Cache (%1 files) %2
T%1 needs to be closed to continue this operation.
T%1 needs to be closed to continue this operation.
Closing application...TThe application is taking a long time to close.
Closing application...TThe application is taking a long time to close.
Intelligent Cookie Scan'Intelligently scan for cookies to keep?pThis will allow CCleaner to keep your persistent logins for websites, such as GMail, Outlook.com and Yahoo Mail.
Intelligent Cookie Scan'Intelligently scan for cookies to keep?pThis will allow CCleaner to keep your persistent logins for websites, such as GMail, Outlook.com and Yahoo Mail.
Please re-enter your details.úiled to save registration key file.
Please re-enter your details.úiled to save registration key file.
Total supportvYour CCleaner Professional trial expires in %1 %2. Buy Now to continue benefiting from a cleaner, safer and faster PC.
Total supportvYour CCleaner Professional trial expires in %1 %2. Buy Now to continue benefiting from a cleaner, safer and faster PC.
.Your Upgrade to CCleaner %1 has been completed
.Your Upgrade to CCleaner %1 has been completed
Null license key
Null license key
Null machine key
Null machine key
Invalid license key
Invalid license key
Expired license key
Expired license key
Inactive license key8CCleaner could not be updated. Your license has expired.7CCleaner could not be updated. Your license is invalid.ePlease click the Purchase button below to renew your license, or contact support through our website.
Inactive license key8CCleaner could not be updated. Your license has expired.7CCleaner could not be updated. Your license is invalid.ePlease click the Purchase button below to renew your license, or contact support through our website.
&RegisterQThe latest version contains important changes. It is recommended that you update.
&RegisterQThe latest version contains important changes. It is recommended that you update.
Reducing IT support costs
Reducing IT support costs
Clo&se program after cleaning&&Run CCleaner when the computer starts6&Add "Run CCleaner" option to Recycle Bin context menu:A&dd "Open CCleaner..." option to Recycle Bin context menu>O&nly delete files in Windows Temp folders older than 24 hours
Clo&se program after cleaning&&Run CCleaner when the computer starts6&Add "Run CCleaner" option to Recycle Bin context menu:A&dd "Open CCleaner..." option to Recycle Bin context menu>O&nly delete files in Windows Temp folders older than 24 hours
Simple Overwrite (1 pass)
Simple Overwrite (1 pass)
Advanced Overwrite (3 passes)
Advanced Overwrite (3 passes)
Complex Overwrite (7 passes),Show detailed log of Firefox temporary files
Complex Overwrite (7 passes),Show detailed log of Firefox temporary files
!Secure file deletion enabled - %1"Very Complex Overwrite (35 passes)
!Secure file deletion enabled - %1"Very Complex Overwrite (35 passes)
&Enable Windows Jump List Tasks&Sho&w initial results in detailed view
&Enable Windows Jump List Tasks&Sho&w initial results in detailed view
Windows Event Logs
Windows Event Logs
&Import
&Import
E&xport
E&xport
&Delete nowJCookies are being deleted. Are you sure you want to cancel this operation?dThis process will delete the selected cookie(s) from your system.
&Delete nowJCookies are being deleted. Are you sure you want to cancel this operation?dThis process will delete the selected cookie(s) from your system.
e.g. *.tmp;*.logCFor system safety reasons you cannot select this specific location.
e.g. *.tmp;*.logCFor system safety reasons you cannot select this specific location.
Cannot delete MSI installer.,All selected restore points will be removed.DSelect a program from the list you want to remove from your computer;This app and its related info will be removed from this PC.
Cannot delete MSI installer.,All selected restore points will be removed.DSelect a program from the list you want to remove from your computer;This app and its related info will be removed from this PC.
Free Space Only&Entire Drive (All data will be erased)9WARNING! ALL DATA ON SELECTED DISK DRIVES WILL BE ERASED!,To proceed with this, type the word %1 here:/Are you sure you want to cancel this operation?
Free Space Only&Entire Drive (All data will be erased)9WARNING! ALL DATA ON SELECTED DISK DRIVES WILL BE ERASED!,To proceed with this, type the word %1 here:/Are you sure you want to cancel this operation?
Are you sure you want to do this?OThe operation has been completed.
Are you sure you want to do this?OThe operation has been completed.
Windows Explorer
Windows Explorer
Firefox
Firefox
Opera
Opera
Windows Store
Windows Store
Index.dat files
Index.dat files
Saved Passwords
Saved Passwords
Windows Log Files
Windows Log Files
Windows Error Reporting
Windows Error Reporting
FTP Accounts
FTP Accounts
Network Passwords
Network Passwords
Old Windows Installation
Old Windows Installation
Website Icons
Website Icons
9This will take effect next time the computer is rebooted.
9This will take effect next time the computer is rebooted.
Wiping Free Space will significantly increase the amount of time the cleaning takes. We recommend you leave this disabled for normal usage.jThis will clear all Windows Event Logs from your computer. These logs are often used to diagnose problems.
Wiping Free Space will significantly increase the amount of time the cleaning takes. We recommend you leave this disabled for normal usage.jThis will clear all Windows Event Logs from your computer. These logs are often used to diagnose problems.
Windows Services
Windows Services
Obsolete software key
Obsolete software key
Old Start Menu key
Old Start Menu key
Unused registry key
Unused registry key
uThe file %1 is referenced as a Shared DLL and doesn't exist. These are often left behind after uninstalling software.xThe file extension %1 references an invalid program identifier. These are often left behind after uninstalling software.jThe COM component %1 references an invalid CLSID. These are often left behind after uninstalling software.{The Application referenced at: %1 could not be located. These references are often left behind after uninstalling software.cThe Font %1 could not be found. These references are often left behind after uninstalling software.{The Application referenced at: %1 could not be located. These references are often left behind after uninstalling software.yThe Help File referenced at: %1 could not be located. These references are often left behind after uninstalling software.
uThe file %1 is referenced as a Shared DLL and doesn't exist. These are often left behind after uninstalling software.xThe file extension %1 references an invalid program identifier. These are often left behind after uninstalling software.jThe COM component %1 references an invalid CLSID. These are often left behind after uninstalling software.{The Application referenced at: %1 could not be located. These references are often left behind after uninstalling software.cThe Font %1 could not be found. These references are often left behind after uninstalling software.{The Application referenced at: %1 could not be located. These references are often left behind after uninstalling software.yThe Help File referenced at: %1 could not be located. These references are often left behind after uninstalling software.
The software key: %1 does not contain any information so can be removed. These references are often left behind after uninstalling software.
The software key: %1 does not contain any information so can be removed. These references are often left behind after uninstalling software.
The key %1 does not contain any information so can be removed. These references are often left behind after uninstalling software.8A file referenced by a shortcut does not exist. File: %1tThe file referenced at: %1 could not be located. These references are often left behind after uninstalling software.wThe TypeLib referenced at: %1 could not be located. These references are often left behind after uninstalling software.tThe file referenced at: %1 could not be located. These references are often left behind after uninstalling software.~The Application %1 referenced at: %2 could not be located. These references are often left behind after uninstalling software.uThe CLSID referenced at: %1 could not be located. These references are often left behind after uninstalling software.tThe file referenced at: %1 could not be located. These references are often left behind after uninstalling software.
The key %1 does not contain any information so can be removed. These references are often left behind after uninstalling software.8A file referenced by a shortcut does not exist. File: %1tThe file referenced at: %1 could not be located. These references are often left behind after uninstalling software.wThe TypeLib referenced at: %1 could not be located. These references are often left behind after uninstalling software.tThe file referenced at: %1 could not be located. These references are often left behind after uninstalling software.~The Application %1 referenced at: %2 could not be located. These references are often left behind after uninstalling software.uThe CLSID referenced at: %1 could not be located. These references are often left behind after uninstalling software.tThe file referenced at: %1 could not be located. These references are often left behind after uninstalling software.
$Solution: Delete the registry value."Solution: Delete the registry key..Solution: Delete the DefaultIcon registry key.#Solution: Delete the shortcut file.
$Solution: Delete the registry value."Solution: Delete the registry key..Solution: Delete the DefaultIcon registry key.#Solution: Delete the shortcut file.
Save to text file...cThis process will delete the selected files(s) from your system.
Save to text file...cThis process will delete the selected files(s) from your system.
5, 12, 00, 5431
5, 12, 00, 5431
ccleaner.exe
ccleaner.exe
svchost.exe_2208:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
msvcrt.dll
msvcrt.dll
API-MS-Win-Core-ProcessThreads-L1-1-0.dll
API-MS-Win-Core-ProcessThreads-L1-1-0.dll
KERNEL32.dll
KERNEL32.dll
NTDLL.DLL
NTDLL.DLL
API-MS-Win-Security-Base-L1-1-0.dll
API-MS-Win-Security-Base-L1-1-0.dll
API-MS-WIN-Service-Core-L1-1-0.dll
API-MS-WIN-Service-Core-L1-1-0.dll
API-MS-WIN-Service-winsvc-L1-1-0.dll
API-MS-WIN-Service-winsvc-L1-1-0.dll
RPCRT4.dll
RPCRT4.dll
ole32.dll
ole32.dll
ntdll.dll
ntdll.dll
_amsg_exit
_amsg_exit
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
GetProcessHeap
GetProcessHeap
svchost.pdb
svchost.pdb
version="5.1.0.0"
version="5.1.0.0"
name="Microsoft.Windows.Services.SvcHost"
name="Microsoft.Windows.Services.SvcHost"
Host Process for Windows Services
Host Process for Windows Services
Software\Microsoft\Windows NT\CurrentVersion\Svchost
Software\Microsoft\Windows NT\CurrentVersion\Svchost
Software\Microsoft\Windows NT\CurrentVersion\MgdSvchost
Software\Microsoft\Windows NT\CurrentVersion\MgdSvchost
\PIPE\
\PIPE\
Host Process for Windows Services
Host Process for Windows Services
6.1.7600.16385 (win7_rtm.090713-1255)
6.1.7600.16385 (win7_rtm.090713-1255)
svchost.exe
svchost.exe
Windows
Windows
Operating System
Operating System
6.1.7600.16385
6.1.7600.16385
svchost.exe_2208_rwx_00070000_00001000:
KERNEL32.DLL
KERNEL32.DLL
svchost.exe_2208_rwx_000B0000_00001000:
KERNEL32.DLL
KERNEL32.DLL
svchost.exe_2208_rwx_00120000_00001000:
KERNEL32.DLL
KERNEL32.DLL
svchost.exe_2208_rwx_00210000_00001000:
KERNEL32.DLL
KERNEL32.DLL
svchost.exe_2208_rwx_00250000_00001000:
KERNEL32.DLL
KERNEL32.DLL
svchost.exe_2208_rwx_002A0000_00001000:
KERNEL32.DLL
KERNEL32.DLL
svchost.exe_2208_rwx_002D0000_00001000:
advapi32.dll
advapi32.dll
svchost.exe_2208_rwx_00300000_00001000:
RegOpenKeyA
RegOpenKeyA
svchost.exe_2208_rwx_00310000_00001000:
advapi32.dll
advapi32.dll
svchost.exe_2208_rwx_00340000_00001000:
gdi32.dll
gdi32.dll
svchost.exe_2208_rwx_00380000_00001000:
gdi32.dll
gdi32.dll
svchost.exe_2208_rwx_005B0000_00001000:
gdiplus.dll
gdiplus.dll
svchost.exe_2208_rwx_005F0000_00001000:
gdiplus.dll
gdiplus.dll
svchost.exe_2208_rwx_00660000_00001000:
mpr.dll
mpr.dll
svchost.exe_2208_rwx_006E0000_00001000:
mpr.dll
mpr.dll
svchost.exe_2208_rwx_00710000_00001000:
msacm32.dll
msacm32.dll
svchost.exe_2208_rwx_01460000_00001000:
msacm32.dll
msacm32.dll
svchost.exe_2208_rwx_01490000_00001000:
ntdll.dll
ntdll.dll
svchost.exe_2208_rwx_014D0000_00001000:
ntdll.dll
ntdll.dll
svchost.exe_2208_rwx_01540000_00001000:
ole32.dll
ole32.dll
svchost.exe_2208_rwx_015C0000_00001000:
ole32.dll
ole32.dll
svchost.exe_2208_rwx_01630000_00001000:
oleaut32.dll
oleaut32.dll
svchost.exe_2208_rwx_016B0000_00001000:
oleaut32.dll
oleaut32.dll
svchost.exe_2208_rwx_016E0000_00001000:
powrprof.dll
powrprof.dll
svchost.exe_2208_rwx_01720000_00001000:
powrprof.dll
powrprof.dll
svchost.exe_2208_rwx_01760000_00001000:
shell32.dll
shell32.dll
svchost.exe_2208_rwx_017A0000_00001000:
shell32.dll
shell32.dll
svchost.exe_2208_rwx_01810000_00001000:
user32.dll
user32.dll
svchost.exe_2208_rwx_01890000_00001000:
user32.dll
user32.dll
svchost.exe_2208_rwx_01900000_00001000:
version.dll
version.dll
svchost.exe_2208_rwx_01940000_00001000:
version.dll
version.dll
svchost.exe_2208_rwx_019B0000_00001000:
wininet.dll
wininet.dll
svchost.exe_2208_rwx_019E0000_00001000:
FtpOpenFileA
FtpOpenFileA
svchost.exe_2208_rwx_019F0000_00001000:
wininet.dll
wininet.dll
svchost.exe_2208_rwx_01AA0000_00001000:
winmm.dll
winmm.dll
svchost.exe_2208_rwx_01B20000_00001000:
winmm.dll
winmm.dll
svchost.exe_2208_rwx_01B50000_00001000:
wsock32.dll
wsock32.dll
svchost.exe_2208_rwx_01B90000_00001000:
wsock32.dll
wsock32.dll
svchost.exe_2208_rwx_10480000_00070000:
`.rsrc
`.rsrc
kernel32.dll
kernel32.dll
Portions Copyright (c) 1999,2003 Avenger by NhT
Portions Copyright (c) 1999,2003 Avenger by NhT
SHFileOperationA
SHFileOperationA
shell32.dll
shell32.dll
URLDownloadToFileA
URLDownloadToFileA
urlmon.dll
urlmon.dll
ShellExecuteA
ShellExecuteA
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
\Internet Explorer\iexplore.exe
\Internet Explorer\iexplore.exe
####@####
####@####
AVKWCtlX64.exe
AVKWCtlX64.exe
AVKWCtl.exe
AVKWCtl.exe
avgnt.exe
avgnt.exe
avp.exe
avp.exe
mbam.exe
mbam.exe
a2service.exe
a2service.exe
Vba32arkit.exe
Vba32arkit.exe
ClamWin.exe
ClamWin.exe
avesvc.exe
avesvc.exe
ashdisp.exe
ashdisp.exe
avgcc.exe
avgcc.exe
bdss.exe
bdss.exe
spider.exe
spider.exe
kavsvc.exe
kavsvc.exe
nod32krn.exe
nod32krn.exe
cclaw.exe
cclaw.exe
dvpapi.exe
dvpapi.exe
ewidoctrl.exe
ewidoctrl.exe
mcshield.exe
mcshield.exe
pavfires.exe
pavfires.exe
almon.exe
almon.exe
ccapp.exe
ccapp.exe
pccntmon.exe
pccntmon.exe
fssm32.exe
fssm32.exe
ekrn.exe
ekrn.exe
ccSvcHst.exe
ccSvcHst.exe
avgrsx.exe
avgrsx.exe
egui.exe
egui.exe
PSUNMAIN.exe
PSUNMAIN.exe
SSScheduler.exe
SSScheduler.exe
Dr.Web
Dr.Web
GDFwSvcx64.exe
GDFwSvcx64.exe
GDFwSvc.exe
GDFwSvc.exe
avfwsvc.exe
avfwsvc.exe
oacat.exe
oacat.exe
issvc.exe
issvc.exe
vsmon.exe
vsmon.exe
cpf.exe
cpf.exe
ca.exe
ca.exe
tnbutil.exe
tnbutil.exe
kavpf.exe
kavpf.exe
mpfservice.exe
mpfservice.exe
npfmsg.exe
npfmsg.exe
outpost.exe
outpost.exe
tpsrv.exe
tpsrv.exe
kpf4ss.exe
kpf4ss.exe
persfw.exe
persfw.exe
vsserv.exe
vsserv.exe
smc.exe
smc.exe
op_mon.exe
op_mon.exe
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
Portugal
Portugal
Turkey
Turkey
FirstExecution
FirstExecution
Windows 3.1
Windows 3.1
Windows 95 (Release 2)
Windows 95 (Release 2)
Windows 95
Windows 95
Windows 98 SE
Windows 98 SE
Windows 98
Windows 98
Windows ME
Windows ME
Windows 7
Windows 7
Windows Vista
Windows Vista
%s %s
%s %s
Windows XP Professional x64
Windows XP Professional x64
Windows XP Home
Windows XP Home
Windows XP Professional
Windows XP Professional
Windows 2000 Professional
Windows 2000 Professional
Windows NT %d.%d
Windows NT %d.%d
Windows 2008
Windows 2008
%s %s Server
%s %s Server
Windows 2003 Server Datacenter
Windows 2003 Server Datacenter
Windows 2003 Server Enterprise
Windows 2003 Server Enterprise
Windows 2003 Server Web Edition
Windows 2003 Server Web Edition
Windows 2003 Server
Windows 2003 Server
Windows Home Server
Windows Home Server
Windows 2003 Server (Release 2)
Windows 2003 Server (Release 2)
Windows 2000 Server Datacenter
Windows 2000 Server Datacenter
Windows 2000 Server Enterprise
Windows 2000 Server Enterprise
Windows 2000 Server Web Edition
Windows 2000 Server Web Edition
Windows 2000 Server
Windows 2000 Server
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server
Windows NT 4.0 Server
Unknown Platform ID (%d)
Unknown Platform ID (%d)
%d.%d
%d.%d
%s (Build: %d
%s (Build: %d
- Service Pack: %s
- Service Pack: %s
KERNEL32.DLL
KERNEL32.DLL
v3.4.2.2
v3.4.2.2
Set colFirewall = objSecurityCenter.ExecQuery("SELECT * FROM FirewallProduct","WQL",0)
Set colFirewall = objSecurityCenter.ExecQuery("SELECT * FROM FirewallProduct","WQL",0)
Set colAntiVirus = objSecurityCenter.ExecQuery("SELECT * FROM AntiVirusProduct","WQL",0)
Set colAntiVirus = objSecurityCenter.ExecQuery("SELECT * FROM AntiVirusProduct","WQL",0)
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFile = objFileSystem.CreateTextFile("
Set objFile = objFileSystem.CreateTextFile("
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & Enter
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & Enter
objFile.WriteLine(Info)
objFile.WriteLine(Info)
objFile.Close
objFile.Close
cscript.exe
cscript.exe
AVICAP32.dll
AVICAP32.dll
BuildImportTable: can't load library:
BuildImportTable: can't load library:
BuildImportTable: ReallocMemory failed
BuildImportTable: ReallocMemory failed
BuildImportTable: GetProcAddress failed
BuildImportTable: GetProcAddress failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: exported symbol not found
BTMemoryGetProcAddress: exported symbol not found
SetupApi.dll
SetupApi.dll
SetupDiOpenClassRegKey
SetupDiOpenClassRegKey
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExW
SetupDiOpenClassRegKeyExW
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiOpenDeviceInterfaceRegKey
SetupDiOpenDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyW
SetupDiCreateDevRegKeyW
SetupDiOpenDevRegKey
SetupDiOpenDevRegKey
SetupDiDeleteDevRegKey
SetupDiDeleteDevRegKey
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
127.0.0.1
127.0.0.1
iphlpapi.dll
iphlpapi.dll
AllocateAndGetTcpExTableFromStack
AllocateAndGetTcpExTableFromStack
AllocateAndGetUdpExTableFromStack
AllocateAndGetUdpExTableFromStack
SetTcpEntry
SetTcpEntry
GetExtendedTcpTable
GetExtendedTcpTable
GetExtendedUdpTable
GetExtendedUdpTable
ConnectWebcam
ConnectWebcam
DisconnectWebcam
DisconnectWebcam
ListWebcams
ListWebcams
CaptureWebcam
CaptureWebcam
IsWebcamConnected
IsWebcamConnected
StartHttpProxy
StartHttpProxy
1.2.3
1.2.3
keyboardkey
keyboardkey
webcaminactive
webcaminactive
webcamgetbuffer
webcamgetbuffer
webcam
webcam
webcamstart
webcamstart
checkwebcamfile
checkwebcamfile
checkwebcamfileback
checkwebcamfileback
webcamdllloaded
webcamdllloaded
enviarexecnormal
enviarexecnormal
enviarexechidden
enviarexechidden
openweb
openweb
openwebpage
openwebpage
openwebhidden
openwebhidden
downexec
downexec
sendftp
sendftp
keylogger
keylogger
keyloggergetlog
keyloggergetlog
keyloggereraselog
keyloggereraselog
keyloggerativar
keyloggerativar
keyloggerdesativar
keyloggerdesativar
renamekey
renamekey
windowsfechar
windowsfechar
windowsmax
windowsmax
windowsmin
windowsmin
windowsmostrar
windowsmostrar
windowsocultar
windowsocultar
windowsmintodas
windowsmintodas
windowscaption
windowscaption
listarportas
listarportas
listarportasdns
listarportasdns
finalizarprocessoportas
finalizarprocessoportas
webcamsettings
webcamsettings
chatmsg
chatmsg
getpassword
getpassword
updateservidorweb
updateservidorweb
keyloggersearch
keyloggersearch
urlredirect
urlredirect
urlredirecttrue
urlredirecttrue
onlinekeyloggereraselog
onlinekeyloggereraselog
onlinekeyloggerstart
onlinekeyloggerstart
onlinekeyloggerstop
onlinekeyloggerstop
onlinekeyloggererror
onlinekeyloggererror
keyloggerlist
keyloggerlist
tFtpAccess
tFtpAccess
onlinekeyloggerstart|onlinekeyloggerstart|
onlinekeyloggerstart|onlinekeyloggerstart|
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
PSAPI.dll
PSAPI.dll
%SYS%
%SYS%
ÞSKTOP%
ÞSKTOP%
TPasswordItem
TPasswordItem
TArrayPasswod
TArrayPasswod
sqlite3_open
sqlite3_open
sqlite3_prepare_v2
sqlite3_prepare_v2
sqlite3_column_text
sqlite3_column_text
sqlite3_step
sqlite3_step
sqlite3_close
sqlite3_close
sqlite3_column_blob
sqlite3_column_blob
sqlite3_column_bytes
sqlite3_column_bytes
Crypt32.dll
Crypt32.dll
ole32.dll
ole32.dll
Advapi32.dll
Advapi32.dll
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\
SOFTWARE\MOZILLA\MOZILLA FIREFOX
SOFTWARE\MOZILLA\MOZILLA FIREFOX
SOFTWARE\MOZILLA\MOZILLA FIREFOX\version.dll\Main
SOFTWARE\MOZILLA\MOZILLA FIREFOX\version.dll\Main
mozcrt19.dll
mozcrt19.dll
mozglue.dll
mozglue.dll
nspr4.dll
nspr4.dll
plc4.dll
plc4.dll
plds4.dll
plds4.dll
nssutil3.dll
nssutil3.dll
mozsqlite3.dll
mozsqlite3.dll
nss3.dll
nss3.dll
PK11_GetInternalKeySlot
PK11_GetInternalKeySlot
\Mozilla\Firefox\profiles.ini
\Mozilla\Firefox\profiles.ini
\Mozilla\Firefox\
\Mozilla\Firefox\
signons.sqlite
signons.sqlite
select * from moz_logins
select * from moz_logins
Firefox
Firefox
SOFTWARE\MOZILLA\MOZILLA FIREFOX\
SOFTWARE\MOZILLA\MOZILLA FIREFOX\
sqlite3.dll
sqlite3.dll
\Flock\Browser\profiles.ini
\Flock\Browser\profiles.ini
Flock-Firefox
Flock-Firefox
\1-abc\personal calendar\sqlite3.dll
\1-abc\personal calendar\sqlite3.dll
\clipdiary\sqlite3.dll
\clipdiary\sqlite3.dll
\conceptworld\recentx\sqlite3.dll
\conceptworld\recentx\sqlite3.dll
\darq software\transmute\sqlite3.dll
\darq software\transmute\sqlite3.dll
\delphish\sqlite3.dll
\delphish\sqlite3.dll
\ditto\sqlite3.dll
\ditto\sqlite3.dll
\du meter\sqlite3.dll
\du meter\sqlite3.dll
\fcleaner\sqlite3.dll
\fcleaner\sqlite3.dll
\file seeker\sqlite3.dll
\file seeker\sqlite3.dll
\flashnote\sqlite3.dll
\flashnote\sqlite3.dll
\flashpaste\sqlite3.dll
\flashpaste\sqlite3.dll
\gorecord\sqlite3.dll
\gorecord\sqlite3.dll
\gorecord2\sqlite3.dll
\gorecord2\sqlite3.dll
\linkcollector portable\sqlite3.dll
\linkcollector portable\sqlite3.dll
\ma-config.com\sqlite3.dll
\ma-config.com\sqlite3.dll
\macrovirus\sqlite3.dll
\macrovirus\sqlite3.dll
\msnsniffer2\sqlite3.dll
\msnsniffer2\sqlite3.dll
\notecable\sqlite3.dll
\notecable\sqlite3.dll
\nzbleecher\sqlite3.dll
\nzbleecher\sqlite3.dll
\outlook express\sqlite3.dll
\outlook express\sqlite3.dll
\page update watcher\sqlite3.dll
\page update watcher\sqlite3.dll
\pipi\sqlite3.dll
\pipi\sqlite3.dll
\qloud\sqlite3.dll
\qloud\sqlite3.dll
\qloud\winamp\sqlite3.dll
\qloud\winamp\sqlite3.dll
\qloud\windows media player\sqlite3.dll
\qloud\windows media player\sqlite3.dll
\recordtheradio\sqlite3.dll
\recordtheradio\sqlite3.dll
\rightload\sqlite3.dll
\rightload\sqlite3.dll
\smm\funny sms10\sqlite3.dll
\smm\funny sms10\sqlite3.dll
\smm\simple mail 7\sqlite3.dll
\smm\simple mail 7\sqlite3.dll
\spiceworks\bin\sqlite3.dll
\spiceworks\bin\sqlite3.dll
\spyware-secure\sqlite3.dll
\spyware-secure\sqlite3.dll
\timelog\sqlite3.dll
\timelog\sqlite3.dll
\video2webcam\sqlite3.dll
\video2webcam\sqlite3.dll
\webmarkers\sqlite3.dll
\webmarkers\sqlite3.dll
\webmediaplayer\sqlite3.dll
\webmediaplayer\sqlite3.dll
\windows media player\plugins\qloud\sqlite3.dll
\windows media player\plugins\qloud\sqlite3.dll
\Mozilla Firefox\sqlite3.dll
\Mozilla Firefox\sqlite3.dll
\VirusGuardPlus\sqlite3.dll
\VirusGuardPlus\sqlite3.dll
\Safari\sqlite3.dll
\Safari\sqlite3.dll
\AIMP2\sqlite3.dll
\AIMP2\sqlite3.dll
\Live-Player\sqlite3.dll
\Live-Player\sqlite3.dll
\TrustedProtection\sqlite3.dll
\TrustedProtection\sqlite3.dll
\PCTotalDefender\sqlite3.dll
\PCTotalDefender\sqlite3.dll
\Common Files\eEye Digital Security\Application Bus\sqlite3.dll
\Common Files\eEye Digital Security\Application Bus\sqlite3.dll
SELECT * FROM logins
SELECT * FROM logins
Google Chrome
Google Chrome
Flock-Chrome
Flock-Chrome
\Mozilla Firefox\mozcrt19.dll
\Mozilla Firefox\mozcrt19.dll
Google\Chrome\User Data\Default\
Google\Chrome\User Data\Default\
Login Data
Login Data
Web Data
Web Data
WindowsLive:name=*
WindowsLive:name=*
Windows Live Messenger
Windows Live Messenger
Password
Password
DynDNS\Updater\config.dyndns
DynDNS\Updater\config.dyndns
Password=
Password=
Software\DownloadManager\Passwords
Software\DownloadManager\Passwords
Software\DownloadManager\Passwords\
Software\DownloadManager\Passwords\
EncPassword
EncPassword
YLoginWnd
YLoginWnd
FileZilla\recentservers.xml
FileZilla\recentservers.xml
FileZilla\sitemanager.xml
FileZilla\sitemanager.xml
FileZilla\filezilla.xml
FileZilla\filezilla.xml
.purple\accounts.xml
.purple\accounts.xml
abe2869f-9b47-4cd9-a358-c22904dba7f7
abe2869f-9b47-4cd9-a358-c22904dba7f7
%UUUU1E
%UUUU1E
%UUUU3
%UUUU3
U_GrabOpera
U_GrabOpera
Opera|WandData :
Opera|WandData :
wand.dat
wand.dat
Opera\
Opera\
trillian.ini
trillian.ini
accounts.ini
accounts.ini
password
password
profiles.ini
profiles.ini
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trillian
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trillian
Trillian\trillian.exe
Trillian\trillian.exe
TPasswordGrabSV
TPasswordGrabSV
%s|%s|%s|%s|%s|
%s|%s|%s|%s|%s|
chatmsg|
chatmsg|
xXx_key_xXx
xXx_key_xXx
-wchelper.dll
-wchelper.dll
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
listarjanelas|windowsfechar|
listarjanelas|windowsfechar|
listarjanelas|windowsmax|
listarjanelas|windowsmax|
listarjanelas|windowsmin|
listarjanelas|windowsmin|
listarjanelas|windowsmostrar|
listarjanelas|windowsmostrar|
listarjanelas|windowsocultar|
listarjanelas|windowsocultar|
listarjanelas|windowsmintodas|
listarjanelas|windowsmintodas|
listarjanelas|windowscaption|
listarjanelas|windowscaption|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
listarportas|listadeportaspronta|
listarportas|listadeportaspronta|
listarportas|finalizarconexao|
listarportas|finalizarconexao|
listarportas|finalizarprocessoportas|Y|
listarportas|finalizarprocessoportas|Y|
listarportas|finalizarprocessoportas|N|
listarportas|finalizarprocessoportas|N|
URL_VISITOR
URL_VISITOR
registro|renamekey|
registro|renamekey|
Key name has been successfully changed
Key name has been successfully changed
Unable to change key name
Unable to change key name
registro|registro|Key name has been successfully changed|"
registro|registro|Key name has been successfully changed|"
registro|registro|Unable to change key name|"
registro|registro|Unable to change key name|"
registro|registro|The key or value has been deleted successfully|"
registro|registro|The key or value has been deleted successfully|"
registro|registro|Unable to delete key or value|"
registro|registro|Unable to delete key or value|"
registro|registro|The key was created successfully|"
registro|registro|The key was created successfully|"
registro|registro|Could not create key|"
registro|registro|Could not create key|"
keylogger|keyloggerlist|
keylogger|keyloggerlist|
ak.tmp
ak.tmp
onlinekeyloggerstart|onlinekeyloggererror|
onlinekeyloggerstart|onlinekeyloggererror|
keylogger|keylogger|keyloggerativar|
keylogger|keylogger|keyloggerativar|
keylogger|keylogger|keyloggerdesativar|
keylogger|keylogger|keyloggerdesativar|
keylogger|keyloggergetlog|
keylogger|keyloggergetlog|
keylogger|keylogger|keyloggervazio|
keylogger|keylogger|keyloggervazio|
keyloggersearchok|
keyloggersearchok|
checkwebcamfileback|
checkwebcamfileback|
webcamdlltransferdone|
webcamdlltransferdone|
webcam|webcaminactive|
webcam|webcaminactive|
webcamdllloaded|
webcamdllloaded|
checkwebcamfile|no|
checkwebcamfile|no|
webcam|webcamactive|
webcam|webcamactive|
webcam|webcamstop|
webcam|webcamstop|
getpassword|getpasswordlist|
getpassword|getpasswordlist|
USER32.DLL
USER32.DLL
C:\Windows\System32\drivers\etc\hosts
C:\Windows\System32\drivers\etc\hosts
temp.vbs
temp.vbs
liststartup|renamekey|
liststartup|renamekey|
liststartup|liststartup|Key name has been successfully changed|"
liststartup|liststartup|Key name has been successfully changed|"
liststartup|liststartup|Unable to change key name|"
liststartup|liststartup|Unable to change key name|"
liststartup|liststartup|The key or value has been deleted successfully|"
liststartup|liststartup|The key or value has been deleted successfully|"
liststartup|liststartup|Unable to delete key or value|"
liststartup|liststartup|Unable to delete key or value|"
liststartup|liststartup|The key was created successfully|"
liststartup|liststartup|The key was created successfully|"
liststartup|liststartup|Could not create key|"
liststartup|liststartup|Could not create key|"
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
KWindows
KWindows
U_GrabPassword
U_GrabPassword
8U_GrabOpera
8U_GrabOpera
\U_GrabChrome
\U_GrabChrome
6U_GrabFirefox
6U_GrabFirefox
.UnitBytesSize
.UnitBytesSize
YU_GrabFirefox8
YU_GrabFirefox8
U_GrabFirefox10
U_GrabFirefox10
UnitExecutarComandos
UnitExecutarComandos
UrlMon
UrlMon
uftp
uftp
UnitListarPortasAtivas
UnitListarPortasAtivas
UnitKeylogger
UnitKeylogger
GetProcessHeap
GetProcessHeap
WinExec
WinExec
SetNamedPipeHandleState
SetNamedPipeHandleState
CreatePipe
CreatePipe
RegOpenKeyExA
RegOpenKeyExA
RegOpenKeyA
RegOpenKeyA
RegEnumKeyExA
RegEnumKeyExA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyA
RegCreateKeyA
RegCloseKey
RegCloseKey
GdiplusShutdown
GdiplusShutdown
ShellExecuteExA
ShellExecuteExA
keybd_event
keybd_event
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
MapVirtualKeyExA
MapVirtualKeyExA
MapVirtualKeyA
MapVirtualKeyA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyboardLayoutNameA
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetAsyncKeyState
GetAsyncKeyState
ExitWindowsEx
ExitWindowsEx
EnumWindows
EnumWindows
InternetOpenUrlA
InternetOpenUrlA
FtpGetFileSize
FtpGetFileSize
FtpSetCurrentDirectoryA
FtpSetCurrentDirectoryA
FtpOpenFileA
FtpOpenFileA
9!!!$'')#
9!!!$'')#
&!!$'''#
&!!$'''#
.idata
.idata
.reloc
.reloc
P.rsrc
P.rsrc
advapi32.dll
advapi32.dll
gdi32.dll
gdi32.dll
gdiplus.dll
gdiplus.dll
mpr.dll
mpr.dll
msacm32.dll
msacm32.dll
ntdll.dll
ntdll.dll
oleaut32.dll
oleaut32.dll
powrprof.dll
powrprof.dll
user32.dll
user32.dll
version.dll
version.dll
wininet.dll
wininet.dll
winmm.dll
winmm.dll
wsock32.dll
wsock32.dll
Explorer.EXE_244_rwx_01F00000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_244_rwx_02C90000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_244_rwx_035A0000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_244_rwx_039B0000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_244_rwx_03B90000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_244_rwx_03D20000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_244_rwx_03D90000_00001000:
advapi32.dll
advapi32.dll
Explorer.EXE_244_rwx_03EB0000_00001000:
RegOpenKeyA
RegOpenKeyA
Explorer.EXE_244_rwx_03EC0000_00001000:
advapi32.dll
advapi32.dll
Explorer.EXE_244_rwx_03F30000_00001000:
gdi32.dll
gdi32.dll
Explorer.EXE_244_rwx_04030000_00001000:
gdi32.dll
gdi32.dll
Explorer.EXE_244_rwx_040E0000_00001000:
gdiplus.dll
gdiplus.dll
Explorer.EXE_244_rwx_04560000_00001000:
gdiplus.dll
gdiplus.dll
Explorer.EXE_244_rwx_04650000_00001000:
mpr.dll
mpr.dll
Explorer.EXE_244_rwx_04710000_00001000:
mpr.dll
mpr.dll
Explorer.EXE_244_rwx_04750000_00001000:
msacm32.dll
msacm32.dll
Explorer.EXE_244_rwx_047E0000_00001000:
msacm32.dll
msacm32.dll
Explorer.EXE_244_rwx_04850000_00001000:
ntdll.dll
ntdll.dll
Explorer.EXE_244_rwx_04A20000_00001000:
ntdll.dll
ntdll.dll
Explorer.EXE_244_rwx_04A90000_00001000:
ole32.dll
ole32.dll
Explorer.EXE_244_rwx_06670000_00001000:
ole32.dll
ole32.dll
Explorer.EXE_244_rwx_066A0000_00001000:
oleaut32.dll
oleaut32.dll
Explorer.EXE_244_rwx_06760000_00001000:
oleaut32.dll
oleaut32.dll
Explorer.EXE_244_rwx_06AD0000_00001000:
powrprof.dll
powrprof.dll
Explorer.EXE_244_rwx_06BD0000_00001000:
powrprof.dll
powrprof.dll
Explorer.EXE_244_rwx_06C00000_00001000:
shell32.dll
shell32.dll
Explorer.EXE_244_rwx_06C40000_00001000:
shell32.dll
shell32.dll
Explorer.EXE_244_rwx_06C70000_00001000:
user32.dll
user32.dll
Explorer.EXE_244_rwx_06CF0000_00001000:
user32.dll
user32.dll
Explorer.EXE_244_rwx_06D20000_00001000:
version.dll
version.dll
Explorer.EXE_244_rwx_06D60000_00001000:
version.dll
version.dll
Explorer.EXE_244_rwx_06DD0000_00001000:
wininet.dll
wininet.dll
Explorer.EXE_244_rwx_06E00000_00001000:
FtpOpenFileA
FtpOpenFileA
Explorer.EXE_244_rwx_06E10000_00001000:
wininet.dll
wininet.dll
Explorer.EXE_244_rwx_06E40000_00001000:
winmm.dll
winmm.dll
Explorer.EXE_244_rwx_06E80000_00001000:
winmm.dll
winmm.dll
Explorer.EXE_244_rwx_06EF0000_00001000:
wsock32.dll
wsock32.dll
Explorer.EXE_244_rwx_06F30000_00001000:
wsock32.dll
wsock32.dll
Explorer.EXE_244_rwx_10410000_00070000:
`.rsrc
`.rsrc
kernel32.dll
kernel32.dll
Portions Copyright (c) 1999,2003 Avenger by NhT
Portions Copyright (c) 1999,2003 Avenger by NhT
SHFileOperationA
SHFileOperationA
shell32.dll
shell32.dll
URLDownloadToFileA
URLDownloadToFileA
urlmon.dll
urlmon.dll
ShellExecuteA
ShellExecuteA
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
\Internet Explorer\iexplore.exe
\Internet Explorer\iexplore.exe
####@####
####@####
AVKWCtlX64.exe
AVKWCtlX64.exe
AVKWCtl.exe
AVKWCtl.exe
avgnt.exe
avgnt.exe
avp.exe
avp.exe
mbam.exe
mbam.exe
a2service.exe
a2service.exe
Vba32arkit.exe
Vba32arkit.exe
ClamWin.exe
ClamWin.exe
avesvc.exe
avesvc.exe
ashdisp.exe
ashdisp.exe
avgcc.exe
avgcc.exe
bdss.exe
bdss.exe
spider.exe
spider.exe
kavsvc.exe
kavsvc.exe
nod32krn.exe
nod32krn.exe
cclaw.exe
cclaw.exe
dvpapi.exe
dvpapi.exe
ewidoctrl.exe
ewidoctrl.exe
mcshield.exe
mcshield.exe
pavfires.exe
pavfires.exe
almon.exe
almon.exe
ccapp.exe
ccapp.exe
pccntmon.exe
pccntmon.exe
fssm32.exe
fssm32.exe
ekrn.exe
ekrn.exe
ccSvcHst.exe
ccSvcHst.exe
avgrsx.exe
avgrsx.exe
egui.exe
egui.exe
PSUNMAIN.exe
PSUNMAIN.exe
SSScheduler.exe
SSScheduler.exe
Dr.Web
Dr.Web
GDFwSvcx64.exe
GDFwSvcx64.exe
GDFwSvc.exe
GDFwSvc.exe
avfwsvc.exe
avfwsvc.exe
oacat.exe
oacat.exe
issvc.exe
issvc.exe
vsmon.exe
vsmon.exe
cpf.exe
cpf.exe
ca.exe
ca.exe
tnbutil.exe
tnbutil.exe
kavpf.exe
kavpf.exe
mpfservice.exe
mpfservice.exe
npfmsg.exe
npfmsg.exe
outpost.exe
outpost.exe
tpsrv.exe
tpsrv.exe
kpf4ss.exe
kpf4ss.exe
persfw.exe
persfw.exe
vsserv.exe
vsserv.exe
smc.exe
smc.exe
op_mon.exe
op_mon.exe
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
Portugal
Portugal
Turkey
Turkey
FirstExecution
FirstExecution
Windows 3.1
Windows 3.1
Windows 95 (Release 2)
Windows 95 (Release 2)
Windows 95
Windows 95
Windows 98 SE
Windows 98 SE
Windows 98
Windows 98
Windows ME
Windows ME
Windows 7
Windows 7
Windows Vista
Windows Vista
%s %s
%s %s
Windows XP Professional x64
Windows XP Professional x64
Windows XP Home
Windows XP Home
Windows XP Professional
Windows XP Professional
Windows 2000 Professional
Windows 2000 Professional
Windows NT %d.%d
Windows NT %d.%d
Windows 2008
Windows 2008
%s %s Server
%s %s Server
Windows 2003 Server Datacenter
Windows 2003 Server Datacenter
Windows 2003 Server Enterprise
Windows 2003 Server Enterprise
Windows 2003 Server Web Edition
Windows 2003 Server Web Edition
Windows 2003 Server
Windows 2003 Server
Windows Home Server
Windows Home Server
Windows 2003 Server (Release 2)
Windows 2003 Server (Release 2)
Windows 2000 Server Datacenter
Windows 2000 Server Datacenter
Windows 2000 Server Enterprise
Windows 2000 Server Enterprise
Windows 2000 Server Web Edition
Windows 2000 Server Web Edition
Windows 2000 Server
Windows 2000 Server
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server
Windows NT 4.0 Server
Unknown Platform ID (%d)
Unknown Platform ID (%d)
%d.%d
%d.%d
%s (Build: %d
%s (Build: %d
- Service Pack: %s
- Service Pack: %s
KERNEL32.DLL
KERNEL32.DLL
v3.4.2.2
v3.4.2.2
Set colFirewall = objSecurityCenter.ExecQuery("SELECT * FROM FirewallProduct","WQL",0)
Set colFirewall = objSecurityCenter.ExecQuery("SELECT * FROM FirewallProduct","WQL",0)
Set colAntiVirus = objSecurityCenter.ExecQuery("SELECT * FROM AntiVirusProduct","WQL",0)
Set colAntiVirus = objSecurityCenter.ExecQuery("SELECT * FROM AntiVirusProduct","WQL",0)
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFile = objFileSystem.CreateTextFile("
Set objFile = objFileSystem.CreateTextFile("
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & Enter
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & Enter
objFile.WriteLine(Info)
objFile.WriteLine(Info)
objFile.Close
objFile.Close
cscript.exe
cscript.exe
AVICAP32.dll
AVICAP32.dll
BuildImportTable: can't load library:
BuildImportTable: can't load library:
BuildImportTable: ReallocMemory failed
BuildImportTable: ReallocMemory failed
BuildImportTable: GetProcAddress failed
BuildImportTable: GetProcAddress failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: exported symbol not found
BTMemoryGetProcAddress: exported symbol not found
SetupApi.dll
SetupApi.dll
SetupDiOpenClassRegKey
SetupDiOpenClassRegKey
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExW
SetupDiOpenClassRegKeyExW
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiOpenDeviceInterfaceRegKey
SetupDiOpenDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyW
SetupDiCreateDevRegKeyW
SetupDiOpenDevRegKey
SetupDiOpenDevRegKey
SetupDiDeleteDevRegKey
SetupDiDeleteDevRegKey
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
127.0.0.1
127.0.0.1
iphlpapi.dll
iphlpapi.dll
AllocateAndGetTcpExTableFromStack
AllocateAndGetTcpExTableFromStack
AllocateAndGetUdpExTableFromStack
AllocateAndGetUdpExTableFromStack
SetTcpEntry
SetTcpEntry
GetExtendedTcpTable
GetExtendedTcpTable
GetExtendedUdpTable
GetExtendedUdpTable
ConnectWebcam
ConnectWebcam
DisconnectWebcam
DisconnectWebcam
ListWebcams
ListWebcams
CaptureWebcam
CaptureWebcam
IsWebcamConnected
IsWebcamConnected
StartHttpProxy
StartHttpProxy
1.2.3
1.2.3
keyboardkey
keyboardkey
webcaminactive
webcaminactive
webcamgetbuffer
webcamgetbuffer
webcam
webcam
webcamstart
webcamstart
checkwebcamfile
checkwebcamfile
checkwebcamfileback
checkwebcamfileback
webcamdllloaded
webcamdllloaded
enviarexecnormal
enviarexecnormal
enviarexechidden
enviarexechidden
openweb
openweb
openwebpage
openwebpage
openwebhidden
openwebhidden
downexec
downexec
sendftp
sendftp
keylogger
keylogger
keyloggergetlog
keyloggergetlog
keyloggereraselog
keyloggereraselog
keyloggerativar
keyloggerativar
keyloggerdesativar
keyloggerdesativar
renamekey
renamekey
windowsfechar
windowsfechar
windowsmax
windowsmax
windowsmin
windowsmin
windowsmostrar
windowsmostrar
windowsocultar
windowsocultar
windowsmintodas
windowsmintodas
windowscaption
windowscaption
listarportas
listarportas
listarportasdns
listarportasdns
finalizarprocessoportas
finalizarprocessoportas
webcamsettings
webcamsettings
chatmsg
chatmsg
getpassword
getpassword
updateservidorweb
updateservidorweb
keyloggersearch
keyloggersearch
urlredirect
urlredirect
urlredirecttrue
urlredirecttrue
onlinekeyloggereraselog
onlinekeyloggereraselog
onlinekeyloggerstart
onlinekeyloggerstart
onlinekeyloggerstop
onlinekeyloggerstop
onlinekeyloggererror
onlinekeyloggererror
keyloggerlist
keyloggerlist
tFtpAccess
tFtpAccess
onlinekeyloggerstart|onlinekeyloggerstart|
onlinekeyloggerstart|onlinekeyloggerstart|
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
PSAPI.dll
PSAPI.dll
%SYS%
%SYS%
ÞSKTOP%
ÞSKTOP%
TPasswordItem
TPasswordItem
TArrayPasswod
TArrayPasswod
sqlite3_open
sqlite3_open
sqlite3_prepare_v2
sqlite3_prepare_v2
sqlite3_column_text
sqlite3_column_text
sqlite3_step
sqlite3_step
sqlite3_close
sqlite3_close
sqlite3_column_blob
sqlite3_column_blob
sqlite3_column_bytes
sqlite3_column_bytes
Crypt32.dll
Crypt32.dll
ole32.dll
ole32.dll
Advapi32.dll
Advapi32.dll
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\
SOFTWARE\MOZILLA\MOZILLA FIREFOX
SOFTWARE\MOZILLA\MOZILLA FIREFOX
SOFTWARE\MOZILLA\MOZILLA FIREFOX\version.dll\Main
SOFTWARE\MOZILLA\MOZILLA FIREFOX\version.dll\Main
mozcrt19.dll
mozcrt19.dll
mozglue.dll
mozglue.dll
nspr4.dll
nspr4.dll
plc4.dll
plc4.dll
plds4.dll
plds4.dll
nssutil3.dll
nssutil3.dll
mozsqlite3.dll
mozsqlite3.dll
nss3.dll
nss3.dll
PK11_GetInternalKeySlot
PK11_GetInternalKeySlot
\Mozilla\Firefox\profiles.ini
\Mozilla\Firefox\profiles.ini
\Mozilla\Firefox\
\Mozilla\Firefox\
signons.sqlite
signons.sqlite
select * from moz_logins
select * from moz_logins
Firefox
Firefox
SOFTWARE\MOZILLA\MOZILLA FIREFOX\
SOFTWARE\MOZILLA\MOZILLA FIREFOX\
sqlite3.dll
sqlite3.dll
\Flock\Browser\profiles.ini
\Flock\Browser\profiles.ini
Flock-Firefox
Flock-Firefox
\1-abc\personal calendar\sqlite3.dll
\1-abc\personal calendar\sqlite3.dll
\clipdiary\sqlite3.dll
\clipdiary\sqlite3.dll
\conceptworld\recentx\sqlite3.dll
\conceptworld\recentx\sqlite3.dll
\darq software\transmute\sqlite3.dll
\darq software\transmute\sqlite3.dll
\delphish\sqlite3.dll
\delphish\sqlite3.dll
\ditto\sqlite3.dll
\ditto\sqlite3.dll
\du meter\sqlite3.dll
\du meter\sqlite3.dll
\fcleaner\sqlite3.dll
\fcleaner\sqlite3.dll
\file seeker\sqlite3.dll
\file seeker\sqlite3.dll
\flashnote\sqlite3.dll
\flashnote\sqlite3.dll
\flashpaste\sqlite3.dll
\flashpaste\sqlite3.dll
\gorecord\sqlite3.dll
\gorecord\sqlite3.dll
\gorecord2\sqlite3.dll
\gorecord2\sqlite3.dll
\linkcollector portable\sqlite3.dll
\linkcollector portable\sqlite3.dll
\ma-config.com\sqlite3.dll
\ma-config.com\sqlite3.dll
\macrovirus\sqlite3.dll
\macrovirus\sqlite3.dll
\msnsniffer2\sqlite3.dll
\msnsniffer2\sqlite3.dll
\notecable\sqlite3.dll
\notecable\sqlite3.dll
\nzbleecher\sqlite3.dll
\nzbleecher\sqlite3.dll
\outlook express\sqlite3.dll
\outlook express\sqlite3.dll
\page update watcher\sqlite3.dll
\page update watcher\sqlite3.dll
\pipi\sqlite3.dll
\pipi\sqlite3.dll
\qloud\sqlite3.dll
\qloud\sqlite3.dll
\qloud\winamp\sqlite3.dll
\qloud\winamp\sqlite3.dll
\qloud\windows media player\sqlite3.dll
\qloud\windows media player\sqlite3.dll
\recordtheradio\sqlite3.dll
\recordtheradio\sqlite3.dll
\rightload\sqlite3.dll
\rightload\sqlite3.dll
\smm\funny sms10\sqlite3.dll
\smm\funny sms10\sqlite3.dll
\smm\simple mail 7\sqlite3.dll
\smm\simple mail 7\sqlite3.dll
\spiceworks\bin\sqlite3.dll
\spiceworks\bin\sqlite3.dll
\spyware-secure\sqlite3.dll
\spyware-secure\sqlite3.dll
\timelog\sqlite3.dll
\timelog\sqlite3.dll
\video2webcam\sqlite3.dll
\video2webcam\sqlite3.dll
\webmarkers\sqlite3.dll
\webmarkers\sqlite3.dll
\webmediaplayer\sqlite3.dll
\webmediaplayer\sqlite3.dll
\windows media player\plugins\qloud\sqlite3.dll
\windows media player\plugins\qloud\sqlite3.dll
\Mozilla Firefox\sqlite3.dll
\Mozilla Firefox\sqlite3.dll
\VirusGuardPlus\sqlite3.dll
\VirusGuardPlus\sqlite3.dll
\Safari\sqlite3.dll
\Safari\sqlite3.dll
\AIMP2\sqlite3.dll
\AIMP2\sqlite3.dll
\Live-Player\sqlite3.dll
\Live-Player\sqlite3.dll
\TrustedProtection\sqlite3.dll
\TrustedProtection\sqlite3.dll
\PCTotalDefender\sqlite3.dll
\PCTotalDefender\sqlite3.dll
\Common Files\eEye Digital Security\Application Bus\sqlite3.dll
\Common Files\eEye Digital Security\Application Bus\sqlite3.dll
SELECT * FROM logins
SELECT * FROM logins
Google Chrome
Google Chrome
Flock-Chrome
Flock-Chrome
\Mozilla Firefox\mozcrt19.dll
\Mozilla Firefox\mozcrt19.dll
Google\Chrome\User Data\Default\
Google\Chrome\User Data\Default\
Login Data
Login Data
Web Data
Web Data
WindowsLive:name=*
WindowsLive:name=*
Windows Live Messenger
Windows Live Messenger
Password
Password
DynDNS\Updater\config.dyndns
DynDNS\Updater\config.dyndns
Password=
Password=
Software\DownloadManager\Passwords
Software\DownloadManager\Passwords
Software\DownloadManager\Passwords\
Software\DownloadManager\Passwords\
EncPassword
EncPassword
YLoginWnd
YLoginWnd
FileZilla\recentservers.xml
FileZilla\recentservers.xml
FileZilla\sitemanager.xml
FileZilla\sitemanager.xml
FileZilla\filezilla.xml
FileZilla\filezilla.xml
.purple\accounts.xml
.purple\accounts.xml
abe2869f-9b47-4cd9-a358-c22904dba7f7
abe2869f-9b47-4cd9-a358-c22904dba7f7
%UUUU1E
%UUUU1E
%UUUU3
%UUUU3
U_GrabOpera
U_GrabOpera
Opera|WandData :
Opera|WandData :
wand.dat
wand.dat
Opera\
Opera\
trillian.ini
trillian.ini
accounts.ini
accounts.ini
password
password
profiles.ini
profiles.ini
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trillian
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trillian
Trillian\trillian.exe
Trillian\trillian.exe
TPasswordGrabSV
TPasswordGrabSV
%s|%s|%s|%s|%s|
%s|%s|%s|%s|%s|
chatmsg|
chatmsg|
xXx_key_xXx
xXx_key_xXx
-wchelper.dll
-wchelper.dll
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
listarjanelas|windowsfechar|
listarjanelas|windowsfechar|
listarjanelas|windowsmax|
listarjanelas|windowsmax|
listarjanelas|windowsmin|
listarjanelas|windowsmin|
listarjanelas|windowsmostrar|
listarjanelas|windowsmostrar|
listarjanelas|windowsocultar|
listarjanelas|windowsocultar|
listarjanelas|windowsmintodas|
listarjanelas|windowsmintodas|
listarjanelas|windowscaption|
listarjanelas|windowscaption|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
listarportas|listadeportaspronta|
listarportas|listadeportaspronta|
listarportas|finalizarconexao|
listarportas|finalizarconexao|
listarportas|finalizarprocessoportas|Y|
listarportas|finalizarprocessoportas|Y|
listarportas|finalizarprocessoportas|N|
listarportas|finalizarprocessoportas|N|
URL_VISITOR
URL_VISITOR
registro|renamekey|
registro|renamekey|
Key name has been successfully changed
Key name has been successfully changed
Unable to change key name
Unable to change key name
registro|registro|Key name has been successfully changed|"
registro|registro|Key name has been successfully changed|"
registro|registro|Unable to change key name|"
registro|registro|Unable to change key name|"
registro|registro|The key or value has been deleted successfully|"
registro|registro|The key or value has been deleted successfully|"
registro|registro|Unable to delete key or value|"
registro|registro|Unable to delete key or value|"
registro|registro|The key was created successfully|"
registro|registro|The key was created successfully|"
registro|registro|Could not create key|"
registro|registro|Could not create key|"
keylogger|keyloggerlist|
keylogger|keyloggerlist|
ak.tmp
ak.tmp
onlinekeyloggerstart|onlinekeyloggererror|
onlinekeyloggerstart|onlinekeyloggererror|
keylogger|keylogger|keyloggerativar|
keylogger|keylogger|keyloggerativar|
keylogger|keylogger|keyloggerdesativar|
keylogger|keylogger|keyloggerdesativar|
keylogger|keyloggergetlog|
keylogger|keyloggergetlog|
keylogger|keylogger|keyloggervazio|
keylogger|keylogger|keyloggervazio|
keyloggersearchok|
keyloggersearchok|
checkwebcamfileback|
checkwebcamfileback|
webcamdlltransferdone|
webcamdlltransferdone|
webcam|webcaminactive|
webcam|webcaminactive|
webcamdllloaded|
webcamdllloaded|
checkwebcamfile|no|
checkwebcamfile|no|
webcam|webcamactive|
webcam|webcamactive|
webcam|webcamstop|
webcam|webcamstop|
getpassword|getpasswordlist|
getpassword|getpasswordlist|
USER32.DLL
USER32.DLL
C:\Windows\System32\drivers\etc\hosts
C:\Windows\System32\drivers\etc\hosts
temp.vbs
temp.vbs
liststartup|renamekey|
liststartup|renamekey|
liststartup|liststartup|Key name has been successfully changed|"
liststartup|liststartup|Key name has been successfully changed|"
liststartup|liststartup|Unable to change key name|"
liststartup|liststartup|Unable to change key name|"
liststartup|liststartup|The key or value has been deleted successfully|"
liststartup|liststartup|The key or value has been deleted successfully|"
liststartup|liststartup|Unable to delete key or value|"
liststartup|liststartup|Unable to delete key or value|"
liststartup|liststartup|The key was created successfully|"
liststartup|liststartup|The key was created successfully|"
liststartup|liststartup|Could not create key|"
liststartup|liststartup|Could not create key|"
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
KWindows
KWindows
U_GrabPassword
U_GrabPassword
8U_GrabOpera
8U_GrabOpera
\U_GrabChrome
\U_GrabChrome
6U_GrabFirefox
6U_GrabFirefox
.UnitBytesSize
.UnitBytesSize
YU_GrabFirefox8
YU_GrabFirefox8
U_GrabFirefox10
U_GrabFirefox10
UnitExecutarComandos
UnitExecutarComandos
UrlMon
UrlMon
uftp
uftp
UnitListarPortasAtivas
UnitListarPortasAtivas
UnitKeylogger
UnitKeylogger
GetProcessHeap
GetProcessHeap
WinExec
WinExec
SetNamedPipeHandleState
SetNamedPipeHandleState
CreatePipe
CreatePipe
RegOpenKeyExA
RegOpenKeyExA
RegOpenKeyA
RegOpenKeyA
RegEnumKeyExA
RegEnumKeyExA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyA
RegCreateKeyA
RegCloseKey
RegCloseKey
GdiplusShutdown
GdiplusShutdown
ShellExecuteExA
ShellExecuteExA
keybd_event
keybd_event
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
MapVirtualKeyExA
MapVirtualKeyExA
MapVirtualKeyA
MapVirtualKeyA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyboardLayoutNameA
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetAsyncKeyState
GetAsyncKeyState
ExitWindowsEx
ExitWindowsEx
EnumWindows
EnumWindows
InternetOpenUrlA
InternetOpenUrlA
FtpGetFileSize
FtpGetFileSize
FtpSetCurrentDirectoryA
FtpSetCurrentDirectoryA
FtpOpenFileA
FtpOpenFileA
9!!!$'')#
9!!!$'')#
&!!$'''#
&!!$'''#
.idata
.idata
.reloc
.reloc
P.rsrc
P.rsrc
advapi32.dll
advapi32.dll
gdi32.dll
gdi32.dll
gdiplus.dll
gdiplus.dll
mpr.dll
mpr.dll
msacm32.dll
msacm32.dll
ntdll.dll
ntdll.dll
oleaut32.dll
oleaut32.dll
powrprof.dll
powrprof.dll
user32.dll
user32.dll
version.dll
version.dll
wininet.dll
wininet.dll
winmm.dll
winmm.dll
wsock32.dll
wsock32.dll