home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Chip 2011 November
/
CHIP_2011_11.iso
/
Programy
/
Narzedzia
/
CCleaner
/
ccsetup310.exe
/
CCleaner64.exe
/
1033
/
INI
/
273
< prev
Wrap
Text File
|
2011-08-25
|
101KB
|
2,746 lines
; CCleaner - Application Cleaning file
[Global]
Revision=2075
NextIDValue=2267
;
; WARNING - DO NOT EDIT THIS FILE
; If you would like to create custom entries then create a new file
; called winapp2.ini which follows the same format as this one.
; CCleaner will automatically pick up the new file.
;
; Copyright ⌐2004-2011 Piriform Ltd, All Rights Reserved.
; This file and it's contents may not be copied or distributed
; without the express permission of the author.
;
; Notes
; ---------------------------------------
; LangSecRef
; 3021 = Applications
; 3022 = Internet
; 3023 = Multimedia
; 3024 = Utilities
; 3025 = Windows
; 3026 = Firefox/Mozilla
; 3027 = Opera
; 3028 = Safari
; 3029 = Google Chrome
[Mozilla - Internet Cache]
ID=2001
LangSecRef=3026
LangRef=3161
Default=True
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_CACHE
[Mozilla - Internet History]
ID=2002
LangSecRef=3026
LangRef=3162
Default=True
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_HISTORY
[Mozilla - Download History]
ID=2003
LangSecRef=3026
LangRef=3163
Default=True
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_DOWNLOAD
[Mozilla - Cookies]
ID=2004
LangSecRef=3026
LangRef=3102
Default=True
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_COOKIES
[Mozilla - Saved Form Information]
ID=2005
LangSecRef=3026
LangRef=3164
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_FORM
[Mozilla - Saved Passwords]
ID=2181
LangSecRef=3026
LangRef=3109
WarningRef=3202
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_PASSWORD
[Mozilla - Session]
ID=2153
LangSecRef=3026
LangRef=3167
Default=True
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_SESSION
[Mozilla - Site Preferences]
ID=2222
LangSecRef=3026
LangRef=3168
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_SITE_PREFERENCES
[Mozilla - Compact Databases]
ID=2146
LangSecRef=3026
LangRef=3165
Default=False
SpecialDetect=DET_MOZILLA
SpecialKey1=N_MOZ_COMPACT_DATABASES
[Opera - Internet Cache]
ID=2006
LangSecRef=3027
LangRef=3161
Default=True
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_CACHE
[Opera - Internet History]
ID=2007
LangSecRef=3027
LangRef=3162
Default=True
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_HISTORY
[Opera - Cookies]
ID=2008
LangSecRef=3027
LangRef=3102
Default=True
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_COOKIES
[Opera - Recently Typed URLs]
ID=2224
LangSecRef=3027
LangRef=3104
Default=True
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_RECENTLY_TYPED_URLS
[Opera - Last Download Location]
ID=2223
LangSecRef=3027
LangRef=3108
Default=True
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_LAST_DOWNLOAD_LOCATION
[Opera - Saved Passwords]
ID=2182
LangSecRef=3027
LangRef=3109
WarningRef=3202
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_PASSWORD
[Opera - Session]
ID=2225
LangSecRef=3027
LangRef=3167
Default=True
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_SESSION
[Opera - Website Icons]
ID=2149
LangSecRef=3027
LangRef=3166
Default=True
SpecialDetect=DET_OPERA
SpecialKey1=N_OPERA_WEBSITE_ICONS
[Safari - Internet Cache]
ID=2009
LangSecRef=3028
LangRef=3161
Default=True
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%localappdata%\Apple Computer\Safari|Cache.db
[Safari - Internet History]
ID=2010
LangSecRef=3028
LangRef=3162
Default=True
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari|History.plist
FileKey2=%appdata%\Apple Computer\Safari|LastSession.plist
FileKey3=%appdata%\Apple Computer\Safari|Downloads.plist
FileKey4=%localappdata%\Apple Computer\Safari\History|*.*
FileKey5=%localappdata%\Apple Computer\Safari\Webpage Previews|*.*|RECURSE
SpecialKey1=N_SAFARI_HISTORY
[Safari - Cookies]
ID=2011
LangSecRef=3028
LangRef=3102
Default=True
DetectFile=%ProgramFiles%\Safari\Safari.exe
SpecialKey1=N_SAFARI_COOKIES
[Safari - Saved Form Information]
ID=2012
LangSecRef=3028
LangRef=3164
Default=False
DetectFile=%ProgramFiles%\Safari\Safari.exe
FileKey1=%appdata%\Apple Computer\Safari|Form Values.plist
[Safari - Saved Passwords]
ID=2183
LangSecRef=3028
LangRef=3109
WarningRef=3202
SpecialDetect=DET_SAFARI_PASSWORD
SpecialKey1=N_SAFARI_PASSWORD
[Google Chrome - Internet Cache]
ID=2013
LangSecRef=3029
LangRef=3161
Default=True
Detect=HKCU\Software\Chromium
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
DetectFile3=%localappdata%\Flock\Application\flock.exe
DetectFile4=%ProgramFiles%\Flock\Application\flock.exe
DetectFile5=%localappdata%\Google\Chrome SxS\Application\chrome.exe
DetectFile6=%ProgramFiles%\Google\Chrome SxS\Application\chrome.exe
DetectFile7=%localappdata%\SRWare Iron\iron.exe
DetectFile8=%ProgramFiles%\SRWare Iron\iron.exe
DetectFile9=%ProgramFiles%\Chromium\chrome.exe
DetectFile10=%localappdata%\Chromium\chrome.exe
DetectFile11=%ProgramFiles%\Chromium\Application\chrome.exe
DetectFile12=%localappdata%\Chromium\Application\chrome.exe
DetectFile13=%AppData%\ChromePlus\chrome.exe
DetectFile14=%localappdata%\RockMelt\Application\rockmelt.exe
DetectFile15=%ProgramFiles%\RockMelt\Application\rockmelt.exe
DetectFile16=%LocalAppData%\Comodo\Dragon\dragon.exe
DetectFile17=%ProgramFiles%\Comodo\Dragon\dragon.exe
SpecialKey1=N_CHROME_CACHE
[Google Chrome - Internet History]
ID=2014
LangSecRef=3029
LangRef=3162
Section = Chrome
Default=True
Detect=HKCU\Software\Chromium
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
DetectFile3=%localappdata%\Flock\Application\flock.exe
DetectFile4=%ProgramFiles%\Flock\Application\flock.exe
DetectFile5=%localappdata%\Google\Chrome SxS\Application\chrome.exe
DetectFile6=%ProgramFiles%\Google\Chrome SxS\Application\chrome.exe
DetectFile7=%localappdata%\SRWare Iron\iron.exe
DetectFile8=%ProgramFiles%\SRWare Iron\iron.exe
DetectFile9=%ProgramFiles%\Chromium\chrome.exe
DetectFile10=%localappdata%\Chromium\chrome.exe
DetectFile11=%ProgramFiles%\Chromium\Application\chrome.exe
DetectFile12=%localappdata%\Chromium\Application\chrome.exe
DetectFile13=%AppData%\ChromePlus\chrome.exe
DetectFile14=%localappdata%\RockMelt\Application\rockmelt.exe
DetectFile15=%ProgramFiles%\RockMelt\Application\rockmelt.exe
DetectFile16=%LocalAppData%\Comodo\Dragon\dragon.exe
DetectFile17=%ProgramFiles%\Comodo\Dragon\dragon.exe
SpecialKey1=N_CHROME_HISTORY
[Google Chrome - Download History]
ID=2015
LangSecRef=3029
LangRef=3163
Default=True
Detect=HKCU\Software\Chromium
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
DetectFile3=%localappdata%\Flock\Application\flock.exe
DetectFile4=%ProgramFiles%\Flock\Application\flock.exe
DetectFile5=%localappdata%\Google\Chrome SxS\Application\chrome.exe
DetectFile6=%ProgramFiles%\Google\Chrome SxS\Application\chrome.exe
DetectFile7=%localappdata%\SRWare Iron\iron.exe
DetectFile8=%ProgramFiles%\SRWare Iron\iron.exe
DetectFile9=%ProgramFiles%\Chromium\chrome.exe
DetectFile10=%localappdata%\Chromium\chrome.exe
DetectFile11=%ProgramFiles%\Chromium\Application\chrome.exe
DetectFile12=%localappdata%\Chromium\Application\chrome.exe
DetectFile13=%AppData%\ChromePlus\chrome.exe
DetectFile14=%localappdata%\RockMelt\Application\rockmelt.exe
DetectFile15=%ProgramFiles%\RockMelt\Application\rockmelt.exe
DetectFile16=%LocalAppData%\Comodo\Dragon\dragon.exe
DetectFile17=%ProgramFiles%\Comodo\Dragon\dragon.exe
SpecialKey1=N_CHROME_DOWNLOAD
[Google Chrome - Cookies]
ID=2016
LangSecRef=3029
LangRef=3102
Default=True
Detect=HKCU\Software\Chromium
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
DetectFile3=%localappdata%\Flock\Application\flock.exe
DetectFile4=%ProgramFiles%\Flock\Application\flock.exe
DetectFile5=%localappdata%\Google\Chrome SxS\Application\chrome.exe
DetectFile6=%ProgramFiles%\Google\Chrome SxS\Application\chrome.exe
DetectFile7=%localappdata%\SRWare Iron\iron.exe
DetectFile8=%ProgramFiles%\SRWare Iron\iron.exe
DetectFile9=%ProgramFiles%\Chromium\chrome.exe
DetectFile10=%localappdata%\Chromium\chrome.exe
DetectFile11=%ProgramFiles%\Chromium\Application\chrome.exe
DetectFile12=%localappdata%\Chromium\Application\chrome.exe
DetectFile13=%AppData%\ChromePlus\chrome.exe
DetectFile14=%localappdata%\RockMelt\Application\rockmelt.exe
DetectFile15=%ProgramFiles%\RockMelt\Application\rockmelt.exe
DetectFile16=%LocalAppData%\Comodo\Dragon\dragon.exe
DetectFile17=%ProgramFiles%\Comodo\Dragon\dragon.exe
SpecialKey1=N_CHROME_COOKIES
[Google Chrome - Saved Form Information]
ID=2017
LangSecRef=3029
LangRef=3164
Default=False
Detect=HKCU\Software\Chromium
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
DetectFile3=%localappdata%\Flock\Application\flock.exe
DetectFile4=%ProgramFiles%\Flock\Application\flock.exe
DetectFile5=%localappdata%\Google\Chrome SxS\Application\chrome.exe
DetectFile6=%ProgramFiles%\Google\Chrome SxS\Application\chrome.exe
DetectFile7=%localappdata%\SRWare Iron\iron.exe
DetectFile8=%ProgramFiles%\SRWare Iron\iron.exe
DetectFile9=%ProgramFiles%\Chromium\chrome.exe
DetectFile10=%localappdata%\Chromium\chrome.exe
DetectFile11=%ProgramFiles%\Chromium\Application\chrome.exe
DetectFile12=%localappdata%\Chromium\Application\chrome.exe
DetectFile13=%AppData%\ChromePlus\chrome.exe
DetectFile14=%localappdata%\RockMelt\Application\rockmelt.exe
DetectFile15=%ProgramFiles%\RockMelt\Application\rockmelt.exe
DetectFile16=%LocalAppData%\Comodo\Dragon\dragon.exe
DetectFile17=%ProgramFiles%\Comodo\Dragon\dragon.exe
SpecialKey1=N_CHROME_FORM
[Google Chrome - Saved Passwords]
ID=2184
LangSecRef=3029
LangRef=3109
WarningRef=3202
Default=False
Detect=HKCU\Software\Chromium
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
DetectFile3=%localappdata%\Flock\Application\flock.exe
DetectFile4=%ProgramFiles%\Flock\Application\flock.exe
DetectFile5=%localappdata%\Google\Chrome SxS\Application\chrome.exe
DetectFile6=%ProgramFiles%\Google\Chrome SxS\Application\chrome.exe
DetectFile7=%localappdata%\SRWare Iron\iron.exe
DetectFile8=%ProgramFiles%\SRWare Iron\iron.exe
DetectFile9=%ProgramFiles%\Chromium\chrome.exe
DetectFile10=%localappdata%\Chromium\chrome.exe
DetectFile11=%ProgramFiles%\Chromium\Application\chrome.exe
DetectFile12=%localappdata%\Chromium\Application\chrome.exe
DetectFile13=%AppData%\ChromePlus\chrome.exe
DetectFile14=%localappdata%\RockMelt\Application\rockmelt.exe
DetectFile15=%ProgramFiles%\RockMelt\Application\rockmelt.exe
DetectFile16=%LocalAppData%\Comodo\Dragon\dragon.exe
DetectFile17=%ProgramFiles%\Comodo\Dragon\dragon.exe
SpecialKey1=N_CHROME_PASSWORD
[Google Chrome - Session]
ID=2152
LangSecRef=3029
LangRef=3167
Default=True
Detect=HKCU\Software\Chromium
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
DetectFile3=%localappdata%\Flock\Application\flock.exe
DetectFile4=%ProgramFiles%\Flock\Application\flock.exe
DetectFile5=%localappdata%\Google\Chrome SxS\Application\chrome.exe
DetectFile6=%ProgramFiles%\Google\Chrome SxS\Application\chrome.exe
DetectFile7=%localappdata%\SRWare Iron\iron.exe
DetectFile8=%ProgramFiles%\SRWare Iron\iron.exe
DetectFile9=%ProgramFiles%\Chromium\chrome.exe
DetectFile10=%localappdata%\Chromium\chrome.exe
DetectFile11=%ProgramFiles%\Chromium\Application\chrome.exe
DetectFile12=%localappdata%\Chromium\Application\chrome.exe
DetectFile13=%AppData%\ChromePlus\chrome.exe
DetectFile14=%localappdata%\RockMelt\Application\rockmelt.exe
DetectFile15=%ProgramFiles%\RockMelt\Application\rockmelt.exe
DetectFile16=%LocalAppData%\Comodo\Dragon\dragon.exe
DetectFile17=%ProgramFiles%\Comodo\Dragon\dragon.exe
SpecialKey1=N_CHROME_SESSION
[Google Chrome - Compact Databases]
ID=2147
LangSecRef=3029
LangRef=3165
Default=False
Detect=HKCU\Software\Chromium
DetectFile=%localappdata%\Google\Chrome\Application\chrome.exe
DetectFile2=%ProgramFiles%\Google\Chrome\Application\chrome.exe
DetectFile3=%localappdata%\Flock\Application\flock.exe
DetectFile4=%ProgramFiles%\Flock\Application\flock.exe
DetectFile5=%localappdata%\Google\Chrome SxS\Application\chrome.exe
DetectFile6=%ProgramFiles%\Google\Chrome SxS\Application\chrome.exe
DetectFile7=%localappdata%\SRWare Iron\iron.exe
DetectFile8=%ProgramFiles%\SRWare Iron\iron.exe
DetectFile9=%ProgramFiles%\Chromium\chrome.exe
DetectFile10=%localappdata%\Chromium\chrome.exe
DetectFile11=%ProgramFiles%\Chromium\Application\chrome.exe
DetectFile12=%localappdata%\Chromium\Application\chrome.exe
DetectFile13=%AppData%\ChromePlus\chrome.exe
DetectFile14=%localappdata%\RockMelt\Application\rockmelt.exe
DetectFile15=%ProgramFiles%\RockMelt\Application\rockmelt.exe
DetectFile16=%LocalAppData%\Comodo\Dragon\dragon.exe
DetectFile17=%ProgramFiles%\Comodo\Dragon\dragon.exe
SpecialKey1=N_CHROME_COMPACT_DATABASES
[Adobe Acrobat Reader 5.0]
ID=2018
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles
Default=True
RegKey1=HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles
[Adobe Acrobat Reader 6.0]
ID=2019
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral
Default=True
RegKey1=HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral\cRecentFiles
[Adobe Acrobat Reader 7.0]
ID=2020
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral
Default=True
RegKey1=HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\7.0\Cache\Search70|*.*
FileKey2=%ProgramFiles%\Adobe\Acrobat 7.0\Reader|*.bak
FileKey3=%ProgramFiles%\Adobe\Acrobat 7.0\ActiveX|*.bak
FileKey4=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\plug_ins|*.bak
FileKey5=%ProgramFiles%\Adobe\Acrobat 7.0\Reader\Updater|*.bak
[Adobe Reader 8.0]
ID=2021
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\8.0
Default=True
RegKey1=HKCU\Software\Adobe\Acrobat Reader\8.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\8.0\Cache\Search80|*.*
[Adobe Reader 9.0]
ID=2137
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\9.0
Default=True
RegKey1=HKCU\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Acrobat\9.0\Cache\Search|*.*
FileKey2=%LocalLowAppData%\Adobe\Acrobat\9.0\Search|*.*
[Adobe Reader 10.0]
ID=2176
LangSecRef=3021
Detect=HKCU\Software\Adobe\Acrobat Reader\10.0
Default=True
RegKey1=HKCU\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Acrobat\10.0\Cache\Search|*.*
FileKey2=%LocalLowAppData%\Adobe\Acrobat\10.0\Search|*.*
[Adobe Acrobat 8.0]
ID=2022
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\8.0
Default=True
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\8.0\AVGeneral\cRecentFiles
FileKey1=%localappdata%\Adobe\Acrobat\8.0\Cache\Search80|*.*
[Adobe Acrobat 9.0]
ID=2185
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\9.0
Default=True
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\9.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Acrobat\9.0\Cache\Search|*.*
FileKey2=%LocalLowAppData%\Adobe\Acrobat\9.0\Search|*.*
[Adobe Acrobat 10.0]
ID=2186
LangSecRef=3021
Detect=HKCU\Software\Adobe\Adobe Acrobat\10.0
Default=True
RegKey1=HKCU\Software\Adobe\Adobe Acrobat\10.0\AVGeneral\cRecentFiles
FileKey1=%LocalAppData%\Adobe\Acrobat\10.0\Cache\Search|*.*
FileKey2=%LocalLowAppData%\Adobe\Acrobat\10.0\Search|*.*
[Adobe ImageReady 7.0]
ID=2023
LangSecRef=3021
Default=True
Detect=HKCU\Software\Adobe\ImageReady 7.0
RegKey1=HKCU\Software\Adobe\ImageReady 7.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 7.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 7.0\Preferences\RecentFiles
[Adobe ImageReady CS]
ID=2154
LangSecRef=3021
Detect=HKCU\Software\Adobe\ImageReady 8.0
Default=True
RegKey1=HKCU\Software\Adobe\ImageReady 8.0\Preferences\URLHistory
RegKey2=HKCU\Software\Adobe\ImageReady 8.0\Preferences|SaveDir
RegKey3=HKCU\Software\Adobe\ImageReady 8.0\Preferences\RecentFiles
[Adobe Photoshop 6.0]
ID=2024
LangSecRef=3021
Default=True
Detect=HKCU\Software\Adobe\Photoshop\6.0
RegKey1=HKCU\Software\Adobe\Photoshop\6.0\VisitedDirs
[Adobe Photoshop 7.0]
ID=2025
LangSecRef=3021
Default=True
Detect=HKCU\Software\Adobe\Photoshop\7.0
RegKey1=HKCU\Software\Adobe\Photoshop\7.0\VisitedDirs
[Adobe Photoshop CS]
ID=2026
LangSecRef=3021
Default=True
Detect=HKCU\Software\Adobe\Photoshop\8.0
RegKey1=HKCU\Software\Adobe\Photoshop\8.0\VisitedDirs
[Adobe Photoshop CS2]
ID=2027
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\9.0
Default=True
RegKey1=HKCU\Software\Adobe\Photoshop\9.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
FileKey1=%appdata%\Adobe\CameraRaw\Cache|*.*
[Adobe Photoshop CS3]
ID=2139
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\10.0
Default=True
RegKey1=HKCU\Software\Adobe\Photoshop\10.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
[Adobe Photoshop CS4]
ID=2140
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\11.0
Default=True
RegKey1=HKCU\Software\Adobe\Photoshop\11.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
[Adobe Photoshop CS5]
ID=2156
LangSecRef=3021
Detect=HKCU\Software\Adobe\Photoshop\12.0
Default=True
RegKey1=HKCU\Software\Adobe\Photoshop\12.0\VisitedDirs
RegKey2=HKCU\Software\Adobe\MediaBrowser\MRU\Photoshop\FileList
[Adobe Illustrator]
ID=2144
LangSecRef=3021
Detect=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator
Default=True
RegKey1=HKCU\Software\Adobe\MediaBrowser\MRU\illustrator\FileList
[Adobe Air]
ID=2201
LangSecRef=3024
DetectFile=%LocalAppData%\Adobe\Air
Defualt=True
FileKey1=%LocalAppData%\Adobe\Air\Logs|*.*
[Acrobat Distiller 10]
ID=2264
LangSecRef=3021
DetectFile=%AppData%\Adobe\Acrobat\Distiller 10
Default=True
FileKey1=%AppData%\Adobe\Acrobat\Distiller 10|messages.log
[Advanced Searchbar]
ID=2202
LangSecRef=3022
DetectFile=%ProgramFiles%\AdvancedSearchbar\advancedsearchbar.dll
Default=True
FileKey1=%ProgramFiles%\AdvancedSearchbar\Cache|*.*
RegKey1=HKCU\Software\Advanced Searchbar\Toolbar\Historysearchbox1
[Yahoo Toolbar]
ID=2028
LangSecRef=3022
Detect=HKCU\Software\Yahoo\Companion
Default=True
RegKey1=HKCU\Software\Yahoo\Companion\SearchHistory
[Windows Live Toolbar]
ID=2029
LangSecRef=3022
Detect=HKCU\Software\Microsoft\MSN Apps\SearchBox
Default=True
RegKey1=HKCU\Software\Microsoft\MSN Apps\SearchBox|History
RegKey2=HKCU\Software\Microsoft\MSN Apps\MSN Toolbar|SearchStrings
[Google Toolbar]
ID=2030
LangSecRef=3022
Detect=HKCU\Software\Google\NavClient\1.1
Default=True
RegKey1=HKCU\Software\Google\NavClient\1.1\History
RegKey2=HKCU\Software\Google\NavClient\1.1\Options|KillPopupCount
[Google Toolbar IE]
ID=2031
LangSecRef=3022
Detect=HKCU\Software\Google\Google Toolbar
Default=True
FileKey1=%appdata%\Google\Local Search History|*.*
[Google Deskbar]
ID=2032
LangSecRef=3022
Detect=HKCU\Software\Google\Deskbar
Default=True
RegKey1=HKCU\Software\Google\Deskbar\termhistory
RegKey2=HKCU\Software\Google\Deskbar\urlhistory
[Google Calendar Sync]
ID=2159
LangSecRef=3022
Detect=HKCU\Software\Google\Google Calendar Sync
Default=True
FileKey1=%localappdata%\Google\Google Calendar Sync\logs|*.log
[Google Talk]
ID=2158
LangSecRef=3022
Detect=HKCU\Software\Google\Google Talk
DetectFile1=%ProgramFiles%\Google\Google Talk
DetectFile2=%appdata%\Google\Google Talk
DetectFile3=%localappdata%\Google\Google Talk
Default=False
FileKey1=%localappdata%\Google\Google Talk\status|*.txt
FileKey2=%localappdata%\Google\Google Talk\chatlogs|*.log
[Kantaris Media Player]
ID=2232
LangSecRef=3023
DetectFile=%AppData%\Christofer Persson\Kantaris Media Player
Default=True
FileKey1=%AppData%\Christofer Persson\Kantaris Media Player|*.jpg
[KMPlayer]
ID=2233
LangSecRef=3023
Detect=HKCU\Software\KMPlayer
Default=True
RegKey1=HKCU\Software\KMPlayer\KMP2.0|LastFileName
RegKey2=HKCU\Software\KMPlayer\WideAlbum\(Default Album)
RegKey3=HKCU\Software\KMPlayer\albumart|LastAlbumName
[Windows Media Player]
ID=2033
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MediaPlayer\Player
Default=True
RegKey1=HKCU\Software\Microsoft\MediaPlayer\Player\RecentFileList
RegKey2=HKCU\Software\Microsoft\MediaPlayer\Player\RecentURLList
RegKey3=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayList
RegKey4=HKCU\Software\Microsoft\MediaPlayer\Preferences|LastPlayListIndex
RegKey5=HKCU\Software\Microsoft\MediaPlayer\Player\Settings|SaveAsDir
RegKey6=HKCU\Software\Microsoft\MediaPlayer\AutoComplete\MediaEdit
RegKey7=HKCU\Software\Microsoft\MediaPlayer\Radio\MRUList
FileKey1=%LocalAppData%\Microsoft\Media Player|lastplayed.wpl
FileKey2=%LocalAppData%\Microsoft\Media Player|cacheentry*.*|RECURSE
[Real Player]
ID=2034
LangSecRef=3023
Detect=HKCU\Software\RealNetworks\RealPlayer\6.0
Default=True
RegKey1=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins1
RegKey10=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins2
RegKey11=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins3
RegKey12=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins4
RegKey13=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins5
RegKey14=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins6
RegKey15=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins7
RegKey16=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins8
RegKey17=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\LastOpenFileDir
RegKey18=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips1
RegKey19=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips2
RegKey20=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips3
RegKey21=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips4
RegKey22=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips5
RegKey23=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips6
RegKey24=HKCU\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips7
FileKey1=%appdata%\Real\RealOne Player|cookies.txt
FileKey2=%appdata%\Real\RealOne Player|ctd.dat
FileKey3=%appdata%\Real\RealOne Player|realplayer.ste
FileKey4=%appdata%\Real\RealOne Player\History|*.*
FileKey5=%appdata%\Real\RealPlayer|cookies.txt
FileKey6=%appdata%\Real\RealPlayer|ctd.dat
FileKey7=%appdata%\Real\RealPlayer|realplayer.ste
FileKey8=%appdata%\Real\RealPlayer\History|*.*
FileKey9=%ProgramFiles%\Common Files\Real\Update_OB|RealPlayer-log.txt
FileKey10=%AppData%\Real\RealPlayer\ErrorLogs|*.*
FileKey11=%AppData%\Real\RealPlayer\WatchFolders|*.log|RECURSE
[Real Player SP]
ID=2150
LangSecRef=3023
Detect=HKCU\Software\RealNetworks\RealPlayer\12.0
Default=True
RegKey1=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips1
RegKey2=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips2
RegKey3=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips3
RegKey4=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips4
RegKey5=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips5
RegKey6=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips6
RegKey7=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips7
RegKey8=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentClips8
RegKey9=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins1
RegKey10=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins2
RegKey11=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins3
RegKey12=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins4
RegKey13=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins5
RegKey14=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins6
RegKey15=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins7
RegKey16=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\MostRecentSkins8
RegKey17=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\LastOpenFileDir
RegKey18=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips1
RegKey19=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips2
RegKey20=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips3
RegKey21=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips4
RegKey22=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips5
RegKey23=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips6
RegKey24=HKCU\Software\RealNetworks\RealPlayer\12.0\Preferences\OpenLocationClips7
RegKey25=HKCU\Software\RealNetworks\RealConverter\12.0\Preferences\BrowsePath
RegKey26=HKCU\Software\RealNetworks\RealConverter\12.0\Preferences\DestinationPath
RegKey27=HKCU\Software\RealNetworks\RealTrimmer\12.0\Preferences\BrowsePath
FileKey1=%appdata%\Real\RealPlayer|cookies.txt
FileKey2=%appdata%\Real\RealPlayer|ctd.dat
FileKey3=%appdata%\Real\RealPlayer|realplayer.ste
FileKey4=%appdata%\Real\RealPlayer|RealPlayer-log.txt
FileKey5=%appdata%\Real\RealPlayer\History|*.*
FileKey6=%AppData%\Real\RealPlayer\ErrorLogs|*.*
FileKey7=%AppData%\Real\RealPlayer\WatchFolders|*.log|RECURSE
[Quicktime Player]
ID=2035
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=True
RegKey1=HKLM\Software\Apple Computer, Inc.\QuickTime\Recent Movies
FileKey1=%userprofile%|QTPlayerSession.xml
FileKey2=%appdata%\Apple Computer\QuickTime|QTPlayerSession.xml
FileKey3=%localappdata%\Apple Computer\QuickTime|QTPlayerSession.xml
[Quicktime Player Cache]
ID=2036
LangSecRef=3023
Detect=HKLM\Software\Apple Computer, Inc.\QuickTime
Default=True
FileKey1=%localappdata%\Apple Computer\QuickTime\downloads|*.*|RECURSE
FileKey2=%locallowappdata%\Apple Computer\quicktime\downloads|*.*|RECURSE
[AVI Preview]
ID=2037
LangSecRef=3023
Detect=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit www.avipreview.com for more
Default=True
RegKey1=HKCU\Software\Andrei Jefremov\AVIPreview by Andrei Jefremov, visit www.avipreview.com for more\Recent File List
[Steam]
ID=2203
LangSecRef=3023
DetectFile=%ProgramFiles%\Steam\Steam.exe
Default=True
FileKey1=%ProgramFiles%\Steam|*.mdmp
FileKey2=%ProgramFiles%\Steam\Dumps|*.*|RECURSE
FileKey3=%ProgramFiles%\Steam|*.log
FileKey4=%ProgramFiles%\Steam\Logs|*.*|RECURSE
[Xfire]
ID=2204
LangSecRef=3023
DetectFile=%ProgramFiles%\Xfire\Xfire.exe
Default=True
FileKey1=%CommonAppData%\Xfire|*-*-*-*-*-*-*.log
FileKey2=%CommonAppData%\Xfire|xfire_exe_log.txt
FileKey3=%CommonAppData%\Xfire|xfire_toucan_log.txt
FileKey4=%ProgramFiles%\Xfire|*-*-*-*-*-*-*.log
FileKey5=%ProgramFiles%\Xfire|xfire_exe_log.txt
FileKey6=%ProgramFiles%\Xfire|xfire_toucan_log.txt
[XML Spy]
ID=2038
LangSecRef=3021
Detect=HKCU\Software\Altova\XML Spy
Default=True
RegKey1=HKCU\Software\Altova\XML Spy\Recent File List
RegKey2=HKCU\Software\Altova\XML Spy\Recent Project List
[SWiSH]
ID=2039
LangSecRef=3023
Detect=HKCU\Software\DJJ Holdings\SWiSH
Default=True
RegKey1=HKCU\Software\DJJ Holdings\SWiSH\Recent File List
[Paint Shop Pro 7.0]
ID=2040
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 7
Default=True
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 7\Recent File List
RegKey2=HKCU\Software\Jasc\Animation Shop 3\Recent File List
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 7\General|FolderHistory
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveAsDirectory
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 7\General|SaveCopyDirectory
[Paint Shop Pro 8.0]
ID=2041
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 8
Default=True
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 8\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 8\WorkspaceMRU
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdPyScript\RunScript|FileName
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdFile\FileSaveAs|FileFolder
RegKey5=HKCU\Software\Jasc\Paint Shop Pro 8\JascCmdNonGraphic\SaveWorkspace|WorkspaceFilename
RegKey6=HKCU\Software\Jasc\Paint Shop Pro 8\ScriptMRU
[Paint Shop Pro 9.0]
ID=2042
LangSecRef=3023
Detect=HKCU\Software\Jasc\Paint Shop Pro 9
Default=True
RegKey1=HKCU\Software\Jasc\Paint Shop Pro 9\Recent File List
RegKey2=HKCU\Software\Jasc\Paint Shop Pro 9\WorkspaceMRU
RegKey3=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Jasc\Paint Shop Pro 9\JascCmdFile\FileOpen|Folder
[Paint Shop Pro X]
ID=2043
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\10
Default=True
RegKey1=HKCU\Software\Corel\Paint Shop Pro\10\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\10\WorkspaceMRU
RegKey3=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\10\CmdFile\FileOpen|Folder
[Paint Shop Pro XI]
ID=2044
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\11
Default=True
RegKey1=HKCU\Software\Corel\Paint Shop Pro\11\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\11\WorkspaceMRU
RegKey3=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\11\CmdFile\FileOpen|Folder
[Paint Shop Pro X2]
ID=2148
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\12
Detect2=HKCU\Software\Corel\Paint Shop Pro\12.5
Default=True
RegKey1=HKCU\Software\Corel\Paint Shop Pro\12\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\12\WorkspaceMRU
RegKey3=HKCU\Software\Corel\Paint Shop Pro\12\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\12\CmdFile\FileOpen|Folder
RegKey5=HKCU\Software\Corel\Paint Shop Pro\12.5\Recent File List
RegKey6=HKCU\Software\Corel\Paint Shop Pro\12.5\WorkspaceMRU
RegKey7=HKCU\Software\Corel\Paint Shop Pro\12.5\CmdFile\FileSaveAs|FileFolder
RegKey8=HKCU\Software\Corel\Paint Shop Pro\12.5\CmdFile\FileOpen|Folder
[Paint Shop Pro X3]
ID=2167
LangSecRef=3023
Detect=HKCU\Software\Corel\Paint Shop Pro\13
Default=True
RegKey1=HKCU\Software\Corel\Paint Shop Pro\13\Recent File List
RegKey2=HKCU\Software\Corel\Paint Shop Pro\13\WorkspaceMRU
RegKey3=HKCU\Software\Corel\Paint Shop Pro\13\CmdFile\FileSaveAs|FileFolder
RegKey4=HKCU\Software\Corel\Paint Shop Pro\13\CmdFile\FileOpen|Folder
[MS Works 4.0]
ID=2045
LangSecRef=3021
Detect= HKCU\Software\Microsoft\Works\4.0
Default=True
RegKey1=HKCU\Software\Microsoft\Works\4.0\Recent File List
[Office 97]
ID=2046
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\8.0\Common
Default=True
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\8.0\Excel\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\8.0\Project\Recent File List
RegKey3=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent File List
RegKey4=HKCU\Software\Microsoft\Office\8.0\PowerPoint\Recent Folder List
RegKey5=HKCU\Software\Microsoft\Office\8.0\Common\Internet\LocationOfComponents
RegKey6=HKCU\Software\Microsoft\Office\8.0\Access\Settings
[Office XP]
ID=2047
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\10.0\Common
Default=True
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\10.0\PowerPoint\Recent File List
RegKey2=HKCU\Software\Microsoft\Office\10.0\Excel\Recent Files
RegKey3=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent File List
RegKey4=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List
RegKey5=HKCU\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List
RegKey6=HKCU\Software\Microsoft\Office\10.0\Word\Recent Templates
RegKey7=HKCU\Software\Microsoft\Office\10.0\Common\Internet|UseRWHlinkNavigation
[Office 2003]
ID=2048
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\11.0\Common
Default=True
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\11.0\Excel\Recent Files
RegKey2=HKCU\Software\Microsoft\Office\11.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey3=HKCU\Software\Microsoft\Office\11.0\PowerPoint\Recent File List
RegKey4=HKCU\Software\Microsoft\Office\11.0\Publisher\Recent File List
RegKey5=HKCU\Software\Microsoft\Office\11.0\InfoPath\Recent File List
RegKey6=HKCU\Software\Microsoft\Office\11.0\Common\Internet\Server Cache
RegKey7=HKCU\Software\Microsoft\Office\11.0\Common\Internet|UseRWHlinkNavigation
RegKey8=HKCU\Software\Microsoft\MSPaper 11.0\Persist File Name
RegKey9=HKCU\Software\Microsoft\MSPaper 11.0\Recent File List
RegKey10=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile1
RegKey11=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile2
RegKey12=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile3
RegKey13=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile4
RegKey14=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile5
RegKey15=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile6
RegKey16=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile7
RegKey17=HKCU\Software\Microsoft\Office\11.0\Visio\Application|LastFile8
RegKey18=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|QuickFindMRU
RegKey19=HKCU\Software\Microsoft\Office\11.0\Outlook\Contact|StripSearchMRU
RegKey20=HKCU\Software\Microsoft\Office\11.0\Outlook\Preferences|LocationMRU
RegKey21=HKCU\Software\Microsoft\Office\11.0\Excel Viewer\Recent Files
[Office 2007]
ID=2049
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\12.0\Common
Default=True
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey2=HKCU\Software\Microsoft\Office\12.0\Word\File MRU
RegKey3=HKCU\Software\Microsoft\Office\12.0\Excel\File MRU
RegKey4=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU1
RegKey5=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU2
RegKey6=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU3
RegKey7=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU4
RegKey8=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU5
RegKey9=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU6
RegKey10=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU7
RegKey11=HKCU\Software\Microsoft\Office\12.0\Access\Settings|MRU8
RegKey12=HKCU\Software\Microsoft\Office\12.0\PowerPoint\File MRU
RegKey13=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Save As\File Name MRU
RegKey14=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open\File Name MRU
RegKey15=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office InfoPath\Settings\Save As\File Name MRU
RegKey16=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Excel\Settings\Save As\File Name MRU
RegKey17=HKCU\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Publisher\Settings\Save As\File Name MRU
RegKey18=HKCU\Software\Microsoft\Office\12.0\Publisher\Recent File List
RegKey19=HKCU\Software\Microsoft\Office\12.0\InfoPath\Recent File List
RegKey20=HKCU\Software\Microsoft\Office\12.0\Excel Viewer\Viewer File MRU
[Office 2010]
ID=2151
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office\14.0\Common
Default=True
FileKey1=%appdata%\Microsoft\Office\Recent|*.*
RegKey1=HKCU\Software\Microsoft\Office\14.0\Access\File MRU
RegKey2=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Default Database Path\File Name MRU
RegKey3=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Default Theme for New Databases\File Name MRU
RegKey4=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\File New Database\File Name MRU
RegKey5=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\File Open\File Name MRU
RegKey6=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\File Save\File Name MRU
RegKey7=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Open\File Name MRU
RegKey8=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Access\Settings\Save As\File Name MRU
RegKey9=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Default Database Path\File Name MRU
RegKey10=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Default Theme for New Databases\File Name MRU
RegKey11=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\File New Database\File Name MRU
RegKey12=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\File Open\File Name MRU
RegKey13=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\File Save\File Name MRU
RegKey14=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Open\File Name MRU
RegKey15=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Access\Settings\Save As\File Name MRU
RegKey16=HKCU\Software\Microsoft\Office\14.0\Word\File MRU
RegKey17=HKCU\Software\Microsoft\Office\14.0\Word\Place MRU
RegKey18=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\Browse\File Name MRU
RegKey19=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\File Open\File Name MRU
RegKey20=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\File Save\File Name MRU
RegKey21=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\Modify Location\File Name MRU
RegKey22=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Word\Settings\Save As\File Name MRU
RegKey23=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\Browse\File Name MRU
RegKey24=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\File Open\File Name MRU
RegKey25=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\File Save\File Name MRU
RegKey26=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\Modify Location\File Name MRU
RegKey27=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Word\Settings\Save As\File Name MRU
RegKey28=HKCU\Software\Microsoft\Office\14.0\Excel\File MRU
RegKey29=HKCU\Software\Microsoft\Office\14.0\Excel\Place MRU
RegKey30=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\Browse\File Name MRU
RegKey31=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\File Open\File Name MRU
RegKey32=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\File Save\File Name MRU
RegKey33=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\Modify Location\File Name MRU
RegKey34=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Excel\Settings\Save As\File Name MRU
RegKey35=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\Browse\File Name MRU
RegKey36=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\File Open\File Name MRU
RegKey37=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\File Save\File Name MRU
RegKey38=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\Modify Location\File Name MRU
RegKey39=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Excel\Settings\Save As\File Name MRU
RegKey40=HKCU\Software\Microsoft\Office\14.0\Publisher\File MRU
RegKey41=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\File Open\File Name MRU
RegKey42=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\File Save\File Name MRU
RegKey43=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\Open Publication\File Name MRU
RegKey44=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Publisher\Settings\Save As\File Name MRU
RegKey45=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\File Open\File Name MRU
RegKey46=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\File Save\File Name MRU
RegKey47=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\Open Publication\File Name MRU
RegKey48=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Publisher\Settings\Save As\File Name MRU
RegKey49=HKCU\Software\Microsoft\Office\14.0\PowerPoint\File MRU
RegKey50=HKCU\Software\Microsoft\Office\14.0\PowerPoint\Place MRU
RegKey51=HKCU\Software\Microsoft\Office\14.0\PowerPoint\RecentFolderList
RegKey52=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\Browse\File Name MRU
RegKey53=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\File Open\File Name MRU
RegKey54=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\File Save\File Name MRU
RegKey55=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\Open\File Name MRU
RegKey56=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft PowerPoint\Settings\Save As\File Name MRU
RegKey57=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Browse\File Name MRU
RegKey58=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\File Open\File Name MRU
RegKey59=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\File Save\File Name MRU
RegKey60=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Open\File Name MRU
RegKey61=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office PowerPoint\Settings\Save As\File Name MRU
RegKey62=HKCU\Software\Microsoft\Office\14.0\InfoPath\Designer File MRU
RegKey63=HKCU\Software\Microsoft\Office\14.0\InfoPath\Filler File MRU
RegKey64=HKCU\Software\Microsoft\Office\14.0\InfoPath\Recent Templates
RegKey65=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Browse\File Name MRU
RegKey66=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\File Open\File Name MRU
RegKey67=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\File Save\File Name MRU
RegKey68=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Open\File Name MRU
RegKey69=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Open in Design Mode\File Name MRU
RegKey70=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft InfoPath\Settings\Save As\File Name MRU
RegKey71=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Browse\File Name MRU
RegKey72=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\File Open\File Name MRU
RegKey73=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\File Save\File Name MRU
RegKey74=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open\File Name MRU
RegKey75=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Open in Design Mode\File Name MRU
RegKey76=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office InfoPath\Settings\Save As\File Name MRU
RegKey77=HKCU\Software\Microsoft\Office\14.0\OneNote\OpenNotebooks
RegKey78=HKCU\Software\Microsoft\Office\14.0\OneNote\RecentNotebooks
RegKey79=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\File Open\File Name MRU
RegKey80=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\File Save\File Name MRU
RegKey81=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Open Backup\File Name MRU
RegKey82=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Open Notebook\File Name MRU
RegKey83=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Save As\File Name MRU
RegKey84=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Select File\File Name MRU
RegKey85=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft OneNote\Settings\Select Folder\File Name MRU
RegKey86=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\File Open\File Name MRU
RegKey87=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\File Save\File Name MRU
RegKey88=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Open Backup\File Name MRU
RegKey89=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Open Notebook\File Name MRU
RegKey90=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Save As\File Name MRU
RegKey91=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Select File\File Name MRU
RegKey92=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office OneNote\Settings\Select Folder\File Name MRU
RegKey93=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\Create or Open Outlook Data File\File Name MRU
RegKey94=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\File Open\File Name MRU
RegKey95=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\File Save\File Name MRU
RegKey96=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\Open Calendar\File Name MRU
RegKey97=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Outlook\Settings\Open Outlook Data File\File Name MRU
RegKey98=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\Create or Open Outlook Data File\File Name MRU
RegKey99=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\File Open\File Name MRU
RegKey100=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\File Save\File Name MRU
RegKey101=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\Open Calendar\File Name MRU
RegKey102=HKCU\Software\Microsoft\Office\14.0\Common\Open Find\Microsoft Office Outlook\Settings\Open Outlook Data File\File Name MRU
[Installshield Developer 7.0]
ID=2050
LangSecRef=3021
Detect=HKCU\Software\InstallShield\Developer\7.0
Default=True
RegKey1=HKCU\Software\InstallShield\Developer\7.0\Recent File List
[Macromedia Flash 4.0]
ID=2051
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 4
Default=True
RegKey1=HKCU\Software\Macromedia\Flash 4\Recent File List
[Macromedia Flash 5.0]
ID=2052
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 5
Default=True
RegKey1=HKCU\Software\Macromedia\Flash 5\Recent File List
[Macromedia Flash MX]
ID=2053
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 6
Default=True
RegKey1=HKCU\Software\Macromedia\Flash 6\Recent File List
[Macromedia Flash MX 2004]
ID=2054
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Flash 7
Default=True
RegKey1=HKCU\Software\Macromedia\Flash 7\Recent File List
[Adobe Flash Player]
ID=2055
LangSecRef=3023
Detect=HKCR\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
DetectFile=%SystemDirectory%\Macromed\flash\flashplayer.xpt
Default=True
SpecialKey1=N_FLASH_COOKIES
[Macromedia Homesite 5.0]
ID=2056
LangSecRef=3021
Detect=HKCU\Software\Macromedia\HomeSite5
Default=True
RegKey1=HKCU\Software\Macromedia\HomeSite5\RecentFiles
[Macromedia Fireworks 6.0]
ID=2057
LangSecRef=3021
Default=True
Detect=HKCU\Software\Macromedia\Firework 6
RegKey1=HKCU\Software\Macromedia\Firework 6\Recent File List
[Macromedia Dreamweaver MX]
ID=2058
LangSecRef=3021
Default=True
Detect=HKCU\Software\Macromedia\Dreamweaver MX 2004
RegKey1=HKCU\Software\Macromedia\Dreamweaver MX 2004\Recent File List
[Macromedia Shockwave 10]
ID=2189
LangSecRef=3023
Detect=HKCU\Software\Macromedia\Shockwave 10
Detect=HKLM\Software\Macromedia\Shockwave 10
Default=True
RegKey1=HKCU\Software\Macromedia\Shockwave 10\movies
RegKey2=HKCU\Software\AppDataLow\Software\Macromedia\Shockwave 10\movies
RegKey3=HKCU\Software\AppDataLow\Software\Macromedia\Shockwave 10\statistics
FileKey1=%LocalLowAppData%\Macromedia\Shockwave Player|Shockwave Log
[Macromedia Shockwave 11]
ID=2190
LangSecRef=3023
Detect=HKLM\Software\Adobe\Shockwave 11
Detect=HKCU\Software\Adobe\Shockwave 11
Default=True
RegKey1=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\moviestats\movies
RegKey2=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\moviestats\sessions
RegKey3=HKCU\Software\Adobe\Shockwave 11\moviestats\movies
RegKey4=HKCU\Software\Adobe\Shockwave 11\moviestats\sessions
RegKey5=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\movies
RegKey6=HKCU\Software\Adobe\Shockwave 11\movies
RegKey7=HKCU\Software\AppDataLow\Software\Adobe\Shockwave 11\statistics
FileKey1=%LocalLowAppData%\Adobe\Shockwave Player 11|Shockwave Log
[Microsoft Silverlight]
ID=2169
LangSecRef=3023
DetectFile=%LocalAppData%\Microsoft\Silverlight\is
DetectFile2=%LocalLowAppData%\Microsoft\Silverlight\is
Detect=HKLM\Software\Microsoft\Silverlight
Default=True
FileKey1=%LocalAppData%\Microsoft\Silverlight\is|*.*|RECURSE
FileKey2=%LocalLowAppData%\Microsoft\Silverlight\is|*.*|RECURSE
ExcludeKey1=FILE|%LocalAppData%\Microsoft\Silverlight\is\*\|disabled.dat
ExcludeKey2=FILE|%LocalLowAppData%\Microsoft\Silverlight\is\*\|disabled.dat
[Ulead Smart Saver Pro 3.0]
ID=2059
LangSecRef=3023
Detect=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0
Default=True
RegKey1=HKCU\Software\Ulead Systems\Ulead SmartSaver Pro\3.0\Recent File List
[Norton AntiVirus]
ID=2060
LangSecRef=3024
Detect=HKLM\SOFTWARE\Symantec\Norton AntiVirus NT\Install\7.50
Default=True
FileKey1=%commonappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey2=%localappdata%\Symantec\Norton AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|*.*
[Symantec AntiVirus]
ID=2061
LangSecRef=3024
Detect=HKLM\SOFTWARE\Symantec\Symantec AntiVirus\Install\7.50
Default=True
FileKey1=%commonappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey2=%localappdata%\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs|*.log
FileKey3=%commonappdata%\Symantec\LiveUpdate\Downloads|*.*
[MS Snapshot Viewer]
ID=2062
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Snapshot Viewer
Default=True
RegKey1=HKCU\Software\Microsoft\Snapshot Viewer\Recent File List
[Remote Desktop]
ID=2063
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Terminal Server Client
Default=True
FileKey1=%localappdata%\Microsoft\Terminal Server Client\Cache|*.*
RegKey1=HKCU\Software\Microsoft\Terminal Server Client\Default
ExcludeKey1=REG|HKCU\Software\Microsoft\Terminal Server Client\Default\AddIns
[MS Management Console]
ID=2064
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Microsoft Management Console
Default=True
RegKey1=HKCU\Software\Microsoft\Microsoft Management Console\Recent File List
[MS Wordpad]
ID=2065
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad
Default=True
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List
[MS Paint]
ID=2066
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint
Default=True
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List
[MS Photo Editor]
ID=2067
LangSecRef=3025
Detect=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor
Default=True
RegKey1=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile1
RegKey2=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile2
RegKey3=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile3
RegKey4=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastFile4
RegKey5=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType1
RegKey6=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType2
RegKey7=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType3
RegKey8=HKCU\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor|LastType4
[MS Search]
ID=2266
LangSecRef=3025
DetectFile=%CommonAppData%\Microsoft\Search
Default=True
FileKey1=%CommonAppData%\Microsoft\Search|*.log|RECURSE
FileKey2=%CommonAppData%\Microsoft\Search|*.jrs|RECURSE
[Nero Burning ROM]
ID=2068
LangSecRef=3021
Detect=HKCU\Software\ahead\Nero - Burning Rom
Default=True
RegKey1=HKCU\Software\ahead\Nero - Burning Rom\Settings|BrowserDir
RegKey2=HKCU\Software\ahead\Nero - Burning Rom\Settings|ImageDir
RegKey3=HKCU\Software\ahead\Nero - Burning Rom\Settings|WorkingDir
RegKey4=HKLM\Software\Ahead\Nero - Burning Rom\Settings|ImageDir
RegKey5=HKLM\Software\Ahead\Nero - Burning Rom\Settings|BootImageDir
RegKey6=HKCU\Software\Ahead\Nero - Burning Rom\Recent File List
RegKey7=HKCU\Software\Ahead\Cover Designer\Recent File List
RegKey8=HKCU\Software\Ahead\Nero Wave Editor\Recent File List
FileKey1=%ProgramFiles%\Ahead\Nero|NeroHistory.log
[Nero Burning ROM 9]
ID=2142
LangSecRef=3021
Detect=HKCU\Software\Nero\Nero 9
Default=True
RegKey1=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BrowserDir
RegKey2=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|ImageDir
RegKey3=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|WorkingDir
RegKey4=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Settings|BootImageDir
RegKey5=HKCU\Software\Nero\Nero 9\Nero Burning ROM\Recent File List
FileKey1=%appdata%\Nero\Nero 9\Nero Burning ROM|*.log
[Nero Burning ROM 10]
ID=2155
LangSecRef=3021
Detect=HKCU\Software\Nero\Nero 10
Default=True
RegKey1=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|BrowserDir
RegKey2=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|ImageDir
RegKey3=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|WorkingDir
RegKey4=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|BootImageDir
RegKey5=HKCU\Software\Nero\Nero 10\Nero Burning ROM\Settings|NeroCompilation
RegKey6=HKCU\Software\Nero\Nero 10\Nero\Recent File List
FileKey1=%appdata%\Nero\Nero 10\Nero Burning ROM|*.log
[WinAce 2.0]
ID=2069
LangSecRef=3024
Detect=HKCU\Software\e-merge\WinAce\2.0
Default=True
RegKey1=HKCU\Software\e-merge\WinAce\2.0\Favorites
RegKey2=HKCU\Software\e-merge\WinAce\2.0\MRU Items
[SpyBot Search and Destroy]
ID=2070
LangSecRef=3024
Detect=HKCU\Software\Safer Networking Limited\SpybotSnD
Default=True
FileKey1=%commonappdata%\Spybot - Search & Destroy\Logs|*.*
FileKey2=%ProgramFiles%\Spybot - Search & Destroy|advdebug.txt
FileKey3=%commonappdata%\Spybot - Search & Destroy|Statistics.ini
FileKey4=%windir%\All Users\Application Data\Spybot - Search & Destroy\Logs|*.*
FileKey5=%windir%\All Users\Application Data\Spybot - Search & Destroy|Statistics.ini
FileKey6=%commonappdata%\Spybot - Search & Destroy\Backups|*.log
[Ad-Aware SE Personal]
ID=2071
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
Default=True
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Personal|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt
[Ad-Aware SE Professional]
ID=2072
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
Default=True
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Professional|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt
[Ad-Aware SE Plus]
ID=2073
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe
Default=True
FileKey1=%ProgramFiles%\Lavasoft\Ad-Aware SE Plus|defs.ref.old
FileKey2=%appdata%\Lavasoft\Ad-Aware\Logs|*.txt
[Ad-Aware]
ID=2163
LangSecRef=3024
DetectFile=%ProgramFiles%\Lavasoft\Ad-Aware\Ad-Aware.exe
Default=True
Filekey1=%commonappdata%\Lavasoft\Ad-Aware\Logs|*.log
[Webroot SpySweeper]
ID=2074
LangSecRef=3024
Detect=HKCU\Software\Webroot\SpySweeper
FileKey1=%ProgramFiles%\Webroot\Spy Sweeper\Temp|*.*
FileKey2=%appdata%\Webroot\Spy Sweeper\Logs|*Log.txt
[Driver Cleaner Pro]
ID=2075
LangSecRef=3024
DetectFile=%ProgramFiles%\Driver Cleaner Pro\DCleaner.exe
Default=True
FileKey1=%ProgramFiles%\Driver Cleaner Pro\Log|*.log
[Kazaa (Search History)]
ID=2076
LangSecRef=3022
Detect=HKCU\Software\Kazaa
Default=True
RegKey1=HKCU\Software\Kazaa\Search
[Netscape Navigator 4.x]
ID=2077
LangSecRef=3022
Detect=HKCU\Software\Netscape\Netscape Navigator\Main
Default=True
FileKey1=%ProgramFiles%\Netscape\Users\default|netscape.hst
FileKey2=%ProgramFiles%\Netscape\Users\default|cookies.txt
FileKey3=%ProgramFiles%\Netscape\Users\default\cache|*.*
[Microsoft Visual Studio 6.0]
ID=2078
LangSecRef=3021
Detect=HKCU\Software\Microsoft\VisualStudio\6.0
Default=True
RegKey1=HKCU\Software\Microsoft\VisualStudio\6.0\FileMRUList
RegKey2=HKCU\Software\Microsoft\VisualStudio\6.0\MenuMRUList
RegKey3=HKCU\Software\Microsoft\VisualStudio\6.0\ProjectMRUList
RegKey4=HKCU\Software\Microsoft\Visual Basic\6.0\RecentFiles
[Axialis IconWorkshop]
ID=2079
LangSecRef=3023
Detect=HKCU\Software\Axialis\IconWorkshop
Default=True
RegKey1=HKCU\Software\Axialis\IconWorkshop\Recent File List
RegKey2=HKCU\Software\Axialis\IconWorkshop\Axialis Recent Files
RegKey3=HKCU\Software\Axialis\IconWorkshop\CoolBarList
FileKey1=%appdata%\Axialis\Temporary Preview Files|*.*|RECURSE
[eMule (Search History)]
ID=2080
LangSecRef=3022
Detect=HKCU\Software\eMule
Default=True
FileKey1=%ProgramFiles%\eMule\config|AC_SearchStrings.dat
FileKey2=%LocalAppData%\eMule\config|AC_SearchStrings.dat
FileKey3=%CommonAppData%\eMule\config|AC_SearchStrings.dat
[eMule (File Hashes)]
ID=2081
LangSecRef=3022
Detect=HKCU\Software\eMule
Default=False
FileKey1=%ProgramFiles%\eMule\config|known.met
FileKey2=%ProgramFiles%\eMule\config|known2.met
FileKey3=%ProgramFiles%\eMule\config|known2_64.met
FileKey4=%LocalAppData%\eMule\config|known.met
FileKey5=%LocalAppData%\eMule\config|known2.met
FileKey6=%LocalAppData%\eMule\config|known2_64.met
FileKey7=%CommonAppData%\eMule\config|known.met
FileKey8=%CommonAppData%\eMule\config|known2.met
FileKey9=%CommonAppData%\eMule\config|known2_64.met
[WinISO]
ID=2082
LangSecRef=3024
Detect=HKLM\Software\WinISO
Default=True
RegKey1=HKLM\Software\WinISO\Reopen
[IsoBuster]
ID=2083
LangSecRef=3021
Detect=HKCU\Software\Smart Projects\IsoBuster
Default=True
RegKey1=HKCU\Software\Smart Projects\IsoBuster|ImageFilePath
[Media Player Classic]
ID=2084
LangSecRef=3023
Detect=HKCU\Software\Gabest\Media Player Classic
Default=True
RegKey1=HKCU\Software\Gabest\Media Player Classic\Recent File List
RegKey2=HKCU\Software\Gabest\Media Player Classic\Recent Dub List
RegKey3=HKCU\Software\Gabest\Media Player Classic\Capture|FileName
FileKey1=%appdata%\Media Player Classic|default.mpcpl
[BSPlayer]
ID=2085
LangSecRef=3023
Detect=HKCU\Software\BST\bsplayer
Default=True
RegKey1=HKCU\Software\BST\bsplayer|File0
RegKey2=HKCU\Software\BST\bsplayer|File1
RegKey3=HKCU\Software\BST\bsplayer|File2
RegKey4=HKCU\Software\BST\bsplayer|File3
RegKey5=HKCU\Software\BST\bsplayer|File4
RegKey6=HKCU\Software\BST\bsplayer|File5
RegKey7=HKCU\Software\BST\bsplayer|File6
RegKey8=HKCU\Software\BST\bsplayer|File7
RegKey9=HKCU\Software\BST\bsplayer|File8
RegKey10=HKCU\Software\BST\bsplayer|File9
[VLC Media Player]
ID=2164
LangSecRef=3023
DetectFile=%ProgramFiles%\videolan\vlc\vlc.exe
Default=True
FileKey1=%appdata%\vlc\art\artistalbum\|*.*|REMOVESELF
[MediaMonkey]
ID=2165
LangSecRef=3023
Detect=HKCU\Software\MediaMonkey
DetectFile=%ProgramFiles%\MediaMonkey\MediaMonkey.exe
Default=True
FileKey1=%localappdata%\MediaMonkey|MediaMonkey.m3u
FileKey2=%localappdata%\MediaMonkey\Previews|*.*|RECURSE
[Winamp]
ID=2166
LangSecRef=3023
Detect=HKCU\Software\Winamp
Default=True
FileKey1=%ProgramFiles%\Winamp|winamp.m3u
FileKey2=%ProgramFiles%\Winamp|winamp.m3u8
FileKey3=%ProgramFiles%\Winamp\Plugins\ml|recent.dat
FileKey4=%ProgramFiles%\Winamp\Plugins\ml\cache|*.*|RECURSE
FileKey5=%appdata%\Winamp|winamp.m3u
FileKey6=%appdata%\Winamp|winamp.m3u8
FileKey7=%appdata%\Winamp\Plugins\ml|recent.dat
FileKey8=%appdata%\Winamp\Plugins\ml\Cache|*.*|RECURSE
[MusicMatch Jukebox]
ID=2231
LangSecRef=3023
Detect=HKCU\Software\Musicmatch\Musicmatch Jukebox
Default=True
FileKey1=%LocalAppData%\Musicmatch\Jukebox|*.log
FileKey2=%LocalAppData%\Musicmatch\Jukebox|*log.txt
FileKey3=%ProgramFiles%\MUSICMATCH\Musicmatch Jukebox\TEMP|*.*
[Sound Forge 6.0]
ID=2086
LangSecRef=3022
Detect=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics
Default=True
RegKey1=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30110
RegKey2=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30111
RegKey3=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30112
RegKey4=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30113
RegKey5=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30114
RegKey6=HKCU\Software\Sonic Foundry\Sound Forge\6.0\Metrics|S30115
[Audacity]
ID=2171
LangSecRef=3022
Detect=HKCU\Software\Audacity
Default=True
RegKey1=HKCU\Software\Audacity\Audacity\RecentFiles
[Windows Live Messenger]
ID=2087
LangSecRef=3022
Detect=HKCU\Software\Microsoft\MSNMessenger\PerPassportSettings
Default=True
RegKey1=HKCU\Software\Microsoft\MessengerService\ListCache\.NET Messenger Service
FileKey1=%appdata%\Microsoft\MSN Messenger|*.sqm|RECURSE
FileKey2=%LocalAppData%\Microsoft\Messenger|*.uccapilog
FileKey3=%LocalAppData%\Microsoft\Messenger|*.bak
FileKey4=%UserProfile%\Tracing|WindowsLiveMessenger*.uccapilog
FileKey5=%UserProfile%\Tracing|WindowsLiveMessenger*.uccapilog.bak
[Skype]
ID=2205
LangSecRef=3022
DetectFile=%ProgramFiles%\Skype\Phone\Skype.exe
Default=True
FileKey1=%AppData%\Skype|temp*
[AOL Instant Messenger]
ID=2206
LangSecRef=3022
DetectFile=%ProgramFiles%\AIM\aim.exe
Default=True
FileKey1=%AppData%\acccore\caches\bart|*.*|RECURSE
FileKey2=%AppData%\acccore\caches\users|*.*|REMOVESELF
FileKey3=%LocalAppData%\AIM\Settings\aolbartcache|*.*|RECURSE
[Camfrog Video Chat]
ID=2207
LangSecRef=3022
DetectFile=%ProgramFiles%\Camfrog\Camfrog Video Chat\CamfrogNET.exe
Default=True
FileKey1=%LocalAppData%\CrashRpt|*.*|REMOVESELF
[Miranda Instant Messenger]
ID=2208
LangSecRef=3022
DetectFile1=%ProgramFiles%\Miranda IM\miranda32.exe
DetectFile2=%ProgramFiles%\Miranda IM\miranda64.exe
Default=True
FileKey1=%AppData%\Miranda|*.jpg|REMOVESELF
[Pidgin]
ID=2209
LangSecRef=3022
DetectFile=%ProgramFiles%\Pidgin\pidgin.exe
Default=True
FileKey1=%AppData%\.purple\autoaccept|*.*|REMOVESELF
FileKey2=%AppData%\.purple\icons|*.*
[Yahoo Messenger]
ID=2210
LangSecRef=3022
DetectFile=%ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe
Default=True
FileKey1=%ProgramFiles%\Yahoo!\Messenger\Cache|*.*|RECURSE
FileKey2=%ProgramFiles%\Yahoo!\Messenger\IMVCache|*.*|RECURSE
FileKey3=%ProgramFiles%\Yahoo!\Messenger|ypager.log
FileKey4=%ProgramFiles%\Yahoo!\Messenger\Logs|*.*
FileKey5=%ProgramFiles%\Yahoo!\Messenger\Games|*.gif|RECURSE
[ooVoo]
ID=2211
LangSecRef=3022
DetectFile=%ProgramFiles%\ooVoo\ooVoo.exe
Default=True
FileKey1=%AppData%\ooVoo Details\cache|*.*
FileKey2=%AppData%\ooVoo Details\logs|*.*
[TeamSpeak]
ID=2212
LangSecRef=3022
DetectFile1=%ProgramFiles%\TeamSpeak 3 Client\ts3client_win32.exe
DetectFile2=%ProgramFiles%\TeamSpeak 3 Client\ts3client_win64.exe
Default=True
FileKey1=%AppData%\TS3Client\cache|*.*|REMOVESELF
FileKey2=%AppData%\TS3Client\Logs|*.*
[Ventrilo Client]
ID=2213
LangSecRef=3022
DetectFile=%ProgramFiles%\Ventrilo\Ventrilo.exe
Default=True
FileKey1=%AppData%\Ventrilo|ventrilo.log
FileKey2=%AppData%\Ventrilo\temp|*.*
FileKey3=%AppData%\Ventrilo\recordings|*.*
[Ventrilo Server]
ID=2214
LangSecRef=3022
DetectFile=%ProgramFiles%\VentSrv\ventrilo_srv.exe
Default=True
FileKey1=%ProgramFiles%\VentSrv|ventrilo_srv.log
[MySpaceIM]
ID=2230
LangSecRef=3022
Detect=HKCU\Software\MySpace\IM
Default=True
FileKey1=%AppData%\MySpace\IM\Install|*.*
FileKey2=%AppData%\MySpace\IM\Logs|*.*
[Acronis True Image]
ID=2175
LangSecRef=3024
Detect=HKCU\Software\Acronis\TrueImage
Detect2=HKCU\Software\Acronis\TrueImageHome
Detect3=HKCU\Software\Acronis\ True Image Home
Detect4=HKLM\Software\Acronis\TrueImage
Default=False
FileKey1=%AppData%\Acronis\TrueImage\Logs|*.log
FileKey2=%AppData%\Acronis\TrueImageHome\Logs|*.log
FileKey3=%CommonAppData%\Acronis\TrueImage\Logs|*.log
FileKey4=%CommonAppData%\Acronis\TrueImageHome\Logs|*.log
[WinZip]
ID=2088
LangSecRef=3024
Detect=HKCU\Software\Nico Mak Computing\WinZip
Default=True
RegKey1=HKCU\Software\Nico Mak Computing\WinZip\filemenu
RegKey2=HKCU\Software\Nico Mak Computing\WinZip\extract
RegKey3=HKCU\Software\Nico Mak Computing\WinZip\directories|DefDir
RegKey4=HKCU\Software\Nico Mak Computing\WinZip\directories|ExtractTo
RegKey5=HKCU\Software\Nico Mak Computing\WinZip\directories|gzAddDir
RegKey6=HKCU\Software\Nico Mak Computing\WinZip\directories|zDefDir
RegKey7=HKCU\Software\Nico Mak Computing\WinZip\directories|AddDir
RegKey8=HKCU\Software\Nico Mak Computing\WinZip\directories|gzExtractTo
RegKey9=HKCU\Software\Nico Mak Computing\WinZip\rrs\Opened
[WinRAR]
ID=2089
LangSecRef=3024
Detect=HKCU\Software\WinRAR
Default=True
RegKey1=HKCU\Software\WinRAR\ArcHistory
RegKey2=HKCU\Software\WinRAR\General|LastFolder
RegKey3=HKCU\Software\WinRAR\DialogEditHistory\Arcname
RegKey4=HKCU\Software\WinRAR\DialogEditHistory\ExtrPath
[7-Zip]
ID=2090
LangSecRef=3024
Default=True
Detect=HKCU\Software\7-Zip\
RegKey1=HKCU\Software\7-Zip\Compression\ArcHistory
RegKey2=HKCU\Software\7-Zip\Extraction\PathHistory
RegKey3=HKCU\Software\7-Zip\FM|CopyHistory
RegKey4=HKCU\Software\7-Zip\FM|FolderHistory
RegKey5=HKCU\Software\7-Zip\FM|PanelPath0
RegKey6=HKCU\Software\7-Zip\Compression|ArcHistory
RegKey7=HKCU\Software\7-Zip\Extraction|PathHistory
[PowerArchiver]
ID=2091
LangSecRef=3024
Detect=HKCU\Software\PowerArchiver
Default=True
RegKey1=HKCU\Software\PowerArchiver\Files|Active_File1
RegKey2=HKCU\Software\PowerArchiver\Files|Active_File2
RegKey3=HKCU\Software\PowerArchiver\Files|Active_File3
RegKey4=HKCU\Software\PowerArchiver\Files|Active_File4
RegKey5=HKCU\Software\PowerArchiver\Files|Active_File5
RegKey6=HKCU\Software\PowerArchiver\Files|Extract1
RegKey7=HKCU\Software\PowerArchiver\Files|Extract2
RegKey8=HKCU\Software\PowerArchiver\Files|Extract3
RegKey9=HKCU\Software\PowerArchiver\Files|Extract4
RegKey10=HKCU\Software\PowerArchiver\Files|Extract5
RegKey11=HKCU\Software\PowerArchiver\Files|Last open dir
RegKey12=HKCU\Software\PowerArchiver\Files|Last backup dir
RegKey13=HKCU\Software\PowerArchiver\Files|Last add dir
[ZipMagic]
ID=2092
LangSecRef=3024
Default=True
Detect=HKCU\Software\Mijenix\ZipMagic
RegKey1=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Recent
RegKey2=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Archive Manager\UnZip To
RegKey3=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\UnZip To
RegKey4=HKCU\Software\Mijenix\ZipMagic\CurrentVersion\Zip To
[PicoZip]
ID=2093
LangSecRef=3024
Detect=HKCU\Software\PicoZip
Default=True
RegKey1=HKCU\Software\PicoZip\MRU Items
RegKey2=HKCU\Software\PicoZip\MRUExtract
[Sun Java]
ID=2094
LangSecRef=3022
Detect=HKLM\SOFTWARE\JavaSoft\Java Plug-in
Default=False
FileKey1=%appdata%\Sun\Java\Deployment\cache|*.*|RECURSE
FileKey2=%appdata%\Sun\Java\Deployment\javaws\cache|*.*|RECURSE
[FreshDownload]
ID=2095
LangSecRef=3022
Detect=HKCU\Software\FreshDevices\FreshDownload
Default=True
RegKey1=HKCU\Software\FreshDevices\FreshDownload\History
[Windows Movie Maker]
ID=2096
LangSecRef=3023
Detect=HKCU\Software\Microsoft\MovieMaker
Default=True
FileKey1=%localappdata%\Microsoft\Movie Maker|MEDIATAB0.DAT
[TextPad]
ID=2097
LangSecRef=3021
Detect=HKCU\Software\Helios\TextPad 4
Default=True
RegKey1=HKCU\Software\Helios\TextPad 4\Recent File List
RegKey2=HKCU\Software\Helios\TextPad 4\Recent Strings
[VirtualDub]
ID=2098
LangSecRef=3023
Default=True
Detect=HKCU\Software\Freeware\VirtualDub
RegKey1=HKCU\Software\Freeware\VirtualDub\MRU List
[RegEdit]
ID=2099
LangSecRef=3025
Default=True
RegKey1=HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit|LastKey
[Game Explorer]
ID=2174
LangSecRef=3025
DetectOS=6.0
DetectFile=%%LocalAppData%\Microsoft Games
DetectFile2=%LocalAppData%\Microsoft\Windows\GameExplorer
Default=False
FileKey1=%LocalAppData%\Microsoft Games|*.xml.bak|RECURSE
FileKey2=%LocalAppData%\Microsoft\Windows\GameExplorer\GameStatistics|*.*|REMOVESELF
[AceHTML 5]
ID=2100
LangSecRef=3024
Default=True
Detect=HKCU\Software\Visicom Media\AceHTML 5 Freeware
RegKey1=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last URLs
RegKey2=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Projects
RegKey3=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Open
RegKey4=HKCU\Software\Visicom Media\AceHTML 5 Freeware\Last Files
[Alcohol 120%]
ID=2101
LangSecRef=3024
Default=True
Detect=HKCU\Software\Alcohol Soft\Alcohol 120%
RegKey1=HKCU\Software\Alcohol Soft\Alcohol 120%\MountedMRU
[LeechGet]
ID=2102
LangSecRef=3022
Default=True
Detect=HKCU\Software\Cronosoft\LeechGet
RegKey1=HKCU\Software\Cronosoft\LeechGet\History
[GetRight]
ID=2103
LangSecRef=3022
Default=True
Detect=HKCU\Software\Headlight\GetRight\
RegKey1=HKCU\Software\Headlight\GetRight\MRU
RegKey2=HKCU\Software\Headlight\GetRight\TypedURLS
RegKey3=HKCU\Software\Headlight\GetRight\Recent File List
FileKey1=%ProgramFiles%\GetRight|GetRight.hst
[Download Accelerator Plus]
ID=2104
LangSecRef=3022
Detect=HKCU\Software\SpeedBit\Download Accelerator
Default=True
RegKey1=HKLM\SOFTWARE\SpeedBit\Download Accelerator\FileList
RegKey2=HKCU\Software\SpeedBit\Download Accelerator\HistoryCombo
RegKey3=HKCU\Software\SpeedBit\Download Accelerator\ADS\SecondMedia
FileKey1=%ProgramFiles%\DAP\Temp|*.*
FileKey2=%ProgramFiles%\DAP\Ads|*.*
FileKey3=%ProgramFiles%\DAP\Log|*.*
[Free Download Manager]
ID=2194
LangSecRef=3022
DetectFile=%ProgramFiles%\Free Download Manager\fdm.exe
DetectFile2=%AppData%\Free Download Manager
Default=True
RegKey1=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings|Find
RegKey2=HKCU\Software\FreeDownloadManager.ORG\Free Download Manager\Settings|History
FileKey1=%AppData%\Free Download Manager|*.bak
FileKey2=%AppData%\Free Download Manager|dlmgrsi.sav
FileKey3=%AppData%\Free Download Manager|downloads.his.sav
FileKey4=%AppData%\Free Download Manager|history.sav
FileKey5=%AppData%\Free Download Manager|spider.sav
[Internet Download Accelerator]
ID=2195
LangSecRef=3022
Detect=HKCU\Software\2VG\Internet Download Accelerator
DetectFile=%CommonAppData%\Speedbit\DAP
Default=True
FileKey1=%AppData%\Internet Download Accelerator|history.xml
FileKey2=%AppData%\Internet Download Accelerator\temp|*.hnt
FileKey3=%AppData%\Internet Download Accelerator\temp|lastnews.*
FileKey4=%AppData%\Internet Download Accelerator\temp|playflv.html
FileKey5=%AppData%\Internet Download Accelerator\temp\Preview|*.*
FileKey6=%AppData%\Internet Download Accelerator\lists|default.xml
FileKey7=%CommonAppData%\Speedbit\DAP\Log|*.*
FileKey8=%CommonAppData%\Speedbit\DAP\temp|*.tmp
FileKey9=%CommonAppData%\Speedbit\DAP\History|*.dat|RECURSE
[Internet Download Manager]
ID=2196
LangSecRef=3022
Detect=HKLM\Software\Internet Download Manager
Default=True
FileKey1=%AppData%\IDM|UrlHistory*.txt
[Orbit Downloader]
ID=2234
LangSecRef=3022
Detect=HKLM\SOFTWARE\Orbit
Default=True
FileKey1=%AppData%\Orbit|fileinfo.dat
FileKey2=%AppData%\Orbit|filesave.dat
[Morpheus]
ID=2105
LangSecRef=3022
Default=True
Detect=HKCU\Software\Morpheus
RegKey1=HKCU\Software\Morpheus\Morpheus\Recent File List
[VNCViewer 3]
ID=2106
LangSecRef=3024
Default=True
Detect=HKCU\Software\ORL\VNCviewer
RegKey1=HKCU\Software\ORL\VNCviewer\MRU
[VNCViewer 4]
ID=2107
LangSecRef=3024
Default=True
Detect=HKCU\Software\RealVNC\VNCviewer4
RegKey1=HKCU\Software\RealVNC\VNCviewer4\MRU
[DVD Shrink]
ID=2108
LangSecRef=3023
Default=True
Detect=HKCU\Software\DVD Shrink\
RegKey1=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent Targets
RegKey2=HKCU\Software\DVD Shrink\DVD Shrink 3.2\Recent File List
RegKey3=HKCU\Software\DVD Shrink\DVDSHRINK103\TargetFiles
RegKey4=HKCU\Software\DVD Shrink\DVDSHRINK103\SourceFolders
[Tivo Desktop]
ID=2109
LangSecRef=3023
Default=True
Detect=HKCU\SOFTWARE\TiVo\Desktop
FileKey1=%localappdata%\TiVo Desktop\Cache|*.*
[CA Anti-Virus]
ID=2110
LangSecRef=3024
Default=True
Detect=HKLM\SOFTWARE\ComputerAssociates\Anti-Virus
FileKey1=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|*.log
FileKey2=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus|*log.txt
FileKey3=%ProgramFiles%\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ArcTemp|*.tmp
FileKey4=%commonappdata%\CA\Consumer\AV|*.tmp|RECURSE
FileKey5=%commonappdata%\CA\Consumer\AV|*.txt|RECURSE
FileKey6=%commonappdata%\CA\Consumer\CCube|*.tmp|RECURSE
FileKey7=%commonappdata%\CA\Consumer\CCube|*.txt|RECURSE
FileKey8=%commonappdata%\CA\Consumer\ISS\FeedStore|*.txt|RECURSE
FileKey9=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\ArcTemp|*.*
FileKey10=%ProgramFiles%\CA\CA Internet Security Suite\CA Anti-Virus\tmp|*.*
[ZoneAlarm (Logs)]
ID=2111
LangSecRef=3022
Detect=HKLM\SOFTWARE\Zone Labs\ZoneAlarm
Default=True
FileKey1=%windir%\Internet Logs|ZALog*.*
[Google Earth]
ID=2112
LangSecRef=3021
Detect=HKLM\SOFTWARE\Google\Google Earth Plus
Detect2=HKLM\SOFTWARE\Google\Google Earth Pro
Detect3=HKCU\SOFTWARE\Google\Google Earth Plus
Detect4=HKCU\SOFTWARE\Google\Google Earth Pro
Default=True
FileKey1=%appdata%\Google\GoogleEarth|dbcache.dat
FileKey2=%appdata%\Google\GoogleEarth|dbcache.dat.index
FileKey3=%localappdata%\Google\GoogleEarth|dbcache.dat
FileKey4=%localappdata%\Google\GoogleEarth|dbcache.dat.index
FileKey5=%locallowappdata%\Google\GoogleEarth|dbcache.dat
FileKey6=%locallowappdata%\Google\GoogleEarth|dbcache.dat.index
RegKey1=HKCU\Software\Google\Google Earth Plus\Search
RegKey2=HKCU\Software\Google\Google Earth Pro\Search
[Microsoft AntiSpyware]
ID=2113
LangSecRef=3024
DetectFile=%ProgramFiles%\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
Default=True
FileKey1=%ProgramFiles%\Microsoft AntiSpyware|errors.log
FileKey2=%ProgramFiles%\Microsoft AntiSpyware|tracksEraser.log
FileKey3=%ProgramFiles%\Microsoft AntiSpyware|cleaner.log
[PerfectDisk 7.0]
ID=2114
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\7.0
Default=True
FileKey1=%commonappdata%\Raxco\PerfectDisk\7.0|PerfectDisk.log
[Daemon Tools]
ID=2187
LangSecRef=3024
Detect=HKCU\Software\DT Soft
DetectFile=%AppData%\DAEMON Tools Lite\
DetectFile2=%AppData%\DAEMON Tools Pro\
DetectFile3=%AppData%\DAEMON Tools\
Default=True
FileKey1=%AppData%\Daemon Tools lite\iconscache|*.*
FileKey2=%AppData%\DAEMON Tools Lite|imagecatalog.xml
FileKey3=%AppData%\DAEMON Tools|imagecatalog.xml
FileKey4=%AppData%\DAEMON Tools Pro|imagecatalog.xml
[Vuze]
ID=2115
LangSecRef=3022
Detect=HKCU\Software\Azureus
DetectFile=%appdata%\Azureus\.lock
Default=True
FileKey1=%appdata%\Azureus\logs|*.log
FileKey2=%appdata%\Azureus\logs\save|*.log
FileKey3=%appdata%\Azureus\tmp|*.*
FileKey4=%appdata%\Azureus|*.bak
FileKey5=%appdata%\Azureus|*.log
FileKey6=%appdata%\Azureus\active|*.bak
[BitTorrent]
ID=2173
LangSecRef=3022
Detect=HKCU\Software\BitTorrent
DetectFile=%ProgramFiles%\BitTorrent\BitTorrent.exe
Default=true
FileKey1=%appdata%\BitTorrent|*.old
[FrostWire]
ID=2215
LangSecRef=3022
DetectFile=%ProgramFiles%\FrostWire\FrostWire.exe
Default=True
FileKey1=%AppData%\FrostWire|*.cache
FileKey2=%AppData%\FrostWire\image_cache|*.*|REMOVESELF
FileKey3=%AppData%\FrostWire|gnutella.net
FileKey4=%AppData%\FrostWire|*.bak
FileKey5=%AppData%\FrostWire|checkandupdate.txt
[uTorrent]
ID=2216
LangSecRef=3022
DetectFile=%ProgramFiles%\uTorrent\uTorrent.exe
Default=True
FileKey1=%ProgramFiles%\uTorrent|*.dmp
FileKey2=%AppData%\utorrent|*.old
FileKey3=%AppData%\utorrent\dlimagecache|*.*|RECURSE
[Shareaza]
ID=2217
LangSecRef=3022
DetectFile=%ProgramFiles%\Shareaza Applications\Shareaza\Shareaza.exe
Default=True
FileKey1=%LocalAppData%\Shareaza\Temp|*.*
FileKey2=%LocalAppData%\Shareaza|shistory.im
FileKey3=%LocalAppData%\Shareaza\Artwork|*.*
[iMesh]
ID=2218
LangSecRef=3022
DetectFile=%ProgramFiles%\iMesh Applications\iMesh\iMesh.exe
Default=True
FileKey1=%LocalAppData%\iMesh\Temp|*.*
FileKey2=%LocalAppData%\iMesh|shistory.im
FileKey3=%LocalAppData%\iMesh\Artwork|*.*
[BearShare]
ID=2219
LangSecRef=3022
DetectFile=%ProgramFiles%\BearShare Applications\BearShare\BearShare.exe
Default=True
FileKey1=%LocalAppData%\BearShare\Temp|*.*
FileKey2=%LocalAppData%\BearShare|shistory.im
FileKey3=%LocalAppData%\BearShare\Artwork|*.*
[DC++]
ID=2220
LangSecRef=3022
DetectFile=%ProgramFiles%\DC++\DCPlusPlus.exe
Default=True
FileKey1=%ProgramFiles%\DC++|files.xml.bz2
FileKey2=%ProgramFiles%\DC++\FileLists|*.*
FileKey3=%ProgramFiles%\DC++\Logs|*.*
FileKey4=%LocalAppData%\DC++|files.xml.bz2
FileKey5=%LocalAppData%\DC++\FileLists|*.*
FileKey6=%LocalAppData%\DC++\Logs|*.*
[Ares]
ID=2221
LangSecRef=3022
DetectFile=%ProgramFiles%\Ares\Ares.exe
Default=True
Regkey1=HKCU\Software\Ares\Search.History
[CuteFTP Pro 7.0]
ID=2116
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Professional
Default=True
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\7.0\CacheThumbs|*.*|RECURSE
[CuteFTP Home 7.0]
ID=2117
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 7 Home
Default=True
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP\7.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP\7.0\CacheThumbs|*.*|RECURSE
[CuteFTP Pro 8.0]
ID=2118
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Professional
Default=True
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Pro\8.0\CacheThumbs|*.*|RECURSE
[CuteFTP Home 8.0]
ID=2119
LangSecRef=3022
Detect=HKLM\SOFTWARE\GlobalSCAPE\CuteFTP 8 Home
Default=True
RegKey1=HKCU\Software\GlobalSCAPE\CuteFTP 8 Home\Recent|LastSiteID
FileKey1=%localappdata%\GlobalSCAPE\CuteFTP Home\8.0\Cache|*.*|RECURSE
FileKey2=%localappdata%\GlobalSCAPE\CuteFTP Home\8.0\CacheThumbs|*.*|RECURSE
FileKey3=%AppData%\GlobalSCAPE\CuteFTP Home\8.0|*.log|RECURSE
[Core FTP]
ID=2226
LangSecRef=3022
Detect=HKCU\Software\FTPWare
Default=True
FileKey1=%AppData%\CoreFTP|*.dir
FileKey2=%ProgramFiles%\CoreFTP|COREFTP.LOG
[FileZilla]
ID=2227
LangSecRef=3022
Detect=HKLM\SOFTWARE\FileZilla Client
Detect2=HKCU\SOFTWARE\FileZilla Client
Default=True
FileKey1=%AppData%\FileZilla|recentservers.xml
FileKey2=%AppData%\FileZilla|search.xml
[SmartFTP]
ID=2228
LangSecRef=3022
Detect=HKCU\Software\SmartFTP
Default=True
RegKey1=HKCU\Software\SmartFTP\Client 2.0\Settings\History\Items
FileKey1=%AppData%\SmartFTP\Client 2.0\Log|*.*|RECURSE
FileKey2=%AppData%\SmartFTP\Client 2.0\Storage|*.*
[ClamWin]
ID=2120
LangSecRef=3024
Detect=HKCU\Software\ClamWin
Default=True
FileKey1=%allusersprofile%\.clamwin\log|*.*
FileKey2=%userprofile%\.clamwin\log|*.*
FileKey3=%windir%\All Users\.clamwin\log|*.*
[Ewido Anti-Malware (Log)]
ID=2121
LangSecRef=3024
Detect=HKLM\Software\ewido
Default=True
FileKey1=%ProgramFiles%\Ewido\Security Suite|logfile.txt
FileKey2=%ProgramFiles%\Ewido Anti-Malware|logfile.txt
[AVG Anti-Spyware]
ID=2122
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\AVGAntiSpyware
Default=True
FileKey1=%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5|logfile.txt
[Malwarebytes Anti Malware]
ID=2162
LangSecRef=3024
DetectFile=%ProgramFiles%\Malwarebytes' Anti-Malware\mbam.exe
Default=False
FileKey1=%appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Logs|*.txt
FileKey2=%appdata%\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine|*.*
[Spyware Terminator]
ID=2262
LangSecRef=3024
Detect=HKCU\Software\Spyware Terminator
Default=False
FileKey1=%ProgramFiles%\Spyware Terminator\update|*.*
FileKey2=%AppData%\Spyware Terminator\Reports|*.*
[SUPERAntiSpyware]
ID=2263
LangSecRef=3024
Detect=HKLM\Software\SUPERAntiSpyware.com\SUPERAntiSpyware
Default=True
FileKey1=%AppData%\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs|*.log
FileKey2=%AppData%\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs|*.dmp
FileKey3=%AppData%\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs|*.SDB
[A-Squared]
ID=2229
LangSecRef=3024
Detect=HKLM\Software\Emsi Software GmbH\a-squared Free
Default=True
FileKey1=%MyDocuments%\a-squared Free\Reports|*.txt
[Foxit Reader]
ID=2123
LangSecRef=3021
Detect=HKCU\Software\Foxit Software\Foxit Reader
Default=True
RegKey1=HKCU\Software\Foxit Software\Foxit Reader\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit Reader\History
[Paint.NET]
ID=2124
LangSecRef=3021
Detect=HKCU\Software\Paint.NET
Default=True
RegKey1=HKCU\Software\Paint.NET|MRU0
RegKey2=HKCU\Software\Paint.NET|MRU1
RegKey3=HKCU\Software\Paint.NET|MRU2
RegKey4=HKCU\Software\Paint.NET|MRU3
RegKey5=HKCU\Software\Paint.NET|MRU4
RegKey6=HKCU\Software\Paint.NET|MRU5
RegKey7=HKCU\Software\Paint.NET|MRU6
RegKey8=HKCU\Software\Paint.NET|MRU7
RegKey9=HKCU\Software\Paint.NET|MRU0Thumb
RegKey10=HKCU\Software\Paint.NET|MRU1Thumb
RegKey11=HKCU\Software\Paint.NET|MRU2Thumb
RegKey12=HKCU\Software\Paint.NET|MRU3Thumb
RegKey13=HKCU\Software\Paint.NET|MRU4Thumb
RegKey14=HKCU\Software\Paint.NET|MRU5Thumb
RegKey15=HKCU\Software\Paint.NET|MRU6Thumb
RegKey16=HKCU\Software\Paint.NET|MRU7Thumb
[OpenOffice 1.14]
ID=2125
LangSecRef=3021
DetectFile=%ProgramFiles%\OpenOffice.org1.1.4\program\soffice.exe
Default=True
FileKey1=%ProgramFiles%\OpenOffice.org1.1.4\user\registry\data\org\openoffice\Office|Common.xcu
[OpenOffice 2.0]
ID=2126
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.0
Default=True
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu
[OpenOffice 2.1]
ID=2127
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\2.1
Default=True
FileKey1=%appdata%\OpenOffice.org2\user\registry\data\org\openoffice\Office|Common.xcu
[OpenOffice 3]
ID=2143
LangSecRef=3021
Detect=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.0
Detect2=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.1
Detect3=HKLM\SOFTWARE\OpenOffice.org\OpenOffice.org\3.2
Detect4=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.0
Detect5=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.1
Detect6=HKCU\SOFTWARE\OpenOffice.org\OpenOffice.org\3.2
Default=True
FileKey1=%appdata%\OpenOffice.org\3\user\registry\data\org\openoffice\Office|Histories.xcu
[Grisoft AVG 7.0]
ID=2128
LangSecRef=3024
Detect=HKLM\SOFTWARE\Grisoft\Avg7
Default=True
FileKey1=%commonappdata%\Grisoft\Avg7Data|*.log
FileKey2=%commonappdata%\Grisoft\Avg7Data\upd7bin|*.*
FileKey3=%commonappdata%\Grisoft\Avg7Data\$history|*.*
FileKey4=%commonappdata%\Grisoft\Avg7Data\avg7upd|*.log
FileKey5=%windir%\All Users\Application Data\Grisoft\Avg7Data\upd7bin|*.*
FileKey6=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|$history
FileKey7=%windir%\All Users\Application Data\Grisoft\Avg7Data\avg7upd|*.log
FileKey8=%windir%\All Users\Application Data\Grisoft\Avg7Data|*.log
FileKey9=%windir%\Application Data\AVG7\Log|*.log
[AVG AntiVirus 8.0]
ID=2141
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg8
Default=True
FileKey1=%CommonAppData%\avg8\Log|*.log
FileKey2=%CommonAppData%\avg8\scanlogs|*.log
FileKey3=%CommonAppData%\avg8\Log|*.xml
FileKey4=%CommonAppData%\avg8\update\backup|*.*
FileKey5=%CommonAppData%\avg8\Emc\Log|*.log
[AVG AntiVirus 9.0]
ID=2145
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg9
Default=True
FileKey1=%CommonAppData%\avg9\Log|*.log
FileKey2=%CommonAppData%\avg9\scanlogs|*.log
FileKey3=%CommonAppData%\avg9\Log|*.xml
FileKey4=%CommonAppData%\avg9\update\backup|*.*
FileKey5=%CommonAppData%\avg9\Emc\Log|*.log
[AVG AntiVirus 10.0]
ID=2170
LangSecRef=3024
Detect=HKLM\SOFTWARE\AVG\Avg10
Default=True
FileKey1=%CommonAppData%\avg10\Log|*.log
FileKey2=%CommonAppData%\avg10\scanlogs|*.log
FileKey3=%CommonAppData%\avg10\Log|*.xml
FileKey4=%CommonAppData%\avg10\update\backup|*.*
FileKey5=%CommonAppData%\avg10\Emc\Log|*.log
FileKey6=%CommonAppData%\avg10\IDS\config|*List.zip.bak
FileKey7=%CommonAppData%\avg10\IDS\profile|globalLoadable.bak
FileKey8=%CommonAppData%\avg10\Temp|*.tmp
[AntiVir Desktop]
ID=2138
LangSecRef=3024
Detect=HKLM\SOFTWARE\Avira\AntiVir Desktop
Default=True
FileKey1=%CommonAppData%\Avira\AntiVir Desktop\TEMP|*.*
FileKey2=%CommonAppData%\Avira\Antivir Desktop\BACKUP\FAILSAFE\*.tmp
FileKey3=%CommonAppData%\Avira\AntiVir Desktop|*.old
FileKey4=%CommonAppData%\Avira\AntiVir Desktop|*.tmp
FileKey5=%ProgramFiles%\Avira\AntiVir Desktop|*.old
FileKey6=%ProgramFiles%\Avira\AntiVir Desktop|*.tmp
FileKey7=%ProgramFiles%\Avira\AntiVir Desktop\FAILSAFE|*.tmp
[Avast! Antivirus 4]
ID=2160
LangSecRef=3024
Detect=HKCU\Software\ALWIL Software\Avast\4.0
Default=True
FileKey1=%ProgramFiles%\Alwil Software\Avast4\DATA\report|avast.xsl;Resident protection.txt;Simple user interface.txt;Simple user interface*.xml
FileKey2=%ProgramFiles%\Alwil Software\Avast4\DATA\log|*.*
[Avast! Antivirus 5]
ID=2161
LangSecRef=3024
Detect=HKCU\Software\ALWIL Software\Avast\5.0
Default=True
FileKey1=%ProgramData%\Alwil Software\Avast5\report|avast.xsl;avast.xsl;Resident protection.txt;Simple user interface.txt;Simple user interface*.xml
FileKey2=%ProgramData%\Alwil Software\Avast5\log|*.*
[TUGZip]
ID=2131
LangSecRef=3024
Detect=HKCU\Software\TUGZip
Default=True
RegKey1=HKCU\Software\TUGZip|mainRecent
RegKey2=HKCU\Software\TUGZip|extrRecent
RegKey3=HKCU\Software\TUGZip|cmpWorkingDir
[Windows Defender]
ID=2132
LangSecRef=3024
Detect=HKLM\SOFTWARE\Microsoft\Windows Defender
Default=True
FileKey1=%commonappdata%\Microsoft\Windows Defender\Scans\History\Results\Quick|*.*
FileKey2=%commonappdata%\Microsoft\Windows Defender\Scans\History\Results\Resource|*.*
FileKey3=%CommonAppData%\Microsoft\Windows Defender\Support|*.log
[IZArc]
ID=2133
LangSecRef=3024
Detect=HKCU\Software\IZSoftware\IZArc
Default=True
RegKey1=HKCU\Software\IZSoftware\IZArc|AppCurrentDir
RegKey2=HKCU\Software\IZSoftware\IZArc\Recent
RegKey3=HKCU\Software\IZSoftware\IZArc\History
[Google Toolbar Firefox]
ID=2134
LangSecRef=3022
Default=True
SpecialDetect=DET_MOZILLA_GOOGLE_TOOLBAR
SpecialKey1=N_MOZ_GOOGLE_TOOLBAR
[MS Search Helper Extension]
ID=2191
LangSecRef=3021
DetectFile=%ProgramFiles%\Microsoft\Search Enhancement Pack\Search Helper
Default=True
FileKey1=%LocalAppData%\Microsoft\Search Enhancement Pack\Search Box Extension|searchhs.dat
FileKey2=%LocalLowAppData%\Microsoft\Search Enhancement Pack\Search Box Extension|searchhs.dat
[MS Office Picture Manager]
ID=2135
LangSecRef=3021
Detect=HKCU\Software\Microsoft\Office
Default=True
FileKey1=%LocalAppData%\Microsoft\OIS|OIScatalog.cag
FileKey2=%LocalAppData%\Microsoft\OIS\thumbnails|*.*
[ImgBurn]
ID=2136
LangSecRef=3021
Detect=HKCU\Software\ImgBurn
DetectFile=%ProgramFiles%\Imgburn\imgburn.exe
Default=False
RegKey1=HKCU\Software\ImgBurn|ISOBUILD_MRUBootImage
RegKey2=HKCU\Software\ImgBurn|ISOBUILD_MRUDeviceName
RegKey3=HKCU\Software\ImgBurn|ISOBUILD_MRUSourceFile
RegKey4=HKCU\Software\ImgBurn|ISOBUILD_MRUSourceFolder
RegKey5=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Destination
RegKey6=HKCU\Software\ImgBurn|ISOBUILD_RecentFiles_Source
RegKey7=HKCU\Software\ImgBurn|ISOBUILD_RecentFolders_Destination
RegKey8=HKCU\Software\ImgBurn|ISOWRITE_MRUDeviceName
RegKey9=HKCU\Software\ImgBurn|ISOWRITE_RecentFiles_Source
FileKey1=%AppData%\ImgBurn|ImgBurn.log
FileKey2=%AppData%\ImgBurn\IBG Files|*.*
FileKey3=%AppData%\imgburn\graph data files|*.*
FileKey4=%AppData%\imgburn\Log Files|*.*
[CloneCD]
ID=2177
LangSecRef=3021
Detect=HKLM\Software\SlySoft\CloneCD
Default=False
RegKey1=HKCU\Software\SlySoft\CloneCD\Settings|ImageFileName
[WinPatrol]
ID=2168
LangSecRef=3024
Detect=HKCU\Software\BillP Studios\WinPatrol
Default=True
FileKey1=%ProgramFiles%\BillP Studios\WinPatrol|WinPatrolLog.*
FileKey2=%SystemDrive%|HijackPatrol.log
[LogMeIn Hamachi]
ID=2172
LangSecRef=3022
Detect=HKCU\Software\LogMeIn
Default=True
FileKey1=%LocalAppData%\LogMeIn Hamachi|*.log
FileKey2=%LocalAppData%\LogMeIn Hamachi|*.old
FileKey3=%LocalAppData%\LogMeIn Hamachi|*.bak
[Ashampoo Burning Studio 10]
ID=2178
LangSecRef=3024
Detect=HKCU\Software\Ashampoo\Ashampoo Burning Studio 10
Default=False
FileKey1=%AppData%\Ashampoo\Ashampoo Burning Studio 10|backupmetainfo.xml
FileKey2=%AppData%\Ashampoo\Ashampoo Burning Studio 10\Log|*.xml
FileKey3=%AppData%\Ashampoo\Log|*.txt
[ExamDiff]
ID=2179
LangSecRef=3024
Detect=HKCU\Software\PrestoSoft\ExamDiff
Default=False
RegKey1=HKCU\Software\PrestoSoft\ExamDiff\AutoPick
RegKey2=HKCU\Software\PrestoSoft\ExamDiff\Recent Find Strings
RegKey3=HKCU\Software\PrestoSoft\ExamDiff\Recent Left Files
RegKey4=HKCU\Software\PrestoSoft\ExamDiff\Recent Right Files
RegKey5=HKCU\Software\PrestoSoft\ExamDiff\Settings|File 1
RegKey6=HKCU\Software\PrestoSoft\ExamDiff\Settings|File 2
[ExamDiff Pro]
ID=2180
LangSecRef=3024
Detect=HKCU\Software\PrestoSoft\ExamDiff Pro
Default=False
RegKey1=HKCU\Software\PrestoSoft\ExamDiff Pro\AutoPick
RegKey2=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Find Strings Bin
RegKey3=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Left Directories
RegKey4=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Left Files
RegKey5=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Right Directories
RegKey6=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Right Files
RegKey7=HKCU\Software\PrestoSoft\ExamDiff Pro\Recent Session Files
RegKey8=HKCU\Software\PrestoSoft\ExamDiff Pro\Settings|File 1
RegKey9=HKCU\Software\PrestoSoft\ExamDiff Pro\Settings|File 2
[Compare It!]
ID=2188
LangSecRef=3024
Detect=HKCU\Software\grigsoft.com\Compare It!
Default=False
RegKey1=HKCU\Software\grigsoft.com\Compare It!\Combos
RegKey2=HKCU\Software\grigsoft.com\Compare It!\dirs
RegKey3=HKCU\Software\grigsoft.com\Compare It!\options|Recent0
RegKey4=HKCU\Software\grigsoft.com\Compare It!\options|Recent1
RegKey5=HKCU\Software\grigsoft.com\Compare It!\options|Recent2
RegKey6=HKCU\Software\grigsoft.com\Compare It!\options|Recent3
RegKey7=HKCU\Software\grigsoft.com\Compare It!\options|Recent4
RegKey8=HKCU\Software\grigsoft.com\Compare It!\options|Recent5
RegKey9=HKCU\Software\grigsoft.com\Compare It!\options|Recent6
RegKey10=HKCU\Software\grigsoft.com\Compare It!\options|Recent7
RegKey11=HKCU\Software\grigsoft.com\Compare It!\options|Recent8
RegKey12=HKCU\Software\grigsoft.com\Compare It!\options|Recent9
RegKey13=HKCU\Software\grigsoft.com\Compare It!\options|Recent10
[WinDiff]
ID=2198
LangSecRef=3024
Detect=HKCU\Software\Microsoft\Windiff
Default=True
RegKey1=HKCU\Software\Microsoft\Windiff|NameLeft
RegKey2=HKCU\Software\Microsoft\Windiff|NameRight
[FeedDemon]
ID=2193
LangSecRef=3022
Detect=HKCU\Software\Bradbury\FeedDemon\1.0
DetectFile=%LocalAppData%\FeedDemon\v1
Default=True
RegKey1=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TypedURLs
RegKey2=HKCU\Software\Bradbury\FeedDemon\1.0\SavedLists\TabbedBrowserUrls
RegKey3=HKCU\Software\Bradbury\FeedDemon\1.0\SearchFeedKeywords
[Last.FM]
ID=2200
LangSecRef=3023
DetectFile=%ProgramFiles%\Last.fm\LastFM.exe
Default=True
FileKey1=%LocalAppData%\Last.fm\client\cache|*.*
FileKey2=%LocalAppData%\Last.fm\client|*.log
[Pando]
ID=2235
LangSecRef=3021
DetectFile=%LocalAppData%\Pando\Pando Files
Default=True
FileKey1=%LocalAppData%\Pando\Pando Files|*.log
[Sandboxie]
ID=2236
LangSecRef=3024
DetectFile=%ProgramFiles%\Sandboxie\Start.exe
Default=False
FileKey1=%SystemDrive%\Sandbox\%UserName%|*.*|RECURSE
ExcludeKey1=FILE|%SystemDrive%\Sandbox\%UserName%\DONT-USE.TXT
ExcludeKey2=FILE|%SystemDrive%\Sandbox\%UserName%\desktop.ini
[Snagit 9]
ID=2237
LangSecRef=3024
Detect=HKCU\Software\TechSmith\SnagIt\9
Default=True
RegKey1=HKCU\Software\TechSmith\SnagIt\9\Recent Captures
RegKey2=HKCU\Software\TechSmith\SnagIt\9\SnagItEditor\Recent File List
FileKey1=%LocalAppData%\TechSmith\SnagIt|Tray.bin
[Snagit 10]
ID=2238
LangSecRef=3024
Detect=HKCU\Software\TechSmith\SnagIt\10
Default=True
RegKey1=HKCU\Software\TechSmith\SnagIt\10\Recent Captures
RegKey2=HKCU\Software\TechSmith\SnagIt\10\SnagItEditor\Recent File List
FileKey1=%LocalAppData%\TechSmith\SnagIt|Tray.bin
[Ditto]
ID=2239
LangSecRef=3021
DetectFile=%AppData%\Ditto
Default=False
FileKey1=%AppData%\Ditto|ditto.db
[Evernote]
ID=2240
LangSecRef=3021
Detect=HKCU\Software\Evernote
Default=True
FileKey1=%LocalAppData%\Evernote\Evernote\Logs|*.*
[I2P]
ID=2241
LangSecRef=3022
DetectFile=%AppData%\I2P
Default=True
FileKey1=%AppData%\I2P\logs|*.*
[McAfee AntiVirus]
ID=2242
LangSecRef=3021
DetectFile=%CommonAppData%\McAfee\MCLOGS
Default=True
FileKey1=%CommonAppData%\McAfee\MCLOGS|*.log|RECURSE
[MS AntiMalware]
ID=2243
LangSecRef=3025
DetectFile=%CommonAppData%\Microsoft\Microsoft antimalware
Default=True
FileKey1=%CommonAppData%\Microsoft\Microsoft antimalware\support|*.log
FileKey2=%CommonAppDAta%\Microsoft\Microsoft antimalware\network inspection system\Support|*.log
FileKey3=%CommonAppData%\Microsoft\Microsoft antimalware\scans\history\results\Quick|*.*|REMOVESELF
FileKey4=%CommonAppData%\Microsoft\Microsoft antimalware\scans\history\results\System|*.*|REMOVESELF
FileKey5=%CommonAppData%\Microsoft\Microsoft antimalware\scans\history\results\resource|*.*|REMOVESELF
[PerfectDisk 8]
ID=2244
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\8.0
Default=True
FileKey1=%CommonAppData%\Raxco\PerfectDisk\8.0|PDBootLog
[PerfectDisk 9]
ID=2245
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\9.0
Default=True
FileKey1=%CommonAppData%\Raxco\PerfectDisk\9.0|PDBootLog
[PerfectDisk 10]
ID=2246
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\10.0
Default=True
FileKey1=%CommonAppData%\Raxco\PerfectDisk\10.0|PDBootLog
[PerfectDisk 11]
ID=2247
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\11.0
Default=True
FileKey1=%CommonAppData%\Raxco\PerfectDisk\11.0|PDBootLog
[PerfectDisk 12]
ID=2248
LangSecRef=3024
Detect=HKCU\Software\Raxco\PerfectDisk\12.0
Default=True
FileKey1=%CommonAppData%\Raxco\PerfectDisk\12.0|PDBootLog
[PowerISO]
ID=2249
LangSecRef=3024
Detect=HKCU\Software\PowerISO
Default=True
RegKey1=HKCU\Software\PowerISO|Reopen0
RegKey2=HKCU\Software\PowerISO|Reopen1
RegKey3=HKCU\Software\PowerISO|Reopen2
RegKey4=HKCU\Software\PowerISO|Reopen3
RegKey5=HKCU\Software\PowerISO|ExtractPath0
RegKey6=HKCU\Software\PowerISO|ExtractPath1
RegKey7=HKCU\Software\PowerISO|ExtractPath2
RegKey8=HKCU\Software\PowerISO|ExtractPath3
RegKey9=HKCU\Software\PowerISO|ExtractPath4
RegKey10=HKCU\Software\PowerISO|ExtractPath5
RegKey11=HKCU\Software\PowerISO|ExtractPath6
RegKey12=HKCU\Software\PowerISO|ExtractPath7
[UltraISO]
ID=2250
LangSecRef=3024
Detect=HKCU\Software\EasyBoot Systems\UltraISO\5.0
Default=True
RegKey1=HKCU\Software\EasyBoot Systems\UltraISO\5.0|Reopen
RegKey2=HKCU\Software\EasyBoot Systems\UltraISO\5.0|a
RegKey3=HKCU\Software\EasyBoot Systems\UltraISO\5.0|b
RegKey4=HKCU\Software\EasyBoot Systems\UltraISO\5.0|c
RegKey5=HKCU\Software\EasyBoot Systems\UltraISO\5.0|d
RegKey6=HKCU\Software\EasyBoot Systems\UltraISO\5.0|e
RegKey7=HKCU\Software\EasyBoot Systems\UltraISO\5.0|f
RegKey8=HKCU\Software\EasyBoot Systems\UltraISO\5.0|g
RegKey9=HKCU\Software\EasyBoot Systems\UltraISO\5.0|h
RegKey10=HKCU\Software\EasyBoot Systems\UltraISO\5.0|i
[GIMP 2.4]
ID=2251
LangSecRef=3021
DetectFile=%UserProfile%\.gimp-2.4
Default=True
FileKey1=%UserProfile%\.thumbnails\normal|*.*
FileKey2=%UserProfile%\.gimp-2.4|documents
[GIMP 2.6]
ID=2252
LangSecRef=3021
Default=True
DetectFile=%UserProfile%\.gimp-2.6
FileKey1=%UserProfile%\.thumbnails\normal|*.*
[Go!Zilla]
ID=2253
LangSecRef=3022
DetectFile=%AppData%\Go!Zilla
Default=True
FileKey1=%AppData%\Go!Zilla|GoZilla.hst
[MagicISO]
ID=2254
LangSecRef=3024
Detect=HKCU\Software\MagicISO
Default=True
RegKey1=HKCU\Software\MagicISO\Reopen
[Zune]
ID=2255
LangSecRef=3023
DetectFile=%LocalAppData%\Microsoft\zune
Default=True
FileKey1=%LocalAppData%\Microsoft\zune\art cache|*.*|REMOVESELF
FileKey2=%LocalAppData%\Microsoft\Zune|NowPlaying.dat
[BreezeBrowser Pro]
ID=2256
LangSecRef=3021
Detect=HKCU\Software\BreezeSystems\BreezeBrowserPro
Default=True
RegKey1=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU0
RegKey2=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU1
RegKey3=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU2
RegKey4=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU3
RegKey5=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU4
RegKey6=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU5
RegKey7=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU6
RegKey8=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU7
RegKey9=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU8
RegKey10=HKCU\Software\BreezeSystems\BreezeBrowserPro\100|MRU9
[FastStone Image Viewer]
ID=2257
LangSecRef=3023
DetectFile=%AppData%\FastStone\FSIV
Default=True
FileKey1=%AppData%\FastStone\FSIV|HisFolderList.db
[Notepad++]
ID=2258
LangSecRef=3021
DetectFile=%AppData%\notepad++
Default=False
FileKey1=%AppData%\notepad++|session.xml
[NoteXpad]
ID=2259
LangSecRef=3021
Detect=HKLM\Software\NoteXpad
Default=False
RegKey1=HKLM\Software\NoteXpad\Recent
[RegEditX]
ID=2260
LangSecRef=3024
Detect=HKLM\SOFTWARE\DCSoft\RegEditX
Default=True
FileKey1=%ProgramFiles%\DCSoft\RegEditX\x86|RegEditX.sav
FileKey2=%ProgramFiles%\DCSoft\RegEditX\x64|RegEditX.sav
FileKey3=%ProgramFiles%\DCSoft\RegEditX\x86|RegEditX.bak
FileKey4=%ProgramFiles%\DCSoft\RegEditX\x64|RegEditX.bak
[Foxit Reader 5.0]
ID=2265
LangSecRef=3021
Detect=HKCU\Software\Foxit Software\Foxit Reader 5.0
Default=True
RegKey1=HKCU\Software\Foxit Software\Foxit Reader 5.0\Recent File List
RegKey2=HKCU\Software\Foxit Software\Foxit Reader 5.0\RecentFiles
RegKey3=HKCU\Software\Foxit Software\Foxit Reader 5.0\Preferences\History\LastOpen
RegKey4=HKCU\Software\Foxit Software\Foxit Reader 5.0\Preferences\History\LastSession
RegKey5=HKCU\Software\Foxit Software\Foxit Reader 5.0\Preferences\Others|csInitialOpenDir