mickey58 commited on
Commit
df528bc
·
verified ·
1 Parent(s): b8f1f48

Upload 3 files

Browse files
Files changed (1) hide show
  1. HMGC DIrect FF.txt +1030 -0
HMGC DIrect FF.txt ADDED
@@ -0,0 +1,1030 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ HMGC DIrect FF
2
+
3
+ //=========================================================================
4
+ // FILE: DIRCTRL.DAT
5
+ // APPLIES TO: Windows
6
+ //
7
+ // This file has three sections used for controlling various aspects
8
+ // of DG with regards to directories.
9
+ //
10
+ // SECTION AFE
11
+ // -----------
12
+ // Each line consists of a directory specification, using DOS style
13
+ // wildcards (*,?), that will be excluded from the encryption engine.
14
+ //
15
+ // SECTION SCAN
16
+ // ------------
17
+ // Each line consists of a directory or directory pattern, using DOS style
18
+ // wildcards (*,?), that will be included or excluded from scanning.
19
+ // If no wildcard is used at the beginning of the directory then the directory
20
+ // should start with a UNC "\\" specifier or a drive letter.
21
+ //
22
+ // SECTION ACI
23
+ // -----------
24
+ // Eache line consists of a directory to exclude from ACI.
25
+ // (Currently no wildcards)
26
+ //
27
+ // All comments begin with '//', and blank lines and whitespace are
28
+ // ignored. Exception: whitespace within a directory name.
29
+ //
30
+ //(Version 7.7)
31
+ //=========================================================================
32
+ //
33
+
34
+
35
+ //=========================================================================
36
+ // AFE SECTION
37
+ //
38
+ // Changes by Naren::
39
+ // PATTERN EXPECTED PATH
40
+ //
41
+ // V16
42
+ // *PROGRA* C:\Program files\*
43
+ // *DOCUME*\APPLIC*; C:\Documents and Settings\ANY USER\APPLICATION DATA
44
+ // *DOCUME*\LOCAL* C:\Documents and Settings\ANY USER\Local Settings
45
+ // *DOCUME*\USERD* C:\Documents and Settings\ANY USER\USERDATA
46
+ // *DOCUME*\WINDO* C:\Documents and Settings\ANY USER\WINDOWS
47
+ // *DOCUME*\COOKIE* C:\Documents and Settings\ANY USER\COOKIES
48
+ // *DOCUME*\TEMPLA* C:\Documents and Settings\ANY USER\TEMPLATES
49
+ // *DOCUME*\NETWO* C:\Documents and Settings\NetworkService
50
+ // *DOCUME*\SENDTO* C:\Documents and Settings\ANY USER\SENDTO (avoid *.desklink, *.mapimail, *compressed folder*)
51
+ // *SYSTEM* C:\SYSTEM VOLUME INFORMATION\ (Used for SYSTEM RESTORE)
52
+ // C:\SYSTEM.SAV\ (HP Laptop)
53
+ // *INETPUB\* C:\INETPUB\ (used by IIS)
54
+ // *CONFIG.MS* C:\CONFIG.MSI (used by windows update)
55
+
56
+ // For specific customers
57
+
58
+ // For specific machines
59
+ // *DELL\* C:\DELL (when dell machine is used)
60
+ // *DRIVERS\* C:\DRIVERS (IBM Thinkpad drivers)
61
+ // *SWSHARE\* C:\SWSHARE (IBM Thinkpad)
62
+ // *SWSETUP\* C:\SWSETUP (HP laptop)
63
+ // *SYSTEM* C:\SYSTEM.SAV\ (HP Laptop)
64
+ // *IBMTOOLS\* C:\IBMTOOLS\
65
+
66
+ // FOR Specific apps
67
+ // *CL32V* C:\CL32V (when Novell Ver X is used)
68
+ // *DGAGENT* Agent Directory (Agent may be outside Program files)
69
+ // *MSOCAC* C:\MSOCACHE\
70
+ // *LOTUS\* C:\LOTUS\
71
+
72
+ // Filed based should be added to registry through PENDING_UPDATE
73
+ // *NTUSER.* C:\Documents and Settings\ANY USER\NTUSER.* and C:\Documents and Settings\NTUSER.DAT (file)
74
+ // *.??_ Files compressed using CAB
75
+ //
76
+ // *.EXE*;*.DLL*;*.SYS*;*.COM*;*.LNK*;*NTUSER*.*;*NTLDR*;*BOOT.INI*;*.??_
77
+ // *.UTX*;*.XTU*;*.INI*;*.JAR*;*.LSL*;*.FON*;*.DAT* All Lotus Notes file exclusions
78
+ //
79
+ // Full string:
80
+ // *.EXE*;*.DLL*;*.SYS*;*.COM*;*.LNK*;*.UTX*;*.XTU*;*.INI*;*.JAR*;*.LSL*;*.FON*;*.DAT*;*NTUSER*.*;*NTLDR*;*BOOT.INI*;*.??_
81
+ //
82
+
83
+ // Full string:
84
+ // *PROGRA*;*DOCUME*\APPLIC*;*DOCUME*\LOCAL*;*DOCUME*\USERDA*;*DOCUME*\WINDO*;*DOCUME*\COOKIE*;*DOCUME*\TEMPL*;*DOCUME*\NETWO*;*DOCUME*\SENDTO*;*INETPUB\*;*SYSTEM*;*CONFIG.MS*;*DELL\*;*DRIVERS\*;*SWSHARE\*;*SWSETUP\*;*IBMTOOLS\*;*DGAGENT\*;*CL32V*;*MSOCAC*;*LOTUS\*
85
+ //=========================================================================
86
+
87
+ //=========================================================================
88
+ // SECTION AFE IS USED ONLY BY PRE-5.2 AGENTS!
89
+ //=========================================================================
90
+ SECTION AFE:
91
+ *PROGRA*\*;*DOCUME*\APPLIC*\*;*DOCUME*\LOCAL*\*;*DOCUME*\USERDA*\*;*DOCUME*\WINDO*\*
92
+ *DOCUME*\COOKIE*\*;*DOCUME*\TEMPL*\*;*DOCUME*\NETWO*\*;*DOCUME*\SENDTO*\*
93
+ *INETPUB\*;*SYSTEM*\*;*CONFIG.MS*
94
+ *DELL\*;*DRIVERS\*;*SWSHARE\*;*SWSETUP\*;*IBMTOOLS\*
95
+ *DGAGENT\*;*CL32V*;*MSOCAC*\*;*LOTUS\*
96
+ *DOCUME*\ALL*\NTUSER*\*
97
+ <java home>
98
+ SECTION END:
99
+
100
+ //=========================================================================
101
+ // SCANNER SECTION - directories to include or exclude from scanning
102
+ //=========================================================================
103
+ SECTION ADJUST SCAN:
104
+ INCLUDE:
105
+ END:
106
+ EXCLUDE:
107
+ *.PST
108
+ *.PST.TMP
109
+ *.OST
110
+ END:
111
+ SECTION END:
112
+
113
+ //=========================================================================
114
+ // AFE Directory Exclusions - These directories will be ignored by AFE in NON-FDE mode
115
+ //=========================================================================
116
+ AFE DIR EXCLUSIONS:
117
+
118
+ // Entire System root is now excluded
119
+ %SystemRoot%\*
120
+
121
+ // Program files
122
+ ?:\PROGRA*\*;
123
+
124
+ <user profile>*\COOKIE*\*;
125
+ <user profile>*\TEMPL*\*;
126
+ <user profile>*\NETWO*\*;
127
+ <user profile>*\SENDTO*\*
128
+ <user profile>*\ALL*\NTUSER*\*
129
+
130
+ ?:\INETPUB\*;
131
+ ?:\*CONFIG.MS*
132
+ ?:\*DELL\*;
133
+ ?:\*SWSETUP\*;
134
+ ?:\*IBMTOOLS\*
135
+ ?:\*DGAGENT\*;
136
+ ?:\*CL32V*;
137
+ ?:\*MSOCAC*\*;
138
+ ?:\*LOTUS\*
139
+ ?:\SWSHARE\*
140
+
141
+ // Java directory
142
+ <java home>\*
143
+
144
+ // OPTIONAL - System Restore and System Drive-State functions temp files. Removal could
145
+ // cause performance issues. Highly recommend keeping.
146
+ ?:\System Volume Information\*
147
+ ?:\SYSTEM~1*\*
148
+
149
+ // OPTIONAL - Symantec AV working locations
150
+ ?:\Progra*\Symant*\*
151
+ ?:\Progra*\Common*\Symant*\*
152
+ %ALLUSERSPROFILE%\App*\Symant*\*
153
+
154
+ SECTION END:
155
+
156
+ //=========================================================================
157
+ // AFE File Exclusions - these files will not be encrypted in NON-FDE mode
158
+ //=========================================================================
159
+ AFE FILE EXCLUSIONS:
160
+ *.EXE;*.DLL;*.SYS;*.COM;*.LNK;*.UTX;*.XTU;*.INI;*.JAR;*.LSL;*.FON;*.DAT;
161
+
162
+ // REQUIRED Windows Boot sequence & Registry
163
+ %SystemDrive%\*NTUSER*.*;
164
+ %SystemDrive%\IO.SYS
165
+ %SystemDrive%\MSDOS.SYS
166
+ %SystemDrive%\boot.ini
167
+ %SystemDrive%\ntldr
168
+ %SystemDrive%\autoexec.bat
169
+ ?:\pagefile.sys
170
+ ?:\hiberfil.sys
171
+ ?:\*.??_
172
+
173
+
174
+ // REQUIRED Windows Recycle Bin
175
+ ?:\RECYCLE*\*\INFO2
176
+
177
+ // REQUIRED DG Agent temp files during uninstall via Add/Remove Programs
178
+ <user profile>\*\APPLIC*\*\DGAgen*.*
179
+ <user profile>\*\APPLIC*\{*\instance.dat
180
+
181
+ // REQUIRED - Windows New User Creation and Roaming Profile Temp Files
182
+ ?:\*\PRF*.tmp
183
+
184
+ // OPTIONAL - example to avoid PerfectDisk conflict
185
+ ?:\Perfec*\Perfec*.adm
186
+ ?:\Perfec*\PDHelpEN.chm
187
+ ?:\Perfec*\Config.ini
188
+ ?:\Perfec*\Upd.ini
189
+ ?:\Perfec*\PDAgen*.mof
190
+
191
+ // OPTIONAL - example to avoid IBM / Lenovo ThinkVantage and Biometric Fingerprint Scanner
192
+ %SystemDrive%\SWSHARE\sfr.log
193
+ %SystemDrive%\Progra*\*Fingerprint*\*.xml
194
+ %SystemDrive%\Progra*\*Fingerprint*\rsc\sheetcc.css
195
+
196
+ // OPTIONAL - PointSec Driver
197
+ %SystemDrive%\prot_ins.sys
198
+
199
+ SECTION END:
200
+
201
+ //=========================================================================
202
+ // AFE FDE DGCIPHER FOLDERS - where to copy dgcipher for cd burns if file is encrypted with password
203
+ //=========================================================================
204
+ AFE FDE DGCIPHER FOLDERS:
205
+ <user profile>\Desktop\CdBurn
206
+ %SystemDrive%\CdBurnTemp
207
+ SECTION END:
208
+
209
+ //=========================================================================
210
+ // AFE FDE SYSTEM KEY - these files will be encryped by a random key, which
211
+ // in turn will be encrypted by the SYSTEM KEY
212
+ // ALGORITHM:
213
+ // If a file/directory is not found in this ("SYSTEM KEY") section,
214
+ // including its "exception" subsection, then or "SESSION KEY" section
215
+ // is checked (exception entries are checked first then inlusion entries)
216
+ // If a file or a directory could not be found there either
217
+ // than "afe-DefaultKeyProtectionType" value of config.xml is used
218
+ // 0 is for SYSTEM KEY, and 1 is for SESSION KEY. If there is no such
219
+ // configuration value than SYSTEM KEY is used by default for FDE installation
220
+ // and SESSION KEY is used for AFE installation.
221
+ //
222
+ // For removable media, these path are not checked, SESSION KEY are always used
223
+ //=========================================================================
224
+ AFE FDE SYSTEM KEY:
225
+ %SystemRoot%\*
226
+ %ProgramFiles%\*
227
+ ?:\Progra~?\*
228
+ %SystemDrive%\autoexec.bat
229
+
230
+ //"c:\Documents and Settings\user\Application Data\Sun\Java\Deployment\deployment.properties"
231
+ ?:\DOCUME~?\*\deployment.properties
232
+
233
+ ?:\DOCUME~?\*\ntuser.ini
234
+ ?:\RRbackups\*
235
+ ?:\RRback~?\*
236
+ ?:\SWSHARE\*
237
+ <java home>\*
238
+ // everything in documents in settings except user data
239
+ ?:\DOCUME~?\*
240
+ ?:\Documents?and?Settings\*
241
+ // except my documents and desktop, which are encrypted with session key
242
+ -|<user profile>\My?Documents\*
243
+ -|<user profile>\Desktop\*
244
+ -|?:\DOCUME~?\*\MyDocu~?\*
245
+ -|?:\DOCUME~?\*\Desktop\*
246
+ SECTION END:
247
+
248
+ //=========================================================================
249
+ // AFE FDE SESSION KEY - these files will be encryped by a random key, which
250
+ // in turn will be encrypted by the SESSION KEY
251
+ //
252
+ // If, previously, a file/directory is not found "SYSTEM KEY" section,
253
+ // including its "exception" subsection, then or this ("SESSION KEY") section
254
+ // is checked (exception entries are checked first then inlusion entries).
255
+ // If a file or a directory could not be found here either
256
+ // than "afe-DefaultKeyProtectionType" value of config.xml is used
257
+ // 0 is for SYSTEM KEY, and 1 is for SESSION KEY. If there is no such
258
+ // configuration value than SYSTEM KEY is used by default for FDE installation
259
+ // and SESSION KEY is used for AFE installation.
260
+ //
261
+ // For removable media, these path are not checked, SESSION KEY are always used
262
+ //=========================================================================
263
+ AFE FDE SESSION KEY:
264
+ *.DOC;*.DOCX;*.RTF;*.XLS;*.XLSX;*.PPT;*.PPTX;*.OST;*.PST;*.PDF;
265
+ <user profile>\*
266
+ -|<user profile>\Local Settings\Temp\*
267
+ ?:\DOCUME~?\*
268
+ -|?:\DOCUME~?\*\LOCALS~1\Temp\*
269
+ ?:\*
270
+ -|%SystemRoot%\*
271
+ SECTION END:
272
+
273
+ //=========================================================================
274
+ // FDE Directory Exclusions - FDE does not exclude any directories
275
+ // except these SYMANTEC SEP related directories.
276
+ //=========================================================================
277
+ FDE DIR EXCLUSIONS:
278
+ // REQUIRED registry avoidance vs. extensionless registry files
279
+ %SystemRoot%\system32\config\*
280
+
281
+ // OPTIONAL - System Restore and System Drive-State functions temp files. Removal could
282
+ // cause performance issues. Highly recommend keeping.
283
+ ?:\System Volume Information\*
284
+ ?:\SYSTEM~1*\*
285
+
286
+ // OPTIONAL - Symantec AV working locations
287
+ ?:\Progra*\Symant*\*
288
+ ?:\Progra*\Common*\Symant*\*
289
+ %ALLUSERSPROFILE%\App*\Symant*\*
290
+ SECTION END:
291
+
292
+ //=========================================================================
293
+ // FDE File Exclusions - these files will not be encrypted in FDE mode
294
+ //=========================================================================
295
+ FDE FILE EXCLUSIONS:
296
+ // REQUIRED Windows Boot sequence & Registry
297
+ %SystemDrive%\IO.SYS
298
+ %SystemDrive%\MSDOS.SYS
299
+ %SystemDrive%\boot.ini
300
+ %SystemDrive%\ntldr
301
+ ?:\pagefile.sys
302
+ ?:\hiberfil.sys
303
+ %SystemRoot%\system32\hal.dll
304
+ %SystemRoot%\system32\ntoskrnl.exe
305
+ %SystemRoot%\system32\atiicdxx.dat
306
+ %SystemRoot%\security\logs\winlogon.log
307
+ %SystemRoot%\Regist*\*.crmlog
308
+ %SystemRoot%\inf\*.inf
309
+ %SystemRoot%\inf\*.pnf
310
+ %SystemRoot%\inf\*.adm
311
+ %SystemRoot%\inf\*.iem
312
+ %SystemRoot%\bootstat.dat
313
+
314
+ // REQUIRED Windows Boot sequence - User Profiles
315
+ %SystemRoot%\system32\Micros*\Protect\*\Prefer*
316
+ %SystemRoot%\system32\Micros*\Protect\*\User\Prefer*
317
+
318
+ // REQIURED Windows Product Activation
319
+ %SystemRoot%\system32\wpa.dbl
320
+ %SystemRoot%\system32\wpa.bak
321
+
322
+ // REQUIRED Windows Recycle Bin
323
+ ?:\RECYCLE*\*\INFO2
324
+
325
+ // REQUIRED DG Agent temp files during uninstall via Add/Remove Programs
326
+ ?:\DOCUME*\*\APPLIC*\*\DGAgen*.*
327
+ ?:\DOCUME*\*\APPLIC*\{*\instance.dat
328
+
329
+ // REQUIRED - Windows New User Creation and Roaming Profile Temp Files
330
+ ?:\*\PRF*.tmp
331
+
332
+ // OPTIONAL - example to permit Windows user-mode debugging
333
+ %SystemRoot%\debug\UserMode\userenv.log
334
+
335
+ // OPTIONAL - example to avoid PerfectDisk conflict
336
+ ?:\Perfec*\Perfec*.adm
337
+ ?:\Perfec*\PDHelpEN.chm
338
+ ?:\Perfec*\Config.ini
339
+ ?:\Perfec*\Upd.ini
340
+ ?:\Perfec*\PDAgen*.mof
341
+
342
+ // OPTIONAL - example to avoid IBM / Lenovo ThinkVantage and Biometric Fingerprint Scanner
343
+ %SystemDrive%\SWSHARE\sfr.log
344
+ %SystemDrive%\Progra*\*Fingerprint*\*.xml
345
+ %SystemDrive%\Progra*\*Fingerprint*\rsc\sheetcc.css
346
+
347
+ // OPTIONAL - PointSec Driver
348
+ %SystemDrive%\prot_ins.sys
349
+ SECTION END:
350
+
351
+ //=========================================================================
352
+ // ACI SECTION - old style for old agents who don't understand the new format
353
+ // specify directories where files are not classified
354
+ //=========================================================================
355
+ SECTION ACI:
356
+ c:\program files\common files\symantec shared
357
+ c:\program files\symantec
358
+ c:\program files\symantec client security
359
+ c:\program files\norton internet security
360
+ c:\windows
361
+ c:\winnt
362
+ C:\documents and settings\all users\application data\microsoft\crypto
363
+ c:\system volume information
364
+ c:\msocache
365
+ c:\config.msi
366
+ c:\inetpub
367
+
368
+ //Customer specific requirements
369
+ c:\drivers
370
+ SECTION END:
371
+
372
+ //=========================================================================
373
+ // ACI2 SECTION - new and improved version (5.3.1+)
374
+ // specify directories where files are not classified
375
+ //=========================================================================
376
+ SECTION ACI2:
377
+ %SystemDrive%\windows\*
378
+ %SystemDrive%\progra*\common*\symant*\*
379
+ %SystemDrive%\progra*\symant*\*
380
+ %SystemDrive%\progra*\norton*\*
381
+ %SystemDrive%\winnt\*
382
+ %SystemDrive%\docume*\all*\applic*\micros*\crypto\*
383
+ %SystemDrive%\system*\*
384
+ %SystemDrive%\msocache\*
385
+ %SystemDrive%\config.msi\*
386
+ %SystemDrive%\inetpub\*
387
+ %SystemDrive%\progra*\citrix\person*\logs\*
388
+ %SystemDrive%\progra*\citrix\pvsage*\*
389
+ %SystemDrive%\progra*\vmware\vmware*\*
390
+ %SystemDrive%\progra*\dgagent\readops\*
391
+ %SystemDrive%\progra*\malwarebytes endpoint agent\logs*
392
+
393
+ //Customer specific requirements
394
+ %SystemDrive%\drivers\*
395
+
396
+ // more filtering for IE
397
+ %SystemDrive%\users*\appdata\local\microsoft\windows\webcache\*.log
398
+ %SystemDrive%\users*\appdata\roaming\microsoft\windows\recent\customdestinations\*.tmp
399
+ %SystemDrive%\users*\appdata\roaming\microsoft\windows\recent\customdestinations\*-ms
400
+
401
+
402
+ // Windows 8 Apps special directories
403
+ <windows apps home>\*
404
+ <windows apps repository>\*
405
+
406
+
407
+ // Customer specific, filtering for AppSense desktop redirection with Office
408
+ \\mmfiles\*\appsense\*\*tmp
409
+
410
+ // Windows 10 Performance improvements
411
+ %SystemDrive%\Program Files (x86)\adobe\acrobat reader dc\reader\webresources\resource0\*.html
412
+ %SystemDrive%\Program Files (x86)\adobe\acrobat reader dc\reader\webresources\resource0\static\images\*.png
413
+ %SystemDrive%\Program Files (x86)\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\images\*.png
414
+ %SystemDrive%\Program Files (x86)\apple software update\softwareupdate.resources\software update.tiff
415
+ %SystemDrive%\Program Files (x86)\cisco systems\cisco jabber\*.xml
416
+ %SystemDrive%\Program Files (x86)\cisco systems\cisco jabber\avatars\*.svg
417
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\dropboxcrashhandler.exe
418
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\dropboxupdate.exe
419
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\dropboxupdatebroker.exe
420
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\dropboxupdatehelper.msi
421
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\dropboxupdateondemand.exe
422
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\goopdate.dll
423
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\goopdateres_*.dll
424
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\npdropboxupdate*.dll
425
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\psmachine.dll
426
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\psuser.dll
427
+ %SystemDrive%\Program Files (x86)\dropbox\update\install\{*}\dropboxupdatesetup_*.exe
428
+ %SystemDrive%\Program Files (x86)\dyn\updater\*.txt
429
+ %SystemDrive%\Program Files (x86)\dyn\updater\images\*.png
430
+ %SystemDrive%\Program Files\itunes\itunes.resources\missingartworkloading.png
431
+ %SystemDrive%\Program Files*\microsoft office\*.thmx
432
+ %SystemDrive%\Program Files\microsoft office\appxmanifest.xml
433
+ %SystemDrive%\Program Files\microsoft office\filesystemmetadata.xml
434
+ %SystemDrive%\Program Files\microsoft office\root\office16\microsoft.lync.model.zip
435
+ %SystemDrive%\Program Files\microsoft office\root\office16\microsoft.lync.utilities.controls.zip
436
+ %SystemDrive%\Program Files\microsoft office\root\office16\microsoft.lync.utilities.zip
437
+ %SystemDrive%\Program Files\microsoft office\root\office16\ocomprivate.zip
438
+ %SystemDrive%\Program Files\microsoft office\root\office16\system.windows.controls.theming.toolkit.zip
439
+ %SystemDrive%\Program Files\microsoft office\updates\detection\*\versiondescriptor.xml
440
+ %SystemDrive%\Program Files\windowsapps\microsoft.skypeapp*\skypeapp\assets\images\*.png
441
+ %SystemDrive%\ProgramData\{*}.zip
442
+ %SystemDrive%\ProgramData\apple computer\itunes\sc info\sc info.txt
443
+ %SystemDrive%\ProgramData\application data\dyn\updater\frontend.log
444
+ %SystemDrive%\ProgramData\application data\dyn\updater\frontend.log.*
445
+ %SystemDrive%\ProgramData\cisco\cisco anyconnect secure mobility client\*.xml
446
+ %SystemDrive%\ProgramData\cisco\cisco anyconnect secure mobility client\logs\updatehistory_*_log.txt
447
+ %SystemDrive%\programdata\dropbox\update\log\*
448
+ %SystemDrive%\ProgramData\dropbox\update\log\dropboxupdate.log-*
449
+ %SystemDrive%\ProgramData\dropbox\update\log\dropboxupdate.log-*-finished
450
+ %SystemDrive%\ProgramData\microsoft\clicktorun\machinedata\catalog\packages\*\deploymentconfiguration.xml
451
+ %SystemDrive%\ProgramData\microsoft\clicktorun\machinedata\catalog\packages\*\manifest.xml
452
+ %SystemDrive%\ProgramData\microsoft\clicktorun\machinedata\catalog\packages\*\userdeploymentconfiguration.xml
453
+ %SystemDrive%\ProgramData\microsoft\clicktorun\productreleases\*\en-us.16\masterdescriptor.en-us.xml
454
+ %SystemDrive%\ProgramData\microsoft\clicktorun\productreleases\*\x-none.16\masterdescriptor.x-none.xml
455
+ %SystemDrive%\ProgramData\microsoft\diagnosis\downloadedscenarios\windows.siuf.xml
456
+ %SystemDrive%\ProgramData\microsoft\office\heartbeat\heartbeatcache.xml
457
+ %SystemDrive%\ProgramData\microsoft\provisioning\*\masterdatastore.xml
458
+ %SystemDrive%\ProgramData\microsoft\provisioning\*\prov\runtime.xml
459
+ %SystemDrive%\ProgramData\microsoft\windows\power efficiency diagnostics\energy-report-*.xml
460
+ %SystemDrive%\ProgramData\microsoft\windows\power efficiency diagnostics\energy-report-latest.xml
461
+ %SystemDrive%\programdata\microsoft\windows\power efficiency diagnostics\energy-report*
462
+ %SystemDrive%\ProgramData\microsoft\windows\wer\reportqueue\*.txt
463
+ %SystemDrive%\ProgramData\microsoft\windows\wer\reportqueue\*.xml
464
+ %SystemDrive%\programdata\microsoft\windows\wer\reportqueue\*\report.wer
465
+ %SystemDrive%\programdata\microsoft\windows\wer\reportqueue\*\report.wer.tmp
466
+ %SystemDrive%\ProgramData\microsoft\windows\wer\temp\*.xml
467
+ %SystemDrive%\programdata\nvidia corporation\drs\update.bin
468
+ %SystemDrive%\ProgramData\nvidia corporation\shadowplay\capturecore.log
469
+ %SystemDrive%\ProgramData\nvidia corporation\shadowplay\capturecore.old
470
+ %SystemDrive%\ProgramData\sccomm\Logs\sccomm.txt
471
+ %SystemDrive%\ProgramData\sccomm\sccomm.txt
472
+ %SystemDrive%\ProgramData\vmware\*.txt
473
+ %SystemDrive%\Users\*\AppData\Local\{*}
474
+ %SystemDrive%\Users\*\AppData\Local\cisco\cisco anyconnect secure mobility client\preferences.xml
475
+ %SystemDrive%\Users\*\AppData\Local\cisco\unified communications\jabber\csf\history\*\_db.key
476
+ %SystemDrive%\users\*\appdata\local\cisco\unified communications\jabber\csf\logs\jabber.log.*
477
+ %SystemDrive%\Users\*\AppData\Local\cisco\unified communications\jabber\csf\photo cache\*.png
478
+ %SystemDrive%\Users\*\AppData\Local\cisco\unified communications\jabber\csf\telemetry\*.txt
479
+ %SystemDrive%\users\*\appdata\local\google\chrome\user data\*
480
+ %SystemDrive%\Users\*\AppData\Local\microsoft\clr_v4.0\ngendisable.txt
481
+ %SystemDrive%\Users\*\AppData\Local\microsoft\internet explorer\urlblock\urlblock_*.bin
482
+ %SystemDrive%\Users\*\AppData\Local\microsoft\msoidentitycrl\production\fplist.xml
483
+ %SystemDrive%\Users\*\AppData\Local\microsoft\office\*\lync.exe_rules.xml
484
+ %SystemDrive%\users\*\appdata\local\microsoft\office\*\lync\tracing\*.etl
485
+ %SystemDrive%\users\*\appdata\local\microsoft\office\*\lync\tracing\*.etl.bak
486
+ %SystemDrive%\users\*\appdata\local\microsoft\office\*\lync\tracing\*.uccapilog
487
+ %SystemDrive%\users\*\appdata\local\microsoft\office\*\msoia.exe_rules.xml
488
+ %SystemDrive%\Users\*\AppData\Local\microsoft\office\*\outlook.exe_rules.xml
489
+ %SystemDrive%\users\*\appdata\local\microsoft\onedrive\logs\*
490
+ %SystemDrive%\users\*\appdata\local\microsoft\onedrive\settings\*
491
+ %SystemDrive%\Users\*\AppData\Local\microsoft\onedrive\standaloneupdater\update.xml
492
+ %SystemDrive%\Users\*\AppData\Local\microsoft\onedrive\update\update.xml
493
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\*.com.nst.tmp
494
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\*.com.ost
495
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\*.com.ost.tmp
496
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\*\autod.*.com.xml
497
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\*autodiscover.xml
498
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\inferences*.xml
499
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\oab2.xml
500
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\oab3.xml
501
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\actioncentercache\dropbox-desktop-client_*.png
502
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\actioncentercache\flipboard-flipboard_*.jpg
503
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\actioncentercache\microsoft-explorer-notification--*.png
504
+ %SystemDrive%\users\*\appdata\local\microsoft\windows\actioncentercache\microsoft-explorer-notification*.png
505
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\actioncentercache\microsoft-office-outlook-exe-*.png
506
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\actioncentercache\microsoft-skypeapp_*-app_*.png
507
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\explorer\notifyicon\microsoft.explorer.notification.*.png
508
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*.htm
509
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*.jpg
510
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\compare_1_5_6_uni_dll1.zip
511
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\edgecompatviewlist[*].xml
512
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\edgecompatviewlist*.xml
513
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\edgecompatviewlist1.xml
514
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\img_spacer1.png
515
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\jabber_logo1.png
516
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\pluginmanager_*.zip
517
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\plugins*.zip
518
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\low\ie\*.htm
519
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\low\ie\*.png
520
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\low\ie\*.txt
521
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\notifications\wpnidm\*.jpg
522
+ %SystemDrive%\users\*\appdata\local\microsoft\windows\webcache\*
523
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\webcache\*.log
524
+ %SystemDrive%\Users\*\AppData\Local\microsoftedge\sharedcachecontainers\microsoftedge_iecompat\iecompatdata.xml
525
+ %SystemDrive%\Users\*\AppData\Local\nvidia corporation\shadowplay\capturecore.old
526
+ %SystemDrive%\users\*\appdata\local\nvidia\nvbackend\*
527
+ %SystemDrive%\Users\*\AppData\Local\nvidia\nvbackend\*.xml
528
+ %SystemDrive%\Users\*\AppData\Local\packages\*.dropbox_*\localstate\dbxdata.dat
529
+ %SystemDrive%\Users\*\AppData\Local\packages\*.dropbox_*\localstate\dbxdata.dat.bak
530
+ %SystemDrive%\users\*\appdata\local\packages\*.netflix_*\localstate\offlineinfo*
531
+ %SystemDrive%\users\*\appdata\local\packages\*.netflix_*\localstate\onlineinfo*
532
+ %SystemDrive%\users\*\appdata\local\packages\*.netflix_*\localstate\resumeinfo*
533
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\inetcache\*\*.htm
534
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\inetcache\*\*.jpg
535
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\inetcache\*\*.png
536
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\inetcache\*\*.txt
537
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\microsoft\internet explorer\domstore\*\*.xml
538
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\temp\*.tmp
539
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\localstate\*.xml
540
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\localstate\*.xml.~tmp
541
+ %SystemDrive%\Users\*\AppData\Local\packages\facebook.facebook_*\localstate\appdata\local\osmeta\_store_*\image_cache.v*\fbimagedownloader-*.jpg
542
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.aad.brokerplugin_*\ac\temp\*.tmp
543
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.aad.brokerplugin_*\localstate\*
544
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.aad.brokerplugin_*\localstate\*.tmp
545
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.bingweather_*\ac\inetcache\*.jpg
546
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.bingweather_*\ac\inetcache\*.png
547
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.bingweather_*\localstate\*.xml
548
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.bingweather_*\localstate\*.xml*.tmp
549
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.flv
550
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.htm
551
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.jpg
552
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.png
553
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.svg
554
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.svg
555
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.swf
556
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.txt
557
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.xml
558
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\microsoftedge\urlblock\urlblock_*.bin
559
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\temp\*.tmp
560
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.oneconnect_*\localstate\*
561
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\contactsonprimarytile.txt
562
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\contactsonprimarytile.txt.~tmp
563
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\diagoutputdir\peoplebackgroundtasklog.etl
564
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\diagoutputdir\peoplebackgroundtasklog.last.etl
565
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\tilethumbnails\primarytileimage_*.jpg
566
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\tilethumbnails\primarytileimage_*.jpgtemp
567
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\ac\temp\*.tmp
568
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\localstate\assets\*
569
+ %SystemDrive%\users\*\appdata\local\packages\microsoft.windows.contentdeliverymanager_*\localstate\contentmanagementsdk\creatives\*
570
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\localstate\contentmanagementsdk\creatives\*
571
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\localstate\contentmanagementsdk\creatives\*.tmp
572
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\localstate\stagedassets\*
573
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\localstate\tips\*.xml
574
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.cortana_*\ac\appcache\*.htm
575
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.cortana_*\ac\nvidia corporation\shadowplay\capturecore.log
576
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.cortana_*\ac\temp\*.tmp
577
+ %SystemDrive%\users\*\appdata\local\packages\microsoft.windows.cortana_*\localstate\*
578
+ %SystemDrive%\users\*\appdata\local\packages\microsoft.windows.cortana_*\tempstate\*
579
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.photos_*\ac\nvidia corporation\shadowplay\capturecore.log
580
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.photos_*\ac\nvidia corporation\shadowplay\capturecore.old
581
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.photos_*\localstate\framenavigationservicestate.xml
582
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.photos_*\localstate\photosapptile\tile*.jpg
583
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.photos_*\localstate\timelineprefetchthumbnails.xml
584
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscalculator_*\ac\nvidia corporation\shadowplay\capturecore.log
585
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\ac\nvidia corporation\shadowplay\capturecore.log
586
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\ac\nvidia corporation\shadowplay\capturecore.old
587
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\ac\temp\*.tmp
588
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\*.jpg
589
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\files\*.jpg
590
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\files\*.pdf
591
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\files\*.png
592
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\files\s0\*\image00*.png
593
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\localfiles\*.jpg
594
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\localfiles\*.pdf
595
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\localfiles\*.png
596
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\tempstate\content.mso\*.tmp
597
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\tempstate\syncenginesnapshot.xml
598
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\tempstate\syncenginesnapshotold.xml
599
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\inetcache\*.htm
600
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\inetcache\*.jpg
601
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\inetcache\*.png
602
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\nvidia corporation\shadowplay\capturecore.log
603
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\nvidia corporation\shadowplay\capturecore.old
604
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\temp\*.tmp
605
+ %SystemDrive%\Users\*\AppData\Local\publishers\*\fonts\fontcache\2\fontcachemetadata.xml
606
+ %SystemDrive%\users\*\appdata\local\temp\*
607
+ %SystemDrive%\Users\*\appdata\local\xo communications\worktime\*
608
+ %SystemDrive%\Users\*\AppData\Locallow\lastpass\debug.txt
609
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\itunes\cookies\cookies.binarycookies
610
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\itunes\cookies\cookies.binarycookies_tmp_*.dat
611
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\preferences\byhost\com.apple.itunes.{*}.plist
612
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\preferences\byhost\com.apple.itunes.{*}.plist.*
613
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\preferences\com.apple.itunes.plist
614
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\preferences\com.apple.itunes.plist.*
615
+ %SystemDrive%\users\*\appdata\roaming\cisco\unified communications\jabber\csf\config\*
616
+ %SystemDrive%\Users\*\AppData\roaming\microsoft\templates\livecontent\*.thmx
617
+ %SystemDrive%\users\*\appdata\roaming\microsoft\office\*\*\proofing\*.tmp
618
+ %SystemDrive%\users\*\appdata\roaming\microsoft\office\*\*\proofing\roamingcustom.dic
619
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\outlook\outlook.xml
620
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\signatures\*.htm
621
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\signatures\*\colorschememapping.xml
622
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\signatures\*\themedata.thmx
623
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\templates\~$rmalemail.dotm
624
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\templates\~wrd*.tmp
625
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\templates\normalemail.dotm
626
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\~ictures.tmp
627
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\~ocuments.tmp
628
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\documents.library-ms
629
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\documents.library-ms~*.tmp
630
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\pictures.library-ms
631
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\pictures.library-ms~*.tmp
632
+ %SystemDrive%\users\*\appdata\roaming\microsoft\windows\recent\customdestinations\*
633
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\config.xml
634
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\contextmenu.xml
635
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\langs.xml
636
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\plugins\config\pluginmanagerplugins.zip
637
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\session.xml
638
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\shortcuts.xml
639
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\stylers.xml
640
+ %SystemDrive%\Users\*\evernote\logs\applog_*.txt
641
+ %SystemDrive%\Users\*\music\itunes\*.tmp
642
+ %SystemDrive%\Users\*\music\itunes\it.tmp
643
+ %SystemDrive%\Users\*\music\itunes\itunes library.itl
644
+ %SystemDrive%\Users\*\music\itunes\temp*.tmp
645
+ %SystemDrive%\windows\inf\wmiaprpl\*
646
+ %SystemDrive%\windows\system32\perfstringbackup.tmp
647
+ %SystemDrive%\windows\system32\wbem\performance\*
648
+ %SystemDrive%\windows\temp\*.exe
649
+
650
+
651
+ SECTION END:
652
+
653
+ //=========================================================================
654
+ // DOCPROPS SECTION - specify directories where files are not docprops done
655
+ //=========================================================================
656
+ SECTION DOCPROPS:
657
+ %SystemDrive%\windows\*
658
+ %SystemDrive%\progra*\common*\symant*\*
659
+ %SystemDrive%\progra*\symant*\*
660
+ %SystemDrive%\progra*\norton*\*
661
+ %SystemDrive%\winnt\*
662
+ %SystemDrive%\docume*\all*\applic*\micros*\crypto\*
663
+ %SystemDrive%\system*\*
664
+ %SystemDrive%\msocache\*
665
+ %SystemDrive%\config.msi\*
666
+ %SystemDrive%\inetpub\*
667
+ %SystemDrive%\progra*\citrix\person*\logs\*
668
+ %SystemDrive%\progra*\citrix\pvsage*\*
669
+ %SystemDrive%\progra*\vmware\vmware*\*
670
+ %SystemDrive%\progra*\dgagent\readops\*
671
+
672
+ //Customer specific requirements
673
+ %SystemDrive%\drivers\*
674
+
675
+ // Windows 8 Apps special directories
676
+ <windows apps home>\*
677
+ <windows apps repository>\*
678
+
679
+ // Windows 10 Performance improvements
680
+ %SystemDrive%\Program Files (x86)\adobe\acrobat reader dc\reader\webresources\resource0\*.html
681
+ %SystemDrive%\Program Files (x86)\adobe\acrobat reader dc\reader\webresources\resource0\static\images\*.png
682
+ %SystemDrive%\Program Files (x86)\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\images\*.png
683
+ %SystemDrive%\Program Files (x86)\apple software update\softwareupdate.resources\software update.tiff
684
+ %SystemDrive%\Program Files (x86)\cisco systems\cisco jabber\*.xml
685
+ %SystemDrive%\Program Files (x86)\cisco systems\cisco jabber\avatars\*.svg
686
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\dropboxcrashhandler.exe
687
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\dropboxupdate.exe
688
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\dropboxupdatebroker.exe
689
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\dropboxupdatehelper.msi
690
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\dropboxupdateondemand.exe
691
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\goopdate.dll
692
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\goopdateres_*.dll
693
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\npdropboxupdate*.dll
694
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\psmachine.dll
695
+ %SystemDrive%\Program Files (x86)\dropbox\update\*\psuser.dll
696
+ %SystemDrive%\Program Files (x86)\dropbox\update\install\{*}\dropboxupdatesetup_*.exe
697
+ %SystemDrive%\Program Files (x86)\dyn\updater\*.txt
698
+ %SystemDrive%\Program Files (x86)\dyn\updater\images\*.png
699
+ %SystemDrive%\Program Files\itunes\itunes.resources\missingartworkloading.png
700
+ %SystemDrive%\Program Files*\microsoft office\*.thmx
701
+ %SystemDrive%\Program Files\microsoft office\appxmanifest.xml
702
+ %SystemDrive%\Program Files\microsoft office\filesystemmetadata.xml
703
+ %SystemDrive%\Program Files\microsoft office\root\office16\microsoft.lync.model.zip
704
+ %SystemDrive%\Program Files\microsoft office\root\office16\microsoft.lync.utilities.controls.zip
705
+ %SystemDrive%\Program Files\microsoft office\root\office16\microsoft.lync.utilities.zip
706
+ %SystemDrive%\Program Files\microsoft office\root\office16\ocomprivate.zip
707
+ %SystemDrive%\Program Files\microsoft office\root\office16\system.windows.controls.theming.toolkit.zip
708
+ %SystemDrive%\Program Files\microsoft office\updates\detection\*\versiondescriptor.xml
709
+ %SystemDrive%\Program Files\windowsapps\microsoft.skypeapp*\skypeapp\assets\images\*.png
710
+ %SystemDrive%\ProgramData\{*}.zip
711
+ %SystemDrive%\ProgramData\apple computer\itunes\sc info\sc info.txt
712
+ %SystemDrive%\ProgramData\application data\dyn\updater\frontend.log
713
+ %SystemDrive%\ProgramData\application data\dyn\updater\frontend.log.*
714
+ %SystemDrive%\ProgramData\cisco\cisco anyconnect secure mobility client\*.xml
715
+ %SystemDrive%\ProgramData\cisco\cisco anyconnect secure mobility client\logs\updatehistory_*_log.txt
716
+ %SystemDrive%\programdata\dropbox\update\log\*
717
+ %SystemDrive%\ProgramData\dropbox\update\log\dropboxupdate.log-*
718
+ %SystemDrive%\ProgramData\dropbox\update\log\dropboxupdate.log-*-finished
719
+ %SystemDrive%\ProgramData\microsoft\clicktorun\machinedata\catalog\packages\*\deploymentconfiguration.xml
720
+ %SystemDrive%\ProgramData\microsoft\clicktorun\machinedata\catalog\packages\*\manifest.xml
721
+ %SystemDrive%\ProgramData\microsoft\clicktorun\machinedata\catalog\packages\*\userdeploymentconfiguration.xml
722
+ %SystemDrive%\ProgramData\microsoft\clicktorun\productreleases\*\en-us.16\masterdescriptor.en-us.xml
723
+ %SystemDrive%\ProgramData\microsoft\clicktorun\productreleases\*\x-none.16\masterdescriptor.x-none.xml
724
+ %SystemDrive%\ProgramData\microsoft\diagnosis\downloadedscenarios\windows.siuf.xml
725
+ %SystemDrive%\ProgramData\microsoft\office\heartbeat\heartbeatcache.xml
726
+ %SystemDrive%\ProgramData\microsoft\provisioning\*\masterdatastore.xml
727
+ %SystemDrive%\ProgramData\microsoft\provisioning\*\prov\runtime.xml
728
+ %SystemDrive%\ProgramData\microsoft\windows\power efficiency diagnostics\energy-report-*.xml
729
+ %SystemDrive%\ProgramData\microsoft\windows\power efficiency diagnostics\energy-report-latest.xml
730
+ %SystemDrive%\programdata\microsoft\windows\power efficiency diagnostics\energy-report*
731
+ %SystemDrive%\ProgramData\microsoft\windows\wer\reportqueue\*.txt
732
+ %SystemDrive%\ProgramData\microsoft\windows\wer\reportqueue\*.xml
733
+ %SystemDrive%\programdata\microsoft\windows\wer\reportqueue\*\report.wer
734
+ %SystemDrive%\programdata\microsoft\windows\wer\reportqueue\*\report.wer.tmp
735
+ %SystemDrive%\ProgramData\microsoft\windows\wer\temp\*.xml
736
+ %SystemDrive%\programdata\nvidia corporation\drs\update.bin
737
+ %SystemDrive%\ProgramData\nvidia corporation\shadowplay\capturecore.log
738
+ %SystemDrive%\ProgramData\nvidia corporation\shadowplay\capturecore.old
739
+ %SystemDrive%\ProgramData\sccomm\Logs\sccomm.txt
740
+ %SystemDrive%\ProgramData\sccomm\sccomm.txt
741
+ %SystemDrive%\ProgramData\vmware\*.txt
742
+ %SystemDrive%\Users\*\AppData\Local\{*}
743
+ %SystemDrive%\Users\*\AppData\Local\cisco\cisco anyconnect secure mobility client\preferences.xml
744
+ %SystemDrive%\Users\*\AppData\Local\cisco\unified communications\jabber\csf\history\*\_db.key
745
+ %SystemDrive%\users\*\appdata\local\cisco\unified communications\jabber\csf\logs\jabber.log.*
746
+ %SystemDrive%\Users\*\AppData\Local\cisco\unified communications\jabber\csf\photo cache\*.png
747
+ %SystemDrive%\Users\*\AppData\Local\cisco\unified communications\jabber\csf\telemetry\*.txt
748
+ %SystemDrive%\users\*\appdata\local\google\chrome\user data\*
749
+ %SystemDrive%\Users\*\AppData\Local\microsoft\clr_v4.0\ngendisable.txt
750
+ %SystemDrive%\Users\*\AppData\Local\microsoft\internet explorer\urlblock\urlblock_*.bin
751
+ %SystemDrive%\Users\*\AppData\Local\microsoft\msoidentitycrl\production\fplist.xml
752
+ %SystemDrive%\Users\*\AppData\Local\microsoft\office\*\lync.exe_rules.xml
753
+ %SystemDrive%\users\*\appdata\local\microsoft\office\*\lync\tracing\*.etl
754
+ %SystemDrive%\users\*\appdata\local\microsoft\office\*\lync\tracing\*.etl.bak
755
+ %SystemDrive%\users\*\appdata\local\microsoft\office\*\lync\tracing\*.uccapilog
756
+ %SystemDrive%\users\*\appdata\local\microsoft\office\*\msoia.exe_rules.xml
757
+ %SystemDrive%\Users\*\AppData\Local\microsoft\office\*\outlook.exe_rules.xml
758
+ %SystemDrive%\users\*\appdata\local\microsoft\onedrive\logs\*
759
+ %SystemDrive%\users\*\appdata\local\microsoft\onedrive\settings\*
760
+ %SystemDrive%\Users\*\AppData\Local\microsoft\onedrive\standaloneupdater\update.xml
761
+ %SystemDrive%\Users\*\AppData\Local\microsoft\onedrive\update\update.xml
762
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\*.com.nst.tmp
763
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\*.com.ost
764
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\*.com.ost.tmp
765
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\*\autod.*.com.xml
766
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\*autodiscover.xml
767
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\inferences*.xml
768
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\oab2.xml
769
+ %SystemDrive%\Users\*\AppData\Local\microsoft\outlook\oab3.xml
770
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\actioncentercache\dropbox-desktop-client_*.png
771
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\actioncentercache\flipboard-flipboard_*.jpg
772
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\actioncentercache\microsoft-explorer-notification--*.png
773
+ %SystemDrive%\users\*\appdata\local\microsoft\windows\actioncentercache\microsoft-explorer-notification*.png
774
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\actioncentercache\microsoft-office-outlook-exe-*.png
775
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\actioncentercache\microsoft-skypeapp_*-app_*.png
776
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\explorer\notifyicon\microsoft.explorer.notification.*.png
777
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*.htm
778
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*.jpg
779
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\compare_1_5_6_uni_dll1.zip
780
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\edgecompatviewlist[*].xml
781
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\edgecompatviewlist*.xml
782
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\edgecompatviewlist1.xml
783
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\img_spacer1.png
784
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\jabber_logo1.png
785
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\pluginmanager_*.zip
786
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\ie\*\plugins*.zip
787
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\low\ie\*.htm
788
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\low\ie\*.png
789
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\inetcache\low\ie\*.txt
790
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\notifications\wpnidm\*.jpg
791
+ %SystemDrive%\users\*\appdata\local\microsoft\windows\webcache\*
792
+ %SystemDrive%\Users\*\AppData\Local\microsoft\windows\webcache\*.log
793
+ %SystemDrive%\Users\*\AppData\Local\microsoftedge\sharedcachecontainers\microsoftedge_iecompat\iecompatdata.xml
794
+ %SystemDrive%\Users\*\AppData\Local\nvidia corporation\shadowplay\capturecore.old
795
+ %SystemDrive%\users\*\appdata\local\nvidia\nvbackend\*
796
+ %SystemDrive%\Users\*\AppData\Local\nvidia\nvbackend\*.xml
797
+ %SystemDrive%\Users\*\AppData\Local\packages\*.dropbox_*\localstate\dbxdata.dat
798
+ %SystemDrive%\Users\*\AppData\Local\packages\*.dropbox_*\localstate\dbxdata.dat.bak
799
+ %SystemDrive%\users\*\appdata\local\packages\*.netflix_*\localstate\offlineinfo*
800
+ %SystemDrive%\users\*\appdata\local\packages\*.netflix_*\localstate\onlineinfo*
801
+ %SystemDrive%\users\*\appdata\local\packages\*.netflix_*\localstate\resumeinfo*
802
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\inetcache\*\*.htm
803
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\inetcache\*\*.jpg
804
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\inetcache\*\*.png
805
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\inetcache\*\*.txt
806
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\microsoft\internet explorer\domstore\*\*.xml
807
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\ac\temp\*.tmp
808
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\localstate\*.xml
809
+ %SystemDrive%\Users\*\AppData\Local\packages\amazon.com.amazon_*\localstate\*.xml.~tmp
810
+ %SystemDrive%\Users\*\AppData\Local\packages\facebook.facebook_*\localstate\appdata\local\osmeta\_store_*\image_cache.v*\fbimagedownloader-*.jpg
811
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.aad.brokerplugin_*\ac\temp\*.tmp
812
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.aad.brokerplugin_*\localstate\*
813
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.aad.brokerplugin_*\localstate\*.tmp
814
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.bingweather_*\ac\inetcache\*.jpg
815
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.bingweather_*\ac\inetcache\*.png
816
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.bingweather_*\localstate\*.xml
817
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.bingweather_*\localstate\*.xml*.tmp
818
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.flv
819
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.htm
820
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.jpg
821
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.png
822
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.svg
823
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.svg
824
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.swf
825
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.txt
826
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\*\microsoftedge\cache\*.xml
827
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\microsoftedge\urlblock\urlblock_*.bin
828
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.microsoftedge_*\ac\temp\*.tmp
829
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.oneconnect_*\localstate\*
830
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\contactsonprimarytile.txt
831
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\contactsonprimarytile.txt.~tmp
832
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\diagoutputdir\peoplebackgroundtasklog.etl
833
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\diagoutputdir\peoplebackgroundtasklog.last.etl
834
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\tilethumbnails\primarytileimage_*.jpg
835
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.people_*\localstate\tilethumbnails\primarytileimage_*.jpgtemp
836
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\ac\temp\*.tmp
837
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\localstate\assets\*
838
+ %SystemDrive%\users\*\appdata\local\packages\microsoft.windows.contentdeliverymanager_*\localstate\contentmanagementsdk\creatives\*
839
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\localstate\contentmanagementsdk\creatives\*
840
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\localstate\contentmanagementsdk\creatives\*.tmp
841
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\localstate\stagedassets\*
842
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.contentdeliverymanager_*\localstate\tips\*.xml
843
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.cortana_*\ac\appcache\*.htm
844
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.cortana_*\ac\nvidia corporation\shadowplay\capturecore.log
845
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.cortana_*\ac\temp\*.tmp
846
+ %SystemDrive%\users\*\appdata\local\packages\microsoft.windows.cortana_*\localstate\*
847
+ %SystemDrive%\users\*\appdata\local\packages\microsoft.windows.cortana_*\tempstate\*
848
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.photos_*\ac\nvidia corporation\shadowplay\capturecore.log
849
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.photos_*\ac\nvidia corporation\shadowplay\capturecore.old
850
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.photos_*\localstate\framenavigationservicestate.xml
851
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.photos_*\localstate\photosapptile\tile*.jpg
852
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windows.photos_*\localstate\timelineprefetchthumbnails.xml
853
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscalculator_*\ac\nvidia corporation\shadowplay\capturecore.log
854
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\ac\nvidia corporation\shadowplay\capturecore.log
855
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\ac\nvidia corporation\shadowplay\capturecore.old
856
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\ac\temp\*.tmp
857
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\*.jpg
858
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\files\*.jpg
859
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\files\*.pdf
860
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\files\*.png
861
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\files\s0\*\image00*.png
862
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\localfiles\*.jpg
863
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\localfiles\*.pdf
864
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\localstate\localfiles\*.png
865
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\tempstate\content.mso\*.tmp
866
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\tempstate\syncenginesnapshot.xml
867
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowscommunicationsapps_*\tempstate\syncenginesnapshotold.xml
868
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\inetcache\*.htm
869
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\inetcache\*.jpg
870
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\inetcache\*.png
871
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\nvidia corporation\shadowplay\capturecore.log
872
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\nvidia corporation\shadowplay\capturecore.old
873
+ %SystemDrive%\Users\*\AppData\Local\packages\microsoft.windowsstore_*\ac\temp\*.tmp
874
+ %SystemDrive%\Users\*\AppData\Local\publishers\*\fonts\fontcache\2\fontcachemetadata.xml
875
+ %SystemDrive%\users\*\appdata\local\temp\*
876
+ %SystemDrive%\Users\*\AppData\Locallow\lastpass\debug.txt
877
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\itunes\cookies\cookies.binarycookies
878
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\itunes\cookies\cookies.binarycookies_tmp_*.dat
879
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\preferences\byhost\com.apple.itunes.{*}.plist
880
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\preferences\byhost\com.apple.itunes.{*}.plist.*
881
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\preferences\com.apple.itunes.plist
882
+ %SystemDrive%\Users\*\AppData\Roaming\apple computer\preferences\com.apple.itunes.plist.*
883
+ %SystemDrive%\users\*\appdata\roaming\cisco\unified communications\jabber\csf\config\*
884
+ %SystemDrive%\Users\*\AppData\roaming\microsoft\templates\livecontent\*.thmx
885
+ %SystemDrive%\users\*\appdata\roaming\microsoft\office\*\*\proofing\*.tmp
886
+ %SystemDrive%\users\*\appdata\roaming\microsoft\office\*\*\proofing\roamingcustom.dic
887
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\outlook\outlook.xml
888
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\signatures\*.htm
889
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\signatures\*\colorschememapping.xml
890
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\signatures\*\themedata.thmx
891
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\templates\~$rmalemail.dotm
892
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\templates\~wrd*.tmp
893
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\templates\normalemail.dotm
894
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\~ictures.tmp
895
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\~ocuments.tmp
896
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\documents.library-ms
897
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\documents.library-ms~*.tmp
898
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\pictures.library-ms
899
+ %SystemDrive%\Users\*\AppData\Roaming\microsoft\windows\libraries\pictures.library-ms~*.tmp
900
+ %SystemDrive%\users\*\appdata\roaming\microsoft\windows\recent\customdestinations\*
901
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\config.xml
902
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\contextmenu.xml
903
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\langs.xml
904
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\plugins\config\pluginmanagerplugins.zip
905
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\session.xml
906
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\shortcuts.xml
907
+ %SystemDrive%\Users\*\AppData\Roaming\notepad++\stylers.xml
908
+ %SystemDrive%\Users\*\evernote\logs\applog_*.txt
909
+ %SystemDrive%\Users\*\music\itunes\*.tmp
910
+ %SystemDrive%\Users\*\music\itunes\it.tmp
911
+ %SystemDrive%\Users\*\music\itunes\itunes library.itl
912
+ %SystemDrive%\Users\*\music\itunes\temp*.tmp
913
+ %SystemDrive%\windows\inf\wmiaprpl\*
914
+ %SystemDrive%\windows\system32\perfstringbackup.tmp
915
+ %SystemDrive%\windows\system32\wbem\performance\*
916
+ %SystemDrive%\windows\temp\*.exe
917
+ %SystemDrive%\users\*\appdata\local\microsoft\edge\user data\*
918
+ SECTION END:
919
+
920
+ //=========================================================================
921
+ // AFE FDE NO REPARSE FILES -
922
+ // These are meant to suppress warning dialogs from firewalls
923
+ //=========================================================================
924
+ SECTION AFE FDE FILE NO REPARSE:
925
+
926
+ //Transactional NTFS and registry
927
+ // Legacy entries - not needed any more ...
928
+ //*\USERS\*\NTUSER*
929
+ //*\USERS\*\USRCLASS*
930
+ *\TxR\*
931
+
932
+ // OPTIONAL - Symantec AV
933
+ // *\PROGRA*\SYMANT*\*\*.exe
934
+ // *\PROGRA*\COMMON*\SYMANT*\*.exe
935
+ // *\PROG*\*\SRTSP*\*
936
+
937
+ // OPTIONAL - Symantec Tamper Protection
938
+ *\NOMADIC\DBENG8.EXE
939
+ *\SYSTEM32\SERVICES.EXE
940
+
941
+ // OPTIONAL - McAfee AV
942
+ *\PROGRA*\MCAFEE*\*
943
+
944
+ // OPTIONAL - VMWare Workstation and VMWare Player
945
+ *\VMWARE-AUTHD.exe
946
+
947
+ // OPTIONAL - Siebel DB client
948
+ *\sfadialer\SFADial.exe
949
+
950
+ // AME DGFS: without this AFE will decrypt temporary files
951
+ // that AME encrypted when replacing attachment
952
+ //*\09D849B6-32D3-4A40-85EE-6B84BA29E35B\msgs\*
953
+
954
+ // This is a fix for DGAGENT-1448, HP systems running out of stack space.
955
+ *\system32\atiok3*.dll
956
+
957
+ // This is a fix for DGAGENT-1893 Cannot launch start menu when AFE is enabled on Win8
958
+ // On start Explorer tries to open .lnk files in this directory with OpLocks
959
+ *\USERS\*\APPDATA\LOCAL\MICRO*\WINDOWS\WINX\*
960
+
961
+ // Fix For Universal Apps
962
+ *\USERS\*\APPDATA\LOCAL\PACKAGE?\*
963
+ *\WINDOWS\SYSTEM32\WWAHOST.EXE
964
+ *\WINDOWS\SYSTEM32\BYTECODEGENERATOR.EXE
965
+ *\WINDOWS\SYSTEM32\RUNTIMEBROKER.EXE
966
+ *\WINDOWS\SYSTEM32\BACKGROUNDTASKHOST.EXE
967
+ *\USERS\*\APPDATA\LOCAL\MICRO*\WINDOWS\APPLIC*\*
968
+ *\WINDOWS\WINSTOR*
969
+ *\PROG*\WINDOWSAPP*
970
+
971
+ //SA-24054: Fixed RS3 AFE compatibility issue.
972
+ *\WINDOWS\FONTS*
973
+
974
+ // Fix for DGAGENT-2893 (Sep12 RU3) and DGAGENT-3507 (Sep12 RU4) and future versions of
975
+ // Symantec Endpoint Protection Client Installations
976
+ *\SYMANT*12.1.*
977
+ *\PROGRA*\SYMANT*\SYMANT*\CURRENT*
978
+
979
+ // This is a fix for DGAGENT-5975, [Kraft Group] Latency accessing network shares with AFE enabled?
980
+ *\SRVSVC*
981
+
982
+ *WINDOWS\WINSX*
983
+ *WINDOWS\SOFTWAREDISTRIBUTIO*
984
+ *WINDOWS\SOFTWA~1*
985
+ *WINDOWS\CBSTEM*
986
+ *\CBSTEM*PACKAGE*KB*.CAT*
987
+ *WINDOWS\SERVICIN*
988
+ *WINDOWS\SERVIC*\PACK*
989
+ *WINDOWS\REGISTRATIO*
990
+ *WINDOWS\REGIST~1*
991
+ *WINDOWS\GLOBALIZATION*
992
+ *WINDOWS\GLOBAL~1*
993
+ *TIWORKER.EX*
994
+ *WINDOWS\LOGS*
995
+ *WINDOWS\SYS*\SMI\STORE*
996
+ *PROGRAMDATA\USOPRIVAT*
997
+ *PROGRAMDATA\MICROSOFT*
998
+ *WINDOWS\SYS*\CONFIG*
999
+ *WINDOWS\APPPATC*
1000
+ *SYS*\CATROO*
1001
+ *\WINDOWS\INF*
1002
+
1003
+ // Don't reparse any basic EXE types
1004
+ // Fix for DGAGENT-17152
1005
+ *.EXE*;*.DLL*;*.SYS*;*.COM;*.CPL
1006
+
1007
+ SECTION END:
1008
+
1009
+ //=========================================================================
1010
+ // AFE PROCESS NO REPARSE FILES -
1011
+ // No reparse of the specified files. Effeects processses marked with RP flag.
1012
+ // e.g sfttray.exe,RP+PR - see prcsflgs.dat for example(s)
1013
+ //========================================================================
1014
+ SECTION AFE PROCESS NO REPARSE FILES:
1015
+ // OPTIONAL - AppV Application (see sfttray.exe in prcsflgs.dat )
1016
+ sfttray.exe:*.DLL
1017
+
1018
+ // OPTIONAL - Adobe Reader X 10.0.0 (see acrord32.exe in prcsflgs.dat)
1019
+ acrord32.exe:*\USERS\*\APPDATA\*\ADOBE\*
1020
+ acrord32.exe:*\DOC*\*\APP*\ADOBE\*
1021
+
1022
+ // SEP12 has issues during install
1023
+ ccSvcHst.exe:*SYMANTEC*
1024
+
1025
+ // SCEP 2015
1026
+ msmpeng.exe:*.CMD
1027
+
1028
+ // Universal Apps :aka MetroApps - Excluded for AFE
1029
+ sihost.exe:*.JPG
1030
+ SECTION END: