Here is a list of extensions that could be excluded from being scanned on the average system.  Feel free to add your own.

aac, acs, adc, adm, ai, am, art, avi, awe, bat, bin, bkf, bmp, cab, cat, cfg, chm, class, clx, cmd, cnt, cnv, com, config, cpl, cpp, cs, csf, css, cur, cw, dic, dll, dlm, dotx, env, eps, evt, evtx, exe, flt, fon, gif, h, hhk, hiv, hlp, hxs, hxw, hyp, icc, icm, ico, idx, inf, ini, iso, its, jar, jpeg, jpg, js, jse, lex, lib, liveupdate, lnk, lxa, m4a, m4p, m4v, mda, mdf, mid, mof, mov, mp3, mp4, mpeg, mpg, msc, msi, msp, mst, ngr, ocx, ogg, olb, pf, pfb, pfm, pnf, png, ps1, psd, psp, py, pyw, query, rll, rm, rmm, rmx, rp, rpm, rpv, rts, sdb, smi, spd, swp, sys, theme, tif, tiff, toc, ttc, ttf, vb, vbe, vbn, vbs, vdf, vhd, vmdk, vsd, wav, wma, wmb, wmdb, wmv, wpc, wsf, wsh, xaml, xdr, xml

[Added January 6, 2010 by jpb6]

Here is ILR's exclude list using the format required by ORCA when creating a custom MSI:

[HCLM] Software\Identity Finder\Client\FirstRun\Settings\Locations\Files\FileExtensions

aac;1[]acs;1[]adc;1[]adm;1[]ai;1[]am;1[]api;1[]art;1[]avi;1[]awe;1[]bat;1[]bin;1[]bkf;1[]bmp;1[]cab;1[]cat;1[]cfg;1[]chm;1[]class;1[]clx;1[]cmd;1[]cnt;1[]cnv;1[]com;1[]config;1[]cpl;1[]cpp;1[]cs;1[]csf;1[]css;1[]cur;1[]cw;1[]dic;1[]dll;1[]dlm;1[]dotx;1[]env;1[]eps;1[]evt;1[]evtx;1[]exe;1[]flt;1[]fon;1[]gif;1[]h;1[]hhk;1[]hiv;1[]hlp;1[]hpd;1[]hxs;1[]hxw;1[]hyp;1[]icc;1[]icm;1[]ico;1[]idx;1[]inf;1[]ini;1[]iso;1[]its;1[]jar;1[]jpeg;1[]jpg;1[]js;1[]jse;1[]lex;1[]lib;1[]liveupdate;1[]lnk;1[]lxa;1[]m4a;1[]m4p;1[]m4v;1[]mda;1[]mdf;1[]mid;1[]mof;1[]mov;1[]mp3;1[]mp4;1[]mpeg;1[]mpg;1[]msb;1[]msc;1[]msi;1[]msp;1[]mst;1[]mui;1[]nlm;1[]nls;1[]ngr;1[]ocx;1[]ogg;1[]olb;1[]pf;1[]pfb;1[]pfm;1[]pnf;1[]png;1[]ppd;1[]ps1;1[]psd;1[]psp;1[]py;1[]pyw;1[]query;1[]rll;1[]rm;1[]rmm;1[]rmx;1[]rp;1[]rpm;1[]rpv;1[]rts;1[]sdb;1[]smi;1[]spd;1[]swp;1[]sys;1[]theme;1[]tif;1[]tiff;1[]toc;1[]ttc;1[]ttf;1[]vb;1[]vbe;1[]vbn;1[]vbs;1[]vdf;1[]vhd;1[]vmdk;1[]vsd;1[]wav;1[]wma;1[]wmb;1[]wmdb;1[]wmv;1[]wpc;1[]wsf;1[]wsh;1[]xaml;1[]xdr;1[~]xml;1

NOTE: We use the FirstRun key to populate the users HKCU hive.  This allows them to add extensions in the IDF GUI if needed.

  • No labels