O&O ShutUp10++ – Free anti-spy tool for Windows 10, 11
oo-software.com
oo-software.com
I plan on going through them to weed out duplicates and duds. You shouldn't trust any of those blindly, but definitely read through the code; I'm particularly interested in coming up with a list of services and scheduled tasks that can be safely disabled without impacting any of the applications and services I'm using (I want Windows Update, OneDrive, Office, Defender, Store and store apps, MS Account login and Xbox Gaming for example, which most tools want to disable).
Is it intuitive to anyone that a third party web browser would be doing this by default?
I have a single remaining windows box that is completely idle with a rust disk and it's started spinning up for no apparent reason
how did you figure out it was Chrome?
edit: going to try procmon with the filter set to the disk
Someone might post a binary build there soon with 94 (until yesterday they only had the ancient 89), but you can build it yourself as well (on my 32-core 5950x with 64Gb RAM it took 2.5+ hours to build, just to be prepared for that).
Note that it won't have the Google Chrome Store, so the process for installing extensions (ahem, uBlock Origin) is a bit more involved: https://ungoogled-software.github.io/ungoogled-chromium-wiki...
Nvidia is another culprit, Geforce Experience scans all your drives constantly to look for new games or something like that.
https://www.google.com/chrome/privacy/whitepaper.html#unwant...
> In addition, if you have opted in to automatically report details of possible security incidents to Google, Chrome will report information about unwanted software, including relevant file metadata and system settings linked to the unwanted software found on your computer.
I don't think I ever opted in to this but they may have have had tricky wording or I just didn't catch it. From searching around, there seems to be no way to opt out of the scan itself (not the submission) except denying read permissions to the software_reporter_tool.exe's folder. So if you have spinning drives that you want to keep idle when not in use, for power and longevity reasons, you are SOL without remembering each time you setup a machine.
which says
After installation, programs should not engage in deceptive or unexpected behavior. Some examples of deceptive or unexpected behavior include:[...]Preventing the user from controlling the software[...]The user must have a meaningful opportunity to review and approve any principal and significant updates or settings changes.
Disclosure is especially important if data collection is a non-obvious feature of the software.
Pure unadulterated hypocrisy. Not surprising coming from Google.
> Don't scare the user. Software must not misrepresent the state of the user's machine to the user, for example by claiming the system is in a critical security state or infected with viruses.
Yet Google Chrome continues to tell users that many harmless executables are malware even after they have been informed of the false positive many times.
Maybe they should prevent people from downloading Chrome instead.
I fixed it by replacing the software_reporter_tool.exe with a blank file named "software_reporter_tool.exe" and setting it to read-only.
>As applied in Chrome Cleanup, ESET’s technology is used by Google to alert users about unwanted or potentially harmful software attempting to get on users’ devices through stealth, for example, by being bundled into the download of legitimate software or content. Google Chrome, using ESET’s security technology, then provides users with the option to remove the unwanted software. Chrome Cleanup operates in the background, without visibility or interruptions to the user. It deletes the unwanted software and notifies the user once the cleanup has been successfully completed.
https://www.eset.com/int/about/newsroom/press-releases/compa...
I think it's foolish to go use software like this, and expect some privacy to happen. Windows and its user are just not on the same page.
What refreshed my hope in IT is the FOSS ecosystem. Where software is passively uncaring about me, the user, instead of working actively against me, which is the case in most of proprietary stuff nowadays.
Well, you run the tool again. It even tells you to do that after making changes.
Great credit to the authors of the tool. I used it many times when I was stuck with windows - and I'm grateful that they did all the work to make it.
I don't think it's possible to (easily) figure out when to run something right after the updates change any settings, but it's a good idea to automate away manual work as much as possible!
The person that you're replying to certainly has a point about having to run the tool manually being a hassle. Sadly, at the moment there are also no ways to automate running the tool (that i know of), since it's GUI only, as opposed to offering CLI functionality or silent launch options.
But looking at the broader context npteljes has a point.
Why fight an insecure tool (let's say Windows is insecure for the sake of the argument, I do not have a strong opinion about it) then patch the security on top. Surely the obvious choice is to stop using the insecure tool.
Sometimes people want a technical answer, when the answer is to do the obvious. I don't think that is pessimism.
For the longest time I felt that I have the upper hand. That I could install a software for my every need, limit this, change that, bend the whole system to my will. But the realization grew on me, that me and the system are wanting two very different things. And whatever I do, I won't win. At most, we can be engaged in a cat-and-mouse game, as long as I'm up for fighting for it. If I'm not, then my cause is lost.
With this realization, I felt betrayed by the entity I otherwise liked very much. And this is the feeling I wanted to convey with my previous comment.
Windows is a threat to national security and Microsoft must be sanctioned. Business if they wish to avoid crypto lockers and actually care about "cyber security" will drop windows in favor of Mac/Linux.
My friend just put Windows 11 on his (original) Surface Go (Pentium Gold 4415Y, 8GB RAM, 128GB), and he cannot stop raving about how fast it is. He said he was considering putting Linux on it, but he isn't feeling the need to now. To be sure, that's not a 5400rpm desk, though, yeah, I haven't had to suffer through one of those in over a decade!
And who I think should change to Linux or BSD is not just business, it's governments especially. How they enable an auto-updating system of another superpower is beyond me.
Best way to forget about the existence of spyware (aka telemetry) that I found is to not connect a Windows box directly to internet. I configured my router to give it a gateway and DNS IPs which don't exist in the network. Eat that, Microsoft. And I can still connect to internet by manually setting a SOCKSv5a proxy to the router in Firefox and other software that I trust (make sure there is no automatic proxy discovery mechanism in the router).
Yep.
https://www.tenforums.com/network-sharing/178379-disable-wla...
And it appears it may be part of 20h2, not 21h1 update.
https://www.tenforums.com/network-sharing/178379-disable-wla...
And it appears it may be part of 20h2, not 21h1 update.
[1] https://wiki.archlinux.org/title/NetworkManager#Checking_con...
I mean, I do have a couple of containers up and running on a Raspberry Pi offering nothing but intranet SSH services while the containers are connected via OpenVPN to differnt VPN servers, so that I can use different browsers which connect via SOCKS each to one container in order to have one browser per country on one machine.
It never occurred to me that I can use this same technique (but without OpenVPN) in order to disallow that machine to connect to the internet but still have a working browser...
https://github.com/farag2/Sophia-Script-for-Windows
IMO the best and most holistic solution for debloating and de-botnetting Windows.
> Due to the fact that the script includes more than 150 functions with different arguments, you must read the entire Sophia.ps1 carefully and comment out/uncomment those functions that you do/do not want to be executed.
https://benchtweakgaming.com/2020/11/12/windows-10-debloat-t...
> Furthermore, as touched upon on the main page, 94% of critical Windows 10 vulnerabilities can be mitigated by revoking administrator privileges from the default user.
> Of these critical vulnerabilities, 94% were found to be mitigated by removing admin rights, up from 85% reported last year.
It's a very fine line, but they're mitigated by not running stuff as admin, not just removing admin rights from the main user's account. With Ameliorated, people will still want to set up software as admin and install to Program Files, so if they take the advice from the FAQ, they might think they're fine just having a separate Admin account they use for UAC pop-ups to install the programs, while leaving their main as a standard user, which is indeed not going to solve any zero-days compared to users just being able to click 'yes' at UAC.
0: https://web.archive.org/web/20170310043706/https://www.avect...
Same exact reason people should strongly consider staying away from LineageOS builds and other such things, where the dev team of half a dozen non-vetted anonymous forum users is responsible for everything running on your phone. The "open-source means security because code gets vetted" argument only applies to big projects like Chromium, where hundreds of major corporations with world-class software engineers review, and contribute to the source code. Not to Lineage, where every phone model has its own build and dev team, and each build gets used by maybe a few hundred or thousand people, and reviewed by practically nobody. If there was one single Lineage build for all phones, I'd feel much more comfortable with it.
Though I have zero reason to distrust the Ameliorated folks, you generally never want to mess with software (especially OSes) downloaded from anyone other than the official vendor. The risk of using this is much higher than running proprietary ShutUp10, which is already non-zero since it's proprietary.
The community is NOT stupid. All it takes is one person to find out someone is trying to be malicious, and mass ostracisation will take place. For most of civilization we didn't need corporate overlords to tell us who to trust --- that's a very very recent development.
where hundreds of major corporations with world-class software engineers
LOL. The same "world-class software engineers" who brought us https://news.ycombinator.com/item?id=18189139 and are constantly fighting against the user?
It makes no sense to compare how we live and behave in real life with the Internet.
Or
https://old.reddit.com/r/TronScript/
If you have trouble opening any reddit website on mobile change "www" with just the letter 'i' or 'old'.
Once they don't allow these workarounds I am leaving reddit for good.
I will leave reddit too if they remove the old version.
>DO NOT DOWNLOAD TRON FROM GITHUB, IT WILL NOT WORK!! YOU NEED THE ENTIRE PACKAGE FROM r/TronScript
> Download Tron. The download links are in the top post in /r/TronScript. If you download the self-extracting .exe file, run it and it will extract tron.bat and the \resources folder to the current directory. Copy both of them to the Desktop of the target
Why package a BAT file with an EXE? Even if it has to be distributed in a container, why not a simple ZIP?
And the subreddit literally has a thread with a table that contains download links and a torrent, why would you not include that in the readme?
The reason is present the software as open-source while in reality it's closed source with unimportant data files being published on GitHub.
I dread to think how many well-meaning sons and daughters have run it on their parents and relatives PCs and then left, leaving behind a system that is now a nightmare to use.
Also, it takes literally hours to run. I mean, what the hell? ShutUp10 is done in seconds.
I probably still won’t trust it on a critical system without a reputable audit though, I think I’d still prefer to either trust Microsoft or Apple or go run OpenBSD or Linux instead.
It's explained in the help.
(Then again, the double negatives in Windows' own Group Policy Editor, where some if not all of this stuff is also configurable, are just as confusing sometimes; but there, at least the UI controls themselves don't add any more ambiguity.)
[x] stop unwanted apps windows auto-installs
[x] start menu suggestions
[x] ads in explorer
notice how the first checkbox has "stop" and the second and third don't? to me, if "ads in explorer" is checked, it means you have ads in explorer. not to the winaero guys though. if "ads" are checked, no ads. sometimes. sometimes if "stop ads" is checked, no ads.
my favorite is android, where you have a toggle, and depending on how it's set, the description of the toggle changes. so you have the toggle "off" and it says "disable this feature."
"Gold Microsoft Partner"
To attain a competency, partner must:
Pass required exams and skill validation.
Meet performance requirements.
Pay the annual fee.
$4,730If they left it enabled by default, but provided an option to opt-out, realistically only a small segment of users would do so, and most of them would likely be power users who are already taking other steps to try to prevent telemetry being collected and/or sent. So they'd take an insignificant hit to telemetry, but would gain a lot in goodwill.
Any reason not to do this?
Anti-government meme made with GIMP at a specific timestamp? One search through the telemetry logs to find who exported a file at that exact moment.
Any data collection is also government surveillance unless proven otherwise.
https://blogs.windows.com/windowsexperience/2018/01/24/micro...
I don’t work for microsoft anymore but I laugh at these sorts of suggestions. I don’t know much about bing but I do know a decent bit about the telemetry pipeline and the idea of an anti government meme detection is ludicrous at best.
That's a fun strawman you made, but the actual idea in the post was that telemetry might note when different programs do events like save.
You're replacing an abusive part with another with the same potential of abuse and you can't check of modify either of them.
They have a clear business model: Develop software for Windows that companies need. See their About page: https://www.oo-software.com/en/company
Hence, it is clear what benefit they draw from releasing this software for free: Marketing. They are not in the business of brokering user data or mining bitcoin covertly. This tool isn't even installed, it's "run once". To me, that's about as trustworthy as it could be.
Now.
It is not a matter of having incentives. It is a matter that they can abuse and you simply have no way to check or control it.
- Run it in a Windows VM. The program could detect this and not phone home in this case, of course.
- Monitoring on network level (wireshark on same network, Pi-hole, router itself...). This is virtually impossible for the program to circumvent.
You could also audit the changes it made to the system (resorting to stuff like diffing disk images before/after if you really want zero trust) to verify that nothing sneaky was left after running the program once.
They technically don't have an incentive now, but if they ever get one, it'll be super easy to abuse this position to embed malware. Don't think of the threat as the current company, but someone buying them for $millions and quietly doing this years later.
This is portable by the way, so I don't really see the point in worrying about rogue company takeovers.
because it does not run as a service/persist, it will be undone by the next big windows update anyways.
I'll leave this here: https://ameliorated.info/
No Windows Update for you, so security is debatable.
Only caveat: There's no way of telling what versions of W10 it's compatible with (I imagine it breaks some versions). I have an old VM with AME installed and manually enabled updates by hacking the registry. (You could also alter the .BAT script to enable updates, but you have to know what to remove).
This project is cute, but I only ever used it for an offline sandbox for running low resource games and cracked versions of Photoshop. I am scared as shit to connect this thing to the Internet. I only connect to receive updates.
[0] https://wiki.ameliorated.info/doku.php?id=documentation_20H2
What do you mean by that? AME 21H1 was released just the other day.
> This project is cute, but I only ever used it for an offline sandbox for running low resource games and cracked versions of Photoshop.
It's perfect for VM use, but I would never use it as my main OS.
Thanks for the update!
If it was open source, then maybe there would be some reason to trust it.
They could also give people a true option during installation to really for-really-real disable telemetry regardless of what license home, pro, enterprise, ltsc they are using.
Maybe some one could write an application to delete as many files as possible from a pristine windows copy to turn it simply into a kernel launched by a bootloader. Is there any project that does that?
These companies can exist the same way Winrar can exist: give people the tool for free, wait for them to want to use it at their business and sell the subscriptions there. Businesses are much more wary if pirated software than consumers so Winrar manages to survive to this day. To me, the amount of telemetry collected from modern crapware indicates a lack of trust in the product from even the developers themselves, which in turn proves to me that the product isn't very good on some level I might not be able to see.
Just because something is free doesn't mean it's not reliable if there are business subscriptions funding the product itself. The way programs stalk their customers these days used to be rare and the O&O team seems to follow the old software shop practices rather than "modernising" and adding the very thing they try to block to their own product.
I actually saw some people using mostly FLOSS on windows as a step before full migration away from it.
Also, since it is very intrusive, I don't think running it into a sandbox may give good diagnostics.
Windows loves to silently update things, even if it ends up breaking everything, too. Especially drivers where it isn't super obvious that it was updated and something just stops working. Windows 10 is _way_ more aggressive with forcing updates than 7/8 were, automatically re-enabling Windows Update after 30 days of disabling. The easiest solution that I've found is just blocking everything at the DNS level. They can obviously use IP addresses as a workaround if they really want telemetry, but I haven't had issues after blocking a bunch of MS domains in the hosts file.
> Gold Microsoft Partner
Why would MS partner with a company that makes software to "bypass" their spyware?
Why would O&O partner with a company that has spyware in the OS, then proudly display the Gold MS partner badge on the same page?
Why is the source code obfuscated?
Think about it.
Gold competency: To attain a competency, partner must:
Pass required exams and skill validation.
Meet performance requirements.
Pay the annual fee.
$4,730It seems less malevolent in that light
A screenshot of the application on the website shows this option. I don't understand; are advertisements via Bluetooth some kind of Windows functionality and how does it work?
Some Bluetooth LE devices use advertising as a way to constantly send out payloads without a direct receiver.
An example to follow
I went from perfect system health , progressively into blue screen death, it got so bad that it happened every 2 hours after spiking my i7 to 100% cpu use. The decline happened within a month of a win10 update back in Aug/Sept.
A couple of MS support tickets and a windows reinstall later, I finally gave up had to do a complete fresh PC install to fix.
No issues since but i still get the occasional 100% cpu clock.
Ive also turned on windows10 selective update download.
Sounds like every Windows since 3.1. Instead of telemetry I wish they'd focus on making an OS that stays robust and performant indefinitely.
Sure wish I could run MSFS 2020 in Linux. (I have X-Plane for Linux but the whole-earth scenery of MSFS 2020 is pretty compelling.)
Unfortunately I can only use windows 10/11 as AMD has no driver for RAID on Linux. https://www.amd.com/en/support/chipsets/amd-socket-strx4/trx...
Using Asus hyper with 4 nvme drives on RAID. Anyone else in this situation?
https://raid.wiki.kernel.org/index.php/RAID_setup
That AMD-"raid" is Software too..the same as linux.
~pure Hardware raid's never need drivers, because you tell the hardware (raid controller) to present the hard-disks as one (or whatever you want) device to the Operating-system. Some management tools are sometimes used (start raid scrubbing etc).
BTW: Don't use Raid5 if you don't have a UPS (if you use software raid), or a battery buffered write-cache (hardware raid) aka write-hole:
https://serverfault.com/questions/844791/write-hole-which-ra...
I wonder what the sales pitch would be to sell privacy focussed products to the average Joe.
Not sure where you got the idea of “icloud syncing your every move” but literally every icloud implementation can be disabled at your discretion.
I for one only have my reminders, wallet, calendar and drive synced.
Even with that said, none of this implies a lack of privacy in any way.
And it’s sole purpose is to help people find their devices, it’s saved many people i know from a very large catastrophe.
Ironically, Linux sometimes has better driver and software support for specialized things like Thunderbolt ethernet adapters, or software if it was written for MacOS but later adapted to Linux because of their similarity within the scope of POSIX. And, because Windows can't run 16-bit software on 64-bit CPUs at all, Linux has the total advantage here because WINE works with 16-bit as well.
Broadcom/Realtek (sometimes)? Good luck. Intel/AMD/Aquantia? Probably good to go.
There are vendors that give Linux first-class support; buy them.
edit: Realtek is a little hard to pinpoint, they tend to have drivers... but fairly buggy.
I have to replace the r8169 module or something similar with r8125 for my (onboard) networking to work under stress. If I push too much bandwidth, it'll just drop.
Older versions of Windows were the product, and the customer was the end user
With New versions of consumer Windows, user data is the product, companies and advertisers are the customer, and end users are the data source.
Commercial/Server versions of Windows not so much.
okay...let's think. lets take for example postgresql. all right is opensource, we all love it. but how some company uses it - well this is not open source. only few businesses dare to be open source and typically open the non-critical parts.
why so much pressure on MS?
the idea that the world is embracing opensource is absolutely disconnected with the reality ever since the idea of open source came to existence.
once again - even when the building are open source, the way they are tied together is usually not. and their usage in business systems - also not open source. period.
there is fair chance, that whoever is reading this comment works is paid by a company that is using open source, but is not open sourcing.
"WPD 1.5 and DashboardX 1.0 with Windows 11 support coming in mid-October!"
> Wieso ist die Software nicht Open-Source? "Die Community" könnte mithelfen, die Software weiterzuentwickeln etc. …
"Why is this software not Open-Source?"
[0] binisoft.org/wfc
Apparently you cannot:
> On May 2017 a security researcher named Mark Burnett demonstrated that disabling the default data collection toggles, found in Windows 10's settings app, are entirely useless. Furthermore he showed that even through using intensive group policy modifications, in a process heavily scrutinized and iterated upon over several days, he was not able to prevent Windows 10 from sending critical, personally identifiable information with certainty.
From: https://wiki.ameliorated.info/doku.php?id=faq
In my last job I had contact with Microsoft and I approached them about datamining issues several times. I noticed they simply don't understand the concerns at all. Microsoft is becoming a highly 'data driven' company and every time I approached them about data gathering the response was along the lines of "Oh but we only use this for improving your performance / our products / whatever". They think it matters what the purpose is, they don't understand (or they don't want to!) that some people are against telemetry whatever the reason.
Our own company is thinking along similar lines, with the exception of the German parts of the business, for whom we had to make some exceptions. I'm not German but I'm heavily aligned with their thinking on this.
https://cdimage.debian.org/debian-cd/current/amd64/iso-dvd/
(The easiest Debian install experience might be to ignore the scary official documentation, simply burn that hybrid installer image raw to a USB stick or DVD+R, boot it on your target PC, and have an Ethernet cable handy until you boot your installed pristine Debian and then can enable install of "non-free" firmware. If you need help, I'd use Web search.)