Windows 10 minus the spyware plus added stability and security
ameliorated.info
ameliorated.info
Ok, so PSA: if you don't want "Spyware" don't use windows. In Forensics, you learn there are many many ways windows tracks what you do, some of which can be disabled but it is all architectures into the OS. If you looked at a specific folder in explorer, that can be proven in court, executed a specific program? At least 4-5 ways come to mind . Take a peek at c:\windows\system32\winevt\logs\ (equivalent of /var/log/) and that's just one place.
I mean the spyware has measurable and valuable security benefits. If you wanna really test your malware dev skills, leave cloud submission turned on Defender and write any basic malware (harmful not just undesirable) and avoid detection for longer than a day. It was very hard when I tried it (for legit purposes).
I bash on Linux because of all its problems (only because I love it and want to see it improve) but if you want privacy, use Linux, the cliche holds true. You can always use windows in vbox+seamless mode for most things or on a separate device if you can afford it.
Also, closed source means it is hard for me to be sure which of those logs are sent to MS.
But comparing logging to spyware is nuts.
Event logs are just one of endpoints for event tracing mechanism and event viewer is just one crappy UI for that. You can turn on/off various logging to your hearts desire, including various diagnostic/tracing info. You can go all the way to capture stack traces, cpu context switches and whatnot. Windows is pretty configurable in this regard.
Also telemetry is well documented and configurable: https://docs.microsoft.com/en-us/windows/privacy/configure-w...
Defender doesn't hide option for cloud based scanning and it is up-front in settings. I dunno if it is enabled by default or not, but in our org, we had to explicitly rollout changes to enable it (we are pretty locked down by default)
The subject here is personal use, not corporate use. For example you might torrent a movie and then uninstall the torrent application, files and downloaded content. If you get sued and (i know it is rare) your windows install is submitted as evidence it can be proven that you executed the torrent program, the torrent program transferred so many bytes and that you opened the folder of the torrented content without looking at any file directly related to the torrent app or windows event logs. Or let's say you downloaded content from a site but then cleared your browing history and uninstalled your browser. Thanks to motw the downloaded files on your pc show the sites frol where you downloaded them and the referrer that lead to you visiting the download link. These are only some examples.
Have a look at what a typical Android phone sends out! Including your GPS location! Apple isn’t immune either because the Facebook SDK that’s included with everything would make the NSA blush. TikTok even tracks your phone motion sensor.
IMHO raging about 30-year old diagnostic features is misplaced anger. Be angry about how every piece of software now goes through these stages:
1) Opt-out telemetry only collecting the important stuff, we promise!
2) Okay, collecting it synchronously was a mistake and it slowed down everything for everyone that’s not sitting in our head office. We fixed it though, don’t worry!
3) Umm.. apparently some people are behind corporate web proxies which makes the async code leak threads and melt CPUs. We fixed it though!
4) Some people have used the newly added proxy support to inspect the encrypted blob. We promise that it was an honest mistake collecting every single point of information we possibly could about your system including mouse movements and key presses. Don’t worry, we fixed it! We now “anonymise” the information. Don’t worry about why that’s in quotes.
5) Those socialist Europeans sued us when we said we deleted their data but it was still there when they reactivated their accounts. Oopsie! Our bad. We promise to “wipe” your data including telemetry when you request this form. Fill it out in triplicate and fax it to this Cayman Islands number please.
6) We can no longer sell our software in some jurisdictions. Don’t ask why or what that implies about how we treat our customers in other jurisdictions with weaker legal protections.
Your list of complaints is whataboutism and is not directly related to OS privacy expectations and reality.
Linux is better at this because it gives you more control over what is logged and the code is open source.
> There’s definitely a demand for windows that can play games and do nothing else.
It's called a "games console". Microsoft makes one called XBox.
I like being able to use emulators. Can XBox do that?
I like being able to use mod's for any given game. Can XBox do that?
I use Linux for my gaming these days because I just don't like Windows, but even Windows is much more powerful for gaming than a console.
There's a place for console's, but they don't replace everything.
I suspect XBox isn't good for this, but the Nintendo Switch is actually probably better than a PC for this particular usecase.
The general-purpose stuff (emulators, mods) I agree with, though.
XBox I actually called out specifically because when we got an XBox 1, we discovered there is no way to do anything - setup of the console, launching a game, etc - without having an XBox Live account per user of the machine.
PC gaming is a weird and wonderful ocean; console gaming more like a highly curated pond.
I imagine using steam in big picture mode would be equivalent if you're not streaming though. Maybe it's something else, I just can't remember a Windows pop-up ever interrupting my gaming whether I'm playing on my TV or not.
Bonus: disabling autorun is better security!
Important account credentials are on macOS or iOS. Local copies of my important files are on a system running Linux, and the Windows machine doesn't have access to that (doesn't need to, all I do on it is play games, if I didn't PC game I wouldn't have Windows at all).
[EDIT] However, mine does have Windows Update turned on.
>> Some of us have windows just to play games
What bank accounts do you think are on that machine? Perhaps it's risking credentials to ex. Steam and such, but again, if all you run is games where are you getting malware from?
Edit: Actually, to steel man the argument: If you pirate a game and get a keylogger that way, and then type in your credit card to buy a game (ex. on Steam), then you'd have a problem. I maintain that it's perfectly possible to maintain a... "DMZ PC" for games, but there are ways for it to end badly.
I don't think there's a need to dramatize and exaggerate. Once you get setup on Windows and uninstall the stuff you want to uninstall that’s pretty much the end of it.
https://docs.microsoft.com/en-us/windows/security/threat-pro...
You can make it log everything, but the performance hit is noticeable.
Next thing you’re going to start complaining about dtrace spying on you.
Im a Dev. But outside of reversing games for hacks and cheats I havent done anything with Windows specifically.
Any links, books, articles, etc.. you can provide to learn more about this?
I do agree that trying to make a consensual OS out of Windows is an uphill battle. If you're stuck using it, however, for whatever reason, a patchkit like this is better than nothing.
Good luck if explorer previewed wrong file.
Good luck if trusted website has been hacked and serves malicious content.
Good luck if you do npm install.
You'll find most if not all of these in `.bash_history`, wouldn't you?
Probably, it's possible to setup an install of Linux in such a way, that the user won't leave any traces in the system, but this is definitely not the default behavior. And the system setup in this way is likely a pain to use. But if you have a specific need, by all means, go for it. After all, with Linux you're in control.
But saying Windows is spyware because it logs your activity locally is stretching it.
I don't know how much of this MS collects and anyone who says they do, I would challenge them for evidence because there are many plausibly deniable and benign reasons to extract this information from the host.
I would say at best windows is spyware-friendly.
If I workes for the CCP and was instructed to get a list of people that used Signal so they can be sent for re-education, I would not even look to see if Signal.exe is installed in windows, I would just check prefetch and srum.
Spyware is not the same as local system logs. Spyware in this case is software that sends unnecessary or intrusive information to Microsoft. The goal of Windows Ameliorated is to remove spyware, not prove your innocence in court.
You used Windows Defender as an example of a security benefit. There are alternatives to Windows Defender, and IMO If you're a tech literate power user, an AV isn't useful in most cases. If you have the time, consider reading this: https://wiki.ameliorated.info/doku.php?id=antivirus Personally I believe antivirus software in general does more harm than good, as they are generally quite resource hungry and privacy intrusive.
Also, AME does greatly help to mitigate the attack surface of Windows:
Windows Ameliorated ships with a non-administrator user account by default, which mitigates ~70% of Windows vulnerabilities. (Source: https://web.archive.org/web/20210618023509/https://www.beyon...). Of course you can still do admin actions, it just requires the admin password.
You can even update Windows offline if you want to.[0]
It's quite refreshing to be able to prep a USB stick containing all the updates for a clean install of a certain build of Windows and be able to deploy them without needing to connect to the internet.
Cracked Windows, no security updates since 2018, iso distributed through some telegram channel. This is the software equivalent of trying to buy a homemade vaccine from craigslist because you're afraid that Bill Gates is going to microchip you.
I do agree removing Windows Update does pose some security risk, however I don't think said risk is nearly as bad as some make it out to be, and I personally think the benefits of Windows Ameliorated greatly outweigh any security downsides.
Also, AME does greatly help to mitigate the attack surface of Windows:
Windows Ameliorated ships with a non-administrator user account by default, which mitigates ~70% of Windows vulnerabilities. (Source: https://web.archive.org/web/20210618023509/https://www.beyon...). Of course you can still do admin actions, it just requires the admin password.
I'm okay with providing documentation, tools and scripts to remove the cruft and increase privacy within Windows 10, but the ISO linked from a Telegram channel is dubious at best.
However i had to chuckle at "is dubious at best", since all the spyware shipped with Windows nowadays... is perhaps equally dubious.
This already happened when Linus Tech Tips posted a video regarding Ameliorated [0].
https://linustechtips.com/topic/1243421-windows-10-ameliorat...
There is detailed documentation for performing a manual amelioration, it uses fully open-source scripts. (https://wiki.ameliorated.info/doku.php?id=documentation_21h1)
I can't imagine this is more secure than standard Windows 10.
Secure in literally any other way: outside the scope of the project
What is a good NAT as opposed to a bad one?
"Dude the DHCP on this network is AWESOME" lol
In any case, if you wanted security in the way you describe, how would you justify running Windows 10 at all? The onus isn’t on this project to secure Windows when they had no part in making it insecure to begin with. If Windows were open source, these measures wouldn’t be necessary, and wouldn’t result in less security. This is the current best effort that the devs can do to accomplish their goals. It’s fair to criticize the goal or the results, but issues you’re describing are present in stock Windows 10 to begin with.
I’m sure that some kind of auto build script could be created, so that whenever new Windows Updates are released, a new build is created.
Different people have different attacker models. I can imagine something like this would be perfect for keeping a mostly airgapped machine to access archives of documents created by Windows. (Or to use legitimately licensed, pre-everything as a service software in perpetuity)
The entire site screams "download this and use it in production". They have big friendly ISO download buttons front and center, with absolutely no disclaimer anywhere that it might be a terrible idea. If it truly is merely "educational", then this is highly irresponsible.
> AME is developed for educational purposes only, which emphasizes an effort to reverse engineer, disable or replace components of the Microsoft Windows 10 operating system. The goal is an endeavour to better understand and mitigate the collection of Personally identifiable information (PII), as has been clearly outlined by numerous outlets covering the topic, including comments by famed whistle-blower Edward Snowden. Another goal is to replace included proprietary Windows software, such as the Edge web-browser, with ethically verifiable alternatives using open-source licenses.
https://wiki.ameliorated.info/doku.php?id=faq#legal_consider...
This isn’t the pwn you think it is, lol
Also, as a personal testimony, my whole family and I have been running AME as a daily driver for awhile now, and haven't run into any significant issues (funnily enough, I've had less issues with Windows Ameliorated than I have with Windows). From my experience it really is stable, and IMO even more stable than stock Windows.
I ask that you actually try out a project before making claims about it.
Also, AME does greatly help to mitigate the attack surface of Windows:
Windows Ameliorated ships with a non-administrator user account by default, which mitigates ~70% of Windows vulnerabilities. (Source: https://web.archive.org/web/20210618023509/https://www.beyon...). Of course you can still do admin actions, it just requires the admin password.
I'll take my chances with Microsoft-sanctioned telemetry over whatever this is.
It's also warez and no one but microsoft can distribute Windows ISO images.
The ISO has been used by hundreds of people, with no sign of malicious intent, so personally I'm willing to trust that as well.
-In order to secure the system properly, it is strongly advised to revoke administrator privileges from the default user.
-By using any of these images you agree that you have obtained a genuine product key or are able to activate by an other authorized method.
-Can AME be activated with a legit key, like normal Windows? No.
This is ludicrous.1. ~70% of the Windows attack surface as of 2020 is caused by using an administrator user (Source: https://web.archive.org/web/20210618023509/https://www.beyon...). This does not mean you cannot do administrator actions, it only requires the admin password on each UAC prompt.
2. This is for legal reasons. You're not going to get in trouble if you don't follow it, and many people don't. (Unless you're a business)
3. Windows activation has telemetry, and there's no real reason to have it in the first place. If you still wish to activate with a license key, you can activate Windows before performing a manual amelioration (Guide here: https://wiki.ameliorated.info/doku.php?id=documentation_21h1)
For everyone else: Chris Titus Tech's debloat script is what you want especially if you thought for a millisecond installing Windows from this ISO is a good idea.
The script you mentioned does NOT fully disable or remove the spyware within Windows. Windows Ameliorated gets rid of the spyware on an executable level, meaning the functionality of the spyware is not just disabled, but completely removed.
This doesn't seem better....
Certainly. The question is what provisions the software has made to mitigate those potential vulnerabilities by notifying users that a patch is available and allowing them to automatically apply that patch.
Deliberately removing these mitigations from a piece of software which is highly exposed to exploits, like a web browser or an operating system, is nothing short of irresponsible.
Most no-auth exploits take advantage of the user already being an administrator, and then bypassing UAC for example. The configuration mentioned above would likely mitigate this issue, although I'm not educated enough on this subject to say for sure
Windows can be ameliorated completely legally by doing the amelioration process manually and entering the key before running the scripts. (Guide on the ameliorated.info site)
This thing is not on the list, because it's obviously extremely sketchy (in addition to it being illegal / piracy / etc. the actual "functionality" of removing Windows Update and Windows Defender is bonkers).
As far as Windows Defender goes, I believe antivirus software in general does more harm than good. They are generally quite resource hungry, and won't prevent most zero-days or unknown malware. If you're a tech literate power user, I don't think an AV is useful to you.
I do agree removing Windows Update does pose some security risk, however I don't think said risk is nearly as bad as some make it out to be, and I personally think the benefits of Windows Ameliorated greatly outweigh any security downsides.
Also, AME does greatly help to mitigate the attack surface of Windows:
Windows Ameliorated ships with a non-administrator user account by default, which mitigates ~70% of Windows vulnerabilities. (Source: https://web.archive.org/web/20210618023509/https://www.beyon...). Of course you can still do admin actions, it just requires the admin password.
- < v11
- easy to find (versus looking on torrent sites for ...)
- debloated
- will not update and restart itself if granted internet access temporarily!
The last one has really screwed me when setting up fiddly product demos on win environments the night before an early morning meeting.BTW, torrent is also here if you don't use telegram. Review comments are meh but we'll see. https://archive.org/details/windows10-ame-21h1-2021-08-09
It's not always as simple as "want privacy? Switch to Linux!". Some people want Windows as well as privacy.
echo '#!/bin/bash' | cat - script.sh > temp && mv temp script.sh
Is there a benefit to doing this instead of just appending to script.sh? I see the last "echo '#!/bin/bash' ..." line, but why not do that first?I've found that to be a very simple, well documented antidote to Windows constant desire to violate my privacy
I run it every time you see a new windows update roll through and it has constantly kept up with their most egregious attempts - feels like a good middle ground
https://t.me/amereleases -> Telegram.
No matter how many times you go around all the links, you only get the same BS. This feels like a "join Telegram" scam.
If this were a real project, they wouldn't require getting an account to try it out.
Even if it's un-toggled the weather feature in the taskbar works fine. At this point I've given up, need Edge unfortunately so can't use LTSC.
My whole family and I have been running AME as a daily driver for awhile now, and haven't run into any significant issues (funnily enough, I've had less issues with Windows Ameliorated than I have with Windows). From my experience it really is stable, and IMO even more stable than stock Windows.
What makes you think most people would be better off running LTSC? For privacy, Windows Ameliorated is by far the best option.
If you have the time, I am curios about what stopped working. Thanks for your input nonetheless
As far as WU goes, personally I think it is overrated. The only real use for them is security, however I've found that even that is really not necessary at all. Just from my own experience I've never seen anyone run into issues/get infected purely because they didn't update, and I think that if you're tech literate it really is unnecessary, to a certain point that is.
It is still a tradeoff, but I personally find the benefits and peace of mind more valuable than missing out on security updates.
But I don't see how this version is more secure? Yes, no telemetry and lots of services disabled. But will lack updates, right?
(*): To be precise since "grouped" means different things: In 7's taskbar, multiple windows of the same application would be forced to be adjacent. I preferred my windows to be ordered by context, not by which application they belonged to, eg VS-terminal-explorer-browser for project 1, then VS-terminal-explorer-browser for project 2, and so on. Eventually 7 Taskbar Tweaker became a thing that allowed this, so I switched.
Also since it disables updates, doesn't this mean I run a vulnerable system 'frozen in time', as it were, impervious to the latest patches?
It does lack Windows Update yes, as WU is a threat to privacy. Windows Ameliorated helps mitigate this by shipping a non-administrator user account by default. Of course you can still do admin actions, it just requires the admin password. ~70% of Windows vulnerabilities are caused by using an admin user (Source: https://web.archive.org/web/20210618023509/https://www.beyon...)
P.S. Personally I think security updates are a bit overrated, as in all practicality, there's extremely little chance of getting attacked unless you download FreeFortniteVbucks.exe
Are there any companies that deploy this internally? I would expect that some law firms adverse to Microsoft, and Microsoft competitors, might want to do so.
I should hope not. This is a cracked copy of Windows. The FAQ explains that it can't even be activated properly, as some of the components required for that process have been removed.
https://wiki.ameliorated.info/doku.php?id=faq#can_ame_be_act...
Forcing people to create or sign in with an account is bad, particularly when one considers that the ISO is of questionable legality.
What would be infinitely more useful would be a program which directly modifies an ISO image that the end user can download herself directly from Microsoft.
Usability? What's wrong with its usability? There have been a lot of BS claims in this topic but this one looks the most egregious. Anyways, the topic was hidden from the main page and can only by found by a direct link.
Recently I've spent many hours using Windows 7 on one computer and Windows 10 on another.
So far, I prefer Windows 7. For the difference in "usability", maybe you mean the changes and/or additions since Windows 7.
To me it seems that there are some people at Microsoft who have a vision of user interface, user experience, usability they want and want Windows to move to that. The early, seed example of their vision is the GUI, graphical user interface, but I am guessing they want to move to hand gestures, eyeball tracking, special 3D goggles, lots of inferencing to guess, anticipate what a user wants, etc.
Some people can really like that vision, especially if it is done well, but that seems difficult.
For some parts of computing, versions of such a vision might be the right things to pursue.
For me, for a computer I would use, I don't want the vision. The changes I saw from Windows 7 to Windows 10 seem to be part of the vision, and, whatever they are, I don't like them. One big issue is, I don't know what all the changes are: Apparently I'm supposed just to discover the changes. Well, maybe I've discovered less than half of the changes.
Some of the changes I really hate: E.g., with Windows 10 too often suddenly all the open windows disappear! And too often I'm trying to work quickly, by accident hit some strange key combinations, and suddenly big, goofy things happen.
For me, personally, my main used of a computer are just (a) typing text, (b) Web browsing, (c) watching movies on DVDs, (d) occasionally printing some letters or addressing envelopes.
So, my most heavily used program is the one I use for nearly all my typing, my favorite text editor, Kedit -- right, trying Emacs is on my TODO list. Otherwise, I use Firefox and Chrome for Web browsing and VLC or PowerDVD for movies (or music CDs).
Otherwise my favorite part of Windows is the hierarchical file system NTFS (new technology file system), and to help me use that I use the scripting language Rexx, have written a lot of macros, and have written a simple shell (runs in console windows and gets my typing and does the right things with it).
Windows 10, 7 and maybe even still XP and 2000 are all plenty good at all of that.
So, point: For me, personally, for the parts of Windows 7 I use, usability is fine; I don't want to be bothered with changes; in Windows 10 I'd welcome a big OFF switch so that I could get rid of the results of the vision.
For me, my car is not my destination and is just a tool I use to get to some destinations. For my personal usage, my computer is not my destination but just a tool. For me, the goals of the vision make bad tools.
I should insert: For me, often GUIs are inefficient because it is tough to script such programs, that is, run one of them 200,000 times to automate some work.
For the rest of my interest in "usability":
I'm trying to do an Internet startup, that is, a Web site. For that I've done some programming, appear to have the code working as intended, but no doubt will need to do more. And I will need to handle some dozens of terabytes of data.
I settled on Visual Basic .NET for the programming language, ASP.NET for the Web pages, ADO.NET and SQL Server for the data base.
For .NET, it looks quite capable. Also, Microsoft seems to be taking it very seriously, and a lot of important work is being done with it. So, it seem like a good choice for my startup.
Visual Basic .NET (VB)? It appears to be a perfectly good way to get to the .NET framework and the CLR (common language runtime). C# seems to have borrowed some of the C syntax that, as I recall from Kernighan and Ritchie, was deliberately idiosyncratic. To me, the VB syntax is more traditional, more like Basic, Fortran, Algol, PL/I, Pascal, etc. and is easier to teach, learn, read, and write and less error prone. My understanding is that the semantics of VB and C# are (or long were) essentially the same, and that there is a program to translate from either one to the other. So, the difference is syntactic sugar.
For .NET? I welcome the work on managed code, garbage collection (management of dynamic memory allocation and freeing), etc. If managed code is a little slower than C, C++, or assembler, fine with me: Current processors with 8, 10, 16, etc. cores and clock speeds 4+ GHz seem plenty up to running managed code for the Web site of my startup. And for servers processors with, what, 256 cores are coming?
For the last time I checked ad rates, a day my Web site with a 4.0 GHz 8 core processor gets busy should be a good day for my bank account.
For Visual Studio, once I tried it for about an hour, could make no sense out of it, and never tried it again. I type my code into Kedit. So far, it's worked fine. Then I wrote a few little macros that make Kedit work even better. Happy camper time. I know; likely Emacs could be still better.
For my business, writing and running .NET code as above is the "usability" I want.
If Microsoft wants some improvements, then okay:
(1) Copying files for backup: Robocopy seems to work, and it is what I use. Getting all the options set took a while. The log file it writes is ugly, and I can't make any sense out of a lot of it.
To me, XCOPY has some serious problems with how it handles dates and times.
For Microsoft's "Windows 7 backup", for Acronis, etc., I can make little or no sense out of them.
So, for a step forward, I'd like a better backup program. Right, no vision thing. No GUI. Command line only. Excellent design. Good documentation.
(2) List of the names in a file system directory tree.
Commands DIR and ATTRIB are ways to get a good list. I have a command SUBDIR from Rexx that is my favorite. But a better program would be welcome. Right, no vision thing. No GUI. Command line only. Excellent design. Good documentation.
(3) Check two files for equality.
I just want to see if two files are equal or not. Don't assume anything about the contents of the files -- don't assume that they are lines of text, from Office Word, etc. Don't try to find all the places the two files are different or the same.
So, COMP is the wrong tool. And FC can't handle legal file tree names.
So need a program that will compare two files for being equal, yes or no, and with the output only the first byte where they are not equal. Right, no vision thing. No GUI. Command line only. Excellent design. Good documentation.
I wrote my own using Rexx and its function Charin.
Now for the important topic of security:
Some months ago I did download that last update for Windows 7 Professional. Then I noticed that apparently that update also is for the corresponding edition of Windows Server, apparently 2008.
Uh, I should interject here: In my startup, I will need some simple, routine, lightly used file sharing among a few computers. From my information gathering, I conclude that such file sharing will be a lot easier with Windows 7 Professional than with any version of Windows Server. So, at least for the early months of my startup going live, it appears that it will be easier to use Windows 7 Professional than Windows Server.
So, I begin to conclude that with that last update Windows 7 Professional is as secure as Windows Server 2008.
Then I have to assume that for some years many of the most important companies in the world ran fine on Windows Server 2008.
Gathering information for my planning for the first months of going live with my Web site, I learned
(1) For updates, e.g., for security, Microsoft seems to be cooperating with customers who are still using versions of Windows Server that go way back, to 2008 and before.
(2) Microsoft has announced that they will continue to have security updates for Windows Professional into 2023.
So, from my need to make decisions based on limited information, I'm concluding that:
(a) Basically Windows, just the (apparently at most slowly changing) operating system itself is and has for 10+ years been quite, maybe rock solidly, secure. Maybe the US NSA (National Security Agency, the main US organization for communications security) knows better, but as just a startup entrepreneur I'm f'getting about such things. Sure, some hacker in North Korea might send goofy UDP packets at my IP address, but Microsoft needed to have Windows Server 2008 protect against those packets already 10+ years ago. So, let the goofy packets come; Windows should throw them into the trash bit bucket. If there really is a DoS (denial of service) attack or some such, maybe I should call CloudFlare.
(b) The security problems Windows 10, 11, etc. struggle with are caused not by Windows itself but by some of the common applications, maybe Web browsers, browser add ons, various programs distributed as EXE files, and some actions of careless users.
Point: Using Windows 7 Professional for my personal computing, startup software development, and startup Web servers seems fine with no worries about usability or security.
You also don't need to do anything special to get it working. However, I opted for the inclusion of a completely optional disk driver during install time to improve performance and sustainability.
You can provide a QEMU virtual CDROM with drivers during installation if necessary, and do the rest of your setup with QEMU native Samba file transfers followed by software installation.
I use the QEMU virtual CDROM to provide VirtIO drivers during Windows installation for super fast virtual drive I/O and DISCARD support.
-drive file=windows.qcow2,index=0,media=disk,if=virtio,discard=unmap
discard=unmap is absolutely essential to keep your QEMU QCOW2 file on your host from growing excessively as you delete stuff in your Windows guest. This is the main reason I use VirtIO.
To learn more about QEMU I recommend the Arch Wiki page on it
The main goal of Windows Ameliorated is to restore privacy, and it does this by removing said spyware on an executable level, not by just simply using registry edits or what have you.
Some people desire or require Windows, but they don't want the included spyware. Windows Ameliorated is for those people.
Do not use, do not download, do not touch.
It's based on the premise that Windows is spying on you which has never been proven/shown in the first place. Yes, Windows 10/11 send a ton of DNS queries - it's _not_ spying. Yes, Windows 10/11 send mini crash dumps and EXE files hash sums to Microsoft - that's _not_ spying.